Skip to content

Keep Setup Security settings outside the Harness area - #600

Merged
JacobStephens2 merged 2 commits into
mainfrom
issue-597
Oct 9, 2026
Merged

JacobStephens2 merged 2 commits into
mainfrom
issue-597

Conversation

@JacobStephens2

@JacobStephens2 JacobStephens2 commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Setup keeps Security in its own area after Harness settings, including when upgrading an older config or repairing an existing split. Configured values and comments survive the move.

 [harness.codex]
-[security]
 [harness.agy]
 ...
 [harness.opencode]
+[security]

Closes #597

Evidence

  • Before: cargo test --test setup upgrading_setup_puts_security_after_all_harness_settings -- --exact failed: Security appeared between Codex and agy.
    After: passes; fresh and upgraded configs place Security after all Harness sections.
  • Before: Spec S1's exact Python reproduction failed with exit 1. The retained CLI regression cargo test --test setup setup_keeps_existing_security_outside_completed_harness_settings -- --exact also failed.
    After: both pass. Security values, heading/key comments, and a second Setup run are covered.
  • Full cargo test: 1661 passed, 1 ignored, 0 failed.
  • Type checking, formatting, Clippy, all 22 Setup integration tests, all 31 config tests, and all 48 Setup unit tests pass.

Test seams

  • thirdshift setup CLI: fresh defaults, upgrades with absent or existing Security settings, repair of an interleaved Security section, retained settings/comments, and idempotence.

Review

Reviewed against main with thirdshift-code-review. Standards: no findings. Spec: S1 reproduced and fixed; no outstanding findings. Both axes read every changed file (README.md, src/config.rs, src/setup.rs, tests/setup.rs). Changed files left unread: none.

Unaddressed findings

Standards

None.

Spec

None; S1 was reproduced, fixed, and covered by a retained regression test.

Security

None. Completed a single-session guidance-mode source review against pinned merge base f51d1596e85de96b3486151aefbd4228cdd57b22, covering all four changed files and supporting config validation, completion, serialization, Setup writes, credential handling, and Security flag consumers. Read the relevant attack-class guidance and ADR 0013's execution trust assumptions; no repository SECURITY.md or dedicated threat model was found. No introduced security boundary violation warranted a proof-of-concept test or fix. Tests were not rerun in this source review.

Security review outcome

No unaddressed introduced findings.

Merge Danger

Door: two-way

Only config section placement changes; configured values and comments are retained.

Blast Radius: Setup

Built with codex · gpt-6.1-sol · high

@JacobStephens2
JacobStephens2 merged commit 7b6feb3 into main Oct 9, 2026
17 checks passed
@JacobStephens2
JacobStephens2 deleted the issue-597 branch October 9, 2026 14:17
@JacobStephens2 JacobStephens2 mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

after thirdshift setup , [security] block of config.toml was in the middle of harness settings rather than in its own area

1 participant