pub struct ClosedRemoteObject { /* private fields */ }Expand description
One closed remote object and the payload bytes its row will name.
A record holds references into the payload spool, so a record on its own is not yet something a row can name — the files have to be there first. This carries both from the moment the record is closed to the transaction that installs the files and writes the row, and the map is keyed by exactly the hashes the record claims, so a claim whose bytes are missing cannot be written down.
Implementations§
Source§impl ClosedRemoteObject
impl ClosedRemoteObject
Sourcepub fn with_payloads(
record: RemoteObjectRecord,
payloads: BTreeMap<ObjectHash, Vec<u8>>,
) -> Result<Self, RemoteObjectRecordError>
pub fn with_payloads( record: RemoteObjectRecord, payloads: BTreeMap<ObjectHash, Vec<u8>>, ) -> Result<Self, RemoteObjectRecordError>
A record and the bytes for exactly the payloads it claims.
Used both when a record is first closed and when one is read back from its row alongside its spool files. The spool names files by the digest of their contents, so bytes found under a claimed hash are that payload; all this has to check is that the set matches.
pub fn record(&self) -> &RemoteObjectRecord
pub fn into_record(self) -> RemoteObjectRecord
Sourcepub fn map_record(
self,
transition: impl FnOnce(RemoteObjectRecord) -> Result<RemoteObjectRecord, RemoteObjectRecordError>,
) -> Result<Self, RemoteObjectRecordError>
pub fn map_record( self, transition: impl FnOnce(RemoteObjectRecord) -> Result<RemoteObjectRecord, RemoteObjectRecordError>, ) -> Result<Self, RemoteObjectRecordError>
Advance the record this holds, keeping its payloads. A transition never changes what a record names — neither hash mutates and the domain changes re-wrap the same reference — so the payload set carries over unchanged, and is re-checked against the new record rather than assumed.
Sourcepub fn payload_bytes(&self) -> &BTreeMap<ObjectHash, Vec<u8>>
pub fn payload_bytes(&self) -> &BTreeMap<ObjectHash, Vec<u8>>
The payload files this record names, by the hash each is stored under.
Named apart from the record’s own RemoteObjectRecord::payloads,
which says where the payloads are rather than carrying them.
Sourcepub fn semantic_bytes(&self) -> Option<&[u8]>
pub fn semantic_bytes(&self) -> Option<&[u8]>
The record’s plaintext: the locator a stored blob’s row carries, or the
spool file every other domain’s identity names. None for the image
domains, which name their payload by reference and have no body here.
Sourcepub fn stored_bytes(&self) -> Option<&[u8]>
pub fn stored_bytes(&self) -> Option<&[u8]>
The ciphertext this record uploads, for the domains that seal one.
Methods from Deref<Target = RemoteObjectRecord>§
Sourcepub fn validate(&self) -> Result<(), RemoteObjectRecordError>
pub fn validate(&self) -> Result<(), RemoteObjectRecordError>
Everything this record asserts about itself that does not need its payloads: where those payloads live, that the identity is the one the record is filed under, and that its ownership state holds together.
Byte agreement is Self::validate_payload’s job, and it is checked
where bytes arrive from outside this device’s own durable state, rather
than on every load. Identity and payload cannot drift apart afterwards:
neither hash mutates across transitions, and the two domain changes that
do happen re-wrap the same reference.
Sourcepub fn validate_payload(
&self,
canonical_semantic_bytes: &[u8],
) -> Result<(), RemoteObjectRecordError>
pub fn validate_payload( &self, canonical_semantic_bytes: &[u8], ) -> Result<(), RemoteObjectRecordError>
Check this record’s identity against the plaintext it names — the whole domain parse, its signature verifications, and its agreement with the reference.
Called where bytes enter from somewhere this device does not already trust: a constructor handed the payload, a pull that parsed it off the wire. Reading back this device’s own durable state does not run it — neither loading the row nor reading the spool file the row names, which is named for the digest of its own contents and was fixed by this record’s identity when it was built.
Sourcepub fn records_verified_upload(&self) -> bool
pub fn records_verified_upload(&self) -> bool
Whether this device already created these exact bytes at the provider and settled the create.
The record is the evidence, so nothing that holds one needs to read the object back to know its content: the bytes were hashed locally before the upload and the provider’s exact-upload verification settled the create. Reading it back would test the provider’s durability, not this device’s correctness, and an object that later goes missing surfaces on the read that wants it.
pub fn cleanup_target(&self) -> Option<&ExactObjectRef>
pub fn candidate_cleanup_complete( &self, candidate: &StoreBatchCommitRef, ) -> Result<bool, RemoteObjectRecordError>
pub fn candidate_nonactivation_proof( &self, candidate: &StoreBatchCommitRef, ) -> Result<Option<&CandidateNonactivationProof>, RemoteObjectRecordError>
pub fn object(&self) -> &ExactObjectRef
pub fn payloads(&self) -> &RemoteObjectPayloads
Sourcepub fn semantic_payload(&self) -> SemanticPayload<'_>
pub fn semantic_payload(&self) -> SemanticPayload<'_>
Where this record’s plaintext is. A stored blob carries its locator in the row, the image domains have no plaintext of their own, and every other domain names its plaintext in the spool by the identity’s semantic hash.
Sourcepub fn stored_payload(&self) -> Option<ObjectHash>
pub fn stored_payload(&self) -> Option<ObjectHash>
The spooled ciphertext this record uploads, when the ciphertext is its own to upload.
Sourcepub fn payload_claims(&self) -> BTreeSet<ObjectHash>
pub fn payload_claims(&self) -> BTreeSet<ObjectHash>
Every spool file this record names. The claim it holds while its row exists, and what the row’s deletion lets go of.
pub fn object_id(&self) -> ObjectHash
pub fn is_activated_stored_blob(&self) -> bool
pub fn validate_reclaimable_store_package( &self, target: &StorePackageRef, activation: &StoreBatchCommitRef, ) -> Result<(), RemoteObjectRecordError>
pub fn validate_reclaimable_circle_package( &self, target: &CirclePackageRef, activation: &StoreBatchCommitRef, ) -> Result<(), RemoteObjectRecordError>
pub fn store_package_is_retained_for_replay( &self, target: &StorePackageRef, activation: &StoreBatchCommitRef, ) -> Result<bool, RemoteObjectRecordError>
pub fn circle_package_is_retained_for_replay( &self, target: &CirclePackageRef, activation: &StoreBatchCommitRef, ) -> Result<bool, RemoteObjectRecordError>
Sourcepub fn validate_reclaimable_circle_bootstrap_image(
&self,
image: &SnapshotImageRef,
activation: &StoreBatchCommitRef,
) -> Result<(), RemoteObjectRecordError>
pub fn validate_reclaimable_circle_bootstrap_image( &self, image: &SnapshotImageRef, activation: &StoreBatchCommitRef, ) -> Result<(), RemoteObjectRecordError>
A Circle bootstrap image is reclaimable when its single activating Store commit is its only surviving owner: no pending activation and exactly one activated owner. A bootstrap image accretes a per-activating-commit owner, so more than one means a live successor still references it.
Sourcepub fn validate_reclaimable_snapshot_image(
&self,
image: &SnapshotImageRef,
owner: &SnapshotObjectOwner,
) -> Result<(), RemoteObjectRecordError>
pub fn validate_reclaimable_snapshot_image( &self, image: &SnapshotImageRef, owner: &SnapshotObjectOwner, ) -> Result<(), RemoteObjectRecordError>
A snapshot image is reclaimable when the generation that published it is its
only surviving owner: no pending activation and exactly one activated owner,
the Snapshot owner naming that stream and generation. A snapshot image
accretes no further owners, so anything else means the record is not the one
the claim describes.
Sourcepub fn validate_reclaimable_membership_rollup(
&self,
rollup: &MembershipRollupRef,
owner: &SnapshotObjectOwner,
) -> Result<(), RemoteObjectRecordError>
pub fn validate_reclaimable_membership_rollup( &self, rollup: &MembershipRollupRef, owner: &SnapshotObjectOwner, ) -> Result<(), RemoteObjectRecordError>
A membership rollup is reclaimable when the generation named as its owner is its only owner. A rollup two generations point at carries both, and stays until the other one is reclaimed as well.
Sourcepub fn validate_reclaimable_stored_blob(
&self,
stored: &StoredBlobRef,
) -> Result<(), RemoteObjectRecordError>
pub fn validate_reclaimable_stored_blob( &self, stored: &StoredBlobRef, ) -> Result<(), RemoteObjectRecordError>
A stored blob is reclaimable when it is the exact activated blob the target names. Unlike a package or an image, a blob legitimately carries several activated owners — one per commit that bound it — so ownership count is not the eligibility question here; whether any live row or installable image still needs it is, and the reclaim verified that before reaching closure.
Sourcepub fn stored_blob_commit_owners(&self) -> Vec<StoreBatchCommitRef>
pub fn stored_blob_commit_owners(&self) -> Vec<StoreBatchCommitRef>
The activated Store commits that published this stored blob. A blob accretes one per commit whose package bindings named it, so a republished blob carries several.
pub fn snapshot_owners(&self) -> impl Iterator<Item = &SnapshotObjectOwner>
pub fn retained_replay_owners( &self, ) -> impl Iterator<Item = &RetainedReplayOwner>
Trait Implementations§
Source§impl Clone for ClosedRemoteObject
impl Clone for ClosedRemoteObject
Source§fn clone(&self) -> ClosedRemoteObject
fn clone(&self) -> ClosedRemoteObject
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for ClosedRemoteObject
impl Debug for ClosedRemoteObject
Source§impl Deref for ClosedRemoteObject
impl Deref for ClosedRemoteObject
Source§impl PartialEq for ClosedRemoteObject
impl PartialEq for ClosedRemoteObject
impl Eq for ClosedRemoteObject
impl StructuralPartialEq for ClosedRemoteObject
Auto Trait Implementations§
impl Freeze for ClosedRemoteObject
impl RefUnwindSafe for ClosedRemoteObject
impl Send for ClosedRemoteObject
impl Sync for ClosedRemoteObject
impl Unpin for ClosedRemoteObject
impl UnsafeUnpin for ClosedRemoteObject
impl UnwindSafe for ClosedRemoteObject
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.