`prompt_async` answers 204 as soon as OpenCode forks the run and reports every later failure only on the session event stream, so an unusable model, agent, or variant produced a session with no message while the result still claimed `promptDispatched: true`. Validate an explicitly requested model, agent, and variant against the directory's own agent and provider lists before any session, worktree, or goal is created, and confirm a new user message actually reached the session before reporting the dispatch. A failed or empty lookup never turns a valid selection into a rejection.
3.0 KiB
3.0 KiB
OpenChamber Control Service
Purpose
This module owns the typed control contract shared by the OpenChamber CLI and
the managed OpenCode openchamber tool. Both adapters delegate to
createOpenChamberControlService(); neither adapter may call or spawn the
other.
Boundaries
service.jsvalidates and executes the fixed project, model, session, and scheduled-task action allowlist.actions.jsmarks CLI-only actions withagentExposed: false(currentlyschedule.status); the agent tool consumes the filteredOPENCHAMBER_AGENT_TOOL_*exports.schedule.togglerequires thedisabledboolean and replaces separate enable/disable actions;schedule.listalso returns scheduler status asscheduler.routes.jsis the authenticated CLI HTTP adapter. It forwards one action, preserves service status and partial-result details, and propagates request cancellation.../agent-tool/runtime.jsis the managed-tool adapter. It wraps service results in the versioned native-tool envelope and uses a separate ephemeral loopback credential.../openchamber-sessions/routes.jsand../scheduled-tasks/service.jsown their domain operations and are composed into this service.
Invariants
- Session status and messages come from official directory-scoped OpenCode
APIs. Message output includes only ordered
textparts. - Wait never treats an initial idle response as completion after dispatch. It requires observed activity or a newly completed assistant message.
- Timeout and cancellation are failures, never authoritative idle results.
- Validation that protects side effects runs before session creation or
dispatch. An explicitly requested model, agent, or variant is checked against
the directory's own OpenCode agent and provider lists before any session,
worktree, or goal is created, because
prompt_asyncaccepts an unusable selection and then fails only on the event stream. A failed or empty lookup never turns a valid selection into a rejection. promptDispatchedreports an observed dispatch, never an accepted request. Afterprompt_asyncthe service confirms a new user message reached the session; when it does not, the result reportspromptDispatched: falsewithpromptErrorinstead of claiming success.- Send and fork dispatches without an explicit model/agent/variant reuse the target session's last user-message selection before falling back to the configured defaults; only session creation resolves defaults directly.
- Usage errors name the missing or conflicting input so CLI and agent-tool callers can correct an invalid request without an upfront usage manual.
- Explicit
projectIdordirectoryscope takes precedence over the managed tool's current-session directory fallback; the fallback never creates a conflicting second scope. - One failed directory status lookup produces
unknownfor only that directory and does not erase other session results. - Destructive session/worktree deletion and project-path registration are not part of the action contract.