From ae4cbd78c24fd18c5dd3a7ec63ef1ab493c5c656 Mon Sep 17 00:00:00 2001 From: Rudy Celekli <47457359+rudycelekli@users.noreply.github.com> Date: Tue, 6 Oct 2026 10:03:21 -0400 Subject: [PATCH] fix(questions): verify provider answer question identities Signed-off-by: Rudy Celekli <47457359+rudycelekli@users.noreply.github.com> --- src/benchmark_radar/questions.py | 2 ++ tests/test_questions.py | 23 +++++++++++++++++++++++ 2 files changed, 25 insertions(+) diff --git a/src/benchmark_radar/questions.py b/src/benchmark_radar/questions.py index 023f3a0a..07afcdfa 100644 --- a/src/benchmark_radar/questions.py +++ b/src/benchmark_radar/questions.py @@ -420,6 +420,8 @@ def _validate( for answer, question in zip(answers, group["questions"], strict=True): if not isinstance(answer, dict): raise BriefingError("OpenAI returned a malformed answer") + if answer.get("question") != question: + raise BriefingError("OpenAI returned an answer for a different question") unknown_stats = [ stat_id for stat_id in answer.get("stat_ids") or [] if stat_id not in stats_by_id ] diff --git a/tests/test_questions.py b/tests/test_questions.py index 4b8ee13f..57343257 100644 --- a/tests/test_questions.py +++ b/tests/test_questions.py @@ -578,3 +578,26 @@ def fake_translate(url, payload, **kwargs): for a in answers ) assert result["zh_translation"]["response_id"] == "resp_zh" + + +def test_daily_questions_rejects_provider_answers_bound_to_wrong_questions(monkeypatch): + current = snapshot_for_run(_run([_item(1), _item(2)])) + + def post_json(url, payload, **kwargs): + packet = json.loads(payload["input"]) + answers = [ + _answer(question=question, signal="Captured records need review.") + for question in reversed(packet["questions"]) + ] + return { + "output": [ + { + "type": "message", + "content": [{"type": "output_text", "text": json.dumps({"answers": answers})}], + } + ] + } + + monkeypatch.setattr(questions, "post_json", post_json) + with pytest.raises(BriefingError, match="question"): + questions.generate_daily_questions([], current, [], "test-key")