Skip to content

Use published namespace repair in Laravel and polyglot examples - #137

Merged
rmcdaniel merged 2 commits into
mainfrom
fix/repair-runtime-consumers
Oct 5, 2026
Merged

rmcdaniel merged 2 commits into
mainfrom
fix/repair-runtime-consumers

Conversation

@rmcdaniel

@rmcdaniel rmcdaniel commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Customer outcome

The checked-in Laravel application and microservice both install the published
Workflow 2.3.4 namespace repair. The polyglot examples use the exact published
artifact tuple that passed the lifecycle qualification with Server 2.4.40.

Follows durable-workflow/workflow#605 and
durable-workflow/server#299.

Changes

  • Update both Composer locks from Workflow 2.3.2 to 2.3.4 at
    e66d22482541ddcaa03964fe006538a7340083fe. Preserve the existing ^2.0 constraints
    and all other package versions/source/dist references.
  • Update the qualified tuple to Server 2.4.40, Workflow 2.3.4 and Rust SDK 2.1.5.
    PHP 2.1.6, Python 2.3.9, CLI 2.1.3 and Waterline 2.0.9 remain the tested versions.
  • Update both prepared Rust Cargo locks to SDK 2.1.5. Its published manifest
    requires uuid exactly 1.26.1, so both locks also adopt that dependency.
    Both Cargo manifests and every other locked Rust package remain unchanged.

Qualification

Fresh published-package installations verify all 124 application and 116
microservice installed tuples against their locks, with 123/115 unrelated
packages unchanged. The installed repair bytes match the published release.
Both Composer validations pass.

Focused application workflow, preview and Waterline asset checks pass
10 cases / 20 assertions. The complete microservice suite passes
5 cases / 5 assertions. These local checks use isolated SQLite databases,
with the microservice's two connection aliases pointing at the same file.
Normal MySQL CI passes on PHP 8.4/8.5 on corrected commit
417af7f:
https://github.com/durable-workflow/sample-app/actions/runs/37273405615.
Application PHP 8.4 reports 145 passed, one warning and 1189 assertions.
PHP 8.5 reports 84 passed, 61 deprecated, one warning and 1189 assertions.
Both Node cases pass on both jobs. Microservice PHP 8.4 reports five passed,
while PHP 8.5 reports one passed and four deprecated, each with five assertions.
Composer validation/audit, artifact graph and central action policy pass.

The published PHP/Python/Rust workflow completes on the selected tuple:
https://github.com/durable-workflow/sample-app/actions/runs/37273405640.
Docker Compose embedded workflow samples also pass:
https://github.com/durable-workflow/sample-app/actions/runs/37273405646.
The candidate development image passes Codespaces startup, prepared SDK doctor
checks and locked offline Rust compilation:
https://github.com/durable-workflow/sample-app/actions/runs/37273405683.
All 11 checks pass on the corrected head before merge.

Both Cargo locks were resolved using Rust 1.86 container tooling. Locked Cargo
metadata succeeds for both consumers and confirms SDK 2.1.5 with its exact
uuid 1.26.1 requirement. The initial CI caught the prepared lock mismatch with
the tuple. The existing contract tests and doctor checks remain unchanged.
The corrected normal CI passes without changing tests or doctor checks.
Merged as 5a3ee54 with the exact qualified
source tree. The merged remote branch is deleted and verified absent.
Target-branch CI, polyglot and Compose checks pass.

Protected publication and native startup qualification pass for both published
development image architectures:
https://github.com/durable-workflow/sample-app/actions/runs/37273979941.
Qualification includes anonymous pulling, OCI source identity, per-platform
attestations, HTTP readiness, prepared SDK versions, locked offline Rust
compilation, browser/SSH/database checks and an unchanged tracked checkout.
Measured qualification duration is 87 seconds on amd64 and 85 seconds on arm64.

Published development image index:
sha256:d2a87c22b5e5763e7cd4dd6433ddb45b3b84622f3a6d40bd85c987e67ea41c46.
The immutable sha-5a3ee547bc4b84733c79d6a0e4612176d1eea7be-run-37273979941-1
tag and promoted main channel return the same bytes/digest from Docker Hub and
GHCR through anonymous registry reads. Both architecture manifests verify
against their digests and identify the merged source commit.

Server 2.4.40 is published at immutable digest
sha256:1f34d9dc4bfcfff281a35a6e6f0490be313ef481952a5d56755b4fa10e576116
for amd64 and arm64. Its first-run readiness, source-free Compose and protocol
catalog checks pass, and matching Helm 0.1.136 passes anonymous installation:
https://github.com/durable-workflow/server/actions/runs/37271564195.

All 12 published lifecycle cells pass on this exact tuple, with no missing
evidence, runner blocker or local product source used as pass evidence:
https://github.com/durable-workflow/server/actions/runs/37272048053.
The PHP SDK's 14 conformance scenarios also pass. An additional real HTTP
drill in the unchanged published image repairs and completes four workflows
across default/custom namespaces while excluding another namespace.

No unchanged SDK or Waterline package release is needed for this consumer
update. Workflow605 remains open until the consumer PR passes CI and lands.

@rmcdaniel

Copy link
Copy Markdown
Member Author

Corrected candidate: 417af7f.

Both prepared Rust locks now resolve durable-workflow 2.1.5. The published SDK
requires uuid exactly 1.26.1, so this required transitive dependency changes
in both locks as well. No other Cargo package or either manifest changes.
Rust 1.86 container tooling resolves both locks and cargo metadata --locked
succeeds for both consumers. Existing contract tests and doctor checks remain
unchanged. Normal repository CI is running on the corrected commit.

Initial CI 37272614319 caught the mismatch between the selected tuple and the
prepared Rust locks in two existing application tests. The microservice,
polyglot and Compose workflow checks passed on that initial commit. Those
checks are running again on the corrected head before merge.

No provider resource was allocated. Both bounded Cargo containers and task
dependency scratch were removed at completion before their 06:50 deadline.

@rmcdaniel
rmcdaniel marked this pull request as ready for review October 5, 2026 06:43
@rmcdaniel

Copy link
Copy Markdown
Member Author

Reviewed candidate 417af7f, tree
97423a537b6eb50f0ed499212436a30f7116864c, against current main
f0003da.

Five files change. Both Composer locks select the actual published Workflow
2.3.4 commit e66d22482541ddcaa03964fe006538a7340083fe while preserving ^2.0
constraints and every other installed package version/source/dist tuple.
The qualified artifact tuple selects the already published and tested Server
2.4.40, Workflow2.3.4 and RustSDK2.1.5. The remaining published SDK/CLI/Waterline
versions stay unchanged.

Both prepared Rust locks select published SDK2.1.5 with its published checksum
and required exactuuid1.26.1 dependency. No other Cargo package or manifest
changes. Locked metadata was actually executed successfully for both consumers
using Rust1.86. Existing matching-version tests and doctor checks are unchanged.

Corrected normal CI37273405615 succeeds on this head. Application PHP8.4:
145passed,1existing warning,1189assertions. Application PHP8.5:
84passed,61deprecated,1warning,1189assertions. Both have2passingNodecases.
Microservice PHP8.4:5passed/5assertions. PHP8.5:1passed,4deprecated/5assertions.
Composer validation/audit, stable tuple resolution, artifact graph and central
action policy also succeed. Initial lock mismatch and failed CI are retained.

No behavioral test, required gate, application source or public protocol changes.
All11 checks now pass on the exact head, including published polyglot execution,
Compose workflow examples and the candidate image's Codespaces startup, prepared
SDK doctor checks and locked offline Rust compilation. The target branch is
unchanged and the source is clean. No review finding remains for this update.
After merge, verify the target tree and both published development image
architectures through the repository's protected main publisher.

@rmcdaniel
rmcdaniel merged commit 5a3ee54 into main Oct 5, 2026
11 checks passed
@rmcdaniel
rmcdaniel deleted the fix/repair-runtime-consumers branch October 5, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants