Skip to main content

Immutable

Struct Immutable 

Source
pub struct Immutable<F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>>, H: Hasher, T: Translator, S: Strategy>
where C::Item: EncodeShared,
{ /* private fields */ }
Expand description

An authenticated database that only supports adding new keyed values (no updates or deletions).

§Invariant

A key must be set at most once across the database history. If a key is set more than once, reads of that key may return any of its written values.

Use fixed::Db or variable::Db for concrete instantiations.

Implementations§

Source§

impl<F, E, K, V, C, H, T, S> Immutable<F, E, K, V, C, H, T, S>
where F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>>, C::Item: EncodeShared, H: Hasher, T: Translator, S: Strategy,

Source

pub fn to_batch(&self) -> Arc<MerkleizedBatch<F, H::Digest, K, V, S>>

Create an initial MerkleizedBatch from the committed DB state.

Source§

impl<F: Family, E: Context, K: Array, V: FixedValue, H: Hasher, T: Translator, S: Strategy> Immutable<F, E, K, FixedEncoding<V>, Journal<E, Operation<F, K, FixedEncoding<V>>>, H, T, S>

Source

pub async fn init(context: E, cfg: Config<T, S>) -> Result<Self, Error<F>>

Returns a Db initialized from cfg. Any uncommitted log operations will be discarded and the state of the db will be as of the last committed operation.

Source§

impl<F: Family, E: Context, K: Key, V: VariableValue, H: Hasher, T: Translator, S: Strategy> Immutable<F, E, K, VariableEncoding<V>, Journal<E, Operation<F, K, VariableEncoding<V>>>, H, T, S>

Source

pub async fn init( context: E, cfg: Config<T, <Operation<F, K, V> as Read>::Cfg, S>, ) -> Result<Self, Error<F>>

Returns a Db initialized from cfg. Any uncommitted log operations will be discarded and the state of the db will be as of the last committed operation.

Source§

impl<F, E, K, V, C, H, T, S> Immutable<F, E, K, V, C, H, T, S>
where F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>>, C::Item: EncodeShared, H: Hasher, T: Translator, S: Strategy,

Source

pub const fn inactivity_floor_loc(&self) -> Location<F>

Return the inactivity floor location declared by the last committed batch.

Source

pub fn size(&self) -> Location<F>

Return the Location of the next operation appended to this db.

Source

pub fn bounds(&self) -> Range<Location<F>>

Return [start, end) where start and end - 1 are the Locations of the oldest and newest retained operations respectively.

Source

pub const fn sync_boundary(&self) -> Location<F>

Return the most recent location from which this database can safely be synced, and the upper bound on Self::prune’s loc. For immutable databases, this equals the inactivity floor declared by the last committed batch.

Source

pub async fn get(&self, key: &K) -> Result<Option<V::Value>, Error<F>>

Get the value of key in the db, or None if it has no value or its corresponding operation has been pruned.

Source

pub async fn get_many( &self, keys: &[&K], ) -> Result<Vec<Option<V::Value>>, Error<F>>

Batch read multiple keys.

Returns results in the same order as the input keys.

Source

pub async fn get_metadata(&self) -> Result<Option<V::Value>, Error<F>>

Get the metadata associated with the last commit.

Source

pub async fn historical_proof( &self, op_count: Location<F>, start_loc: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, K, V>>), Error<F>>

Analogous to proof but with respect to the state of the database when it had op_count operations.

§Contract

op_count must be a commit-boundary size: the operation at op_count - 1 must itself be a commit op. Non-commit-boundary sizes are not supported because the inactivity floor governing them is not directly retrievable.

§Errors

Returns crate::merkle::Error::LocationOverflow if op_count or start_loc > crate::merkle::Family::MAX_LEAVES. Returns crate::merkle::Error::RangeOutOfBounds if op_count > number of operations, or if start_loc >= op_count. Returns Error::OperationPruned if start_loc has been pruned. Returns Error::HistoricalFloorPruned if op_count - 1 is retained but is not a commit op, either because the caller passed a non-commit-boundary op_count or because pruning removed the commit that would have governed op_count.

Source

pub async fn proof( &self, start_index: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, K, V>>), Error<F>>

Generate and return:

  1. a proof of all operations applied to the db in the range starting at (and including) location start_loc, and ending at the first of either:
    • the last operation performed, or
    • the operation max_ops from the start.
  2. the operations corresponding to the leaves in this range.
Source

pub async fn prune(self, loc: Location<F>) -> Result<Self, Error<F>>

Prune operations prior to prune_loc. This does not affect the db’s root, but it will affect retrieval of any keys that were set prior to prune_loc.

Pruning is irreversible and requires no prior commit. After a crash, the database remains recoverable; uncommitted operations are not guaranteed to survive.

§Errors
Source

pub async fn rewind(self, size: Location<F>) -> Result<Self, Error<F>>

Rewind the database to size operations, where size is the location of the next append.

This rewinds both the operations journal and its Merkle structure to the historical state at size, and removes rewound set operations from the in-memory snapshot.

§Errors

Returns an error when:

  • size is not a valid rewind target
  • the target’s required logical range is not fully retained (for immutable, this means the oldest retained location is already beyond the rewind boundary)
  • size - 1 is not a commit operation

Any error from this method is fatal for this handle. Rewind may mutate journal state before this method finishes rebuilding in-memory rewind state. Callers must drop this database handle after any Err from rewind and reopen from storage.

A successful rewind is not restart-stable until a subsequent Immutable::commit or Immutable::sync completes, or until the handle returned by a subsequent Immutable::start_sync completes.

Source

pub const fn root(&self) -> H::Digest

Return the canonical QMDB root of the db.

Source

pub const fn strategy(&self) -> &S

Return a reference to the merkleization strategy.

Source

pub async fn pinned_nodes_at( &self, loc: Location<F>, ) -> Result<Vec<H::Digest>, Error<F>>

Return the pinned Merkle nodes at the given location.

Source

pub async fn sync(self) -> Result<Self, Error<F>>

Sync all database state to disk. While this isn’t necessary to ensure durability of committed operations, periodic invocation may reduce memory usage and the time required to recover the database on restart.

Source

pub async fn start_sync(self) -> Result<(Self, Handle<()>), Error<F>>

Begin durably persisting the journal state published by prior Immutable::apply_batch calls.

Awaiting the returned Handle provides the same durability guarantee as Self::commit, plus a best-effort attempt to bound the recovery needed on startup. Use Self::sync to guarantee none is needed. A new sync waits for the prior sync before starting. Failures of the deferred durability work surface on the returned handle. A failed data sync also fails the next durability operation. A failed recovery-watermark sync is not observed by Self::commit, and a failed merkle-node sync may not be. Both resurface on the next Self::sync.

Source

pub async fn commit(self) -> Result<Self, Error<F>>

Durably commit the journal state published by prior Immutable::apply_batch calls.

Source

pub async fn destroy(self) -> Result<(), Error<F>>

Destroy the db, removing all data from disk.

Source

pub fn new_batch(&self) -> UnmerkleizedBatch<F, H, K, V, S>

Create a new speculative batch of operations with this database as its parent.

Source

pub fn validate_batch( &self, batch: &MerkleizedBatch<F, H::Digest, K, V, S>, ) -> Result<(), Error<F>>

Check that batch can be applied to the database in its current state, without applying it.

Self::apply_batch runs the same validation but consumes the database when it fails; callers that want to reject a bad batch and keep the handle can check first.

Source

pub async fn apply_batch( self, batch: Arc<MerkleizedBatch<F, H::Digest, K, V, S>>, ) -> Result<(Self, Range<Location<F>>), Error<F>>

Apply a batch::MerkleizedBatch to the database.

A batch is valid only if every batch applied to the database since this batch’s ancestor chain was created is an ancestor of this batch. Applying a batch from a different fork returns Error::StaleBatch (see crate::qmdb::batch_chain for more details).

§Errors
  • Error::StaleBatch if the batch is detected as stale (see crate::qmdb::batch_chain for more details).
  • Error::FloorRegressed if any commit in the chain (the tip or any unapplied ancestor) declares an inactivity floor below the previous commit’s floor (or, for the oldest unapplied commit, below the database’s current floor).
  • Error::FloorBeyondSize if any commit in the chain (the tip or any unapplied ancestor) declares an inactivity floor that exceeds its own commit operation’s location. The maximum valid floor for a commit is its own location; a floor past the commit would permit pruning the commit itself.

Floor validation happens before any journal mutation, so on floor errors the on-disk state is unchanged and reopening recovers the database as it was.

Returns the range of locations written.

This publishes the batch to the in-memory database state and appends it to the journal. Call Immutable::commit or Immutable::sync, or await the handle returned by Immutable::start_sync, to make the applied state durable.

Trait Implementations§

Source§

impl<F, E, K, V, C, H, T, S> Database for Immutable<F, E, K, V, C, H, T, S>
where F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>> + Journal<F, Context = E, Op = Operation<F, K, V>>, C::Item: EncodeShared, C::Config: Clone + Send, H: Hasher, T: Translator, S: Strategy,

Source§

async fn from_sync_result( context: Self::Context, db_config: Self::Config, log: Self::Journal, pinned_nodes: Option<Vec<Self::Digest>>, range: NonEmptyRange<Location<F>>, apply_batch_size: NonZeroU64, ) -> Result<Self, Error<F>>

Returns an Immutable initialized from data collected in the sync process.

§Behavior

This method handles different initialization scenarios based on existing data:

  • If the Merkle journal is empty or the last item is before the range start, it creates a fresh Merkle structure from the provided pinned_nodes
  • If the Merkle journal has data but is incomplete (has length < range end), missing operations from the log are applied to bring it up to the target state
  • If the Merkle journal has data beyond the range end, it is rewound to match the sync target
§Returns

A super::Immutable db populated with the state from the given range. The pruning boundary is set to the range start.

Source§

type Family = F

Source§

type Op = Operation<F, K, V>

Source§

type Journal = C

Source§

type Hasher = H

Source§

type Config = Config<T, <C as Journal<F>>::Config, S>

Source§

type Digest = <H as Hasher>::Digest

Source§

type Context = E

Source§

async fn persist_sync_result(self) -> Result<Self, Error<F>>

Persist any state that must remain provisional until the engine verifies the rebuilt root. Read more
Source§

async fn local_pinned_nodes( context: Self::Context, config: &Self::Config, target: &Target<F, Self::Digest>, journal: &Self::Journal, ) -> Result<Option<Vec<Self::Digest>>, Error<F>>

Return locally available pinned nodes for the target, if persisted local state can authenticate them. Read more
Source§

fn root(&self) -> Self::Digest

Get the root digest of the database for verification
Source§

impl<F, E, K, V, C, H, T, S> Debug for Immutable<F, E, K, V, C, H, T, S>
where F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>>, C::Item: EncodeShared, H: Hasher, T: Translator, S: Strategy,

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<F, E, K, V, C, H, T, S> Source for Immutable<F, E, K, V, C, H, T, S>
where F: Family, E: Context, K: Key, V: ValueEncoding, C: Mutable<Item = Operation<F, K, V>>, C::Item: EncodeShared, H: Hasher, T: Translator, S: Strategy,

Source§

type Family = F

The merkle family backing this source’s proofs.
Source§

type Digest = <H as Hasher>::Digest

The digest type used in this source’s proofs.
Source§

type Op = Operation<F, K, V>

The type of operations this source yields.
Source§

type Error = Error<F>

Why this source could not answer.
Source§

async fn serve( &self, request: Request<F>, ) -> Result<(Response<F, Self::Op, Self::Digest>, FeedbackTx), Self::Error>

Serve a request.

Auto Trait Implementations§

§

impl<F, E, K, V, C, H, T, S> !RefUnwindSafe for Immutable<F, E, K, V, C, H, T, S>

§

impl<F, E, K, V, C, H, T, S> !UnwindSafe for Immutable<F, E, K, V, C, H, T, S>

§

impl<F, E, K, V, C, H, T, S> Freeze for Immutable<F, E, K, V, C, H, T, S>
where Journal<F, E, C, H, S>: Freeze, <H as Hasher>::Digest: Freeze, Index<T, Location<F>>: Freeze, Location<F>: Freeze, Metrics<E>: Freeze,

§

impl<F, E, K, V, C, H, T, S> Send for Immutable<F, E, K, V, C, H, T, S>
where Journal<F, E, C, H, S>: Send, <H as Hasher>::Digest: Send, Index<T, Location<F>>: Send, Location<F>: Send, Metrics<E>: Send,

§

impl<F, E, K, V, C, H, T, S> Sync for Immutable<F, E, K, V, C, H, T, S>
where Journal<F, E, C, H, S>: Sync, <H as Hasher>::Digest: Sync, Index<T, Location<F>>: Sync, Location<F>: Sync, Metrics<E>: Sync,

§

impl<F, E, K, V, C, H, T, S> Unpin for Immutable<F, E, K, V, C, H, T, S>
where Journal<F, E, C, H, S>: Unpin, <H as Hasher>::Digest: Unpin, Index<T, Location<F>>: Unpin, Location<F>: Unpin, Metrics<E>: Unpin,

§

impl<F, E, K, V, C, H, T, S> UnsafeUnpin for Immutable<F, E, K, V, C, H, T, S>
where Journal<F, E, C, H, S>: UnsafeUnpin, <H as Hasher>::Digest: UnsafeUnpin, Index<T, Location<F>>: UnsafeUnpin, Location<F>: UnsafeUnpin, Metrics<E>: UnsafeUnpin,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FutureExt for T

Source§

fn with_context(self, otel_cx: Context) -> WithContext<Self>

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
Source§

fn with_current_context(self) -> WithContext<Self>

Attaches the current Context to this type, returning a WithContext wrapper. Read more
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<DB, S> SourceFor<DB> for S
where S: Source<Family = <DB as Database>::Family, Op = <DB as Database>::Op, Digest = <DB as Database>::Digest> + 'static, DB: Database,

Source§

impl<T> Threaded<T> for T

Source§

type Rest = ()

The outputs beyond the threaded value.
Source§

fn split(self) -> (T, ())

Splits into the threaded value and the extra outputs.
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more