Synced from monorepo

Synced from monorepo

Changes:
- Temporarily disable session share link creation in the TUI
- Do not approve plan on empty Enter from the revise prompt
- Expose chat product Skills via ACP available_commands_update
- Return immediately from a blocking wait on an already-completed ACP task
- Split headless pager module for clearer structure
- Stop git worktree prune from removing user registrations on resume
- Use compaction sampler tokenizer for item token counts
- Opt-in extra root CAs via GROK_EXTRA_CA_BUNDLE
- Cancel all session subagents when the user stops
- Let the session persistence actor exit when its session ends
- Make fullscreen terminal resize much cheaper on long sessions
- Report honestly from kill_task when an ACP task does not exist
- Hide /usage for external-auth deployments
- Forward the history-load trailer’s computer_reason to the client
- Remove ineffective no-op tool reminder
- Declare slash-command screen-mode support in one place
- Keep settings enum picker on the committed value until Enter
- Reap a PTY’s full process tree
- Stream tool calls from headless mode over ACP
- Bridge gateway task lifecycle to ACP for chat session background tasks
- Don’t warn about truncated history on a suppressed replay
- Fit full-replace summarizer input and recover on context-length errors
- Stop dropping agents over an unrecognized frontmatter color
- Add /undo as a slash alias for /rewind
- Harden sleep/wake token-refresh paths against forced re-login
- Add session/list ACP method
- Give each sampling backend its own conversion module
- Treat an unenrolled child process as a lint error
- Suppress the cancelled marker on send-now wake turns
- Stop tearing down Roslyn on every edit, and read C# diagnostics

Source-Revision: 2a28b4a86cfc4a4c133c35b7fc2a6a9964387c39
This commit is contained in:
grokkybara[bot] 2026-07-30 19:07:40 +00:00
commit dd04f397b1
367 changed files with 29489 additions and 10051 deletions

View file

@ -0,0 +1,22 @@
//! Process-isolated: missing GROK_EXTRA_CA_BUNDLE path → fail-open client build.
#[test]
fn missing_bundle_path_builds_clients_without_panic() {
// Safety: sole test in this binary; set before any OnceLock resolve.
unsafe {
std::env::set_var(
xai_grok_extra_ca::ENV_GROK_EXTRA_CA_BUNDLE,
"/nonexistent/grok-extra-ca-bundle-invalid-file.pem",
);
}
assert!(xai_grok_extra_ca::extra_root_ders().is_empty());
xai_grok_extra_ca::with_extra_root_certificates(reqwest::Client::builder())
.build()
.expect("async client builds when bundle is unreadable");
xai_grok_extra_ca::with_extra_root_certificates_blocking(reqwest::blocking::Client::builder())
.build()
.expect("blocking client builds when bundle is unreadable");
}

View file

@ -0,0 +1,34 @@
//! Process-isolated: oversize GROK_EXTRA_CA_BUNDLE → ignored; client still builds.
use std::io::Write;
#[test]
fn oversized_bundle_ignored_clients_build() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("oversized.pem");
{
let mut f = std::fs::File::create(&path).expect("create");
let chunk = vec![b'X'; 64 * 1024];
let mut written = 0u64;
let target = xai_grok_extra_ca::MAX_EXTRA_CA_BUNDLE_BYTES + 1;
while written < target {
let n = ((target - written) as usize).min(chunk.len());
f.write_all(&chunk[..n]).expect("write");
written += n as u64;
}
}
// Safety: sole test in this binary; set before any OnceLock resolve.
unsafe {
std::env::set_var(
xai_grok_extra_ca::ENV_GROK_EXTRA_CA_BUNDLE,
path.as_os_str(),
);
}
assert!(xai_grok_extra_ca::extra_root_ders().is_empty());
xai_grok_extra_ca::with_extra_root_certificates(reqwest::Client::builder())
.build()
.expect("client builds after oversized reject");
}

View file

@ -0,0 +1,41 @@
//! Process-isolated: valid GROK_EXTRA_CA_BUNDLE loads one root via OnceLock.
#[test]
fn valid_bundle_loads_one_root() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("ca.pem");
const CERT: &str = "-----BEGIN CERTIFICATE-----\n\
MIIDFTCCAf2gAwIBAgIUT2czXTuxSAjDjEh92UMB1OVahZYwDQYJKoZIhvcNAQEL\n\
BQAwGjEYMBYGA1UEAwwPdGVzdC1leHRyYS1jYS0xMB4XDTI2MDcyOTE4MzUwNFoX\n\
DTM2MDcyNjE4MzUwNFowGjEYMBYGA1UEAwwPdGVzdC1leHRyYS1jYS0xMIIBIjAN\n\
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1gNk2BQwUy+n5cCaTFtGpSzVQv//\n\
d7QD+3QWeE411wIGJzp3nrd7np55X8JHxeg/pRhspQvLQAF7bt55LSkL/+sSth3S\n\
QTbBqhftic9CXik3llAwbdQkAM9srz5zXWW9KVjZ57dxjjxrS15SCXu/UmvGZy98\n\
faJcS++TRkczsNFzwQEqeDYARVc/no0C0I++NhGLPaNMfFAevvnu6Kt3CYMI5ls4\n\
KCFgnlau4CjgRCMSfRDCRcwEwUAp+DyX9IU+tvDAQY1ncVoa/05tvaEvw7pQ+UgW\n\
0wRG0lk7PLlcWmUkLcFpO+sL5GRkC8RoWM4cFbIOiXoVxUFks/z2y0GCEQIDAQAB\n\
o1MwUTAdBgNVHQ4EFgQU+lyC70W5aR6BIf4VNtjfiWMNzzkwHwYDVR0jBBgwFoAU\n\
+lyC70W5aR6BIf4VNtjfiWMNzzkwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0B\n\
AQsFAAOCAQEA02972nA7LshRgubz6BwXbh1gA5pLzTd5KEae+94Hq6mP2zJ1T0gk\n\
x+me0NtSgG4BJLdBIylUzo2UmsfB/sz+ght6WX1uB38Vc2UQsp0sRPeeiMovSd6n\n\
I7xZyuZEF3noYJVBBlKQ8XsCUIBNIROlyKlNjNcWY8tGqPh9cepvtZYkBgRZr1vW\n\
hJAE3EOL2ZddrMPF64QeU9UhvCm0Ch+Ceqa1ZWE0MygccggX5s2yQwtXO2ovJdjH\n\
6vW0I02r8sE+NX0d1u8rIPJEKlp89UwCwniD7SxHTNw8bbsTCWz+AMod7vC7De3X\n\
4Daxme+vD8adOfCeOIu5vNrlXLNST2yaTw==\n\
-----END CERTIFICATE-----\n";
std::fs::write(&path, CERT).expect("write cert");
// Safety: sole test in this binary; set before any OnceLock resolve.
unsafe {
std::env::set_var(
xai_grok_extra_ca::ENV_GROK_EXTRA_CA_BUNDLE,
path.as_os_str(),
);
}
assert_eq!(xai_grok_extra_ca::extra_root_ders().len(), 1);
xai_grok_extra_ca::with_extra_root_certificates(reqwest::Client::builder())
.build()
.expect("client with env-loaded root builds");
}

View file

@ -0,0 +1,22 @@
//! Process-isolated: configured garbage file → zero roots; client still builds.
#[test]
fn configured_garbage_file_yields_zero_roots_and_builds() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("garbage.pem");
std::fs::write(&path, b"not a pem at all").expect("write");
// Safety: sole test in this binary; set before any OnceLock resolve.
unsafe {
std::env::set_var(
xai_grok_extra_ca::ENV_GROK_EXTRA_CA_BUNDLE,
path.as_os_str(),
);
}
assert!(xai_grok_extra_ca::extra_root_ders().is_empty());
xai_grok_extra_ca::with_extra_root_certificates(reqwest::Client::builder())
.build()
.expect("client builds after zero-cert configured file");
}