feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift, workflow exec cancellations (#6247)

* feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift

* fix(execution): harden compatibility and secret diagnostics

* fix(execution): harden generated JavaScript literals

* fix(execution): align timeout cleanup semantics

* fix(tables): decouple stale job cleanup

* fix(execution): drain stale workflow backlog

* test(sandbox): make deadline assertions timing-safe

* fix(execution): lock cleanup candidate batches

* fix(execution): preserve cleanup failure metrics

* cancel route fixes

* separate out mship template and func template

* fix

* fix(execution): harden secret projection and block runs

* fix(workflow): validate draft execution state

* run from block ui disabling

* feat(copilot): expose Sim sandboxes to mothership

* feat(copilot): expose sandbox capability catalog in VFS

* Updates

* fix legacy logs showing up

* fix(copilot): keep sandbox config visible

* fix model provenance issues

* fix lint'

* more lint

* more

* test(files): align provenance copy query order

* consolidate migrations, rollout compat

* integration projections

* update skills

* fix

* add provenance linters

* fix: address review and compatibility regressions

* fix: make tool boundary audit Bun 1.3 compatible

---------

Co-authored-by: Siddharth Ganesan <siddharthganesan@gmail.com>
This commit is contained in:
Vikhyath Mondreti
2026-08-05 19:22:04 -07:00
committed by GitHub
co-authored by Siddharth Ganesan
parent 5baa7a41ec
commit 117fe3137b
826 changed files with 95636 additions and 7877 deletions
+29 -10
View File
@@ -547,15 +547,15 @@ export const STORAGE_SETUP = defineCapabilitySetup(STORAGE_CAPABILITY, {
})
export const SANDBOX_SETUP = defineCapabilitySetup(SANDBOX_CAPABILITY, {
label: 'Remote sandboxes',
message: 'Remote sandbox provider?',
label: 'Function sandboxes',
message: 'Function sandbox provider?',
actions: {
disabled: {
label: 'Disabled',
hint: 'local JavaScript execution only',
env: {
NEXT_PUBLIC_E2B_ENABLED: 'false',
NEXT_PUBLIC_SANDBOX_ENABLED: 'false',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'false',
},
currentWhen: {
kind: 'all',
@@ -567,7 +567,7 @@ export const SANDBOX_SETUP = defineCapabilitySetup(SANDBOX_CAPABILITY, {
},
{
kind: 'not',
condition: { kind: 'present', key: 'DAYTONA_SHELL_SNAPSHOT_ID' },
condition: { kind: 'present', key: 'DAYTONA_FUNCTION_SNAPSHOT_ID' },
},
],
},
@@ -575,19 +575,37 @@ export const SANDBOX_SETUP = defineCapabilitySetup(SANDBOX_CAPABILITY, {
},
providers: {
e2b: {
hint: 'remote code interpreter sandboxes',
hint: 'dedicated Function code and CLI sandboxes',
env: {
NEXT_PUBLIC_E2B_ENABLED: 'true',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
},
prompts: [{ type: 'field', key: 'E2B_API_KEY', input: 'secret', required: true }],
prompts: [
{ type: 'field', key: 'E2B_API_KEY', input: 'secret', required: true },
{
type: 'field',
key: 'E2B_FUNCTION_TEMPLATE_ID',
input: 'text',
required: true,
validate: true,
hint: 'immutable <template>:<build-id> ref printed by the Function E2B builder',
},
{
type: 'field',
key: 'E2B_FUNCTION_TEMPLATE_GENERATION',
input: 'text',
required: true,
validate: true,
hint: 'release generation printed by the Function E2B builder',
},
],
currentWhen: { kind: 'truthy', key: 'E2B_ENABLED' },
},
daytona: {
hint: 'remote Daytona sandboxes',
hint: 'dedicated Function code and CLI sandboxes',
env: {
NEXT_PUBLIC_E2B_ENABLED: 'false',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
},
prompts: [
{
@@ -598,10 +616,11 @@ export const SANDBOX_SETUP = defineCapabilitySetup(SANDBOX_CAPABILITY, {
},
{
type: 'field',
key: 'DAYTONA_SHELL_SNAPSHOT_ID',
key: 'DAYTONA_FUNCTION_SNAPSHOT_ID',
input: 'text',
required: true,
validate: true,
hint: 'immutable snapshot ID printed by the Function Daytona builder',
},
],
},
+15 -13
View File
@@ -2,6 +2,8 @@ import { describe, expect, it } from 'bun:test'
import { OAUTH_CLIENT_CAPABILITIES } from '../../apps/sim/lib/core/config/env-capabilities.ts'
import { buildEnvCapabilityStatus } from './capability-status.ts'
const DAYTONA_FUNCTION_SNAPSHOT_ID = '00000000-0000-4000-8000-000000000002'
describe('env capability status', () => {
it('reports built-in defaults without treating them as configured services', () => {
const status = buildEnvCapabilityStatus({})
@@ -26,12 +28,12 @@ describe('env capability status', () => {
SANDBOX_PROVIDER: 'e2b',
E2B_ENABLED: 'false',
NEXT_PUBLIC_E2B_ENABLED: 'false',
NEXT_PUBLIC_SANDBOX_ENABLED: 'false',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'false',
})
expect(status.features.sandbox).toEqual({
id: 'sandbox',
label: 'Remote sandboxes',
label: 'Function sandboxes',
setupCommand: 'bun run setup sandbox',
state: 'default',
providerId: 'disabled',
@@ -62,8 +64,8 @@ describe('env capability status', () => {
const status = buildEnvCapabilityStatus({
SANDBOX_PROVIDER: 'daytona',
DAYTONA_API_KEY: 'daytona-secret',
DAYTONA_SHELL_SNAPSHOT_ID: 'mothership-shell:v1',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
DAYTONA_FUNCTION_SNAPSHOT_ID,
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
STORAGE_PROVIDER: 's3',
AWS_REGION: 'us-east-1',
S3_BUCKET_NAME: 'files',
@@ -79,11 +81,11 @@ describe('env capability status', () => {
})
})
it('reports Daytona as missing when its default shell snapshot is absent', () => {
it('reports Daytona as missing when its Function snapshot is absent', () => {
const status = buildEnvCapabilityStatus({
SANDBOX_PROVIDER: 'daytona',
DAYTONA_API_KEY: 'daytona-secret',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
})
expect(status.features.sandbox).toMatchObject({
@@ -91,15 +93,15 @@ describe('env capability status', () => {
providerId: 'daytona',
issue: { state: 'missing' },
})
expect(status.features.sandbox.issue?.message).toContain('DAYTONA_SHELL_SNAPSHOT_ID')
expect(status.features.sandbox.issue?.message).toContain('DAYTONA_FUNCTION_SNAPSHOT_ID')
})
it('reports an untagged or floating Daytona shell snapshot as invalid', () => {
it('reports a mutable Daytona Function snapshot name as invalid', () => {
const status = buildEnvCapabilityStatus({
SANDBOX_PROVIDER: 'daytona',
DAYTONA_API_KEY: 'daytona-secret',
DAYTONA_SHELL_SNAPSHOT_ID: 'mothership-shell:latest',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
DAYTONA_FUNCTION_SNAPSHOT_ID: 'mothership-shell:latest',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
})
expect(status.features.sandbox).toMatchObject({
@@ -107,14 +109,14 @@ describe('env capability status', () => {
providerId: 'daytona',
issue: { state: 'invalid' },
})
expect(status.features.sandbox.issue?.message).toContain('explicit, non-floating name:tag')
expect(status.features.sandbox.issue?.message).toContain('immutable Daytona snapshot ID')
})
it('reports remote sandbox server/browser drift as partial', () => {
const status = buildEnvCapabilityStatus({
SANDBOX_PROVIDER: 'daytona',
DAYTONA_API_KEY: 'daytona-secret',
DAYTONA_SHELL_SNAPSHOT_ID: 'mothership-shell:v1',
DAYTONA_FUNCTION_SNAPSHOT_ID,
})
expect(status.features.sandbox).toMatchObject({
@@ -122,7 +124,7 @@ describe('env capability status', () => {
providerId: 'daytona',
issue: { state: 'partial' },
})
expect(status.features.sandbox.issue?.message).toContain('NEXT_PUBLIC_SANDBOX_ENABLED')
expect(status.features.sandbox.issue?.message).toContain('NEXT_PUBLIC_SANDBOXES_ENABLED')
})
it('captures partial and invalid entries without aborting the snapshot', () => {
+4 -2
View File
@@ -245,8 +245,10 @@ function inspectSandbox(values: EnvCapabilityValues): SandboxCapabilityStatus {
coherenceProblems.push('E2B_ENABLED and NEXT_PUBLIC_E2B_ENABLED disagree')
}
const remoteAvailable = providerId !== null && providerId !== 'disabled'
if (remoteAvailable !== isTruthyEnvCapabilityValue(values, 'NEXT_PUBLIC_SANDBOX_ENABLED')) {
coherenceProblems.push('remote sandbox availability and NEXT_PUBLIC_SANDBOX_ENABLED disagree')
if (remoteAvailable !== isTruthyEnvCapabilityValue(values, 'NEXT_PUBLIC_SANDBOXES_ENABLED')) {
coherenceProblems.push(
'remote sandbox availability and NEXT_PUBLIC_SANDBOXES_ENABLED disagree'
)
}
if (coherenceProblems.length > 0) {
return {
+25 -15
View File
@@ -4,7 +4,6 @@ import {
CORE_CONFIGURATION_KEYS,
EMAIL_CAPABILITY,
EnvCapabilityConfigurationError,
hasEnvCapabilityValue,
inspectCapability,
inspectOAuthClientCapability,
OAUTH_CLIENT_CAPABILITIES,
@@ -382,25 +381,36 @@ function checkCoherence(ctx: CheckContext): Finding[] {
})
}
// NEXT_PUBLIC_SANDBOX_ENABLED is not a 1:1 twin: remote execution is available
// under E2B_ENABLED or, when SANDBOX_PROVIDER=daytona, DAYTONA_API_KEY. Without
// it the Function block hides its language dropdown and sandbox selector even
// though the server would happily run Python.
const sandboxProvider = inspectCapability(SANDBOX_CAPABILITY, sim.vars).providerId
/**
* Function sandbox visibility is not a 1:1 server/client twin. The selected
* provider is ready only when its credential and immutable Function base are
* valid, while the browser separately reads the public visibility flag.
*/
const sandboxInspection = inspectCapability(SANDBOX_CAPABILITY, sim.vars)
const sandboxProvider = sandboxInspection.providerId
const selectedSandboxProvider = sandboxInspection.providers.find(
(provider) => provider.id === sandboxProvider
)
const remoteSandboxAvailable =
sandboxProvider === 'daytona'
? hasEnvCapabilityValue(sim.vars, 'DAYTONA_API_KEY')
: sandboxProvider === 'e2b'
? isTruthy(sim.vars.get('E2B_ENABLED'))
: false
if (remoteSandboxAvailable && !isTruthy(sim.vars.get('NEXT_PUBLIC_SANDBOX_ENABLED'))) {
!sandboxInspection.error && selectedSandboxProvider?.state === 'ready'
const publicSandboxEnabled = isTruthy(sim.vars.get('NEXT_PUBLIC_SANDBOXES_ENABLED'))
if (remoteSandboxAvailable && !publicSandboxEnabled) {
findings.push({
group: 'coherence',
status: 'fail',
message:
'remote sandboxes are configured but NEXT_PUBLIC_SANDBOX_ENABLED is unset — the Function block will hide its language and sandbox controls',
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOX_ENABLED=true',
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOX_ENABLED: 'true' }),
'remote sandboxes are configured but NEXT_PUBLIC_SANDBOXES_ENABLED is unset — the Function block will hide its language and sandbox controls',
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOXES_ENABLED=true',
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOXES_ENABLED: 'true' }),
})
} else if (!remoteSandboxAvailable && publicSandboxEnabled) {
findings.push({
group: 'coherence',
status: 'fail',
message:
'NEXT_PUBLIC_SANDBOXES_ENABLED is on but the selected provider lacks credentials or a valid immutable Function base — the UI exposes a runtime that will reject execution',
fix: 'doctor --fix sets NEXT_PUBLIC_SANDBOXES_ENABLED=false; finish provider setup before enabling it',
autofix: () => writeEnvValues(sim.target, { NEXT_PUBLIC_SANDBOXES_ENABLED: 'false' }),
})
}
+48 -13
View File
@@ -8,6 +8,9 @@ import { buildCapabilitySetupTransition } from './capability-setup.ts'
import type { ConfigurationSource } from './configuration-sources.ts'
import { reconcileLlmSetup, resolveFeatureSetupDestination } from './feature-setup.ts'
const E2B_FUNCTION_TEMPLATE_ID = 'sim-function:00000000-0000-4000-8000-000000000001'
const DAYTONA_FUNCTION_SNAPSHOT_ID = '00000000-0000-4000-8000-000000000002'
function source(
kind: ConfigurationSource['kind'],
managedByCurrentCheckout: boolean,
@@ -59,21 +62,44 @@ describe('resolveFeatureSetupDestination', () => {
})
describe('sandbox capability setup', () => {
it('requires an explicit non-floating snapshot tag', () => {
const validate = (value: string) =>
validateCapabilityFieldInput(SANDBOX_CAPABILITY, 'DAYTONA_SHELL_SNAPSHOT_ID', value)
expect(validate('mothership-shell:v1')).toBeUndefined()
expect(validate('mothership-shell')).toContain('name:tag')
expect(validate('mothership-shell:latest')).toContain('name:tag')
it('requires immutable Function base references', () => {
expect(
validateCapabilityFieldInput(
SANDBOX_CAPABILITY,
'DAYTONA_FUNCTION_SNAPSHOT_ID',
DAYTONA_FUNCTION_SNAPSHOT_ID
)
).toBeUndefined()
expect(
validateCapabilityFieldInput(
SANDBOX_CAPABILITY,
'DAYTONA_FUNCTION_SNAPSHOT_ID',
'mothership-shell:v1'
)
).toContain('immutable Daytona snapshot ID')
expect(
validateCapabilityFieldInput(
SANDBOX_CAPABILITY,
'E2B_FUNCTION_TEMPLATE_ID',
E2B_FUNCTION_TEMPLATE_ID
)
).toBeUndefined()
expect(
validateCapabilityFieldInput(
SANDBOX_CAPABILITY,
'E2B_FUNCTION_TEMPLATE_ID',
'sim-function:latest'
)
).toContain('immutable E2B build reference')
})
it('writes Daytona API and shell snapshot configuration and disables E2B', () => {
it('writes Daytona API and Function snapshot configuration and disables E2B', () => {
const result = buildCapabilitySetupTransition(
SANDBOX_SETUP,
'daytona',
{
DAYTONA_API_KEY: 'daytona-key',
DAYTONA_SHELL_SNAPSHOT_ID: 'mothership-shell:v1',
DAYTONA_FUNCTION_SNAPSHOT_ID,
},
{}
)
@@ -81,19 +107,28 @@ describe('sandbox capability setup', () => {
expect(result.remove).toContain('E2B_API_KEY')
expect(result.values).toMatchObject({
DAYTONA_API_KEY: 'daytona-key',
DAYTONA_SHELL_SNAPSHOT_ID: 'mothership-shell:v1',
DAYTONA_FUNCTION_SNAPSHOT_ID,
E2B_ENABLED: 'false',
NEXT_PUBLIC_E2B_ENABLED: 'false',
NEXT_PUBLIC_SANDBOX_ENABLED: 'true',
NEXT_PUBLIC_SANDBOXES_ENABLED: 'true',
})
})
it('removes stale Daytona configuration for E2B and disabled modes', () => {
expect(
buildCapabilitySetupTransition(SANDBOX_SETUP, 'e2b', { E2B_API_KEY: 'e2b-key' }, {}).remove
).toEqual(expect.arrayContaining(['DAYTONA_API_KEY', 'DAYTONA_SHELL_SNAPSHOT_ID']))
buildCapabilitySetupTransition(
SANDBOX_SETUP,
'e2b',
{
E2B_API_KEY: 'e2b-key',
E2B_FUNCTION_TEMPLATE_ID,
E2B_FUNCTION_TEMPLATE_GENERATION: '1',
},
{}
).remove
).toEqual(expect.arrayContaining(['DAYTONA_API_KEY', 'DAYTONA_FUNCTION_SNAPSHOT_ID']))
expect(buildCapabilitySetupTransition(SANDBOX_SETUP, 'disabled', {}, {}).remove).toEqual(
expect.arrayContaining(['DAYTONA_API_KEY', 'DAYTONA_SHELL_SNAPSHOT_ID'])
expect.arrayContaining(['DAYTONA_API_KEY', 'DAYTONA_FUNCTION_SNAPSHOT_ID'])
)
})
})