mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
<!-- Write all pull request text in Simplified Technical English (ASD-STE100): short sentences, one instruction per sentence, simple approved vocabulary, and the active voice. --> ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Execution workspaces isolate an agent task from the primary checkout. > - Pull request preparation can need a branch that already contains completed work. > - The workspace policy could not require an exact existing branch. > - Workspace cleanup also treated worktree creation as branch ownership. > - This pull request adds an exact existing-branch policy and separate branch ownership metadata. > - The benefit is safe pull request preparation that preserves every existing commit and operator-owned branch. ## Linked Issues or Issue Description **What happened?** A pull request preparation run could not pin its execution workspace to an exact existing branch. Workspace reuse and cleanup could also confuse worktree creation with branch ownership. **Expected behavior** The run must attach only to the requested branch in an isolated Git worktree. It must fail if the branch is missing, busy, or inconsistent. Cleanup must not delete a branch that Paperclip does not own. **Steps to reproduce** 1. Create a branch that contains completed work. 2. Configure a pull request preparation task to use that branch. 3. Start the task and observe that the prior policy cannot require the exact branch. **Paperclip version or commit** This behavior reproduces on the base revision before this pull request. **Deployment mode** Local development with isolated Git worktrees. ## What Changed - Add `existingBranch` to the execution workspace policy and shared validation contracts. - Require `existingBranch` to use an isolated Git worktree and reject conflicting branch templates. - Attach to the exact branch without creating, renaming, resetting, or deleting it. - Track branch ownership separately from worktree creation and use that ownership during cleanup. - Return HTTP 422 for invalid existing-branch settings on every issue-producing route. - Add a bounded repair script for existing pull request preparation tasks. - Add focused policy, route, heartbeat, runtime, and ready-comment tests. - Document the exact-branch behavior and safety rules. ## Verification - `pnpm exec vitest run server/src/__tests__/execution-workspace-policy.test.ts server/src/__tests__/heartbeat-workspace-session.test.ts server/src/__tests__/issue-existing-branch-validation-status.test.ts server/src/__tests__/workspace-runtime.test.ts server/src/services/workspace-runtime-exposure.test.ts server/src/services/workspace-runtime-ready-comment.test.ts` passed 335 tests. - `pnpm -r typecheck` passed for all workspace projects. - `pnpm test:run` passed 4,431 tests. Two unrelated embedded-Postgres setup hooks timed out under aggregate load. Their isolated rerun passed 74 tests. - `pnpm build` passed for all workspace projects. - The two review regressions passed with 139 unrelated tests skipped. - All latest-head CI gates passed after one unrelated timing-sensitive test passed on rerun. - Greptile scored the latest head 5/5 with no unresolved review threads. ## Risks - Invalid workspace settings now return HTTP 422 instead of a generic validation response. - The exact branch must already exist and must not be checked out by another worktree. - The new policy fails closed when it cannot prove branch identity or ownership. - This change has no database migration. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex from the GPT-5 family assisted with this change. The runtime did not expose its exact deployment ID or context window. The agent used high-reasoning mode, repository tools, shell execution, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
88 lines
3.5 KiB
JavaScript
88 lines
3.5 KiB
JavaScript
#!/usr/bin/env node
|
|
// Bounded repair for PR-preparation issues stranded on a shared or stale
|
|
// execution-workspace binding (PAP-17617). For each explicit issue=branch
|
|
// pair, this pins the issue's executionWorkspaceSettings to the exact-branch
|
|
// isolated-worktree contract:
|
|
// { mode: "isolated_workspace",
|
|
// workspaceStrategy: { type: "git_worktree", existingBranch: "<branch>" } }
|
|
// Dispatch then attaches a git worktree on exactly that branch and ignores a
|
|
// mismatched inherited reuse_existing binding. The script only PATCHes issues
|
|
// through the company-scoped API; it never runs git and never mutates or
|
|
// deletes any branch.
|
|
//
|
|
// Usage:
|
|
// node scripts/repair-pr-prep-workspace-attachment.mjs PAP-16555=PAP-14380-salvage-pap-9514 [more ISSUE=BRANCH ...] [--apply]
|
|
//
|
|
// Without --apply it reports the current binding and the patch it would send.
|
|
// Requires PAPERCLIP_API_URL and PAPERCLIP_API_KEY in the environment.
|
|
|
|
const args = process.argv.slice(2);
|
|
const apply = args.includes("--apply");
|
|
const pairs = args.filter((arg) => !arg.startsWith("--")).map((arg) => {
|
|
const separator = arg.indexOf("=");
|
|
if (separator <= 0 || separator === arg.length - 1) {
|
|
console.error(`Expected ISSUE=BRANCH, got "${arg}"`);
|
|
process.exit(1);
|
|
}
|
|
return { issue: arg.slice(0, separator), branch: arg.slice(separator + 1) };
|
|
});
|
|
if (pairs.length === 0) {
|
|
console.error("No ISSUE=BRANCH pairs given. Nothing to repair.");
|
|
process.exit(1);
|
|
}
|
|
|
|
const apiUrl = process.env.PAPERCLIP_API_URL;
|
|
const apiKey = process.env.PAPERCLIP_API_KEY;
|
|
if (!apiUrl || !apiKey) {
|
|
console.error("PAPERCLIP_API_URL and PAPERCLIP_API_KEY are required.");
|
|
process.exit(1);
|
|
}
|
|
const apiBase = apiUrl.replace(/\/$/, "").replace(/\/api$/, "");
|
|
const headers = {
|
|
Authorization: `Bearer ${apiKey}`,
|
|
"Content-Type": "application/json",
|
|
...(process.env.PAPERCLIP_RUN_ID ? { "X-Paperclip-Run-Id": process.env.PAPERCLIP_RUN_ID } : {}),
|
|
};
|
|
|
|
let failed = false;
|
|
for (const { issue, branch } of pairs) {
|
|
const current = await fetch(`${apiBase}/api/issues/${issue}`, { headers });
|
|
if (!current.ok) {
|
|
console.error(`${issue}: fetch failed (${current.status})`);
|
|
failed = true;
|
|
continue;
|
|
}
|
|
const existing = await current.json();
|
|
const settings = {
|
|
mode: "isolated_workspace",
|
|
workspaceStrategy: { type: "git_worktree", existingBranch: branch },
|
|
};
|
|
console.log(
|
|
`${issue}: status=${existing.status} preference=${existing.executionWorkspacePreference ?? "null"} ` +
|
|
`workspace=${existing.executionWorkspaceId ?? "null"} settings=${JSON.stringify(existing.executionWorkspaceSettings)}`,
|
|
);
|
|
if (!apply) {
|
|
console.log(`${issue}: would PATCH executionWorkspaceSettings=${JSON.stringify(settings)}`);
|
|
continue;
|
|
}
|
|
const response = await fetch(`${apiBase}/api/issues/${issue}`, {
|
|
method: "PATCH",
|
|
headers,
|
|
body: JSON.stringify({
|
|
executionWorkspaceSettings: settings,
|
|
comment:
|
|
`Repair for PAP-17617/PAP-17618: pinned this PR-preparation task to an isolated git worktree on the exact ` +
|
|
`existing branch \`${branch}\` via workspaceStrategy.existingBranch. Dispatch will attach that branch ` +
|
|
`(never create or reset it) and will not reuse the stale inherited workspace binding.`,
|
|
}),
|
|
});
|
|
const body = await response.text();
|
|
if (!response.ok) {
|
|
console.error(`${issue}: PATCH failed (${response.status}): ${body.slice(0, 500)}`);
|
|
failed = true;
|
|
continue;
|
|
}
|
|
console.log(`${issue}: PATCHED — executionWorkspaceSettings now pins existingBranch=${branch}`);
|
|
}
|
|
process.exit(failed ? 1 : 0);
|