mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 16:11:46 +02:00
## Thinking Path > - Paperclip is the open source control plane people use to manage AI agents for work > - Local agent execution uses isolated git worktrees with worktree-specific config, environment, storage, and ports > - Legacy worktree repair and runtime-port persistence must mutate only the worktree they are serving > - A leaked ambient `PAPERCLIP_IN_WORKTREE=true` could be combined with config resolution pointing at the default instance > - The server test suite reproduced that combination and repeatedly rewrote the live default instance `.env` with its old fixture name > - Existing PR #3071 guards configs under Paperclip home, but does not require the target itself to attest worktree ownership and does not cover runtime-port persistence > - This pull request requires both a worktree config layout and target-local persisted worktree attestation before either writer adopts the target > - The benefit is that ambient process state can never turn the main instance into a worktree on its next restart ## Linked Issues or Issue Description Related implementation: Refs #3071 **Pre-submission checklist** - [x] Searched open and closed issues and pull requests; #3071 is the only direct related implementation. - [x] Reproduced on current `master` before applying the fix. - [x] Confirmed the mutation originates in Paperclip's worktree config repair path. **What happened?** A process with leaked `PAPERCLIP_IN_WORKTREE=true` could resolve `PAPERCLIP_CONFIG` to the default instance and cause worktree repair to rewrite that instance's `.env`. The recurring trigger was `server/src/__tests__/worktree-config.test.ts`: an ambient config path from the developer shell survived into a test whose fixture worktree name was `PAP-884-ai-commits-component`, explaining the stale name repeatedly written to the live file. **Expected behavior** Worktree repair and worktree runtime-port persistence must mutate a target only when that target is independently provisioned and persisted as a worktree. Ambient environment flags alone must never authorize writes to the default instance or a normal repository-local `.paperclip` config. **Steps to reproduce on unpatched `master`** 1. Export `PAPERCLIP_CONFIG` pointing to a default instance config and set `PAPERCLIP_IN_WORKTREE=true`. 2. Run `server/src/__tests__/worktree-config.test.ts` from that shell. 3. Observe that the default instance `.env` is rewritten with the test fixture's worktree marker and name. **Environment** - Version: `master` at `e4e12bfb8` - Deployment/install: local source checkout with pnpm - Adapter: not adapter-specific; core server config - Database/access context: not applicable - OS: Linux **Privacy** - [x] All paths and values in this description are generic and contain no credentials or personally identifying data. ## What Changed - Reject config targets unless their parent directory is the worktree-specific `.paperclip` layout. - Require the target's own persisted `.env` to declare `PAPERCLIP_IN_WORKTREE=true` before repair or runtime-port persistence can mutate it. - Scrub ambient `PAPERCLIP_*` variables before every worktree-config test so developer-machine exports cannot escape test isolation. - Add regressions for default-instance config poisoning, runtime-port persistence, and unattested repository-local `.paperclip` targets. - Preserve valid provisioned worktree behavior by adding persisted worktree markers to the existing positive fixtures. ## Verification - `NODE_ENV=test pnpm --filter @paperclipai/server exec vitest run src/__tests__/worktree-config.test.ts` — 12 tests passed. - Branch is based directly on current `origin/master`; only two server files changed. - No `pnpm-lock.yaml`, workflow, migration, UI, or generated asset changes. ## Risks - Low risk: the new guard intentionally refuses repair for targets that lack provisioning evidence. - A manually assembled worktree that sets only ambient flags but never writes its worktree marker will no longer be auto-repaired; the supported provisioning path already writes that marker. - No schema, API, migration, or user-facing command changes. > This is a focused correctness fix and does not overlap with planned core work in `ROADMAP.md`. ## Model Used - Implementation and root-cause investigation: Anthropic Claude through the `claude_local`/Claude Code runtime, reported by the producing agent as “Claude Fable 5”; the runtime did not expose a more specific provider model ID or context-window value. Capabilities used: extended reasoning, shell tool use, code editing, and test execution. - PR preparation and verification: OpenAI Codex CLI runtime; the harness did not expose the exact underlying model ID or context-window value. Capabilities used: repository inspection, shell tool use, Git/GitHub operations, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used with all model details exposed by the runtimes - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked #3071 above - [x] I have described the issue in-PR following the bug report template - [x] I have not referenced internal/instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket ID - [x] I have run the focused tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have assessed documentation impact; no documentation change is required for this internal guard - [x] I have considered and documented risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Paperclip <noreply@paperclip.ing>