Skip to content

fix(sandbox): preserve workbench output provenance - #8485

Merged
icecrasher321 merged 2 commits into
stagingfrom
codex/sandbox-output-boundary
Sep 30, 2026
Merged

icecrasher321 merged 2 commits into
stagingfrom
codex/sandbox-output-boundary

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Preserve accumulated input provenance across workbench calls using the existing durable history and redaction registries.
  • Apply that history to model output, file exports, and CLI inputs. Align provider exceptions and visible secret values with shared redaction policy.
  • Reuse existing provenance budgets and lifecycle rules. Workbenches with missing or unclassifiable history withhold output until replacement.

Type of Change

  • Bug fix

Testing

34,949 application tests passed under Node 24 (20 skipped), plus 14 real Redis integration checks and 13 local-process acceptance tests. Regression checks confirmed the relevant cases fail without the fixes.

Full lint, application type-check, API validation, all 52 audits, staging-aware block registry checks, docs manifest verification, and diff checks passed. Hosted-provider validation was not run.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 30, 2026 10:58pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 26 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/mothership/agent-cli/run-cli.ts
Comment thread apps/sim/lib/mothership/tools/handlers/function-execute.ts Outdated
Comment thread apps/sim/lib/webhooks/provider-subscriptions.ts
@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Refactors secret provenance tracking across sandbox execution.

The PR appears safe to merge based on the changes since the previous review.

Summary

The PR preserves encrypted secret provenance across workbench calls and applies accumulated history to output, file exports, and CLI inputs. The latest changes also distinguish file-size and provenance-storage failures, refine webhook exception redaction, and allow empty mounted values.

Reviews (2) · Last reviewed commit: "fix(sandbox): preserve boundary compatib..."

Comment thread apps/sim/lib/execution/remote-sandbox/session-files.ts Outdated
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 28 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit 9ae8ba8 into staging Sep 30, 2026
33 checks passed
@icecrasher321
icecrasher321 deleted the codex/sandbox-output-boundary branch September 30, 2026 23:19

This branch was previously deployed

1 inactive deployment
Preview — b4f471ce Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant