Skip to content

fix(core): load managed config directory and macOS managed preferences - #51337

Open
rntdrts wants to merge 1 commit into
anomalyco:v2from
rntdrts:fix/managed-config-v2
Open

rntdrts wants to merge 1 commit into
anomalyco:v2from
rntdrts:fix/managed-config-v2

Conversation

@rntdrts

@rntdrts rntdrts commented Sep 25, 2026 •

Copy link
Copy Markdown

Issue for this PR

Closes #51107

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

V1 loaded admin-managed config from the system directory (/Library/Application Support/opencode, /etc/opencode, %ProgramData%\opencode) and, on macOS, from MDM profiles in the ai.opencode.managed domain. The V2 loader never picked either up, so fleets that enforce providers or settings this way lose enforcement on upgrade.

This adds both sources back in Config.load, ranked above every other file. Managed text goes through the same normalize path as other config, so V1-shaped managed files keep working (e.g. enabled_providers becomes deny/allow policies). Wherever policies are evaluated (provider, MCP, skill and plugin checks), managed statements come after authored ones and before Console organization statements.

Managed paths are set through Config.Options (defaulting to the platform locations) rather than env vars, so a user can't point them elsewhere. Tests pass explicit paths, and the core test preload keeps a host's real MDM profile out of other suites.

Not included: watching managed files for changes (they apply on the next reload), and managed-dir plugin discovery.

How did you verify your code works?

  • New tests in test/config/managed.test.ts and test/config/policy.test.ts: override of user/project/inline config, missing and malformed sources, plist ranking above the directory, V1-shaped managed config, and policy ordering against authored and Console statements.
  • Full core suite: same failures as v2 without this change (all environment-related on my machine).
  • Loaded my own Jamf-deployed V1 profile and managed opencode.json through the new loader: both documents load with no normalization diagnostics and provider policies are produced.

Screenshots / recordings

N/A

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

@github-actions

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch from 9db8c32 to 41c5113 Compare September 25, 2026 13:37
@github-actions github-actions Bot added needs:compliance This means the issue will auto-close after 2 hours. and removed needs:compliance This means the issue will auto-close after 2 hours. labels Sep 25, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thanks for updating your PR! It now meets our contributing guidelines. 👍

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch 2 times, most recently from 57b1e7c to 25bc21f Compare September 25, 2026 16:47
@rntdrts

rntdrts commented Sep 27, 2026

Copy link
Copy Markdown
Author

@rekram1-node not sure who to link here, but if someone can please take a look at this, I would appreciate it! 🙏

Thank you in advance!

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch 3 times, most recently from f131e7e to 860b526 Compare September 29, 2026 08:35
@felipecrs

felipecrs commented Sep 29, 2026 •

Copy link
Copy Markdown

I'd also appreciate if this PR was merged (or the bug was fixed).

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch 2 times, most recently from 5b2b686 to 4a89c60 Compare September 30, 2026 09:30
@chetaldrich

Copy link
Copy Markdown

I'd also appreciate if this made it into main, as a user of v1.

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch from 4a89c60 to 8ce51cb Compare October 1, 2026 11:31
@smdahlen

smdahlen commented Oct 2, 2026

Copy link
Copy Markdown

+1 for this PR as well.

@jasontyping

Copy link
Copy Markdown

Strongly support this. This is also a security regression for sandboxed environments that rely on the managed config directory to restrict agents' ability to alter opencode configuration settings.

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch from d071894 to 3053e2f Compare October 6, 2026 12:52
@bilogic

bilogic commented Oct 7, 2026

Copy link
Copy Markdown

deploying?

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch 2 times, most recently from a3bebe5 to fbd6243 Compare October 7, 2026 16:22
@bilogic

bilogic commented Oct 7, 2026

Copy link
Copy Markdown

Actually, opencode v2 does read /home/opencode.json, that's equivalent to /etc/opencode for me

@rntdrts

rntdrts commented Oct 7, 2026 •

Copy link
Copy Markdown
Author

Actually, opencode v2 does read /home/opencode.json, that's equivalent to /etc/opencode for me

Thanks for digging into this! Yes, v2 walks up parent directories, so an opencode.json in /home/ gets picked up when you're working under /home/. But that's project-config discovery, not the managed directory: user/global config still overrides it, and it only applies inside /home/**. Managed config (/etc/opencode, %ProgramData%\opencode, /Library/Application Support/opencode, plus macOS MDM profiles) sits above everything and applies regardless of cwd, that's what this PR restores.

@joe-workman

joe-workman commented Oct 7, 2026 •

Copy link
Copy Markdown

Just wanted to say I built and tested this on macOS/ Windows and was able to push a .mobileconfig / %programData%/opencode config to update my allowed models in OpenCode, this is exactly what I need to manage this in my organization. Anything I can do to help?

@rntdrts

rntdrts commented Oct 7, 2026

Copy link
Copy Markdown
Author

Hi @joe-workman, thank you for taking the time to test it! 🙏 I've been sharing the PR in the Discord channel to catch a maintainer's eye for review. Hopefully, we can get a review soon!

@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch 5 times, most recently from 08c1b30 to 01e49b1 Compare October 8, 2026 13:57
V2 dropped the admin-managed configuration channel V1 supported, so
MDM-deployed profiles and system-managed opencode.json files stopped
being enforced.

Load opencode.json(c) from the system-managed directory and, on macOS,
the ai.opencode.managed plist (MDM metadata keys stripped). Managed
documents rank above every other source, and their policy statements
follow authored ones and precede Console organization statements.

Managed paths come from Config.Options rather than environment
variables, so users cannot redirect them; tests pass explicit paths and
the core test preload keeps host profiles out of other suites.

Fixes anomalyco#51107

Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
@rntdrts
rntdrts force-pushed the fix/managed-config-v2 branch from 01e49b1 to 9ad6c3b Compare October 8, 2026 20:06
@felipecrs

Copy link
Copy Markdown

I don't think there's a need to rebase unless there's a merge conflict.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants