Skip to content

fix: restore native OpenCode workflows - #471

Merged
sjungwon03 merged 1 commit into
mainfrom
fix/470-opencode-inline-images
Oct 6, 2026
Merged

sjungwon03 merged 1 commit into
mainfrom
fix/470-opencode-inline-images

Conversation

@sjungwon03

Copy link
Copy Markdown
Member

Closes #470

OpenCode 1.18.5 automatically sends X-Session-Id. The gateway's global OpenRouter header fallback introduced session_id into managed requests, where native transports rejected it before secret resolution; the client then retried 5xx. Scope header-only fallback to delegated routes after approved route resolution. Capture/validate the selected bounded value before awaits and preserve body presence: managed invokers omit only header-derived session_id, explicit native body identifiers still reject, and delegated exact forwarding/body precedence is unchanged. The header never controls authorization, route choice, limits or accounting identity. No native session equivalence or arbitrary header forwarding is introduced.

Extend isolated named-client conformance with a valid synthetic PNG, explicit fixture image modalities and omitted detail across delegated OpenRouter and managed OpenAI/Anthropic/Gemini on both bases. Image probes supply a fixed title and require exactly one unmodified image on every captured request, actual fixture.txt read execution, correlated result continuation, initial model/provider Deny, fresh follow-up Deny, native cancellation and private audit/usage. Retain environment/config/Git isolation, --pure, disabled external plugins/skills/config/model fetch, fixture-only tool permissions, bounded process lifetime/output and cleanup. The default command has 98 probes (existing fifty plus 48 image cases); final image-only rerun verifies the fixed-title/all-request assertions. No live inference is used.

Red/green: configuration regression first observed missing modalities; the minimal config extension passed. A new native OpenAI socket image case with X-Session-Id then reproduced 502 instead of 200 before production changes; the header-scope correction made it pass. Focused gateway/config/native/session/SDK suite passes 251 tests. Seventy-one new default-CI cases cover exact image payload assertions and all four route/base socket modes, native header success and explicit body rejection, early malformed-header rejection, async capture, authentication/IAM/limits, required audit/usage failures, upstream error and missing usage. Existing delegated body/header and SDK regressions remain green.

Full npm run check passes strict types, lint, 5553 tests with one existing PostgreSQL skip, planning/contracts/fixture scans and all three offline structural pins. npm run format and git diff --check pass. All three pinned JSON files are byte-identical to main. Update PRD, architecture, acceptance, session/image contracts, reproduction guide and the compatibility checkpoint (chat v31/24 selected request definitions plus query v2 and model response v1).

Material behavior change: valid header-only managed requests now proceed as ordinary native calls rather than failing before secrets. Explicit native body identifiers and selected overlong headers remain rejected. Native/live model image support, pixel/format limits, remote/detail/cache/output images, signed-image combinations, broader named-client versions/interactive behavior and complete #116 certification remain open. Jev #7 stays unresolved. Actual client results use only fixed mocked hosts and fixture keys; AI-assisted account review is not independent human certification.

Plan: 470-opencode-inline-images. Contract: opencode-inline-images.

Validation: full npm run check passes strict typing, lint, 5553 tests with one existing PostgreSQL skip, planning/contracts and offline schema integrity. Full #116 remains open.

Assisted-by: Codex

Refs: #470
Assisted-by: Codex
Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@github-actions
github-actions Bot requested a review from sjungwon03-ai October 6, 2026 05:19
@github-actions github-actions Bot added ai-review-requested Review requested from sjungwon03-ai type:bug Defect correction labels Oct 6, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the exact published head and its base diff, including shared gateway normalization/route dispatch, native/delegated invoker boundaries, client process isolation, image assertions, public regression tests and contracts. No blocking findings.

The body-presence marker is captured before route resolution. Only a validated header-derived session_id is omitted for a managed route; explicit native body preferences still reject, while delegated precedence/capture/forwarding and early malformed-header rejection are unchanged. Authentication, full IAM/Deny, limits, registered hosts, Jev and required audit/usage still govern invocation. No identifier is substituted into identity, attribution, metadata or cache fields.

The installed-client probes use valid synthetic PNG bytes, explicit image modalities, fixed image titles, fixed mocked native/delegated hosts and fixture keys. Require exactly one image per actual image request/continuation, completed read-tool correlation, fresh Deny and cancellation accounting. The environment allowlist, --pure, disabled external config/skills/plugins/model fetch, precise fixture-file permission, bounded output/deadline and cleanup remain intact. New assertion negatives and session security/failure regressions exercise public boundaries rather than duplicating production logic.

Verified red/green evidence, 251 focused tests, 5553 full-check passes with one existing PostgreSQL skip, installed-client baseline and final image probes, planning/contract integrity, unchanged three schema pins and both exact-head CI checks. Scope and behavior change are explicit in the issue/plan/PR; runtime image/native session mapping, authorization and schema scope are not widened. No dependency, migration, destructive action or provider secret is introduced.

Remaining risks are accurately recorded: mocked transport does not certify live vision/models, remote/detail/cache/output images, signed-image combinations, other client versions or general interactive retry behavior. Full #116 and unresolved #7 remain open. This is AI-assisted review under the user's account authorization, not independent human certification.

Reviewed by Codex operating as sjungwon03-ai, as explicitly authorized by the contributor. Assisted-by: Codex.

@sjungwon03
sjungwon03 merged commit 07eedf9 into main Oct 6, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-review-requested Review requested from sjungwon03-ai type:bug Defect correction

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: preserve native OpenCode image workflows with session headers

2 participants