Repository navigation
Conversation
1890511 to
dea671f
Compare
Profile encryptedSecrets never reached workspace_* sessions: only plain variables did, and only the legacy plane decrypted secrets. Carry the worker-encrypted snapshot inside the DO-private credential source and decrypt it only in the Sandbox DO, when it builds the session.prepare frame. The decrypted values and the new frame-only secretEnvKeys exist only in that frame, never in a route row or stored payload. A grant-issued credential of the same name is restored over a profile secret. A secret-bearing prepare is sent only to a wrapper that advertised redactsNamedSecrets in hello; otherwise the attempt fails with workspace_setup_failed rather than risk printing a secret in clear. A prepare without secrets is unchanged for older wrappers. Skip repository snapshots for a route with setup commands: capture runs after setup, and the snapshot key names only the user and repository, so setup output and anything setup wrote would be published under it.
dea671f to
b96f997
Compare
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit adds the 1–200 character path bound to the shared Files Reviewed (2 files)
Previous Review Summaries (4 snapshots, latest commit b53ba18)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit b53ba18)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe incremental commit fixes the prior critical (runtime profile collections now survive Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (9 files)
Fix these issues in Kilo Cloud Previous review (commit 850e220)Status: 1 Critical, 4 Suggestions | Recommendation: Address before merge Executive SummaryThe new control-plane profile delivery is wired end to end at registration but never reaches the wrapper: the Sandbox DO's Overview
Issue Details (click to expand)CRITICAL
SUGGESTION
Files Reviewed (19 files)
Targeted carry-forward checks on unchanged files: Fix these issues in Kilo Cloud Previous review (commit 111c699)Status: 3 Issues Found | Recommendation: Address before merge Executive SummaryProfile secrets now reach Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (15 files)
Fix these issues in Kilo Cloud Previous reviewStatus: 3 Issues Found | Recommendation: Address before merge Executive SummaryProfile secrets now reach workspace control-plane frames, but a sibling session sharing a worktree directory can reuse one Kilo runtime and thereby apply one session's decrypted secrets while dropping its own. Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (14 files)
Reviewed by deepseek-v4.1-flash · Input: 36.6K · Output: 6.7K · Cached: 226.7K Review guidance: REVIEW.md from base branch |
… failures Address three Kilo Code Review findings on profile-secret delivery: - A secret-bearing spec now forces `runtimeIsolation: 'per-session'` so a sibling sharing the worktree directory cannot reuse a Kilo runtime whose env already holds another session's decrypted secrets. - Read-only Bitbucket code reviews no longer receive profile secrets, matching the legacy plane and the withheld MCP snapshot. - The prepare frame fails closed only when a secret value actually reaches the frame (`secretEnvKeys` non-empty), not merely when the encrypted snapshot is non-empty, so a snapshot whose keys are all restored or dropped still prepares on a version-3 wrapper.
8ef2261 to
111c699
Compare
Summary
Profiles were resolved into metadata, but
workspace_*control-plane sessions received neither encrypted environment variables nor skills, custom agents, or Kilo commands. This change delivers all profile collections through control-plane preparation.KILO_CONFIGfile, allowing large valid prompts/templates without exceeding process environment limits. Credential refresh preserves the config path; preparation clears stale profile artifacts from restored homes.Verification
No additional manual full-stack run was performed for the skills/agents/commands addition. Earlier validation of this branch on a local stack verified that a secret supplied through the follow-up environment change reached a
workspace_*sandbox, appeared as[REDACTED]in setup output, and was absent from Worker logs and Durable Object state. A profile-secret launch itself was not separately exercised; the snapshot skip remains covered by tests.Visual Changes
N/A
Reviewer Notes
Stacked on #7237; review the three commits above that base. The newest commit completes skill/agent/command delivery and isolates plain-env profiles.
Current checks passed: focused Worker registration/preflight/session-service/sandbox suites, wrapper preparation/materialization/legacy-bootstrap tests, service and wrapper typecheck, service lint, wrapper build, formatting, and the duplication ratchet (no new duplication). A pinned Kilo 7.8.1 discovery test confirmed that the actual CLI exposes the delivered skill, skill slash command, custom agent, and Kilo command, and that the companion file is present. Artifact tests cover credential-refresh preservation, sibling isolation, stale artifact removal, safe companion paths, and 100KB command templates using disk-backed config.
The earlier commits also passed the sandbox-control Workers integration suites and the full cloud-agent-next unit suite; those broad checks were not repeated for the newest commit.
Rollout requires the rebuilt wrapper. Existing allocations with an older wrapper cannot consume the new profile fields; secret-bearing launches on wrappers lacking named-secret redaction continue to fail closed until the allocation stops. No production deployment was performed.