Skip to content

OpenCode Merge v1.18.21…v1.18.26 - #14449

Merged
marius-kilocode merged 167 commits into
mainfrom
marius-kilocode/kilo-opencode-v1.18.26
Sep 25, 2026
Merged

marius-kilocode merged 167 commits into
mainfrom
marius-kilocode/kilo-opencode-v1.18.26

Conversation

@marius-kilocode

@marius-kilocode marius-kilocode commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

OpenCode v1.18.26

Core

Improvements

  • Azure CLI sign-in now asks for the resource name directly instead of querying Azure management APIs.

Bugfixes

  • Claude 5 sessions now tolerate stale thinking blocks instead of failing after prompt or tool changes.
  • Bedrock GPT-5.6 models now accept none reasoning effort.
  • Bedrock reasoning and replay handling is more reliable.
  • Tool call timing now stays accurate when tools update their metadata while still running.
  • apply_patch no longer emits an empty move path in permission metadata.

OpenCode v1.18.25

Core

Bugfixes

  • Fixed Azure authentication so Azure CLI sign-in works without requiring Bun.

OpenCode v1.18.24

Core

Improvements

  • Azure providers can now sign in with Microsoft Entra ID through the Azure CLI instead of requiring an API key.
  • V1 now reads supported V2 config fields so newer config files keep working in more mixed setups.

Bugfixes

  • Bedrock reasoning responses no longer get cached into unreplayable empty messages.

OpenCode v1.18.23

Core

Bugfixes

  • Fixed Cloudflare AI Gateway routing for third-party providers so non-Workers models work through the gateway's REST API.
  • Fixed Anthropic models through Cloudflare AI Gateway by converting dotted model IDs like claude-haiku-4.5 to the dashed slug Anthropic expects.
  • Fixed parent session IDs being sent in request headers for session-aware providers.

TUI

Bugfixes

  • Fixed GitHub auth for immutable OIDC subject tokens.

OpenCode v1.18.22

Core

Bugfixes

  • Removed outdated OpenCode Go first-month discount messaging and pricing.
  • Fixed OpenCode device login links when servers return relative verification URLs or use a base path.
  • Fixed textVerbosity being sent to OpenAI-compatible providers that do not support it.
  • Updated the Amazon Bedrock provider for compatibility fixes.

OpenCode v1.18.21

Core

Bugfixes

  • Continue responses when a model reports an unknown finish reason instead of stopping early.
  • Route Vertex AI eu and us multi-region Gemini requests through REP endpoints.

Merge decisions

Where Kilo intentionally differs from upstream, Kilo behavior is preserved and the upstream test is adapted with a kilocode_change note:

  • Azure auth: keeps Kilo's resource-name or full-endpoint prompts (Support Azure OpenAI endpoint setup #10016) and adopts upstream's Microsoft Entra ID sign-in through the Azure CLI. The client User-Agent stays kilocode/. The Entra ID method stays hidden unless the az CLI is available.
  • Provider headers: keeps Kilo's x-kilocode-mode and X-KILOCODE-* headers and also sends upstream's x-parent-session-id; the header keys are disjoint.
  • Bedrock reasoning replay: the unsigned-reasoning filter stays gated to Claude models, not every Bedrock model.
  • Retry: Kilo still returns no OpenCode Go upsell for FreeUsageLimitError/GoUsageLimitError.
  • Unknown stream finish: Kilo uses its bounded incomplete-response recovery instead of continuing every unknown finish at the prompt-loop boundary, so upstream's "loop continues when finish is unknown" test is adapted to Kilo's settled outcome.
  • Config: keeps Kilo's normalizeLoadedConfig, excess-key warnings, updateProjectConfig delegation, and global merge/preserve behavior, and adopts upstream's V2-compat lowering.
  • Session tools: keeps Kilo's finish/Board notice handling, sandbox flags, processor.metadata, and askPermission provenance.

Merge repairs

  • Restored the SDK ./permission export and the client ./promise and ui ./file-path, ./session-diff, ./pierre subpath exports that the merge dropped.
  • Restored the root check:architecture and check:duplication scripts and the CLI test:httpapi --shards 4 flag.
  • Kept the Kilo workspace dependency for @opencode-ai/client in session-ui instead of upstream's packages/app vendored tarball, which does not exist in this repo.
  • Restored the HttpServerRequest import required by the Kilo SSE event stream.
  • Kept the Kilo-Org repository URLs in packages/http-recorder.
  • Excluded the Azure OAuth scope URLs from the source-links extractor so the link checker does not treat them as documentation links.
  • Removed the upstream-only unlock.yml SST workflow.
  • Regenerated the SDK, client, docs tables, and CLI reference; updated source links.

Adapted upstream tests

  • v2-compat read fixtures include Kilo's default experimental.openTelemetry: true.
  • V2 loading test expects Kilo's built-in plugins instead of an empty plugin list.
  • Global update diagnostics test expects the kilo.json global config path.
  • update-global/update-project v1-overrides outputs reflect Kilo's stripNulls empty-object cleanup.
  • update-project fixtures and native-permission tests target kilo.json instead of config.json.
  • Native project permission rejection asserts Kilo's graceful skip-with-warning contract.
  • Session tools test uses Kilo's resolve contract and processor.metadata.
  • Bedrock replay test keeps the Claude-only filter behavior.
  • Patched dependency guard accepts a workspace that resolves another patched version of the same dependency, because Kilo patches both @ai-sdk/openai-compatible 2.0.41 (nested Alibaba consumer) and 2.0.48 (direct).

Validation

Local checks:

  • bun turbo typecheck: 30 tasks successful (includes JetBrains and webview).
  • bun run compile (extension): check-types, webview types, lint, and bundle pass.
  • bun test ./test/provider: 612 pass, 0 fail.
  • bun test ./test/session: 469 pass, 0 fail.
  • bun test ./test/config: 245 pass, 0 fail.
  • bun test ./test/patched-dependencies.test.ts: 22 pass, 0 fail.
  • Kilo suites (test/kilocode/server, test/kilocode/config, test/kilocode/session): 442 pass, 1 known under-load flake.
  • Guards: check-workflows, check-md-table-padding, check-forbidden-strings, check-kilocode-change, check-architecture, check:duplication, check-model-tool-network, knip, check-opencode-promise-facades, source links, and opencode annotations all pass.

Manual test

Isolated VS Code instance running the CLI and extension built from this branch (disposable workspace and data directory, staged login, no real credentials in output):

  • Sidebar onboarding and the provider/model catalog load with no errors, and model search works.
  • Providers settings renders connected providers and the full provider list, including Azure Cognitive Services.
  • The Azure connect dialog opens. With no az CLI installed only the API key method is offered, which is the intended gating for Entra ID.
  • A chat turn completed end to end through a local OpenAI-compatible fixture provider: the user turn was accepted and the assistant replied MERGE_UI_OK with no error card.
  • Agent Manager opened with the Local workspace card and no errors.

Not exercised manually: live Cloudflare AI Gateway routing, Codex limits, and the real Azure CLI sign-in, which need external credentials or an Azure CLI.

What to test

  • Provider and model selection, and a chat turn through the VS Code sidebar.
  • Azure provider setup, including the endpoint prompt and Entra ID sign-in when the Azure CLI is available.
  • Cloudflare AI Gateway routing for a non-Workers model.
  • Subagent task failure and resume.
  • Config editing and update, including V2-style keys.
  • Agent Manager session creation and switching.

opencode and others added 30 commits August 21, 2026 08:09
Co-authored-by: Aiden Cline <rekram1-node@users.noreply.github.com>
Co-authored-by: Filip <34747899+neriousy@users.noreply.github.com>
Co-authored-by: rekram1-node <rekram1-node@users.noreply.github.com>
Co-authored-by: thdxr <826656+thdxr@users.noreply.github.com>
Co-authored-by: Slickstef11 <98915060+Slickstef11@users.noreply.github.com>
Co-authored-by: neriousy <34747899+neriousy@users.noreply.github.com>
…tible providers (#43915)

Co-authored-by: Joel Stucki <joel.stucki@example.com>
The bounded virtual-clock loop could exhaust before the forked re-arm
fiber armed its next window, so the schedule appeared to stall and the
test failed intermittently on loaded CI hosts. Yield each pass and use a
generous bound so the loop waits for the schedule instead of racing the
scheduler.
….18.26' into marius-kilocode/kilo-opencode-v1.18.26
Self-testing the merged build found two Kilo behaviours the merge
resolution lost:

- The gpt-5 textVerbosity gate no longer excluded the azure provider.
- GlobalUpgradeInput made target required, so the upgrade endpoint could
  no longer fall back to the latest version.

Restore both, keep upstream semver validation for a provided target, and
regenerate the SDK so the client signature is optional again.
The frame helper retried for about 125ms before returning whatever it had,
so a slow Windows runner could hand an empty frame to the assertions and
fail the file tree test. Wait up to five seconds for the first painted
frame instead, which keeps the same contract for tests that pass.
Restoring the optional target was not enough. With a plain struct payload
Effect rejects an empty body before the handler runs, so the SDK, which
strips an empty body slot, could never reach installation.latest.

Restore the NoContent payload union and read the payload defensively, and
cover a bodyless request in the global HttpApi tests.
The test parsed the leader pid out of captured output, but the first line
can still be missing when the ready pattern matches on a loaded Windows
runner, so the assertion received NaN. The leader now writes its pid
before spawning the child, which the ready signal already depends on.
@WebReflection

Copy link
Copy Markdown
Contributor

Rechecked unchanged head 7f22634ab3. Most earlier concerns are addressed; raising three remaining Kilo integration points for maintainer review, not upstream-only fixes:

  1. MCP header safeguard: V2 mcp.servers.<name>.headers bypasses the flat-only sanitizer. A {file:secret.txt} reference inside the project is expanded before lowering and can reach outgoing remote MCP headers. Extend the Kilo sanitizer to nested servers before substitution. Env/out-of-root protections remain intact.

  2. Azure Entra onboarding: The callback requires resourceName/AZURE_RESOURCE_NAME, but shared prompts offer a full URL and disappear for AZURE_OPENAI_RESOURCE_NAME or AZURE_OPENAI_ENDPOINT; those paths fail. VS Code also sends no OAuth inputs, so ordinary Entra onboarding fails without AZURE_RESOURCE_NAME. Align prompts/callback and forward required inputs.

  3. V2 settings writes: The Kilo writer validates raw JSON against V1. A supported V2 model object can load, but an unrelated settings save then fails. The project overlay reader similarly skips lowering (overlay.ts:286). Apply V2 lowering for validation while preserving original JSONC.

Focused in-memory probes support 1/2; 3 is code-traced, not runtime-reproduced. Suggested scope: targeted Kilo adapter fixes and regression tests, leaving the deferred upstream-only issues out of this PR.

Azure Entra sign-in required AZURE_RESOURCE_NAME and ignored a full
endpoint URL from the connect dialog. Resolve the account from inputs,
AZURE_RESOURCE_NAME, AZURE_OPENAI_RESOURCE_NAME, or AZURE_OPENAI_ENDPOINT;
store an oauth baseURL so the loader honors a custom endpoint; and collect
OAuth method prompts in the VS Code dialog to forward them as inputs.

Extend the project MCP header sanitizer to nested mcp.servers entries.
Comment thread packages/kilo-vscode/webview-ui/src/components/settings/ProviderConnectDialog.tsx Outdated
Comment thread packages/opencode/test/kilocode/config/mcp-headers.test.ts Outdated
Comment thread packages/opencode/test/kilocode/plugin/azure-endpoint.test.ts
Extract the shared prompt list plus no-field error into one PromptFields
component so the provider connect dialog passes the duplication guard, and
apply the repo Prettier style to the new host handler line.
The OAuth prompt view blocked submission for optional prompts. Skip
optional prompts like the API-key view does, and mark snowflake-cortex
role optional so it is not forced.

Add regression tests for the Azure dialog resource-name path and the flat
server named servers case in the nested MCP header sanitizer.
…lTest

Rows hide their PR badges while a reload reports progress, so the fixed
flush in panelWithPr raced the load and intermittently emptied
secondaryBadges. Wait for every row to leave the progress state using the
existing waitUntil helper.
@WebReflection

Copy link
Copy Markdown
Contributor

Follow-up to the earlier review, rechecked at current head 59b0a812:

  • Resolved: nested MCP header protection, Azure Entra onboarding, and the bot comments about optional OAuth fields and missing test cases. Those three bot threads can be marked resolved.
  • Still open: V2 settings compatibility. The writer and project overlay reader still validate raw documents against V1 without V2 lowering. A model object such as {"model":{"providerID":"anthropic","model":"claude-sonnet"}} loads through the main config path, but saving an unrelated setting through Kilo settings fails before writing.

Remaining request: apply V2 lowering before validation in these Kilo-owned adapters, preserve the original JSONC, and add an unrelated-setting update regression test. Ordinary V1 configs are unaffected; no broader upstream changes are requested.

CI is green. This remaining finding is source-traced, not runtime-reproduced, and is the only outstanding code change I would request before approval.

@marius-kilocode

Copy link
Copy Markdown
Collaborator Author

We kept this scoped to Kilo adapter compatibility, not broader V2 support. Upstream v1 already accepts supported V2 config values, so our Settings reader and writer should not reject those same documents. The adapters now lower in memory before validation while preserving the original JSONC and Kilo-specific settings on disk. No upstream source changes or V2-aware editing were added. Fixed in b1ea859, with focused preservation and rejection tests; all 41 settings-adapter tests pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sponsor
SponsoredKunjungi sekarang
Promo