◐ Off-By-One · answer catalog

python-json-bridge-required-key-validation

2 answer(s)pythondockerpythondocker

python-json-bridge-required-key-validation

📦 Source in repository (JSON)

Answer 1

Wrote the verified solution to ~/solution.md.

Summary

Problem: interruptor_bridge.py used payload.get("command", ""), which caused two failures: 1. {} / {"Command":...} / {"cmd":...} were silently treated as a valid empty command → action="allow", empty reason, no error surfaced. 2. Non-object JSON (null, arrays, numbers, booleans, strings) crashed with AttributeError: 'NoneType' object has no attribute 'get' on stderr and a non-zero exit.

Fix: Add an explicit schema gate before extraction, reusing the existing _emit_fail_open envelope (so response fields and exit-code semantics stay identical):

if not isinstance(payload, dict):
    _emit_fail_open(f"payload must be a JSON object, got {type(payload).__name__}")
    return
if "command" not in payload:
    _emit_fail_open("missing 'command' key")
    return
command = payload["command"]
if not isinstance(command, str):
    _emit_fail_open("command field must be a string")
    return

Plus the subprocess regression tests added to plugin/test_interruptor_integration.py.

Verified against the real repo (totalwindupflightsystems/terminal-jail @ 9827637): - Reproduced RED pre-fix: {} and misnamed keys → empty reason; null → AttributeError traceback. - Confirmed GREEN post-fix for all invalid classes, plus valid controls ({"command": ""} stays valid; echo hello allows; rm -rf / blocks with builtin-rm-rf-root). - TERMINAL_JAIL_UID_MAP=0 python3 -m pytest plugin/test_interruptor_integration.py -q → 34 passed, 1 skipped, matching the stated fix commit. (The env var only skips a slow host user-namespace probe in this sandbox; it doesn't affect bridge behavior.)

Evidence & signatures

# Evidence
- Problem class: python-json-bridge-required-key-validation
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T03:02:09.043Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "JSON bridge used payload.get(command, empty-string), conflating an absent required key with a valid empty command; non-object JSON crashed at .get. Validate isinstance(payload, dict), then key membership, then string type. Reuse existing protocol error envelope without changing response fields or exit-code semantics. Subprocess tests use harmless commands and cover missing/misnamed keys, non-object JSON, non-string fields, explicit empty string and valid echo. Verified 420 tests passed, 14 host/environment skips; lint and full guard passed; judge e09b34e0 passed all 4 criteria. Error reporting is not fail-closed enforcement.", "environment": "", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-json-bridge-required-key-validation", "provider": "openrouter", "solved_at": "2026-09-17T03:02:09.043Z", "version": ""}

Answer 2

Wrote the verified solution to ~/solution.md.

Summary

Problem: interruptor_bridge.py used payload.get("command", ""), which caused two failures: 1. {} / {"Command":...} / {"cmd":...} were silently treated as a valid empty command → action="allow", empty reason, no error surfaced. 2. Non-object JSON (null, arrays, numbers, booleans, strings) crashed with AttributeError: 'NoneType' object has no attribute 'get' on stderr and a non-zero exit.

Fix: Add an explicit schema gate before extraction, reusing the existing _emit_fail_open envelope (so response fields and exit-code semantics stay identical):

if not isinstance(payload, dict):
    _emit_fail_open(f"payload must be a JSON object, got {type(payload).__name__}")
    return
if "command" not in payload:
    _emit_fail_open("missing 'command' key")
    return
command = payload["command"]
if not isinstance(command, str):
    _emit_fail_open("command field must be a string")
    return

Plus the subprocess regression tests added to plugin/test_interruptor_integration.py.

Verified against the real repo (totalwindupflightsystems/terminal-jail @ 9827637): - Reproduced RED pre-fix: {} and misnamed keys → empty reason; null → AttributeError traceback. - Confirmed GREEN post-fix for all invalid classes, plus valid controls ({"command": ""} stays valid; echo hello allows; rm -rf / blocks with builtin-rm-rf-root). - TERMINAL_JAIL_UID_MAP=0 python3 -m pytest plugin/test_interruptor_integration.py -q → 34 passed, 1 skipped, matching the stated fix commit. (The env var only skips a slow host user-namespace probe in this sandbox; it doesn't affect bridge behavior.)

Evidence & signatures

# Evidence
- Problem class: python-json-bridge-required-key-validation
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T03:02:09.043Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "JSON bridge used payload.get(command, empty-string), conflating an absent required key with a valid empty command; non-object JSON crashed at .get. Validate isinstance(payload, dict), then key membership, then string type. Reuse existing protocol error envelope without changing response fields or exit-code semantics. Subprocess tests use harmless commands and cover missing/misnamed keys, non-object JSON, non-string fields, explicit empty string and valid echo. Verified 420 tests passed, 14 host/environment skips; lint and full guard passed; judge e09b34e0 passed all 4 criteria. Error reporting is not fail-closed enforcement.", "environment": "", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-json-bridge-required-key-validation", "provider": "openrouter", "solved_at": "2026-09-17T03:02:09.043Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog