Customer problem
A workflow task heartbeat must renew only the caller's current owner and attempt. The current Server controller checks ownership before the separate Native renewal transaction. If Native reclaims an expired lease between those operations, the old heartbeat can renew the replacement lease and return a positive acknowledgment under the old owner and attempt.
A controlled two-process HTTP interleaving reproduced this against Server draft #291 at c32434cc784a1bf870dcf19568bef944a320f6a7 with published Native Workflow 2.3.1. The original guard passed, Native actually reclaimed the task to a replacement owner and attempt, and the original heartbeat returned HTTP 200, renewed: true, attempt 1 and the original owner. No lease row was manually changed. Current main has the same validation/renewal separation. This is a source reproduction, not a published-image or deployment claim.
Acceptance
- Lock the namespace-scoped task, validate current ownership and registration, and renew within the same transaction. Preserve existing response schemas, refusal reasons and lock-pressure handling.
- Add a deterministic two-process regression using actual Native claims and renewal. Verify that a positive acknowledgment matches the persisted owner and attempt, and that a concurrent poll cannot replace a claim renewed under the lock.
- Retain wrong-owner, wrong-attempt, expired lease, missing task, stale registration and backend-pressure coverage. Pass the owning repository's normal CI.
- Deliver the existing protocol fix independently of cooperative cancellation. Keep default protocol 1.19 and ordinary capabilities unchanged.
- Publish a patch image through reviewed Server changes and verify the exact artifact and affected published PHP/Python/Rust worker behavior. Record versions, digests and results before closing.
Next action: extract the locked heartbeat and ordinary-protocol concurrency regression onto current main, qualify it, and carry the same fix into #291 before Rust coordinator integration.
Customer problem
A workflow task heartbeat must renew only the caller's current owner and attempt. The current Server controller checks ownership before the separate Native renewal transaction. If Native reclaims an expired lease between those operations, the old heartbeat can renew the replacement lease and return a positive acknowledgment under the old owner and attempt.
A controlled two-process HTTP interleaving reproduced this against Server draft #291 at
c32434cc784a1bf870dcf19568bef944a320f6a7with published Native Workflow 2.3.1. The original guard passed, Native actually reclaimed the task to a replacement owner and attempt, and the original heartbeat returned HTTP 200,renewed: true, attempt 1 and the original owner. No lease row was manually changed. Currentmainhas the same validation/renewal separation. This is a source reproduction, not a published-image or deployment claim.Acceptance
Next action: extract the locked heartbeat and ordinary-protocol concurrency regression onto current main, qualify it, and carry the same fix into #291 before Rust coordinator integration.