Skip to content

Fix OpenCode plugin loading, validation, and asset upgrades - #3

Merged
jacobprall merged 1 commit into
mainfrom
codex/fix-opencode-integration
Oct 9, 2026
Merged

jacobprall merged 1 commit into
mainfrom
codex/fix-opencode-integration

Conversation

@starmorph

@starmorph starmorph commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR fixes nine OpenCode integration problems inherited from main. The skills sync and version bump remain in #2.

Problems and fixes

  1. The npm plugin installs but does not load.

    Problem: OpenCode's package loader cannot find the plugin entry point with only the existing root export.

    Fix: Add a ./server export pointing to the plugin entry point.

  2. The npm setup command silently does nothing.

    Problem: The executable checks its own filename against the npm-created symlink path, so its setup function never runs.

    Fix: Resolve the symlink before checking whether the file is being executed directly.

  3. Relative Blueprint paths use the wrong directory.

    Problem: Validation resolves paths from the OpenCode server's working directory, which can differ from the user's project directory.

    Fix: Resolve paths from the tool's session directory, or the plugin's project directory for automatic validation.

  4. Validation can check the wrong Blueprint file.

    Problem: The requested filename is omitted from the Render CLI call. Render defaults to render.yaml, even when the agent requested render.yml.

    Fix: Pass the requested absolute filename explicitly, along with --output json.

  5. GPT-style patch edits do not trigger validation.

    Problem: The hook searches ordinary tool arguments for filenames and misses OpenCode's apply_patch calls.

    Fix: Read the patch result's file metadata, validate every affected Blueprint and moved destination, and skip deleted files. Include a path-header fallback for clients without that metadata.

  6. Reads trigger validation, and explicit validation runs twice.

    Problem: The hook runs whenever tool arguments contain a Blueprint path, including reads and the explicit validation tool itself.

    Fix: Run automatic validation only after file-mutation tools: write, edit, multiedit, and apply_patch.

  7. npm setup overwrites existing Render MCP settings.

    Problem: --enable-mcp replaces an existing mcp.render entry, including disabled servers or custom authentication settings.

    Fix: Preserve the existing entry unless --force is supplied; retain other config fields and MCP servers when replacing it.

  8. Both installers ignore the XDG config location.

    Problem: Installation defaults to ~/.config/opencode even when the user configured a different XDG directory.

    Fix: Use this precedence: --config-dir, OPENCODE_CONFIG_DIR, XDG_CONFIG_HOME/opencode, then ~/.config/opencode.

  9. Upgrades leave a mixture of old and new skills.

    Problem: Existing files are skipped, so old skill instructions remain alongside new references, and obsolete references are never removed.

    Fix: Track installed file hashes, update unchanged bundled files, remove obsolete unchanged files, and preserve user edits. Recognize unchanged legacy 0.1.0 installations too. --force replaces modified bundled files.

Supporting changes

  • Both installation flows use one shared installer, and the standalone plugin is generated from the npm source.
  • Add regression tests and CI for both installation flows. Document upgrades, credentials, workspace selection, and avoiding duplicate plugin loading.
  • Add a validation timeout and cancellation support, and update locked dependencies. npm audit reports zero vulnerabilities.

Verification

  • Build and all 22 unit/installer tests passed.
  • Both installation flows passed real OpenCode tests on 1.15.11 and 1.18.35, using a local scripted model and mock Render CLI.
  • Live tests passed with Render CLI 2.28.0: MCP connection, workspace/service discovery, and explicit and automatic validation of valid and invalid Blueprints. No Render resources were created or changed.
  • Both legacy upgrade flows updated 21 skills, removed five obsolete references, and preserved customized files.
  • The branch merges cleanly with Sync skills from skills-v1.0.0 and bump to 0.2.0 #2. The combined 0.2.0 package passed all 22 tests and both OpenCode installation flows on 1.18.35.

Merge these integration fixes first, then update #2 before releasing.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedesbuild@​0.28.0 ⏵ 0.28.292 +1100 +173 +187100
Updatedvitest@​4.1.7 ⏵ 4.1.1198 +1100 +279 +199100

View full report

@starmorph
starmorph marked this pull request as ready for review October 8, 2026 22:20

@jacobprall jacobprall left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@jacobprall
jacobprall merged commit 257f615 into main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants