fix(runner): make Grok isolated-write lanes usable - #92
Open
andrewfree wants to merge 2 commits into
Open
andrewfree wants to merge 2 commits into
andrewfree wants to merge 2 commits into
Conversation
- allowlist the Grok shell tool by its real name: grok 1.0.41 calls it
run_terminal_command, so run_terminal_cmd was ignored and every shell
call fell through to a headless approver that cancelled the lane
("User cancelled the execution for tool run_terminal_command")
- run isolated-write Grok lanes under bypassPermissions: acceptEdits still
routes multi-line commands (heredocs) to that approver; the workspace
sandbox stays on and is what confines the writer, read-only keeps plan
Verified on grok 1.0.41: a runner lane executed a shell command and a
python heredoc and completed; 50 runner tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Tick the box to add this pull request to the merge queue (same as
|
|
…nges Codex GPT-6 Astra review round. The writer test asserts the complete Grok argv instead of arrayContaining, so a flag cannot drift from its value. The runner comment and provider-dispatch.md say that bypassPermissions is Grok's always-approve policy (deny rules and hooks still apply) and that the workspace profile is what confines the writer: reads everywhere, writes only to the lane's cwd, Grok state, and the system temp dirs, child network open. Verified against the Grok sandbox and permissions docs; bun tests, typecheck, manifests, and static invariants pass. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #
What changed
Two fixes for the external runner's Grok lane, found while driving
pstack-runner --provider grokfrom Claude Code with grok CLI 1.0.41.run_terminal_cmd, but grok 1.0.41 names itrun_terminal_command. The unknown name is ignored, so every shell call falls through to an approver that a headless run cannot answer, and the lane is cancelled withUser cancelled the execution for tool run_terminal_command.acceptEditsstill routes multi-line commands (apython3 - <<'PY'heredoc) to that approver. Isolated-write Grok lanes now pass--permission-mode bypassPermissions, which is Grok's always-approve policy, while keeping--sandbox workspace; the sandbox, not the approver, confines the writer (reads everywhere, writes only to the lane's cwd, Grok's own state, and the system temp dirs; child network stays open). Read-only lanes keepplanplusread-only.Review round (Codex GPT-6 Astra, xhigh): the writer test now asserts the complete Grok argv instead of
arrayContaining, and the comment plusprovider-dispatch.mdstate the approval-policy change and the sandbox's actual bounds, verified against the Grok sandbox and permissions docs.Verification
Live evidence:
scripts/runner/pstack-runnerat the reviewed commit, run from a checkout of the branch, with grok CLI 1.0.41 and model grok-4.7 (reportedgrok-4.7-build). Claude Code additionally has open-pstack 1.4.4 installed from the fork, which carries this change.pstack-runner --parent claude --provider grok --model grok-4.7 --mode isolated-writewith a prompt asking for a file written through a shell heredoc. Receipt:status: complete,modelVerified: true; the workspace containsproof.txtwithpr92 claude; final replydone.--parent codex. Receipt:status: complete,modelVerified: true;proof.txtcontainspr92 codex; final replydone.bun testinscripts/runner: 50 tests pass.🤖 Generated with Claude Code