mirror of
https://github.com/getpaseo/paseo.git
synced 2026-07-29 12:01:31 +00:00
fix(opencode): prevent indexing the entire home directory (#1704)
* fix(opencode): prevent indexing the entire home directory Paseo launches opencode serve with cwd=os.homedir() and refreshes the global provider snapshot with directory=/Users/admin. OpenCode treats that as a workspace and starts location services + bigram indexing for the entire home tree, causing ~466% CPU and ~4GB RAM usage. - Use a neutral scratch directory as the opencode serve cwd. - Use a separate scratch directory for global provider catalog refresh so model/mode discovery no longer triggers home directory indexing. Fixes high CPU/RAM when Paseo starts opencode with no explicit project. * fix(opencode): use realpath-aware matcher for home detection in catalog refresh Switch the home-directory check in fetchCatalog from a string-based path.resolve() comparison to createRealpathAwarePathMatcher, so we catch macOS /private/var/... aliases, symlinks, trailing separators, and Windows casing — consistent with the rest of opencode-agent.ts. Also: - Hoist the matcher to module scope so each fetchCatalog call doesn't rebuild it (the matcher runs realpathSync twice on construction). - Log a debug line when we rewrite the cwd to the scratch path, so it's easy to diagnose missing per-directory config in catalog scope. - Update opencode-agent.test.ts to expect the scratch directory when cwd === os.homedir(), with a comment pointing to the rationale. * fix(opencode): isolate helper server home * fix(opencode): pass semantic global catalog scope * fix(opencode): release catalog acquisition on home resolution failure --------- Co-authored-by: rex-chang <rex-chang@users.noreply.github.com> Co-authored-by: Mohamed Boudra <boudra.moha@gmail.com>
This commit is contained in:
@@ -56,15 +56,15 @@ Daemon bootstrap reconciles that ledger in the background, without blocking star
|
||||
|
||||
## Provider Snapshot Refresh Contract
|
||||
|
||||
The daemon keeps provider snapshots per resolved working directory. Missing or blank cwd resolves to the user's home directory. Workspace selectors and old model/mode list requests should pass the cwd that will launch the provider so providers with project-specific models or modes are probed in the right context. Settings/provider management intentionally uses the home-directory snapshot.
|
||||
The daemon keeps provider snapshots per resolved working directory, with a separate semantic global scope for settings/provider management and requests that do not carry a cwd. Provider catalog probes receive a discriminated `FetchCatalogOptions`: `{ scope: "global", force }` for global catalog refreshes, or `{ scope: "workspace", cwd, force }` for project-scoped refreshes. Providers decide what global means for their runtime; do not infer global by comparing a cwd to the user's home directory.
|
||||
|
||||
Snapshot reads may probe providers only while the requested cwd scope is cold. Once an entry is warm, its `ready`, `error`, or `unavailable` state stays cached until an explicit refresh. Do not add TTL revalidation, focus-triggered refreshes, selector-open refreshes, or config-reload refreshes. Selector-open refetches may read an already-loading or stale React Query, but they must not force provider probing on their own.
|
||||
|
||||
Settings refresh is the user-facing "forget stale provider knowledge everywhere" action. A settings refresh clears provider snapshot caches and in-flight loads across all cwd scopes, then immediately refreshes only the home-directory snapshot with `force: true`. Workspace snapshots are re-probed lazily on the next scoped read; do not fan out a settings refresh across every known workspace.
|
||||
Settings refresh is the user-facing "forget stale provider knowledge everywhere" action. A settings refresh clears provider snapshot caches and in-flight loads across all cwd scopes, then immediately refreshes only the global snapshot with `force: true`. Workspace snapshots are re-probed lazily on the next scoped read; do not fan out a settings refresh across every known workspace.
|
||||
|
||||
Registry/config replacement may update visible metadata such as label, description, default mode, enabled state, and provider membership, but it must not spawn provider processes. If a provider needs to be re-probed after a config change, route that through the explicit settings refresh path.
|
||||
|
||||
Boundary tests should assert observable behavior: cold reads may call provider availability/model/mode discovery for that cwd; warm reads and registry replacement must not; explicit workspace refreshes affect only one cwd; settings refresh wipes all scopes but immediately refreshes only home.
|
||||
Boundary tests should assert observable behavior: cold reads may call provider availability/model/mode discovery for that scope; warm reads and registry replacement must not; explicit workspace refreshes affect only one cwd; settings refresh wipes all scopes but immediately refreshes only global.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user