From 822fc5bed409191f60dbbceb39c8ffb50736f417 Mon Sep 17 00:00:00 2001 From: Neil <4138956+nwparker@users.noreply.github.com> Date: Sun, 4 Oct 2026 19:34:47 -0700 Subject: [PATCH] Add repository OpenCode permission defaults (#25326) * test(config): reproduce rejected repository OpenCode config * Add repository OpenCode permissions and allow its reviewed root config * fix: preserve sensitive OpenCode confirmation prompts --------- Co-authored-by: Orca campaign recovery Co-authored-by: Orca OpenCode Campaign --- .../scripts/check-root-directory-entries.mjs | 5 ++--- .../check-root-directory-entries.test.mjs | 11 +++++++++++ opencode.json | 17 +++++++++++++++++ 3 files changed, 30 insertions(+), 3 deletions(-) create mode 100644 opencode.json diff --git a/.github/scripts/check-root-directory-entries.mjs b/.github/scripts/check-root-directory-entries.mjs index 5b63326691d..a428c8cc090 100644 --- a/.github/scripts/check-root-directory-entries.mjs +++ b/.github/scripts/check-root-directory-entries.mjs @@ -13,9 +13,8 @@ function readRootEntries(sha) { return stdout.split('\0').filter(Boolean) } -// Why: the Cloud workspace import is the one reviewed root addition; it stays -// listed until it lands on main, after which the base tree carries it. -const REVIEWED_ROOT_ENTRIES = new Set(['cloud']) +// These reviewed additions stay listed until the base tree carries them. +const REVIEWED_ROOT_ENTRIES = new Set(['cloud', 'opencode.json']) function checkRootDirectoryEntries(argv) { if (argv.length !== 2) { diff --git a/config/scripts/check-root-directory-entries.test.mjs b/config/scripts/check-root-directory-entries.test.mjs index 6de07a053c7..57da7adbd95 100644 --- a/config/scripts/check-root-directory-entries.test.mjs +++ b/config/scripts/check-root-directory-entries.test.mjs @@ -114,6 +114,17 @@ describe('root directory guard', () => { expect(result.status).toBe(0) }) + it('allows the reviewed repository OpenCode permission config', () => { + const fixture = makeFixture() + const head = commitFiles(fixture.root, [ + ['opencode.json', '{"permission":{"*":{"*":"allow"}}}\n'] + ]) + + const result = runGuard({ ...fixture, head }) + + expect(result.status).toBe(0) + }) + it('rejects a new top-level directory', () => { const fixture = makeFixture() const head = commitFiles(fixture.root, [['new-folder/file.txt', 'too prominent\n']]) diff --git a/opencode.json b/opencode.json new file mode 100644 index 00000000000..030babec933 --- /dev/null +++ b/opencode.json @@ -0,0 +1,17 @@ +{ + "$schema": "https://opencode.ai/config.json", + "permission": { + "*": { + "*": "allow" + }, + "read": { + "*.env": "ask", + "*.env.*": "ask", + "*.env.example": "allow" + }, + "external_directory": { + "*": "ask" + }, + "doom_loop": "ask" + } +}