Deferred from the v0.9.3 pre-release review.
Current behavior
SessionStatus.publishPhase(name, ...) in packages/opencode/src/session/status.ts accepts any string for the name argument. Today the set produced by bootstrap.* spans is static and benign, and the TUI's packages/tui/src/util/phase-label.ts falls back to "Thinking..." on unknown names.
Gap
There is no validation at the publishPhase call site that the name is limited to a registered set. A future span whose name accidentally embeds a filesystem path, a secret, or a sensitive env reference would surface as a user-visible TUI label without any signal that it was unintended.
Proposal
Add a Set<string> of known phase names. publishPhase logs a warning (not throws) when an unregistered name is used and drops the label. Cover with a unit test that asserts a warning fires on an unregistered name so a regression is loud.
Why deferred
Guardrail against a future regression; the current phase-name set is static and benign so there is no user-visible risk today.
Deferred from the v0.9.3 pre-release review.
Current behavior
SessionStatus.publishPhase(name, ...)inpackages/opencode/src/session/status.tsaccepts any string for thenameargument. Today the set produced bybootstrap.*spans is static and benign, and the TUI'spackages/tui/src/util/phase-label.tsfalls back to "Thinking..." on unknown names.Gap
There is no validation at the
publishPhasecall site that thenameis limited to a registered set. A future span whose name accidentally embeds a filesystem path, a secret, or a sensitive env reference would surface as a user-visible TUI label without any signal that it was unintended.Proposal
Add a
Set<string>of known phase names.publishPhaselogs a warning (not throws) when an unregistered name is used and drops the label. Cover with a unit test that asserts a warning fires on an unregistered name so a regression is loud.Why deferred
Guardrail against a future regression; the current phase-name set is static and benign so there is no user-visible risk today.