Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Backport #2191: fix forwarded stream encryption across deployments - #2202

Merged
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable
Jun 1, 2026
Merged

Backport #2191: fix forwarded stream encryption across deployments#2202
TooTallNate merged 1 commit into
stablefrom
pranaygp/codex/backport-pr-2191-to-stable

Conversation

@pranaygp

@pranaygppranaygp commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Why this needed manual resolution

The automated #2191 backport failed with conflicts (comment, run). PR #2070 has now merged the direct forwarded-stream path into stable, so this PR has been rebased to contain only the targeted encryption fix.

The remaining conflict resolution is specific to the stable layout: step execution remains in packages/core/src/runtime/step-handler.ts, and SerializableSpecial remains inline in packages/core/src/serialization.ts rather than bringing over main-only split modules.

Validation

  • git diff --check origin-https/stable...HEAD
  • fnm exec --using=22.22.0 -- pnpm turbo build --filter=@workflow/core --filter=@workflow/world
  • fnm exec --using=22.22.0 -- pnpm --filter @workflow/core test (645 tests passed)

Note: the local shell defaults to unsupported Node v25.2.1, where the untouched src/vm/uint8array-base64.test.ts reports cross-realm error-constructor assertion failures. The full suite passes on supported Node v22.22.0.

@vercel

vercelBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@changeset-bot

changeset-botBot commented Jun 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0c7c38c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@workflow/corePatch
@workflow/worldPatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
workflowPatch
@workflow/world-testingPatch
@workflow/world-localPatch
@workflow/world-postgresPatch
@workflow/world-vercelPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production923067990
✅ 💻 Local Development9940861080
✅ 📦 Local Production9940861080
✅ 🐘 Local Postgres9940861080
✅ 🪟 Windows900090
❌ 🌍 Community Worlds136920228
✅ 📋 Other504036540
Total4635923615088

❌ Failed Tests

🌍 Community Worlds (92 failed)

mongodb (14 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

redis (9 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (68 failed):

  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • addTenWorkflow | wrun_01KT29SAM4118M5DYGQ8H9DCWG
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KT29V85JFJF5N0FM87PM07BB
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KT29SHVP561X58HE7QV1N251
  • promiseRaceWorkflow | wrun_01KT29SP4F7EWVHR2FJ2RP0Y8X
  • promiseAnyWorkflow | wrun_01KT29SS89N635CVP53EAG66YR
  • importedStepOnlyWorkflow | wrun_01KT29VK81Y3P6NVRK0GXH2H24
  • readableStreamWorkflow | wrun_01KT29SX0P7H49KRATKNDVK081
  • hookWorkflow | wrun_01KT29T9G0CWPZZJ2VM76H3CZF
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KT29THGHBKBQXRTWFWNJGFZT
  • webhookWorkflow | wrun_01KT29TNN3MBMZ7G9CPRS9CZ1B
  • sleepingWorkflow | wrun_01KT29TVZFQ2YXWQH6Q786F6TX
  • parallelSleepWorkflow | wrun_01KT29VAZ20R6GBGCDJQ7QWGPY
  • nullByteWorkflow | wrun_01KT29VF1PQSHG27SCXCF6SATR
  • workflowAndStepMetadataWorkflow | wrun_01KT29VGWQT7XJMPN6SMNGYT4W
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KT29Y6MZRBNKD82QYC6ARW04
  • writableForwardedFromWorkflowWorkflow | wrun_01KT29YPECQCFGRZ9VHEC3TY9R
  • writableForwardedFromStepWorkflow | wrun_01KT29YTTM020TDJKRY29W86D2
  • fetchWorkflow | wrun_01KT29YY2VQYN21JWZW4J2HH7E
  • promiseRaceStressTestWorkflow | wrun_01KT29Z0ZZJXXGMFETTAVGR4G1
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KT2A281JNDTQHH4DRZ7PECDW
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KT2A2KTBH0MMN7SHTJ8P9XRK
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KT2A31GJBZ42WXRHABP03D1R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KT2A3FYFVVGNFG9GFSMCJSPR
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KT2A3RWCX7MHS7D7QXRXRAPY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KT2A405KVYZ2ZJAHWD10GRK5
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KT2A41ZKN1QNA3D86XY2MS6J
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KT2A4FF03EAFQ8YVD7Q6NZB8
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KT2A4PR5798PHP8WYMACAAJN
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KT2A4WP52SGVZVVM738HGQ8A
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KT2A52MTCDPNRNPR9B90FVYV
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KT2A5962Y5R02MF3V36SDK11
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KT2A5F1S8HWSZZ8D3X6MQBEV
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KT2A5P53V8GCTMTTBMH4H2SX
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KT2A62JZP836XXD111M4NWFH
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KT2A6ASBA183658DAXYQBWMC
  • cancelRun - cancelling a running workflow | wrun_01KT2A6JGCTEQNA4C93JXJJ77M
  • cancelRun via CLI - cancelling a running workflow | wrun_01KT2A6VF24109EXCGYP1M13W8
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KT2A76J9SK62H4YQF2EY2X7Q
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KT2A7NQV4C3YN70E8YMB8M3Q
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KT2A7ZPJJTXJFGVWDY24MHMY
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KT2A873VJP2517Z2XT41H5W0
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KT2A88YAQEY7XWYANPVD32GP
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KT2A8BKXT2K0T0T8P39YAG14

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8307
✅ example8307
✅ express8307
✅ fastify8307
✅ hono8307
✅ nextjs-turbopack8802
✅ nextjs-webpack8802
✅ nitro8307
✅ nuxt8307
✅ sveltekit8307
✅ vite8307
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8406
✅ express-stable8406
✅ fastify-stable8406
✅ hono-stable8406
✅ nextjs-turbopack-canary71019
✅ nextjs-turbopack-stable9000
✅ nextjs-webpack-canary71019
✅ nextjs-webpack-stable9000
✅ nitro-stable8406
✅ nuxt-stable8406
✅ sveltekit-stable8406
✅ vite-stable8406
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack9000
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev500
❌ mongodb57140
✅ redis-dev500
❌ redis6290
❌ turso-dev410
❌ turso3680
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8406
✅ e2e-local-dev-tanstack-start-stable8406
✅ e2e-local-postgres-nest-stable8406
✅ e2e-local-postgres-tanstack-start-stable8406
✅ e2e-local-prod-nest-stable8406
✅ e2e-local-prod-tanstack-start-stable8406

📋 View full workflow run


⚠️Community world tests failed (non-blocking):

  • Community Worlds: failure

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports PR #2191 to stable, fixing forwarded writable stream encryption when a child workflow runs on a newer deployment than its parent. The fix stamps the owning deployment ID onto forwarded writable descriptors so the child can resolve the parent run's encryption key via getEncryptionKeyForRun(runId, { deploymentId }), with a fallback path that loads the owning run for legacy descriptors.

Changes:

  • Adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL and threads workflowDeploymentId through StepContext, getWritable, serialization reducers/revivers, and hydrateStepArguments.
  • Routes forwarded writable key resolution through a new getForwardedWritableEncryptionKey helper that prefers { deploymentId } context and falls back to world.runs.get(runId).
  • Adds regression tests for both new and legacy descriptor paths plus a changeset.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/core/src/symbols.tsAdds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL.
packages/core/src/step/context-storage.tsAdds optional workflowDeploymentId to StepContext.
packages/core/src/step/writable-stream.tsStamps the deployment ID on the writable when available.
packages/core/src/step/writable-stream.test.tsVerifies the deployment-ID stamping.
packages/core/src/serialization.tsCarries deploymentId through descriptors; centralizes forwarded key resolution; threads it through step revivers and hydrateStepArguments.
packages/core/src/serialization.test.tsCovers new descriptor key lookup and legacy fallback via runs.get.
packages/core/src/runtime/step-handler.tsPasses VERCEL_DEPLOYMENT_ID into hydration and step context.
packages/world/src/interfaces.tsDocuments expanded usage of getEncryptionKeyForRun for forwarded streams.
.changeset/cross-deployment-stream-keys.mdPatch changeset for @workflow/core and @workflow/world.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNateTooTallNate left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — faithful backport with appropriate stable-shape adaptations

I approved the original #2191 last week. This is the manual backport now that #2070 has landed on stable (which provided the prerequisite forwarded-stream plumbing). Comparing file-by-file:

Byte-identical to original

  • changeset — identical
  • packages/core/src/symbols.ts — adds STREAM_SERVER_DEPLOYMENT_ID_SYMBOL identically
  • packages/core/src/step/writable-stream.ts — adds the symbol-stamping block identically
  • packages/core/src/step/context-storage.ts — adds workflowDeploymentId?: string identically
  • packages/world/src/interfaces.ts — same JSDoc tweak on getEncryptionKeyForRun

Justified stable-shape adaptations (all flagged in PR body)

  1. SerializableSpecial['WritableStream'] inline in serialization.ts: stable doesn't have the serialization/types.ts split that main does (a main-only refactor). The deploymentId?: string field is correctly added to the inline declaration with the same JSDoc.

  2. getWorld() (sync) vs getWorldLazy() (async): stable still uses the sync version. The new getForwardedWritableEncryptionKey helper correctly uses getWorld() for stable.

  3. getStreamAndRequestRevivers(getStepRevivers(...)) wrapper missing on stable: another main-only refactor. The backport correctly threads deploymentId through getStepRevivers directly without the wrapper.

  4. Test fixture differences: stable doesn't have makeStepCtx() / makeMockWorld() helpers (those are main-only). Tests inline the equivalent construction. Assertions are functionally identical.

  5. Omitted files: runtime.ts and step-executor.ts (V2 runtime, main-only) and serialization/types.ts (main-only split) are correctly absent from the backport.

What I verified locally

  • pnpm install --frozen-lockfile
  • pnpm turbo run build --filter @workflow/core
  • pnpm --filter @workflow/core test src/serialization.test.ts src/step/writable-stream.test.ts ✓ (125 passing — 122 serialization + 3 writable-stream)
  • All three new tests pass specifically:
    • uses the forwarded stream deployment to resolve its encryption key
    • loads the owner run for forwarded descriptors from older deployments
    • tags a writable with its owning deployment for child workflow forwarding

CI noise

5 failures, all pre-existing on stable or infrastructure:

  • E2E Community World (Turso / MongoDB / Redis)same 3 tests fail on stable's latest baseline run (26776100981), so pre-existing
  • E2E Vercel Prod Tests (astro) — single workflow run flake (wrun_01KT29TFQKXARPV5DNYXDNB786 failed on Vercel infra)
  • E2E Required Check — cascading from astro

None are caused by this PR.

Carry-over concern from the original

The step-handler.ts change sources workflowDeploymentId from process.env.VERCEL_DEPLOYMENT_ID (current runtime deployment), not the workflow's actual deployment. I flagged this on #2191 and the same analysis applies here: it's consistent with how step encryption already resolves keys on stable (also assumes current-deployment), so it doesn't make any existing behavior worse, but doesn't fix it either. The parent/child cross-deployment case (the PR's actual scope) is handled correctly because forwarded writables carry their deployment ID explicitly.

Backport stance

Faithful backport. Ready to merge once it comes out of draft.

@TooTallNate
TooTallNate enabled auto-merge (squash) June 1, 2026 19:56
@TooTallNate
TooTallNate merged commit 5a0ce9a into stableJun 1, 2026
155 of 163 checks passed
@TooTallNate
TooTallNate deleted the pranaygp/codex/backport-pr-2191-to-stable branch June 1, 2026 20:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pranaygp@TooTallNate