feat(grok): add Grok Build (xAI) as a seventh CLI run mode

SessionMode gains 'grok', a first-class backend alongside Claude Code,
shell, OpenCode, Codex, Gemini, Antigravity and Pi: its own PTY, tmux
session, charcoal tab identity ('gk' badge), welcome button, run-mode
entry, cron agentType, Docker and remote-SSH command defaults, and
clone-repo Brain option. Flag surface verified live against grok 1.0.5.

Grok mixes two existing shapes and the wiring follows from that:

- Codex-shaped on permissions: the bypass switch is GrokConfig.alwaysApprove
  (--always-approve, grok's bypassPermissions mode; config-level deny rules
  still apply on top). The Run button sends it true, like runAntigravity(),
  and clampExternalCliBypassForOwner() puts grok in the only-if-sent branch:
  a bare grok spawn is grok's own ask-mode default, which is already safe,
  so only a sent config needs the flag forced off. Cron needs nothing for
  the same reason.
- OpenCode-shaped on rendering: grok is a fullscreen alternate-screen TUI
  with mouse support, so it stays OUT of isAltScreenStripMode() and lands
  on the narrow tmux-attach strip and the 'buffer' local-echo fallthrough
  (unmeasured against an authenticated composer; documented fallback is the
  'off' branch).
- Pi-shaped on resolution: 'grok' has npm squatters (@vibe-kit/grok-cli
  also installs a grok bin), so grok-cli-resolver.ts version-probes every
  candidate (grok --version, killSignal SIGKILL, VITEST-gated) and
  GET /api/grok/status surfaces path AND version; GROK_VERSION_REGEX is
  shared with the dependency registry so doctor and run mode cannot drift.

Env allowlist gains GROK_* plus the XAI_* vendor namespace (XAI_API_KEY is
grok's documented headless auth var), the same narrow-vendor reasoning as
GOOGLE_* for gemini. Resume is id-regexed on purpose: grok's own --resume
also matches session titles, which are arbitrary user strings that must
never reach the bash -c spawn line.

Docker: grok is not on npm, so the agent image installs it in its own step
(xAI's installer has no --dir override; the binary is copied to
/usr/local/bin and root's ~/.grok dropped in the same layer), and
credentials are seeded per-file (auth.json, config.toml, pager.toml; the
dir also holds sessions/, memory/ and the ~160MB binary). Remote SSH routes
through the login-shell wrapper like the other agent CLIs.

Verified end to end on an isolated CODEMAN_INSTANCE with grok 1.0.5
installed: /api/grok/status resolves and reports the probed version,
quick-start spawns a pane whose command line ends in 'grok
--always-approve', the real TUI renders (OAuth device screen on an
unauthenticated box), and grokConfig round-trips through state.json.
Docs: docs/grok-integration.md (user guide) + docs/grok-integration-plan.md
(decisions, verification record, follow-ups).

Tests: test/grok-mode.test.ts, test/grok-cli-resolver.test.ts, plus
extended clamp/system-routes/render-index-html/run-mode-ui/mobile-overview/
local-echo-gating coverage. npm test (the CI gate) green: 5910 tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-23 08:39:03 +02:00
parent 88bb98de43
commit 3f8c8e99d1
55 changed files with 1474 additions and 119 deletions
+48 -21
View File
@@ -5,7 +5,7 @@
* `POST /api/quick-start` and, until pi was added, had no tests at all.
*
* The helper has two shapes and the difference is the whole point:
* - only-if-sent (codex, antigravity): an ABSENT config already spawns safe, so
* - only-if-sent (codex, antigravity, grok): an ABSENT config already spawns safe, so
* only a sent config needs its flag forced off.
* - MATERIALIZE (gemini, pi): the absent-config default is itself unsafe for a
* non-granted owner (gemini's builder defaults to `yolo`; pi's default is an
@@ -25,20 +25,23 @@ describe('clampExternalCliBypassForOwner — single-user mode', () => {
{ dangerouslyBypassApprovals: true },
{ approvalMode: 'yolo' },
{ dangerouslySkipPermissions: true },
{ approveProjectTrust: true }
{ approveProjectTrust: true },
{ alwaysApprove: true }
);
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: true });
expect(out.geminiConfig).toEqual({ approvalMode: 'yolo' });
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: true });
expect(out.piConfig).toEqual({ approveProjectTrust: true });
expect(out.grokConfig).toEqual({ alwaysApprove: true });
});
it('leaves absent configs absent', async () => {
const out = await _clampExternalCliBypassForOwner(undefined, undefined, undefined, undefined, undefined);
const out = await _clampExternalCliBypassForOwner(undefined, undefined, undefined, undefined, undefined, undefined);
expect(out.codexConfig).toBeUndefined();
expect(out.geminiConfig).toBeUndefined();
expect(out.antigravityConfig).toBeUndefined();
expect(out.piConfig).toBeUndefined();
expect(out.grokConfig).toBeUndefined();
});
});
@@ -64,57 +67,75 @@ describe('clampExternalCliBypassForOwner — multi-user mode', () => {
{ dangerouslyBypassApprovals: true },
undefined,
{ dangerouslySkipPermissions: true },
{ approveProjectTrust: true }
{ approveProjectTrust: true },
{ alwaysApprove: true }
);
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: true });
expect(out.geminiConfig).toBeUndefined();
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: true });
expect(out.piConfig).toEqual({ approveProjectTrust: true });
expect(out.grokConfig).toEqual({ alwaysApprove: true });
});
it('passes through for a user holding the bypass grant', async () => {
const out = await _clampExternalCliBypassForOwner('trusted', undefined, undefined, undefined, {
approveProjectTrust: true,
});
const out = await _clampExternalCliBypassForOwner(
'trusted',
undefined,
undefined,
undefined,
{ approveProjectTrust: true },
{ alwaysApprove: true }
);
expect(out.piConfig).toEqual({ approveProjectTrust: true });
expect(out.grokConfig).toEqual({ alwaysApprove: true });
});
it('forces codex/antigravity bypass off for a non-granted owner (only-if-sent branch)', async () => {
it('forces codex/antigravity/grok bypass off for a non-granted owner (only-if-sent branch)', async () => {
const out = await _clampExternalCliBypassForOwner(
'peon',
{ dangerouslyBypassApprovals: true, model: 'gpt-5' },
undefined,
{ dangerouslySkipPermissions: true, model: 'gemini-3-pro' },
undefined
undefined,
{ alwaysApprove: true, model: 'grok-4.5' }
);
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: false, model: 'gpt-5' });
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: false, model: 'gemini-3-pro' });
expect(out.grokConfig).toEqual({ alwaysApprove: false, model: 'grok-4.5' });
});
it('leaves codex/antigravity absent when nothing was sent (they already spawn safe)', async () => {
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
it('leaves codex/antigravity/grok absent when nothing was sent (they already spawn safe)', async () => {
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined, undefined);
expect(out.codexConfig).toBeUndefined();
expect(out.antigravityConfig).toBeUndefined();
expect(out.grokConfig).toBeUndefined();
});
it('MATERIALIZES gemini to auto_edit even when no config was sent', async () => {
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined, undefined);
expect(out.geminiConfig).toEqual({ approvalMode: 'auto_edit' });
});
it('MATERIALIZES pi to --no-approve even when no config was sent', async () => {
// The load-bearing case: omitting --approve is NOT a clamp for pi, because
// pi's own default is to ASK, and the session user can answer that prompt.
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined, undefined);
expect(out.piConfig).toEqual({ approveProjectTrust: false });
});
it('forces a sent pi approveProjectTrust:true down to false, keeping other fields', async () => {
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, {
approveProjectTrust: true,
model: 'sonnet:high',
provider: 'anthropic',
});
const out = await _clampExternalCliBypassForOwner(
'peon',
undefined,
undefined,
undefined,
{
approveProjectTrust: true,
model: 'sonnet:high',
provider: 'anthropic',
},
undefined
);
expect(out.piConfig).toEqual({
approveProjectTrust: false,
model: 'sonnet:high',
@@ -123,10 +144,16 @@ describe('clampExternalCliBypassForOwner — multi-user mode', () => {
});
it('fails closed for an unknown/deleted owner', async () => {
const out = await _clampExternalCliBypassForOwner('ghost', undefined, undefined, undefined, {
approveProjectTrust: true,
});
const out = await _clampExternalCliBypassForOwner(
'ghost',
undefined,
undefined,
undefined,
{ approveProjectTrust: true },
{ alwaysApprove: true }
);
expect(out.piConfig).toEqual({ approveProjectTrust: false });
expect(out.geminiConfig).toEqual({ approvalMode: 'auto_edit' });
expect(out.grokConfig).toEqual({ alwaysApprove: false });
});
});
+42
View File
@@ -92,6 +92,12 @@ vi.mock('../../src/utils/pi-cli-resolver.js', () => ({
getPiCliVersion: vi.fn(() => null),
}));
vi.mock('../../src/utils/grok-cli-resolver.js', () => ({
isGrokAvailable: vi.fn(() => false),
resolveGrokDir: vi.fn(() => null),
getGrokCliVersion: vi.fn(() => null),
}));
import fs from 'node:fs/promises';
import { existsSync, readdirSync } from 'node:fs';
import { subagentWatcher } from '../../src/subagent-watcher.js';
@@ -100,6 +106,7 @@ import { isOpenCodeAvailable, resolveOpenCodeDir } from '../../src/utils/opencod
import { isGeminiAvailable, resolveGeminiDir } from '../../src/utils/gemini-cli-resolver.js';
import { isAntigravityAvailable, resolveAntigravityDir } from '../../src/utils/antigravity-cli-resolver.js';
import { isPiAvailable, resolvePiDir, getPiCliVersion } from '../../src/utils/pi-cli-resolver.js';
import { isGrokAvailable, resolveGrokDir, getGrokCliVersion } from '../../src/utils/grok-cli-resolver.js';
const mockedReadFile = vi.mocked(fs.readFile);
const mockedWriteFile = vi.mocked(fs.writeFile);
@@ -116,6 +123,9 @@ const mockedResolveAntigravityDir = vi.mocked(resolveAntigravityDir);
const mockedIsPiAvailable = vi.mocked(isPiAvailable);
const mockedResolvePiDir = vi.mocked(resolvePiDir);
const mockedGetPiCliVersion = vi.mocked(getPiCliVersion);
const mockedIsGrokAvailable = vi.mocked(isGrokAvailable);
const mockedResolveGrokDir = vi.mocked(resolveGrokDir);
const mockedGetGrokCliVersion = vi.mocked(getGrokCliVersion);
describe('system-routes', () => {
let harness: RouteTestHarness;
@@ -881,6 +891,38 @@ describe('system-routes', () => {
});
});
// ========== GET /api/grok/status ==========
describe('GET /api/grok/status', () => {
it('returns unavailable when grok is not installed', async () => {
mockedIsGrokAvailable.mockReturnValue(false);
mockedResolveGrokDir.mockReturnValue(null);
mockedGetGrokCliVersion.mockReturnValue(null);
const res = await harness.app.inject({ method: 'GET', url: '/api/grok/status' });
expect(res.statusCode).toBe(200);
const body = JSON.parse(res.body);
expect(body.available).toBe(false);
expect(body.path).toBeNull();
expect(body.version).toBeNull();
});
it('returns available with path AND version when grok is installed', async () => {
// `version` matters for the same reason as pi: `grok` has known squatters,
// so this endpoint is where a misresolution shows up.
mockedIsGrokAvailable.mockReturnValue(true);
mockedResolveGrokDir.mockReturnValue('/home/user/.grok/bin');
mockedGetGrokCliVersion.mockReturnValue('1.0.5');
const res = await harness.app.inject({ method: 'GET', url: '/api/grok/status' });
expect(res.statusCode).toBe(200);
const body = JSON.parse(res.body);
expect(body.available).toBe(true);
expect(body.path).toBe('/home/user/.grok/bin');
expect(body.version).toBe('1.0.5');
});
});
// ========== GET /api/execution/model-config ==========
describe('GET /api/execution/model-config', () => {