Files
msd-core/bin
Tom Boucher e14ef535aa fix(install): allow codex hooks.state.<key> as regular table (#3285) (#3289)
* test: codex hooks.state.<key> tables must validate as regular tables (#3285 RED)

Drive validateCodexConfigSchema with a fixture containing both [hooks.state]
and [[hooks.SessionStart]] entries. Expect the state tables to pass as regular
tables. Currently fails — validator over-classifies every hooks.* path as AoT.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(install): treat codex hooks.state as regular table not AoT (#3285)

validateCodexConfigSchema was over-classifying every hooks.* section header
as an event-handler array-of-tables, rejecting the hooks.state.* namespace
that Codex CLI 0.130.0+ uses for per-hook trust persistence.

Fix:
1. Section-header check: carve out `hooks.state` and `hooks.state.*` from
   the AoT-required rule — only paths that are neither of those still
   require double-bracket form.
2. Parsed-object check: skip the `state` key when iterating Object.entries
   (parsed.hooks) so the "must be array" guard does not fire for the trust
   namespace object.

All other hooks.<EVENT> validation (SessionStart AoT, handler-field placement)
is unchanged.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* changeset: pr=3289 for #3285

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(install): codex hooks.state must be regular-table, reject AoT/scalar (CR finding 1)

- migrateCodexHooksMapFormat: exclude hooks.state and hooks.state.* from
  legacy-map detection so [hooks.state] is never promoted to [[hooks.state]] AoT
- validateCodexConfigSchema: reject [[hooks.state]] / [[hooks.state.*]] AoT at
  section level; reject Array/scalar values at parsed-object level
- Accept only plain-object shape for hooks.state and hooks.state.* (Codex
  CLI 0.130.0+ trust-persistence namespace)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: assert codex hooks.state trust entry preserved with original values (CR finding 2)

Strengthen post-install preservation assertion to verify the actual trust
entry key and its enabled/trusted_hash values survive — not just that
hooks.state is an object. Add two validator-reject tests for [[hooks.state]]
and [[hooks.state.foo]] AoT forms.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-09 07:42:22 -04:00
..