Skip to content

fix(sandbox): redact temporary session credentials in model output - #8503

Merged
icecrasher321 merged 3 commits into
stagingfrom
codex/sandbox-session-env-provenance
Oct 1, 2026
Merged

icecrasher321 merged 3 commits into
stagingfrom
codex/sandbox-session-env-provenance

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Carry host-issued callback credential provenance into the existing model-output registry when Function execution completes, including export failures. Scan returned JSON in place without an extra response copy.
  • Keep these lease-scoped credentials out of durable file lineage so ordinary binary exports remain usable. Reuse the existing matching rules, placeholders, and provenance budgets.

Type of Change

  • Bug fix

Testing

  • 25 process acceptance checks with real Redis, covering JavaScript, shell, one-shot fallback, credential revocation, binary exports, export errors, nested results, deep traversal, and large ordinary results. Each output guard was removed independently and its regression checks failed; JSON reports retained locally.
  • Focused application and session tests, application type-check, lint, all 52 audits, base-aware block registry check, and docs manifest check.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 2:18am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/function-execution/execute-request.ts
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Adds credential redaction to sandbox session output handling.

The PR appears safe to merge; no outstanding findings remain.

Summary

The PR registers lease-scoped sandbox callback credentials for model-output redaction, including export-error responses, without adding those credentials to durable file provenance. Since the previous review, it replaces the recursive output scan with an iterative one and adds deep-nesting tests.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Sandbox session issues callback credential] --> B[Sandbox execution returns JSON]
  B --> C[Scan output for credential]
  C --> D[Import matching provenance into model-output registry]
  D --> E[Compact and return response]
  C --> F[Keep credential out of durable file lineage]
Loading

Reviews (3) · Last reviewed commit: "fix(sandbox): scan session output withou..."

Comment thread apps/sim/lib/function-execution/execute-request.ts Outdated
@icecrasher321
icecrasher321 force-pushed the codex/sandbox-session-env-provenance branch from 3fc9011 to b440da7 Compare October 1, 2026 02:08
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/function-execution/execute-request.ts
Comment thread apps/sim/lib/mothership/tools/sandbox-session.ts Outdated
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@icecrasher321 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@icecrasher321
icecrasher321 merged commit a0b859b into staging Oct 1, 2026
33 checks passed
@icecrasher321
icecrasher321 deleted the codex/sandbox-session-env-provenance branch October 1, 2026 02:28

This branch was previously deployed

1 inactive deployment
Preview — 1dddf80a Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant