Skip to content

fix(core): recover wellknown sources and login plugin after startup outage - #53823

Open
kitlangton wants to merge 1 commit into
v2from
wellknown-cold-recovery
Open

kitlangton wants to merge 1 commit into
v2from
wellknown-cold-recovery

Conversation

@kitlangton

@kitlangton kitlangton commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Why

When OpenCode starts while a persisted .well-known/opencode origin is unreachable, initial manifest discovery fails and leaves wellknown.snapshot() empty. Two cold-start paths then prevent recovery for the life of the process: the 10-minute config refresh loop exits early whenever wellknown.snapshot() is empty instead of calling wellknown.refresh(), and the built-in opencode.wellknown plugin uses Effect.orDie on initial discovery before registering its integration transform or subscribing to WellKnown.Event.Updated. Because built-in plugins have a static "internal" revision, the plugin supervisor never retries the failed slot on later config reloads.

What Changes

  • 10-minute config poll (packages/core/src/config.ts): Always calls wellknown.refresh() on the 10-minute timer so persisted origins in KV (wellknown:sources) are retried after a cold startup failure. If refresh() reports no manifest change, reload() only runs when wellknown.snapshot().length > 0.
  • Well-known login plugin (packages/core/src/wellknown/plugin.ts): Catches initial wellknown.entries() failures and logs a warning instead of dying during setup, allowing the plugin to register its integration transform and subscribe to WellKnown.Event.Updated so login methods appear once discovery succeeds.
sequenceDiagram
    participant KV as KV (wellknown:sources)
    participant P as WellKnownPlugin
    participant T as Config 10m Timer
    participant W as WellKnown.Service
    participant I as Integration.Service

    Note over P,W: Cold startup during manifest outage (503)
    P->>W: entries()
    W->>KV: get("wellknown:sources")
    W-->>P: Error (manifest unreachable)
    P->>I: register transform + subscribe(WellKnown.Event.Updated)

    Note over T,W: 10 minutes later (endpoint healthy)
    T->>W: refresh()
    W->>KV: get("wellknown:sources")
    W-->>P: publish WellKnown.Event.Updated
    P->>I: reload() -> registers "login" command method
Loading

Demo

pr-53823-v4.mp4

Scope

This PR owns cold-start recovery for the 10-minute well-known discovery timer and the built-in opencode.wellknown plugin. Warm remote config caching and TUI session model retention are in separate PRs.

Verification

cd packages/core
bun run test test/config/wellknown-timer.test.ts test/plugin/wellknown-recovery.test.ts
bun typecheck
  • test/config/wellknown-timer.test.ts: 2 tests pass (19 assertions) exercising the 10-minute TestClock loop for both cold persisted sources and warm manifest outages.
  • test/plugin/wellknown-recovery.test.ts: 1 test passes (7 assertions) verifying that opencode.wellknown stays active across a cold discovery failure and registers the login command when discovery recovers without a plugin revision change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant