Customer outcome
Recover an expired workflow task while an older remote activity is still leased, so accepted workflow work can reach a replacement worker without waiting for the activity's separate five-minute lease.
Confirmed defect
Found while qualifying the real Python remote worker in shared cancellation work. Python head 88f0e31bf1736271deaabcc67d74df9ce98df491, Server 073a516bbd4063f57d4ad65ad732ec423131c8ff, published Workflow 2.3.0, MySQL 8.0 and Redis 7 reproduce it in candidate CI and a fresh isolated local stack.
- Run the actual Python worker and block a remote activity without user heartbeats.
- Kill its process, leaving its already-issued workflow long poll on the Server.
- Request cooperative cancellation. That outstanding poll claims the new workflow task for the dead owner.
- The configured ten-second workflow lease expires. A different replacement worker polls the same queue.
- Server invokes the package's
attemptRepair(), but the summary selects the older, still-leased activity. Repair repeatedly records repair_not_needed with activity_task_leased. The expired workflow task stays leased and the replacement receives no claim.
The local snapshot shows the activity lease expiring at 06:59:28.256350Z, while the workflow lease expired at 06:54:38.541218Z. At 06:54:44.542725Z that workflow task was still leased at attempt 1 and repair count 0. Four successive repair events reported repair_not_needed. The kill qualification fails before receiving the replacement workflow claim. This is a native recovery-selection defect, not evidence for increasing the fixture timeout.
Work and verification
- Make an expired workflow lease visible to the native repair decision even when another task remains legitimately in flight.
- Preserve the existing activity owner, attempt, lease and history while reclaiming only the expired workflow task.
- Cover the fresh-lease case, replacement claim fencing and the combination of an active remote activity with pending workflow work.
- Run the Workflow quality cycle and supported database gates. Rerun the real Python SIGKILL scenario against the exact corrected package and Server source.
- Publish the qualified patch through the normal artifact contract and update dependent qualification. Candidate cooperative protocol activation remains a separate shared release gate.
Delivered and verified artifacts
The native correction merged in #600 and shipped as Workflow 2.3.1, exact source fb3f3e59a4342fdebf8ced6160798906c3ee4387. Supported database/quality gates and published package/embedded-upgrade verification pass. Server 2.4.35 incorporates that package at published index sha256:49560f7f861271931125348a9d01638cd722e13ee976b5b732ef122548f15dab. Its release retains the unchanged ordinary-protocol before/after recovery probe and all twelve passing published PHP/Python/Rust lifecycle cells with hashes and raw artifacts. The corrected actual Python SIGKILL candidate scenario also passes against the pinned corrected native source.
Sample App's main app and portable tuple were updated in #129, with bounded ARM64 publication repair #130. #132 completes the secondary Laravel microservice and bundled CLI correction. Its protected publication 36840788892 passes both native builds and anonymous published startup qualification. Actual contents on AMD64 and ARM64 confirm Workflow 2.3.1 in both Laravel apps and CLI 2.1.3. GHCR/Docker Hub main and immutable indexes all resolve anonymously to sha256:671498a741b86386cdebf603479e0c87f5f2777ebb7a86c6bfc76f33bd4a5977 at merged source 11ee4c7143a37cbfc22981af547120e293339933.
The final published consumer gate is complete. All merged task branches were deleted and their GitHub absence verified. Cooperative protocol activation remains the separate shared published-artifact gate in durable-workflow/.github#136. Cloud qualification stays in its private owning record. No production or customer namespace is used in this qualification.
Customer outcome
Recover an expired workflow task while an older remote activity is still leased, so accepted workflow work can reach a replacement worker without waiting for the activity's separate five-minute lease.
Confirmed defect
Found while qualifying the real Python remote worker in shared cancellation work. Python head
88f0e31bf1736271deaabcc67d74df9ce98df491, Server073a516bbd4063f57d4ad65ad732ec423131c8ff, published Workflow 2.3.0, MySQL 8.0 and Redis 7 reproduce it in candidate CI and a fresh isolated local stack.attemptRepair(), but the summary selects the older, still-leased activity. Repair repeatedly recordsrepair_not_neededwithactivity_task_leased. The expired workflow task stays leased and the replacement receives no claim.The local snapshot shows the activity lease expiring at
06:59:28.256350Z, while the workflow lease expired at06:54:38.541218Z. At06:54:44.542725Zthat workflow task was still leased at attempt 1 and repair count 0. Four successive repair events reportedrepair_not_needed. The kill qualification fails before receiving the replacement workflow claim. This is a native recovery-selection defect, not evidence for increasing the fixture timeout.Work and verification
Delivered and verified artifacts
The native correction merged in #600 and shipped as Workflow 2.3.1, exact source
fb3f3e59a4342fdebf8ced6160798906c3ee4387. Supported database/quality gates and published package/embedded-upgrade verification pass. Server 2.4.35 incorporates that package at published indexsha256:49560f7f861271931125348a9d01638cd722e13ee976b5b732ef122548f15dab. Its release retains the unchanged ordinary-protocol before/after recovery probe and all twelve passing published PHP/Python/Rust lifecycle cells with hashes and raw artifacts. The corrected actual Python SIGKILL candidate scenario also passes against the pinned corrected native source.Sample App's main app and portable tuple were updated in #129, with bounded ARM64 publication repair #130. #132 completes the secondary Laravel microservice and bundled CLI correction. Its protected publication 36840788892 passes both native builds and anonymous published startup qualification. Actual contents on AMD64 and ARM64 confirm Workflow 2.3.1 in both Laravel apps and CLI 2.1.3. GHCR/Docker Hub main and immutable indexes all resolve anonymously to
sha256:671498a741b86386cdebf603479e0c87f5f2777ebb7a86c6bfc76f33bd4a5977at merged source11ee4c7143a37cbfc22981af547120e293339933.The final published consumer gate is complete. All merged task branches were deleted and their GitHub absence verified. Cooperative protocol activation remains the separate shared published-artifact gate in durable-workflow/.github#136. Cloud qualification stays in its private owning record. No production or customer namespace is used in this qualification.