Investigate and fix the grokrouter repo so it supports version 0.61.0 (… - #4
Conversation
…ies [tag-release] * Harden host recovery and gate releases on verified acceptance * Add exact 0.36 host selection and bind live gates to each desktop version * Intercept the expanded native skill invocation before inference * Record verified maintenance work and pending live release gates * Recognize brokered message delivery and remove fabricated launch recovery * Preserve Bot state and audit history when replacing the runtime * Make Doctor exit status reflect real runtime and adapter health * Return child results through the host response stream * Give native workflow registration enough time to load and reconcile * Recover empty Codex replies once without replaying completed work * Recover failed deliveries and preserve parent versus child completion * Register native commands before restarting the Grok host * Revive native child completions by durable host request ID * Preserve native child dispatch identity through hidden completion formatting * Document native completion identity and verified installation order * Normalize native completion envelopes before durable request recognition * Record real Codex and OpenRouter returned-child verification * Show current reasoning effort from the native status command * Prevent Codex automatic greetings from dispatching outer tools * Route native group controls from durable human message metadata * Recognize the native first-run greeting behind host procedure context * Preserve prerequisite tools when a task specifies exact final output * Defer parent delivery until a running child actually completes * Read background launch state from the structured native result * Recognize the native Task broker canonical launch receipt * Match verified native Task receipt paragraph spacing * Acknowledge verified background launches once while deferring results * Isolate native memory extraction from chat tools and conversation state * Preserve native maintenance sessions outside the chat adapter * Normalize verified literal delivery envelopes without executing tools * Decode exact literal replies inside verified broker delivery envelopes * Isolate periodic episode summaries from routed chat state and tools * Record exact-artifact live acceptance on official Grok Bot 0.36.0 * Record final acceptance on both supported Grok Bot versions
Upstream promptadvisers/grokrouter beta.47 diverged from this fork at c8eea82 (beta.46). This merge takes all of it and keeps every fork feature. Taken from upstream: - Grok Bot 0.36.0 manifest, signed 0.36.0 host registry and compatibility/supported-apps.json (exact desktop-version binding). - Exact reviewed stock-host trust only. The structural "anchor-verified" tier is disabled because anchors alone do not prove stock provenance. - Previous-adapter reconstruction (patch/previous_adapter.py), hardened host recovery, and child-completion, broker-delivery, memory/episode isolation and Doctor fixes. - Release/acceptance verification scripts, CodeQL, and acceptance docs. - Stock hash 3364e421... moves to the 0.36.0 manifest (live-accepted there). Kept from the fork: - Anthropic (Claude Agent SDK) and xAI OAuth providers, the full OpenRouter catalog, live per-provider model discovery and failure diagnostics. - The 0.44.0 manifest and hash/anchor manifest selection, used when no desktop version is recorded. - Version-tracking pipeline (version-watch, probe-ingest, host/auto probe). README.md takes upstream's text; the docs rewrite follows. TEST-MATRIX and RELEASE_NOTES keep beta.47's gate and list the fork's claims separately. Adopting 0.44.0 into beta.47's per-version gates follows in the next commit. Refs SPE-4551
…d newer version - 0.44.0 joins beta.47's exact per-version gates: supported-apps.json, anchorVerifiedHosts disabled, and a signed 0.44.0 host registry. - The fork signs host registries with its own Ed25519 key. All three registries are re-signed, and refresh downloads from swcstudiospace. - A Grok Bot strictly newer than every reviewed version (0.61.0 today) can be installed only through an unchecked-by-default installer checkbox. The Bot side then accepts the host by structural verification (no router marker, every anchor including beta.47's three patch seams exactly once, a node --check dry run, and the template size band). It reports HOSTTRUST=UNREVIEWED-ANCHOR-VERIFIED, and restore/repair/doctor honour the mode. Reviewed, older and in-between versions never receive structural trust. - Probes, scaffolding and diagnostics count the three patch seams. new-manifest-from-probe writes the beta.47 layout plus an unsigned registry for local signing. - Upgrades authenticate the upstream beta.45/46/47 and fork 7190a9e adapters by byte-exact reconstruction from patch/previous/. - Installer model fields are editable, with strict per-provider ID validation in both installers and install.sh. Suggestions include anthropic/claude-sonnet-5.5 and anthropic/claude-opus-5.5. - The installer status test no longer pipes into grep -q under pipefail, which killed the writer with SIGPIPE. Refs SPE-4552 Refs SPE-4550
…odel - Codex lists models from the pinned CLI's `codex debug models`: account refresh first, then the bundled catalog, then cache, then the packaged list. It runs through execFile with a timeout and bounded output. - /model sonnet|opus|haiku|fable|sol|terra|luna|astra|grok picks the newest matching model in the cached catalog, so Sonnet 5.5 and Opus 5.5 appear without a release. When the catalog has no match it falls back to the pinned alias. - Every remote model ID is validated before it is stored, listed or used. /models and /router doctor show where the catalog came from and how old it is. - The packaged fallback adds the live-verified OpenRouter claude-sonnet-5.5, claude-opus-5.5 and grok-4.7, plus the Codex CLI's bundled gpt-5.5 and gpt-5.2. Refs SPE-4550
- The macOS source installer downloads swcstudiospace/grokrouter at source-v0.1.0-beta.48. - New native Windows source installer (scripts/install-windows.ps1, with Install GrokRouter.cmd for ZIP/clone users). It checks for Node.js 22.12+ and Git for Windows and prints the winget commands instead of installing anything. It builds locally and installs per-user. It keeps one previous install, and it refuses to replace a folder that is not a GrokRouter install. - verify-release and tag-release require both installers and both README commands to pin the same tag in this repository. Tagging still requires the live acceptance record. - Windows CI parse-checks the installer and runs it twice to prove it is idempotent and never touches unrelated folders. - Versions bumped to 0.1.0-beta.48. Refs SPE-4550 Refs SPE-4554
…ne installs The README gives the Mac and Windows install commands inline from swcstudiospace/grokrouter, with from-clone alternatives until the beta.48 tag exists. It adds a per-version compatibility table, the unreviewed- version opt-in and its risk, and how new models appear. AGENTS.md, VERSION-TRACKING, ARCHITECTURE, HOW-IT-WORKS, RELEASE, FRESH-BOT-ACCEPTANCE, TEST-MATRIX (fork claims), MAINTENANCE-STATUS and RELEASE_NOTES are updated to match. Dated beta.47 evidence files are unchanged. Refs SPE-4554
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_946af4fe-230f-4687-bf48-a751186efa0d) |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
- Native memory-extraction and episode-summary tasks run on the Bot's own provider through runProvider. Before this, Anthropic and xAI Bots fell through to Codex with a non-Codex model ID. On Anthropic they run with no Claude Code tools, one turn and no session resume. The native-task test now asserts each transport serves its own provider. - install-windows.ps1 removes the staging copy and restores the previous install on any failed step, including a failed move of the old install. - grokbot-router and its watchdog read patch arguments with a read loop instead of bash 4's mapfile. The installer suite also runs these under macOS bash 3.2, where mapfile exits 127. Refs SPE-4550
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_63e21e76-eaa0-45f6-a183-0af445832212) |
Serialize Windows source installs per folder with an exclusive, delete-on-close lock file taken before the build and released in finally. A concurrent run fails fast instead of sharing or removing another run's staging copy or backup. Refs SPE-4550
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_93afa97e-1c30-4a52-a68c-72c5a69475eb) |
The Windows install lock reports 'already running' only for a real sharing violation (32/33 on Windows, EAGAIN under .NET on Unix). Any other failure, such as a permission error, now names the folder and the underlying reason. Refs SPE-4550
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_056f6335-5f02-4a4b-b59e-c8c478f4cf2a) |
GitHub's powershell wrapper exits with $LASTEXITCODE, which the deliberately refused install into a non-GrokRouter folder left at 1. Both real install passes and the refusal itself already succeeded on windows-2025. Refs SPE-4550
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_4f467352-e765-4c7b-b49e-e4dee0ca3a03) |
Summary
The branch implements a version-gate change (exact reviewed versions plus an opt-in 'unreviewed newer version' path referencing 0.61.0), restores/extends the macOS and Windows (native PowerShell + .cmd) installers, adds live model/family discovery in runtime/model-catalog.mjs and runtime/openrouter-catalog.mjs, adds signed compatibility registry tooling, CI workflows (including a Windows install round-trip test and CodeQL), and a substantial documentation rewrite (README, MAINTENANCE-STATUS.md, VERSION-TRACKING.md, TEST-MATRIX.md) declaring this repo the maintained fork with inline install commands. Test files were extensively expanded (compatibility, model-catalog, runtime, installer, windows-installer, release) suggesting verification was built alongside the feature work.
Linked issues
Fixes SPE-4548 — [n1] Understand repo structure and version-gate mechanism
https://linear.app/swcstudio/issue/SPE-4548/n1-understand-repo-structure-and-version-gate-mechanism
Fixes SPE-4550 — [n5] Design cross-platform installer and model auto-discovery flow
https://linear.app/swcstudio/issue/SPE-4550/n5-design-cross-platform-installer-and-model-auto-discovery-flow
Fixes SPE-4549 — [n3] Root-cause the 0.33/0.44-only restriction
https://linear.app/swcstudio/issue/SPE-4549/n3-root-cause-the-033044-only-restriction
Fixes SPE-4551 — [n2] Git-archaeology on the 'Muse' installer revert
https://linear.app/swcstudio/issue/SPE-4551/n2-git-archaeology-on-the-muse-installer-revert
Fixes SPE-4552 — [n4] Design version-gate fix and compatibility strategy
https://linear.app/swcstudio/issue/SPE-4552/n4-design-version-gate-fix-and-compatibility-strategy
Fixes SPE-4553 — [n6] Identify missing/ambiguous information requiring user clarification
https://linear.app/swcstudio/issue/SPE-4553/n6-identify-missingambiguous-information-requiring-user-clarification
Fixes SPE-4554 — [n7] Plan documentation rewrite for self-contained install instructions
https://linear.app/swcstudio/issue/SPE-4554/n7-plan-documentation-rewrite-for-self-contained-install-instructions
Fixes SPE-4555 — [n8] Ordered execution plan in file-disjoint waves
https://linear.app/swcstudio/issue/SPE-4555/n8-ordered-execution-plan-in-file-disjoint-waves
Notion task: https://app.notion.com/p/3eabc1a0c7ae815d8accfc57992e5412?pvs=204
Assessment
ultrathink graph ut-mumj0sn7-6137eec4
Note
High Risk
Changes host-trust, signed compatibility registries, and install/upgrade paths that patch Grok Bot cloud hosts; mistakes could weaken version gates or break installs, though the design stays fail-closed with expanded automated tests.
Overview
This PR retargets GrokRouter to the maintained
swcstudiospace/grokrouterfork and ships the 0.1.0-beta.48 candidate: upstream beta.47 exact-host trust is merged with fork-specific providers, 0.44.0 manifests/registries, and install commands pinned to the new repo/tag.Version and trust gates change materially. Reviewed Grok Bot builds are listed in
compatibility/supported-apps.jsonwith per-version signed*-hosts.jsonand a new Ed25519 registry key (upstream signatures dropped). Both installers add a default-off Allow unreviewed Grok Bot version (experimental) path for versions strictly newer than every reviewed release—structural anchor/seam checks only,HOSTTRUST=UNREVIEWED-ANCHOR-VERIFIED, no signed registry. Probe-ingest and version-watch workflows now scaffold unsigned registries and require local maintainer signing before merge.Windows and release automation expand. New
scripts/install-windows.ps1andInstall GrokRouter.cmd, README PowerShell one-liner, and CI that parses the script and installs twice (idempotency, pruning, refusal to replace non-GrokRouter dirs). Mac/Windows CI gainsverify-release.mjs, CodeQL, and tag-release now runs full CI plus acceptance verification before tagging.Runtime and docs: live model catalog discovery (including Codex CLI), family aliases, installer model fields; README and agent docs rewritten for self-contained install/troubleshooting; installation issue template collects Grok Bot version and install source separately.
Reviewed by Cursor Bugbot for commit cb70ccb. Bugbot is set up for automated code reviews on this repo. Configure here.
Verification
tests/installer.test.shpassed end to end without two host-dependent blocks: the PREF123 check needs/usr/binwithout node, and the other block needs macOSswiftc.swiftc -parsepasses, the payload builds,verify-releaseagrees on beta.48, and actionlint is clean.install-windows.ps1passed a parse check with pwsh 7.6. On Linux pwsh its failure paths all end correctly:-Fileexits 1,-Command "…| iex"exits 1, and an interactiveiexsession survives. Windows CI now runs it twice and checks that it never replaces or prunes a folder that isn't GrokRouter.codex debug models --bundled.anthropic/claude-sonnet-5.5andclaude-opus-5.5were confirmed in the live OpenRouter catalog.Not verified live (gates before tagging
source-v0.1.0-beta.48)verify-acceptancecorrectly refuses to tag.No outstanding finding or new issue in the post-review change prevents merging.
Summary
The PR adds experimental, opt-in handling for newer Grok Bot versions, cross-platform source installers, model discovery, signed compatibility data, and release checks.
Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Windows CI smoke test] --> B[Install twice] B --> C[Check installed app and backup] C --> D[Attempt install into occupied non-GrokRouter folder] D --> E[Check refusal and preserved user file] E --> F[Clear expected nonzero exit code]Reviews (5) · Last reviewed commit: "Keep the expected installer refusal from..."