Repository navigation
Bound A2A unary RPC errors so remote HTTP bodies cannot enter tool envelopes - #360
Merged
Merged
Conversation
…velopes Client::rpc concatenated the entire non-200 response body into err_out. /a2a call copies that string into the calling agent's tool result, so a verbose or hostile remote could dump unbounded HTML/JSON (and any secrets it echoed) into conversation history. Report HTTP <status> plus a 200-byte single-line JSON-RPC error.message when present. Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
This was referenced Sep 20, 2026
…r-bound # Conflicts: # CHANGELOG.md
tylerreckart
marked this pull request as ready for review
September 21, 2026 12:58
tylerreckart
enabled auto-merge (squash)
September 21, 2026 12:58
Keep both Unreleased changelog bullets: A2A unary HTTP error bounding and the already-landed --connect base URL query/userinfo reject (#366). Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
Main landed the LaTeX recursion-depth and key-file O_NOFOLLOW notes alongside this PR's A2A unary HTTP error bound. Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
…r-bound # Conflicts: # CHANGELOG.md
Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
…r-bound Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Client::rpcconcatenated the entire non-200 HTTP body intoerr_out:/a2a call(the production outbound path viamake_a2a_invoker→send_message) copies that string into the calling agent's tool envelope. A verbose or hostile remote can return megabytes of HTML/JSON — stack traces, echoed cookies, login pages — which then persist in conversation history and are visible to the model. JSON-RPCerror.messageon HTTP 200 was similarly unbounded and could contain CR/LF.This is the same class as provider-error sanitization on the inbound/delegation paths (#311 / #321), for the outbound A2A client.
Fix
format_rpc_http_errorreportsHTTP <status>plus a JSON-RPCerror.message(or top-level stringerror) when the body is JSON.sanitize_rpc_error_textdrops CR/LF/NUL/other ASCII controls and UTF-8-safely truncates at 200 bytes.format_rpc_json_error.src/a2a/types.cpp+include/a2a/types.h+src/a2a/client.cpp+tests/test_a2a.cpp.Tests
unit_a2a:HTTP 500/HTTP 502/HTTP 401with no body leak.{"error":"…"}keep a short detail.Suite 29/29 locally (215 assertions) + ASan + UBSan.
arbitercompiles.Independently mergeable against
main(0456350).git merge-tree --write-treevs #321, #326, #331, #342, #351, #354, #358, and #359 is CLEAN. Do not re-fix #321–#359.Note
Medium Risk
Changes what agents see on A2A failures (shorter, sanitized errors) but reduces risk of unbounded or sensitive remote content entering persisted conversation history.
Overview
Outbound A2A unary RPC errors are capped so hostile or verbose remotes cannot flood agent tool results and conversation history.
Client::rpcpreviously builterr_outasHTTP <status>: <full body>;/a2a callforwards that string into the caller’s tool envelope. Non-200 responses now useformat_rpc_http_error: status only when the body is plain HTML/text, or status plus a parsed JSON-RPCerror.message(or top-level string"error") when the body is JSON. HTTP 200 JSON-RPC failures go throughformat_rpc_json_errorwith the same rules.Shared
sanitize_rpc_error_textstrips CR/LF and other controls, normalizes tabs, and UTF-8–safely truncates at 200 bytes (kMaxRpcErrorDetail). Helpers live intypes.h/types.cppsounit_a2acan test bounds without the HTTP client. CHANGELOG documents the fix;test_a2acovers HTML omission, JSON detail retention, control stripping, and truncation.Reviewed by Cursor Bugbot for commit 0fc19c0. Bugbot is set up for automated code reviews on this repo. Configure here.