Skip to content

Upgrade to Zod 4.5 and compile schemas - #3902

Merged
VaguelySerious merged 18 commits into
mainfrom
codex/zod-4-5-schema-compilation
Sep 11, 2026
Merged

VaguelySerious merged 18 commits into
mainfrom
codex/zod-4-5-schema-compilation

Conversation

@NathanColosimo

@NathanColosimo NathanColosimo commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Description

Upgrade the workspace Zod catalog to 4.5.4.

Enable compilation on SDK-owned Zod schema roots across the World contract and the local, Postgres, Vercel, and testing packages using z.compile(schema). Derived schemas are compiled after methods such as .refine(), .extend(), and .transform() create the final schema. Existing Zod import styles are preserved, and published libraries do not import the application-global zod/compile preload.

The recursive JSON z.lazy() schema remains on the standard parser. Directly compiling it during its const initialization breaks the self-reference, and Zod does not compile recursive schemas after a safe two-stage construction.

The Zod 4.5 migration also makes two previously implicit Vercel response behaviors explicit:

  • A response-only event wire schema accepts payload fields omitted for lazy/unresolved data, while CreateEventSchema remains strict.
  • The no-page create-event response branch explicitly allows omitted events, cursor, and hasMore keys.

No public event schemas or unrelated wire behavior are changed. This PR includes the terminal lazy-run compatibility fix from #3914 through the latest main merge.

Current verification

  • @workflow/world: 169/169 tests passed
  • @workflow/world-vercel: build passed; 584/584 tests passed
  • Biome formatting/check and diff checks passed
  • The bundle-size gate has the allow-bundle-size-growth label for the intentional Zod compiler payload

PR Checklist - Required to merge

  • 📦 pnpm changeset was run to create a changelog for this PR
  • 🔒 DCO sign-off passes
  • 📝 Ping @vercel/workflow in a comment once the PR is ready, and the above checklist is complete

Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
@changeset-bot

changeset-bot Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 02904de

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
Name Type
@workflow/ai Patch
@workflow/cli Patch
@workflow/core Patch
@workflow/world Patch
@workflow/world-local Patch
@workflow/world-postgres Patch
@workflow/world-testing Patch
@workflow/world-vercel Patch
workflow Patch
@workflow/builders Patch
@workflow/next Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/web Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
example-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-astro-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-express-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-fastify-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-hono-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-nitro-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-python-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workbench-vite-workflow Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workflow-docs Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workflow-swc-playground Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workflow-tarballs Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC
workflow-web Ready Ready Preview, v0 Sep 11, 2026 3:26am UTC

@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

✅ All tests passed

⚠️ Flaky E2E Tests (passed on retry)

These tests failed at least once and passed on a retry. A recurring entry here is a real race worth investigating.

  • addTenWorkflow (vite)
  • cancelRun via CLI - cancelling a running workflow (express)
  • cancelRun via CLI - cancelling a running workflow (hono)
  • cancelRun via CLI - cancelling a running workflow (nextjs-turbopack)
  • cancelRun via CLI - cancelling a running workflow (nextjs-webpack)
  • cancelRun via CLI - cancelling a running workflow (nitro)
  • cancelRun via CLI - cancelling a running workflow (sveltekit)
  • experimental_retention: 0 purges the run payloads once the run finishes (vite)
  • promiseAllWorkflow (nuxt)

🛠 Infra Events (absorbed by the harness)

Platform anomalies the e2e harness detected and worked around (e.g. a run the queue never picked up, replaced by a fresh run). Clustered timestamps indicate a backend blip; a steady drip indicates a platform issue worth escalating.

  • cold-start-warmup · suite warmup (tanstack-start) · at 03:28:44Z · abandoned wrun_01M2784H03HF9ZJ8YCT2SSWH91
  • run-pickup-stall · hookCleanupTestWorkflow - hook token reuse after workflow completion (nextjs-webpack) · at 03:33:05Z · abandoned wrun_01M278CWBSTB1CW470GZCGN07Z

E2E Test Summary

Summary
Passed Failed Skipped Total
✅ ▲ Vercel Production 3662 0 685 4347
✅ 💻 Local Development 3922 0 586 4508
✅ 📦 Local Production 3922 0 586 4508
✅ 🐘 Local Postgres 3922 0 586 4508
✅ 🪟 Windows 320 0 2 322
✅ 🌐 Cross-language Conformance 68 0 74 142
✅ vercel-http-transport 823 0 143 966
✅ vercel-multi-region 27 0 0 27
✅ vercel-ws-transport 557 0 87 644
Total 17223 0 2749 19972
Details by Category

✅ ▲ Vercel Production

App Passed Failed Skipped
✅ astro-node 133 0 28
✅ astro-quickjs 133 0 28
✅ example-node 133 0 28
✅ example-quickjs 133 0 28
✅ express-node 133 0 28
✅ express-quickjs 133 0 28
✅ fastify-node 133 0 28
✅ fastify-quickjs 133 0 28
✅ hono-node 133 0 28
✅ hono-quickjs 133 0 28
✅ nest-node 133 0 28
✅ nest-quickjs 133 0 28
✅ nextjs-turbopack-node 158 0 3
✅ nextjs-turbopack-quickjs 158 0 3
✅ nextjs-webpack-node 158 0 3
✅ nextjs-webpack-quickjs 158 0 3
✅ nitro-node 133 0 28
✅ nitro-quickjs 133 0 28
✅ nuxt-node 133 0 28
✅ nuxt-quickjs 133 0 28
✅ python-node 66 0 95
✅ sveltekit-node 152 0 9
✅ sveltekit-quickjs 152 0 9
✅ tanstack-start-node 133 0 28
✅ tanstack-start-quickjs 133 0 28
✅ vite-node 133 0 28
✅ vite-quickjs 133 0 28

✅ 💻 Local Development

App Passed Failed Skipped
✅ astro-stable-node 134 0 27
✅ astro-stable-quickjs 134 0 27
✅ express-stable-node 134 0 27
✅ express-stable-quickjs 134 0 27
✅ fastify-stable-node 134 0 27
✅ fastify-stable-quickjs 134 0 27
✅ hono-stable-node 134 0 27
✅ hono-stable-quickjs 134 0 27
✅ nest-stable-node 134 0 27
✅ nest-stable-quickjs 134 0 27
✅ nextjs-turbopack-canary-node 141 0 20
✅ nextjs-turbopack-canary-quickjs 141 0 20
✅ nextjs-turbopack-stable-node 160 0 1
✅ nextjs-turbopack-stable-quickjs 160 0 1
✅ nextjs-webpack-canary-node 141 0 20
✅ nextjs-webpack-canary-quickjs 141 0 20
✅ nextjs-webpack-stable-node 160 0 1
✅ nextjs-webpack-stable-quickjs 160 0 1
✅ nitro-stable-node 134 0 27
✅ nitro-stable-quickjs 134 0 27
✅ nuxt-stable-node 134 0 27
✅ nuxt-stable-quickjs 134 0 27
✅ sveltekit-stable-node 153 0 8
✅ sveltekit-stable-quickjs 153 0 8
✅ tanstack-start-node 134 0 27
✅ tanstack-start-quickjs 134 0 27
✅ vite-stable-node 134 0 27
✅ vite-stable-quickjs 134 0 27

✅ 📦 Local Production

App Passed Failed Skipped
✅ astro-stable-node 134 0 27
✅ astro-stable-quickjs 134 0 27
✅ express-stable-node 134 0 27
✅ express-stable-quickjs 134 0 27
✅ fastify-stable-node 134 0 27
✅ fastify-stable-quickjs 134 0 27
✅ hono-stable-node 134 0 27
✅ hono-stable-quickjs 134 0 27
✅ nest-stable-node 134 0 27
✅ nest-stable-quickjs 134 0 27
✅ nextjs-turbopack-canary-node 141 0 20
✅ nextjs-turbopack-canary-quickjs 141 0 20
✅ nextjs-turbopack-stable-node 160 0 1
✅ nextjs-turbopack-stable-quickjs 160 0 1
✅ nextjs-webpack-canary-node 141 0 20
✅ nextjs-webpack-canary-quickjs 141 0 20
✅ nextjs-webpack-stable-node 160 0 1
✅ nextjs-webpack-stable-quickjs 160 0 1
✅ nitro-stable-node 134 0 27
✅ nitro-stable-quickjs 134 0 27
✅ nuxt-stable-node 134 0 27
✅ nuxt-stable-quickjs 134 0 27
✅ sveltekit-stable-node 153 0 8
✅ sveltekit-stable-quickjs 153 0 8
✅ tanstack-start-node 134 0 27
✅ tanstack-start-quickjs 134 0 27
✅ vite-stable-node 134 0 27
✅ vite-stable-quickjs 134 0 27

✅ 🐘 Local Postgres

App Passed Failed Skipped
✅ astro-stable-node 134 0 27
✅ astro-stable-quickjs 134 0 27
✅ express-stable-node 134 0 27
✅ express-stable-quickjs 134 0 27
✅ fastify-stable-node 134 0 27
✅ fastify-stable-quickjs 134 0 27
✅ hono-stable-node 134 0 27
✅ hono-stable-quickjs 134 0 27
✅ nest-stable-node 134 0 27
✅ nest-stable-quickjs 134 0 27
✅ nextjs-turbopack-canary-node 141 0 20
✅ nextjs-turbopack-canary-quickjs 141 0 20
✅ nextjs-turbopack-stable-node 160 0 1
✅ nextjs-turbopack-stable-quickjs 160 0 1
✅ nextjs-webpack-canary-node 141 0 20
✅ nextjs-webpack-canary-quickjs 141 0 20
✅ nextjs-webpack-stable-node 160 0 1
✅ nextjs-webpack-stable-quickjs 160 0 1
✅ nitro-stable-node 134 0 27
✅ nitro-stable-quickjs 134 0 27
✅ nuxt-stable-node 134 0 27
✅ nuxt-stable-quickjs 134 0 27
✅ sveltekit-stable-node 153 0 8
✅ sveltekit-stable-quickjs 153 0 8
✅ tanstack-start-node 134 0 27
✅ tanstack-start-quickjs 134 0 27
✅ vite-stable-node 134 0 27
✅ vite-stable-quickjs 134 0 27

✅ 🪟 Windows

App Passed Failed Skipped
✅ nextjs-turbopack-node 160 0 1
✅ nextjs-turbopack-quickjs 160 0 1

✅ 🌐 Cross-language Conformance

App Passed Failed Skipped
✅ python 68 0 74

✅ vercel-http-transport

App Passed Failed Skipped
✅ example 133 0 28
✅ express 133 0 28
✅ hono 133 0 28
✅ nextjs-turbopack 158 0 3
✅ nitro 133 0 28
✅ vite 133 0 28

✅ vercel-multi-region

App Passed Failed Skipped
✅ nextjs-turbopack 27 0 0

✅ vercel-ws-transport

App Passed Failed Skipped
✅ example 133 0 28
✅ express 133 0 28
✅ nextjs-turbopack 158 0 3
✅ vite 133 0 28

📋 View full workflow run

@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit 02904de · Fri, 11 Sep 2026 03:49:16 GMT · run logs

Backend: vercel · app: nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 197 (-74%) 💚 1582 🔴 (+44%) 🔻 1612 🔴 (+40%) 🔻 1873 🔴 (+38%) 🔻 30
TTFS stream 186 (-27%) 💚 1630 🔴 (+52%) 🔻 1646 🔴 (+49%) 🔻 1823 🔴 (+62%) 🔻 30
TTFS hook + stream 1893 (+119%) 🔻 1975 🔴 (+52%) 🔻 2001 🔴 (+46%) 🔻 2073 🔴 (+7.2%) 30
Fan-out TTFS Promise.all(100 steps) 635 (+4.6%) 865 (+5.7%) 1577 (+88%) 🔻 2876 (+62%) 🔻 10
Fan-out TTLS Promise.all(100 steps) 2591 (+63%) 🔻 5283 (+19%) 🔻 5946 (-11%) 9658 (+12%) 10
STSO 1020 steps (inline) 118 (+3.5%) 148 (+8.8%) 166 (+8.5%) 246 (+25%) 🔻 1019
WO 1020 steps 148891 (+9.3%) 148891 (+9.3%) 148891 (+9.3%) 148891 (+9.3%) 1
CRTT first chunk (pooled) 64 (-15%) 92 (-32%) 💚 99 (-63%) 💚 141 (-50%) 💚 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 74 (-24%) 164 (-34%) 232 (-52%) 520 (-17%) 172 (-39%) 10
size sweep (100/s, 160B-12KB) 81.5 (-16%) 148 (-65%) 187 (-74%) 294 (-75%) 119 (-66%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 73 (-49%) 135 (-25%) 194 (-21%) 499 (+6%) 346 (-5%) 3
replay eve-gpt-5.6-sol-2000t (1x) 88.5 (-21%) 132 (-37%) 186 (-57%) 1103 (-4%) 630 (+10%) 2
replay eve-gpt-5.6-sol-2000t (2x) 93 (-31%) 196 (-60%) 275 (-59%) 598 (-33%) 348 (-26%) 3
📈 STSO distribution vs main (inline / queue-hop histograms)

1020 steps (inline)

Cumulative STSO time: main 136104ms → this run 148683ms (Δ +12579ms, +9%)

100-150 ms  ████████████████████┃███  main 894  this 787  -107
150-200 ms  ███░┃                     main 117  this 195   +78
200-250 ms  ┃                         main   8  this  27   +19
250-300 ms  ┃                         main   0  this   7    +7
300-350 ms  ┃                         main   0  this   1    +1
350-400 ms  ┃                         main   0  this   2    +2
📈 CRTT drill-down vs main (RTT distributions & profiles)
variant  RTT 1ms→5s+             avg         p50         p90         p99     n
control  ······▄█▂▁···  134.6 (-33%)  117 (-28%)  232 (-52%)  520 (-17%)  3000
sweep    ······▅█▁····  119.2 (-57%)  114 (-40%)  187 (-74%)  294 (-75%)  3000
gw 1x    ·····▁▇█▁▁···  120.7 (-19%)  106 (-22%)  194 (-21%)   499 (+6%)  5295
eve 1x   ·····▁██▁▁▁··  123.6 (-35%)   99 (-26%)  186 (-57%)  1103 (-4%)  5186
eve 2x   ·····▁▃█▃▁···  159.7 (-41%)  138 (-36%)  275 (-59%)  598 (-33%)  7779

RTT over stream progress (avg per tenth of stream, bars scaled min→max):

control  ██▆▄▂▄▃▁▂▇  107–164ms
sweep    █▆▄▇▄▅▁█▄▄  105–130ms
gw 1x    ▆▄▂▃█▁▂▁▃▂  101–163ms
eve 1x   ▂▂▃▂▁▁█▂▂▁  94–233ms
eve 2x   ▄▁▂▂▂▆▄█▃▁  124–233ms

RTT by chunk size (avg per log size bin, ~160B → ~12KB serialized, bars scaled min→max):

sweep  ▄▃▁▆▆█▆  118–120ms

Delivery jitter over stream progress (avg positive CDV per tenth of stream, bars scaled min→max):

control  ▇▅█▄▂▄▃▁▃▆  31–55ms
sweep    ▄▅▅▇█▅▃▆▆▁  40–56ms
gw 1x    ▇▄▃▂█▁▃▁▃▃  30–44ms
eve 1x   ▄▃▅▃▁▂█▂▄▁  21–32ms
eve 2x   █▃▁▄▃▇▆▅▃▃  22–32ms
ℹ️ Metric definitions & methodology

Streams: first-chunk RTT (the stream-open path, before any buffering/backpressure), CRTT percentiles, and worst delivery stall (CDV max). Cells are medians across iterations; per-run values in the artifacts. No 🔴/🟢 marks until targets attach.

The collapsed STSO distribution section above buckets every step gap, split inline (same warm process — pure framework overhead) vs queue-hop (fresh process — dispatch, reinit, replay). █ = main, ┃ = this run, ░ = fill.

The collapsed CRTT drill-down: per-variant RTT histograms (fixed log bins, · = empty) and mean RTT/positive-CDV profile lines over stream progress and chunk size. Histograms, avgs, and profiles merge exactly across runs; p50–p99 are percentile-of-percentiles. Per-index rows live in the artifacts.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body) · Fan-out TTFS: fan-out time to first step (in-deployment start() → first of the parallel step bodies to complete) · Fan-out TTLS: fan-out time to last step (in-deployment start() → last of the parallel step bodies to complete, i.e. when the Promise.all resolves) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · CRTT: chunk round-trip time (per-chunk write → read latency, one clock domain: deployment → stream backend → same deployment) · CDV: chunk delay variation / delivery jitter (inter-arrival gap minus inter-write gap per seq-adjacent pair; skew-free; the row is each run's MAX positive value, so one stall moves it)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · Promise.all(100 steps): 100 trivial no-op steps started together in a single Promise.all; Fan-out TTFS is the first of them to complete and Fan-out TTLS the last, both from the in-deployment clientStart, so their gap is the spread the runtime adds across the fan-out · paced control (100/s, 60B): the control: 300 tiny (~60B) deltas metronome-paced at 100/s — zero workload structure, so it reads the transport floor and flush cadence, and disambiguates transport-wide vs workload-specific when a replay row moves · size sweep (100/s, 160B-12KB): same pacing as the control with deltas padded in rotation across seven log-spaced sizes (~160B–12KB) — rotation decouples size from stream position, so it isolates whether chunk size causes latency · replay gateway-gpt-5.4-nano-2000t (1x): raw provider SSE cadence captured at the AI gateway boundary (gpt-5.4-nano, the most popular gateway model; per-token deltas p50 208B = the modal production chunk size), replayed exactly as measured — the typical customer's workload; its CDV is the typical customer's real delivery jitter · replay eve-gpt-5.6-sol-2000t (1x): a captured eve turn (gpt-5.6-sol, the most-used demanding eve model; ~2000 output tokens = production p50 turn length) replayed exactly as measured — eve's envelope protocol re-ships the cumulative message so sizes ramp 142B→13KB; the demanding outlier tenant's reality · replay eve-gpt-5.6-sol-2000t (2x): the same eve capture at 2x — the headroom/stress row; real fast-tier models emit the same chunk sizes at proportionally higher rate, so time compression is a faithful speed model · first chunk (pooled): every run's seq-0 RTT pooled across all stream scenarios — the first chunk precedes any workload differentiation, so pooling samples one shared stream-open path with exact percentiles

Replay cadences (semantic sha256) — eve-gpt-5.6-sol-2000t eaf22f5946e7c61f3c65c7006d550df180cfabd4e706254a09f22aec0cfb420d · gateway-gpt-5.4-nano-2000t 6f24ac518b6b83ff1d0e85a5fe78230db192716d66a7fc6b2fe022752001d041

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600

All timestamps are deployment-side; runs are triggered in-deployment, so the CI runner and api.vercel.com sit outside every measured window. TTFS = start() → first step body (includes dispatch + any cold start); Fan-out TTFS/TTLS = first/last step completion of one Promise.all from the same anchor (the gap is the runtime’s fan-out spread); STSO/WO between step bodies; CRTT inside the workflow (excludes the api.vercel.com read path).

Cold starts stay in the numbers (real bursty-workload latency, inflates P75+); Best is the warm floor.

@socket-security

socket-security Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​zod@​4.3.6 ⏵ 4.5.410010010096100

View full report

@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Sim World

Simulated world deterministic testing for races. Traces

🟠 world-sim scenario book — 1 fail of 41 total

fence=per-spec

scenario outcome events virt replay violations
✅ smoke-no-steps completed 3 0ms ok 0
✅ smoke-one-step completed 6 0ms ok 0
✅ hook-at-step-started completed 12 0ms ok 0
✅ hook-at-step-completed completed 12 0ms ok 0
✅ hook-at-hook-created completed 12 0ms ok 0
✅ deadline-hook-wins completed 7 1.0h ok 0
✅ deadline-expires completed 7 1.0h ok 0
✅ long-sleep completed 11 30.0d ok 0
✅ hook-never-arrives stalled 3 0ms skipped 0
✅ step-retries-twice completed 10 2.0s ok 0
✅ parallel-steps completed 9 0ms ok 0
✅ hook-on-execution-state completed 12 0ms ok 0
✅ peek-hook-before-branch completed 12 0ms ok 0
✅ peek-hook-after-branch completed 12 0ms ok 0
✅ peek-hook-at-registration completed 12 0ms ok 0
✅ race-hook-before-probe completed 12 0ms ok 0
✅ race-hook-after-probe completed 12 0ms ok 0
✅ race-duplicate-delivery completed 13 0ms ok 0
✅ attr-hook-before-step completed 11 0ms ok 0
✅ attr-hook-after-step completed 11 0ms ok 0
✅ attr-from-step-body completed 13 0ms ok 0
✅ fork-hook-after-timeout completed 14 1.0m ok 0
✅ fork-hook-before-timeout completed 14 1.0m ok 0
✅ count-hook-after-timeout completed 17 1.0m ok 0
✅ count-hook-before-timeout completed 20 1.0m ok 0
✅ stale-read-step-count-fork completed 20 1.0m ok 0
✅ stale-read-equal-step-counts completed 14 1.0m ok 0
✅ step-vs-step-fork completed 12 0ms ok 0
✅ step-vs-step-fork-fenced completed 12 0ms ok 0
✅ fence-catches-benign-direction completed 12 5ms ok 0
✅ in-flight-before-decision completed 17 1.0m ok 0
❌ in-flight-before-decision-counted completed 17 1.0m ok 0
✅ in-flight-after-decision completed 19 2.0m ok 0
✅ stale-read-step-count-fork-fenced completed 20 1.0m ok 0
✅ fork-hook-wins completed 13 1.0m ok 0
✅ fork-timeout-wins completed 13 1.0m ok 0
✅ unclaimed-payload-under-fork completed 17 1.0m ok 0
✅ claimed-payload-under-fork completed 17 1.0m ok 0
✅ writers-independent-step-bodies completed 12 0ms ok 0
✅ writers-scripted-tempo completed 12 0ms ok 0
✅ cancel-mid-step cancelled 7 0ms skipped 0

Full trace: world-sim.txt

@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor
Framework Flow route Step reg. Framework output
hono 236.0 KiB (+34.4 KiB) ⚠️ 42.3 KiB (±0) 1.80 MiB (+14.1 KiB)
nextjs-turbopack 242.2 KiB (+34.4 KiB) ⚠️ 439 B (±0) 835.2 KiB (+55.8 KiB)
About these numbers

Sizes are gzip; parentheses show the change against main.
Flow route and Step reg. gate this job, on raw bytes rather than the gzip shown, at max(2%, 50.0 KiB). Framework output is informational.
⚠️ marks growth past the threshold. Add the allow-bundle-size-growth label to accept it.

02904de · run

Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
…compilation

# Conflicts:
#	packages/world/src/runs.ts
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>
Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>

@vercel vercel Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional Suggestion:

The legacy v1Compat path parses /v1/runs/{id}/events responses with the bare EventSchema, which under Zod 4.5 throws SCHEMA_VALIDATION when a hook_received response omits the required payload key, breaking hook resume for legacy spec-1 runs.

Fix on Vercel

vercel Bot and others added 4 commits September 10, 2026 21:51
…es with the bare `EventSchema`, which under Zod 4.5 throws `SCHEMA_VALIDATION` when a `hook_received` response omits the required `payload` key, breaking hook resume for legacy spec-1 runs.

This commit fixes the issue reported at packages/world-vercel/src/events.ts:687

## The bug

In `packages/world-vercel/src/events.ts`, `createWorkflowRunEventInner`'s `v1Compat` catch-all POSTs to the legacy `/v1/runs/{id}/events` endpoint and validates the response with the **bare** `EventSchema`:

```ts
const wireResult = await makeRequest({
  endpoint: `/v1/runs/${encodeURIComponent(id)}/events`,
  options: { method: 'POST' },
  data,
  config,
  schema: EventSchema, // <- bare, strict schema
});
```

`makeRequest` (`packages/world-vercel/src/utils.ts`) runs `schema.safeParse(parseResult.data)` and throws a `WorkflowWorldError` with code `SCHEMA_VALIDATION` on failure.

Under Zod ~4.5, an object property backed by `z.any()` / a union-with-`z.any()` is **no longer implicitly optional** — a *missing* key fails parse. `HookReceivedEventSchema` declares `payload: SerializedDataSchema` as a **required** key, and `SerializedDataSchema` is `z.union([BinarySerializedDataSchema, LegacySerializedDataSchemaV1(z.any())])`.

Commits `6971586` / `c3dc008` / `19adcf9` ("Fix Zod 4.5 Vercel event response parsing") fixed this regression for every v4 site by introducing `VercelEventWireSchema` in `events-v4.ts` — a preprocess/transform wrapper that materializes an omitted payload as a private `OMITTED_EVENT_PAYLOAD` sentinel before `EventSchema.parse`, then strips only that synthesized value again. It replaced `EventSchema` at the three v4 decode call sites and in `CreateEventV4BodyBaseSchema` / `CreateEventV4PageSchema` — **but the `v1Compat` catch-all in `events.ts` was left on bare `EventSchema`.**

## Reachability

*   `resumeHook<T = any>(token, payload)` accepts any payload, including `undefined`. For legacy runs it takes the `v1Compat` path (`isLegacySpecVersion(hook.specVersion)`), dehydrates via the JSON `revive(stringify(...))` branch, and posts `eventData: { payload: dehydratedPayload }`.
*   When the resume payload is `undefined` (a signal-only hook / empty webhook body), the legacy v1 server has no payload value to echo back, so its JSON response's `eventData` omits the `payload` key entirely — exactly the "event responses may omit an unresolved payload field" contract that motivated `VercelEventWireSchema`.
*   The response is then parsed with bare `EventSchema`, which now throws `SCHEMA_VALIDATION`. This error is not a `HookNotFoundError`/`RunExpiredError`, so resume-hook rethrows it and the hook resume fails.

Confirmed the new regression test (`hook_received` response with `eventData: {}`) fails against bare `EventSchema` and passes against `VercelEventWireSchema`.

## The fix

*   Exported `VercelEventWireSchema` from `events-v4.ts`.
*   Imported it into `events.ts` and swapped `schema: EventSchema` → `schema: VercelEventWireSchema` in the `v1Compat` catch-all, matching every v4 site. Removed the now-unused `EventSchema` import.
*   Added a regression test asserting the `v1Compat` path parses a `hook_received` response whose `eventData` omits `payload`.

`pnpm typecheck` is clean and all 52 tests in `events.test.ts` pass.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: VaguelySerious <mittgfu@gmail.com>
Merging main (which added the world-local retention/purge feature)
into this Zod 4.5 branch surfaced a real behavior change: Zod 4.5
rejects a required object key that is entirely absent, even when the
field's own schema (a union ending in z.any()) would accept
`undefined` as a value. Zod 4.3.6 tolerated the missing key.

world-local's zero-retention purge deletes an event's payload ref
field (input/result/error/payload) outright rather than writing it
back as an explicit `undefined`. Under Zod 4.5 this makes
`run_created`/`step_created`/`step_completed`/etc. events fail
EventSchema validation after a purge, and paginatedFileSystemQuery
silently drops them, corrupting storage.events.list() for any
zero-retention run (packages/world-local/src/storage/run-retention.test.ts
"drops every event payload but keeps the log" caught this).

Rather than loosening the shared @workflow/world EventSchema (which
also backs the create-time contract used by world-vercel, e.g.
run_created requiring input when the run is actually being created),
add a world-local-local ReadEventSchema that restores a purged ref
field as an explicit `undefined` before delegating to EventSchema.
Every read of a stored event in events-storage.ts now goes through it.

Separately, world-postgres's retention.test.ts seeds a step_completed
event with `eventData: { output }`, but the schema (and storage.ts's
own step-completion handler) expects `result`. This slipped past Zod
4.3.6 for the same missing-required-key reason and broke all 16 tests
in that file under Zod 4.5. Fixed the seed to use `result`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
main advanced since the previous merge (including the devalue bump
and a new replayDivergence.eventIds field on WorkflowInvokePayloadSchema).
Resolved the WorkflowInvokePayloadSchema conflict in packages/world/src/queue.ts
by keeping this branch's z.compile() wrapping and folding in main's new
eventIds field and its doc comment. pnpm-lock.yaml/pnpm-workspace.yaml
merged cleanly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

No backport to stable for 7a46a81 (AI decision).

This is a routine dependency bump (Zod 4.3 -> 4.5) combined with a broad performance change (wrapping nearly every SDK-owned schema in z.compile), not a fix for a user-visible defect on stable. The only fix-shaped parts (the omitted-payload-tolerant VercelEventWireSchema/ReadEventSchema and the no-page create-event response branch) exist solely to absorb Zod 4.5's stricter missing-vs-undefined property semantics, so they are meaningless without the upgrade they accompany. Shipping a minor Zod bump plus a sweeping schema-construction rewrite to a maintenance line is exactly the kind of churn stable users stayed behind to avoid.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

7a46a81a53d91ddcff75b073b917a900f3cb956b

This branch was successfully deployed

18 active deployments
Preview – workflow-swc-playground — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – example-nextjs-workflow-webpack — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workflow-docs — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-nuxt-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – example-nextjs-workflow-turbopack — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-sveltekit-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-tanstack-start-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-vite-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-astro-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – example-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-fastify-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-express-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-nestjs-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-nitro-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-hono-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workflow-tarballs — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workflow-web — 02904def Deployed Sep 11, 2026 by vercel[bot]
Preview – workbench-python-workflow — 02904def Deployed Sep 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

allow-bundle-size-growth Accept intentional bundle-size growth for this pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants