a3de1d764d
## Thinking Path > - Paperclip is a control plane for autonomous AI companies, where adapters are the boundary between the board, agents, and execution runtimes. > - Local adapters currently expose a primary runtime configuration, but operators often need a cheaper model lane for routine or low-risk work. > - That cheap lane has to stay adapter-owned: runtime profile settings should not mutate the primary adapter config or bypass existing auth/secret mediation. > - Issue creation also needs an ergonomic way to request primary, cheap, or custom model behavior for a selected assignee. > - This pull request adds a first-class `cheap` model profile contract across adapter capabilities, heartbeat config resolution, agent configuration, and issue creation. > - The benefit is cheaper task execution can be configured and requested explicitly while preserving adapter boundaries, secret handling, and audit visibility. ## What Changed - Added adapter model-profile capability metadata and a `cheap` profile contract for supported local adapters. - Applied `runtimeConfig.modelProfiles.cheap.adapterConfig` during heartbeat config resolution, including requested/applied/fallback run metadata. - Added agent configuration UI for cheap model profile settings without writing those settings into primary `adapterConfig`. - Added New Issue assignee model lane controls for Primary / Cheap / Custom and request payload handling. - Added run ledger profile badges and Storybook stories for the new cheap-lane UI states. - Added tests for validators, heartbeat model profile application, permission/secret mediation, UI payload helpers, and run ledger rendering. - Added committed UI verification screenshots under `docs/pr-screenshots/pap-2837/`. - Addressed Greptile review feedback around cheap-profile defaults, shared profile types, and fallback test data. ## Verification Local: - `pnpm exec vitest run packages/shared/src/validators/issue.test.ts server/src/__tests__/adapter-registry.test.ts server/src/__tests__/agent-permissions-routes.test.ts server/src/__tests__/heartbeat-model-profile.test.ts ui/src/components/IssueRunLedger.test.tsx ui/src/lib/agent-config-patch.test.ts ui/src/lib/issue-assignee-overrides.test.ts ui/src/lib/new-agent-runtime-config.test.ts` — passed, 8 files / 103 tests. - `pnpm exec vitest run ui/src/lib/new-agent-runtime-config.test.ts ui/src/components/IssueRunLedger.test.tsx` — passed after Greptile/rebase follow-up, 2 files / 17 tests. - `pnpm --filter @paperclipai/ui typecheck` — passed after Greptile/rebase follow-up. - `pnpm -r typecheck` — passed. - `pnpm build` — passed. - `pnpm test:run` — did not complete successfully in this local worktree: it stopped in pre-existing `@paperclipai/adapter-utils` sandbox/SSH fixture suites outside this PR diff. Failures were 5s local timeouts plus `git init -b` unsupported by this machine's Git 2.21.0. The branch-specific targeted suites above passed. - Branch was fetched/rebased onto `public-gh/master`; `git rev-list --left-right --count public-gh/master...HEAD` reports `0 9`. Remote PR checks on latest head `e30bf399146451c86cee98ed528d51d33fa5af5a`: - `policy` — passed. - `verify` — passed. - `e2e` — passed. - `Greptile Review` — passed, confidence score 5/5; Greptile review threads resolved. - `security/snyk (cryppadotta)` — passed. Screenshots: - [New issue cheap lane desktop](https://github.com/paperclipai/paperclip/blob/PAP-2837-plan-cheap-model-for-adapters-that-can-support-it/docs/pr-screenshots/pap-2837/newissue-cheap-desktop.png) - [New issue custom lane desktop](https://github.com/paperclipai/paperclip/blob/PAP-2837-plan-cheap-model-for-adapters-that-can-support-it/docs/pr-screenshots/pap-2837/newissue-custom-desktop.png) - [New issue unsupported adapter desktop](https://github.com/paperclipai/paperclip/blob/PAP-2837-plan-cheap-model-for-adapters-that-can-support-it/docs/pr-screenshots/pap-2837/newissue-unsupported-desktop.png) - [Run ledger model profile badges desktop](https://github.com/paperclipai/paperclip/blob/PAP-2837-plan-cheap-model-for-adapters-that-can-support-it/docs/pr-screenshots/pap-2837/runledger-profile-badges-desktop.png) - Mobile variants are also in `docs/pr-screenshots/pap-2837/`. ## Risks - Medium: heartbeat config mediation now merges runtime model profiles into adapter configs, so adapter secret normalization and host-command restrictions must keep covering nested config paths. - Medium: the UI adds another issue creation choice; unsupported adapters must keep hiding the cheap lane and preserve primary behavior. - Low migration risk: no database migration is included. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex coding agent using GPT-5-class reasoning with repo tool use and command execution. Exact served model/context window was not exposed by the runtime. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] If this change affects the UI, I have included before/after screenshots - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
119 lines
3.6 KiB
TypeScript
119 lines
3.6 KiB
TypeScript
import type { Request } from "express";
|
|
import { forbidden } from "../errors.js";
|
|
|
|
function isRecord(value: unknown): value is Record<string, unknown> {
|
|
return typeof value === "object" && value !== null && !Array.isArray(value);
|
|
}
|
|
|
|
function hasOwn(value: Record<string, unknown>, key: string) {
|
|
return Object.prototype.hasOwnProperty.call(value, key);
|
|
}
|
|
|
|
function prefixPath(prefix: string, key: string) {
|
|
return prefix.length > 0 ? `${prefix}.${key}` : key;
|
|
}
|
|
|
|
function collectWorkspaceStrategyCommandPaths(raw: unknown, prefix: string): string[] {
|
|
if (!isRecord(raw)) return [];
|
|
const paths: string[] = [];
|
|
if (hasOwn(raw, "provisionCommand")) {
|
|
paths.push(prefixPath(prefix, "provisionCommand"));
|
|
}
|
|
if (hasOwn(raw, "teardownCommand")) {
|
|
paths.push(prefixPath(prefix, "teardownCommand"));
|
|
}
|
|
return paths;
|
|
}
|
|
|
|
function collectExecutionWorkspaceConfigCommandPaths(raw: unknown, prefix: string): string[] {
|
|
if (!isRecord(raw)) return [];
|
|
const paths: string[] = [];
|
|
if (hasOwn(raw, "provisionCommand")) {
|
|
paths.push(prefixPath(prefix, "provisionCommand"));
|
|
}
|
|
if (hasOwn(raw, "teardownCommand")) {
|
|
paths.push(prefixPath(prefix, "teardownCommand"));
|
|
}
|
|
if (hasOwn(raw, "cleanupCommand")) {
|
|
paths.push(prefixPath(prefix, "cleanupCommand"));
|
|
}
|
|
return paths;
|
|
}
|
|
|
|
export function assertNoAgentHostWorkspaceCommandMutation(req: Request, paths: string[]) {
|
|
if (req.actor.type !== "agent" || paths.length === 0) return;
|
|
throw forbidden(
|
|
`Agent keys cannot modify host-executed workspace commands (${paths.join(", ")}).`,
|
|
);
|
|
}
|
|
|
|
export function collectAgentAdapterWorkspaceCommandPaths(
|
|
adapterConfig: unknown,
|
|
prefix = "adapterConfig",
|
|
): string[] {
|
|
if (!isRecord(adapterConfig)) return [];
|
|
return collectWorkspaceStrategyCommandPaths(
|
|
adapterConfig.workspaceStrategy,
|
|
`${prefix}.workspaceStrategy`,
|
|
);
|
|
}
|
|
|
|
export function collectProjectExecutionWorkspaceCommandPaths(policy: unknown): string[] {
|
|
if (!isRecord(policy)) return [];
|
|
return collectWorkspaceStrategyCommandPaths(
|
|
policy.workspaceStrategy,
|
|
"executionWorkspacePolicy.workspaceStrategy",
|
|
);
|
|
}
|
|
|
|
export function collectProjectWorkspaceCommandPaths(
|
|
workspacePatch: unknown,
|
|
prefix = "",
|
|
): string[] {
|
|
if (!isRecord(workspacePatch)) return [];
|
|
return hasOwn(workspacePatch, "cleanupCommand")
|
|
? [prefixPath(prefix, "cleanupCommand")]
|
|
: [];
|
|
}
|
|
|
|
export function collectIssueWorkspaceCommandPaths(input: {
|
|
executionWorkspaceSettings?: unknown;
|
|
assigneeAdapterOverrides?: unknown;
|
|
}): string[] {
|
|
const paths: string[] = [];
|
|
if (isRecord(input.executionWorkspaceSettings)) {
|
|
paths.push(
|
|
...collectWorkspaceStrategyCommandPaths(
|
|
input.executionWorkspaceSettings.workspaceStrategy,
|
|
"executionWorkspaceSettings.workspaceStrategy",
|
|
),
|
|
);
|
|
}
|
|
if (isRecord(input.assigneeAdapterOverrides)) {
|
|
const adapterConfig = input.assigneeAdapterOverrides.adapterConfig;
|
|
if (isRecord(adapterConfig)) {
|
|
paths.push(
|
|
...collectWorkspaceStrategyCommandPaths(
|
|
adapterConfig.workspaceStrategy,
|
|
"assigneeAdapterOverrides.adapterConfig.workspaceStrategy",
|
|
),
|
|
);
|
|
}
|
|
}
|
|
return paths;
|
|
}
|
|
|
|
export function collectExecutionWorkspaceCommandPaths(input: {
|
|
config?: unknown;
|
|
metadata?: unknown;
|
|
}): string[] {
|
|
const paths: string[] = [];
|
|
if (input.config !== undefined) {
|
|
paths.push(...collectExecutionWorkspaceConfigCommandPaths(input.config, "config"));
|
|
}
|
|
if (isRecord(input.metadata) && hasOwn(input.metadata, "config")) {
|
|
paths.push(...collectExecutionWorkspaceConfigCommandPaths(input.metadata.config, "metadata.config"));
|
|
}
|
|
return paths;
|
|
}
|