refactor(doctor): share retired permission flag cleanup (#162320)

This commit is contained in:
Peter Steinberger 2026-09-30 20:06:22 -07:00 • committed by GitHub
parent 57ff6e21b1
commit 00f3a20630
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 56 additions and 22 deletions

View file

@ -0,0 +1,50 @@
import { expect, it } from "vitest";
import { LEGACY_CONFIG_MIGRATIONS_RUNTIME } from "./legacy-config-migrations.runtime.js";
it("removes retired path flags without dropping provider or install-exec records", () => {
const raw = {
secrets: {
providers: {
configured: {
source: "exec",
command: "/usr/bin/printf",
allowInsecurePath: false,
allowSymlinkCommand: undefined,
},
empty: { allowInsecurePath: false },
malformed: [],
absent: null,
},
},
security: {
installPolicy: {
enabled: false,
exec: { allowInsecurePath: undefined, allowSymlinkCommand: false },
},
},
};
const expected = {
secrets: {
providers: {
configured: { source: "exec", command: "/usr/bin/printf" },
empty: {},
malformed: [],
absent: null,
},
},
security: { installPolicy: { enabled: false, exec: {} } },
};
const apply = () => {
const changes: string[] = [];
for (const migration of LEGACY_CONFIG_MIGRATIONS_RUNTIME) {
migration.apply(raw, changes);
}
return changes;
};
expect(apply()).toEqual([
"Applied tier-eval tranche retirements; canonical settings and built-in defaults now apply.",
]);
expect(raw).toStrictEqual(expected);
expect(apply()).toEqual([]);
expect(raw).toStrictEqual(expected);
});

View file

@ -388,30 +388,14 @@ export function migrateTierEvalTranche(raw: Record<string, unknown>, changes: st
for (const retiredPath of TIER_EVAL_RETIRED_ROOT_PATHS) {
stripped = deleteRetiredPath(raw, retiredPath) || stripped;
}
const secrets = getRecord(raw.secrets);
const providers = getRecord(secrets?.providers);
if (providers) {
for (const provider of Object.values(providers)) {
const entry = getRecord(provider);
if (entry) {
stripped =
Object.hasOwn(entry, "allowInsecurePath") ||
Object.hasOwn(entry, "allowSymlinkCommand") ||
stripped;
delete entry.allowInsecurePath;
delete entry.allowSymlinkCommand;
}
for (const owner of [
...Object.values(getRecord(getRecord(raw.secrets)?.providers) ?? {}),
getRecord(getRecord(raw.security)?.installPolicy)?.exec,
]) {
for (const key of ["allowInsecurePath", "allowSymlinkCommand"]) {
stripped = deleteRetiredPath(owner, [key]) || stripped;
}
}
const installExec = getRecord(getRecord(getRecord(raw.security)?.installPolicy)?.exec);
if (installExec) {
stripped =
Object.hasOwn(installExec, "allowInsecurePath") ||
Object.hasOwn(installExec, "allowSymlinkCommand") ||
stripped;
delete installExec.allowInsecurePath;
delete installExec.allowSymlinkCommand;
}
if (stripped || changes.length > initialChangeCount) {
changes.push(
"Applied tier-eval tranche retirements; canonical settings and built-in defaults now apply.",