Skip to content

fix(opencode): read usage from each instance data directory - #17759

Open
fixfon wants to merge 2 commits into
pingdotgg:mainfrom
fixfon:fix/opencode-instance-usage-roots
Open

fixfon wants to merge 2 commits into
pingdotgg:mainfrom
fixfon:fix/opencode-instance-usage-roots

Conversation

@fixfon

@fixfon fixfon commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Problem

OpenCode usage scans received configured provider instances but resolved data directories from the host environment once. History from instances with their own OPENCODE_DATA_DIR or XDG_DATA_HOME was omitted.

Change

Resolve roots from each instance's already merged environment, then deduplicate canonical paths across all instances before scanning. Preserve the existing comma-separated override precedence, home expansion, XDG fallback, and history reader.

Fixes #17631.

Scope and approval

#17631 was filed by maintainer Julius and specifies per-instance root resolution, canonical deduplication, and a two-instance regression test. This PR implements that scope in the OpenCode scanner and focused provider/service usage tests. The portable alias regression extends the existing service-test junction fixture; it adds no diagnostic suppression.

Verification

macOS, Node 24.21.0; synthetic temporary SQLite stores, no live provider history.

  • Before the fix, the distinct-instance history regression failed because the scanner returned the unrelated host root. The default compatibility cases passed. The alias test also fails when only cross-instance root deduplication is disabled: it receives two scanner sources instead of one, before aggregation.
  • After the fix, the two instance stores both contribute distinct messages (200 combined input tokens); aliases yield one canonical source and one record. Absolute, relative, and absent XDG_DATA_HOME default cases pass. The existing SQLite/WAL and legacy migration test passes.
  • node node_modules/vite-plus/bin/vp test run packages/provider-opencode/src/server/usage.test.ts apps/server/src/usage/UsageService.test.ts — 33 tests passed across two files, independently rerun after commit.
  • node node_modules/typescript/bin/tsc --noEmit -p packages/provider-opencode/tsconfig.json and node node_modules/typescript/bin/tsc --noEmit -p apps/server/tsconfig.json — exit 0; existing Effect suggestions elsewhere, no errors.
  • node node_modules/vite-plus/bin/vp lint packages/provider-opencode/src/server/usage.ts packages/provider-opencode/src/server/usage.test.ts apps/server/src/usage/UsageService.test.ts and the equivalent vp fmt --check — passed. git diff --check passed.

The local Vite+ entry point was invoked with Node 24 directly because the global installation wrapper selected a different runtime. Windows was not executed; the alias fixture uses a directory junction for Windows compatibility.

Implemented with GPT-6.1-Sol through Codex desktop; reviewed independently through Codex.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 10, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at d2990e8

Macroscope's review found this PR approvable — This is a localized OpenCode usage-reading fix that resolves each configured instance’s data directory and deduplicates aliases, with focused regression tests and no schema, deployment, default-setting, or diagnostic-suppression changes.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9a6931c5-1077-40d4-b644-c17acaf8411d

📥 Commits

Reviewing files that changed from the base of the PR and between d2990e8 and 2aea70d.


📒 Files selected for processing (3)
  • apps/server/src/usage/UsageService.test.ts
  • packages/provider-opencode/src/server/usage.test.ts
  • packages/provider-opencode/src/server/usage.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.



📝 Walkthrough

Walkthrough

The OpenCode usage reader now resolves history directories from each provider instance’s environment. It combines and deduplicates the roots before scanning. Tests cover per-instance overrides, directory aliases, default-directory fallback, and usage aggregation.

Changes

OpenCode usage scanning

Layer / File(s) Summary
Resolve and scan per-instance data roots
packages/provider-opencode/src/server/usage.ts, packages/provider-opencode/src/server/usage.test.ts, apps/server/src/usage/UsageService.test.ts
The scan resolves roots from each instance’s environment and deduplicates directories before scanning. Tests cover environment overrides, aliases, default-directory behavior, and aggregated OpenCode usage.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge


Merge Risk | ⚪ Minimal · up to 2aea7

Merge Risk: ⚪ Minimal · up to 2aea7

The per-instance directory change is ready to merge after normal checks; no actionable issue is established.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 2aea7

The scanner now reads history locations configured for each OpenCode instance. Existing provider-management permissions and authenticated usage access remain enforced, and history scans remain read-only. No material security risk was identified in the changed behavior.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The changed read scope is the union of configured OpenCode history roots accessible to the server process, including histories from disabled instances. Scanning recognizes OpenCode database filenames and legacy message files rather than exposing a general file-read API.

Security Findings and Attack Paths

  • inferred — The investigated path requires provider-management authority to select additional roots and diagnostics-read authority to request usage. It does not establish an introduced privilege escalation: provider management already controls the OpenCode executable and process environment, while usage requests cannot directly nominate paths.

Trust Boundaries and Controls

  • observed — WebSocket connections are authenticated before per-session RPC authorization is installed. Provider-instance updates require providers:manage through both supported update forms, and usage-summary reads require diagnostics:read. These enforcement paths are unchanged by the PR.

Resilience and Maintainability Implications

  • observed — Root and record deduplication state is local to each invocation. Database connections remain read-only with extensions disabled and scoped close finalizers. Handled read failures produce partial status rather than modifying provider history, so repetition or interruption introduces no new persistent cleanup obligation.

Pre-merge checks | Passed 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description check Passed The description covers the problem, implementation, scope, linked issue, focused verification, test results, limitations, and agent attribution. It is complete enough for review.
Title check Passed The title is concise, specific, and accurately describes the main change: reading OpenCode usage from each instance data directory.
Linked Issues check Passed Issue #17631 requires per-instance root resolution, canonical-path deduplication, and a two-instance regression test. openCodeUsageReader.scan resolves roots from each instance.environment and add…
Out of Scope Changes check Passed The changes are limited to the OpenCode usage reader and focused provider and usage-service tests. The service test uses an aliased OpenCode root to verify the required cross-instance canonical dedupl…

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@fixfon

fixfon commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Addressed the new diagnostic-suppression concern in d2990e8 by reusing the existing junction fixture in UsageService.test.ts. The cumulative PR now adds no diagnostic suppression or native filesystem import.

That fixture directly calls the public OpenCode usage reader with two instance environments and asserts one canonical scanner source before aggregation. Disabling only cross-instance root deduplication makes this assertion fail (two sources instead of one), so service-level record deduplication cannot hide duplicate scans. The distinct-root and default regressions remain in the provider tests. Production behavior is unchanged from the previous head.

Independently reran the final focused suites: 33/33 tests pass. Both affected-package typechecks and three-file lint/format pass. Updated the PR body and linked issue evidence to this final coverage. A scoped independent code re-review found the suppression concern addressed and no new findings.

@fixfon

fixfon commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

@macroscope-app please re-run the approvability check on the current head (d2990e8). The "Not approved" verdict above was posted at 07:54 UTC for 72458d8, before d2990e8 moved the alias regression onto the existing junction fixture in UsageService.test.ts. The current cumulative diff adds no diagnostic suppression.

@macroscopeapp

macroscopeapp Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Sorry, I'm unable to act on this request because you do not have permissions within this repository.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 11, 2026 — with ChatGPT Codex Connector
@fixfon
fixfon force-pushed the fix/opencode-instance-usage-roots branch from d2990e8 to 2aea70d Compare October 11, 2026 12:02

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Usage: OpenCode history ignores each instance's XDG_DATA_HOME / OPENCODE_DATA_DIR

2 participants