Files
PaperClipAI/packages/plugins/sandbox-providers
Valentin PalkovicandClaude Opus 5.5 bb73f2fe39 feat(exe-dev): copy a source VM with exe.dev cp (#14975)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The exe.dev sandbox provider plugin gives each run its own exe.dev
VM
> - Today the plugin always creates that VM with `exe.dev new`, so every
run starts from a bare image
> - Large repositories need a long setup on each VM: toolchain, agent
CLIs, package caches, and browsers for tests
> - exe.dev has a `cp` command that copies an existing VM, disk and
config included
> - This pull request adds an optional `sourceVm` setting. When it is
set, the plugin copies that VM with `exe.dev cp` instead of creating a
new one
> - The benefit is that operators prepare one VM once, and each run
starts from it

## Linked Issues or Issue Description

Refs #13575. That open PR rewrites this plugin for durable exe.dev
environments. It does not add `cp`. The two changes touch the same files
and can conflict.

I found no issue for this. Feature description:

**Subsystem affected**
packages/plugins: the exe.dev sandbox provider plugin
(`packages/plugins/sandbox-providers/exe-dev`).

**Problem or motivation**
Each run gets a fresh exe.dev VM from `exe.dev new`. We use a large
monorepo (Storybook). Before the agent can work, each run must install
Node, the agent CLIs, and Playwright browsers. Each run must also fill
the package manager cache. This setup takes a long time on each run.

**Proposed solution**
Add a `sourceVm` setting ("Source VM" in the environment form). When it
is set, lease acquisition and probes run `exe.dev cp <sourceVm>
<generated-name> --json`. The command also sends the configured `cpu`,
`memory`, and `disk`. The VM name, the SSH setup, the workspace, and the
release and destroy steps do not change. When the setting is blank, the
plugin uses `exe.dev new` as before.

**Alternatives considered**
- A custom image with `--image`: the operator must build and push a
large image for each change. A private registry needs `--registry-auth`,
and the plugin does not support it.
- `--setup-script`: it runs on every new VM, so each run still pays the
setup cost. It also has a 10 KiB limit.
- `reuseLease`: it keeps one VM for one lease. It does not give each run
a fresh copy of a prepared VM.

**Roadmap alignment**
The change stays inside an existing sandbox provider plugin.
`ROADMAP.md` lists "Cloud / Sandbox agent support" as done and does not
plan VM copies. CONTRIBUTING.md asks to discuss features in Discord
`#dev` first. I open this pull request as a draft and start that
discussion in `#dev`.

**Additional context**
exe.dev documents `cp` here: https://exe.dev/docs/cli-cp. exe.dev token
permissions are documented here: https://exe.dev/docs/https-api.

## What Changed

- `plugin.ts`: add `sourceVm` to the driver config.
- `plugin.ts`: `buildCreateCommand` sends `cp` when `sourceVm` is set.
- `plugin.ts`: config validation rejects `sourceVm` together with
settings that `cp` cannot apply (`image`, `command`, `comment`, `env`,
`integrations`, `tags`, `setupScript`, `prompt`). The error names the
settings to clear. The server shows validation errors in the form, but
it does not show warnings after a successful save.
- `manifest.ts`: add the "Source VM" field to the "VM creation" group.
Its description says that the API token must allow `cp`, because exe.dev
returns 403 for a command that the token does not list. The API key
description now also mentions `cp`.
- `README.md`: document `sourceVm`, its limits, and the token
permission.
- `plugin.test.ts`: add tests for the `cp` command, the validation
error, and the form field. Add `sourceVm: null` to the expected
normalized config.

## Verification

- `vitest run --config vitest.config.ts` in
`packages/plugins/sandbox-providers/exe-dev`: 38 tests pass. The three
new tests fail without the change.
- `tsc --noEmit -p packages/plugins/sandbox-providers/exe-dev`: no
errors.
- Manual test on a self-hosted Paperclip instance (2026.1001.0). I
applied the same change to the installed plugin. I prepared a source VM
and set "Source VM" on an exe.dev environment. Then I ran agent tasks.
Each run copied the source VM and ran in the copy. Paperclip deleted the
copy at release.
- With an API token that does not list `cp`, the run fails with `exe.dev
API command failed (403) for: cp '<source>' '<name>' --json ...`. The
new field description tells operators about this.

## Risks

- Low risk. The new code runs only when `sourceVm` is set. The `new`
path is unchanged.
- `cp` uses the same `/exec` endpoint and its 30-second request limit. A
copy of a very large disk can take longer than the limit.
- Every copy inherits the source VM disk. The README tells operators not
to keep secrets on the source VM.
- Can conflict with #13575.

## Model Used

- Provider and model: Anthropic Claude Opus 5.5.
- Model ID: `claude-opus-5-5`.
- Tool: Claude Code, with tool use (shell commands and file edits) and
extended thinking.
- Context window: the tool does not report it.
- The model wrote the change and the tests. A human tested the feature
on a real exe.dev setup.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<img width="1166" height="852" alt="Bildschirmfoto 2026-10-02 um 23 04
32"
src="https://github.com/user-attachments/assets/c057bee4-9f27-4a69-945e-0f71d5bcc1ba"
/>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-05 22:11:59 -07:00
..