Skip to content

bug(sdk): unguarded JSON.parse on tool-call args kills sendStream (session.ts) #29308

Description

@aniruddhaadak80

What happened?

packages/sdk/src/session.ts:252-258 calls JSON.parse on model-provided args inside the stream loop with no try/catch:

let args = toolCall.args;
if (typeof args === 'string') {
  args = JSON.parse(args);
}

A single malformed ToolCallRequest.args string throws inside sendStream(), killing the entire for await loop instead of returning a tool error the model can retry. One bad tool call poisons the whole turn.

What did you expect to happen?

Malformed args should produce a functionResponse error part (model-visible) and continue processing remaining events, matching normal tool-error semantics.

Client information

  • Repo: google-gemini/gemini-cli @ main 9c1b0a610
  • Area: packages/sdk/src/session.ts:252-264
  • Platform: source checkout, SDK sendStream path

Login information

N/A — reproducible with a unit test feeding ToolCallRequest with args: "{bad json".

Anything else we need to know?

Fix direction: wrap in try/catch; on failure push error functionResponse and continue; add session.test.ts malformed-args case asserting stream survives + error part emitted. Also consider length cap on string args before parse.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/non-interactiveIssues related to GitHub Actions, SDK, 3P Integrations, Shell Scripting, Command line automationeffort/small1 day or less: trivial logic, UI adjustments, docskind/bugpriority/p2Important but can be addressed in a future release.status/bot-triagedstatus/need-information

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions