Synced from monorepo

Changes:
- Classify clipboard delivery confidence
- Add durable session update append
- Scope the xAI session bearer to first-party memory embedding endpoints
- Persist subagent outputs to disk and bound long-lived agent state
- Add MiniSweAgent:bash for mini-swe-agent parity
- Revert taking local sessions off the persistent shell
- Contextual tip recommending grok wrap on SSH sessions
- Voice STT bearer from model BYOK env_key/api_key
- Define exact website policies for sandbox
- Gate unsafe shell environments
- Shared pin hoist; single require_sha gate for marketplace plugins
- Server-signed is-managed claim (closes sidecar-removal downgrade)
- Optional require_sha pin for remote plugin installs
- Show session title and last exchange in the exit resume hint
- Gate shell output redirects
- Warn when fail_closed is present but not a boolean
- Add canonical text editing core (ratatui-textarea)
- Keep execution state out of goal scratch
- Add acknowledged persistence primitives
- Inherit child network restrictions in sandbox
- Fail closed when hook matchers fail to recompile
- Add MCP setup preferences for plugin MCPs
- Gate sourced shell scripts
- Gate file-typed project hooks
- grok wrap: restore terminal modes on child death
- Harden owner-only permissions on auth and MCP credentials
- Create crash dump files with owner-only permissions
- Write the agent_id cache owner-only (0600)
- SessionMetrics mode skips Mixpanel profile sync
- Dashboard: slim live-tail peek
- Yank full queued prompt text, not (+N lines)
- Defeat clock-rollback on the signed managed-config cache
- Stop early session/cancel from overtaking the prompt and wedging the turn slot
- Self-heal a diverged agent entrypoint on startup
- Add matched inference expectations in test-support
- Add AuthSingleFlight cancel/successor gap tests
- Remove consumer from external OTEL allowlist and pin scrub coverage
- Enable /copy in minimal mode
- Surface capacity and API-key detail on 429 errors
- Single-flight interactive auth
- Fix PageUp/PageDown skipping lines behind sticky prompt header
This commit is contained in:
grokkybara[bot] 2026-07-17 14:19:50 +01:00
commit 98c3b2438a
225 changed files with 18836 additions and 7156 deletions

View file

@ -4,9 +4,7 @@
//! ecosystem (package-manager / toolchain) writable paths into helpers
//! consumed by [`super::profiles`].
#[cfg(all(feature = "enforce", unix))]
use std::path::Path;
use std::path::PathBuf;
use std::path::{Path, PathBuf};
// ── Grok state directory ────────────────────────────────────────────────────
@ -51,7 +49,6 @@ pub(crate) const DEVICE_DIRS: &[&str] = &[
/// `/private/var/folders/` (the real `TMPDIR` / `NSTemporaryDirectory()`).
/// git, compilers, and other tools write temp files to `$TMPDIR` which
/// resolves to `/private/var/folders/xx/.../T/` on macOS.
#[cfg(all(feature = "enforce", unix))]
pub(crate) fn temp_writable_paths() -> Vec<PathBuf> {
let mut paths = vec![PathBuf::from("/tmp"), PathBuf::from("/var/tmp")];
@ -81,7 +78,6 @@ pub(crate) fn temp_writable_paths() -> Vec<PathBuf> {
/// Writable directory paths for profiles that allow workspace writes (workspace, devbox, strict).
/// Device files are handled separately via `allow_file` in `to_capability_set_with_config`.
#[cfg(all(feature = "enforce", unix))]
pub(crate) fn essential_writable_paths(workspace: &Path) -> Vec<PathBuf> {
let mut paths = vec![workspace.to_path_buf(), grok_home()];
paths.extend(temp_writable_paths());
@ -90,7 +86,6 @@ pub(crate) fn essential_writable_paths(workspace: &Path) -> Vec<PathBuf> {
/// Writable directory paths for the read-only profile (minimal: just ~/.grok + temp).
/// Device files are handled separately via `allow_file` in `to_capability_set_with_config`.
#[cfg(all(feature = "enforce", unix))]
pub(crate) fn essential_writable_paths_minimal() -> Vec<PathBuf> {
let mut paths = vec![grok_home()];
paths.extend(temp_writable_paths());