Skip to content

fix(lifecycle): retain shared resources when creators leave - #8762

Open
mzxchandra wants to merge 5 commits into
stagingfrom
codex/shared-resource-lifecycle
Open

mzxchandra wants to merge 5 commits into
stagingfrom
codex/shared-resource-lifecycle

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Transfer shared workspace resources to the existing billed account before removing access, and transfer organization-only resources to an existing organization owner. Preserve archived roots, child rows/documents, and file history without changing non-null API contracts.
  • Preserve implicit upload attribution through handoff, including empty uploads, and keep legitimate first writes at version 1. Serialize content writes, archive rollback, and retention cleanup with member removal by locking the workspace before existing files.
  • Repair references from earlier departures before permanent account deletion, using transactional successor validation and a user-row barrier against late creator references. Both v1 admin removal routes use the common revocation path.
  • Retain public MCP execution identity and block creator deletion until an admin makes the server private or deletes it. Require live workspace API keys to be replaced/revoked instead of transferring credentials.

Type of Change

  • Bug fix

Testing

  • 74 affected real PostgreSQL cases pass: file history, full member-removal races, lifecycle retention, and storage accounting. Eight contention cases verify both arrival orders for content writes, archive rollback, and retention cleanup.
  • The unchanged code reproduced four PostgreSQL deadlocks. Removing each early lock independently reproduced its failure; restored code passes. Earlier history controls verify uploader attribution, first-write numbering, restored versions, and retained storage references.
  • 158 affected unit tests pass. Scoped Biome, API-validation and test-pattern audits, generated artifacts, and diff checks pass. Full repository tests, typecheck and build run in CI.
  • Earlier HTTP lifecycle acceptance verifies handoff, departed-user denial, account deletion, surviving-user access, file bytes, non-null contracts, and storage/history preservation; it was not rerun for the lock-order correction.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

Scope notes

Shared service-account and workspace-env credential lifecycle is intentionally deferred: their existing creator cascade remains, with no new transfer or deletion guard. Existing workflow owner-based execution/environment fallback is preserved. Public MCP execution-identity cleanup is a separate follow-up. Already-admitted requests may finish after departure; permanent deletion repairs their committed references or rejects late user references. HTTP document setup uses a provider-independent fixture, so these tests do not claim connector indexing or provider execution coverage.

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 8, 2026 7:14am UTC

Request Review

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 10 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/app/api/v1/admin/workspaces/[id]/members/route.ts
@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Refactors member removal to centralize access revocation logic.

The reviewed changes appear safe to merge; no new blocking issue was found.

What we checked:

  • File operations wait safely: The changed operations and member removal take the workspace lock first. One waits before it can hold the file lock needed by the other.

Summary

This PR keeps shared resources when their creators leave and repairs older creator references before account deletion. The latest changes align file operations with member removal.

  • Content writes, archive rollback, and retention cleanup now lock the workspace before existing files.
  • PostgreSQL tests cover both arrival orders and check file history, access removal, and storage totals.
  • No new actionable issues were found in the changes since the previous review. Checks were based on code inspection; tests were not run.
  • mzxchandra explicitly deferred shared service-account and workspace-env credential retention, and public MCP execution-identity cleanup.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Content write] --> L[Lock workspace]
  B[Archive rollback] --> L
  C[Retention cleanup] --> L
  D[Member removal] --> L
  L --> F[Lock existing files]
  F --> M[Write content, purge files, or transfer creators]
  M --> T[Commit together]
Loading

Reviews (7) · Last reviewed commit: "fix(lifecycle): order workspace locks be..." · Reviewed by Greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@mzxchandra
mzxchandra marked this pull request as ready for review October 7, 2026 22:43

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/uploads/contexts/workspace/creator-handoff.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/uploads/contexts/workspace/creator-handoff.ts
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 18 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@mzxchandra
mzxchandra marked this pull request as ready for review October 8, 2026 07:47

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 18 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — ef198efa Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant