|
33 | 33 | TURN_LANE_DIR_NAME = ".lanes" |
34 | 34 | TURN_LANE_UNATTRIBUTED_AGENT = "unattributed" |
35 | 35 | # Public-safe holder fields only: the lock record also carries a lock id, a |
36 | | -# policy name, and the private lock path, which never leave this process. |
37 | | -TURN_LANE_HOLDER_TEXT_FIELDS = ("agent_id", "operation", "acquired_at") |
| 36 | +# policy name, and the private lock path, which never leave this process. The |
| 37 | +# host is projected because two hosts can share one runtime root: a refusal on |
| 38 | +# the second host must not print a pid that cannot exist there. |
| 39 | +TURN_LANE_HOLDER_TEXT_FIELDS = ("agent_id", "operation", "acquired_at", "host") |
38 | 40 | # A refusal taken here stops before the journal, the host, and quota, so the |
39 | 41 | # payload reports the same effect shape an executing Turn does -- all false. |
40 | 42 | TURN_LANE_NO_EFFECTS: dict[str, bool] = { |
@@ -104,9 +106,11 @@ def turn_lane_singleflight( |
104 | 106 | def turn_lane_holder_readback(target: Path) -> dict[str, Any]: |
105 | 107 | """Return the public-safe identity of the Turn holding one lane, else ``{}``. |
106 | 108 |
|
107 | | - Only names, a timestamp, and a process id are projected: the holder record's |
108 | | - private lock path and lock id stay out, so a refusal can say who is running |
109 | | - without publishing where this machine keeps its runtime state. |
| 109 | + Only names, a timestamp, a machine name and a process id are projected: the |
| 110 | + holder record's private lock path and lock id stay out, so a refusal can say |
| 111 | + who is running where without publishing where a machine keeps its runtime |
| 112 | + state. The machine name is what makes the projected pid actionable when two |
| 113 | + hosts share one runtime root. |
110 | 114 | """ |
111 | 115 |
|
112 | 116 | try: |
|
0 commit comments