Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions .changeset/browser-async-method-identity.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@mcp-b/do-runtime": patch
---

Preserve native async-method identity when lowering browser awaits. This lets the Agents SDK keep synchronous methods synchronous while starting a cold Agent before its async methods run; lowered continuations still restore browser async context.
8 changes: 8 additions & 0 deletions .changeset/october-workerd-sync.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
"@mcp-b/do-runtime": minor
---

Align the runtime with workerd 1.20261002.1: allow multiple output-gate failure
observers, raise SQLite values to 8 MiB plus serialization padding, and support
chainable tracing span name and status updates. Pin the conformance oracle and
Workers types to the October 2 release.
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -241,7 +241,7 @@ Web Worker and supply the sqlite-wasm backend shown in the runnable examples.
For a standalone TypeScript host, install the ambient Node and Workers types:

```bash
pnpm add -D typescript @types/node @cloudflare/workers-types@5.20260911.1
pnpm add -D typescript @types/node @cloudflare/workers-types@5.20261002.1
```

Use the following `tsconfig.json`. An existing Workers project can keep its
Expand Down Expand Up @@ -490,7 +490,7 @@ The browser cannot reproduce every workerd facility. Unsupported runtime APIs th
| SQL function allowlist | Not enforced. Workerd's authorizer denies any function outside its 138-name `ALLOWED_SQLITE_FUNCTIONS` list; this runtime allows every function the backend compiled, including build-detail readers such as `sqlite_version()` and `sqlite_source_id()`. |
| SQLite internal functions and default expressions | The current engines lack workerd's internal-function and default-expression authorizer patches. Native authorizer callbacks exist in both engines, but the runtime does not wire them into its SQL policy. See the [engine findings](docs/workerd-sync.md#sqlite-engine-work-still-required). |
| PRAGMA allowlist | Workerd's allowlist enforced from tokenized SQL text. A `pragma_*` table-valued function with a string or bound argument is authorized by pragma name only, where workerd's authorizer also sees the resolved argument; the pinned conformance row is the contract. |
| Node SQLite length limit | Bound and returned strings and blobs are capped at 4 MiB; `node:sqlite` cannot cap an unreturned SQL-computed value. The browser backend uses SQLite's native limit. |
| Node SQLite length limit | Bound and returned strings and blobs are capped at 8 MiB plus 34 bytes of serialization padding; `node:sqlite` cannot cap an unreturned SQL-computed value. The browser backend uses SQLite's native limit. |
| Response BYOB readers | Refused; their continuation cannot be re-gated. Use a default reader or `arrayBuffer()`. |
| Facet `setAlarm()` | Refused synchronously, where workerd breaks the actor asynchronously ([workerd#6810](https://github.com/cloudflare/workerd/issues/6810)). |
| Alarm exception provenance | Unclassified handler failures stay retryable; browser errors lack jsg provenance. |
Expand Down Expand Up @@ -558,7 +558,7 @@ it does not need a sibling checkout, SDK source aliases, or a local candidate
archive. Publish a new source tag for each SDK change instead of replacing
an existing release's assets. The runtime's npm release remains independent.

Change runtime behaviour with the corresponding workerd source open (line citations use release `v1.20260713.1`; the conformance oracle is pinned to `v1.20260911.1`). Ask the workerd lane an observable question before inventing a local rule; record any intentional divergence in the table above and in a conformance row. Keep host seams small and typed, keep gates internal, and keep product knowledge out of the port. See [`docs/decisions.md`](docs/decisions.md) for the invariants the code cites.
Change runtime behaviour with the corresponding workerd source open (line citations use release `v1.20260713.1`; the conformance oracle is pinned to `v1.20261002.1`). Ask the workerd lane an observable question before inventing a local rule; record any intentional divergence in the table above and in a conformance row. Keep host seams small and typed, keep gates internal, and keep product knowledge out of the port. See [`docs/decisions.md`](docs/decisions.md) for the invariants the code cites.

## Acknowledgements

Expand Down
11 changes: 6 additions & 5 deletions conformance/fixtures/probe.ts
Original file line number Diff line number Diff line change
Expand Up @@ -969,15 +969,16 @@ export class Probe extends DurableObject<ProbeEnv> {
};
}

/** Workerd caps every SQLite string or blob at 4 MiB. */
/** ← workerd 1b9b6ea02: 8 MiB rows plus 34 bytes of serialization padding. */
sqliteLengthLimit(): Record<string, unknown> {
const sql = this.ctx.storage.sql;
const allowed = sql.exec("SELECT length(?) AS length", "x".repeat(4_000_000)).one();
const allowed = sql.exec("SELECT length(?) AS length", "x".repeat(8_000_000)).one();
const padded = sql.exec("SELECT length(?) AS length", new Uint8Array(8 * 1024 * 1024 + 34)).one();
try {
sql.exec("SELECT length(?)", new Uint8Array(4 * 1024 * 1024 + 1));
return { allowed: allowed.length, tooBig: "allowed" };
sql.exec("SELECT length(?)", new Uint8Array(8 * 1024 * 1024 + 35));
return { allowed: allowed.length, padded: padded.length, tooBig: "allowed" };
} catch (error) {
return { allowed: allowed.length, tooBig: String(error) };
return { allowed: allowed.length, padded: padded.length, tooBig: String(error) };
}
}

Expand Down
23 changes: 23 additions & 0 deletions conformance/suite/module.spec.ts
Original file line number Diff line number Diff line change
Expand Up @@ -51,3 +51,26 @@ it("§1.12 untraced spans expose chainable attributes and nested active scopes",
return value + 1;
}, 41)).toBe(42);
});

it("§1.12 untraced spans support name and status updates, including after end", () => {
const span = tracing.startSpan("original");
for (const ended of [false, true]) {
if (ended) span.end();
expect(span.updateName("updated")).toBe(span);
for (const code of ["unset", "ok", "error"] as const) {
expect(span.setStatus({ code, message: "unrecorded" })).toBe(span);
}
let reads = 0;
expect(span.setStatus({
get code() {
reads++;
return "ok" as const;
},
})).toBe(span);
expect(reads).toBe(1);
expect(() => Reflect.apply(span.setStatus, span, [{ code: "invalid" }])).toThrow(
"Span status code must be 'unset', 'ok', or 'error'.",
);
expect(span.isTraced).toBe(false);
}
});
5 changes: 3 additions & 2 deletions conformance/suite/sql.spec.ts
Original file line number Diff line number Diff line change
Expand Up @@ -158,10 +158,11 @@ it("§1.4 public SQL values follow workerd's JSG conversion", async () => {
});
});

it("§1.4 SQLite strings and blobs are limited to 4 MiB", async () => {
it("§1.4 SQLite strings and blobs allow 8 MiB plus serialization padding", async () => {
const probe = await host.spawn("sql-length-limit");
expect(await probe.call("sqliteLengthLimit")).toEqual({
allowed: 4_000_000,
allowed: 8_000_000,
padded: 8 * 1024 * 1024 + 34,
tooBig: "Error: string or blob too big: SQLITE_TOOBIG",
});
});
Expand Down
102 changes: 102 additions & 0 deletions docs/cloudflare-sync-2026-10-02.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
# Cloudflare refresh — October 2, 2026

This refresh advances the runtime oracle to
[workerd 1.20261002.1](https://github.com/cloudflare/workerd/releases/tag/v1.20261002.1)
and the six-package SDK fork to
[Agents 0.26.0](https://github.com/cloudflare/agents/tree/74570a19aafc676dd85831a31af047817e7bba12).
Think is 0.20.0, AI Chat 0.12.1, Codemode 0.5.3, Voice 0.5.0 and Shell 0.4.3.
Workers types match the oracle in the runtime, both examples and SDK workspace.

## Review and implementation

The [workerd audit](workerd-sync.md) covers all 688 intervening commits, with a
[complete disposition table](workerd-sync-2026-10-02.csv). The runtime ports
multi-observer output-gate failure, SQLite's 8 MiB plus 34-byte limit, and the
tracing name/status API. Unsupported distributed retry behavior remains outside
the local host contract.

The [SDK audit](../vendor/agents/docs/audit/agents-sync-2026-10-02.md) covers all
104 intervening commits. It records the exact merge base and target, imported
APIs, storage implications and reasons for retaining each local behavior.
Upstream replaces the original-method helper, React cleanup guard and most
deleted-facet routing patches. The [fork inventory](../vendor/agents/docs/fork-diff.md)
records the remaining owners and retirement conditions.

Integration fixes preserve completion metadata, Stop and cancellation evidence,
lossless stored/live replay, terminal-only delivery, and bounded recovery reads.
Browser compilation preserves async method identity so cold asynchronous RPC
initializes correctly while synchronous methods remain synchronous. Both
examples use a real browser implementation for Sessions' synchronous hashing.
The extension recovery assertion now checks one canonical assistant message
and its exact durable prefix plus continuation.

The root `sdk:test` command selects the same workerd binary as conformance.
The maintained SDK gate includes the new cold-RPC, model, browser capability,
terminal-order, metadata, prompt-cache and address-change regressions.

## Dependency work

The [security review](dependency-security.md) records every exact override,
advisory source, remaining dependency path and audit count. Compatible fixes
apply to the installed major versions. The pool and Wrangler remain on their
existing compatible versions; updating Wrangler alone would leave the pool's
older transitive copies installed. The export checker uses Node's built-in glob
instead of an otherwise-unused dependency.

The optional Evalite runner and its single credentialed scheduling evaluation
were removed after the user delegated that decision. Neither was part of the
maintained regression gate. This removes the remaining high and moderate
development-tooling advisories and two obsolete overrides without adding a
replacement framework. Runtime scheduling and its deterministic tests remain.
The lockfile drops 76 package versions and adds none; both workspaces now report
only the existing low-severity elliptic finding.

## Verification

| Gate | Result |
| --- | --- |
| Runtime unit suite | 1,022 tests passed |
| Native workerd conformance | 82 passed |
| Node conformance | 82 passed |
| Chromium conformance | 95 passed |
| Transformed Node / Chromium conformance | 82 passed in each lane |
| SDK regression gate | 3,162 passed in Linux CI: React 103, chat 639, Agents 989, AI Chat 111, Think 1,033, Voice 21, Shell 194, browser 72 |
| Final admission-failure regression | All 28 reconnect tests passed, including a new test proving an identical request can retry after terminal-state cleanup fails |
| Native browser connector | 24 passed with the local Browser Rendering simulator; teardown now targets only listening processes |
| SDK exports, formatting, lint and TypeScript | Passed for the maintained six-package closure |
| Evalite removal follow-up | Both frozen installs, all six SDK builds, `sdk:check` and 70 retained scheduling tests passed; fresh audits have no high or moderate findings |
| Runtime and example TypeScript | Passed |
| Runtime package | Build, publint, declaration checks and installed-package smoke passed |
| SDK packages | All six release tarballs packed; export targets exist and release dependency ranges contain no workspace/file references |
| Dependency installation and oracle | Both frozen lockfile installs and all four Workers type pins passed |
| Extension Chromium journey | Passed, including exact recovery content, Stop, host recreation and alarm watchdog |
| Vibe platform | Production build and Chromium journey passed, including exported Worker deployment dry run |

The tracing getter follow-up was verified separately in all three ordinary
conformance lanes after the full runtime gate. Windows launcher syntax was
reviewed; Windows execution was not tested. These are maintained
regression gates, not every optional upstream evaluation or live-provider test.

## Rollout policy

The release can proceed for existing 0.24 consumers without a browser export
migration: no retained package subpath was removed, `CdpSession` remains an
alias, and the deleted interaction contract was unexported. Think's AI 7 / React
SDK 4 peer floor already matches this fork. Native RPC users with unnamed
Durable Object IDs must adopt named addressing.

- **Forward-only upgrades:** the user explicitly chose not to support
downgrades of migrated stores. Fixes roll forward; no downgrade compatibility
layer or rollback project will be added. Existing forward migrations remain
necessary to preserve stored user data during upgrades. Old 0.24 writes can
leave the new Sessions content digest stale, and old recovery code does not
recognize completed legacy-fiber markers. The
[SDK audit](../vendor/agents/docs/audit/agents-sync-2026-10-02.md#storage-and-rollout)
retains the exact source and scope of those unsupported downgrade behaviors.
- **Optional evaluation tooling:** remove Evalite and its optional live-model
scheduling sample. The remaining low-severity browser-crypto finding is
recorded in the security review; there is no pending Evalite migration.

No release was published and no application deployment or stored user data was
modified by this refresh. Work was isolated from the original checkout's
uncommitted README, lint configuration, package and tooling edits.
8 changes: 4 additions & 4 deletions docs/decisions.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,9 @@ the index the citations resolve to, not a second specification.
Workerd line citations throughout the source use release `v1.20260713.1`, commit
`03c396e9b14ea5644dfcfb696086d8df040a4efc` of
[cloudflare/workerd](https://github.com/cloudflare/workerd). The conformance
oracle is pinned separately to release `v1.20260911.1`, commit
`925464ba9fe5751e4468626ce77f7a5810df274f`.
The [September sync audit](workerd-sync.md) records the reviewed changes and
oracle is pinned separately to release `v1.20261002.1`, commit
`51a48a5bb7863fbeab791358bee8dff22c3ce83f`.
The [workerd sync audit](workerd-sync.md) records the reviewed changes and
remaining host-engine differences. New source comments name their upstream
commit when the July line baseline no longer applies.

Expand Down Expand Up @@ -297,7 +297,7 @@ consumer peer dependencies retain one identity.
| The pinned SQLite engines lack workerd's default-expression and internal-function patches | Native callbacks alone cannot enforce these new restrictions; the [sync audit](workerd-sync.md#sqlite-engine-work-still-required) records observed engine behavior and the required follow-up |
| A native outbound WebSocket handshake cannot wait for storage confirmation | Actor-global `new WebSocket(url)` throws before opening the connection; pairs and host-owned transports remain supported |
| No tracing observer or generic async span context | Spans are no-ops; active identity is scoped to the synchronous callback and is restored on return or throw |
| `node:sqlite` exposes no `sqlite3_limit()` | Bound and returned strings and blobs enforce workerd's 4 MiB limit; SQL-computed values that are never returned may exceed it. The browser backend sets the native limit. |
| `node:sqlite` exposes no `sqlite3_limit()` | Bound and returned strings and blobs enforce workerd's 8 MiB plus 34-byte limit; SQL-computed values that are never returned may exceed it. The browser backend sets the native limit. |
| A response BYOB reader cannot be re-gated after `read(view)` | BYOB readers throw; callers use a default reader or `arrayBuffer()` |
| A workerd facet alarm appears to schedule and then breaks asynchronously ([workerd#6810](https://github.com/cloudflare/workerd/issues/6810)) | This runtime refuses facet `setAlarm()` synchronously |
| A host may lose a physical wake between durable and platform timer writes | The host timer journals an opaque one-shot token before arming; the scheduler remains authoritative |
Expand Down
Loading
Loading