Synced from monorepo

Changes:
- Non-blocking coding-data sharing upsell banner
- Consolidate remediation in Doctor
- Auto mode defers fail-closed gate asks to the classifier
- Coalesce marketplace list fetches
- Allow removing a marketplace source by name
- Contain hung git marketplace sources (timeouts, non-blocking refresh, unbrick modal)
- Label failed workspace RPCs with error_kind
- Drop redundant explicit tonic/prost deps from xai-grok-shell
- Report real exit codes for completed background shells
- Narrow the date-rollover reminder to date-bearing templates
- Wire toolOverrides through the session and agent
- Security: Bash(git:*) allowlist matches whole command chain by prefix
- Split prompt-trigger telemetry and record classifier provenance
- Raise connectors-manager timeout to 60s
- Auto classifier honors recorded approvals for repeat actions
- Apply doctor fixes in the TUI
- Auto-mode classifier timeouts prompt instead of silently denying
- Scope subagent completion drains to the owning session
- Add the toolOverrides wire types
- Set client_identifier=grok-agent-sdk
- Accept both spellings of the workspace-teleport kill switch
- Persist one-shot occurrence journal
- Stop turns that poll the exact same tool call 16x in a row
- Copy compaction checkpoint files when forking sessions
- Auto-focus permission prompt from scrollback
- Esc cancels the running turn in non-vim and minimal modes
- List Ctrl+Z undo and redo in keyboard shortcuts
- Out-of-process macOS mic capture
- Show active auth mode on session-info
- Install the npm binary under $GROK_HOME
- Remove hover/click dead zones between dashboard items
- Route startup warnings to doctor
- Document [feedback.user] author identity config
- Extend bang command timeout
- Close combine-queued edit-hold race
- Integrate relocation recovery
- Expose privacy notice rollout flag
- Break harness discovery ref cycle so connections can idle-evict
- Shift/Alt+Enter inserts newline when editing a queued prompt
- Gate project Claude permissions on folder trust
- Echo response.create.event_id on response.created
- Toast when session creation fails from disk full
- Add shared test process lifecycle
- Enable dynamic workflows by default
- Add relocation transaction state machine
- Add shared test sandbox
- Surface auth failures on model-switch compact
- Persist durable scheduler expiry
- Confirm before removing extensions-modal items
- Re-run compact and prompt after login when compact hit expired auth
- Recap sends hosted tools under backend search
This commit is contained in:
grokkybara[bot] 2026-07-22 19:18:53 +01:00
commit a5727c5960
482 changed files with 37627 additions and 13402 deletions

View file

@ -204,13 +204,19 @@ fn toml_to_json(v: &toml::Value) -> Value {
/// merges rules from requirements.toml, managed-settings.json,
/// managed_config.toml, config.toml, and `.claude/settings.json`.
///
/// `project_trusted` gates project-tier permission sources (same contract as
/// env/hooks/plugins). Hub/cloud callers outside the local folder-trust model
/// should pass `true`.
///
/// Returns a JSON object with `sources`, `loaded` (rule count), and
/// `skipped` (unrecognized rules). Returns `Value::Null` if no
/// permission sources are configured.
pub async fn load_permissions(root_cwd: &Path) -> Value {
pub async fn load_permissions(root_cwd: &Path, project_trusted: bool) -> Value {
use crate::permission::resolution;
let Some(resolved) = resolution::resolve_permissions_with_provenance(root_cwd).await else {
let Some(resolved) =
resolution::resolve_permissions_with_provenance(root_cwd, project_trusted).await
else {
return Value::Null;
};
@ -536,7 +542,7 @@ mod tests {
#[tokio::test]
async fn load_permissions_returns_valid_json() {
let tmp = tempfile::tempdir().unwrap();
let result = load_permissions(tmp.path()).await;
let result = load_permissions(tmp.path(), true).await;
// Result is either Null (no sources) or an object with
// sources, loaded, and skipped fields. Both branches assert
// a definite pass criterion.
@ -563,7 +569,7 @@ mod tests {
)
.unwrap();
let result = load_permissions(tmp.path()).await;
let result = load_permissions(tmp.path(), true).await;
assert!(result.is_object(), "should return an object, got {result}");
assert!(result["sources"].is_array(), "sources should be an array");
assert!(result["loaded"].is_number(), "loaded should be a number");