§9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed

The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok'
crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party
license archives, README provenance, and the required 'Based on Grok
Build Open Source' attribution, now sourced from version_attribution.txt).

Wire-visible renames (both sides in this repo, changed in lockstep):
- Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode).
- Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* /
  _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps
  a read-side alias for the legacy '_x.ai/session/update' method so
  existing updates.jsonl histories load; writes emit only the new name
  (both directions test-pinned).
- Agent types grok-build* → kigi* with a documented legacy-prefix alias
  at resolution time so persisted sessions keep resolving.
- ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case
  kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build
  implementation dirs renamed to kigi*.
- x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes
  grokday/groknight → kigiday/kiginight (old persisted values fall back
  to the default theme), web_fetch allowlist xAI hosts → kimi.com +
  moonshot platforms, changelog CDN → this repo, grok-build changelog
  archives deleted.
- BYOK default endpoint removed: [endpoints] api_base_url is now truly
  optional with NO default — consumers fail fast with the flag name when
  unset (no silent x.ai egress). Mock harnesses inject it explicitly.
- System-prompt identity fixed: 'released by xAI' → 'an unofficial
  community CLI for Kimi' (template + regenerated encrypted form).

Also repaired pre-existing grok-era test debt found by the sweep: the
stale trace_classify default-model pin, the grok-pager UA label test,
pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY
test could previously reach the real api.moonshot.cn), and the outdated
oauth fixture scope key.

Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings);
FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed;
deny advisories ok.
This commit is contained in:
2026-07-18 02:48:46 -04:00
parent 86e3724310
commit 6f31415ed6
1056 changed files with 8410 additions and 18307 deletions
@@ -26,7 +26,7 @@
//!
//! # Compare an old release artifact, text mode only, JSON to a file:
//! cargo bench -p kigi-pager-pty-harness --bench paste_latency -- \
//! --binary ~/Downloads/grok-old --mode text --json /tmp/paste-old.json
//! --binary ~/Downloads/kigi-old --mode text --json /tmp/paste-old.json
//! ```
use std::path::{Path, PathBuf};
@@ -21,7 +21,7 @@
//!
//! Run every scenario in CI and fail on >15% p99 regression:
//! ```bash
//! PAGER_BINARY=./artifacts/grok-${VERSION}-linux-x86_64 \
//! PAGER_BINARY=./artifacts/kigi-${VERSION}-linux-x86_64 \
//! cargo bench -p kigi-pager-pty-harness \
//! --bench pty_bench -- --all \
//! --baseline benches/pty_baselines/linux-x86_64.json
@@ -20,7 +20,7 @@ struct Cli {
#[arg(long, value_name = "PATH")]
scenario: PathBuf,
/// Pager binary. Defaults to PAGER_BINARY, CARGO_BIN_EXE_kigi-tui,
/// Pager binary. Defaults to PAGER_BINARY, CARGO_BIN_EXE_kigi,
/// or a locally-built debug binary.
#[arg(long, value_name = "PATH")]
binary: Option<PathBuf>,
@@ -53,7 +53,7 @@ struct Cli {
#[arg(long, value_name = "DIR", default_value = "target/scroll-matrix")]
artifacts: PathBuf,
/// Pager binary. Defaults to PAGER_BINARY, CARGO_BIN_EXE_kigi-tui,
/// Pager binary. Defaults to PAGER_BINARY, CARGO_BIN_EXE_kigi,
/// or a locally-built debug binary.
#[arg(long, value_name = "PATH")]
binary: Option<PathBuf>,
@@ -92,6 +92,11 @@ impl ContentController {
("KIGI_SHARE_DIR".into(), kigi_home),
("KIGI_CODE_BASE_URL".into(), self.url()),
("KIGI_API_BASE_URL".into(), self.url()),
// Hermeticity: bundled open-platform (moonshot) model entries
// carry real platform base URLs; the documented dev/test override
// pins them to the mock so no PTY test can reach a live endpoint.
("KIGI_MOONSHOT_CN_BASE_URL".into(), self.url()),
("KIGI_MOONSHOT_AI_BASE_URL".into(), self.url()),
("XAI_API_KEY".into(), "test-key-for-ci".into()),
("KIGI_TELEMETRY_ENABLED".into(), "false".into()),
("KIGI_FEEDBACK_ENABLED".into(), "false".into()),
@@ -210,7 +215,7 @@ mod tests {
/// The pre-delegation mock always served 200 `{"allow_access": true}`;
/// the shared server defaults to 404-until-set. A 404 strands the pager
/// on the SuperGrok upsell screen and breaks every PTY test.
/// on the subscription upsell screen and breaks every PTY test.
#[tokio::test]
async fn settings_endpoint_allows_access_by_default() {
let content = ContentController::start().await.unwrap();
@@ -280,12 +285,14 @@ mod tests {
);
assert_eq!(get("KIGI_CODE_BASE_URL"), Some(content.url()));
assert_eq!(get("KIGI_API_BASE_URL"), Some(content.url()));
assert_eq!(get("KIGI_MOONSHOT_CN_BASE_URL"), Some(content.url()));
assert_eq!(get("KIGI_MOONSHOT_AI_BASE_URL"), Some(content.url()));
assert_eq!(get("XAI_API_KEY").as_deref(), Some("test-key-for-ci"));
assert_eq!(get("KIGI_TELEMETRY_ENABLED").as_deref(), Some("false"));
assert_eq!(get("KIGI_FEEDBACK_ENABLED").as_deref(), Some("false"));
assert_eq!(get("KIGI_TRACE_UPLOAD").as_deref(), Some("false"));
assert_eq!(get("KIGI_PROMPT_SUGGESTIONS").as_deref(), Some("false"));
assert_eq!(get("KIGI_MAX_RETRIES").as_deref(), Some("0"));
assert_eq!(env.len(), 10, "env list must not silently grow or shrink");
assert_eq!(env.len(), 12, "env list must not silently grow or shrink");
}
}
@@ -26,28 +26,28 @@ fn target_dir() -> Result<PathBuf> {
fn local_pager_binary_path() -> Result<PathBuf> {
Ok(target_dir()?
.join("debug")
.join(format!("kigi-tui{}", std::env::consts::EXE_SUFFIX)))
.join(format!("kigi{}", std::env::consts::EXE_SUFFIX)))
}
fn ensure_local_pager_binary(binary: &std::path::Path) -> Result<()> {
if binary.exists() {
return Ok(());
}
// Always invoke cargo: an existing binary may be stale relative to the
// sources under test (an early-return here once let PTY tests silently
// exercise an outdated build). Cargo itself makes this a fast no-op
// when the binary is already fresh.
let cargo = std::env::var("CARGO").unwrap_or_else(|_| "cargo".to_owned());
let mut cmd = Command::new(&cargo);
cmd.current_dir(workspace_root()?)
.args(["build", "-p", "kigi-bin", "--bin", "kigi-tui"])
.args(["build", "-p", "kigi-bin", "--bin", "kigi"])
.stdin(Stdio::null())
.envs(kigi_tty_utils::pager_env());
kigi_tty_utils::detach_std_command(&mut cmd);
let output = cmd
.output()
.with_context(|| format!("failed to spawn {cargo} to build kigi-tui"))?;
.with_context(|| format!("failed to spawn {cargo} to build the kigi binary"))?;
if !output.status.success() {
bail!(
"failed to build kigi-tui (exit {:?})\nstdout:\n{}\nstderr:\n{}",
"failed to build the kigi binary (exit {:?})\nstdout:\n{}\nstderr:\n{}",
output.status.code(),
String::from_utf8_lossy(&output.stdout),
String::from_utf8_lossy(&output.stderr),
@@ -55,7 +55,7 @@ fn ensure_local_pager_binary(binary: &std::path::Path) -> Result<()> {
}
if !binary.exists() {
bail!(
"kigi-tui build completed but binary missing at {}",
"kigi build completed but binary missing at {}",
binary.display()
);
}
@@ -66,9 +66,9 @@ fn ensure_local_pager_binary(binary: &std::path::Path) -> Result<()> {
///
/// Resolution order:
/// 1. `PAGER_BINARY` env var (for CI / explicit override)
/// 2. `CARGO_BIN_EXE_kigi-tui` (set by `cargo test`)
/// 2. `CARGO_BIN_EXE_kigi` (set by `cargo test`)
/// 3. Build locally via `cargo build -p kigi-bin` (the composition-
/// root package that owns the `kigi-tui` binary)
/// root package that owns the `kigi` binary)
pub fn pager_binary() -> Result<PathBuf> {
if let Ok(path) = std::env::var("PAGER_BINARY") {
let p = PathBuf::from(path);
@@ -81,7 +81,7 @@ pub fn pager_binary() -> Result<PathBuf> {
.with_context(|| format!("failed to absolutize PAGER_BINARY: {}", p.display()));
}
if let Ok(path) = std::env::var("CARGO_BIN_EXE_kigi-tui") {
if let Ok(path) = std::env::var("CARGO_BIN_EXE_kigi") {
let p = PathBuf::from(path);
if p.exists() {
return Ok(p);
@@ -67,12 +67,13 @@ pub fn inference_request_count(content: &ContentController) -> usize {
.count()
}
/// Seed a fake xAI OAuth entry into the isolated home's `auth.json` so the
/// shell has session auth (the harness's `XAI_API_KEY` is ApiKey/BYOK mode
/// and never enters the auth manager). Load-bearing details: the scope key
/// must be `<issuer>::<client_id>`, `auth_mode` must be `oidc`, and
/// `expires_at` must be far-future so no network refresh is attempted; the
/// mock server accepts any bearer. Pair with [`oauth_env_for_pager`].
/// Seed a fake Kimi Code OAuth entry into the isolated home's `auth.json` so
/// the shell has session auth (the harness's `XAI_API_KEY` is ApiKey/BYOK mode
/// and never enters the auth manager). Load-bearing details: the map key must
/// be the Kimi Code scope key (`oauth/kimi-code`), `auth_mode` must be
/// `oauth`, and `expires_at` must be far-future so no network refresh is
/// attempted; the mock server accepts any bearer. Pair with
/// [`oauth_env_for_pager`].
pub fn seed_fake_oauth(content: &ContentController, user: &str) {
let kigi_home = content.home().join(".kigi");
std::fs::create_dir_all(&kigi_home).expect("create temp .kigi");
@@ -80,16 +81,14 @@ pub fn seed_fake_oauth(content: &ContentController, user: &str) {
kigi_home.join("auth.json"),
format!(
r#"{{
"https://auth.x.ai::b1a00492-073a-47ea-816f-4c329264a828": {{
"oauth/kimi-code": {{
"key": "pty-test-oauth-token",
"auth_mode": "oauth",
"create_time": "2026-01-01T00:00:00Z",
"user_id": "{user}",
"email": "{user}@test.invalid",
"expires_at": "2030-01-01T00:00:00Z",
"refresh_token": "pty-test-refresh-token",
"oidc_issuer": "https://auth.x.ai",
"oidc_client_id": "b1a00492-073a-47ea-816f-4c329264a828"
"refresh_token": "pty-test-refresh-token"
}}
}}"#
),
@@ -38,7 +38,7 @@ impl LeaderCluster {
// One shared KIGI_SHARE_DIR => one leader; the socket lives beneath it so
// every client (sharing the same env) elects/attaches to the same one.
let kigi_home = content.home().join(".kigi");
std::fs::create_dir_all(&kigi_home).context("create grok home")?;
std::fs::create_dir_all(&kigi_home).context("create kigi home")?;
let socket = kigi_home.join("leader-e2e.sock");
let binary = pager_binary().context("resolve pager binary")?;
Ok(Self {
@@ -194,14 +194,14 @@ mod tests {
/// Wrap a session update as the envelope stored in `updates.jsonl`.
fn envelope(update_json: &str) -> String {
format!(
r#"{{"timestamp":1,"method":"_x.ai/session/update","params":{{"sessionId":"s","update":{update_json}}}}}"#
r#"{{"timestamp":1,"method":"_kigi/session/update","params":{{"sessionId":"s","update":{update_json}}}}}"#
)
}
#[test]
fn parse_update_payloads_unwraps_and_tolerates_torn_trailing_line() {
let body = format!(
"{}\n{}\n{{\"timestamp\":2,\"method\":\"_x.ai/sess",
"{}\n{}\n{{\"timestamp\":2,\"method\":\"_kigi/sess",
envelope(
r#"{"sessionUpdate":"agent_message_chunk","content":{"type":"text","text":"hi"}}"#
),
@@ -256,12 +256,12 @@ impl PtyHarness {
}
/// Feed bytes **directly into the virtual screen only**, bypassing the
/// child (grok).
/// child (kigi).
///
/// Simulates an out-of-band repaint/reflow by an outer layer (tmux, or an
/// nvim/vim `:terminal`) that changes what's on screen without going
/// through grok's stdout. Used to reproduce the doubled-line class of bugs
/// where grok's diff renderer never re-asserts a region it didn't write
/// through kigi's stdout. Used to reproduce the doubled-line class of bugs
/// where kigi's diff renderer never re-asserts a region it didn't write
/// itself (since the harness is a single faithful emulator and cannot nest
/// a real tmux/nvim).
pub fn feed_screen(&mut self, bytes: &[u8]) {
@@ -2,7 +2,7 @@
//!
//! When `exit_plan_mode` is parked and the user quits, the shell persists
//! `awaiting_plan_approval = true` in `plan_mode.json`. On `--continue` the
//! shell re-issues the `x.ai/exit_plan_mode` reverse-request — a real live ACP
//! shell re-issues the `kigi/exit_plan_mode` reverse-request — a real live ACP
//! waiter — so the pager re-shows approval chrome through its normal path with
//! no pager-side disk logic. Approving then leaves plan mode and starts the
//! implement turn.