fix(server): Grok's "Always allow this session" no longer saves a project-wide grant - #13796
Conversation
…ject-wide grant The approval card offered "Always allow this session" on every Grok prompt and answered it with Grok's `allow_always` option. On bash, monitor and MCP prompts that option is Grok's persistent always-allow, which it writes to `~/.grok/sessions/<cwd>/permission_*.toml` for the whole project. A new Supervised Grok thread in the same project then ran the command with no prompt. The Grok flavor now advertises per-request approval options. File-change prompts keep a session choice, relabelled "Allow all edits this session", because Grok's `allow-edits-session` answer lasts only the session. Other prompts offer Approve, Decline and Cancel. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This focused fix changes Grok’s production permission behavior by preventing a misleading session choice from creating project-wide command grants while preserving the genuine session-only edit option. Because it affects authorization and persistence of tool permissions, human review is warranted. You can add or adjust custom eligibility rules. Learn more. |
954dbd7
into
t3code/codex-turn-mapping
Choosing Always allow this session on a Grok command approval gives Grok a permanent, project-wide allow for that command. A brand-new Supervised Grok thread in the same project then runs it without asking.
Reproduced live with Grok 1.0.41 (
grok-4.7-build-fast) in a disposable repo:rm marker1.txt". The approval card appears, and I pick Always allow this session.~/.grok/sessions/<repo>/permission_grok-code-extension.tomlcontainingallowed_bash_commands = ["rm marker1.txt"].grok --permission-mode default agent stdioprocess): "runrm marker1.txt". It runs with no prompt, and the DB has 0 runtime requests for thread B.Why
The ACP adapter maps
acceptForSessionto whichever option has kindallow_always. With T3'sclientType: "extension"(#13732), Grok's bash and monitor prompts offeralways-allow("Yes, and don't ask again for bash commands"). Grok records that as a persistent grant for the project (crates/codegen/xai-grok-workspace/src/permission/grants.rsrecord_prompt_outcome, persisted bymanager/mod.rspersist_state, at f0e3be1), not for the session. The only session-scopedallow_alwaysGrok sends isallow-edits-sessionon edit prompts (prompter.rsALLOW_EDITS_SESSION_OPTION_ID, "Session-only and never persisted"). The recorded fixtures show exactly these option sets:grok_auto_blocked_command)always-allow,allow-once,reject-once,reject-alwaysgrok_monitor)tool_call_read_only_on_request)allow-edits-session,allow-once,reject-oncegrok_background_subagent)allow-once,reject-onceWhat changed
The Grok flavor now sets
approvalOptions(the hook Antigravity already uses), so clients render only choices the request can honor. Edit prompts offer Allow all edits this session, because Grok scopes it to the session. Bash, monitor, MCP and subagent prompts offer Approve, Decline and Cancel. Web and mobile already renderoptionswhen present. This is Grok-only; the generic ACP adapter is unchanged. The user docs sentence that promised a remembered command is updated.Out of scope, noted for follow-up: when T3's own policy auto-approves a Grok prompt (Full access with an explicit override),
selectAutoApprovedPermissionOptionin the generic ACP adapter still prefersallow_always. Thegrok_monitorfixture shows T3 answeringalways-allowthere.Cleanup note
My live repro left a real grant file for the disposable repo:
~/.grok/sessions/%2Fhome%2F<user>%2Ftmp%2Fbughunt-grok%2Frepo3/permission_grok-code-extension.toml(plus an earlier one for.../repo1/). I did not delete anything outside the scratch directory.Verification
clientType: "extension"initialize_meta):grok_auto_blocked_commandnow asserts that the bash approval card offerscancel, decline, accept, and still that Approve answers Grok'sallow-once.tool_call_read_only_on_request/groknow asserts that the edit card offerscancel, decline, acceptForSession, accept.expected undefined to deeply equal [...]). With the fix, both pass.vp test run src/orchestration-v2/testkit/OrchestratorReplayFixtures.integration.test.ts -t grok: 13 passed.vp test run src/provider/acp/GrokAcpSupport.test.ts src/orchestration-v2/Adapters/GrokAdapterV2.test.ts src/orchestration-v2/Adapters/AcpAdapterV2.test.ts src/orchestration-v2/testkit/OrchestratorReplayFixtures.contract.test.ts: 152 passed.vp exec tsc --noEmit -p .inapps/server: no errors.knip --workspace apps/server --exports: clean.vp linton touched files: only pre-existing warnings on untouched lines.Model: Claude Opus 5.5 (Claude Code)
🤖 Generated with Claude Code