Skip to content

fix(core): skip invalid TOML policy rules - #29431

Closed
andreivince wants to merge 3 commits into
google-gemini:mainfrom
andreivince:fix/policy-rule-validation
Closed

andreivince wants to merge 3 commits into
google-gemini:mainfrom
andreivince:fix/policy-rule-validation

Conversation

@andreivince

@andreivince andreivince commented Sep 20, 2026 •

Copy link
Copy Markdown

Summary

Skip TOML policy rules that already produced validation errors. An empty tool name currently reaches PolicyEngine and crashes startup, while conflicting shell-command fields are reported as invalid but still enforced.

Details

Track invalid rule indices before transformation and array expansion, including empty names in safety checker rules. Valid siblings and rules in other files continue to load, with original diagnostic indices preserved. Warning-only rules retain their existing behavior.

Cover each existing shell-syntax error, empty scalar and array names, checker rules, file isolation, and actual policy decisions. The same matrix checks diagnostics and skipped-rule behavior, replacing four repeated diagnostic-only cases. Add two recorded-response CLI tests and document the behavior, including a valid schema example.

Related Issues

Fixes #29050

How to Validate

From the repository root with Node.js 20.19.6:

GEMINI_CLI_TRUST_WORKSPACE=true npm run preflight
  • Full macOS preflight passed: 15,678 tests passed and 65 existing skips, including coverage, build, lint, formatting, and type checks.
  • The final loader suite passed all 67 tests. The diagnostic and invalid-rule assertions share one matrix, and changing either diagnostic phrase makes the retained assertions fail. The earlier revision passed all 385 policy tests on macOS and Linux ARM64.
  • All nine policy-headless.test.ts and user-policy.test.ts CLI tests passed on both platforms with recorded model responses. The two new cases failed against the unchanged implementation and passed five consecutive runs with retries disabled after the fix.
  • Packaged CLI installation, version, and help checks passed on macOS and Linux. Linux validation ran in an isolated Docker container.

The consolidated revision was revalidated on macOS; Linux checks cover the earlier revision. Windows and the Docker, Podman, and Seatbelt CLI sandbox modes were not tested. Integration tests used recorded responses rather than live model credentials.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@andreivince
andreivince requested review from a team as code owners September 20, 2026 23:50
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request improves the reliability of the TOML policy engine by introducing a filtering mechanism for invalid rule configurations. Previously, certain malformed rules could cause startup failures or unexpected behavior; this change ensures that invalid rules are identified and ignored while allowing valid policies to remain active. The update includes comprehensive test suites to validate these scenarios and updates documentation to reflect the new behavior.

Highlights

  • Robust TOML Policy Loading: Implemented a mechanism to track and skip invalid TOML policy rules and safety checkers during the loading process, preventing startup crashes caused by empty tool names or conflicting shell-command configurations.
  • Improved Fault Tolerance: Ensured that when specific rules are found to be invalid, the system continues to load valid sibling rules and policies from other files, preserving overall system functionality.
  • Comprehensive Regression Testing: Added extensive test coverage in both integration and unit tests to verify the handling of empty tool names, conflicting shell fields, and various edge cases in policy definitions.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added the size/m A medium sized PR label Sep 20, 2026
@google-cla

google-cla Bot commented Sep 20, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/L

  • Lines changed: 291
  • Additions: +233
  • Deletions: -58
  • Files changed: 4

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies the TOML policy loader in packages/core to skip individual invalid rules and safety checkers (such as those with empty tool names or invalid shell-command syntax) rather than failing the entire loading process. Valid sibling rules within the same file are now preserved and successfully loaded. The PR also updates the policy engine documentation to explain this behavior and adds comprehensive unit and integration tests to verify the new logic. As there are no review comments, I have no additional feedback to provide.

@gemini-cli

gemini-cli Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@github-actions github-actions Bot added the size/l A large sized PR label Sep 30, 2026
@andreivince

Copy link
Copy Markdown
Author

this one's for #29050 — invalid TOML policy rules were erroring out instead of being skipped. fix + tests are in. asked about the help wanted label on the issue a few days back, no word yet.

@gemini-cli

gemini-cli Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/l A large sized PR size/m A medium sized PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: invalid policy TOML rules are reported as errors but still loaded - empty toolName crashes startup

1 participant