M2 audit: excise the Computer Hub stack — Kigi's last remote-cloud surface

Removed root-and-branch for the zero-egress guarantee (the hub was xAI's
remote-workspace/cloud-sandbox service):

- Crates deleted: kigi-computer-hub-core, kigi-computer-hub-sdk,
  kigi-computer-hub-mcp-adapter, kigi-workspace-client (hub-proxied
  workspace RPC client), and kigi-tracing (its sole network path was the
  OTLP gRPC exporter; zero consumers remained). kigi-tracing-macros
  (purely local) stays.
- kigi-workspace: every hub surface deleted — hub server/channel/auth,
  HITL-over-hub permissions, donation/metrics pumps, file upload RPCs,
  hub tool-snapshot merge (resolve pipeline is MCP-only now),
  WorkspaceOps::Proxy. Local worktrees, sessions, leader IPC, MCP, and
  the ACP permission prompt path are untouched; LocalRegistry re-homed
  into kigi-tool-runtime on the existing ToolDyn types so in-process
  tool dispatch is unchanged.
- kigi-shell: leader workspace-exposure control surface (incl. the
  wss://computer-hub... URL), [hub] config, ObservabilityBridge, hub
  WebSocket proxy, dead OTLP config knobs. ClientMode::Headless (never
  constructed) removed.
- kigi-tui/bin: hidden `kigi workspace` command removed (`kigi
  worktree` stays).
- Renames: --xai-api-base-url → --api-base-url / KIGI_API_BASE_URL /
  [endpoints] api_base_url (serde alias keeps old configs working; the
  flag feeds BYOK/custom-endpoint routing, not main inference);
  grok_version → kigi_version in inspect/models-cache/trace metadata
  (old caches self-heal via version-mismatch refetch).
- Dependency tree: dropped fastrace*, opentelemetry-otlp/http/proto,
  tokio-tungstenite from the workspace; fixed the 4 real useless_format
  violations the fastrace lint allowance was masking and removed the
  allowance.
- marketplaceAllowlist kept: it gates the LOCAL plugin-marketplace
  feature, not an xAI service.

Known §9 leftover (deliberate, for the M3 sweep): the BYOK default base
URL string. Gates: workspace check/clippy 0/0, fmt, deny ok; suites
green (workspace 1042, shell 4918, tui 6634, tools 2608, tool-runtime
47, mcp 154).
This commit is contained in:
2026-07-17 22:34:10 -04:00
parent 5919526e91
commit fa75eb139a
90 changed files with 452 additions and 9702 deletions
+1 -36
View File
@@ -8,9 +8,6 @@ description = "Core host-local workspace library (FS, VCS, execution, discovery)
[dependencies]
anyhow = { workspace = true }
arc-swap = { workspace = true }
# Diagnostics HTTP server (in-guest readiness/status endpoint); pinned to the
# workspace version already used by the sibling preview proxy.
axum = { workspace = true }
dunce = { workspace = true }
kigi-version = { workspace = true }
async-stream = { workspace = true }
@@ -41,7 +38,6 @@ uuid = { workspace = true, features = ["v4", "v5", "v7"] }
kigi-agent = { path = "../kigi-agent" }
kigi-tools = { path = "../kigi-tools" }
kigi-tools-api = { path = "../kigi-tools-api" }
kigi-workspace-client = { path = "../kigi-workspace-client" }
kigi-workspace-types = { path = "../kigi-workspace-types" }
kigi-config = { workspace = true }
# Leaf config value types (RemoteSettings, BoolFlag) for the folder-trust decision.
@@ -73,53 +69,28 @@ glob = "0.3"
kigi-sandbox = { path = "../kigi-sandbox", default-features = false }
kigi-hooks = { path = "../kigi-hooks" }
kigi-hunk-tracker = { path = "../kigi-hunk-tracker" }
# `metrics` enables the SDK's metric-donation client (periodic Prometheus
# registry gather → OTLP → hub donation pump); see metric_donation_reporter.
kigi-computer-hub-sdk = { workspace = true, features = ["metrics"] }
kigi-computer-hub-mcp-adapter = { path = "../../common/kigi-computer-hub-mcp-adapter" }
kigi-mcp = { path = "../kigi-mcp" }
kigi-file-utils = { path = "../kigi-file-utils" }
kigi-auth = { path = "../kigi-auth" }
kigi-log = { workspace = true }
kigi-tty-utils = { workspace = true }
kigi-sqlite-journal = { workspace = true }
reqwest = { workspace = true }
kigi-tool-protocol = { workspace = true }
kigi-tool-runtime = { workspace = true }
kigi-tool-types = { workspace = true }
tokio-util = { workspace = true }
urlencoding = "2"
kigi-fast-worktree = { path = "../kigi-fast-worktree", features = ["metadata"] }
# tonic stays for `tonic::Status`/`Code` mapping in workspace_ops deploy errors.
tonic = { workspace = true }
kigi-fsnotify = { path = "../kigi-fsnotify" }
clap = { workspace = true }
tracing-subscriber = { workspace = true }
# "enable" required for the SDK's spans to record at all.
fastrace = { workspace = true, features = ["enable"] }
kigi-tracing = { workspace = true }
rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] }
tokio-tungstenite = { workspace = true, features = ["rustls-tls-webpki-roots"] }
tempfile = { workspace = true }
zstd = { workspace = true }
# Only referenced by the Unix self-daemonize path (fork/setsid/dup2/chdir).
# Only referenced by the Unix foreign-session capability probe (O_DIRECTORY etc.).
[target.'cfg(unix)'.dependencies]
libc = { workspace = true }
# Only referenced by the Windows self-daemonize path (SetStdHandle).
[target.'cfg(windows)'.dependencies]
windows = { workspace = true }
[[bin]]
name = "kigi-workspace-server"
path = "src/bin/workspace_server.rs"
[[bin]]
name = "workspace-server-probe"
path = "src/bin/workspace_server_probe.rs"
[features]
default = ["sandbox-enforce"]
compression = []
@@ -137,12 +108,6 @@ filetime = { workspace = true }
tempfile = { workspace = true }
tokio = { workspace = true, features = ["test-util"] }
kigi-test-utils = { path = "../../common/kigi-test-utils" }
# Decode tar.gz archives produced by workspace upload helpers in tests.
flate2 = { workspace = true }
tar = { workspace = true }
[package.metadata.cargo-shear]
ignored = ["tokio-tungstenite"]
[lints]
workspace = true