Skip to content

fix(xai): report a current Grok CLI version on the OAuth path - #6341

Merged
lidge-jun merged 2 commits into
devfrom
codex/fix-xai-grok-cli-version
Oct 1, 2026
Merged

lidge-jun merged 2 commits into
devfrom
codex/fix-xai-grok-cli-version

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

xAI now rejects Grok OAuth (SuperGrok) requests that report a client version below 1.0.13 with HTTP 426: Your Grok CLI version (0.2.93) is outdated. Please update to version 1.0.13 or later. OpenCodex hardcoded 0.2.93 in XAI_GROK_COMPATIBILITY, which feeds x-grok-client-version and the User-Agent on the OAuth path, so every Grok OAuth request failed. This was reproduced on 2026-10-01 through the running proxy (an Aside agent session routed to xAI returned exactly that 426).

This reports 1.0.25, the current stable Grok CLI (grok 1.0.25 (f7e67d6988e2) [stable] from the official installer). The quota probe derives from the same constant.

Carries #6339 by @unsafe9, which proposed 1.0.22; this uses the newer stable release.

Co-authored-by: unsafe9 24631203+unsafe9@users.noreply.github.com

Verification

  • bun test tests/providers/xai/xai-transport.test.ts tests/server/server-xai-responses-streaming.test.ts tests/server/server-xai-chat-reasoning-streaming.test.ts: 58 pass / 0 fail.
  • bun test tests/providers/provider-quota.test.ts tests/providers/provider-account-quota.test.ts: 238 pass / 0 fail.
  • bun x tsc --noEmit passes.
  • Live check after release: re-run the Grok-routed Aside session that hit the 426.
  • Full local suite not run by maintainer instruction; Cross-platform CI runs once on the final dev tip.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

xAI now answers Grok OAuth requests that report a client version below 1.0.13 with HTTP 426 ("Your Grok CLI version (0.2.93) is outdated"), so every SuperGrok OAuth request failed. Report 1.0.25, the current stable Grok CLI, in x-grok-client-version and the User-Agent.

Carries #6339.

Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner October 1, 2026 02:06
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T02:09:36.626527Z 04b7a4f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the intake: hygiene-blocked Deterministic PR hygiene checks failed label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⚠️ Deterministic hygiene checks failed.

  • missing_regression_test — Behavior changed under src/ or gui/src/ without a test change. Add focused coverage or obtain test-exception-approved.

@github-actions github-actions Bot added the bug Something isn't working label Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer integration into dev (MAINTAINERS.md, dev-only exception) by @lidge-jun. Fixes the HTTP 426 that rejects every Grok OAuth request (reproduced today through the running proxy). An independent review found that the header snapshot test derived its expectation from the production constant, so reverting the version still passed; the test now pins the literal value, and reverting to 0.2.93 fails 3 cases. Local: xAI transport/streaming tests 58 pass, quota tests 238 pass, bun x tsc --noEmit passes. Security: header value only; credential destinations, authorization and token handling unchanged. Cross-platform CI runs once on the final dev tip before release.

@lidge-jun
lidge-jun merged commit 6f2f6ae into dev Oct 1, 2026
4 checks passed
@lidge-jun
lidge-jun deleted the codex/fix-xai-grok-cli-version branch October 1, 2026 02:08

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 04b7a4f114

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

export const XAI_GROK_COMPATIBILITY = {
version: "0.2.93",
userAgent: "opencodex-grok/0.2.93",
version: "1.0.25",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin the accepted Grok client version independently

Add a focused regression that independently asserts the reported version is at least the upstream-required 1.0.13 floor (or pins the supported 1.0.25 profile). The existing assertions in tests/providers/xai/xai-transport.test.ts and the quota tests derive their expectations from XAI_GROK_CLIENT_VERSION, so they passed with 0.2.93 and still pass after this edit; reverting or downgrading the constant would therefore recreate the OAuth-wide HTTP 426 failure without making the suite red.

AGENTS.md reference: AGENTS.md:L448-L452

Useful? React with 👍 / 👎.

Comment on lines +31 to +32
version: "1.0.25",
userAgent: "opencodex-grok/1.0.25",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Document the new Grok compatibility floor

Update the owned structure documentation for this transport change. structure/providers/xai-grok.md currently records only that a single compatibility-profile constant exists, but not the newly load-bearing 1.0.13 upstream floor or the 1.0.25 profile reported here; without that update, the source-owner documentation omits the invariant whose violation disables every OAuth request.

AGENTS.md reference: src/AGENTS.md:L11-L11

Useful? React with 👍 / 👎.

wongang2 pushed a commit to wongang2/opencodex that referenced this pull request Oct 2, 2026
…jun#6341)

* fix(xai): report a current Grok CLI version on the OAuth path

xAI now answers Grok OAuth requests that report a client version below 1.0.13 with HTTP 426 ("Your Grok CLI version (0.2.93) is outdated"), so every SuperGrok OAuth request failed. Report 1.0.25, the current stable Grok CLI, in x-grok-client-version and the User-Agent.

Carries lidge-jun#6339.

Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>

* test(xai): pin Grok compatibility header regression

---------

Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>
(cherry picked from commit 6f2f6ae)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working intake: hygiene-blocked Deterministic PR hygiene checks failed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant