You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(files): retain known lineage through binary exports and extraction - #8614
Preserve encrypted secret lineage on binary Function exports and extracted archive files so runtime readback can use the existing redaction boundary.
Keep direct opaque model delivery protected, preserve the shared matching policy, and reuse bounded compiled lineage within an execution.
Type of Change
Bug fix
Testing
Real Function-to-storage/readback coverage replaces mocked writer assertions. Validation includes 46 local-process/Redis workbench checks, 75 PostgreSQL/Redis integrations, 153 focused tests, and the full repository test command. Independent guard removals fail as expected, including both persistence writers, private mount-envelope admission, and the shared short-value cutoff. Repository-wide type-check, lint, all 58 audits, generators, block-registry and docs-manifest checks passed.
Checklist
Code follows project style guidelines
Self-reviewed my changes
Tests added/updated and passing (new tests pass the test-audit authoring gate)
[Medium risk] Changes how secret provenance flows through file exports and archives.
The PR appears safe to merge; no outstanding findings remain.
Summary
This PR retains known encrypted secret lineage through binary Function exports and archive extraction while keeping direct opaque delivery restricted. The latest changes add real-storage coverage for complete and corrupt private mount envelopes.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
A[Function secret candidates] --> B[Binary export]
B --> C[Stored file provenance]
C --> D[Runtime import and redacted readback]
C --> E[Direct opaque delivery refused]
C --> F[Archive extraction]
F --> G[Extracted files inherit candidates]
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Type of Change
Testing
Real Function-to-storage/readback coverage replaces mocked writer assertions. Validation includes 46 local-process/Redis workbench checks, 75 PostgreSQL/Redis integrations, 153 focused tests, and the full repository test command. Independent guard removals fail as expected, including both persistence writers, private mount-envelope admission, and the shared short-value cutoff. Repository-wide type-check, lint, all 58 audits, generators, block-registry and docs-manifest checks passed.
Checklist
test-auditauthoring gate)