Skip to content

[superseded by #54] fix: observe outer Code Mode execute evidence - #53

Closed
bateau84 wants to merge 24 commits into
refactor/trusted-checkout-evidencefrom
fix/runtime-evidence-outer-execute
Closed

bateau84 wants to merge 24 commits into
refactor/trusted-checkout-evidencefrom
fix/runtime-evidence-outer-execute

Conversation

@bateau84

@bateau84 bateau84 commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Superseded by #54 after #52 merged into the target branch. #54 is based on the post-#52 head and contains only the final-review defect fix.

Purpose

Correct the blocking outer-execute evidence gap found during the independent final review of #45.

Defect

Stock OpenCode 2.0.23 creates the model-facing Code Mode execute tool inside Tool.snapshot, after registration transforms have run. The production observer therefore did not emit a native observation for that real outer invocation. Inner records were linked only to an internal native-outer-unobserved:... token.

That allowed the public native boundary to remain complete with zero outer-execute observations even when Code Mode really ran.

Correction

  • Observe the real model-facing outer execute invocation at stock execute.before.
  • Keep Session-owned session.tool.success / session.tool.failed as its terminal authority.
  • Bind inner Code Mode records to that observed outer invocation ID.
  • Reject dangling, wrong-tool, or identity-mismatched Code Mode parents in canonical evidence accounting/validation.
  • Add provider-free acceptance checks for:
    • observed outer execute;
    • exact parent ID resolution;
    • Session/message/actor/CallID agreement;
    • native coverage that cannot falsely report zero during Code Mode;
    • concurrent reverse-completion calls sharing the same observed outer parent.
  • Document that the synthetic outer execute input is observed exactly at execute.before, before CodeMode.Input decode. Registered direct tools remain observed after decode.

Scope

No threat-model expansion. No OpenCode patch/fork, protected channel, signing, broker, process isolation, or hostile-plugin machinery.

Targets refactor/trusted-checkout-evidence.

@bateau84 bateau84 changed the title fix: observe outer Code Mode execute evidence [superseded by #54] fix: observe outer Code Mode execute evidence Oct 6, 2026
@bateau84 bateau84 closed this Oct 6, 2026
bateau84 added a commit that referenced this pull request Oct 6, 2026
## Purpose

Correct the blocking outer-`execute` evidence gap found during the
independent final review of #45.

This branch is based on the post-#52 target head
`b10c52d50aaf0c038e77e80eaca3890347d5fa82`.

## Defect

Stock OpenCode 2.0.23 creates the model-facing Code Mode `execute` tool
inside `Tool.snapshot`, after registration transforms have run. The
integrated observer therefore did not emit a native observation for that
real outer invocation. Inner records were linked only to an internal
opaque token.

That allowed the public native boundary to report complete/zero
outer-`execute` observations while Code Mode had actually run.

## Correction

- Observe the real model-facing outer `execute` invocation at stock
`execute.before`.
- Keep `session.tool.success` / `session.tool.failed` as terminal
authority.
- Bind Code Mode inner records to that observed outer invocation ID.
- Reject dangling, wrong-tool, or identity-mismatched parents in
canonical accounting/validation.
- Strengthen provider-free acceptance checks for outer observation,
exact parent resolution, identity agreement, non-zero native coverage,
concurrency, and reverse completion.
- Document that synthetic outer `execute` input is exact at
`execute.before` but pre-`CodeMode.Input` decode.

## Scope

No threat-model expansion. No OpenCode patch/fork, protected channel,
signing, broker, process isolation, or hostile-plugin machinery.

Targets `refactor/trusted-checkout-evidence`.

## Validation

Head: `221af580640360c16e263cc05136d3be0d090a0f`

- CI #307 / run 37525849151: **PASS**, 94/94 Python tests; stock Code
Mode diagnostic probe PASS; OpenCode **2.0.23**.
- Provider-free runtime evidence acceptance #21 / run 37525849081:
**PASS**, 6/6 helper tests and all 10 scenarios.
- Stock native observer integration #33 / run 37525849107: **PASS**.
- PR is mergeable against the current #45 branch.

#53 is closed as superseded; it became dirty only because #52 merged
while this review was in progress.
@bateau84
bateau84 deleted the fix/runtime-evidence-outer-execute branch October 7, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant