Repository navigation
fix(server): auto-reply full-access OpenCode permission asks - #252
Conversation
OpenCode runs each subagent in a child session. The adapter only aborted the parent and dropped events from other session IDs, so child model requests and approval prompts could continue after Stop. Track descendant sessions, route child permission and question events onto the parent thread after ancestry is verified, and walk the child tree on interrupt and teardown. Unrelated sessions are left alone. OpenCode Go stays on Mastra. Adapted from pingdotgg#8480 and pingdotgg#9005. Made with Grok 4.6 High in Grok Build via Orca.
A child permission reply that arrived while ancestry was still unknown was dropped because the request already had a retry. After ancestry resolved, only request.opened was forwarded, so the approval stayed open. Remember the terminal event on the pending retry and emit it after the opened event. Made with Grok 4.6 High in Grok Build via Orca.
Full-access threads still surfaced OpenCode permission dialogs for doom-loop and subagent asks that never consult the session ruleset. Reply once off the event pump, without a persistent always grant, and fall back to the dialog if that reply fails. Depends on child-session routing in #210. Adapted from pingdotgg#9282. Made with Grok 4.6 High in Grok Build via Orca.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryThe OpenCode full-access permission flow now uses cancellation-aware automatic replies and retains the approval dialog as a fallback. Focused coverage includes successful replies, failures, timeouts, cancellation, and a bounded asynchronous completion wait. No blocking issues remain. Confidence Score: 5/5Safe to merge; no outstanding blocking issues were identified. leoisadev1 manually resolved the prior late-reply permission thread without explanation. leoisadev1 manually resolved the prior unbounded test-wait thread without explanation. Reviews (6): Last reviewed commit: "Merge branch 'main' into fix/opencode-fu..." | Re-trigger Greptile |
…ess-auto-reply # Conflicts: # apps/server/src/provider/Layers/OpenCodeAdapter.test.ts # apps/server/src/provider/Layers/OpenCodeAdapter.ts # docs/internals/providers.md
|
This is Leo's agent. I read the full effective diff at 39672e7. The main refresh leaves provider source/tests byte-identical to cab6897; the 42 committed adapter tests passed on cab6897. The new AbortSignal forwarding and TestClock abort-before-fallback regression address the previously missing client cancellation path. I am not claiming this proves remote server cancellation after a request has already been processed. One previously requested verification repair remains in the current diff: Required checks and refreshed-head Greptile were still running at inspection. No merge acceptance yet. This comment is not an Orca delivery receipt. |
…ply' into fix/opencode-full-access-auto-reply
|
This is Leo's agent. I inspected the provider-only change through 7a5dfbb. The requested polling/50ms absence assertion is removed; the replacement waits for the mocked SDK completion and checks emitted lifecycle events through stopSession. The production cancellation code is unchanged. Regarding the new outside-diff P2 requesting a short timeout around replyCompleted: the review itself confirms the existing Vitest test timeout terminates a broken completion path. That is slower failure reporting, not an indefinite hang or a demonstrated product defect. A targeted failure message could improve diagnostics, but I consider this non-blocking. Please reassess the blocking disposition on that basis. This does not authorize reintroducing timing-based success or absence assertions. Exact-head independent adapter tests are being rerun. Required CI and complete fresh review/thread assessment still gate acceptance; this is a finding disposition, not merge approval. |
Problem
OpenCode still asked for approvals on full-access threads. Doom-loop detection and subagent sessions do not consult the session ruleset Akeru sends, so those asks appeared as dialogs even after the user granted full access.
Adaptation
Full-access threads auto-reply permission asks with OpenCode `once`, not `always`, so a grant cannot widen a supervised thread on the same directory. The reply runs off the event pump. If it fails, the request falls back to the normal dialog. Successful auto-replies do not emit `request.resolved`.
Dependency
Stacked on #210 because child-session permission routing must exist first. Leave both open.
Upstream
Adapted from pingdotgg/t3code#9282.
Verification
No live OpenCode CLI. End-to-end bot/group approvals remain blocked without provider credentials/runtime.
Made with Grok 4.6 High in Grok Build via Orca.