Repository navigation
Commit 40b315b
Fixes #20273
Clause-②: no (narrowing)
Retires the connector resilience family under ADR-0049
enforce-or-remove, one batch, by the triage verdict RETIRE (comment
5858520070) under the maintainer's criterion on #18900:
`connector.health` (the `healthCheck` probe, eight keys, and the
`circuitBreaker`, six keys), `connector.status` and the connector-nested
`webhooks` — sixteen authorable keys that nothing read. Authoring any of
them is now a tsc error and a parse error that carries the prescription;
no alias window.
## Census first (origin/main 3f86dc5, each zero beside a lit control)
| family | readers outside `packages/spec` | lit control, same scan |
|:--|:--|:--|
| the fourteen `health.healthCheck.*` / `health.circuitBreaker.*` leaves
| 0 (`circuitBreaker`, `fallbackStrategy`, `halfOpenMaxRequests`,
`unhealthyThreshold`, `healthyThreshold`, `monitoringWindowMs`,
`resetTimeoutMs` outside generated docs; `healthCheck` only as the
kernel plugin-health contract; no `.health.` read in
`packages/connectors` or `service-automation`) | `retryConfig` read 17
times in `packages/connectors` + `service-automation` |
| `status` | 0 connector reads: one member-read pattern over connectors,
service-automation, rest, runtime, metadata and objectql finds 38
`.status` reads, every one on an HTTP answer, an error case or a
flow-run entry | the same pattern finds `requestTimeoutMs` read off a
connector entry / provider context 5 times |
| nested `webhooks` | 0 reads of a connector's own array (the one test
that authors one pins that it is NOT hoisted) | `stack.webhooks` read 5
times |
objectui: nothing imports a removed name at the pinned `.objectui-sha`
f8a9d0fb (one comment mentions `WebhookEventSchema`), and no connector
`status` / `health` / `webhooks` reader at objectui main 610819c40. No
key had a live reader, so no `premise_still_valid` fork.
## What changed
- **Tombstones.** `health`, `status`, `webhooks` are `retiredKey()`
tombstones on the private `ConnectorBaseSchema` that both published
carriers wrap (`ConnectorSchema`, `DeclarativeConnectorEntrySchema`), so
`defineConnector`, `registerConnector`, `stack.connectors[]` and `PUT
/api/v1/meta/connector/:name` all refuse them. Six
`RETIRED_KEYS_BY_MAJOR[18]` rows.
- **Residue.** `status` was `.default('inactive')`, emitted by every
17.x parse into every connector; `status: 'inactive'` joins
`connectionTimeoutMs: 30000` in `CONNECTOR_RETIRED_KEY_RESIDUE`
(accepted and stripped). Every other value is refused.
- **Seven defs leave whole** (`RETIRED_DEFS_BY_MAJOR[18]`):
`ConnectorHealth`, `HealthCheckConfig`, `CircuitBreakerConfig`,
`ConnectorStatus`, `WebhookConfig`, `WebhookEvent`,
`WebhookSignatureAlgorithm`. The manifest keys and baseline rows were
deleted deliberately after the build named them.
- **D2 conversion `connector-resilience-keys-removed`** (step 18,
retired from the load path): strips the three keys from `connectors[]`
and from stored rows, one notice per key; nested webhooks are stripped,
never moved.
- **D3 entry `connector-resilience-keys-retired`** (one per family,
ruling B on #17152), naming the D2 and the chain below.
- **Writers deleted.** `status: 'active'` in the four shipped connector
packages and `status: 'error'` on the automation service's degraded husk
were writes nothing read back; tsc found the husk's test fixture too.
- `packages/spec/docs/SYNC_ARCHITECTURE.md`: the "Monitoring: Health
checks" tick is gone, and so are the ticks and example lines this
retirement made false (connector webhooks, circuit breaker, `status:
'active'`); the doc's compile gate (`connector-author-shape.test.ts`)
holds the example.
- `automation/webhook.zod.ts`: its connector-webhook note is corrected,
and the `extraKeys: ['signatureAlgorithm']` suggestion is dropped (the
only surface accepting that key is gone, so a typo on the delivered
webhook would have been pointed at a refused key).
- Ledger: `status` and `webhooks` stay one `dead` row each, now
tombstones; `connector/webhooks` left the undrilled baseline (the gate
called it stale); `state-counts.md` and the README notes cell
regenerated / corrected (dead 44 to 30).
- Projections regenerated by their generators only:
`migrations/registry.ts`, `api-surface/`, `declaration-map/`,
`export-origins/`, `authorable-surface/`, `authorable-defaults/`,
`json-schema.manifest/`, `content/docs/references/**`, strictness
counts, `test-typecheck-debt.json` (shrink only). `spec-changes.json`
and `docs/protocol-upgrade-guide.md` do not move: they fold majors up to
`PROTOCOL_MAJOR` 17, and this is step 18 (`check:spec-changes` /
`check:upgrade-guide` green).
- `docs/adr/0122-...md` is NOT edited: no gate forced it.
`type-alias-convention.pin.test.ts` loses the three isomorphic pins of
the removed enums (783 to 780 on the merged tree; #19920 landed first
with its own 786 to 783), the way the error-mapping precedent did.
## Deviations from the dispatch's mechanism assumptions (measured)
1. **Per-key tombstones vs. defs leaving.** The dispatch asked for one
tombstone per key AND for `ConnectorHealth` / `ConnectorStatus` to leave
via `RETIRED_DEFS_BY_MAJOR`. Both cannot hold for the fourteen
`health.*` leaves: once `ConnectorHealth` leaves, its leaves have no
shape to carry a tombstone. I followed the error-mapping precedent
(13c48c2): one carrier tombstone per key the walk still reaches
(`health`, `status`, `webhooks`), defs whole.
2. **"The liveness rows stay dead."** The fourteen drilled `health.*`
rows cannot stay: with `health` a leaf, `check:liveness` refuses them
(measured: `connector/health (declared children but property is not a
container)`). `health` is one `dead` tombstone row whose note carries
the fourteen verdicts and their census.
3. **"Rename, then removal."** Keeping the breaker half of
`connector-health-and-trigger-durations-unit-in-key` is impossible under
the conversion table's disjoint-fixture contract: the rename's own
fixture carries a `health` block that the removal strips. Per
`spec-property-retirement` §0 (same unreleased step) the breaker half is
ABSORBED: the rename now carries only `triggers[].interval`, and the
removal serves an author holding either spelling (a pin replays
`monitoringWindow` plus a trigger `interval` and gets exactly one rename
notice and one removal notice).
4. **`plugin.ts:1792` was not comment-only.** The line under that
comment WROTE `status: 'error'` into the husk def, which the tombstone
makes a tsc error and a registration-time parse refusal; the write is
deleted and the comment corrected.
5. **File surface grew beyond the claim**, each forced by the
retirement: the four connector packages and one service-automation test
(writers), `automation/webhook.zod.ts` (orphaned `extraKeys`),
plugin-webhooks' docblock and its pin test's docblock (they quoted the
retired spec prose), `rest-server.test.ts` (a stale comment),
`connector-author-shape.test.ts`, `type-alias-convention.pin.test.ts`.
## Acceptance notes
- **PR #20255 merged before this PR was finished**, so `main` was merged
here and its D3 entry `connector-resilience-durations-unit-in-key` is
reconciled in this PR: it now prescribes only `triggers[].interval` to
`intervalSeconds` and tells an author holding `monitoringWindow` /
`monitoringWindowMs` that the renamed key is itself retired (delete the
`health` block). `triggers[].interval` is untouched otherwise.
- The out-of-repo consumer population of `@objectstack/spec` is not
measured.
## Evidence (head 153f652)
- `pnpm --filter @objectstack/spec build` green (manifest and baseline
gates fired on the seven defs first, as they must on a whole-def
removal, then passed once the rows were deleted deliberately).
- `check:generated`: all 15 artifacts current. `check:liveness`,
`check:migration-registry`, `check:spec-changes`, `check:upgrade-guide`
green.
- Gate union from `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` at 153f652, reconciled with
`--ran`: 118 derived, 113 run with exit 0, 5 NOT MEASURED —
`check:skill-examples`, `check:dual-build-cjs-loads`, `check:i18n`,
`check:type-check-debt` refused with exit 3 (PREREQUISITE NOT MET:
builds outside this diff's closure — client-react, the CLI plugin set,
the whole monorepo), `check:query-options-erasure` (repo-wide ESLint
scan; self-test passed, the ratchet outran a 300s per-gate bound — exit
124). CI runs all five.
- Tests at 153f652: spec `--project local` over `src/migrations`,
`src/conversions`, `src/integration`, the ADR-0122 pin, `rest-server`,
`webhook`, `stack` — 18 files, 777 passed; spec `--project repo` (this
PR's pin, the connectionTimeoutMs pin, the migrate-sentence pin, two
sibling tree-scoped pins, three reference-tree scripts) — 8 files, 221
passed.
- Earlier on this branch (pre-second-merge heads): full spec `--project
local` 552 files / 16265 passed; `service-automation` 146 files / 1757
passed; connector-mcp / -openapi / -rest / -slack and plugin-webhooks 27
files / 255 passed; typecheck of those six packages green; dogfood
`expression-conformance` 7 passed.
- ESLint over the 32 changed lintable files (`--no-inline-config
--format json`): 32 files, 0 errors, 0 warnings. Population:
`eslint.config.mjs` flat config over
`**/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs}`; the config enables no type-aware
linting (no `parserOptions.project`), so this diff cannot move a verdict
in an untouched file. The repo-wide `pnpm lint` is CI's.
## Ablation (one per closed door)
Via `node scripts/ablation-replace.mjs` (anchor must hit, restore proven
by blob hash equal to HEAD and an empty `git diff HEAD`), on committed
head 849fb62, running `connector-resilience-keys-retirement.test.ts`:
| tombstone deleted (bare strip) | result |
|:--|:--|
| `health` | 4 failed / 17 passed — REJECTS `health`, the three-door
refusal, the either-spelling breaker refusal, the walked-shape pin |
| `status` | 4 failed / 17 passed — REJECTS `status`, the three-door
refusal, the non-default-value refusal, the walked-shape pin |
| `webhooks` | 3 failed / 18 passed — REJECTS `webhooks`, the three-door
refusal, the walked-shape pin |
Each leg restored to blob 704684d (HEAD's). No permanent ablation
test is left.
---
_Generated by [Claude
Code](https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV)_
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 789b2ae commit 40b315b
50 files changed
Lines changed: 1769 additions & 1072 deletions
File tree
- .changeset
- content/docs/references
- integration
- docs/audits
- packages
- connectors
- connector-mcp/src
- connector-openapi/src
- connector-rest/src
- connector-slack/src
- plugins/plugin-webhooks/src
- services/service-automation/src
- spec
- api-surface
- authorable-defaults
- authorable-surface
- declaration-map
- docs
- export-origins
- json-schema.manifest
- liveness
- scripts/liveness
- src
- api
- automation
- conversions
- integration
- migrations
- entries
- retired-defs
- retired-keys
- semantic
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
| |||
186 | 186 | | |
187 | 187 | | |
188 | 188 | | |
189 | | - | |
| 189 | + | |
190 | 190 | | |
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
194 | 194 | | |
195 | | - | |
| 195 | + | |
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
| |||
0 commit comments