pub struct CancelToken<'a> { /* private fields */ }Implementations§
Source§impl<'a> CancelToken<'a>
impl<'a> CancelToken<'a>
pub const fn none() -> Self
pub const fn from_flag(f: &'a AtomicBool) -> Self
Sourcepub const fn with_deadline(
self,
now_fn: MonotonicNowFn,
deadline_us: u64,
) -> Self
pub const fn with_deadline( self, now_fn: MonotonicNowFn, deadline_us: u64, ) -> Self
v7.17.0 Phase 2.3 — attach a monotonic deadline. now_fn
must return microseconds since a stable origin; the token
trips when now_fn() >= deadline_us. Compose with
from_flag(...) when both a watchdog flag and a per-statement
timeout are in play (e.g. server-wide SPG_QUERY_TIMEOUT_MS
plus session statement_timeout); the tighter of the two
wins by virtue of either signaling first.
pub fn is_cancelled(self) -> bool
Sourcepub fn check(self) -> Result<(), EngineError>
pub fn check(self) -> Result<(), EngineError>
Returns Err(Cancelled) if the token has been tripped.
Used at row-loop checkpoints to bail cooperatively without
scattering raw is_cancelled checks across the executor.
Sourcepub fn check_with_budget(
self,
last_check_us: &mut u64,
budget_us: u64,
) -> Result<(), EngineError>
pub fn check_with_budget( self, last_check_us: &mut u64, budget_us: u64, ) -> Result<(), EngineError>
v7.37.14 (B2.3 [PG+]) — time-budgeted cooperative cancel
check. PG’s CHECK_FOR_INTERRUPTS is per-tuple-count: the
scanning loop calls it every N rows. That bounds latency to
“N tuple processing time”, which on a wide-row scan can
stretch into seconds before a Ctrl-C is honoured.
SPG goes past that with a time-budget variant: callers
thread a last_check_us cursor through the loop and the
helper guarantees the underlying full check (flag +
deadline) fires at most budget_us after the previous one,
regardless of tuple count. 100ms is the recommended budget;
it bounds cancel-surface latency to that wall-clock window
even on a single-tuple-takes-seconds path (large aggregate
over a wide column, deep recursive CTE, etc.).
last_check_us MUST be initialised to 0 by the caller and
is updated in place when a real check runs (so the first
call always falls through to a real check). With no
deadline attached this method is a no-op — the budget only
kicks in when there’s a deadline that could trip.
Hot-path overhead: one monotonic clock read (~20 ns vDSO)
- one u64 subtraction. The full check fires only every budget window, so per-tuple cost stays in the single-digit nanoseconds.
§Errors
Same as Self::check — EngineError::Cancelled if the
underlying flag or deadline has tripped.
Trait Implementations§
Source§impl<'a> Clone for CancelToken<'a>
impl<'a> Clone for CancelToken<'a>
Source§fn clone(&self) -> CancelToken<'a>
fn clone(&self) -> CancelToken<'a>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more