Skip to content

Keep repaired tasks discoverable in their original namespace - #299

Merged
rmcdaniel merged 2 commits into
mainfrom
fix/repair-task-namespace
Oct 5, 2026
Merged

rmcdaniel merged 2 commits into
mainfrom
fix/repair-task-namespace

Conversation

@rmcdaniel

@rmcdaniel rmcdaniel commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Customer outcome

A repaired workflow remains visible to the worker in its original namespace.
The repair API must recover both a missing workflow task and an existing Ready
task with a missing namespace, including a custom tenant namespace. A worker
from another namespace must not claim either task.

This consumes the published Workflow 2.3.4 fix for
durable-workflow/workflow#605. Workflow 2.3.4 is
available on Packagist at e66d22482541ddcaa03964fe006538a7340083fe.
Its published package contract and all 16 supported Laravel/PHP upgrade cells
passed in https://github.com/durable-workflow/workflow/actions/runs/37269932357.

Changes

  • Add four API regression cases covering default/custom namespaces and
    missing tasks/existing orphan tasks. Each starts a real workflow, injects
    the fault, repairs it, checks queue visibility and namespace isolation,
    claims the task and completes the workflow through the Server API.
  • Pin the runtime dependency and lock to the published Workflow 2.3.4.
  • Prepare Server 2.4.40 and Helm chart 0.1.136 using the existing source-release
    manifest and generator. No other dependency version/source/dist tuple changes.

Qualification

The four regression cases fail at the missing-namespace assertion with the
original published Workflow 2.3.3. The corrected source passed the complete
18-case repair API class. A separate fresh Composer installation of the actual
published 2.3.4 package then passed all 50 affected cases and 392 assertions:

  • TransportRepairTest: 18 cases, 213 assertions, no skips or failures.
  • WorkflowPackageApiFloorTest: 32 cases, 179 assertions, no skips or failures.

An independent check verifies the complete 118-package installed/locked set,
117 unchanged dependency tuples, exact published source/dist commit, installed
repair source SHA-256 c84c0189896e8af95cdfe00208e5725bfd3047fa4e1154af4ba5507cf7d77280,
and the unique XML case inventory. Syntax, Pint and generated source-release
consistency checks pass. Local checks used a UID 1000 container with init,
2 CPUs, 2 GiB memory and no additional swap allowance.

Release follow-through

All 14 repository check runs pass at edd1b31,
including feature/source and performance qualification, both database rolling
upgrades, concurrent HTTP and Helm kind installation. The complete feature,
Nexus and regression-corpus invocation passes 2,260 cases and 47,335 assertions
and reports six PHPUnit deprecations. Source review is recorded in
#299 (comment).

After merge, publish the
immutable 2.4.40 multiarch image through the protected repository workflow,
verify its exact Workflow package contents and repair API behavior, and run
the affected published PHP/Python/Rust lifecycle and recovery qualification.
The owning issue stays open until required downstream consumers are verified.
This PR makes no Cloud deployment claim.

@rmcdaniel

Copy link
Copy Markdown
Member Author

Reviewed Server299 at edd1b31,
tree a3b3f3e3d26e039ae87762d0d5b6fefa77df80c7, against unchanged
main7a592593c3a2c998626e819322e0117c002ef8b2.

The changes are four API regression cases, the exact published Workflow2.3.4
dependency and generated Server2.4.40/Helm0.1.136 release metadata. No Server
runtime, authentication, schema or protocol implementation changed. The
ten-line runtime repair correction is already published in Workflow2.3.4.

The test deliberately removes the fixture listener that would otherwise mask
omitted namespaces. It injects the fault after a real API start, refreshes the
history projection and checks repair counts, original task identity, Ready
state, queue visibility, cross-namespace exclusion, lease owner and successful
completion. The existing orphan uses the actual redispatch policy and past
availability. Both default and custom namespaces are covered for both faults.
The original published baseline fails all four at the intended assertion.

Fresh actual Packagist installation passes the entire repair/API-floor
selection, 50 cases and 392 assertions, with exact installed source bytes and
all 117 unrelated dependency tuples preserved. Source-release consistency,
Composer metadata, syntax and style pass. Target main remains unchanged and
the worktree is clean. The new release uses the existing protected publisher
and immutable tags. Registry/package identity, first-run readiness, Compose,
protocol catalog and Helm installation remain enforced there.

Repository contract/action policy, complete feature/Nexus/corpus source
qualification, both MySQL/PostgreSQL rolling upgrades, concurrent MySQL HTTP,
Helm lint/render/kind install, public boundary and bounded-growth contract
checks pass. Wait for the remaining polling cache-growth job before merge.
Then verify the exact multiarch published image and affected PHP/Python/Rust
lifecycle/recovery. No review finding requires another source change.

Workflow605 remains open for publication and embedded-consumer follow-through.
Cloud qualification and deployment remain separate private decisions.

@rmcdaniel
rmcdaniel marked this pull request as ready for review October 5, 2026 06:10
@rmcdaniel
rmcdaniel merged commit e478c8e into main Oct 5, 2026
14 checks passed
@rmcdaniel
rmcdaniel deleted the fix/repair-task-namespace branch October 5, 2026 06:15
@rmcdaniel

Copy link
Copy Markdown
Member Author

Server 2.4.40 is published and its exact image is verified:
https://github.com/durable-workflow/server/releases/tag/2.4.40.

Immutable digest:
sha256:1f34d9dc4bfcfff281a35a6e6f0490be313ef481952a5d56755b4fa10e576116,
amd64 and arm64. Source e478c8e,
with Workflow 2.3.4 from e66d22482541ddcaa03964fe006538a7340083fe.
PR299 is merged, its remote branch is absent, and tag2.4.40 is immutable.

Protected publication, bare first-run readiness, source-free Compose,
protocol catalog convergence and Helm0.1.136 anonymous installation pass:
https://github.com/durable-workflow/server/actions/runs/37271564195.

All12 published lifecycle cells pass, with no missing cell/evidence or runner
blocker. The exact tuple is Server2.4.40, Workflow2.3.4, PHP2.1.6, Python2.3.9,
Rust2.1.5, CLI2.1.3 and Waterline2.0.9. PHP's14 conformance scenarios also pass:
https://github.com/durable-workflow/server/actions/runs/37272048053.

A separate real HTTP drill in the unchanged published amd64 image passes
all four default/custom namespace and missing/orphan task combinations.
Each task becomes visible in its original namespace, remains excluded from
another namespace, is claimed and completes. Independent verification checks
all38 raw HTTP responses, four distinct runs/tasks, OCI identity, provenance
and installed repair bytes.

Raw evidence is retained as release assets and was independently downloaded
and byte compared after upload:

The downstream example update is
durable-workflow/sample-app#137. Its microservice MySQL
jobs pass on PHP8.4/8.5, while both main application jobs currently fail and
are being investigated. Required polyglot/Compose/image checks are still
running. Workflow605 stays open until that consumer update is qualified and
landed. This publishes the stable1.19 repair fix. Cooperative1.20 candidate
publication and the stronger cancellation acceptance remain separate work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants