Dashboard › opencode › Distillation
1b30eca8-7fbb-449c-807e-643fd2b119ed["lore_tm_v1_Hi4gVz9h8ZRUi6qMIFeSvnRrst2wRixVU0kxC_3ngKw","lore_tm_v1_ejdM3uDYWIBr4YnUkBZI0DueLek6FZHzAyb1aS5Y5aY","lore_tm_v1_1e5T5OgWTSpHZf73oF25wKNZmCUTgI-H7paDuBzbroo","lore_tm_v1_-leQqN-nSIdmUBDpFJr408WjRfsRfB5FJcIn7dCoZko","lore_tm_v1_4mawAd1Q-HZ5_JOiOKBofPwfpEB2CjrKFU7BkNHPP-s","lore_tm_v1_XF1zCLPohShU9hPVqrvMv3RauJ3aREhkCin2va2QclM","lore_tm_v1_K3DlxGbmxKkRyqIMCmvvV6nKrWbuEU_3Ty0U5ohNJa0","lore_tm_v1_J2BskP5KrhjP-oWbclxyZgje0OpWWu9XVQEXtWUXdBg","lore_tm_v1_S8i-dwETgz_suoNXIA5oiOMxEUoxSSCx4cheOVtDEC4","lore_tm_v1_6z3GKJuDKhwhr1xtz0F2Z3nqV6VQnDjmIIkFZaeDqYY","lore_tm_v1_uw6el0Dj9CZ2XizPHDvwAJShfb6VOW4ocr2WImuU-CI","lore_tm_v1_BjVvLN7U2AqcexNyNotjx-ewTdLuyHzXRnVyMkJOw9w","lore_tm_v1_QWshZIf19TIHeamNltK-GkTLK-cNoI7gEApIRyWADnk","lore_tm_v1_IOyREaBTG240rJJaNUhPXEn0sbIXh0of26uZeOfuvPo","lore_tm_v1_CgnZUs8t6VmwI0fNg3JdCHsLcd-pLfhbywu55_270q0","lore_tm_v1_cCq8QsaUhB5JkRN4zLXURyIsEyT8qMMYiYoLxzBmLHs"]
/home/byk/.local/share/opencode-v2-pilot/opencode-v2.service defines Description=OpenCode V2 Server, orders itself after network.target and opencode-pty-supervisor.service, requires opencode-pty-supervisor.service, and uses Type=simple.opencode-v2.service loads /home/byk/.opencode/env and /home/byk/.local/share/opencode-v2-pilot/server.env; sets OPENCODE_CONFIG_DIR=/home/byk/.local/share/opencode-v2-pilot/config/opencode, OPENCODE_DB=/home/byk/.local/share/opencode-v2-pilot/data/opencode/opencode.db, XDG_DATA_HOME=/home/byk/.local/share/opencode-v2-pilot/data, XDG_CACHE_HOME=/home/byk/.local/share/opencode-v2-pilot/cache, XDG_CONFIG_HOME=/home/byk/.local/share/opencode-v2-pilot/config, and XDG_STATE_HOME=/home/byk/.local/share/opencode-v2-pilot/state.opencode-v2.service runs as User=byk from WorkingDirectory=/home/byk; ExecStart is /home/byk/Code/opencode-v2-pilot/packages/cli/dist-v2-pilot-final/cli-node-linux-x64/bin/opencode2-node serve --hostname=0.0.0.0 --port=4096.opencode-v2.service uses an ExecCondition requiring /etc/opencode/pty-supervisor-verified to exist, not be a symlink, have metadata 0:0:644, contain exactly 4 lines, begin with revision=[0-9a-f]{40,64}, and have lines 2β4 pass /usr/bin/sha256sum --check --strict -.opencode-v2.service sets Restart=always, RestartSec=5, Nice=-5, LimitNOFILE=65535, LimitNPROC=4096, MemoryMax=13G, MemoryHigh=12G, NoNewPrivileges=true, ProtectSystem=strict, ProtectHome=read-only, ReadWritePaths=/home/byk, PrivateTmp=yes, and an empty SupplementaryGroups; it is wanted by multi-user.target./home/byk/.local/share/opencode-v2-pilot/supervisor/PROTOCOL.md states one Unix SOCK_STREAM connection is used per PTY; the Node SEA process opens and retains it, and the supervisor authenticates its immutable peer credentials against the exact opencode-v2.service MainPID.3 and approved directory at fd 4; the helper sends the start frame and fd 4, exits, and all other Node children inherit neither descriptor.OPTY; byte 4 version 1; byte 5 type; bytes 6β7 zero; bytes 8β11 unsigned big-endian payload length. Maximum frame payload is 71,680 bytes; input/output payloads are at most 32,768 bytes; one accepted 65,536-byte plugin write is split into at most two input frames.1 start frame with exactly one SCM_RIGHTS descriptor. The supervisor receives descriptors atomically using MSG_CMSG_CLOEXEC, closes every received descriptor on every error, requires exactly one directory descriptor, and compares its st_dev and st_ino with the frame.st_dev; 2. 8-byte unsigned big-endian st_ino; 3. 4-byte unsigned big-endian runtime seconds where zero selects the 3,600-second default; 4. 2-byte unsigned big-endian command byte length; 5. 2-byte unsigned big-endian argument count; 6. command bytes; 7. each argument as a 2-byte unsigned big-endian length followed by its bytes.1β4,096 UTF-8 bytes; at most 128 arguments; each argument at most 16,384 UTF-8 bytes; aggregate argument bytes at most 65,536; runtime at most 3,600 seconds.started (type 6) with the generated unit name.opencode-pty-[0-9a-f]{32}.service.started frame.input type 2, non-empty opaque client-to-PTY bytes up to 32,768; output type 3, non-empty opaque PTY-to-client bytes up to 32,768; exit type 4, structured systemd completion; error type 5, non-empty UTF-8 truncated to 32,768 bytes; stop type 7, empty client request to stop and wait for the complete unit cgroup; stopped type 8, empty acknowledgement sent only after bounded cleanup and final-output drain.ExecMainCode, four-byte unsigned big-endian ExecMainStatus, four-byte unsigned big-endian result-string length, then that many UTF-8 bytes of the systemd Service Result. The plugin maps CLD_EXITED status to exitCode, maps CLD_KILLED/CLD_DUMPED status to numeric exitSignal, and retains the exact systemd result.stopped to result stopped, CLD_KILLED, and signal 15; this is a protocol completion record rather than a claimed systemd ExecMain result.BindsTo enforces shutdown cleanup.fchdir(2); replaces stderr with stdout; accepts only canonical a[A-Za-z0-9_-]* URL-safe unpadded base64 arguments; clears the environment; binds its reviewed executable to fd 3; places bounded encoded argv in one temporary environment value; and executes /usr/bin/script -q -e -f -c "/bin/sh -i -c 'exec /proc/self/fd/3 --exec'" /dev/null.3, and directly calls execve with the original argv vector. The fixed inner shell is interactive; script -e preserves normal command status; command arguments are never shell-evaluated; argv boundaries are retained./home/byk/.local/share/opencode-v2-pilot/supervisor/ROOT-ACCEPTANCE.md forbids installing, starting, enabling, or marking the candidate ready until every check passes on the exact target host; source tests do not substitute for target-host checks.0755 files /usr/local/libexec/opencode-pty-supervisor, /usr/local/libexec/opencode-pty-launcher, and /usr/local/libexec/opencode-pty-client, after creating /usr/local/libexec root-owned mode 0755./usr/local/libexec, every parent directory, and all three binaries are root-owned and never writable by byk or a group; verify the Node SEA service uses the reviewed fixed helper path and cannot replace it.0644 on a disposable test VM; run systemd-analyze verify; inspect every transient property over D-Bus; reject unknown, ignored, or weakened directives; do not alter production units.active/running, /system.slice/opencode-v2.service, and 16-byte InvocationID; require SO_PEERPIDFD and fail closed on kernels lacking it; replace MainPID and invocation between authentication/start and confirm pidfd/invocation rechecks reject both.3 as Nodeβs connected socket duplicate, and fd 4 as approved directory; sends one bounded start frame with one SCM_RIGHTS descriptor; exits; marks both descriptors close-on-exec; and leaks neither authenticated socket nor helper descriptors to unrelated Node children.opencode-pty-[0-9a-f]{32}.service, run as byk:byk with no supplementary groups, and retain no docker, lxd, sudo, or other groups; also verify empty capability/ambient sets, closed devices, no cgroup delegation, restricted proc/namespaces/address families/syscalls, fixed environment, fd-selected cwd, and inaccessible supervisor, Docker, system D-Bus, and user D-Bus sockets.4,096 command bytes, 128 arguments, 16,384 bytes per argument, 65,536 aggregate argument bytes, 3,600 seconds runtime, and splitting 65,536-byte writes into 32,768-byte frames; reject malformed UTF-8, NUL, missing/extra descriptors, MSG_CTRUNC, metadata mismatch, wrong direction, unknown types, and oversized frames./bin/sh -i inner shell across spaces, quotes, shell metacharacters, newlines, terminal input/modes, stdout/stderr ordering, EOF, script -e, zero/nonzero exits, and signal exits without losing argv boundaries.16 concurrent sessions and reject the 17th; cover slow/disconnected readers, blocked input plus disconnect, backpressure, maximum output, runtime expiry, TERM-to-KILL escalation, protocol failure, server shutdown, closed D-Bus signal channels, D-Bus timeouts, startup cancellation, and every StartTransientUnit non-done or ambiguous result.StartTransientUnit, confirm bounded StopUnit and full cgroup removal; ensure cleanup errors reach client and journal; restart only the disposable supervisor and verify strict-name plus exact-BindsTo orphan cleanup removes owned orphans while leaving lookalike/foreign units untouched.10 times against the freshly built helper and isolated disposable supervisor, covering permissions, source identity, ownership, deletion, in-flight deletion, reservations, JSON envelopes, regex bounds, UTF-8 write bounds, transport framing, helper transfer, notifications, timeouts, and cleanup.0644 regular /etc/opencode/pty-supervisor-verified with exactly 4 linesβrevision=<reviewed revision> followed by three standard sha256sum records for the installed supervisor, launcher, and client. Empty or stale markers never grant readiness./home/byk/.local/share/opencode-v2-pilot/CUTOVER.md states the V2 executable serves API and web UI from one origin and nginx must not be added.4096; 2. confirm candidate revision with git -C /home/byk/Code/opencode-v2-pilot rev-parse HEAD and smoke-build version with /home/byk/Code/opencode-v2-pilot/packages/cli/dist-v2-pilot-final/cli-node-linux-x64/bin/opencode2-node --version; 3. test isolated candidate port 14102 using authenticated /api/health and /; 4. call POST /api/plugin/await-activation and confirm both local plugins active; 5. create mode-0600 /home/byk/.local/share/opencode-v2-pilot/server.env containing OPENCODE_PASSWORD=<password>.supervisor/ROOT-ACCEPTANCE.md checks against freshly built root-owned binaries; 7. prove Session deletion, plugin unload, runtime expiry, explicit kill, disconnect, and every ambiguous start remove the complete transient cgroup including descendants outside the original process group; 8. prove socket/cwd descriptor access is limited to the fixed helper and block cutover on same-UID impersonation/inheritance/delegation; 9. obtain independent correctness/security approval for exact revision and three hashes; 10. create the exact content-bound mode-0644 readiness marker only after all gates; 11. run systemd-analyze verify and confirm candidate ordering/requires without changing production during preflight./etc/systemd/system/opencode-v2.service; 2. sudo systemctl daemon-reload; 3. sudo systemctl stop opencode.service; 4. sudo systemctl start opencode-v2.service; 5. verify /api/health, /, /site.webmanifest, /sw.js, and /openapi.json on port 4096; 6. await plugin activation and confirm followup plus local-pty; 7. observe browser traffic and run one follow-up plus one PTY smoke; 8. enable V2 only after all checks and keep legacy installed/disabled.sudo systemctl stop opencode-v2.service; 2. sudo systemctl start opencode.service; 3. verify legacy health and browser UI on port 4096; 4. disable V2 only after legacy health is confirmed. The V2 database remains isolated under /home/byk/.local/share/opencode-v2-pilot/data, and rollback never rewrites or deletes either database./home/byk/.local/share/opencode-v2-pilot/supervisor/go.mod defines module opencode-pty-supervisor, Go 1.22, and dependencies github.com/coreos/go-systemd/v22 v22.5.0, github.com/godbus/dbus/v5 v5.1.0, and golang.org/x/sys v0.20.0.supervisor/go.sum includes checksums for github.com/coreos/go-systemd/v22 v22.5.0, github.com/godbus/dbus/v5 v5.1.0, and golang.org/x/sys v0.20.0, plus go.mod sums including historical github.com/godbus/dbus/v5 v5.0.4/go.mod./home/byk/.local/share/opencode-v2-pilot/config/opencode contains exactly 8 entries: bun.lock, node_modules/, opencode.json, package.json, plugins/, service-v2-pilot.json, test/, and tsconfig.json./home/byk/.local/share/opencode-v2-pilot/config/opencode/plugins/pty-transport.ts and /home/byk/.local/share/opencode-v2-pilot/config/opencode/plugins/pty.ts.bun-pty native artifacts include librust_pty.so, librust_pty_musl.so, librust_pty_arm64.so, librust_pty_arm64_musl.so, librust_pty.dylib, librust_pty_arm64.dylib, and rust_pty.dll under /home/byk/.local/share/opencode-v2-pilot/config/opencode/node_modules/bun-pty/rust-pty/target/release/./home/byk/.local/share/opencode-v2-pilot/config/opencode/package.json is private, uses ES modules, depends on effect version 4.0.0-rc.112, and has dev dependency @types/bun version 1.2.21./home/byk/.local/share/opencode-v2-pilot/config/opencode/tsconfig.json uses allowImportingTsExtensions: true, libs ESNext, DOM, DOM.Iterable, module: "Preserve", moduleResolution: "Bundler", noEmit: true, skipLibCheck: true, strict: true, target: "ESNext", types ["bun"], and includes plugins/**/*.ts plus test/**/*.ts."@opencode/plugin": ["/home/byk/Code/opencode-v2-pilot/packages/plugin/src/promise/index.ts"] and "@opencode/plugin/*": ["/home/byk/Code/opencode-v2-pilot/packages/plugin/src/promise/*.ts"].github.com/coreos/go-systemd/v22@v22.5.0 located PropExecStart() at dbus/properties.go:57, PropType() at :83, PropBindsTo() at :138, PropAfter() at :186, PropSlice() at :222, StopUnitContext() at dbus/methods.go:122, StartTransientUnitContext() at :191, GetUnitPropertiesContext() at :272, GetUnitTypePropertiesContext() at :347, and ListUnitsByPatternsContext() at :477.go-systemdβs PropExecStart(command []string, uncleanIsFailure bool) constructs an execStart whose Path is command[0], Args is the complete command slice including argv0, and UncleanIsFailure is supplied by the caller, then returns property ExecStart.go-systemd dependency/property helpers return D-Bus variants: PropType() sets Type; PropBindsTo() uses dependency name BindsTo; PropAfter() uses After; and PropSlice() sets Slice.go-systemdβs StopUnitContext(ctx, name, mode, ch) calls startJob(ctx, ch, "org.freedesktop.systemd1.Manager.StopUnit", name, mode). StartTransientUnitContext(ctx, name, mode, properties, ch) calls startJob(ctx, ch, "org.freedesktop.systemd1.Manager.StartTransientUnit", name, mode, properties, make([]PropertyCollection, 0)).go-systemd documents that a successful job call may return job ID 0 even though the real underlying ID is nonzero, so ID 0 is not authoritative; errors return alongside job ID 0.go-systemdβs KillUnitContext(ctx, name, signal) targets all unit processes through KillUnitWithTarget(ctx, name, All, signal), whose D-Bus call is org.freedesktop.systemd1.Manager.KillUnit.