Dashboard › opencode-lore › No free-form content in logs or Sentry
01a0af08-18d2-70f0-9182-2ca34b109f53Never log, persist, export, or send across worker IPC free-form application or provider content: prompts, paths, URLs, commands, tool payloads, SQL parameters, credentials, exception text, diagnostics, callback errors, or client-controlled IDs. Raw failures look diagnostic but can leak hostile text and machine state through stderr, Sentry, persistent logs, or LogSink. Silently drain embedding-worker stdout/stderr with resume() and no payload-observing data listener; native dependencies may emit model paths, tensors, IDs, and process details. Emit only fixed categorical failure codes after validation, keep original exceptions private and ephemeral, and ensure telemetry or host sink failures never interrupt embedding or stream consumption.