Skip to content

feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift, workflow exec cancellations - #6247

Open
icecrasher321 wants to merge 41 commits into
stagingfrom
feat/func-cli-resolver
Open

feat(code): cli sandboxes, enterprise timeouts, secrets projections, resolver lift, workflow exec cancellations#6247
icecrasher321 wants to merge 41 commits into
stagingfrom
feat/func-cli-resolver

Conversation

@icecrasher321

@icecrasher321 icecrasher321 commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Allow CLIs in Sandboxes (with 25 managed CLIs out of the box)
  • Add Shell as supported language in function block
  • Enterprise metadata can set custom timeouts now
  • Resolver lifted to be central compiler adhering to secrets mgmt policies and applying across the board
  • Workflow execution cancellations to cancel trigger dev side too

Type of Change

  • New feature

Testing

Tested manually with @Sg312

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

…lver

# Conflicts:
#	apps/sim/components/settings/navigation.test.ts
#	apps/sim/components/settings/navigation.ts
#	apps/sim/providers/index.test.ts
@icecrasher321
icecrasher321 requested a review from a team as a code owner August 4, 2026 08:23
@gitguardian

gitguardian Bot commented Aug 4, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
35640005 Triggered Generic Password 1a7c79b apps/desktop/src/main/browser-import/import-service.test.ts View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@vercel

vercel Bot commented Aug 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
docs Skipped Skipped Aug 5, 2026 11:05pm

Request Review

@cursor

cursor Bot commented Aug 4, 2026

Copy link
Copy Markdown

PR Summary

High Risk
The change set touches secret handling, model-input provenance, remote sandbox supply chain, and long-running execution lifecycle/cleanup—any regression could leak secrets, break sandboxes, or terminate or leave runs in a bad state.

Overview
This PR expands remote Function sandboxes with a curated managed CLI catalog (pinned artifacts, checksums, client vs server registries, content-addressed image identity) plus Debian system packages, and documents how self-hosted deployments build separate Function and Mothership shell bases on E2B/Daytona. The Function block gains Shell, clearer Python __sim_result__ semantics, and updated sandbox/docs around PATH, managed CLIs, and secret placeholders in code.

Execution policy and cleanup add Enterprise-configurable async workflow timeouts (up to seven days), the async-only X-Execution-Timeout-Seconds API header (cannot extend account policy), and a reworked stale-execution cron that batches mutations with SKIP LOCKED, honors executionDeadlineAt, and separates table-job heartbeat rules from workflow timeout policy.

Secrets and provenance are documented and enforced across integrations/tools: opt-in modelInput projection, opaqueModelInput rejection before external I/O, secretProvenance for durable Sim-owned data, and shared executor boundaries—without blanket sanitization of third-party API results. Function/Custom Tool code binds {{KEY}} at a central compiler boundary instead of pasting plaintext into source; model and log views project placeholders where applicable.

Smaller contract fixes include distinct execution attachment keys for multipart uploads, upload receipt tokens on batch presigned URLs, and aligned OpenAPI/docs for async timeout headers and storage CORS (GCS/Azure).

Reviewed by Cursor Bugbot for commit 7636c7d. Configure here.

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

Comment thread apps/sim/app/api/cron/cleanup-stale-executions/route.ts
@greptile-apps

greptile-apps Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR centralizes execution-time placeholder and secret handling while expanding sandbox, timeout, and cancellation capabilities.

  • Adds curated managed CLIs and Shell execution to Function sandboxes.
  • Adds configurable Enterprise asynchronous execution timeouts and exposes per-request timeout controls through the SDKs.
  • Extends cancellation across local, database-backed, Trigger.dev, resumed, and grouped workflow executions.
  • Projects resolved secrets out of traces and model-visible tool results.
  • Updates database schema, API contracts, documentation, UI configuration, and tests for the new behavior.

Confidence Score: 5/5

The PR appears safe to merge within the scope of this follow-up review.

No blocking failure remains in the eligible follow-up review scope.

Important Files Changed

Filename Overview
apps/sim/executor/variables/resolver.ts Centralizes code-context resolution while preserving environment placeholders for execution-boundary compilation.
apps/sim/lib/execution/code-placeholders/index.ts Introduces the shared JavaScript, Python, and Shell placeholder-compilation boundary.
apps/sim/lib/execution/remote-sandbox/cli-tools.server.ts Defines pinned, checksum-verified server-side installation recipes for managed sandbox CLIs.
apps/sim/lib/billing/execution-timeout-defaults.ts Resolves plan and Enterprise-specific execution timeout policies.
apps/sim/app/api/workflows/[id]/executions/[executionId]/cancel/route.ts Coordinates durable cancellation state, backend job cancellation, local aborts, resumed executions, and terminal event publication.
apps/sim/lib/core/async-jobs/backends/trigger-dev.ts Adds execution-scoped Trigger.dev cancellation using tags and payload verification.
packages/db/schema.ts Adds persisted metadata supporting configurable Enterprise execution limits and related sandbox behavior.

Sequence Diagram

sequenceDiagram
  participant Client
  participant API as Execution API
  participant Policy as Timeout Policy
  participant Queue as Async Backend
  participant Executor
  participant Sandbox
  participant Projection as Secret Projection

  Client->>API: Start workflow
  API->>Policy: Resolve account and request timeout
  Policy-->>API: Effective deadline
  API->>Queue: Enqueue execution with deadline
  Queue->>Executor: Run workflow
  Executor->>Sandbox: Execute Function or Shell with managed CLIs
  Sandbox-->>Executor: Block output
  Executor->>Projection: Sanitize traces and model-visible output
  Projection-->>Client: Stream projected result
  Client->>API: Cancel execution
  API->>Queue: Cancel queued or running job
  API->>Executor: Signal local or resumed execution
Loading

Reviews (14): Last reviewed commit: "run from block ui disabling" | Re-trigger Greptile

Comment thread apps/sim/lib/execution/code-placeholders/javascript.ts Fixed
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cursor review

Comment thread apps/sim/app/api/cron/cleanup-stale-executions/route.ts
Comment thread apps/sim/app/api/cron/cleanup-stale-executions/route.ts Outdated
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cursor review

Comment thread apps/sim/app/api/cron/cleanup-stale-executions/route.ts Outdated
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@greptile

@icecrasher321

Copy link
Copy Markdown
Collaborator Author

@cursor review

Comment thread apps/sim/app/api/cron/cleanup-stale-executions/route.ts

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 8558c19. Configure here.

…lver

# Conflicts:
#	apps/sim/executor/handlers/agent/agent-handler.ts
#	apps/sim/lib/copilot/vfs/workspace-vfs.ts
#	apps/sim/tools/generated/tool-metadata.ts
#	apps/sim/tools/generated/tool-outputs.ts
…lver

# Conflicts:
#	apps/docs/content/docs/en/workflows/blocks/function.mdx
#	apps/sim/app/workspace/[workspaceId]/w/[workflowId]/components/panel/components/editor/components/sub-block/components/code/code.tsx
#	apps/sim/lib/copilot/request/tools/executor.test.ts
#	apps/sim/tools/generated/tool-metadata.ts
@icecrasher321

Copy link
Copy Markdown
Collaborator Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7636c7d. Configure here.

updatedAt: new Date(),
})
.where(and(staleProcessingPredicate, inArray(asyncJobs.id, candidates)))
.returning({ id: asyncJobs.id })

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unsafe batched cleanup subquery locking

High Severity

runBatchedMutation and deployment pruning embed SELECT ... LIMIT ... FOR UPDATE SKIP LOCKED inside WHERE id IN (...). PostgreSQL can re-execute that IN subquery as a join, so LIMIT is not reliably single-evaluated. Batches can return more rows than requested, trip the oversized-batch throw, abort the rest of that cleanup section, and make short pages an unreliable exhaustion signal. Workflow cleanup already avoids this with an explicit transaction.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7636c7d. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants