Skip to content

Investigate and fix the grokrouter repo so it supports version 0.61.0 (… - #4

Merged
SomeRandmGuyy merged 11 commits into
mainfrom
feat/grokbot-0.61-maintained-fork
Sep 29, 2026
Merged

SomeRandmGuyy merged 11 commits into
mainfrom
feat/grokbot-0.61-maintained-fork

Conversation

@SomeRandmGuyy

@SomeRandmGuyy SomeRandmGuyy commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The branch implements a version-gate change (exact reviewed versions plus an opt-in 'unreviewed newer version' path referencing 0.61.0), restores/extends the macOS and Windows (native PowerShell + .cmd) installers, adds live model/family discovery in runtime/model-catalog.mjs and runtime/openrouter-catalog.mjs, adds signed compatibility registry tooling, CI workflows (including a Windows install round-trip test and CodeQL), and a substantial documentation rewrite (README, MAINTENANCE-STATUS.md, VERSION-TRACKING.md, TEST-MATRIX.md) declaring this repo the maintained fork with inline install commands. Test files were extensively expanded (compatibility, model-catalog, runtime, installer, windows-installer, release) suggesting verification was built alongside the feature work.

Linked issues

Fixes SPE-4548 — [n1] Understand repo structure and version-gate mechanism
https://linear.app/swcstudio/issue/SPE-4548/n1-understand-repo-structure-and-version-gate-mechanism

Fixes SPE-4550 — [n5] Design cross-platform installer and model auto-discovery flow
https://linear.app/swcstudio/issue/SPE-4550/n5-design-cross-platform-installer-and-model-auto-discovery-flow

Fixes SPE-4549 — [n3] Root-cause the 0.33/0.44-only restriction
https://linear.app/swcstudio/issue/SPE-4549/n3-root-cause-the-033044-only-restriction

Fixes SPE-4551 — [n2] Git-archaeology on the 'Muse' installer revert
https://linear.app/swcstudio/issue/SPE-4551/n2-git-archaeology-on-the-muse-installer-revert

Fixes SPE-4552 — [n4] Design version-gate fix and compatibility strategy
https://linear.app/swcstudio/issue/SPE-4552/n4-design-version-gate-fix-and-compatibility-strategy

Fixes SPE-4553 — [n6] Identify missing/ambiguous information requiring user clarification
https://linear.app/swcstudio/issue/SPE-4553/n6-identify-missingambiguous-information-requiring-user-clarification

Fixes SPE-4554 — [n7] Plan documentation rewrite for self-contained install instructions
https://linear.app/swcstudio/issue/SPE-4554/n7-plan-documentation-rewrite-for-self-contained-install-instructions

Fixes SPE-4555 — [n8] Ordered execution plan in file-disjoint waves
https://linear.app/swcstudio/issue/SPE-4555/n8-ordered-execution-plan-in-file-disjoint-waves

Notion task: https://app.notion.com/p/3eabc1a0c7ae815d8accfc57992e5412?pvs=204

Assessment

  • Done: yes
  • Confidence: 0.68
  • Judge (advisory): done yes, confidence 0.68
  • Judge notes:
    • 0.61.0 is only supported via an opt-in 'unreviewed version' structural-trust path rather than a fully reviewed manifest, which is a reasonable maintainer trade-off per the clarifications but means 0.61.0 is not first-class reviewed support — worth confirming this matches user expectations.
    • Native Windows install verification only occurs in CI (not locally in this Linux sandbox), consistent with stated environment limits and not counted against completion.
    • Patch is truncated so some later files (docs/MODELS-equivalent content, full README diff) could not be fully inspected, though the diff stat and commit log strongly indicate broad completion across all workflow waves.

ultrathink graph ut-mumj0sn7-6137eec4


Note

High Risk
Changes host-trust, signed compatibility registries, and install/upgrade paths that patch Grok Bot cloud hosts; mistakes could weaken version gates or break installs, though the design stays fail-closed with expanded automated tests.

Overview
This PR retargets GrokRouter to the maintained swcstudiospace/grokrouter fork and ships the 0.1.0-beta.48 candidate: upstream beta.47 exact-host trust is merged with fork-specific providers, 0.44.0 manifests/registries, and install commands pinned to the new repo/tag.

Version and trust gates change materially. Reviewed Grok Bot builds are listed in compatibility/supported-apps.json with per-version signed *-hosts.json and a new Ed25519 registry key (upstream signatures dropped). Both installers add a default-off Allow unreviewed Grok Bot version (experimental) path for versions strictly newer than every reviewed release—structural anchor/seam checks only, HOSTTRUST=UNREVIEWED-ANCHOR-VERIFIED, no signed registry. Probe-ingest and version-watch workflows now scaffold unsigned registries and require local maintainer signing before merge.

Windows and release automation expand. New scripts/install-windows.ps1 and Install GrokRouter.cmd, README PowerShell one-liner, and CI that parses the script and installs twice (idempotency, pruning, refusal to replace non-GrokRouter dirs). Mac/Windows CI gains verify-release.mjs, CodeQL, and tag-release now runs full CI plus acceptance verification before tagging.

Runtime and docs: live model catalog discovery (including Codex CLI), family aliases, installer model fields; README and agent docs rewritten for self-contained install/troubleshooting; installation issue template collects Grok Bot version and install source separately.

Reviewed by Cursor Bugbot for commit cb70ccb. Bugbot is set up for automated code reviews on this repo. Configure here.

Verification

  • Automated, on this branch: runtime 103/103, patch 45/45, Windows installer 17/17, release and compatibility 8/8. The full tests/installer.test.sh passed end to end without two host-dependent blocks: the PREF123 check needs /usr/bin without node, and the other block needs macOS swiftc. swiftc -parse passes, the payload builds, verify-release agrees on beta.48, and actionlint is clean.
  • install-windows.ps1 passed a parse check with pwsh 7.6. On Linux pwsh its failure paths all end correctly: -File exits 1, -Command "…| iex" exits 1, and an interactive iex session survives. Windows CI now runs it twice and checks that it never replaces or prunes a folder that isn't GrokRouter.
  • Codex discovery parsing was checked against the real Codex CLI 0.151.0 codex debug models --bundled. anthropic/claude-sonnet-5.5 and claude-opus-5.5 were confirmed in the live OpenRouter catalog.
  • An independent review of trust gating, injection and upgrade authentication found nothing. Its two Windows-installer findings are fixed.

Not verified live (gates before tagging source-v0.1.0-beta.48)

  • No fresh-Bot acceptance on any version for beta.48. verify-acceptance correctly refuses to tag.
  • 0.44.0: beta.47's three patch seams are unproven on a live 0.44.0 host.
  • 0.61.0: no reviewed probe exists. Only the experimental opt-in is available, and no live 0.61.0 install has run.
  • Windows: no native install run yet; the CI smoke test runs on this PR.

RetriggerConfidence Score: 5/5

No outstanding finding or new issue in the post-review change prevents merging.

Summary

The PR adds experimental, opt-in handling for newer Grok Bot versions, cross-platform source installers, model discovery, signed compatibility data, and release checks.

  • The change since the previous review clears the Windows CI step’s exit code after its expected installer refusal.
  • Greptile automatically discovered a related ticket that helped explain the purpose of this PR: provide cross-platform installation and model discovery. The ticket describes intended behavior, not evidence of live acceptance.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Windows CI smoke test] --> B[Install twice]
  B --> C[Check installed app and backup]
  C --> D[Attempt install into occupied non-GrokRouter folder]
  D --> E[Check refusal and preserved user file]
  E --> F[Clear expected nonzero exit code]
Loading

Reviews (5) · Last reviewed commit: "Keep the expected installer refusal from..."

promptadvisers and others added 7 commits September 9, 2026 07:05
…ies [tag-release]

* Harden host recovery and gate releases on verified acceptance

* Add exact 0.36 host selection and bind live gates to each desktop version

* Intercept the expanded native skill invocation before inference

* Record verified maintenance work and pending live release gates

* Recognize brokered message delivery and remove fabricated launch recovery

* Preserve Bot state and audit history when replacing the runtime

* Make Doctor exit status reflect real runtime and adapter health

* Return child results through the host response stream

* Give native workflow registration enough time to load and reconcile

* Recover empty Codex replies once without replaying completed work

* Recover failed deliveries and preserve parent versus child completion

* Register native commands before restarting the Grok host

* Revive native child completions by durable host request ID

* Preserve native child dispatch identity through hidden completion formatting

* Document native completion identity and verified installation order

* Normalize native completion envelopes before durable request recognition

* Record real Codex and OpenRouter returned-child verification

* Show current reasoning effort from the native status command

* Prevent Codex automatic greetings from dispatching outer tools

* Route native group controls from durable human message metadata

* Recognize the native first-run greeting behind host procedure context

* Preserve prerequisite tools when a task specifies exact final output

* Defer parent delivery until a running child actually completes

* Read background launch state from the structured native result

* Recognize the native Task broker canonical launch receipt

* Match verified native Task receipt paragraph spacing

* Acknowledge verified background launches once while deferring results

* Isolate native memory extraction from chat tools and conversation state

* Preserve native maintenance sessions outside the chat adapter

* Normalize verified literal delivery envelopes without executing tools

* Decode exact literal replies inside verified broker delivery envelopes

* Isolate periodic episode summaries from routed chat state and tools

* Record exact-artifact live acceptance on official Grok Bot 0.36.0

* Record final acceptance on both supported Grok Bot versions
Upstream promptadvisers/grokrouter beta.47 diverged from this fork at
c8eea82 (beta.46). This merge takes all of it and keeps every fork feature.

Taken from upstream:
- Grok Bot 0.36.0 manifest, signed 0.36.0 host registry and
  compatibility/supported-apps.json (exact desktop-version binding).
- Exact reviewed stock-host trust only. The structural "anchor-verified"
  tier is disabled because anchors alone do not prove stock provenance.
- Previous-adapter reconstruction (patch/previous_adapter.py), hardened
  host recovery, and child-completion, broker-delivery, memory/episode
  isolation and Doctor fixes.
- Release/acceptance verification scripts, CodeQL, and acceptance docs.
- Stock hash 3364e421... moves to the 0.36.0 manifest (live-accepted there).

Kept from the fork:
- Anthropic (Claude Agent SDK) and xAI OAuth providers, the full OpenRouter
  catalog, live per-provider model discovery and failure diagnostics.
- The 0.44.0 manifest and hash/anchor manifest selection, used when no
  desktop version is recorded.
- Version-tracking pipeline (version-watch, probe-ingest, host/auto probe).

README.md takes upstream's text; the docs rewrite follows. TEST-MATRIX and
RELEASE_NOTES keep beta.47's gate and list the fork's claims separately.
Adopting 0.44.0 into beta.47's per-version gates follows in the next commit.

Refs SPE-4551
…d newer version

- 0.44.0 joins beta.47's exact per-version gates: supported-apps.json,
  anchorVerifiedHosts disabled, and a signed 0.44.0 host registry.
- The fork signs host registries with its own Ed25519 key. All three
  registries are re-signed, and refresh downloads from swcstudiospace.
- A Grok Bot strictly newer than every reviewed version (0.61.0 today) can
  be installed only through an unchecked-by-default installer checkbox.
  The Bot side then accepts the host by structural verification (no router
  marker, every anchor including beta.47's three patch seams exactly once,
  a node --check dry run, and the template size band). It reports
  HOSTTRUST=UNREVIEWED-ANCHOR-VERIFIED, and restore/repair/doctor honour
  the mode. Reviewed, older and in-between versions never receive
  structural trust.
- Probes, scaffolding and diagnostics count the three patch seams.
  new-manifest-from-probe writes the beta.47 layout plus an unsigned
  registry for local signing.
- Upgrades authenticate the upstream beta.45/46/47 and fork 7190a9e
  adapters by byte-exact reconstruction from patch/previous/.
- Installer model fields are editable, with strict per-provider ID
  validation in both installers and install.sh. Suggestions include
  anthropic/claude-sonnet-5.5 and anthropic/claude-opus-5.5.
- The installer status test no longer pipes into grep -q under pipefail,
  which killed the writer with SIGPIPE.

Refs SPE-4552
Refs SPE-4550
…odel

- Codex lists models from the pinned CLI's `codex debug models`: account
  refresh first, then the bundled catalog, then cache, then the packaged
  list. It runs through execFile with a timeout and bounded output.
- /model sonnet|opus|haiku|fable|sol|terra|luna|astra|grok picks the
  newest matching model in the cached catalog, so Sonnet 5.5 and Opus 5.5
  appear without a release. When the catalog has no match it falls back to
  the pinned alias.
- Every remote model ID is validated before it is stored, listed or used.
  /models and /router doctor show where the catalog came from and how old
  it is.
- The packaged fallback adds the live-verified OpenRouter
  claude-sonnet-5.5, claude-opus-5.5 and grok-4.7, plus the Codex CLI's
  bundled gpt-5.5 and gpt-5.2.

Refs SPE-4550
- The macOS source installer downloads swcstudiospace/grokrouter at
  source-v0.1.0-beta.48.
- New native Windows source installer (scripts/install-windows.ps1, with
  Install GrokRouter.cmd for ZIP/clone users). It checks for Node.js 22.12+
  and Git for Windows and prints the winget commands instead of installing
  anything. It builds locally and installs per-user. It keeps one previous
  install, and it refuses to replace a folder that is not a GrokRouter
  install.
- verify-release and tag-release require both installers and both README
  commands to pin the same tag in this repository. Tagging still requires
  the live acceptance record.
- Windows CI parse-checks the installer and runs it twice to prove it is
  idempotent and never touches unrelated folders.
- Versions bumped to 0.1.0-beta.48.

Refs SPE-4550
Refs SPE-4554
…ne installs

The README gives the Mac and Windows install commands inline from
swcstudiospace/grokrouter, with from-clone alternatives until the beta.48
tag exists. It adds a per-version compatibility table, the unreviewed-
version opt-in and its risk, and how new models appear. AGENTS.md,
VERSION-TRACKING, ARCHITECTURE, HOW-IT-WORKS, RELEASE, FRESH-BOT-ACCEPTANCE,
TEST-MATRIX (fork claims), MAINTENANCE-STATUS and RELEASE_NOTES are updated
to match. Dated beta.47 evidence files are unchanged.

Refs SPE-4554
@cursor

cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_946af4fe-230f-4687-bf48-a751186efa0d)

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread runtime/run-provider.mjs Outdated
Comment thread scripts/install-windows.ps1
Comment thread runtime/model-catalog.mjs
- Native memory-extraction and episode-summary tasks run on the Bot's own
  provider through runProvider. Before this, Anthropic and xAI Bots fell
  through to Codex with a non-Codex model ID. On Anthropic they run with no
  Claude Code tools, one turn and no session resume. The native-task test
  now asserts each transport serves its own provider.
- install-windows.ps1 removes the staging copy and restores the previous
  install on any failed step, including a failed move of the old install.
- grokbot-router and its watchdog read patch arguments with a read loop
  instead of bash 4's mapfile. The installer suite also runs these under
  macOS bash 3.2, where mapfile exits 127.

Refs SPE-4550
@cursor

cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_63e21e76-eaa0-45f6-a183-0af445832212)

Comment thread scripts/install-windows.ps1
Serialize Windows source installs per folder with an exclusive, delete-on-close lock file taken before the build and released in finally. A concurrent run fails fast instead of sharing or removing another run's staging copy or backup.

Refs SPE-4550
@cursor

cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_93afa97e-1c30-4a52-a68c-72c5a69475eb)

Comment thread scripts/install-windows.ps1 Outdated
greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 29, 2026
The Windows install lock reports 'already running' only for a real sharing violation (32/33 on Windows, EAGAIN under .NET on Unix). Any other failure, such as a permission error, now names the folder and the underlying reason.

Refs SPE-4550
@greptile-apps
greptile-apps Bot dismissed their stale review September 29, 2026 14:04

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@cursor

cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_056f6335-5f02-4a4b-b59e-c8c478f4cf2a)

greptile-apps[bot]
greptile-apps Bot previously approved these changes Sep 29, 2026
GitHub's powershell wrapper exits with $LASTEXITCODE, which the deliberately refused install into a non-GrokRouter folder left at 1. Both real install passes and the refusal itself already succeeded on windows-2025.

Refs SPE-4550
@greptile-apps
greptile-apps Bot dismissed their stale review September 29, 2026 14:16

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@cursor

cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_4f467352-e765-4c7b-b49e-e4dee0ca3a03)

@SomeRandmGuyy
SomeRandmGuyy merged commit 9ce7e87 into main Sep 29, 2026
9 checks passed
@SomeRandmGuyy
SomeRandmGuyy deleted the feat/grokbot-0.61-maintained-fork branch September 29, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants