Skip to main content

Module blob

Module blob 

Source
Expand description

Content-addressed bytes, kept out of the chain.

The journal refuses a record over Record::MAX_RECORD_BYTES, and this is the other half of that refusal: somewhere for the bytes to go. The pattern is the field’s — Temporal calls it a claim check, offloading payloads above a threshold and passing a reference through the event history instead — with one difference that matters here.

The reference is the digest. Temporal’s token identifies a payload; a digest is the payload’s identity. So the hash chain still commits to the exact bytes even though it does not contain them: an auditor who fetches a blob can check it against the digest the chain already signed, and a swapped blob is as detectable as a rewritten record. A reference that merely pointed at mutable storage would move the tamper-evidence boundary without saying so.

Three properties follow, and each is a rule rather than a nicety:

  • The store computes the digest, never the caller. A caller who supplied both bytes and digest could supply a pair that does not match, and every later verification would compare a blob against a claim rather than a fact.
  • Reads verify before returning. Storage is the least trusted thing here — it is the part an operator can reach with a text editor.
  • Writes are idempotent by construction. Same bytes, same address; there is nothing to race and no transaction to need. That is precisely why an object store is the right shape for this and the wrong shape for the journal, which needs ordered scans and multi-key atomicity.

Structs§

Erased
What an erasure did, and the copies outside the plane it did not reach.
MemoryBlobs
Blobs held in memory for the life of the process.
OpenDalBlobs
Content-addressed blobs on an OpenDAL operator.
ScopedBlobs
A BlobStore that keeps one erasure unit’s blobs under addresses of its own.

Enums§

BlobError
What can go wrong reaching content-addressed storage.
EraseError
Why an erasure did not happen.

Constants§

TOMBSTONE_FORMAT_VERSION
The tombstone layout this build writes and reads.

Traits§

BlobStore
Bytes addressed by their own hash.

Functions§

erase_case
Expire every blob a case produced.
erase_run
Destroy the erasure scope of a run that belongs to no case.
unit_address
Where one unit’s copy of digest lives in the backing store.