Skip to content

Commit 2c65978

Browse files
committed
docs(daemon): correct the claim-gate and managed-owner comments
- The claim-gate docstring claimed there is no other way to obtain device operations. That is true of command handlers, but two daemon-owned recovery paths bind outside the seam: application-lifecycle-recovery.ts (ordinary intent, daemon shutdown) and durable-capture-runtime-recovery.ts (exact-owner intent read back from a durable envelope, which this unit makes able to carry a managed local owner). Name them instead of claiming coverage the seam does not have. - The open path's comment described a session executing under an allocator-held claim, a state this route cannot produce. Say what the `{ kind: 'ordinary' }` literal actually is: the truth of a route that binds ordinarily, which the Host open route replaces with the request's exact intent when it lands. - Name U3 as the unit that fills the exact-owner selection arm, rather than the whole ADR.
1 parent 66d93da commit 2c65978

3 files changed

Lines changed: 11 additions & 6 deletions

File tree

‎src/daemon/device-claim-admission.ts‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,12 +21,16 @@ import {
2121
* happens here, under every policy: an ordinary owner takes a transient claim
2222
* only when the executing command's declared {@link DeviceClaimPolicy} is
2323
* `transient-exclusive`; a managed local owner is verified against its
24-
* allocator-held claim; a provider owner takes nothing. There is no other way
25-
* to obtain device operations, so none of it can be forgotten by a handler.
24+
* allocator-held claim; a provider owner takes nothing.
2625
*
2726
* `admit` is called once per device binding by the request runtime bindings,
2827
* which is where per-device deduplication already lives, with the binding
29-
* intent the gateway bound.
28+
* intent the gateway bound. A command handler has no other way to obtain
29+
* device operations, so a handler cannot forget any of this. Two daemon-owned
30+
* recovery paths do bind outside the seam and are the known gap:
31+
* application-lifecycle-recovery.ts (ordinary intent, daemon shutdown) and
32+
* durable-capture-runtime-recovery.ts (exact-owner intent read back from a
33+
* durable envelope).
3034
*/
3135
export type DeviceClaimAdmission = AsyncDisposable &
3236
Readonly<{

‎src/daemon/session-lifecycle/internal/session-open-execution.ts‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -378,8 +378,9 @@ async function acquireDeviceClaimForOwner(params: {
378378
case 'none':
379379
return { status: 'not-required' };
380380
case 'allocator-held': {
381-
// Session open binds ordinarily and carries no fence; a session admitted under the
382-
// allocator-held claim executes under it and records no claim of its own.
381+
// Session open binds ordinarily, so this literal is the truth of the route and not a
382+
// placeholder: the Host open route replaces it with the request's exact intent when it
383+
// lands. Until then a managed owner reaches here without a fence and is always refused.
383384
const response = buildAllocatorHeldRefusal(
384385
device,
385386
owner,

‎src/platform-runtime-gateway.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -296,7 +296,7 @@ async function selectExactOwner(
296296
throw ownerUnavailable(ref);
297297
}
298298
case 'managed-local':
299-
// No managed owner is registered yet; the exact-only managed registry lands with ADR 0021.
299+
// No managed owner is registered yet; U3 fills this arm with the exact-only registry.
300300
throw ownerUnavailable(ref);
301301
case 'provider-runtime': {
302302
const registration = providersByOwner.get(runtimeOwnerKey(ref));

0 commit comments

Comments
 (0)