Skip to content

fix(runner): make Grok isolated-write lanes usable - #92

Open
andrewfree wants to merge 2 commits into
ericlitman:mainfrom
andrewfree:upstream-runner-fixes
Open

andrewfree wants to merge 2 commits into
ericlitman:mainfrom
andrewfree:upstream-runner-fixes

Conversation

@andrewfree

@andrewfree andrewfree commented Sep 28, 2026 •

Copy link
Copy Markdown

Closes #

What changed

Two fixes for the external runner's Grok lane, found while driving pstack-runner --provider grok from Claude Code with grok CLI 1.0.41.

  1. Tool name. The runner allowlists the shell tool as run_terminal_cmd, but grok 1.0.41 names it run_terminal_command. The unknown name is ignored, so every shell call falls through to an approver that a headless run cannot answer, and the lane is cancelled with User cancelled the execution for tool run_terminal_command.
  2. Permission mode for writers. Even with the right name, acceptEdits still routes multi-line commands (a python3 - <<'PY' heredoc) to that approver. Isolated-write Grok lanes now pass --permission-mode bypassPermissions, which is Grok's always-approve policy, while keeping --sandbox workspace; the sandbox, not the approver, confines the writer (reads everywhere, writes only to the lane's cwd, Grok's own state, and the system temp dirs; child network stays open). Read-only lanes keep plan plus read-only.

Review round (Codex GPT-6 Astra, xhigh): the writer test now asserts the complete Grok argv instead of arrayContaining, and the comment plus provider-dispatch.md state the approval-policy change and the sandbox's actual bounds, verified against the Grok sandbox and permissions docs.

Verification

  • Bun tests, strict typecheck, static invariants, and plugin validation pass.
  • The exact candidate is installed in every affected harness.
  • The changed behavior passes from each real user surface.
  • The installed version, action, and observed result appear below.

Live evidence:

  • Candidate: this branch's scripts/runner/pstack-runner at the reviewed commit, run from a checkout of the branch, with grok CLI 1.0.41 and model grok-4.7 (reported grok-4.7-build). Claude Code additionally has open-pstack 1.4.4 installed from the fork, which carries this change.
  • Claude parent: pstack-runner --parent claude --provider grok --model grok-4.7 --mode isolated-write with a prompt asking for a file written through a shell heredoc. Receipt: status: complete, modelVerified: true; the workspace contains proof.txt with pr92 claude; final reply done.
  • Codex parent: same invocation with --parent codex. Receipt: status: complete, modelVerified: true; proof.txt contains pr92 codex; final reply done.
  • Before the fix, the same lane was cancelled at the first shell call under both parents.
  • bun test in scripts/runner: 50 tests pass.

🤖 Generated with Claude Code

- allowlist the Grok shell tool by its real name: grok 1.0.41 calls it
  run_terminal_command, so run_terminal_cmd was ignored and every shell
  call fell through to a headless approver that cancelled the lane
  ("User cancelled the execution for tool run_terminal_command")
- run isolated-write Grok lanes under bypassPermissions: acceptEdits still
  routes multi-line commands (heredocs) to that approver; the workspace
  sandbox stays on and is what confines the writer, read-only keeps plan

Verified on grok 1.0.41: a runner lane executed a shell command and a
python heredoc and completed; 50 runner tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mergify

mergify Bot commented Sep 28, 2026

Copy link
Copy Markdown

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Changes Grok runner permission and tool configuration.

The PR appears safe to merge; no actionable regression was established.

Summary

The PR updates the Grok shell-tool name in both access modes and uses bypassPermissions for isolated-write lanes while retaining the workspace sandbox. It updates command assertions and the dispatch reference accordingly.

Reviews (1) · Last reviewed commit: "fix(runner): make Grok isolated-write la..."

…nges

Codex GPT-6 Astra review round. The writer test asserts the complete
Grok argv instead of arrayContaining, so a flag cannot drift from its
value. The runner comment and provider-dispatch.md say that
bypassPermissions is Grok's always-approve policy (deny rules and hooks
still apply) and that the workspace profile is what confines the writer:
reads everywhere, writes only to the lane's cwd, Grok state, and the
system temp dirs, child network open. Verified against the Grok sandbox
and permissions docs; bun tests, typecheck, manifests, and static
invariants pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant