Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Backport #2030: [codex] Guard event consumers during replay - #2042

Merged
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable
May 20, 2026
Merged

Backport #2030: [codex] Guard event consumers during replay#2042
pranaygp merged 1 commit into
stablefrom
backport/pr-2030-to-stable

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Manual backport of #2030 (cherry-pick b124365) to stable.

Conflict resolution notes:

  • Preserved the stable runtime/step-handler shape while adding replay guard metadata for step, wait, and hook events.
  • Kept files that do not exist on stable deleted instead of reviving main-only runtime splits.

Validation:

  • pnpm --filter @workflow/errors --filter @workflow/utils --filter @workflow/serde --filter @workflow/world --filter @workflow/world-local --filter @workflow/world-vercel build
  • pnpm --filter @workflow/core exec vitest run src/workflow/sleep.test.ts src/workflow/hook.test.ts src/step.test.ts src/runtime.test.ts src/runtime/runs.test.ts
  • pnpm --filter @workflow/core typecheck
  • pnpm --filter @workflow/core build
  • pnpm changeset status --since=main -> no changeset needed
  • git diff --check HEAD~1 HEAD

Note: local checks were run with Node v25.2.1, which emits the repo engine warning (^18 || ^20 || ^22 || ^24).

@pranaygp
pranaygp requested a review from a team as a code ownerMay 20, 2026 20:15
CopilotAI review requested due to automatic review settings May 20, 2026 20:15
@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ff812fa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented May 20, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production901067968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4406693614836

❌ Failed Tests

🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • addTenWorkflow | wrun_01KS3H5MJ017HHBQE9QXP7N29G
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS3H6D6BDW292RY6W2Z5P9T3
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS3H5VZYZ79XMCS31S3WRVJE
  • promiseRaceWorkflow | wrun_01KS3H60YAG6MRFMBT7BCX99RC
  • promiseAnyWorkflow | wrun_01KS3H639JQCJ6WFXZWZMSQVN8
  • importedStepOnlyWorkflow | wrun_01KS3H6SSQE3256QEDX750502Y
  • readableStreamWorkflow | wrun_01KS3H65QK2J6Y3FFVZFC3HP3T
  • hookWorkflow | wrun_01KS3H6R9ANESS6QVCG9ZNT8F9
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS3H71WDE12N3DPBXMBTDFPH
  • webhookWorkflow | wrun_01KS3H76GX67DH1RYMJ4TA8110
  • sleepingWorkflow | wrun_01KS3H7DKG1K90ESYD2AQM0HTV
  • parallelSleepWorkflow | wrun_01KS3H7YG12M10GHGHA4KDYFA6
  • nullByteWorkflow | wrun_01KS3H82GSTM2NNQY432S2STJ1
  • workflowAndStepMetadataWorkflow | wrun_01KS3H8566V1JQDS40H0W2V3T3
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS3HAMZC3FDSE8S7TZWHSMB7
  • fetchWorkflow | wrun_01KS3HB4AXC8RE5K0H04RTY979
  • promiseRaceStressTestWorkflow | wrun_01KS3HB87RW1XKSFY4FSF4EDVN
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS3HETDZHD25VFWSEMN010B1
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS3HF8FJ226RSYNQ3TF8C5ZS
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS3HFS85G0FC63VWYMQ1WQXC
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS3HGAQWAHR3XA0TY54MVCZ5
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS3HGMA6T5BC2NRPPN07XPWZ
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS3HGTJEGT5BKBBA34PBAKGB
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS3HGWZGFJ5W17M8S9PV5Z1H
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS3HHDXAGMMNW5G0EZGAX2WV
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS3HHM3BQX4J0ZX9GSY0Q90C
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS3HHW2KPZ7CZG5KPVFE51AH
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS3HJ3MV6MA78C9HP78JW4HY
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS3HJB3KKRXG961YRRDMP0AG
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS3HJJXKC3P34MSQMQPXSR98
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS3HJTPYGFDN0YXKWN43MX0H
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS3HK86ZD92WHX1FV9D5B34Q
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS3HKGZB9RT8W9TBDHVQHY6S
  • cancelRun - cancelling a running workflow | wrun_01KS3HKRPFQSFG5K6CVXRJ578R
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS3HM2EFZC23679YGNJFD1YH
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS3HMFRW7WZR40XGSF6WP895
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS3HN19NAKWFAXHWJFAPCYR2
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS3HNC76SFYHGYQT9Y1F7WQA
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS3HNMX0QB3PDBWAXC5BFAVC
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS3HNQCANM4C4JNCJ2W0X1HP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS3HNSS3KHX5R409VYRE620Q

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
✅ nextjs-webpack8602
✅ nitro8107
✅ nuxt8107
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports #2030 to stable by adding replay-time “ownership” guards for step, wait, and hook lifecycle events. This helps the runtime detect corrupted/mismatched event logs during replay (so consumers don’t resolve solely by correlationId when guard metadata is present) and fail deterministically.

Changes:

  • Extend event schemas to persist optional guard metadata (stepName, wait resumeAt, hook token) on relevant events.
  • Add replay-time validation in step/sleep/hook consumers to raise WorkflowRuntimeError on guard mismatches.
  • Update runtime emitters to include guard metadata on newly-created events and add focused unit + runtime-entrypoint tests.

Reviewed changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
packages/world/src/events.tsAdds optional guard fields to step/hook/wait event schemas so metadata can be stored and preserved under resolveData: 'none'.
packages/core/src/workflow/sleep.tsValidates wait_completed.eventData.resumeAt against the expected wait during replay.
packages/core/src/workflow/sleep.test.tsUpdates existing wait tests and adds coverage for missing/invalid/mismatched resumeAt.
packages/core/src/workflow/hook.tsValidates hook event token ownership during replay.
packages/core/src/workflow/hook.test.tsUpdates fixtures to include tokens and adds mismatch coverage for multiple hook event types.
packages/core/src/step.tsValidates step event stepName ownership during replay.
packages/core/src/step.test.tsAdds mismatch coverage for step event stepName.
packages/core/src/runtime/suspension-handler.tsIncludes hook disposal token in emitted hook_disposed events.
packages/core/src/runtime/step-handler.tsIncludes stepName in emitted step lifecycle events (and refactors queue-derived name extraction).
packages/core/src/runtime/runs.tsIncludes resumeAt when emitting wait_completed for wake-up flows (non-legacy).
packages/core/src/runtime/runs.test.tsUpdates expectations to include resumeAt on wait_completed.
packages/core/src/runtime/resume-hook.tsIncludes hook token in hook_received when not in v1 compatibility mode.
packages/core/src/runtime.tsIncludes resumeAt when auto-completing elapsed waits during replay.
packages/core/src/runtime.test.tsAdds runtime-entrypoint coverage for guard mismatches producing run_failed with RUNTIME_ERROR.
.changeset/guard-step-consumer-events.mdAdds a changeset for the backported behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +6
---
'@workflow/core': patch
'@workflow/world': patch
---

Validate step, wait, and hook lifecycle events against replay ownership metadata.
} = StepInvokePayloadSchema.parse(message_);
const { requestId } = metadata;
const stepNameFromQueue = metadata.queueName.slice('__wkf_step_'.length);

* Guard event consumers during replay
* Address event guard review feedback
* Update event guard test fixtures
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pranaygp