Repository navigation
fix: align @microsoft/agent-governance-opencode plugin with the actual OpenCode plugin contract - #2993
Conversation
…al code was never called. Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de>
…ned in the original PR Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de>
|
Welcome to the Agent Governance Toolkit! Thanks for your first pull request. |
|
❔ Contributor Check: UNKNOWN
Automated check by AGT Contributor Check. |
🤖 AI Agent: contributor-guide — Actionable Items:
Welcome, and thank you for contributing! Great job on aligning the plugin with the OpenCode contract and providing detailed explanations in the PR description. Actionable Items:
For guidance, please refer to CONTRIBUTING.md. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
@microsoft-github-policy-service agree company="bluehands" |
Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de>
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
The core contract realignment is correct and well-reasoned. I verified the claims against the official OpenCode plugin contract (the `@opencode-ai/plugin` Hooks type): hooks are flat string keys (`session.created`, `event`, `tool.execute.before`/`after`), `session.start` and `tool.execute.error` are not real, custom tools belong under the singular `tool` key returning a plain value (not an MCP envelope), and `message.part.updated` with `part.type === "text"` is the correct text-bearing event. The old broad `chat|message|prompt|user` regex matched event types that do not exist. Fail-closed deny/redaction logic is preserved, and the tests are updated to the new shape with good new coverage. Nice work.
Two must-fix items before merge:
-
package-lock.json leaks fork identity. `agent-governance-opencode/package-lock.json` lines 2 and 8 now read `"name": "@ax0l0tl/agent-governance-opencode"` / `"version": "4.0.4"`, while package.json is `@microsoft/agent-governance-opencode` v4.1.0. This looks like an accidental commit of a local `npm install` under your fork name. Please regenerate the lockfile so it reads `@microsoft/agent-governance-opencode` at 4.1.0.
-
Docs describe removed hooks. README.md (around lines 50, 56), docs/packages/opencode-governance.md (around 31, 35), and the JSDoc at src/index.mjs:20 (`event (chat.params/start)`) still document `session.start` / `tool.execute.error` and the old event description. Update them to the new hook set so the docs match the code.
Should-address (non-blocking, can be follow-ups):
- The OpenCode `tool()` contract expects `args` to be a Zod schema, but src/index.mjs:145,154 pass a raw object. Your live smoke test suggests OpenCode tolerates it, but please confirm and ideally add a test exercising registration.
- The removed `tool.execute.error` hook was dead code (never fired), but it was the documented audit path for failed tool calls; that audit coverage is now simply gone. Worth a note or a real replacement.
- Deny currently throws inside the `event` handler which hangs the TUI rather than surfacing the block. The contract's `permission.ask` hook is the correct mechanism for review/deny; consider a follow-up so prompt-level governance is cleanly usable.
Happy to re-review quickly once the lockfile and docs are fixed.
|
Thanks for the update, but both original blockers are still open: 1. package-lock.json fork identity -- To fix: delete 2. Docs for removed hooks -- The inline comment added in the latest commit is a good code note but doesn't address either blocker. |
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Contract alignment with OpenCode 1.17.4 looks correct. Approving.
|
/ok-to-test |
28753fb
into
microsoft:main
…l OpenCode plugin contract (microsoft#2993) * Fix open code plugin. Adapt to real open code plugin contract, original code was never called. Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de> * Remove opencode-ai/plugin dependency because it was explicitly mentioned in the original PR Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de> * - revert temporary changes to package.json * comment about throwing in event handler Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de> --------- Signed-off-by: Alexander Wiedemann <wiedemann@bluehands.de> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
|
Validated follow-up work from the contract alignment in this PR:
Linking these here so the runtime correction, remaining documentation drift, and operational follow-ups stay connected without reopening this merged PR. |
Description
Aligns the @microsoft/agent-governance-opencode plugin with the OpenCode plugin contract as shipped in the current OpenCode release (1.17.4).
The hook and tool registration shapes are corrected to match the real OpenCode plugin contract (flat string keys, singular
tool:, plain string returns from custom tools). The prompt event filter is narrowed tomessage.part.updatedwithpart.type === "text", which is the only event type that carries user-submitted text (smoked tested via live event log). The other event types handled, do not exist.The plugin is not really working well, because, if user or agent prompt messages are denied, the exception thrown in the event handler causes the OpenCode user interaction to hang (cursor blinking, never returns), but at least now it does anything.
Type of Change
Package(s) Affected
agent-governance-opencode(@microsoft/agent-governance-opencode)Checklist
node --checkpasses on all.mjsfiles)npm run check: 25/25)Attribution & Prior Art
AI Assistance
OpenCode (AI coding agent) was used to investigate the real OpenCode plugin contract, identify the mismatches, implement the fixes, and verify via in-session smoke tests of both
agt_policy_statusandagt_policy_check_text.IP, Patents, and Licensing
Related Issues
Related: #2658 (original plugin PR)