Skip to content

Add native contract-generated ordinary API client - #47

Draft
kvz wants to merge 50 commits into
mainfrom
sdk-contract
Draft

kvz wants to merge 50 commits into
mainfrom
sdk-contract

Conversation

@kvz

@kvz kvz commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Why

Prove canonical-contract generation in a second native language and deliver real workflows through
that new opt-in surface, without implementing the scenarios through legacy SDK adapters.

October 6 bounded grant-authentication correction

  • Integrate landed producer #9439. Both SDK emitters preserve the source-owned form selector
    through one shared lowering function; neither native transport owns an endpoint/grant list.
  • Explicit credentialless configuration is supported: Node authentication: { kind: 'none' }
    and Go NoAccountCredentials: true. Missing, malformed or contradictory credentials and
    protected calls without account authentication fail locally.
  • Code/refresh grants omit SDK-managed Authorization and ambient cookies even on an authenticated
    client. Their grant proof is still required. Basic client-credentials issuance is unchanged.
    Authentication uses the same validated form snapshot that is serialized on the wire.
  • Shared tests cover all nine grant/configuration combinations, invalid selectors/configuration,
    cookie isolation, redirect rejection, single-attempt errors and preserved response data.
  • Both full post-review yarn check runs pass, as do 93 focused Node tests, both strict packed
    Node consumers and Go native/example/offline race, vet and build checks. Current pinned-source
    generation/shared/actual API2-tusd acceptance passes in 2.4 minutes with no failures/flakes.
    Generated Node/Go files match check-mode output byte for byte.
  • Two combined source-access-verified council rounds are complete. Undefined optional settings
    and a prototype-named selector have fail-first fixes; the last redirect-test assertion issue is
    repaired. A separate envelope-key concern is disproved by the installed strict validator and
    retained as a negative regression. There are no outstanding actionable council findings.
  • Scope excludes login/consent UI, credential storage, automatic refresh and a full OAuth workflow
    canary. Complete OAuth onboarding is not automatically a release blocker. Registration,
    discovery/revocation and producer-owned OAuth error-code identity remain separate follow-ups.
  • Frozen heads: API2 7cad7b7db43f405c88114145f14c81ce805c3499,
    Node 56f455944f5652226b59055a291b47652ce48ac6,
    Go d152a4105ebe51aa63ad02d2beed0d13adc0060a.
    The Node immutable implementation pin remains 71196f2: all four pinned files are byte-identical
    at the final head, whose only extra change fixes the unit-test harness.
  • Exact-head Node CI
    and Go CI are green.
    API2 CI is also green,
    including the 95.02% changed-line coverage gate. Final acceptance receipt
    closes the pre-push living-document checkpoint, with all review/test evidence and flaky-test details.
    Contract SHA-256: 6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.

All three PRs remain experimental drafts, unmerged. No deployment or Content repin.

Scope

  • Add a contract package for 37 ordinary operations and three bounded tus bindings, with stable
    domain types, semantic unions, exact integers and omission/null distinctions.
  • Deliver wait, cancel, fixed-size ReaderAt upload and persisted-session/fresh-client resume.
    Validate admitted uploaders, exact metadata bytes, file digest, offsets and transferred receipts.
    Keep request buffers owned until HTTP body closure; never forward credentials to capabilities.
  • Consume generated API2 lifecycle, tus metadata and receipt policies/accessors, not another native
    endpoint/receipt inventory. Empty/binary unrelated metadata is supported and tested.
  • Bound safe reads and tus recovery, honor backoff and never automatically retry creation/cancel.
    Ordinary Assembly discovery does not retry HTTP 409. Lost PATCH replies reconcile accepted bytes.
  • Return REQUEST_ABORTED as a finite, unsuccessful wait result. Explicit cancellation reaches
    its uploader once; a later active/aborted status cannot conceal a failed DELETE or prove cleanup.
  • Expose both failed DELETE and confirmation attempts through
    AssemblyCancellationConfirmationError, including errors.Is/errors.As with cancellation-first
    matching and direct access to both errors. Preserve caller context/deadline precedence and Go 1.15.
  • Keep the 8 MB generated-source ceiling, strict native decoding and opt-in import boundary.
    Shared upload/resume acceptance invokes the delivered contract workflow, never an adapter fallback.

Existing-API behavior changes

CreateSignedSmartCDNUrl follows canonical shared signing vectors: path escaping, UTF-16 key order
and millisecond expiration can change generated strings/signatures. Callers caching/comparing old
output need to account for the correction. Legacy WaitForAssembly preserves cancellation/deadline
identity and keeps polling ASSEMBLY_REPLAYING. API shapes remain compatible, but these intentional
tested behavior changes are documented, not described as unchanged behavior.

October 6 reader compatibility

  • Unknown nonempty Assembly error codes are terminal failures, not invalid workflow responses.
    Known codes remain autocomplete hints. Malformed errors and unknown success/progress codes
    remain rejected; the public reader and current runtime emitter are tested separately.
  • Derive admission from the canonical response schema, removing the duplicate finite SDK list.
    Preserve the exact error as data, without interpolating it into diagnostic messages.
  • Keep compact atomic Go string codecs and TypeScript known-literal completion. Shared synthetic
    observations exercise 16 cases through 10 native modes per SDK (320 observations total),
    including failed-cancellation confirmation, partial resume and completed-upload receipts.
  • Fail-first review repairs cover bounded response cleanup, persisted custom upload fields,
    permanent Node fetch failures being retried, and examples/canaries losing cleanup ownership.
    Go's experimental OnSession callback now receives the derived upload context; all callers
    and the README are updated so persistence can honor the shorter upload deadline.
  • Harden Go representation reuse and getters. Naming and declarations now share branch admission;
    unsupported literal/union/intersection combinations fail generation instead of silently widening
    codecs or emitting invalid Go. Current generated clients stay byte-identical after these repairs.
    These codecs are not complete JSON Schema validators.
  • Frozen producer: b646c529fb0bf0e3aa4295c1a3208cdd028dd681.
    Native pins: Node d63d6ccce4cf0f43464d8e351eb96f493de52155,
    Go 5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c.
    Generated bytes remain those from producer f8947685ba; contract SHA-256
    4c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.
  • Post-council full API2 and Node checks pass. Node has 1,381 passing tests and one existing skip,
    plus the other workspace suites; both fresh packed package names pass strict root/subpath/example
    compilation. Go contract/shared/example race tests, vet and build pass.
  • All four source/shared/generation/actual local API2-tusd suites pass on the final native pins:
    zero failures or flakes, 2.1 minutes. All ten generated files match byte-for-byte.
    Generated client sizes remain 5,012,654 bytes (TypeScript) and 7,581,401 bytes (Go), under 6/8 MB.
  • The final source-access-verified council retains no new reader/lowering findings, only the
    explicitly deferred OAuth blocker below. The same required checks pass again after review.
  • Exact native CI is green: Node
    and all five Go versions.
    The final producer run is API2 CI;
    its final status is recorded in the immutable completion receipt below.

The authentication limitation described in this historical reader receipt is addressed by the
bounded correction above. Its former blanket OAuth release-blocker wording is superseded by the
user-approved narrower scope. Earlier CI receipts do not certify the new candidate.

Historical October 4 acceptance

  • Frozen native commit: 93dedeb94a67166fad12fa80f1d5a27a9110afaa.
  • Generated from integrated producer #9252, frozen at 0b4c13d7de0674077ddcfa390d72e676bfe50b20;
    contract SHA-256 4246893330e3fa724407e19fa3d8d49501f87132b7aff9665f850a2f10fd8c53.
    Its generation check-mode output matches the committed Go client exactly.
  • Native contract/shared race tests, go vet and the workflow example build pass. Compound-error
    regressions retain both causes, including failures with identical concrete types.
  • Exact-head CI 37192510704
    passes Go 1.15, 1.20, 1.24, 1.25 and 1.26.
  • All 32 shared metadata/receipt cases run through public native workflows. Actual local API2/tusd
    acceptance with immutable source/hash pins passes all four producer/model/shared/native suites:
    zero failures/flakes, 3.0 minutes. Complete earlier councils are triaged; the fresh source-access-
    verified final combined council reports No issues found. Contract/shared race, vet and
    example-build checks pass again after review; the frozen native source remains clean.
  • The final two fail-first transport/HTTP cases prove invalid confirmation inspection also retains
    the original DELETE diagnostic. Caller/deadline precedence, validation and one DELETE stay intact.

The historical timed Opus reader completed all five live tasks on a35909efb8, including a process
restart and HEAD-confirmed resume. It did not test later fixes. This iteration adds no live
credentialed tests or customer writes.

Boundaries

Fixed-size ReaderAt inputs and simple upload IDs only; no deferred lengths, concatenation or
non-seekable streams. Caller-owned readers/callbacks must return promptly. Session URLs are private;
local failure does not prove remote cleanup. Trusted origins are additive, proxy receipt rewriting
must be consistent, and the complete deadline includes hashing, persistence and transfer.
Types/decoders preserve modeled wire semantics, not every server schema constraint.

Template-content typing, deterministic multipart ordering and SSE/Webhook
receivers remain separate work. Unrelated empty tus metadata and generated receipt-policy lowering
are now completed and verified, not unresolved interoperability placeholders.

All three SDK PRs remain experimental drafts: do not merge, release or deploy.
Canonical record: API2 docs/prompts/2026-07-09-handover-sdks-branch-restructure.md.
Native checklist: docs/prompts/2026-09-29-contract-finality.md; these immutable receipts supersede
its historical pre-push boxes without a copy-only CI restart.

Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517.

@codecov-commenter

codecov-commenter commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.33564% with 262 lines in your changes missing coverage. Please review.
✅ Project coverage is 5.39%. Comparing base (b567a3e) to head (d152a41).

Files with missing lines Patch % Lines
contract/transport.go 76.42% 74 Missing and 42 partials ⚠️
contract/workflows.go 82.24% 50 Missing and 45 partials ⚠️
examples/contract-workflow/main.go 50.52% 35 Missing and 12 partials ⚠️
transloadit.go 93.10% 2 Missing ⚠️
wait.go 60.00% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #47       +/-   ##
==========================================
- Coverage   82.60%   5.39%   -77.22%     
==========================================
  Files           6      10        +4     
  Lines         345   32493    +32148     
==========================================
+ Hits          285    1754     +1469     
- Misses         32   30497    +30465     
- Partials       28     242      +214     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@kvz

kvz commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Verification footprint for 0ad7504039190ca004bfad76d48cdca9be1a6d01 against b567a3eefef5ce3e74767ba239cb00cbaf33ac2c:

1,040 authored additions; 55,282 generated additions; 1 deletion. Generated classifications and destructive regeneration procedure are recorded in the shared API2 receipt and maintainer guide. Generated lines are not a claim of native/runtime proof; both SDK CI and API2's local-native acceptance passed separately.

Raw canonical numstat (additions, deletions, path):

4	0	.gitattributes
1	1	Makefile
34	0	README.md
39316	0	contract/client_generated.go
15894	0	contract/coverage.json
200	0	contract/live_test.go
45	0	contract/manifest.json
461	0	contract/transport.go
332	0	contract/transport_test.go
27	0	contract/wire-vectors.json
8	0	transloadit.go

@kvz
kvz marked this pull request as draft September 25, 2026 13:27
@kvz
kvz marked this pull request as ready for review September 25, 2026 15:25
@kvz

kvz commented Sep 25, 2026 •

Copy link
Copy Markdown
Member Author

Final source footprint and review receipt

The approved first-party SDK slice is implemented. Existing SDK entrypoints remain intact; the new namespaces are experimental. No SDK release, deployment or merge was performed.

Repository Base Final source head Authored additions Generated additions Deletions Files
API2 c449a7b1f871e12e30a2a544fce1739187d83cf8 8e601e6ffd274fb9f7c00032a3e2b30b3cd0f3ae 2,993 398 143 27
Node SDK 34970b60c770a34c3dc227ad9ecb1ec9283ecd77 30cb8807dab7b8098ba8eb5c53635c84e08b98cc 799 29,488 2 15
Go SDK b567a3eefef5ce3e74767ba239cb00cbaf33ac2c 1897a050f4ba658787abbd9e113c2468c03f0ba0 1,363 84,283 1 11
Total 5,155 114,169 146 53

Measured with the canonical text/Myers/no-renames/no-indent-heuristic numstat command from the living document. Generated ownership: API2's generated contract; each SDK's client/manifest/coverage/vectors; Node's existing legacy-package README/package projection. All native transport, tests, documentation and receipt additions count as authored. The conservative historical authored lower bound is now 59,141, not a fully reconciled program total or an additional footprint authorization. The last API2 increment is the targeted cold-artifact test-budget correction and its CI receipt; production and generated SDK bytes are unchanged.

All council findings have dispositions and fail-first evidence in API2's repodocs/prompts/2026-09-25-sdk-contract.md (six producer, five Go, two Node rounds). Final guards are deliberately narrow and fail closed. Full yarn check, exact-byte generation checks, native wire/race/vet/example checks, actual Go 1.15 tests and both devdock SDK suites pass.

All three exact-head CI runs are now green: API2 36161865722, Node 36136692611, and Go 36153479049. The prescribed API2 watcher finished with all checks passed on September 25 at 17:34 UTC. The generator suite passed in 2.8 minutes under coverage and the actual native SDK server canary in 30.5 seconds. API2 changed-line coverage is 93.62% (514/549); the unchanged 80% gate passed. No review threads were open at this final checkpoint.

The green API2 run also reports two already nonblocking cloud-image .flaky.vitest.ts failures: Fal's visual-diff artifact upload and SVG generation's upstream 503. Their sources, fixtures, thresholds and classification are unchanged. No new test skip or failure waiver was added. The preceding related SDK regression timeout was fixed and passed, not classified as unrelated. All three PRs are ready for review; no merge, SDK release or deployment was performed.

Before landing: API2 main has since advanced by one Slack-workflow/test commit, 8e5c2e0dfe8a2e2f963324a7ec9140179945c165 (#9258). API2 is mergeable but behind and still needs review; integrate and validate that main update before merging. The exact-head CI and footprint receipt above remain unchanged. Node and Go are cleanly mergeable.

Producer first, then consumers:

@kvz
kvz marked this pull request as draft September 28, 2026 15:40
@kvz

kvz commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Type-identity acceptance receipt, September 28, 22:24 UTC.

  • Exact head 3729aa43116d8deca6d04b5020390e6ad3bf9e02 passes
    CI run 36488758965 on all five
    versions: Go 1.15, 1.20, 1.24, 1.25 and 1.26. The watcher exited successfully.
  • Local contract race tests, vet, examples and exact generated-byte checks pass. API2's hash-pinned
    native canary uses the migrated source-owned domain types against owned local resources. The
    final commit only clarifies generated multipart support, so the native source pin remains valid.
  • Council's final Go finding was the corrected README wording. The later Node review identified an
    additional cleanup/routing gap in both examples: cancellation must safely follow the returned
    owning uploader and verify a terminal response. This is a documented next-slice merge blocker,
    not waived by green type tests or CI. API2's living document records the source evidence and
    multi-uploader acceptance requirements.

The type-identity cleanup is accepted locally and in CI. This does not establish generated-client
workflow parity. The PR stays draft; nothing was merged, released or deployed.

https://github.com/transloadit/api2/pull/9252
transloadit/node-sdk#517
#47

@kvz

kvz commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Upload/resume acceptance receipt, September 29

This closes the upload/resume slice's historical pending review/check items in the canonical living
document and repodocs/prompts/2026-09-27-sdk-dx.md. It is not merge, release or deployment approval.
All three PRs remain draft.

Repository Exact candidate CI
API2 49824420400c6947a39a260c314ef26a1d95d608 Green: API2, attempt 2, Utils, CRM routing, Statuspage
Node 88ec0f37a201ceff422696f2e6fedf8b4527ee26 Green: all 11 checks
Go ee28c68dd85d3878c0affffaa429714628581edc Green: all five Go versions

Local acceptance

  • Full API2 and Node yarn check pass. Node's focused native/shared suites pass 213 tests.
  • Both packed Node package names pass strict installed-consumer compilation, including their
    contract entrypoints and shipped example.
  • Go go vet ./..., native/example race tests and shared workflow race tests pass.
  • Canonical contract/OpenAPI and both generated SDKs pass exact-byte check mode.
  • All six post-main pinned devdock suites pass: workflow paths, Companion compatibility,
    dispatch-registry, SDK generation, shared SDK workflows and actual local API2/tusd native canaries.
    The owned clone-7 test container is stopped afterward; its persistent volume is retained.

Main a4f9e02f4e landed while the preceding CI was running. The one conflict was in workflow tests:
retain both SDK Go-toolchain guards and remove only the obsolete vendored Companion hydration
tests, matching main's published-package migration. Generated contract/SDK bytes are unchanged.
Superseded API2 runs 36593626095 and 36590500301 were canceled after the new merged candidate
was pushed; cancellation is not a passing CI result. Node/Go commits did not change.

API2 attempt 1 stopped in the Core suite before the API2 suites: 161/162 Core suites passed and
core/test/unit/alphalib/net.vitest.ts failed its negative TCP-readiness assertion because the
promise resolved instead of rejecting. Both the test and core/alphalib/net.ts, plus Core's package
and lockfile, are unchanged from main. Their Git blob IDs are respectively
c70734526c6c8f1bb2d5c56c7aa54ed4bd347d0a and 3b77eee8fc5c4d9a358ae78901e20b672830c7f7.
The fixture closes an ephemeral listener, then assumes that port stays unavailable. A disposable
devdock reproducer that binds a second listener in that gap triggers the identical assertion;
the original isolated suite passes. This verifies the unrelated fixture race, not which process
held the port in CI. The probe is retained only under ignored local evidence and the container is
stopped. No assertion was weakened. Only the failed CI job was retried on the unchanged commit;
attempt 2 confirms all 162 executed Core suites pass, including this TCP test (one non-test fixture
is skipped), and the complete workflow is green. Stabilizing this inherited negative-port fixture
is a separate follow-up. The intermediate report is retained under
tmp/sdk-tus.vVDVAO/api2-attempt2-results.json, generated at 2026-09-29T16:36:07.172Z.

The final API2 report records 1,821 passed suites, 19 passing suites already marked flaky, one
non-blocking flaky failure and 67 skips. Every SDK-specific suite (models, command, generation,
shared workflows and native runtime) passes without a flaky disposition, as do dispatch-registry,
workflow paths and Companion compatibility. The remaining flaky failure is the pre-marked
cloud_ai/image_generate/provider-fal.flaky.vitest.ts image comparison: difference 0.0903001
against threshold 0.05. Its test, comparison helper and fixture are unchanged from main. No image
fixture, threshold, skip or flakiness marker was changed to obtain green.

GitHub tested merge 17c47d1b16d8c10dd4eee9082aa7090a8cfff8b5, whose parents are main
a4f9e02f4e and candidate 4982442040. Its tree is identical to the candidate's
df00ef5a2bf3f98ec09f1296f34c04184a0c26a3. The prescribed watcher reports six passing checks,
zero failing and zero pending at 17:19:21Z. All checkouts are clean; no owned devdock remains.

Review disposition

The last API2 council found no issues. All accepted native council findings are reproduced and
fixed, with fail-first regressions. The final small dispositions are not claimed as another clean
council run: processing failure does not prevent read-only confirmation of finished file transfer;
receipt URLs share capability normalization/admission; ownerless aborted cancellation retains its
unconfirmed outcome; response-body cleanup cannot discard HTTP retry/backoff metadata; configured
proxy prefixes cannot be bypassed without explicit bare-origin admission. Applicable fixes are
mirrored. Earlier fixes cover request deadlines, partial/lost PATCH responses, stopped-state write
prevention, Go buffer ownership and bounded response handling. No creation/cancel write retry.

Independent consumer evidence and limits

Both fresh Opus 5.5 readers completed all five tasks, with successful compiles and actual new-process
resume after 65,536/147,052 bytes, HEAD confirmation and no replacement POST or legacy workflow
fallback. Go completed live tasks in about 2m48s and Node in 3m10s. Neutral reports were sealed
before separate hypothetical Rauch/DHH assessments.

Those readers tested Node 50b659d5ac and Go a35909efb8, not subsequent fixes. Two automated runs
are not a human usability study or exhaustive race proof. Node's checksum/dimension observations
were not all assertions; Go recorded SHA-256 without an independent expected checksum. Shared
exact-byte vectors and local runtime tests are separate evidence. The cleanup-reconciliation
canary simulates only HEAD 404 and reads the matching receipt from real API2; it does not execute
the actual cleanup scheduler. Owned Templates were deleted, Assemblies completed/canceled and
secret checkpoints removed; results expire normally. No more live-reader writes under that budget.

Reader-driven example/transport clarification is included. Follow-ups, not implemented here:
public persisted-session parser reusing the native validator, more semantic source-owned Go names,
an honest typed Template-content view and separated consumer/maintainer guidance. Do not narrow
general Template JSON or erase null/omission distinctions merely to simplify generated types.

Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517 · #47.

@kvz

kvz commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Exact-head CI receipt: 9af9601a29b5fccbe3e2f86769adfd3b700d613d is green in run 36627589552, all five supported Go versions passing. Contract/example race tests and go vet ./... also pass after the documentation follow-up. This closes the CI gate, not the quota-blocked full council or the refreshed producer runtime-canary gate. Nothing merged or released.

@kvz

kvz commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Immutable native verification receipt

Frozen Go head: 93dedeb94a67166fad12fa80f1d5a27a9110afaa.
Exact-head CI 37192510704
passes Go 1.15, 1.20, 1.24, 1.25 and 1.26.

  • Final source-access-verified combined Opus 5.5/GPT-6 Astra/arbiter council: No issues found.
    Native contract/shared race tests, vet and the workflow example build pass again after review,
    leaving the frozen native source tree clean.
  • The final two fail-first transport/HTTP cases retain the failed DELETE when confirming GET
    inspection is unusable. Caller/deadline precedence and a single cancellation write remain intact.
    Public compound errors retain both attempts, including same-concrete-type causes, with Go 1.15
    compatible errors.Is/errors.As behavior.
  • API2 producer 0b4c13d7de pins this exact head and source hashes. Both generated clients remain
    byte-identical. All four actual local API2/tusd/model/generation/shared suites pass, zero failures
    or flakes in 3.0 minutes, on these final Node/Go source pins. All 32 shared metadata/receipt cases
    exercise delivered public workflows.
  • The producer's own exact-head CI 37192838803
    is also green, including the full test job and the unchanged 80% patch-coverage gate (94.65%).

These immutable receipts supersede historical pending boxes in the pre-push checklist. The timed
credentialed reader tested a35909efb8, not this head; no additional live-resource test was run.
All three companion PRs remain experimental drafts, unmerged and not release-ready. No release
or deployment was performed.

Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517.

@kvz

kvz commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

October 6 immutable reader-slice verification receipt

This closes the forward-compatible Assembly reader slice, not the experimental SDK release.
The OAuth work below remains an explicit, user-confirmed merge/release blocker.

Frozen sources and generation

Repository Verified commit
API2 b646c529fb0bf0e3aa4295c1a3208cdd028dd681
Node SDK d63d6ccce4cf0f43464d8e351eb96f493de52155
Go SDK 5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c
  • Contract SHA-256: 4c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.
  • All ten generated consumer files match check-mode generation byte for byte. The latest producer
    safety repairs do not change the generated bytes from producer f8947685ba.
  • TypeScript remains 5,012,654 bytes and Go 7,581,401 bytes, within unchanged 6/8 MB guards.
    Immutable native source pins and per-file hashes match the verified consumer commits.

Behavior and fail-first review repairs

  • Unknown nonempty Assembly errors remain exact terminal-failure data through GET, wait, cancel,
    upload/resume and receipt handling. Known errors retain autocomplete. Malformed errors,
    contradictory states and unknown success/progress codes remain rejected.
  • The public response schema drives admission; the duplicate finite SDK error inventory is gone.
    Sixteen shared observations run in ten modes in each language: 320 synthetic observations.
    These distinguish public reader acceptance from the current runtime emitter's closed inventory;
    they do not claim production has emitted future codes.
  • Fail-first tests cover response cleanup exceeding deadlines, forgotten persisted custom fields,
    permanent Node fetch failures being retried and lost cancellation ownership in executable
    examples and actual canaries. Go's experimental OnSession receives the derived upload context.
  • Go lowering now shares representation and union-branch decisions across naming, declarations
    and getters. Unsupported literal/union/intersection combinations fail generation rather than
    widen codecs or emit uncompilable Go. Positive supported controls remain. These codecs are not
    complete JSON Schema validators.

Final verification

  • Full API2 and Node yarn check pass after council. API2 verifies all six deterministic artifacts.
    Node passes 1,381 tests with one existing skip, plus the remaining workspace suites. Both freshly
    packed package names pass strict root, /contract and shipped-example compilation.
  • Go contract, shared and example race tests, go vet ./... and go build ./... pass after council.
  • All four source/shared/generation/actual local API2-tusd suites pass on the final pins with zero
    failures or flakes in 2.1 minutes. This is local runtime acceptance, not a new credentialed live test.
  • Final source-access-verified council retains no new reader/lowering findings. Its only retained
    finding is the already disclosed and explicitly deferred OAuth blocker below. The reviewed API2
    source archive has SHA-256 a3cd55bce9ad75344dec7c89339c67e7165583e0a1ec40c895f2f51a59645a7e.
  • Exact-head Node CI and
    five-version Go CI, including
    Go 1.15, are green. API2 Utils CI
    and CRM scope checks pass.
  • Exact-head API2 CI is green:
    lint, build, tests and the patch-coverage gate pass. Changed-line coverage is 94.75% (940/992),
    above the unchanged 80% target. The structured gating summary records failedCount: 0,
    omittedFailedCount: 0 and no failing tests. Conditional deployment jobs were skipped.
  • The requested core/alphalib/bin/gh-run-watch.ts exits successfully at 10:47:09 UTC:
    five passing API2-repository checks, zero failed and zero pending. All three final source trees
    are clean, all three PRs are still draft, no review threads remain open, and build-api2 remains set.
  • Separate non-gating observation: the existing provider-fal.flaky.vitest.ts image comparison
    reports a difference of 0.0975448 against its 0.05 threshold. Its assertions reached the final
    image comparison, not an SDK reader failure. The test, shared system helper and Robot paths are
    unchanged by this branch. No flaky classification, fixture or threshold was changed to get green.

The completion receipt supersedes the pre-push pending boxes in the canonical living document
docs/prompts/2026-07-09-handover-sdks-branch-restructure.md and the existing SDK checklists.
Earlier passing snapshots and deliberately canceled superseded runs are not approval of these heads.
Local evidence is retained under studio1:/tmp/sdk-readers.c3epZn/. The owned devdock container was
stopped and removed after acceptance; its persistent data was preserved.

Next slice and release boundary

Public OAuth authorization_code and refresh_token exchanges must not require or send Basic
account credentials. The source/runtime already supports grant-specific admission, but the draft
SDK projection and client configuration still impose unconditional authentication. Fix this in the
producer and native transports, regenerate and test credentialless public grants alongside Basic
client-credentials grants. Do not patch generated files or recommend account credentials as a workaround.

The user explicitly chose to defer this authentication slice. All three PRs remain experimental
drafts, unmerged and not release-ready. No release, deployment, Content repin or additional
credentialed live-resource test was performed for this reader slice.

https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517 · #47

@kvz

kvz commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

October 6 completion receipt: bounded native grant authentication

This completes the final two acceptance gates in the canonical living document's October 6
checkpoint. It is acceptance of this narrow correction, not a release seal for the experimental SDKs.

Frozen revisions and CI

Repository Revision Final CI
API2 7cad7b7db43f405c88114145f14c81ce805c3499 37483773020: green
Node 56f455944f5652226b59055a291b47652ce48ac6 37483624192: all 11 gates green
Go d152a4105ebe51aa63ad02d2beed0d13adc0060a 37480359213: all five versions green, including Go 1.15

API2 build, test job and patch-coverage gate pass: 95.02% (956/1,006) changed lines covered
against an 80% target. Generation, shared workflows and actual API2/tusd native canaries each pass
in this exact CI run. The overall runner reports 1,866 regular passes, 19 premarked flaky passes,
one premarked flaky failure and zero blocking failures. The flaky failure is the unchanged
cloud_ai/image_generate/provider-fal.flaky.vitest.ts image comparison (0.076971 versus 0.05);
the test and Robot/cloud-AI sources are byte-unchanged from integrated main. No quarantine,
threshold, fixture or timeout was changed. Utils passes; CRM's workflow passes its flag checks
and correctly skips build/deployment for this final test/documentation-only push.

The old producer runs at b03b7df971 and 24d9a8c396 were canceled as superseded, not treated
as passing. Node's earlier 71196f2 run encountered a public-ECR Docker-pull rate limit before
the Edge test and passed a targeted retry. The final Node head passes its complete CI without retry.

Local acceptance and review

  • Full post-review API2 and Node yarn check pass. API2 verifies all six deterministic artifacts.
    Node reports 1,414 Node tests passed, one existing skip, plus all other workspaces.
  • All 93 focused Node auth/client tests pass; freshly packed @transloadit/node and
    transloadit pass strict root/subpath/installed-example compilation.
  • Go native/example race, offline shared/signature/type race, vet and build pass. Old credentialed
    root tests were not claimed as a local pass; existing CI owns those tests.
  • Fresh immutable-pinned generation/shared/local API2-tusd suites pass in 2.4 minutes with zero
    failures/flakes; the final selector-envelope negative regression's full generator suite passes
    again in 1.3 minutes. Both language outputs pass generation check mode and match consumer bytes.
  • Two source-access-verified combined council rounds complete. Undefined optional settings and
    mixed prototype-named selectors have fail-first repairs. The last retained finding is fixed by
    moving HTTP header assertions from the server callback into the awaited test. A suggested
    selector-envelope defect was disproved with the installed strict validator; an explicit negative
    regression and explanatory comment remain. No actionable council findings remain.
  • The final Node commit changes only that test harness. All four immutable source-pin files are
    byte-identical to 71196f2; the pin therefore remains valid. Go stays at d152a41.
    Contract SHA-256: 6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.
    OpenAPI SHA-256: c0c434452d2729ea597507a90c82d4925b36674d341ce1cf26e571d1c04cca66.

Boundaries

Form-selected account authentication and explicit credentialless configuration are implemented.
Grant proof is still required; custom transports remain trusted application code. No login/consent
UI, token store, auto-refresh manager or full OAuth workflow canary was added. Full OAuth onboarding
is not automatically a release blocker. Registration/discovery/revocation and producer-owned OAuth
error-code identity remain separately recorded follow-ups.

The existing living document is updated; this immutable receipt closes its pre-push CI checkbox.
All three checkouts are clean and the owned devdock is stopped. All three PRs remain experimental
drafts, unmerged and unreleased. No deployment or Content repin.

Companions: https://github.com/transloadit/api2/pull/9252 ·
transloadit/node-sdk#517 · #47

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants