fix(ai): reject messages after tool approval responses#17551
Open
jstar0 wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(ai): reject messages after tool approval responses
Background
streamTextcurrently treats any approval response in message history asresolving its tool call during prompt validation, while local approval execution
only consumes responses from the final tool message. A later user, system, or
assistant message can therefore leave a dangling tool call that reaches the
provider without executing the approved tool or producing a denial result.
The earlier approach in #17036 searches backward and executes approvals after
trailing context. This change instead follows the later maintainer guidance in
#17033 that such messages break the required
assistant -> tool -> assistant -> usersequence and should be rejected.Summary
Align prompt validation with the approval boundary consumed by the current
streamTextorgenerateTextinvocation. Invalid histories are rejected beforean approved side effect or provider request can be silently skipped.
Changes
message, matching the boundary consumed by the current invocation.
invocation by using the existing
MissingToolResultsError.streamTextand prompt-validation regression coverage plus a patchchangeset for
ai.Contributor Credit
End-to-End Verification
An approved response followed by a user message now reports
MissingToolResultsErrorbefore either the tool or model is called. The sameboundary rejects denied and other unresolved trailing histories. A final
approval response still follows the normal execution path, and a completed tool
result can still be followed by assistant and user messages.
Verification
Checklist
pnpm changesetin the project root)Related Issues
Fixes #17033