@@ -50,6 +50,23 @@ async function withFixture<T>(
5050 }
5151}
5252
53+ async function withNamedConfig < T > (
54+ name : string ,
55+ run : ( paths : { cwd : string ; customConfig : string } ) => Promise < T > ,
56+ ) : Promise < T > {
57+ const parent = await mkdtemp ( join ( tmpdir ( ) , "cl9386-dated-config-" ) ) ;
58+ const cwd = join ( parent , "ws" ) ;
59+ await mkdir ( cwd , { recursive : true } ) ;
60+ const customConfig = join ( cwd , name ) ;
61+ await writeFile ( customConfig , `${ SKIP_PAYLOAD } \n` ) ;
62+ await writeFile ( join ( cwd , "scratch.txt" ) , "ordinary workspace file\n" ) ;
63+ try {
64+ return await run ( { cwd, customConfig } ) ;
65+ } finally {
66+ await rm ( parent , { recursive : true , force : true } ) ;
67+ }
68+ }
69+
5370function runner (
5471 cwd : string ,
5572 skipPermissions : boolean ,
@@ -158,6 +175,32 @@ describe("CL-9386 runtime-denylist the active --config path holding skip", () =>
158175 } ) ;
159176 } ) ;
160177
178+ for ( const datedName of [
179+ "2026-09-26-config.json" ,
180+ "gpt-4-1.json" ,
181+ ] as const ) {
182+ test ( `${ mode } : dir-scoped grep does not surface extras-denied ${ datedName } ` , async ( ) => {
183+ await withNamedConfig ( datedName , async ( { cwd, customConfig } ) => {
184+ const { tools } = runner ( cwd , skipPermissions , customConfig ) ;
185+ const result = await tools . run (
186+ {
187+ id : "1" ,
188+ name : "grep" ,
189+ arguments : {
190+ pattern : "dangerouslySkipPermissions" ,
191+ path : "." ,
192+ } ,
193+ } ,
194+ new AbortController ( ) . signal ,
195+ ) ;
196+ expect ( result . isError !== true ) . toBe ( true ) ;
197+ expect ( String ( result . content ) ) . not . toContain (
198+ "dangerouslySkipPermissions" ,
199+ ) ;
200+ } ) ;
201+ } ) ;
202+ }
203+
161204 test ( `${ mode } : dir-scoped search_files does not surface extras-denied names` , async ( ) => {
162205 await withFixture ( async ( { cwd, customConfig } ) => {
163206 const { tools } = runner ( cwd , skipPermissions , customConfig ) ;
@@ -254,6 +297,29 @@ describe("CL-9386 runtime-denylist the active --config path holding skip", () =>
254297 } ) ;
255298 } ) ;
256299
300+ for ( const datedName of [ "2026-09-26-config.json" , "gpt-4-1.json" ] as const ) {
301+ test ( `rg missing: fallback grep does not surface extras-denied ${ datedName } ` , async ( ) => {
302+ await withNamedConfig ( datedName , async ( { cwd, customConfig } ) => {
303+ const tools = createPosixTools ( {
304+ cwd,
305+ plugins : [ ripgrepPlugin ( cwd , { } , rgMissingSpawn , [ customConfig ] ) ] ,
306+ } ) ;
307+ const result = await tools . run (
308+ {
309+ id : "1" ,
310+ name : "grep" ,
311+ arguments : { pattern : "dangerouslySkipPermissions" , path : cwd } ,
312+ } ,
313+ new AbortController ( ) . signal ,
314+ ) ;
315+ expect ( result . isError !== true ) . toBe ( true ) ;
316+ expect ( String ( result . content ) ) . not . toContain (
317+ "dangerouslySkipPermissions" ,
318+ ) ;
319+ } ) ;
320+ } ) ;
321+ }
322+
257323 test ( "rg missing: fallback search_files does not surface extras-denied names" , async ( ) => {
258324 await withFixture ( async ( { cwd, customConfig } ) => {
259325 const tools = createPosixTools ( {
0 commit comments