Repository navigation
Conversation
bateau84
force-pushed
the
fix/final-runtime-evidence-blockers
branch
from
October 6, 2026 21:16
fa7f3e0 to
a0b2a60
Compare
bateau84
marked this pull request as ready for review
October 6, 2026 21:19
bateau84
commented
Oct 6, 2026
bateau84
left a comment
Owner
Author
There was a problem hiding this comment.
Review — READY
The final capture-transport blocker is closed.
- Production authority no longer reads
/tmp/runtime/runtime-observer.jsonl. - The runner parent owns a loopback listener and accepts one connection only.
- The trusted observer connects during plugin startup, then the listener closes.
- The endpoint is removed from the runtime process environment before evaluated tool subprocesses execute.
- Capture bytes are drained directly into the existing parser/builder/validator and transport failures remain fail-closed.
- The old path can be created/deleted/recreated/appended by evaluated shell code without affecting authoritative evidence.
- Outer Code Mode
executeauthority from #54 remains intact. - Stock OpenCode 2.0.23 and the reduced trusted-checkout threat model are preserved.
Validation confirmed: 95/95 unit tests, 11/11 provider-free scenarios including capture_tamper, stock Code Mode probe PASS, and native observer integration PASS.
No BLOCKING, IMPORTANT, or MINOR correctness findings requiring changes.
Verdict: READY TO MERGE #55.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Focused corrective child of #45, targeting
refactor/trusted-checkout-evidence.The base now includes merged #54 (
b10c8e9), which closes the authoritative outer Code Modeexecuteblocker. This PR is rebased directly on that commit and contains only the remaining authoritative-capture transport correction plus its regression coverage.Stock OpenCode remains 2.0.23. No threat-model expansion.
Blocker 1 — outer Code Mode
executeClosed in the base by #54 and revalidated here.
The current integrated runtime evidence:
executeat the supported stockexecute.beforeboundary;session.tool.success/session.tool.failedas terminal authority;The Code Mode probe remains green after the capture-transport change.
Blocker 2 — remove target-writable authoritative capture
The production observer no longer uses:
/tmp/runtime/runtime-observer.jsonlAuthoritative observer records now cross the process boundary through a runner-owned one-connection loopback stream:
127.0.0.1immediately before the real OpenCode invocation;process.envbefore evaluated tool subprocesses run;A direct inherited memfd/FD was tried first, but stock
@opencode/cli@2.0.23crosses an internal process boundary that does not preserve arbitrary extra descriptors. The one-connection stream keeps stock OpenCode unchanged and avoids filesystem authority without introducing security-platform machinery.Protection against a deliberately malicious same-process plugin remains explicitly out of scope.
Tamper regression
Provider-free acceptance includes an evaluated tool that spawns
/bin/shand:The scenario passes only if the shell tamper completes, authoritative evidence remains complete/eligible, the real tamper tool is observed, and the forged invocation/tool never appears in
runtime_evidence.Preserved
opencode-eval-runner/runtime-evidence/v1;invokebehavior;No signing/HMAC, protected channel, remote PluginHost, capability broker, hostile-plugin isolation, or OpenCode patch is introduced.
Validation
Current clean head is based directly on merged #54 and is mergeable.
diagnostics_passed: true)Merge scope
This PR is ready for review against
refactor/trusted-checkout-evidence.Do not merge PR #45 as part of this change.