Skip to content

Validate world.analytics arguments up front - #3943

Merged
karthikscale3 merged 7 commits into
mainfrom
kk/analytics-events-input-guards
Sep 3, 2026
Merged

karthikscale3 merged 7 commits into
mainfrom
kk/analytics-events-input-guards

Conversation

@karthikscale3

@karthikscale3 karthikscale3 commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

world.analytics passed its arguments straight through, so a bad id or an out-of-range page limit failed the request instead of the call. Because analytics is optional, callers wrap it in a catch — which turned those failures into what looked like an empty result.

Every method now checks its arguments first and throws a RangeError naming the limit it broke:

  • ids (runId, stepId, eventId, hookId, waitId, correlationId)
  • pagination.limit against the right cap for that listing
  • the attribute filter's pair count, key length and value size

Two arguments that used to be dropped silently now fail too: pagination.limit: 0 fell back to the default page size, and a startTime without an endTime turned a listing you meant to bound into an unbounded one that looked like a normal answer.

Also exports ANALYTICS_RUN_SCOPED_PAGE_LIMIT, ANALYTICS_PAGE_LIMIT and ANALYTICS_MAX_ATTRIBUTE_FILTERS so callers can check the bounds themselves, deprecates events.listByCorrelationId() in favour of events.list({ runId, correlationId }), and fills in the reference docs — events.getMany() was undocumented and none of the limits were written down.

Notes for review

  • The throws are synchronous, matching the existing normalizeEventIds guard in the same file. Callers using try/await are unaffected; a bare .catch() without await would not catch them.
  • analytics.events.listByCorrelationId() keeps its own implementation rather than delegating to list(): list() treats correlationId as optional and skips an empty one, so delegating would turn an empty id into an unfiltered listing.

Docs preview

Page Preview
Analytics reference /docs/api-reference/workflow-runtime/world/analytics

Behind deployment protection, so the link needs Vercel team access.

Backporting

Not for stable. world.analytics does not exist on 4.x — @workflow/world there exports no analytics namespace and @workflow/world-vercel ships no analytics implementation — so there is nothing for these guards to apply to. The new exports and the deprecation are additive API on a 5.x-only namespace.

@changeset-bot

changeset-bot Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5fe57bb

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
Name Type
@workflow/world Minor
@workflow/world-vercel Minor
@workflow/errors Minor
@workflow/web Patch
@workflow/cli Patch
@workflow/core Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/world-local Patch
@workflow/world-postgres Patch
@workflow/world-testing Patch
@workflow/builders Patch
workflow Patch
@workflow/nitro Patch
@workflow/next Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
example-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-astro-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-express-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-fastify-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-hono-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-nitro-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-python-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workbench-vite-workflow Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workflow-docs Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workflow-swc-playground Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workflow-tarballs Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC
workflow-web Ready Ready Preview, v0 Sep 2, 2026 11:19pm UTC

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit 5fe57bb · Wed, 02 Sep 2026 23:43:41 GMT · run logs

Backend: vercel · app: nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 1237 (+538%) 🔻 1466 🔴 (+42%) 🔻 1498 🔴 (+31%) 🔻 1791 🔴 (+23%) 🔻 30
TTFS stream 921 (+522%) 🔻 1296 🔴 (+27%) 🔻 1332 🔴 (+29%) 🔻 1353 🔴 (+16%) 🔻 30
TTFS hook + stream 1306 (+193%) 🔻 1596 🔴 (+11%) 1679 🔴 (-63%) 💚 5616 🔴 (+9.7%) 30
Fan-out TTFS Promise.all(100 steps) 613 (+3.9%) 1910 (+155%) 🔻 1987 (+27%) 🔻 2101 (+24%) 🔻 10
Fan-out TTLS Promise.all(100 steps) 2009 (+11%) 3677 (+39%) 🔻 4178 (+36%) 🔻 8441 (+22%) 🔻 10
STSO 1020 steps (inline) 87 (-16%) 💚 129 (-3.0%) 155 (-1.9%) 610 (-64%) 💚 1019
WO 1020 steps 140148 (-19%) 💚 140148 (-19%) 💚 140148 (-19%) 💚 140148 (-19%) 💚 1
CRTT first chunk (pooled) 63 (+21%) 🔻 108 (+4.9%) 154 (+19%) 🔻 275 (+30%) 🔻 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 81.5 (+4%) 155 (+21%) 204 (-5%) 451 (+7%) 125 (-14%) 10
size sweep (100/s, 160B-12KB) 92 (+7%) 153 (+12%) 189 (-7%) 550 (+55%) 111 (-23%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 67 (-46%) 135 (+4%) 179 (-9%) 340 (-19%) 257 (±0%) 3
replay eve-gpt-5.6-sol-2000t (1x) 98 (-25%) 132 (-7%) 179 (-55%) 369 (-89%) 225 (-89%) 2
replay eve-gpt-5.6-sol-2000t (2x) 92 (-11%) 188 (+12%) 272 (+11%) 426 (-27%) 201 (-28%) 3
📈 STSO distribution vs main (inline / queue-hop histograms)

1020 steps (inline)

Cumulative STSO time: main 172379ms → this run 138755ms (Δ -33624ms, -20%)

   50-100 ms  ┃                         main   0  this   6    +6
  100-150 ms  ███████████████████████┃  main 873  this 882    +9
  150-200 ms  █┃█                       main 111  this  91   -20
  200-250 ms  ┃                         main   6  this  13    +7
  250-300 ms  ┃                         main   2  this   2    +0
  300-350 ms  ┃                         main   1  this   0    -1
  350-400 ms  ┃                         main   0  this   1    +1
  400-450 ms  ┃                         main   0  this   2    +2
  450-500 ms  ┃                         main   0  this   2    +2
  500-550 ms  ┃                         main   0  this   3    +3
  550-600 ms  ┃                         main   0  this   6    +6
  600-650 ms  ┃                         main   0  this   7    +7
  650-700 ms  ┃                         main   0  this   1    +1
  750-800 ms  ┃                         main   0  this   1    +1
 950-1000 ms  ┃                         main   1  this   0    -1
1000-1050 ms  ┃                         main   3  this   0    -3
1050-1100 ms  ┃                         main   1  this   0    -1
1100-1150 ms  ┃                         main   1  this   0    -1
1150-1200 ms  ┃                         main   1  this   0    -1
1250-1300 ms  ┃                         main   1  this   0    -1
1300-1350 ms  ┃                         main   1  this   0    -1
1350-1400 ms  ┃                         main   2  this   2    +0
1400-1450 ms  ┃                         main   1  this   0    -1
1500-1550 ms  ┃                         main   1  this   0    -1
1550-1600 ms  ┃                         main   2  this   0    -2
1650-1700 ms  ┃                         main   1  this   0    -1
1750-1800 ms  ┃                         main   2  this   0    -2
2000-2050 ms  ┃                         main   1  this   0    -1
2050-2100 ms  ┃                         main   2  this   0    -2
2100-2150 ms  ┃                         main   1  this   0    -1
2200-2250 ms  ┃                         main   1  this   0    -1
2250-2300 ms  ┃                         main   1  this   0    -1
2400-2450 ms  ┃                         main   1  this   0    -1
2550-2600 ms  ┃                         main   1  this   0    -1
📈 CRTT drill-down vs main (RTT distributions & profiles)
variant  RTT 1ms→5s+             avg         p50         p90         p99     n
control  ······▃█▁····  130.5 (+18%)  123 (+24%)   204 (-5%)   451 (+7%)  3000
sweep    ······▃█▁▁···   128.8 (+9%)  117 (+11%)   189 (-7%)  550 (+55%)  3000
gw 1x    ·····▁▅█▁····   117.1 (+4%)  109 (+11%)   179 (-9%)  340 (-19%)  5295
eve 1x   ·····▁██▁····    113 (-50%)   102 (-2%)  179 (-55%)  369 (-89%)  5186
eve 2x   ·····▁▃█▂▁···   144.8 (+3%)  132 (+11%)  272 (+11%)  426 (-27%)  7779

RTT over stream progress (avg per tenth of stream, bars scaled min→max):

control  █▆▃▂▃▃▁▃▁▂  119–155ms
sweep    █▄▄▂▂▂▃▁▁▂  110–180ms
gw 1x    ▃▇█▁▄▃▁▁▃▄  104–139ms
eve 1x   ▅▃▃▆▁▄▆█▄▆  94–131ms
eve 2x   ▃▂▄▂▁▄▄█▄▃  108–208ms

RTT by chunk size (avg per log size bin, ~160B → ~12KB serialized, bars scaled min→max):

sweep  ▁▂▁▅█▅▂  128–131ms

Delivery jitter over stream progress (avg positive CDV per tenth of stream, bars scaled min→max):

control  ▄▇▁▂▄█▄▅▄▂  33–43ms
sweep    ▂▂▇▃█▆▄▁▃▂  44–55ms
gw 1x    ▃█▇▁▇▄▄▃▄▆  29–42ms
eve 1x   ▃█▁▃▃▅▃▄▅▇  20–26ms
eve 2x   ▇▄▅▁▂█▁▄▂▆  20–28ms
📜 Previous results (1)

b03f27c

Wed, 02 Sep 2026 22:30:45 GMT · run logs

vercel / nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 1130 (+12%) 1302 🔴 (+14%) 1323 🔴 (+12%) 1514 🔴 (+22%) 🔻 30
TTFS stream 214 (-67%) 💚 1184 🔴 (+5.7%) 1221 🔴 (+3.1%) 1252 🔴 (-1.5%) 30
TTFS hook + stream 1483 (+10%) 1531 🔴 (+6.2%) 1572 🔴 (+5.9%) 1799 🔴 (+18%) 🔻 30
Fan-out TTFS Promise.all(100 steps) 489 (-29%) 💚 797 (-56%) 💚 802 (-60%) 💚 1937 (-6.2%) 10
Fan-out TTLS Promise.all(100 steps) 1391 (-39%) 💚 4932 (+31%) 🔻 5528 (+35%) 🔻 8118 (-2.4%) 10
STSO 1020 steps (inline) 86 (-27%) 💚 127 (-26%) 💚 144 (-25%) 💚 203 (-22%) 💚 1019
WO 1020 steps 128204 (-26%) 💚 128204 (-26%) 💚 128204 (-26%) 💚 128204 (-26%) 💚 1
CRTT first chunk (pooled) 87 (+18%) 🔻 107 (-16%) 💚 141 (-6.0%) 149 (-19%) 💚 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 99 (-7%) 127 (-36%) 166 (-41%) 249 (-71%) 104 (-42%) 10
size sweep (100/s, 160B-12KB) 103 (-3%) 114 (-56%) 136 (-61%) 182 (-88%) 92.5 (-45%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 114 (-7%) 104 (-46%) 125 (-58%) 204 (-74%) 142 (-74%) 3
replay eve-gpt-5.6-sol-2000t (1x) 95.5 (-4%) 106 (-44%) 140 (-44%) 263 (-63%) 255 (-44%) 2
replay eve-gpt-5.6-sol-2000t (2x) 100 (-19%) 142 (-77%) 197 (-90%) 385 (-90%) 191 (-47%) 3
ℹ️ Metric definitions & methodology

Streams: first-chunk RTT (the stream-open path, before any buffering/backpressure), CRTT percentiles, and worst delivery stall (CDV max). Cells are medians across iterations; per-run values in the artifacts. No 🔴/🟢 marks until targets attach.

The collapsed STSO distribution section above buckets every step gap, split inline (same warm process — pure framework overhead) vs queue-hop (fresh process — dispatch, reinit, replay). █ = main, ┃ = this run, ░ = fill.

The collapsed CRTT drill-down: per-variant RTT histograms (fixed log bins, · = empty) and mean RTT/positive-CDV profile lines over stream progress and chunk size. Histograms, avgs, and profiles merge exactly across runs; p50–p99 are percentile-of-percentiles. Per-index rows live in the artifacts.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body) · Fan-out TTFS: fan-out time to first step (in-deployment start() → first of the parallel step bodies to complete) · Fan-out TTLS: fan-out time to last step (in-deployment start() → last of the parallel step bodies to complete, i.e. when the Promise.all resolves) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · CRTT: chunk round-trip time (per-chunk write → read latency, one clock domain: deployment → stream backend → same deployment) · CDV: chunk delay variation / delivery jitter (inter-arrival gap minus inter-write gap per seq-adjacent pair; skew-free; the row is each run's MAX positive value, so one stall moves it)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · Promise.all(100 steps): 100 trivial no-op steps started together in a single Promise.all; Fan-out TTFS is the first of them to complete and Fan-out TTLS the last, both from the in-deployment clientStart, so their gap is the spread the runtime adds across the fan-out · paced control (100/s, 60B): the control: 300 tiny (~60B) deltas metronome-paced at 100/s — zero workload structure, so it reads the transport floor and flush cadence, and disambiguates transport-wide vs workload-specific when a replay row moves · size sweep (100/s, 160B-12KB): same pacing as the control with deltas padded in rotation across seven log-spaced sizes (~160B–12KB) — rotation decouples size from stream position, so it isolates whether chunk size causes latency · replay gateway-gpt-5.4-nano-2000t (1x): raw provider SSE cadence captured at the AI gateway boundary (gpt-5.4-nano, the most popular gateway model; per-token deltas p50 208B = the modal production chunk size), replayed exactly as measured — the typical customer's workload; its CDV is the typical customer's real delivery jitter · replay eve-gpt-5.6-sol-2000t (1x): a captured eve turn (gpt-5.6-sol, the most-used demanding eve model; ~2000 output tokens = production p50 turn length) replayed exactly as measured — eve's envelope protocol re-ships the cumulative message so sizes ramp 142B→13KB; the demanding outlier tenant's reality · replay eve-gpt-5.6-sol-2000t (2x): the same eve capture at 2x — the headroom/stress row; real fast-tier models emit the same chunk sizes at proportionally higher rate, so time compression is a faithful speed model · first chunk (pooled): every run's seq-0 RTT pooled across all stream scenarios — the first chunk precedes any workload differentiation, so pooling samples one shared stream-open path with exact percentiles

Replay cadences (semantic sha256) — eve-gpt-5.6-sol-2000t eaf22f5946e7c61f3c65c7006d550df180cfabd4e706254a09f22aec0cfb420d · gateway-gpt-5.4-nano-2000t 6f24ac518b6b83ff1d0e85a5fe78230db192716d66a7fc6b2fe022752001d041

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600

All timestamps are deployment-side; runs are triggered in-deployment, so the CI runner and api.vercel.com sit outside every measured window. TTFS = start() → first step body (includes dispatch + any cold start); Fan-out TTFS/TTLS = first/last step completion of one Promise.all from the same anchor (the gap is the runtime’s fan-out spread); STSO/WO between step bodies; CRTT inside the workflow (excludes the api.vercel.com read path).

Cold starts stay in the numbers (real bursty-workload latency, inflates P75+); Best is the warm floor.

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

✅ All tests passed

⚠️ Flaky E2E Tests (passed on retry)

These tests failed at least once and passed on a retry. A recurring entry here is a real race worth investigating.

  • cancelRun via CLI - cancelling a running workflow (nuxt)
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps (fastify)
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered (nextjs-turbopack)
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep (nextjs-webpack)

🛠 Infra Events (absorbed by the harness)

Platform anomalies the e2e harness detected and worked around (e.g. a run the queue never picked up, replaced by a fresh run). Clustered timestamps indicate a backend blip; a steady drip indicates a platform issue worth escalating.

  • cold-start-warmup · suite warmup (tanstack-start) · at 23:22:08Z · abandoned wrun_01M1J6V854SX4SF0XHAHX3V82M
  • run-pickup-stall · hookCleanupTestWorkflow - hook token reuse after workflow completion (nextjs-webpack) · at 23:29:16Z · abandoned wrun_01M1J78NJANF5BXSRDTDHVREP2

E2E Test Summary

Summary
Passed Failed Skipped Total
✅ ▲ Vercel Production 3636 0 684 4320
✅ 💻 Local Development 3922 0 558 4480
✅ 📦 Local Production 3922 0 558 4480
✅ 🐘 Local Postgres 3922 0 558 4480
✅ 🪟 Windows 320 0 0 320
✅ 🌐 Cross-language Conformance 68 0 73 141
✅ vercel-http-transport 817 0 143 960
✅ vercel-multi-region 27 0 0 27
✅ vercel-ws-transport 553 0 87 640
Total 17187 0 2661 19848
Details by Category

✅ ▲ Vercel Production

App Passed Failed Skipped
✅ astro-node 132 0 28
✅ astro-quickjs 132 0 28
✅ example-node 132 0 28
✅ example-quickjs 132 0 28
✅ express-node 132 0 28
✅ express-quickjs 132 0 28
✅ fastify-node 132 0 28
✅ fastify-quickjs 132 0 28
✅ hono-node 132 0 28
✅ hono-quickjs 132 0 28
✅ nest-node 132 0 28
✅ nest-quickjs 132 0 28
✅ nextjs-turbopack-node 157 0 3
✅ nextjs-turbopack-quickjs 157 0 3
✅ nextjs-webpack-node 157 0 3
✅ nextjs-webpack-quickjs 157 0 3
✅ nitro-node 132 0 28
✅ nitro-quickjs 132 0 28
✅ nuxt-node 132 0 28
✅ nuxt-quickjs 132 0 28
✅ python-node 66 0 94
✅ sveltekit-node 151 0 9
✅ sveltekit-quickjs 151 0 9
✅ tanstack-start-node 132 0 28
✅ tanstack-start-quickjs 132 0 28
✅ vite-node 132 0 28
✅ vite-quickjs 132 0 28

✅ 💻 Local Development

App Passed Failed Skipped
✅ astro-stable-node 134 0 26
✅ astro-stable-quickjs 134 0 26
✅ express-stable-node 134 0 26
✅ express-stable-quickjs 134 0 26
✅ fastify-stable-node 134 0 26
✅ fastify-stable-quickjs 134 0 26
✅ hono-stable-node 134 0 26
✅ hono-stable-quickjs 134 0 26
✅ nest-stable-node 134 0 26
✅ nest-stable-quickjs 134 0 26
✅ nextjs-turbopack-canary-node 141 0 19
✅ nextjs-turbopack-canary-quickjs 141 0 19
✅ nextjs-turbopack-stable-node 160 0 0
✅ nextjs-turbopack-stable-quickjs 160 0 0
✅ nextjs-webpack-canary-node 141 0 19
✅ nextjs-webpack-canary-quickjs 141 0 19
✅ nextjs-webpack-stable-node 160 0 0
✅ nextjs-webpack-stable-quickjs 160 0 0
✅ nitro-stable-node 134 0 26
✅ nitro-stable-quickjs 134 0 26
✅ nuxt-stable-node 134 0 26
✅ nuxt-stable-quickjs 134 0 26
✅ sveltekit-stable-node 153 0 7
✅ sveltekit-stable-quickjs 153 0 7
✅ tanstack-start-node 134 0 26
✅ tanstack-start-quickjs 134 0 26
✅ vite-stable-node 134 0 26
✅ vite-stable-quickjs 134 0 26

✅ 📦 Local Production

App Passed Failed Skipped
✅ astro-stable-node 134 0 26
✅ astro-stable-quickjs 134 0 26
✅ express-stable-node 134 0 26
✅ express-stable-quickjs 134 0 26
✅ fastify-stable-node 134 0 26
✅ fastify-stable-quickjs 134 0 26
✅ hono-stable-node 134 0 26
✅ hono-stable-quickjs 134 0 26
✅ nest-stable-node 134 0 26
✅ nest-stable-quickjs 134 0 26
✅ nextjs-turbopack-canary-node 141 0 19
✅ nextjs-turbopack-canary-quickjs 141 0 19
✅ nextjs-turbopack-stable-node 160 0 0
✅ nextjs-turbopack-stable-quickjs 160 0 0
✅ nextjs-webpack-canary-node 141 0 19
✅ nextjs-webpack-canary-quickjs 141 0 19
✅ nextjs-webpack-stable-node 160 0 0
✅ nextjs-webpack-stable-quickjs 160 0 0
✅ nitro-stable-node 134 0 26
✅ nitro-stable-quickjs 134 0 26
✅ nuxt-stable-node 134 0 26
✅ nuxt-stable-quickjs 134 0 26
✅ sveltekit-stable-node 153 0 7
✅ sveltekit-stable-quickjs 153 0 7
✅ tanstack-start-node 134 0 26
✅ tanstack-start-quickjs 134 0 26
✅ vite-stable-node 134 0 26
✅ vite-stable-quickjs 134 0 26

✅ 🐘 Local Postgres

App Passed Failed Skipped
✅ astro-stable-node 134 0 26
✅ astro-stable-quickjs 134 0 26
✅ express-stable-node 134 0 26
✅ express-stable-quickjs 134 0 26
✅ fastify-stable-node 134 0 26
✅ fastify-stable-quickjs 134 0 26
✅ hono-stable-node 134 0 26
✅ hono-stable-quickjs 134 0 26
✅ nest-stable-node 134 0 26
✅ nest-stable-quickjs 134 0 26
✅ nextjs-turbopack-canary-node 141 0 19
✅ nextjs-turbopack-canary-quickjs 141 0 19
✅ nextjs-turbopack-stable-node 160 0 0
✅ nextjs-turbopack-stable-quickjs 160 0 0
✅ nextjs-webpack-canary-node 141 0 19
✅ nextjs-webpack-canary-quickjs 141 0 19
✅ nextjs-webpack-stable-node 160 0 0
✅ nextjs-webpack-stable-quickjs 160 0 0
✅ nitro-stable-node 134 0 26
✅ nitro-stable-quickjs 134 0 26
✅ nuxt-stable-node 134 0 26
✅ nuxt-stable-quickjs 134 0 26
✅ sveltekit-stable-node 153 0 7
✅ sveltekit-stable-quickjs 153 0 7
✅ tanstack-start-node 134 0 26
✅ tanstack-start-quickjs 134 0 26
✅ vite-stable-node 134 0 26
✅ vite-stable-quickjs 134 0 26

✅ 🪟 Windows

App Passed Failed Skipped
✅ nextjs-turbopack-node 160 0 0
✅ nextjs-turbopack-quickjs 160 0 0

✅ 🌐 Cross-language Conformance

App Passed Failed Skipped
✅ python 68 0 73

✅ vercel-http-transport

App Passed Failed Skipped
✅ example 132 0 28
✅ express 132 0 28
✅ hono 132 0 28
✅ nextjs-turbopack 157 0 3
✅ nitro 132 0 28
✅ vite 132 0 28

✅ vercel-multi-region

App Passed Failed Skipped
✅ nextjs-turbopack 27 0 0

✅ vercel-ws-transport

App Passed Failed Skipped
✅ example 132 0 28
✅ express 132 0 28
✅ nextjs-turbopack 157 0 3
✅ vite 132 0 28

📋 View full workflow run

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Sim World

Simulated world deterministic testing for races. Traces

🟠 world-sim scenario book — 1 fail of 41 total

fence=per-spec

scenario outcome events virt replay violations
✅ smoke-no-steps completed 3 0ms ok 0
✅ smoke-one-step completed 6 0ms ok 0
✅ hook-at-step-started completed 12 0ms ok 0
✅ hook-at-step-completed completed 12 0ms ok 0
✅ hook-at-hook-created completed 12 0ms ok 0
✅ deadline-hook-wins completed 7 1.0h ok 0
✅ deadline-expires completed 7 1.0h ok 0
✅ long-sleep completed 11 30.0d ok 0
✅ hook-never-arrives stalled 3 0ms skipped 0
✅ step-retries-twice completed 10 2.0s ok 0
✅ parallel-steps completed 9 0ms ok 0
✅ hook-on-execution-state completed 12 0ms ok 0
✅ peek-hook-before-branch completed 12 0ms ok 0
✅ peek-hook-after-branch completed 12 0ms ok 0
✅ peek-hook-at-registration completed 12 0ms ok 0
✅ race-hook-before-probe completed 12 0ms ok 0
✅ race-hook-after-probe completed 12 0ms ok 0
✅ race-duplicate-delivery completed 13 0ms ok 0
✅ attr-hook-before-step completed 11 0ms ok 0
✅ attr-hook-after-step completed 11 0ms ok 0
✅ attr-from-step-body completed 13 0ms ok 0
✅ fork-hook-after-timeout completed 14 1.0m ok 0
✅ fork-hook-before-timeout completed 14 1.0m ok 0
✅ count-hook-after-timeout completed 17 1.0m ok 0
✅ count-hook-before-timeout completed 20 1.0m ok 0
✅ stale-read-step-count-fork completed 20 1.0m ok 0
✅ stale-read-equal-step-counts completed 14 1.0m ok 0
✅ step-vs-step-fork completed 12 0ms ok 0
✅ step-vs-step-fork-fenced completed 12 0ms ok 0
✅ fence-catches-benign-direction completed 12 5ms ok 0
✅ in-flight-before-decision completed 17 1.0m ok 0
❌ in-flight-before-decision-counted completed 17 1.0m ok 0
✅ in-flight-after-decision completed 19 2.0m ok 0
✅ stale-read-step-count-fork-fenced completed 20 1.0m ok 0
✅ fork-hook-wins completed 13 1.0m ok 0
✅ fork-timeout-wins completed 13 1.0m ok 0
✅ unclaimed-payload-under-fork completed 17 1.0m ok 0
✅ claimed-payload-under-fork completed 17 1.0m ok 0
✅ writers-independent-step-bodies completed 12 0ms ok 0
✅ writers-scripted-tempo completed 12 0ms ok 0
✅ cancel-mid-step cancelled 7 0ms skipped 0

Full trace: world-sim.txt

Every analytics method now checks its arguments before making a request
and throws a RangeError naming the limit it broke: the ids, the
pagination limit against the cap for that listing, and the attribute
filter's pair count, key length and value size. Because analytics is an
optional capability, callers wrap it in a catch, which turned an invalid
argument into what looked like an empty result rather than an error.

Two arguments that used to be dropped silently now fail too. A limit of 0
fell back to the default page size, and a startTime without a matching
endTime turned a listing you meant to bound into an unbounded one that
looked like a normal answer.

Exports ANALYTICS_RUN_SCOPED_PAGE_LIMIT, ANALYTICS_PAGE_LIMIT and
ANALYTICS_MAX_ATTRIBUTE_FILTERS so callers can check the bounds
themselves.

Deprecates analytics.events.listByCorrelationId() in favour of
analytics.events.list({ runId, correlationId }), which issues the same
request and also accepts an eventType filter. It keeps its own
implementation rather than delegating: list() treats correlationId as
optional and skips an empty one, so a delegation would turn an empty id
into an unfiltered listing of the run.

Documents every analytics method in the reference. events.getMany() was
missing entirely, seven methods shared one code block with no parameters
or return shapes, and none of the limits were written down.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@karthikscale3
karthikscale3 marked this pull request as ready for review September 2, 2026 21:58
@karthikscale3
karthikscale3 requested a review from a team as a code owner September 2, 2026 21:59
@karthikscale3
karthikscale3 force-pushed the kk/analytics-events-input-guards branch from 1e0ba67 to 98c3a03 Compare September 2, 2026 21:59
firstSeenAt and lastSeenAt were the only analytics timestamps still on a
plain date coercion. The values arrive without a timezone designator, so
that read them in the process's local zone and every other field in the
namespace read them as UTC — a seven-hour skew on those two fields alone
for anyone running outside UTC.

The added test fails without the fix under TZ=America/Los_Angeles.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor
Framework Flow route Step reg. Framework output
hono 200.9 KiB (±0) 40.7 KiB (+126 B) 1.77 MiB (+2.7 KiB)
nextjs-turbopack 206.3 KiB (±0) 439 B (±0) 766.8 KiB (+1.0 KiB)
About these numbers

Sizes are gzip; parentheses show the change against main.
Flow route and Step reg. gate this job, on raw bytes rather than the gzip shown, at max(2%, 50.0 KiB). Framework output is informational.

5fe57bb · run

karthikscale3 and others added 5 commits September 2, 2026 15:13
A reference page should describe the API you should reach for. The
deprecation notice lives on the method itself, so editors surface it
where it matters without the page advertising a method nobody should
start using. Also drops it from the page-limit table.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Run ids were validated with workflowRunIdSchema while every other id used
a regex mirroring the backend. Those disagree: z.ulid() accepts a
lowercase body and a first character above 7, and the backend accepts
neither, so the most-used parameter had the leakiest guard and still
produced the 400 this is meant to prevent. Run ids now use the same
pattern as the rest.

A supplied-but-empty filter value was also still being dropped —
correlationId, the optional runId scope on hooks.get, and workflowName
all tested truthiness. Dropping one widens the result set rather than
narrowing it, so an empty correlationId listed the whole run and an
empty workflowName listed every workflow. That is the same failure the
limit and time-window guards were added to prevent, and the comment on
listByCorrelationId already described the hazard. They now compare
against undefined, so an empty id throws and an empty name is forwarded
for the backend to match.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The guards threw bare RangeErrors, which left a caller — or an agent
driving this API — parsing English to decide whether to fix the call or
retry it. They now raise WorkflowWorldError with
code: 'INVALID_ARGUMENT', the code the rest of this client already uses
for its transport and throttle failures, so the retry decision is a
field lookup. normalizeEventIds moves with them rather than staying the
one guard that throws a different type.

Also sharpens the four messages that made a caller do the work:
a half-open window now names the bound that is missing rather than
restating the rule, an inverted window prints both ends, and the
attribute-value and event-id batch errors report the size measured
rather than only the bound they broke.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two things a caller could not get without reading prose. The same guard
runs behind several methods, so `runId must be a workflow run id` was
identical whether it came from events.list or steps.get — fine with a
stack, lossy once the error has crossed a log line. And the offending
argument was only available as the first token of the message, which is
the part most likely to be reworded.

Messages now open with the method, and WorkflowWorldError carries an
optional `field`:

  analytics.runs.list: pagination.limit must be an integer between 1
  and 100 (received 9999)
  → code: 'INVALID_ARGUMENT', field: 'pagination.limit'

`field` is additive on the error class and set only by these guards, so
nothing that reads the existing properties changes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot mentioned this pull request Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

No backport to stable for fbfb9fe (AI decision).

The change is confined to the world.analytics namespace, which does not exist on stable — git ls-tree origin/stable shows no packages/world/src/analytics.ts, no packages/world-vercel/src/analytics.ts, and no v5 analytics reference page — so there is nothing for these guards to apply to. It is also additive API surface (new ANALYTICS_* exports, a new field property on WorkflowWorldError, a deprecation) carrying a minor changeset, i.e. feature work rather than a stability fix. The one genuine bug fix inside it, the local-timezone skew on AnalyticsAttributeKeySchema.firstSeenAt/lastSeenAt, is likewise 5.x-only.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

fbfb9fe869980d1ccc351ba594be0ae847165762

This branch was successfully deployed

18 active deployments
Preview – workflow-swc-playground — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workflow-docs — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – example-nextjs-workflow-turbopack — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-nuxt-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-vite-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – example-nextjs-workflow-webpack — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workflow-tarballs — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-tanstack-start-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-fastify-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-sveltekit-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – example-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-astro-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-express-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-nitro-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-hono-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-nestjs-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workflow-web — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Preview – workbench-python-workflow — 5fe57bb3 Deployed Sep 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants