Files
paperclip/scripts/ensure-plugin-build-deps.mjs
DottaandPaperclip 30c63af0e6 fix(cli): recover abandoned workspace build locks (#13288)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The test-drive command starts an isolated instance for local
testing.
> - Source startup builds shared packages before it starts the server.
> - An interrupted build can leave an empty lock directory.
> - Later starts wait without output and fail after 60 seconds.
> - This pull request recovers abandoned locks and shows build progress.
> - Local testing can start again without manual lock removal.

## Linked Issues or Issue Description

**What happened?**

`pnpm paperclipai test-drive` stopped at “Starting Paperclip server…” in
a source checkout. A leftover plugin build lock caused a silent
60-second wait and then a timeout.

**Expected behavior**

Startup should recover an abandoned build lock. It should show when it
waits for a live build. An interrupted or failed build should not leave
partial output that the next start accepts as complete.

**Steps to reproduce**

1. Leave an empty `node_modules/.cache/paperclip-plugin-build-deps.lock`
directory after an interrupted build.
2. Make the shared or plugin SDK build output out of date.
3. Run `pnpm paperclipai test-drive --api-key placeholder --no-browser`
with a fresh data directory.
4. Observe the silent wait at server startup.

**Paperclip version or commit**

Reproduced at `2083bf6f9`.

**Deployment mode**

Local source checkout with an isolated embedded PostgreSQL instance.

Related work: #12894 added test-drive. #12898 restored its credential
inputs. Neither change handles abandoned workspace build locks. No
duplicate fix was found.

## What Changed

- Publish a lock directory with an owner record in one rename.
- Recover locks after their owner and compiler exit. Recover legacy
empty locks after two minutes.
- Keep the lock until the compiler stops on SIGINT or SIGTERM.
- Print build and lock-wait progress.
- Record source, dependency, compiler-config, and output content
fingerprints only after a successful compile. Recover partial output
even when modification times are unchanged.
- Add 12 process-level regression tests and update the development
guide.

## Verification

- `node --test scripts/__tests__/ensure-plugin-build-deps.test.mjs`: 12
tests pass.
- `pnpm exec vitest run --config cli/vitest.config.ts
cli/src/__tests__/test-drive.test.ts`: 32 tests pass.
- `pnpm --filter paperclipai typecheck`: passed.
- `pnpm --filter paperclipai build`: passed.
- Live smoke tests: fresh startup and startup with an abandoned lock
both reach ready state. The API and UI respond. The command creates the
company and CEO and enables worktree execution. Test instances stop
cleanly.
- Full repository `pnpm -r typecheck` and `pnpm build`: passed.
- Full Vitest suite coverage completed using the repository-supported
server, chat, workspace, and serialized shards. The initial local run
needed the fresh-worktree fake native-provider binary built and focused
reruns for port/socket races and load-related timeouts; all affected
tests passed on rerun. Suites skipped by fail-fast exits were run
separately and passed. The initial serial `pnpm test:run` was stopped in
favor of these shards.
- Greptile: 5/5 on commit `8b5a790c2af06a52b5dc76e5f52331966df990b8`,
with all review threads resolved.
- CI: 31 checks passed and two Storybook checks intentionally skipped.
The initial workspace and browser jobs were interrupted by runner
shutdowns; both passed on the second attempt. Build, typecheck, canary
dry run, all general and serialized tests, all browser shards, security
checks, and final verification summaries are green. [CI
run](https://github.com/paperclipai/paperclip/actions/runs/34654730783)

## Risks

- This changes shared source-build locking for the CLI and plugin SDK
commands.
- Legacy locks have no owner identity. Recovery uses a two-minute age
threshold for empty legacy directories.
- Startup reads and hashes source and output files to verify the build
cache. Identical direct builds reuse the cache. Changed or partial
output requires a rebuild.
- A reused process ID can delay recovery. Live owner or compiler
processes keep their lock.
- No database, API, or UI contract changes.

## Model Used

OpenAI GPT-6 in Codex, with reasoning, tool use, code execution, and
process-level testing. A more specific API model identifier and
context-window size are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-11 18:25:42 -05:00

249 lines
8.5 KiB
JavaScript

#!/usr/bin/env node
import { spawn } from "node:child_process";
import fs from "node:fs";
import path from "node:path";
import { fileURLToPath } from "node:url";
import { createHash, randomUUID } from "node:crypto";
import { setTimeout as sleep } from "node:timers/promises";
const scriptDir = path.dirname(fileURLToPath(import.meta.url));
const rootDir = path.resolve(scriptDir, "..");
const tscCliPath = path.join(rootDir, "node_modules", "typescript", "bin", "tsc");
const lockDir = path.join(rootDir, "node_modules", ".cache", "paperclip-plugin-build-deps.lock");
const lockTimeoutMs = 60_000;
const lockPollMs = 100;
const buildTargets = [
{
name: "@paperclipai/shared",
output: path.join(rootDir, "packages/shared/dist/index.js"),
completion: path.join(rootDir, "packages/shared/dist/.paperclip-build-complete"),
sourceDir: path.join(rootDir, "packages/shared/src"),
tsconfig: path.join(rootDir, "packages/shared/tsconfig.json"),
dependencies: [],
},
{
name: "@paperclipai/plugin-sdk",
output: path.join(rootDir, "packages/plugins/sdk/dist/index.js"),
completion: path.join(rootDir, "packages/plugins/sdk/dist/.paperclip-build-complete"),
sourceDir: path.join(rootDir, "packages/plugins/sdk/src"),
tsconfig: path.join(rootDir, "packages/plugins/sdk/tsconfig.json"),
dependencies: [0],
},
];
if (!fs.existsSync(tscCliPath)) {
throw new Error(`TypeScript CLI not found at ${tscCliPath}`);
}
function directoryFingerprint(directory, exclude) {
const hash = createHash("sha256");
function visit(dir) {
for (const entry of fs.readdirSync(dir, { withFileTypes: true }).sort((a, b) => a.name.localeCompare(b.name))) {
const entryPath = path.join(dir, entry.name);
if (entryPath === exclude) continue;
if (entry.isDirectory()) {
visit(entryPath);
} else if (entry.isFile()) {
const content = fs.readFileSync(entryPath);
hash.update(JSON.stringify([path.relative(directory, entryPath), content.length]));
hash.update(content);
}
}
}
visit(directory);
return hash.digest("hex");
}
function sourceFingerprint(target) {
const hash = createHash("sha256");
hash.update(directoryFingerprint(target.sourceDir));
for (const config of [
target.tsconfig,
path.join(path.dirname(target.tsconfig), "package.json"),
path.join(rootDir, "tsconfig.json"),
path.join(rootDir, "tsconfig.base.json"),
path.join(rootDir, "node_modules/typescript/package.json"),
]) {
if (fs.existsSync(config)) hash.update(fs.readFileSync(config));
}
for (const dependency of target.dependencies) hash.update(sourceFingerprint(buildTargets[dependency]));
return hash.digest("hex");
}
function outputFingerprint(target) {
return directoryFingerprint(path.dirname(target.output), target.completion);
}
function needsBuild(target) {
if (!fs.existsSync(target.output)) return true;
try {
const completed = JSON.parse(fs.readFileSync(target.completion, "utf8"));
// Content fingerprints detect partial direct builds even on filesystems
// with coarse timestamps, while identical successful direct builds reuse
// the certified output without another compile.
return completed.sources !== sourceFingerprint(target)
|| completed.outputs !== outputFingerprint(target);
} catch (error) {
if (error.code === "ENOENT" || error instanceof SyntaxError) return true;
throw error;
}
}
function allOutputsCurrent() {
return buildTargets.every((target) => !needsBuild(target));
}
// Publish an already-populated directory so another contender never mistakes a
// newly acquired lock for an abandoned, ownerless lock. Never recursively remove
// the shared path: another process may have acquired it since we last read it.
const ownerFile = `owner-${process.pid}-${randomUUID()}.json`;
let child = null;
let stoppingSignal = null;
let holdsLock = false;
function processAlive(pid) {
if (!Number.isInteger(pid) || pid <= 0) return true;
try {
process.kill(pid, 0);
return true;
} catch (error) {
return error.code !== "ESRCH";
}
}
function removeOwner(file) {
try {
fs.unlinkSync(path.join(lockDir, file));
} catch (error) {
if (error.code === "ENOENT") return;
throw error;
}
try {
fs.rmdirSync(lockDir);
} catch (error) {
if (!["ENOENT", "ENOTEMPTY", "EEXIST"].includes(error.code)) throw error;
}
}
function releaseLock() {
if (!holdsLock) return;
removeOwner(ownerFile);
holdsLock = false;
}
function recoverAbandonedLock() {
try {
const entries = fs.readdirSync(lockDir);
if (entries.length === 0) {
// Older versions wrote no owner. Allow their bounded CLI build to finish
// before reclaiming an empty directory left by interruption or timeout.
if (Date.now() - fs.statSync(lockDir).mtimeMs < 120_000) return;
fs.rmdirSync(lockDir);
} else if (entries.length === 1 && /^owner-.*\.json$/.test(entries[0])) {
const owner = JSON.parse(fs.readFileSync(path.join(lockDir, entries[0]), "utf8"));
if (processAlive(owner.pid) || (owner.childPid && processAlive(owner.childPid))) return;
removeOwner(entries[0]);
} else {
return;
}
console.log("[paperclip] Recovered abandoned workspace build lock.");
} catch (error) {
if (["ENOENT", "ENOTEMPTY", "EEXIST"].includes(error.code) || error instanceof SyntaxError) return;
throw error;
}
}
async function acquireLock() {
fs.mkdirSync(path.dirname(lockDir), { recursive: true });
const candidate = fs.mkdtempSync(`${lockDir}.candidate-`);
fs.writeFileSync(path.join(candidate, ownerFile), JSON.stringify({ pid: process.pid }));
const startedAt = Date.now();
let reportedWait = false;
try {
while (!stoppingSignal) {
// Do not replace a fresh empty lock held by an older script.
recoverAbandonedLock();
if (!fs.existsSync(lockDir)) {
try {
fs.renameSync(candidate, lockDir);
holdsLock = true;
return;
} catch (error) {
if (!["ENOTEMPTY", "EEXIST", "EPERM"].includes(error.code)) throw error;
}
}
if (!reportedWait) {
console.log(`[paperclip] Waiting for another workspace build (${lockDir})...`);
reportedWait = true;
}
if (Date.now() - startedAt >= lockTimeoutMs) {
throw new Error(`Timed out waiting for workspace build lock at ${lockDir}. Another build may still be running.`);
}
await sleep(lockPollMs);
}
} finally {
fs.rmSync(candidate, { recursive: true, force: true });
}
}
async function build(target) {
console.log(`[paperclip] Building ${target.name}...`);
// A hard kill bypasses cleanup. Only a completed compile may restore this
// marker, so recovery never trusts index.js emitted partway through a build.
fs.rmSync(target.completion, { force: true });
const sources = sourceFingerprint(target);
const code = await new Promise((resolve, reject) => {
child = spawn(process.execPath, [tscCliPath, "-p", target.tsconfig], {
cwd: rootDir,
stdio: "inherit",
});
// A hard-killed parent must not let a successor race its surviving compiler.
fs.writeFileSync(path.join(lockDir, ownerFile), JSON.stringify({ pid: process.pid, childPid: child.pid }));
child.once("error", (error) => {
fs.rmSync(target.output, { force: true });
reject(error);
});
child.once("close", (code) => {
child = null;
resolve(code ?? 1);
});
});
// tsc emits index.js before it finishes the package. A failed or interrupted
// compile must not make the next startup accept that partial build as current.
if (code !== 0) fs.rmSync(target.output, { force: true });
else fs.writeFileSync(target.completion, JSON.stringify({ sources, outputs: outputFingerprint(target) }) + "\n");
return code;
}
if (allOutputsCurrent() && !fs.existsSync(lockDir)) {
process.exit(0);
}
// Keep the lock until the compiler has stopped, including when the foreground
// CLI's build timeout terminates this helper.
for (const signal of ["SIGINT", "SIGTERM"]) {
process.on(signal, () => {
stoppingSignal = signal;
child?.kill(signal);
});
}
process.once("exit", releaseLock);
let exitCode = 0;
try {
await acquireLock();
if (holdsLock) {
for (const target of buildTargets) {
if (stoppingSignal) break;
if (!needsBuild(target)) continue;
exitCode = await build(target);
if (exitCode !== 0) break;
}
}
} finally {
releaseLock();
}
process.exitCode = stoppingSignal === "SIGINT" ? 130 : stoppingSignal ? 143 : exitCode;