Skip to content

[Task] Preserve atomic BPMN edits in Mongo workflow definitions #8294

Description

@sfmskywalker

Accepted on main — 2026-10-08

Final acceptance verifies the required scope on main 179749636fd4ddce07b186d4fe3456a43fa91162. This issue is closed; earlier checkpoints below retain their historical status and limitations. Parent #8214 and program #8194 remain open for their own outcomes.

Program: #8194
Parent: #8286
Related: #8287

Deliverable

Implement atomic latest-definition compare-and-swap in the MongoDB persistence provider so BPMN document PUT has a real single-row concurrency guard and transactional published-to-draft transition.

Acceptance

  • Match the supplied predicate against the latest row in the tenant scope selected by filter.TenantAgnostic, then derive the update from that loaded snapshot.
  • Same-ID updates use an atomic conditional replace/update against the loaded snapshot, including persisted metadata, with explicit collation behavior where required; require exactly one matched row.
  • Published-to-draft updates conditionally unmark the prior latest row and insert the new draft in a Mongo session transaction on a replica set. Standalone Mongo must fail or be excluded explicitly rather than silently weakening atomicity.
  • Preserve the selected row tenant ID on mutation and do not broaden tenant visibility or overwrite it from ambient state.
  • Add replica-set integration coverage for winner/loser, stale metadata, not-found, tenant isolation, and published-to-draft rollback/conflict. Record any unavailable environment as unverified.
  • Do not publish packages or import upstream publisher workflows.

Scope boundary

This task implements and verifies the MongoDB provider path only. It does not claim every distributed persistence provider is concurrency-safe.

Corrective readiness checkpoint (2026-10-07)

Reopened after lead and independent final-layout audit. The historical preparation and its 12-case replica-set receipt remain valid for their recorded rehearsal source only. At that reopening checkpoint, imported TryUpdateLatestAsync unmarked and inserted outside a transaction, and its selected-field CAS filter omitted persisted metadata. The then-current import's six CAS cases were not the reviewed replica-set suite. The accepted #8654 correction below supersedes those source defects. No matching open corrective PR was found in fresh Core and Extensions intake.

The correction is merged through PR #8654 into the program branch at eccc39fe15d2e525af866bd5a2e59f12821de381, with tree equal to reviewed ce99df5c48de6ae3f5086572bbe48956669fdbf1. All exact-head CI, independent source/runtime APPROVE + HIGH and Greptile 5/5 passed. Focused proof passed 103 Mongo and ten BPMN cases with zero skips, both intended baseline regressions, three fixture compiles, three framework builds and actual write-filter/topology/image guards.

This Task remains OPEN, Todo / Not Ready / Verification Pending, because native sibling blocker #8655 owns final integration and exact-main verification. The program-branch merge does not close this Task or its reopened parent rollups. #8655 is now the sole active delivery Task. No publication or deployment occurred.

Implementation boundary

  • Forward-port the reviewed session-aware MongoDbStore read overload and atomic TryUpdateLatestAsync implementation; share current tenant-visibility logic. Session reads must still include visible global * rows and preserve tenant-agnostic/default-empty behavior. Do not reuse strict tenant write scoping as read visibility.
  • Use a session transaction with snapshot reads, primary reads and majority writes from the collection's owning client. Match the full raw BSON snapshot with simple collation and require exactly one matched write. Unmark the published row and insert its draft in one transaction, preserving the selected TenantId and logical-definition identity. Keep current new-draft IsLatest=true behavior and public constructor/interface signatures.
  • Preserve later tenant-owned upserts/default normalization (c405a11bf3a39700b8afaaf534f4421ac83346c2) and strict update-scope/serializer/key-value fixes (db59d7d1df0d398cfc699d66c3059851c9393c72). Do not mix unrelated Mongo cleanup.
  • No callback or transaction retries. Propagate callback failures and ambiguous commit failures; classify only the reviewed known write-conflict error as Conflict. A standalone deployment must fail explicitly without weakening atomicity.
  • Extend the existing CAS fixture and current evidence documentation; retain historical receipts unchanged.

Required exact-head proof

Use hosted Linux Docker and the repository's centrally resolved dependencies. Record MongoDB image identity/digest and verify replica set rs1. No heavy local workload while the host remains overloaded.

  • Demonstrate omitted-metadata and draft-insertion rollback regressions fail against the unfixed baseline, then pass on the corrected source.
  • Cover existing NotFound/false-predicate/no-longer-latest behavior, callbacks once, barrier-synchronized competing writers with one winner, stale StringData/Name/previously omitted metadata, narrow error classification, predicate/update callback errors, tenant visibility and tenant-agnostic owner preservation, logical identity rejection, and unknown BSON fields under the default class map.
  • Verify published-to-draft success changes only the prior row's IsLatest and insertion failure rolls that write back. Verify standalone failure leaves state unchanged.
  • Run the complete Elsa.MongoDb.UnitTests project on net10 with per-case evidence and zero skips, including later tenant/serializer/key-value regressions. Run BpmnDocumentPutCompareAndSwapTests from Elsa.Bpmn.Interchange.IntegrationTests as separate consumer-contract evidence.
  • Compile both fixtures first and build Mongo production for net8.0/net9.0/net10.0; retain the broader consolidated build gate. Record exact source/inputs, sanitized receipts and all failures/skips accurately.
  • Require lead review, independent Elsa 3 APPROVE + HIGH, Greptile 5/5 and repository exact-head CI before merging to codex/elsa-integration-program. Reconcile the final main integration requirement explicitly before closing this task and its reopened parent rollups.

No package publication, production database migration or source-publisher cutover is authorized by this correction.

Active final-main verification

#8655 is now the sole active delivery Task in PR #8657, head 0da8146aaeaf35cb06feb1a7c87920cf3bb3df20, base main b38e7523f79297076e51701fd951c426145aa99c. Accepted #8654 is contained in this promotion. This Mongo Task remains open and inactive until combined-head and post-merge exact-main proof are accepted; program-slice acceptance is not final-main acceptance.

Activity

  1. added
    elsa 3This issue is specific to Elsa 3
    enhancementNew feature or request
    prio highIs on the roadmap for the near-future
    on Sep 23, 2026
  2. sfmskywalker commented on Sep 23, 2026

    @sfmskywalker
    MemberAuthor

    Preparation PR #8304 merged as d3feb19b780c3534c27ea0435574e02ccb995798 after current-head checks and 5/5 review. Root independently replayed all 12 Mongo tests at reviewed 4a24f416b8f082922ad78538594700674f02cf04 and rebuilt the complete combined solution successfully (0 errors, 1,556 warnings; retained in #8306). The task remains open until actual history-preserving source integration and final-layout conformance. No package publication or cutover occurred.

  3. sfmskywalker commented on Oct 7, 2026

    @sfmskywalker
    MemberAuthor

    Reopened after a lead and independent acceptance audit found the final imported implementation does not satisfy this Task.

    The preparation PR #8304 and its retained replica-set proof explicitly required final-layout integration before closure. The later #8409 run did execute the Mongo project (42 passed, zero skipped), but its CAS fixture contains six standalone cases, not the reviewed replica-set concurrency/rollback suite.

    More importantly, the current imported src/extensions/persistence/Elsa.Persistence.MongoDb/Modules/Management/WorkflowDefinitionStore.cs still performs published-to-draft UpdateOneAsync followed by InsertOneAsync outside a transaction. Insertion failure can therefore leave the prior row unmarked. The same-row conditional filter checks selected fields instead of the reviewed full persisted snapshot. The approved transaction implementation remains only in the preparation patch scripts/integration-program/consolidated-build/mongo-atomic-updates.patch.

    #8294 is now queued Todo / Not Ready / verification Pending while a bounded source/PR readiness audit checks how to restore the reviewed behavior without losing later tenant fixes. This is not a second active implementation: #8651 remains the sole active Task. This data-integrity correction will precede the queued Studio hover task #8653 once ready. No source PR, package publisher or production database was changed.

  4. sfmskywalker commented on Oct 7, 2026

    @sfmskywalker
    MemberAuthor

    Activated #8294 as the sole delivery Task after #8651 was accepted through merged #8652 (23b852ad6262c4bf07b9f311090c892dbecd740b). Refreshed native dependencies: no blockers. Source/PR readiness audit found no matching open fix to adopt. Board: In Progress / Assigned / verification Pending.

    Sol 6.1 owns the bounded source/test forward-port in an isolated worktree from that program head; the lead owns hosted verification, integration and QA. Hosted proof will require the omitted-metadata and insertion-rollback regressions to fail behaviorally against unfixed source before accepting the corrected full replica-set suite. Later tenant fixes and historical receipts are preserved. #8653 stays ready and queued.

  5. sfmskywalker commented on Oct 7, 2026

    @sfmskywalker
    MemberAuthor

    Merged into the program branch: eccc39fe15d2e525af866bd5a2e59f12821de381, 2026-10-07T21:48:30Z. Its parents are accepted program 23b852ad6262c4bf07b9f311090c892dbecd740b and reviewed ce99df5c48de6ae3f5086572bbe48956669fdbf1; lead verified the merge tree exactly equals reviewed tree b0fcb352747f7dbedd7d322ee9d2e0b0271612d5.

    Before merge, all five exact-head workflow runs succeeded: Packages 37688811905 (including package build), Mongo proof 37688819358, integration-program tools 37688819520, package impact 37688819377, and imported-source selection 37688819453. Broad logs report 4,870 unit/integration passes with 144 skips, plus 226 component passes with one skip. Those skips are not focused Mongo acceptance evidence. Publication/deployment jobs were intentionally skipped.

    Focused evidence and artifact: 103 Mongo plus ten BPMN passes, zero skips; both expected baseline failures; three fixture compiles and three framework builds; actual write-filter, topology and image evidence; fourteen input hashes and independently verified retained bytes. Independent Elsa 3 source/runtime review is APPROVE + HIGH. Greptile is 5/5 on the exact head, with the indexed-filter finding resolved. Copilot was requested but no delivered Copilot review is claimed. CodeRabbit's success represents its base-branch review skip.

    This accepts the implementation on the program branch. #8294 stays OPEN, Todo / Not Ready / Verification Pending, behind native final-main blocker #8655; #8286 and #8214 remain open. The merge message skips redundant merge CI; no separate merge-head CI is claimed. The future main promotion must run its own required gates. #8653 becomes the sole active delivery Task. No publication or deployment occurred.

  6. sfmskywalker commented on Oct 8, 2026

    @sfmskywalker
    MemberAuthor

    Exact-main Mongo correction accepted

    The correction from #8654 is now on main through #8657 at 179749636fd4ddce07b186d4fe3456a43fa91162, with tree equal to the exact reviewed candidate. The main-focused receipt acceptance records run37711786315/attempt1:103 Mongo plus10 BPMN cases, zero skips, all20 CAS cases, two intended unfixed-baseline failures, replica-set/standalone and Mongo image identity, three fixture/three production framework builds and14 exact-source hashes. Independent runtime audit and lead receipt/source/hash checks passed. The complete main Packages and analysis gates also passed under #8655.

    The accepted production code retains full-snapshot conditional writes, session-aware reads with current tenant visibility, transactional published-to-draft mutation, explicit standalone rejection and conservative unknown/error behavior. Source and runtime review preserve the task's narrow Mongo/BPMN boundary; no general distributed-provider guarantee, publication or database migration is inferred.

    The final-main dependency is now satisfied. Closing this correction and marking its board verification Passed; #8286 is reconciled separately and #8214/#8194 remain open for their own outcomes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    elsa 3This issue is specific to Elsa 3enhancementNew feature or requestprio highIs on the roadmap for the near-futuretriaged

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions