Goal
isolate YAML aliases when merging configuration layers.
Background and evidence
Release-preparation review of 7d8e7d7e902ace88495c5e0ff3b9db4f4a7bf5d2 on macOS arm64. Python 3.13.15, Click 8.5.0, Typer 0.27.2.
A project override of left.nested.value also changes right.nested.value when the user layer uses a YAML alias, although no right-side override exists. Provenance continues to report the right-side value as user. This can silently change an unrelated endpoint or policy setting.
Minimal reproduction from the repository root with PyYAML installed:
from pathlib import Path
from tempfile import TemporaryDirectory
from base_cli.config import BatteriesIncludedConfigLoader
with TemporaryDirectory() as d:
root = Path(d)
user, project = root / "user", root / "project"
user.mkdir(); project.mkdir()
(user / "config.yaml").write_text(
"left: &common\n nested:\n value: user\nright: *common\n"
)
(project / ".base-cli.yaml").write_text("left:\n nested:\n value: project\n")
result = BatteriesIncludedConfigLoader(user_config_dir=user).load(project, None)
print(result.config)
print(dict(result.provenance))
Actual: both values are project, while right.nested.value provenance is user. Expected: left is project, right remains user. _merge_mapping_validated copies only the first mapping level; deeper shared mappings remain aliased and a subsequent recursive merge mutates both paths.
The existing shared-alias test checks initial insertion only and never overlays one branch.
Scope and acceptance criteria
- Preserve independent effective values for aliased mapping paths when a later layer overrides one path.
- Keep provenance consistent with every effective leaf.
- Preserve accepted acyclic aliases, while retaining cycle/depth/node limits.
- Add nested shared-alias overlay tests, including defaults/user/project/explicit layers and caller-owned input immutability.
Validation
Run focused batteries-included configuration tests, then ./tests/full_validate.sh.
Source references:
Non-goals
No release publication or unrelated API redesign. Preserve documented compatibility except for the defective behavior identified above.
Project fields
- Project:
base-cli
- Status:
Ready
- Priority:
P2
- Area:
Runtime
- Initiative:
v1.0 Readiness
- Size:
M
- Milestone:
v1.0.0
Agent assignment
Assignee: @codeforester. Implementation may be handled through the normal issue-backed worktree and reviewed PR workflow.
Goal
isolate YAML aliases when merging configuration layers.
Background and evidence
Release-preparation review of
7d8e7d7e902ace88495c5e0ff3b9db4f4a7bf5d2on macOS arm64. Python 3.13.15, Click 8.5.0, Typer 0.27.2.A project override of
left.nested.valuealso changesright.nested.valuewhen the user layer uses a YAML alias, although no right-side override exists. Provenance continues to report the right-side value asuser. This can silently change an unrelated endpoint or policy setting.Minimal reproduction from the repository root with PyYAML installed:
Actual: both values are
project, whileright.nested.valueprovenance isuser. Expected: left isproject, right remainsuser._merge_mapping_validatedcopies only the first mapping level; deeper shared mappings remain aliased and a subsequent recursive merge mutates both paths.The existing shared-alias test checks initial insertion only and never overlays one branch.
Scope and acceptance criteria
Validation
Run focused batteries-included configuration tests, then
./tests/full_validate.sh.Source references:
Non-goals
No release publication or unrelated API redesign. Preserve documented compatibility except for the defective behavior identified above.
Project fields
base-cliReadyP2Runtimev1.0 ReadinessMv1.0.0Agent assignment
Assignee: @codeforester. Implementation may be handled through the normal issue-backed worktree and reviewed PR workflow.