§9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed
The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok' crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party license archives, README provenance, and the required 'Based on Grok Build Open Source' attribution, now sourced from version_attribution.txt). Wire-visible renames (both sides in this repo, changed in lockstep): - Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode). - Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* / _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps a read-side alias for the legacy '_x.ai/session/update' method so existing updates.jsonl histories load; writes emit only the new name (both directions test-pinned). - Agent types grok-build* → kigi* with a documented legacy-prefix alias at resolution time so persisted sessions keep resolving. - ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build implementation dirs renamed to kigi*. - x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes grokday/groknight → kigiday/kiginight (old persisted values fall back to the default theme), web_fetch allowlist xAI hosts → kimi.com + moonshot platforms, changelog CDN → this repo, grok-build changelog archives deleted. - BYOK default endpoint removed: [endpoints] api_base_url is now truly optional with NO default — consumers fail fast with the flag name when unset (no silent x.ai egress). Mock harnesses inject it explicitly. - System-prompt identity fixed: 'released by xAI' → 'an unofficial community CLI for Kimi' (template + regenerated encrypted form). Also repaired pre-existing grok-era test debt found by the sweep: the stale trace_classify default-model pin, the grok-pager UA label test, pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY test could previously reach the real api.moonshot.cn), and the outdated oauth fixture scope key. Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings); FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed; deny advisories ok.
This commit is contained in:
@@ -3,7 +3,7 @@ license = "Apache-2.0"
|
||||
edition.workspace = true
|
||||
name = "kigi-secrets"
|
||||
version.workspace = true
|
||||
description = "Regex sanitizer for Grok Build outbound data (Sentry / Mixpanel / product-event scrubbing)"
|
||||
description = "Regex sanitizer for Kigi outbound data (Sentry / Mixpanel / product-event scrubbing)"
|
||||
|
||||
[dependencies]
|
||||
regex = { workspace = true }
|
||||
|
||||
@@ -336,7 +336,7 @@ mod tests {
|
||||
redact_secrets("just a normal log line"),
|
||||
Cow::Borrowed(_)
|
||||
));
|
||||
assert!(matches!(redact_secrets("model=grok-3"), Cow::Borrowed(_)));
|
||||
assert!(matches!(redact_secrets("model=kigi-3"), Cow::Borrowed(_)));
|
||||
}
|
||||
|
||||
/// Joins fixture fragments at runtime so realistic-looking fake tokens
|
||||
@@ -461,14 +461,14 @@ mod tests {
|
||||
|
||||
#[test]
|
||||
fn redacts_sensitive_url_query_params() {
|
||||
let out = redact_secrets("callback https://x.ai/cb?code=ABC123XYZ&state=xyz789 failed");
|
||||
let out = redact_secrets("callback https://kimi.com/cb?code=ABC123XYZ&state=xyz789 failed");
|
||||
assert!(!out.contains("ABC123XYZ"), "OAuth code leaked: {out}");
|
||||
assert!(!out.contains("xyz789"), "state leaked: {out}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn url_regex_excludes_trailing_punctuation() {
|
||||
let out = redact_secrets("see `https://x.ai/cb?code=ABCD12345`");
|
||||
let out = redact_secrets("see `https://kimi.com/cb?code=ABCD12345`");
|
||||
assert!(out.ends_with('`'), "trailing backtick lost: {out}");
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user