Merge CB-538: opencode peers launch with --auto
A spawned peer has no human at its pane, so an approval prompt is not a pause — it is a wedge. The agent stops, looks identical to a legitimate mid-turn wait, and can never reach its bridge_reply, so the delegation dies silently and the lead learns nothing until the timeout. Unconditional rather than a per-profile knob, which is the right call: there is no configuration under which a bridge-spawned opencode worker WANTS to block on an approval it has no way to answer. opencode's help calls --auto 'dangerous!', and that warning is written for a human at a terminal; the blast radius here is already bounded by the layer above — a worker runs in its own git worktree, on its own branch, off-subscription, and cannot merge. The lead is the gate. Reviewed by me rather than fanned out: 24 lines across one method and its two tests, below the threshold where a reviewer pass pays for itself. argvWithModel is re-signatured to take composed argv instead of building it, so the two flag-appenders compose rather than each owning construction.
This commit is contained in:
@@ -144,7 +144,7 @@ public final class OpenCodeLauncher extends HerdrPeerLauncher {
|
||||
workerEnv.put("OPENCODE_CONFIG", writeConfig(cfg).toString());
|
||||
}
|
||||
applyGitToken(workerEnv, cfg);
|
||||
return new Launch(workerEnv, argvWithModel(cfg));
|
||||
return new Launch(workerEnv, argvWithModel(argvWithAuto(cfg), cfg));
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -161,9 +161,24 @@ public final class OpenCodeLauncher extends HerdrPeerLauncher {
|
||||
return cfg.baseUrl() != null && !cfg.baseUrl().isBlank();
|
||||
}
|
||||
|
||||
/** The launch argv plus, when a model is configured, the opencode {@code -m provider/model} flag. */
|
||||
private List<String> argvWithModel(BridgedConfig.Worker cfg) {
|
||||
/**
|
||||
* The launch argv plus the unconditional {@code --auto} flag, which auto-approves the
|
||||
* permissions opencode does not explicitly deny. It is unconditional, not a preference: a
|
||||
* spawned peer has no human at its pane — the bridge spawned it — so one that stops at an
|
||||
* approval prompt is a wedged agent, indistinguishable from a legitimate mid-turn wait and
|
||||
* unable to end its turn with {@code bridge_reply}. opencode's own help calls this
|
||||
* "dangerous!", but the blast radius here is already bounded by design: a worker runs in its
|
||||
* own git worktree on its own branch, is off-subscription, and cannot merge — the lead is the
|
||||
* gate.
|
||||
*/
|
||||
private List<String> argvWithAuto(BridgedConfig.Worker cfg) {
|
||||
List<String> argv = mutableArgv(cfg.argv());
|
||||
argv.add("--auto");
|
||||
return argv;
|
||||
}
|
||||
|
||||
/** The launch argv plus, when a model is configured, the opencode {@code -m provider/model} flag. */
|
||||
private List<String> argvWithModel(List<String> argv, BridgedConfig.Worker cfg) {
|
||||
if (cfg.model() != null && !cfg.model().isBlank()) {
|
||||
argv.add("-m");
|
||||
argv.add(cfg.model());
|
||||
|
||||
Reference in New Issue
Block a user