Skip to content

bug: isolate YAML aliases when merging configuration layers #407

Description

@codeforester

Goal

isolate YAML aliases when merging configuration layers.

Background and evidence

Release-preparation review of 7d8e7d7e902ace88495c5e0ff3b9db4f4a7bf5d2 on macOS arm64. Python 3.13.15, Click 8.5.0, Typer 0.27.2.

A project override of left.nested.value also changes right.nested.value when the user layer uses a YAML alias, although no right-side override exists. Provenance continues to report the right-side value as user. This can silently change an unrelated endpoint or policy setting.

Minimal reproduction from the repository root with PyYAML installed:

from pathlib import Path
from tempfile import TemporaryDirectory
from base_cli.config import BatteriesIncludedConfigLoader

with TemporaryDirectory() as d:
    root = Path(d)
    user, project = root / "user", root / "project"
    user.mkdir(); project.mkdir()
    (user / "config.yaml").write_text(
        "left: &common\n  nested:\n    value: user\nright: *common\n"
    )
    (project / ".base-cli.yaml").write_text("left:\n  nested:\n    value: project\n")
    result = BatteriesIncludedConfigLoader(user_config_dir=user).load(project, None)
    print(result.config)
    print(dict(result.provenance))

Actual: both values are project, while right.nested.value provenance is user. Expected: left is project, right remains user. _merge_mapping_validated copies only the first mapping level; deeper shared mappings remain aliased and a subsequent recursive merge mutates both paths.

The existing shared-alias test checks initial insertion only and never overlays one branch.

Scope and acceptance criteria

  • Preserve independent effective values for aliased mapping paths when a later layer overrides one path.
  • Keep provenance consistent with every effective leaf.
  • Preserve accepted acyclic aliases, while retaining cycle/depth/node limits.
  • Add nested shared-alias overlay tests, including defaults/user/project/explicit layers and caller-owned input immutability.

Validation

Run focused batteries-included configuration tests, then ./tests/full_validate.sh.

Source references:

Non-goals

No release publication or unrelated API redesign. Preserve documented compatibility except for the defective behavior identified above.

Project fields

  • Project: base-cli
  • Status: Ready
  • Priority: P2
  • Area: Runtime
  • Initiative: v1.0 Readiness
  • Size: M
  • Milestone: v1.0.0

Agent assignment

Assignee: @codeforester. Implementation may be handled through the normal issue-backed worktree and reviewed PR workflow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething is not working

Type

No type

Projects

  • Status
    Ready

Relationships

None yet

Development

No branches or pull requests

Issue actions