Skip to content

refactor(a2a-server): implement V1 to V2 settings migration logic - #29450

Merged
DavidAPierce merged 10 commits into
google-gemini:mainfrom
jvargassanchez-dot:b_561555622
Sep 29, 2026
Merged

DavidAPierce merged 10 commits into
google-gemini:mainfrom
jvargassanchez-dot:b_561555622

Conversation

@jvargassanchez-dot

@jvargassanchez-dot jvargassanchez-dot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This change updates the configuration loader in packages/a2a-server
(src/config/settings.ts and src/config/config.ts) to support the
hierarchical V2 configuration schema while preserving transparent in-memory
backward compatibility with flat V1 settings files.

From an architectural perspective, this unifies the configuration processing
pipeline between @google/gemini-cli and @google/gemini-cli-a2a-server by
introducing in-memory key normalization (migrateDeprecatedSettings), recursive
multi-scope object merging (customDeepMerge), recursive environment variable
interpolation (resolveEnvVarsInObject), and deterministic schema validation
(validateSettings / settingsZodSchema).

Details

  • In-Memory V1-to-V2 Configuration Normalization
    (migrateDeprecatedSettings)
    :
    • Mapped legacy flat V1 configuration keys (MIGRATION_MAP) and inverted
      boolean flags (such as telemetryDisabled $\rightarrow$
      telemetry.enabled, logLevel $\rightarrow$ logging.level, coreTools
      $\rightarrow$ tools.core, excludeTools $\rightarrow$ tools.exclude,
      allowedTools $\rightarrow$ tools.allowed, folderTrust $\rightarrow$
      security.folderTrust.enabled, showMemoryUsage $\rightarrow$
      ui.showMemoryUsage, checkpointing $\rightarrow$ general.checkpointing,
      and fileFiltering $\rightarrow$ context.fileFiltering) into their
      corresponding V2 nested structure in memory without modifying user
      configuration files on disk.
    • Added non-enumerable compatibility accessors on the resolved Settings
      object and updated loadConfig / setIsTrusted in
      packages/a2a-server/src/config/config.ts to read canonical V2 paths with
      fallback support.
  • Recursive Multi-Scope Merging (customDeepMerge):
    • Replaced shallow top-level object spreading
      ({ ...userSettings, ...workspaceSettings }) with customDeepMerge so
      workspace-scoped nested settings merge cleanly with user-scoped nested
      settings without discarding sibling properties.
    • Filtered reserved object prototype keys (__proto__, constructor,
      prototype) during recursive merging and environment resolution to ensure
      deterministic object construction.
  • Recursive Environment Variable Interpolation (resolveEnvVarsInObject):
    • Updated resolveEnvVarsInString and resolveEnvVarsInObject to support
      $VAR, ${VAR}, and ${VAR:-default} syntax across nested V2 objects and
      arrays with WeakSet circular-reference tracking.
  • Deterministic V2 Schema Validation (validateSettings /
    settingsZodSchema)
    :
    • Added Zod schema validation (settingsZodSchema) for V2 configuration
      sections and validated normalized settings during configuration loading.
  • Unit Test Coverage:
    • Added automated unit tests in
      packages/a2a-server/src/config/settings.test.ts,
      packages/a2a-server/src/config/config.test.ts, and
      packages/a2a-server/src/http/app.test.ts verifying V1-to-V2 in-memory
      conversion and Zod schema validation, V2 structure preservation and deep
      merging across scopes, reserved key filtering in customDeepMerge, nested
      environment variable interpolation, and V1/V2 settings handling in
      loadConfig, setIsTrusted, and createApp.

Related Issues

fixes: GH-28261

How to Validate

  1. Run the targeted unit test suites added for V1-to-V2 settings migration, config loading, and HTTP server bootstrap:
    ```bash
    npm test -w @google/gemini-cli-a2a-server -- src/config/settings.test.ts src/config/config.test.ts src/http/app.test.ts

• Expected result: All 3 test files (63/63 tests) pass, verifying:
• src/config/settings.test.ts (12/12 tests):
• 100% legacy V1 flat settings (telemetryDisabled, logLevel, coreTools, excludeTools, allowedTools, folderTrust,
showMemoryUsage, checkpointing, fileFiltering) are migrated in memory to V2 nested properties (telemetry.enabled,
logging.level, tools.*, security.folderTrust.enabled, ui.showMemoryUsage, general.checkpointing, context.fileFiltering)
without modifying settings.json on disk, and pass Zod V2 schema validation (validateSettings).
• 100% V2 nested settings preserve their structure and deep-merge across User and Workspace scopes via customDeepMerge
without overwriting sibling properties.
• Edge cases: customDeepMerge and resolveEnvVarsInObject filter out proto, constructor, and prototype keys
(prototype pollution protection), handle circular references via WeakSet, and recursively interpolate $VAR, ${VAR}, and
${VAR:-default} across nested objects and arrays.
• src/config/config.test.ts (30/30 tests):
• loadConfig() and setIsTrusted() read canonical V2 settings (security.folderTrust.enabled, general.checkpointing.
enabled, ui.showMemoryUsage, context.fileFiltering, logging.level) while maintaining fallback support for unmigrated V1
objects and preserving environment variable overrides (GEMINI_FOLDER_TRUST, CHECKPOINTING, CUSTOM_IGNORE_FILE_PATHS,
GEMINI_CLI_TRUST_WORKSPACE).
• src/http/app.test.ts (21/21 tests):
• createApp() reads V2 security.folderTrust.enabled from loadSettings() during initial HTTP server startup.
2. Run the full @google/gemini-cli-a2a-server package test suite and repository preflight:
npm test -w @google/gemini-cli-a2a-server
npm run preflight

  • Expected result: All 16/16 test files (164/164 tests) in @google/gemini-cli-a2a-server and the full workspace preflight
  (clean, install, build, lint, typecheck, and all workspace test suites) pass with 0 errors.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • [ x] Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • [ x] Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • [ x] Linux
      • [ x] npm run
      • npx
      • Docker

Unify configuration loading in @google/gemini-cli-a2a-server with the V2 hierarchical settings schema while preserving transparent in-memory backward compatibility for legacy V1 settings files.

- Add migrateDeprecatedSettings() and legacy compatibility getters in settings.ts to map flat V1 keys and inverted boolean flags into V2 nested paths in memory without mutating files on disk.
- Replace shallow user/workspace scope spread with customDeepMerge() with prototype pollution filtering.
- Support recursive environment variable interpolation ($VAR, ${VAR}, ${VAR:-default}) with circular reference protection.
- Add Zod V2 schema validation (settingsZodSchema / validateSettings).
- Update loadConfig(), setIsTrusted(), and createApp() to read canonical V2 settings paths with legacy fallback.
- Add unit tests covering V1-to-V2 migration, V2 deep merging, prototype pollution protection, env var resolution, and server bootstrap.

Fixes google-gemini#28261
@jvargassanchez-dot
jvargassanchez-dot requested a review from a team as a code owner September 22, 2026 20:54
@github-actions github-actions Bot added the size/xl An extra large PR label Sep 22, 2026
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/XL

  • Lines changed: 1489
  • Additions: +1394
  • Deletions: -95
  • Files changed: 6

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request refactors the configuration management system in a2a-server to support a hierarchical V2 schema. By implementing a robust migration pipeline, the changes ensure transparent backward compatibility with existing flat V1 settings. The update improves the reliability of configuration loading through deep merging, recursive environment variable resolution, and strict schema validation, while maintaining existing functionality for end-users.

Highlights

  • V1 to V2 Migration: Implemented in-memory migration logic to map legacy flat V1 configuration keys to the new hierarchical V2 structure without modifying disk files.
  • Configuration Merging: Introduced customDeepMerge to handle nested object merging across user and workspace scopes, preventing data loss during configuration resolution.
  • Schema Validation: Integrated Zod schema validation to ensure configuration integrity and deterministic object construction.
  • Environment Variable Interpolation: Added support for recursive environment variable interpolation ($VAR, ${VAR}, ${VAR:-default}) within nested configuration objects.
  • Backward Compatibility: Added non-enumerable compatibility accessors to the resolved settings object, allowing legacy code to access V2 properties using V1 keys.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces full compatibility with the V2 nested settings structure in packages/a2a-server. It implements robust migration logic (migrateDeprecatedSettings), legacy compatibility getters (attachLegacyCompatibilityGetters), a prototype-pollution-safe deep merge utility (customDeepMerge), and Zod-based schema validation for configuration settings. Additionally, environment variable resolution is enhanced to support default values and circular reference detection. The feedback recommends removing the backward-compatibility fallback logic for deprecated root-level properties like folderTrust in favor of directly using the canonical V2 paths with safe defaults, ensuring strict adherence to the interface contract.

Comment thread packages/a2a-server/src/config/config.ts Outdated
Comment thread packages/a2a-server/src/http/app.ts Outdated
@jvargassanchez-dot

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces support for the V2 nested settings structure in the a2a-server package, implementing a migration path from legacy V1 flat settings, Zod-based validation, and deep merging capabilities. The changes update configuration loading, workspace trust checks, and associated tests to align with the new hierarchical settings schema. The review feedback highlights two important robustness improvements: refining the isPlainObject helper to prevent non-plain objects (such as Date or RegExp) from being incorrectly merged, and using this helper within resolveEnvVarsInObjectInternal to avoid stripping prototypes of non-plain objects during environment variable resolution.

Comment thread packages/a2a-server/src/config/settings.ts
Comment thread packages/a2a-server/src/config/settings.ts
@jvargassanchez-dot

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements full compatibility with the V2 nested settings structure in packages/a2a-server. It introduces a Zod schema (settingsZodSchema) for validation, migration logic (migrateDeprecatedSettings) to transition legacy V1 flat settings to V2 hierarchical paths, and a secure deep merge utility (customDeepMerge) with prototype pollution protection. Additionally, it updates configuration loading, environment variable resolution, and workspace trust checks to align with the new schema, accompanied by comprehensive unit and integration tests. There are no review comments, and I have no feedback to provide.

@gemini-cli gemini-cli Bot added priority/p1 Important and should be addressed in the near term. area/non-interactive Issues related to GitHub Actions, SDK, 3P Integrations, Shell Scripting, Command line automation and removed status/need-issue Pull requests that need to have an associated issue. labels Sep 25, 2026
@DavidAPierce
DavidAPierce added this pull request to the merge queue Sep 29, 2026
Merged via the queue into google-gemini:main with commit c88b0a6 Sep 29, 2026
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/non-interactive Issues related to GitHub Actions, SDK, 3P Integrations, Shell Scripting, Command line automation priority/p1 Important and should be addressed in the near term. size/xl An extra large PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

refactor(a2a-server): implement V1 to V2 settings migration logic

2 participants