[Bug]: REST transport: getTask builds an invalid URL for single-digit historyLength
维护者通常 1 天内回复
@014-code 已经在做这个了。
开始于 2026年10月2日。
评估
调研方向
从 client/transport/rest/src/main/java/io/a2aproject/a2a/client/transport/rest/RestTransport.java 中的 getTask 开始,检查 URL 格式化。使用一位数的 historyLength(例如 5)运行 RestTransportTest.testGetTask,然后添加回归测试覆盖,以表明生成的 URI 有效且查询没有填充;如果相关格式字符串包含在此次更改中,则将其规范化。
由索引模型根据 Issue 内容生成。
描述
What happened?
Summary
RestTransport.getTask builds the request URL with a String.format pattern that uses width specifiers (%2d) where argument-index specifiers (%2$d) were intended. For a single-digit historyLength (0–9), %2d left-pads the value with a space, producing historyLength= 5. A raw space is illegal in a URI, so java.net.URI.create(...) throws IllegalArgumentException: Illegal character in query, and the getTask call fails before any request is sent.
Affected code
client/transport/rest/src/main/java/io/a2a/client/transport/rest/RestTransport.java, in getTask:
url.append(String.format("/tasks/%1s?historyLength=%2d", taskQueryParams.id(), taskQueryParams.historyLength()));
In Java format syntax, an argument index requires a trailing $ (%2$d). Without it, %2d means "decimal, minimum width 2", and %1s means "string, minimum width 1" — these are width fields, not argument references. The %1s on the id is harmless only by accident (a UUID is always wider than 1, so nothing is padded); the %2d on the integer pads any single-digit value.
Reproduction
String.format("/tasks/%1s?historyLength=%2d", "de38c76d-d54c-436c-8b9f-4c2703648d64", 5);
// => "/tasks/de38c76d-d54c-436c-8b9f-4c2703648d64?historyLength= 5"
// ^ stray space
URI.create("https://host/tasks/de38c76d-d54c-436c-8b9f-4c2703648d64?historyLength= 5");
// => java.lang.IllegalArgumentException: Illegal character in query at index N: ...historyLength= 5
Behavior by value:
| historyLength | formatted query | valid URI? |
|---|---|---|
| 1–9 | historyLength= N (leading space) |
❌ |
| 0 | n/a — getTask skips the query when historyLength <= 0 |
✅ |
| ≥ 10 | historyLength=NN |
✅ |
So any getTask call with historyLength in 1–9 fails. This is the common case (clients typically request a small history window), which makes the practical impact high.
Why existing tests don't catch it
RestTransportTest.testGetTask uses new TaskQueryParams("...", 10) — a two-digit value that satisfies the width-2 field, so no space is injected and the URL stays valid. Single-digit values are never exercised.
Suggested fix
Drop the width (preferred) or use real positional indices:
// simplest
url.append(String.format("/tasks/%s?historyLength=%d", taskQueryParams.id(), taskQueryParams.historyLength()));
// or, if explicit indices are desired
url.append(String.format("/tasks/%1$s?historyLength=%2$d", taskQueryParams.id(), taskQueryParams.historyLength()));
Also recommend adding a regression test that calls getTask with a single-digit historyLength (e.g. 5) and asserts the resulting URL/query is well-formed.
Related occurrences (same specifier mistake, latent)
The same %Ns width-vs-index pattern appears on other URL-building sites in RestTransport.java (e.g. /tasks/%1s:cancel, /tasks/%1s/pushNotificationConfigs/%2s, /tasks/%1s:subscribe). These don't currently misbehave because their arguments are strings whose length exceeds the width, so no padding occurs — but they're the same bug waiting on a short/empty value and would be worth normalizing to %s in the same change.
Environment
- Observed on the v1.x line (
org.a2aproject.sdk) and the v0.3 line (io.github.a2asdk:0.3.3.Final); both contain the identicalhistoryLength=%2dline, and it is still present on the latestmain. - Transport: HTTP+JSON (REST). JSON-RPC transport is unaffected (it doesn't build this query).
Relevant log output
Code of Conduct
- I agree to follow this project's Code of Conduct
- 主要语言
- Java
- 星标
- 504
- 派生
- 184
- 平均合并
- 1 天 13 小时
- 30 天内合并 PR
- 31
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
a2aproject/a2a-java 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 75/100
a2aproject/a2a-java#1012 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 65/100
a2aproject/a2a-java#464 · 1 条评论 ·
维护者通常 1 天内回复
-
Create a sample that demonstrates how to use a shared contextId across multiple tasks可能重新可做 @tanish111 于 353 天前认领,目前没有进行中的 PR。 未关闭sample
难度 2/5 1-3 小时 新手友好度 70/100
a2aproject/a2a-java#375 · 5 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
a2aproject/a2a-java#1207 ·
维护者通常 1 天内回复
-
Enable checkstyle failOnViolation=true可能已有人在做 @ZYZ666-RGB 于 1 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 58/100
a2aproject/a2a-java#1206 · 2 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 a2aproject/a2a-java 的全部 Issue
相似的 Issue
-
`Processing lsp` never exits and leaves orphaned processes可能已有人在做 @overcast302 今天认领。 未关闭bug
难度 2/5 1-3 小时 新手友好度 72/100
processing/processing4#1578 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 60/100
维护者通常 1 天内回复
-
[BUG] S3 CORS responses omit Access-Control-Allow-Credentials for matched origins可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
securityHeaders replaces a route's own Content-Security-Policy (0.9.9; weakens embedders' pages)未关闭bug
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
sqlcipher/sqlcipher-android#97 · 1 条评论 ·