1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
//! [`SnapshotBound`] — what a continuity snapshot's time bound turned out to be.
use ;
/// The outcome of checking a continuity snapshot's time bound.
///
/// # Why this is not a boolean
///
/// The signatures on an expired snapshot are **fine**. Reporting it as invalid
/// would be misleading — it would send a reader looking for tampering that did
/// not happen — and reporting it as valid would be wrong. There is no third
/// boolean, so there is no boolean.
///
/// The failure this shape exists to prevent is a caller collapsing the cases at
/// its first `if`, which is why there is deliberately **no `is_valid()`**. Two
/// different questions get asked of a snapshot and only the caller can know
/// which one it means:
///
/// - *is a bound claimed here, and does it hold?* — answered by matching.
/// - *may this copy be served?* — depends on where the copy came from, which
/// this crate cannot see. A live read legitimately carries no bound
/// ([`Self::Absent`]); a copy off the static tier that carries none has had
/// its bound stripped, and those two are the same value here.
///
/// So an `is_valid()` would have to guess the caller's question, and whichever
/// it guessed would be silently wrong for the other one.