Dashboard › opencode › Distillation
44979eba-89d8-41c3-ad97-2658b27a599f["lore_tm_v1_0GjFAh2jPWvUvcjvC_DeVOACXFSkONuF0n5y24DF4us","lore_tm_v1_2GNg15TSy8zj7MI0sNeufQWge8FpQDbrsdHYdxWSIeE"]
/home/byk/Code/opencode-v2-pilot/packages/plugin/src/promise/tool.ts is exactly 69 lines and re-exports CallID and Error, plus types Metadata, Options, and Result, from @opencode/schema/tool.ToolContext extends Omit<Tool.Context, "progress"> and replaces progress with (update: Tool.Metadata) => Promise<void>; generic Info<Input, Output> replaces Tool.Infoβs execute with a Promise-returning executor that receives typed input and ToolContext and returns Promise<Tool.Result<Output>>.ToolEditor exposes list(), get(id), namespace(namespace), add(tool), update(id, update), and remove(id); update mutates Types.Mutable<Info> and silently ignores missing IDs.ToolHooks defines "execute.before" with mutable tool and input plus readonly sessionID, agent, messageID, and tool-call id; "execute.after" includes readonly identifying/input fields and either { status:"completed", result: Tool.Result } or { status:"error", error: Tool.Error }.ToolDomain exposes readonly transform: Transform<ToolEditor>, reload: () => Promise<void>, and hook: Hooks<ToolHooks>./home/byk/.local/share/opencode-v2-pilot/supervisor/ROOT-ACCEPTANCE.md passes on the exact target host; source tests never substitute for these checks.CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags=-buildid=, requiring both build sets to match, and recording the content-bound source revision, Go version, dependency sums, complete commands, and SHA-256 hashes. Only those hashes may be installed: bin/opencode-pty-supervisor β /usr/local/libexec/opencode-pty-supervisor, bin/opencode-pty-launcher β /usr/local/libexec/opencode-pty-launcher, bin/opencode-pty-client β /usr/local/libexec/opencode-pty-client, and verify-readiness β /usr/local/libexec/opencode-pty-verify-readiness, all root-owned mode 0755; /usr/local/libexec must be created root-owned mode 0755./usr/local/libexec, every parent directory, and all three binaries to be root-owned and never writable by byk or a group; the Node SEA service must use the reviewed fixed helper path and be unable to replace it.0644, running systemd-analyze verify against installed files, inspecting every transient property over D-Bus, rejecting unknown, ignored, or weakened directives, and never altering production units.active/running, /system.slice/opencode-v2.service, and the 16-byte InvocationID; requiring mandatory SO_PEERPIDFD and failing closed on kernels without it; and confirming pidfd/invocation rechecks reject replacement of either MainPID or invocation between authentication and start.3 as a duplicate of Nodeβs connected socket, and fd 4 as the approved directory; send one bounded start frame with one SCM_RIGHTS descriptor; and exit. Only reviewed Go-runtime metadata reads such as /sys/kernel/mm/transparent_hugepage/hpage_pmd_size may be permitted when observed on the exact Go/runtime build; every application-selected path open and every socket/connect operation must be rejected. Both received descriptors must become close-on-exec, and no unrelated Node child may inherit the authenticated socket or helper descriptors.5 seconds.opencode-pty-[0-9a-f]{32}.service, run as byk:byk with an empty supplementary-group list, and never retain docker, lxd, sudo, or other groups. It also requires empty capability and ambient sets, closed devices, no cgroup delegation, restricted proc/namespaces/address families/syscalls, a fixed environment, descriptor-selected cwd, and inaccessible supervisor, Docker, system D-Bus, and user D-Bus sockets.ptrace, /proc descriptor access, process control, and descriptor delegation cannot let another process impersonate the MainPID, obtain or inherit its connected socket, or delegate work through an inherited descriptor. Source changes never prove this exact-host property, and any unblocked same-UID delegation path blocks deployment.4,096 command bytes, 128 arguments, 16,384 bytes per argument, 65,536 aggregate argument bytes, 3,600 seconds maximum runtime, and 65,536-byte writes split into 32,768-byte frames. It requires rejecting malformed UTF-8, NUL, missing or extra descriptors, MSG_CTRUNC, metadata mismatch, wrong frame direction, unknown types, and oversized frames./bin/sh -i inner shell, covering spaces, quotes, shell metacharacters, newlines, terminal input, terminal modes, stdout/stderr ordering, EOF, script -e, zero and nonzero exits, and signal exits without losing argv boundaries.16 concurrent sessions and rejecting the 17th; it must cover slow and disconnected readers, blocked input plus disconnect, backpressure, maximum output, runtime expiry, TERM-to-KILL escalation, protocol failure, server shutdown, closed D-Bus signal channels, D-Bus timeouts, startup cancellation, and every StartTransientUnit non-done or ambiguous result.StopUnit and full cgroup removal after every path that called StartTransientUnit, with cleanup errors reaching both client and journal. Restarting only the disposable supervisor must prove strict-name plus exact-BindsTo orphan cleanup removes owned orphans while leaving lookalike and foreign units untouched.bun /tmp/opencode/pty-plugin-smoke.ts exactly 10 times while keeping that reviewed harness outside the auto-discovered plugin directory, then running it against the freshly built helper and an isolated disposable supervisor. Required coverage includes permissions, source identity, ownership, deletion, in-flight deletion, reservations, JSON envelopes, regex bounds, UTF-8 write bounds, pre-listener output bounds, saturated STOP bounds, transport framing, helper transfer, notifications, timeouts, and cleanup.26.4 SEA, a deterministic inheritance probe against the final binary that passes only the connected supervisor socket and approved cwd to the fixed helper, enumerates the helperβs descriptors before its first application operation, and spawns an unrelated child to prove it inherits neither descriptor. Node 24 results never satisfy this gate. This privileged/runtime acceptance item remains pending unless the final SEA binary proves it unprivileged without starting any service.review-source-hash must run from the unchanged source tree and equal the pty-source:sha256 embedded in verify-readiness; the reviewed verifier must be installed root-owned mode 0755 as /usr/local/libexec/opencode-pty-verify-readiness./etc/opencode/pty-supervisor-verified may be created only after both independent reviews approve and every target-host check passes. It must be a root-owned mode-0644 regular file containing exactly four newline-terminated lines in fixed order: first revision=opencode-v2-pilot:git:<reviewed-40-hex-commit>;pty-source:sha256:<reviewed-source-manifest-hash> exactly as embedded in verify-readiness, followed by standard sha256sum records for /usr/local/libexec/opencode-pty-supervisor, /usr/local/libexec/opencode-pty-launcher, and /usr/local/libexec/opencode-pty-client. Duplicate or trailing lines are invalid.ExecCondition may run only the root-controlled verifier; an arbitrary hex string, empty marker, stale marker, or mismatched source-manifest value never grants readiness.26.4 SEA inheritance, same-UID delegation/ptrace isolation, target-host systemd properties, and independent reviews remain deployment blockers until performed on final artifacts; source tests never close these gates.