diff --git a/plugins/pstack/skills/poteto-mode/references/provider-dispatch.md b/plugins/pstack/skills/poteto-mode/references/provider-dispatch.md index 74ab90da..7374f283 100644 --- a/plugins/pstack/skills/poteto-mode/references/provider-dispatch.md +++ b/plugins/pstack/skills/poteto-mode/references/provider-dispatch.md @@ -80,7 +80,7 @@ Start the background process, continue launching the other lanes, then drain the The runner and its preflight have no implicit timeout. Do not invent a duration from role, mode, or a convenient round number; real implementation lanes can run for 90 minutes or much longer. Pass `--timeout` only when the user, an external service deadline, or a measured task contract supplies a real bound. That value starts at wrapper entry, before module loading and argument parsing, and remains one absolute deadline across setup, preflight, model execution, and output capture. It is never a fresh allowance per child, and long waits are armed in runtime-safe chunks without shortening the supplied deadline. Otherwise supervise liveness through the retained background task/session handle and cancel manually only on evidence that the run is dead. Cancel through that retained handle so the runner receives SIGINT or SIGTERM, sends it to an active child when one remains, stops waiting on inherited output pipes, removes the empty output reservation, and writes a `cancelled` receipt. Preserve that receipt; a retry is a new attempt with new unique output and receipt paths. Unchanged running state is not a dropout, and Claude's ten-minute foreground ceiling is never a reason to terminate a healthy lane. -Read-only mode maps to Claude plan mode with project-only settings and an explicit tool list, Codex's read-only sandbox, and Grok plan mode plus its `read-only` sandbox and read-oriented tool list. Grok's built-in read-only profile deliberately keeps its own state and system temporary directories writable, so point a read-only Grok lane at the actual checkout rather than a worktree under `/tmp`, `/var/tmp`, or the host's temporary directory. `isolated-write` maps to Claude `acceptEdits` with project-only settings, Codex `workspace-write`, and Grok `acceptEdits` plus its `workspace` sandbox and write-capable tool list. Give every writer only a dedicated worktree or output directory. Never route a writer into the primary checkout. +Read-only mode maps to Claude plan mode with project-only settings and an explicit tool list, Codex's read-only sandbox, and Grok plan mode plus its `read-only` sandbox and read-oriented tool list. Grok's built-in read-only profile deliberately keeps its own state and system temporary directories writable, so point a read-only Grok lane at the actual checkout rather than a worktree under `/tmp`, `/var/tmp`, or the host's temporary directory. `isolated-write` maps to Claude `acceptEdits` with project-only settings, Codex `workspace-write`, and Grok `bypassPermissions` plus its `workspace` sandbox and write-capable tool list. Grok's `acceptEdits` (tested on grok 1.0.41) still sends multi-line shell commands to an approver that a headless run cannot answer, so the sandbox, not the approver, is what confines a Grok writer: `bypassPermissions` is Grok's always-approve policy and skips ordinary tool approvals (deny rules and hooks still apply), while the `workspace` profile allows reads everywhere, writes only to the lane's cwd, Grok's own state, and the system temporary directories, and does not block child network access (on macOS no profile does). Give every writer only a dedicated worktree or output directory. Never route a writer into the primary checkout. Every concurrent external lane needs distinct prompt, output, and receipt paths. The launcher reserves output and receipt paths exclusively and refuses to overwrite them. diff --git a/plugins/pstack/skills/poteto-mode/scripts/runner/commands.test.ts b/plugins/pstack/skills/poteto-mode/scripts/runner/commands.test.ts index ea697ff2..67f5de0d 100644 --- a/plugins/pstack/skills/poteto-mode/scripts/runner/commands.test.ts +++ b/plugins/pstack/skills/poteto-mode/scripts/runner/commands.test.ts @@ -100,7 +100,7 @@ describe("invocationCommand", () => { "--sandbox", "read-only", "--tools", - "read_file,grep,list_dir,run_terminal_cmd", + "read_file,grep,list_dir,run_terminal_command", "--disallowed-tools", "Agent,search_tool,use_tool", "--output-format", @@ -113,7 +113,7 @@ describe("invocationCommand", () => { ]); }); - it("uses bounded write modes without blanket bypasses", () => { + it("confines writers with sandboxes rather than approvals", () => { const codex = invocationCommand(options({ mode: "isolated-write" })); expect(codex.args).toEqual( expect.arrayContaining(["--sandbox", "workspace-write"]) @@ -121,17 +121,29 @@ describe("invocationCommand", () => { const grok = invocationCommand( options({ provider: "grok", model: "grok-4.6", mode: "isolated-write" }) ); - expect(grok.args).toEqual( - expect.arrayContaining([ - "--permission-mode", - "acceptEdits", - "--sandbox", - "workspace", - "--tools", - "read_file,grep,list_dir,run_terminal_cmd,search_replace", - ]) - ); - expect(grok.args).not.toContain("--always-approve"); + expect(grok.args).toEqual([ + "--prompt-file", + "/tmp/prompt.md", + "--model", + "grok-4.6", + "--reasoning-effort", + "max", + "--permission-mode", + "bypassPermissions", + "--sandbox", + "workspace", + "--tools", + "read_file,grep,list_dir,run_terminal_command,search_replace", + "--disallowed-tools", + "Agent,search_tool,use_tool", + "--output-format", + "streaming-messages-json", + "--cwd", + "/tmp/worktree", + "--no-subagents", + "--disable-web-search", + "--verbatim", + ]); const claude = invocationCommand( options({ provider: "claude", model: "fable", mode: "isolated-write" }) diff --git a/plugins/pstack/skills/poteto-mode/scripts/runner/commands.ts b/plugins/pstack/skills/poteto-mode/scripts/runner/commands.ts index 5f2b10c6..7fc9fd7e 100644 --- a/plugins/pstack/skills/poteto-mode/scripts/runner/commands.ts +++ b/plugins/pstack/skills/poteto-mode/scripts/runner/commands.ts @@ -51,7 +51,7 @@ function grokSandbox(mode: AccessMode): string { } function grokTools(mode: AccessMode): string { - const readonly = ["read_file", "grep", "list_dir", "run_terminal_cmd"]; + const readonly = ["read_file", "grep", "list_dir", "run_terminal_command"]; return [...readonly, ...(mode === "isolated-write" ? ["search_replace"] : [])].join(","); } @@ -59,6 +59,17 @@ function permissionMode(mode: AccessMode): string { return mode === "read-only" ? "plan" : "acceptEdits"; } +// Grok's acceptEdits (grok 1.0.41) still routes multi-line shell commands +// (heredocs) to an approver that a headless run cannot answer, which cancels +// the lane. bypassPermissions is Grok's always-approve policy: ordinary tool +// approvals are skipped (deny rules and hooks still apply), so the workspace +// sandbox is what confines the writer: reads anywhere, writes only to the +// lane's cwd, Grok's own state, and the system temp dirs; child network +// stays open. +function grokPermissionMode(mode: AccessMode): string { + return mode === "read-only" ? "plan" : "bypassPermissions"; +} + function effortOverride(effort: Effort): string { return `model_reasoning_effort=${JSON.stringify(effort)}`; } @@ -129,7 +140,7 @@ export function invocationCommand(options: RunnerOptions): CommandSpec { "--reasoning-effort", options.effort, "--permission-mode", - permissionMode(options.mode), + grokPermissionMode(options.mode), "--sandbox", grokSandbox(options.mode), "--tools",