mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-08 11:13:44 +02:00
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - The `opencode-local` adapter runs the OpenCode harness; its
model/provider routing assumes built-in providers (anthropic/openai/...)
and their default models
> - Deployments increasingly put an OpenAI/Anthropic-compatible LLM
gateway between the harness and the model for cost, governance, or
data-residency reasons: LiteLLM, OpenRouter, Portkey, Kong, a corporate
proxy, self-hosted models (vLLM/Ollama), or region-pinned/sovereign
endpoints. But OpenCode only resolves `--model provider/model` when the
model is registered in a provider's `models` map, and
`OPENCODE_ALLOW_ALL_MODELS` does NOT bypass its internal `getModel()`
> - Several lanes also fall back to built-in default models the gateway
may not serve: the auxiliary/title model (e.g. `claude-haiku-*`) and the
budget/recovery "cheap" lane (`openai/gpt-5.1-codex-mini`); these abort
runs with "no keys found that support model"
> - This pull request makes the adapter's provider/model wiring
declarative via env, so any such deployment can register gateway models
+ pin the auxiliary/budget lanes without code changes; nothing here is
specific to one hosting setup
> - The benefit is OpenCode works behind any compatible gateway with
config only; with no env set, behavior is unchanged
## Linked Issues or Issue Description
No existing issue; describing in-PR (feature / adapter enhancement).
- **Gap:** there is no supported way to register custom/gateway
providers + models for `opencode-local`, nor to pin the auxiliary
(title-gen) and budget (recovery) model lanes, so routing OpenCode
through a gateway fails at `getModel()` or on the default helper models.
- Related: #5737 (exe.dev sandbox installs for gemini/opencode local),
#5823 (unblock claude_local on remote sandbox providers).
> Note on ROADMAP: this is adapter-level, opt-in config (defaults
unchanged) that *enables* gateway routing for one harness; it is not the
core "Cloud / Sandbox agents" platform work itself. Happy to
redirect/discuss in #dev if preferred.
## What Changed
- `PAPERCLIP_OPENCODE_PROVIDERS`: merge custom/extended providers
(OpenCode `provider` shape) into the runtime `opencode.json`, so gateway
models are registered and `--model provider/model` resolves. `{env:VAR}`
placeholders are expanded server-side (so a key need not depend on the
sandbox run env).
- A malformed `PAPERCLIP_OPENCODE_PROVIDERS` is no longer silently
ignored: invalid JSON, a non-object value, and individual provider
entries with non-object values (which are skipped by name) each append a
visible note to the run notes so the misconfiguration is diagnosable
(addresses both review P1s).
- `PAPERCLIP_OPENCODE_SMALL_MODEL` / `PAPERCLIP_OPENCODE_CHEAP_MODEL`:
pin the auxiliary (title-generation) and budget (recovery-retry) lanes
to gateway-served models; defaults unchanged.
- Honour `OPENCODE_ALLOW_ALL_MODELS` on the **remote** execution path
too (was local-only, a parity gap).
- `PAPERCLIP_OPENCODE_PRINT_LOGS`: optional toggle adding `--print-logs`
so OpenCode logs surface on stderr for diagnosing remote/sandbox runs.
- `buildOpenCodeModelProfiles()` guards its `process.env` default with
`typeof process` so the shared client/server module stays browser-safe
(a bare `process.env` at module load threw ReferenceError in the browser
under Vite dev middleware and broke UI rendering in the e2e lane).
## Verification
- `pnpm --filter @paperclipai/adapter-opencode-local build` and
`typecheck` (tsc clean)
- `pnpm exec vitest run packages/adapters/opencode-local/src` shows 33
passing (incl. new tests for the provider merge, `{env:}` expansion, the
malformed/non-object/skipped-entry provider notes, small/cheap-model
resolution, and the remote allow-all bypass)
- Manually verified end-to-end against a real
OpenAI-/Anthropic-compatible gateway: with the providers + small/cheap
model set, both the title-gen and main task route to the configured
gateway model and the agent completes (a real completion is returned and
billed). That deployment supplies the verification evidence; the
mechanism is gateway-agnostic.
## Risks
Low. Everything is env-driven and opt-in; with no env set the generated
config output is unchanged, and the cheap model profile keeps its model
(the only difference is its updated human-readable description).
Defaults preserved: built-in providers, Codex-mini cheap lane with
`variant: low`, no `--print-logs`. No migration/UI impact.
## Model Used
Claude Opus 4.8 (`claude-opus-4-8`, 1M context), extended thinking +
tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md (adapter-level opt-in config enabling
gateway routing; not the core sandbox-platform work, noted above)
- [x] I have searched GitHub for duplicate or related PRs and linked
them above (#5737, #5823)
- [x] I have either (a) linked existing issues OR (b) described the
issue in-PR following the relevant issue template
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] If this change affects the UI, I have included before/after
screenshots (n/a, no UI)
- [ ] I have updated relevant documentation to reflect my changes (env
vars documented inline via comments; no central doc references the
adapter env yet)
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(the P1 about silently dropped malformed providers JSON is addressed in
6eeb803, the follow-up P1 about silently skipped non-object entries in
2f4045a; the latest review has no further findings, and a re-review is
requested for the final note-copy/test-fixture polish at head)
- [x] I will address all Greptile and reviewer comments before
requesting merge
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
233 lines
7.9 KiB
TypeScript
233 lines
7.9 KiB
TypeScript
import { createHash } from "node:crypto";
|
|
import os from "node:os";
|
|
import type { AdapterModel } from "@paperclipai/adapter-utils";
|
|
import {
|
|
asString,
|
|
ensurePathInEnv,
|
|
runChildProcess,
|
|
} from "@paperclipai/adapter-utils/server-utils";
|
|
import { isValidOpenCodeModelId } from "../index.js";
|
|
|
|
const MODELS_CACHE_TTL_MS = 60_000;
|
|
const MODELS_DISCOVERY_TIMEOUT_MS = 20_000;
|
|
|
|
function resolveOpenCodeCommand(input: unknown): string {
|
|
const envOverride =
|
|
typeof process.env.PAPERCLIP_OPENCODE_COMMAND === "string" &&
|
|
process.env.PAPERCLIP_OPENCODE_COMMAND.trim().length > 0
|
|
? process.env.PAPERCLIP_OPENCODE_COMMAND.trim()
|
|
: "opencode";
|
|
return asString(input, envOverride);
|
|
}
|
|
|
|
const discoveryCache = new Map<string, { expiresAt: number; models: AdapterModel[] }>();
|
|
const VOLATILE_ENV_KEY_PREFIXES = ["PAPERCLIP_", "npm_", "NPM_"] as const;
|
|
const VOLATILE_ENV_KEY_EXACT = new Set(["PWD", "OLDPWD", "SHLVL", "_", "TERM_SESSION_ID", "HOME"]);
|
|
|
|
export function requireOpenCodeModelId(input: unknown): string {
|
|
const model = asString(input, "").trim();
|
|
if (!isValidOpenCodeModelId(model)) {
|
|
throw new Error("OpenCode requires `adapterConfig.model` in provider/model format.");
|
|
}
|
|
return model;
|
|
}
|
|
|
|
function dedupeModels(models: AdapterModel[]): AdapterModel[] {
|
|
const seen = new Set<string>();
|
|
const deduped: AdapterModel[] = [];
|
|
for (const model of models) {
|
|
const id = model.id.trim();
|
|
if (!id || seen.has(id)) continue;
|
|
seen.add(id);
|
|
deduped.push({ id, label: model.label.trim() || id });
|
|
}
|
|
return deduped;
|
|
}
|
|
|
|
function sortModels(models: AdapterModel[]): AdapterModel[] {
|
|
return [...models].sort((a, b) =>
|
|
a.id.localeCompare(b.id, "en", { numeric: true, sensitivity: "base" }),
|
|
);
|
|
}
|
|
|
|
function firstNonEmptyLine(text: string): string {
|
|
return (
|
|
text
|
|
.split(/\r?\n/)
|
|
.map((line) => line.trim())
|
|
.find(Boolean) ?? ""
|
|
);
|
|
}
|
|
|
|
export function parseOpenCodeModelsOutput(stdout: string): AdapterModel[] {
|
|
const parsed: AdapterModel[] = [];
|
|
for (const raw of stdout.split(/\r?\n/)) {
|
|
const line = raw.trim();
|
|
if (!line) continue;
|
|
const firstToken = line.split(/\s+/)[0]?.trim() ?? "";
|
|
if (!firstToken.includes("/")) continue;
|
|
const provider = firstToken.slice(0, firstToken.indexOf("/")).trim();
|
|
const model = firstToken.slice(firstToken.indexOf("/") + 1).trim();
|
|
if (!provider || !model) continue;
|
|
parsed.push({ id: `${provider}/${model}`, label: `${provider}/${model}` });
|
|
}
|
|
return dedupeModels(parsed);
|
|
}
|
|
|
|
function normalizeEnv(input: unknown): Record<string, string> {
|
|
const envInput = typeof input === "object" && input !== null && !Array.isArray(input)
|
|
? (input as Record<string, unknown>)
|
|
: {};
|
|
const env: Record<string, string> = {};
|
|
for (const [key, value] of Object.entries(envInput)) {
|
|
if (typeof value === "string") env[key] = value;
|
|
}
|
|
return env;
|
|
}
|
|
|
|
function isVolatileEnvKey(key: string): boolean {
|
|
if (VOLATILE_ENV_KEY_EXACT.has(key)) return true;
|
|
return VOLATILE_ENV_KEY_PREFIXES.some((prefix) => key.startsWith(prefix));
|
|
}
|
|
|
|
function hashValue(value: string): string {
|
|
return createHash("sha256").update(value).digest("hex");
|
|
}
|
|
|
|
function discoveryCacheKey(command: string, cwd: string, env: Record<string, string>) {
|
|
const envKey = Object.entries(env)
|
|
.filter(([key]) => !isVolatileEnvKey(key))
|
|
.sort(([a], [b]) => a.localeCompare(b))
|
|
.map(([key, value]) => `${key}=${hashValue(value)}`)
|
|
.join("\n");
|
|
return `${command}\n${cwd}\n${envKey}`;
|
|
}
|
|
|
|
function pruneExpiredDiscoveryCache(now: number) {
|
|
for (const [key, value] of discoveryCache.entries()) {
|
|
if (value.expiresAt <= now) discoveryCache.delete(key);
|
|
}
|
|
}
|
|
|
|
export async function discoverOpenCodeModels(input: {
|
|
command?: unknown;
|
|
cwd?: unknown;
|
|
env?: unknown;
|
|
} = {}): Promise<AdapterModel[]> {
|
|
const command = resolveOpenCodeCommand(input.command);
|
|
const cwd = asString(input.cwd, process.cwd());
|
|
const env = normalizeEnv(input.env);
|
|
// Ensure HOME points to the actual running user's home directory.
|
|
// When the server is started via `runuser -u <user>`, HOME may still
|
|
// reflect the parent process (e.g. /root), causing OpenCode to miss
|
|
// provider auth credentials stored under the target user's home.
|
|
let resolvedHome: string | undefined;
|
|
try {
|
|
resolvedHome = os.userInfo().homedir || undefined;
|
|
} catch {
|
|
// os.userInfo() throws a SystemError when the current UID has no
|
|
// /etc/passwd entry (e.g. `docker run --user 1234` with a minimal
|
|
// image). Fall back to process.env.HOME.
|
|
}
|
|
// Prevent OpenCode from writing an opencode.json into the working directory.
|
|
const runtimeEnv = normalizeEnv(ensurePathInEnv({ ...process.env, ...env, ...(resolvedHome ? { HOME: resolvedHome } : {}), OPENCODE_DISABLE_PROJECT_CONFIG: "true" }));
|
|
|
|
const result = await runChildProcess(
|
|
`opencode-models-${Date.now()}-${Math.random().toString(16).slice(2)}`,
|
|
command,
|
|
["models"],
|
|
{
|
|
cwd,
|
|
env: runtimeEnv,
|
|
timeoutSec: MODELS_DISCOVERY_TIMEOUT_MS / 1000,
|
|
graceSec: 3,
|
|
onLog: async () => {},
|
|
},
|
|
);
|
|
|
|
if (result.timedOut) {
|
|
throw new Error(`\`opencode models\` timed out after ${MODELS_DISCOVERY_TIMEOUT_MS / 1000}s.`);
|
|
}
|
|
if ((result.exitCode ?? 1) !== 0) {
|
|
const detail = firstNonEmptyLine(result.stderr) || firstNonEmptyLine(result.stdout);
|
|
throw new Error(detail ? `\`opencode models\` failed: ${detail}` : "`opencode models` failed.");
|
|
}
|
|
|
|
return sortModels(parseOpenCodeModelsOutput(result.stdout));
|
|
}
|
|
|
|
export async function discoverOpenCodeModelsCached(input: {
|
|
command?: unknown;
|
|
cwd?: unknown;
|
|
env?: unknown;
|
|
} = {}): Promise<AdapterModel[]> {
|
|
const command = resolveOpenCodeCommand(input.command);
|
|
const cwd = asString(input.cwd, process.cwd());
|
|
const env = normalizeEnv(input.env);
|
|
const key = discoveryCacheKey(command, cwd, env);
|
|
const now = Date.now();
|
|
pruneExpiredDiscoveryCache(now);
|
|
const cached = discoveryCache.get(key);
|
|
if (cached && cached.expiresAt > now) return cached.models;
|
|
|
|
const models = await discoverOpenCodeModels({ command, cwd, env });
|
|
discoveryCache.set(key, { expiresAt: now + MODELS_CACHE_TTL_MS, models });
|
|
return models;
|
|
}
|
|
|
|
export function isTruthyEnvFlag(value: string | undefined): boolean {
|
|
if (value === undefined) return false;
|
|
const v = value.trim().toLowerCase();
|
|
return v === "true" || v === "1" || v === "yes";
|
|
}
|
|
|
|
export async function ensureOpenCodeModelConfiguredAndAvailable(input: {
|
|
model?: unknown;
|
|
command?: unknown;
|
|
cwd?: unknown;
|
|
env?: unknown;
|
|
}): Promise<AdapterModel[]> {
|
|
const model = requireOpenCodeModelId(input.model);
|
|
|
|
// When the caller opts into OPENCODE_ALLOW_ALL_MODELS, OpenCode accepts any
|
|
// provider/model at run time (e.g. gateway-routed models that never appear in
|
|
// `opencode models` output). Honour that by skipping the availability probe;
|
|
// we still enforce the provider/model format above and do not second-guess
|
|
// the configured model. Prefer the explicit run env, then the process env.
|
|
const env = normalizeEnv(input.env);
|
|
if (isTruthyEnvFlag(env.OPENCODE_ALLOW_ALL_MODELS ?? process.env.OPENCODE_ALLOW_ALL_MODELS)) {
|
|
return [{ id: model, label: model }];
|
|
}
|
|
|
|
const models = await discoverOpenCodeModelsCached({
|
|
command: input.command,
|
|
cwd: input.cwd,
|
|
env: input.env,
|
|
});
|
|
|
|
if (models.length === 0) {
|
|
throw new Error("OpenCode returned no models. Run `opencode models` and verify provider auth.");
|
|
}
|
|
|
|
if (!models.some((entry) => entry.id === model)) {
|
|
const sample = models.slice(0, 12).map((entry) => entry.id).join(", ");
|
|
throw new Error(
|
|
`Configured OpenCode model is unavailable: ${model}. Available models: ${sample}${models.length > 12 ? ", ..." : ""}`,
|
|
);
|
|
}
|
|
|
|
return models;
|
|
}
|
|
|
|
export async function listOpenCodeModels(): Promise<AdapterModel[]> {
|
|
try {
|
|
return await discoverOpenCodeModelsCached();
|
|
} catch {
|
|
return [];
|
|
}
|
|
}
|
|
|
|
export function resetOpenCodeModelsCacheForTests() {
|
|
discoveryCache.clear();
|
|
}
|