Skip to content

feat(agentconfig): overlay validation (5/15) - #473

Merged
gusfcarvalho merged 2 commits into
lisa/agent-config/04-redactionfrom
lisa/agent-config/05-overlay-validation
Oct 6, 2026
Merged

gusfcarvalho merged 2 commits into
lisa/agent-config/04-redactionfrom
lisa/agent-config/05-overlay-validation

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 5/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #472 (lisa/agent-config/04-redaction). Review and merge in order.

What's in this layer

Fifth layer of the agent remote-configuration stack (split from #465): ValidateOverlay (strict decode, size, locked keys, plugin names, env references, schedules incl. the TZ= prefix guard, NUL characters) and the ValidationErrors/FieldError vocabulary. pkg/agentconfig is complete after this layer.

Size: +1732 -61 = 1793 changed lines (without docs/go.sum) (1361 without the generated pkg/agentconfig/testdata/conformance.json).

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 13663f80-16d6-4db4-9db8-1f3d96cba191

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

Fifth layer of the agent remote-configuration stack (split from #465): ValidateOverlay (strict decode, size, locked keys, plugin names, env references, schedules incl. the TZ= prefix guard, NUL characters) and the ValidationErrors/FieldError vocabulary. pkg/agentconfig is complete after this layer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Export the agentconfig rule tables so the UI can check its copy of the rules

The UI agent-config stack (compliance-framework/ui#322–#342) re-implements some pkg/agentconfig rules in the browser, for its per-field edit hints and add-plugin gating:

  • MatchTrustedSource and MatchOverridableConfigFlag
  • KindOf / IsOCISource
  • PluginNamePattern
  • ParseSchedule
  • per-field Classify + WillApply

It tests them against src/utils/agent-config/__tests__/fixtures/agentconfig-conformance.json. That file is a hand copy of this package's test tables (remoteconfig_test.go, sources_test.go and classify_test.go from #470/#471, and cron_test.go from this PR), pinned to 83ed7d6.

Problem: 83ed7d6 is no longer in this stack's history, because the stack has been rewritten since. Nothing fails on either side when a rule changes here. The rule files happen to be identical between 83ed7d6 and the stack top today, so the UI is in sync, but nothing guarantees it.

Requested change (this PR): this is the last layer that touches these rules, and the first where all four test tables exist.

  • Write the existing test tables to a golden file, e.g. pkg/agentconfig/testdata/conformance.json, in the UI fixture's shape: trustedSources, overridableConfigFlags, sourceKinds, schedules, pluginNames, and the applySafe classify/will-apply cases.
  • Add a test that fails when the file is stale, with a -update flag to regenerate it.

Follow-up in the UI: once this lands, the UI replaces its hand-copied fixture with this file and checks it in CI (ccf-review finding CORE-DUP-001 on ui#341).

…ables

The UI re-implements MatchTrustedSource, MatchOverridableConfigFlag,
KindOf/IsOCISource, PluginNamePattern, ParseSchedule and the per-field
apply_safe outcome of Classify + WillApply, and tested them against a
hand-copied fixture pinned to an old api commit, so a rule change failed on
neither side.

Hoist those test tables to package-level vars and generate
testdata/conformance.json from them (in the UI fixture's shape), with every
expected value computed by the real functions. TestConformanceGolden fails
when the file is stale; regenerate it with
  go test ./pkg/agentconfig -run TestConformanceGolden -update
The apply_safe cases are a new table (applySafeCases) whose field state is
derived from Classify + WillApply over probe overlays. The UI fixture's
drift cases are added to the Go tables (two '%' registries for KindOf,
'*/5 * * * *' and '@hourly' for ParseSchedule), plus a re-enabled local
plugin source case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config/05-overlay-validation branch from 675982d to c0b3792 Compare October 6, 2026 13:06

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

@gusfcarvalho
gusfcarvalho merged commit 36f5a3b into main Oct 6, 2026
9 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config/05-overlay-validation branch October 6, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant