Evidence record / grok-build

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-grok-build-sandbox-profiles-now-write-deny-grok-s-own-config-trust-and-policy-files

Sandbox profiles now write-deny Grok’s own config, trust, and policy files. Under a sandbox profile, the agent could previously write its own settings, folder-trust list, and requirements file, which is a path to relax its own permissions for the next session. That path is now closed at the kernel level for the named files. Side effect: accepting folder trust, /model, and mode changes inside a sandboxed session no longer persist.

Channel: tagged-release (joined to sync a28ee2b20634, crate 1.0.35); the config write-deny has no release note. Half: defect. Date: between 2026-09-15 and 2026-09-17 (builds 1.0.33 to 1.0.35); strict narrowing in 1.0.14 (2026-08-31).

Operator consequence: If you use --sandbox, run 1.0.35 or later. Remember the default is off: none of this applies unless you pass a profile. Child-network blocking is Linux-only (documented as a no-op on macOS).

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-grok-build-sandbox-profiles-now-write-deny-grok-s-own-config-trust-and-policy-files

Profile citations

  • grok-build / claim / sandbox-write-denies-own-config

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact