Skip to content

improvement(provenance): enforce tracked durable reads - #7938

Merged
icecrasher321 merged 2 commits into
stagingfrom
codex/enforce-durable-provenance
Sep 17, 2026
Merged

icecrasher321 merged 2 commits into
stagingfrom
codex/enforce-durable-provenance

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Enforce exact, current provenance for tracked durable content across memory, tables, knowledge, and files; remove the configuration bypass and its permissive-read plumbing.
  • Preserve legacy records with null tracking markers, historical memory recovery, external-download semantics, and existing attachment-error handling.
  • Keep write/refusal diagnostics in a dedicated telemetry module and update tests to cover unconditional enforcement.

Type of Change

  • Improvement

Testing

Validated with Bun 1.4.1:

  • 543 focused unit tests across 20 files, including agent attachment replay.
  • 37 PostgreSQL table/memory tests and 19 file, archive, and knowledge integration tests.
  • App type check, repository lint, and all 46 repository audits, including API validation.
  • Block registry and documentation checks; generated artifacts are current.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 17, 2026 7:33pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no actionable new defect or outstanding repository-rule violation was identified.

Summary

This PR removes configurable permissive reads for tracked durable secret provenance and uniformly refuses unknown, stale, malformed, or otherwise unverifiable tracked content before trusted runtime or model projection.

  • Preserves compatibility for legacy records whose provenance tracking marker is null.
  • Applies unconditional tracked-read enforcement across memory, table rows, knowledge content, and workspace files.
  • Separates durable provenance write and refusal diagnostics into a dedicated telemetry module.
  • Removes the obsolete environment variable and updates documentation and tests accordingly.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
    A[Durable content read] --> B{Tracking marker}
    B -->|Null legacy marker| C[Preserve legacy compatibility]
    B -->|Tracked| D{Provenance exact and current?}
    D -->|Yes| E[Import secret evidence]
    E --> F[Trusted runtime or model projection]
    D -->|No| G[Refuse projection]
    G --> H[Emit refusal telemetry]
Loading

Reviews (2) · Last reviewed commit: "fix(provenance): mark legacy attachment ..."

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 37 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit de19e11 into staging Sep 17, 2026
34 of 35 checks passed
@icecrasher321
icecrasher321 deleted the codex/enforce-durable-provenance branch September 17, 2026 19:41

This branch was previously deployed

1 inactive deployment
Preview — ba8e6fbe Deployed Sep 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant