Registries
The registries in this section are normative and scoped to the exact Standard revision. Allocation and compatibility duties are under Obligations of the Standard.
Vendor-defined entries use a namespace controlled by their defining specification and do not modify a Standard registry.
Reserved Step-Path Segment Registry
Section titled “Reserved Step-Path Segment Registry”Reserved step-path segments identify auxiliary executable work and have the syntax defined by reserved-segment.
This revision registers the following segment names. Unlisted names are not allocated by the Standard.
| Segment | Owner | Meaning |
|---|---|---|
source |
Core | The action source of wf.for_each. |
catch |
Core | Steps in the selected failure handler. |
reconcile |
Durable Execution Profile | Steps that reconcile an ambiguous action attempt. |
undo |
Durable Execution Profile | The compensation action attached to a successful action step. |
on_exhausted |
Agent Execution Capability | Steps in an agent budget-exhaustion handler. |
Error Code Registry
Section titled “Error Code Registry”A Standard error code matches the standard-error-code production in the Syntax Reference.
Invalid and unsupported codes classify document or target diagnostics, rejected codes classify invocation operations for which no run starts, and fault codes classify deterministic failures discovered while evaluating an expression or template. Failure codes classify a failed step or terminal run disposition produced by a construct, profile, executor, or embedded runtime rather than by a connector. A failure-class code does not imply a definite classified connector failure; in particular, flow.action_ambiguous identifies the executor’s terminal disposition for an outcome that remains unknown.
Connector-declared codes and author-selected wf.fail codes are separate vocabularies and MUST NOT be represented as Standard registry allocations. This revision registers the following codes.
A more specific code takes precedence over a general code that could describe the same condition.
| Code | Class | Meaning |
|---|---|---|
syntax.yaml |
invalid | Input violates YAML syntax or the serialization rules. |
syntax.expression |
invalid | An interpolation, expression, duration, timestamp, operation key, type expression, or literal regular expression violates its grammar. |
document.structure |
invalid | A standard document has a missing, conflicting, duplicate, unknown, or wrongly shaped structural member. |
document.name |
invalid | A declared name is malformed, reserved, duplicated, or shadows a visible binding. |
document.reference |
invalid | A local name, binding, path, schema, state, branch, output, literal target, or referenced member of a conforming selected manifest is absent or out of scope. |
document.type |
invalid | A value, expression, default, example, argument, result declaration, or guard has a statically inferred type incompatible with its required type or constraint, or a literal argument is outside its operation’s declared domain. |
document.template |
invalid | A template violates its tag or block structure, include-containment, variable-supply, variable-use, partial-context, partial-nesting, or part-name derivation rules. |
document.control |
invalid | Control-flow declarations are incomplete, contradictory, unbounded where prohibited, non-exhaustive where required, or unsafe under their resolved operational contracts. |
dependency.unresolved |
invalid | An initial lookup against supplied project content cannot find a required project-local callee, template, schema, or other definition-owned reference. Missing validation input and unavailable previously pinned content follow Resolution and Pinning. |
dependency.invalid |
invalid | A resolved manifest, package, overlay, callee, template set, fixture set, digest syntax, namespace binding, or cross-document contract is invalid. Content that fails to match a pin instead uses deployment.dependency. |
invocation.inputs |
rejected | Invocation inputs are missing, undeclared, or incompatible with the workflow input contract. No run starts. |
invocation.trigger |
rejected | A trigger invocation does not select exactly one declared entry or does not supply a payload satisfying that entry. No run starts. |
invocation.dry_run |
rejected | A dry-run invocation requires a live external event source for which no profile-defined simulated source is supplied. No run starts. |
deployment.version |
unsupported | The target does not support the selected Workfile format or Standard revision. |
deployment.capability |
unsupported | The target lacks a structurally required capability or profile. |
deployment.connection |
unsupported | A required connection is missing, ambiguous, incompatible, incomplete, or lacks a determinable required scope. |
deployment.dependency |
unsupported | A required catalog artifact, runtime, time-zone database, pinned content, or other deployment dependency is unavailable or incompatible, including content that fails to match its pin. This code does not assert resolved validity. |
deployment.limit |
unsupported | The definition is known before execution to exceed a documented target limit. |
fault.type |
fault | A runtime value has the wrong kind, constraint, arity, member, index, guard, argument, or result type where static validation could not decide it. |
fault.arithmetic |
fault | Arithmetic divides by zero, overflows, produces a non-finite value, or uses an unsupported numeric domain. |
fault.expression |
fault | A pure expression or filter fails for another registered deterministic reason. |
fault.filter_signature |
fault | A value typed too broadly for static rejection violates a filter signature at runtime. |
fault.template |
fault | Template evaluation or rendering fails. |
flow.timeout |
failure | A base construct or agent operation exceeds its effective timeout where no more specific registered timeout code applies. |
flow.limit |
failure | Runtime input or consumption exceeds a documented applicable limit. |
flow.max_exceeded |
failure | A wf.for_each source supplies more elements than its integer max. |
flow.max_exhausted |
failure | wf.repeat reaches max while until remains false. |
flow.child_cancelled |
failure | A child run is cancelled independently while its wf.call remains active. |
flow.action_ambiguous |
failure | The executor terminates a run because an action’s external effect or result remains unknown and no explicit Durable policy resolves it. |
state.ambiguous_subscription |
failure | More than one state subscription becomes eligible where static validation could not establish the ambiguity. |
agent.unavailable |
failure | The resolved agent runtime cannot accept or continue the node. |
agent.tool_failed |
failure | An allowlisted tool cannot be completed safely under its connector contract. |
agent.invalid_result |
failure | The agent result does not satisfy returns. |
agent.budget_exhausted |
failure | The first declared agent budget bound is reached. |
An implementation MAY expose a finer vendor diagnostic in addition to the required code, but the vendor code MUST NOT replace it. A later compatible revision MAY add a more specific code only for a newly distinguishable condition and MUST state whether earlier implementations report an existing general code.
Codes not listed above are not allocated by the Standard.
Reserved Connector Code Registry
Section titled “Reserved Connector Code Registry”Reserved connector codes are produced by the executor when applying the Connector Execution Contract. They occupy the connector-code vocabulary but have the classifications and consequences fixed by this specification.
A connector manifest MUST NOT declare, classify, or reuse one.
| Code | Classification | Meaning |
|---|---|---|
invalid_output |
fatal |
An invalid connector-reported success, as defined under Successful Results. |
timeout |
Context-dependent | A timeout before or after dispatch has the attempt result defined under Action Timeouts. |
Capability Registry
Section titled “Capability Registry”Every wf.* entry identifies its normative definition, structural activation predicate or explicitly declares none, prerequisites, validator-owned checks, and applicable conformance-test tag. The complete requirements are the referenced section plus the general Capability requirements; the table is not an independent summary that can weaken them.
| Capability | Activation predicate | Prerequisites | Validator-owned checks | Normative definition and test tag |
|---|---|---|---|---|
wf.scheduled-initiation |
A resolved trigger has kind: schedule. |
Workfile Core; Connector Manifest | Base: trigger declarations, configuration signatures and source-literal constraints under Trigger Configuration and Inferred Capability Requirements. Occurrence evaluation and admission are operational. | Scheduled, External-Event, and Polling Initiation; capability:wf.scheduled-initiation |
wf.external-event-initiation |
A resolved trigger has kind: external. |
Workfile Core; Connector Manifest | Base: trigger declarations, configuration, resolved payload and identity contracts under Triggers. Payload acceptance and deduplication are operational. | Scheduled, External-Event, and Polling Initiation; capability:wf.external-event-initiation |
wf.polling-initiation |
A resolved trigger has kind: poll. |
Workfile Core; Connector Manifest | Base: trigger declarations, configuration, and resolved poll, identity, and correlation contracts under Triggers. Polling and acceptance are operational. | Scheduled, External-Event, and Polling Initiation; capability:wf.polling-initiation |
wf.template-rendering |
The Workfile uses wf.render. |
Workfile Core | Base: step shape, with, and literal paths. Capability-owned: grammar, expressions, variable/partial checks, and part derivation under Templates and wf.render; source-available checks belong to the document phase, checks needing files or dependency contracts to resolved validation. |
Templates and wf.render; capability:wf.template-rendering |
wf.composition |
The Workfile uses wf.call. |
Workfile Core | Base: literal path and with; callee resolution, inputs/outputs, full call graph, and transitive dependencies under wf.call. No additional capability-owned checks. |
wf.call; capability:wf.composition |
wf.action-source-iteration |
wf.for_each uses an action-call source. |
Workfile Core; Connector Manifest | Base: source shape and arguments; resolved read effects, single-list output, and iteration element typing under wf.for_each. No additional capability-owned checks. |
wf.for_each; capability:wf.action-source-iteration |
wf.run-records |
None; claimed, never inferred. | Core Executor | None; this capability has no validator-target claim. | Run Records Capability; capability:wf.run-records |
wf.agent-execution |
The Workfile uses wf.agent. |
Workfile Core; Connector Manifest | Base: literal identity, goal/with, returns declarations and output inference, tools syntax/member resolution/key compatibility, budget domains, and handler scopes. Agent configuration availability is deployment support; tool dispatch and result enforcement are operational. |
Agent Execution Capability; capability:wf.agent-execution |
In this table, Workfile Core means the claimed primary target; operational action, iteration, composition, rendering, and agent behavior requires Core Executor conformance, while initiation behavior belongs to an initiation implementation. Validator-owned checks follow Validation Ownership; only the template-content checks require an additional validator capability claim.
The selected language capability for wf.run is allocated with its language entry and is not currently present because the language registry is empty. Vendor capabilities MUST NOT use wf..
Their names MUST contain a namespace controlled by the defining specification, and conformance claims MUST identify that specification by immutable version. A vendor capability MUST NOT alter base syntax or semantics, claim a reserved name, or suppress a standard activation predicate.
Connector Namespace Registry
Section titled “Connector Namespace Registry”The following connector namespaces are canonical and identify the corresponding Standard Library connector in the selected edition: time, store, blob, sync, http, data, and llm. Their meanings are those defined under Standard Connector Definitions and their canonical manifests.
wf is reserved and MUST NOT identify a connector. No other connector namespace is reserved by this revision.
A compatible revision MAY assign a new canonical connector only under a previously reserved namespace; reserving or assigning an existing vendor-owned namespace requires an incompatible revision. A canonical namespace MUST NOT be reassigned, augmented by a catalog, or used for a noncanonical artifact.
Filter Package Namespace Registry
Section titled “Filter Package Namespace Registry”The following filter-package namespaces are canonical and identify the corresponding Standard Library package in the selected edition: text, html, money, rank, workweek, human, url, markup, match, and phone. Their meanings are those defined under Built-in Filters and Standard Filter Packages and their canonical manifests.
wf is reserved and MUST NOT identify a filter package. Bare built-in filter names do not occupy this registry.
No other filter-package namespace is reserved by this revision. Allocation, compatibility, and non-reassignment follow the Connector Namespace Registry rules independently; the same vendor spelling can therefore exist in both artifact kinds.
wf.run Language Registry
Section titled “wf.run Language Registry”The Standard revision registers no wf.run language. Consequently every wf.run step names an unregistered language and is invalid with document.reference; no implementation can claim a wf.run.<language> capability for this revision.