fix(runner): make Grok isolated-write lanes usable - #92
andrewfree wants to merge 2 commits into
Conversation
- allowlist the Grok shell tool by its real name: grok 1.0.41 calls it
run_terminal_command, so run_terminal_cmd was ignored and every shell
call fell through to a headless approver that cancelled the lane
("User cancelled the execution for tool run_terminal_command")
- run isolated-write Grok lanes under bypassPermissions: acceptEdits still
routes multi-line commands (heredocs) to that approver; the workspace
sandbox stays on and is what confines the writer, read-only keeps plan
Verified on grok 1.0.41: a runner lane executed a shell command and a
python heredoc and completed; 50 runner tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
|
…nges Codex GPT-6 Astra review round. The writer test asserts the complete Grok argv instead of arrayContaining, so a flag cannot drift from its value. The runner comment and provider-dispatch.md say that bypassPermissions is Grok's always-approve policy (deny rules and hooks still apply) and that the workspace profile is what confines the writer: reads everywhere, writes only to the lane's cwd, Grok state, and the system temp dirs, child network open. Verified against the Grok sandbox and permissions docs; bun tests, typecheck, manifests, and static invariants pass. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Thanks for this, @andrewfree. I appreciate the time you put into it. Open Pstack now accepts contributions as detailed issues rather than pull requests, so I'm closing this one. If it's still relevant, please open an issue describing the problem, how to reproduce it, and the change you'd suggest. I'll take it from there. |
|
Follow-up to the close: this work is already tracked in #34, so there is no need to open a new issue. This PR is noted there as prior art and will be credited when the fix lands. |
Closes #
What changed
Two fixes for the external runner's Grok lane, found while driving
pstack-runner --provider grokfrom Claude Code with grok CLI 1.0.41.run_terminal_cmd, but grok 1.0.41 names itrun_terminal_command. The unknown name is ignored, so every shell call falls through to an approver that a headless run cannot answer, and the lane is cancelled withUser cancelled the execution for tool run_terminal_command.acceptEditsstill routes multi-line commands (apython3 - <<'PY'heredoc) to that approver. Isolated-write Grok lanes now pass--permission-mode bypassPermissions, which is Grok's always-approve policy, while keeping--sandbox workspace; the sandbox, not the approver, confines the writer (reads everywhere, writes only to the lane's cwd, Grok's own state, and the system temp dirs; child network stays open). Read-only lanes keepplanplusread-only.Review round (Codex GPT-6 Astra, xhigh): the writer test now asserts the complete Grok argv instead of
arrayContaining, and the comment plusprovider-dispatch.mdstate the approval-policy change and the sandbox's actual bounds, verified against the Grok sandbox and permissions docs.Verification
Live evidence:
scripts/runner/pstack-runnerat the reviewed commit, run from a checkout of the branch, with grok CLI 1.0.41 and model grok-4.7 (reportedgrok-4.7-build). Claude Code additionally has open-pstack 1.4.4 installed from the fork, which carries this change.pstack-runner --parent claude --provider grok --model grok-4.7 --mode isolated-writewith a prompt asking for a file written through a shell heredoc. Receipt:status: complete,modelVerified: true; the workspace containsproof.txtwithpr92 claude; final replydone.--parent codex. Receipt:status: complete,modelVerified: true;proof.txtcontainspr92 codex; final replydone.bun testinscripts/runner: 50 tests pass.🤖 Generated with Claude Code