You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
[0.3.0] - 2026-09-06
Added
Add /cross-review-audit and the cross_review_audit tool to inspect a
parent session's owned runs through the local run-store and SDK sessions,
reporting protocol checks and role behavior without reading OpenCode
internal storage.
Accept an optional gitcodeCli absolute path in cross-review config and
persist it from guided setup after npx open-codeasier detect-gitcode
locates gitcode-cli (PATH, then ~/miniconda3 / ~/anaconda3 including env bin/Scripts; --version output must contain gitcode, so a Graphviz gc is ignored). GitCode targets (gitcode.com URLs or remotes) fetch
PR/Issue details with that CLI in the parent session and always pass context; GitHub fetching still uses gh.
Changed
Load project .opencode/cross-review.json exclusively when present, without
reading or merging ~/.config/opencode/cross-review.json. Global fallback
applies only when the project file is absent. A present-but-empty project
config, including the model-free {} created by init, is no longer
backfilled from global; tell callers to configure reviewers in the existing
project file or pass --review-models.
Fixed
Embed non-PR shared context up to the 1,000,000-character schema cap
instead of silently clipping reviewer briefs (and judge briefs for
parent-provided context) at 100,000 characters, set warning when
gatherer output or an unenforced parent context still exceeds the
embed limit, and tighten that budget from the tightest known
reviewer/judge limit.context (4 ASCII chars/token, 1 non-ASCII
char/token, 25% reserve) so a typical payload cannot blow a smaller
known window. Models without limit.context still use the 1M schema
cap.
Treat never-dispatched cross-review roles as insufficient-evidence in /cross-review-audit, keep per-run protocol timelines attributed by runID, and let a later silent-model-replace fail win over an earlier
truncated session.
Fail /cross-review-audit silent-model-replace on a visible prompt-model
mismatch even when that session is truncated, and treat cancelled/failed
roles that never landed a prompt as insufficient-evidence.
Continue gitcode-cli discovery when a PATH entry is unreadable or not a
directory, and when listing conda env directories fails with EPERM, so detect-gitcode no longer crashes on those filesystem errors.
Treat host type-default cross-review overrides (reviewModels: [] and 0
for agents, maxConcurrency, and reviewerTimeoutMs) as omitted so they
fall back to the loaded config instead of failing validation before it is
applied. Truly illegal overrides still fail fast. Empty or zero values that
still reach validation mention omitting the argument to use config. Blank judgeModel still means parent-session judging; empty focus is unchanged.
Harden the asynchronous cross-review parent-session protocol. Finalize
rejects while gathering, reviewers, the explicit judge, or a pending
timeout decision are still active, so it cannot be used as a poll; readyToFinalize is true when reviewers are terminal, the explicit
judge is terminal, or the run is already in a terminal phase. A timeoutAction on the poll that first observes an already-overdue
session is applied instead of being ignored. Empty or
whitespace-only context is omitted,
including PR snapshot notes.md. A stray timeoutAction on an
ordinary poll is ignored with a warning, including abort after a
preserved session has already finished.
Reject a non-PR cross_review_start or legacy cross_review when
parent-session judging omits context, instead of dispatching
reviewers with a warning. Read-only reviewer, gatherer, and judge
briefs now forbid .git/** reads, guessed historical or host-absolute
paths, whole-tree glob/re-read detours, and webfetch retries after
403/404/429.