Skip to content

Feat/subscription lease lifecycle - #130

Merged
ucekmez merged 2 commits into
mainfrom
feat/subscription-lease-lifecycle
Sep 23, 2026
Merged

ucekmez merged 2 commits into
mainfrom
feat/subscription-lease-lifecycle

Conversation

@ucekmez

@ucekmez ucekmez commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Summary

Scope

  • Spec / schema only
  • TypeScript package(s)
  • Python package(s)
  • Tests / CI
  • Docs / examples
  • Other: ___

Checklist

  • I read CONTRIBUTING.md and CODE_OF_CONDUCT.md.
  • Tests added or updated where appropriate (npm test / pytest in affected packages).
  • Breaking change to public API or normative spec? If yes, describe impact and note CHANGELOG.md / migration path.
  • Documentation updated for user-visible behavior.

Notes for reviewers

The envelope defined eight `eep_`-prefixed extensions while using none
of the optional CloudEvents attributes that solve the same problems.
`subject`, `dataschema` and `dataref` were all absent, as were the
Distributed Tracing extension attributes — in a protocol whose whole
premise is agents consuming events efficiently across multiple hops.

- `subject` — which thing inside `source` changed. Without it a
  subscriber must parse `data` to decide whether it wanted the event at
  all, which is exactly the context bloat EEP claims to remove.
- `dataschema` — the payload contract travels with the event instead of
  being documented out of band, so a subscriber can validate or
  typed-decode a payload it has never seen.
- `dataref` — the Claim Check pattern. A publisher sends a reference and
  only subscribers that need the body pay for it. Notable by its absence
  in a project whose front-page demo is "2.2 KB instead of 46 KB".
  Retrieval is an ordinary Layer 1 request and stays subject to the
  entity's gates, so a claim check does not become a gate bypass.
- `traceparent` / `tracestate` — EEP is multi-hop by design (agent →
  publisher → subscriber → downstream agent) and the causal chain broke
  at every boundary. `docs/ops/observability.md` said "use
  OpenTelemetry" but no wire field carried the context.

Changes:
- `event.envelope.json` gains all five, with a W3C Trace Context pattern
  on `traceparent`. Types regenerated.
- New normative §7.1 covering when to set each, the rule that a
  `dataref` without `data` MUST be fetched, and the prohibition on
  sending `data` and a `dataref` that disagree.
- `WebhookDispatcher` mirrors trace context into HTTP headers per the
  CloudEvents Distributed Tracing extension. Only well-formed values are
  forwarded: a malformed `traceparent` is worse than none, because it
  silently roots the subscriber's spans under a trace that never
  existed.
- Conformance vectors for the standard attributes, a claim-check event,
  and a malformed `traceparent`.
- §7 records the CloudEvents attribute-naming problem: the existing
  `eep_`-prefixed names contain underscores, which CloudEvents v1.0.2
  excludes. Documented as an open issue rather than renamed — a rename
  is breaking and deserves its own decision.

All additions are optional, so existing publishers stay conformant.

Refs: EEP audit 2026-08 findings B5, B6
Signed-off-by: Ugur Cekmez <ucekmez@gmail.com>
…utes

feat(spec,schemas): adopt the CloudEvents attributes EEP had skipped
Copilot AI lite review requested due to automatic review settings September 23, 2026 05:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@ucekmez
ucekmez merged commit f6ae28c into main Sep 23, 2026
23 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants