Synced from monorepo

Changes:
- Non-blocking coding-data sharing upsell banner
- Consolidate remediation in Doctor
- Auto mode defers fail-closed gate asks to the classifier
- Coalesce marketplace list fetches
- Allow removing a marketplace source by name
- Contain hung git marketplace sources (timeouts, non-blocking refresh, unbrick modal)
- Label failed workspace RPCs with error_kind
- Drop redundant explicit tonic/prost deps from xai-grok-shell
- Report real exit codes for completed background shells
- Narrow the date-rollover reminder to date-bearing templates
- Wire toolOverrides through the session and agent
- Security: Bash(git:*) allowlist matches whole command chain by prefix
- Split prompt-trigger telemetry and record classifier provenance
- Raise connectors-manager timeout to 60s
- Auto classifier honors recorded approvals for repeat actions
- Apply doctor fixes in the TUI
- Auto-mode classifier timeouts prompt instead of silently denying
- Scope subagent completion drains to the owning session
- Add the toolOverrides wire types
- Set client_identifier=grok-agent-sdk
- Accept both spellings of the workspace-teleport kill switch
- Persist one-shot occurrence journal
- Stop turns that poll the exact same tool call 16x in a row
- Copy compaction checkpoint files when forking sessions
- Auto-focus permission prompt from scrollback
- Esc cancels the running turn in non-vim and minimal modes
- List Ctrl+Z undo and redo in keyboard shortcuts
- Out-of-process macOS mic capture
- Show active auth mode on session-info
- Install the npm binary under $GROK_HOME
- Remove hover/click dead zones between dashboard items
- Route startup warnings to doctor
- Document [feedback.user] author identity config
- Extend bang command timeout
- Close combine-queued edit-hold race
- Integrate relocation recovery
- Expose privacy notice rollout flag
- Break harness discovery ref cycle so connections can idle-evict
- Shift/Alt+Enter inserts newline when editing a queued prompt
- Gate project Claude permissions on folder trust
- Echo response.create.event_id on response.created
- Toast when session creation fails from disk full
- Add shared test process lifecycle
- Enable dynamic workflows by default
- Add relocation transaction state machine
- Add shared test sandbox
- Surface auth failures on model-switch compact
- Persist durable scheduler expiry
- Confirm before removing extensions-modal items
- Re-run compact and prompt after login when compact hit expired auth
- Recap sends hosted tools under backend search
This commit is contained in:
grokkybara[bot] 2026-07-22 19:18:53 +01:00
commit a5727c5960
482 changed files with 37627 additions and 13402 deletions

View file

@ -117,7 +117,7 @@ pub fn flush() {
if let Some(state) = SANDBOX.get()
&& let Err(e) = state.logger.flush_to_disk()
{
tracing::warn!(error = % e, "Failed to flush sandbox events to disk");
tracing::warn!(error = %e, "Failed to flush sandbox events to disk");
}
}
/// Violation metrics, or `None` if sandbox is not active.
@ -156,7 +156,7 @@ impl SandboxManager {
let support = Sandbox::support_info();
if !support.is_supported {
tracing::warn!(
details = % support.details,
details = %support.details,
"Sandbox not supported on this platform, continuing without sandbox"
);
self.logger.log(SandboxEvent::apply_failed(
@ -177,7 +177,8 @@ impl SandboxManager {
&resolved,
));
tracing::info!(
profile = % self.profile, workspace = % workspace.display(),
profile = %self.profile,
workspace = %workspace.display(),
restrict_network_configured = self.net_restricted,
"Sandbox applied (kernel-enforced, irreversible)"
);
@ -185,7 +186,8 @@ impl SandboxManager {
}
Err(e) => {
tracing::warn!(
profile = % self.profile, error = % e,
profile = %self.profile,
error = %e,
"Sandbox could not be applied, continuing without sandbox"
);
self.logger.log(SandboxEvent::apply_failed(
@ -201,7 +203,7 @@ impl SandboxManager {
#[cfg(not(all(feature = "enforce", unix)))]
pub fn apply(&mut self, _workspace: &Path) -> anyhow::Result<()> {
tracing::info!(
profile = % self.profile,
profile = %self.profile,
"Sandbox enforcement unavailable (built without 'enforce' feature)"
);
Ok(())