pub struct ProtocolEngine {
pub batch_depth: Cell<u32>,
pub batch_persist_dirty: Cell<bool>,
/* private fields */
}Fields§
§batch_depth: Cell<u32>While > 0, persist() only flips batch_persist_dirty instead of
serializing+writing. AppCore wraps catch-up bursts and other
multi-event entry points so an N-event burst issues one persist
instead of N. The exclusive SQLite write under iOS DELETE-mode
journaling can keep UI reads blocked on the connection mutex for
hundreds of ms each — N of them stacked produced the multi-second
foreground freeze.
batch_persist_dirty: Cell<bool>Implementations§
§impl ProtocolEngine
impl ProtocolEngine
pub fn load_or_create_for_local_device( storage: Arc<dyn StorageAdapter>, owner_pubkey: PublicKey, device_keys: &Keys, ) -> Result<Self>
pub fn debug_snapshot(&self) -> ProtocolEngineDebugSnapshot
pub fn is_known_local_owner_device(&self, device_pubkey: PublicKey) -> bool
pub fn owner_hint_for_device( &self, device_pubkey: PublicKey, ) -> Option<ProtocolDeviceOwnerHint>
pub fn has_pending_inbound_direct_events(&self) -> bool
pub fn has_pending_retry_work(&self) -> bool
pub fn has_pending_inbound_direct_event_id(&self, event_id: &str) -> bool
pub fn queued_owner_claim_targets(&self) -> Vec<String>
pub fn direct_send_readiness( &self, peer_pubkey: PublicKey, ) -> DirectSendReadiness
pub fn authenticate_local_owner_for_sending( &mut self, owner_keys: &Keys, ) -> Result<()>
pub fn local_invite(&self) -> Option<Invite>
pub fn local_invite_response_pubkey(&self) -> Option<PublicKey>
Walks every session and returns its expected event-author
pubkeys, but only for sessions whose peer owner passes the
accept_owner predicate. The owner-aware variant lets the
caller drop blocked / non-accepted peers from the subscription
filter without losing the device-ephemeral keys that nostr
actually filters on.
pub fn known_group_sender_event_pubkeys(&self) -> Vec<PublicKey>
pub fn group_sender_event_pubkeys_for_owner( &self, owner: PublicKey, ) -> Vec<PublicKey>
pub fn group_sender_event_pubkeys_for_group( &self, group_id: &str, ) -> Vec<PublicKey>
pub fn is_potential_group_sender_key_event(&self, event: &Event) -> bool
pub fn is_group_sender_key_candidate_with_local_group_context( &self, event: &Event, ) -> bool
pub fn header_message_sender_has_verified_owner(&self, event: &Event) -> bool
pub fn header_message_sender_has_tracked_session(&self, event: &Event) -> bool
pub fn known_device_identity_pubkeys_for_owner( &self, owner_pubkey: PublicKey, ) -> Vec<PublicKey>
pub fn known_device_identity_pubkeys_for_owner_with_snapshot( &self, snapshot: &SessionManagerSnapshot, owner_pubkey: PublicKey, ) -> Vec<PublicKey>
pub fn session_manager_snapshot(&self) -> SessionManagerSnapshot
pub fn session_manager_snapshot(&self) -> SessionManagerSnapshot
SessionManager::snapshot clones every user record + every
device state — the runtime debug builder fans out per known
user, so callers that hit multiple owners in one pass must
share a single snapshot via the _with_snapshot helpers
below instead of paying that clone cost per owner.
pub fn message_session_debug_snapshots_with_snapshot( snapshot: &SessionManagerSnapshot, owner_pubkey: PublicKey, ) -> Vec<ProtocolMessageSessionDebugSnapshot>
pub fn verified_message_session_snapshots_for_owner( &self, owner_pubkey: PublicKey, ) -> Vec<ProtocolMessageSessionDebugSnapshot>
pub fn active_session_count_for_owner_with_snapshot( snapshot: &SessionManagerSnapshot, owner_pubkey: PublicKey, ) -> usize
pub fn active_session_count_for_owner(&self, owner_pubkey: PublicKey) -> usize
pub fn active_roster_session_count_for_owner( &self, owner_pubkey: PublicKey, ) -> usize
pub fn active_roster_session_count_for_owner_with_snapshot( &self, snapshot: &SessionManagerSnapshot, owner_pubkey: PublicKey, ) -> usize
pub fn owner_device_binding_is_verified( &self, owner_pubkey: PublicKey, device_pubkey: PublicKey, ) -> bool
pub fn known_verified_peer_owner_pubkeys(&self) -> Vec<PublicKey>
pub fn has_delivery_blocking_message_work(&self, message_id: &str) -> bool
§impl ProtocolEngine
impl ProtocolEngine
pub fn session_manager_snapshot_for_test(&self) -> SessionManagerSnapshot
pub fn group_manager_snapshot_for_test(&self) -> GroupManagerSnapshot
pub fn pending_inbound_for_test(&self) -> Vec<ProtocolPendingInboundTestDebug>
pub fn pending_decrypted_deliveries_len_for_test(&self) -> usize
§impl ProtocolEngine
impl ProtocolEngine
pub fn install_device_sync_group(
&mut self,
snapshot: GroupSnapshot,
) -> Result<bool>
pub fn install_device_sync_group( &mut self, snapshot: GroupSnapshot, ) -> Result<bool>
Install metadata copied from an authenticated sibling device. Signed roster facts can advance this copy, but restoring removed membership requires a newer revision.
pub fn ingest_group_roster_fact_event( &mut self, event: &Event, ) -> Result<Option<ProtocolGroupRosterIngestionResult>>
§impl ProtocolEngine
impl ProtocolEngine
pub fn ingest_app_keys_snapshot( &mut self, owner_pubkey: PublicKey, app_keys: AppKeys, created_at: u64, ) -> Result<ProtocolRetryBatch>
pub fn ingest_app_keys_event( &mut self, event: &Event, ) -> Result<ProtocolRetryBatch>
pub fn observe_invite_event( &mut self, event: &Event, ) -> Result<ProtocolRetryBatch>
pub fn observe_invite_response_event( &mut self, event: &Event, ) -> Result<ProtocolRetryBatch>
pub fn accept_invite( &mut self, invite: &Invite, owner_pubkey_hint: Option<PublicKey>, ) -> Result<ProtocolAcceptInviteOutcome>
pub fn import_session_state( &mut self, peer_pubkey: PublicKey, device_id: Option<String>, state: SessionState, now: UnixSeconds, ) -> Result<ProtocolRetryBatch>
pub fn create_group( &mut self, name: String, member_owners: Vec<PublicKey>, now: UnixSeconds, ) -> Result<ProtocolGroupSendResult>
pub fn update_group_name( &mut self, group_id: &str, name: String, ) -> Result<ProtocolGroupSendResult>
pub fn update_group_picture( &mut self, group_id: &str, picture: Option<String>, ) -> Result<ProtocolGroupSendResult>
pub fn update_group_about( &mut self, group_id: &str, about: Option<String>, ) -> Result<ProtocolGroupSendResult>
pub fn add_group_members( &mut self, group_id: &str, members: Vec<PublicKey>, ) -> Result<ProtocolGroupSendResult>
pub fn remove_group_member( &mut self, group_id: &str, member: PublicKey, ) -> Result<ProtocolGroupSendResult>
pub fn set_group_admin( &mut self, group_id: &str, member: PublicKey, is_admin: bool, ) -> Result<ProtocolGroupSendResult>
pub fn send_group_payload( &mut self, group_id: &str, payload: Vec<u8>, inner_event_id: Option<String>, ) -> Result<ProtocolGroupSendResult>
pub fn send_direct_text( &mut self, peer_pubkey: PublicKey, chat_id: &str, text: &str, expires_at_secs: Option<u64>, now: UnixSeconds, ) -> Result<ProtocolDirectSendResult>
pub fn send_direct_text_created_at(
&mut self,
peer_pubkey: PublicKey,
chat_id: &str,
text: &str,
expires_at_secs: Option<u64>,
created_at: UnixSeconds,
now: UnixSeconds,
) -> Result<ProtocolDirectSendResult>
pub fn send_direct_text_created_at( &mut self, peer_pubkey: PublicKey, chat_id: &str, text: &str, expires_at_secs: Option<u64>, created_at: UnixSeconds, now: UnixSeconds, ) -> Result<ProtocolDirectSendResult>
Keep the authored time separate from the transport/retry clock.
pub fn send_direct_unsigned_event( &mut self, peer_pubkey: PublicKey, chat_id: &str, rumor: UnsignedEvent, now: UnixSeconds, ) -> Result<ProtocolDirectSendResult>
pub fn send_direct_unsigned_event_to_peer_only( &mut self, peer_pubkey: PublicKey, chat_id: &str, rumor: UnsignedEvent, now: UnixSeconds, ) -> Result<ProtocolDirectSendResult>
pub fn send_local_sibling_unsigned_event( &mut self, conversation_owner: PublicKey, chat_id: &str, rumor: UnsignedEvent, now: UnixSeconds, ) -> Result<ProtocolDirectSendResult>
§impl ProtocolEngine
impl ProtocolEngine
pub fn retire_pending_local_sibling_events(
&mut self,
matches: impl Fn(PublicKey, &UnsignedEvent) -> bool,
) -> Result<usize>
pub fn retire_pending_local_sibling_events( &mut self, matches: impl Fn(PublicKey, &UnsignedEvent) -> bool, ) -> Result<usize>
Retire matching plaintext sibling intents, including intents waiting for roster discovery. Already sealed events and all other queues are untouched. Callers must durably migrate the source data first and must not expose this engine for sending if retirement fails.
Source§impl ProtocolEngine
impl ProtocolEngine
pub fn import_private_invite_session_once( &mut self, response_event_id: &str, owner_pubkey: PublicKey, authenticated_device: PublicKey, state: SessionState, now: UnixSeconds, ) -> Result<ProtocolInviteSessionImportOutcome>
Reads only existing protocol state and checks exact signed AppKeys evidence. It never creates protocol state or treats a generic cached roster projection as authorization.
§impl ProtocolEngine
impl ProtocolEngine
Whether retained, verified identity-signed evidence authorizes this device.
pub fn ingest_invite_response_owner_proof(
&mut self,
invite: &Invite,
response: &Event,
claimed_owner: PublicKey,
authenticated_device: PublicKey,
) -> Result<ProtocolRetryBatch>
pub fn ingest_invite_response_owner_proof( &mut self, invite: &Invite, response: &Event, claimed_owner: PublicKey, authenticated_device: PublicKey, ) -> Result<ProtocolRetryBatch>
Read the account-signed authorization carried by a successfully decrypted handshake. The caller supplies the owner and device authenticated by that handshake, so unrelated signed records cannot establish its sender.
§impl ProtocolEngine
impl ProtocolEngine
pub fn has_device_roster_entry_for_owner( &self, owner_pubkey: PublicKey, device_pubkey: PublicKey, ) -> bool
§impl ProtocolEngine
impl ProtocolEngine
pub fn message_targets_another_device(&self, event: &Event) -> bool
pub fn message_targets_another_device(&self, event: &Event) -> bool
Shared bootstrap authors can expose ciphertext addressed to other devices. Untargeted legacy messages and group broadcasts remain eligible.
pub fn has_due_pending_retry_work(&self, now: NdrUnixSeconds) -> bool
pub fn process_direct_message_event( &mut self, event: &Event, ) -> Result<Option<ProtocolDecryptedMessage>>
pub fn process_group_outer_event( &mut self, event: &Event, ) -> Result<ProtocolGroupIncomingResult>
pub fn process_group_pairwise_payload( &mut self, payload: &[u8], from_owner_pubkey: PublicKey, from_sender_device_pubkey: Option<PublicKey>, ) -> Result<ProtocolGroupIncomingResult>
pub fn process_local_sibling_group_pairwise_payload( &mut self, payload: &[u8], from_owner_pubkey: PublicKey, from_sender_device_pubkey: Option<PublicKey>, ) -> Result<ProtocolGroupIncomingResult>
pub fn retry_pending_protocol( &mut self, now: NdrUnixSeconds, ) -> Result<ProtocolRetryBatch>
pub fn ack_pending_decrypted_deliveries(&mut self) -> Result<()>
pub fn ack_decrypted_delivery_ids(
&mut self,
event_ids: &HashSet<String>,
) -> Result<()>
pub fn ack_decrypted_delivery_ids( &mut self, event_ids: &HashSet<String>, ) -> Result<()>
Only acknowledge deliveries that the application has durably applied. Other saves must not discard plaintext waiting for its first delivery.