feat(spec)!: retire the connector resilience family — health (probe + breaker), status and nested webhooks, sixteen keys nothing read (#20273) - #20350
Conversation
… nested webhooks tombstones, defs, D2, D3, pins Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…; tombstone rows regenerated Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…eference docs, strictness counts and the shrunk test-typecheck debt Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…atus default Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…n no longer spells the sibling retirement's key Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…nnector-resilience-keys-retired # Conflicts: # packages/spec/src/migrations/registry.ts
…hors the retired status Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…re note name the resilience removal Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…nnector-resilience-keys-retired # Conflicts: # packages/spec/src/migrations/registry.ts
… the merged tree; reconcile the duration-rename D3 entry with the absorbed breaker half The rename family's D3 entry (landed from the D3-per-family census) still prescribed `monitoringWindow` -> `monitoringWindowMs`; that renamed key is itself retired with the whole `health` block, so the entry now prescribes the trigger rename only and sends the breaker spelling to the removal. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
Contract reviewServed-tier: 62/62 ① Derived judgments
② Semver levelPASS. ③ Boundary flags
Implemented-by: VERDICT: PASS |
…nnector-resilience-keys-retired
Main moved the action and translation rows; the connector row keeps this branch's retirement (dead 30, total 60). Regenerated with gen:liveness-counts, never hand-merged. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
…ooks as a row that has left Review nit on the retirement: the `_containers` prose still described `connector/webhooks` as a recorded row after the row was deleted. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
📓 Docs Drift CheckThis PR changes 7 package(s): 4 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 3 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 136 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin f1c7f44fb8f7db113f71aedd920eabc5368a4a01 && git checkout f1c7f44fb8f7db113f71aedd920eabc5368a4a01
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin f39ea95961b2359b56e6b45774d0ce124f373c84 597e867f4d1c1575b22be23eb337ca84283cdad4 && git checkout -B drift-repro f39ea95961b2359b56e6b45774d0ce124f373c84 && git merge --no-ff 597e867f4d1c1575b22be23eb337ca84283cdad4
node scripts/docs-audit/affected-docs.mjs --json f39ea95961b2359b56e6b45774d0ce124f373c84
|
Fixes #20273
Clause-②: no (narrowing)
Retires the connector resilience family under ADR-0049 enforce-or-remove, one batch, by the triage verdict RETIRE (comment 5858520070) under the maintainer's criterion on #18900:
connector.health(thehealthCheckprobe, eight keys, and thecircuitBreaker, six keys),connector.statusand the connector-nestedwebhooks— sixteen authorable keys that nothing read. Authoring any of them is now a tsc error and a parse error that carries the prescription; no alias window.Census first (origin/main 3f86dc5, each zero beside a lit control)
packages/spechealth.healthCheck.*/health.circuitBreaker.*leavescircuitBreaker,fallbackStrategy,halfOpenMaxRequests,unhealthyThreshold,healthyThreshold,monitoringWindowMs,resetTimeoutMsoutside generated docs;healthCheckonly as the kernel plugin-health contract; no.health.read inpackages/connectorsorservice-automation)retryConfigread 17 times inpackages/connectors+service-automationstatus.statusreads, every one on an HTTP answer, an error case or a flow-run entryrequestTimeoutMsread off a connector entry / provider context 5 timeswebhooksstack.webhooksread 5 timesobjectui: nothing imports a removed name at the pinned
.objectui-shaf8a9d0fb (one comment mentionsWebhookEventSchema), and no connectorstatus/health/webhooksreader at objectui main 610819c40. No key had a live reader, so nopremise_still_validfork.What changed
health,status,webhooksareretiredKey()tombstones on the privateConnectorBaseSchemathat both published carriers wrap (ConnectorSchema,DeclarativeConnectorEntrySchema), sodefineConnector,registerConnector,stack.connectors[]andPUT /api/v1/meta/connector/:nameall refuse them. SixRETIRED_KEYS_BY_MAJOR[18]rows.statuswas.default('inactive'), emitted by every 17.x parse into every connector;status: 'inactive'joinsconnectionTimeoutMs: 30000inCONNECTOR_RETIRED_KEY_RESIDUE(accepted and stripped). Every other value is refused.RETIRED_DEFS_BY_MAJOR[18]):ConnectorHealth,HealthCheckConfig,CircuitBreakerConfig,ConnectorStatus,WebhookConfig,WebhookEvent,WebhookSignatureAlgorithm. The manifest keys and baseline rows were deleted deliberately after the build named them.connector-resilience-keys-removed(step 18, retired from the load path): strips the three keys fromconnectors[]and from stored rows, one notice per key; nested webhooks are stripped, never moved.connector-resilience-keys-retired(one per family, ruling B on [Decision] 一次退役,要写一条记录还是两条?—— 迁移条目的 D2/D3 约定,两处成文相互矛盾 #17152), naming the D2 and the chain below.status: 'active'in the four shipped connector packages andstatus: 'error'on the automation service's degraded husk were writes nothing read back; tsc found the husk's test fixture too.packages/spec/docs/SYNC_ARCHITECTURE.md: the "Monitoring: Health checks" tick is gone, and so are the ticks and example lines this retirement made false (connector webhooks, circuit breaker,status: 'active'); the doc's compile gate (connector-author-shape.test.ts) holds the example.automation/webhook.zod.ts: its connector-webhook note is corrected, and theextraKeys: ['signatureAlgorithm']suggestion is dropped (the only surface accepting that key is gone, so a typo on the delivered webhook would have been pointed at a refused key).statusandwebhooksstay onedeadrow each, now tombstones;connector/webhooksleft the undrilled baseline (the gate called it stale);state-counts.mdand the README notes cell regenerated / corrected (dead 44 to 30).migrations/registry.ts,api-surface/,declaration-map/,export-origins/,authorable-surface/,authorable-defaults/,json-schema.manifest/,content/docs/references/**, strictness counts,test-typecheck-debt.json(shrink only).spec-changes.jsonanddocs/protocol-upgrade-guide.mddo not move: they fold majors up toPROTOCOL_MAJOR17, and this is step 18 (check:spec-changes/check:upgrade-guidegreen).docs/adr/0122-...mdis NOT edited: no gate forced it.type-alias-convention.pin.test.tsloses the three isomorphic pins of the removed enums (786 to 783), the way the error-mapping precedent did.Deviations from the dispatch's mechanism assumptions (measured)
ConnectorHealth/ConnectorStatusto leave viaRETIRED_DEFS_BY_MAJOR. Both cannot hold for the fourteenhealth.*leaves: onceConnectorHealthleaves, its leaves have no shape to carry a tombstone. I followed the error-mapping precedent (13c48c2): one carrier tombstone per key the walk still reaches (health,status,webhooks), defs whole.health.*rows cannot stay: withhealtha leaf,check:livenessrefuses them (measured:connector/health (declared children but property is not a container)).healthis onedeadtombstone row whose note carries the fourteen verdicts and their census.connector-health-and-trigger-durations-unit-in-keyis impossible under the conversion table's disjoint-fixture contract: the rename's own fixture carries ahealthblock that the removal strips. Perspec-property-retirement§0 (same unreleased step) the breaker half is ABSORBED: the rename now carries onlytriggers[].interval, and the removal serves an author holding either spelling (a pin replaysmonitoringWindowplus a triggerintervaland gets exactly one rename notice and one removal notice).plugin.ts:1792was not comment-only. The line under that comment WROTEstatus: 'error'into the husk def, which the tombstone makes a tsc error and a registration-time parse refusal; the write is deleted and the comment corrected.automation/webhook.zod.ts(orphanedextraKeys), plugin-webhooks' docblock and its pin test's docblock (they quoted the retired spec prose),rest-server.test.ts(a stale comment),connector-author-shape.test.ts,type-alias-convention.pin.test.ts.Acceptance notes
mainwas merged here and its D3 entryconnector-resilience-durations-unit-in-keyis reconciled in this PR: it now prescribes onlytriggers[].intervaltointervalSecondsand tells an author holdingmonitoringWindow/monitoringWindowMsthat the renamed key is itself retired (delete thehealthblock).triggers[].intervalis untouched otherwise.@objectstack/specis not measured.Evidence (head 153f652)
pnpm --filter @objectstack/spec buildgreen (manifest and baseline gates fired on the seven defs first, as they must on a whole-def removal, then passed once the rows were deleted deliberately).check:generated: all 15 artifacts current.check:liveness,check:migration-registry,check:spec-changes,check:upgrade-guidegreen.node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commandsat 153f652, reconciled with--ran: 118 derived, 113 run with exit 0, 5 NOT MEASURED —check:skill-examples,check:dual-build-cjs-loads,check:i18n,check:type-check-debtrefused with exit 3 (PREREQUISITE NOT MET: builds outside this diff's closure — client-react, the CLI plugin set, the whole monorepo),check:query-options-erasure(repo-wide ESLint scan; self-test passed, the ratchet outran a 300s per-gate bound — exit 124). CI runs all five.--project localoversrc/migrations,src/conversions,src/integration, the ADR-0122 pin,rest-server,webhook,stack— 18 files, 777 passed; spec--project repo(this PR's pin, the connectionTimeoutMs pin, the migrate-sentence pin, two sibling tree-scoped pins, three reference-tree scripts) — 8 files, 221 passed.--project local552 files / 16265 passed;service-automation146 files / 1757 passed; connector-mcp / -openapi / -rest / -slack and plugin-webhooks 27 files / 255 passed; typecheck of those six packages green; dogfoodexpression-conformance7 passed.--no-inline-config --format json): 32 files, 0 errors, 0 warnings. Population:eslint.config.mjsflat config over**/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs}; the config enables no type-aware linting (noparserOptions.project), so this diff cannot move a verdict in an untouched file. The repo-widepnpm lintis CI's.Ablation (one per closed door)
Via
node scripts/ablation-replace.mjs(anchor must hit, restore proven by blob hash equal to HEAD and an emptygit diff HEAD), on committed head 849fb62, runningconnector-resilience-keys-retirement.test.ts:healthhealth, the three-door refusal, the either-spelling breaker refusal, the walked-shape pinstatusstatus, the three-door refusal, the non-default-value refusal, the walked-shape pinwebhookswebhooks, the three-door refusal, the walked-shape pinEach leg restored to blob 704684dc6f0c (HEAD's). No permanent ablation test is left.
Generated by Claude Code