Synced from monorepo

Changes:
- Classify clipboard delivery confidence
- Add durable session update append
- Scope the xAI session bearer to first-party memory embedding endpoints
- Persist subagent outputs to disk and bound long-lived agent state
- Add MiniSweAgent:bash for mini-swe-agent parity
- Revert taking local sessions off the persistent shell
- Contextual tip recommending grok wrap on SSH sessions
- Voice STT bearer from model BYOK env_key/api_key
- Define exact website policies for sandbox
- Gate unsafe shell environments
- Shared pin hoist; single require_sha gate for marketplace plugins
- Server-signed is-managed claim (closes sidecar-removal downgrade)
- Optional require_sha pin for remote plugin installs
- Show session title and last exchange in the exit resume hint
- Gate shell output redirects
- Warn when fail_closed is present but not a boolean
- Add canonical text editing core (ratatui-textarea)
- Keep execution state out of goal scratch
- Add acknowledged persistence primitives
- Inherit child network restrictions in sandbox
- Fail closed when hook matchers fail to recompile
- Add MCP setup preferences for plugin MCPs
- Gate sourced shell scripts
- Gate file-typed project hooks
- grok wrap: restore terminal modes on child death
- Harden owner-only permissions on auth and MCP credentials
- Create crash dump files with owner-only permissions
- Write the agent_id cache owner-only (0600)
- SessionMetrics mode skips Mixpanel profile sync
- Dashboard: slim live-tail peek
- Yank full queued prompt text, not (+N lines)
- Defeat clock-rollback on the signed managed-config cache
- Stop early session/cancel from overtaking the prompt and wedging the turn slot
- Self-heal a diverged agent entrypoint on startup
- Add matched inference expectations in test-support
- Add AuthSingleFlight cancel/successor gap tests
- Remove consumer from external OTEL allowlist and pin scrub coverage
- Enable /copy in minimal mode
- Surface capacity and API-key detail on 429 errors
- Single-flight interactive auth
- Fix PageUp/PageDown skipping lines behind sticky prompt header
This commit is contained in:
grokkybara[bot] 2026-07-17 14:19:50 +01:00
commit 98c3b2438a
225 changed files with 18836 additions and 7156 deletions

View file

@ -451,16 +451,24 @@ mod imp {
Ok(p) => p,
Err(_) => return false,
};
// Owner-only: crash blobs hold stack IPs / fault addresses.
let fd = unsafe {
libc::open(
c_path.as_ptr(),
libc::O_WRONLY | libc::O_CREAT | libc::O_TRUNC,
0o644,
0o600,
)
};
if fd < 0 {
return false;
}
// open's mode is create-only; tighten upgrades of older 0644 blobs.
if unsafe { libc::fchmod(fd, 0o600) } != 0 {
unsafe {
libc::close(fd);
}
return false;
}
CRASH_FD.store(fd, Ordering::Relaxed);
// Store version string.
@ -920,4 +928,55 @@ mod tests {
"full install should replace the minimal handler"
);
}
#[test]
fn install_creates_owner_only_crash_blob() {
use std::os::unix::fs::PermissionsExt;
let _guard = SIGNAL_STATE_LOCK.lock().unwrap_or_else(|e| e.into_inner());
let dir = std::env::temp_dir().join(format!(
"xai-crash-handler-test-0600-{}",
std::process::id()
));
let _ = std::fs::remove_dir_all(&dir);
std::fs::create_dir_all(&dir).expect("create crash dir");
assert!(super::install(&dir, "test-version"));
let path = dir.join("last-crash.bin");
let mode = std::fs::metadata(&path).expect("meta").permissions().mode();
assert_eq!(mode & 0o777, 0o600, "new last-crash.bin must be owner-only");
let _ = std::fs::remove_dir_all(&dir);
}
#[test]
fn install_tightens_preexisting_0644_crash_blob() {
use std::os::unix::fs::PermissionsExt;
let _guard = SIGNAL_STATE_LOCK.lock().unwrap_or_else(|e| e.into_inner());
let dir = std::env::temp_dir().join(format!(
"xai-crash-handler-test-tighten-{}",
std::process::id()
));
let _ = std::fs::remove_dir_all(&dir);
std::fs::create_dir_all(&dir).expect("create crash dir");
let path = dir.join("last-crash.bin");
std::fs::write(&path, b"old").expect("seed");
let mut perms = std::fs::metadata(&path).expect("meta").permissions();
perms.set_mode(0o644);
std::fs::set_permissions(&path, perms).expect("set 0644");
assert_eq!(
std::fs::metadata(&path).expect("meta").permissions().mode() & 0o777,
0o644
);
assert!(super::install(&dir, "test-version"));
let mode = std::fs::metadata(&path).expect("meta").permissions().mode();
assert_eq!(
mode & 0o777,
0o600,
"install must fchmod preexisting 0644 blobs to owner-only"
);
let _ = std::fs::remove_dir_all(&dir);
}
}