Skip to content

Sync workerd 20261002 and Agents 0.26 with browser and recovery fixes - #84

Merged
MiguelsPizza merged 7 commits into
mainfrom
alex/cloudflare-october-sync
Oct 3, 2026
Merged

MiguelsPizza merged 7 commits into
mainfrom
alex/cloudflare-october-sync

Conversation

@MiguelsPizza

@MiguelsPizza MiguelsPizza commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Refresh the workerd oracle to 1.20261002.1 and the six-package fork to Agents 0.26.0 / Think 0.20.0, preserving the browser runtime, durable Stop, recovery, and reconnect contracts.

The workerd changes port multi-observer output-gate failure, the 8 MiB + 34-byte SQLite value limit, and tracing name/status updates. The SDK integration adopts upstream override detection, React cleanup/address reset, and deleted-facet routing while retiring equivalent local implementations. Regression fixes preserve async method identity, completion metadata, stored/live replay ordering, request-owned resume offers, terminal-only delivery, and bounded cancellation recovery. Both examples now supply the synchronous browser hashing required by Sessions.

Reviewed upstream ranges: workerd (688 commits), Agents (104 commits). The committed audits contain a disposition for every commit and distinguish endpoint integration from per-commit testing.

Compatible security fixes and removal of the optional Evalite runner reduce root advisories from 18 to one low and vendor advisories from 62 to one low. Evalite served only a credentialed scheduling-quality sample outside the maintained gate; remove its sample and command, 76 package versions, and two obsolete overrides. Runtime scheduling and its deterministic tests remain. Node's built-in glob replaces the only use of fast-glob. The remaining elliptic fix is not published. Security details records exact selectors and advisory sources.

Validation: 1,445 runtime/unit/conformance tests across all five host lanes; 3,162 SDK regression tests using the same October 2 workerd binary; 24 native browser-connector tests; exports, formatting, lint, and TypeScript; both Chromium examples; package validation and all six SDK tarballs. After Evalite removal, both frozen installs, all six SDK builds, SDK checks, and all 70 retained scheduling tests pass; fresh audits confirm no high or moderate findings. Exact counts and limitations are in the refresh report.

The follow-up CI run exposed two browser-test timing assumptions: a default loader suspended on an unsupported history endpoint, and a reconnect wait accepted the original connection identity before the deferred close. The tests now use address-specific history responses and require a second identity handshake, while retaining real WebSockets, token-routing checks and terminal-close assertions. Both causes were reproduced; three consecutive full React runs (103 tests each, retries disabled) and SDK checks pass. The complete Linux CI run passes on commit e461a7df, including all SDK and runtime tests, both Chromium examples, package validation and all six SDK tarballs.

Upgrades are forward-only. Preserve migrations that carry existing actor data and queued work into the current version; downgrading code against upgraded stores is unsupported. No rollback compatibility layer or Evalite replacement is added to the maintenance backlog. No retained browser package export subpath was removed. No package publication or deployment is included.

Port Cloudflare's sticky multi-observer failure signal so storage harnesses and IoContext can share the same gate. Remove the test-only workaround that reserved its single notification slot.

Upstream: cloudflare/workerd@275f7b2

Validation: 217 gate, storage, and loader tests passed; the added two-observer case failed before the port.
Move the exact oracle to 1.20261002.1 and Workers types to 5.20261002.1.
Update the tracing span name/status API and the SQLite value limit to
8 MiB plus 34 bytes in the same commit so conformance remains coherent
when the oracle changes. Read status.code once to match native getter
semantics, and cover the exact SQLite boundary in all host lanes.

Guard the oracle and example type pins against drift. Source provenance
tracks the deployed tag rather than an arbitrary newer upstream commit.

Upstream: https://github.com/cloudflare/workerd/releases/tag/v1.20261002.1
SQLite: cloudflare/workerd@1b9b6ea
Validation: workerd, Node, Chromium and transformed conformance; targeted
getter-side-effect coverage agrees with the native runtime.
Audit the full September 7 through October 2 range, including the gap left by the September 11 re-pin. Keep source ports distinct from host-only RPC retry, eviction, native engine and separate-service changes; link all 688 commits in the review ledger.

Upstream: cloudflare/workerd@v1.20260907.1...v1.20261002.1

Validation: 1021 unit tests and all five conformance lanes passed (82 workerd, 82 Node, 95 browser, 82 each transformed lane). Oracle consistency check passes.
Advance the retained six-package closure from c076e4c9 to 74570a19. Review
all 104 intervening commits and merge against the recorded upstream base,
retiring local method-override, React cleanup, and deleted-facet code where
upstream now owns the same behavior.

The new SDK initializes cold async RPC, hashes Sessions content, and tracks
stream sequences and terminal-only child events. Preserve native async-method
identity through browser await lowering, provide synchronous browser hashing
in both examples, and reconcile these upstream changes with durable Stop,
canonical completion metadata, atomic live replay, and request-owned resumes.
Keep this integration together because the vendored lifecycle wrapper and
browser compiler changes must ship together.

Align Workers types and run the SDK with the exact runtime workerd oracle.
Apply compatible security fixes in both dependency graphs and replace the
only fast-glob use with Node's built-in glob. Record remaining Evalite and
browser-crypto advisories rather than forcing unsupported major overrides.

Upstream: cloudflare/agents@c076e4c...74570a1
Validation: expanded SDK/native/browser suites, runtime conformance, both
browser examples, frozen installs, exports, types, lint, and package checks.
The committed audits retain exact counts, scope, and migration limitations.
Tie the workerd and Agents commit inventories to the final runtime, SDK, browser, package and lockfile checks. Separate the verified forward migration from untested downgrade behavior, and record the optional evaluation-tooling choice without treating compatible dependency overrides as a clean security audit.
@MiguelsPizza
MiguelsPizza marked this pull request as ready for review October 3, 2026 01:49
Evalite only served a credentialed scheduling-quality sample outside the
maintained SDK gate. Remove that sample, its command and runner rather than
maintaining a separate application dependency graph. Regenerating the lockfile
removes 76 package versions; Fastify and find-my-way overrides are now unused
and can go too. Both workspaces retain only the existing low elliptic finding.

Record forward-only upgrades as the support policy. Preserve migrations needed
to read existing actor data and queued work, but do not create downgrade
compatibility layers or a rollback backlog. Keep the Evalite exclusion in the
fork inventory so future upstream syncs do not restore it accidentally.

Validation: both frozen installs, all six SDK builds, SDK export/format/lint/type
checks, 70 deterministic scheduling tests on the pinned workerd, and fresh audits.
Runtime implementation and maintained regression coverage are unchanged.
CI exposed two browser test races. The default history loader suspended on a cold 404 from TestStateAgent, which has no history endpoint, outlasting the mount helper. Supply address-specific history responses through the real default loader and assert both rendered histories and every completed-load token URL.

The close RPC returns before its deferred socket close, so identified could still describe the original connection. Require the second identity callback and the observed nonterminal close before sending the terminal close; retain the real socket, RPC, error, and reconnect-policy assertions. Await rendering and asynchronous cleanup.

Both faulty assumptions were reproduced with temporary diagnostics, then removed. Validation: three consecutive 103-test React runs with retries disabled on workerd 1.20261002.1; SDK exports, format, lint, and type checks; independent Astra review.
@MiguelsPizza
MiguelsPizza merged commit 2213762 into main Oct 3, 2026
1 check passed
@MiguelsPizza
MiguelsPizza deleted the alex/cloudflare-october-sync branch October 3, 2026 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant