fix(telegram): sanitize outbound tool traces#95774
Conversation
|
@clawsweeper review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
|
@clawsweeper re-review |
|
Codex review: needs maintainer review before merge. Reviewed June 23, 2026, 7:38 AM ET / 11:38 UTC. Summary PR surface: Source +3, Tests +13. Total +16 across 2 files. Reproducibility: yes. Current main has no Telegram Review metrics: 1 noteworthy metric.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Mantis proof suggestion Risk before merge
Maintainer options:
Next step before merge
Security Review detailsBest possible solution: Keep this as a focused Telegram adapter hook using the canonical sanitizer chain, then merge after maintainer review or optional Telegram visible proof. Do we have a high-confidence way to reproduce the issue? Yes. Current main has no Telegram Is this the best way to solve the issue? Yes. The Telegram outbound adapter is the right owner boundary because the shared delivery pipeline already owns when sanitizer hooks run, and sibling channels use the same canonical sanitizer pattern. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against e856a24754c3. Label changesLabel changes:
Label justifications:
Evidence reviewedPR surface: Source +3, Tests +13. Total +16 across 2 files. View PR surface stats
What I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
Mantis Telegram Desktop ProofSummary: Mantis captured Telegram Desktop before/after GIFs: Main shows the tool failure line, and this PR shows only the final answer.
Motion-trimmed clips: |
f85bb70 to
f3c1115
Compare
|
Landed via rebase onto main.
Thanks @mushuiyu886! |
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit 25490d4)
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214).
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit cd6d0f9)
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit c026546)
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit cd6d0f9)
…penclaw#97360) Wrap the signal outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit c026546)
…penclaw#97372) Wrap the matrix outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit 25490d4)
…enclaw#97367) Wrap the slack outbound sanitizeText hook with sanitizeAssistantVisibleText so assistant internal tool-trace scaffolding is stripped before delivery, matching the sibling channel fixes under openclaw#90684 (Telegram openclaw#95774, Google Chat openclaw#95084, IRC openclaw#97214). (cherry picked from commit cd6d0f9)




Summary
sanitizeTexthook for the shared delivery pipeline to invoke.sanitizeForPlainText(sanitizeAssistantVisibleText(text)).extensions/telegram/src/outbound-adapter.tsnow declaressanitizeText, andextensions/telegram/src/telegram-outbound.test.tslocks in both stripping an internal tool-trace failure line and preserving ordinary assistant prose. The follow-up commit also passes the requiredpayloadargument in those test calls socheck-test-typesmatches the adapter contract.⚠️ 🛠️ ... failedappended to a final reply.Origin / follow-up
Competition / linked PR analysis
telegramOutbound.sanitizeText.Real behavior proof
f85bb708b6. The command imports the actual Telegram outbound adapter production module throughtsxand calls its channel sanitizer hook with the required payload shape.node --import tsx -e 'import { telegramOutbound } from "./extensions/telegram/src/outbound-adapter.ts"; const trace = "Done.\n⚠️ 🛠️ `search \"Pipeline\" in /tmp/openclaw-workspace-* (agent)` failed"; console.log(JSON.stringify({ sanitizedTrace: telegramOutbound.sanitizeText?.({ text: trace, payload: { text: trace } }), ordinary: telegramOutbound.sanitizeText?.({ text: "The pipeline has 3 deals.", payload: { text: "The pipeline has 3 deals." } }) }, null, 2));'{ "sanitizedTrace": "Done.", "ordinary": "The pipeline has 3 deals." }Regression Test Plan
extensions/telegram/src/telegram-outbound.test.ts, with dependency guard coverage fromsrc/infra/outbound/sanitize-text.test.tsandsrc/shared/text/assistant-visible-text.test.ts.Done.plus an assistant-visible tool-trace failure line sanitizes toDone., while ordinary text likeThe pipeline has 3 deals.is preserved exactly.CI failure attribution
check-test-typeson the initial PR head20ea432337.pnpm check:test-types, which failed only in the two newly addedextensions/telegram/src/telegram-outbound.test.tssanitizer assertions because the test calls omitted the requiredpayloadproperty forChannelOutboundAdapter.sanitizeText.payload: { text }.Additional validation
Merge risk
message-deliveryandcompatibility; notauth-provider,session-state,security-boundary, oravailability.Root Cause
sanitizeTextcontract hook, sosrc/infra/outbound/deliver.tscould not run the canonical assistant-visible delivery sanitizer for Telegram before normalized payload delivery. That missing source-of-truth mapping caused internal tool-trace failure text to remain in outbound Telegram text.sanitizeTextatextensions/telegram/src/outbound-adapter.tsfixes the missing source mapping before send instead of masking the symptom later in Telegram send code.ChannelOutboundAdapter.sanitizeTextcontract as implemented by the Telegram plugin adapter; the shared delivery path already consumes that contract before downstream send/payload handling.