Create-session runs EnsureProjectOpencode before platform validation #533

Closed
opened 2026-08-20 02:55:18 +02:00 by dries · 1 comment
Owner

Found during review of PR #523 (fix: relaunch a killed opencode on local create). Shape is pre-existing on the remote path; the PR extended it to local.

In the create-session handler (internal/server/handlers.go), the ensure step runs before the platform id is validated. A request naming an unknown/unregistered platform still triggers EnsureProjectOpencode — launching a managed opencode instance (tmux pane, port allocation, managed_opencode row) for a request that is then rejected.

Fix: validate the platform (and any other cheap request validation) before the ensure side effect, on both local and remote paths. Cheap reorder; add a handler test asserting an invalid-platform create performs no ensure call (the shared fakePlatform harness in internal/server should cover this).

Found during review of PR #523 (fix: relaunch a killed opencode on local create). Shape is pre-existing on the remote path; the PR extended it to local. In the create-session handler (`internal/server/handlers.go`), the ensure step runs **before** the platform id is validated. A request naming an unknown/unregistered platform still triggers `EnsureProjectOpencode` — launching a managed opencode instance (tmux pane, port allocation, `managed_opencode` row) for a request that is then rejected. Fix: validate the platform (and any other cheap request validation) before the ensure side effect, on both local and remote paths. Cheap reorder; add a handler test asserting an invalid-platform create performs no ensure call (the shared `fakePlatform` harness in `internal/server` should cover this).
Author
Owner

Validated against main @ 2d661364: remote path only. On main there is no local pre-ensure at all (handlers.go:474-479: local Create discovers/launches its own port); PR #523 is unmerged, so the local half doesn't apply yet. The remote half is real today: host.EnsureProjectOpencode (handlers.go:487) runs before sessions.Create validates the platform (sessionsvc/service.go:316-318), and resolveOwner only validates the remote id — so r-:bogus launches a managed opencode on the remote before rejection. Fix the remote ordering now; re-check the local path in PR #523's review.

Validated against main @ 2d661364: **remote path only**. On main there is no local pre-ensure at all (handlers.go:474-479: local Create discovers/launches its own port); PR #523 is unmerged, so the local half doesn't apply yet. The remote half is real today: host.EnsureProjectOpencode (handlers.go:487) runs before sessions.Create validates the platform (sessionsvc/service.go:316-318), and resolveOwner only validates the remote id — so r-<remote>:bogus launches a managed opencode on the remote before rejection. Fix the remote ordering now; re-check the local path in PR #523's review.
dries closed this issue 2026-08-20 23:12:38 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dries/ocman#533
No description provided.