chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(opencode): sync fork dev with upstream v1.17.13 - #19

Merged
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13
Jul 7, 2026
Merged

chore(opencode): sync fork dev with upstream v1.17.13#19
shoootyou merged 621 commits into
devfrom
fork/sync-v1-17-13

Conversation

@shoootyou

Copy link
Copy Markdown
Owner

Summary

Syncs dev with upstream/dev (anomalyco/opencode) through the last stable released tag v1.17.13, via a true merge (git merge --no-ff, not rebase) — preserving the fork's own commit history and identities.

  • 613 upstream commits merged, already stabilized across public releases v1.17.5 → v1.17.13.
  • 93 additional unreleased/experimental upstream/dev commits (post-v1.17.13, kit/*, worktree-*, effect-*, draft/* branches) are explicitly excluded — not merged, not in scope.
  • Merge base: fe2e4e21d (fork's divergence point at v1.17.4). Fork's 36 pre-existing commits remain intact and reachable in git log.

Conflict reconciliation (7 points)

The merge surfaced 28 conflicts: 17 trivial i18n conflicts (resolved by concatenating non-overlapping translation blocks) and 11 non-trivial conflicts across 7 reconciliation points, fully specified ahead of implementation in spec-reconciliation.md (workspace planning tree, plan 123-opencode-fork-sync-v1-17-13 — evidence, contracts, pseudocode, and verdict per point, sourced from direct git show reads against dev, v1.17.13, and the merge-base).

  1. Login / server-sdk.tsx — upstream's structural refactor (createServerSdkContextBase, event coalescing) prevails; fork's isUnauthorizedSseError + redirectToLogin/shouldRedirectToLogin call-sites reinjected at the same structural points.
  2. Auth / @opencode-ai/protocol — upstream's authorizationLayer architecture (incl. PTY ticket bypass) prevails; fork's bare-401 behavior (no www-authenticate header) preserved. PTY bypass regex confirmed to correctly match the fork's real mounted /api/pty/*/connect routes. Formal RFC: 025-adopt-protocol-auth-contracts.
  3. Skills escaping (xmlEscape vs escapeHtml) — upstream's escapeHtml adopted as the single implementation, applied to all 3 fields (name/description/location-as-URL).
  4. Path-traversal guard in discovery.ts (both packages/opencode/ and packages/core/ copies) — upstream's atomic staging/versioning flow prevails; fork's isSafeName/isSafeFilePath boundary checks extended to all 3 path-construction points (root in both branches, staging in the new versioned branch). See audit section below — this was the subject of the round-1 CRITICAL finding.
  5. Archive/unarchive vs. MenuV2 — upstream's dual MenuV2/DropdownMenu structure (flag-gated rollout) prevails; fork's archive/unarchive toggle duplicated into both branches of the <Show> (no git conflict flagged this one — required manual reconciliation).
  6. PWA index.html theming — fork's colors/theme-color win (not upstream v2's tokens), since newLayoutDesignsDefault is hardcoded false on the prod channel. Remaining PWA improvements from both sides merged via direct union.
  7. Commands/events + projector.ts — upstream's LegacyEvent.CommandExecuted + revert.messageID coercion prevails; fork's Event.CatalogUpdated, lazy skill-as-command registration, and 5 null-coercion fixes in sessionRow() preserved.

Audit cycle

Per the workspace's mandatory quality gate, 2 audit rounds (Sho + Ei) ran before this push was authorized:

  • Round 1: 1 critical remediated, 1 high remediated, 1 critical scoped out (see note below), several medium/low/nit all resolved (none carried to backlog).
    • CRITICAL (Ei) — remediated: path-traversal boundary-check bypass in discovery.ts via skill.name: ".". Fixed in e74e1f213, covered by new tests in ca130c6ec. Ei re-verified with edge-case coverage and empirical reproduction of the pre-fix bug.
    • HIGH (Sho) — remediated: ptyConnectAuthorizationLayer had no dedicated test. Test added in httpapi-instance-route-auth.test.ts.
  • Round 2: Ei → approve (zero new critical/high). Sho → COMMENT/approved (zero new findings). Gate passed — stopped early per the "clean round" rule; round 3 (of the 2-round cap) not needed.

Artifacts: .yui-soul/reviews/123-opencode-fork-sync-v1-17-13/{r1.md, r1-sho-p2p5-tests.md, r2-sho-p2p5-tests.md, r2-ei-discovery.md}.

⚠️ Known follow-up required: PR #17 (fork/skill-hot-reload)

This sync will produce conflicts for the currently-open fork/skill-hot-reloaddev PR (#17) once this PR merges. Audit round 1 confirmed the merged dev here has genuine content conflicts against PR #17 in:

  • packages/core/src/skill.ts
  • packages/core/src/filesystem/watcher.ts

Upstream migrated SkillV2LayerNode in the same region PR #17 modifies. This is a known, explicitly scoped-out finding (Decision D11 in the plan) — intentionally not resolved in this PR. A separate follow-up plan is required to rebase fork/skill-hot-reload against the new dev tip and reconcile the SkillV2/LayerNode conflict in both files.

Not in this PR

  • No merge performed. This PR is opened for review only — merging into dev is a separate, explicitly-gated step requiring additional human authorization (including the squash-vs-merge-commit decision).
  • dev (local and origin/dev) is untouched by this push — verified at 19e6bbc4c24c140654d762cd050a408489a3b0d6 before and after.

Plan: 123-opencode-fork-sync-v1-17-13

Co-authored-by: yui-soul 284271367+yui-soul@users.noreply.github.com

opencode-agentBotand others added 30 commits June 25, 2026 18:36
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Test <test@opencode.test>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
…o#34020)
Co-authored-by: Luke Parker <10430890+Hona@users.noreply.github.com>
Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com>
opencode-agentBotand others added 27 commits July 1, 2026 01:44
Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
Co-authored-by: Brendan Allan <git@brendonovich.dev>
# Conflicts:
#	packages/app/index.html
#	packages/app/src/context/server-sdk.test.ts
#	packages/app/src/context/server-sdk.tsx
#	packages/app/src/i18n/ar.ts
#	packages/app/src/i18n/br.ts
#	packages/app/src/i18n/bs.ts
#	packages/app/src/i18n/da.ts
#	packages/app/src/i18n/de.ts
#	packages/app/src/i18n/es.ts
#	packages/app/src/i18n/fr.ts
#	packages/app/src/i18n/ja.ts
#	packages/app/src/i18n/ko.ts
#	packages/app/src/i18n/no.ts
#	packages/app/src/i18n/pl.ts
#	packages/app/src/i18n/ru.ts
#	packages/app/src/i18n/th.ts
#	packages/app/src/i18n/tr.ts
#	packages/app/src/i18n/uk.ts
#	packages/app/src/i18n/zh.ts
#	packages/app/src/i18n/zht.ts
#	packages/app/src/pages/session/timeline/message-timeline.tsx
#	packages/core/src/session/projector.ts
#	packages/opencode/src/command/index.ts
#	packages/opencode/src/server/routes/instance/httpapi/server.ts
#	packages/opencode/src/skill/discovery.ts
#	packages/opencode/src/skill/index.ts
#	packages/opencode/src/tool/skill.ts
#	packages/opencode/test/server/httpapi-ui.test.ts
#	packages/opencode/test/tool/task.test.ts
#	packages/server/src/middleware/authorization.ts
Corrige 4 gaps reales encontrados por Shin (E2) tras el merge de
v1.17.13, consecuencia del refactor upstream de LayerNode y no
arreglos nuevos de feature.
- server.ts: elimina import duplicado de Workspace (lineas 13 y 70),
probable artefacto de merge automatico que conservo ambos hunks.
Corrige TS2300: Duplicate identifier 'Workspace'.
- 5 archivos de test del fork migrados del patron viejo .layer/
.defaultLayer al nuevo LayerNode.compile(...)/AppNodeBuilder.build(...)
que trajo upstream para Skill, FSUtil, Global, CrossSpawnSpawner,
Database, EventV2Bridge, Storage, SessionProjector y BackgroundJob:
- test/skill-hot-reload.test.ts
- test/tool/reload-skills.test.ts
- src/server/shared/ui.test.ts
- test/command/catalog-event.test.ts
- test/server/session-list-archived.test.ts
- EventV2Bridge: aggregateEvents() ya no existe en Interface, se
reemplaza por durable(); se retiran sync()/beforeCommit() de los
mocks, tambien removidos de la interfaz.
Verificado: bun typecheck limpio en packages/opencode y
packages/server (sin TS2300); bun test en verde en los 5 archivos
corregidos (36 pass, 0 fail).
Fuera de scope (documentado, no tocado): tsconfig de packages/app sin
bun-types, cobertura de MenuV2 en Punto 5, fallos de
effect-flock/flock y tool.write por sandbox root.
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
Co-authored-by: yui-soul <yui-soul@users.noreply.github.com>
…ry checks
isSafeName/isSafeFilePath did not reject the literal "." segment, and the
three resolved-boundary checks in discovery.ts treated exact equality with
the base directory (root === resolvedCache, dest === resolvedRoot, dest ===
resolvedStaging) as safe. Since path.join(cache, ".") normalizes to exactly
cache, a remote skill.name: "." defeated the boundary check at all three
construction points (root fast-path, root slow-path swap, staging
slow-path), allowing a malicious index.json to write files into arbitrary
sibling skill directories or destroy the entire shared skills cache during
a versioned refresh.
- isSafeName/isSafeFilePath now explicitly reject name/file === "."
- Removes the "x !== base" exception from all three boundary checks; exact
equality with the base directory is never a safe write target
- Exports isSafeName/isSafeFilePath for unit testing
Found by Ei in audit round 1 of plan 123-opencode-fork-sync-v1-17-13.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
…mmand basedir, discovery name-guard units)
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
The v1.17.13 upstream merge (613 commits) grew the main app bundle
past Workbox's default 2 MiB precache limit (reported at 2.68 MB),
causing OPENCODE_CHANNEL=prod builds to fail during PWA precaching.
Raise maximumFileSizeToCacheInBytes to 6 MiB to cover the current
bundle with headroom for reasonable future growth.
Co-authored-by: yui-soul <284271367+yui-soul@users.noreply.github.com>
@shoootyou
shoootyou merged commit 1835983 into devJul 7, 2026
@shoootyou
shoootyou deleted the fork/sync-v1-17-13 branch July 7, 2026 23:46
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

20 participants

@shoootyou@Brendonovich@rekram1-node@kitlangton@usrnk1@vimtor@Hona@nexxeln@arvsrn@ariane-emory@adamdotdevin@Slickstef11@thdxr@affanali2k3@fwang@jlongster@OpeOginni@BenGu3@neriousy@MaxAnderson95