What happened?
packages/sdk/src/session.ts:252-258 calls JSON.parse on model-provided args inside the stream loop with no try/catch:
let args = toolCall.args;
if (typeof args === 'string') {
args = JSON.parse(args);
}
A single malformed ToolCallRequest.args string throws inside sendStream(), killing the entire for await loop instead of returning a tool error the model can retry. One bad tool call poisons the whole turn.
What did you expect to happen?
Malformed args should produce a functionResponse error part (model-visible) and continue processing remaining events, matching normal tool-error semantics.
Client information
- Repo:
google-gemini/gemini-cli @ main 9c1b0a610
- Area:
packages/sdk/src/session.ts:252-264
- Platform: source checkout, SDK
sendStream path
Login information
N/A — reproducible with a unit test feeding ToolCallRequest with args: "{bad json".
Anything else we need to know?
Fix direction: wrap in try/catch; on failure push error functionResponse and continue; add session.test.ts malformed-args case asserting stream survives + error part emitted. Also consider length cap on string args before parse.
What happened?
packages/sdk/src/session.ts:252-258callsJSON.parseon model-provided args inside the stream loop with notry/catch:A single malformed
ToolCallRequest.argsstring throws insidesendStream(), killing the entirefor awaitloop instead of returning a tool error the model can retry. One bad tool call poisons the whole turn.What did you expect to happen?
Malformed args should produce a
functionResponseerror part (model-visible) and continue processing remaining events, matching normal tool-error semantics.Client information
google-gemini/gemini-cli@main9c1b0a610packages/sdk/src/session.ts:252-264sendStreampathLogin information
N/A — reproducible with a unit test feeding
ToolCallRequestwithargs: "{bad json".Anything else we need to know?
Fix direction: wrap in
try/catch; on failure push errorfunctionResponseand continue; addsession.test.tsmalformed-args case asserting stream survives + error part emitted. Also consider length cap on string args before parse.