Skip to content

fix(pixel-inference): validate stop parameter type as string, array of strings, or null - #5942

Open
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-stop-type
Open

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-stop-type

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/extensions/services/pixel-inference/app/main.py, _prepare(payload, grant) lists stop in the permitted FIELDS set but does not enforce type validation on its value. The completions specification requires stop to be either null, a string, or an array of strings (e.g. ["\n", "END"]). When a client supplies a non-string scalar (such as integer 123, boolean false, or dictionary mapping) or a list containing non-string elements, the payload passes through _prepare and causes downstream serializer failures or unhandled 500 exceptions in inference engines.

This change adds explicit validation for the stop argument in _prepare. It accepts None, strings, or lists of strings, while raising ShareError(400, 'invalid_stop') for any other scalar type or mixed-type list. Standard string and array stop words continue to operate without alteration.

Validation

  • Tested baseline reproduction against unpatched code: passing {"stop": 123} or {"stop": [True]} bypassed _prepare without error.
  • Tested post-fix behavior: non-string scalar types and lists with non-string elements are rejected with HTTP 400 and code invalid_stop; valid strings and string arrays pass cleanly.
  • Telemetry statement: "Pixel-inference suites: 3 passed. New-test Ruff, py_compile, and diff checks pass; new regression wired into Linux CI."

Overlap check

Risk / AI disclosure

AI-assisted defect analysis, implementation, and test isolation. This restricts malformed request parameters at the API gateway layer and does not modify persistent storage, models, or container runtime states. Independent human review remains a gate.

Follow-up integration evidence

Composed cleanly on top of #5569, #5871, and #5875 at HEAD without conflicts. Production and test diffs passed together; adjacent pixel-agent and pixel-settings checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant