From 10ef3eab1bc1b32d2e3958ad8ad053bb2345880e Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:00:52 +0200 Subject: [PATCH 01/13] test(evals): reproduce ordinary authorization status rejection --- tests/inspection-capture.test.ts | 59 ++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index 9b294a3d..3a5d2165 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -291,3 +291,62 @@ for (const suffix of [ }); }); } + +for (const content of [ + "Separate authorization is required before product repairs.\n", + "Authorization is needed before changing product files.\n", + "Explicit authorization was requested before repair work.\n", + "Authorization is pending for repairs.\n", + "Authorization is granted for the repair task.\n", + "Authorization is denied for deployment.\n", + "Prior authorization was obtained to change product files.\n", + "The authorization is necessary before code modification.\n", + "Authorization is not required before this inspection.\n", + "Authorization was not granted for repairs.\n", + "- Separate authorization is required before product repairs.\n", + "## Repair scope\nSeparate authorization is required before product repairs.\n", + "Separate authorization is required before product repairs.\n\n## Key findings\nThe parser has a defect.\n", + "Separate authorization is required before repairs; authorization is needed to modify code.\n", +]) { + test(`complete permission status is retained ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "observed", + content, + sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + }); + }); +} + +for (const content of [ + "Authorization is required.\n", + "Authorization is opaque-short.\n", + "Authorization is required opaque-short.\n", + "Authorization is required before repairs opaque-short.\n", + "Authorization is required before repairs.opaque-short\n", + "Authorization is required before\nopaque-short.\n", + "Authorization is required before repairs; the token is opaque-short.\n", + "Authorization is required before repairs. The authorization is required.\n", + "Authorization is required before repairs.\n\nThe authorization is opaque-short.\n", + "Authorization is required before repairs.\n\nThe token is opaque-short.\n", + "API_AUTHORIZATION is required before repairs.\n", + "authorizationToken is required before repairs.\n", + "The credential is required before repairs.\n", + '"authorization" is required before repairs.\n', + "`authorization` is required before repairs.\n", + "`Authorization is required before repairs.`\n", + "```text\nAuthorization is required before repairs.\n```\n", + "~~~text\nAuthorization is required before repairs.\n~~~\n", + "````text\n```\nAuthorization is required before repairs.\n````\n", + " Authorization is required before repairs.\n", + "\tAuthorization is required before repairs.\n", + "## Authorization is required before repairs.\n", + "Authorization: is required before repairs.\n", + "Authorization=is required before repairs.\n", +]) { + test(`ambiguous or encoded permission value remains private ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); +} From cc948220364205b6326f366a389f39079ff9a118 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:02:01 +0200 Subject: [PATCH 02/13] test(evals): keep heading authorization statuses private --- tests/inspection-capture.test.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index 3a5d2165..a629c40f 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -340,6 +340,7 @@ for (const content of [ " Authorization is required before repairs.\n", "\tAuthorization is required before repairs.\n", "## Authorization is required before repairs.\n", + "## Repair scope. Authorization is required before repairs.\n", "Authorization: is required before repairs.\n", "Authorization=is required before repairs.\n", ]) { From d5735475a5e340b5c59a35e9fb4f0c424e0a370a Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:02:01 +0200 Subject: [PATCH 03/13] fix(evals): distinguish task permission status from credential values --- evals/harness.ts | 40 ++++++++++++++++++++++++++++++++++++++-- 1 file changed, 38 insertions(+), 2 deletions(-) diff --git a/evals/harness.ts b/evals/harness.ts index f1c9fcc8..37ba0b03 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -381,7 +381,7 @@ const SENSITIVE_DOCUMENT_ASSIGNMENT = const SENSITIVE_DOCUMENT_FIELD_NAME = /\b(?:[A-Za-z_][A-Za-z0-9_-]*?)?(?:token|password|passwd|secret|key|authorization|credential)[A-Za-z0-9_-]*\b/i; const SENSITIVE_DOCUMENT_DISCLOSURE = - /(?:^|[\s"'`{,])(?:[A-Za-z_][A-Za-z0-9_-]*?)?(?:token|password|passwd|secret|key|authorization|credential)[A-Za-z0-9_-]*\s*["'`]?\s+(?:is|was|are|were|equals?|contains?)\s+["'`]?[\S]+/im; + /(?:^|[\s"'`{,])((?:[A-Za-z_][A-Za-z0-9_-]*?)?(?:token|password|passwd|secret|key|authorization|credential)[A-Za-z0-9_-]*)\s*["'`]?\s+((?:is|was|are|were|equals?|contains?)\s+["'`]?[\S]+)/gim; const SENSITIVE_INLINE_ASSIGNMENT = /(?:token|password|passwd|secret|key|authorization)\s*=/i; @@ -403,8 +403,44 @@ function documentPrefixHasCodeFence(prefix: string): boolean { return fence !== null; } +function isPermissionStatusClause( + content: string, + fieldStart: number, + predicateStart: number, +): boolean { + const lineStart = content.lastIndexOf("\n", fieldStart) + 1; + const linePrefix = content.slice(lineStart, fieldStart); + const prefix = linePrefix.split(/[.;!?](?=\s|$)/).at(-1) ?? ""; + if ( + /[`"']/.test(linePrefix) || + /^(?: {4}|\t)/.test(linePrefix) || + /^ {0,3}#{1,6}\s/.test(linePrefix) || + documentPrefixHasCodeFence(content.slice(0, fieldStart)) || + !/^\s*(?:[-*+]\s+)?(?:(?:the|this|separate|explicit|prior|additional|user|human)\s+)*$/i.test( + prefix, + ) + ) + return false; + const remainder = content.slice(predicateStart); + const boundary = remainder.search(/[;.!?](?=\s|$)|\r?\n/); + const predicate = ( + boundary < 0 ? remainder : remainder.slice(0, boundary) + ).trim(); + return /^(?:is|was|are|were)\s+(?:not\s+)?(?:required|needed|necessary|pending|requested|granted|denied|obtained)\s+(?:before|for|to)\s+(?:(?:(?:the|this|product|code|test|gate)\s+)*(?:repairs?|inspection|review|modification|deployment)(?:\s+(?:work|task))?|(?:repair(?:ing)?|inspect(?:ing)?|review(?:ing)?|modify|modifying|change|changing|deploy(?:ing)?)\s+(?:(?:the|this|product|code|test|gate)\s+)*(?:files|code|product|tests|gate))$/i.test( + predicate, + ); +} + function hasSensitiveDocumentAssignment(content: string): boolean { - if (SENSITIVE_DOCUMENT_DISCLOSURE.test(content)) return true; + for (const match of content.matchAll(SENSITIVE_DOCUMENT_DISCLOSURE)) { + const fieldStart = match.index + match[0].indexOf(match[1] ?? ""); + const predicateStart = match.index + match[0].lastIndexOf(match[2] ?? ""); + if ( + match[1]?.toLowerCase() !== "authorization" || + !isPermissionStatusClause(content, fieldStart, predicateStart) + ) + return true; + } for (const match of content.matchAll(SENSITIVE_DOCUMENT_ASSIGNMENT)) { const keyStart = match.index + match[0].indexOf(match[1] ?? ""); const prefix = content.slice( From 6ab90961f3df3150f643b09e3c66e577459fba30 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:06:30 +0200 Subject: [PATCH 04/13] test(evals): protect indented permission predicate context --- tests/inspection-capture.test.ts | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index a629c40f..bec710f8 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -294,6 +294,7 @@ for (const suffix of [ for (const content of [ "Separate authorization is required before product repairs.\n", + "Authorization\nis required before repairs.\n", "Authorization is needed before changing product files.\n", "Explicit authorization was requested before repair work.\n", "Authorization is pending for repairs.\n", @@ -339,6 +340,8 @@ for (const content of [ "````text\n```\nAuthorization is required before repairs.\n````\n", " Authorization is required before repairs.\n", "\tAuthorization is required before repairs.\n", + "Authorization\n is required before repairs.\n", + "Authorization\n\tis required before repairs.\n", "## Authorization is required before repairs.\n", "## Repair scope. Authorization is required before repairs.\n", "Authorization: is required before repairs.\n", From b279c68de2019527c202f44a5671b4a9031bd6c0 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:06:30 +0200 Subject: [PATCH 05/13] fix(evals): reject indented permission predicates --- evals/harness.ts | 3 +++ 1 file changed, 3 insertions(+) diff --git a/evals/harness.ts b/evals/harness.ts index 37ba0b03..b5324de9 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -410,10 +410,13 @@ function isPermissionStatusClause( ): boolean { const lineStart = content.lastIndexOf("\n", fieldStart) + 1; const linePrefix = content.slice(lineStart, fieldStart); + const predicateLineStart = content.lastIndexOf("\n", predicateStart) + 1; + const predicateLinePrefix = content.slice(predicateLineStart, predicateStart); const prefix = linePrefix.split(/[.;!?](?=\s|$)/).at(-1) ?? ""; if ( /[`"']/.test(linePrefix) || /^(?: {4}|\t)/.test(linePrefix) || + /^(?: {4}|\t)/.test(predicateLinePrefix) || /^ {0,3}#{1,6}\s/.test(linePrefix) || documentPrefixHasCodeFence(content.slice(0, fieldStart)) || !/^\s*(?:[-*+]\s+)?(?:(?:the|this|separate|explicit|prior|additional|user|human)\s+)*$/i.test( From db491fb93430990510f899205142d1d6168fa937 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:10:58 +0200 Subject: [PATCH 06/13] test(evals): reproduce mixed tab permission indentation --- tests/inspection-capture.test.ts | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index bec710f8..64978c99 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -354,3 +354,29 @@ for (const content of [ }); }); } + +for (const spaces of [0, 1, 2, 3]) { + for (const content of [ + `${" ".repeat(spaces)}\tAuthorization is required before repairs.\n`, + `Authorization\n${" ".repeat(spaces)}\tis required before repairs.\n`, + ]) { + test(`tab-indented permission context remains private ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + } + for (const content of [ + `${" ".repeat(spaces)}Authorization is required before repairs.\n`, + `Authorization\n${" ".repeat(spaces)}is required before repairs.\n`, + ]) { + test(`ordinary prose indentation retains permission context ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "observed", + content, + sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + }); + }); + } +} From 5eaae8801cc0bb29e93d583631dbe63b80c7bf49 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:10:58 +0200 Subject: [PATCH 07/13] fix(evals): keep mixed tab indentation outside prose permission --- evals/harness.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/evals/harness.ts b/evals/harness.ts index b5324de9..065cc938 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -415,8 +415,8 @@ function isPermissionStatusClause( const prefix = linePrefix.split(/[.;!?](?=\s|$)/).at(-1) ?? ""; if ( /[`"']/.test(linePrefix) || - /^(?: {4}|\t)/.test(linePrefix) || - /^(?: {4}|\t)/.test(predicateLinePrefix) || + /^(?: {4}| {0,3}\t)/.test(linePrefix) || + /^(?: {4}| {0,3}\t)/.test(predicateLinePrefix) || /^ {0,3}#{1,6}\s/.test(linePrefix) || documentPrefixHasCodeFence(content.slice(0, fieldStart)) || !/^\s*(?:[-*+]\s+)?(?:(?:the|this|separate|explicit|prior|additional|user|human)\s+)*$/i.test( From 23a3e3bab0500274efc759aa93d3ba49a5448751 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:21:44 +0200 Subject: [PATCH 08/13] test(evals): cover permission capture across Markdown line endings --- tests/inspection-capture.test.ts | 64 +++++++++++++++++++++++++------- 1 file changed, 51 insertions(+), 13 deletions(-) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index 64978c99..373807f1 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -355,27 +355,65 @@ for (const content of [ }); } -for (const spaces of [0, 1, 2, 3]) { - for (const content of [ - `${" ".repeat(spaces)}\tAuthorization is required before repairs.\n`, - `Authorization\n${" ".repeat(spaces)}\tis required before repairs.\n`, - ]) { - test(`tab-indented permission context remains private ${content}`, async () => { - expect(await observe(content)).toEqual({ +for (const lineEnding of ["\n", "\r\n", "\r"]) { + for (const spaces of [0, 1, 2, 3]) { + for (const content of [ + `Repair scope${lineEnding}${" ".repeat(spaces)}\tAuthorization is required before repairs.${lineEnding}`, + `Authorization${lineEnding}${" ".repeat(spaces)}\tis required before repairs.${lineEnding}`, + ]) { + test(`tab-indented permission context remains private ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + } + for (const content of [ + `Repair scope${lineEnding}${" ".repeat(spaces)}Authorization is required before repairs.${lineEnding}`, + `Authorization${lineEnding}${" ".repeat(spaces)}is required before repairs.${lineEnding}`, + ]) { + test(`ordinary prose indentation retains permission context ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "observed", + content, + sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + }); + }); + } + } + for (const fence of ["```", "~~~"]) { + const encoded = `${fence}text${lineEnding}Authorization is required before repairs.${lineEnding}${fence}${lineEnding}`; + test(`active fence permission remains private ${encoded}`, async () => { + expect(await observe(encoded)).toEqual({ kind: "unavailable", reason: "review-document-not-safe-to-retain", }); }); + const prose = `${fence}text${lineEnding}Ordinary example.${lineEnding}${fence}${lineEnding}Authorization is required before repairs.${lineEnding}`; + test(`closed fence permits ordinary permission prose ${prose}`, async () => { + expect(await observe(prose)).toEqual({ + kind: "observed", + content: prose, + sha256: `sha256:${createHash("sha256").update(prose).digest("hex")}`, + }); + }); } + const content = `Authorization is required before repairs${lineEnding}Next action.${lineEnding}`; + test(`physical line ends the permission predicate ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "observed", + content, + sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + }); + }); for (const content of [ - `${" ".repeat(spaces)}Authorization is required before repairs.\n`, - `Authorization\n${" ".repeat(spaces)}is required before repairs.\n`, + `Authorization${lineEnding} is required before repairs.${lineEnding}`, + `Repair scope${lineEnding} Authorization is required before repairs.${lineEnding}`, ]) { - test(`ordinary prose indentation retains permission context ${content}`, async () => { + test(`space-indented permission context remains private ${content}`, async () => { expect(await observe(content)).toEqual({ - kind: "observed", - content, - sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + kind: "unavailable", + reason: "review-document-not-safe-to-retain", }); }); } From a702377c06acffa0c33bbcffe946619294aa3f4e Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:22:02 +0200 Subject: [PATCH 09/13] fix(evals): parse permission context with Markdown line endings --- evals/harness.ts | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/evals/harness.ts b/evals/harness.ts index 065cc938..23b18c16 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -408,9 +408,17 @@ function isPermissionStatusClause( fieldStart: number, predicateStart: number, ): boolean { - const lineStart = content.lastIndexOf("\n", fieldStart) + 1; + const lineStart = + Math.max( + content.lastIndexOf("\n", fieldStart), + content.lastIndexOf("\r", fieldStart), + ) + 1; const linePrefix = content.slice(lineStart, fieldStart); - const predicateLineStart = content.lastIndexOf("\n", predicateStart) + 1; + const predicateLineStart = + Math.max( + content.lastIndexOf("\n", predicateStart), + content.lastIndexOf("\r", predicateStart), + ) + 1; const predicateLinePrefix = content.slice(predicateLineStart, predicateStart); const prefix = linePrefix.split(/[.;!?](?=\s|$)/).at(-1) ?? ""; if ( @@ -418,14 +426,16 @@ function isPermissionStatusClause( /^(?: {4}| {0,3}\t)/.test(linePrefix) || /^(?: {4}| {0,3}\t)/.test(predicateLinePrefix) || /^ {0,3}#{1,6}\s/.test(linePrefix) || - documentPrefixHasCodeFence(content.slice(0, fieldStart)) || + documentPrefixHasCodeFence( + content.slice(0, fieldStart).replace(/\r\n?/g, "\n"), + ) || !/^\s*(?:[-*+]\s+)?(?:(?:the|this|separate|explicit|prior|additional|user|human)\s+)*$/i.test( prefix, ) ) return false; const remainder = content.slice(predicateStart); - const boundary = remainder.search(/[;.!?](?=\s|$)|\r?\n/); + const boundary = remainder.search(/[;.!?](?=\s|$)|[\r\n]/); const predicate = ( boundary < 0 ? remainder : remainder.slice(0, boundary) ).trim(); From 797dc79a5d1c2ccbcfd4e90d61509e1254b8a4ff Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:33:43 +0200 Subject: [PATCH 10/13] test(evals): reproduce quoted permission retention --- tests/inspection-capture.test.ts | 62 ++++++++++++++++++++++++++++++++ 1 file changed, 62 insertions(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index 373807f1..10475c42 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -418,3 +418,65 @@ for (const lineEnding of ["\n", "\r\n", "\r"]) { }); } } + +for (const lineEnding of ["\n", "\r\n", "\r"]) { + const markers = [ + ...([0, 1, 2, 3] as const).map((spaces) => `${" ".repeat(spaces)}> `), + ">> ", + "> > ", + "- > ", + "1. > ", + "1. - > ", + ]; + for (const marker of markers) { + for (const content of [ + `${marker}Status. Authorization is required before repairs.${lineEnding}`, + `${marker}Status.${lineEnding}Authorization is required before repairs.${lineEnding}`, + ]) { + test(`quoted permission paragraph remains private ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + } + } + for (const separator of [ + lineEnding, + `>${lineEnding}`, + `## Repair scope${lineEnding}`, + ]) { + const content = `> Status.${lineEnding}${separator}Authorization is required before repairs.${lineEnding}`; + test(`permission prose outside a quoted paragraph is retained ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "observed", + content, + sha256: `sha256:${createHash("sha256").update(content).digest("hex")}`, + }); + }); + } + for (const spaces of [0, 1, 2, 3]) { + const content = `> Status.${lineEnding}${" ".repeat(spaces)}Authorization is required before repairs.${lineEnding}`; + test(`partial plain prefix remains in its lazy quote ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + } + const quoted = `> Authorization is required before repairs.${lineEnding}`; + test(`partial quote marker remains private ${quoted}`, async () => { + expect(await observe(quoted)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + const ordinary = `> Status.${lineEnding}- Authorization is required before repairs.${lineEnding}`; + test(`new list interrupts the quoted paragraph ${ordinary}`, async () => { + expect(await observe(ordinary)).toEqual({ + kind: "observed", + content: ordinary, + sha256: `sha256:${createHash("sha256").update(ordinary).digest("hex")}`, + }); + }); +} From d23dbfb94b8b2d3aa075129df9aa885b81036138 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:34:26 +0200 Subject: [PATCH 11/13] fix(evals): exclude quoted permission paragraphs from capture --- evals/harness.ts | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/evals/harness.ts b/evals/harness.ts index 23b18c16..2fe2655d 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -403,6 +403,29 @@ function documentPrefixHasCodeFence(prefix: string): boolean { return fence !== null; } +function documentPrefixHasBlockQuote(prefix: string): boolean { + const lines = prefix.split(/\r\n?|\n/); + const current = lines.pop() ?? ""; + const quotePrefix = /^ {0,3}(?:(?:[-*+]|\d{1,9}[.)])[ \t]+)*(?:>[ \t]*)+/; + let quotedParagraph = false; + for (const line of lines) { + const quote = quotePrefix.exec(line); + if (quote) { + quotedParagraph = line.slice(quote[0].length).trim() !== ""; + } else if ( + !line.trim() || + /^ {0,3}(?:#{1,6}(?:[ \t]|$)|(?:[-*+]|1[.)])[ \t]+\S)/.test(line) + ) { + quotedParagraph = false; + } + } + if (quotePrefix.test(current)) return true; + return ( + quotedParagraph && + !/^ {0,3}(?:#{1,6}[ \t]|(?:[-*+]|1[.)])[ \t]+)/.test(current) + ); +} + function isPermissionStatusClause( content: string, fieldStart: number, @@ -422,6 +445,7 @@ function isPermissionStatusClause( const predicateLinePrefix = content.slice(predicateLineStart, predicateStart); const prefix = linePrefix.split(/[.;!?](?=\s|$)/).at(-1) ?? ""; if ( + documentPrefixHasBlockQuote(content.slice(0, fieldStart)) || /[`"']/.test(linePrefix) || /^(?: {4}| {0,3}\t)/.test(linePrefix) || /^(?: {4}| {0,3}\t)/.test(predicateLinePrefix) || From 513f2ef038e60d4cb20577785c51fb0e76a58546 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:37:53 +0200 Subject: [PATCH 12/13] test(evals): cover quote markers inside closed code fences --- tests/inspection-capture.test.ts | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/tests/inspection-capture.test.ts b/tests/inspection-capture.test.ts index 10475c42..79c81122 100644 --- a/tests/inspection-capture.test.ts +++ b/tests/inspection-capture.test.ts @@ -480,3 +480,27 @@ for (const lineEnding of ["\n", "\r\n", "\r"]) { }); }); } + +for (const lineEnding of ["\n", "\r\n", "\r"]) { + for (const fence of ["```", "~~~"]) { + const closed = `${fence}text${lineEnding}> shell output${lineEnding}${fence}${lineEnding}Authorization is required before repairs.${lineEnding}`; + test(`quote-like code cannot taint prose after its closed fence ${closed}`, async () => { + expect(await observe(closed)).toEqual({ + kind: "observed", + content: closed, + sha256: `sha256:${createHash("sha256").update(closed).digest("hex")}`, + }); + }); + for (const content of [ + `${fence}text${lineEnding}> shell output${lineEnding}Authorization is required before repairs.${lineEnding}`, + `> Status.${lineEnding}> ${fence}${lineEnding}Authorization is required before repairs.${lineEnding}`, + ]) { + test(`active code or quoted fence content remains private ${content}`, async () => { + expect(await observe(content)).toEqual({ + kind: "unavailable", + reason: "review-document-not-safe-to-retain", + }); + }); + } + } +} From fd1749177d9e05d6e9e2795479872eadcdb36f21 Mon Sep 17 00:00:00 2001 From: vriesd Date: Fri, 9 Oct 2026 18:37:54 +0200 Subject: [PATCH 13/13] fix(evals): reset quoted paragraph state at code fence boundaries --- evals/harness.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/evals/harness.ts b/evals/harness.ts index 2fe2655d..ff8851a2 100644 --- a/evals/harness.ts +++ b/evals/harness.ts @@ -414,6 +414,7 @@ function documentPrefixHasBlockQuote(prefix: string): boolean { quotedParagraph = line.slice(quote[0].length).trim() !== ""; } else if ( !line.trim() || + /^ {0,3}(?:`{3,}|~{3,})/.test(line) || /^ {0,3}(?:#{1,6}(?:[ \t]|$)|(?:[-*+]|1[.)])[ \t]+\S)/.test(line) ) { quotedParagraph = false;