Skip to content

Move headless permission setup out of the workspace allocator #37

Description

@FreshlyBrewedCode

Parent

#32

What to build

The agent runtime prepares its own workspace, so lib/workspace.ts goes back to being about git.

Today allocateWorkspace calls writeHeadlessPermissions, which writes an opencode.json
carrying permission: {"*": "allow"} into every run tree and registers it in the clone's
.git/info/exclude. That policy exists for a reason that is entirely opencode's: opencode asks
permissions that nobody can answer headless, and the adapter cannot even see the asks, so one ask
is a permanent silent deadlock of the run, its WIP slot and its workspace (#24). A workspace
allocator has no way to know that and no business knowing it.

After this ticket the agent runtime carries a workspace-preparation responsibility, and the
opencode adapter is what writes opencode's config. lib/workspace.ts keeps mirror, clone, identity
and retention — and nothing else. resetClone, which writes the same file on the legacy
single-clone path, moves with it.

The behaviour must not change: #24 was a real deadlock found in production, and this ticket is a
relocation, not a reconsideration. The existsSync guard in allocateWorkspace — which exists
only because workspace.test.ts's injected fake exec spawns nothing and so leaves dir absent —
should disappear along with the responsibility.

See docs/adr/0012-agent-runtime-seam.md §3.

Acceptance criteria

  • lib/workspace.ts and lib/clone.ts contain no opencode-specific knowledge
  • Workspace preparation is a responsibility of the agent runtime, invoked for both the per-run clone path and the legacy resetClone path
  • A clone workspace still ends up with opencode.json and the matching .git/info/exclude entry before the first agent step runs
  • writeBack still never stages opencode.json
  • A scratch workspace behaves exactly as it does today
  • The existsSync guard added for the injected-fake-exec case is gone
  • bun run check passes

Blocked by

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    taskA single self-contained piece of work that ships as one PR

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions