Skip to content

Fix secret scope permission level - #6299

Merged
radakam merged 4 commits into
mainfrom
fix-secret-scope-permission-level
Aug 18, 2026
Merged

radakam merged 4 commits into
mainfrom
fix-secret-scope-permission-level

Conversation

@radakam

@radakam radakam commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Changes

Add Values() on SecretScopePermissionLevel so generated enum validation covers the field, matching other resource permission levels.

Why

Invalid secret_scopes permission levels (e.g. 12, fuzz_badlevel) passed bundle validate --strict, then failed at deploy in direct mode when collapsing ACLs.

Found by fuzz testing.

Tests

Acceptance: TestAccept/bundle/validate/secret_scope_invalid_permission_level (warns on invalid secret_scopes permission levels (12, fuzz_badlevel); fails with --strict).

Without Values(), generated enum validation skipped permissions[*].level,
so invalid levels passed validate --strict and only failed at deploy.
Multiple secret_scopes map keys made warning order non-deterministic across
engines; keep the cases as ordered permissions on one scope instead.
errcode only records tolerated failures; musterr asserts validate --strict must fail.
@radakam
radakam marked this pull request as ready for review August 18, 2026 08:36
@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: d1a5b06

Run: 32123774304

Env 🟨​KNOWN 💚​RECOVERED 🙈​SKIP ✅​pass 🙈​skip Time
🟨​ aws linux 3 1 4 286 1151 7:40
🟨​ aws windows 3 1 4 288 1149 7:18
🟨​ azure linux 3 1 4 285 1151 7:03
🟨​ azure windows 3 1 4 287 1149 7:19
💚​ gcp linux 1 5 286 1151 5:54
💚​ gcp windows 1 5 288 1149 5:41
8 interesting tests: 4 SKIP, 3 KNOWN, 1 RECOVERED
Test Name aws linux aws windows azure linux azure windows gcp linux gcp windows
💚​ TestAccept 💚​R 💚​R 💚​R 💚​R 💚​R 💚​R
🙈​ TestAccept/bundle/invariant/no_drift 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/bundle/resources/vector_search_endpoints/drift/recreated_same_name 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/bundle/resources/vector_search_indexes/recreate/embedding_dimension 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/ssh/connection 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🟨​ TestFetchRepositoryInfoAPI_FromRepo 🟨​K 🟨​K 🟨​K 🟨​K 🙈​S 🙈​S
🟨​ TestFetchRepositoryInfoAPI_FromRepo/root 🟨​K 🟨​K 🟨​K 🟨​K
🟨​ TestFetchRepositoryInfoAPI_FromRepo/subdir 🟨​K 🟨​K 🟨​K 🟨​K
Top 6 slowest tests (at least 2 minutes):
duration env testname
5:42 aws windows TestAccept
5:33 azure windows TestAccept
5:33 gcp windows TestAccept
3:56 azure linux TestAccept
3:53 aws linux TestAccept
3:47 gcp linux TestAccept

Add a changelog fragment, simplify the acceptance fixture, and align
permission-level constant order with privilege rank.
@radakam
radakam enabled auto-merge August 18, 2026 10:34
@radakam
radakam added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit 18bb9c1 Aug 18, 2026
26 checks passed
@radakam
radakam deleted the fix-secret-scope-permission-level branch August 18, 2026 11:01
janniklasrose pushed a commit that referenced this pull request Sep 15, 2026
## Changes
Add `Values()` on `SecretScopePermissionLevel` so generated enum
validation covers the field, matching other resource permission levels.

## Why
Invalid `secret_scopes` permission levels (e.g. `12`, `fuzz_badlevel`)
passed `bundle validate --strict`, then failed at deploy in direct mode
when collapsing ACLs.

_Found by fuzz testing._

## Tests
Acceptance:
`TestAccept/bundle/validate/secret_scope_invalid_permission_level`
(warns on invalid `secret_scopes` permission levels (12, fuzz_badlevel);
fails with `--strict`).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants