Skip to content

fix(runtime): repair OneCLI-backed OpenCode qualification - #838

Merged
danshapiro merged 14 commits into
mainfrom
fix/opencode-onecli-live-qa
Oct 4, 2026
Merged

danshapiro merged 14 commits into
mainfrom
fix/opencode-onecli-live-qa

Conversation

@danshapiro

@danshapiro danshapiro commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What changed

  • Configure the managed OpenCode qualification to use the explicit OneCLI grant files, authenticated proxy, and gateway CA. Keep loopback runtime calls local, and keep Freshell MCP control-plane requests off the model proxy.
  • Include the bundled MCP server entry in the runtime image and make qualification fail immediately with useful evidence when authentication is rejected, including after OpenCode redraws its screen.
  • Preserve the active PTY stream epoch when supervisor inventory refreshes the same terminal. Rebind only when the terminal identity changes.
  • Fix test harness issues found while making the qualification reliable: keep recall prompts tool-free and bind Electron's port from the kernel instead of reacquiring a released port.
  • Keep Electron's staging receipt aligned with electron-builder: omit dependency .gitkeep placeholders that the builder always strips, while retaining real runtime files.
  • Make Rust settings test-home IDs unique under parallel execution with a per-process counter.

Regression cause

After a PTY host restarted, it published output on a new stream ID tied to that host boot. The supervisor inventory still carried the stable launch stream ID. Recovery reconciliation overwrote the live pane's new stream ID with the stale inventory value, so the browser reattached to the wrong output stream. The merge now preserves the live stream for the same terminal; transport attach/change messages remain authoritative, and a different terminal still adopts its projected stream ID.

Additional CI failures fixed

The first Electron build failed on all three operating systems because electron-builder omits mcp/node_modules/undici/lib/llhttp/.gitkeep, but Freshell's staging receipt incorrectly required that empty dependency placeholder. The runtime stager now skips that name only inside deployed dependency trees. Its regression test confirms the placeholder is absent from the receipt and the real llhttp-wasm.js file remains included.

The first Rust CI run exposed a parallel-test race: test homes used PID plus wall-clock time as their IDs, so tests could collide and one could remove another test's config before it was read. The IDs now include a monotonic per-process sequence, and the failing test passes both in the full server suite and pre-push checks.

Verification

  • GCLOUD_ROBOT_REQUIRE=1 FRESHELL_TEST_SUMMARY='OneCLI runtime stream recovery regression' pnpm run verify — passed, including all four Cloud Run Vitest shards, Rust, and Electron.
  • FRESHELL_RUNTIME_OPENCODE_QUALIFICATION_LIVE=1 pnpm run test:e2e:chromium test/e2e-browser/specs/runtime-opencode-provider-qualification-rust.spec.ts — passed against the live managed runtime using the private OneCLI grant files. This qualification is intentionally run on the local live lane because the Cloud Run E2E job does not receive those private files or managed-runtime Docker access.
  • pnpm run test:vitest run test/unit/electron/prepare-electron-runtime.test.ts --config config/vitest/vitest.electron.config.ts — passed (17 tests).
  • pnpm run prepare:electron-runtime, pnpm exec electron-builder --config config/electron-builder.yml, and pnpm run verify:electron-artifact — passed for Linux; artifact receipt/hash validation succeeded and real Undici llhttp runtime files were present.
  • GCLOUD_ROBOT_REQUIRE=1 FRESHELL_TEST_SUMMARY='Rust test fixture isolation' pnpm run test:server — passed (1,175 unit tests, zero failures, plus Rust integration tests).
  • Pre-push hook on the current branch — passed Rust formatting, workspace Clippy, targeted Rust tests, and TypeScript typecheck.

@danshapiro
danshapiro merged commit 96e57e8 into main Oct 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant