Expand description
Content-addressed bytes, kept out of the chain.
The journal refuses a record over Record::MAX_RECORD_BYTES, and this is
the other half of that refusal: somewhere for the bytes to go. The pattern is
the field’s — Temporal calls it a claim check, offloading payloads above a
threshold and passing a reference through the event history instead — with
one difference that matters here.
The reference is the digest. Temporal’s token identifies a payload; a digest is the payload’s identity. So the hash chain still commits to the exact bytes even though it does not contain them: an auditor who fetches a blob can check it against the digest the chain already signed, and a swapped blob is as detectable as a rewritten record. A reference that merely pointed at mutable storage would move the tamper-evidence boundary without saying so.
Three properties follow, and each is a rule rather than a nicety:
- The store computes the digest, never the caller. A caller who supplied both bytes and digest could supply a pair that does not match, and every later verification would compare a blob against a claim rather than a fact.
- Reads verify before returning. Storage is the least trusted thing here — it is the part an operator can reach with a text editor.
- Writes are idempotent by construction. Same bytes, same address; there is nothing to race and no transaction to need. That is precisely why an object store is the right shape for this and the wrong shape for the journal, which needs ordered scans and multi-key atomicity.
Structs§
- Erased
- What an erasure did, and the copies outside the plane it did not reach.
- Memory
Blobs - Blobs held in memory for the life of the process.
- Open
DalBlobs - Content-addressed blobs on an
OpenDALoperator. - Scoped
Blobs - A
BlobStorethat keeps one erasure unit’s blobs under addresses of its own.
Enums§
- Blob
Error - What can go wrong reaching content-addressed storage.
- Erase
Error - Why an erasure did not happen.
Constants§
- TOMBSTONE_
FORMAT_ VERSION - The tombstone layout this build writes and reads.
Traits§
- Blob
Store - Bytes addressed by their own hash.
Functions§
- erase_
case - Expire every blob a case produced.
- erase_
run - Destroy the erasure scope of a run that belongs to no case.
- unit_
address - Where one unit’s copy of
digestlives in the backing store.