Skip to main content

Finding

Enum Finding 

Source
pub enum Finding {
    Chain {
        run: RunId,
        detail: String,
    },
    NotInLog {
        run: RunId,
    },
    BadInclusion {
        run: RunId,
    },
    LeafMismatch {
        run: RunId,
    },
    SealClaim {
        run: RunId,
    },
    GroupUnsettled {
        run: RunId,
        group: String,
    },
    EffectUndecided {
        run: RunId,
        step: StepId,
        effect: EffectKey,
        doubt: &'static str,
    },
    NotAppendOnly {
        old_size: u64,
        obtained_from: String,
    },
    WrongLog {
        theirs: String,
        ours: String,
        obtained_from: String,
    },
    Shrunk {
        old_size: u64,
        now: u64,
        obtained_from: String,
    },
    StaleWitness {
        key_id: KeyId,
        obtained_from: String,
        timestamp: u64,
        age_secs: u64,
    },
    WitnessTimeAhead {
        key_id: KeyId,
        obtained_from: String,
        timestamp: u64,
        ahead_secs: u64,
    },
}
Expand description

One thing wrong with a plane’s history.

Variants§

§

Chain

Fields

§run: RunId
§detail: String
§

NotInLog

Fields

§run: RunId
§

BadInclusion

Fields

§run: RunId
§

LeafMismatch

The chain the store served is not the chain the log committed to.

The one that catches a truncated-but-internally-consistent record set: a prefix of a chain verifies on its own, and the leaf the log holds is the terminal hash of the whole run — so an audit that verified the records and then checked the store-supplied leaf against the tree, without ever holding the two to each other, was verifying two halves of two different claims.

Fields

§run: RunId
§

SealClaim

The sealing record’s own claim disagrees with the chain it sits in.

RunSealed.chain_head is the head the conclusion was drawn over — by construction, the record’s own prev_hash. A mismatch means the conclusion was composed against a different history than the one it was appended to, which no honest writer produces.

Fields

§run: RunId
§

GroupUnsettled

A sealed conclusion over an undecided transactional unit.

GroupOpened/GroupSettled bracket several effects that take together or not at all, and the settlement is the most consequential thing a group does. A run still open with a group unsettled is the ordinary crash shape — the resume re-walks the members and settles, and the run itself sits in a findable backlog until it does. A sealed run is the state no honest writer produces: nothing may resume it, so nothing will ever settle the group, and whether its members were taken or taken back is permanently unanswerable from a history that claims to be complete.

Fields

§run: RunId
§group: String
§

EffectUndecided

A sealed conclusion over an effect whose outcome was never established.

The finding that outlives the run. A quarantine is a status, and a status is something a later action overwrites: abandoning the run takes it off the quarantine backlog, which is the only listing that carried it. What the run left in the world does not go away with the listing, so the record of it is derived from the journal instead — where nothing an operator does can take it off.

Under a sealing conclusion only, and for the reason GroupUnsettled is: an open run with an undecided effect is the ordinary crash shape, healed by a resume or answered by a person, and flagging it would teach the reader this finding is weather.

Mutating effects only. A read that never came back is safe to repeat and changed nothing, so there is nothing here for an auditor to act on.

Fields

§run: RunId
§step: StepId
§effect: EffectKey
§doubt: &'static str

Whether the runtime never heard back, or heard back and was told nothing — two different places for an investigator to start.

§

NotAppendOnly

The one that needs an outside artifact.

Names which anchor it failed against, because an audit is held to every checkpoint an auditor brought rather than to one: a fork is visible from whichever observer saw the history it diverged from, and that observer is the first thing an investigator has to go and ask.

Fields

§old_size: u64
§obtained_from: String
§

WrongLog

Fields

§theirs: String
§ours: String
§obtained_from: String
§

Shrunk

Fields

§old_size: u64
§now: u64
§obtained_from: String
§

StaleWitness

A witness key has not seen the log for longer than the auditor allows. Not attributed: plane silence, a failed submission and a witness outage look the same from outside.

Fields

§key_id: KeyId
§obtained_from: String
§timestamp: u64
§age_secs: u64
§

WitnessTimeAhead

A witness key’s signed time is ahead of the auditor’s clock by more than the maximum age, so it cannot be read as fresh.

Fields

§key_id: KeyId
§obtained_from: String
§timestamp: u64
§ahead_secs: u64

Trait Implementations§

Source§

impl Clone for Finding

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Finding

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for Finding

Source§

fn fmt(&self, __formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Finding

Source§

impl Error for Finding

1.30.0 · Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl PartialEq for Finding

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Finding

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> MaybeSend for T
where T: Send,

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToSmolStr for T
where T: Display + ?Sized,

Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more