Commit 5dbc342
authored
fix(provenance): name the importer that condemned a run (#6493)
* fix(provenance): name the importer that condemned a run
A bundle that arrives already incomplete latches the whole registry one-way, so
every later model projection in the run refuses. #6483 made the refusal say what
went wrong; it could not say who. In production the answer was
reason=source-provenance-incomplete with 23 candidate importers and no way to
tell them apart, which is where the last investigation stopped.
Carry a stable origin across the import boundary and retain it beside the reason.
It inherits through forks and merges — the step that erased attribution before,
since a tool crossing forks, imports, then merges back — so the refusal names the
importer even though the latch happened frames earlier. Tool crossings take the
tool id, so a tool-sourced bundle identifies itself rather than being inferred
from timestamps.
Origins are caller-supplied strings rather than a closed union, so unlike reasons
they carry an explicit bound.
No behaviour change: the field is optional, additive, and read only when building
a log record.
* fix(provenance): attribute the path-scoped and short-circuit latches too
importProvenanceForValueAtInputPath took only { trusted }, so the five callers
that bind a crossing to an input path — the block, loop, parallel and workflow
resolvers, and the guardrails route — could not name themselves.
Separately, six latches sit beside a tagged import on the path where the import
did not run or returned false: a bundle already marked incomplete short-circuits
the || before the import, and each catch latches directly. Those reported no
origin while their neighbour reported one.
* fix(provenance): stop a broad catch claiming an incomplete bundle
The catch around table-row provenance loading also covers a database failure in
loadTableRowSecretProvenance, which is not an incomplete bundle. Naming a reason
the catch cannot know is the misattribution this work exists to remove, so it
reports 'unspecified' with its origin, matching every sibling catch. The decrypt
catch keeps its specific reason because its try wraps only the decrypt call.1 parent 156ee3e commit 5dbc342
31 files changed
Lines changed: 240 additions & 65 deletions
File tree
- apps/sim
- app/api
- guardrails/validate
- mcp/serve/[serverId]
- providers
- workflows/[id]/log
- executor
- handlers
- mothership
- workflow
- utils
- variables/resolvers
- lib
- copilot
- request/tools
- tools/handlers
- workflow
- execution
- guardrails
- knowledge
- logs/execution
- table
- rows
- uploads/contexts/workspace
- workflows/executor
- tools
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
244 | 244 | | |
245 | 245 | | |
246 | 246 | | |
| 247 | + | |
247 | 248 | | |
248 | 249 | | |
249 | 250 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
267 | 267 | | |
268 | 268 | | |
269 | 269 | | |
270 | | - | |
| 270 | + | |
271 | 271 | | |
272 | 272 | | |
273 | 273 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
288 | 288 | | |
289 | 289 | | |
290 | 290 | | |
| 291 | + | |
291 | 292 | | |
292 | 293 | | |
293 | 294 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
208 | 208 | | |
209 | 209 | | |
210 | 210 | | |
211 | | - | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
212 | 215 | | |
213 | 216 | | |
214 | 217 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
272 | 272 | | |
273 | 273 | | |
274 | 274 | | |
275 | | - | |
| 275 | + | |
276 | 276 | | |
277 | 277 | | |
278 | 278 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
144 | 144 | | |
145 | 145 | | |
146 | 146 | | |
147 | | - | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
148 | 151 | | |
149 | 152 | | |
150 | 153 | | |
| |||
Lines changed: 4 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
293 | 293 | | |
294 | 294 | | |
295 | 295 | | |
296 | | - | |
| 296 | + | |
297 | 297 | | |
298 | 298 | | |
299 | 299 | | |
| |||
519 | 519 | | |
520 | 520 | | |
521 | 521 | | |
522 | | - | |
| 522 | + | |
523 | 523 | | |
524 | 524 | | |
525 | 525 | | |
| |||
557 | 557 | | |
558 | 558 | | |
559 | 559 | | |
560 | | - | |
| 560 | + | |
561 | 561 | | |
562 | 562 | | |
563 | 563 | | |
| |||
601 | 601 | | |
602 | 602 | | |
603 | 603 | | |
604 | | - | |
| 604 | + | |
605 | 605 | | |
606 | 606 | | |
607 | 607 | | |
| |||
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
378 | 378 | | |
379 | 379 | | |
380 | 380 | | |
381 | | - | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
382 | 385 | | |
383 | 386 | | |
384 | 387 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
450 | 450 | | |
451 | 451 | | |
452 | 452 | | |
| 453 | + | |
453 | 454 | | |
454 | 455 | | |
455 | 456 | | |
| |||
711 | 712 | | |
712 | 713 | | |
713 | 714 | | |
| 715 | + | |
714 | 716 | | |
715 | 717 | | |
716 | 718 | | |
| |||
Lines changed: 29 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
198 | 227 | | |
199 | 228 | | |
200 | 229 | | |
| |||
0 commit comments