mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
SessionMode gains 'grok', a first-class backend alongside Claude Code,
shell, OpenCode, Codex, Gemini, Antigravity and Pi: its own PTY, tmux
session, charcoal tab identity ('gk' badge), welcome button, run-mode
entry, cron agentType, Docker and remote-SSH command defaults, and
clone-repo Brain option. Flag surface verified live against grok 1.0.5.
Grok mixes two existing shapes and the wiring follows from that:
- Codex-shaped on permissions: the bypass switch is GrokConfig.alwaysApprove
(--always-approve, grok's bypassPermissions mode; config-level deny rules
still apply on top). The Run button sends it true, like runAntigravity(),
and clampExternalCliBypassForOwner() puts grok in the only-if-sent branch:
a bare grok spawn is grok's own ask-mode default, which is already safe,
so only a sent config needs the flag forced off. Cron needs nothing for
the same reason.
- OpenCode-shaped on rendering: grok is a fullscreen alternate-screen TUI
with mouse support, so it stays OUT of isAltScreenStripMode() and lands
on the narrow tmux-attach strip and the 'buffer' local-echo fallthrough
(unmeasured against an authenticated composer; documented fallback is the
'off' branch).
- Pi-shaped on resolution: 'grok' has npm squatters (@vibe-kit/grok-cli
also installs a grok bin), so grok-cli-resolver.ts version-probes every
candidate (grok --version, killSignal SIGKILL, VITEST-gated) and
GET /api/grok/status surfaces path AND version; GROK_VERSION_REGEX is
shared with the dependency registry so doctor and run mode cannot drift.
Env allowlist gains GROK_* plus the XAI_* vendor namespace (XAI_API_KEY is
grok's documented headless auth var), the same narrow-vendor reasoning as
GOOGLE_* for gemini. Resume is id-regexed on purpose: grok's own --resume
also matches session titles, which are arbitrary user strings that must
never reach the bash -c spawn line.
Docker: grok is not on npm, so the agent image installs it in its own step
(xAI's installer has no --dir override; the binary is copied to
/usr/local/bin and root's ~/.grok dropped in the same layer), and
credentials are seeded per-file (auth.json, config.toml, pager.toml; the
dir also holds sessions/, memory/ and the ~160MB binary). Remote SSH routes
through the login-shell wrapper like the other agent CLIs.
Verified end to end on an isolated CODEMAN_INSTANCE with grok 1.0.5
installed: /api/grok/status resolves and reports the probed version,
quick-start spawns a pane whose command line ends in 'grok
--always-approve', the real TUI renders (OAuth device screen on an
unauthenticated box), and grokConfig round-trips through state.json.
Docs: docs/grok-integration.md (user guide) + docs/grok-integration-plan.md
(decisions, verification record, follow-ups).
Tests: test/grok-mode.test.ts, test/grok-cli-resolver.test.ts, plus
extended clamp/system-routes/render-index-html/run-mode-ui/mobile-overview/
local-echo-gating coverage. npm test (the CI gate) green: 5910 tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
160 lines
5.6 KiB
TypeScript
160 lines
5.6 KiB
TypeScript
import { describe, expect, it } from 'vitest';
|
|
import { CreateSessionSchema, QuickStartSchema } from '../src/web/schemas.js';
|
|
import { buildSpawnCommand } from '../src/tmux-manager.js';
|
|
import { defaultDockerCommandForMode } from '../src/docker-hosts.js';
|
|
import { defaultRemoteCommandForMode } from '../src/remote-hosts.js';
|
|
import { isExternalCliMode, isAltScreenStripMode } from '../src/session.js';
|
|
|
|
describe('Grok mode schemas', () => {
|
|
it('accepts Grok session creation config', () => {
|
|
const parsed = CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
grokConfig: {
|
|
model: 'grok-4.5',
|
|
alwaysApprove: true,
|
|
},
|
|
});
|
|
|
|
expect(parsed.mode).toBe('grok');
|
|
expect(parsed.grokConfig).toEqual({
|
|
model: 'grok-4.5',
|
|
alwaysApprove: true,
|
|
});
|
|
});
|
|
|
|
it('accepts Grok quick-start config', () => {
|
|
const parsed = QuickStartSchema.parse({
|
|
caseName: 'grok-case',
|
|
mode: 'grok',
|
|
grokConfig: { resumeSessionId: '0198f2b4-aa10-7def-8123-4c5d6e7f8a9b', continueSession: true },
|
|
});
|
|
|
|
expect(parsed.mode).toBe('grok');
|
|
expect(parsed.grokConfig?.resumeSessionId).toBe('0198f2b4-aa10-7def-8123-4c5d6e7f8a9b');
|
|
});
|
|
|
|
it('rejects unsafe Grok model strings', () => {
|
|
expect(() =>
|
|
CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
grokConfig: { model: 'grok; rm -rf /' },
|
|
})
|
|
).toThrow();
|
|
});
|
|
|
|
it('rejects unsafe Grok resumeSessionId values (ids only, never titles or paths)', () => {
|
|
// grok's own --resume also matches session TITLES, which are arbitrary user
|
|
// strings; the id regex is what keeps those (and paths) off the spawn line.
|
|
expect(() =>
|
|
CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
grokConfig: { resumeSessionId: '../../etc/passwd' },
|
|
})
|
|
).toThrow();
|
|
expect(() =>
|
|
CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
grokConfig: { resumeSessionId: 'my session title' },
|
|
})
|
|
).toThrow();
|
|
});
|
|
|
|
it('allows GROK_* and XAI_* env overrides but NOT bare provider keys', () => {
|
|
const parsed = CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
envOverrides: { GROK_HOME: '/tmp/grok-home', XAI_API_KEY: 'xai-test' },
|
|
});
|
|
expect(parsed.envOverrides).toEqual({ GROK_HOME: '/tmp/grok-home', XAI_API_KEY: 'xai-test' });
|
|
|
|
// XAI_* is xAI's own namespace (grok's documented auth var), the same
|
|
// narrow-vendor-namespace reasoning that admitted GOOGLE_* for gemini.
|
|
// Foreign provider keys stay out.
|
|
expect(() =>
|
|
CreateSessionSchema.parse({
|
|
workingDir: '/tmp',
|
|
mode: 'grok',
|
|
envOverrides: { ANTHROPIC_API_KEY: 'sk-test' },
|
|
})
|
|
).toThrow();
|
|
});
|
|
});
|
|
|
|
describe('Grok spawn command', () => {
|
|
it('builds a bare grok command when no config is sent (ask-mode default)', () => {
|
|
const cmd = buildSpawnCommand({ mode: 'grok', sessionId: 'abc12345' });
|
|
expect(cmd).toBe('grok');
|
|
});
|
|
|
|
it('maps alwaysApprove and model to flags', () => {
|
|
const cmd = buildSpawnCommand({
|
|
mode: 'grok',
|
|
sessionId: 'abc12345',
|
|
grokConfig: { alwaysApprove: true, model: 'grok-4.5' },
|
|
});
|
|
expect(cmd).toBe('grok --always-approve --model grok-4.5');
|
|
});
|
|
|
|
it('omits --always-approve when false or absent (grok defaults safe on its own)', () => {
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: { alwaysApprove: false } })).toBe('grok');
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: {} })).toBe('grok');
|
|
});
|
|
|
|
it('passes --resume for resume and skips --continue when both are present', () => {
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: { resumeSessionId: '0198f2b4' } })).toBe(
|
|
'grok --resume 0198f2b4'
|
|
);
|
|
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: { continueSession: true } })).toBe(
|
|
'grok --continue'
|
|
);
|
|
|
|
// The two conflict upstream: a valid explicit session id wins.
|
|
expect(
|
|
buildSpawnCommand({
|
|
mode: 'grok',
|
|
sessionId: 'a',
|
|
grokConfig: { continueSession: true, resumeSessionId: '0198f2b4' },
|
|
})
|
|
).toBe('grok --resume 0198f2b4');
|
|
});
|
|
|
|
it('drops unsafe values rather than escaping them (the result lands in `bash -c "..."`)', () => {
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: { model: 'a`b' } })).toBe('grok');
|
|
expect(buildSpawnCommand({ mode: 'grok', sessionId: 'a', grokConfig: { resumeSessionId: 'x; rm -rf /' } })).toBe(
|
|
'grok'
|
|
);
|
|
});
|
|
|
|
it('never puts a secret-shaped flag on the spawn line (XAI_API_KEY flows via tmux setenv)', () => {
|
|
const cmd = buildSpawnCommand({
|
|
mode: 'grok',
|
|
sessionId: 'a',
|
|
grokConfig: { model: 'grok-4.5', alwaysApprove: true },
|
|
});
|
|
expect(cmd).not.toContain('key');
|
|
expect(cmd).not.toContain('token');
|
|
});
|
|
});
|
|
|
|
describe('Grok mode gates', () => {
|
|
it('is an external CLI mode (readiness/ralph/respawn gating)', () => {
|
|
expect(isExternalCliMode('grok')).toBe(true);
|
|
});
|
|
|
|
it('is NOT an alt-screen strip mode (fullscreen alt-screen TUI with mouse support)', () => {
|
|
expect(isAltScreenStripMode('grok')).toBe(false);
|
|
});
|
|
|
|
it('has docker/remote default commands', () => {
|
|
expect(defaultDockerCommandForMode('grok')).toBe('exec grok');
|
|
// Routed through an interactive login shell so ~/.grok/bin resolves,
|
|
// the same fix as the other remote agent CLIs (see defaultRemoteCommandForMode).
|
|
expect(defaultRemoteCommandForMode('grok')).toBe('exec "${SHELL:-/bin/sh}" -i -l -c \'grok\'');
|
|
});
|
|
});
|