Files
PaperClipAI/cli/src/__tests__/install-store.test.ts
T
DottaandPaperclip 2991a59b17 fix(adapters): prevent engine fallback and preserve usable runtime defaults (#13105)
## Thinking Path

> - Paperclip manages agents that must write work and report task
outcomes through its API.
> - Local adapters select an execution engine and its permission
settings.
> - A higher ACP Node requirement can make an unchanged installation
lose access to its default engine.
> - The adapter then silently selects CLI, which can change permissions
and block API access.
> - This pull request keeps the engine choice fixed and reports missing
prerequisites before work starts.
> - It also gives explicit Codex CLI runs usable defaults and keeps
managed services on a supported Node runtime.

## Linked Issues or Issue Description

Refs #12215. Related changes: #11792 raised the Node requirement; #13094
addressed separate runner networking behavior. This change fixes the
engine-selection and managed-launcher paths.

**What happened?**

An unchanged agent could switch from ACP to CLI after an upgrade. Codex
CLI then used read-only permissions with networking disabled. The run
could finish without updating its task. Repeated recovery attempts used
the same unavailable setup. Managed updates also skipped the Node check
and did not refresh old launchers.

**Expected behavior**

An unavailable engine must fail with a clear setup error. It must not
silently select another engine. Explicit CLI runs must be able to write
workspace files and call the API unless the operator configures stricter
settings. Managed updates must validate Node and keep child tools on
that runtime.

**Steps to reproduce**

1. Run an ACP-default agent under Node 22 after the ACP minimum rises to
24.11.
2. Leave the engine unset and disable the approval/sandbox bypass.
3. Observe the old adapter select CLI and fail to write task disposition
through the API.
4. Start a managed service with an old launcher and a supervisor PATH
that selects a different Node for child tools.

## What Changed

- Remove automatic engine fallback for Codex, Claude, Gemini, and Kimi.
Check prerequisites for default and explicit ACP selections.
- Return a configuration error with proof that provider work did not
start. Stop automatic continuation retries for this error.
- Enable Codex ACP workspace networking at the actual turn boundary.
Upstream mode presets otherwise force it off even when config.toml
enables it. Preserve explicit network denial and read-only mode.
- Set workspace-write and network access defaults for explicit Codex CLI
runs. Preserve explicit sandbox modes, profiles, and network
restrictions.
- Pin the validated Node directory in managed launcher PATH. Refresh
legacy launchers during installs and npm/Git updates.
- Reject updates on unsupported Node. Keep update checks, dry runs, and
rollback available.
- Synchronize the qualified Codex ACP executable identity across server,
TypeScript runner, Rust runner, and provider-pack launch paths.
- Add regression tests and update engine and installation documentation.

## Verification

- [Full CI passed on the final
head](https://github.com/paperclipai/paperclip/actions/runs/34387099695):
typecheck, build/native runner verification, all general and serialized
test shards, all browser shards, release registry, canary dry run, and
policy checks.
- Greptile: 5/5 on `2c1d6e2815830a5cd39e36c8a082cc0c4441b6c0`, with no
unresolved review findings. Security gates are green.
- Full workspace typecheck and build also passed locally. The final
deployed Linux build passed.
- Full Codex, Claude, Gemini, and Kimi source test suites: 804 passed, 2
skipped. Installer, updater, and launcher tests: 47 passed. Installed
ACP turn-boundary tests: 3 passed. ACP packaging tests: 14 passed.
Focused recovery classification tests also passed.
- Real Linux Codex CLI runs, both fresh and resumed, wrote a workspace
file and reached the control-plane health API with the new defaults.
- Explicit read-only and network-disabled control probes retained those
restrictions.
- A real ACP run on the final deployed Linux build wrote a file and
reached the control-plane API with HTTP 200, without engine fallback.
The same probe failed DNS before the turn-policy patch.
- Executable-identity and installed-policy contracts: 12 passed.
Affected native server tests: 197 passed. Runner factory tests: 21
passed. Rust qualification and native provider integration tests: 11
passed.
- Deployed the production changes to a Linux service on Node 24.20 after
a verified database backup. Health, bootstrap readiness, static UI,
executable/cwd identity, and guarded restart checks passed. The restart
lost no runs.
- Corrected stale Kimi skill-default and Gemini remote-archive fixtures;
both suites pass.

## Risks

- Default or legacy auto engine settings now fail when ACP is
unavailable. Operators who intend to use CLI must select it explicitly.
- Codex CLI now permits workspace writes and networking by default, and
ACP workspace-write turns permit networking by default. Explicit
operator sandbox settings remain authoritative.
- Old managed launchers keep their pinned Node until they are
reinstalled under a supported runtime. An old updater cannot repair
itself; the documentation gives the current installer command.
- Custom service wrappers and global/source installations must configure
their runtime PATH. No database migration is required.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, repository inspection,
shell execution, and test tools. The exact serving model identifier and
context-window size are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-09 13:27:24 -05:00

231 lines
9.5 KiB
TypeScript

import fs from "node:fs";
import { execFileSync } from "node:child_process";
import os from "node:os";
import path from "node:path";
import { afterEach, beforeEach, describe, expect, it } from "vitest";
import {
INSTALL_MANIFEST_VERSION,
MANAGED_SHIM_MARKER,
addManagedPathBlock,
buildNextManifest,
flipCurrentAtomic,
isManagedExecutable,
payloadPathFor,
pruneInstallPayloads,
readInstallManifest,
removeManagedPathBlock,
removeManagedShim,
resolveInstallStorePaths,
withInstallStoreLock,
writeInstallManifestAtomic,
writeManagedShim,
type InstallManifest,
type InstallRecord,
} from "../install-store.js";
function record(payloadPath: string, version: string): InstallRecord {
return {
source: "npm",
version,
channel: "latest",
payloadPath,
installedAt: `2026-07-${version.padStart(2, "0")}T00:00:00.000Z`,
};
}
describe("managed install store", () => {
let root: string;
let paths: ReturnType<typeof resolveInstallStorePaths>;
beforeEach(() => {
root = fs.mkdtempSync(path.join(os.tmpdir(), "paperclip-install-store-"));
paths = resolveInstallStorePaths({
homeDir: path.join(root, "home"),
paperclipHome: path.join(root, "home", ".paperclip"),
});
});
afterEach(() => {
fs.rmSync(root, { recursive: true, force: true });
});
it("resolves the documented npm and git payload layout", () => {
expect(payloadPathFor(paths, "npm", "2026.720.0")).toBe(
path.join(paths.cliRoot, "installs", "npm", "2026.720.0"),
);
expect(payloadPathFor(paths, "git", "ab12cd34ef56")).toBe(
path.join(paths.cliRoot, "installs", "git", "ab12cd34ef56"),
);
});
it("writes and reads the manifest atomically with private permissions", () => {
const payloadPath = payloadPathFor(paths, "npm", "1.2.3");
const manifest: InstallManifest = {
schemaVersion: INSTALL_MANIFEST_VERSION,
...record(payloadPath, "1.2.3"),
previous: [],
};
writeInstallManifestAtomic(manifest, paths);
expect(readInstallManifest(paths)).toEqual(manifest);
expect(fs.statSync(paths.manifestPath).mode & 0o777).toBe(0o600);
});
it("leaves the old current payload working when interrupted before rename", () => {
const oldPayload = payloadPathFor(paths, "npm", "1.0.0");
const newPayload = payloadPathFor(paths, "npm", "2.0.0");
fs.mkdirSync(oldPayload, { recursive: true });
fs.mkdirSync(newPayload, { recursive: true });
flipCurrentAtomic(oldPayload, paths);
expect(() =>
flipCurrentAtomic(newPayload, paths, {
beforeRename: () => {
throw new Error("simulated crash");
},
}),
).toThrow("simulated crash");
expect(fs.realpathSync(paths.currentPath)).toBe(fs.realpathSync(oldPayload));
expect(fs.readdirSync(paths.cliRoot).filter((entry) => entry.startsWith(".current-"))).toEqual([]);
});
it("retains current plus two previous payloads and prunes older entries", () => {
const payloads = ["1", "2", "3", "4"].map((version) => payloadPathFor(paths, "npm", version));
for (const payload of payloads) fs.mkdirSync(payload, { recursive: true });
const previousManifest: InstallManifest = {
schemaVersion: INSTALL_MANIFEST_VERSION,
...record(payloads[2], "3"),
previous: [record(payloads[1], "2"), record(payloads[0], "1")],
};
const next = buildNextManifest(record(payloads[3], "4"), previousManifest);
expect(next.previous.map((entry) => entry.version)).toEqual(["3", "2"]);
expect(pruneInstallPayloads(next, paths)).toEqual([payloads[0]]);
expect(fs.existsSync(payloads[0])).toBe(false);
expect(payloads.slice(1).every((payload) => fs.existsSync(payload))).toBe(true);
});
it("writes a stable shim with the validated runtime and custom store path", () => {
writeManagedShim(paths);
const shim = fs.readFileSync(paths.shimPath, "utf8");
expect(shim).toContain(process.execPath);
expect(shim).toContain(paths.currentPath);
expect(shim).not.toContain("PAPERCLIP_HOME");
expect(fs.statSync(paths.shimPath).mode & 0o777).toBe(0o755);
const rcPath = path.join(root, "home", ".bashrc");
expect(addManagedPathBlock(rcPath)).toBe(true);
expect(addManagedPathBlock(rcPath)).toBe(false);
fs.chmodSync(rcPath, 0o640);
expect(removeManagedPathBlock(rcPath)).toBe(true);
expect(fs.readFileSync(rcPath, "utf8")).not.toContain("paperclipai managed PATH");
expect(fs.statSync(rcPath).mode & 0o777).toBe(0o640);
});
it("uses the pinned Node for child tools even with an older node first on the service PATH", () => {
const entrypoint = path.join(paths.currentPath, "node_modules", "paperclipai", "dist", "index.js");
fs.mkdirSync(path.dirname(entrypoint), { recursive: true });
fs.writeFileSync(entrypoint, `console.log(require("node:child_process").execFileSync("node", ["-p", "process.execPath"], {encoding: "utf8"}).trim())`);
const oldBin = path.join(root, "old-bin");
fs.mkdirSync(oldBin);
fs.writeFileSync(path.join(oldBin, "node"), "#!/bin/sh\nexit 42\n", { mode: 0o755 });
writeManagedShim(paths);
const output = execFileSync(paths.shimPath, [], { env: { ...process.env, PATH: oldBin }, encoding: "utf8" });
expect(fs.realpathSync(output.trim())).toBe(fs.realpathSync(process.execPath));
expect(removeManagedShim(paths)).toBe(true);
});
it("upgrades and removes the original managed shim format", () => {
writeManagedShim(paths);
const original = fs.readFileSync(paths.shimPath, "utf8").split("\n").filter((line) => !line.startsWith("export PATH=")).join("\n");
fs.writeFileSync(paths.shimPath, original);
writeManagedShim(paths);
expect(fs.readFileSync(paths.shimPath, "utf8")).toContain("export PATH=");
fs.writeFileSync(paths.shimPath, original);
expect(removeManagedShim(paths)).toBe(true);
});
it("rejects marker substrings that are not the exact managed shim format", () => {
fs.mkdirSync(path.dirname(paths.shimPath), { recursive: true });
fs.writeFileSync(paths.shimPath, `#!/bin/sh\necho '${MANAGED_SHIM_MARKER}'\n`);
expect(removeManagedShim(paths)).toBe(false);
expect(fs.existsSync(paths.shimPath)).toBe(true);
expect(() => writeManagedShim(paths)).toThrow("non-managed command");
});
it("serializes install-store mutations with an exclusive lock", async () => {
await expect(
withInstallStoreLock(
() => withInstallStoreLock(async () => undefined, paths),
paths,
),
).rejects.toThrow("already running");
expect(fs.existsSync(paths.lockPath)).toBe(false);
});
it("recovers a lock owned by a process that no longer exists", async () => {
const staleToken = "2147483647:stale";
await withInstallStoreLock(async () => undefined, paths);
fs.writeFileSync(paths.lockPath, `${staleToken}\n`, { mode: 0o600 });
await expect(withInstallStoreLock(async () => undefined, paths)).resolves.toBeUndefined();
expect(fs.existsSync(paths.lockPath)).toBe(false);
});
it("reports managed provenance only for the payload selected by current", () => {
const manifestPayload = payloadPathFor(paths, "npm", "1.0.0");
const currentPayload = payloadPathFor(paths, "npm", "2.0.0");
const executable = path.join(manifestPayload, "node_modules", "paperclipai", "dist", "index.js");
fs.mkdirSync(path.dirname(executable), { recursive: true });
fs.writeFileSync(executable, "");
fs.mkdirSync(currentPayload, { recursive: true });
flipCurrentAtomic(currentPayload, paths);
const manifest: InstallManifest = {
schemaVersion: INSTALL_MANIFEST_VERSION,
...record(manifestPayload, "1.0.0"),
previous: [],
};
expect(isManagedExecutable(executable, manifest, paths)).toBe(false);
});
it("refuses symlinked payload roots and pre-existing non-managed shims", () => {
const outside = path.join(root, "outside");
fs.mkdirSync(outside, { recursive: true });
fs.mkdirSync(paths.installsRoot, { recursive: true });
fs.symlinkSync(outside, path.join(paths.installsRoot, "npm"), "dir");
const escapedPayload = path.join(paths.installsRoot, "npm", "1.2.3");
fs.mkdirSync(path.join(outside, "1.2.3"));
expect(() => flipCurrentAtomic(escapedPayload, paths)).toThrow("resolves outside");
fs.mkdirSync(path.dirname(paths.shimPath), { recursive: true });
fs.writeFileSync(paths.shimPath, "#!/bin/sh\necho other-command\n");
expect(() => writeManagedShim(paths)).toThrow("non-managed command");
});
it("refuses symlinked rc files, unsafe shim parents, and multiply linked shims", () => {
const outsideRc = path.join(root, "outside-rc");
fs.writeFileSync(outsideRc, "keep\n");
const rcPath = path.join(root, "home", ".bashrc");
fs.mkdirSync(path.dirname(rcPath), { recursive: true });
fs.symlinkSync(outsideRc, rcPath);
expect(() => addManagedPathBlock(rcPath)).toThrow("non-regular shell rc file");
expect(() => removeManagedPathBlock(rcPath)).toThrow("non-regular shell rc file");
expect(fs.readFileSync(outsideRc, "utf8")).toBe("keep\n");
fs.rmSync(rcPath);
const localDir = path.join(root, "home", ".local");
const outsideBin = path.join(root, "outside-bin");
fs.mkdirSync(outsideBin);
fs.symlinkSync(outsideBin, localDir, "dir");
expect(() => writeManagedShim(paths)).toThrow("unsafe shim directory");
fs.rmSync(localDir);
fs.mkdirSync(path.dirname(paths.shimPath), { recursive: true });
fs.writeFileSync(paths.shimPath, `# ${MANAGED_SHIM_MARKER}\n`);
fs.linkSync(paths.shimPath, path.join(root, "linked-shim"));
expect(() => writeManagedShim(paths)).toThrow("multiply linked shim");
});
});