1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
//! # rabs-cas — durable CAS, action cache, and publication transactions
//!
//! Owns immutable blob/pack/chunk storage, the action-cache index, object
//! lifecycle, and the coordinator-only atomic publication transaction
//! (invariants I8/I10/I15/I33; Epic H beads H001–H041).
//!
//! Core commitments encoded here as they land:
//!
//! - streaming digest verification and atomic `put_if_absent` (private temp
//! → verify → fsync per durability policy → atomic rename + directory
//! fsync; no partial path ever published; same-digest/different-bytes is a
//! collision **incident**, never a pick-one);
//! - logical object identity separate from stored representation
//! (`StoredRepresentationId`; risk R81) — raw/zstd/packed encodings
//! coexist without path ambiguity and never change action keys;
//! - deterministic small-object packs and content-defined chunk manifests,
//! acyclic and bounded (risk R95);
//! - pins/leases with authority-scoped monotonic renewal — expiry never
//! compares unsynchronized wall clocks (risk R127); workers can never
//! release a publication root;
//! - mark → tombstone → grace → recheck → unlink GC that provably preserves
//! pinned/reachable objects (risk R26/R58);
//! - scoped quarantine: location < logical object/manifest < action entry
//! (risk R51);
//! - metadata-store abstraction: reference SQLite-compatible backend is the
//! differential/crash truth; FrankenSQLite is dogfood, authoritative only
//! after passing the identical suite (risk R59);
//! - large object bytes never enter the metadata database; the database
//! never lives on NFS/shared mutable storage.
//!
//! ## Dependency rules (binding; enforced by dependency-direction CI, bead A002)
//!
//! - May depend on `rabs-protocol` (and, as Epic H lands, explicitly
//! reviewed pure digest/compression/storage crates).
//! - No direct Tokio or Asupersync dependency. Storage APIs are synchronous;
//! caller-side async adaptation happens in `rabs-asupersync`. The reviewed
//! FrankenSQLite backend encapsulates its runtime and worker lifecycle.
//! - Filesystem effects are this crate's business; network effects are not.
/// Public offer / ready-store builders for downstream live commit tests
/// (bd-g900u). Feature-gated; never compiled into a normal build.