Conversation
Chart CI passedRepository hygiene and Helm validation passed. View the workflow run. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Owner-approved, context-only diagnostic against the unchanged official OpenCode 1.18.29 image and
context-mode@1.0.169. A local deterministic responder exercises real native tool dispatch; memory, production activation and paid inference remain out of scope.Maintainer: makeitworkcloud / xnoto. Driving issue: N/A — owner-directed diagnostic.
Owner correction: the upstream requests #1232 and #1233 have been withdrawn and closed at the owner's request, and their existing author follow-ups withdrawn. No further upstream posting or engagement is requested by this investigation. They are not active remediation requests. This local diagnostic PR remains draft; no code or acceptance gate is changed by the retraction.
Keep draft/red. No failed acceptance gate is waived. Basic native tools and retained-HOME recall work; approval and scoping remain blockers. The denied-tool result is inconclusive, not a demonstrated deny bypass.
Type of change
Validation
At head
b28e621f8d9406a71ee5b6299cbdd700c9c0e22b, runtime CI 36807733689 passed syntax and all 16 unit tests. All 14 runtime cases executed: 10 passed, 4 failed, none unexecuted. Chart CI 36807733675 passed hygiene/Helm and detection; packaging/GitOps updater skipped. No local validation performed.Verified passes include package identity/selected hashes, actual native index/search/schema rejection, separate plugin deny/ask policies, fail-closed security-module behavior, network controls, cleanup, and warm default recall across retained-HOME/fresh-config replacement. Read-only observations confirmed the positive source/marker in both content tables before and after replacement.
The earlier warm miss was a probe confound: the approval-negative test reused the positive source label, and its unexpectedly executed index replaced that source. Unique labels correct the probe, not the plugin.
Remaining failed gates:
ctx_indexcall underaskcompleted and indexed its marker without pending approval. This is specific to the tested custom-plugin path, not every OpenCode tool.The negative-only matcher recognizes supported
invalidrepair only with matching original call ID/target, emitted/unadvertised tool, unavailable-tool error and no side effect. Positive/approval cases never count it as successful target execution. No approval or isolation requirement was relaxed.Architecture, code, security and delivery reviews found no unresolved Critical/High diagnostic-implementation blocker; QA covered the diagnostic delta. These do not clear runtime adoption. No verified released remedy was established by bounded upstream research.
Impact and rollout
Changed paths:
.github/workflows/opencode-context-runtime.ymland.github/tests/opencode-context-runtime/{runtime.py,test_runtime.py,broken-security.mjs,README.md}. Producer/maintainer: charts / xnoto; sole consumer: this PR-only hosted-Ubuntu workflow.No chart content/version, image build/push, generated GitOps pin, cluster resource, Secret, PVC or running-service change. Closed #120/images #58 and older #113 are untouched. No Node/PVC redesign, gcompat preload, custom production bridge, embedding service or paid provider account is introduced.
Supported direct-root and adapter-parent storage overrides are aligned under the same disposable retained HOME without moving OpenCode's configuration overlay. Publication, selection, reconciliation and deployed validation remain separate owner decisions. No merge or activation is authorized by these tests; withdrawing the upstream requests does not waive the runtime gates.
Safety and secrets
The app is non-root/read-only with dropped capabilities, no-new-privileges, bounded resources and no published ports. CHOWN-only preparation touches fresh test volume mountpoints. No production storage, host credentials or Docker socket is mounted into the app.
Cold package downloads precede dispatch; the ordinary bridge is removed and internal-only connectivity asserted. Only synthetic context SQLite databases are inspected. Output is selected enums/booleans, not raw prompts/configuration/logs or authentication stores.
Residual Medium supply-chain limit: selected installed-file verification follows installation and transitive dependencies remain nonhermetic. No full dependency, credential isolation, multiuser privacy, Kubernetes/PVC recovery, HA, ARM, full interpreter support or real-model inference-quality assurance follows.
AI-assisted implementation and supplied-material specialist reviews.