Skip to content

Commit a7b696f

Browse files
committed
docs: record V2 session-relative memory permission
Describe the OpenCode 2 FileAccess.resolve behavior and the deliberate divergence from Codex, which rebinds the consolidator cwd and managed sandbox to the memory root instead. Refs #7
1 parent 1258cf5 commit a7b696f

2 files changed

Lines changed: 14 additions & 1 deletion

File tree

‎ARCHITECTURE.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -203,7 +203,13 @@ differs by host:
203203
- **OpenCode2:** V2 agents are location-scoped, so helpers spawn in the
204204
active plugin location (`setSubSessionDirectory`). Session boundary is the
205205
project; path permissions scope `read`/`edit` + `external_directory` to the
206-
memory workspace. `glob`/`grep` permissions match search patterns, so V2
206+
memory workspace. OpenCode 2 asserts a session-relative resource when the
207+
target is inside the session or project directory, so the helper session
208+
also allows that posix-relative form of its one root. When the helper runs
209+
at or inside the root, relative grants exclude normalized traversal above
210+
that root and absolute paths outside it. `external_directory` grants remain
211+
absolute. Memory remains global. `glob`/`grep` permissions match
212+
search patterns, so V2
207213
wraps their built-in executors to validate paths against the helper's one
208214
session-granted memory root, defaulting relative searches to that root.
209215
Helper creation supplies session-scoped deny-first rules that narrow access

‎codex-map.yaml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -391,6 +391,13 @@ mappings:
391391
upstream is not emitted (no plugin telemetry backend). OpenCode helper
392392
permissions restrict each job to its own memory root even in dual mode;
393393
V1 uses session external_directory rules, V2 uses session deny-first rules.
394+
DELIBERATE DIVERGENCE (OpenCode 2.0.18 FileAccess.resolve): in-tree targets
395+
are asserted as session-relative resources, so V2 helper rules also allow
396+
the posix-relative form of that one memory root, including helpers at or
397+
inside it, with normalized parent escapes denied. external_directory
398+
grants remain absolute. Codex instead rebinds the consolidator cwd and
399+
managed sandbox to the memory root; these string rules adapt OpenCode's
400+
permission API without changing global memory scope.
394401
- ours: src/workspace.ts
395402
theirs: codex-rs/memories/write/src/storage.rs
396403
note: >

0 commit comments

Comments
 (0)