pub struct BudgetGate { /* private fields */ }Expand description
§Fase 72.c — a daemon’s compiled budget { … } as a runnable gate. Holds one
RateLease per quota (keyed by effect + kind), the on_exhausted policy,
and an effect→keys index so the dispatch site can gate a tool emission by
name. Built once when a budgeted daemon starts running its flow; the OSS
reference is single-process (the §72.e enterprise layer swaps the in-process
kernel for the per-tenant Redis RateLimiter behind the same gate shape).
Implementations§
Source§impl BudgetGate
impl BudgetGate
Sourcepub fn from_ir(budget: &IRBudget, scope: &str, now: DateTime<Utc>) -> Self
pub fn from_ir(budget: &IRBudget, scope: &str, now: DateTime<Utc>) -> Self
Build a gate from a compiled crate::ir_nodes::IRBudget. scope is an
opaque prefix (e.g. the daemon name) that namespaces the subject keys.
An invalid-period quota (the type checker prevents this) is skipped.
Sourcepub fn merged_with(self, other: BudgetGate) -> BudgetGate
pub fn merged_with(self, other: BudgetGate) -> BudgetGate
§Fase 114.a — fold another gate into this one.
A program may declare several top-level budgets. They compose into one
gate, and the composition may only ever tighten:
- Quotas accumulate. Subject keys are namespaced by scope, so they
cannot collide. Two budgets over the same tool means both must
grant —
gate()is all-or-none over an effect’s quotas. You cannot satisfy one quota by ignoring another. - The STRICTEST
on_exhaustedwins (block>defer>shed).
That second rule is the load-bearing one. If a lax budget could soften a strict one, then adding a budget could widen what the program is allowed to do — and a quota whose presence increases your permissions is not a quota. Merging must never be a way to buy leniency.
Sourcepub fn gate(&mut self, effect: &str, now: DateTime<Utc>) -> GateDecision
pub fn gate(&mut self, effect: &str, now: DateTime<Utc>) -> GateDecision
Gate one emission of effect (a tool name) at now. An effect with no
quota is GateDecision::Allow (unbudgeted). Otherwise all of its quotas
must grant (all-or-none); on exhaustion the daemon’s on_exhausted policy
rides on the GateDecision::Deny.
Sourcepub fn on_exhausted(&self) -> &str
pub fn on_exhausted(&self) -> &str
The exhaustion policy (block | defer | shed).
Sourcepub fn snapshot(&self) -> Vec<(String, RateLeaseSnapshot)>
pub fn snapshot(&self) -> Vec<(String, RateLeaseSnapshot)>
§Fase 72.e — snapshot the gate’s cumulative state for persistence (the
enterprise supervisor saves this after a tick + restores it before the
next, so a max: 50 per day spans the day’s ticks).
Sourcepub fn restore(&mut self, snaps: &[(String, RateLeaseSnapshot)])
pub fn restore(&mut self, snaps: &[(String, RateLeaseSnapshot)])
§Fase 72.e — restore the gate’s state from a prior snapshot.
Auto Trait Implementations§
impl Freeze for BudgetGate
impl RefUnwindSafe for BudgetGate
impl Send for BudgetGate
impl Sync for BudgetGate
impl Unpin for BudgetGate
impl UnsafeUnpin for BudgetGate
impl UnwindSafe for BudgetGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more