Skip to content

OpenCode Zen Free-Tier Refusal Under the Deny-All Sandbox (opencode_cli) #715

Description

@Yoseph-Zuskin

As a SkillSpector user on OpenCode's free tier, I want a clear error telling me free-tier models are incompatible with the provider's sandbox instead of an opaque exit-code failure.

The gap

Zen answers 403 FreeTierError ("free tier can only be used from within
OpenCode") to any opencode_cli call carrying the deny-all isolation,
bisected to the single variable (OPENCODE_CONFIG_CONTENT or
OPENCODE_PERMISSION alone suffices; model-independent; new since
2026-09-17). Every free-tier semantic scan fails 0/N with
opencode exited with code 1; stderr='', indistinguishable from a crash.

What I am asking for

Please consider mapping the refusal envelope to an actionable fail-closed
error: name the incompatibility, suggest a key-backed model, and refuse to
weaken the sandbox. Done when a Zen refusal surfaces guidance and a plain
non-zero exit keeps the generic message (both covered by unit tests).

This could be achieved by

  • Matching FreeTierError / can only be used from within OpenCode in
    the failed stdout and raising a dedicated AgentCLIError
  • Two cross-platform tests (fake Popen): refusal → guidance, plain
    failure → unchanged generic message

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions