mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-08 11:13:44 +02:00
## Thinking Path > - Paperclip manages AI agents that perform work. > - Paperclip Runner connects durable task runs to local provider processes. > - The full-stack paid matrix exposed failures after the runner integrity repair. > - Verified JavaScript entrypoints lost their relative module graph when Linux executed them through descriptor paths. > - Returned provider startup errors also remained pending and became indeterminate after recovery. > - Sparse Codex tool lifecycle events lost the `write_document` identity before task transcript projection. > - This pull request repairs those three boundaries and makes the structured-question fixture deterministic. > - The benefit is repeatable provider startup, exact failure replay, and correct inline Plan placement. ## Linked Issues or Issue Description Refs #12721 and #12700. **What happened?** The paid runner matrix failed ACPX and OpenCode startup before provider session creation. The runner journal then replaced the original startup error with an indeterminate recovery result. Native Codex saved a Plan but rendered it only as a fallback card. A legacy Claude waiting reply could also echo the reserved terminal marker before the answer arrived. **Expected behavior** Verified JavaScript providers must start from immutable descriptor-backed artifacts. Returned startup failures must persist as terminal failed command results. Native tool lifecycle updates must preserve the `write_document` boundary. Pre-answer fixture output must not contain the reserved terminal marker. **Steps to reproduce** 1. Run the local provider cells in the Runner Full-Stack E2E workflow. 2. Observe ACPX and OpenCode fail during `session.open` before provider execution. 3. Observe recovery report `execution_indeterminate` instead of the original startup error. 4. Run the native Codex Plan cell and observe the fallback Plan card after the tool activity row. 5. Run the legacy Claude structured-question resume cell and observe an early marker echo in waiting prose. **Paperclip version or commit** `0f9452101740835ce0b1488a204bf48acd5bafc3` **Deployment mode** Local development with the paid GitHub Actions acceptance workflow. ## What Changed - Bundle the ACPX sidecar and OpenCode proxy as self-contained Node ESM entrypoints before hashing and verified descriptor launch. - Anchor ACPX dynamic provider package resolution at a controller-derived provider-pack root and keep that root out of the provider child environment. - Persist executor-returned startup errors as redacted durable failed command results while retaining indeterminate recovery for true process death. - Coalesce sparse native tool items by stable ID so a late `write_document` name, input, and result reach the transcript boundary once. - Forbid the structured-question fixture from spelling or announcing its reserved terminal marker before the user answers. ## Verification - Rust and TypeScript regression tests cover durable failed replay, true crash ambiguity, bundle closure, package-root derivation, environment filtering, exact Codex tool lifecycle coalescing, and prompt determinism. - Local execution is intentionally limited to formatters and static diff checks. GitHub Actions will run tests, type checks, builds, and security checks. - After ordinary CI is green, scoped paid cells will validate one ACPX launch, one OpenCode launch, native Codex Plan projection, and legacy Claude structured resume before a complete matrix rerun. - Prior failing matrix: https://github.com/paperclipai/paperclip/actions/runs/33682434315 ## Risks - Bundling changes the bytes covered by provider launch hashes. Provider-pack generation already hashes the final built files. - ACPX still loads qualified provider packages dynamically. The controller supplies a normalized package root, while existing version, digest, path, and descriptor checks remain active. - Durable `failed` is terminal. Replays return the same redacted result and do not execute the provider effect twice. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex based on GPT-5 with agentic reasoning, repository inspection, code editing, Git, parallel subagents, and GitHub Actions coordination. The exact deployed snapshot and context-window size are not exposed to this task. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either linked related public work or described the bug in this PR - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket id - [ ] I have run tests locally and they pass (intentionally deferred to GitHub Actions) - [x] I have added or updated tests where applicable - [x] No documentation change is required for this runtime repair - [x] I have considered and documented the risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
202 lines
7.5 KiB
TypeScript
202 lines
7.5 KiB
TypeScript
import type { AgentAdapterType, EnvironmentDriver } from "./constants.js";
|
|
import type { SandboxEnvironmentProvider } from "./types/environment.js";
|
|
import type {
|
|
JsonSchema,
|
|
PluginEnvironmentTemplateConfigBinding,
|
|
SandboxProviderCapabilities,
|
|
} from "./types/plugin.js";
|
|
|
|
/**
|
|
* Resolve the DECLARED sandbox capabilities of a provider driver, with the
|
|
* legacy `supportsReusableLeases` flag folded in for compatibility.
|
|
*
|
|
* The result is a partial: a key is present only when the driver declared it,
|
|
* so a caller can tell a declared `false` from an absent key. The nested
|
|
* `sandboxCapabilities.reusableLeases` wins over the legacy flag when both are
|
|
* present. This is the DECLARATION only; the runtime still intersects it with
|
|
* the verified worker methods and any narrowing before it grants a capability.
|
|
*/
|
|
export function resolveDeclaredSandboxCapabilities(
|
|
driver: {
|
|
supportsReusableLeases?: boolean;
|
|
sandboxCapabilities?: SandboxProviderCapabilities;
|
|
},
|
|
): SandboxProviderCapabilities {
|
|
const declared: SandboxProviderCapabilities = { ...(driver.sandboxCapabilities ?? {}) };
|
|
if (declared.reusableLeases === undefined && driver.supportsReusableLeases !== undefined) {
|
|
declared.reusableLeases = driver.supportsReusableLeases;
|
|
}
|
|
return declared;
|
|
}
|
|
|
|
export type EnvironmentSupportStatus = "supported" | "unsupported";
|
|
|
|
export interface AdapterEnvironmentSupport {
|
|
adapterType: AgentAdapterType;
|
|
drivers: Record<EnvironmentDriver, EnvironmentSupportStatus>;
|
|
sandboxProviders: Record<SandboxEnvironmentProvider, EnvironmentSupportStatus>;
|
|
}
|
|
|
|
export interface EnvironmentProviderCapability {
|
|
status: EnvironmentSupportStatus;
|
|
supportsSavedProbe: boolean;
|
|
supportsUnsavedProbe: boolean;
|
|
supportsRunExecution: boolean;
|
|
supportsReusableLeases: boolean;
|
|
supportsInteractiveSetup: boolean;
|
|
interactiveSetupConnectionTypes: string[];
|
|
supportsTemplateCapture: boolean;
|
|
templateRefKind?: string;
|
|
templateConfigBinding?: PluginEnvironmentTemplateConfigBinding;
|
|
supportsTemplateDelete: boolean;
|
|
supportsLoginPty: boolean;
|
|
displayName?: string;
|
|
description?: string;
|
|
source?: "builtin" | "plugin";
|
|
pluginKey?: string;
|
|
pluginId?: string;
|
|
configSchema?: JsonSchema;
|
|
}
|
|
|
|
export interface EnvironmentCapabilities {
|
|
adapters: AdapterEnvironmentSupport[];
|
|
drivers: Record<EnvironmentDriver, EnvironmentSupportStatus>;
|
|
sandboxProviders: Record<SandboxEnvironmentProvider, EnvironmentProviderCapability>;
|
|
}
|
|
|
|
const REMOTE_MANAGED_ADAPTERS = new Set<AgentAdapterType>([
|
|
"claude_local",
|
|
"codex_local",
|
|
"paperclip_runner",
|
|
"cursor",
|
|
"gemini_local",
|
|
"grok_local",
|
|
"kimi_local",
|
|
"opencode_local",
|
|
"pi_local",
|
|
]);
|
|
|
|
export function adapterSupportsRemoteManagedEnvironments(adapterType: string): boolean {
|
|
return REMOTE_MANAGED_ADAPTERS.has(adapterType as AgentAdapterType);
|
|
}
|
|
|
|
export function supportedEnvironmentDriversForAdapter(adapterType: string): EnvironmentDriver[] {
|
|
return adapterSupportsRemoteManagedEnvironments(adapterType)
|
|
? ["local", "ssh", "sandbox"]
|
|
: ["local"];
|
|
}
|
|
|
|
export function supportedSandboxProvidersForAdapter(
|
|
adapterType: string,
|
|
additionalProviders: readonly string[] = [],
|
|
): SandboxEnvironmentProvider[] {
|
|
return adapterSupportsRemoteManagedEnvironments(adapterType)
|
|
? Array.from(new Set(additionalProviders)) as SandboxEnvironmentProvider[]
|
|
: [];
|
|
}
|
|
|
|
export function isEnvironmentDriverSupportedForAdapter(
|
|
adapterType: string,
|
|
driver: string,
|
|
): boolean {
|
|
return supportedEnvironmentDriversForAdapter(adapterType).includes(driver as EnvironmentDriver);
|
|
}
|
|
|
|
export function isSandboxProviderSupportedForAdapter(
|
|
adapterType: string,
|
|
provider: string | null | undefined,
|
|
additionalProviders: readonly string[] = [],
|
|
): boolean {
|
|
if (!provider) return false;
|
|
return supportedSandboxProvidersForAdapter(adapterType, additionalProviders).includes(
|
|
provider as SandboxEnvironmentProvider,
|
|
);
|
|
}
|
|
|
|
export function getAdapterEnvironmentSupport(
|
|
adapterType: AgentAdapterType,
|
|
additionalSandboxProviders: readonly string[] = [],
|
|
): AdapterEnvironmentSupport {
|
|
const supportedDrivers = new Set(supportedEnvironmentDriversForAdapter(adapterType));
|
|
const supportedProviders = new Set(supportedSandboxProvidersForAdapter(adapterType, additionalSandboxProviders));
|
|
const sandboxProviders: Record<SandboxEnvironmentProvider, EnvironmentSupportStatus> = {
|
|
fake: "unsupported",
|
|
};
|
|
for (const provider of additionalSandboxProviders) {
|
|
sandboxProviders[provider as SandboxEnvironmentProvider] = supportedProviders.has(provider as SandboxEnvironmentProvider)
|
|
? "supported"
|
|
: "unsupported";
|
|
}
|
|
return {
|
|
adapterType,
|
|
drivers: {
|
|
local: supportedDrivers.has("local") ? "supported" : "unsupported",
|
|
ssh: supportedDrivers.has("ssh") ? "supported" : "unsupported",
|
|
sandbox: supportedDrivers.has("sandbox") ? "supported" : "unsupported",
|
|
plugin: supportedDrivers.has("plugin") ? "supported" : "unsupported",
|
|
},
|
|
sandboxProviders,
|
|
};
|
|
}
|
|
|
|
export function getEnvironmentCapabilities(
|
|
adapterTypes: readonly AgentAdapterType[],
|
|
options: {
|
|
sandboxProviders?: Record<string, Partial<EnvironmentProviderCapability>>;
|
|
} = {},
|
|
): EnvironmentCapabilities {
|
|
const pluginProviderKeys = Object.keys(options.sandboxProviders ?? {});
|
|
const sandboxProviders: Record<SandboxEnvironmentProvider, EnvironmentProviderCapability> = {
|
|
fake: {
|
|
status: "unsupported",
|
|
supportsSavedProbe: true,
|
|
supportsUnsavedProbe: true,
|
|
supportsRunExecution: false,
|
|
// The fake provider runtime declares false. The presentation must match
|
|
// it, so execution and presentation agree.
|
|
supportsReusableLeases: false,
|
|
supportsInteractiveSetup: false,
|
|
interactiveSetupConnectionTypes: [],
|
|
supportsTemplateCapture: false,
|
|
supportsTemplateDelete: false,
|
|
supportsLoginPty: false,
|
|
displayName: "Fake",
|
|
source: "builtin",
|
|
},
|
|
};
|
|
for (const [provider, capability] of Object.entries(options.sandboxProviders ?? {})) {
|
|
sandboxProviders[provider as SandboxEnvironmentProvider] = {
|
|
status: capability.status ?? "supported",
|
|
supportsSavedProbe: capability.supportsSavedProbe ?? true,
|
|
supportsUnsavedProbe: capability.supportsUnsavedProbe ?? true,
|
|
supportsRunExecution: capability.supportsRunExecution ?? true,
|
|
// Default absent to false. A manifest that does not declare reusable
|
|
// leases must present as false, so execution (=== true) agrees.
|
|
supportsReusableLeases: capability.supportsReusableLeases ?? false,
|
|
supportsInteractiveSetup: capability.supportsInteractiveSetup ?? false,
|
|
interactiveSetupConnectionTypes: capability.interactiveSetupConnectionTypes ?? [],
|
|
supportsTemplateCapture: capability.supportsTemplateCapture ?? false,
|
|
templateRefKind: capability.templateRefKind,
|
|
templateConfigBinding: capability.templateConfigBinding,
|
|
supportsTemplateDelete: capability.supportsTemplateDelete ?? false,
|
|
supportsLoginPty: capability.supportsLoginPty ?? false,
|
|
displayName: capability.displayName,
|
|
description: capability.description,
|
|
source: capability.source ?? "plugin",
|
|
pluginKey: capability.pluginKey,
|
|
pluginId: capability.pluginId,
|
|
configSchema: capability.configSchema,
|
|
};
|
|
}
|
|
return {
|
|
adapters: adapterTypes.map((adapterType) => getAdapterEnvironmentSupport(adapterType, pluginProviderKeys)),
|
|
drivers: {
|
|
local: "supported",
|
|
ssh: "supported",
|
|
sandbox: "supported",
|
|
plugin: "unsupported",
|
|
},
|
|
sandboxProviders,
|
|
};
|
|
}
|