Skip to content

[code-review] matrix mention \\b 边界对以非 word 字符结尾的 localpart 失效:@bot- 等合法 Matrix 用户名被静默吞消息 #2749

Description

@topcheer

文件和行号

问题描述

正则 (?i)@ + QuoteMeta(localPart) + \\b:Go 的 \b 是 ASCII word boundary。Matrix spec localpart 合法字符集为 [a-z0-9._=-+/],可以合法地以 .=-+/ 等非 word 字符结尾(如 bot-、x=、dev+)。此时 localpart 末字符与后随空格/标点两侧均为非 word 字符 → \b 不匹配 → mention 漏检。

复核 subagent 实测(独立 go run 复刻正则):localpart 为 bot-/x=/dev+/a./u/ 时 hasMention=false、stripMention 不剥除;my.bot/al 等以 word 字符结尾的正常。

触发场景

requireMention=true 的非 DM 群聊,用户手打短形式 @bot- 帮我查一下(不带域名)→ hasMention false → 消息静默丢弃(无日志提示);即使通过其他路径,stripMention 同源缺陷剥不掉前缀,@bot- 残留在发给 LLM 的正文里。

缓解:MSC3952 user_ids 元数据、完整 @localpart:domain 展开、DM 路径不受影响——命中集中在手打短形式 + 特殊结尾字符的组合。

预期行为 vs 实际行为

  • 预期:合法 Matrix localpart 的 mention 均被识别
  • 实际:以非 word 字符结尾的 localpart 静默漏检

修复建议

\\b 替换为 localpart 语法边界负向前瞻:(?![a-z0-9._=-+/])(对 word 结尾的 localpart 语义等价于 \b 且更精确,保持 #2719 的 al 不匹配 @alex 初衷)。

严重程度

medium(静默丢消息无 workaround 提示,但主流客户端路径有 MSC3952/完整 MXID 兜底)

(初审 + 独立复核 subagent 双重确认,复核含正则实测复现表)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions