Skip to main content

Keyless

Struct Keyless 

Source
pub struct Keyless<F, E, V, C, H, S>
where F: Family, E: Context, V: ValueEncoding, C: Contiguous<Item = Operation<F, V>>, H: Hasher, S: Strategy, Operation<F, V>: EncodeShared,
{ /* private fields */ }
Expand description

A keyless authenticated database.

Implementations§

Source§

impl<F: Family, E: Context, V: FixedValue, H: Hasher, S: Strategy> Keyless<F, E, FixedEncoding<V>, Journal<E, Operation<F, FixedEncoding<V>>>, H, S>

Source

pub async fn init(context: E, cfg: Config<S>) -> Result<Self, Error<F>>

Returns a Db initialized from cfg. Any uncommitted operations will be discarded and the state of the db will be as of the last committed operation.

Source§

impl<F: Family, E: Context, V: VariableValue, H: Hasher, S: Strategy> Keyless<F, E, VariableEncoding<V>, Journal<E, Operation<F, VariableEncoding<V>>>, H, S>

Source

pub async fn init( context: E, cfg: Config<<Operation<F, V> as Read>::Cfg, S>, ) -> Result<Self, Error<F>>

Returns a Db initialized from cfg. Any uncommitted operations will be discarded and the state of the db will be as of the last committed operation.

Source§

impl<F, E, V, C, H, S> Keyless<F, E, V, C, H, S>
where F: Family, E: Context, V: ValueEncoding, C: Mutable<Item = Operation<F, V>>, H: Hasher, S: Strategy, Operation<F, V>: EncodeShared,

Source

pub async fn get(&self, loc: Location<F>) -> Result<Option<V::Value>, Error<F>>

Get the value at location loc in the database.

§Errors

Returns Error::LocationOutOfBounds if loc >= self.bounds().end.

Source

pub async fn get_many( &self, locs: &[Location<F>], ) -> Result<Vec<Option<V::Value>>, Error<F>>

Batch read values at multiple locations.

Locations must be strictly increasing. Returns results in the same order as the input locations.

§Errors

Returns Error::LocationOutOfBounds if any location >= bounds().end.

Source

pub const fn last_commit_loc(&self) -> Location<F>

Returns the location of the last commit.

Source

pub const fn inactivity_floor_loc(&self) -> Location<F>

Returns the inactivity floor declared by the last committed batch.

Source

pub fn bounds(&self) -> Range<Location<F>>

Return [start, end) where start and end - 1 are the Locations of the oldest and newest retained operations respectively.

Source

pub const fn sync_boundary(&self) -> Location<F>

Return the most recent location from which this database can safely be synced, and the upper bound on Self::prune’s loc. For keyless databases, this equals the inactivity floor declared by the last committed batch.

Source

pub async fn get_metadata(&self) -> Result<Option<V::Value>, Error<F>>

Get the metadata associated with the last commit.

Source

pub const fn root(&self) -> H::Digest

Return the root of the db.

Source

pub const fn strategy(&self) -> &S

Return a reference to the merkleization strategy.

Source

pub async fn proof( &self, start_loc: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>

Generate and return:

  1. a proof of all operations applied to the db in the range starting at (and including) location start_loc, and ending at the first of either:
    • the last operation performed, or
    • the operation max_ops from the start.
  2. the operations corresponding to the leaves in this range.
§Errors
Source

pub async fn historical_proof( &self, op_count: Location<F>, start_loc: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>

Analogous to proof, but with respect to the state of the Merkle structure when it had op_count operations.

op_count must be the size of a commit boundary.

§Errors
Source

pub async fn pinned_nodes_at( &self, loc: Location<F>, ) -> Result<Vec<H::Digest>, Error<F>>

Return the pinned Merkle nodes for a lower operation boundary of loc.

Source

pub async fn prune(self, loc: Location<F>) -> Result<Self, Error<F>>

Prune historical operations prior to loc. This does not affect the db’s root.

prune requires no prior commit. After a crash, the database remains recoverable; uncommitted operations are not guaranteed to survive.

§Errors
Source

pub async fn rewind(self, size: Location<F>) -> Result<Self, Error<F>>

Rewind the database to size operations, where size is the location of the next append.

This rewinds both the operations journal and its Merkle structure to the historical state at size. The inactivity floor is restored from the rewind target commit operation, so the post-rewind floor matches the floor that was in effect at that commit.

§Errors

Any error from this method is fatal for this handle. Rewind may mutate journal state before this method finishes updating in-memory rewind state. Callers must drop this database handle after any Err from rewind and reopen from storage.

A successful rewind is not restart-stable until a subsequent Self::commit or Self::sync completes, or until the handle returned by a subsequent Self::start_sync completes.

Source

pub async fn sync(self) -> Result<Self, Error<F>>

Sync all database state to disk. While this isn’t necessary to ensure durability of committed operations, periodic invocation may reduce memory usage and the time required to recover the database on restart.

Source

pub async fn start_sync(self) -> Result<(Self, Handle<()>), Error<F>>

Begin durably persisting the journal state published by prior Keyless::apply_batch calls.

Awaiting the returned Handle provides the same durability guarantee as Self::commit, plus a best-effort attempt to bound the recovery needed on startup. Use Self::sync to guarantee none is needed. A new sync waits for the prior sync before starting. Failures of the deferred durability work surface on the returned handle. A failed data sync also fails the next durability operation. A failed recovery-watermark sync is not observed by Self::commit, and a failed merkle-node sync may not be. Both resurface on the next Self::sync.

Source

pub async fn commit(self) -> Result<Self, Error<F>>

Durably commit the journal state published by prior Keyless::apply_batch calls.

Source

pub async fn destroy(self) -> Result<(), Error<F>>

Destroy the db, removing all data from disk.

Source

pub fn new_batch(&self) -> UnmerkleizedBatch<F, H, V, S>

Create a new speculative batch of operations with this database as its parent.

Source

pub fn to_batch(&self) -> Arc<MerkleizedBatch<F, H::Digest, V, S>>

Create an initial batch::MerkleizedBatch from the committed DB state.

Source

pub fn validate_batch( &self, batch: &MerkleizedBatch<F, H::Digest, V, S>, ) -> Result<(), Error<F>>

Check that batch can be applied to the database in its current state, without applying it.

Self::apply_batch runs the same validation but consumes the database when it fails; callers that want to reject a bad batch and keep the handle can check first.

Source

pub async fn apply_batch( self, batch: Arc<MerkleizedBatch<F, H::Digest, V, S>>, ) -> Result<(Self, Range<Location<F>>), Error<F>>

Apply a batch::MerkleizedBatch to the database.

A batch is valid only if every batch applied to the database since this batch’s ancestor chain was created is an ancestor of this batch. Applying a batch from a different fork returns Error::StaleBatch (see crate::qmdb::batch_chain for more details).

Every commit operation in the batch chain (each unapplied ancestor’s commit plus the tip’s) must satisfy two per-commit invariants:

  1. The floor is monotonically non-decreasing across the chain, starting from the database’s current inactivity floor.
  2. The floor is at most the commit operation’s own location (total_size - 1 at that point). A floor past the commit would let a later prune(floor) remove the last readable commit from the journal.

Violations return Error::FloorRegressed or Error::FloorBeyondSize identifying the offending floor and the bound it crossed (the prior validated floor, or the commit location, respectively). Floor validation happens before any journal mutation, so on floor errors the on-disk state is unchanged and reopening recovers the database as it was.

Returns the range of locations written.

This publishes the batch to the in-memory database state and appends it to the journal. Call Keyless::commit or Keyless::sync, or await the handle returned by Keyless::start_sync, to make the applied state durable.

Trait Implementations§

Source§

impl<F, E, V, C, H, S> Database for Keyless<F, E, V, C, H, S>
where F: Family, E: Context, V: ValueEncoding + Codec, C: Mutable<Item = Operation<F, V>> + Journal<F, Context = E, Op = Operation<F, V>>, C::Config: Clone + Send, H: Hasher, S: Strategy, Operation<F, V>: EncodeShared,

Source§

async fn from_sync_result( context: Self::Context, config: Self::Config, log: Self::Journal, pinned_nodes: Option<Vec<Self::Digest>>, range: NonEmptyRange<Location<F>>, apply_batch_size: NonZeroU64, ) -> Result<Self, Error<F>>

Returns a Keyless db initialized from data collected in the sync process.

§Behavior

This method handles different initialization scenarios based on existing data:

  • If the Merkle journal is empty or the last item is before the range start, it creates a fresh Merkle structure from the provided pinned_nodes
  • If the Merkle journal has data but is incomplete (has length < range end), missing operations from the log are applied to bring it up to the target state
  • If the Merkle journal has data beyond the range end, it is rewound to match the sync target
§Returns

A Keyless db populated with the state from the given range.

Source§

type Family = F

Source§

type Op = Operation<F, V>

Source§

type Journal = C

Source§

type Hasher = H

Source§

type Config = Config<<C as Journal<F>>::Config, S>

Source§

type Digest = <H as Hasher>::Digest

Source§

type Context = E

Source§

async fn persist_sync_result(self) -> Result<Self, Error<F>>

Persist any state that must remain provisional until the engine verifies the rebuilt root. Read more
Source§

async fn local_pinned_nodes( context: Self::Context, config: &Self::Config, target: &Target<F, Self::Digest>, journal: &Self::Journal, ) -> Result<Option<Vec<Self::Digest>>, Error<F>>

Return locally available pinned nodes for the target, if persisted local state can authenticate them. Read more
Source§

fn root(&self) -> Self::Digest

Get the root digest of the database for verification
Source§

impl<F, E, V, C, H, S> Debug for Keyless<F, E, V, C, H, S>
where F: Family, E: Context, V: ValueEncoding, C: Mutable<Item = Operation<F, V>>, H: Hasher, S: Strategy, Operation<F, V>: EncodeShared,

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<F, E, V, C, H, S> Source for Keyless<F, E, V, C, H, S>
where F: Family, E: Context, V: ValueEncoding, C: Mutable<Item = Operation<F, V>>, H: Hasher, S: Strategy, Operation<F, V>: EncodeShared,

Source§

type Family = F

The merkle family backing this source’s proofs.
Source§

type Digest = <H as Hasher>::Digest

The digest type used in this source’s proofs.
Source§

type Op = Operation<F, V>

The type of operations this source yields.
Source§

type Error = Error<F>

Why this source could not answer.
Source§

async fn serve( &self, request: Request<F>, ) -> Result<(Response<F, Self::Op, Self::Digest>, FeedbackTx), Self::Error>

Serve a request.

Auto Trait Implementations§

§

impl<F, E, V, C, H, S> !RefUnwindSafe for Keyless<F, E, V, C, H, S>

§

impl<F, E, V, C, H, S> !UnwindSafe for Keyless<F, E, V, C, H, S>

§

impl<F, E, V, C, H, S> Freeze for Keyless<F, E, V, C, H, S>
where Journal<F, E, C, H, S>: Freeze, <H as Hasher>::Digest: Freeze, Location<F>: Freeze, Metrics<E>: Freeze,

§

impl<F, E, V, C, H, S> Send for Keyless<F, E, V, C, H, S>
where Journal<F, E, C, H, S>: Send, <H as Hasher>::Digest: Send, Location<F>: Send, Metrics<E>: Send,

§

impl<F, E, V, C, H, S> Sync for Keyless<F, E, V, C, H, S>
where Journal<F, E, C, H, S>: Sync, <H as Hasher>::Digest: Sync, Location<F>: Sync, Metrics<E>: Sync,

§

impl<F, E, V, C, H, S> Unpin for Keyless<F, E, V, C, H, S>
where Journal<F, E, C, H, S>: Unpin, <H as Hasher>::Digest: Unpin, Location<F>: Unpin, Metrics<E>: Unpin,

§

impl<F, E, V, C, H, S> UnsafeUnpin for Keyless<F, E, V, C, H, S>
where Journal<F, E, C, H, S>: UnsafeUnpin, <H as Hasher>::Digest: UnsafeUnpin, Location<F>: UnsafeUnpin, Metrics<E>: UnsafeUnpin,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FutureExt for T

Source§

fn with_context(self, otel_cx: Context) -> WithContext<Self>

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
Source§

fn with_current_context(self) -> WithContext<Self>

Attaches the current Context to this type, returning a WithContext wrapper. Read more
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<DB, S> SourceFor<DB> for S
where S: Source<Family = <DB as Database>::Family, Op = <DB as Database>::Op, Digest = <DB as Database>::Digest> + 'static, DB: Database,

Source§

impl<T> Threaded<T> for T

Source§

type Rest = ()

The outputs beyond the threaded value.
Source§

fn split(self) -> (T, ())

Splits into the threaded value and the extra outputs.
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more