pub struct CommandLifetimeLock { /* private fields */ }Expand description
Exclusive custody for one journal operation’s local command attempt.
Persist Self::record and dispatch intent before spawning. This primitive
does not consume durable paid-call authority or qualify a backend’s retry policy.
Implementations§
Source§impl CommandLifetimeLock
impl CommandLifetimeLock
Sourcepub fn acquire(
journal: &Path,
operation_sequence: u64,
) -> Result<Self, CommandLifetimeLockError>
pub fn acquire( journal: &Path, operation_sequence: u64, ) -> Result<Self, CommandLifetimeLockError>
Acquire an operation’s regular no-follow sidecar without waiting.
The journal parent must already exist. The journal leaf may be absent; aliases of an explicitly selected parent resolve to one location.
§Errors
Rejects unsafe journal/sidecar entries, contention, invalid identity and IO failures.
Sourcepub fn record(&self) -> &CommandCustodyRecord
pub fn record(&self) -> &CommandCustodyRecord
Return exact custody evidence for durable retention before dispatch.
Sourcepub fn path(&self) -> &Path
pub fn path(&self) -> &Path
Return the retained sidecar path; dropping custody never removes it.
Sourcepub fn spawn(
&mut self,
command: Command,
) -> Result<Child, CommandLifetimeLockError>
pub fn spawn( &mut self, command: Command, ) -> Result<Child, CommandLifetimeLockError>
Attempt one trusted command with owned descriptor inheritance.
Consumes this guard’s single spawn allowance before the spawn attempt. The command value is consumed and dropped, so its parent-side descriptor copy cannot outlive spawn. The owner descriptor remains close-on-exec. The selected backend must preserve inherited custody in its descendants. Caller code owns argv admission, output/deadline limits and child reaping.
§Errors
Rejects repeated dispatch, replaced sidecars, unsupported hosts and spawn failures.
Sourcepub fn finish(self) -> Result<CommandQuiescenceGuard, CommandLifetimeLockError>
pub fn finish(self) -> Result<CommandQuiescenceGuard, CommandLifetimeLockError>
Close owner custody and admit exact quiescence within a bounded grace period.
Success returns an exclusive non-spawning guard. Contention means another inherited holder remains; command exit alone is insufficient. Failures retain the sidecar and do not establish that a remote effect failed.
§Errors
Returns in-flight custody, changed/missing/unsafe sidecars and IO failures.