Skip to content

test(opencode): validate isolated context-mode host dispatch - #122

Draft
xnoto wants to merge 6 commits into
mainfrom
test/opencode-context-runtime
Draft

xnoto wants to merge 6 commits into
mainfrom
test/opencode-context-runtime

Conversation

@xnoto

@xnoto xnoto commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Owner-approved, context-only diagnostic against the unchanged official OpenCode 1.18.29 image and context-mode@1.0.169. A local deterministic responder exercises real native tool dispatch; memory, production activation and paid inference remain out of scope.

Maintainer: makeitworkcloud / xnoto. Driving issue: N/A — owner-directed diagnostic.

Owner correction: the upstream requests #1232 and #1233 have been withdrawn and closed at the owner's request, and their existing author follow-ups withdrawn. No further upstream posting or engagement is requested by this investigation. They are not active remediation requests. This local diagnostic PR remains draft; no code or acceptance gate is changed by the retraction.

Keep draft/red. No failed acceptance gate is waived. Basic native tools and retained-HOME recall work; approval and scoping remain blockers. The denied-tool result is inconclusive, not a demonstrated deny bypass.

Type of change

  • CI / reusable workflow
  • Documentation
  • Packaged feature / image / GitOps desired state

Validation

  • Required pull-request checks pass — runtime failed, not waived.
  • No generated/centrally distributed files hand-edited; test-owned inputs only.

At head b28e621f8d9406a71ee5b6299cbdd700c9c0e22b, runtime CI 36807733689 passed syntax and all 16 unit tests. All 14 runtime cases executed: 10 passed, 4 failed, none unexecuted. Chart CI 36807733675 passed hygiene/Helm and detection; packaging/GitOps updater skipped. No local validation performed.

Verified passes include package identity/selected hashes, actual native index/search/schema rejection, separate plugin deny/ask policies, fail-closed security-module behavior, network controls, cleanup, and warm default recall across retained-HOME/fresh-config replacement. Read-only observations confirmed the positive source/marker in both content tables before and after replacement.

The earlier warm miss was a probe confound: the approval-negative test reused the positive source label, and its unexpectedly executed index replaced that source. Unique labels correct the probe, not the plugin.

Remaining failed gates:

  1. Native approval: a matching ctx_index call under ask completed and indexed its marker without pending approval. This is specific to the tested custom-plugin path, not every OpenCode tool.
  2. Cross-agent resume: a verified unconsumed snapshot's marker appeared in another agent's system messages in the same project.
  3. Project separation: project B returned the positive source label and known indexed-content phrase seeded in A; returned session directory was checked. This is synthetic retrieval evidence, not a real-user exfiltration claim. Full cause remains unestablished.
  4. Restricted denial: the tool was unadvertised and a matching target ToolPart ended in error with unavailable/invalid markers, but the precise denial predicate was not satisfied. Do not claim an executed denied tool or a proven wildcard-deny bypass.

The negative-only matcher recognizes supported invalid repair only with matching original call ID/target, emitted/unadvertised tool, unavailable-tool error and no side effect. Positive/approval cases never count it as successful target execution. No approval or isolation requirement was relaxed.

Architecture, code, security and delivery reviews found no unresolved Critical/High diagnostic-implementation blocker; QA covered the diagnostic delta. These do not clear runtime adoption. No verified released remedy was established by bounded upstream research.

Impact and rollout

Changed paths: .github/workflows/opencode-context-runtime.yml and .github/tests/opencode-context-runtime/{runtime.py,test_runtime.py,broken-security.mjs,README.md}. Producer/maintainer: charts / xnoto; sole consumer: this PR-only hosted-Ubuntu workflow.

No chart content/version, image build/push, generated GitOps pin, cluster resource, Secret, PVC or running-service change. Closed #120/images #58 and older #113 are untouched. No Node/PVC redesign, gcompat preload, custom production bridge, embedding service or paid provider account is introduced.

Supported direct-root and adapter-parent storage overrides are aligned under the same disposable retained HOME without moving OpenCode's configuration overlay. Publication, selection, reconciliation and deployed validation remain separate owner decisions. No merge or activation is authorized by these tests; withdrawing the upstream requests does not waive the runtime gates.

Safety and secrets

  • No production credentials, decrypted SOPS, state, kubeconfigs, private endpoints or real prompts; API marker and dataset are public synthetic fixtures.
  • No local OpenTofu operations run or claimed.
  • Ownership, effects, rollback limits and remaining gates described.

The app is non-root/read-only with dropped capabilities, no-new-privileges, bounded resources and no published ports. CHOWN-only preparation touches fresh test volume mountpoints. No production storage, host credentials or Docker socket is mounted into the app.

Cold package downloads precede dispatch; the ordinary bridge is removed and internal-only connectivity asserted. Only synthetic context SQLite databases are inspected. Output is selected enums/booleans, not raw prompts/configuration/logs or authentication stores.

Residual Medium supply-chain limit: selected installed-file verification follows installation and transitive dependencies remain nonhermetic. No full dependency, credential isolation, multiuser privacy, Kubernetes/PVC recovery, HA, ARM, full interpreter support or real-model inference-quality assurance follows.

AI-assisted implementation and supplied-material specialist reviews.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Chart CI passed

Repository hygiene and Helm validation passed. View the workflow run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant