FIRE_CLAIM_SKEW_SECONDS now lives in cron/constants.py so a sibling loaded from a newer on-disk tree never resolves it through the cron.jobs object a long-lived process cached at boot. FIRE_CLAIM_TTL_SECONDS is the other half of the fire-claim pair and cron/occurrences.py::unclaimed_pending_slot reached it the same way, through the facade. Move it too, so both bounds have one home and the next sibling cannot re-open the trap by importing the TTL from cron.jobs. jobs.py keeps importing both from the leaf because it uses them (claim TTL default, live-claim checks, skewed early-fire ownership); that import is a consumer, not a re-export shim. Salvaged from #114692 on top of #114675; only the TTL delta and the leaf docstring are kept.
14 lines
735 B
Python
14 lines
735 B
Python
"""Fire-claim timing bounds shared by the job store and its siblings.
|
|
|
|
Import-free on purpose: a sibling loaded fresh from a newer on-disk tree must resolve
|
|
these without going through the ``cron.jobs`` object a long-lived process cached at boot.
|
|
"""
|
|
|
|
# A fire_claim younger than this is a live run (heartbeat cadence is 60 s). One value
|
|
# for claiming, one-shot re-arm, and stale-error recovery so they cannot disagree.
|
|
FIRE_CLAIM_TTL_SECONDS = 300
|
|
# A hosted/webhook fire for the armed slot can arrive a few seconds before the stored
|
|
# ``next_run_at`` (the fire scheduler's clock runs ahead of ours). Claims that early still own
|
|
# the slot; only claims further ahead are off-tick manual/dashboard fires.
|
|
FIRE_CLAIM_SKEW_SECONDS = 60
|