Skip to content

wire: site_withdrawn, the publish refusal for a site that has been withdrawn - #104

Merged
enesismail merged 1 commit into
mainfrom
the-site-withdrawn-code
Oct 5, 2026
Merged

enesismail merged 1 commit into
mainfrom
the-site-withdrawn-code

Conversation

@enesismail

Copy link
Copy Markdown
Contributor

What was missing. A deploy whose site has been withdrawn (it expired, or its owner or the service took it down) will never be published again, and the contract had no code for that. The two publish refusals it would otherwise borrow both say something false: deploy_not_ready tells a client to wait, and deploy_failed tells a person their build was refused. A client switches on codes, so the refusal needs its own.

What changes.

  • pkg/wire: CodeSiteWithdrawn = site_withdrawn, documented as terminal, with no Retry-After, and never a stream event. It is appended at the end of the const block and of AllErrorCodes, so no position a released client can observe moves. It is pinned in every contract table: the order, the constants, the names, CarriesRetryAfter false and StreamOnly false. A golden fixture error_response_site_withdrawn.json holds the envelope and passes the existing marshal-match and unmarshal round-trip rows.
  • Routing: the publish stops on it. The create and login tables list it among the publish step's codes, which cannot reach them, and their comments that count those codes are corrected.
  • Copy: a failure of its own, site-withdrawn. "This deploy's site has been withdrawn." / "A withdrawn site is not published again." / next step "Run curious deploy again to make a fresh one.", with the server's message quoted. It exits 1, not the closed-door 3. It does not say "Nothing has been deployed": the deploy may have been live before its site was withdrawn, and the client cannot tell.
  • The failure id is registered, catalog.json is regenerated (one entry added), and the README has its troubleshooting entry. The publish endpoint's code pass-through test gains the new code, and its comment no longer says the endpoint answers with two.

Shown red first. With the constant added and the routing rows absent, all three range rows went red on site_withdrawn: publish ("the contract defines "site_withdrawn" and the publish has no stated route for it"), create, and login. The new refusal row was red against the old fall-through on all five of its assertions.

The exit row and its control. The refusal table runs every stop code through the same harness. The new row expects exit 1; the capacity and maintenance rows in that same table expect 3, which is what makes the 1 a measurement.

Mutations, each run and reverted:

  • wrap the failure in the closed-door constructor: the row reds, "exit code = 3, want 1" (required);
  • put the nothing-was-deployed line in the body: reds;
  • retry text instead of the fresh-deploy text: reds;
  • drop the quoted message: reds;
  • drop the publish routing row: the range row reds;
  • change only the next action to a wait: the terminal row stays green (the action is not printed), and the regenerated catalog reds;
  • use the building stage instead of the addresses stage: the catalog reds;
  • route it to ask-again instead of stop: the run never ends and the test times out.

…thdrawn

A deploy whose site has been withdrawn (it expired, or its owner or the
service took it down) will never be published again, and no code in the
contract said so. deploy_not_ready would tell a client to wait, and
deploy_failed would tell a person their build was refused; neither is
true. site_withdrawn is terminal, carries no Retry-After and is never a
stream event, and it is appended at the end of the code list so nothing
a released client can observe moves.

The client stops on it at the publish step with its own failure,
site-withdrawn: the site has been withdrawn, a withdrawn site is not
published again, and a fresh deploy is the way forward, with the
server's own message quoted. It exits 1, not the closed-door 3, and it
does not say nothing was deployed, because the deploy may have been live
before its site was withdrawn and this client cannot tell.

Every routing table over the contract states a route for it; the create
and login tables declare it as one of the publish step's codes, which
cannot reach them. The failure id is registered, the catalog is
regenerated and the README carries its entry. A golden fixture holds the
envelope.
@enesismail
enesismail force-pushed the the-site-withdrawn-code branch from 8c82da4 to 38a8d2b Compare October 5, 2026 15:44
@enesismail
enesismail added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit fa916fd Oct 5, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant