{"record":{"id":"aa76570146bd81a1","repo":"Hmbown/CodeWhale","slug":"fleet-worker-trust-level-is-a-legacy-compatibility-field-not","errorCode":null,"errorMessage":"fleet worker {} trust_level is a legacy compatibility field, not Fleet identity; configure execution authority through Runtime policy","messagePattern":"fleet worker (.+?) trust_level is a legacy compatibility field, not Fleet identity; configure execution authority through Runtime policy","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/fleet/task_spec.rs","lineNumber":198,"sourceCode":"        {\n            bail!(\n                \"fleet task {} metadata key {} is reserved for the durable Runtime selection receipt\",\n                task.id,\n                super::worker_runtime::FROZEN_FLEET_MEMBER_METADATA_KEY\n            );\n        }\n        validate_tags(&task.id, &task.tags)?;\n        validate_workspace_requirements(task)?;\n    }\n    let mut worker_ids = BTreeSet::new();\n    for worker in &doc.workers {\n        validate_fleet_identity(\"worker id\", &worker.id)?;\n        if !worker_ids.insert(worker.id.clone()) {\n            bail!(\"duplicate fleet worker id {}\", worker.id);\n        }\n        validate_fleet_name(&format!(\"worker {} name\", worker.id), &worker.name)?;\n        if worker.trust_level.is_some() {\n            bail!(\n                \"fleet worker {} trust_level is a legacy compatibility field, not Fleet identity; configure execution authority through Runtime policy\",\n                worker.id\n            );\n        }\n    }\n    Ok(())\n}\n\nfn validate_fleet_identity(field: &str, value: &str) -> Result<()> {\n    if value.is_empty() {\n        bail!(\"fleet {field} cannot be empty\");\n    }\n    if value.len() > MAX_FLEET_ID_BYTES || !value.chars().all(is_worker_token_char) {\n        bail!(\n            \"fleet {field} must be a simple ASCII token no longer than {MAX_FLEET_ID_BYTES} bytes\"\n        );\n    }\n    Ok(())","sourceCodeStart":180,"sourceCodeEnd":216,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/fleet/task_spec.rs#L180-L216","documentation":"The per-worker `trust_level` field is legacy compatibility only and is not Fleet identity. validate_task_spec_document (crates/tui/src/fleet/task_spec.rs:198) rejects any worker entry that still sets it; execution authority must be configured through Runtime policy instead.","triggerScenarios":"A task spec document's [workers] entry contains a `trust_level` key; detected by validate_task_spec_document during load_task_spec_document or create_queued_run_with_descriptor.","commonSituations":"Specs carried over from the pre-Runtime-policy schema; templates or docs that still document trust_level; partial migrations where the field was left behind.","solutions":["Delete the `trust_level` key from the worker entry","Configure the worker's execution authority through Runtime policy","Re-validate the document before queueing the run"],"exampleFix":"# before\n[[workers]]\nid = \"w1\"\ntrust_level = \"trusted\"\n# after\n[[workers]]\nid = \"w1\"\n# (authority configured via Runtime policy)","handlingStrategy":"validation","validationCode":"for w in &doc.workers {\n    if w.trust_level.is_some() {\n        return Err(format!(\"worker {} must not set trust_level; use Runtime policy\", w.id));\n    }\n}","typeGuard":null,"tryCatchPattern":"match load_task_spec_document(path) {\n    Ok(doc) => doc,\n    Err(e) if e.to_string().contains(\"trust_level is a legacy compatibility field\") => {\n        eprintln!(\"{}: migrate worker authority to Runtime policy\", path.display());\n        return;\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Update templates to drop trust_level after the Runtime policy migration","Grep legacy specs for trust_level before reuse","Keep execution authority in Runtime policy only"],"tags":["config","fleet","deprecated","validation"],"backgroundTag":"deprecated-api-usage","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}