Skip to content

fix(a2a): keep a failed agent's logged URLs only as their scheme and host - #92

Closed
earakely-scale wants to merge 3 commits into
mainfrom
edgararakelyan/redact-agent-log-tail
Closed

earakely-scale wants to merge 3 commits into
mainfrom
edgararakelyan/redact-agent-log-tail

Conversation

@earakely-scale

@earakely-scale earakely-scale commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

When an agent's task fails on a sandbox with docker, fetch_container_logs tails the agent's container logs. Core logs that tail and keeps it with the failed step's error, which is persisted in the run context. An agent that logs the URLs it fetches therefore had its grant and signed URLs stored with the run, credentials and all. OpenCode does this through its HTTP client's request log.

  • agentenv_protocol.transfers.redact_urls(text) cuts each HTTP(S) URL in text to its scheme and host. It is the rule the protocol's httpx log filter already applied to grant requests, now public, and the filter uses it too.
  • fetch_container_logs passes stdout and stderr through it before cutting them to length. Otherwise the cut could leave part of a URL behind with no scheme for the pattern to match. This covers both the solver's and the rubrics judge's failure paths.

Testing

  • Unit:
    • redact_urls on signed, staging and local URLs, leaving the rest of the text alone;
    • fetch_container_logs redacting a URL that the length cut runs through.
  • Integration (fast tier, local agent): the echo agent now prints the text of a fail-with <text> line and fails the task. A local run tells it to log a signed URL and fail. The failed step's persisted error keeps the container-log tail, with the URL cut to its host and no part of its signature or credential left.
  • Mutant checks:
    • main's fetch_container_logs fails the integration test: the full URL is kept;
    • redacting after the cut fails the unit test.
  • Suite: tst/unit + protocol, 6341 passed.
  • Plugin API: no break.
  • On a dev deployment: reran the file-delivery suite from feat(prompt-agent): agents receive store-owned file parts as HTTPS URLs they can read #57 with OpenCode on a VM provider. That's where this was found: its deliberately failing "owned key that doesn't exist" case had one signature in the run context. Now the read cases still pass 9/9. Both failing steps keep their log tails with the URLs redacted, and the stored run holds 0 signatures.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no finding remains outstanding.

What we checked:

  • Later tests can use grants: The next grant starts the closed server again. It gets a certificate from the later test’s state directory.

Summary

Failed-agent container logs now keep URL origins while hiding URL paths and credentials, so signed or temporary links are not retained in failure details.

  • Failed-agent logs keep URL hosts but hide paths and credentials.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
    A[Agent container logs] --> B[Redact HTTP URLs]
    B --> C[Keep the log tail]
    C --> D[Save the failed step error]
Loading

Reviews (2) · Last reviewed commit: "test(a2a): the failure-logs test keeps i..." · Reviewed by Greptile

earakely-scale and others added 2 commits October 6, 2026 22:06
…host

When an agent's task fails on a sandbox with docker, core keeps the tail of the agent's container
logs with the step's error and logs it. An agent that logs the URLs it fetches put grant and
signed URLs there, credentials and all. The tail is now passed through redact_urls, which the
protocol package exposes from the rule its httpx log filter already used, before it is cut to
length, so the cut can't leave part of a URL behind.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…run as its host only

The echo agent prints the text of a `fail-with <text>` line and fails the task, so a local run
shows the container-log tail kept in the failed step's error, with the URL the agent logged cut
to its scheme and host.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@earakely-scale
earakely-scale requested a review from a team as a code owner October 7, 2026 05:11
Comment thread src/agent_env/task_step/task_steps/sandbox_utils/sandbox_utils.py
Comment thread src/agent_env/task_step/task_steps/sandbox_utils/sandbox_utils.py
Comment thread tst/integration/task_step/test_prompt_agent_failure_logs_local.py Outdated
… grant server it used, and fails if the registry never answers

It ran before the file-parts test, which then reached a grant server still serving the first
state root's certificate, and its agents, trusting the new root's CA, couldn't connect.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@earakely-scale

Copy link
Copy Markdown
Collaborator Author

Closing for now: in the last 7 days, none of prod's failed-agent log tails carried a signed URL, so this isn't needed yet. The fix is on branch edgararakelyan/redact-agent-log-tail if it is.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant