Problem
The stable service-mode POST /workflows/{id}/cancel route calls Workflow's terminal attemptCancel() and immediately closes the run, cancels open tasks/timers, and revokes leases. It is not the separate cooperative request path shipped for embedded Laravel in workflow#483 / Workflow 2.2.0. A real-Server Python integration case in sdk-python#69 confirms that an in-flight local activity's next heartbeat loses the lease and no local completion is committed.
Published Python/Rust SDK docstrings and the language-neutral docs call cancel_workflow cooperative/graceful and imply workflow cleanup runs. That claim is false for the current service-mode route and could cause customers to skip external cleanup or reconciliation.
Immediate correction
- Audit the PHP, Python, Rust SDK guides/API docs and main service-mode docs. State plainly that current
cancel is terminal; terminate is also terminal with a distinct outcome/reason. Neither guarantees workflow-code finally cleanup. Do not change stable endpoint semantics under a documentation fix.
- Preserve the accurate embedded-Laravel cooperative-request guidance and clearly label its deployment mode.
- Verify rendered/public guidance after publication with focused link/content checks. Do not turn this into a site-wide screenshot pass.
Additive parity work
- Design a separate service-mode cooperative cancellation request using the already shipped Workflow engine primitive without repurposing
/cancel. Expose the request/observable pending state in Server and PHP/Python/Rust SDKs only after one shared protocol/conformance contract is qualified.
- Cover request-before/after task claim, waiting runs, bounded cleanup, duplicate requests, worker loss/replay, termination during cleanup, SDK task
cancel_requested delivery, and local/remote activity fencing. External effects remain at-least-once and need idempotency/reconciliation.
- Publish capability claims only after exact published Server + SDK artifacts pass cross-language conformance. Keep terminal cancel behavior and compatibility intact.
This is a confirmed product/docs contract gap, not a request to reopen the completed embedded feature. Own the immediate correction first; the additive protocol work follows current accepted release commitments. No private Cloud or customer data belongs here.
Problem
The stable service-mode
POST /workflows/{id}/cancelroute calls Workflow's terminalattemptCancel()and immediately closes the run, cancels open tasks/timers, and revokes leases. It is not the separate cooperative request path shipped for embedded Laravel in workflow#483 / Workflow 2.2.0. A real-Server Python integration case in sdk-python#69 confirms that an in-flight local activity's next heartbeat loses the lease and no local completion is committed.Published Python/Rust SDK docstrings and the language-neutral docs call
cancel_workflowcooperative/graceful and imply workflow cleanup runs. That claim is false for the current service-mode route and could cause customers to skip external cleanup or reconciliation.Immediate correction
cancelis terminal;terminateis also terminal with a distinct outcome/reason. Neither guarantees workflow-codefinallycleanup. Do not change stable endpoint semantics under a documentation fix.Additive parity work
/cancel. Expose the request/observable pending state in Server and PHP/Python/Rust SDKs only after one shared protocol/conformance contract is qualified.cancel_requesteddelivery, and local/remote activity fencing. External effects remain at-least-once and need idempotency/reconciliation.This is a confirmed product/docs contract gap, not a request to reopen the completed embedded feature. Own the immediate correction first; the additive protocol work follows current accepted release commitments. No private Cloud or customer data belongs here.