Repository navigation
Conversation
bateau84
added a commit
that referenced
this pull request
Oct 6, 2026
## Purpose Correct the blocking outer-`execute` evidence gap found during the independent final review of #45. This branch is based on the post-#52 target head `b10c52d50aaf0c038e77e80eaca3890347d5fa82`. ## Defect Stock OpenCode 2.0.23 creates the model-facing Code Mode `execute` tool inside `Tool.snapshot`, after registration transforms have run. The integrated observer therefore did not emit a native observation for that real outer invocation. Inner records were linked only to an internal opaque token. That allowed the public native boundary to report complete/zero outer-`execute` observations while Code Mode had actually run. ## Correction - Observe the real model-facing outer `execute` invocation at stock `execute.before`. - Keep `session.tool.success` / `session.tool.failed` as terminal authority. - Bind Code Mode inner records to that observed outer invocation ID. - Reject dangling, wrong-tool, or identity-mismatched parents in canonical accounting/validation. - Strengthen provider-free acceptance checks for outer observation, exact parent resolution, identity agreement, non-zero native coverage, concurrency, and reverse completion. - Document that synthetic outer `execute` input is exact at `execute.before` but pre-`CodeMode.Input` decode. ## Scope No threat-model expansion. No OpenCode patch/fork, protected channel, signing, broker, process isolation, or hostile-plugin machinery. Targets `refactor/trusted-checkout-evidence`. ## Validation Head: `221af580640360c16e263cc05136d3be0d090a0f` - CI #307 / run 37525849151: **PASS**, 94/94 Python tests; stock Code Mode diagnostic probe PASS; OpenCode **2.0.23**. - Provider-free runtime evidence acceptance #21 / run 37525849081: **PASS**, 6/6 helper tests and all 10 scenarios. - Stock native observer integration #33 / run 37525849107: **PASS**. - PR is mergeable against the current #45 branch. #53 is closed as superseded; it became dirty only because #52 merged while this review was in progress.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Correct the blocking outer-
executeevidence gap found during the independent final review of #45.Defect
Stock OpenCode 2.0.23 creates the model-facing Code Mode
executetool insideTool.snapshot, after registration transforms have run. The production observer therefore did not emit a native observation for that real outer invocation. Inner records were linked only to an internalnative-outer-unobserved:...token.That allowed the public native boundary to remain
completewith zero outer-executeobservations even when Code Mode really ran.Correction
executeinvocation at stockexecute.before.session.tool.success/session.tool.failedas its terminal authority.execute;executeinput is observed exactly atexecute.before, beforeCodeMode.Inputdecode. Registered direct tools remain observed after decode.Scope
No threat-model expansion. No OpenCode patch/fork, protected channel, signing, broker, process isolation, or hostile-plugin machinery.
Targets
refactor/trusted-checkout-evidence.