Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions docs/research/WEB_EVIDENCE_TERMINAL_STRINGS_2026-10-07.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Terminal strings in Web evidence

- Status: validated source and regression evidence
- Created / verified: 2026-10-07
- Source: origin/main at 3cb2ecfe1bfbb98252651885311d309f83749428
- Issue: [#700](https://github.com/openpi-dev/openpi/issues/700)
- Supersedes: none

## Verified facts

Web evidence stripped escape introducers while retaining hidden DCS, PM, APC and SOS payloads. It now uses the canonical shared terminal sanitizer on its bounded candidate. Tests cover ESC/C1 introducers, terminators, unterminated strings and actual tool projections.

## Verification boundary

Eight evidence tests pass. Unicode and tab behavior follows the shared sanitizer. Canonical execution and persisted evidence are unchanged.

Full repository validation results and CI are recorded on the linked PR. Local
Windows failures are retained separately and are not reported as passing.
30 changes: 30 additions & 0 deletions tests/web/evidence.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,36 @@ function call(name: string, args: Record<string, unknown> = {}) {
return part;
}

test("Web evidence strips terminal-owned hidden strings rather than exposing their payloads", () => {
for (const start of [
"\x1bP",
"\x1bX",
"\x1b^",
"\x1b_",
"\u0090",
"\u0098",
"\u009e",
"\u009f",
]) {
for (const end of ["\x1b\\", "\u009c"]) {
assert.equal(
evidenceText(`before${start}hidden${end}after`).text,
"beforeafter",
);
}
assert.equal(evidenceText(`before${start}unterminated`).text, "before");
}
assert.equal(
evidenceText("中文\t👩‍💻\x1b[31mvisible\x1b[0m").text,
"中文 👩‍💻visible",
);
const result = projectToolEvidence(call("bash"), {
content: "before\x1bPhidden\x1b\\after",
isError: false,
});
assert.equal(result.output, "beforeafter");
});

test("bounded messages preserve final bash receipts before output truncation", () => {
const message = projectMessage({
role: "toolResult",
Expand Down
131 changes: 66 additions & 65 deletions web/dist/app.js

Large diffs are not rendered by default.

6 changes: 2 additions & 4 deletions web/protocol/evidence.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
import type { WebLiveMessage, WebMessagePart } from "./types.ts";
import { sanitizeTerminalText } from "../../extensions/shared/terminal-text.ts";

export const EVIDENCE_MAX_BYTES = 12 * 1024;
export const EVIDENCE_MAX_LINES = 300;
Expand All @@ -25,10 +26,7 @@ export function projectEvidenceArguments(input: unknown) {
export function evidenceText(value: string, tail = false) {
// Bound work before stripping terminal controls, including OSC hyperlinks.
const candidate = tail ? value.slice(-EVIDENCE_MAX_BYTES * 2) : value.slice(0, EVIDENCE_MAX_BYTES * 2);
const clean = candidate
.replace(/\x1b\][^\x07\x1b]*(?:\x07|\x1b\\|$)/gu, "")
.replace(/(?:\x1b\[|\x9b)[0-?]*[ -/]*[@-~]/gu, "")
.replace(/[\x00-\x08\x0b-\x1f\x7f-\x9f\u202a-\u202e\u2066-\u2069]/gu, "");
const clean = sanitizeTerminalText(candidate);
const lines = clean.split("\n");
const limited = (tail ? lines.slice(-EVIDENCE_MAX_LINES) : lines.slice(0, EVIDENCE_MAX_LINES)).join("\n");
const bytes = new TextEncoder().encode(limited);
Expand Down
Loading