@@ -2264,11 +2264,13 @@ describe('Function execution request', () => {
22642264 )
22652265
22662266 it . each ( [
2267- { reason : 'source-provenance-incomplete' , status : 200 } ,
2268- { reason : 'entry-decrypt-failed' , status : 400 } ,
2267+ { reason : 'source-provenance-incomplete' , status : 200 , knownMount : false , text : false } ,
2268+ { reason : 'source-provenance-incomplete' , status : 200 , knownMount : true , text : false } ,
2269+ { reason : 'source-provenance-incomplete' , status : 200 , knownMount : true , text : true } ,
2270+ { reason : 'entry-decrypt-failed' , status : 400 , knownMount : false , text : false } ,
22692271 ] as const ) (
2270- 'distinguishes historical absence from provenance faults: $reason' ,
2271- async ( { reason, status } ) => {
2272+ 'distinguishes historical absence from provenance faults: $reason knownMount=$knownMount text=$text ' ,
2273+ async ( { reason, status, knownMount , text } ) => {
22722274 envFlagsMock . isRemoteSandboxEnabled = true
22732275 const registry = new ResolvedSecretTraceRegistry ( [ ] , {
22742276 userId : 'user-123' ,
@@ -2278,7 +2280,7 @@ describe('Function execution request', () => {
22782280 const contentUpdatedAt = new Date ( '2026-01-01T00:00:00Z' )
22792281 mockMountContributors . mockReturnValue ( [
22802282 {
2281- fileId : 'legacy-file' ,
2283+ fileId : knownMount ? 'known-file' : 'legacy-file' ,
22822284 key : 'execution/workspace-1/workflow-1/execution-1/a/input.txt' ,
22832285 context : 'execution' ,
22842286 contentUpdatedAt,
@@ -2287,25 +2289,38 @@ describe('Function execution request', () => {
22872289 dbChainMockFns . limit . mockResolvedValue ( [
22882290 {
22892291 fileContentUpdatedAt : contentUpdatedAt ,
2290- secretProvenanceVersion : null ,
2291- provenanceContentUpdatedAt : null ,
2292- status : null ,
2293- entries : null ,
2292+ secretProvenanceVersion : knownMount ? 1 : null ,
2293+ provenanceContentUpdatedAt : knownMount ? contentUpdatedAt : null ,
2294+ status : knownMount ? 'exact' : null ,
2295+ entries : knownMount
2296+ ? [
2297+ {
2298+ name : 'API_KEY' ,
2299+ encryptedValue : 'encrypted:mounted-secret' ,
2300+ sourceUserId : 'user-123' ,
2301+ sourceWorkspaceId : 'workspace-1' ,
2302+ } ,
2303+ ]
2304+ : null ,
22942305 } ,
22952306 ] )
2296- const buffer = Buffer . from ( 'ordinary file' )
2297- mockExecuteInSandbox . mockResolvedValueOnce ( {
2307+ const buffer = Buffer . from ( text ? 'Bearer mounted-secret' : 'ordinary file' )
2308+ mockExecuteInSandbox . mockResolvedValue ( {
22982309 result : null ,
22992310 stdout : '' ,
23002311 sandboxId : 'sbx' ,
2301- collectedFiles : [
2302- {
2303- relativePath : 'report.zip' ,
2304- path : '/tmp/sim/outputs/report.zip' ,
2305- contentBase64 : buffer . toString ( 'base64' ) ,
2306- byteLength : buffer . length ,
2307- } ,
2308- ] ,
2312+ ...( text
2313+ ? { exportedFiles : { '/home/user/report.txt' : buffer . toString ( 'utf8' ) } }
2314+ : {
2315+ collectedFiles : [
2316+ {
2317+ relativePath : 'report.zip' ,
2318+ path : '/tmp/sim/outputs/report.zip' ,
2319+ contentBase64 : buffer . toString ( 'base64' ) ,
2320+ byteLength : buffer . length ,
2321+ } ,
2322+ ] ,
2323+ } ) ,
23092324 } )
23102325 const response = await POST (
23112326 createMockRequest ( 'POST' , {
@@ -2314,13 +2329,42 @@ describe('Function execution request', () => {
23142329 workspaceId : 'workspace-1' ,
23152330 workflowId : 'workflow-1' ,
23162331 executionId : 'execution-1' ,
2332+ ...( text
2333+ ? {
2334+ outputs : {
2335+ files : [
2336+ {
2337+ path : 'files/report.txt' ,
2338+ sandboxPath : '/home/user/report.txt' ,
2339+ mimeType : 'text/plain' ,
2340+ } ,
2341+ ] ,
2342+ } ,
2343+ }
2344+ : { } ) ,
23172345 } ) ,
23182346 registry
23192347 )
23202348 expect ( response . status ) . toBe ( status )
2321- if ( status === 200 )
2322- expect ( mockUploadExecutionFile . mock . calls [ 0 ] [ 5 ] ) . toEqual ( { status : 'unrecorded' } )
2323- else expect ( mockUploadExecutionFile ) . not . toHaveBeenCalled ( )
2349+ if ( status === 200 ) {
2350+ if ( text ) {
2351+ expect ( mockWriteWorkspaceFileByPath . mock . calls [ 0 ] [ 0 ] . secretProvenance ) . toEqual ( {
2352+ status : 'exact' ,
2353+ entries : [
2354+ {
2355+ name : 'API_KEY' ,
2356+ encryptedValue : 'encrypted:mounted-secret' ,
2357+ sourceUserId : 'user-123' ,
2358+ sourceWorkspaceId : 'workspace-1' ,
2359+ } ,
2360+ ] ,
2361+ } )
2362+ } else {
2363+ expect ( mockUploadExecutionFile . mock . calls [ 0 ] [ 5 ] ) . toEqual ( {
2364+ status : knownMount ? 'unknown' : 'unrecorded' ,
2365+ } )
2366+ }
2367+ } else expect ( mockUploadExecutionFile ) . not . toHaveBeenCalled ( )
23242368 }
23252369 )
23262370
@@ -2567,7 +2611,7 @@ describe('Function execution request', () => {
25672611 it . each ( [
25682612 [ 'a mount with no provenance source' , true ] ,
25692613 [ 'no mounts' , false ] ,
2570- ] as const ) ( 'withholds workbench certification for %s' , async ( _label , mounted ) => {
2614+ ] as const ) ( 'keeps workbench use available for %s' , async ( _label , mounted ) => {
25712615 envFlagsMock . isMothershipSandboxEnabled = true
25722616 mockUnprovenancedMountCount . mockReturnValue ( mounted ? 1 : 0 )
25732617 hybridAuthMockFns . mockCheckInternalAuth . mockResolvedValue ( {
@@ -2588,7 +2632,7 @@ describe('Function execution request', () => {
25882632 expect ( response . status ) . toBe ( 200 )
25892633 const session = mockExecuteInSandbox . mock . calls . at ( - 1 ) ?. [ 0 ] . session
25902634 expect ( session . key ) . toBe ( 'chat-session' )
2591- expect ( session . unprovenancedInputs === true ) . toBe ( mounted )
2635+ expect ( session . unprovenancedInputs ) . not . toBe ( true )
25922636 } )
25932637
25942638 it ( 'gives overlapping calls in one persistent workbench distinct automatic export directories' , async ( ) => {
0 commit comments