Parent
#32
What to build
The agent runtime prepares its own workspace, so lib/workspace.ts goes back to being about git.
Today allocateWorkspace calls writeHeadlessPermissions, which writes an opencode.json
carrying permission: {"*": "allow"} into every run tree and registers it in the clone's
.git/info/exclude. That policy exists for a reason that is entirely opencode's: opencode asks
permissions that nobody can answer headless, and the adapter cannot even see the asks, so one ask
is a permanent silent deadlock of the run, its WIP slot and its workspace (#24). A workspace
allocator has no way to know that and no business knowing it.
After this ticket the agent runtime carries a workspace-preparation responsibility, and the
opencode adapter is what writes opencode's config. lib/workspace.ts keeps mirror, clone, identity
and retention — and nothing else. resetClone, which writes the same file on the legacy
single-clone path, moves with it.
The behaviour must not change: #24 was a real deadlock found in production, and this ticket is a
relocation, not a reconsideration. The existsSync guard in allocateWorkspace — which exists
only because workspace.test.ts's injected fake exec spawns nothing and so leaves dir absent —
should disappear along with the responsibility.
See docs/adr/0012-agent-runtime-seam.md §3.
Acceptance criteria
Blocked by
Parent
#32
What to build
The agent runtime prepares its own workspace, so
lib/workspace.tsgoes back to being about git.Today
allocateWorkspacecallswriteHeadlessPermissions, which writes anopencode.jsoncarrying
permission: {"*": "allow"}into every run tree and registers it in the clone's.git/info/exclude. That policy exists for a reason that is entirely opencode's: opencode askspermissions that nobody can answer headless, and the adapter cannot even see the asks, so one ask
is a permanent silent deadlock of the run, its WIP slot and its workspace (#24). A workspace
allocator has no way to know that and no business knowing it.
After this ticket the agent runtime carries a workspace-preparation responsibility, and the
opencode adapter is what writes opencode's config.
lib/workspace.tskeeps mirror, clone, identityand retention — and nothing else.
resetClone, which writes the same file on the legacysingle-clone path, moves with it.
The behaviour must not change: #24 was a real deadlock found in production, and this ticket is a
relocation, not a reconsideration. The
existsSyncguard inallocateWorkspace— which existsonly because
workspace.test.ts's injected fake exec spawns nothing and so leavesdirabsent —should disappear along with the responsibility.
See
docs/adr/0012-agent-runtime-seam.md§3.Acceptance criteria
lib/workspace.tsandlib/clone.tscontain no opencode-specific knowledgeresetClonepathopencode.jsonand the matching.git/info/excludeentry before the first agent step runswriteBackstill never stagesopencode.jsonexistsSyncguard added for the injected-fake-exec case is gonebun run checkpassesBlocked by