Skip to content

Unable to get permissions to work as intended #22375

Description

@JakeMHughes

Question

I'm pretty new to opencode and I am trying to setup my permissions for everything (putting this in the ~/.config/opencode/opencode.json file). Essentially I want it so when I open opencode in a folder, opencode should be able to edit any file in that folder. but anything one folder up ( ../) should ask for permissions. Now, one of the reasons im having trouble testing this stuff, is because it feels like theres a constant workaround using bash skill.

For example, I set the "list" skill to deny but according to opencode "ls" under bash was allowed so it just ran that instead. I tried setting edit to the below, and asked the model to write hello to a temp file, and the permission was ignored and fell under bash rules because "echo 'Hello' > temp" was used instead

    "edit": {
      "./**": "allow",
      "*": "deny"
    }

So im mostly just looking for some help on what fundamental misunderstanding I have regarding the permissions. also is it possible to have allow for the "current" directory? I know I can hardcode a path, but I want the path to be determined at opencode load time

Activity

  1. added
    coreAnything pertaining to core functionality of the application (opencode server stuff)
    on Apr 14, 2026
  2. github-actions commented on Apr 14, 2026

    @github-actions
    Contributor

    This issue might be a duplicate of existing issues. Please check:

    Please review these issues to see if your question is already answered or being tracked there.

  3. malhashemi commented on Apr 14, 2026

    @malhashemi
    Contributor

    Hey @JakeMHughes ,

    Permissions are evaluated in order. So that last deny is revoking every allow that comes before it.

  4. removed
    coreAnything pertaining to core functionality of the application (opencode server stuff)
    on May 3, 2026
  5. rekram1-node commented on Jun 23, 2026

    @rekram1-node
    Collaborator

    Automated: closing question issues.

    GitHub Issues are for bug reports and feature requests only — questions / support are no longer tracked here.

    If this is a bug or feature request, please open a new issue with the appropriate template.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions