Synced from monorepo

Changes:
- grok-shell: request workspaces:read/write OAuth2 scopes
- security: fix SSRF bypass via HTTP redirect in hook runner
- fix(grok-build): enterprise STT WSS URL + API-key voice bearer
- Harden identity-change purge and sync-marker invariants
- sandbox + workspace-server: delete the legacy ready-file arm
- Show billing URL when browser cannot open
- fix(pager): show folder-trust UI in minimal mode
- fix(pager): drain task_backgrounded before no-wait headless exit
- grok-agent-sdk: stop SDK-spawned agents from staging self-updates they can never adopt
- Split settings_modal into directory module
- Delegate VS Code SSH file links
- grok-shell: release the workspace session binding when a session is removed
- keep skills reachable when their name collides with a client builtin
- Preserve semantic link targets
This commit is contained in:
grokkybara[bot] 2026-07-16 20:27:30 +01:00
commit 8adf9013a0
117 changed files with 16998 additions and 14540 deletions

View file

@ -90,7 +90,7 @@ xai-tool-types = { workspace = true }
tokio-util = { workspace = true, features = ["rt"] }
urlencoding = "2"
xai-fast-worktree = { path = "../xai-fast-worktree", features = ["metadata"] }
# tonic stays for `tonic::Status`/`Code` mapping in workspace_ops deploy errors.
# tonic: Status/Code mapping for deploy errors in workspace_ops.
tonic = { workspace = true }
xai-fsnotify = { path = "../xai-fsnotify" }
@ -123,6 +123,7 @@ path = "src/bin/workspace_server_probe.rs"
[features]
default = ["sandbox-enforce"]
compression = []
test-support = []
sandbox-enforce = ["xai-grok-sandbox/enforce"]
default-bazel = [
"sandbox-enforce",