Synced from monorepo Changes: - Shell: accept target response id on rewind execute - Shell: stamp response id on chat user message chunks - Worktree: optional rebuild and stale git registration cleanup in auto-GC - Worktree: kind-aware auto-GC TTLs and config knobs - Worktree: macOS process CWD scan and Unix PID liveness for GC guards - Worktree: automatic throttled GC on startup (Linux age-based; non-Linux dead-only) - Pager: add `[ui].combine_queued_prompts` to batch queued follow-ups - Shell: stop overwriting user skills - Tools: read markdown in `skills/` directories untruncated - `/usage` shows per-session token and dollar usage in the TUI - Security: prompt on environment-dumping `ps` variants - Security: always-safe `kubectl` no longer runs arbitrary kubeconfig credential plugins without permission - Tools: make scheduler deletion durable - Shell: add relocation storage primitives - Shell: give side model calls their own conversation ids - Fix five workflow-runtime bugs (budget, pause, cancel, reconnect) - Security: peel `env -S` / `--split-string` operands in the Bash permission gate (managed deny/ask) - Pager: expose doctor in the TUI - Security: block unauthorized RCE via abused safe commands - Pager idle watcher cue: "1 subagent still running" instead of "watching · 1 subagent" - Security: block `rg --pre` arbitrary code execution in auto-mode - Voice: diagnose silent-mic failures (macOS permission) and add doctor/terminal-setup Voice section - App builder deployer: `allow_forking` and `show_built_with_grok` - Pager: stop stacking duplicate "Worked for" markers on parked turns - Shell: support `max` as a distinct reasoning effort tier - Tools: serialize background `/loop` fires on the whole work unit - Shell: add working-directory relocation state primitives - Proto: `ClientToolResult` and `ChatConfig` client-side tools - Shell: model providers - Chat: select App Builder product on the Build path - Shell: attach author identity to feedback when the deployment opts in - Doctor: fix for SSH wrap setup - Workflow authoring skills: create-workflow and import-claude-workflow docs - Add read-only grok doctor - Sandbox: apply Landlock without a controlling TTY - Pager: recover image paste over grok wrap on headless remotes - Pager: make actions screen-mode aware - Shell: resume sessions when the working directory moves - Pager: centralize terminal diagnostics - Workspace: gate inline shell file access - Pager: centralize terminal probes - Pager: edit minimal prompts in an external editor - Pager: standardize backgrounding on Ctrl+B - Shell: recap rides the parent turn's prompt cache - Tools: add scheduler lifecycle version clock Source-Revision: 0f4d7c91b8b2b408333f6de1e8a76cb8eaa71899
85 lines
2.7 KiB
Rust
85 lines
2.7 KiB
Rust
pub mod config;
|
|
pub mod grok_auth_credentials;
|
|
pub mod hooks;
|
|
pub(crate) mod subprocess;
|
|
pub(crate) mod user_identity;
|
|
|
|
// The foundation utilities live in `xai-grok-shell-base` (upstream of this
|
|
// crate so they build in parallel). Re-exported at the original paths so
|
|
// existing `crate::util::…` / `xai_grok_shell::util::…` users compile
|
|
// unchanged.
|
|
pub use xai_grok_shell_base::util::*;
|
|
|
|
pub(crate) fn is_user_instruction_path(
|
|
path: &std::path::Path,
|
|
grok_home: &std::path::Path,
|
|
vendor_homes: &[(std::path::PathBuf, bool)],
|
|
workspace_root: Option<&std::path::Path>,
|
|
) -> bool {
|
|
let parent = path.parent();
|
|
let grok_rules = grok_home.join("rules");
|
|
let is_exact_home_surface = parent
|
|
.is_some_and(|parent| parent == grok_home || parent == grok_rules)
|
|
|| vendor_homes.iter().any(|(vendor_home, named_enabled)| {
|
|
parent.is_some_and(|parent| {
|
|
(*named_enabled && parent == vendor_home) || parent == vendor_home.join("rules")
|
|
})
|
|
});
|
|
if is_exact_home_surface {
|
|
return true;
|
|
}
|
|
if workspace_root.is_some_and(|root| path.starts_with(root)) {
|
|
return false;
|
|
}
|
|
path.starts_with(grok_home)
|
|
|| vendor_homes
|
|
.iter()
|
|
.any(|(vendor_home, _)| path.starts_with(vendor_home))
|
|
}
|
|
|
|
/// Aborts the wrapped tokio task when dropped.
|
|
///
|
|
/// Use to tie a spawned helper task's lifetime to an async scope so that
|
|
/// cancelling the parent future (e.g. a turn abort dropping the tool loop)
|
|
/// also tears down the helper instead of leaving it running detached.
|
|
/// Aborting an already-finished task is a no-op, so this is safe to hold
|
|
/// across normal scope exit too.
|
|
pub struct AbortOnDrop(pub tokio::task::JoinHandle<()>);
|
|
|
|
impl Drop for AbortOnDrop {
|
|
fn drop(&mut self) {
|
|
self.0.abort();
|
|
}
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod is_user_instruction_path_tests {
|
|
use super::is_user_instruction_path;
|
|
use std::path::Path;
|
|
|
|
#[test]
|
|
fn grok_home_named_file_nested_in_workspace_is_user_scoped() {
|
|
assert!(is_user_instruction_path(
|
|
Path::new("/repo/config/AGENTS.md"),
|
|
Path::new("/repo/config"),
|
|
&[],
|
|
Some(Path::new("/repo")),
|
|
));
|
|
assert!(!is_user_instruction_path(
|
|
Path::new("/repo/config/src/AGENTS.md"),
|
|
Path::new("/repo/config"),
|
|
&[],
|
|
Some(Path::new("/repo")),
|
|
));
|
|
}
|
|
|
|
#[test]
|
|
fn workspace_descendants_under_grok_home_stay_project_scoped() {
|
|
assert!(!is_user_instruction_path(
|
|
Path::new("/custom/grok/worktrees/repo/src/AGENTS.md"),
|
|
Path::new("/custom/grok"),
|
|
&[],
|
|
Some(Path::new("/custom/grok/worktrees/repo")),
|
|
));
|
|
}
|
|
}
|