feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift, workflow exec cancellations (#6247)

* feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift

* fix(execution): harden compatibility and secret diagnostics

* fix(execution): harden generated JavaScript literals

* fix(execution): align timeout cleanup semantics

* fix(tables): decouple stale job cleanup

* fix(execution): drain stale workflow backlog

* test(sandbox): make deadline assertions timing-safe

* fix(execution): lock cleanup candidate batches

* fix(execution): preserve cleanup failure metrics

* cancel route fixes

* separate out mship template and func template

* fix

* fix(execution): harden secret projection and block runs

* fix(workflow): validate draft execution state

* run from block ui disabling

* feat(copilot): expose Sim sandboxes to mothership

* feat(copilot): expose sandbox capability catalog in VFS

* Updates

* fix legacy logs showing up

* fix(copilot): keep sandbox config visible

* fix model provenance issues

* fix lint'

* more lint

* more

* test(files): align provenance copy query order

* consolidate migrations, rollout compat

* integration projections

* update skills

* fix

* add provenance linters

* fix: address review and compatibility regressions

* fix: make tool boundary audit Bun 1.3 compatible

---------

Co-authored-by: Siddharth Ganesan <siddharthganesan@gmail.com>
This commit is contained in:
Vikhyath Mondreti
2026-08-05 19:22:04 -07:00
committed by GitHub
co-authored by Siddharth Ganesan
parent 5baa7a41ec
commit 117fe3137b
826 changed files with 95636 additions and 7877 deletions
@@ -39,6 +39,7 @@ export interface EnvFlagsMockState {
isSessionPoliciesEnabled: boolean
isForkingEnabled: boolean
isRemoteSandboxEnabled: boolean
isMothershipSandboxEnabled: boolean
isDocSandboxEnabled: boolean
isOllamaConfigured: boolean
isAzureConfigured: boolean
@@ -88,6 +89,7 @@ const defaultEnvFlagsState: EnvFlagsMockState = {
isDataDrainsEnabled: false,
isForkingEnabled: false,
isRemoteSandboxEnabled: false,
isMothershipSandboxEnabled: false,
isDocSandboxEnabled: false,
isOllamaConfigured: false,
isAzureConfigured: false,
@@ -5,8 +5,8 @@ import { vi } from 'vitest'
* `@/lib/logs/execution/logging-session`. Every instance method is backed by a
* shared `vi.fn()` so tests that construct multiple sessions observe identical
* mock state. `mockSafeStart` defaults to `true` because callers branch on the
* boolean result. Projection methods return their input; other methods resolve
* to `undefined`.
* boolean result. Display projection methods return their input, diagnostic projection
* fails closed to structural metadata, and other methods resolve to `undefined`.
*
* @example
* ```ts
@@ -26,9 +26,14 @@ export const loggingSessionMockFns = {
mockWaitForCompletion: vi.fn().mockResolvedValue(undefined),
mockWaitForPostExecution: vi.fn().mockResolvedValue(undefined),
mockSetTrustedExecutionCorrelation: vi.fn(),
mockSetExecutionDeadlineAt: vi.fn(),
mockProjectBlockLogsForDisplay: vi.fn(async (logs: unknown) => logs),
mockProjectDisplayContent: vi.fn(async (content: unknown) => content),
mockProjectLiveDisplayText: vi.fn(async (_field: string, value: string) => ({ value })),
mockProjectDiagnosticError: vi.fn((error: unknown, _details: Record<string, unknown> = {}) => ({
errorType: error instanceof Error ? 'error' : error === null ? 'null' : typeof error,
hasStack: error instanceof Error && typeof error.stack === 'string',
})),
mockSafeComplete: vi.fn().mockResolvedValue(undefined),
mockSafeCompleteWithError: vi.fn().mockResolvedValue(undefined),
mockSafeCompleteWithCancellation: vi.fn().mockResolvedValue(undefined),
@@ -53,9 +58,11 @@ function buildLoggingSessionInstance() {
waitForCompletion: loggingSessionMockFns.mockWaitForCompletion,
waitForPostExecution: loggingSessionMockFns.mockWaitForPostExecution,
setTrustedExecutionCorrelation: loggingSessionMockFns.mockSetTrustedExecutionCorrelation,
setExecutionDeadlineAt: loggingSessionMockFns.mockSetExecutionDeadlineAt,
projectBlockLogsForDisplay: loggingSessionMockFns.mockProjectBlockLogsForDisplay,
projectDisplayContent: loggingSessionMockFns.mockProjectDisplayContent,
projectLiveDisplayText: loggingSessionMockFns.mockProjectLiveDisplayText,
projectDiagnosticError: loggingSessionMockFns.mockProjectDiagnosticError,
safeComplete: loggingSessionMockFns.mockSafeComplete,
safeCompleteWithError: loggingSessionMockFns.mockSafeCompleteWithError,
safeCompleteWithCancellation: loggingSessionMockFns.mockSafeCompleteWithCancellation,
+42
View File
@@ -594,6 +594,16 @@ export const schemaMock = {
size: 'size',
deletedAt: 'deletedAt',
uploadedAt: 'uploadedAt',
updatedAt: 'updatedAt',
contentUpdatedAt: 'contentUpdatedAt',
secretProvenanceVersion: 'secretProvenanceVersion',
},
workspaceFileSecretProvenance: {
fileId: 'fileId',
contentUpdatedAt: 'contentUpdatedAt',
status: 'status',
entries: 'entries',
updatedAt: 'updatedAt',
},
permissionTypeEnum: 'permissionTypeEnum',
workspaceInvitationStatusEnum: 'workspaceInvitationStatusEnum',
@@ -625,10 +635,18 @@ export const schemaMock = {
workspaceId: 'workspaceId',
key: 'key',
data: 'data',
secretProvenanceVersion: 'secretProvenanceVersion',
createdAt: 'createdAt',
updatedAt: 'updatedAt',
deletedAt: 'deletedAt',
},
memorySecretProvenance: {
memoryId: 'memoryId',
contentHash: 'contentHash',
status: 'status',
entries: 'entries',
updatedAt: 'updatedAt',
},
knowledgeBase: {
id: 'id',
userId: 'userId',
@@ -682,8 +700,16 @@ export const schemaMock = {
externalId: 'externalId',
contentHash: 'contentHash',
sourceUrl: 'sourceUrl',
secretProvenanceVersion: 'secretProvenanceVersion',
uploadedAt: 'uploadedAt',
},
documentSecretProvenance: {
documentId: 'documentId',
sourceHash: 'sourceHash',
status: 'status',
entries: 'entries',
updatedAt: 'updatedAt',
},
knowledgeBaseTagDefinitions: {
id: 'id',
knowledgeBaseId: 'knowledgeBaseId',
@@ -700,6 +726,7 @@ export const schemaMock = {
chunkIndex: 'chunkIndex',
chunkHash: 'chunkHash',
content: 'content',
secretProvenanceVersion: 'secretProvenanceVersion',
contentLength: 'contentLength',
tokenCount: 'tokenCount',
embedding: 'embedding',
@@ -728,6 +755,13 @@ export const schemaMock = {
createdAt: 'createdAt',
updatedAt: 'updatedAt',
},
embeddingSecretProvenance: {
embeddingId: 'embeddingId',
contentHash: 'contentHash',
status: 'status',
entries: 'entries',
updatedAt: 'updatedAt',
},
docsEmbeddings: {
chunkId: 'chunkId',
chunkText: 'chunkText',
@@ -1146,10 +1180,18 @@ export const schemaMock = {
workspaceId: 'workspaceId',
data: 'data',
position: 'position',
secretProvenanceVersion: 'secretProvenanceVersion',
createdAt: 'createdAt',
updatedAt: 'updatedAt',
createdBy: 'createdBy',
},
userTableRowSecretProvenance: {
rowId: 'rowId',
contentUpdatedAt: 'contentUpdatedAt',
status: 'status',
entries: 'entries',
updatedAt: 'updatedAt',
},
tableJobs: {
id: 'id',
tableId: 'tableId',
@@ -19,6 +19,7 @@ export const storageServiceMockFns = {
mockDownloadFile: vi.fn(),
mockDeleteFile: vi.fn(),
mockHeadObject: vi.fn(),
mockVerifyPresignedUploadReceipt: vi.fn(),
mockGeneratePresignedUploadUrl: vi.fn(),
mockGenerateBatchPresignedUploadUrls: vi.fn(),
mockGeneratePresignedDownloadUrl: vi.fn(),
@@ -39,6 +40,7 @@ export const storageServiceMock = {
downloadFile: storageServiceMockFns.mockDownloadFile,
deleteFile: storageServiceMockFns.mockDeleteFile,
headObject: storageServiceMockFns.mockHeadObject,
verifyPresignedUploadReceipt: storageServiceMockFns.mockVerifyPresignedUploadReceipt,
generatePresignedUploadUrl: storageServiceMockFns.mockGeneratePresignedUploadUrl,
generateBatchPresignedUploadUrls: storageServiceMockFns.mockGenerateBatchPresignedUploadUrls,
generatePresignedDownloadUrl: storageServiceMockFns.mockGeneratePresignedDownloadUrl,