docs(rfd): Add RFD 096 for terminal output sanitization - #856
Merged
Conversation
Propose sanitizing untrusted content (echoed user messages, streamed LLM output, tool results) before it reaches the terminal. Currently, raw escape sequences in that content execute on the user's terminal instead of being displayed, as happened when a pasted `script` log corrupted a user's display and, since messages are stored verbatim, recurred on every replay. The design allowlists benign SGR styling (colors, bold) while dropping cursor, erase, scroll, DEC-mode, and OSC sequences from content, via a new `jp_term::sanitize::Sanitizer` built on the same `vte::Parser` foundation as the existing `AnsiStripper`. A `style.sanitize` config knob (`strip`/`visualize`/`off`) controls the behavior, defaulting to `strip`. OSC embedding (window titles, hyperlinks) is hardened independently by escaping control characters in spliced strings, since conversation titles are LLM-generated and can otherwise terminate an OSC sequence early. Stored conversation data and LLM input remain untouched; this is a display-only concern scoped to the render pipeline. Signed-off-by: Jean Mertz <git@jeanmertz.com>
JeanMertz
force-pushed
the
terminal-output-sanitization
branch
from
July 8, 2026 13:50
dc32b2b to
7831efa
Compare
Signed-off-by: Jean Mertz <git@jeanmertz.com>
Signed-off-by: Jean Mertz <git@jeanmertz.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Propose sanitizing untrusted content (echoed user messages, streamed LLM output, tool results) before it reaches the terminal. Currently, raw escape sequences in that content execute on the user's terminal instead of being displayed, as happened when a pasted
scriptlog corrupted a user's display and, since messages are stored verbatim, recurred on every replay.The design allowlists benign SGR styling (colors, bold) while dropping cursor, erase, scroll, DEC-mode, and OSC sequences from content, via a new
jp_term::sanitize::Sanitizerbuilt on the samevte::Parserfoundation as the existingAnsiStripper. Astyle.sanitizeconfig knob (strip/visualize/off) controls the behavior, defaulting tostrip. OSC embedding (window titles, hyperlinks) is hardened independently by escaping control characters in spliced strings, since conversation titles are LLM-generated and can otherwise terminate an OSC sequence early.Stored conversation data and LLM input remain untouched; this is a display-only concern scoped to the render pipeline.