Repository navigation
feat: add cooperative cancellation requests and claim-bound delivery - #291
Conversation
|
Connected Python/Server source qualification now passes eleven SQLite cases at Python The current default remains protocol 1.19. Explicit source candidate protocol 1.20 now discovers the capability through the same policy used for request admission. Python's normal suite passes 1,618 local tests, Ruff and strict mypy. Server's affected filter passes 145 tests and 5,165 assertions, with Pint passing. Normal Python CI, Server CI and an explicit exact-pair MySQL qualification are running. The candidate run's three supported Python, package, corpus and lint jobs pass. It retains connected JUnit evidence and removes its stack. Next: finish those source gates, then PHP/Rust equivalents, coordinated protocol/specification activation and the exact published service tuple. These source drafts do not authorize a published cooperative capability claim. Completed local task resources are being removed. |
Connected Python qualification completeAt Python Full scenario evidence covers original identity/deadline/one marker, a discarded successful delivery response, real SIGKILL and cold process replacement, local async/synchronous and remote fencing, shutdown grace/expiry, waiting timer, deadline and termination. Local SQLite passes all eleven cases. All local task containers, worktrees, dependencies, proofs and images are removed. Downloaded CI reports and transport files are removed after this handoff. Server's source/corpus CI passes 2,279 tests and 47,800 assertions. MySQL replay/query topology passes. Polling bounded-growth smoke remains running. Both PRs remain drafts and default protocol remains 1.19. Next: PHP/Rust request, delivery, canonical replay and shielded cleanup parity, remaining backend concurrency, coordinated specification/capability activation and the exact published Server/SDK tuple. No published cooperative capability is authorized by these source-only results. |
Remote activity observation qualified at
|
|
The cooperative Server candidate now consumes published Workflow 2.3.1 at Workflow's complete source matrix and all 16 published Laravel/PHP upgrade combinations pass. Server #292 is separately qualifying stable image 2.4.35. A focused ordinary-protocol signal drill reproduces the expired-workflow/older-active-activity defect on published Server 2.4.34 and PHP SDK 2.1.6, so this repair also affects existing service callers. The entire Python candidate CI is dispatched at unchanged Python |
Heartbeat ownership interleaving reproduced and fixed at sourceThe ordinary protocol 1.19 regression fails against unchanged main Observed baseline: {"heartbeat":{"workflow_task_attempt":1,"lease_owner":"original","renewed":true},"replacement_claim":{"workflow_task_attempt":2,"lease_owner":"replacement"}}The same Native task ID was present in both responses. The positive heartbeat therefore identified a claim that no longer owned the task. The fix in #294 head Cooperative cancellation draft #291 carries the same locked renewal, plus the pending observation read inside that transaction, at Normal CI is running for both heads. This source result does not claim a published image or Cloud deployment. Next finish exact-head CI/review, publish Server 2.4.36/Helm 0.1.132 independently of cooperative cancellation and verify the affected published worker cells. Rust coordinator qualification then uses the requalified #291 head. Default protocol 1.19 and ordinary capabilities remain unchanged. |
Published Server 2.4.35 reproduces the ownership defectThe same committed regression ran inside the unchanged published Server image The two actual HTTP kernels reproduce: {"heartbeat_status":200,"heartbeat":{"workflow_task_attempt":1,"lease_owner":"original","renewed":true,"reason":null},"replacement_claim":{"workflow_task_attempt":2,"lease_owner":"replacement"}}Both responses identify the same actual Native task. The unchanged published image therefore fails the ownership assertion, with 16 assertions reached. SQLite clocks and an IPC barrier control the interleaving; the harness does not edit any lease, owner or attempt row. The original full CI result exposed an overly strict test assertion, not a valid positive acknowledgment. PHP 8.3 uses deferred SQLite transactions even when Next complete revised-head CI and review, publish Server 2.4.36, repeat this exact-image regression and verify the published PHP/Python/Rust lifecycle tuple before closing #293. |
…ellation-service # Conflicts: # app/Http/Controllers/Api/WorkerController.php
|
The ordinary-protocol heartbeat ownership fix has shipped independently as Server 2.4.36, and #293 now has exact published before/after regression and published PHP/Python/Rust lifecycle evidence. This draft incorporates merged main at Local formatting and the focused ownership/cancellation cases pass 25 cases and 565 assertions. Exact-head feature CI passes 2,302 cases and 48,041 assertions. Boundary and replay/query checks pass. Polling smoke is still running at this handoff, so no completed all-checks claim is made yet. Next product action remains Rust #55's real claim/heartbeat cancellation carrier, canonical delivery refresh and replay coordinator, including callback ownership, replacement and physical lifetime checks. Candidate Server/Native and per-language connected gates must use the updated exact source tuple before the final published tuple is released. This stable heartbeat patch does not qualify or activate cooperative cancellation. |
|
The updated Server cancellation draft head Rust #55 has advanced to Next action remains connecting that carrier to the Rust delivery/canonical-refresh/replay coordinator, preserving earlier command prefixes and proving committed delivery before application cancellation. The connected language and physical callback lifetime/ownership/replacement gates remain required before cooperative release or activation. Published Native remains Workflow 2.3.1. |
Pending cancellation remains runnable after a command prefixThe real Rust Worker qualification found a missing Server successor. At Server Fixed in Two regression cases cover request before and after claim, two prefix side effects, repeated completion rejection, a different successor owner, delivery at sequence 3, and no leftover runnable task after terminal cancellation. Raw counterfactual on the preceding Server head: Focused protocol suite after the fix: Local feature/Nexus/corpus/OpenAPI run: The local run omits nine external-service cases. Full Server CI supplies those services and is running. Exact-candidate connected qualification is also running for Rust, PHP, and Python. Next: inspect those results, address any remaining actual Worker/recovery failures, then qualify the complete published tuple before activating the capability. This PR remains a draft. Default Worker protocol remains 1.19. |
Current source qualificationServer All current normal gates passed:
Connected source checks use this exact Server commit and published Workflow 2.3.1:
Shared recovery and replay gates and complete published-tuple qualification remain open. This remains a draft. Published artifacts and ordinary Worker defaults remain unchanged. |
Scoped cleanup transport implementedServer Candidate document 45 defines strict root and scoped proof/snapshot alternatives. No caller deadline is accepted. Root shapes and default/published 1.19 are preserved. This source specification remains unfrozen, and scope execution remains unadvertised. Local affected source checks pass 186/8747, zero errors/failures/skips. HTTP coverage includes duplicate prepare, claim replacement, unknown physical-stop state on recovery, second-attempt cleanup retaining the original snapshot and deadline, stale publication refusal and all-or-nothing groups. Forged request/scope/delivery identities and invented deadlines fail before payload resolution. Strict schema, Pint, public boundary and 44 → 45 evolution checks pass. Locked package metadata retains the same 118 versions/references, with Native source explicitly overlaid. Ordinary CI and exact paired database qualification are running. Task-owned local resources are removed. Next is SDK cleanup/supervision and every hosting-claim renewal path, followed by real scoped SIGKILL recovery and operator inspection. The earlier unexplained Python recovery miss and the published/competitive gates remain open. This PR stays draft and #136 stays open. |
Performance gate follow-upThe current Server head is The first performance canary failed. One of 2,091 worker polls received HTTP 503 The source-built merge commit was The unchanged-threshold current main baseline, exact head Next action: retain MySQL lock/deadlock evidence and diagnose the conflicting transaction path before claiming a correction. No performance limit was relaxed. The paired source qualification subsequently passed: SQLite/MySQL/PostgreSQL The preceding canary |
Completed canary comparisonThe exact current-main baseline and candidate repeat pass the unchanged
Synthetic growth counts accepted starts. Only the separate standard workflow First candidate artifact, The first MySQL poll lock-pressure failure remains unexplained. The preceding |
Pair Server with scoped hosting recoveryServer draft #291 base 13114fa, Native exact First paired run Run the affected scope-delivery HTTP class with the exact Native source overlay, |
Scoped hosting Server source pairing qualifiesServer 30063a6, Native source overlay Ordinary CI The separate locked-package feature suite passes 2,397 / 48,774, retaining Hosted raw source evidence Next: authenticated preparation recovery |
|
Source pairing update at Server Only three Server test files change. First authenticated preparation must shorten the original ordinary claim into a live interval of at most ten seconds. Valid preparation/delivery retries may renew an already bounded interval. All other claim fields remain identical. Pending stop-receipt checks keep run/activity/history snapshots unchanged. The replacement HTTP fixture now uses watchdog repair and worker polling instead of manually incrementing the attempt. Both complete affected HTTP classes pass locally: 56 unique tests / 3,848 assertions, no errors, failures or skips. The case inventory matches the preceding two-class qualification. All three changed files pass Pint and syntax. All 118 ordinary installed metadata tuples match the unchanged Server lock. Three Server file hashes and 581 Native source/composer hashes match. The Native source overlay is explicit and separate from installed published Workflow 2.3.3 metadata. Full source pairing 37238088120 and ordinary package CI 37238035885 are running at this exact head. The new pairing results are pending. The prior Server 30063 / Native acfb pairing remains qualified separately. This is source evidence, not physical scoped worker SIGKILL, SDK-authored scope execution or the complete published mixed-language scenario. Default protocol remains 1.19, candidate 1.20 unfrozen, scope execution unadvertised, and this PR draft. Shared #136 stays open through its complete stronger-model acceptance gates. |
|
The Server 4429d58 / Native 6880706b source pairing 37238088120 hit the source job's 20-minute CI limit. It is not a complete paired qualification. Downloaded JUnit independently verifies SQLite and MySQL each pass 305 unique cases / 11,383 assertions, zero errors/failures/skips, preserving the preceding complete case inventory. Affected SQLite HTTP regressions pass 317 / 3,667, zero errors/failures/skips. PostgreSQL was interrupted with an empty JUnit file, so no PostgreSQL pass is claimed. Artifact 11316419748 binds Server 4429d58 and Native 6880706b in its provenance. Raw log, artifact and independent timing/inventory checks are retained. The MySQL suite took 854.001 seconds, versus 684.953 seconds in the preceding qualified pairing. That preceding entire source job used 18 minutes 52 seconds, leaving little room in a 20-minute budget. Multiple classes increased in duration. These CI timings do not establish an application performance regression or its cause. Increase only this source job's limit to 30 minutes, retaining the same three databases, 305 source cases, 317 regression cases, fail-on-skipped rule and exact Native overlay. No application timeout or original cancellation budget changes. Requalify the exact resulting Server commit and retain the interrupted run separately. Ordinary package CI, replay/query and the automatic performance canary pass at 4429d58. The earlier intermittent canary 503 remains a separate unresolved finding. The complete published mixed-language, scoped SDK, physical recovery, operator-view and competitive gates remain open. Protocol 1.20 stays unfrozen and this PR stays draft. All local task containers and scratch were already removed before their deadlines. |
Scoped preparation hosting recovery qualified in sourceExact pairing: Server d0d7e43, Native 6880706bad722cce69c19dd94a42d54df9771a41. Authenticated preparation bounds recovery before a delivery can wait on child completion or activity stop receipts. Valid retries preserve original frame/root/deadline and may renew the existing recoverable hosting interval. Expired/replaced owners cannot revive it. Server's three changed test files exercise first preparation, valid retries, unchanged run/activity/history and actual watchdog replacement through HTTP polling. Local affected HTTP classes pass 56 unique tests / 3848 assertions, zero errors/failures/skips. Three files pass Pint/syntax and source hashes. All 118 ordinary locked installed version/source/dist tuples match. Native's 581 source/composer hashes match the explicitly labeled overlay. Full exact-head pairing passes. Downloaded JUnit independently verifies every 305 source case exactly once per database, with the preceding source inventory unchanged. SQLite/MySQL/PostgreSQL each 305 / 11383, affected SQLite HTTP regressions 317 / 3667, zero errors/failures/skips. Raw source artifact records both exact revisions. The separate locked published-package suite passes 2397 / 48774, retaining Workflow 2.3.3, with 55 reported skips and six deprecations. Ordinary CI, replay/query CI and automatic performance canary pass at the same Server head. Native's full qualification passes at 6880706b. The first paired run at source component 4429d58 hit its twenty-minute job limit after complete SQLite/MySQL and affected SQLite passes. PostgreSQL has no complete report there. Current d0d7e43 differs only in allowing thirty minutes for that source CI job. All tests/databases/assertions remain required. Runtime timeouts and original cancellation deadlines are unchanged. Variation in hosted job times is not a runtime-performance result. Local test resources are removed. This completes this source pairing. Request-only recovery before preparation, SDK-authored scopes/selective supervision, physical scoped SIGKILL/replay, coherent operator inspection, the exact published mixed-language +30-second cascade and fair competitive qualification remain required. Shared #136 stays open, both model PRs remain draft, default protocol stays 1.19, candidate 1.20 remains unfrozen and scopes remain unadvertised. |
|
Pair the current Server source with Native c8be089f68cde92fa8289f2200e5b0cf939b181c request-before-preparation recovery. Native local qualification passes 489 / 4369 with three existing SQLite database-lock race skips, while its supported-database and ordinary CI gates are running at that exact commit. Assert shortening at acceptance, where the original ordinary lease changes. Preparation and delivery can renew the already bounded claim. Add an unprepared request case: expired original HTTP owner is refused without mutation, TaskWatchdog repairs, HTTP poll acquires the replacement, duplicate preserves original identity/deadline without renewing it, old attempt stays fenced and replacement prepares/delivers under that same budget. Qualify both complete affected HTTP classes and the existing supported-database source matrix with the immutable Native overlay. Ordinary locked-package CI remains separate. This is source qualification, with no dependency/runtime/protocol change and no physical worker kill, SDK-authored scopes, publication or deployment claim. Shared #136 remains open and the model PRs draft. |
Current scoped request pairingServer 92e9f12 pairs with Native Both complete affected HTTP classes pass 57 unique tests / 4069 assertions, Full source pairing |
|
Accepted scoped cancellation is now recoverable before preparation in qualified source Native c30428e47720bab40aee290253f33f6d4006a669 and Server 92e9f12. Acceptance bounds the hosting lease under the original deadline. The real watchdog recovers the unprepared task, the stale owner remains fenced, and the replacement prepares the first delivery boundary. Duplicate requests preserve identity, deadline and current ownership. Native full qualification and ordinary CI pass. Downloaded JUnit independently verifies all 130 feature files and 2255 unique cases exactly once per database. MySQL 2255/21479, PostgreSQL 2255/21420, zero errors/failures, three/eight existing skips. Unit 2400/17412, five skips/fifteen notices. Combined coverage 89.36% (62061/69444) exceeds the 87.85% baseline. Server paired qualification passes with explicit Native input c8be089f68cde92fa8289f2200e5b0cf939b181c. Its 581 runtime/composer file hashes match c30428e4. Downloaded JUnit verifies all preceding 305 cases plus exactly one HTTP request-before-preparation recovery case on each supported database: SQLite/MySQL/PostgreSQL each 306/11604, affected SQLite 317/3667, zero errors/failures/skips. Separate published-package qualification 2397/48774 retains Workflow 2.3.3, 55 reported skips/six deprecations. Both model PRs stay draft and shared #136 stays open. Default/published protocol is 1.19. Candidate 1.20 remains unfrozen. Next is SDK-authored scope execution and selective callback supervision, physical scoped cleanup-worker replacement and the coherent operator view. Published PHP/Python/Rust artifacts, the complete original-budget cascade and fair competitive qualification remain required. Local qualification resources are removed. |
Implements the Server cancellation surface for shared #136.
Supported release boundary
Whole-run cooperative requests expose immutable context and one bounded parent/child/Activity tree. Managed Activity stop receipts fence stale results. Original delivery and cleanup authority survive worker replacement. The diagnostics API explains the entire cascade and cleanup outcome. General independently cancellable scopes remain a disabled source preview outside the supported release claim.
Current pushed head
deb8be3a1e7b98e38a12ec5579850bdd1ef442e5prepares Server 2.5.0-rc.1 with worker protocol 1.20 and Helm 0.1.137-rc.1. Composer locks the published Native 2.4.0-rc.2 at200a3c0ffa1e90557619221458deb3516b8cf955, including the qualified scheduler correction in Native #610. The installed package version, reference and watchdog bytes match that release. Rust's supported version range includes the approved 3.x major. Generated release consumers are synchronized, and RC chart versions retain immutable publication and ordering checks.Qualification
Paired source qualification passes 321 cases / 12,123 assertions on each of SQLite, MySQL and PostgreSQL, plus affected SQLite checks. Server source is
f862da30f895527fbdb4da6be8c021d8be0c37a5with Native22fc0885681a26b00681f19efce87298ec55d97a.Final PHP/Python/Rust source qualification passes 50 cases / 2,789 assertions. Its required mixed cascade passes 237 assertions and completes both runs Cancelled 17.169470 seconds after the original request, before the original 30-second deadline. Physical callback stop without application heartbeats, stale fencing, actual cleanup-worker SIGKILL, replacement replay, duplicate identity/deadline and API/CLI inspection pass.
Captured canary deadlock and correction
The instrumented canary captured the actual cause behind the retained performance finding. At 05:51:37 one transaction held a leased workflow task and awaited its run, while repair held that run and awaited its tasks. This passing canary exposed the internal deadlock despite returning no 503 responses.
Correction
f6ceeceemakes the affected Server mutations acquire the run before the task, revalidate the task's run association under the lock, and preserve owner/attempt fencing inside the transaction. Failure responses also recheck ownership after acquiring the locks. Namespace checks remain part of every acquisition.Eight actual two-process repair races pass with 240 assertions against the published Native RC on MySQL and PostgreSQL. They cover heartbeat, completion, failure and waiting-for-history responses. Each test observes a database waiter, proves that repair can still lock the task, and completes the real repair and HTTP request. Mounting the previous WorkerController into the same consumer makes the original heartbeat and completion tests fail with MySQL error 3572. Normal feature CI runs these cases on its existing isolated databases.
The next instrumented canary completed 22/22 checked standard workflows and 1,000/1,000 starts with no HTTP errors, but captured a separate scheduler deadlock at 06:24:21. Native's watchdog held the task and waited for the run held by operator repair. Its repair report recorded error 1213. Native #610 corrects lease and deadline acquisition order. Both actual races pass on MySQL and PostgreSQL with 43 assertions per database, and both fail with the original published watchdog.
The missing diagnostic envelope on task refusal is corrected and passes the existing ownership/error contracts and namespace regression: 11 cases / 278 assertions. Current affected checks against the actual published Native 2.4.0-rc.2 pass 174 cases / 26,633 assertions. Final feature CI passes 2,410 cases / 54,709 assertions. Replay/query HTTP, both database rolling-upgrade checks, chart source validation and the actual Helm installation pass.
The final instrumented canary passes unchanged workload and thresholds: 1,000/1,000 starts, 17/17 standard workflow completions, all 82 readiness requests successful, no HTTP errors and no scheduler repair failures. Its readable InnoDB trace contains no detected deadlock, and all-deadlock logging was enabled with error verbosity 3 throughout the workload. The attempted global status counter is unavailable on this MySQL build and returned no row, so the finding uses the actual engine trace and full log rather than claiming a numeric counter. Stable follow-through will collect MySQL's
INNODB_METRICS.lock_deadlockscounter instead.The preceding canary's single readiness refusal was a bounded Redis transport
probe_timeout, not an observed SQL deadlock. It is tracked separately when inspecting the final canary. A passing HTTP summary alone will not substitute for checking its database and scheduler diagnostics.Next actions
The corrected candidate gates pass and the canary trace has been checked. Publish both image architectures and the RC chart, then run the registry-only mixed cascade at the immutable digest. Waterline and the site complete the inspection and documentation surfaces. Shared #136 remains open until published acceptance and the qualified stable release are complete. No Cloud deployment or capacity claim is made by this PR.