Skip to content

fix(cloud-agent-next): deliver full profiles to control-plane sessions - #7238

Open
eshurakov wants to merge 5 commits into
eshurakov/redact-named-secretsfrom
eshurakov/deliver-profile-secrets
Open

eshurakov wants to merge 5 commits into
eshurakov/redact-named-secretsfrom
eshurakov/deliver-profile-secrets

Conversation

@eshurakov

@eshurakov eshurakov commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Profiles were resolved into metadata, but workspace_* control-plane sessions received neither encrypted environment variables nor skills, custom agents, or Kilo commands. This change delivers all profile collections through control-plane preparation.

  • The Sandbox DO decrypts profile secrets only for the authenticated prepare frame. Stored route specs retain no decrypted secrets; worker-issued credentials retain precedence. Secret-bearing frames require a wrapper that advertises named-secret redaction.
  • Registration carries validated skills, custom agents, and Kilo commands into the route. Profile env, secrets, MCP, skills, agents, and commands require isolated session runtimes so sibling sessions cannot inherit another profile.
  • The wrapper writes skill markdown and companion files into the session home. Custom agents and commands use a session-owned KILO_CONFIG file, allowing large valid prompts/templates without exceeding process environment limits. Credential refresh preserves the config path; preparation clears stale profile artifacts from restored homes.
  • Profile validation, model normalization, agent/command conversion, and wrapper skill writing have shared owners used by both planes. Read-only Bitbucket reviews continue to withhold secrets, MCP, skills, agents, and commands.
  • Repository snapshots are skipped for routes with setup commands, since setup can write secret-bearing files into a snapshot shared by repository.

Verification

No additional manual full-stack run was performed for the skills/agents/commands addition. Earlier validation of this branch on a local stack verified that a secret supplied through the follow-up environment change reached a workspace_* sandbox, appeared as [REDACTED] in setup output, and was absent from Worker logs and Durable Object state. A profile-secret launch itself was not separately exercised; the snapshot skip remains covered by tests.

Visual Changes

N/A

Reviewer Notes

Stacked on #7237; review the three commits above that base. The newest commit completes skill/agent/command delivery and isolates plain-env profiles.

Current checks passed: focused Worker registration/preflight/session-service/sandbox suites, wrapper preparation/materialization/legacy-bootstrap tests, service and wrapper typecheck, service lint, wrapper build, formatting, and the duplication ratchet (no new duplication). A pinned Kilo 7.8.1 discovery test confirmed that the actual CLI exposes the delivered skill, skill slash command, custom agent, and Kilo command, and that the companion file is present. Artifact tests cover credential-refresh preservation, sibling isolation, stale artifact removal, safe companion paths, and 100KB command templates using disk-backed config.

The earlier commits also passed the sandbox-control Workers integration suites and the full cloud-agent-next unit suite; those broad checks were not repeated for the newest commit.

Rollout requires the rebuilt wrapper. Existing allocations with an older wrapper cannot consume the new profile fields; secret-bearing launches on wrappers lacking named-secret redaction continue to fail closed until the allocation stops. No production deployment was performed.

@eshurakov
eshurakov force-pushed the eshurakov/deliver-profile-secrets branch from 1890511 to dea671f Compare October 7, 2026 08:04
Profile encryptedSecrets never reached workspace_* sessions: only plain
variables did, and only the legacy plane decrypted secrets.

Carry the worker-encrypted snapshot inside the DO-private credential
source and decrypt it only in the Sandbox DO, when it builds the
session.prepare frame. The decrypted values and the new frame-only
secretEnvKeys exist only in that frame, never in a route row or stored
payload. A grant-issued credential of the same name is restored over a
profile secret.

A secret-bearing prepare is sent only to a wrapper that advertised
redactsNamedSecrets in hello; otherwise the attempt fails with
workspace_setup_failed rather than risk printing a secret in clear. A
prepare without secrets is unchanged for older wrappers.

Skip repository snapshots for a route with setup commands: capture runs
after setup, and the snapshot key names only the user and repository, so
setup output and anything setup wrote would be published under it.
@eshurakov
eshurakov force-pushed the eshurakov/deliver-profile-secrets branch from dea671f to b96f997 Compare October 7, 2026 08:23
Comment thread services/cloud-agent-next/src/control-plane/session/registration.ts Outdated
Comment thread services/cloud-agent-next/src/control-plane/session/registration.ts
Comment thread services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts Outdated
@kilo-code-bot

kilo-code-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental commit adds the 1–200 character path bound to the shared isSafeSkillFilePath, closing the over-long-path gap in the legacy skill writer; both changed files are correct.

Files Reviewed (2 files)
  • services/cloud-agent-next/src/shared/runtime-profile.ts
  • services/cloud-agent-next/wrapper/src/control-plane/runtime-profile.test.ts
Previous Review Summaries (4 snapshots, latest commit b53ba18)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit b53ba18)

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

The incremental commit fixes the prior critical (runtime profile collections now survive projectRouteSpec) plus the Bitbucket env/secret, frame-env cap, and missing-key test gaps; one residual suggestion remains in the legacy skill-writer filter.

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1
Issue Details (click to expand)

SUGGESTION

File Line Issue
services/cloud-agent-next/wrapper/src/runtime-skills.ts 24 The legacy skill-writer filter omits the >200-char path guard from the retired isSafeSkillFilePath, so an over-long companion path survives the filter and RuntimeSkillsSchema.parse still throws, failing the whole skill preparation.
Files Reviewed (9 files)
  • services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts
  • services/cloud-agent-next/src/control-plane/session/registration.test.ts
  • services/cloud-agent-next/src/sandbox-session/attach-payload.ts
  • services/cloud-agent-next/src/shared/control-plane-protocol.ts
  • services/cloud-agent-next/src/shared/runtime-profile.ts - 1 issue (shared helper)
  • services/cloud-agent-next/test/integration/sandbox-control-v2-runtime-proxy.test.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts
  • services/cloud-agent-next/wrapper/src/control-plane/runtime-profile.test.ts
  • services/cloud-agent-next/wrapper/src/runtime-skills.ts - 1 issue

Fix these issues in Kilo Cloud

Previous review (commit 850e220)

Status: 1 Critical, 4 Suggestions | Recommendation: Address before merge

Executive Summary

The new control-plane profile delivery is wired end to end at registration but never reaches the wrapper: the Sandbox DO's projectRouteSpec allowlist drops runtimeSkills/runtimeAgents/kiloCommands before the session.prepare frame, so skills/agents/commands are never materialized. Four lower-severity notes remain around skill-write failure behavior, Bitbucket env parity, the frame env cap, and one test's key setup.

Overview

Severity Count
CRITICAL 1
WARNING 0
SUGGESTION 4
Issue Details (click to expand)

CRITICAL

File Line Issue
services/cloud-agent-next/src/control-plane/session/registration.ts 229 The runtime profile collections are added to the route spec, but the Sandbox DO re-projects the spec via an explicit allowlist in projectRouteSpec (control-plane/sandbox/sandbox-do.ts:1934-1946) that omits them; startAttempt stores the projected spec and materializePrepareFrame sends route.spec, so the wrapper never receives skills/agents/commands. runtimeIsolation is projected, so per-session routes still delete HOME/.kilocode/skills and write nothing back. Add the fields to projectRouteSpec.

SUGGESTION

File Line Issue
services/cloud-agent-next/wrapper/src/runtime-skills.ts 11 Retired legacy helper skipped an unsafe companion file (continue); the shared helper now throws on any invalid skill, failing the whole preparation.
services/cloud-agent-next/src/control-plane/session/registration.ts 227 Read-only Bitbucket reviews still carry profile.envVars in the route spec env, unlike the legacy plane which zeroes user env (session-service.ts:1144). (previously reported)
services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts 2436 A decrypted secret above the frame env cap (8192) permanently fails every attempt with workspace_setup_failed; profile secrets may be saved up to 10000 chars (agent-profiles-router.ts:39). (previously reported)
services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts 2841 The "cannot be decrypted" case never clears AGENT_ENV_VARS_PRIVATE_KEY, so it tests a stale-key mismatch, not the no-key branch. (previously reported)
Files Reviewed (19 files)
  • services/cloud-agent-next/docs/control-plane.md
  • services/cloud-agent-next/src/control-plane/session/registration.test.ts
  • services/cloud-agent-next/src/control-plane/session/registration.ts - 1 issue
  • services/cloud-agent-next/src/persistence/model-utils.ts
  • services/cloud-agent-next/src/persistence/schemas.ts
  • services/cloud-agent-next/src/schema.ts
  • services/cloud-agent-next/src/session-service.ts
  • services/cloud-agent-next/src/shared/agent-modes.ts
  • services/cloud-agent-next/src/shared/control-plane-protocol.ts
  • services/cloud-agent-next/src/shared/model-utils.ts
  • services/cloud-agent-next/src/shared/runtime-profile-config.ts
  • services/cloud-agent-next/src/shared/runtime-profile.ts
  • services/cloud-agent-next/wrapper/src/control-plane/prepare.test.ts
  • services/cloud-agent-next/wrapper/src/control-plane/prepare.ts
  • services/cloud-agent-next/wrapper/src/control-plane/runtime-profile.real.test.ts
  • services/cloud-agent-next/wrapper/src/control-plane/runtime-profile.test.ts
  • services/cloud-agent-next/wrapper/src/control-plane/runtime-profile.ts
  • services/cloud-agent-next/wrapper/src/runtime-skills.ts - 1 issue
  • services/cloud-agent-next/wrapper/src/session-bootstrap.ts

Targeted carry-forward checks on unchanged files: services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts, services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts.

Fix these issues in Kilo Cloud

Previous review (commit 111c699)

Status: 3 Issues Found | Recommendation: Address before merge

Executive Summary

Profile secrets now reach workspace_* prepare frames behind a named-secret redaction gate; the three prior findings (runtime isolation, Bitbucket gating, materialized-key gating) are addressed in 111c699, leaving three lower-severity gaps in gate completeness, value bounds, and test coverage.

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 3
Issue Details (click to expand)

SUGGESTION

File Line Issue
services/cloud-agent-next/src/control-plane/session/registration.ts 221 The read-only-Bitbucket gate withholds encryptedSecrets but not profile.envVars, so a review session still gets plaintext user env while the comment claims worker-owned env only (legacy zeroes user env at session-service.ts:1164).
services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts 2436 A decrypted secret over the frame env cap (8192) permanently fails every attempt with only workspace_setup_failed; profile secrets may be saved up to 10000 chars (agent-profiles-router.ts:39).
services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts 2841 The "cannot be decrypted" case never clears the shared AGENT_ENV_VARS_PRIVATE_KEY, so it tests a stale-key mismatch, not the no-key branch.
Files Reviewed (15 files)
  • services/cloud-agent-next/docs/control-plane.md
  • services/cloud-agent-next/src/control-plane/sandbox/frame-env.ts
  • services/cloud-agent-next/src/control-plane/sandbox/frame-env.test.ts
  • services/cloud-agent-next/src/control-plane/sandbox/repo-key.ts
  • services/cloud-agent-next/src/control-plane/sandbox/repo-key.test.ts
  • services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts - 1 issue
  • services/cloud-agent-next/src/control-plane/session/registration.ts - 1 issue
  • services/cloud-agent-next/src/control-plane/session/registration.test.ts
  • services/cloud-agent-next/src/sandbox-control/session-credentials.ts
  • services/cloud-agent-next/src/sandbox-session/attach-payload.ts
  • services/cloud-agent-next/src/shared/control-plane-protocol.ts
  • services/cloud-agent-next/test/integration/helpers/fake-wrapper.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2-repo-snapshots.test.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2-runtime-proxy.test.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts - 1 issue

Fix these issues in Kilo Cloud

Previous review

Status: 3 Issues Found | Recommendation: Address before merge

Executive Summary

Profile secrets now reach workspace control-plane frames, but a sibling session sharing a worktree directory can reuse one Kilo runtime and thereby apply one session's decrypted secrets while dropping its own.

Overview

Severity Count
CRITICAL 0
WARNING 2
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
services/cloud-agent-next/src/control-plane/session/registration.ts 226 Secrets are added to the frame without forcing per-session runtime isolation; a shared worktree directory reuses one Kilo runtime, so one session's decrypted secrets are applied while the other's are dropped.
services/cloud-agent-next/src/control-plane/session/registration.ts 231 encryptedSecrets is not gated for a read-only Bitbucket review, unlike the gated mcpServers snapshot; review sessions can receive profile secrets.

SUGGESTION

File Line Issue
services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts 2415 The redaction gate uses the raw secret count instead of the materialized secretEnvKeys, so a route whose secrets are all restored/deleted still fails closed unnecessarily.
Files Reviewed (14 files)
  • services/cloud-agent-next/docs/control-plane.md
  • services/cloud-agent-next/src/control-plane/sandbox/frame-env.test.ts
  • services/cloud-agent-next/src/control-plane/sandbox/frame-env.ts
  • services/cloud-agent-next/src/control-plane/sandbox/repo-key.test.ts
  • services/cloud-agent-next/src/control-plane/sandbox/repo-key.ts
  • services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts
  • services/cloud-agent-next/src/control-plane/session/registration.test.ts
  • services/cloud-agent-next/src/control-plane/session/registration.ts
  • services/cloud-agent-next/src/sandbox-control/session-credentials.ts
  • services/cloud-agent-next/src/shared/control-plane-protocol.ts
  • services/cloud-agent-next/test/integration/helpers/fake-wrapper.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2-repo-snapshots.test.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2-runtime-proxy.test.ts
  • services/cloud-agent-next/test/integration/sandbox-control-v2.test.ts

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 36.6K · Output: 6.7K · Cached: 226.7K

Review guidance: REVIEW.md from base branch eshurakov/redact-named-secrets

… failures

Address three Kilo Code Review findings on profile-secret delivery:

- A secret-bearing spec now forces `runtimeIsolation: 'per-session'` so a
  sibling sharing the worktree directory cannot reuse a Kilo runtime whose
  env already holds another session's decrypted secrets.
- Read-only Bitbucket code reviews no longer receive profile secrets,
  matching the legacy plane and the withheld MCP snapshot.
- The prepare frame fails closed only when a secret value actually reaches
  the frame (`secretEnvKeys` non-empty), not merely when the encrypted
  snapshot is non-empty, so a snapshot whose keys are all restored or
  dropped still prepares on a version-3 wrapper.
@eshurakov
eshurakov force-pushed the eshurakov/deliver-profile-secrets branch from 8ef2261 to 111c699 Compare October 7, 2026 09:57
Comment thread services/cloud-agent-next/src/control-plane/session/registration.ts
Comment thread services/cloud-agent-next/src/control-plane/sandbox/sandbox-do.ts
@eshurakov eshurakov changed the title fix(cloud-agent-next): deliver profile secrets to control-plane sessions fix(cloud-agent-next): deliver full profiles to control-plane sessions Oct 7, 2026
Comment thread services/cloud-agent-next/src/control-plane/session/registration.ts
Comment thread services/cloud-agent-next/wrapper/src/runtime-skills.ts Outdated
Comment thread services/cloud-agent-next/wrapper/src/runtime-skills.ts
@eshurakov
eshurakov added this pull request to stack #7257 October 7, 2026 15:01

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant