Skip to content

Add experimental contract-generated ordinary API client - #517

Draft
kvz wants to merge 47 commits into
mainfrom
sdk-contract
Draft

kvz wants to merge 47 commits into
mainfrom
sdk-contract

Conversation

@kvz

@kvz kvz commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Why

Provide an experimental contract-generated API and useful native workflows alongside the existing
Node SDK. Blind-reader feedback motivated navigable types; runtime canaries motivated safe uploader
routing and genuinely resumable uploads. Keep API facts in API2, not in a second SDK inventory.

October 6 bounded grant-authentication correction

  • Integrate landed producer #9439. Both SDK emitters preserve the source-owned form selector
    through one shared lowering function; neither native transport owns an endpoint/grant list.
  • Explicit credentialless configuration is supported: Node authentication: { kind: 'none' }
    and Go NoAccountCredentials: true. Missing, malformed or contradictory credentials and
    protected calls without account authentication fail locally.
  • Code/refresh grants omit SDK-managed Authorization and ambient cookies even on an authenticated
    client. Their grant proof is still required. Basic client-credentials issuance is unchanged.
    Authentication uses the same validated form snapshot that is serialized on the wire.
  • Shared tests cover all nine grant/configuration combinations, invalid selectors/configuration,
    cookie isolation, redirect rejection, single-attempt errors and preserved response data.
  • Both full post-review yarn check runs pass, as do 93 focused Node tests, both strict packed
    Node consumers and Go native/example/offline race, vet and build checks. Current pinned-source
    generation/shared/actual API2-tusd acceptance passes in 2.4 minutes with no failures/flakes.
    Generated Node/Go files match check-mode output byte for byte.
  • Two combined source-access-verified council rounds are complete. Undefined optional settings
    and a prototype-named selector have fail-first fixes; the last redirect-test assertion issue is
    repaired. A separate envelope-key concern is disproved by the installed strict validator and
    retained as a negative regression. There are no outstanding actionable council findings.
  • Scope excludes login/consent UI, credential storage, automatic refresh and a full OAuth workflow
    canary. Complete OAuth onboarding is not automatically a release blocker. Registration,
    discovery/revocation and producer-owned OAuth error-code identity remain separate follow-ups.
  • Frozen heads: API2 7cad7b7db43f405c88114145f14c81ce805c3499,
    Node 56f455944f5652226b59055a291b47652ce48ac6,
    Go d152a4105ebe51aa63ad02d2beed0d13adc0060a.
    The Node immutable implementation pin remains 71196f2: all four pinned files are byte-identical
    at the final head, whose only extra change fixes the unit-test harness.
  • Exact-head Node CI
    and Go CI are green.
    API2 CI is also green,
    including the 95.02% changed-line coverage gate. Final acceptance receipt
    closes the pre-push living-document checkpoint, with all review/test evidence and flaky-test details.
    Contract SHA-256: 6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.

All three PRs remain experimental drafts, unmerged. No deployment or Content repin.

Scope

  • Add Transloadit.contract() and package /contract entrypoints for 37 ordinary operations and
    three bounded tus bindings. This is a package export, not a server discovery endpoint.
  • Generate types, bindings, lifecycle and tus metadata/receipt policy from API2; keep native signing,
    transport and orchestration in this SDK. Neither workflow calls legacy SDK methods.
  • Deliver wait, cancel, fixed-size Blob upload and persisted-session/fresh-client resume. Validate
    admitted destinations, exact metadata bytes, file digest and actual server offsets/receipts.
    Never forward account credentials to returned uploader capabilities.
  • Retry only bounded safe reads/tus recovery and honor HTTP backoff. Never automatically repeat
    creation or cancellation. Reconcile ambiguous PATCH acknowledgements before sending more bytes.
  • Return REQUEST_ABORTED as a finite, unsuccessful wait result. Explicit cancel still contacts
    the owner once; active/aborted confirmation never conceals a failed DELETE. Neither completion
    nor cancellation promises stopped workers or billing.
  • Preserve explicit caller abort reasons, including TypeError before headers. Retain received
    HTTP status/backoff for request-owned timeouts and both failed DELETE/GET attempts in ordered
    AggregateError diagnostics. Default messages never include capability URLs or response bodies.
  • Ship both package names, typed examples and strict installed-package consumers. Smart CDN signing
    remains a local helper with shared exact-byte vectors.

Existing-API behavior change

The legacy polling fix makes the configured deadline effective: it aborts in-flight reads/backoff,
rejects late success and does no new poll after an exhausted budget. This affects completion waiting
from createAssembly and resumeAssemblyUploads as well as awaitAssemblyCompletion. Public API
shapes remain compatible; the changeset explicitly describes the intentional behavior change.

October 6 reader compatibility

  • Unknown nonempty Assembly error codes are terminal failures, not invalid workflow responses.
    Known codes remain autocomplete hints. Malformed errors and unknown success/progress codes
    remain rejected; the public reader and current runtime emitter are tested separately.
  • Derive admission from the canonical response schema, removing the duplicate finite SDK list.
    Preserve the exact error as data, without interpolating it into diagnostic messages.
  • Keep compact atomic Go string codecs and TypeScript known-literal completion. Shared synthetic
    observations exercise 16 cases through 10 native modes per SDK (320 observations total),
    including failed-cancellation confirmation, partial resume and completed-upload receipts.
  • Fail-first review repairs cover bounded response cleanup, persisted custom upload fields,
    permanent Node fetch failures being retried, and examples/canaries losing cleanup ownership.
    Go's experimental OnSession callback now receives the derived upload context; all callers
    and the README are updated so persistence can honor the shorter upload deadline.
  • Harden Go representation reuse and getters. Naming and declarations now share branch admission;
    unsupported literal/union/intersection combinations fail generation instead of silently widening
    codecs or emitting invalid Go. Current generated clients stay byte-identical after these repairs.
    These codecs are not complete JSON Schema validators.
  • Frozen producer: b646c529fb0bf0e3aa4295c1a3208cdd028dd681.
    Native pins: Node d63d6ccce4cf0f43464d8e351eb96f493de52155,
    Go 5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c.
    Generated bytes remain those from producer f8947685ba; contract SHA-256
    4c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.
  • Post-council full API2 and Node checks pass. Node has 1,381 passing tests and one existing skip,
    plus the other workspace suites; both fresh packed package names pass strict root/subpath/example
    compilation. Go contract/shared/example race tests, vet and build pass.
  • All four source/shared/generation/actual local API2-tusd suites pass on the final native pins:
    zero failures or flakes, 2.1 minutes. All ten generated files match byte-for-byte.
    Generated client sizes remain 5,012,654 bytes (TypeScript) and 7,581,401 bytes (Go), under 6/8 MB.
  • The final source-access-verified council retains no new reader/lowering findings, only the
    explicitly deferred OAuth blocker below. The same required checks pass again after review.
  • Exact native CI is green: Node
    and all five Go versions.
    The final producer run is API2 CI;
    its final status is recorded in the immutable completion receipt below.

The authentication limitation described in this historical reader receipt is addressed by the
bounded correction above. Its former blanket OAuth release-blocker wording is superseded by the
user-approved narrower scope. Earlier CI receipts do not certify the new candidate.

Historical October 4 acceptance

  • Frozen native commit: c4c3f41f4954c348f94206863c297b30d0d04345.
  • Generated from integrated producer #9252, frozen at 0b4c13d7de0674077ddcfa390d72e676bfe50b20;
    contract SHA-256 4246893330e3fa724407e19fa3d8d49501f87132b7aff9665f850a2f10fd8c53.
    Generated client bytes are unchanged by the final native transport repair and verify exactly.
  • Full yarn check passes: 1,180 Node tests, one existing skip, plus remaining monorepo suites.
    All 287 focused native/shared cases pass, including 32 source-owned metadata/receipt observations.
    Four pre-header abort tests fail before the fix and pass afterward.
  • Both fresh installed package names strictly compile root, /contract and their shipped example,
    with exact optional properties, unchecked indexed access and declaration checks enabled.
  • Exact-head CI 37192604625
    is green: all 11 checks, including Node 20/22/24 and the Supabase Edge fixture.
  • API2's refreshed immutable source pins pass all four actual local API2/tusd/model/generation/
    shared suites: zero failures/flakes, 3.0 minutes. Complete earlier councils are triaged; the fresh
    source-access-verified final combined council reports No issues found. Full yarn check
    passes again after review, with the frozen native source and generated wrapper still clean.
  • Final fail-first review repairs retain tus HTTP status/backoff when cloned-response cleanup
    reaches the request timeout and retain the failed DELETE when confirmation inspection fails.
    Seventeen new failures reproduce the defects; nine POST/HEAD/PATCH × 403/429/503 cases and
    caller/deadline controls pass afterward. No extra cancellation write or wider URL admission.

The historical timed Opus reader completed all five live tasks on 50b659d5ac, including a process
restart and offset-confirmed resume. That receipt does not test later fixes. No additional live
credentialed tests were run; this iteration uses synthetic/native and local API2/tusd acceptance.

Boundaries

Fixed-size replayable Blobs and simple upload IDs only. Deferred lengths, concatenation and streams
remain outside this helper. Session URLs are secrets. Additional uploader origins are configured,
not inferred; proxy receipt rewriting must be consistent. Overall upload deadlines include hashing,
persistence and transfer. Types describe the wire contract, not complete response validation.

Template-content typing, deterministic multipart ordering and SSE/Webhook
receivers remain separate work. Tus identity/receipt policy lowering is completed, not an open
native inventory or adapter-side replacement feature.

All three SDK PRs remain experimental drafts: do not merge, release or deploy.
Canonical record: API2 docs/prompts/2026-07-09-handover-sdks-branch-restructure.md.
Native pre-push checklist: docs/prompts/2026-09-29-contract-finality.md; subsequent immutable
review/CI receipts here supersede its historical pending boxes without restarting CI for copy.

Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/go-sdk#47.

@kvz
kvz marked this pull request as ready for review September 25, 2026 12:57
@kvz

kvz commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Verification footprint for 30cb8807dab7b8098ba8eb5c53635c84e08b98cc against 34970b60c770a34c3dc227ad9ecb1ec9283ecd77:

799 authored additions; 29,488 generated additions; 2 deletions. Generated classifications and destructive regeneration procedure are recorded in the shared API2 receipt and maintainer guide. Generated lines are not a claim of native/runtime proof; both SDK CI and API2's local-native acceptance passed separately.

Raw canonical numstat (additions, deletions, path):

9	0	.changeset/contract-ordinary-api.md
1	0	.gitattributes
2	1	biome.json
36	0	packages/node/README.md
1	0	packages/node/package.json
20	1	packages/node/src/Transloadit.ts
297	0	packages/node/src/contractTransport.ts
13485	0	packages/node/src/generated-contract/client.ts
15894	0	packages/node/src/generated-contract/coverage.json
45	0	packages/node/src/generated-contract/manifest.json
27	0	packages/node/src/generated-contract/wire-vectors.json
162	0	packages/node/test/contractCanary.ts
271	0	packages/node/test/unit/contract-client.test.ts
36	0	packages/transloadit/README.md
1	0	packages/transloadit/package.json

@kvz

kvz commented Sep 25, 2026 •

Copy link
Copy Markdown
Member Author

Final source footprint and review receipt

The approved first-party SDK slice is implemented. Existing SDK entrypoints remain intact; the new namespaces are experimental. No SDK release, deployment or merge was performed.

Repository Base Final source head Authored additions Generated additions Deletions Files
API2 c449a7b1f871e12e30a2a544fce1739187d83cf8 8e601e6ffd274fb9f7c00032a3e2b30b3cd0f3ae 2,993 398 143 27
Node SDK 34970b60c770a34c3dc227ad9ecb1ec9283ecd77 30cb8807dab7b8098ba8eb5c53635c84e08b98cc 799 29,488 2 15
Go SDK b567a3eefef5ce3e74767ba239cb00cbaf33ac2c 1897a050f4ba658787abbd9e113c2468c03f0ba0 1,363 84,283 1 11
Total 5,155 114,169 146 53

Measured with the canonical text/Myers/no-renames/no-indent-heuristic numstat command from the living document. Generated ownership: API2's generated contract; each SDK's client/manifest/coverage/vectors; Node's existing legacy-package README/package projection. All native transport, tests, documentation and receipt additions count as authored. The conservative historical authored lower bound is now 59,141, not a fully reconciled program total or an additional footprint authorization. The last API2 increment is the targeted cold-artifact test-budget correction and its CI receipt; production and generated SDK bytes are unchanged.

All council findings have dispositions and fail-first evidence in API2's repodocs/prompts/2026-09-25-sdk-contract.md (six producer, five Go, two Node rounds). Final guards are deliberately narrow and fail closed. Full yarn check, exact-byte generation checks, native wire/race/vet/example checks, actual Go 1.15 tests and both devdock SDK suites pass.

All three exact-head CI runs are now green: API2 36161865722, Node 36136692611, and Go 36153479049. The prescribed API2 watcher finished with all checks passed on September 25 at 17:34 UTC. The generator suite passed in 2.8 minutes under coverage and the actual native SDK server canary in 30.5 seconds. API2 changed-line coverage is 93.62% (514/549); the unchanged 80% gate passed. No review threads were open at this final checkpoint.

The green API2 run also reports two already nonblocking cloud-image .flaky.vitest.ts failures: Fal's visual-diff artifact upload and SVG generation's upstream 503. Their sources, fixtures, thresholds and classification are unchanged. No new test skip or failure waiver was added. The preceding related SDK regression timeout was fixed and passed, not classified as unrelated. All three PRs are ready for review; no merge, SDK release or deployment was performed.

Before landing: API2 main has since advanced by one Slack-workflow/test commit, 8e5c2e0dfe8a2e2f963324a7ec9140179945c165 (#9258). API2 is mergeable but behind and still needs review; integrate and validate that main update before merging. The exact-head CI and footprint receipt above remain unchanged. Node and Go are cleanly mergeable.

Producer first, then consumers:

@kvz
kvz marked this pull request as draft September 28, 2026 15:40
@kvz

kvz commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Type-identity acceptance receipt, September 28, 22:24 UTC.

  • Exact head 1e9256c25864e21d1fd988b7c5b804231bd81ef2 passes all 11 applicable checks in
    CI run 36491185155, attempt 2.
    The watcher exited successfully. Node 20/22/24, both verification jobs, package build, installed
    consumers, E2E, Next.js, release dry run and real Supabase Edge are green.
  • Attempt 1 failed only while pulling the pinned public ECR image, before SDK execution:
    toomanyrequests: Data limit exceeded. Only that failed job was retried, without source changes.
    No bundle budget or assertion was relaxed.
  • Full local yarn check passes after the last backoff fix. Two regressions failed first and now
    preserve got's AbortError/TimeoutError for non-polling calls, without an additional HTTP request.
    The 46 targeted HTTP/polling/workflow cases pass. Both installed-package strict compiler probes
    passed after the type and packaging migration; generated source still matches API2 exactly.
  • Both council rounds finished. The repeat's backoff issue is fixed. Its separate example cleanup
    issue is not claimed as fixed: the next wait/cancel slice must safely admit and use the returned
    uploader URL, then verify terminal cancellation. This also applies to Go and is recorded in API2's
    canonical living document. No third full council run is claimed for the final narrow backoff fix.

This closes exact-head Node CI monitoring, not the workflow-readiness merge gate. The PR remains
draft. No merge, release, deployment or new workflow implementation occurred.

https://github.com/transloadit/api2/pull/9252
#517
transloadit/go-sdk#47

@kvz

kvz commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Wait/cancel acceptance receipt (2026-09-29)

Candidate: 35cabd5927d686abb35fd25cf2c1820cda7d113e. This remains an experimental, unmerged draft.

  • waitForAssembly and cancelAndWaitForAssembly call generated operations, retain the admitted uploader and do not fall back to legacy orchestration.
  • Focused lifecycle/HTTP/shared suites: 155 passed, one pre-existing skip. Both helpers now accept the contract's ok: null terminal-error shape. Tests also cover explicit versus response-only IPv6, invalid trusted configuration, proxy prefixes, redirects, owner/ID changes, retry/deadline races and credential isolation.
  • Full yarn check passes after the final independent council review; that review reports No issues found.
  • Exact-head CI is green, including Node 20/22/24 and both strict installed-package probes.
  • Both generated consumers passed producer byte checks. API2 candidate adeaef40ba89b05652eac0809126d2c794b9f265 pins this Node source and Go 54bde4cac0ee8370a1976d40e6c8c0a5aada8416; its four fresh local suites pass with zero flakes, including actual completion and owner-routed cancellation canaries.

API2's full remote CI and the last Go review are separate outstanding gates, not implied green by this Node receipt. No new blind-reader test, release, deployment or merge is claimed. Tus/upload/resume remains a later slice; existing coverage is retained until its replacement exists.

Producer: https://github.com/transloadit/api2/pull/9252. Go companion: transloadit/go-sdk#47.

@kvz

kvz commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Upload/resume acceptance receipt, September 29

This closes the upload/resume slice's historical pending review/check items in the canonical living
document and repodocs/prompts/2026-09-27-sdk-dx.md. It is not merge, release or deployment approval.
All three PRs remain draft.

Repository Exact candidate CI
API2 49824420400c6947a39a260c314ef26a1d95d608 Green: API2, attempt 2, Utils, CRM routing, Statuspage
Node 88ec0f37a201ceff422696f2e6fedf8b4527ee26 Green: all 11 checks
Go ee28c68dd85d3878c0affffaa429714628581edc Green: all five Go versions

Local acceptance

  • Full API2 and Node yarn check pass. Node's focused native/shared suites pass 213 tests.
  • Both packed Node package names pass strict installed-consumer compilation, including their
    contract entrypoints and shipped example.
  • Go go vet ./..., native/example race tests and shared workflow race tests pass.
  • Canonical contract/OpenAPI and both generated SDKs pass exact-byte check mode.
  • All six post-main pinned devdock suites pass: workflow paths, Companion compatibility,
    dispatch-registry, SDK generation, shared SDK workflows and actual local API2/tusd native canaries.
    The owned clone-7 test container is stopped afterward; its persistent volume is retained.

Main a4f9e02f4e landed while the preceding CI was running. The one conflict was in workflow tests:
retain both SDK Go-toolchain guards and remove only the obsolete vendored Companion hydration
tests, matching main's published-package migration. Generated contract/SDK bytes are unchanged.
Superseded API2 runs 36593626095 and 36590500301 were canceled after the new merged candidate
was pushed; cancellation is not a passing CI result. Node/Go commits did not change.

API2 attempt 1 stopped in the Core suite before the API2 suites: 161/162 Core suites passed and
core/test/unit/alphalib/net.vitest.ts failed its negative TCP-readiness assertion because the
promise resolved instead of rejecting. Both the test and core/alphalib/net.ts, plus Core's package
and lockfile, are unchanged from main. Their Git blob IDs are respectively
c70734526c6c8f1bb2d5c56c7aa54ed4bd347d0a and 3b77eee8fc5c4d9a358ae78901e20b672830c7f7.
The fixture closes an ephemeral listener, then assumes that port stays unavailable. A disposable
devdock reproducer that binds a second listener in that gap triggers the identical assertion;
the original isolated suite passes. This verifies the unrelated fixture race, not which process
held the port in CI. The probe is retained only under ignored local evidence and the container is
stopped. No assertion was weakened. Only the failed CI job was retried on the unchanged commit;
attempt 2 confirms all 162 executed Core suites pass, including this TCP test (one non-test fixture
is skipped), and the complete workflow is green. Stabilizing this inherited negative-port fixture
is a separate follow-up. The intermediate report is retained under
tmp/sdk-tus.vVDVAO/api2-attempt2-results.json, generated at 2026-09-29T16:36:07.172Z.

The final API2 report records 1,821 passed suites, 19 passing suites already marked flaky, one
non-blocking flaky failure and 67 skips. Every SDK-specific suite (models, command, generation,
shared workflows and native runtime) passes without a flaky disposition, as do dispatch-registry,
workflow paths and Companion compatibility. The remaining flaky failure is the pre-marked
cloud_ai/image_generate/provider-fal.flaky.vitest.ts image comparison: difference 0.0903001
against threshold 0.05. Its test, comparison helper and fixture are unchanged from main. No image
fixture, threshold, skip or flakiness marker was changed to obtain green.

GitHub tested merge 17c47d1b16d8c10dd4eee9082aa7090a8cfff8b5, whose parents are main
a4f9e02f4e and candidate 4982442040. Its tree is identical to the candidate's
df00ef5a2bf3f98ec09f1296f34c04184a0c26a3. The prescribed watcher reports six passing checks,
zero failing and zero pending at 17:19:21Z. All checkouts are clean; no owned devdock remains.

Review disposition

The last API2 council found no issues. All accepted native council findings are reproduced and
fixed, with fail-first regressions. The final small dispositions are not claimed as another clean
council run: processing failure does not prevent read-only confirmation of finished file transfer;
receipt URLs share capability normalization/admission; ownerless aborted cancellation retains its
unconfirmed outcome; response-body cleanup cannot discard HTTP retry/backoff metadata; configured
proxy prefixes cannot be bypassed without explicit bare-origin admission. Applicable fixes are
mirrored. Earlier fixes cover request deadlines, partial/lost PATCH responses, stopped-state write
prevention, Go buffer ownership and bounded response handling. No creation/cancel write retry.

Independent consumer evidence and limits

Both fresh Opus 5.5 readers completed all five tasks, with successful compiles and actual new-process
resume after 65,536/147,052 bytes, HEAD confirmation and no replacement POST or legacy workflow
fallback. Go completed live tasks in about 2m48s and Node in 3m10s. Neutral reports were sealed
before separate hypothetical Rauch/DHH assessments.

Those readers tested Node 50b659d5ac and Go a35909efb8, not subsequent fixes. Two automated runs
are not a human usability study or exhaustive race proof. Node's checksum/dimension observations
were not all assertions; Go recorded SHA-256 without an independent expected checksum. Shared
exact-byte vectors and local runtime tests are separate evidence. The cleanup-reconciliation
canary simulates only HEAD 404 and reads the matching receipt from real API2; it does not execute
the actual cleanup scheduler. Owned Templates were deleted, Assemblies completed/canceled and
secret checkpoints removed; results expire normally. No more live-reader writes under that budget.

Reader-driven example/transport clarification is included. Follow-ups, not implemented here:
public persisted-session parser reusing the native validator, more semantic source-owned Go names,
an honest typed Template-content view and separated consumer/maintainer guidance. Do not narrow
general Template JSON or erase null/omission distinctions merely to simplify generated types.

Companions: https://github.com/transloadit/api2/pull/9252 · #517 · transloadit/go-sdk#47.

@kvz

kvz commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Exact-head CI receipt: 49420a62cf630a40fee8a42c1731ce7db1190cf8 is green in run 36627613893, all 11 checks passing, including Node 20/22/24 and Supabase Edge. Full local yarn check and wrapper provenance check also pass after the documentation follow-up. This closes the CI gate, not the quota-blocked full council or the refreshed producer runtime-canary gate. Nothing merged or released.

@kvz

kvz commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Immutable native verification receipt

Frozen Node head: c4c3f41f4954c348f94206863c297b30d0d04345.
Exact-head CI 37192604625
passes all 11 applicable checks, including Node 20/22/24 and the Supabase Edge fixture.

  • Final source-access-verified combined Opus 5.5/GPT-6 Astra/arbiter council: No issues found.
    Full yarn check passes again afterward: 1,180 Node tests and one existing skip, plus the other
    monorepo suites. The native tree and mechanically synchronized legacy wrapper stay clean.
  • All 287 focused native/shared cases pass. Seventeen Node fail-first failures reproduce the last
    tus cleanup and invalid confirmation defects before repair; explicit caller/deadline controls
    pass afterward. No repeated DELETE or wider destination admission was introduced.
  • Both fresh packed package names compile strict root, /contract and installed-example consumers,
    with declaration checks and exact optional properties enabled.
  • API2 producer 0b4c13d7de pins this exact head and source hashes. Both generated clients remain
    byte-identical. All four actual local API2/tusd/model/generation/shared suites pass, zero failures
    or flakes in 3.0 minutes, on these final Node/Go source pins.
  • The producer's own exact-head CI 37192838803
    is also green, including the full test job and the unchanged 80% patch-coverage gate (94.65%).

These immutable receipts supersede historical pending boxes in the pre-push checklist. The timed
credentialed reader tested 50b659d5ac, not this head; no additional live-resource test was run.
All three companion PRs remain experimental drafts, unmerged and not release-ready. No release
or deployment was performed.

Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/go-sdk#47.

@kvz

kvz commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

October 6 immutable reader-slice verification receipt

This closes the forward-compatible Assembly reader slice, not the experimental SDK release.
The OAuth work below remains an explicit, user-confirmed merge/release blocker.

Frozen sources and generation

Repository Verified commit
API2 b646c529fb0bf0e3aa4295c1a3208cdd028dd681
Node SDK d63d6ccce4cf0f43464d8e351eb96f493de52155
Go SDK 5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c
  • Contract SHA-256: 4c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.
  • All ten generated consumer files match check-mode generation byte for byte. The latest producer
    safety repairs do not change the generated bytes from producer f8947685ba.
  • TypeScript remains 5,012,654 bytes and Go 7,581,401 bytes, within unchanged 6/8 MB guards.
    Immutable native source pins and per-file hashes match the verified consumer commits.

Behavior and fail-first review repairs

  • Unknown nonempty Assembly errors remain exact terminal-failure data through GET, wait, cancel,
    upload/resume and receipt handling. Known errors retain autocomplete. Malformed errors,
    contradictory states and unknown success/progress codes remain rejected.
  • The public response schema drives admission; the duplicate finite SDK error inventory is gone.
    Sixteen shared observations run in ten modes in each language: 320 synthetic observations.
    These distinguish public reader acceptance from the current runtime emitter's closed inventory;
    they do not claim production has emitted future codes.
  • Fail-first tests cover response cleanup exceeding deadlines, forgotten persisted custom fields,
    permanent Node fetch failures being retried and lost cancellation ownership in executable
    examples and actual canaries. Go's experimental OnSession receives the derived upload context.
  • Go lowering now shares representation and union-branch decisions across naming, declarations
    and getters. Unsupported literal/union/intersection combinations fail generation rather than
    widen codecs or emit uncompilable Go. Positive supported controls remain. These codecs are not
    complete JSON Schema validators.

Final verification

  • Full API2 and Node yarn check pass after council. API2 verifies all six deterministic artifacts.
    Node passes 1,381 tests with one existing skip, plus the remaining workspace suites. Both freshly
    packed package names pass strict root, /contract and shipped-example compilation.
  • Go contract, shared and example race tests, go vet ./... and go build ./... pass after council.
  • All four source/shared/generation/actual local API2-tusd suites pass on the final pins with zero
    failures or flakes in 2.1 minutes. This is local runtime acceptance, not a new credentialed live test.
  • Final source-access-verified council retains no new reader/lowering findings. Its only retained
    finding is the already disclosed and explicitly deferred OAuth blocker below. The reviewed API2
    source archive has SHA-256 a3cd55bce9ad75344dec7c89339c67e7165583e0a1ec40c895f2f51a59645a7e.
  • Exact-head Node CI and
    five-version Go CI, including
    Go 1.15, are green. API2 Utils CI
    and CRM scope checks pass.
  • Exact-head API2 CI is green:
    lint, build, tests and the patch-coverage gate pass. Changed-line coverage is 94.75% (940/992),
    above the unchanged 80% target. The structured gating summary records failedCount: 0,
    omittedFailedCount: 0 and no failing tests. Conditional deployment jobs were skipped.
  • The requested core/alphalib/bin/gh-run-watch.ts exits successfully at 10:47:09 UTC:
    five passing API2-repository checks, zero failed and zero pending. All three final source trees
    are clean, all three PRs are still draft, no review threads remain open, and build-api2 remains set.
  • Separate non-gating observation: the existing provider-fal.flaky.vitest.ts image comparison
    reports a difference of 0.0975448 against its 0.05 threshold. Its assertions reached the final
    image comparison, not an SDK reader failure. The test, shared system helper and Robot paths are
    unchanged by this branch. No flaky classification, fixture or threshold was changed to get green.

The completion receipt supersedes the pre-push pending boxes in the canonical living document
docs/prompts/2026-07-09-handover-sdks-branch-restructure.md and the existing SDK checklists.
Earlier passing snapshots and deliberately canceled superseded runs are not approval of these heads.
Local evidence is retained under studio1:/tmp/sdk-readers.c3epZn/. The owned devdock container was
stopped and removed after acceptance; its persistent data was preserved.

Next slice and release boundary

Public OAuth authorization_code and refresh_token exchanges must not require or send Basic
account credentials. The source/runtime already supports grant-specific admission, but the draft
SDK projection and client configuration still impose unconditional authentication. Fix this in the
producer and native transports, regenerate and test credentialless public grants alongside Basic
client-credentials grants. Do not patch generated files or recommend account credentials as a workaround.

The user explicitly chose to defer this authentication slice. All three PRs remain experimental
drafts, unmerged and not release-ready. No release, deployment, Content repin or additional
credentialed live-resource test was performed for this reader slice.

https://github.com/transloadit/api2/pull/9252 · #517 · transloadit/go-sdk#47

@kvz

kvz commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

October 6 completion receipt: bounded native grant authentication

This completes the final two acceptance gates in the canonical living document's October 6
checkpoint. It is acceptance of this narrow correction, not a release seal for the experimental SDKs.

Frozen revisions and CI

Repository Revision Final CI
API2 7cad7b7db43f405c88114145f14c81ce805c3499 37483773020: green
Node 56f455944f5652226b59055a291b47652ce48ac6 37483624192: all 11 gates green
Go d152a4105ebe51aa63ad02d2beed0d13adc0060a 37480359213: all five versions green, including Go 1.15

API2 build, test job and patch-coverage gate pass: 95.02% (956/1,006) changed lines covered
against an 80% target. Generation, shared workflows and actual API2/tusd native canaries each pass
in this exact CI run. The overall runner reports 1,866 regular passes, 19 premarked flaky passes,
one premarked flaky failure and zero blocking failures. The flaky failure is the unchanged
cloud_ai/image_generate/provider-fal.flaky.vitest.ts image comparison (0.076971 versus 0.05);
the test and Robot/cloud-AI sources are byte-unchanged from integrated main. No quarantine,
threshold, fixture or timeout was changed. Utils passes; CRM's workflow passes its flag checks
and correctly skips build/deployment for this final test/documentation-only push.

The old producer runs at b03b7df971 and 24d9a8c396 were canceled as superseded, not treated
as passing. Node's earlier 71196f2 run encountered a public-ECR Docker-pull rate limit before
the Edge test and passed a targeted retry. The final Node head passes its complete CI without retry.

Local acceptance and review

  • Full post-review API2 and Node yarn check pass. API2 verifies all six deterministic artifacts.
    Node reports 1,414 Node tests passed, one existing skip, plus all other workspaces.
  • All 93 focused Node auth/client tests pass; freshly packed @transloadit/node and
    transloadit pass strict root/subpath/installed-example compilation.
  • Go native/example race, offline shared/signature/type race, vet and build pass. Old credentialed
    root tests were not claimed as a local pass; existing CI owns those tests.
  • Fresh immutable-pinned generation/shared/local API2-tusd suites pass in 2.4 minutes with zero
    failures/flakes; the final selector-envelope negative regression's full generator suite passes
    again in 1.3 minutes. Both language outputs pass generation check mode and match consumer bytes.
  • Two source-access-verified combined council rounds complete. Undefined optional settings and
    mixed prototype-named selectors have fail-first repairs. The last retained finding is fixed by
    moving HTTP header assertions from the server callback into the awaited test. A suggested
    selector-envelope defect was disproved with the installed strict validator; an explicit negative
    regression and explanatory comment remain. No actionable council findings remain.
  • The final Node commit changes only that test harness. All four immutable source-pin files are
    byte-identical to 71196f2; the pin therefore remains valid. Go stays at d152a41.
    Contract SHA-256: 6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.
    OpenAPI SHA-256: c0c434452d2729ea597507a90c82d4925b36674d341ce1cf26e571d1c04cca66.

Boundaries

Form-selected account authentication and explicit credentialless configuration are implemented.
Grant proof is still required; custom transports remain trusted application code. No login/consent
UI, token store, auto-refresh manager or full OAuth workflow canary was added. Full OAuth onboarding
is not automatically a release blocker. Registration/discovery/revocation and producer-owned OAuth
error-code identity remain separately recorded follow-ups.

The existing living document is updated; this immutable receipt closes its pre-push CI checkbox.
All three checkouts are clean and the owned devdock is stopped. All three PRs remain experimental
drafts, unmerged and unreleased. No deployment or Content repin.

Companions: https://github.com/transloadit/api2/pull/9252 ·
#517 · transloadit/go-sdk#47

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant