Skip to content

fix(sandbox): preserve workbench availability for unrecorded API responses - #8536

Merged
icecrasher321 merged 2 commits into
stagingfrom
codex/sandbox-api-provenance-policy
Oct 1, 2026
Merged

icecrasher321 merged 2 commits into
stagingfrom
codex/sandbox-api-provenance-policy

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Preserve workbench availability when sandbox API responses have no recorded provenance; record that condition without discarding existing secret history.
  • Reuse file and table delivery provenance and remove the catalog allowlist and response-copying check. Keep explicit unknown-input handling and existing redaction rules.
  • Let table mutations finish before recording response provenance; withhold an undeliverable response with its settled HTTP outcome instead of interrupting completion.

Type of Change

  • Bug fix

Testing

32 live Redis/local-process checks and 61 focused tests passed. Confirmed the new regressions fail before the fix and the table redaction check fails without its admission guard. Application type-check, lint, all repository audits, standard generators, staging-aware block registry, and docs manifest checks passed. Detailed evidence stays local.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced by validation
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 7:57pm UTC

Request Review

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Adjusts sandbox resource transport and test coverage.

The PR appears safe to merge; no new actionable failure was established, and the prior mutation-completion finding is fixed.

Summary

The PR keeps the workbench available after API responses without recorded provenance and defers table-row provenance admission until the API operation completes.

  • File and table delivery observers continue to supply explicit evidence.
  • If table-row provenance cannot be stored, the transport withholds the completed response body and reports its settled HTTP outcome.
Diagram
sequenceDiagram
  participant S as Sandbox
  participant T as Resource transport
  participant A as API handler
  participant P as Provenance storage
  S->>T: API request
  T->>A: Dispatch request
  A-->>T: Completed response and delivery evidence
  T->>P: Record row provenance, if observed
  alt Recording succeeds
    T-->>S: Original response
  else Recording fails
    T-->>S: 502 with body withheld and completed outcome
  end
Loading

Reviews (2) · Last reviewed commit: "fix(sandbox): preserve completed table m..."

Comment thread apps/sim/lib/mothership/tools/sandbox-resource-transport.ts Outdated
Comment thread apps/sim/lib/mothership/tools/sandbox-resource-transport.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit 064cd41 into staging Oct 1, 2026
33 checks passed
@icecrasher321
icecrasher321 deleted the codex/sandbox-api-provenance-policy branch October 1, 2026 20:11

This branch was previously deployed

1 inactive deployment
Preview — 3a741cb6 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant