pub enum Finding {
Chain {
run: RunId,
detail: String,
},
NotInLog {
run: RunId,
},
BadInclusion {
run: RunId,
},
LeafMismatch {
run: RunId,
},
SealClaim {
run: RunId,
},
GroupUnsettled {
run: RunId,
group: String,
},
EffectUndecided {
run: RunId,
step: StepId,
effect: EffectKey,
doubt: &'static str,
},
NotAppendOnly {
old_size: u64,
obtained_from: String,
},
WrongLog {
theirs: String,
ours: String,
obtained_from: String,
},
Shrunk {
old_size: u64,
now: u64,
obtained_from: String,
},
StaleWitness {
key_id: KeyId,
obtained_from: String,
timestamp: u64,
age_secs: u64,
},
WitnessTimeAhead {
key_id: KeyId,
obtained_from: String,
timestamp: u64,
ahead_secs: u64,
},
}Expand description
One thing wrong with a plane’s history.
Variants§
Chain
NotInLog
BadInclusion
LeafMismatch
The chain the store served is not the chain the log committed to.
The one that catches a truncated-but-internally-consistent record set: a prefix of a chain verifies on its own, and the leaf the log holds is the terminal hash of the whole run — so an audit that verified the records and then checked the store-supplied leaf against the tree, without ever holding the two to each other, was verifying two halves of two different claims.
SealClaim
The sealing record’s own claim disagrees with the chain it sits in.
RunSealed.chain_head is the head the conclusion was drawn over — by
construction, the record’s own prev_hash. A mismatch means the
conclusion was composed against a different history than the one it was
appended to, which no honest writer produces.
GroupUnsettled
A sealed conclusion over an undecided transactional unit.
GroupOpened/GroupSettled bracket several effects that take together
or not at all, and the settlement is the most consequential thing a
group does. A run still open with a group unsettled is the ordinary
crash shape — the resume re-walks the members and settles, and the run
itself sits in a findable backlog until it does. A sealed run is
the state no honest writer produces: nothing may resume it, so nothing
will ever settle the group, and whether its members were taken or taken
back is permanently unanswerable from a history that claims to be
complete.
EffectUndecided
A sealed conclusion over an effect whose outcome was never established.
The finding that outlives the run. A quarantine is a status, and a status is something a later action overwrites: abandoning the run takes it off the quarantine backlog, which is the only listing that carried it. What the run left in the world does not go away with the listing, so the record of it is derived from the journal instead — where nothing an operator does can take it off.
Under a sealing conclusion only, and for the reason
GroupUnsettled is: an open run with an
undecided effect is the ordinary crash shape, healed by a resume or
answered by a person, and flagging it would teach the reader this
finding is weather.
Mutating effects only. A read that never came back is safe to repeat and changed nothing, so there is nothing here for an auditor to act on.
Fields
NotAppendOnly
The one that needs an outside artifact.
Names which anchor it failed against, because an audit is held to every checkpoint an auditor brought rather than to one: a fork is visible from whichever observer saw the history it diverged from, and that observer is the first thing an investigator has to go and ask.
WrongLog
Shrunk
StaleWitness
A witness key has not seen the log for longer than the auditor allows. Not attributed: plane silence, a failed submission and a witness outage look the same from outside.
WitnessTimeAhead
A witness key’s signed time is ahead of the auditor’s clock by more than the maximum age, so it cannot be read as fresh.
Trait Implementations§
impl Eq for Finding
Source§impl Error for Finding
impl Error for Finding
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
impl StructuralPartialEq for Finding
Auto Trait Implementations§
impl Freeze for Finding
impl RefUnwindSafe for Finding
impl Send for Finding
impl Sync for Finding
impl Unpin for Finding
impl UnsafeUnpin for Finding
impl UnwindSafe for Finding
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more