Description
Five v1 tools write absent optional inputs into permission metadata as undefined. Encoding the GET /permission response then fails, so one pending request makes the entire listing unreadable. Reported as HTTP 400 on v1.17.18, still present on dev at 7534d235.
Flat:
packages/opencode/src/tool/glob.ts:34 — path
packages/opencode/src/tool/grep.ts:45 — path, include
packages/opencode/src/tool/webfetch.ts:46 — timeout
packages/opencode/src/tool/websearch.ts:125 — numResults, livecrawl, type, contextMaxCharacters
Nested: packages/opencode/src/tool/apply_patch.ts:201 sets movePath: change.movePath inside metadata.files[], undefined for every add, delete, and non-move update.
Writing path: params.path creates the key holding undefined instead of omitting it. Metadata is Schema.Record(Schema.String, Schema.Unknown), and Unknown encodes through Schema.Json, whose guard rejects undefined and recurses into objects and arrays:
Expected JSON value, got undefined
at [0]["metadata"]["path"]
Expected JSON value, got [{"filePath":"a.ts","type":"update","patch":"Index: a.ts","movePath":undefined}]
at [0]["metadata"]["files"]
The fix needs two parts. Strip undefined where the pending request is built at packages/opencode/src/permission/index.ts:92 for the four flat tools, and omit movePath at its construction site, since a top level strip cannot reach inside metadata.files[]. Neither half alone is sufficient; I checked by encoding Schema.Array(PermissionV1.Request) with both metadata shapes.
v1 counterpart of #37650. Originally reported by @su-351917 in #38617 and in #37650 (comment).
Happy to open a PR.
OpenCode version
v1.17.18 as reported; code confirmed present on dev at 7534d235
Steps to reproduce
- Configure permissions to ask.
- Call
glob without the optional path, or apply any ordinary patch with apply_patch.
- While the permission is pending, request
GET /permission.
The endpoint fails to encode its response instead of returning the pending list.
Operating System
Linux, as reported by @su-351917
Description
Five v1 tools write absent optional inputs into permission metadata as
undefined. Encoding theGET /permissionresponse then fails, so one pending request makes the entire listing unreadable. Reported as HTTP 400 on v1.17.18, still present ondevat7534d235.Flat:
packages/opencode/src/tool/glob.ts:34—pathpackages/opencode/src/tool/grep.ts:45—path,includepackages/opencode/src/tool/webfetch.ts:46—timeoutpackages/opencode/src/tool/websearch.ts:125—numResults,livecrawl,type,contextMaxCharactersNested:
packages/opencode/src/tool/apply_patch.ts:201setsmovePath: change.movePathinsidemetadata.files[], undefined for every add, delete, and non-move update.Writing
path: params.pathcreates the key holdingundefinedinstead of omitting it. Metadata isSchema.Record(Schema.String, Schema.Unknown), andUnknownencodes throughSchema.Json, whose guard rejectsundefinedand recurses into objects and arrays:The fix needs two parts. Strip
undefinedwhere the pending request is built atpackages/opencode/src/permission/index.ts:92for the four flat tools, and omitmovePathat its construction site, since a top level strip cannot reach insidemetadata.files[]. Neither half alone is sufficient; I checked by encodingSchema.Array(PermissionV1.Request)with both metadata shapes.v1 counterpart of #37650. Originally reported by @su-351917 in #38617 and in #37650 (comment).
Happy to open a PR.
OpenCode version
v1.17.18 as reported; code confirmed present on
devat7534d235Steps to reproduce
globwithout the optionalpath, or apply any ordinary patch withapply_patch.GET /permission.The endpoint fails to encode its response instead of returning the pending list.
Operating System
Linux, as reported by @su-351917