qwen-code/scripts
Shaojin Wen 0b36e597d4
fix(triage): render the verify report as sanitized markdown, not an escaped pre dump (#8147)
* fix(triage): render the verify report as sanitized markdown, not an escaped pre dump

The sandboxed-verification comment embedded report.md inside
<details><pre><code> with full HTML escaping. Safe, but unreadable:
the report is a curated bilingual document — tables, headings, nested
<details> folds — and it displayed as a wall of raw markdown source
(#8140's verify comment was the exhibit: literal asterisks, table
pipes, and <details> tags shown as text).

report.md now renders as markdown through emit_report, which holds the
same security floor with four line-independent guarantees: every & < >
is escaped and only the structural tags the report legitimately uses
(details/summary/pre/code/br) are un-escaped back to live tags, so no
other tag can form; the comment-open token is broken (the
autofix-proven neutralizer), so no forged qwen-triage:* marker can
appear in the raw body the upsert logic greps; @ becomes &#64;, which
renders identically but can never fire a mention; and unbalanced
<details> opens are counted and closed, so a malformed report cannot
swallow the footer. An oversized report falls back to the escaped-pre
embedding wholesale (truncated markdown dangles fences and folds), as
does any sanitizer failure. The tmux lane's raw-log embedding is
untouched — escaped pre remains right for logs.

The zero-match grep in the fold balancer carries || true: under the
step's pipefail, a report with no folds would otherwise kill the whole
composer.

Tests: a behavioral replay drives the real emit_report — structure
survives (tables, folds, no pre/code), the security floor holds (no
live marker/mention/tag, entities escaped, folds balanced), and the
oversize fallback produces the escaped shape; the full-render ordering
pin follows the new heading.

* fix(triage): cap sanitized report size and use portable ERE sed (#8147)

* fix(triage): budget fold-closer overhead against the report size cap (#8147)

* fix(triage): annotate emit_report fallbacks with distinct warnings (#8147)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>

* fix(triage): sanitize the verify report code-region-aware and re-collapse it (#8147)

Replace the unconditional sed escaping in emit_report with a node
sanitizer that tells code regions apart from prose. CommonMark does not
decode entities in code spans/fences, so escaping & < > @ there showed
&amp;&amp; / &lt;T&gt; / &#64;pkg in the commands, types, and paths a
report is read to copy. Prose is still escaped (< only; & and > are not
security controls and mangling them killed && and blockquotes), code is
left inert, the <!-- break stays global so no forged marker survives in
the raw body the upsert greps, and folds are balanced over prose only so
a fenced </details> can no longer defeat guarantee 4 (surplus closers
dropped, unclosed opens closed).

Wrap the rendered report in a collapsed <details> so it costs one line
again instead of expanding up to 45 KB inline, narrow the tag allowlist
to details/summary, bound the whole wrapped section against the size cap,
and make every fallback label say "truncated".

* fix(triage): close dangling code fences at EOF and test the sanitize-failure fallback (#8147)

* fix(triage): defuse mentions with ZWSP and track HTML blocks in sanitizer (#8147)

* fix(triage): prose-escape code spans inside HTML blocks and widen inHtml entry (#8147)

* fix(triage): degrade to escaped fallback when a code fence is open at EOF (#8147)

* fix(triage): fail closed on paragraph code-span and container-fence divergence (#8147)

* fix(triage): fail closed on escaped-backtick and entity-forgery sanitizer holes (#8147)

---------

Co-authored-by: verify <verify@local>
Co-authored-by: qwen-code-ci-bot <qwen-code-ci-bot@users.noreply.github.com>
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-08-01 05:25:09 +00:00
..
installation fix(packaging): bundle clipboard addon in standalone builds (#6708) 2026-07-11 15:18:24 +00:00
lib feat(core): support QWEN_HOME env var to customize config directory (#2953) 2026-05-09 15:51:52 +08:00
tests fix(triage): render the verify report as sanitized markdown, not an escaped pre dump (#8147) 2026-08-01 05:25:09 +00:00
acp-http-smoke.mjs feat(daemon): merge daemon-mode feature batch into main (#4490) 2026-06-12 00:34:49 +08:00
audit-runtime-critical.js ci: keep the critical-audit gate honest when npm cannot answer (#7743) 2026-07-26 06:59:13 +00:00
benchmark-api-latency.mjs feat(cli): add API preconnect to reduce first-call latency (#3318) 2026-04-27 06:54:55 +08:00
build-hosted-installation-assets.js fix(installer): auto-detect SYSTEM account and default PATH scope to machine (#4903) 2026-06-10 21:02:10 +08:00
build-standalone-release.js fix(packaging): bundle clipboard addon in standalone builds (#6708) 2026-07-11 15:18:24 +00:00
build.js feat(channels): GitHub polling adapter with notification-as-wakeup architecture (#7632) 2026-07-25 09:31:50 +00:00
build_package.js fix(build): clean stale outputs before tsc --build to prevent TS5055 (#4453) 2026-05-23 23:06:31 +08:00
build_sandbox.js fix(sandbox): fall back to 'latest' tag when image name has no colon (#2962) 2026-04-18 09:07:05 +08:00
build_vscode_companion.js Sync upstream Gemini-CLI v0.8.2 (#838) 2025-10-23 09:27:04 +08:00
check-build-status.js fix(review): report what the transcripts prove; build the roster in one call (#7033) 2026-07-18 00:43:57 +00:00
check-desktop-isolation.js feat(desktop): Add desktop app package with Qwen ACP SDK integration (#3778) 2026-06-11 21:57:20 +08:00
check-i18n.ts fix(cli): localize approval mode UI labels (#6592) 2026-07-11 00:07:03 +00:00
check-lockfile.js Sync upstream Gemini-CLI v0.8.2 (#838) 2025-10-23 09:27:04 +08:00
check-serve-fast-path-bundle.js feat(ci): fail the startup bundle check when the CLI entry is hoisted into a chunk (#8203) 2026-07-31 08:57:57 +00:00
clean-package-build-artifacts.js feat(channels): GitHub polling adapter with notification-as-wakeup architecture (#7632) 2026-07-25 09:31:50 +00:00
clean.js feat(desktop): Add desktop app package with Qwen ACP SDK integration (#3778) 2026-06-11 21:57:20 +08:00
cli-entry.js perf(cli): Propagate compile cache to ACP children (#7594) 2026-07-24 04:06:14 +00:00
copy_bundle_assets.js feat(core): add dataviz bundled skill (#6198) 2026-07-03 01:06:39 +00:00
copy_files.js revert: remove unused script modifications 2026-02-10 14:34:36 +08:00
create-standalone-package.js fix(cli): avoid updating active CLI processes (#6874) 2026-07-15 00:33:17 +00:00
create_alias.sh fix: ambiguous literals (#461) 2025-08-27 15:23:21 +08:00
daemon-dev.js fix(scripts): allow multiple dev:daemon instances by probing Vite port (#7212) 2026-07-19 12:49:47 +00:00
desktop-openwork-sync.ts feat(acp): support desktop qwen integration (#4728) 2026-06-09 19:09:44 +08:00
dev.js fix(review): report what the transcripts prove; build the roster in one call (#7033) 2026-07-18 00:43:57 +00:00
esbuild-shims.js perf(cli): code-split lowlight to cut startup V8 parse cost (#4070) 2026-05-15 17:26:18 +08:00
generate-changelog.js feat(release): generate AI-assisted release notes (#6756) 2026-07-12 13:00:22 +00:00
generate-git-commit-info.js # 🚀 Sync Gemini CLI v0.2.1 - Major Feature Update (#483) 2025-09-01 14:48:55 +08:00
generate-release-notes.js fix(release): raise model timeouts and shrink batch size for slow networks (#8007) 2026-07-29 22:38:35 +00:00
generate-settings-schema.ts revert: remove local PR verification gate (#7031) 2026-07-16 11:24:38 +00:00
get-release-version.js fix(release): bump preview base past published stable (#7978) 2026-07-29 23:21:00 +00:00
lint.js revert: remove local PR verification gate (#7031) 2026-07-16 11:24:38 +00:00
local_telemetry.js Merge tag 'v0.3.0' into chore/sync-gemini-cli-v0.3.0 2025-09-11 16:26:56 +08:00
measure-flicker.mjs fix(cli): bound SubAgent display by visual height to prevent flicker (#3721) 2026-04-29 22:34:55 +08:00
pre-commit.js Sync upstream Gemini-CLI v0.8.2 (#838) 2025-10-23 09:27:04 +08:00
prepare-package.js feat(core): add full-resolution image zoom tool (#7809) 2026-07-27 23:40:26 +00:00
prepare.js feat(web-shell): git status chip, visual working-tree diff, and sidebar git status (#7054) 2026-07-18 10:06:07 +00:00
release-script-utils.js feat(installer): add standalone hosted install and uninstall flow (#3828) 2026-05-21 11:57:10 +08:00
run-java-daemon-sdk-e2e.ts fix(sdk-java): Harden daemon transport reliability (#7603) 2026-07-24 04:22:05 +00:00
sandbox_command.js fix(scripts): avoid shell injection in sandbox command detection (#6108) 2026-07-01 16:20:40 +08:00
sdk-node-exporter-stub.js perf(telemetry): lazy-load the SDK and split OTLP exporter chains by protocol (#7276) 2026-07-21 07:35:30 +00:00
sign-release.sh feat(cli): add standalone auto-update support (#4629) 2026-06-04 22:53:12 +08:00
start.js fix(review): report what the transcripts prove; build the roster in one call (#7033) 2026-07-18 00:43:57 +00:00
sync-computer-use-schemas.ts feat(computer-use): configurable screenshot max dimension (setting + env) (#5122) 2026-06-15 15:25:27 +08:00
telemetry.js feat(core): support QWEN_HOME env var to customize config directory (#2953) 2026-05-09 15:51:52 +08:00
telemetry_gcp.js fix(mcp): update OAuth client names and improve MCP commands 2026-02-08 10:46:48 +08:00
telemetry_utils.js feat(core): support QWEN_HOME env var to customize config directory (#2953) 2026-05-09 15:51:52 +08:00
test-rewind-e2e.sh fix(test): update rewind E2E Test 1 assertion after isRealUserTurn fix (#3622) 2026-04-26 06:49:42 +08:00
test-windows-paths.js chore: consistently import node modules with prefix (#3013) 2025-08-25 20:11:27 +00:00
unused-keys-only-in-locales.json feat: add /diff command and git diff statistics utility (#3491) 2026-05-10 11:15:59 +08:00
upload-aliyun-oss-assets.js fix(release): move constants above entry point to avoid TDZ error (#4398) 2026-05-23 22:21:33 +08:00
verify-capture.mjs fix(ci): avoid verify capture color conflict (#8236) 2026-07-31 14:15:40 +00:00
verify-installation-release.js feat(installer): verify release assets + switch public docs to standalone entrypoint (#3855) 2026-06-04 17:23:04 +08:00
version.js fix(release): pin channel-base dep to exact version during release bump (#7953) 2026-07-28 16:58:28 +00:00
workspaces.js feat(desktop): Add desktop app package with Qwen ACP SDK integration (#3778) 2026-06-11 21:57:20 +08:00