Repository navigation
Conversation
a2a-sdk 1.x runs every message of a task in one producer task created by the first request, so follow-up messages saw the first request's contextvars, including BedrockAgentCoreContext and the workload access token. Snapshot contextvars per message in the request context builder and run the executor in that snapshot. Fixes #690
Contributor
✅ No Breaking Changes DetectedNo public API breaking changes found in this PR. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
build_a2a_appandserve_a2aon a2a-sdk 1.x now run each message of a task in the contextvars of the request that sent it.Why
Fixes #690. a2a-sdk 1.x creates one producer task per task id during the first request, and later messages are queued to it. A follow-up message, such as a reply after
input-required, ranexecute()with the first request's contextvars.BedrockAgentCoreContext(workload access token, request and session ids, OAuth2 callback URL, forwarded headers) and any middleware contextvars returned the first request's values. That means@requires_access_tokenand identity propagation used a stale, possibly expired token.No a2a-sdk release fixes this (verified on 1.2.2).
How
_ContextvarsSnapshotRequestContextBuilderwraps a2a'sSimpleRequestContextBuilderand storescontextvars.copy_context()incall_context.statefor every message._PerMessageContextvarsExecutorruns the user'sexecute()in that snapshot, in a child task, so cancellation still reaches it.The snapshot is taken in the request handler and not in
BedrockCallContextBuilder, so it works with a customcontext_builderand with every transport. The a2a-sdk 0.3 path is unchanged because it already runs the executor per request.The ultimate fix belongs upstream:
ActiveTask.enqueue_requestshould capture the sender's context. Filed as a2aproject/a2a-python#1316 with a patch I verified on 1.2.2. Once it lands and our minimum a2a-sdk includes it, both wrapper classes can be deleted.How tested
SendMessageandSendStreamingMessage, checks a middleware contextvar and the workload access token on the follow-up turn. It fails onmainand passes with this change.request-2for turn 2 on a2a-sdk 1.1.2 and 1.2.2, for send and stream.CancelTaskstill cancels the user's executor.