paperclip/packages/adapter-utils/src
Nicky Leach 7ffeafad1f
refactor(codex-local): relocate Codex auth-merge scripts + decision predicate into the adapter (#9785)
## Thinking Path

> - Paperclip is an open source platform for managing AI agent teams,
with adapter packages providing concrete runtime environments (e.g.
`codex-local` runs a local OpenAI Codex sandbox)
> - `adapter-utils` is the shared utilities package — it should hold
only generic, adapter-agnostic primitives (sandbox lifecycle helpers,
merge logic, type definitions) usable by every adapter
> - Three files lived in `adapter-utils/src/` that are entirely
Codex-specific: `codex-auth-merge-extract.sh` (shell script that
extracts auth tokens), `codex-auth-merge-decision.cjs` (CJS decision
helper), and `codex-auth-merge-scripts.ts` (TypeScript factory that
wires them into the inbound provision seam added in PR #9778)
> - Their presence in a "generic" package violates the adapter isolation
principle and requires a cross-package build step to copy `.sh`/`.cjs`
files into `codex-local/dist/server/` at build time
> - This PR completes Phase 2 of the inbound-seam refactor: move all
three files to `packages/adapters/codex-local/src/server/`, rebase the
TypeScript imports, update `execute.ts` to import locally, move the
Codex-auth tests into a new `codex-local` test file, and fix packaging
so `codex-local` copies its own scripts to `dist/server/`
> - Script bytes are identical after the move; no change to inbound
auth-merge behavior or to which bytes cross the sandbox boundary
> - The benefit is a clean ownership boundary: `adapter-utils` retains
only generic runtime code, and the structural "Codex-free core" test in
the adapter-utils suite validates this invariant going forward

## Linked Issues or Issue Description

No pre-existing public GitHub issue. Describing the underlying problem
inline:

**Problem:** `packages/adapter-utils/src/` contains three files
(`codex-auth-merge-extract.sh`, `codex-auth-merge-decision.cjs`,
`codex-auth-merge-scripts.ts`) consumed exclusively by the `codex-local`
adapter. Their presence in a generic utilities package violates adapter
isolation and requires a cross-package build step (copy `.sh`/`.cjs`
into `codex-local/dist/server/`). The inbound provision seam landed in
PR #9778 routed these through `adapter-utils`; this PR finishes the
relocation.

**Related:** Refs #9778 (Phase 1 — generic asset-lifecycle-seam, now
merged).

## What Changed

- Moved `codex-auth-merge-extract.sh`, `codex-auth-merge-decision.cjs`,
and `codex-auth-merge-scripts.ts` from `packages/adapter-utils/src/` →
`packages/adapters/codex-local/src/server/` (script bytes are unchanged;
`codex-auth-merge-scripts.ts` imports rebased to `adapter-utils`
subpaths for `shellQuote` and `SandboxManagedRuntimeAssetProvision`)
- `packages/adapters/codex-local/src/server/execute.ts`: updated import
of `buildCodexAuthInboundProvision` from `adapter-utils` → local
`./codex-auth-merge-scripts`
- New
`packages/adapters/codex-local/src/server/codex-auth-merge.test.ts` — 5
Codex-auth test rows extracted from
`adapter-utils/src/workspace-restore-merge.test.ts`; the generic test
file stays and no longer references Codex
- `packages/adapters/codex-local/package.json`: build now copies
`.sh`/`.cjs` from `src/server/` into `dist/server/` directly
- `packages/adapter-utils/package.json`: removed the now-obsolete
cross-package copy step for those files

## Verification

```sh
# Type-check both affected packages
pnpm --filter @paperclipai/adapter-utils --filter @paperclipai/adapter-codex-local typecheck

# Codex auth-merge suite (moved tests — 5/5 pass)
pnpm --filter @paperclipai/adapter-codex-local test -- --reporter=verbose codex-auth-merge

# Full adapter-utils suite including the structural "core free of Codex literals" test (243 passed, 4 pre-existing skips)
pnpm --filter @paperclipai/adapter-utils test

# Confirm build copies scripts to dist/server
pnpm --filter @paperclipai/adapter-codex-local build
ls packages/adapters/codex-local/dist/server/*.sh packages/adapters/codex-local/dist/server/*.cjs
```

All of the above were run locally and passed before this PR was opened.

## Risks

Low risk — pure file relocation:

- No change to `.sh` or `.cjs` script bytes; the same content reaches
the sandbox boundary as before
- No behavioral change to inbound auth-merge logic from the sandbox's
perspective
- `adapter-utils`' structural "core free of Codex literals" test now
validates that the relocation is complete and will catch any regression
- Only `codex-local` consumed these files from `adapter-utils`; no other
package in the monorepo imported them from there

## Model Used

Claude Sonnet 4.6 (`claude-sonnet-4-6`) — Anthropic, 200k context
window, tool use, agentic reasoning. Used to author the refactor.
`Co-authored-by: Paperclip <noreply@paperclip.ing>` trailer present on
all commits.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Harold Kim <harold@paperclip.ing>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-17 14:45:36 -05:00
..
acpx-engine fix(acpx): configure Codex models at startup (#9700) 2026-07-16 11:41:48 -05:00
test-support feat(mcp) [split 4/8]: wire gateway runtime and Smoke Lab (#9559) 2026-07-14 15:07:30 -05:00
billing.test.ts feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
billing.ts feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
command-managed-runtime.test.ts fix(adapter-utils): improve sandbox restore failure diagnostics (#8903) 2026-07-02 17:06:34 -07:00
command-managed-runtime.ts fix(adapter-utils): improve sandbox restore failure diagnostics (#8903) 2026-07-02 17:06:34 -07:00
command-redaction.ts [codex] Roll up May 17 branch changes (#6210) 2026-05-17 17:15:06 -05:00
exclude-patterns.ts Fix sandbox git publishing and large workspace uploads (#8422) 2026-06-20 22:03:55 -07:00
execution-target-sandbox.test.ts feat: run ACP sessions in sandbox execution targets (#9390) 2026-07-10 17:13:53 -07:00
execution-target.test.ts Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
execution-target.ts feat(adapter-utils): generic per-asset lifecycle-contribution seam (#9778) 2026-07-17 14:18:01 -05:00
git-workspace-sync.test.ts Fix sandbox git publishing and large workspace uploads (#8422) 2026-06-20 22:03:55 -07:00
git-workspace-sync.ts Fix sandbox restore index drift (#8595) 2026-06-24 23:21:13 -07:00
index.ts fix(codex): warn when sandbox auth is shadowed (#9259) 2026-07-15 10:02:28 -07:00
local-process-sandbox.test.ts feat(adapters): confine local coding processes (#9504) 2026-07-14 11:01:19 -05:00
local-process-sandbox.ts feat(adapters): confine local coding processes (#9504) 2026-07-14 11:01:19 -05:00
log-redaction.ts fix(ui): external adapter selection, config field placement, and transcript parser freshness 2026-04-03 21:11:22 +01:00
mcp-isolation.integration.test.ts feat(skills): import skills from projects (#9620) 2026-07-15 18:01:44 -05:00
remote-execution-env.ts Sanitize remote execution envs at the boundary (#5325) 2026-05-05 19:30:14 -07:00
remote-managed-runtime.ts Fix sandbox git publishing and large workspace uploads (#8422) 2026-06-20 22:03:55 -07:00
runtime-progress.test.ts feat(adapter-utils): add observable sandbox sync progress (#8395) 2026-06-20 13:03:42 -07:00
runtime-progress.ts Improve live agent feedback during sandboxed runs (#8915) 2026-07-02 22:21:56 -07:00
sandbox-callback-bridge.test.ts feat: run ACP sessions in sandbox execution targets (#9390) 2026-07-10 17:13:53 -07:00
sandbox-callback-bridge.ts feat: run ACP sessions in sandbox execution targets (#9390) 2026-07-10 17:13:53 -07:00
sandbox-install-command.test.ts Fix exe.dev sandbox installs for gemini/opencode local adapters (#5737) 2026-05-11 14:28:22 -07:00
sandbox-install-command.ts Fix exe.dev sandbox installs for gemini/opencode local adapters (#5737) 2026-05-11 14:28:22 -07:00
sandbox-managed-runtime.test.ts feat(adapter-utils): generic per-asset lifecycle-contribution seam (#9778) 2026-07-17 14:18:01 -05:00
sandbox-managed-runtime.ts feat(adapter-utils): generic per-asset lifecycle-contribution seam (#9778) 2026-07-17 14:18:01 -05:00
sandbox-run-log-stream.ts Improve live agent feedback during sandboxed runs (#8915) 2026-07-02 22:21:56 -07:00
sandbox-shell.ts Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
server-utils.test.ts fix(recovery): route recovery by failure cause (#9634) 2026-07-15 20:04:42 -05:00
server-utils.ts fix(recovery): route recovery by failure cause (#9634) 2026-07-15 20:04:42 -05:00
session-compaction.ts Make ACP the default engine for local adapters (#9238) 2026-07-08 19:05:03 -07:00
ssh-fixture.test.ts feat(adapter-utils): add observable sandbox sync progress (#8395) 2026-06-20 13:03:42 -07:00
ssh.ts feat(adapter-utils): add observable sandbox sync progress (#8395) 2026-06-20 13:03:42 -07:00
types.ts fix(codex): warn when sandbox auth is shadowed (#9259) 2026-07-15 10:02:28 -07:00
workspace-restore-merge.test.ts refactor(codex-local): relocate Codex auth-merge scripts + decision predicate into the adapter (#9785) 2026-07-17 14:45:36 -05:00
workspace-restore-merge.ts Fix sandbox restore index drift (#8595) 2026-06-24 23:21:13 -07:00