构建与修复 · 录制于 2026 年 9 月 28 日

一个 bug。
一个你可以检查的补丁。

我们给 Grok Build 提供了一个有问题的订单总额函数和明确的验收标准。它返回了一个 JavaScript 模块,我们独立进行了检查。

实际运行 · 隔离的示例代码

起点

下面的函数在累加数值时既不检查支付状态,也不转换字符串。它可能把文本拼接起来,并把已退款订单也计入。

// Bug: adding strings concatenates, refunded orders are counted,
// and rounding uses binary floating point without a currency boundary.
export function paidTotal(orders) {
  return orders.reduce((sum, order) => sum + order.amount, 0);
}

下载输入 · 查看确切的提示词

我们要求了什么

仅统计已支付的记录行。接受非负数或最多两位小数的十进制字符串。以整数分进行求和。拒绝格式错误的值和不安全的总计。列表为空时返回零。

实际输出

Grok 返回了一个解析器和一个替换函数。原始输出保留在下方;我们并未为了通过测试而改写它。

查看完整的生成补丁
// Parse one money amount into integer cents, or throw.
function amountToCents(amount) {
  let text;

  if (typeof amount === "number") {
    // NaN, Infinity, and negatives are invalid amounts.
    if (!Number.isFinite(amount) || amount < 0) {
      throw new TypeError("invalid amount");
    }
    // The amount itself must stay inside the safe integer range.
    if (amount > Number.MAX_SAFE_INTEGER) {
      throw new RangeError("amount overflow");
    }
    text = amount.toString();
    // Exponent form means more than two decimal places.
    if (/[eE]/.test(text)) {
      throw new TypeError("invalid amount");
    }
  } else if (typeof amount === "string") {
    // Plain non-negative decimals only; blank and other text are rejected.
    if (!/^\d+(?:\.\d+)?$/.test(amount)) {
      throw new TypeError("invalid amount");
    }
    text = amount;
  } else {
    throw new TypeError("invalid amount");
  }

  const dot = text.indexOf(".");
  const whole = dot === -1 ? text : text.slice(0, dot);
  const frac = dot === -1 ? "" : text.slice(dot + 1);
  if (frac.length > 2) {
    throw new TypeError("invalid amount");
  }

  const digits = whole.replace(/^0+/, "") || "0";
  if (digits.length > 16) {
    throw new RangeError("amount overflow");
  }
  const dollars = Number(digits);
  if (!Number.isSafeInteger(dollars)) {
    throw new RangeError("amount overflow");
  }

  const centsPart = Number(frac.padEnd(2, "0"));
  // This row's cent value must also be a safe integer.
  if (dollars > Math.floor((Number.MAX_SAFE_INTEGER - centsPart) / 100)) {
    throw new RangeError("amount overflow");
  }
  return dollars * 100 + centsPart;
}

// Sum paid orders in cents and return a currency number.
export function paidTotal(orders) {
  if (!Array.isArray(orders)) {
    throw new TypeError("orders must be an array");
  }

  let totalCents = 0;
  for (const order of orders) {
    // Skip non-paid rows and do not validate their amounts.
    if (!order || order.status !== "paid") {
      continue;
    }

    const cents = amountToCents(order.amount);
    if (totalCents > Number.MAX_SAFE_INTEGER - cents) {
      throw new RangeError("sum overflow");
    }
    totalCents += cents;
  }

  return totalCents / 100;
}

下载生成的 JavaScript

通过的内容

24 项独立编写的检查通过。它们覆盖十进制字符串转换、已退款行、0.1 + 0.2、空输入、无效的已支付金额、非数组输入,以及单个或聚合的安全整数溢出。

node verify.mjs
24 checks passed. Original model output unchanged.

下载验证脚本 · 查看捕获的结果

这不能证明什么

这是一个小型、自成一体的编码任务,并非生产级金融实现,也不是对 Grok 在多个代码仓库中表现的评估。判定标准使用普通十进制字符串,而非本地化货币格式。返回的数值总计仍受 JavaScript 数字表示限制的影响;支付系统应全程保留精确的货币表示。

Grok CLI 使用了其配置的 grok-4.7 模型。其运行元数据报告估计模型成本为 $0.0726;这不是已确认的计费金额,也不包含周边开发工作。

人工工作与设置

我们准备了该缺陷,明确了验收标准并编写了独立检查。建站助手运行了这些检查并审阅了补丁;没有单独的真人审阅者对其进行认证。模型没有部署代码或访问生产系统。要重复该工作流程,请安装 Grok CLI、进行身份验证、提供一个隔离的问题,并审阅生成的 diff 和测试。

Grok 官方网站 ↗ · 对比编程智能体 →