§9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed

The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok'
crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party
license archives, README provenance, and the required 'Based on Grok
Build Open Source' attribution, now sourced from version_attribution.txt).

Wire-visible renames (both sides in this repo, changed in lockstep):
- Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode).
- Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* /
  _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps
  a read-side alias for the legacy '_x.ai/session/update' method so
  existing updates.jsonl histories load; writes emit only the new name
  (both directions test-pinned).
- Agent types grok-build* → kigi* with a documented legacy-prefix alias
  at resolution time so persisted sessions keep resolving.
- ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case
  kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build
  implementation dirs renamed to kigi*.
- x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes
  grokday/groknight → kigiday/kiginight (old persisted values fall back
  to the default theme), web_fetch allowlist xAI hosts → kimi.com +
  moonshot platforms, changelog CDN → this repo, grok-build changelog
  archives deleted.
- BYOK default endpoint removed: [endpoints] api_base_url is now truly
  optional with NO default — consumers fail fast with the flag name when
  unset (no silent x.ai egress). Mock harnesses inject it explicitly.
- System-prompt identity fixed: 'released by xAI' → 'an unofficial
  community CLI for Kimi' (template + regenerated encrypted form).

Also repaired pre-existing grok-era test debt found by the sweep: the
stale trace_classify default-model pin, the grok-pager UA label test,
pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY
test could previously reach the real api.moonshot.cn), and the outdated
oauth fixture scope key.

Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings);
FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed;
deny advisories ok.
This commit is contained in:
2026-07-18 02:48:46 -04:00
parent 86e3724310
commit 6f31415ed6
1056 changed files with 8410 additions and 18307 deletions
@@ -4,7 +4,7 @@
//! `tokio::net::UnixStream` / `UnixListener`. Zero wrapper, no unsafe.
//! - **Windows:** wraps `tokio::net::windows::named_pipe::*` (tokio doesn't
//! expose AF_UNIX on Windows). The leader's filesystem path is hashed
//! into `\\.\pipe\grok-leader-<hash>` so callers keep their path-based API.
//! into `\\.\pipe\kigi-leader-<hash>` so callers keep their path-based API.
//!
#[cfg(unix)]
pub use tokio::net::UnixListener as LeaderListener;
@@ -233,7 +233,7 @@ mod windows_impl {
name
}
/// Deterministic leaf name (`grok-leader-<hash>`) for a filesystem path.
/// Deterministic leaf name (`kigi-leader-<hash>`) for a filesystem path.
///
/// Uses SipHash-1-3 with fixed keys so the hash is stable across Rust
/// versions (unlike `DefaultHasher`, whose algorithm is unspecified).
@@ -245,7 +245,7 @@ mod windows_impl {
let mut hasher = SipHasher13::new_with_keys(0x67726f6b_6c656164, 0x65725f70_69706521);
path.hash(&mut hasher);
let hash = hasher.finish();
std::ffi::OsString::from(format!("grok-leader-{hash:016x}"))
std::ffi::OsString::from(format!("kigi-leader-{hash:016x}"))
}
#[cfg(test)]
@@ -255,8 +255,8 @@ mod windows_impl {
#[test]
fn pipe_name_is_deterministic() {
let a = path_to_pipe_name(Path::new("/tmp/grok.sock"));
let b = path_to_pipe_name(Path::new("/tmp/grok.sock"));
let a = path_to_pipe_name(Path::new("/tmp/kigi.sock"));
let b = path_to_pipe_name(Path::new("/tmp/kigi.sock"));
assert_eq!(a, b);
}
@@ -271,14 +271,14 @@ mod windows_impl {
fn pipe_name_has_correct_prefix() {
let name = path_to_pipe_name(Path::new("/tmp/test.sock"));
let s = name.to_string_lossy();
assert!(s.starts_with(r"\\.\pipe\grok-leader-"), "got: {s}");
assert!(s.starts_with(r"\\.\pipe\kigi-leader-"), "got: {s}");
}
#[test]
fn pipe_name_is_bounded() {
let long_path = "/".to_owned() + &"a".repeat(500);
let name = path_to_pipe_name(Path::new(&long_path));
// \\.\pipe\grok-leader- (20 chars) + 16 hex chars = 36 total
// \\.\pipe\kigi-leader- (20 chars) + 16 hex chars = 36 total
assert!(name.len() <= 256, "pipe name too long: {}", name.len());
}
@@ -287,7 +287,7 @@ mod windows_impl {
// Unique path per process so parallel test binaries don't collide on
// the derived pipe name.
let path =
std::env::temp_dir().join(format!("grok-ready-probe-{}.sock", std::process::id()));
std::env::temp_dir().join(format!("kigi-ready-probe-{}.sock", std::process::id()));
// Nothing bound yet -> ERROR_FILE_NOT_FOUND -> not ready.
assert!(!listener_is_ready(&path));