Skip to content

fix: reject inline math when $ is followed by digit (currency false positive) - #3311

Closed
toanalien wants to merge 1 commit into
nesquena:masterfrom
toanalien:fix/inline-math-currency-false-positive
Closed

toanalien wants to merge 1 commit into
nesquena:masterfrom
toanalien:fix/inline-math-currency-false-positive

Conversation

@toanalien

Copy link
Copy Markdown
Contributor

Summary

  • Fix renderMd() inline math regex falsely matching currency amounts as KaTeX math expressions
  • Text like $1,000 xuống ~$95 was rendered as garbled math instead of literal text
  • Add structural test to guard against regression

Problem

CleanShot 2026-06-01 at 13 23 19@2x

The $...$ inline math regex in renderMd() (static/ui.js:3103) matched $1,000 xuống ~$ as an inline math expression because:

  1. Opening $ followed by 1 satisfied [^\s$\n] (non-space, non-dollar, non-newline)
  2. ,000 xuống matched the middle [^$\n]*?
  3. ~ before closing $ satisfied [^\s$\n]

This caused the $ signs to be consumed, the content between them to render as KaTeX math (italic text with ~ as subscript operator), and 95 to appear detached after the closing delimiter.

The streaming-markdown (smd) library already handles this correctly via its se() function which rejects $ followed by digits. But renderMd() (used for finalized/history messages) lacked this guard.

Fix

Regex change in static/ui.js:

Part Before After
First char after $ [^\s$\n] [^\s$\d\n]
Single-char alternate \S [^\s\d]

Adding \d to the exclusion class rejects math when the first character after $ is a digit (0-9), which is a strong currency signal ($1,000, $50, $99.99).

Legitimate math expressions like $x^2$, $\alpha + \beta$ are unaffected since they start with letters or backslash.

Test plan

  • New structural test: test_inline_math_regex_rejects_digit_after_opening_dollar
  • All 35 tests in test_issue347.py pass
  • All 106 tests in test_renderer_comprehensive.py + test_renderer_js_behaviour.py pass (no regression)
  • Manual test: load a chat session containing $1,000 xuống ~$95 and verify literal rendering

…ositive)

Text like "$1,000 xuống ~$95" was incorrectly parsed as KaTeX inline
math because the renderMd() regex matched $1,000 xuống ~$ as a math
expression. Add \d exclusion to the opening boundary character class,
aligning with smd's se() guard which already rejects $ + digit.
@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Reading the diff at static/ui.js:3098-3106 against origin/master, plus the surrounding renderMd() math-stash block (master static/ui.js:3096-3106), the change is correctly scoped and the root-cause analysis in the description holds up.

What the diff does

// before
s=s.replace(/\$([^\s$\n][^$\n]*?[^\s$\n]|\S)\$/g, ...)
// after
s=s.replace(/\$([^\s$\d\n][^$\n]*?[^\s$\n]|[^\s\d])\$/g, ...)

Adding \d to the opening-boundary class ([^\s$\d\n]) and to the single-char alternate ([^\s\d]) means a $ immediately followed by a digit is no longer eligible to open inline math. For $1,000 xuống ~$95 the opening $1 now fails the first-char class, so the delimiter pair never forms and the text renders literally.

Verification

I checked the two relevant invariants in isolation. The new pattern still matches genuine math and now rejects the currency forms:

"$x$"               -> [MATH:$x$]
"$x^2$"             -> [MATH:$x^2$]
"$\alpha$"          -> [MATH:$\alpha$]
"$5$"               -> $5$         (left literal)
"$1,000 xuống ~$95" -> $1,000 xuống ~$95   (left literal)

So legitimate expressions (letter or backslash after $) are unaffected, which matches the claim in the PR body.

One thing worth calling out

The change also means a bare $5$ no longer renders as math. That is intentional and aligns renderMd() with the streaming-markdown path (se() guard) the description references, so the finalized-history renderer and the live-stream renderer now agree. That is the right call — currency is overwhelmingly more common than single-digit inline math in chat — but it is a real (small) behavior change worth a line in the PR description so a future reader doesn't read it as an accidental regression.

Test

The guard test in tests/test_issue347.py is structural (asserts \d appears in the inline-regex source line) rather than behavioral. That's consistent with the existing test_inline_math_regex_requires_non_space_boundaries style in that file, so it fits. If you wanted stronger coverage, a behavioral case feeding $1,000 ~$95 through the renderer and asserting the literal $ survives would catch a future regex refactor that happens to keep \d in the source but breaks the match — but the structural test is in keeping with the file's conventions and is fine as-is.

Net: minimal, correctly targeted, aligned with the smd renderer. Looks good.

@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Shipped in v0.51.199 (stage-batch11, via #3353). Thanks @toanalien — currency like $1,000 no longer renders as inline math. Note for users who relied on digit-leading inline math: use \(2x = 4\) or $$2x = 4$$ (the $2x$ form is now intentionally rejected, matching smd's se() guard). Opus confirmed the display-math / \(...\) / table-escape paths are all unaffected. 🎉

pull Bot pushed a commit to jw5812018/hermes-webui that referenced this pull request Jun 1, 2026
…h currency

nesquena#3330 Fix pinned chat scroll after message rebuild
Co-authored-by: jianongHe <jianongHe@users.noreply.github.com>

nesquena#3311 fix: reject inline math when $ is followed by a digit (currency)
Co-authored-by: toanalien <toanalien@users.noreply.github.com>
pull Bot pushed a commit to jw5812018/hermes-webui that referenced this pull request Jun 1, 2026
eleboucher pushed a commit to eleboucher/homelab that referenced this pull request Jun 2, 2026
…➔ 0.51.210) (#782)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/nesquena/hermes-webui](https://github.com/nesquena/hermes-webui) | patch | `0.51.197` → `0.51.210` |

---

### Release Notes

<details>
<summary>nesquena/hermes-webui (ghcr.io/nesquena/hermes-webui)</summary>

### [`v0.51.210`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051210--2026-06-02--Release-GD-stage-batch1--model-picker-multi-slash-fix--extensionless-preview-highlighting)

[Compare Source](nesquena/hermes-webui@v0.51.209...v0.51.210)

##### Fixed

- Model picker no longer snaps to the wrong model when multiple multi-slash model IDs from the same proxy provider share the same base name. Exact-match priority in `_findModelInDropdown` and first-segment-only stripping in `_normalizeConfiguredModelKey` / `_norm_model_id` prevent collisions in selection, badge assignment, and configured-entry dedup ([#&#8203;3360](nesquena/hermes-webui#3360), [@&#8203;b3nw](https://github.com/b3nw)).
- Workspace file previews now syntax-highlight common code/config filenames without useful extensions, including `Dockerfile`, `Dockerfile.*`, `Makefile`, `GNUmakefile`, `CMakeLists.txt`, `.gitignore`, and `.dockerignore` ([#&#8203;3365](nesquena/hermes-webui#3365), [@&#8203;AJV20](https://github.com/AJV20)).

### [`v0.51.209`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051209--2026-06-02--Release-GC-WebUI-dashboard-plugin-system-with-iframe-isolation)

[Compare Source](nesquena/hermes-webui@v0.51.208...v0.51.209)

##### Added

- WebUI dashboard plugins: plugins that ship a UI under `~/.hermes/plugins/<name>/dashboard/` (with a `manifest.json`) now appear as opt-in cards in Settings → Plugins (default off). Once enabled, an **Open** button renders the plugin page inside a sandboxed iframe (`sandbox="allow-scripts allow-forms allow-popups"` — no `allow-same-origin`, so plugin JS/CSS/modals stay fully isolated from the parent app). New `/plugins/` (shared assets) and `/dashboard-plugins/<name>/` (per-plugin assets) static routes serve only built `dist/`/`static/` files with path-traversal, dotfile, and extension-allowlist protection (plugin source/config such as `plugin_api.py`/`manifest.json`/`.env` is never served), and both the page and asset routes are gated server-side on the enable state + an HTTP `sandbox` CSP + `nosniff`. Plugin `name` and `tab.path` are validated at load. Display-only — no plugin backend/subprocess execution ([#&#8203;2622](nesquena/hermes-webui#2622), [@&#8203;pix0127](https://github.com/pix0127)).

### [`v0.51.208`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051208--2026-06-02--Release-GB-workspace-upload-hardening-hotfix)

[Compare Source](nesquena/hermes-webui@v0.51.207...v0.51.208)

##### Fixed

- Hardened the workspace file-upload surface ([#&#8203;3104](nesquena/hermes-webui#3104) follow-up): (1) a negative `Content-Length` no longer bypasses the size cap and triggers an unbounded `rfile.read(-1)` — the length is now validated `[0, MAX_UPLOAD_BYTES]` centrally in `parse_multipart` for every upload handler; (2) `.tar`, `.tbz2`, and `.txz` archives now auto-extract (the upload handler's archive-suffix set was narrower than `extract_archive`'s, so those silently landed as raw files); (3) a rejected archive (zip-slip / zip-bomb / corrupt / too-many-members) now surfaces an error toast in the workspace panel instead of a misleading "Uploaded" success; (4) an in-workspace symlink subpath can no longer make the upload target `mkdir`/write outside the workspace root. Regression tests added.

### [`v0.51.207`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051207--2026-06-02--Release-GA-Edge-TTS-as-an-alternative-speech-engine)

[Compare Source](nesquena/hermes-webui@v0.51.206...v0.51.207)

##### Added

- Added an optional server-side **Edge TTS** speech engine (Microsoft neural voices) selectable in Settings → Preferences → TTS Engine, alongside the existing browser speech synthesis. The voice list switches to the Edge neural voices when selected. A new `POST /api/tts` endpoint streams the audio, gated by the same-origin CSRF check + session auth, a per-client rate limit, a 5000-character cap, and a voice allowlist. `edge-tts` is an optional dependency — the endpoint returns a clear install hint (503) when it isn't present, so existing installs are unaffected ([#&#8203;2931](nesquena/hermes-webui#2931), [@&#8203;liuqiangweb-svg](https://github.com/liuqiangweb-svg)).

### [`v0.51.206`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051206--2026-06-02--Release-FZ-workspace-file-upload--drag-and-drop-with-archive-extraction)

[Compare Source](nesquena/hermes-webui@v0.51.205...v0.51.206)

##### Added

- Workspace file panel: an **Upload** button and drag-and-drop that POST to a new `/api/workspace/upload` endpoint. Files land in the session workspace (resolved via the trusted-workspace guard), are de-duplicated with `-1`/`-2` suffixes, and archives (`.zip`/`.tar.*`) are auto-extracted into the target subdirectory with zip-bomb (size-cap + member-count-cap) and zip-slip (path-containment) protections. The extraction size cap is tunable via `HERMES_WEBUI_MAX_EXTRACTED_MB` (defaults to 10× the upload cap). Extraction errors are surfaced to the frontend instead of being silently swallowed, and the archive is removed on failure ([#&#8203;3104](nesquena/hermes-webui#3104), [@&#8203;antoniocarlos97ss](https://github.com/antoniocarlos97ss)).

### [`v0.51.205`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051205--2026-06-01--Release-FY-stage-hi1--workspace-syntax-highlighting--generated-image-cards--manual-title-regeneration)

[Compare Source](nesquena/hermes-webui@v0.51.204...v0.51.205)

##### Added

- Workspace file previews now render with syntax highlighting via Prism.js (already loaded for chat code blocks), covering common languages (Python, JS/TS, CSS, JSON, SQL, shell, and more) and degrading gracefully to plain text for unknown/plain files and when offline. The preview code surface uses a single uniform background across light and dark themes ([#&#8203;3337](nesquena/hermes-webui#3337), [@&#8203;mysoul12138](https://github.com/mysoul12138)).
- Generated local image artifacts now render as a clean inline image (with click-to-zoom lightbox) plus a hover/focus-revealed **Download** action overlaid on the image, served through authenticated `/api/media` URLs — matching the common AI-chat pattern of letting the image be the hero rather than wrapping it in a permanent card ([#&#8203;3220](nesquena/hermes-webui#3220), [@&#8203;AJV20](https://github.com/AJV20)).
- The session action menu can regenerate conversation titles on demand from the saved transcript, updating the sidebar without touching conversation chronology and syncing the new title through to state.db when Insights sync is enabled. The menu was also streamlined to a compact icon + label layout (descriptions move to hover tooltips). Closes [#&#8203;3106](nesquena/hermes-webui#3106) ([#&#8203;3223](nesquena/hermes-webui#3223), [@&#8203;AJV20](https://github.com/AJV20)).

### [`v0.51.204`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051204--2026-06-01--Release-FX-stage-batch17--projectsession-operations-honor-the-sessions-own-profile)

[Compare Source](nesquena/hermes-webui@v0.51.203...v0.51.204)

##### Fixed

- Project and session operations (project create/rename/recolor/delete/unassign, session move, and the profile chip label) now key on the session's own profile (`S.session.profile`) instead of the global active profile, so switching between sessions from different profiles no longer causes silent 404s, misleading chip labels, or project-picker entries from the wrong profile. The project picker also filters to the session's profile and surfaces an error toast on failure instead of a silent no-op ([#&#8203;3331](nesquena/hermes-webui#3331), [@&#8203;PINKIIILQWQ](https://github.com/PINKIIILQWQ)).

### [`v0.51.203`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051203--2026-06-01--Release-FW-stage-batch15--sticky-manual-unpin-for-streaming-chat-scroll)

[Compare Source](nesquena/hermes-webui@v0.51.202...v0.51.203)

##### Changed

- Streaming chat scroll now uses a sticky manual-unpin model: once you scroll up to read earlier content during a streaming response, the view stays put and no longer auto-follows the live tail until you scroll back to the bottom (near-bottom hysteresis on downward motion) or click the scroll-to-bottom control. Tool cards, token updates, and layout growth no longer re-pin the viewport after a reading pause. This replaces the [#&#8203;3250](nesquena/hermes-webui#3250) upward-intent timeout and supersedes the v0.51.199 proximity-re-pin ([#&#8203;3330](nesquena/hermes-webui#3330)), matching the streaming-scroll behavior of ChatGPT/Claude/Codex. Fresh streams reset the follow state on attach ([#&#8203;3343](nesquena/hermes-webui#3343), [@&#8203;pamnard](https://github.com/pamnard)).

### [`v0.51.202`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051202--2026-06-01--Release-FV-stage-batch14--filter-interrupted-recovery-control-text-from-visible-transcript)

[Compare Source](nesquena/hermes-webui@v0.51.201...v0.51.202)

##### Fixed

- Interrupted SSE-recovery control text (the synthetic `stale_interrupted_event` run-journal payload) is now kept out of the visible chat transcript instead of being replayed as a message: it's marked `recovery_control` on the backend and filtered across the `msgContent()` render path, the SSE settle/error handlers, and final transcript filtering, so platform-only control state no longer leaks into the conversation ([#&#8203;3321](nesquena/hermes-webui#3321), [@&#8203;franksong2702](https://github.com/franksong2702)).

### [`v0.51.201`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051201--2026-06-01--Release-FU-stage-batch13--colored-diff-lines-in-tool-card-snippets)

[Compare Source](nesquena/hermes-webui@v0.51.200...v0.51.201)

##### Added

- Tool-card result snippets that contain a unified diff now render with the same green/red/cyan diff coloring already used for diffs in chat messages (reusing the existing `.diff-block` styles), with an expand/collapse toggle that preserves the coloring. Non-diff snippets are unchanged ([#&#8203;3336](nesquena/hermes-webui#3336), [@&#8203;mysoul12138](https://github.com/mysoul12138)).

### [`v0.51.200`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051200--2026-06-01--Release-FT-stage-batch12--remote-gateway-health-probe--ephemeral-turn-field-preservation)

[Compare Source](nesquena/hermes-webui@v0.51.199...v0.51.200)

##### Fixed

- The Tasks/Cron panel no longer shows a spurious "Gateway not configured" banner in multi-container Docker deployments where the WebUI image doesn't ship the `gateway` Python package: agent-health now probes the remote gateway via `HERMES_API_URL` before falling back to the local `gateway.status` import. Closes [#&#8203;3281](nesquena/hermes-webui#3281) ([#&#8203;3312](nesquena/hermes-webui#3312), [@&#8203;Sanjays2402](https://github.com/Sanjays2402)).
- Force-reloading the active session (`loadSession(sid, {forceReload:true})`) no longer drops ephemeral turn fields (`_turnUsage`, `_turnDuration`, `_turnTps`, `_gatewayRouting`, `_statusCard`): the ephemeral-field carry-forward now reads the prior `S.messages` before it's reset, so the token-usage badge and status cards survive an external refresh. Closes [#&#8203;3306](nesquena/hermes-webui#3306) ([#&#8203;3313](nesquena/hermes-webui#3313), [@&#8203;Sanjays2402](https://github.com/Sanjays2402)).

### [`v0.51.199`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051199--2026-06-01--Release-FS-stage-batch11--pinned-scroll-recovery--inline-math-currency-false-positive)

[Compare Source](nesquena/hermes-webui@v0.51.198...v0.51.199)

##### Fixed

- Pinned chat now recovers its scroll position after a DOM rebuild: `_setMessageScrollToBottom` retries on the next layout frame, and `scrollIfPinned` re-pins when the pane has drifted more than 500px from the bottom, so a message-list rebuild no longer leaves a pinned conversation stranded mid-scroll. Closes [#&#8203;3319](nesquena/hermes-webui#3319) ([#&#8203;3330](nesquena/hermes-webui#3330), [@&#8203;jianongHe](https://github.com/jianongHe)).
- The `$...$` inline-math renderer no longer treats currency like `$1,000 xuống ~$95` as math: the opening `$` followed by a digit is now rejected (aligning with smd's `se()` guard), so dollar amounts render as plain text. Digit-leading inline math (e.g. `$2x = 4$`) should now use the LaTeX-style `\(2x = 4\)` or display `$$2x = 4$$` delimiters ([#&#8203;3311](nesquena/hermes-webui#3311), [@&#8203;toanalien](https://github.com/toanalien)).

### [`v0.51.198`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v051198--2026-06-01--Release-FR-stage-batch10--custom-provider-reasoning-model-id-normalize--profile-skill-counts--run-adapter-RFC-slice)

[Compare Source](nesquena/hermes-webui@v0.51.197...v0.51.198)

##### Fixed

- Reasoning-effort detection for named `custom:*` providers now normalizes non-slash model ids before applying its fallback family heuristics, so separator variants such as `deepseek.v3.2`, `deepseek_v4_flash`, and vendor-namespaced ids like `vendor.deepseek.v3.2` resolve the same way as `deepseek-v4-flash`. The keyword fallback is now token-aware rather than substring-based, preserving names like `model-thinking-preview` without falsely enabling reasoning for unrelated prefixes such as `thinkinghub.llama-3.1-70b` ([#&#8203;3327](nesquena/hermes-webui#3327), [@&#8203;Carry00](https://github.com/Carry00)).
- Profile cards now show enabled vs compatible skill counts (computed with an 8s TTL cache that clears on profile switch) instead of a single ambiguous count. Closes [#&#8203;3339](nesquena/hermes-webui#3339) ([#&#8203;3341](nesquena/hermes-webui#3341), [@&#8203;b3nw](https://github.com/b3nw)).

##### Changed

- The [#&#8203;1925](nesquena/hermes-webui#1925) runtime-adapter RFC now marks the configured runner-client boundary as shipped in v0.51.188 ([#&#8203;3073](nesquena/hermes-webui#3073) / [#&#8203;3274](nesquena/hermes-webui#3274)) and defines the next Slice 4g gate for a supervised local runner process harness: real runner-owned `AIAgent` execution, restart/reattach proof, bounded runner health diagnostics, and no new WebUI runtime-surrogate globals ([#&#8203;3334](nesquena/hermes-webui#3334), [@&#8203;Michaelyklam](https://github.com/Michaelyklam)).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/782
SysAdminDoc pushed a commit to SysAdminDoc/hermes-webui that referenced this pull request Jun 26, 2026
…h currency

nesquena#3330 Fix pinned chat scroll after message rebuild
Co-authored-by: jianongHe <jianongHe@users.noreply.github.com>

nesquena#3311 fix: reject inline math when $ is followed by a digit (currency)
Co-authored-by: toanalien <toanalien@users.noreply.github.com>
SysAdminDoc pushed a commit to SysAdminDoc/hermes-webui that referenced this pull request Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants