fix: renew workflow heartbeats under the ownership fence - #294
Conversation
Heartbeat ownership interleaving reproduced and fixed at sourceThe ordinary protocol 1.19 regression fails against unchanged main Observed baseline: {"heartbeat":{"workflow_task_attempt":1,"lease_owner":"original","renewed":true},"replacement_claim":{"workflow_task_attempt":2,"lease_owner":"replacement"}}The same Native task ID was present in both responses. The positive heartbeat therefore identified a claim that no longer owned the task. The fix in #294 head Cooperative cancellation draft #291 carries the same locked renewal, plus the pending observation read inside that transaction, at Normal CI is running for both heads. This source result does not claim a published image or Cloud deployment. Next finish exact-head CI/review, publish Server 2.4.36/Helm 0.1.132 independently of cooperative cancellation and verify the affected published worker cells. Rust coordinator qualification then uses the requalified #291 head. Default protocol 1.19 and ordinary capabilities remain unchanged. |
Published Server 2.4.35 reproduces the ownership defectThe same committed regression ran inside the unchanged published Server image The two actual HTTP kernels reproduce: {"heartbeat_status":200,"heartbeat":{"workflow_task_attempt":1,"lease_owner":"original","renewed":true,"reason":null},"replacement_claim":{"workflow_task_attempt":2,"lease_owner":"replacement"}}Both responses identify the same actual Native task. The unchanged published image therefore fails the ownership assertion, with 16 assertions reached. SQLite clocks and an IPC barrier control the interleaving; the harness does not edit any lease, owner or attempt row. The original full CI result exposed an overly strict test assertion, not a valid positive acknowledgment. PHP 8.3 uses deferred SQLite transactions even when Next complete revised-head CI and review, publish Server 2.4.36, repeat this exact-image regression and verify the published PHP/Python/Rust lifecycle tuple before closing #293. |
|
The revised regression passes in the actual PHP 8.3.35 runtime with only the fixed controller supplied from source head 8840d6d: one case, 21 assertions. This exercises the valid stale-owner refusal under deferred SQLite transactions. PHP 8.5 local source also passes the writer-lock renewal outcome. The unchanged published image still fails with a positive old-owner acknowledgment after an actual attempt-2 replacement. Normal exact-head CI is running. No new published-image pass is claimed before publication. |
|
Reviewed exact source 8840d6d against main d0692b1. The runtime change is the namespace-scoped lock plus ownership validation and Native renewal in one retryable transaction, preserving existing refusal and pressure responses. The two test files exercise actual claims and both valid race outcomes. The remaining changes synchronize the single source release record to Server 2.4.36 and Helm 0.1.132, with no dependency version changes. Full feature CI 36866148513 passes 2,253 cases and 47,227 assertions, along with protocol/corpus checks. MySQL/Postgres rolling-upgrade checks, replay/query HTTP topology, chart lint/install and public boundary checks pass. Final polling qualification is still running. After it passes, merge this reviewed head, publish the immutable release and verify the exact image and published worker tuple before closing #293. |
|
Delivered in Server 2.4.36 through merged #294 at
The qualification report and raw before/after evidence with reproduction tooling are release assets. Both were downloaded again and their SHA-256 hashes matched the uploaded originals. The evidence archive hash is Default protocol remains 1.19. No SDK release or database migration is required. Helm's immutable default is updated. Inspection found no affected public consumer pinned to the preceding Server 2.4.35 image that requires a separate update. Cloud deployment qualification remains separately owned. The merged remote branch was deleted and verified absent. The fix is also carried into cancellation draft #291 at |
Customer outcome
Addresses #293. A heartbeat renews only the actual workflow task owner and attempt. Concurrent Native lease replacement cannot make an old worker receive a positive acknowledgment for the new lease.
Lock the namespace-scoped task, validate ownership and worker freshness, and renew inside one transaction. Keep current response fields, refusal reasons, pressure retries, protocol 1.19 and capabilities.
The regression uses two actual HTTP kernels with separate SQLite connections. An IPC barrier pauses before published Native renewal after the original ownership check. Both clocks cross the one-second lease expiry, allowing a replacement worker to attempt an actual Native claim. It does not edit the task lease, owner or attempt. Positive acknowledgment must match the durable claim. If replacement wins, the old heartbeat must instead refuse without renewing the replacement lease.
Qualification
d0692b171a0cabe6eefdc8bfc0f82d249e16128d, Native Workflow 2.3.1: regression fails. Original heartbeat returns renewed=true under attempt 1 while the replacement actually owns attempt 2.Required before delivery
8840d6ddb73df0a78a83e748e38cd3688897d90e. Full feature CI passes 2,253 cases and 47,227 assertions, and all protocol/corpus, polling, replay/query, MySQL/Postgres upgrade, chart installation and boundary gates pass.898c51375ddcb2c25588eb63e41fed26a3fd61b2. Protected image/chart release run36868020232passes. Server 2.4.36 image index issha256:74cdf7feae85052151de905d877a2e1ba5fcbfabf9ef50f3a8aab7c285685204, with both architectures verified. Helm 0.1.132 anonymous installation passes.36868798600passes all 12 required cells with no findings or unproven cells. The report and raw comparison evidence are attached to the Server 2.4.36 release and recorded in Fence workflow heartbeats against concurrent lease replacement #293.24b54c9f8b3f84cad93ec58d5d7cd2f95160458d. Local focused qualification passes 25 cases and 565 assertions. Remaining draft CI and coordinator qualification stay owned by feat: add cooperative cancellation requests and claim-bound delivery #291 and the cancellation issue.Rollback is the preceding immutable Server image and chart. No database migration or protocol change is introduced. Cloud deployment remains its own private qualification decision.