1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
/// SessionCluster - owns resident local rendezvous instances.
///
/// This is the top-level local session coordinator. It manages:
/// - Local rendezvous owners
/// - Session-role endpoint leases for resident endpoints
/// - Dynamic route resolver storage
///
/// Resident mutable state of SessionCluster.
///
/// # Safety Invariants
///
/// The following invariants MUST be maintained by all code accessing `SessionStorage`:
///
/// 1. **No duplicate attach mutation**: at most one `LaneLease` mutates a rendezvous at a time
/// 2. **Session-role exclusivity**: live public endpoints hold unique `(rendezvous, sid, role)` endpoint leases
/// 3. **Rendezvous ownership**: Rendezvous instances are owned by the cluster and remain attached while leases exist
/// 4. **Resolver ownership**: dynamic resolvers are registered only for resident program sites
///
/// Violations of these invariants are guarded by the lease table where possible
/// and audited through TAP events and focused invariant tests.
pub