Fix workflow visibility closure and durable effect receipts - #323
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
This PR addresses a workflow-graph visibility regression and improves durability/observability of represented workflow execution by ensuring workflow children inherit the parent workflow’s exact visibility audience, and by emitting an intermediate durable-submission receipt so timeouts can preserve durable instance identity and recovery affordances.
Changes:
- Enforce and repair workflow child visibility closure: inherit parent visibility for newly created steps/mappings, and reject Workflow Studio publication when an existing authored child is narrower than the workflow root.
- Add an intermediate durable-effect receipt channel in the internal MCP transport and
workflow_execute, and normalise timeout outcomes into truthful “indeterminate” vs “partial (durable submitted)” receipts with recovery affordances. - Preserve durable workflow identity across adaptive-turn retries via stable same-turn idempotency keys, and project durable identifiers into Turn Execution Records.
Reviewed changes
Copilot reviewed 16 out of 16 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tests/test_migrate_jvnautosci_2591_arxiv_identity_workflow.py | Adds regression coverage for repairing the arXiv identity workflow child-visibility closure. |
| tests/backend/test_workflow_turn_capability_service.py | Extends receipt-normalisation tests to cover indeterminate timeouts and durable-submission timeouts. |
| tests/backend/test_workflow_studio_service.py | Adds a preflight test ensuring authored child concepts cannot be narrower than the workflow root’s audience. |
| tests/backend/test_workflow_concept_authority_service.py | Adds unit tests for parent/child visibility coverage and exact visibility inheritance on new children. |
| tests/backend/test_turn_execution_record_service_execution_summary.py | Verifies durable workflow identity is preserved in execution-summary projection for partial effects. |
| tests/backend/test_internal_mcp_workflow_tools.py | Adds coverage for outer timeout behaviour preserving durable instance receipts in workflow_execute. |
| tests/backend/test_internal_mcp_transport_deadlines.py | Validates write-timeout projections preserve an intermediate durable-effect receipt and redact unrelated fields. |
| tests/backend/test_adaptive_turn_service.py | Ensures represented workflow invocations carry stable event idempotency keys and that retries reuse the same durable instance. |
| src/backend/workflows/workflow_studio_service.py | Enhances Studio preflight checks to detect audience-narrower authored children (and refactors concept visibility helper). |
| src/backend/workflows/workflow_concept_authority_service.py | Implements parent/child visibility coverage checks and exact visibility inheritance for newly created steps/mappings. |
| src/backend/services/workflow_turn_capability_service.py | Refines workflow receipt normalisation to distinguish not-started vs indeterminate vs durable-submitted timeouts and set recovery affordances accordingly. |
| src/backend/services/turn_execution_record_service.py | Projects durable workflow identity fields into tool-invocation summaries. |
| src/backend/services/adaptive_turn_service.py | Derives stable same-turn workflow idempotency keys and propagates durable receipt identifiers into tool evidence/invocations. |
| src/backend/integrations/internal_mcp/transport.py | Adds an intermediate effect-receipt recording channel and uses it to produce truthful timeout receipts after durable submission. |
| src/backend/integrations/internal_mcp/catalogue.py | Emits an intermediate durable-submission receipt from workflow_execute immediately after instance creation/submission. |
| scripts/migrate_jvnautosci_2591_arxiv_identity_workflow.py | Adds a visibility-closure repair step and cross-actor graph closure verification to the JVNAUTOSCI-2591 migration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
workflow_executebefore terminal waitingRoot cause
The represented scholarly metadata workflow was global, but its newly created
ensure_arxiv_paper_conceptstep and two mappings inherited the publishing actor's user-only visibility. Other actors therefore loaded an incomplete 21-state graph and failed at the transition. Separately,workflow_executecreated a durable instance inside a bounded handler but exposed no intermediate identity before waiting; an outer timeout was later normalised asnot_starteddespite the persisted instance.Impact
Actors who can see the workflow can now load its complete child graph. A workflow that has already submitted durably but outlives the turn deadline is reported as
partialwith its instance ID and inspection recovery, while no-receipt handler timeouts remain indeterminate and queued/pre-dispatch denials remainnot_started.Validation
/health: healthy on this branch (agent_test_instance=true)git diff --check: cleanA broader mixed workflow-tool suite reached 27 passes, then stalled in a live Atlas SSL read and was interrupted after 288 seconds; the exact affected tests pass in isolation.