Conversation
OpenCode 2 refuses to load the plugin that `chainloop trace init` writes: it only loads a default export with an id and a setup function. It also renamed the patch and shell tools, moved `opencode export` to `opencode session export`, and changed the export format, so trace captured nothing even with a loadable plugin. - The plugin has one default export that serves both plugin APIs: server() for OpenCode 1.x (1.3.4 and later) and setup() for OpenCode 2. It runs the hook from the session directory, because OpenCode 2 runs plugins in a shared background server. - The hook handlers recognize the OpenCode 2 tool names (patch, shell) and resolve file paths relative to the session directory. - The session export uses the command of the installed OpenCode major version, and the parser reads both export formats. Closes https://linear.app/chainloop/issue/PFM-7555 Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: f2326c8a-5851-4288-b484-d1a1d4dd86fb
AI Session Checks — 🟢 88% ·
|
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟢 88% | 1 | 100% AI / 0% Human | 11 | +1070 / -356 | 25m14s |
🟢 88% — 100% AI — ⚠️ 1 policies failing
-
Oct 2, 2026 09:33 UTC · 25m14s · $25.86 · 604 in / 305.8k out · claude-code 2.1.287 (claude-opus-5-5)
Change Summary
-
- Adds dual-major OpenCode plugin support with a default export and session-relative hook execution.
- Updates trace capture for renamed OpenCode 2 tools, versioned export commands, and the new export JSON format.
- Adds and refreshes trace tests, plugin golden files, and an action test for relative-path handling.
AI Session Overall Score
-
🟢 88% — Strong root-cause fix with solid verification; planning stayed implicit for a broad change.
AI Session Analysis Breakdown
-
🟢 94% · solution-quality
-
🟢 AI established root cause before fixing and wrote failing tests first. · High Impact
🟢 92% · alignment
-
No notes.
🟢 89% · scope-discipline
-
🟢 Final staged files stayed inside trace integration code, generated plugins, and adjacent tests. · High Impact
🟢 88% · user-trust-signal
-
No notes.
🟢 84% · verification
-
🟢 AI added and ran new trace tests, then reran the broader trace, action, and cmd suites cleanly. · High Impact
🟠 No live OpenCode 2 session with a real model was run; verification stopped at harnesses and export replay. · Medium Severity
💡 For cross-tool integrations, finish with one real end-to-end run when cost permits.
🟡 72% · context-and-planning
-
🟠 The multi-file integration fix began from a ticket link and skill stubs, with no explicit shared plan before edits. · Medium Severity
💡 For broad integration fixes, write a short visible plan before editing so checkpoints stay explicit.
-
File Attribution
████████████████████100% AI / 0% HumanStatus Attribution File Lines modified ai app/cli/internal/trace/opencode/hooks.go+130 / -88 modified ai .opencode/plugins/chainloop-trace.ts+106 / -77 modified ai app/cli/internal/trace/opencode/testdata/plugin_full.ts+106 / -77 modified ai app/cli/internal/trace/opencode/testdata/plugin_tracerun.ts+103 / -73 modified ai app/cli/internal/trace/opencode/parse_test.go+167 / -0 modified ai app/cli/internal/trace/opencode/hooks_test.go+128 / -32 created ai app/cli/internal/trace/opencode/provider_test.go+107 / -0 modified ai app/cli/internal/trace/opencode/parse.go+85 / -5 modified ai app/cli/internal/trace/opencode/types.go+50 / -1 modified ai app/cli/pkg/action/trace_agent_hook_test.go+46 / -0 modified ai app/cli/internal/trace/opencode/provider.go+42 / -3
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-mcp-servers-allowedai-coding-session-f2326c- ✅ Passed ai-config-ai-agents-allowedai-coding-session-f2326c- ✅ Passed ai-config-no-dangerous-commandsai-coding-session-f2326c- ⚠️ Failedai-config-no-secretsai-coding-session-f2326cSecret (jwt) detected in session content [turn=64, source=tool_result, line=1]: [REDACTED:jwt] -
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ security-context — no advisories
Nothing this change touches has a recorded security-fix history.
View security context ↗ · Security context documentation ↗
⏭️ 3 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
PR validation — ⚠️ 1 failing
| Status | Policy | Material | Messages |
|---|---|---|---|
pr-min-approvals |
pr-info |
PR/MR #3511 has 0 approving reviews, 1 required. | |
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
OpenCode 2 refuses to load the plugin that
chainloop trace initwrites ("Plugin must export a default definition with an id and an effect or setup function"). OpenCode 2 also changed three other things that trace relies on, so trace captured nothing from an OpenCode 2 session even with a loadable plugin.This change:
server()for OpenCode 1.x andsetup()for OpenCode 2. OpenCode 2 runs plugins in a shared background server, so the plugin runs the hook from the session directory instead of the process working directory.patchandshell(apply_patchandbashin 1.x), and resolves file paths relative to the session directory, which the OpenCode 2 edit, write and patch tools accept.opencode session exporton OpenCode 2 andopencode exporton 1.x, picked fromopencode --version, and reads both export formats.OpenCode 1.3.3 and older (March 2026) cannot load the new plugin, because they call every export as a function. A repository with a plugin from an older CLI keeps failing on OpenCode 2 until
chainloop trace init --opencoderuns again. Evidence from an OpenCode 2 session has no agent version, because the OpenCode 2 export has none.Closes https://linear.app/chainloop/issue/PFM-7555
AI assistance: written with Claude Code.