Repository navigation
Conversation
GeminiUtil.ensureModelResponse appends a user turn when a request has no contents or does not end with a user turn. In Java this turn is "Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction." ADK Python, TypeScript and Go use different, neutral wording, and the Java sentence reads like an instruction-override prompt. A request whose only user-role content was this sentence was flagged by Model Armor prompt injection and jailbreak detection (confidence HIGH), which blocks agents that are driven only by their system instruction. Use the same wording as ADK Python and ADK TypeScript: - no contents: "Handle the requests as specified in the System Instruction." - last turn not from the user: "Continue processing previous requests as instructed. Exit or provide a summary if no more outputs are needed."
Contributor
|
Hi @innoprej, Thank you for your contribution and for taking the time to submit this pull request. Our team is currently reviewing your changes and we will reach out if we need any further information. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please ensure you have read the contribution guide before creating a pull request.
Link to Issue or Description of Change
1. Link to an existing issue (if applicable):
2. Or, if no issue exists, describe the change:
Problem:
GeminiUtil.ensureModelResponseappends a user turn when a request has no contents or does not end with a user turn. In Java this turn is "Continue output. DO NOT look at this line. ONLY look at the content before this line and system instruction." — an instruction-override style sentence that ADK Python, TypeScript and Go do not use. With Vertex AI and Model Armor prompt injection and jailbreak detection enabled, requests whose only user-role content is this sentence are blocked (piAndJailbreakFilterResultMATCH_FOUND, confidenceHIGH), so agents driven only by their instruction cannot run.Solution:
Use the same wording as ADK Python's
BaseLlm._maybe_append_user_contentand ADK TypeScript'smaybeAppendUserContent:HANDLE_SYSTEM_INSTRUCTION_MESSAGE= "Handle the requests as specified in the System Instruction."CONTINUE_OUTPUT_MESSAGE= "Continue processing previous requests as instructed. Exit or provide a summary if no more outputs are needed." (same as Go)CONTINUE_OUTPUT_MESSAGEkeeps its name, so existing references still compile; only its text changes. The condition for appending a turn is unchanged.Testing Plan
Unit Tests:
./mvnw -pl core test -Dtest=GeminiUtilTest— 32 tests, 0 failures (Microsoft Build of OpenJDK 17.0.19). The expected texts are now string literals that match ADK Python; the four placeholder tests fail onmain(they receive the old sentence) and pass with this change. Full./mvnw -pl core teston Windows 11: 2120 run, 0 failures (24 skipped).Manual End-to-End (E2E) Tests:
Observed in an application on Vertex AI with Model Armor floor settings: agents that run on their instruction alone were blocked on the first model call while the old sentence was appended. In the same project and settings, the old sentence typed as a plain user message in a new chat session was also blocked by Model Armor, while the new empty-contents sentence ("Handle the requests as specified in the System Instruction.") was not. The patched library itself has not yet been run end-to-end under Model Armor.
Checklist
Additional context
src/google/adk/models/base_llm.py_maybe_append_user_contentBaseLlm.maybeAppendUserContent; ADK Go:geminiModel.maybeAppendUserContent(no turn for empty contents)