Files
Kigi-CLI/crates/codegen/kigi-shell/tests/test_config_update_isolation.rs
T
ZacharyZhang-NY 6f31415ed6 §9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed
The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok'
crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party
license archives, README provenance, and the required 'Based on Grok
Build Open Source' attribution, now sourced from version_attribution.txt).

Wire-visible renames (both sides in this repo, changed in lockstep):
- Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode).
- Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* /
  _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps
  a read-side alias for the legacy '_x.ai/session/update' method so
  existing updates.jsonl histories load; writes emit only the new name
  (both directions test-pinned).
- Agent types grok-build* → kigi* with a documented legacy-prefix alias
  at resolution time so persisted sessions keep resolving.
- ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case
  kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build
  implementation dirs renamed to kigi*.
- x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes
  grokday/groknight → kigiday/kiginight (old persisted values fall back
  to the default theme), web_fetch allowlist xAI hosts → kimi.com +
  moonshot platforms, changelog CDN → this repo, grok-build changelog
  archives deleted.
- BYOK default endpoint removed: [endpoints] api_base_url is now truly
  optional with NO default — consumers fail fast with the flag name when
  unset (no silent x.ai egress). Mock harnesses inject it explicitly.
- System-prompt identity fixed: 'released by xAI' → 'an unofficial
  community CLI for Kimi' (template + regenerated encrypted form).

Also repaired pre-existing grok-era test debt found by the sweep: the
stale trace_classify default-model pin, the grok-pager UA label test,
pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY
test could previously reach the real api.moonshot.cn), and the outdated
oauth fixture scope key.

Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings);
FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed;
deny advisories ok.
2026-07-18 02:48:46 -04:00

173 lines
5.6 KiB
Rust

//! Regression test: `update_config` must not leak values from
//! `managed_config.toml` or `requirements.toml` into the user's `config.toml`.
//!
//! Bug: `update_config` used `load_effective_config()` (which merges all config
//! layers) to populate the `Config` struct, then `save_config` wrote that merged
//! result back to the user's `config.toml`. If `requirements.toml` contained
//! `auto_update = false`, any unrelated config write (theme change, model
//! preference, yolo toggle) would permanently poison the user's config.
use std::fs;
use std::path::PathBuf;
use std::sync::OnceLock;
use serial_test::serial;
/// Shared temp directory that lives for the entire test binary.
/// All tests share this as KIGI_SHARE_DIR (the `OnceLock` in kigi-config
/// only allows one value per process).
fn test_home() -> &'static PathBuf {
static HOME: OnceLock<PathBuf> = OnceLock::new();
HOME.get_or_init(|| {
let dir = tempfile::TempDir::new().unwrap();
// Keep so the directory survives the entire test process.
let path = dir.keep();
// SAFETY: called once at init before other threads touch this var.
unsafe { std::env::set_var("KIGI_SHARE_DIR", &path) };
path
})
}
/// Clean up config files between tests.
fn reset_config_files(home: &std::path::Path) {
let _ = fs::remove_file(home.join("config.toml"));
let _ = fs::remove_file(home.join("requirements.toml"));
let _ = fs::remove_file(home.join("managed_config.toml"));
}
#[tokio::test]
#[serial]
async fn update_config_does_not_leak_requirements_into_user_config() {
let home = test_home();
reset_config_files(home);
// --- Arrange ---
// User's config.toml: auto_update = true
fs::write(
home.join("config.toml"),
"[cli]\nauto_update = true\ninstaller = \"internal\"\n",
)
.unwrap();
// Enterprise requirements.toml overrides auto_update to false
fs::write(
home.join("requirements.toml"),
"[cli]\nauto_update = false\n",
)
.unwrap();
// Sanity-check: effective config should show auto_update = false
// (requirements wins over user config).
let effective = kigi_shell::config::load_effective_config().unwrap();
let effective_cfg = kigi_shell::util::config::load_config_from_toml(&effective);
assert_eq!(
effective_cfg.cli.auto_update,
Some(false),
"precondition: effective config should merge requirements (auto_update=false)"
);
// --- Act ---
// Simulate an unrelated config write (e.g. persisting a model preference).
kigi_shell::util::config::update_config(|cfg| {
cfg.models.default = Some("kigi-3".to_string());
})
.await
.expect("update_config should succeed");
// --- Assert ---
// Read the user's config.toml back from disk (raw, no merge).
let raw = fs::read_to_string(home.join("config.toml")).unwrap();
let user_toml: toml::Value = toml::from_str(&raw).unwrap();
let user_cfg = kigi_shell::util::config::load_config_from_toml(&user_toml);
assert_eq!(
user_cfg.cli.auto_update,
Some(true),
"BUG REPRODUCED: auto_update in user config.toml was overwritten by \
requirements.toml value. The raw file contents:\n{raw}"
);
// Also verify the unrelated write succeeded.
assert_eq!(user_cfg.models.default.as_deref(), Some("kigi-3"));
}
#[tokio::test]
#[serial]
async fn update_config_preserves_none_when_only_requirements_sets_value() {
let home = test_home();
reset_config_files(home);
// User config has no auto_update field at all
fs::write(
home.join("config.toml"),
"[cli]\ninstaller = \"internal\"\n",
)
.unwrap();
// requirements.toml sets auto_update = false
fs::write(
home.join("requirements.toml"),
"[cli]\nauto_update = false\n",
)
.unwrap();
// Write an unrelated field
kigi_shell::util::config::update_config(|cfg| {
cfg.ui.yolo = true;
})
.await
.expect("update_config should succeed");
// Read back
let raw = fs::read_to_string(home.join("config.toml")).unwrap();
let user_toml: toml::Value = toml::from_str(&raw).unwrap();
let user_cfg = kigi_shell::util::config::load_config_from_toml(&user_toml);
assert_eq!(
user_cfg.cli.auto_update, None,
"auto_update should remain absent in user config — requirements.toml \
value must not leak. Raw file:\n{raw}"
);
}
#[tokio::test]
#[serial]
async fn update_config_does_not_leak_managed_config_values() {
let home = test_home();
reset_config_files(home);
// User config has no auto_update — only installer
fs::write(
home.join("config.toml"),
"[cli]\ninstaller = \"internal\"\n",
)
.unwrap();
// managed_config.toml sets auto_update = false and channel = "stable"
fs::write(
home.join("managed_config.toml"),
"[cli]\nauto_update = false\nchannel = \"stable\"\n",
)
.unwrap();
kigi_shell::util::config::update_config(|cfg| {
cfg.models.default = Some("test-model".to_string());
})
.await
.expect("update_config should succeed");
let raw = fs::read_to_string(home.join("config.toml")).unwrap();
let user_toml: toml::Value = toml::from_str(&raw).unwrap();
let user_cfg = kigi_shell::util::config::load_config_from_toml(&user_toml);
assert_eq!(
user_cfg.cli.auto_update, None,
"auto_update from managed_config.toml leaked into user config. Raw:\n{raw}"
);
assert_eq!(
user_cfg.cli.channel, None,
"channel from managed_config.toml leaked into user config. Raw:\n{raw}"
);
}