Skip to main content

Module journal

Module journal 

Source
Expand description

The journal: append-only, hash-chained run history.

This is the product. Recovery, audit, cost accounting, regression testing, and regulatory record-keeping are all views over one log — and because the audit trail is the recovery mechanism, it cannot silently stop working. The system would stop working with it. Logging that exists only for compliance always rots; this cannot.

Modules§

payload
Sealing the payload fields a record carries, without hiding the record.

Structs§

AgentIdentity
Which declaration governed a run.
Append
What the runtime hands the store. Seq, chain links, and hashing are the store’s job, because only it knows the run’s current head.
Cancellation
A durable request that a run stop.
Checkpoint
A commitment to every run sealed so far.
Cosignature
A witness’s attestation that it saw a log at this size and root.
Head
A run’s current chain position.
HttpWitness
A remote witness reached over tlog-witness.
Identity
The identity upcaster: every kind is at v1 and nothing needs lifting.
Inclusion
Evidence that one run is in the log.
Lease
Ownership of a run, held by one instance for a bounded time.
MemoryWitness
A witness that remembers, in this process.
NoteSignature
One signature over a note’s text.
QuorumOutcome
What one submission round produced, against a declared quorum.
Record
A sealed journal entry: body, chain links, and the bytes that were hashed.
RecordBody
The hashed portion of a record.
ReplayCursor
A read cursor over one run’s journaled effects.
SignedNote
A note and the signatures over it.
StepCursor
One step’s effects, in the order that step performed them.
TrustedWitness
A witness this deployment is willing to believe.
WitnessQuorum
A deployment’s answer to how many cosignatures suffice.

Enums§

EffectReplay
What the journal has to say about one effect.
RecordKind
The typed view of a record’s (kind, version, payload).
SqlValue
A value a co-located resource binds into a statement.
WitnessError
Why a witness would not cosign.

Traits§

AtomicJournal
A store whose own transaction a co-located resource can join.
AtomicResource
One member that commits with the journal or not at all.
AtomicTx
As much of the journal’s own transaction as a co-located resource may use.
AtomicWork
What runs inside the journal’s transaction.
JournalStore
Append-only, hash-chained run history.
Upcaster
A pure, total transform from an older record version to the current one.
Witness
Something that will vouch for having seen a log grow.

Functions§

cosign_quorum
Submit one checkpoint to every witness and hold the result to a quorum.
key_id
The canonical key ID for a note-signing key.