Conversation
OpenCode 2 refuses to load the plugin that `chainloop trace init` writes: it only loads a default export with an id and a setup function. It also renamed the patch and shell tools, moved `opencode export` to `opencode session export`, and changed the export format, so trace captured nothing even with a loadable plugin. - The plugin has one default export that serves both plugin APIs: server() for OpenCode 1.x (1.3.4 and later) and setup() for OpenCode 2. It runs the hook from the session directory, because OpenCode 2 runs plugins in a shared background server. - The hook handlers recognize the OpenCode 2 tool names (patch, shell) and resolve file paths relative to the session directory. - The session export uses the command of the installed OpenCode major version, and the parser reads both export formats. Closes https://linear.app/chainloop/issue/PFM-7555 Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: f2326c8a-5851-4288-b484-d1a1d4dd86fb
AI Session Checks — 🟢 91% ·
|
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟢 91% | 1 | 100% AI / 0% Human | 11 | +1083 / -358 | 77h49m34s |
🟢 91% — 100% AI — ⚠️ 1 policies failing
-
Oct 2, 2026 09:33 UTC · 77h49m34s · $44.53 · 1.1k in / 534.9k out · claude-code 2.1.287 (claude-opus-5-5)
Change Summary
-
- Rewrites the OpenCode trace plugin to support both 1.x and 2.x hook APIs.
- Adds OpenCode 2 export-command/version handling and v2 session parsing.
- Expands tests, harness checks, golden plugin files, and follow-up fixes for shell call IDs and session duration parsing.
AI Session Overall Score
-
🟢 91% — Well-verified fix; only setup discipline lagged the scope.
AI Session Analysis Breakdown
-
🟢 95% · solution-quality
-
🟢 Root causes were fixed at the plugin, export, and parser layers. · High Impact
🟢 94% · verification
-
🟢 Failing tests, harnesses, and real OpenCode checks covered the shipped behavior. · High Impact
🟢 93% · alignment
-
🟢 The AI clearly marked unfinished work instead of overstating completion. · Medium Impact
🟢 90% · scope-discipline
-
No notes.
🟢 88% · user-trust-signal
-
No notes.
🟡 74% · context-and-planning
-
🟠 Complex OpenCode 2 work proceeded without a shared written plan or TODO list. · Medium Severity
💡 For multi-file protocol migrations, publish a short step list before editing to bound scope and checkpoints.
-
File Attribution
████████████████████100% AI / 0% HumanStatus Attribution File Lines modified ai app/cli/internal/trace/opencode/hooks.go+130 / -88 modified ai .opencode/plugins/chainloop-trace.ts+106 / -77 modified ai app/cli/internal/trace/opencode/testdata/plugin_full.ts+106 / -77 modified ai app/cli/internal/trace/opencode/testdata/plugin_tracerun.ts+103 / -73 modified ai app/cli/internal/trace/opencode/parse_test.go+173 / -2 modified ai app/cli/internal/trace/opencode/hooks_test.go+128 / -32 created ai app/cli/internal/trace/opencode/provider_test.go+107 / -0 modified ai app/cli/internal/trace/opencode/parse.go+92 / -5 modified ai app/cli/internal/trace/opencode/types.go+50 / -1 modified ai app/cli/pkg/action/trace_agent_hook_test.go+46 / -0 modified ai app/cli/internal/trace/opencode/provider.go+42 / -3
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-ai-agents-allowedai-coding-session-f2326c- ✅ Passed ai-config-no-dangerous-commandsai-coding-session-f2326c- ✅ Passed ai-config-mcp-servers-allowedai-coding-session-f2326c- ⚠️ Failedai-config-no-secretsai-coding-session-f2326c- Secret ([REDACTED:generic-credential-uri) detected in session content [turn=1530, source=tool_result, line=1]: {"author":"javirln","comments":[{"author":"chainloop-platform","body":"\u003c!-- chainloop-pr-analysis:v1 --\u003e\n## AI Session Checks — 🟢 91% ·
⚠️ 2 failing\n\n| Avg score | Sessions | Failing poli... - Secret (generic-credential-uri) detected in session content [turn=1530, source=tool_result, line=1]: {"author":"javirln","comments":[{"author":"chainloop-platform","body":"\u003c!-- chainloop-pr-analysis:v1 --\u003e\n## AI Session Checks — 🟢 91% ·
⚠️ 2 failing\n\n| Avg score | Sessions | Failing poli... - Secret (generic-password) detected in session content [turn=1428, source=tool_result, line=2]: INF redacted secrets from the AI coding session before upload count=14 rules=["generic-[REDACTED:generic-password]","jwt"]
- Secret (generic-password) detected in session content [turn=2578, source=tool_result, line=107]: .attestation.policy_evaluations.ai-coding-session-ses-ef[2].description = Verifies that AI agent configuration files (instructions, skills, MCP config) and AI coding session transcripts do not contain...
- Secret (jwt) detected in session content [turn=1530, source=tool_result, line=1]: {"author":"javirln","comments":[{"author":"chainloop-platform","body":"\u003c!-- chainloop-pr-analysis:v1 --\u003e\n## AI Session Checks — 🟢 91% ·
⚠️ 2 failing\n\n| Avg score | Sessions | Failing poli...
-
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ security-context — no advisories
Nothing this change touches has a recorded security-fix history.
View security context ↗ · Security context documentation ↗
⏭️ 3 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
PR validation — ⚠️ 1 failing
| Status | Policy | Material | Messages |
|---|---|---|---|
pr-min-approvals |
pr-info |
|
|
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
jiparis
left a comment
There was a problem hiding this comment.
please fix the conflicts, and re-check if there are additional fixes to be done (there are additional hooks)
Main added the session-start instruction for spec capture (#3500), which the OpenCode plugin posts to the session. The plugin is rewritten on this branch, so the instruction is ported to both of its entry points. OpenCode 1.x posts it with client.session.prompt and noReply, as main does. OpenCode 2 posts it with ctx.session.synthetic and resume: false, and its prompt hook waits for a session start still in flight, so the instruction is stored before the first prompt. Neither posts it to a subagent's session. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
Main now sends the tool call ID as tool_use_id on the shell hooks, so that overlapping commands keep their own snapshots (#3521). The plugin is rewritten on this branch, so both of its entry points send it: OpenCode 1.x names the ID callID, and OpenCode 2 names it id. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev>
OpenCode 2 sets info.time.updated when the session record changes, such as when the session gets its title seconds in, not on every message. A session parsed from its export was recorded as lasting a few seconds. The session now ends at its last message of any type, or at info.time.updated if that is later. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: f2326c8a-5851-4288-b484-d1a1d4dd86fb
|
(This is Claude Code, replying for @javirln.) @jiparis Conflicts fixed. The two hooks main added now work with both OpenCode 1.x and OpenCode 2:
Tested end to end with OpenCode 2: https://app.chainloop.dev/u/chainloop/sessions/ses_ef3540a26ffeKeCF0Wj7mW2Me5. The test also found a wrong session duration, which bec4f7a fixes, and a spec capture bug that is not specific to OpenCode, filed as PFM-7583. |
|
(This is Claude Code, replying for @javirln.)
|

OpenCode 2 refuses to load the plugin that
chainloop trace initwrites ("Plugin must export a default definition with an id and an effect or setup function"). OpenCode 2 also changed three other things that trace relies on, so trace captured nothing from an OpenCode 2 session even with a loadable plugin.This change:
server()for OpenCode 1.x andsetup()for OpenCode 2. OpenCode 2 runs plugins in a shared background server, so the plugin runs the hook from the session directory instead of the process working directory.patchandshell(apply_patchandbashin 1.x), and resolves file paths relative to the session directory, which the OpenCode 2 edit, write and patch tools accept.opencode session exporton OpenCode 2 andopencode exporton 1.x, picked fromopencode --version, and reads both export formats.OpenCode 1.3.3 and older (March 2026) cannot load the new plugin, because they call every export as a function. A repository with a plugin from an older CLI keeps failing on OpenCode 2 until
chainloop trace init --opencoderuns again. Evidence from an OpenCode 2 session has no agent version, because the OpenCode 2 export has none.Closes https://linear.app/chainloop/issue/PFM-7555
AI assistance: written with Claude Code.