The API server's _resolve_media_to_data_urls ran MEDIA_TAG_CLEANUP_RE over the raw final_response, bypassing the sentinel seam this branch added in gateway/platforms/base.py. A provider that leaked its end-of-sequence token glued to the last MEDIA path (MEDIA:/x.png<|eos|>) therefore still produced no inline image and returned the raw tag to the HTTP client (non-stream and SSE chat completions) - the exact symptom fixed for the chat platforms. The scan now stops at _terminal_sentinel_start and drops the control token only when a tag actually resolved, so unrelated responses stay byte-identical. _terminal_sentinel_start also recognises a run of repeated exact tokens (MEDIA:/x.png<|eos|><|eos|>), so a doubled leak no longer hides the attachment either; mid-text or non-exact sentinels are still not a media boundary. Review finding: api_server sibling MEDIA surface bypassed _mask_media_scan_text; doubled terminal sentinel still leaked
36 lines
1.7 KiB
Python
36 lines
1.7 KiB
Python
"""A leaked terminal ``<|eos|>`` sentinel must not hide a MEDIA attachment (#111046)."""
|
|
|
|
import pytest
|
|
|
|
from gateway.platforms.base import BasePlatformAdapter
|
|
|
|
|
|
@pytest.mark.parametrize("sentinel", ["<|eos|>", "<|eos|><|eos|>"])
|
|
@pytest.mark.parametrize("filename", ["chart.png", "payload.weirdext", "Caddyfile"])
|
|
def test_terminal_eos_sentinel_leaves_extraction_and_cleanup_unchanged(tmp_path, monkeypatch, filename, sentinel):
|
|
"""Known-extension, unknown-extension and extension-less tags glued to a (possibly repeated)
|
|
``<|eos|>`` extract and clean exactly like the same response without the sentinel."""
|
|
root = tmp_path / "media-cache"
|
|
root.mkdir()
|
|
media_file = root / filename
|
|
media_file.write_bytes(b"media")
|
|
monkeypatch.setattr("gateway.platforms.base.MEDIA_DELIVERY_SAFE_ROOTS", (root,))
|
|
clean = f"Here is the file.\nMEDIA:{media_file}"
|
|
|
|
assert BasePlatformAdapter.extract_media(clean + sentinel) == BasePlatformAdapter.extract_media(clean)
|
|
assert BasePlatformAdapter.strip_media_directives_for_display(clean + sentinel) == "Here is the file."
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"text",
|
|
[
|
|
"MEDIA:/tmp/example.png<|EOS|>", # not the exact token: still not a path delimiter
|
|
"MEDIA:/tmp/example.png<|eos|> trailing prose", # not terminal
|
|
"```text\nMEDIA:/tmp/example.png<|eos|>\n```", # protected code stays byte-identical
|
|
'{"example":"MEDIA:/tmp/example.png<|eos|>"}', # protected JSON value
|
|
],
|
|
)
|
|
def test_non_terminal_or_protected_sentinel_is_not_a_media_boundary(text):
|
|
assert BasePlatformAdapter.extract_media(text) == ([], text)
|
|
assert BasePlatformAdapter.strip_media_directives_for_display(text) == text
|