mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-02 10:16:20 +08:00
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - Paperclip Cloud needs a verified image and matching database
migrator before it can deploy a merge.
> - New npm package versions can take minutes to become downloadable
after the package build finishes.
> - The direct producer now publishes signed archives and a complete
dependency lockfile for each master commit.
> - This pull request makes readiness verify those artifacts and removes
the duplicate automatic npm migrator run.
> - Deployment still requires all source checks, exact image identity,
migration compatibility, and pinned dependencies.
## Linked Issues or Issue Description
Refs: #13455, #13454, #13192
**What existing behavior does this improve?**
The time from a master merge to the `Cloud deployable v1` signal.
**Current behavior**
Readiness polls npm metadata for the new DB and shared versions. An
automatic dispatcher also starts a separate npm-only migrator workflow.
A measured source built its packages at 06:22:41 UTC on 2026-09-15, but
both npm archives were not downloadable until 06:31:56 UTC.
**Proposed behavior**
Wait for the successful exact-source direct producer, verify its signed
manifest and all pinned downloads, and publish readiness only after the
existing source and image jobs pass. Keep manual npm migrators and
branch previews available.
**Reason and benefit**
Remove new-version npm propagation from merge-to-deployable time. The
gain depends on whether image building or source verification finishes
later; it is not a fixed subtraction from every run.
## What Changed
- Require a successful producer from the canonical repository, exact
commit, master ref, expected workflow, and approved event.
- Verify the manifest's GitHub attestation with the hosted GitHub CLI.
Enforce the exact source SHA, master workflow identity, and hosted
runner.
- Download and validate both archives and the complete dependency
lockfile after publication succeeds. Reject invalid signatures,
inaccessible objects, corrupt bytes, and source mismatches.
- Remove automatic npm-only migrator dispatch. Retain manual release and
branch-preview publication.
- Document the cloud feature-switch prerequisite and coordinated
rollback.
## Verification
- `node --test .github/scripts/tests/*.test.mjs`: 405 pass.
- Focused readiness, routing, preview, and artifact tests: 249 pass.
- Workflow lint and `git diff --check`: pass.
- `pnpm test:release-registry`: 139 pass after installing this
worktree's dependencies.
- All latest-head GitHub CI checks passed. Greptile is 5/5 with no
unresolved comments.
- Application source is unchanged. Common-source local typecheck and
build passed. The full local application suite has the documented macOS
read-only-directory rename limitation from #13454 (13 failures in two
unchanged suites); Linux CI is the final application gate.
- Live readiness verification of master
da77a0c28c passed in 6.52 seconds,
including the real GitHub CLI signature policy and all artifact
downloads.
- Cloud consumer resolution with the certificate encoding fix passed in
5.45 seconds with zero npm metadata requests or npm processes. The
consumer is deployed and enabled in staging and production; their live
resolution APIs passed in 2.34 and 2.38 seconds. Both report the
expected fixed harness commit. A fresh tenant deployment follows this
cutover merge.
## Risks
- `Cloud deployable v1` no longer promises npm preview availability.
Enable the cloud direct-artifact consumer in staging and production
before merging this change.
- Artifact storage and GitHub attestations become required services for
new direct releases. Missing or invalid evidence fails explicitly.
- Restore the old npm dispatcher and readiness gate together before
disabling the consumer switch. Retain artifacts referenced by existing
releases.
- This change does not expand AWS runner access. The producer and
readiness bookkeeping use GitHub-hosted runners. Existing PR allowlists
and source verification gates remain enforced.
## Model Used
OpenAI GPT-6 through Codex, with reasoning, repository tools, and code
execution. The exact serving model ID and context window are not exposed
by this environment.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused checks; full
application host limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
211 lines
12 KiB
JavaScript
211 lines
12 KiB
JavaScript
#!/usr/bin/env node
|
|
// The build job has no publish credential. The publisher only validates and
|
|
// uploads fixed data files; it never installs or executes package code.
|
|
import { createHash } from "node:crypto";
|
|
import { execFileSync } from "node:child_process";
|
|
import { copyFileSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import { pathToFileURL } from "node:url";
|
|
import { assertMetadata, tarManifest, versionFor } from "./preview-artifacts.mjs";
|
|
|
|
export const artifactBase = "https://d1p6rlowie26tp.cloudfront.net/cloud-migrators/v1";
|
|
export const artifactBucket = "paperclipai-runner-e2e-history-078455283791-us-east-1";
|
|
const prefix = "cloud-migrators/v1/";
|
|
const names = ["db", "shared"];
|
|
const maximumBytes = 32 * 1024 * 1024;
|
|
const integrityFor = (bytes) => `sha512-${createHash("sha512").update(bytes).digest("base64")}`;
|
|
|
|
export function descriptor(bytes, extension) {
|
|
const hash = createHash("sha512").update(bytes).digest("hex");
|
|
return { url: `${artifactBase}/blobs/${hash}.${extension}`, integrity: integrityFor(bytes), size: bytes.length };
|
|
}
|
|
|
|
function assertDescriptor(pin, extension) {
|
|
if (!pin || typeof pin.integrity !== "string" || !/^sha512-[A-Za-z0-9+/]{86}==$/.test(pin.integrity) ||
|
|
!Number.isSafeInteger(pin.size) || pin.size <= 0 || pin.size > maximumBytes) throw new Error("Invalid artifact integrity or size.");
|
|
const digest = Buffer.from(pin.integrity.slice(7), "base64");
|
|
if (digest.toString("base64") !== pin.integrity.slice(7) || pin.url !== `${artifactBase}/blobs/${digest.toString("hex")}.${extension}`) {
|
|
throw new Error("Artifact URL does not match its content hash and trusted origin.");
|
|
}
|
|
}
|
|
|
|
export function assertManifest(manifest, sha) {
|
|
if (manifest?.version !== 1 || manifest.sourceSha !== sha || manifest.packageVersion !== versionFor(sha)) throw new Error("Artifact source identity mismatch.");
|
|
for (const name of names) assertDescriptor(manifest.packages?.[name], "tgz");
|
|
assertDescriptor(manifest.lockfile, "json");
|
|
}
|
|
|
|
export function assertLockfile(lock, manifest) {
|
|
const version = manifest.packageVersion;
|
|
if (lock?.lockfileVersion !== 3 || !lock.packages || Array.isArray(lock.packages) ||
|
|
JSON.stringify(lock.packages[""]?.dependencies) !== JSON.stringify({ "@paperclipai/db": version })) throw new Error("Invalid migrator lockfile root.");
|
|
for (const name of names) {
|
|
const pin = lock.packages[`node_modules/@paperclipai/${name}`];
|
|
const expected = manifest.packages[name];
|
|
if (pin?.version !== version || pin.integrity !== expected.integrity || pin.resolved !== expected.url || pin.link || pin.inBundle) throw new Error("Migrator lockfile package pin mismatch.");
|
|
}
|
|
if (lock.packages["node_modules/@paperclipai/db"].dependencies?.["@paperclipai/shared"] !== version) throw new Error("Migrator shared dependency mismatch.");
|
|
for (const [key, entry] of Object.entries(lock.packages)) {
|
|
if (key === "") continue;
|
|
if (!entry || typeof entry !== "object" || entry.link) throw new Error("Invalid migrator lockfile entry.");
|
|
if (/(?:^|\/)node_modules\/@paperclipai\/[^/]+$/.test(key) && !names.some((name) => key === `node_modules/@paperclipai/${name}`)) throw new Error("Unexpected internal migrator dependency.");
|
|
if (entry.inBundle === true) {
|
|
if (!key.startsWith("node_modules/@paperclipai/db/node_modules/")) throw new Error("Unexpected bundled dependency.");
|
|
continue;
|
|
}
|
|
if (!/^sha512-[A-Za-z0-9+/]{86}==$/.test(entry.integrity ?? "")) throw new Error("Migrator dependency has no strong integrity pin.");
|
|
if (names.some((name) => key === `node_modules/@paperclipai/${name}`)) continue;
|
|
const url = new URL(entry.resolved);
|
|
if (url.origin !== "https://registry.npmjs.org" || url.username || url.password || url.search || url.hash) throw new Error("Migrator dependency must resolve to npm.");
|
|
}
|
|
}
|
|
|
|
export function buildBundle(directory, sha, { exec = execFileSync } = {}) {
|
|
versionFor(sha);
|
|
directory = path.resolve(directory);
|
|
const packages = {};
|
|
for (const name of names) {
|
|
const bytes = readFileSync(path.join(directory, `${name}.tgz`));
|
|
assertMetadata(tarManifest(bytes), `@paperclipai/${name}`, sha);
|
|
packages[name] = descriptor(bytes, "tgz");
|
|
}
|
|
const scratch = mkdtempSync(path.join(os.tmpdir(), "cloud-migrator-lock-"));
|
|
try {
|
|
for (const name of names) copyFileSync(path.join(directory, `${name}.tgz`), path.join(scratch, `${name}.tgz`));
|
|
const root = { name: "paperclip-migrator-install-root", version: "0.0.0", private: true,
|
|
dependencies: { "@paperclipai/db": "file:db.tgz", "@paperclipai/shared": "file:shared.tgz" } };
|
|
writeFileSync(path.join(scratch, "package.json"), JSON.stringify(root));
|
|
exec("npm", ["install", "--package-lock-only", "--ignore-scripts", "--no-audit", "--no-fund", "--registry=https://registry.npmjs.org"], { cwd: scratch, stdio: "inherit", timeout: 180_000 });
|
|
const lock = JSON.parse(readFileSync(path.join(scratch, "package-lock.json"), "utf8"));
|
|
// Both new packages are local during resolution. npm ci subsequently uses
|
|
// these immutable URLs, without looking up the new npm versions.
|
|
lock.packages[""].dependencies = { "@paperclipai/db": versionFor(sha) };
|
|
for (const name of names) lock.packages[`node_modules/@paperclipai/${name}`].resolved = packages[name].url;
|
|
const lockBytes = Buffer.from(JSON.stringify(lock) + "\n");
|
|
const manifest = { version: 1, sourceSha: sha, packageVersion: versionFor(sha), packages, lockfile: descriptor(lockBytes, "json") };
|
|
assertManifest(manifest, sha);
|
|
assertLockfile(lock, manifest);
|
|
writeFileSync(path.join(directory, "package-lock.json"), lockBytes);
|
|
writeFileSync(path.join(directory, "manifest.json"), JSON.stringify(manifest) + "\n");
|
|
return manifest;
|
|
} finally { rmSync(scratch, { recursive: true, force: true }); }
|
|
}
|
|
|
|
function verifyBytes(bytes, pin) {
|
|
if (bytes.length !== pin.size || integrityFor(bytes) !== pin.integrity) throw new Error("Artifact bytes do not match their immutable pin.");
|
|
}
|
|
|
|
export function validateBundle(directory, sha) {
|
|
const manifest = JSON.parse(readFileSync(path.join(directory, "manifest.json"), "utf8"));
|
|
assertManifest(manifest, sha);
|
|
for (const name of names) {
|
|
const bytes = readFileSync(path.join(directory, `${name}.tgz`));
|
|
verifyBytes(bytes, manifest.packages[name]);
|
|
assertMetadata(tarManifest(bytes), `@paperclipai/${name}`, sha);
|
|
}
|
|
const bytes = readFileSync(path.join(directory, "package-lock.json"));
|
|
verifyBytes(bytes, manifest.lockfile);
|
|
assertLockfile(JSON.parse(bytes), manifest);
|
|
return manifest;
|
|
}
|
|
|
|
/** Exercise the real dependency graph before publishing, with no new npm versions. */
|
|
export function verifyInstall(directory, sha, { exec = execFileSync } = {}) {
|
|
const manifest = validateBundle(directory, sha);
|
|
const scratch = mkdtempSync(path.join(os.tmpdir(), "cloud-migrator-install-"));
|
|
try {
|
|
const lock = JSON.parse(readFileSync(path.join(directory, "package-lock.json"), "utf8"));
|
|
for (const name of names) {
|
|
copyFileSync(path.join(directory, `${name}.tgz`), path.join(scratch, `${name}.tgz`));
|
|
// The public objects do not exist yet. Only transport changes for this
|
|
// smoke install; exact versions, integrity, root and transitive pins stay.
|
|
lock.packages[`node_modules/@paperclipai/${name}`].resolved = `file:${name}.tgz`;
|
|
}
|
|
writeFileSync(path.join(scratch, "package.json"), JSON.stringify({ name: "paperclip-migrator-install-root", version: "0.0.0", private: true,
|
|
dependencies: { "@paperclipai/db": manifest.packageVersion } }));
|
|
writeFileSync(path.join(scratch, "package-lock.json"), JSON.stringify(lock));
|
|
exec("npm", ["ci", "--ignore-scripts", "--no-audit", "--no-fund", "--update-notifier=false", "--cache", path.join(scratch, "empty-cache"),
|
|
"--registry=https://registry.npmjs.org"], { cwd: scratch, stdio: "inherit", timeout: 180_000 });
|
|
for (const name of names) assertMetadata(JSON.parse(readFileSync(path.join(scratch, "node_modules", "@paperclipai", name, "package.json"), "utf8")), `@paperclipai/${name}`, sha);
|
|
exec(process.execPath, ["--input-type=module", "--eval", "await import('@paperclipai/db'); await import('@paperclipai/shared');"], { cwd: scratch, stdio: "inherit", timeout: 30_000 });
|
|
} finally { rmSync(scratch, { recursive: true, force: true }); }
|
|
}
|
|
|
|
async function download(url, fetchImpl) {
|
|
const response = await fetchImpl(url, { redirect: "error", signal: AbortSignal.timeout(60_000) });
|
|
if (!response.ok) throw new Error(`Artifact download failed: HTTP ${response.status}`, { cause: { status: response.status } });
|
|
const reader = response.body.getReader();
|
|
const chunks = [];
|
|
let size = 0;
|
|
try {
|
|
while (true) {
|
|
const { done, value } = await reader.read();
|
|
if (done) break;
|
|
size += value.length;
|
|
if (size > maximumBytes) throw new Error("Artifact exceeds size limit.");
|
|
chunks.push(value);
|
|
}
|
|
} finally { await reader.cancel(); }
|
|
return Buffer.concat(chunks);
|
|
}
|
|
|
|
export async function verifyPublished(sha, fetchImpl = fetch, { verifyProvenance } = {}) {
|
|
versionFor(sha);
|
|
const bytes = await download(`${artifactBase}/${sha}/manifest.json`, fetchImpl);
|
|
const manifest = JSON.parse(bytes);
|
|
assertManifest(manifest, sha);
|
|
if (verifyProvenance) await verifyProvenance(bytes, sha);
|
|
await Promise.all(names.map(async (name) => {
|
|
const bytes = await download(manifest.packages[name].url, fetchImpl);
|
|
verifyBytes(bytes, manifest.packages[name]);
|
|
assertMetadata(tarManifest(bytes), `@paperclipai/${name}`, sha);
|
|
}));
|
|
const lock = await download(manifest.lockfile.url, fetchImpl);
|
|
verifyBytes(lock, manifest.lockfile);
|
|
assertLockfile(JSON.parse(lock), manifest);
|
|
return manifest;
|
|
}
|
|
|
|
export async function publishBundle(directory, sha, { exec = execFileSync, fetchImpl = fetch, sleep = (ms) => new Promise((resolve) => setTimeout(resolve, ms)) } = {}) {
|
|
const manifest = validateBundle(directory, sha);
|
|
const key = `${prefix}${sha}/manifest.json`;
|
|
const verifyVisible = async () => {
|
|
for (let attempt = 0; ; attempt++) {
|
|
try { return await verifyPublished(sha, fetchImpl); }
|
|
catch (error) {
|
|
// A consumer may have cached a missing-object response just before
|
|
// publication. Wait through the CDN error TTL, never through bad bytes.
|
|
if (attempt >= 6 || ![403, 404].includes(error.cause?.status)) throw error;
|
|
await sleep(2_000);
|
|
}
|
|
}
|
|
};
|
|
const aws = (args) => exec("aws", ["s3api", ...args, "--bucket", artifactBucket, "--region", "us-east-1"], { encoding: "utf8", maxBuffer: 1024 * 1024 });
|
|
// Exact prefix listing distinguishes missing objects from permission errors.
|
|
const exists = (objectKey) => JSON.parse(aws(["list-objects-v2", "--prefix", objectKey, "--max-keys", "1"])).Contents?.some((object) => object.Key === objectKey);
|
|
if (exists(key)) return verifyVisible();
|
|
const upload = (file, objectKey, contentType) => {
|
|
if (exists(objectKey)) return;
|
|
aws(["put-object", "--key", objectKey, "--body", path.resolve(directory, file), "--content-type", contentType,
|
|
"--cache-control", "public,max-age=31536000,immutable", "--if-none-match", "*"]);
|
|
};
|
|
for (const name of names) upload(`${name}.tgz`, prefix + manifest.packages[name].url.slice(`${artifactBase}/`.length), "application/gzip");
|
|
upload("package-lock.json", prefix + manifest.lockfile.url.slice(`${artifactBase}/`.length), "application/json");
|
|
// Publish the commit marker last; readers can never observe a partial bundle.
|
|
upload("manifest.json", key, "application/json");
|
|
return verifyVisible();
|
|
}
|
|
|
|
if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) {
|
|
const [command, directory, sha] = process.argv.slice(2);
|
|
try {
|
|
if (command === "build") buildBundle(directory, sha);
|
|
else if (command === "validate") validateBundle(directory, sha);
|
|
else if (command === "verify-install") verifyInstall(directory, sha);
|
|
else if (command === "publish") await publishBundle(directory, sha);
|
|
else if (command === "verify") await verifyPublished(directory);
|
|
else throw new Error("Expected build, validate, verify-install, publish, or verify.");
|
|
} catch (error) { console.error(error.message); process.exitCode = 1; }
|
|
}
|