fix(a2a): scope A2A_PUBLIC_URL per multiplex profile - #110131
Closed
EloquentBrush0x wants to merge 1 commit into
Closed
EloquentBrush0x wants to merge 1 commit into
EloquentBrush0x wants to merge 1 commit into
Conversation
A2A_PORT and A2A_ADVERTISED_TOOLSETS are already captured at construction time (inside _profile_runtime_scope) via _get_scoped_secret(), but A2A_PUBLIC_URL was still read with a bare os.getenv() inside A2ARequestHandler._request_public_url() - which runs on ThreadingHTTPServer's per-connection OS thread, not the constructing thread. Raw threading.Thread never inherits contextvars, so even swapping the reader to _get_scoped_secret() at that call site would not help: the request thread has no scope, secret_scope falls back to os.environ either way. The value must be captured once at construction time (which does run in profile scope) and threaded through as instance state instead - same fix shape as A2A_PORT above. A secondary multiplex profile without its own A2A_PUBLIC_URL now falls back to the X-Forwarded-Host/Host-derived URL (or the bind host) instead of silently advertising the default profile's public URL in its Agent Card / discovery response. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Collaborator
|
Thanks @EloquentBrush0x — landed on main via #110293 (merge |
This was referenced Sep 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A2A_PORTandA2A_ADVERTISED_TOOLSETSare already captured at construction time (inside_profile_runtime_scope) via_get_scoped_secret(), butA2A_PUBLIC_URLwas still read with a bareos.getenv()insideA2ARequestHandler._request_public_url()— which runs onThreadingHTTPServer's per-connection OS thread, not the constructing thread.threading.Threadnever inherits contextvars, so simply swapping the reader to_get_scoped_secret()at that call site would not have helped: the request thread has no scope installed, soget_scoped_secret()'s internalUnscopedSecretErrorhandling would just fall back toos.environanyway — the value has to be captured once at construction time (which does run in profile scope) and threaded through as instance state, same shape as the existingA2A_PORTfix.A2A_PUBLIC_URLnow falls back to theX-Forwarded-Host/Host-derived URL (or the bind host), instead of silently advertising the default profile's public URL in its Agent Card / discovery response.Scope note: I initially also fixed the analogous
A2A_REPLY_TIMEOUTgap in_await_reply/_rpc_tasks_subscribe, but a fresh competitor check turned up an active, more comprehensive open PR (#91686, "make reply deadline config-native") that already capturesself.reply_timeoutat construction time and fixes the exact same two call sites, plus addsconfig.yaml-native configuration. I dropped that half from this PR to avoid duplicating #91686 — this PR is scoped toA2A_PUBLIC_URLonly.Test plan
TestMultiplexConstructionScopeintests/plugins/test_a2a_plugin.py(the existing scoped-construction test class for this exact adapter) with_public_urlassertions in both directions: a secondary profile's ownA2A_PUBLIC_URLis honored, a secondary profile without one falls back to""(not the default profile's URL), and the unscoped default-profile path still gets its own env value.AttributeError: 'A2AAdapter' object has no attribute '_public_url'.tests/plugins/test_a2a_plugin.py(full suite,-m ""to include normally-deselected slices): 115 passed, no regressions.🤖 Generated with Claude Code