mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Cloud deployment requires source verification for the exact merged commit. > - Contributor PRs leave lockfile updates to a separate bot PR. > - Most release checks can refresh an outdated lockfile while installing dependencies. > - Two Runner checks still require a frozen lockfile and fail after dependency changes. > - This PR gives those checks the same install policy as the other release checks. > - A valid dependency change can become deployable without waiting for another merge. ## Linked Issues or Issue Description Refs #13257. The dependency change in #13256 exposed this gap. The separate lockfile update is #13279. Related #12115 addresses the bot PR check trigger; this PR fixes exact-source cloud verification itself. **What happened?** [Cloud readiness for2083bf6](https://github.com/paperclipai/paperclip/actions/runs/34651761811) failed in the Runner scorer and chaos jobs with `ERR_PNPM_OUTDATED_LOCKFILE`. The commit added `svix` to server dependencies. The tracked lockfile still describes the previous manifest. The other release checks install with `--no-frozen-lockfile`. **Expected behavior** Every source check installs and tests the same checked-out commit. A pending bot lockfile PR must not block cloud readiness. **Steps to reproduce** 1. Check out master commit250deab, which retains the manifest/lockfile mismatch. 2. Run `pnpm install --ignore-scripts --frozen-lockfile`. It fails with the same outdated-lockfile error. 3. Run `pnpm install --ignore-scripts --no-frozen-lockfile --resolution-only`. It succeeds. 4. Restore the generated lockfile. This PR does not commit it. ## What Changed - Use `--no-frozen-lockfile` in the release Runner scorer job. - Use the same option in the reusable Runner chaos workflow. - Document why cloud source checks allow a job-local lockfile refresh. - Update the existing Runner scorer workflow assertion to match its install policy. ## Verification - All 457 workflow tests pass across `.github/scripts/tests/*.test.mjs` and `scripts/__tests__/release-verify-workflow.test.mjs`. - `actionlint` passes for both changed workflows. - Reproduced the frozen install failure against the real tracked manifest and lockfile. The refresh command passes in 4.6 seconds. - `git diff --check` passes. No lockfile changes remain. - No application source changes. Full local application typecheck, build, and test commands were not rerun in this dependency-free workflow worktree. Current-head GitHub CI must pass before merge. - After merge, verify both affected jobs pass on the exact master source even if the lockfile bot PR remains pending. ## Risks pnpm can resolve allowed dependency ranges when a manifest outgrows the tracked lockfile. This matches the existing release install policy. The resulting lockfile stays in the job workspace. Verification commands and runner routing are unchanged. The security reviewer explicitly accepted this existing dependency-policy tradeoff for both jobs after reviewing repository policy and the source/authorization checks. A future shared immutable dependency artifact would improve reproducibility across jobs. ## Model Used OpenAI GPT-6 through Codex, with reasoning, repository tools, and code execution. The exact serving model ID and context window are not exposed by this environment. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] Local verification passes: all 457 workflow tests, actionlint, and the stale-lockfile reproduction described above. - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
86 lines
3.6 KiB
YAML
86 lines
3.6 KiB
YAML
name: Runner Chaos Evals
|
|
|
|
on:
|
|
schedule:
|
|
- cron: "43 7 * * 0"
|
|
workflow_dispatch:
|
|
workflow_call:
|
|
inputs:
|
|
ref:
|
|
description: Commit SHA, branch, or tag to verify before release
|
|
required: false
|
|
type: string
|
|
|
|
concurrency:
|
|
# Reusable calls inherit the caller's workflow name. Cloud readiness and
|
|
# Release verify the same SHA independently and must not cancel each other.
|
|
group: runner-chaos-evals-${{ github.workflow }}-${{ inputs.ref || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
chaos_and_recovery:
|
|
name: Restart, replay, trace, and recovery faults
|
|
runs-on: ${{ vars.AWS_POST_MERGE_CI_ENABLED == 'true' && github.repository == 'paperclipai/paperclip' && github.repository_id == '1170821064' && github.ref == 'refs/heads/master' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.sha != '' && inputs.ref == github.sha && 'runs-on/fleet=paperclip-post-merge-x64/env=public-ci' || 'ubuntu-latest' }}
|
|
timeout-minutes: ${{ vars.AWS_POST_MERGE_CI_ENABLED == 'true' && github.repository == 'paperclipai/paperclip' && github.repository_id == '1170821064' && github.ref == 'refs/heads/master' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.sha != '' && inputs.ref == github.sha && 40 || 45 }}
|
|
permissions:
|
|
contents: read
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
with:
|
|
ref: ${{ inputs.ref || github.sha }}
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
|
|
with:
|
|
version: 9.15.4
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
|
|
with:
|
|
node-version: 24
|
|
cache: pnpm
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --no-frozen-lockfile
|
|
|
|
- name: Build eval and Runner contracts
|
|
run: |
|
|
pnpm --filter @paperclipai/paperclip-eval-kernel build
|
|
pnpm --filter @paperclipai/paperclip-runner report:runner-chaos-evals
|
|
|
|
- name: Run Runner fault and replay suites
|
|
run: |
|
|
pnpm --filter @paperclipai/paperclip-runner exec vitest run \
|
|
src/eval/workflow-evals.test.ts \
|
|
src/native-session-runtime.test.ts \
|
|
src/live/live-session.test.ts \
|
|
src/live/turn-stream.test.ts \
|
|
src/protocol/replay-contract.test.ts \
|
|
src/drivers/opencode/mcp-bridge.test.ts \
|
|
src/drivers/acpx/runtime-host.test.ts
|
|
|
|
- name: Build server test dependencies
|
|
run: pnpm --filter @paperclipai/plugin-sdk ensure-build-deps
|
|
|
|
- name: Run server finalization and recovery suites
|
|
run: |
|
|
pnpm --filter @paperclipai/server exec vitest run \
|
|
src/__tests__/native-finalization-recovery.test.ts \
|
|
src/__tests__/heartbeat-process-recovery.test.ts \
|
|
src/__tests__/heartbeat-comment-wake-batching.test.ts \
|
|
src/__tests__/heartbeat-dependency-scheduling.test.ts \
|
|
src/__tests__/provider-trace-store.test.ts \
|
|
src/services/issue-thread-interaction-resolution.test.ts \
|
|
src/services/recovery/successful-run-handoff.test.ts
|
|
|
|
- name: Upload chaos eval bundle
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
with:
|
|
name: runner-chaos-evals-${{ github.run_id }}
|
|
path: packages/paperclip-runner/.paperclip-local/evals/workflows/
|
|
retention-days: 30
|
|
if-no-files-found: error
|