Skip to content

fix(files): refuse Chat current-file reads no provenance observer records - #8864

Merged
waleedlatif1 merged 3 commits into
stagingfrom
fix/file-provenance
Oct 10, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
fix/file-provenance

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • fix(files): refuse delegated version reads no provenance observer records #8843 refused a Chat version-text read that had no delivery observer recording the snapshot's secret provenance, "whatever transport composed the call". The current-file text read and download, which handle the same bytes, still relied on Chat's file-read transport to install the observer. Not reachable today, because Chat always composes that transport, but it is the class fix(files): refuse delegated version reads no provenance observer records #8843 set out to close
  • readWorkspaceFileText and downloadWorkspaceFileStream now apply the same application-layer guard before loading any bytes. The v2 file error policy already maps the refusal to 503 SERVICE_UNAVAILABLE
  • The agent CLI's transport stack moves into createAgentCliTransport (lib/mothership/agent-cli/transport.ts), which executeBoundAgentCliRequest uses unchanged. The integration harness now runs on that exact composition instead of a hand-assembled subset
  • The guard keys on the Copilot service rather than on any delegated principal (requireCopilotWorkspaceFileDeliveryObserver). Current-file reads also admit the workflow executor. Its reads feed blocks rather than Chat's model and nothing observes them, so a delegation-wide check would break every workflow file read. Version reads admit only Copilot, so their behavior is unchanged

Type of Change

  • Bug fix

Testing

  • copilot-file-versions.integration.ts (real Postgres, local storage, Chat's in-process transports) gains 4 cases:
    • a Chat text read without the observer answers 503 and returns no secret. On staging it answered 200 with the raw secret
    • a Chat download without the observer is refused before streaming. On staging it streamed
    • a workflow-executor download still streams the bytes
    • a Chat download through the real transport answers 200 with the secret redacted
    • a sim files read through the real CLI and composed transport returns the text with the secret redacted
    • 15/15 pass. Every existing Chat case in the file now also runs on the production composition
  • sandbox-resource-transport.test.ts: the workbench proxy dispatches a file read under a delivery observer that the Copilot guard admits, and records its provenance
  • lib/workspace-files, app/api/v2/files, lib/mothership unit suites; full gate: bun run lint, type-check, check:audits, docs-manifest:check, block-registry check, root bun run test

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 10, 2026 12:39am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/workspace-files/application/file-versions.ts
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High impact] The PR appears safe to merge; no blocking issues remain.

Summary

Chat file reads and downloads now refuse requests without an observer to record secret provenance. Workflow reads remain allowed. The CLI transport moves into the shared createAgentCliTransport helper.

  • Chat file reads stop before bytes load without an observer.
  • Chat commands and engines use one shared transport stack.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[File read or download] --> B{Copilot caller?}
  B -->|No| E[Continue authorized read]
  B -->|Yes| C{Delivery observer present?}
  C -->|No| D[Refuse before loading bytes]
  C -->|Yes| E
  E --> F[Return file content]
Loading

Reviews (3) · Last reviewed commit: "test(sandbox): assert the observed file ..." · Reviewed by Greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/mothership/tools/sandbox-resource-transport.test.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 1f570d3 into staging Oct 10, 2026
48 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/file-provenance branch October 10, 2026 02:38

This branch was previously deployed

1 inactive deployment
Preview — 89527b60 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant