Skip to content

bug: preserve distinct application identities in default configuration directories #425

Description

@codeforester

Goal

Keep the default user configuration of distinct explicitly named applications isolated.

Background and reproduction

Release review of 3253c10975ac674eb2e79c146bb7729d5c4cb251; reproduced on macOS arm64 with Python 3.13.15.

Both CliProfile.batteries_included and BatteriesIncludedConfigLoader call normalize_cli_name, which treats the identity as a program filename and removes its final dotted component. The public App identity and runtime namespaces preserve those components. As a result acme.tools, acme.deploy, and acme all read <config-root>/acme/config.yaml, even though they are distinct application identities with separate runtime directories. Space replacement and basename extraction introduce further collisions.

Harmless public-API reproduction:

from pathlib import Path
from tempfile import TemporaryDirectory
from base_cli import CliProfile

with TemporaryDirectory() as tmp:
    root = Path(tmp)
    (root / "acme").mkdir()
    (root / "acme/config.yaml").write_text("service: shared-from-acme\n")
    for name in ("acme.tools", "acme.deploy", "acme"):
        profile = CliProfile.batteries_included(name, config_root=root)
        print(name, profile.load_config(None, None).config)

All three print {'service': 'shared-from-acme'}. Direct loaders for the first two names also expose the same user_config_path. This can silently select another application's endpoints or settings.

local-config.md promises an isolated directory selected by the identity. The regression added for #313 only compares Alpha Tool and beta, so it misses identity collisions. This is a remaining isolation gap after #313, distinct from ancestor-project trust in #385.

Source: profile factory, loader, filename normalization.

Scope and acceptance criteria

  • Use an explicit-identity namespace policy in both public entry points that preserves distinct supported identities and cannot escape the config root. Reuse the runtime namespace policy where appropriate.
  • Cover dotted names, space/hyphen collisions, unsafe path characters, and ordinary existing names through loader and profile APIs.
  • Keep explicit user_config_dir authoritative, including intentional sharing.
  • Document the resulting path contract and compatibility/migration treatment; do not silently merge or automatically move existing config directories.

Validation

Run the public reproducer, focused configuration/identity tests, generated documentation checks, strict typing, and tests/full_validate.sh.

Non-goals

No release publication, unrelated API redesign, or changes to consumer workspaces.

Project fields

  • Status: Ready
  • Priority: P2
  • Area: Python
  • Initiative: Adoption Polish
  • Size: M
  • Milestone: v0.5.0

Agent assignment

Assignee: @codeforester. Implement through the normal issue-backed worktree and reviewed PR workflow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething is not working

Type

Projects

  • Status
    Ready

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions