FIX: Handle bio/cyber refusals - #2714
Open
Roman Lutz (romanlutz) wants to merge 1 commit into
Open
Roman Lutz (romanlutz) wants to merge 1 commit into
Roman Lutz (romanlutz) wants to merge 1 commit into
Conversation
Preserve explicit provider refusals through shared content-filter handling and cover SDK HTTP 400 behavior with offline transport tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
| It does not bypass provider safeguards or change attack branching or retry policies. | ||
| Malformed requests, invalid parameters, and schema errors still raise. | ||
|
|
||
| The shared `CONTENT_FILTER_MARKERS` set includes `bio_policy` and `cyber_policy`, both observed |
Contributor
There was a problem hiding this comment.
this seems a bit verbose; I don't think we need a separate doc section for this?
Richard Lundeen (richlundeen)
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Provider HTTP 400 refusals with
bio_policyorcyber_policycurrently propagate as SDK errors instead of being recorded as blocked responses. Add these two codes to the existing shared content-filter markers so callers retain the refusal and its original error details. Malformed requests, invalid parameters, and schema errors still raise; attack branching, retry policies, and provider safeguards are unchanged.bio_policyis listed in the OpenAI Responses API reference. Both codes have explicit handling in OpenAI Codex and HTTP 400 tests that assert no retry. The documentation distinguishes this official client behavior from a universal API contract.Tests and Documentation
tycheck, documentation validation, and the other applicable commit hooks passed. The large-file hook passed independently; only its commit-time invocation was skipped because itsgit check-attrsubprocess fails on Windows.JupyText: N/A; no notebooks or executable documentation examples changed.