pub struct Keyless<F, E, V, C, H, S>where
F: Family,
E: Context,
V: ValueEncoding,
C: Contiguous<Item = Operation<F, V>>,
H: Hasher,
S: Strategy,
Operation<F, V>: EncodeShared,{ /* private fields */ }Expand description
A keyless authenticated database.
Implementations§
Source§impl<F: Family, E: Context, V: FixedValue, H: Hasher, S: Strategy> Keyless<F, E, FixedEncoding<V>, Journal<E, Operation<F, FixedEncoding<V>>>, H, S>
impl<F: Family, E: Context, V: FixedValue, H: Hasher, S: Strategy> Keyless<F, E, FixedEncoding<V>, Journal<E, Operation<F, FixedEncoding<V>>>, H, S>
Source§impl<F: Family, E: Context, V: VariableValue, H: Hasher, S: Strategy> Keyless<F, E, VariableEncoding<V>, Journal<E, Operation<F, VariableEncoding<V>>>, H, S>
impl<F: Family, E: Context, V: VariableValue, H: Hasher, S: Strategy> Keyless<F, E, VariableEncoding<V>, Journal<E, Operation<F, VariableEncoding<V>>>, H, S>
Source§impl<F, E, V, C, H, S> Keyless<F, E, V, C, H, S>where
F: Family,
E: Context,
V: ValueEncoding,
C: Mutable<Item = Operation<F, V>>,
H: Hasher,
S: Strategy,
Operation<F, V>: EncodeShared,
impl<F, E, V, C, H, S> Keyless<F, E, V, C, H, S>where
F: Family,
E: Context,
V: ValueEncoding,
C: Mutable<Item = Operation<F, V>>,
H: Hasher,
S: Strategy,
Operation<F, V>: EncodeShared,
Sourcepub async fn get(&self, loc: Location<F>) -> Result<Option<V::Value>, Error<F>>
pub async fn get(&self, loc: Location<F>) -> Result<Option<V::Value>, Error<F>>
Get the value at location loc in the database.
§Errors
Returns Error::LocationOutOfBounds if loc >=
self.bounds().end.
Sourcepub async fn get_many(
&self,
locs: &[Location<F>],
) -> Result<Vec<Option<V::Value>>, Error<F>>
pub async fn get_many( &self, locs: &[Location<F>], ) -> Result<Vec<Option<V::Value>>, Error<F>>
Batch read values at multiple locations.
Locations must be strictly increasing. Returns results in the same order as the input locations.
§Errors
Returns Error::LocationOutOfBounds if any location >= bounds().end.
Sourcepub const fn last_commit_loc(&self) -> Location<F>
pub const fn last_commit_loc(&self) -> Location<F>
Returns the location of the last commit.
Sourcepub const fn inactivity_floor_loc(&self) -> Location<F>
pub const fn inactivity_floor_loc(&self) -> Location<F>
Returns the inactivity floor declared by the last committed batch.
Sourcepub fn bounds(&self) -> Range<Location<F>> ⓘ
pub fn bounds(&self) -> Range<Location<F>> ⓘ
Return [start, end) where start and end - 1 are the Locations of the oldest and newest
retained operations respectively.
Sourcepub const fn sync_boundary(&self) -> Location<F>
pub const fn sync_boundary(&self) -> Location<F>
Return the most recent location from which this database can safely be synced, and the
upper bound on Self::prune’s loc. For keyless databases, this equals the
inactivity floor declared by the last committed batch.
Sourcepub async fn get_metadata(&self) -> Result<Option<V::Value>, Error<F>>
pub async fn get_metadata(&self) -> Result<Option<V::Value>, Error<F>>
Get the metadata associated with the last commit.
Sourcepub async fn proof(
&self,
start_loc: Location<F>,
max_ops: NonZeroU64,
) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>
pub async fn proof( &self, start_loc: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>
Generate and return:
- a proof of all operations applied to the db in the range starting at (and including)
location
start_loc, and ending at the first of either:- the last operation performed, or
- the operation
max_opsfrom the start.
- the operations corresponding to the leaves in this range.
§Errors
- Returns
Error::Merklewithcrate::merkle::Error::RangeOutOfBoundsifstart_loc= the number of operations.
- Returns
Error::Journalwithcrate::journal::Error::ItemPrunedifstart_lochas been pruned.
Sourcepub async fn historical_proof(
&self,
op_count: Location<F>,
start_loc: Location<F>,
max_ops: NonZeroU64,
) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>
pub async fn historical_proof( &self, op_count: Location<F>, start_loc: Location<F>, max_ops: NonZeroU64, ) -> Result<(Proof<F, H::Digest>, Vec<Operation<F, V>>), Error<F>>
Analogous to proof, but with respect to the state of the Merkle structure when it had
op_count operations.
op_count must be the size of a commit boundary.
§Errors
- Returns
Error::Merklewithcrate::merkle::Error::RangeOutOfBoundsifstart_loc=
op_countorop_count> number of operations. - Returns
Error::Journalwithcrate::journal::Error::ItemPrunedifstart_lochas been pruned. - Returns
Error::HistoricalFloorPrunedifop_count - 1is retained but is not a commit op.
Sourcepub async fn pinned_nodes_at(
&self,
loc: Location<F>,
) -> Result<Vec<H::Digest>, Error<F>>
pub async fn pinned_nodes_at( &self, loc: Location<F>, ) -> Result<Vec<H::Digest>, Error<F>>
Return the pinned Merkle nodes for a lower operation boundary of loc.
Sourcepub async fn prune(self, loc: Location<F>) -> Result<Self, Error<F>>
pub async fn prune(self, loc: Location<F>) -> Result<Self, Error<F>>
Prune historical operations prior to loc. This does not affect the db’s root.
prune requires no prior commit. After a crash, the database remains recoverable;
uncommitted operations are not guaranteed to survive.
§Errors
- Returns
Error::PruneBeyondMinRequiredifloc> the inactivity floor.
Sourcepub async fn rewind(self, size: Location<F>) -> Result<Self, Error<F>>
pub async fn rewind(self, size: Location<F>) -> Result<Self, Error<F>>
Rewind the database to size operations, where size is the location of the next append.
This rewinds both the operations journal and its Merkle structure to the historical state
at size. The inactivity floor is restored from the rewind target commit operation, so
the post-rewind floor matches the floor that was in effect at that commit.
§Errors
- Returns
Error::Journalwithcrate::journal::Error::InvalidRewindifsizeis 0 or exceeds the current committed size. - Returns
Error::Journalwithcrate::journal::Error::ItemPrunedif the operation atsize - 1has been pruned. - Returns
Error::UnexpectedDataif the operation atsize - 1is not a commit.
Any error from this method is fatal for this handle. Rewind may mutate journal state
before this method finishes updating in-memory rewind state. Callers must drop this
database handle after any Err from rewind and reopen from storage.
A successful rewind is not restart-stable until a subsequent Self::commit or
Self::sync completes, or until the handle returned by a subsequent
Self::start_sync completes.
Sourcepub async fn sync(self) -> Result<Self, Error<F>>
pub async fn sync(self) -> Result<Self, Error<F>>
Sync all database state to disk. While this isn’t necessary to ensure durability of committed operations, periodic invocation may reduce memory usage and the time required to recover the database on restart.
Sourcepub async fn start_sync(self) -> Result<(Self, Handle<()>), Error<F>>
pub async fn start_sync(self) -> Result<(Self, Handle<()>), Error<F>>
Begin durably persisting the journal state published by prior Keyless::apply_batch
calls.
Awaiting the returned Handle provides the same durability guarantee as Self::commit, plus a best-effort attempt to bound the recovery needed on startup. Use Self::sync to guarantee none is needed. A new sync waits for the prior sync before starting. Failures of the deferred durability work surface on the returned handle. A failed data sync also fails the next durability operation. A failed recovery-watermark sync is not observed by Self::commit, and a failed merkle-node sync may not be. Both resurface on the next Self::sync.
Sourcepub async fn commit(self) -> Result<Self, Error<F>>
pub async fn commit(self) -> Result<Self, Error<F>>
Durably commit the journal state published by prior Keyless::apply_batch calls.
Sourcepub async fn destroy(self) -> Result<(), Error<F>>
pub async fn destroy(self) -> Result<(), Error<F>>
Destroy the db, removing all data from disk.
Sourcepub fn new_batch(&self) -> UnmerkleizedBatch<F, H, V, S>
pub fn new_batch(&self) -> UnmerkleizedBatch<F, H, V, S>
Create a new speculative batch of operations with this database as its parent.
Sourcepub fn to_batch(&self) -> Arc<MerkleizedBatch<F, H::Digest, V, S>> ⓘ
pub fn to_batch(&self) -> Arc<MerkleizedBatch<F, H::Digest, V, S>> ⓘ
Create an initial batch::MerkleizedBatch from the committed DB state.
Sourcepub fn validate_batch(
&self,
batch: &MerkleizedBatch<F, H::Digest, V, S>,
) -> Result<(), Error<F>>
pub fn validate_batch( &self, batch: &MerkleizedBatch<F, H::Digest, V, S>, ) -> Result<(), Error<F>>
Check that batch can be applied to the database in its current state, without
applying it.
Self::apply_batch runs the same validation but consumes the database when it
fails; callers that want to reject a bad batch and keep the handle can check first.
Sourcepub async fn apply_batch(
self,
batch: Arc<MerkleizedBatch<F, H::Digest, V, S>>,
) -> Result<(Self, Range<Location<F>>), Error<F>>
pub async fn apply_batch( self, batch: Arc<MerkleizedBatch<F, H::Digest, V, S>>, ) -> Result<(Self, Range<Location<F>>), Error<F>>
Apply a batch::MerkleizedBatch to the database.
A batch is valid only if every batch applied to the database since this batch’s
ancestor chain was created is an ancestor of this batch. Applying a batch from a
different fork returns Error::StaleBatch (see crate::qmdb::batch_chain for
more details).
Every commit operation in the batch chain (each unapplied ancestor’s commit plus the tip’s) must satisfy two per-commit invariants:
- The floor is monotonically non-decreasing across the chain, starting from the database’s current inactivity floor.
- The floor is at most the commit operation’s own location (
total_size - 1at that point). A floor past the commit would let a laterprune(floor)remove the last readable commit from the journal.
Violations return Error::FloorRegressed or Error::FloorBeyondSize identifying
the offending floor and the bound it crossed (the prior validated floor, or the commit
location, respectively). Floor validation happens before any journal mutation, so on floor
errors the on-disk state is unchanged and reopening recovers the database as it was.
Returns the range of locations written.
This publishes the batch to the in-memory database state and appends it to the journal.
Call Keyless::commit or Keyless::sync, or await the handle returned by
Keyless::start_sync, to make the applied state durable.
Trait Implementations§
Source§impl<F, E, V, C, H, S> Database for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> Database for Keyless<F, E, V, C, H, S>
Source§async fn from_sync_result(
context: Self::Context,
config: Self::Config,
log: Self::Journal,
pinned_nodes: Option<Vec<Self::Digest>>,
range: NonEmptyRange<Location<F>>,
apply_batch_size: NonZeroU64,
) -> Result<Self, Error<F>>
async fn from_sync_result( context: Self::Context, config: Self::Config, log: Self::Journal, pinned_nodes: Option<Vec<Self::Digest>>, range: NonEmptyRange<Location<F>>, apply_batch_size: NonZeroU64, ) -> Result<Self, Error<F>>
Returns a Keyless db initialized from data collected in the sync process.
§Behavior
This method handles different initialization scenarios based on existing data:
- If the Merkle journal is empty or the last item is before the range start, it creates
a fresh Merkle structure from the provided
pinned_nodes - If the Merkle journal has data but is incomplete (has length < range end), missing operations from the log are applied to bring it up to the target state
- If the Merkle journal has data beyond the range end, it is rewound to match the sync target
§Returns
A Keyless db populated with the state from the given range.
type Family = F
type Op = Operation<F, V>
type Journal = C
type Hasher = H
type Config = Config<<C as Journal<F>>::Config, S>
type Digest = <H as Hasher>::Digest
type Context = E
Source§async fn persist_sync_result(self) -> Result<Self, Error<F>>
async fn persist_sync_result(self) -> Result<Self, Error<F>>
Source§async fn local_pinned_nodes(
context: Self::Context,
config: &Self::Config,
target: &Target<F, Self::Digest>,
journal: &Self::Journal,
) -> Result<Option<Vec<Self::Digest>>, Error<F>>
async fn local_pinned_nodes( context: Self::Context, config: &Self::Config, target: &Target<F, Self::Digest>, journal: &Self::Journal, ) -> Result<Option<Vec<Self::Digest>>, Error<F>>
Source§impl<F, E, V, C, H, S> Debug for Keyless<F, E, V, C, H, S>where
F: Family,
E: Context,
V: ValueEncoding,
C: Mutable<Item = Operation<F, V>>,
H: Hasher,
S: Strategy,
Operation<F, V>: EncodeShared,
impl<F, E, V, C, H, S> Debug for Keyless<F, E, V, C, H, S>where
F: Family,
E: Context,
V: ValueEncoding,
C: Mutable<Item = Operation<F, V>>,
H: Hasher,
S: Strategy,
Operation<F, V>: EncodeShared,
Auto Trait Implementations§
impl<F, E, V, C, H, S> !RefUnwindSafe for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> !UnwindSafe for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> Freeze for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> Send for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> Sync for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> Unpin for Keyless<F, E, V, C, H, S>
impl<F, E, V, C, H, S> UnsafeUnpin for Keyless<F, E, V, C, H, S>where
Journal<F, E, C, H, S>: UnsafeUnpin,
<H as Hasher>::Digest: UnsafeUnpin,
Location<F>: UnsafeUnpin,
Metrics<E>: UnsafeUnpin,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
Source§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more