Repository navigation
Conversation
A malformed tool-call payload with a non-string path/file_path/workdir threw in normalizePath/filetype/path.resolve and tore down the session view on the Bun shipped build. Extract type-safe path labels and degrade untrusted values to empty labels instead. Fixes XiaomiMiMo#2558
Author
|
@yanyihan-xiaomi @lilei-xiaomi @JinyuXiang-Mimo — second small TUI hardening PR for review (related to #2607, different bug). Fixes #2558: non-string Fork PR will also sit on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A malformed tool-call payload with a non-string
path/file_path/workdirthrew inpath.isAbsolute/path.extname/path.resolveand tore down the whole session view (fatal on the Bun-shipped build). Three renderer helpers insession/index.tsx,session/permission.tsx, andrun.tsall read rawpart.state.inputwith no type check — zod only runs inexecute().packages/cli/src/cli/cmd/tui/util/tool-path.ts(normalizePath,normalizePermissionPath,normalizeRunPath,filetype) that acceptunknownand degrade to""/"none"typeof workdir === "string"beforepath.resolvein the Bash tool lineDisplay-only safety —
execute()zod/schema behavior is unchanged. Each surface keeps its own path formatting (session relative/absolute, permission~, run relative).Verified with
bun run typecheckandbun test test/cli/tui/tool-path.test.ts(11 pass — untrusted matrix + three display behaviors). Fork PR will need a maintainer to approve the workflow runs.Fixes #2558