mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
fix(grok): address adversarial-review findings across the grok-CLI conversion
A 7-dimension adversarial review (find -> independently refute) surfaced 14 real issues; fixed each: Runtime bugs - GrokCliSession.send drained stdout fully BEFORE stderr — a >64KB stderr burst would deadlock the turn forever (spinner never clears). Drain stderr concurrently, and add a per-turn watchdog (ROBOCO_GROK_TURN_TIMEOUT_SECONDS, default 600s) that kills a wedged process and emits error+turn_end. - Crash-restarted grok agents launched `grok -p ""` (empty prompt) — Claude gets a scan-for-work fallback. Default the prompt in _spawn_container so every dedicated provider gets it too. - _grok_usage_json read /data/grok-usage unconditionally while its writers branch compose-vs-local, so a local-mode agent finalized at $0 and the cost-cap was inert. Single-source the path in a new _grok_usage_dir helper (read == write). - GrokCliSession secretary role fell through to "unknown" (get_agent_role returns a truthy sentinel, never None), defeating the ROBOCO_AGENT_ROLE fallback. Parity / hardening - --deny set was missing `git tag -d` / `git reflog delete` that the Claude bash-guard blocks — added them (the "same set" claim is now true). - Interactive mains now install the bash-guard hook too (defense-in-depth). - Compose: collapse the GROK_AUTH_DIR / ROBOCO_HOST_GROK_DIR auth-mount pair into one canonical var so a partial override can't silently break agent auth. Docs / comments - Panel routing card + architecture security doc no longer say Grok runs on the deleted opencode runtime; orchestrator comments point at the renamed entrypoint. Tests - Cover the interactive _render_grok_config MCP wiring (ModuleNotFound guard + secretary HMAC env), the cost-cap kill-failure + interactive relay-close paths, the local-mode usage read, the role fallback, the turn timeout, and the new git denies. (#13 — a separate grok "Write" tool — investigated: grok's only built-in file-mutation tool is search_replace, already removed; no gap.) Gate green: ruff, mypy, xenon, tests.
This commit is contained in:
@@ -130,18 +130,21 @@ def test_max_turns_is_emitted() -> None:
|
||||
|
||||
|
||||
def test_bash_roles_deny_the_full_git_mutation_set() -> None:
|
||||
# Graceful native --deny rules (the agent recovers) covering the same git
|
||||
# network / branch / history ops the Claude bash-guard blocks.
|
||||
# Graceful native --deny rules (the agent recovers) covering the SAME git
|
||||
# network / branch / history ops the Claude bash-guard blocks — including the
|
||||
# tag-deletion / reflog-deletion the hook matches.
|
||||
args = gc.grok_cli_args_for_role("developer")
|
||||
for op in ("push", "fetch", "clone", "checkout", "merge", "rebase", "revert"):
|
||||
assert f"Bash(git {op}*)" in args
|
||||
assert "Bash(git tag -d*)" in args
|
||||
assert "Bash(git reflog delete*)" in args
|
||||
assert "Bash(rm -rf*)" in args
|
||||
|
||||
|
||||
def test_bash_guard_hook_config_skips_git() -> None:
|
||||
handler = gc.bash_guard_hook_config("/app/scripts/bash-guard-hook.sh")[
|
||||
"hooks"
|
||||
]["PreToolUse"][0]
|
||||
handler = gc.bash_guard_hook_config("/app/scripts/bash-guard-hook.sh")["hooks"][
|
||||
"PreToolUse"
|
||||
][0]
|
||||
assert handler["matcher"] == "Bash"
|
||||
inner = handler["hooks"][0]
|
||||
assert inner["command"] == "/app/scripts/bash-guard-hook.sh"
|
||||
|
||||
Reference in New Issue
Block a user