@@ -77,6 +77,7 @@ import {
7777 readSandboxResourceScope ,
7878 withSandboxResourceScope ,
7979} from '@/lib/mothership/tools/sandbox-resources'
80+ import { buildMothershipSandboxSession } from '@/lib/mothership/tools/sandbox-session'
8081import { chatSandboxSessionKey } from '@/lib/mothership/tools/sandbox-session-key'
8182import { ResolvedSecretTraceRegistry } from '@/executor/utils/resolved-secret-trace-registry'
8283import { buildFunctionExecuteBody , functionExecuteTool } from '@/tools/function/execute'
@@ -369,6 +370,31 @@ describe('persistent workbench output confidentiality', () => {
369370 expect ( result . raw . output ) . toHaveProperty ( 'result.length' , 100_001 )
370371 expect ( result . projected . safe ) . toBe ( true )
371372 } )
373+ it . each ( [
374+ [ 'array' , '[' , ']' ] ,
375+ [ 'object' , '{"nested":' , '}' ] ,
376+ ] ) (
377+ 'classifies deeply nested %s output without exhausting the call stack' ,
378+ async ( _kind , open , close ) => {
379+ await inResourceScope ( async ( ) => {
380+ const session = await buildMothershipSandboxSession ( {
381+ ...scope ,
382+ sessionKey : chatSandboxSessionKey ( chatId ) ,
383+ } )
384+ const credential = session . envs ! . SIM_API_KEY
385+ const nested = ( leaf : string ) =>
386+ JSON . parse ( open . repeat ( 12_000 ) + JSON . stringify ( leaf ) + close . repeat ( 12_000 ) )
387+ expect ( session . outputProvenance ! ( nested ( 'ordinary output' ) ) ) . toEqual ( {
388+ status : 'exact' ,
389+ entries : [ ] ,
390+ } )
391+ expect ( session . outputProvenance ! ( nested ( credential ) ) ) . toMatchObject ( {
392+ status : 'exact' ,
393+ entries : [ { name : 'SIM_API_KEY' } ] ,
394+ } )
395+ } )
396+ }
397+ )
372398 it ( 'revokes callback authentication before a result reaches the model' , async ( ) => {
373399 const result = await run (
374400 'printf "%s" "$SIM_API_KEY" > session-key.txt; printf "%s" "$SIM_ENDPOINT" > session-endpoint.txt; printf done'
0 commit comments