Skip to content

Enforce user-role canonicalization on runner inbound messages - #7143

Open
AUTHENSOR wants to merge 1 commit into
google:mainfrom
AUTHENSOR:fix/runner-inbound-role-canonicalization
Open

AUTHENSOR wants to merge 1 commit into
google:mainfrom
AUTHENSOR:fix/runner-inbound-role-canonicalization

Conversation

@AUTHENSOR

Copy link
Copy Markdown

Fixes #7142.

The A2A converter already canonicalizes inbound roles to user (the fencing/forced-user family). This applies the same rule at the runner inbound boundary: a caller-chosen Content.role is not preserved into the provider call, closing the unfixed sibling documented in #7142 (including the session-restore author bypass of fencing).

Patch is 5 lines mirroring the converter rule; the applied test flips the splice cells (P1/P2) to held while the restore seam is left open for maintainer design (per the issue).

…oogle#7142)

Apply the same forced-user rule the A2A converter already uses to
Runner inbound new_message content: a caller-supplied role must not
survive into the provider call, and session-restore must not accept
arbitrary authors that bypass fencing.
@google-cla

google-cla Bot commented Sep 16, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Runner.run_async keeps a caller-chosen Content.role on inbound messages; only the A2A route canonicalizes roles

2 participants