refactor(a2a)!: remove the S3 transfer forms - #54
Merged
Merged
Conversation
agent-env now moves a skill bundle, snapshot or changelog only through transfer grants. The s3_prefix, presigned_post and skill_s3_url call shapes are gone, with the agent-echoed prefix they relied on, and a trajectory answer that only names a trajectory_s3_prefix is refused. A call whose agent does not advertise the object form, or whose object store issues no grants, fails before anything is sent. A snapshot captured in the runtime's own layout cannot be restored. Inline skills and inline trajectories are unchanged. DeployAgentTaskStep drops agent_changelog_s3_prefix, changelog_apply_call drops portable and skill_add_call drops forms; the validator stops probing the S3 forms. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
earakely-scale
marked this pull request as ready for review
October 5, 2026 16:02
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ngelog source Dropping agent_changelog_s3_prefix on load left the step loadable but skipped the rewind it asked for. A stored step that still names one is now refused; an empty field, which every stored step carries, still loads. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
agent-env moves skill bundles, snapshots and changelogs only through transfer grants. The S3 call shapes are removed:
s3_prefix,presigned_postandskill_s3_url. agent-env also no longer reads atrajectory_s3_prefixthat an agent names in its answer. SDK agents haven't taken those shapes since the object variants shipped. Keeping them meant a second path through every call builder, plus an agent-echoed prefix that had to be clamped before it was registered.Behaviour
RuntimeErrornaming which one, before any request is sent or grant issued. Changelog enable still raisesGrantUnavailableErrorwhen the store can't sign a namespace grant that lasts the agent's lifetime.trajectoryobject) is refused, so those captures can no longer be restored.getanswer that names onlytrajectory_s3_prefixnow raises. Every caller already treats a failed trajectory fetch as best effort, so this shows up as a warning instead of a silently missing trajectory. If the answer also has an inline trajectory, the inline one is used.skill_md) and inline trajectory gets;TransferModevalues;snapshot_load_call's signature;ObjectStore.signed_post, whichissue_upload_policyuses;SkillArtifact'sskill_s3_urlalias;skill_s3_url/s3_urispellings of an object-backed skill in adeploy_agentstep, which now go as a bundle.Breaking for downstream
DeployAgentTaskStep: dropsagent_changelog_s3_prefix, andVerifyA2ASkillConfigStepdropsskill_s3_url. A storedVerifyA2ASkillConfigStepwithskill_s3_urlloads, and the key isn't written back. A storeddeploy_agentstep whoseagent_changelog_s3_prefixis set is refused when it loads, since an S3-form changelog can't be applied and silently skipping the rewind would change what the step does; the empty field every stored step carries still loads.changelog_apply_calldropsportable;skill_add_calldropsforms;bounded_echoandFetchedTrajectory.legacy_prefixare removed.skill_s3_urlortrajectory_s3_prefix. Its reports drop thes3keys and those options.check_plugin_api.py --base origin/mainreports no break to the plugin surface. The!is for agents that take only the S3 forms.Merge order
_s3_form_urlguard goes away along with the forms it guards, and its reachability reason moves into the object-form refusal.How it was tested
pytest tst/unit packages/agentenv-protocol/tests -n auto: 5824 passed, 13 skipped (with main merged in).git grepfor the removed shapes now finds only the refusal message, theSkillArtifactalias,PromptResponse.agent_trajectory_s3_prefix(agent-env's own output prefix), and the CLI's--skill-s3-urlsource option.🤖 Generated with Claude Code
The PR appears safe to merge once deployments no longer rely on the removed S3 forms.
Summary
AgentEnv removes S3-shaped transfer calls for skills, snapshots, changelogs, and trajectory reads, leaving transfer grants as the path for object-backed data. This simplifies the transfer choices while keeping inline skills and trajectories available.
trajectoryobject; trajectory reads refuse prefix-only answers.Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Load stored deploy step] --> B{S3 changelog source?} B -->|Yes| C[Refuse to load] B -->|No| D[Load step] D --> E{Object changelog source?} E -->|Yes| F[Apply with read grants] E -->|No| G[Continue without rewind]Reviews (3) · Last reviewed commit: "fix(task-step): refuse a stored deploy_a..."