Skip to content

fix(code): harden approval content rendering - #4581

Merged
Mason Daugherty (mdrxy) merged 1 commit into
mainfrom
mdrxy/code/harden-approval-content-rendering
Jul 9, 2026
Merged

fix(code): harden approval content rendering#4581
Mason Daugherty (mdrxy) merged 1 commit into
mainfrom
mdrxy/code/harden-approval-content-rendering

Conversation

@mdrxy

@mdrxy Mason Daugherty (mdrxy) commented Jul 9, 2026

Copy link
Copy Markdown
Member

Closes #4575

Defend against crashes where malformed streamed file-edit tool arguments could break the manual approval screen before the tool call was validated.


The manual approval UI renders tool-call arguments before the filesystem tool schema has a chance to validate them. If a streamed write_file or edit_file call contains malformed non-string content, the approval widgets could call string methods on raw objects and crash the TUI.

This change makes approval rendering defensive by formatting arbitrary raw content into displayable text before line counting, diff generation, or Markdown rendering. Valid string content still passes through unchanged; malformed objects are JSON-formatted when possible and fall back to str() otherwise.

@github-actions github-actions Bot added p0 Critical priority / immediate response dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: S 50-199 LOC labels Jul 9, 2026

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Open SWE Review: No issues found

Open SWE reviewed this PR and found no potential bugs to report.

Open in WebView Open SWE trace

@mdrxy
Mason Daugherty (mdrxy) merged commit 38446fd into main Jul 9, 2026
64 of 66 checks passed
@mdrxy
Mason Daugherty (mdrxy) deleted the mdrxy/code/harden-approval-content-rendering branch July 9, 2026 02:05
Mason Daugherty (mdrxy) added a commit that referenced this pull request Jul 9, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Everything below this line will be the GitHub release body._

---


##
[0.1.35](deepagents-code==0.1.34...deepagents-code==0.1.35)
(2026-07-09)

### Features

* Restore interrupted prompt to input on ESC
([#4544](#4544))
([fccf037](fccf037))
* Add `[startup].mode` default approval mode
([#4573](#4573))
([7c5bf54](7c5bf54))
* Offer restart after saving Tavily key via `/auth`
([#4560](#4560))
([12df81a](12df81a))
* Reload env from `/auth` modal via Ctrl+R
([#4566](#4566))
([f07d638](f07d638))
* Toast on saved `/auth` API key
([#4558](#4558))
([ee3c264](ee3c264))

### Bug Fixes

* Harden approval content rendering
([#4581](#4581))
([38446fd](38446fd))
* Preserve transcript order during virtualization
([#4549](#4549))
([f6ee70c](f6ee70c))
* Run stdio MCP server pre-flight check off the event loop
([#4434](#4434))
([c9636e2](c9636e2))
* Avoid duplicate "criteria ready" message on `/goal` revisions
([#4559](#4559))
([1110497](1110497))
* Restore welcome banner tips
([#4528](#4528))
([3f1e55e](3f1e55e))
* Clarify managed `rg` install failures
([#4578](#4578))
([434c84a](434c84a))
* Dedupe update/install log path output
([#4553](#4553))
([1398fee](1398fee))
* Keep notification center open for API-key entry
([#4568](#4568))
([6e89417](6e89417))
* Queue `/mcp login` sent before the server connects
([#4533](#4533))
([edac82c](edac82c))
* Serialize MCP OAuth token refreshes to prevent reuse revocation
([#4565](#4565))
([c37100d](c37100d))

---

_Everything above this line will be the GitHub release body._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Mason Daugherty <github@mdrxy.com>
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
Closes langchain-ai#4575

Defend against crashes where malformed streamed file-edit tool arguments
could break the manual approval screen before the tool call was
validated.

---

The manual approval UI renders tool-call arguments before the filesystem
tool schema has a chance to validate them. If a streamed `write_file` or
`edit_file` call contains malformed non-string content, the approval
widgets could call string methods on raw objects and crash the TUI.

This change makes approval rendering defensive by formatting arbitrary
raw content into displayable text before line counting, diff generation,
or Markdown rendering. Valid string content still passes through
unchanged; malformed objects are JSON-formatted when possible and fall
back to `str()` otherwise.
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Everything below this line will be the GitHub release body._

---


##
[0.1.35](langchain-ai/deepagents@deepagents-code==0.1.34...deepagents-code==0.1.35)
(2026-07-09)

### Features

* Restore interrupted prompt to input on ESC
([langchain-ai#4544](langchain-ai#4544))
([fccf037](langchain-ai@fccf037))
* Add `[startup].mode` default approval mode
([langchain-ai#4573](langchain-ai#4573))
([7c5bf54](langchain-ai@7c5bf54))
* Offer restart after saving Tavily key via `/auth`
([langchain-ai#4560](langchain-ai#4560))
([12df81a](langchain-ai@12df81a))
* Reload env from `/auth` modal via Ctrl+R
([langchain-ai#4566](langchain-ai#4566))
([f07d638](langchain-ai@f07d638))
* Toast on saved `/auth` API key
([langchain-ai#4558](langchain-ai#4558))
([ee3c264](langchain-ai@ee3c264))

### Bug Fixes

* Harden approval content rendering
([langchain-ai#4581](langchain-ai#4581))
([38446fd](langchain-ai@38446fd))
* Preserve transcript order during virtualization
([langchain-ai#4549](langchain-ai#4549))
([f6ee70c](langchain-ai@f6ee70c))
* Run stdio MCP server pre-flight check off the event loop
([langchain-ai#4434](langchain-ai#4434))
([c9636e2](langchain-ai@c9636e2))
* Avoid duplicate "criteria ready" message on `/goal` revisions
([langchain-ai#4559](langchain-ai#4559))
([1110497](langchain-ai@1110497))
* Restore welcome banner tips
([langchain-ai#4528](langchain-ai#4528))
([3f1e55e](langchain-ai@3f1e55e))
* Clarify managed `rg` install failures
([langchain-ai#4578](langchain-ai#4578))
([434c84a](langchain-ai@434c84a))
* Dedupe update/install log path output
([langchain-ai#4553](langchain-ai#4553))
([1398fee](langchain-ai@1398fee))
* Keep notification center open for API-key entry
([langchain-ai#4568](langchain-ai#4568))
([6e89417](langchain-ai@6e89417))
* Queue `/mcp login` sent before the server connects
([langchain-ai#4533](langchain-ai#4533))
([edac82c](langchain-ai@edac82c))
* Serialize MCP OAuth token refreshes to prevent reuse revocation
([langchain-ai#4565](langchain-ai#4565))
([c37100d](langchain-ai@c37100d))

---

_Everything above this line will be the GitHub release body._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Mason Daugherty <github@mdrxy.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization p0 Critical priority / immediate response size: S 50-199 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dcode crashes on promt to create a JSON file

1 participant