Repository navigation
Add cooperative cancellation to the PHP SDK - #91
Conversation
|
The PHP SDK request foundation is now in draft PR #91 at It requires explicit Server capability discovery, validates the workflow/run acknowledgment and preserves the original request ID, deadline and opaque history refresh token. PHP exposes current-run and explicitly selected-run handle operations using its existing handle convention. Default protocol remains 1.19, and the PHP worker does not advertise cooperative cancellation support. Local qualification on PHP 8.4.26 passes the full 804-case source suite with 4,745 assertions and one existing skip, plus static analysis. The new request tests cover 26 cases and 72 assertions. The normal supported PHP and framework CI is running against the latest draft head. Fresh development installation identified an independent phpDocumentor dependency advisory. PR #92 fixed it with one advisory-specific resolution exception that remains visible to audits. Its normal CI, documentation, clean runtime dependency audit and unchanged blocking of the older Flysystem advisory were verified before merge. Next for PHP: consume canonical request/delivery history, replay cancellation at the recorded authored boundary, integrate lease-fenced delivery and history refresh, then qualify shutdown and cold replacement against the same Server candidate. Rust support and exact published artifact qualification remain required before the shared capability is enabled. |
PHP request and canonical history foundation verifiedExact source: Local qualification at this source on PHP 8.4.26 passes:
The tests exercise capability refusal before mutation, selected-run and namespace binding, scoped control credentials, duplicate requests retaining Server identity/deadline, malformed acknowledgment rejection, immutable canonical request/delivery state, wrong-run and changed-deadline rejection, reordered/duplicate markers, valid and invalid parallel/selection operation ranges, and preservation of earlier committed results, failures and selection winners. The local runner used an isolated path consumer for the SDK, PHPUnit 11.5.56 and PHPStan 2.2.16, with the repository's PHPUnit configuration and test namespace bootstrap. The ordinary CI uses the normal contributor This remains a draft. The canonical reader is not yet connected to replay, and the PHP worker does not advertise this capability. Next is to inject cancellation at the recorded authored boundary, commit delivery through the live task lease, reload canonical paged history and qualify cleanup shielding, worker lifetime and cold replacement against the connected Server candidate. Rust parity and exact published artifact qualification remain required before shared capability activation. Published protocol defaults remain 1.19. Cleanup is complete. Both clean task worktrees, all task dependency/build/cache/diagnostic directories, the temporary security negative-check consumer, and the local PHP tool image and its task layers have been removed. No task container or volume remains. No paid infrastructure was used or created. |
PHP replay and cleanup shielding implementedExact candidate source: Canonical delivery now throws
Local qualification on PHP 8.4.26, PHPUnit 11.5.56 and PHPStan 2.2.16:
The selection test starts with the retained runtime-produced selection fixture, preserves the committed winner, removes the pending loser's completion and verifies that cancellation targets its earlier operation range while cleanup follows the delivery slot. The local activity check proves that a pending request does not execute the callback. This remains source work in a draft. Claim/heartbeat negotiation, fenced delivery transport, canonical history refresh, local activity interruption, shutdown and real connected PHP Server qualification remain required. Default protocol remains 1.19 and the PHP worker does not advertise cooperative support. Rust parity and exact published artifact conformance remain required before the shared capability is enabled. |
Latest PHP source foundation verifiedExact source: The delivery client uses worker credentials, the selected namespace, current task/owner/attempt and the complete authored call range. Malformed acknowledgments and changed request, sequence, kind or operation range are rejected. Source qualification may select protocol 1.20 explicitly through the Client constructor. Default protocol remains 1.19, and the managed PHP worker does not advertise cooperative support. Local PHP 8.4.26 qualification passes 114 focused cooperative cases with 257 assertions and the complete ordinary source suite of 892 cases with 4,930 assertions, one existing skip and no failures. PHPStan and Replay/cleanup behavior and the 20 new replay cases are detailed in the preceding report. No SDK release or published capability claim is made from this source work. Next: integrate immutable claim/heartbeat observations, fenced delivery and canonical paged history refresh into Worker. Qualify in-flight local activities with and without user heartbeats, preserved earlier local reports, cleanup deadlines, shutdown and cold replacement against the same Server candidate. PHP synchronous callbacks require an explicit lifetime solution before the worker can advertise support. Rust parity and exact published artifact conformance remain required. The clean task worktree, dependency/build/cache data and PHP tool image plus its task layers have been removed. No task container, volume or paid infrastructure was created or retained. |
PHP Worker integration and connected qualificationExact PHP source: Ordinary CI, both public boundary checks and the complete connected MySQL run pass at this head, including target branch qualification. The connected job verifies the exact Server commit, runs real SDK worker processes against its isolated MySQL/Redis stack, and removes its containers, network and local images afterward.
Worker now observes immutable task/heartbeat requests, renews the exact lease fence, performs delivery through worker credentials, reloads every canonical history page through the Server-issued opaque token and proves the matching committed delivery before workflow cleanup. Lost or malformed replies cannot manufacture delivery. Earlier local reports commit before later cancellation. Unsafe claims are abandoned without an application failure event. Real connected history exposed a start-prefix defect: new histories begin with This remains a draft and source qualification. The no-user-heartbeat callback case proves rejection after a bounded callback returns, not interruption during an arbitrary blocking callback. Next PHP action is a deliberate execution-lifetime solution and real in-flight checks for cancellation, lease loss, shutdown, grace/deadline expiry and SIGKILL replacement, plus remote activity fencing. Rust parity and exact published Server/SDK conformance remain required before the shared capability is published or enabled by default. Existing terminal cancel/terminate behavior stays intact. Local task evidence is retained here before removing the clean worktree, dependencies, test/build caches, counterfactual files and tool image. No local Server stack, paid infrastructure or customer state was created for this qualification. |
October 1 source baseline at
|
|
The connected run at
|
PHP local activity lifetime qualified at
|
Bounded payload I/O implemented, October 1Current source is Optional bounded binary interfaces preserve ordinary transport signatures and settings. Cooperative registration rejects adapters that expose legacy binary I/O without bounded counterparts. The default cooperative transport requires Guzzle with cURL, forces complete-response mode even when the caller enables streaming, and uses Guzzle's finite temporary sink. Upload replies are capped at 64 KiB, successful downloads still require the exact declared size and metadata, and the Client preserves namespace, role and digest validation. Temporary storage spills to disk instead of retaining an unbounded transfer in memory. Large transfers must finish within the worker budget, so a slow link may be refused rather than pinning task ownership. Ordinary workers keep their existing settings and protocol1.19. Local PHP8.4.26 qualification passes 966 cases / 5,387 assertions / eight opt-in runtime skips, static analysis, the dependency boundary, Compose configuration and Ordinary public CI and explicit connected source qualification are running on this exact head. The connected suite now includes a unique namespace and a task-owned shared payload volume. An actual cooperative Worker must hydrate and complete a value above the ordinary 2 MiB request limit, with the stored result reference, bytes and digest checked. No connected pass is claimed yet. Existing Server/Python evidence remains retained. Next resolve these exact checks, then continue remote activity lifetime/fencing, graceful shutdown and active-task cold replacement. Rust parity and exact published-tuple conformance remain required before release/default activation. No Cloud deployment or stable release occurred. |
Payload bounds qualified on exact PHP source, October 1Exact PHP head Against exact Server Commands are the repository's opt-in Local PHP8.4.26 passes 966 cases / 5,387 assertions / eight opt-in runtime skips, static analysis, the dependency boundary, Compose configuration and Cooperative control I/O now shares one monotonic five-second budget across discovery, payload upload, the API response and hydration. Long polls retain their offered wait, followed by one five-second hydration budget shared by references. Guzzle's cURL complete-transfer mode and finite temporary sinks close the per-read timeout gap. Optional bounded binary interfaces preserve ordinary transport signatures. Whole-second transport limits may overshoot the final fractional second before the budget check rejects a late reply. Slow large transfers can be refused, and custom adapters/handlers must honor their bounded capability. No new dependency, published capability, stable release or Cloud deployment is claimed. Next: PHP remote activity lifetime/fencing, graceful shutdown and active-task cold replacement, then Rust parity and exact published-tuple conformance before release/default activation. Preserve terminal cancel/terminate behavior, user-heartbeat timeout semantics and at-least-once external effects. Existing Python remote proof fences heartbeat and late publication after canonical delivery. It does not prove an owning Worker can supervise a blocked remote callback without user heartbeats, so carry that distinction into the next shared-contract review. |
Committed unshielded subtree replay is source-qualifiedPushed Local PHP 8.4 passes 1993 tests / 9733 assertions, zero errors/failures and The preceding blanket descendant-refusal test is deliberately replaced by an Ordinary CI Worker scope execution remains off, protocol 1.20 remains unfrozen/unpublished, |
Frozen descendant replay: hosted qualification passedPHP source
Worker scope execution remains OFF, candidate protocol 1.20 remains unfrozen/unpublished, and PR91 stays draft. The next step is live claim coordination and selective physical scoped supervision using the original delivery boundaries, request lineage and authority ceiling. The exact published PHP-parent/Python-child/Rust-remote/PHP-local cascade and unified inspection view remain closing requirements for #136. |
Pending scope boundary selection source candidatePushed PHP Local qualification passes 2014 tests / 9883 assertions, no errors/failures and the same forty opt-in skips. The new suite is 21 / 150. All 1993 preceding test identities and exact results are unchanged. All 108 original SDK dependency references, seven source files, unchanged Native-produced fixture hashes, static analysis, syntax and whitespace are independently verified. Removing ordering or the prepared-boundary termination check makes its regression fail. Exact restoration passes and precedes the final full suite. Ordinary CI and connected source qualification are queued at the exact head. Results remain pending. Local container and scratch were removed at 14:03:17 UTC, ahead of their 15:15 deadline. Worker scopes remain OFF. Candidate 1.20 is unfrozen/unpublished, PR91 draft and shared #136 open. Claim-bound preparation/delivery coordination, selective physical scoped supervision and the exact published cross-language cascade remain required. This source profile grants no callback execution authority. |
Pending scope boundary selection: hosted qualification passedAt PHP
The local task was removed at 14:03:17, before its 15:15 deadline. Worker scopes remain OFF, protocol1.20 unfrozen/unpublished, PR91 draft and shared136 open. Next: integrate claim-bound preparation/delivery coordination with selective physical scope supervision. The exact published cross-language cascade, unified inspection and competitive closing requirements remain. |
Source coordination qualified, scope execution remains disabledSDK PHP draft PR91 now contains The original monotonic budget is shared across mutation, reply-loss recovery Local full suite: 2030 / 9933, no errors/failures and the same 40 opt-in The task container and scratch were removed at 14:40:39 UTC, before their Next: qualify selective physical scoped supervision and live Worker |
Exact source head passes hosted qualificationSDK PHP Ordinary CI passes 31 gates and its expected connected skip. The Connected qualification passes all 32 gates, including hosted stack/image Five polling-sensitive cases vary by -1, +1, +1, -2 and +2 assertions as The new scope coordinator remains a source candidate. Worker scope execution |
Implements the PHP consumer and published demonstration for
shared cancellation #136.
Supported release boundary
Whole-run cooperative requests, immutable request context and inherited budget,
Activity/Child policies, supervised callback stop without application heartbeats,
stale fencing, shielded cleanup and canonical replacement replay. Ordinary
workers stay protocol 1.19. Cooperation opts into 1.20. Independently cancellable
scopes stay a disabled source preview. Local Abandon is refused before admission.
PHP process supervision requires pcntl/posix and callback-owned connections.
Verified
Connected source qualification
passes 50 cases / 2,789 assertions without failures, errors or skips. Memo restart
adds 1 / 67. The required PHP parent, Python child, Rust remote Activity and PHP
local Activity case passes 237 assertions. Both workflows complete cancellation
17.169470 seconds after the original request, before its unchanged 30-second
deadline. It asserts both physical stops, stale publication rejection, cleanup
SIGKILL/replay, duplicate identity/deadline and the shared API/CLI cascade.
Current head
f38babb2f21da38108fb1eaf512b1b11be539a63passes all ordinaryPHP 8.1–8.4, framework, package, docs, analysis and corpus gates. Later changes
prepare the RC onboarding identity and reuse the mixed case with registry SDKs,
the released CLI and an immutable Server digest. The runner rejects source
fallback and records actual installed package identities.
Publication
Publish PHP SDK 2.2.0-rc.1 for Server 2.5.0-rc.1 and run Published mixed
cancellation with the exact tuple. This PR does not close #136 or claim that
published qualification has already passed.