mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Local adapters run agents in local or remote sandboxes. > - A remote Grok subscription run needs its credential file inside the sandbox. > - The adapter did not stage the Grok home, so the sandbox had no credential file. > - This pull request stages only the allowed Grok credential file and sets the reported home path. > - The adapter removes the temporary staged home before teardown completes. > - The benefit is reliable Grok subscription authentication with limited credential exposure. ## Linked Issues or Issue Description **What happened?** A remote Grok subscription run had no credential file in its sandbox. The adapter sent no Grok home asset. **Expected behavior** The adapter should stage the allowed Grok credential file and set `GROK_HOME` to the reported sandbox path. **Steps to reproduce** 1. Start a remote Grok run in subscription mode. 2. Inspect the sandbox environment and home asset. 3. Confirm that the run has `GROK_HOME` and `auth.json`. **Paperclip version or commit** `3df33b5b8f49063a5d1ab608f8ce372572ef09d1` **Deployment mode** Remote sandbox run. ## What Changed - Stage a private temporary Grok home for remote subscription runs. - Copy only the allowed `auth.json` file and set its mode to `0600`. - Pass the staged directory as the remote `home` asset. - Set `GROK_HOME` to the path that the remote runtime reports. - Remove the staged directory before awaited teardown calls. - Keep the API-key lane free of credential staging. - Add tests for the allowlist, file mode, empty source home, run lanes, and teardown cleanup. ## Verification - `pnpm vitest run packages/adapters/grok-local` passes. - `pnpm --filter @paperclipai/adapter-grok-local typecheck` passes. - `grok-home.test.ts` covers the allowlist, mode `0600`, and empty source home. - `execute.test.ts` covers the remote subscription lane, the API-key lane, and cleanup after restore failure. ## Risks - The change affects only remote Grok subscription runs that use a credential file. - The allowlist limits the staged content to `auth.json`. - The API-key lane does not stage a home or set `GROK_HOME`. - CI must confirm adapter behavior across the supported runtime matrix. ## Model Used - Codex, GPT-5, current 2026 model version, large context window, reasoning mode, and tool use assisted the repository handoff and pull request management. The implementation author supplied the code and local verification. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>