fix(grok): address adversarial-review findings across the grok-CLI conversion

A 7-dimension adversarial review (find -> independently refute) surfaced 14 real
issues; fixed each:

Runtime bugs
- GrokCliSession.send drained stdout fully BEFORE stderr — a >64KB stderr burst
  would deadlock the turn forever (spinner never clears). Drain stderr
  concurrently, and add a per-turn watchdog (ROBOCO_GROK_TURN_TIMEOUT_SECONDS,
  default 600s) that kills a wedged process and emits error+turn_end.
- Crash-restarted grok agents launched `grok -p ""` (empty prompt) — Claude gets
  a scan-for-work fallback. Default the prompt in _spawn_container so every
  dedicated provider gets it too.
- _grok_usage_json read /data/grok-usage unconditionally while its writers branch
  compose-vs-local, so a local-mode agent finalized at $0 and the cost-cap was
  inert. Single-source the path in a new _grok_usage_dir helper (read == write).
- GrokCliSession secretary role fell through to "unknown" (get_agent_role returns
  a truthy sentinel, never None), defeating the ROBOCO_AGENT_ROLE fallback.

Parity / hardening
- --deny set was missing `git tag -d` / `git reflog delete` that the Claude
  bash-guard blocks — added them (the "same set" claim is now true).
- Interactive mains now install the bash-guard hook too (defense-in-depth).
- Compose: collapse the GROK_AUTH_DIR / ROBOCO_HOST_GROK_DIR auth-mount pair into
  one canonical var so a partial override can't silently break agent auth.

Docs / comments
- Panel routing card + architecture security doc no longer say Grok runs on the
  deleted opencode runtime; orchestrator comments point at the renamed entrypoint.

Tests
- Cover the interactive _render_grok_config MCP wiring (ModuleNotFound guard +
  secretary HMAC env), the cost-cap kill-failure + interactive relay-close paths,
  the local-mode usage read, the role fallback, the turn timeout, and the new
  git denies. (#13 — a separate grok "Write" tool — investigated: grok's only
  built-in file-mutation tool is search_replace, already removed; no gap.)

Gate green: ruff, mypy, xenon, tests.
This commit is contained in:
Renn F
2026-06-19 06:09:15 +02:00
parent 0aa21639ab
commit a402de61bc
16 changed files with 378 additions and 68 deletions
@@ -74,8 +74,8 @@ const AGENTS: { slug: string; label: string }[] = [
{ slug: "ux-dev-1", label: "UX/UI Dev" },
{ slug: "ux-qa", label: "UX/UI QA" },
{ slug: "ux-doc", label: "UX/UI Documenter" },
// Interactive (held-open chat) roles. Claude (SDK driver) and Grok (opencode
// serve) are the supported runtimes; assigning a Grok model routes them to
// Interactive (held-open chat) roles. Claude (SDK driver) and Grok (grok CLI)
// are the supported runtimes; assigning a Grok model routes them to
// the grok-prompter / grok-secretary image.
{ slug: "intake-1", label: "Intake (Prompter)" },
{ slug: "secretary-1", label: "Secretary" },
@@ -493,7 +493,7 @@ export function AIRoutingCard() {
) : null}
{currentMode === "grok" || currentMode === "mix" ? (
<p className="text-xs text-muted-foreground">
Grok agents run on the opencode runtime; the command /
Grok agents run on xAI&apos;s official grok CLI; the command /
secret-exfiltration guard, the prompt-injection guard, and the
per-agent cost cap all apply.
</p>