mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Local adapters such as `grok_local` invoke a host CLI (`grok`) for each heartbeat > - Grok authenticates from `GROK_HOME/auth.json` when that env var is set, otherwise from `~/.grok` > - Recent work (#12469, #12618) isolated subscription credentials into a company-scoped Grok home filled only by sandbox device login > - Local_trusted instances have only a Local environment, so that login never runs, the company home stays empty, and execute still sets `GROK_HOME` to it > - This pull request stops pinning `GROK_HOME` on local subscription runs unless the company home already has usable auth, a managed AI connection supplied a home, or the run is remote/sandbox > - The benefit is that `grok login` on the host works again for local Grok agents, without leaking host credentials into sandboxes ## Linked Issues or Issue Description Fixes: #13568 Related PRs (predecessors, not duplicates): - Refs #12469 - Refs #12618 - Refs #12696 I searched GitHub for `GROK_HOME`, `grok login`, `not signed in`, and `device-code`. No existing PR restores host-login fallback for local `grok_local` runs. ## What Changed - Local subscription execute no longer sets `GROK_HOME` when the company Grok home has no usable `auth.json` - Remote/sandbox runs and managed AI connections still pin `GROK_HOME` so they cannot fall through to the host login - Local runs still pin `GROK_HOME` once a company home has a usable credential (completed device login) - Adapter configuration notes document the host-login vs company-home split - Subscription detection respects an explicit empty `XAI_API_KEY` that clears an inherited host key. This keeps a valid company login selected. - Tests cover a real child process reading fixture host credentials, custom host homes, malformed company credentials, API-key overrides, managed connections, and empty remote homes. - Original fix by @hawikk. The follow-up preserves the contributor commit and adds independent regression coverage. ## Verification - `pnpm exec vitest run packages/adapters/grok-local`: 131 tests pass in 12 files. - `pnpm --filter @paperclipai/adapter-grok-local typecheck`: passes. - The new subprocess host-login regression fails against `master` and passes with this fix. It uses disposable fixture credentials and makes no provider request. - The explicit-empty-key regression fails against the contributed commit and passes with the follow-up. - `pnpm -r typecheck` and `pnpm build`: pass locally. - `pnpm test:run`: attempted locally, then stopped after embedded PostgreSQL startup failures. A focused retry of `ai-legacy-compatibility.test.ts` reproduced the same startup failure after five attempts. - All CI checks pass on `f4a380fec`: 54 successful checks and two intentional Storybook skips. This includes all general tests, serialized server suites, runner checks, browser shards, typecheck, build, and canary packaging. - Greptile reviewed `f4a380fec` at 5/5 with no actionable findings. GitHub reports no merge conflicts. - Grok CLI 1.0.13 is installed on the verification host, but it has no signed-in account. A live authenticated inference run was not performed. ## Risks - Low. Behavior changes only local subscription runs whose company Grok home has no usable `auth.json`. - Remote/sandbox isolation is unchanged: those runs still pin `GROK_HOME` and never use host `~/.grok`. - Managed AI connections still pin even with an empty home (fail closed rather than using the host account). - Operators who previously copied `auth.json` into the company home keep the pinned-home path. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - Provider: xAI Grok - Model: Grok 4.6 (`grok-4.6`) - Tool use: yes (repository search, local tests, GitHub issue/PR) - Human-authored: no — AI-assisted implementation - Follow-up review, code, and tests: OpenAI GPT-6 in Codex, with reasoning, repository tools, and code execution. Exact backend model ID and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Dotta <bippadotta@protonmail.com>