fix: recognise discourse-marker lead-ins before a leaked shell-JSON call

'Next, I'll create the script.' / 'First, let me check the directory.' /
'Okay — running the tests.' followed by a closing {"cmd": ...} object were not
classified as leaked tool calls because the lead-in pattern anchored the action
verb at line start. Allow an optional Next/First/Then/Okay/OK/Alright marker
(with comma/dash) before the existing prefixes; the 'closes the message' and
'cmd' key constraints are unchanged, so bare/explained JSON answers still pass
through (#56920).
This commit is contained in:
teknium1
2026-09-19 01:20:46 -07:00
committed by Teknium
parent f5fbe9a609
commit cdac150ec3
2 changed files with 4 additions and 1 deletions

View File

@@ -67,7 +67,8 @@ _SHELL_JSON_LEAK_PATTERN = re.compile(
)
_ACTION_VERBS = r"creat(?:e|ing)|writ(?:e|ing)|runn?(?:ing)?|execut(?:e|ing)|check(?:ing)?|verif(?:y|ying)|updat(?:e|ing)|install(?:ing)?|edit(?:ing)?|mak(?:e|ing)"
_SHELL_JSON_LEAK_LEADIN_PATTERN = re.compile(
rf"^(?:sure,\s*)?(?:now\s+)?(?:let\s+me\s+|i(?:'|’)?ll\s+|i\s+will\s+|i(?:'|’)?m\s+|i\s+am\s+)?(?:{_ACTION_VERBS})\b",
rf"^(?:(?:next|first|then|okay|ok|alright)\b[\s,—–-]*)?(?:sure,\s*)?(?:now\s+)?"
rf"(?:let\s+me\s+|i(?:'|’)?ll\s+|i\s+will\s+|i(?:'|’)?m\s+|i\s+am\s+)?(?:{_ACTION_VERBS})\b",
re.IGNORECASE,
)

View File

@@ -837,6 +837,8 @@ def _final_text_response(text):
@pytest.mark.parametrize("text", [
'Creating the PowerShell script now.\n{"cmd": "mkdir -p /c/Temp && cat > /c/Temp/x.ps1 <<\'EOF\'"}',
'Sure, let me run the tests.\n{"cmd": "pytest -q", "workdir": "/repo", "timeout": 120}',
'Next, I\'ll create the script.\n{"cmd": "cat > x.sh"}',
'Okay — running the tests.\n{"cmd": "pytest -q"}',
"Calling tool now to=functions.terminal {\"command\": \"ls\"}",
])
def test_normalize_codex_response_treats_leaked_tool_call_text_as_incomplete(text):