§9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed

The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok'
crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party
license archives, README provenance, and the required 'Based on Grok
Build Open Source' attribution, now sourced from version_attribution.txt).

Wire-visible renames (both sides in this repo, changed in lockstep):
- Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode).
- Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* /
  _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps
  a read-side alias for the legacy '_x.ai/session/update' method so
  existing updates.jsonl histories load; writes emit only the new name
  (both directions test-pinned).
- Agent types grok-build* → kigi* with a documented legacy-prefix alias
  at resolution time so persisted sessions keep resolving.
- ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case
  kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build
  implementation dirs renamed to kigi*.
- x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes
  grokday/groknight → kigiday/kiginight (old persisted values fall back
  to the default theme), web_fetch allowlist xAI hosts → kimi.com +
  moonshot platforms, changelog CDN → this repo, grok-build changelog
  archives deleted.
- BYOK default endpoint removed: [endpoints] api_base_url is now truly
  optional with NO default — consumers fail fast with the flag name when
  unset (no silent x.ai egress). Mock harnesses inject it explicitly.
- System-prompt identity fixed: 'released by xAI' → 'an unofficial
  community CLI for Kimi' (template + regenerated encrypted form).

Also repaired pre-existing grok-era test debt found by the sweep: the
stale trace_classify default-model pin, the grok-pager UA label test,
pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY
test could previously reach the real api.moonshot.cn), and the outdated
oauth fixture scope key.

Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings);
FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed;
deny advisories ok.
This commit is contained in:
2026-07-18 02:48:46 -04:00
parent 86e3724310
commit 6f31415ed6
1056 changed files with 8410 additions and 18307 deletions
@@ -1,4 +1,4 @@
//! Detects whether grok is running inside an editor's embedded `:terminal`
//! Detects whether kigi is running inside an editor's embedded `:terminal`
//! (Neovim/Vim `:terminal`, Emacs `vterm`).
//!
//! WHY this matters: inside an editor `:terminal` the *immediate* terminal
@@ -13,7 +13,7 @@ use std::collections::HashMap;
use super::env_get;
/// Which embedded editor `:terminal` grok is running inside.
/// Which embedded editor `:terminal` kigi is running inside.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum EmbeddedEditor {
/// Neovim `:terminal` (sets `NVIM`, or legacy `NVIM_LISTEN_ADDRESS`).
@@ -178,7 +178,7 @@ pub fn hyperlink_capabilities(brand: TerminalName) -> HyperlinkCapabilities {
native_plain_url_open: false,
},
// Electron app; behavior undocumented.
TerminalName::GrokDesktop => HyperlinkCapabilities {
TerminalName::KigiDesktop => HyperlinkCapabilities {
osc8: Unknown,
id_param: false,
scheme_filter: SchemeFilter::Standard,
@@ -54,7 +54,7 @@ static GRAPHICS_PROTOCOL: OnceLock<GraphicsProtocol> = OnceLock::new();
/// When set, scrollback inline-media overlays are forced **off** process-wide,
/// regardless of the terminal's graphics capability. The scrollback-native
/// minimal mode (`grok --minimal`) sets this once at startup: it never runs the
/// minimal mode (`kigi --minimal`) sets this once at startup: it never runs the
/// interactive draw loop that paints inline images, so committed media blocks
/// must always fall back to the `[Open …]` text affordance — and must not
/// reserve blank image rows. See [`set_inline_overlay_force_off`].
@@ -281,8 +281,8 @@ fn convert_via_sips(image_data: &[u8]) -> Option<Vec<u8>> {
.duration_since(std::time::UNIX_EPOCH)
.unwrap_or_default()
.as_nanos();
let src = tmp_dir.join(format!("grok-sips-{id}-{ts}.dat"));
let dst = tmp_dir.join(format!("grok-sips-{id}-{ts}.png"));
let src = tmp_dir.join(format!("kigi-sips-{id}-{ts}.dat"));
let dst = tmp_dir.join(format!("kigi-sips-{id}-{ts}.png"));
// Write source bytes to temp file.
let mut f = std::fs::File::create(&src).ok()?;
@@ -117,7 +117,7 @@ fn macos_capabilities(brand: TerminalName) -> KeyboardCapabilities {
// Apple Terminal: Cmd+Bsp captured by the window manager.
// Opt+Bsp and modified Enter are dropped; CG can rescue both.
TerminalName::AppleTerminal => (Unrecoverable, Dropped, Dropped),
TerminalName::GrokDesktop => (Unknown, Unknown, Unknown),
TerminalName::KigiDesktop => (Unknown, Unknown, Unknown),
// VTE-based terminals (incl. Terminator) on macOS are unusual;
// classify when we have evidence rather than guessing.
TerminalName::Vte | TerminalName::Terminator => (Unknown, Unknown, Unknown),
@@ -201,7 +201,7 @@ mod tests {
fn unknown_brands_skip_rescue() {
for brand in [
TerminalName::Unknown,
TerminalName::GrokDesktop,
TerminalName::KigiDesktop,
TerminalName::Vte,
TerminalName::JetBrains,
] {
@@ -129,9 +129,9 @@ pub enum TerminalName {
/// indistinguishable. All capabilities are conservative/Unknown.
#[strum(to_string = "JetBrains")]
JetBrains,
/// Grok Desktop (Electron app).
#[strum(to_string = "Grok Desktop")]
GrokDesktop,
/// Kigi Desktop (Electron app).
#[strum(to_string = "Kigi Desktop")]
KigiDesktop,
/// VTE-based terminal (GNOME Terminal, kgx/GNOME Console, Tilix, etc.).
#[strum(to_string = "VTE")]
Vte,
@@ -276,7 +276,7 @@ pub struct TerminalContext {
pub multiplexer: MultiplexerKind,
/// Whether Byobu is wrapping the session, and which backend it uses.
pub byobu: Option<ByobuBackend>,
/// Which embedded editor `:terminal` grok is running inside, if any.
/// Which embedded editor `:terminal` kigi is running inside, if any.
pub embedded_editor: Option<EmbeddedEditor>,
/// tmux client metadata (populated only when `multiplexer == Tmux`).
pub tmux_meta: TmuxClientMeta,
@@ -323,7 +323,7 @@ impl TerminalContext {
/// Whether an outer layer (embedded-editor :terminal or multiplexer) can
/// repaint our pane out of band, stranding rows until a full clear. A heal
/// keyed off this only fires when a FocusGained actually reaches grok, which
/// keyed off this only fires when a FocusGained actually reaches kigi, which
/// needs focus reporting enabled upstream (e.g. tmux `focus-events on`, off
/// by default).
pub fn repaints_pane_out_of_band(&self) -> bool {
@@ -645,7 +645,7 @@ fn detect_terminal_context() -> TerminalContext {
// per-pane vars don't survive) and over SSH (not forwarded), except
// brands with SSH-surviving markers (the VS Code family, and iTerm2
// via LC_TERMINAL). tmux -g global env is stale (reflects the server's
// first client, not the current one). Revisit when `grok ssh` can
// first client, not the current one). Revisit when `kigi ssh` can
// forward env vars.
let mut ctx = build_terminal_context_from_env(&env);
ctx.brand = refine_unknown_brand_for_host(ctx.brand, HostOs::current());
@@ -980,7 +980,7 @@ fn terminal_name_from_term_program(value: &str) -> Option<TerminalName> {
"rio" => Some(TerminalName::Rio),
"terminator" => Some(TerminalName::Terminator),
"zed" => Some(TerminalName::Zed),
"grokdesktop" => Some(TerminalName::GrokDesktop),
"kigidesktop" => Some(TerminalName::KigiDesktop),
"windowsterminal" => Some(TerminalName::WindowsTerminal),
"otty" => Some(TerminalName::Otty),
_ => None,