Customer problem
A workflow task completion can return recorded: false because the run timed out while still publishing the stream item carried by its rejected record_side_effect command. A subscriber can therefore consume output with no matching accepted SideEffect history.
WorkerController currently applies stream directives before Native accepts the batch. A Native refusal is a returned outcome rather than an exception, so the surrounding transaction can commit the preceding stream write. This was found while qualifying scope admission for shared #136 and Server #291. It also reproduces with the pinned published Native 2.3.3 dependency and the existing completion path. It must ship independently of the unfinished cancellation scopes.
Acceptance
- A genuinely timed-out run rejects completion and publishes no stream or item and no SideEffect history.
- Native's timeout history and terminal state still commit. Do not roll back legitimate timeout/cancellation decisions merely because completion was refused.
- Successful final workflow completion commits its last stream item and close together with history.
- A stream failure rolls back Native's successful admission, leaving the original claim and run state intact.
- Existing stream behavior and affected worker/payload/quota tests pass against the locked published Native package.
- Merge a reviewed Server PR, publish the routine patch image and qualify the exact published artifact with affected PHP/Python/Rust stream conformance.
Source qualification and the narrow regression are recorded in #291 (comment). Candidate scope metadata, protocol 1.20 and the new Native role are excluded from this stable fix.
Customer problem
A workflow task completion can return
recorded: falsebecause the run timed out while still publishing the stream item carried by its rejectedrecord_side_effectcommand. A subscriber can therefore consume output with no matching accepted SideEffect history.WorkerController currently applies stream directives before Native accepts the batch. A Native refusal is a returned outcome rather than an exception, so the surrounding transaction can commit the preceding stream write. This was found while qualifying scope admission for shared #136 and Server #291. It also reproduces with the pinned published Native 2.3.3 dependency and the existing completion path. It must ship independently of the unfinished cancellation scopes.
Acceptance
Source qualification and the narrow regression are recorded in #291 (comment). Candidate scope metadata, protocol 1.20 and the new Native role are excluded from this stable fix.