llama.cpp Jinja input marking is_input special-token injection defence

Parent: Mac local LLMs: llama.cpp internals · Published reference · snapshot 2026-10-05

↓ Facts as markdownall context files

`common/chat-auto-parser.h` defaults `mark_input = true` and `common/chat.cpp` passes it to `global_from_json`, so the Jinja side marks input strings.

These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.

Facts

Children

← the whole tree · 3D view· how to read this page