Create-session runs EnsureProjectOpencode before platform validation #533
Labels
No labels
backend
bug
chore
duplication
effort:complex
effort:medium
effort:trivial
enhancement
follow-up
frontend
fullstack
priority:high
ready-for-agent
refactor
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
dries/ocman#533
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found during review of PR #523 (fix: relaunch a killed opencode on local create). Shape is pre-existing on the remote path; the PR extended it to local.
In the create-session handler (
internal/server/handlers.go), the ensure step runs before the platform id is validated. A request naming an unknown/unregistered platform still triggersEnsureProjectOpencode— launching a managed opencode instance (tmux pane, port allocation,managed_opencoderow) for a request that is then rejected.Fix: validate the platform (and any other cheap request validation) before the ensure side effect, on both local and remote paths. Cheap reorder; add a handler test asserting an invalid-platform create performs no ensure call (the shared
fakePlatformharness ininternal/servershould cover this).Validated against main @
2d661364: remote path only. On main there is no local pre-ensure at all (handlers.go:474-479: local Create discovers/launches its own port); PR #523 is unmerged, so the local half doesn't apply yet. The remote half is real today: host.EnsureProjectOpencode (handlers.go:487) runs before sessions.Create validates the platform (sessionsvc/service.go:316-318), and resolveOwner only validates the remote id — so r-:bogus launches a managed opencode on the remote before rejection. Fix the remote ordering now; re-check the local path in PR #523's review.