Important
Decision Surface
Problem: No type definitions or config parsing exist for per-model trust-tier permissions.
Approach: Define the TrustTier, DirectoryPermissions, Effect, and ProviderPermissionsConfig schema types. Add config parsing and validation with 4 default tier presets (Trusted, Limited, Untrusted, Unassigned).
Scope: Schema types + config parsing + validation + defaults. No runtime enforcement yet.
Acceptance Criteria
ProviderPermissionsConfig, TrustTier, DirectoryPermissions, and Effect types are exported from packages/schema/src/
Config parser reads providerPermissions from opencode.jsonc and validates it against the schema
Invalid configs (missing fields, unknown effects, duplicate tier IDs) produce clear error messages
When providerPermissions is absent from config, 4 default tiers are created: Trusted (all allow), Limited (read allow, rest deny), Untrusted (all deny), Unassigned (all ask)
The defaultTier field must reference an existing tier ID; validation rejects orphan references
Model assignments map modelId → tierId; validation rejects assignments to non-existent tiers
Directory keys are valid glob patterns
Key Decisions
#
Decision
Rationale
1
4 action groups (read/write/execute/network), not 8+ individual fields
Covers the real privacy boundaries while keeping the schema cognitively manageable
2
Presets are created at parse-time when config is absent, not hardcoded elsewhere
Single source of truth for defaults; tests can override
Data Contract
type Effect = "allow" | "deny" | "ask"
type DirectoryPermissions = {
read : Effect
write : Effect
execute : Effect
network : Effect
}
type TrustTier = {
id : string
label : string
directories : Record < string , DirectoryPermissions >
}
type ProviderPermissionsConfig = {
defaultTier : string
tiers : TrustTier [ ]
assignments : Record < string , string >
}
Testing Decisions
Schema validation: test valid configs parse, invalid configs reject with specific errors
Default creation: test absent config produces the 4 preset tiers
Assignment validation: test orphan tier references are rejected
Glob validation: test invalid glob patterns are caught
Constraints & Invariants
The "Unassigned" tier must always exist in the parsed config (validation enforces this)
Tier IDs are unique within the array
A model appears in assignments at most once
Source
Part of #163
Important
Decision Surface
Problem: No type definitions or config parsing exist for per-model trust-tier permissions.
Approach: Define the
TrustTier,DirectoryPermissions,Effect, andProviderPermissionsConfigschema types. Add config parsing and validation with 4 default tier presets (Trusted, Limited, Untrusted, Unassigned).Scope: Schema types + config parsing + validation + defaults. No runtime enforcement yet.
Acceptance Criteria
ProviderPermissionsConfig,TrustTier,DirectoryPermissions, andEffecttypes are exported frompackages/schema/src/providerPermissionsfromopencode.jsoncand validates it against the schemaproviderPermissionsis absent from config, 4 default tiers are created: Trusted (all allow), Limited (read allow, rest deny), Untrusted (all deny), Unassigned (all ask)defaultTierfield must reference an existing tier ID; validation rejects orphan referencesmodelId → tierId; validation rejects assignments to non-existent tiersKey Decisions
Data Contract
Testing Decisions
Constraints & Invariants
Source
Part of #163