Hmbown/CodeWhale · error

fleet worker trust_level is a legacy compatibility field…

Error message

fleet worker {} trust_level is a legacy compatibility field, not Fleet identity; configure execution authority through Runtime policy

What it means

The per-worker `trust_level` field is legacy compatibility only and is not Fleet identity. validate_task_spec_document (crates/tui/src/fleet/task_spec.rs:198) rejects any worker entry that still sets it; execution authority must be configured through Runtime policy instead.

Solutions

  1. Delete the `trust_level` key from the worker entry
  2. Configure the worker's execution authority through Runtime policy
  3. Re-validate the document before queueing the run

Example fix

# before
[[workers]]
id = "w1"
trust_level = "trusted"
# after
[[workers]]
id = "w1"
# (authority configured via Runtime policy)
Defensive patterns

Strategy: validation

Validate before calling

for w in &doc.workers {
    if w.trust_level.is_some() {
        return Err(format!("worker {} must not set trust_level; use Runtime policy", w.id));
    }
}

Try / catch

match load_task_spec_document(path) {
    Ok(doc) => doc,
    Err(e) if e.to_string().contains("trust_level is a legacy compatibility field") => {
        eprintln!("{}: migrate worker authority to Runtime policy", path.display());
        return;
    }
    Err(e) => return Err(e),
}

Prevention

When it happens

Trigger: A task spec document's [workers] entry contains a `trust_level` key; detected by validate_task_spec_document during load_task_spec_document or create_queued_run_with_descriptor.

Common situations: Specs carried over from the pre-Runtime-policy schema; templates or docs that still document trust_level; partial migrations where the field was left behind.

Understand the failure class

Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/aa76570146bd81a1. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/fleet/task_spec.rs:198

        {
            bail!(
                "fleet task {} metadata key {} is reserved for the durable Runtime selection receipt",
                task.id,
                super::worker_runtime::FROZEN_FLEET_MEMBER_METADATA_KEY
            );
        }
        validate_tags(&task.id, &task.tags)?;
        validate_workspace_requirements(task)?;
    }
    let mut worker_ids = BTreeSet::new();
    for worker in &doc.workers {
        validate_fleet_identity("worker id", &worker.id)?;
        if !worker_ids.insert(worker.id.clone()) {
            bail!("duplicate fleet worker id {}", worker.id);
        }
        validate_fleet_name(&format!("worker {} name", worker.id), &worker.name)?;
        if worker.trust_level.is_some() {
            bail!(
                "fleet worker {} trust_level is a legacy compatibility field, not Fleet identity; configure execution authority through Runtime policy",
                worker.id
            );
        }
    }
    Ok(())
}

fn validate_fleet_identity(field: &str, value: &str) -> Result<()> {
    if value.is_empty() {
        bail!("fleet {field} cannot be empty");
    }
    if value.len() > MAX_FLEET_ID_BYTES || !value.chars().all(is_worker_token_char) {
        bail!(
            "fleet {field} must be a simple ASCII token no longer than {MAX_FLEET_ID_BYTES} bytes"
        );
    }
    Ok(())

View on GitHub (pinned to 73e0f67d83)