{"record":{"id":"70d47ab2a9179e31","repo":"Hmbown/CodeWhale","slug":"fleet-task-spec-security-policy-is-a-legacy-compatibility","errorCode":null,"errorMessage":"fleet task spec security_policy is a legacy compatibility field, not executable Fleet identity; configure trust, secrets, approvals, sandboxing, and tool authority through Runtime policy","messagePattern":"fleet task spec security_policy is a legacy compatibility field, not executable Fleet identity; configure trust, secrets, approvals, sandboxing, and tool authority through Runtime policy","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/fleet/task_spec.rs","lineNumber":154,"sourceCode":"        .file_stem()\n        .and_then(|s| s.to_str())\n        .filter(|s| !s.is_empty())\n        .unwrap_or(\"fleet-run\")\n        .to_string();\n    let parsed = match path.extension().and_then(|s| s.to_str()) {\n        Some(\"toml\") => toml::from_str::<FleetTaskSpecFile>(&raw)\n            .with_context(|| format!(\"parsing TOML fleet task spec {}\", path.display()))?,\n        _ => serde_json::from_str::<FleetTaskSpecFile>(&raw)\n            .with_context(|| format!(\"parsing JSON fleet task spec {}\", path.display()))?,\n    };\n    let doc = parsed.into_document(fallback_name);\n    validate_task_spec_document(&doc)?;\n    Ok(doc)\n}\n\npub fn validate_task_spec_document(doc: &FleetTaskSpecDocument) -> Result<()> {\n    if doc.security_policy.is_some() {\n        bail!(\n            \"fleet task spec security_policy is a legacy compatibility field, not executable Fleet identity; configure trust, secrets, approvals, sandboxing, and tool authority through Runtime policy\"\n        );\n    }\n    if doc.tasks.is_empty() {\n        bail!(\"fleet task spec must include at least one task\");\n    }\n    let mut ids = BTreeSet::new();\n    for task in &doc.tasks {\n        validate_fleet_identity(\"task id\", &task.id)?;\n        if !ids.insert(task.id.clone()) {\n            bail!(\"duplicate fleet task id {}\", task.id);\n        }\n        validate_fleet_name(&format!(\"task {} name\", task.id), &task.name)?;\n        if task.instructions.trim().is_empty() {\n            bail!(\"fleet task {} instructions cannot be empty\", task.id);\n        }\n        if let Some(objective) = &task.objective\n            && objective.trim().is_empty()","sourceCodeStart":136,"sourceCodeEnd":172,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/fleet/task_spec.rs#L136-L172","documentation":"validate_task_spec_document (crates/tui/src/fleet/task_spec.rs:154) rejects any fleet task spec that sets `security_policy`. The field is legacy compatibility only: trust, secrets, approvals, sandboxing, and tool authority are configured through Runtime policy, not executable Fleet identity.","triggerScenarios":"Loading or validating a task spec document (load_task_spec_document, create_queued_run_with_descriptor) whose TOML still contains a `security_policy` key — typically a spec written for the pre-Runtime-policy schema.","commonSituations":"Reusing old fleet spec files from before the Runtime policy migration; docs or templates that still show security_policy; migrated specs where the field was left in place instead of deleted.","solutions":["Delete the `security_policy` key from the task spec TOML","Move the intended security configuration into Runtime policy (trust, secrets, approvals, sandboxing, tool authority)","Validate again via load_task_spec_document"],"exampleFix":"# before\nsecurity_policy = \"standard\"\n[[tasks]]\nid = \"build\"\n# after\n[[tasks]]\nid = \"build\"\n# (security configured via Runtime policy)","handlingStrategy":"validation","validationCode":"if doc.security_policy.is_some() {\n    return Err(\"remove security_policy from task spec; configure Runtime policy instead\".into());\n}","typeGuard":null,"tryCatchPattern":"match load_task_spec_document(path) {\n    Ok(doc) => doc,\n    Err(e) if e.to_string().contains(\"security_policy is a legacy compatibility field\") => {\n        eprintln!(\"{}: migrate to Runtime policy\", path.display());\n        return;\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Regenerate old specs from current templates after schema migrations","Keep security configuration in Runtime policy, never in task specs","Run spec validation as a pre-commit check"],"tags":["config","fleet","deprecated","validation"],"backgroundTag":"deprecated-api-usage","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}