OpenCode Vitals 0.1.2
What this release contains
The audit fixes, published as they were. 0.1.1 went to npm before an audit of the shipped code, so it contains the two dangerous bugs below; 0.1.2 is 0.1.1 plus every fix, each with a test that fails on the old behaviour.
- Windows: the liveness check killed the process it checked. Python hands any signal other than
CTRL_C_EVENT/CTRL_BREAK_EVENTtoTerminateProcess, soos.kill(pid, 0)would have terminated the OpenCode process the bar belongs to. Windows now asksOpenProcess/GetExitCodeProcess. - A bar that died at once was retried every five seconds forever — measured four spawns in sixteen seconds. Short-lived exits back off 15s, 30s, 60s … capped at five minutes, with the reason logged once. After the fix: attempts at 0s, 15s and 30s over fifty seconds.
- A failed compaction swallowed the next response — measured zero records where one was expected.
- Signalling trusted the pid alone, so a recycled pid in a stale lock could receive SIGTERM; nothing is signalled unless the command line says
bar.py. - A malformed event no longer ends the subscription. The host call for missing token counts has a deadline. The storage lock waits before its fail-open path. Session totals are evicted by least recently updated.
- The installer follows OpenCode's real plugin path (
XDG_CONFIG_HOME || ~/.config) on every platform,--forceover a file no longer crashes, and--uninstallrefuses to remove a stranger. - The selftest no longer counts any plugin folder as an installed Vitals, and no longer calls a machine untrustworthy before the plugin is installed: runtime facts are notes, and the verdict names the real state.
One thing in this release does not work
The install command this release's README prints, npx opencode-vitals-install, is answered with 404 by npm — npx resolves package names, and that is the name of a file inside the package — and the installer exits silently with no output when npm runs it through its shim. Both are fixed in 0.1.3, which is otherwise the same code: npx opencode-vitals install.
Measured
- 156 plugin checks and 56 bar checks, up from 132 and 44. Both headline fixes were re-measured with the same probes that found them.
Upgrading from 0.1.1: npx --package=opencode-vitals@0.1.2 -- opencode-vitals-install does not work, so either add the plugins entry and let OpenCode resolve this version, or use 0.1.3 and run npx opencode-vitals install.