fix(runner): preserve remote continuation state scope

This commit is contained in:
Dotta 2026-09-03 22:09:10 -05:00
parent 49910c1c24
commit b8d84471a3
4 changed files with 39 additions and 4 deletions

View File

@ -42,9 +42,10 @@ permissions:
contents: read
concurrency:
group: runner-full-stack-e2e-${{ inputs.target_branch || github.event.repository.default_branch }}
group: runner-full-stack-e2e-${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch && format('development-{0}', inputs.target_branch) || format('protected-{0}', github.run_id) }}
# Development branch campaigns supersede older runs for the same target.
# Preserve every default-branch campaign for its paid audit trail.
# Give protected/default-branch campaigns unique groups because GitHub also
# replaces pending runs when cancel-in-progress is false.
cancel-in-progress: ${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch }}
jobs:

View File

@ -3073,6 +3073,7 @@ describe("runnerd provider runtime wiring", () => {
executionWorkspaceId: "run-projectless-next",
},
} as NativeExecutionInputV1;
const remoteCwd = "/home/daytona/paperclip-workspace";
try {
state.createBackend.mockClear();
state.createTransport.mockClear();
@ -3135,7 +3136,37 @@ describe("runnerd provider runtime wiring", () => {
execution: continuation,
runnerInstanceId: "runner-new-heartbeat",
useRunnerd: true,
runnerExecutionTarget: {
kind: "remote",
transport: "ssh",
remoteCwd,
spec: {
host: "runner.internal",
port: 22,
username: "runner",
remoteWorkspacePath: remoteCwd,
remoteCwd,
privateKey: null,
knownHosts: null,
strictHostKeyChecking: true,
},
},
});
expect(state.createBackend).toHaveBeenCalledWith(
expect.objectContaining({
workspace: expect.objectContaining({ cwd: remoteCwd }),
}),
expect.objectContaining({
workingDirectoryAuthority: "remote_runner",
}),
);
expect(state.execute).toHaveBeenCalledWith(
expect.objectContaining({
input: expect.objectContaining({
workspace: expect.objectContaining({ cwd: remoteCwd }),
}),
}),
);
const backendOptions = state.createBackend.mock.calls[0]![1];
backendOptions.codexTransportFactory!();
expect(state.createTransport).toHaveBeenCalledWith(

View File

@ -3865,7 +3865,10 @@ async function executePaperclipNativeSessionWithinScope(
input.useRunnerd && input.backend === undefined
? await createRunnerdBackend({
...input,
execution: runnerExecution,
// Durable scope and prior-run verification use the controller's
// canonical workspace identity. createRunnerdBackend separately
// projects remoteCwd into the provider execution boundary.
execution: input.execution,
runnerInstanceId: effectiveRunnerInstanceId,
durableEnvironmentLeaseId: durableRunnerBinding?.environmentLeaseId,
trace,

View File

@ -282,7 +282,7 @@ describe("public repository paid workflow security", () => {
'[ "$MAX_PARALLEL" -gt "$MAX_PARALLEL_LIMIT" ]',
);
expect(fullStack).toContain(
"group: runner-full-stack-e2e-${{ inputs.target_branch || github.event.repository.default_branch }}",
"group: runner-full-stack-e2e-${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch && format('development-{0}', inputs.target_branch) || format('protected-{0}', github.run_id) }}",
);
expect(fullStack).toContain(
"cancel-in-progress: ${{ github.event_name == 'workflow_dispatch' && inputs.target_branch != '' && inputs.target_branch != github.event.repository.default_branch }}",