Repository navigation
fix: restore native OpenCode workflows - #471
Conversation
Refs: #470 Assisted-by: Codex Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Reviewed the exact published head and its base diff, including shared gateway normalization/route dispatch, native/delegated invoker boundaries, client process isolation, image assertions, public regression tests and contracts. No blocking findings.
The body-presence marker is captured before route resolution. Only a validated header-derived session_id is omitted for a managed route; explicit native body preferences still reject, while delegated precedence/capture/forwarding and early malformed-header rejection are unchanged. Authentication, full IAM/Deny, limits, registered hosts, Jev and required audit/usage still govern invocation. No identifier is substituted into identity, attribution, metadata or cache fields.
The installed-client probes use valid synthetic PNG bytes, explicit image modalities, fixed image titles, fixed mocked native/delegated hosts and fixture keys. Require exactly one image per actual image request/continuation, completed read-tool correlation, fresh Deny and cancellation accounting. The environment allowlist, --pure, disabled external config/skills/plugins/model fetch, precise fixture-file permission, bounded output/deadline and cleanup remain intact. New assertion negatives and session security/failure regressions exercise public boundaries rather than duplicating production logic.
Verified red/green evidence, 251 focused tests, 5553 full-check passes with one existing PostgreSQL skip, installed-client baseline and final image probes, planning/contract integrity, unchanged three schema pins and both exact-head CI checks. Scope and behavior change are explicit in the issue/plan/PR; runtime image/native session mapping, authorization and schema scope are not widened. No dependency, migration, destructive action or provider secret is introduced.
Remaining risks are accurately recorded: mocked transport does not certify live vision/models, remote/detail/cache/output images, signed-image combinations, other client versions or general interactive retry behavior. Full #116 and unresolved #7 remain open. This is AI-assisted review under the user's account authorization, not independent human certification.
Reviewed by Codex operating as sjungwon03-ai, as explicitly authorized by the contributor. Assisted-by: Codex.
Closes #470
OpenCode 1.18.5 automatically sends X-Session-Id. The gateway's global OpenRouter header fallback introduced session_id into managed requests, where native transports rejected it before secret resolution; the client then retried 5xx. Scope header-only fallback to delegated routes after approved route resolution. Capture/validate the selected bounded value before awaits and preserve body presence: managed invokers omit only header-derived session_id, explicit native body identifiers still reject, and delegated exact forwarding/body precedence is unchanged. The header never controls authorization, route choice, limits or accounting identity. No native session equivalence or arbitrary header forwarding is introduced.
Extend isolated named-client conformance with a valid synthetic PNG, explicit fixture image modalities and omitted detail across delegated OpenRouter and managed OpenAI/Anthropic/Gemini on both bases. Image probes supply a fixed title and require exactly one unmodified image on every captured request, actual fixture.txt read execution, correlated result continuation, initial model/provider Deny, fresh follow-up Deny, native cancellation and private audit/usage. Retain environment/config/Git isolation, --pure, disabled external plugins/skills/config/model fetch, fixture-only tool permissions, bounded process lifetime/output and cleanup. The default command has 98 probes (existing fifty plus 48 image cases); final image-only rerun verifies the fixed-title/all-request assertions. No live inference is used.
Red/green: configuration regression first observed missing modalities; the minimal config extension passed. A new native OpenAI socket image case with X-Session-Id then reproduced 502 instead of 200 before production changes; the header-scope correction made it pass. Focused gateway/config/native/session/SDK suite passes 251 tests. Seventy-one new default-CI cases cover exact image payload assertions and all four route/base socket modes, native header success and explicit body rejection, early malformed-header rejection, async capture, authentication/IAM/limits, required audit/usage failures, upstream error and missing usage. Existing delegated body/header and SDK regressions remain green.
Full npm run check passes strict types, lint, 5553 tests with one existing PostgreSQL skip, planning/contracts/fixture scans and all three offline structural pins. npm run format and git diff --check pass. All three pinned JSON files are byte-identical to main. Update PRD, architecture, acceptance, session/image contracts, reproduction guide and the compatibility checkpoint (chat v31/24 selected request definitions plus query v2 and model response v1).
Material behavior change: valid header-only managed requests now proceed as ordinary native calls rather than failing before secrets. Explicit native body identifiers and selected overlong headers remain rejected. Native/live model image support, pixel/format limits, remote/detail/cache/output images, signed-image combinations, broader named-client versions/interactive behavior and complete #116 certification remain open. Jev #7 stays unresolved. Actual client results use only fixed mocked hosts and fixture keys; AI-assisted account review is not independent human certification.
Plan: 470-opencode-inline-images. Contract: opencode-inline-images.
Validation: full npm run check passes strict typing, lint, 5553 tests with one existing PostgreSQL skip, planning/contracts and offline schema integrity. Full #116 remains open.
Assisted-by: Codex