Repository navigation
feat(agentconfig): overlay validation (5/15) - #473
gusfcarvalho merged 2 commits into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
a5ae52e to
675982d
Compare
Fifth layer of the agent remote-configuration stack (split from #465): ValidateOverlay (strict decode, size, locked keys, plugin names, env references, schedules incl. the TZ= prefix guard, NUL characters) and the ValidationErrors/FieldError vocabulary. pkg/agentconfig is complete after this layer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gusfcarvalho
left a comment
There was a problem hiding this comment.
Export the agentconfig rule tables so the UI can check its copy of the rules
The UI agent-config stack (compliance-framework/ui#322–#342) re-implements some pkg/agentconfig rules in the browser, for its per-field edit hints and add-plugin gating:
MatchTrustedSourceandMatchOverridableConfigFlagKindOf/IsOCISourcePluginNamePatternParseSchedule- per-field
Classify+WillApply
It tests them against src/utils/agent-config/__tests__/fixtures/agentconfig-conformance.json. That file is a hand copy of this package's test tables (remoteconfig_test.go, sources_test.go and classify_test.go from #470/#471, and cron_test.go from this PR), pinned to 83ed7d6.
Problem: 83ed7d6 is no longer in this stack's history, because the stack has been rewritten since. Nothing fails on either side when a rule changes here. The rule files happen to be identical between 83ed7d6 and the stack top today, so the UI is in sync, but nothing guarantees it.
Requested change (this PR): this is the last layer that touches these rules, and the first where all four test tables exist.
- Write the existing test tables to a golden file, e.g.
pkg/agentconfig/testdata/conformance.json, in the UI fixture's shape:trustedSources,overridableConfigFlags,sourceKinds,schedules,pluginNames, and theapplySafeclassify/will-apply cases. - Add a test that fails when the file is stale, with a
-updateflag to regenerate it.
Follow-up in the UI: once this lands, the UI replaces its hand-copied fixture with this file and checks it in CI (ccf-review finding CORE-DUP-001 on ui#341).
…ables The UI re-implements MatchTrustedSource, MatchOverridableConfigFlag, KindOf/IsOCISource, PluginNamePattern, ParseSchedule and the per-field apply_safe outcome of Classify + WillApply, and tested them against a hand-copied fixture pinned to an old api commit, so a rule change failed on neither side. Hoist those test tables to package-level vars and generate testdata/conformance.json from them (in the UI fixture's shape), with every expected value computed by the real functions. TestConformanceGolden fails when the file is stale; regenerate it with go test ./pkg/agentconfig -run TestConformanceGolden -update The apply_safe cases are a new table (applySafeCases) whose field state is derived from Classify + WillApply over probe overlays. The UI fixture's drift cases are added to the Go tables (two '%' registries for KindOf, '*/5 * * * *' and '@hourly' for ParseSchedule), plus a re-enabled local plugin source case. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
675982d to
c0b3792
Compare
Part 5/15 of the agent remote-configuration stack
This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without
docs/,go.sumand Markdown). The last layer's tree is identical to #465, which already has its review history.Stacked on #472 (
lisa/agent-config/04-redaction). Review and merge in order.What's in this layer
Fifth layer of the agent remote-configuration stack (split from #465): ValidateOverlay (strict decode, size, locked keys, plugin names, env references, schedules incl. the TZ= prefix guard, NUL characters) and the ValidationErrors/FieldError vocabulary. pkg/agentconfig is complete after this layer.
Size: +1732 -61 = 1793 changed lines (without docs/go.sum) (1361 without the generated pkg/agentconfig/testdata/conformance.json).
Verification
Each layer builds on its own:
go build,go vet(also with-tags integration),golangci-lint runandgo test ./...pass, andmake swagleaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.🤖 Generated with Claude Code