Skip to content

feat(config): add YAML safety mode defaults - #3860

Merged
dgageot merged 1 commit into
mainfrom
feat/3837-yaml-safety-defaults
Jul 28, 2026
Merged

dgageot merged 1 commit into
mainfrom
feat/3837-yaml-safety-defaults

Conversation

@Sayt-0

@Sayt-0 Sayt-0 commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add declarative safety defaults to team runtime, individual agents, user settings, and aliases
  • enforce CLI, user-owned, author-owned, and persisted-session precedence without weakening user preferences
  • preserve legacy YOLO/yolo behavior and validate canonical YAML values
  • update the schema, documentation, example configuration, sandbox forwarding, and session/API coverage

Closes #3837

Precedence

Priority Source
1 explicit --safety
2 explicit --yolo
3 alias safety or legacy yolo
4 settings.safety or legacy settings.YOLO
5 selected agents.<name>.safety
6 runtime.safety
7 historical unset behavior

At the same scope, safety wins over the legacy boolean alias. Resumed sessions keep their persisted mode unless an explicit CLI override is supplied.

Acceptance criteria

Expectation Implementation
Team-wide default runtime.safety is propagated through the loaded team
Per-agent override the initially selected agent's safety wins over the runtime default
User-wide protection settings and alias defaults outrank local, URL, and OCI author configuration
CLI precedence explicit flag state is tracked independently from defaults
Resume behavior only explicit CLI safety flags replace persisted state
Agent/session inheritance switches, handoffs, spawned sessions, and delegated sessions preserve or inherit the effective mode
Compatibility settings.YOLO, alias yolo, and --yolo remain autonomous aliases
Validation only strict, balanced, and autonomous are accepted in new YAML fields
Schema and docs schema, CLI/config docs, headless guidance, and safety example are updated
Tests precedence, validation, selection, resume, API, sandbox, and persistence paths are covered

Validation

  • env -u HTTP_PROXY -u HTTPS_PROXY -u http_proxy -u https_proxy go test ./...
  • go test -race -count=1 ./pkg/server -run 'TestAuthorSafetyDefault|TestSessionManager_SetSessionAgentModel'
  • golangci-lint run
  • go run ./lint .
  • go build ./...
  • go mod tidy -diff
  • jq empty agent-schema.json
  • npx --yes markdownlint-cli2@0.22.1
  • ./scripts/docs-check-canonical.sh
  • ./scripts/docs-check-llms-txt.sh

Known limitation

An API session created without a safety choice receives author defaults when its first run starts. If the server restarts before that first run, it retains the conservative historical unset behavior rather than being re-defaulted later.

@Sayt-0
Sayt-0 requested a review from a team as a code owner July 28, 2026 13:36
@aheritier aheritier added area/config For configuration parsing, YAML, environment variables area/core Core agent runtime, session management area/docs Documentation changes area/runtime Runtime engine, agent loop execution, tool dispatch, loop detection area/sessions For features/issues/fixes related to session lifecycle (resume, persistence, export) kind/feat PR adds a new feature (maps to feat:). Use on PRs only. labels Jul 28, 2026
@dgageot
dgageot merged commit aaf8bbd into main Jul 28, 2026
20 checks passed
@dgageot
dgageot deleted the feat/3837-yaml-safety-defaults branch July 28, 2026 15:18
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
docker-agent 1.119.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>This release introduces first-class plan management with a new CLI command group and TUI browser, adds YAML safety mode defaults, and includes several bug fixes for runtime stability and structured output handling.

## What's New

- Adds `docker agent plans` CLI command group and a host-facing plan service package for managing plans from outside the agent runtime
- Adds a `/plans` browser, detail view, and action dialogs to the TUI for interactive plan management
- Adds YAML safety mode defaults to team runtime, individual agents, user settings, and aliases, with declarative precedence rules
- Adds an `Active agents only` option in TUI settings to filter the sidebar to agents participating in the current session
- Logs a warning when Docker Desktop serves an expired token to the models gateway

## Bug Fixes

- Fixes runtime re-entry loop when a content-only turn ends with a bare EOF and no `finish_reason` from the provider
- Fixes structured output handling for Claude models served through OpenAI-compatible endpoints by reinforcing schema constraints in system instructions
- Fixes evaluation budget termination outcomes so `budget_exceeded` results are preserved correctly across transcripts, SQLite, and session JSON
- Hardens host plan management and stabilizes asynchronous TUI workflows for plans
- Fixes atomic file replacement on Windows to allow plan storage reads during open file operations

## Technical Changes

- Exports `ValidateName`, `CorruptPlanError`, `SharedStorage`, and `ChangeNotifier` from the plan package
- Adds `PlanChangedEvent` emission on shared plan mutations in the runtime
- Centralizes plan editor handling in the TUI
- Adds plan storage testing on Windows as a CI gate
- Adds documentation for the Provider Credentials section in eval containers, clarifying `GITHUB_TOKEN` forwarding behavior
---

## What's Changed
* docs: update CHANGELOG.md for v1.118.0 by @docker-read-write[bot] in docker/docker-agent#3861
* fix(openai): reinforce structured output for Claude proxies by @Sayt-0 in docker/docker-agent#3863
* feat(config): add YAML safety mode defaults by @Sayt-0 in docker/docker-agent#3860
* fix(eval): preserve budget termination outcomes by @Sayt-0 in docker/docker-agent#3862
* docs: explain GITHUB_TOKEN forwarding for eval containers by @priyanka25aug in docker/docker-agent#3857
* feat: add first-class host UX for plan management (#3844) by @Sayt-0 in docker/docker-agent#3853
* feat(tui): filter sidebar to active agents by @Sayt-0 in docker/docker-agent#3864
* fix(plans): address review follow-ups from #3853 by @Sayt-0 in docker/docker-agent#3865
* fix(runtime): stop content-only turns that end with a bare EOF (no `finish_reason`) by @awschmeder in docker/docker-agent#3669
* feat(desktop): log when Docker Desktop serves an expired token by @trungutt in docker/docker-agent#3867

## New Contributors
* @priyanka25aug made their first contribution in docker/docker-agent#3857
* @awschmeder made their first contribution in docker/docker-agent#3669

**Full Changelog**: docker/docker-agent@v1.118.0...v1.119.0
</pre>
  <p>View the full release notes at <a href="https://github.com/docker/docker-agent/releases/tag/v1.119.0">https://github.com/docker/docker-agent/releases/tag/v1.119.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!15464
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/config For configuration parsing, YAML, environment variables area/core Core agent runtime, session management area/docs Documentation changes area/runtime Runtime engine, agent loop execution, tool dispatch, loop detection area/sessions For features/issues/fixes related to session lifecycle (resume, persistence, export) kind/feat PR adds a new feature (maps to feat:). Use on PRs only.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: allow safety mode defaults to be configured in YAML

4 participants