Skip to content

fix: preserve managed prompt dispatch and enforce coding ownership - #648

Merged
chubes4 merged 1 commit into
mainfrom
fix/647-managed-prompt-dispatch
Oct 1, 2026
Merged

chubes4 merged 1 commit into
mainfrom
fix/647-managed-prompt-dispatch

Conversation

@chubes4

@chubes4 chubes4 commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

Fixes #647.

  • Mutate the retained system array in place so OpenCode serializes the filtered instructions, rather than the original array.
  • Normalize fresh/resumed/compaction instruction surfaces and refuse late system/provider reinjection before dispatch.
  • Enforce managed coding-route ownership independently of prompt text, while preserving permitted bridge operations and ordinary quoted data.
  • Add native OpenCode loopback tests to the managed rig and CI; preserve composed guidance around the canonical bridge text.

Verification

The original filter failed the native final-HTTP-payload probe; the candidate passes fresh and resumed requests. The real tool hook refuses a forbidden command before a harmless sentinel executable runs. Deliberate late reinjection produces an actionable diagnostic and zero provider requests.

Passed:

  • node tests/kimaki-dispatch-contract.mjs
  • bash tests/kimaki-managed-plugin-rig.sh (includes native OpenCode dispatch proof)
  • bash tests/kimaki-system-message-patch.sh
  • bash tests/kimaki-agent-fallback.sh
  • node tests/effective-prompt/run.mjs
  • CI coverage, dead-mechanism, duplicate-mechanism, and diff checks

Tests use an isolated temporary project and a loopback model fixture, with no production model account or bot restart. The native probe covers the OpenAI-compatible HTTP path; instruction-option contracts are additionally covered without claiming a paid live OAuth evaluation. The command guard is operational ownership enforcement, not an arbitrary-code sandbox.

AI assistance

OpenAI gpt-6.1-sol through OpenCode directly investigated, implemented, and verified the repair. Chris identified the leaked orchestration route, requested the fix, and authorized landing this PR.

@chubes4
chubes4 merged commit 2a97f21 into main Oct 1, 2026
82 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Managed Kimaki context leaks coding/worktree guidance: add final-dispatch and ownership guards

1 participant