Skip to content

feat(agentconfig): change-safety classification and wire types (3/15) - #471

Open
ccf-lisa[bot] wants to merge 2 commits into
lisa/agent-config/02-diff-envrefs-sourcesfrom
lisa/agent-config/03-classify
Open

ccf-lisa[bot] wants to merge 2 commits into
lisa/agent-config/02-diff-envrefs-sourcesfrom
lisa/agent-config/03-classify

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Part 3/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #470 (lisa/agent-config/02-diff-envrefs-sources). Review and merge in order.

What's in this layer

Third layer of the agent remote-configuration stack (split from #465): Classify/WillApply decide which overlay changes an agent applies under each remote_config mode (forbidden locked keys, unsafe new sources and re-enabled plugins, sources of enabled plugins already in use, trusted sources, overridable flags), plus the agent<->API wire types and FieldError.

Size: +934 -0 = 934 changed lines (without docs/go.sum).

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

Third layer of the agent remote-configuration stack (split from #465): Classify/WillApply decide which overlay changes an agent applies under each remote_config mode (forbidden locked keys, unsafe new sources and re-enabled plugins, sources of enabled plugins already in use, trusted sources, overridable flags), plus the agent<->API wire types and FieldError.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 926b4a9b-c1ec-48b1-baa9-005c4e772ad0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: REQUEST_CHANGES

1 Must-fix.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

Comment thread pkg/agentconfig/classify.go Outdated
…erences

Re-enabling a disabled plugin only checked its source, so its policy
entries and ${env:} references, which no enabled plugin uses, were
never classified and apply_safe could run an untrusted or local policy
the host had disabled. They are now classified like a new plugin's.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant