Skip to content

feat(agentconfig): change-safety classification and wire types (3/15) - #471

Merged
gusfcarvalho merged 3 commits into
lisa/agent-config/02-diff-envrefs-sourcesfrom
lisa/agent-config/03-classify
Oct 6, 2026
Merged

gusfcarvalho merged 3 commits into
lisa/agent-config/02-diff-envrefs-sourcesfrom
lisa/agent-config/03-classify

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 3/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #470 (lisa/agent-config/02-diff-envrefs-sources). Review and merge in order.

What's in this layer

Third layer of the agent remote-configuration stack (split from #465): Classify/WillApply decide which overlay changes an agent applies under each remote_config mode (forbidden locked keys, unsafe new sources and re-enabled plugins, sources of enabled plugins already in use, trusted sources, overridable flags), plus the agent<->API wire types and FieldError.

Size: +1055 -0 = 1055 changed lines (without docs/go.sum).

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 8d9f4afa-dcd6-406b-8410-f7bd720468e5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: REQUEST_CHANGES

1 Must-fix.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

Comment thread pkg/agentconfig/classify.go Outdated

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

ccf-lisa Bot and others added 3 commits October 6, 2026 08:37
Third layer of the agent remote-configuration stack (split from #465): Classify/WillApply decide which overlay changes an agent applies under each remote_config mode (forbidden locked keys, unsafe new sources and re-enabled plugins, sources of enabled plugins already in use, trusted sources, overridable flags), plus the agent<->API wire types and FieldError.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…erences

Re-enabling a disabled plugin only checked its source, so its policy
entries and ${env:} references, which no enabled plugin uses, were
never classified and apply_safe could run an untrusted or local policy
the host had disabled. They are now classified like a new plugin's.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…new one

Re-enabling a plugin the base disables only checked trusted_sources, so a
local-path source was just unsafe/reenables-plugin and apply_all applied it
even with allow_local_sources=false. Run the kept local source through the
source rules too: forbidden/local-source-not-allowed unless apply_all with
allow_local_sources (then unsafe/new-local-source).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config/03-classify branch from 26bfc21 to 4a5babf Compare October 6, 2026 13:06

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

@gusfcarvalho
gusfcarvalho merged commit bb9391d into main Oct 6, 2026
9 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config/03-classify branch October 6, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant