headroom/Makefile
Rudimar Ronsoni b4571cc346
feat: headroom wrap opencode / unwrap opencode CLI (#1105)
## Summary

This PR implements transparent `headroom wrap opencode` support without
asking users to edit OpenCode provider URLs, choose an extra CLI flag,
or maintain a static provider list.

The wrapper now lives at the runtime transport boundary: OpenCode keeps
its user/provider config, while Headroom intercepts outbound provider
traffic in-process and routes it through the local Headroom proxy.

## What changed

### Transparent OpenCode wrapping

- `headroom wrap opencode` injects the `headroom-opencode` plugin
through `OPENCODE_CONFIG_CONTENT`.
- Existing OpenCode provider URLs are preserved. We do not rewrite user
config URLs to point at Headroom.
- Existing `OPENAI_BASE_URL` and `ANTHROPIC_BASE_URL` env vars are
preserved.
- Local OpenCode traffic, localhost traffic, and Headroom proxy traffic
bypass the shim to avoid loops.

### Runtime transport interception

- Added an OpenCode plugin transport shim that wraps:
  - `globalThis.fetch`
  - `http.request` / `http.get`
  - `https.request` / `https.get`
- External provider calls are routed to the local Headroom proxy.
- The original upstream origin is passed through `x-headroom-base-url`,
so the proxy can forward to the real provider without changing OpenCode
config.
- External `http2.connect` is blocked loudly instead of allowing direct
provider traffic to leak outside Headroom.

### Live provider additions

Provider coverage is no longer based on a static config scan. Because
routing happens at outbound request time, providers added mid-session
are routed through Headroom automatically as long as they use the
covered Node transport paths.

### Subagent and child-process coverage

- The parent OpenCode plugin sets a packaged Node preload shim through
`NODE_OPTIONS=--import=.../hook-shim/handler.js`.
- The transport shim patches `child_process.spawn`, `exec`, `execFile`,
and `fork` so child Node processes receive the Headroom preload even
when OpenCode passes a custom `env`.
- The child-process shim fails closed if it loads without
`HEADROOM_OPENCODE_TRANSPORT_PROXY_URL`.
- This closes the subagent leak path where a child Node process could
otherwise start without Headroom transport interception.

## Why this goes beyond PR #1089

PR #1089 improves OpenCode provider registration, but it still focuses
on provider config shape. This PR moves the enforcement boundary to
runtime transport interception.

This PR goes further because:

- No provider URL rewriting is required.
- New providers added mid-session are covered automatically.
- Subagents and child Node processes inherit the Headroom transport
shim.
- Direct external HTTP/2 paths fail loudly instead of leaking.
- The wrap remains transparent to the user's OpenCode provider config.
- The wrapper is fail-closed for unsupported child-process preload
state.

## Additional robustness fixes

While validating the change in Docker, the full Python suite exposed
unrelated Linux/container robustness issues. These are fixed in this PR
so the suite is green:

- Binary cache handling now treats cache paths under a non-writable
existing parent as unavailable, including when tests run as root in
Docker.
- `release_version.py` honors `MANUAL_VER` before git calls so direct
script execution works outside a `.git` checkout.
- Test logger isolation now resets relevant Headroom child loggers so
proxy logging setup cannot poison later `caplog` tests.
- The scanner missing-path test now uses a guaranteed missing `tmp_path`
child instead of relying on `/nonexistent/path`.

## Validation

All implementation validation was run inside Docker.

- Full Python suite from a fresh Docker copy: `6605 passed, 523
skipped`.
- Ruff on changed Python/OpenCode paths: passed.
- OpenCode plugin typecheck: passed.
- OpenCode plugin tests: `9 passed`.
- OpenCode plugin build: passed.
- Hook shim preload smoke test: passed.

## Notes

This PR intentionally does not add a CLI option. `headroom wrap
opencode` means full wrap. Either Headroom wraps OpenCode transparently,
or the path fails loudly instead of silently leaking provider traffic.

---------

Co-authored-by: Rudimar Ronsoni <6081613+rudironsoni@users.noreply.github.com>
2026-06-22 11:07:12 -05:00

157 lines
6.6 KiB
Makefile

# Headroom Rust build targets. `just` is not installed on dev boxes; this
# Makefile is the source of truth and is mirrored by .github/workflows/rust.yml.
SHELL := /bin/bash
CARGO ?= cargo
MATURIN ?= maturin
PYTHON ?= python3
FIXTURES ?= tests/parity/fixtures
.PHONY: help test test-parity bench build-proxy build-wheel fmt fmt-check lint clippy clean ci-precheck ci-precheck-rust ci-precheck-python ci-precheck-commitlint install-git-hooks verify-rust-core
help:
@echo "Headroom Rust targets:"
@echo " make test - cargo test --workspace"
@echo " make test-parity - maturin develop + parity-run against fixtures"
@echo " make bench - cargo bench --workspace"
@echo " make build-proxy - release build + strip headroom-proxy, print size"
@echo " make build-wheel - release wheel for headroom-py"
@echo " make verify-rust-core - build + install + import-verify headroom._core"
@echo " make fmt - cargo fmt --all"
@echo " make fmt-check - cargo fmt --all -- --check"
@echo " make lint - cargo clippy --workspace -- -D warnings"
@echo " make clean - cargo clean"
@echo ""
@echo "E2e targets:"
@echo " make build-e2e-wrap - build the wrap-e2e Docker image"
@echo " make run-e2e-wrap - build + run the wrap-e2e Docker container"
@echo ""
@echo "Pre-push verification (run BEFORE git push to catch CI failures locally):"
@echo " make ci-precheck - run all CI gates (rust + python + commitlint)"
@echo " make ci-precheck-rust - cargo fmt --check + clippy + test"
@echo " make ci-precheck-python - smart_crusher-affected python tests"
@echo " make ci-precheck-commitlint - lint commits since origin/main"
@echo " make install-git-hooks - install pre-commit, commit-msg, and pre-push hooks"
test:
$(CARGO) test --workspace
test-parity:
@if [ -z "$$VIRTUAL_ENV" ]; then \
echo "error: activate a venv first (e.g. source .venv/bin/activate)"; \
exit 1; \
fi
$(MATURIN) develop -m crates/headroom-py/Cargo.toml
$(CARGO) run -p headroom-parity -- run --fixtures $(FIXTURES)
bench:
$(CARGO) bench --workspace
build-proxy:
$(CARGO) build --release -p headroom-proxy
@BIN=target/release/headroom-proxy; \
if command -v strip >/dev/null 2>&1; then strip "$$BIN" || true; fi; \
SIZE=$$(wc -c < "$$BIN"); \
printf 'headroom-proxy: %s bytes (%.1f MiB)\n' "$$SIZE" "$$(echo "$$SIZE / 1048576" | bc -l)"
build-wheel:
$(MATURIN) build --release -m crates/headroom-py/Cargo.toml
# Hotfix-A0: maturin-develop + symlink + import-verify in one shot. Run this
# any time you suspect the proxy is silently falling back to Python-only
# mode (Finding #2 in HEADROOM_PROXY_LOG_FINDINGS_2026_05_03.md). The
# proxy itself runs the same check at lifespan startup; this target
# exposes it as a developer-facing one-liner.
verify-rust-core:
@if [ -z "$$VIRTUAL_ENV" ]; then \
echo "error: activate a venv first (e.g. source .venv/bin/activate)"; \
exit 1; \
fi
bash scripts/build_rust_extension.sh
fmt:
$(CARGO) fmt --all
fmt-check:
$(CARGO) fmt --all -- --check
clippy lint:
$(CARGO) clippy --workspace -- -D warnings
clean:
$(CARGO) clean
# ─── Pre-push CI gate ──────────────────────────────────────────────────────
#
# These targets run the same checks GitHub Actions runs, locally. The intent
# is: if `make ci-precheck` is green, `git push` will not turn red. The
# 2026-04-27 push surfaced five CI breaks (cargo fmt drift, x86_64-apple-
# darwin wheel, headroom._core not built in test-extras + smoke-test,
# commitlint footer-leading-blank). The first three are caught by the gates
# below; the last two are caught by the workflow fixes themselves.
#
# Run before EVERY `git push`. Install the git hook (one-time) with:
# make install-git-hooks
ci-precheck: ci-precheck-rust ci-precheck-python ci-precheck-commitlint
@echo ""
@echo "✅ ci-precheck PASSED — safe to push."
ci-precheck-rust:
@echo "── ci-precheck-rust ────────────────────────────────────────────"
$(CARGO) fmt --all -- --check
$(CARGO) clippy --workspace -- -D warnings
$(CARGO) test --workspace
# Mirrors the smart_crusher-affected test files we expect green on every
# push. Builds the Rust extension first because most of these tests
# instantiate `SmartCrusher`, which hard-imports `headroom._core`.
ci-precheck-python:
@echo "── ci-precheck-python ─────────────────────────────────────────"
@if [ -z "$$VIRTUAL_ENV" ]; then \
echo "error: activate a venv first (e.g. source .venv/bin/activate)"; \
exit 1; \
fi
bash scripts/build_rust_extension.sh
$(PYTHON) -m pytest -q \
tests/test_transforms/test_smart_crusher_bugs.py \
tests/test_transforms/test_smart_crusher_rust_parity.py \
tests/test_transforms/test_diff_compressor.py \
tests/test_transforms/test_diff_compressor_rust_parity.py \
tests/test_relevance.py \
tests/test_relevance_extra.py \
tests/test_ccr.py \
tests/test_acceptance.py \
tests/test_critical_fixes.py \
tests/test_quality_retention.py \
tests/test_toin_integration.py
# Lint commits since `origin/main`. Requires npx (Node 18+) on PATH.
ci-precheck-commitlint:
@echo "── ci-precheck-commitlint ─────────────────────────────────────"
@if ! command -v npx >/dev/null 2>&1; then \
echo "error: npx not on PATH (install Node 18+ to enable commitlint checks)"; \
exit 1; \
fi
@if ! git rev-parse --verify origin/main >/dev/null 2>&1; then \
echo "error: origin/main not fetched (run 'git fetch origin main')"; \
exit 1; \
fi
npx --yes --package=@commitlint/cli --package=@commitlint/config-conventional -- \
commitlint --from origin/main --to HEAD --config .commitlintrc.json
install-git-hooks:
@scripts/install-git-hooks.sh
# ─── E2e Docker targets ────────────────────────────────────────────────────
#
# The wrap-e2e Dockerfile uses manylinux_2_28_x86_64 as its builder stage,
# which only ships amd64 binaries. Pass --platform linux/amd64 explicitly
# so the build works on Apple Silicon (requires QEMU emulation). On native
# x86_64 hosts the flag is harmless and matches CI behaviour.
build-e2e-wrap:
docker build --platform linux/amd64 -f e2e/wrap/Dockerfile -t headroom-wrap-e2e .
run-e2e-wrap: build-e2e-wrap
docker run --rm headroom-wrap-e2e