Files
PaperClipAI/server/src/__tests__/environment-live-ssh.test.ts
T
DottaandPaperclip 2dbaf4a7fa External object references across issue surfaces (#8512)
## Thinking Path

> - Paperclip is the open source control plane people use to coordinate
AI agents, issues, approvals, comments, and work products.
> - The involved subsystem is issue context: markdown links, issue
properties, related work, lists, filters, inbox/sidebar status, and
plugin-provided external context.
> - The gap is that URLs to external systems currently remain mostly
plain links, so humans and agents must manually open them to understand
status, identity, and liveness.
> - This matters because external work objects such as GitHub issues and
pull requests are part of the operational state of a Paperclip company.
> - The implementation keeps core provider-neutral: shared contracts,
storage, sync, routes, and UI surfaces live in core while providers can
contribute detection and status resolution.
> - This pull request adds the external object reference foundation,
GitHub provider support, issue-surface rendering, filters,
sidebar/list/inbox signals, and test/story coverage.
> - The benefit is that linked external work becomes inspectable
Paperclip context without hardcoding every provider directly into the
UI.

## Linked Issues or Issue Description

No public GitHub issue exists for this work.

Feature request:

- Problem: URLs in Paperclip issues, comments, documents, and related
surfaces do not expose provider status or object identity inline.
- Proposed behavior: detect supported external object URLs, persist
normalized references, refresh provider status, and render concise
status-aware links across issue surfaces.
- Users affected: board users, agents, and maintainers who triage issues
containing external work links.
- Acceptance: external object references are company-scoped,
provider-extensible, visible in key issue surfaces, filterable where
relevant, and covered by focused shared/server/UI tests.

Related PR search:

- No open duplicate PRs found for `external object references`.
- Closed related prior attempt: #4556.

## What Changed

- Added shared external-object contracts, validators, status/liveness
helpers, and plugin protocol declarations.
- Added database schema and additive migrations for external objects,
source mentions, and display metadata.
- Added server services/routes for detecting, syncing, summarizing,
refreshing, and resolving external objects across issues, documents,
comments, projects, and plugins.
- Added a GitHub external-object provider plus plugin SDK authoring
docs.
- Wired UI presentation across markdown links, comments, issue chat,
documents, properties, related work, issue rows, filters, inbox/sidebar
badges, and Storybook stories.
- Rebasing cleanup: moved the branch onto current `master`, repaired
stale worktree provision config, hardened environment-sensitive
tests/mocks, and removed committed screenshot artifacts from the PR
branch to keep the reviewable file set below tool limits.

## Verification

- `pnpm exec vitest run packages/shared/src/external-objects.test.ts
server/src/__tests__/external-object-routes.test.ts
server/src/__tests__/external-objects-service.test.ts
ui/src/components/ExternalObjectPill.test.tsx
ui/src/lib/external-objects.test.ts` passed after rebasing: 5 files, 56
tests.
- Historical branch verification before this PR creation included `pnpm
test:run`, `pnpm -r typecheck`, and `pnpm build`; this PR body does not
claim those were rerun after the final rebase.

## Risks

- Medium: this adds a new cross-surface sync path on
issue/document/comment writes. The implementation uses safe sync
wrappers so external-object failures warn instead of blocking core
mutations.
- Medium: the migrations introduce new tables and indexes. They are
additive and company-scoped.
- Medium: provider-specific URL parsing can miss or misclassify edge
cases. Shared canonicalization tests and provider tests cover current
GitHub shapes.
- Low: UI badge/filter behavior could add visual noise for object-heavy
issues; component tests and Storybook stories cover the intended
surfaces.

> Roadmap checked: `ROADMAP.md` references the plugin system as the
current extension path and does not list a duplicate core feature.
Related long-range docs discuss external references, work products,
preview URLs, and plugin extension points; this PR implements the scoped
external-object reference foundation.

## Model Used

OpenAI Codex, GPT-5 coding-agent runtime, with shell and GitHub CLI tool
use. Reasoning mode: medium. Exact deployed runtime model ID and context
window were not exposed in the environment.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-06-23 08:27:19 -05:00

185 lines
6.0 KiB
TypeScript

import { readFile } from "node:fs/promises";
import path from "node:path";
import { afterAll, describe, expect, it } from "vitest";
import {
buildSshEnvLabFixtureConfig,
ensureSshWorkspaceReady,
readSshEnvLabFixtureStatus,
runSshCommand,
startSshEnvLabFixture,
stopSshEnvLabFixture,
type SshConnectionConfig,
} from "@paperclipai/adapter-utils/ssh";
async function readOptionalSecret(
value: string | undefined,
filePath: string | undefined,
): Promise<string | null> {
if (value && value.trim().length > 0) {
return value;
}
if (filePath && filePath.trim().length > 0) {
return await readFile(filePath, "utf8");
}
return null;
}
/**
* Resolve the env-lab state path for this instance. Falls back to a temp
* directory scoped to the test run so parallel runs don't collide.
*/
function resolveEnvLabStatePath(): string {
const instanceRoot =
process.env.PAPERCLIP_INSTANCE_ROOT?.trim() ||
path.join(process.env.HOME ?? "/tmp", ".paperclip-worktrees", "instances", "live-ssh-test");
return path.join(instanceRoot, "env-lab", "ssh-fixture", "state.json");
}
/** Attempt to build config from explicit PAPERCLIP_ENV_LIVE_SSH_* env vars. */
function tryExplicitConfig(): {
host: string;
port: number;
username: string;
remoteWorkspacePath: string;
} | null {
const host = process.env.PAPERCLIP_ENV_LIVE_SSH_HOST?.trim() ?? "";
const username = process.env.PAPERCLIP_ENV_LIVE_SSH_USERNAME?.trim() ?? "";
const remoteWorkspacePath =
process.env.PAPERCLIP_ENV_LIVE_SSH_REMOTE_WORKSPACE_PATH?.trim() ?? "";
const port = Number.parseInt(process.env.PAPERCLIP_ENV_LIVE_SSH_PORT ?? "22", 10);
if (!host || !username || !remoteWorkspacePath || !Number.isInteger(port) || port < 1 || port > 65535) {
return null;
}
return { host, port, username, remoteWorkspacePath };
}
/** Try to use an already-running env-lab fixture. */
async function tryEnvLabFixture(): Promise<SshConnectionConfig | null> {
const statePath = resolveEnvLabStatePath();
const status = await readSshEnvLabFixtureStatus(statePath);
if (status.running && status.state) {
return buildSshEnvLabFixtureConfig(status.state);
}
return null;
}
/**
* Start a fresh env-lab SSH fixture for this test run. Returns the config
* and a cleanup function to stop it afterwards.
*/
async function startEnvLabForTest(): Promise<{
config: SshConnectionConfig;
cleanup: () => Promise<void>;
} | null> {
const statePath = resolveEnvLabStatePath();
try {
const state = await startSshEnvLabFixture({ statePath });
const config = await buildSshEnvLabFixtureConfig(state);
return {
config,
cleanup: async () => {
await stopSshEnvLabFixture(statePath);
},
};
} catch {
return null;
}
}
let envLabCleanup: (() => Promise<void>) | null = null;
/**
* Resolve an SSH connection config from (in order):
* 1. Explicit PAPERCLIP_ENV_LIVE_SSH_* env vars
* 2. An already-running env-lab fixture
* 3. Auto-starting an env-lab fixture
*/
async function resolveSshConfig(): Promise<SshConnectionConfig | null> {
// 1. Explicit env vars
const explicit = tryExplicitConfig();
if (explicit) {
return {
...explicit,
privateKey: await readOptionalSecret(
process.env.PAPERCLIP_ENV_LIVE_SSH_PRIVATE_KEY,
process.env.PAPERCLIP_ENV_LIVE_SSH_PRIVATE_KEY_PATH,
),
knownHosts: await readOptionalSecret(
process.env.PAPERCLIP_ENV_LIVE_SSH_KNOWN_HOSTS,
process.env.PAPERCLIP_ENV_LIVE_SSH_KNOWN_HOSTS_PATH,
),
strictHostKeyChecking:
(process.env.PAPERCLIP_ENV_LIVE_SSH_STRICT_HOST_KEY_CHECKING ?? "true").toLowerCase() !== "false",
};
}
// 2. Already-running env-lab
const running = await tryEnvLabFixture();
if (running) return running;
// 3. Auto-start env-lab
if (process.env.PAPERCLIP_ENV_LIVE_SSH_NO_AUTO_FIXTURE !== "true") {
const started = await startEnvLabForTest();
if (started) {
envLabCleanup = started.cleanup;
return started.config;
}
}
return null;
}
let resolvedConfig: SshConnectionConfig | null | undefined;
const describeLiveSsh = (() => {
// Eagerly check explicit env vars for sync skip decision.
// If explicit vars are set, use them. Otherwise, we'll attempt env-lab in beforeAll.
if (tryExplicitConfig()) return describe;
// If NO_AUTO_FIXTURE is set and no explicit config, skip immediately
if (process.env.PAPERCLIP_ENV_LIVE_SSH_NO_AUTO_FIXTURE === "true") {
console.warn(
"Skipping live SSH smoke test. Set PAPERCLIP_ENV_LIVE_SSH_HOST, PAPERCLIP_ENV_LIVE_SSH_USERNAME, and PAPERCLIP_ENV_LIVE_SSH_REMOTE_WORKSPACE_PATH to enable it, or remove PAPERCLIP_ENV_LIVE_SSH_NO_AUTO_FIXTURE to auto-start env-lab.",
);
return describe.skip;
}
// Will attempt env-lab — don't skip yet
return describe;
})();
describeLiveSsh("live SSH environment smoke", () => {
afterAll(async () => {
if (envLabCleanup) {
await envLabCleanup();
envLabCleanup = null;
}
});
it("connects to the configured SSH environment and verifies basic runtime tools", async () => {
if (resolvedConfig === undefined) {
resolvedConfig = await resolveSshConfig();
}
if (!resolvedConfig) {
console.warn(
"Live SSH smoke test could not resolve SSH config from env vars or env-lab fixture. Set PAPERCLIP_ENV_LIVE_SSH_NO_AUTO_FIXTURE=true to mark this suite skipped intentionally.",
);
return;
}
const config = resolvedConfig;
const ready = await ensureSshWorkspaceReady(config);
const quotedRemoteWorkspacePath = JSON.stringify(config.remoteWorkspacePath);
const result = await runSshCommand(
config,
`cd ${quotedRemoteWorkspacePath} && which git && which tar && pwd`,
{ timeoutMs: 30000, maxBuffer: 256 * 1024 },
);
expect(ready.remoteCwd).toBe(config.remoteWorkspacePath);
expect(result.stdout).toContain(config.remoteWorkspacePath);
expect(result.stdout).toContain("git");
expect(result.stdout).toContain("tar");
}, 30_000);
});