Skip to content

Harden launch security and support all OpenCode Go models - #32

Merged
kartikkabadi merged 4 commits into
mainfrom
devin/1789551911-launch-hardening
Sep 16, 2026
Merged

kartikkabadi merged 4 commits into
mainfrom
devin/1789551911-launch-hardening

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Prepares the proxy for a public launch as an independent, single-user adapter with strict credential, routing, and process-ownership boundaries.

  • route(model) resolves explicit opencode-go/<id>, Zen, and native ownership before dispatch; malformed, unknown, and uncertified Go IDs fail closed
  • all 28 documented Go IDs work through the Responses client API, while the 16 Chat Completions and 8 Anthropic Messages models also support their native direct API formats; streaming and non-streaming requests use family-correct endpoints and authentication
  • macOS has one supervisor (the menu-bar app, no launchd service) and Linux has one systemd user service; both own one loopback listener on 127.0.0.1:8787, with release-pinned sources and truthful adapter identity
  • direct Chat and Messages relays retain upstream 4xx responses but map upstream 5xx failures to local 502, including failures before a streaming response is committed
  • authenticated /models discovery is filtered through the certified protocol map and merged with the offline seed using collision-safe explicit Go slugs
  • remote caller authentication stays separate from Go, Zen, and native credentials; non-loopback operation requires explicit opt-in

Validation: uv sync; 916 pytest tests passed with 2 skipped and 12 subtests; Ruff passed; Python source/wheel build passed; Swift build passed; 6 Swift tests passed; git diff --check passed.


Summary by cubic

Hardens launch security and model routing so the proxy fails closed instead of allowing unauthenticated remote clients or silently swapping unknown models, and routes every documented OpenCode Go model by protocol family.

  • Non-loopback binds now require OPENCODE_GO_PROXY_ALLOW_REMOTE=1 and OPENCODE_GO_PROXY_CALLER_TOKEN (at least 32 characters), and remote clients must send the token in X-OpenCode-Go-Proxy-Token.
  • The token is checked against the actual socket peer, so a forged Host: localhost header no longer admits a remote client.
  • Responses, Chat Completions, and Messages requests now reject unknown or malformed models with 400 before routing; previously unknown IDs silently became deepseek-v4-flash.
  • Go models route by documented family (Responses, Chat, Messages); discovery now uses the authenticated /models endpoint and catalog entries are namespaced opencode-go/<model>.
  • Startup skips reverse-DNS lookups and starts catalog refresh only after the listener is ready.
  • README, security guidance, and the package description now document the single-user credential boundary and remote deployment requirements.

Written for commit 79cb542. Summary will update on new commits.

Review in cubic

Link to Devin session: https://app.devin.ai/sessions/d1b9b744fad04ef69de26d2c4ca6261d
Open in Devin Desktop: https://app.devin.ai/desktop/session/d1b9b744fad04ef69de26d2c4ca6261d?variant=devin
Requested by: @kartikkabadi

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 4172fe89-8a16-46ba-a490-c2c9f998d3b1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

Completed the adversarial end-to-end smoke test against PR #32 head e40bdfa using production proxy subprocesses and isolated local mock upstreams.

Runtime evidence

PR #32 adversarial proxy smoke test

  • Local health became ready in 0.230s.
  • Go seed, user-overlay, native, and Zen models routed to their expected upstream surfaces.
  • Unknown Responses models failed closed with 400 model_not_found and zero upstream calls.
  • Streaming unknown models were rejected as JSON before SSE headers.
  • Unknown-model Chat Completions preserved the complete future-compatible payload and exact response bytes.
  • Forged Host: localhost did not bypass actual remote-peer authentication: missing token returned 401; valid token returned 200.
  • Insecure non-loopback startup exited 2 before listener/state side effects.
  • Listener readiness remained 0.113s with a five-second resolver delay and blocked refresh.
  • server.start preceded catalog.refresh.start.
  • SIGTERM exited cleanly during normal and blocked-refresh operation.

No provider quota or real provider credentials were used. All upstream traffic was captured by local recording services; all ten planned runtime assertions passed.

Devin testing session

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title Harden launch security, routing, and positioning Harden launch security and support all OpenCode Go models Sep 16, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

Tested PR #32 head 79cb542 with the official Codex CLI and macOS desktop app. Live compatibility is not yet fully verified because desktop first launch requires ChatGPT sign-in before the workspace and model picker become available.

Official OpenAI installer Desktop authentication blocker
Official Codex DMG installer ChatGPT sign-in blocker

The managed proxy setup, loopback health, and exact opencode-go/muse-spark-1.3-contributor catalog entry passed. No provider request was sent and no quota was consumed; the live routing assertion remains pending until an entitled user completes ChatGPT sign-in.

Written by Devin

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@kartikkabadi
kartikkabadi merged commit c7374ef into main Sep 16, 2026
5 checks passed
@kartikkabadi

Copy link
Copy Markdown
Owner

Merged locally into main as c7374ef (4 commits + merge) and pushed. Tests: 916 passed, ruff clean. Closing as content is now in main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant