mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-08 00:54:38 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Remote environments realize the workspace at a provider-owned path. > - Run startup probes Git and network context before it starts the agent. > - The probe used the controller path inside the remote environment. > - A missing directory stopped the run before any provider work began. > - This pull request uses the remote execution target's working directory. ## Linked Issues or Issue Description Refs #13094, which introduced this probe. Related: #8997 and #10419 address other workspace-directory handoffs; this patch fixes the newer Git-context probe. **What happened?** Remote runs failed with `setup_failed: Could not read execution-target Git context`, including tasks that did not use Git. The provider shell could not enter the controller's workspace directory. **Expected behavior** Startup must inspect Git and network context in the realized remote workspace. **Steps to reproduce** 1. Select a remote sandbox whose workspace is `/home/daytona/paperclip-workspace`. 2. Start a task whose controller workspace is under `/paperclip/instances/default/workspaces/`. 3. The startup probe exits when the controller directory does not exist in the sandbox. **Paperclip version or commit** Reproduced on `622376e99` and in the regression test before this patch. **Deployment mode** Docker controller with a remote Daytona sandbox. The same helper also serves SSH targets. ## What Changed - Use `remote.remoteCwd` for the remote Git-context probe. - Cover a missing controller directory in both credential modes. - Verify that SSH reads Git metadata from the remote workspace even when the caller directory exists. ## Verification - Before the fix, both new missing-directory tests failed with the reported error. - The launcher environment suite passes: 18 tests. - The adapter-utils suite passes: 1,085 passed, 11 skipped. - Adapter-utils typecheck passes. - A disposable sandbox with the affected deployment's image reproduced the old `cd` failure and passed with the corrected helper. The sandbox was deleted afterward. - Full repository typecheck and build pass locally. All CI gates pass at `61b522c`: regular test shards, serialized server suites, browser shards, Runner verification, build, policy, and security checks. - The first CI Build attempt hit a Runner suspension-acknowledgment timeout outside the changed code. The affected 13-case recovery group passes locally with its Rust fixtures built, and the unchanged CI job passed on its single retry. - The full serial local test run was stopped in favor of the complete CI matrix; it is not claimed as a local pass. ## Risks The probe now uses the provider-resolved target directory for sandbox and SSH execution. Local execution keeps its existing directory. There are no schema or API changes. Existing local credential and Git metadata tests pass. ## Model Used OpenAI GPT-6 in Codex, with tool-assisted code analysis, implementation, and live and automated testing. The exact model identifier and context-window size are not exposed by this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>
265 lines
14 KiB
TypeScript
265 lines
14 KiB
TypeScript
import { execFile } from "node:child_process";
|
|
import { mkdtemp, mkdir, readFile, realpath, rm, writeFile } from "node:fs/promises";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import { promisify } from "node:util";
|
|
import { afterEach, describe, expect, it, vi } from "vitest";
|
|
import * as ssh from "./ssh.js";
|
|
import type { CommandManagedRuntimeRunner } from "./command-managed-runtime.js";
|
|
import {
|
|
ensureAdapterExecutionTargetCommandResolvable,
|
|
prepareGitHubOperationLaunchers,
|
|
prepareGitHubExecutionEnvironment,
|
|
runAdapterExecutionTargetProcess,
|
|
} from "./execution-target.js";
|
|
|
|
const exec = promisify(execFile);
|
|
const roots: string[] = [];
|
|
afterEach(async () => {
|
|
vi.restoreAllMocks();
|
|
vi.unstubAllEnvs();
|
|
await Promise.all(roots.splice(0).map((root) => rm(root, { recursive: true, force: true })));
|
|
});
|
|
|
|
async function sandbox(layout: string) {
|
|
const root = await mkdtemp(path.join(os.tmpdir(), "paperclip-launcher-env-"));
|
|
roots.push(root);
|
|
const bin = path.join(root, layout);
|
|
await mkdir(bin, { recursive: true });
|
|
for (const cli of ["claude", "codex", "git", "gh"]) {
|
|
await writeFile(path.join(bin, cli), `#!/bin/sh\nprintf '%s\\n' '${cli} started'\n`, { mode: 0o700 });
|
|
}
|
|
const remotePath = `${bin}:${path.dirname(process.execPath)}:/usr/local/bin:/usr/bin:/bin`;
|
|
// Execute real shells and staged launchers, with a provider-owned environment.
|
|
// Do not inherit the controller's PATH, HOME, credentials, or shell hooks.
|
|
const execute: CommandManagedRuntimeRunner["execute"] = async (input) => {
|
|
const startedAt = new Date().toISOString();
|
|
try {
|
|
const execution = exec(input.command, input.args ?? [], {
|
|
cwd: input.cwd ?? root,
|
|
env: { HOME: root, PATH: remotePath, ...input.env },
|
|
timeout: input.timeoutMs ?? 15_000,
|
|
});
|
|
const inputComplete = new Promise<void>((resolve, reject) => {
|
|
const stdin = execution.child.stdin;
|
|
if (!stdin) return resolve();
|
|
// Hash-skip staging can exit before reading the supplied file body.
|
|
// Its exit result still determines success; other input errors fail.
|
|
stdin.on("error", (error: NodeJS.ErrnoException) => {
|
|
if (error.code === "EPIPE") resolve();
|
|
else reject(error);
|
|
});
|
|
stdin.end(input.stdin ?? "", resolve);
|
|
});
|
|
const [result] = await Promise.all([execution, inputComplete]);
|
|
return { ...result, exitCode: 0, signal: null, timedOut: false, pid: null, startedAt };
|
|
} catch (error) {
|
|
const result = error as Error & { code?: number; killed?: boolean; stdout?: string; stderr?: string };
|
|
return { exitCode: result.code ?? 1, signal: null, timedOut: result.killed ?? false,
|
|
stdout: result.stdout ?? "", stderr: result.stderr ?? "", pid: null, startedAt };
|
|
}
|
|
};
|
|
const runner = { execute: vi.fn(execute) };
|
|
const target = { kind: "remote" as const, transport: "sandbox" as const,
|
|
providerKey: "fixture", remoteCwd: root, runner };
|
|
return { root, bin, remotePath, runner, target };
|
|
}
|
|
|
|
describe("managed GitHub launcher environment", () => {
|
|
it.each([false, true])("probes the remote workspace when the controller cwd is absent (host credentials: %s)", async (hostCredentials) => {
|
|
const fixture = await sandbox("usr/bin");
|
|
const env = await prepareGitHubExecutionEnvironment({
|
|
target: fixture.target,
|
|
cwd: path.join(fixture.root, "controller-only", "agent-workspace"),
|
|
env: {},
|
|
hostCredentials,
|
|
networkAccess: true,
|
|
});
|
|
|
|
expect(env.PAPERCLIP_RUNNER_NETWORK_ACCESS).toBe("enabled");
|
|
expect(env.PAPERCLIP_GIT_METADATA_ROOTS).toBe("[]");
|
|
expect(JSON.parse(env.PAPERCLIP_RUNNER_NETWORK_ROOTS!)).not.toHaveLength(0);
|
|
expect(fixture.runner.execute).toHaveBeenCalledWith(expect.objectContaining({ cwd: fixture.root }));
|
|
});
|
|
|
|
it("reads Git metadata from the SSH workspace instead of an existing controller directory", async () => {
|
|
const fixture = await sandbox("ssh-toolchain/bin");
|
|
// Use real Git for the probe, not the launcher fixture's stub.
|
|
await rm(path.join(fixture.bin, "git"));
|
|
await exec("git", ["init", fixture.root]);
|
|
const controllerCwd = path.join(fixture.root, "controller");
|
|
await mkdir(controllerCwd);
|
|
vi.spyOn(ssh, "createSshCommandManagedRuntimeRunner").mockReturnValue(fixture.runner);
|
|
const target = { kind: "remote" as const, transport: "ssh" as const, remoteCwd: fixture.root,
|
|
spec: { host: "sandbox.example.test", port: 22, username: "runner", remoteCwd: fixture.root,
|
|
remoteWorkspacePath: fixture.root, privateKey: null, knownHosts: null, strictHostKeyChecking: true } };
|
|
|
|
const env = await prepareGitHubExecutionEnvironment({
|
|
target, cwd: controllerCwd, env: {}, hostCredentials: false, networkAccess: true,
|
|
});
|
|
|
|
expect(JSON.parse(env.PAPERCLIP_GIT_METADATA_ROOTS!)).toEqual([await realpath(path.join(fixture.root, ".git"))]);
|
|
});
|
|
|
|
it("uses target Git configuration without importing controller credentials", async () => {
|
|
const fixture = await sandbox("usr/bin");
|
|
vi.stubEnv("GH_TOKEN", "controller-secret");
|
|
await mkdir(path.join(fixture.root, ".config/gh"), { recursive: true });
|
|
await writeFile(path.join(fixture.root, ".config/gh/hosts.yml"), "host credential fixture");
|
|
const execute = fixture.runner.execute.getMockImplementation()!;
|
|
fixture.runner.execute.mockImplementation(async (input) => {
|
|
expect(input.command).toBe("sh"); // No Node executable is required on the SSH host.
|
|
const result = await execute(input);
|
|
return { ...result, stdout: `SSH login banner\n${result.stdout}\nlogout` };
|
|
});
|
|
const env = await prepareGitHubExecutionEnvironment({
|
|
target: fixture.target, cwd: fixture.root, env: {
|
|
PAPERCLIP_GIT_METADATA_ROOTS: '["/injected"]',
|
|
PAPERCLIP_RUNNER_NETWORK_ROOTS: '["/injected"]',
|
|
PAPERCLIP_GITHUB_HOST_HOME: "/injected",
|
|
PAPERCLIP_GITHUB_AUTH_MODE: "managed",
|
|
PAPERCLIP_RUNNER_NETWORK_ACCESS: "disabled",
|
|
}, hostCredentials: true, networkAccess: true,
|
|
});
|
|
expect(env.PAPERCLIP_GIT_METADATA_ROOTS).not.toContain("/injected");
|
|
expect(env.PAPERCLIP_RUNNER_NETWORK_ROOTS).not.toContain("/injected");
|
|
expect(env.PAPERCLIP_GITHUB_AUTH_MODE).toBe("host");
|
|
expect(env.PAPERCLIP_RUNNER_NETWORK_ACCESS).toBe("enabled");
|
|
expect(env.PAPERCLIP_GITHUB_HOST_HOME).toBe(fixture.root);
|
|
expect(env.GH_CONFIG_DIR).toBe(path.join(fixture.root, ".config/gh"));
|
|
expect(env.GH_TOKEN).toBeUndefined();
|
|
expect(env.PAPERCLIP_GITHUB_LAUNCHER_DIR).toBeUndefined();
|
|
});
|
|
|
|
it("preserves local host credential helpers and validates worktree metadata", async () => {
|
|
const root = await mkdtemp(path.join(os.tmpdir(), "paperclip-host-git-")); roots.push(root);
|
|
vi.stubEnv("HOME", root);
|
|
vi.stubEnv("GH_TOKEN", "legacy-token");
|
|
await writeFile(path.join(root, ".gitconfig"), '[credential]\n helper = store\n');
|
|
await exec("git", ["init", path.join(root, "repo")]);
|
|
const env = await prepareGitHubExecutionEnvironment({ target: null, cwd: path.join(root, "repo"), env: {}, hostCredentials: true, networkAccess: true });
|
|
expect(env.GH_TOKEN).toBe("legacy-token");
|
|
expect(env.GIT_CONFIG_GLOBAL).toBeUndefined();
|
|
expect(env.PAPERCLIP_GIT_METADATA_ROOTS).toContain("/repo/.git");
|
|
const config = await exec("git", ["config", "credential.helper"], { cwd: root, env: { ...process.env, ...env } });
|
|
expect(config.stdout.trim()).toBe("store");
|
|
const isolated = await prepareGitHubExecutionEnvironment({ target: null, cwd: root, env: {}, hostCredentials: false, networkAccess: false });
|
|
expect(isolated.GH_TOKEN).toBeUndefined();
|
|
expect(isolated.PAPERCLIP_RUNNER_NETWORK_ACCESS).toBe("disabled");
|
|
expect(isolated.PAPERCLIP_GITHUB_HOST_HOME).toBeUndefined();
|
|
});
|
|
|
|
it.each(["nvm/current/bin", "usr/local/bin", "tools with 'quotes'/bin"])(
|
|
"preserves %s CLIs and keeps GitHub wrappers first in child shells",
|
|
async (layout) => {
|
|
const fixture = await sandbox(layout);
|
|
vi.stubEnv("PATH", "/controller-only/bin");
|
|
const env = await prepareGitHubOperationLaunchers({
|
|
runId: "run-layout", target: fixture.target, cwd: "/controller", env: {},
|
|
});
|
|
expect(env.PATH).toBe(`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}:${fixture.remotePath}`);
|
|
for (const cli of ["claude", "codex"]) {
|
|
await ensureAdapterExecutionTargetCommandResolvable(cli, fixture.target, fixture.root, env);
|
|
const result = await runAdapterExecutionTargetProcess("run-layout", fixture.target, "bash", [
|
|
"--noprofile", "--norc", "-c", `command -v git; command -v gh; ${cli}`,
|
|
], { cwd: fixture.root, env, timeoutSec: 5, graceSec: 1, onLog: async () => {} });
|
|
expect(result.exitCode, result.stderr).toBe(0);
|
|
expect(result.stdout.trim().split("\n")).toEqual([
|
|
`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}/git`,
|
|
`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}/gh`,
|
|
`${cli} started`,
|
|
]);
|
|
}
|
|
for (const profile of [".profile", ".bash_profile", ".bashrc", ".zshenv", ".zprofile", ".zshrc"]) {
|
|
const script = await readFile(path.join(env.PAPERCLIP_GITHUB_LAUNCHER_DIR, profile), "utf8");
|
|
const result = await fixture.runner.execute({ command: "sh", args: ["-c", `${script}\nprintf '%s' "$PATH"`] });
|
|
expect(result.stdout).toBe(env.PATH);
|
|
}
|
|
// The wrappers' Node interpreter and underlying commands are still reachable.
|
|
const github = await fixture.runner.execute({ command: "bash", args: ["-c", "git; gh"], env });
|
|
expect(github.exitCode, github.stderr).toBe(0);
|
|
expect(github.stdout).toBe("git started\ngh started\n");
|
|
},
|
|
);
|
|
|
|
it("preserves an explicit remote PATH without querying the remote environment", async () => {
|
|
const fixture = await sandbox("custom/bin");
|
|
const env = await prepareGitHubOperationLaunchers({
|
|
runId: "run-explicit", target: fixture.target, cwd: fixture.root, env: { PATH: fixture.remotePath },
|
|
});
|
|
expect(env.PATH).toBe(`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}:${fixture.remotePath}`);
|
|
expect(fixture.runner.execute.mock.calls.every(([input]) => !input.args?.join(" ").includes("$PATH"))).toBe(true);
|
|
});
|
|
|
|
it("does not copy an inherited controller PATH into a remote launcher", async () => {
|
|
const fixture = await sandbox("nvm/bin");
|
|
vi.stubEnv("PATH", "/controller-only/bin");
|
|
const env = await prepareGitHubOperationLaunchers({
|
|
runId: "run-inherited", target: fixture.target, cwd: fixture.root, env: { PATH: process.env.PATH! },
|
|
});
|
|
expect(env.PATH).toBe(`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}:${fixture.remotePath}`);
|
|
});
|
|
|
|
it("keeps an explicit empty remote PATH empty apart from the managed wrappers", async () => {
|
|
const fixture = await sandbox("nvm/bin");
|
|
const env = await prepareGitHubOperationLaunchers({
|
|
runId: "run-empty", target: fixture.target, cwd: fixture.root, env: { PATH: "" },
|
|
});
|
|
expect(env.PATH).toBe(env.PAPERCLIP_GITHUB_LAUNCHER_DIR);
|
|
expect(fixture.runner.execute.mock.calls.every(([input]) => !input.args?.join(" ").includes("$PATH"))).toBe(true);
|
|
const result = await fixture.runner.execute({ command: "/bin/sh", args: ["-c", "command -v claude"], env });
|
|
expect(result.exitCode).not.toBe(0);
|
|
});
|
|
|
|
it("reads the SSH target PATH and ignores login banners", async () => {
|
|
const fixture = await sandbox("ssh-toolchain/bin");
|
|
fixture.runner.execute.mockResolvedValueOnce({ exitCode: 0, timedOut: false, signal: null,
|
|
stdout: `Welcome\n\0${fixture.remotePath}\0\n`, stderr: "", pid: null, startedAt: new Date().toISOString() });
|
|
vi.spyOn(ssh, "createSshCommandManagedRuntimeRunner").mockReturnValue(fixture.runner);
|
|
const target = { kind: "remote" as const, transport: "ssh" as const, remoteCwd: fixture.root,
|
|
spec: { host: "sandbox.example.test", port: 22, username: "runner", remoteCwd: fixture.root,
|
|
remoteWorkspacePath: fixture.root, privateKey: null, knownHosts: null, strictHostKeyChecking: true } };
|
|
const env = await prepareGitHubOperationLaunchers({ runId: "run-ssh", target, cwd: fixture.root, env: {} });
|
|
expect(env.PATH).toBe(`${env.PAPERCLIP_GITHUB_LAUNCHER_DIR}:${fixture.remotePath}`);
|
|
expect(fixture.runner.execute.mock.calls[0]?.[0].env).toBeUndefined();
|
|
});
|
|
|
|
it("uses the launch environment for install and re-probe after a missing command", async () => {
|
|
const fixture = await sandbox("custom/bin");
|
|
const env = { PATH: fixture.remotePath, HOME: fixture.root };
|
|
await ensureAdapterExecutionTargetCommandResolvable("fixture-cli", fixture.target, fixture.root, env, {
|
|
installCommand: `cp ${ssh.shellQuote(path.join(fixture.bin, "claude"))} ${ssh.shellQuote(path.join(fixture.bin, "fixture-cli"))}`,
|
|
});
|
|
expect(fixture.runner.execute.mock.calls).toHaveLength(3);
|
|
for (const [input] of fixture.runner.execute.mock.calls) expect(input.env).toEqual(env);
|
|
});
|
|
|
|
it("checks command availability with the launch environment, not the provider default", async () => {
|
|
const fixture = await sandbox("nvm/bin");
|
|
const env = { PATH: "/usr/bin:/bin" };
|
|
// The binary exists on the provider PATH, but the requested launch excludes it.
|
|
await expect(ensureAdapterExecutionTargetCommandResolvable(
|
|
"claude", fixture.target, fixture.root, env,
|
|
)).rejects.toThrow('Command "claude" is not installed or not on PATH');
|
|
const result = await runAdapterExecutionTargetProcess("run-missing", fixture.target, "sh", ["-c", "claude"], {
|
|
cwd: fixture.root, env, timeoutSec: 5, graceSec: 1, onLog: async () => {},
|
|
});
|
|
expect(result.exitCode).toBe(127);
|
|
});
|
|
|
|
it.each([
|
|
{ exitCode: 1, timedOut: false, stdout: "" },
|
|
{ exitCode: 0, timedOut: true, stdout: "" },
|
|
{ exitCode: 0, timedOut: false, stdout: "login banner only" },
|
|
{ exitCode: 0, timedOut: false, stdout: "\0\0" },
|
|
])("fails before staging when remote PATH discovery fails: %j", async (failure) => {
|
|
const fixture = await sandbox("nvm/bin");
|
|
fixture.runner.execute.mockResolvedValueOnce({ ...failure, signal: null, stderr: "private diagnostic",
|
|
pid: null, startedAt: new Date().toISOString() });
|
|
await expect(prepareGitHubOperationLaunchers({
|
|
runId: "run-failure", target: fixture.target, cwd: fixture.root, env: {},
|
|
})).rejects.toThrow("Could not resolve remote PATH for managed GitHub launchers");
|
|
expect(fixture.runner.execute).toHaveBeenCalledTimes(1);
|
|
});
|
|
});
|