Repository navigation
fix(mothership): clear errors and a working direct path for CLI version, function and grep commands - #8736
fix(mothership): clear errors and a working direct path for CLI version, function and grep commands#8736waleedlatif1 wants to merge 2 commits into
Conversation
…on, function and grep commands
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
Summary
GET/PATCH /api/v2/workflows/{id}/versions/{version}(and every other route usingversionNumberPathSchema) answered a non-numeric segment such aslatestorv2with zod'sInvalid input: expected number, received NaN, which names neither the parameter nor what it takes. The CLI validates flags locally but passes positionals straight through, sosim workflows versions get <id> latestsurfaced that message verbatim. The shared path schema now saysversion must be a positive integer, the same wording the body schema already used.function_executethroughPOST /api/v2/tools/{id}/execute: a direct tool call has no workflow run, so there is no executor delegation origin, and the Function operation threw the rawExecutor delegation origin is required(it is the one in-process operation whose error skips the identity-fault classifier). It now takes its authority from the authenticated caller the route already passes ascallerPrincipal, the way the File operations do. A Mothership invocation is narrowed to the function-execution audience withbindCopilotWorkspaceOperation. Any other principal goes to the function-execution operation policy unchanged, and that policy still admits only delegated executor/Copilot principals, so personal API keys are still refused. Workflow runs and Copilot tool calls keep their existing branches.grep --scope knowledge:--in knowledgealready redirected to semanticknowledge search, but--scope knowledge(orkb) only returnedUnknown scope. Both selectors now share the same redirect.TOOL_EXECUTION_DELEGATION_AUDIENCEto replace the inline'sim:tool-execution'literal, so the Function operation can name the audience it rebinds from.Investigated and left unchanged:
tools get <id>answeringTool not foundis intentional. A tool that no visible block exposes is a 404, not a 403, so its existence is not leaked.run_code: run_code can run authenticated CLI scripts and network calls, and its handler explicitly says it is not a read-only sandbox. Keeping it out of the read-only set is correct.Type of Change
Testing
app/api/v2/workflows/[workflowId]/versions/[version]/route.test.ts(non-numeric version segment)lib/internal/function/execute-direct-call.test.ts(direct calls through the real function-execution policy, only the sandbox stubbed: an admitted Mothership caller runs, a personal API key is still refused)lib/mothership/agent-cli/engines/universal-grep.test.ts(--scope knowledge/kb)lib/api/contracts,lib/internal/function,lib/mothership/agent-cli,lib/tool-execution,lib/workflows/application,app/api/v2/tools,app/api/v2/workflows/.../versions,app/api/v2/files,tools/assistant-execution.test.tspackages/sim-clibun run lint,bun run type-check,bun run check:audits(58/58),docs-manifest:check,check-block-registry, rootbun run testChecklist
test-auditauthoring gate)