Repository navigation
Conversation
|
Thanks for your contribution! This PR doesn't have a linked issue. All PRs must reference an existing issue. Please:
See CONTRIBUTING.md for details. |
|
The following comment was made by an LLM, it may be inaccurate: |
9db8c32 to
41c5113
Compare
|
Thanks for updating your PR! It now meets our contributing guidelines. 👍 |
57b1e7c to
25bc21f
Compare
|
@rekram1-node not sure who to link here, but if someone can please take a look at this, I would appreciate it! 🙏 Thank you in advance! |
f131e7e to
860b526
Compare
|
I'd also appreciate if this PR was merged (or the bug was fixed). |
5b2b686 to
4a89c60
Compare
|
I'd also appreciate if this made it into main, as a user of v1. |
4a89c60 to
8ce51cb
Compare
|
+1 for this PR as well. |
8ce51cb to
d071894
Compare
|
Strongly support this. This is also a security regression for sandboxed environments that rely on the managed config directory to restrict agents' ability to alter opencode configuration settings. |
d071894 to
3053e2f
Compare
|
deploying? |
a3bebe5 to
fbd6243
Compare
|
Actually, opencode v2 does read |
Thanks for digging into this! Yes, v2 walks up parent directories, so an |
|
Just wanted to say I built and tested this on macOS/ Windows and was able to push a .mobileconfig / %programData%/opencode config to update my allowed models in OpenCode, this is exactly what I need to manage this in my organization. Anything I can do to help? |
|
Hi @joe-workman, thank you for taking the time to test it! 🙏 I've been sharing the PR in the Discord channel to catch a maintainer's eye for review. Hopefully, we can get a review soon! |
08c1b30 to
01e49b1
Compare
V2 dropped the admin-managed configuration channel V1 supported, so MDM-deployed profiles and system-managed opencode.json files stopped being enforced. Load opencode.json(c) from the system-managed directory and, on macOS, the ai.opencode.managed plist (MDM metadata keys stripped). Managed documents rank above every other source, and their policy statements follow authored ones and precede Console organization statements. Managed paths come from Config.Options rather than environment variables, so users cannot redirect them; tests pass explicit paths and the core test preload keeps host profiles out of other suites. Fixes anomalyco#51107 Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
01e49b1 to
9ad6c3b
Compare
|
I don't think there's a need to rebase unless there's a merge conflict. |
Issue for this PR
Closes #51107
Type of change
What does this PR do?
V1 loaded admin-managed config from the system directory (
/Library/Application Support/opencode,/etc/opencode,%ProgramData%\opencode) and, on macOS, from MDM profiles in theai.opencode.manageddomain. The V2 loader never picked either up, so fleets that enforce providers or settings this way lose enforcement on upgrade.This adds both sources back in
Config.load, ranked above every other file. Managed text goes through the same normalize path as other config, so V1-shaped managed files keep working (e.g.enabled_providersbecomes deny/allow policies). Wherever policies are evaluated (provider, MCP, skill and plugin checks), managed statements come after authored ones and before Console organization statements.Managed paths are set through
Config.Options(defaulting to the platform locations) rather than env vars, so a user can't point them elsewhere. Tests pass explicit paths, and the core test preload keeps a host's real MDM profile out of other suites.Not included: watching managed files for changes (they apply on the next reload), and managed-dir plugin discovery.
How did you verify your code works?
test/config/managed.test.tsandtest/config/policy.test.ts: override of user/project/inline config, missing and malformed sources, plist ranking above the directory, V1-shaped managed config, and policy ordering against authored and Console statements.v2without this change (all environment-related on my machine).opencode.jsonthrough the new loader: both documents load with no normalization diagnostics and provider policies are produced.Screenshots / recordings
N/A
Checklist