Skip to content

fix(files): align workbench reads with provenance policy - #8553

Merged
icecrasher321 merged 3 commits into
stagingfrom
codex/workbench-file-provenance-policy
Oct 2, 2026
Merged

icecrasher321 merged 3 commits into
stagingfrom
codex/workbench-file-provenance-policy

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Keep files without producer provenance usable and record the coverage gap through the existing audit path. Preserve known secret contributions and explicit verification failures across reads, mounts, archives, and ingestion.
  • Classify generated workbench files from settled machine history and carry captured version provenance through historical downloads, text reads, and transformation errors. Preserve recorded byte receipts when another delivery has no producer evidence. Keep the existing redaction cutoff, placeholders, and resource budgets.
  • Audit accepted files under canonical ownership, avoid duplicate import events, and emit document admission events only after commit. Record workbench transfer acceptance after receipt persistence.
  • Remove redundant classification of intentional chat uploads; reuse existing file delivery, history, and provenance utilities.

Type of Change

  • Bug fix

Testing

45 live workbench checks, 110 PostgreSQL/Redis integration checks, and 413 focused tests passed. Regressions failed before their fixes; removing individual safety guards made their checks fail. Application type-checking, lint, all 55 audits, generators, staging-aware block registry, and docs manifest checks passed. Repeatable JSON reports retained locally.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 2, 2026 1:27am UTC

Request Review

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 34 files

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread apps/sim/lib/function-execution/execute-request.ts
Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-secret-provenance.ts Outdated
Comment thread apps/sim/lib/mothership/tools/handlers/function-execute.ts
Comment thread apps/sim/lib/mothership/chat/application/read-sandbox-file.ts
Comment thread apps/sim/lib/knowledge/documents/service.ts Outdated
Comment thread packages/testing/src/mocks/workspace-file-secret-provenance.mock.ts
Comment thread apps/sim/lib/knowledge/application/add-workspace-files.ts Outdated
Comment thread apps/sim/lib/knowledge/documents/service.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 34 files

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread apps/sim/lib/function-execution/execute-request.ts
Comment thread apps/sim/lib/mothership/chat/application/read-sandbox-file.ts
Comment thread apps/sim/lib/mothership/agent-cli/file-read-transport.ts
Comment thread apps/sim/lib/mothership/agent-cli/run-cli.ts
Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-secret-provenance.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Reclassifies unrecorded file provenance from blocked to allowed.

The PR appears safe to merge; no outstanding finding or new blocking issue was established.

Summary

The PR aligns file reads and knowledge admission with the unrecorded-provenance policy while retaining known-secret and explicit-failure protections. Since the previous review, it also moves workbench transfer auditing until after receipt persistence and adds acceptance and failure-path tests.

Reviews (3) · Last reviewed commit: "fix(files): audit completed workbench tr..."

Comment thread apps/sim/lib/mothership/tools/handlers/function-execute.ts
Comment thread apps/sim/lib/knowledge/documents/service.ts Outdated
@icecrasher321
icecrasher321 force-pushed the codex/workbench-file-provenance-policy branch from d0dc392 to afd36ad Compare October 2, 2026 01:04
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 35 files

Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/mothership/agent-cli/workbench-file-provenance.ts
@icecrasher321
icecrasher321 force-pushed the codex/workbench-file-provenance-policy branch from afd36ad to 5dbc8ac Compare October 2, 2026 01:26
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 36 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit 2cbc59e into staging Oct 2, 2026
34 checks passed
@icecrasher321
icecrasher321 deleted the codex/workbench-file-provenance-policy branch October 2, 2026 01:39

This branch was previously deployed

1 inactive deployment
Preview — 5dbc8ac1 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant