Dashboard › opencode › Distillation
11f27283-70a2-490e-ab98-335fb3cb1aeb["lore_tm_v1_OD7zXIq8puwaguT9I8crqD73rOh2e6PpaZRv_moZLuE","lore_tm_v1_YB-bbJEkFtaqh167_Cg7_S6VyC-bauaKvEPMBDYhTVc","lore_tm_v1_bvX6o7UVPklyoGGCO7riA9SLJSfS7OJOmqAP49I2H9Q","lore_tm_v1_009D6fxQcxYqaKU86NLjcHRlp5ce_Jjb_bdo63B8bJw","lore_tm_v1_hwM9c7Bnz0FZ-74hSVLIv-9oDzfmJyEOLGtqgYhXcx4"]
Date: Sep 8, 2026
bin/opencode-pty-supervisor = ff03df72fc6a401e8070db776ceba524e9111d9d907c6f4939244354564a86f2 (replacing previously reported supervisor hash); bin/opencode-pty-launcher = d833c859476f021565e8f425e6ee51353909060fa5f64ce629fb07d3411987dd; bin/opencode-pty-client = fb8739d98ff7882782005e04ef731b6120e8daf0719e606362a1fe620adc2cde./usr/local/libexec/opencode-pty-supervisor for opencode-pty-supervisor.service and /usr/local/libexec/opencode-pty-verify-readiness for opencode-v2.service. Result counters were verify=1 security=0./usr/local/libexec, every parent directory, and all three PTY binaries must be root-owned and never writable by byk or a group; the Node SEA service must use the reviewed fixed helper path and be unable to replace it.SCM_RIGHTS descriptor, then exits; reviewed Go runtime metadata reads such as /sys/kernel/mm/transparent_hugepage/hpage_pmd_size are allowed only when observed on the exact Go/runtime build.ptrace, /proc descriptor access, process control, inheritance, or descriptor delegation must not allow another process to impersonate the MainPID, obtain/inherit its connected socket, or delegate work through an inherited descriptor; any unblocked same-UID delegation path blocks deployment.ptrace isolation, target-host systemd properties, and independent reviews remain deployment blockers until performed on the final artifacts.supervisor/ROOT-ACCEPTANCE.md requires two reproducible builds of all three binaries using CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags=-buildid=, matching both build sets and recording the content-bound source revision, Go version, dependency sums, complete commands, and SHA-256 hashes.supervisor/ROOT-ACCEPTANCE.md requires disposable-VM testing of reviewed service and slice candidates as root-owned mode 0644, systemd-analyze verify on installed files, and D-Bus inspection of every transient property, rejecting unknown, ignored, or weakened directives without altering production units.bun /tmp/opencode/pty-plugin-smoke.ts exactly 10 times with the reviewed harness outside the auto-discovered plugin directory, then against the freshly built helper and an isolated disposable supervisor. Required checks cover permissions, source identity, ownership, deletion, in-flight deletion, reservations, JSON envelopes, regex bounds, UTF-8 write bounds, pre-listener output bounds, saturated STOP bounds, transport framing, helper transfer, notifications, timeouts, and cleanup.review-source-hash from the unchanged source tree must equal the pty-source:sha256 embedded in verify-readiness.0755 supervisor/verify-readiness must be installed at /usr/local/libexec/opencode-pty-verify-readiness. Only after all reviews and target-host checks pass may root create /etc/opencode/pty-supervisor-verified as a root-owned mode-0644 regular file./etc/opencode/pty-supervisor-verified must contain exactly 4 newline-terminated lines in fixed order: 1. revision=opencode-v2-pilot:git:<reviewed-40-hex-commit>;pty-source:sha256:<reviewed-source-manifest-hash> exactly as embedded in verify-readiness; 2. standard sha256sum record for /usr/local/libexec/opencode-pty-supervisor; 3. standard record for /usr/local/libexec/opencode-pty-launcher; 4. standard record for /usr/local/libexec/opencode-pty-client. Duplicate or trailing lines are invalid, and arbitrary revision hex, absent/symlinked/empty/stale/writable/wrong-owner/wrong-mode markers, or hash/source-manifest mismatches cannot grant readiness.supervisor/PROTOCOL.md specifies one Unix SOCK_STREAM connection per PTY, retained by the Node SEA process and authenticated by the supervisor using immutable peer credentials against the exact opencode-v2.service MainPID.fchdir(2), replaces stderr with stdout, accepts only canonical a[A-Za-z0-9_-]* URL-safe unpadded base64 arguments, clears the environment, binds its reviewed executable to fd 3, and passes bounded encoded argv through one temporary environment value./usr/bin/script -q -e -f -c "/bin/sh -i -c 'exec /proc/self/fd/3 --exec'" /dev/null; the inner launcher decodes argv, clears the temporary value, restores the fixed environment, closes fd 3, and directly calls execve with the original argv vector. The design states that command arguments are not evaluated as shell syntax and retain argv boundaries.packages/core/src/plugin/host.ts, packages/core/test/plugin.test.ts, packages/core/test/plugin/fixture.ts, packages/core/test/plugin/host.ts, packages/plugin/src/effect/permission.ts, packages/plugin/src/promise/adapter.ts, and packages/plugin/src/promise/permission.ts. Untracked directories were packages/cli/dist-v2-pilot-final/, packages/cli/dist-v2-pilot-next/, and packages/cli/dist-v2-pilot/.packages/core/src/plugin/host.ts 1 added line; packages/core/test/plugin.test.ts 102 lines changed; packages/core/test/plugin/fixture.ts 114 lines changed; packages/core/test/plugin/host.ts 1 added line; packages/plugin/src/effect/permission.ts 12 added lines; packages/plugin/src/promise/adapter.ts 41 lines changed; and packages/plugin/src/promise/permission.ts 11 added lines. Current commit was 2ac698d65a feat(ai): add Moonshot provider (#47851)./home/byk/.local/share/opencode-v2-pilot/supervisor/internal/supervisor/systemd_test.go lines 93β111 define TestClientIdentityUsesRealSystemdInterfaces: decodeClientIdentity accepts ActiveState, SubState, and a 16-byte InvocationID from the Unit properties plus MainPID=42 and ControlGroup=expectedClientCgroup from Service properties, while rejecting ControlGroup supplied through the Unit interface.TestSystemd255IntrospectionPlacesPropertiesOnExactInterfaces in systemd_test.go lines 113β142 queries dbus.service; it requires Unit properties ActiveState, SubState, and InvocationID, Service properties MainPID and ControlGroup, and rejects unexpected exposure of ControlGroup through Unit.TestForgedUnitRemovedSignalCannotProveCleanup in systemd_test.go lines 144β164 injects a forged org.freedesktop.systemd1.Manager.UnitRemoved signal from sender :1.999 for opencode-pty-0123456789abcdef0123456789abcdef.service; verifiedStopped must still perform exactly 1 cleanup query and return stopped=false.TestBoundedSignalHandlerDropsFlood in systemd_test.go lines 166β174 delivers 10,000 signals to newBoundedSignalHandler(1) and requires the signal queue length to remain exactly 1.TestReadinessVerifierBindsExactSourceAndCondition in systemd_test.go lines 176β199 reads ../../verify-readiness, runs ../../review-source-hash, requires a 64-character digest embedded as ;pty-source:sha256:<digest>', requires ../../../opencode-v2.service to contain ExecCondition=/usr/local/libexec/opencode-pty-verify-readiness, and validates verifier shell syntax with /bin/sh -n ../../verify-readiness.