Skip to content

fix(tui): guard non-string tool-call path fields in renderers - #2608

Open
goakshit wants to merge 1 commit into
XiaomiMiMo:mainfrom
goakshit:fix/tui-tool-input-path-guard
Open

goakshit wants to merge 1 commit into
XiaomiMiMo:mainfrom
goakshit:fix/tui-tool-input-path-guard

Conversation

@goakshit

@goakshit goakshit commented Oct 4, 2026

Copy link
Copy Markdown

A malformed tool-call payload with a non-string path / file_path / workdir threw in path.isAbsolute / path.extname / path.resolve and tore down the whole session view (fatal on the Bun-shipped build). Three renderer helpers in session/index.tsx, session/permission.tsx, and run.ts all read raw part.state.input with no type check — zod only runs in execute().

  • Extract type-safe labels to packages/cli/src/cli/cmd/tui/util/tool-path.ts (normalizePath, normalizePermissionPath, normalizeRunPath, filetype) that accept unknown and degrade to "" / "none"
  • Rewire the three call sites to those helpers (drop the local copies)
  • Require typeof workdir === "string" before path.resolve in the Bash tool line

Display-only safety — execute() zod/schema behavior is unchanged. Each surface keeps its own path formatting (session relative/absolute, permission ~, run relative).

Verified with bun run typecheck and bun test test/cli/tui/tool-path.test.ts (11 pass — untrusted matrix + three display behaviors). Fork PR will need a maintainer to approve the workflow runs.

Fixes #2558

A malformed tool-call payload with a non-string path/file_path/workdir
threw in normalizePath/filetype/path.resolve and tore down the session
view on the Bun shipped build. Extract type-safe path labels and degrade
untrusted values to empty labels instead.

Fixes XiaomiMiMo#2558
@goakshit

goakshit commented Oct 4, 2026

Copy link
Copy Markdown
Author

@yanyihan-xiaomi @lilei-xiaomi @JinyuXiang-Mimo — second small TUI hardening PR for review (related to #2607, different bug).

Fixes #2558: non-string path / file_path / workdir in a tool-call payload crashed the whole TUI. Display-only guards in the three renderers; 11 unit tests pass; typecheck clean.

Fork PR will also sit on action_required for typecheck / lint / test until a maintainer approves the workflow runs. I only have pull access here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fatal TUI crash: non-string tool-call path throws "The ""path"" property must be of type string" and destroys the session view

1 participant