Goal
Keep the default user configuration of distinct explicitly named applications isolated.
Background and reproduction
Release review of 3253c10975ac674eb2e79c146bb7729d5c4cb251; reproduced on macOS arm64 with Python 3.13.15.
Both CliProfile.batteries_included and BatteriesIncludedConfigLoader call normalize_cli_name, which treats the identity as a program filename and removes its final dotted component. The public App identity and runtime namespaces preserve those components. As a result acme.tools, acme.deploy, and acme all read <config-root>/acme/config.yaml, even though they are distinct application identities with separate runtime directories. Space replacement and basename extraction introduce further collisions.
Harmless public-API reproduction:
from pathlib import Path
from tempfile import TemporaryDirectory
from base_cli import CliProfile
with TemporaryDirectory() as tmp:
root = Path(tmp)
(root / "acme").mkdir()
(root / "acme/config.yaml").write_text("service: shared-from-acme\n")
for name in ("acme.tools", "acme.deploy", "acme"):
profile = CliProfile.batteries_included(name, config_root=root)
print(name, profile.load_config(None, None).config)
All three print {'service': 'shared-from-acme'}. Direct loaders for the first two names also expose the same user_config_path. This can silently select another application's endpoints or settings.
local-config.md promises an isolated directory selected by the identity. The regression added for #313 only compares Alpha Tool and beta, so it misses identity collisions. This is a remaining isolation gap after #313, distinct from ancestor-project trust in #385.
Source: profile factory, loader, filename normalization.
Scope and acceptance criteria
Validation
Run the public reproducer, focused configuration/identity tests, generated documentation checks, strict typing, and tests/full_validate.sh.
Non-goals
No release publication, unrelated API redesign, or changes to consumer workspaces.
Project fields
- Status: Ready
- Priority: P2
- Area: Python
- Initiative: Adoption Polish
- Size: M
- Milestone: v0.5.0
Agent assignment
Assignee: @codeforester. Implement through the normal issue-backed worktree and reviewed PR workflow.
Goal
Keep the default user configuration of distinct explicitly named applications isolated.
Background and reproduction
Release review of
3253c10975ac674eb2e79c146bb7729d5c4cb251; reproduced on macOS arm64 with Python 3.13.15.Both
CliProfile.batteries_includedandBatteriesIncludedConfigLoadercallnormalize_cli_name, which treats the identity as a program filename and removes its final dotted component. The public App identity and runtime namespaces preserve those components. As a resultacme.tools,acme.deploy, andacmeall read<config-root>/acme/config.yaml, even though they are distinct application identities with separate runtime directories. Space replacement and basename extraction introduce further collisions.Harmless public-API reproduction:
All three print
{'service': 'shared-from-acme'}. Direct loaders for the first two names also expose the sameuser_config_path. This can silently select another application's endpoints or settings.local-config.md promises an isolated directory selected by the identity. The regression added for #313 only compares
Alpha Toolandbeta, so it misses identity collisions. This is a remaining isolation gap after #313, distinct from ancestor-project trust in #385.Source: profile factory, loader, filename normalization.
Scope and acceptance criteria
Validation
Run the public reproducer, focused configuration/identity tests, generated documentation checks, strict typing, and tests/full_validate.sh.
Non-goals
No release publication, unrelated API redesign, or changes to consumer workspaces.
Project fields
Agent assignment
Assignee: @codeforester. Implement through the normal issue-backed worktree and reviewed PR workflow.