mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-02 02:07:25 +08:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents ask for decisions and optional details through cards in chat. > - A clear approval in a message can leave the matching card pending. > - An unanswered question can also block an unrelated later reply. > - Decisions need a saved source message, while optional questions need to remain answerable in history. > - This pull request records conversational decisions and lets users move on from questions and answer them later. ## Linked Issues or Issue Description **What happened?** Native Claude and Codex could act on approval in chat while the original approval card stayed pending. Pending question forms stayed above the composer, were absent from history, and could suppress later chat replies. A late native question answer could wait for a finished run to reconnect. **Expected behavior** The active agent records a clear approval or refusal against the exact card and user message. Ambiguous replies do not grant consent. Users can send another message without answering a question. The question remains pending in history and can be reopened and answered later. The saved answer reaches the agent. **Steps to reproduce** 1. Ask an agent to propose work with a confirmation card, then approve it in chat. 2. Check that the original card records that approval before work starts. 3. Ask an interactive question, send an unrelated message, and reload. 4. Open the unanswered question from history and submit an answer. Related work: #14408 added completion delivery. #14607 tests completion reporting turns. Neither records conversational answers on approval cards. ## What Changed - Add a confirmation endpoint backed by a user comment, with schema validation, OpenAPI discovery, and native Plan-mode access. Ask mode remains read-only. - Check company, active run, actor, current session, message provenance, revision, and resolver policy. Save the decision and audit in one transaction. Retries do not repeat effects. Emit resolution telemetry after commit. - Give fresh and resumed chat turns the actual pending confirmation identities. Teach agents to save clear conversational decisions before acting and to clarify ambiguity. - Keep unanswered Agent Chat questions as compact history entries. A newer user message closes the old form. Question cards never contribute to composer pending counts or navigation, including after dismissing a fresh form. The history card is the sole reminder; clicking it restores that exact form and draft. - Preserve Agent Chat questions when later messages or questions arrive. Historical ordinary inputs no longer gate later chat replies. Current-run requests, task execution, and governed approvals keep their gates. Remove the special acknowledgement-publication proof helpers that this rule replaces. - Route answers to finished native runs through durable fresh-wake delivery, with existing idempotency and source-question context. Settle late replies against contiguous completed conversation turns and freeze their history replay; failed, unhandled, and newly arriving messages remain actionable. - Add real-component Storybook scenarios, database and UI regressions, and a three-turn native Claude/Codex E2E case. Capture distinct, UI-ready screenshots and report the individual assertions. ## Verification - Focused decision/publication/UI regressions after merging master: 288 passed; subsequent UI draft, failed-send, and conversation checks: 199 passed. - Native question and durable delivery regressions: 106 passed, including all four terminal run states and exactly-once late delivery. Seven targeted regressions fail against the original implementation and pass with the fix. - Latest conversation/decision/native-delivery regressions after the master merge: 121 passed. Covers completed progress, missing or failed intervening turns, new messages during a late reply, stale sessions, and frozen retry/replay boundaries. Four new assertions fail before the ordering fix. - E2E support suite after the master merge: 792 passed. Negative controls reject expired cards, wrong questions/answers, stale or missing replies, unrelated clarification forms, and unexpected tasks. - The embedded-browser walkthrough caught one additional defect: dismissing a fresh question still showed a composer badge. Both Cancel and close-button regressions failed before the fix. The fix at `65f2ade12` passes 170 chat-thread tests and 792 E2E support tests. After merging master, 232 chat-thread/confirmation tests, server/UI typechecks, and token gates pass. The preview and two-provider live E2E pass at `e5512a206`; Greptile is 5/5 with zero unresolved threads at that commit. All 55 checks are now successful at `e5512a206` (four conditional checks skipped), including the aggregate verification gate and clean-install canary test. The first attempt was interrupted by simultaneous CI worker shutdowns; one failed-job rerun passed without code changes. - [Published Storybook](https://d1p6rlowie26tp.cloudfront.net/storybook/branches/codex~2Fchat-approval-resolution/?path=/story/chat-comments-agent-chat-unanswered-questions--moved-on): nine real-component scenarios. Manually exercised move on, reopen, preserve draft, answer later, answer one of multiple questions, and a custom mobile answer in the embedded browser. Retested fresh Cancel and close-button dismissal in the updated build, then reopened and submitted the preserved Green selection and inspected its answered receipt. Static preview has no live model/backend; its callbacks are fixture responses. - [First live campaign](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36714504406-1/) reproduced the late-answer completion-state defect on both providers despite correct saved answers and acknowledgements. It also exposed a valid imperative clarification rejected by the old oracle. Both issues are fixed with regression controls; this failing run is retained as evidence. - [Four-cell qualification](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36717804064-1/) passed 4/4 at `2bf8a1009`: unanswered-question return and ambiguous confirmation, each on native Claude and Codex. Inspected saved state, source-message decisions, visible cards, and agent replies. Both late-answer chats settled to waiting; no unrequested tasks were created. [Final branch rerun](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36719666238-1/) passed 2/2 at `142630720`: the same unanswered-question journey after merging master, plus an additional screenshot and browser assertion for the actual late-answer acknowledgement. - [Composer-reminder E2E](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36727006818-1/) passed 2/2 at `5b62c52d9`: native Claude and Codex, three turns each, with explicit no-badge assertions before and after reload. Inspected saved pending/answered state, both screenshots with a clear composer, and actual Blue acknowledgements; all five behavioral matchers passed per provider and neither created tasks. Cost coverage is partial; this is bounded workflow qualification. - [Fresh-dismissal E2E](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36742773318-1/) passed 2/2 at `e5512a206`: native Claude and Codex, including fresh Cancel, clear composer, reopen, unrelated message, reload, late Blue answer, and actual agent acknowledgement. All five behavioral matchers pass per provider. Inspected the fresh-dismissal screenshots and saved pending/answered identity; neither created tasks. Cost coverage is partial (4/6 runs). - Prior evidence remains available in [the earlier campaign](https://d1p6rlowie26tp.cloudfront.net/runner-e2e/campaigns/gha-36642252725-1/). Its early loading screenshot and overwritten final capture prompted the UI-ready, distinct screenshot fixes. ## Risks - The model interprets intent. The server verifies permission and provenance; it does not infer consent from text. Ambiguous and unrelated replies are not approvals. - Historical questions can accumulate. They remain visible, pending, and answerable; no automatic answer or expiry is invented. - The change to completion gates is scoped to Agent Chat and ordinary historical inputs. Current-turn and governed approvals retain their existing controls. - Live qualification is limited to the selected stories. Broader native onboarding finalization remains separate work. - No database migration. Telemetry adds no fields or values; the contract and README document the commit boundary. Privacy review was requested on the PR. ## Model Used OpenAI Codex, GPT-6 family, with reasoning, repository tools, code execution, and browser-test orchestration. The exact model ID and context-window size are not exposed to this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
96 lines
3.7 KiB
JavaScript
96 lines
3.7 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { readFile } from "node:fs/promises";
|
|
import { resolve } from "node:path";
|
|
import { test } from "node:test";
|
|
|
|
import { capabilityGroups, validateInventorySchema, validateInventories } from "./lib/capability-inventory.mjs";
|
|
|
|
const inventorySchema = JSON.parse(await readFile(
|
|
resolve(import.meta.dirname, "../spec/capability/inventory.schema.json"),
|
|
"utf8",
|
|
));
|
|
|
|
function row(id, group = "hb") {
|
|
return {
|
|
id,
|
|
group,
|
|
sourceAnchor: "source:1",
|
|
expectedSemantics: "semantic",
|
|
primaryDisposition: "control_plane_owned",
|
|
requiredGrants: [],
|
|
assertionClasses: ["control_plane_invariant"],
|
|
evidenceIds: [id],
|
|
};
|
|
}
|
|
|
|
function validInventories() {
|
|
const evaluations = Array.from({ length: 106 }, (_, index) => row(`eval-${index}`, capabilityGroups[index % capabilityGroups.length]));
|
|
const aliases = Array.from({ length: 42 }, (_, index) => ({
|
|
id: `mcp:tool-${index}`,
|
|
name: `tool-${index}`,
|
|
sourceAnchor: `source:${index + 1}`,
|
|
expectedSemantics: `legacy semantic ${index}`,
|
|
foldedInto: `eval:eval-${index}`,
|
|
evidenceId: `mcp:tool-${index}`,
|
|
}));
|
|
for (const [index, alias] of aliases.entries()) {
|
|
evaluations[index].legacyMcpAliases = [alias.id];
|
|
evaluations[index].evidenceIds.push(alias.evidenceId);
|
|
}
|
|
return {
|
|
capabilities: {
|
|
schemaVersion: 2,
|
|
inventoryRole: "normative",
|
|
generatedFrom: ["skills/paperclip/SKILL.md"],
|
|
rows: Array.from({ length: 157 }, (_, index) => row(`capability-${index}`)),
|
|
},
|
|
evaluations: {
|
|
schemaVersion: 2,
|
|
inventoryRole: "normative",
|
|
generatedFrom: "paperclip-evals/cases",
|
|
rows: evaluations,
|
|
},
|
|
legacyMcpAliases: {
|
|
schemaVersion: 2,
|
|
inventoryRole: "legacy_alias_index",
|
|
generatedFrom: "packages/mcp-server/src/tools.ts",
|
|
normativeSources: ["capabilities", "evaluations"],
|
|
rows: aliases,
|
|
},
|
|
};
|
|
}
|
|
|
|
test("capability inventory validator accepts exact baseline counts", () => {
|
|
const inventories = validInventories();
|
|
assert.deepEqual(validateInventorySchema(inventories, inventorySchema), []);
|
|
assert.deepEqual(validateInventories(inventories), []);
|
|
});
|
|
|
|
test("capability inventory validator rejects duplicate rows and invalid dispositions", () => {
|
|
const inventories = validInventories();
|
|
inventories.legacyMcpAliases.rows[1].id = inventories.legacyMcpAliases.rows[0].id;
|
|
inventories.evaluations.rows[0].primaryDisposition = "both";
|
|
const errors = validateInventories(inventories);
|
|
assert.ok(errors.some((error) => error.includes("duplicate id")));
|
|
assert.ok(errors.some((error) => error.includes("invalid primaryDisposition")));
|
|
});
|
|
|
|
test("capability inventory validator rejects an independent MCP classification", () => {
|
|
const inventories = validInventories();
|
|
inventories.legacyMcpAliases.rows[0].primaryDisposition = "optional_agent_tool";
|
|
const schemaErrors = validateInventorySchema(inventories, inventorySchema);
|
|
const errors = validateInventories(inventories);
|
|
assert.ok(schemaErrors.some((error) => error.includes("boolean schema is false")));
|
|
assert.ok(errors.some((error) => error.includes("must not define an independent primaryDisposition")));
|
|
});
|
|
|
|
test("capability inventory validator rejects missing, duplicate, and unknown MCP folds", () => {
|
|
const inventories = validInventories();
|
|
inventories.evaluations.rows[0].legacyMcpAliases = [];
|
|
inventories.evaluations.rows[1].legacyMcpAliases.push(inventories.legacyMcpAliases.rows[1].id);
|
|
inventories.legacyMcpAliases.rows[2].foldedInto = "eval:missing";
|
|
const errors = validateInventories(inventories);
|
|
assert.ok(errors.some((error) => error.includes("must be folded exactly once")));
|
|
assert.ok(errors.some((error) => error.includes("unknown normative row")));
|
|
});
|