Skip to content

fix(files): retain known lineage through binary exports and extraction - #8614

Merged
icecrasher321 merged 3 commits into
stagingfrom
codex/generated-file-secret-lineage
Oct 4, 2026
Merged

icecrasher321 merged 3 commits into
stagingfrom
codex/generated-file-secret-lineage

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Preserve encrypted secret lineage on binary Function exports and extracted archive files so runtime readback can use the existing redaction boundary.
  • Keep direct opaque model delivery protected, preserve the shared matching policy, and reuse bounded compiled lineage within an execution.

Type of Change

  • Bug fix

Testing

Real Function-to-storage/readback coverage replaces mocked writer assertions. Validation includes 46 local-process/Redis workbench checks, 75 PostgreSQL/Redis integrations, 153 focused tests, and the full repository test command. Independent guard removals fail as expected, including both persistence writers, private mount-envelope admission, and the shared short-value cutoff. Repository-wide type-check, lint, all 58 audits, generators, block-registry and docs-manifest checks passed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 4, 2026 8:09pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Changes how secret provenance flows through file exports and archives.

The PR appears safe to merge; no outstanding findings remain.

Summary

This PR retains known encrypted secret lineage through binary Function exports and archive extraction while keeping direct opaque delivery restricted. The latest changes add real-storage coverage for complete and corrupt private mount envelopes.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Function secret candidates] --> B[Binary export]
  B --> C[Stored file provenance]
  C --> D[Runtime import and redacted readback]
  C --> E[Direct opaque delivery refused]
  C --> F[Archive extraction]
  F --> G[Extracted files inherit candidates]
Loading

Reviews (3) · Last reviewed commit: "chore(tests): cover private mount envelo..."

Comment thread apps/sim/lib/function-execution/execute-request.test.ts Outdated
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit f782409 into staging Oct 4, 2026
34 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/generated-file-secret-lineage branch October 5, 2026 07:54

This branch was previously deployed

1 inactive deployment
Preview — 247f849d Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant