Synced from monorepo

Synced from monorepo

Changes:
- Report invalid MCP server config instead of failing startup
- Keep completed terminal output when the gateway connection is lost
- Show a duration-only detail view for single-task task output
- Don't let a stale registry turn counter hide local sessions
- Raise the file-descriptor soft limit on Linux and log effective limits at startup
- Stop aborting when HTTP client construction fails
- Make session thread and runtime spawn failures recoverable
- Fix main-prompt paste parity in the question freeform input
- Fire SessionEnd hooks on /exit and headless quit
- Embed the deployment-config signing public key
- Repaint paste-chip background on inline panel inputs
- Security: prevent acceptEdits from auto-approving agent writes into the always-trusted global hook root
- Fix stacked "Worked for" markers so parks render as status and turns close with exactly one marker
- Parse hooks from config files
- Add a remote kill-switch for managed-config signature verification
- Security: fix workspace file-reference resolution bypassing workspace filesystem confinement

Source-Revision: d02693a856a54f1030695b36b91d276e96b30b23
This commit is contained in:
grokkybara[bot] 2026-07-25 18:44:42 +00:00
commit 47348d13ec
138 changed files with 7283 additions and 5796 deletions

View file

@ -53,6 +53,15 @@ fn matches_trusted_base_url(candidate: &str, trusted_base: &str) -> bool {
&& candidate.port_or_known_default() == trusted.port_or_known_default()
&& path_matches
}
/// Production cli-chat-proxy base only (compiled-in constant).
///
/// Unlike [`is_cli_chat_proxy_url`], this rejects loopback and staging/dev hosts.
/// Used for security-sensitive remote kill-switches that must not become env
/// toggles via `GROK_CLI_CHAT_PROXY_BASE_URL` (or similar) pointing at an
/// attacker-controlled origin.
pub fn is_prod_cli_chat_proxy_url(url: &str) -> bool {
matches_trusted_base_url(url, crate::env::PROD_CLI_CHAT_PROXY_BASE_URL)
}
/// True for cli-chat-proxy URLs (production, plus local-dev hosts when the
/// optional non-production feature is enabled). When that feature is on,
/// runtime env overrides can extend this trust set. Loopback is always