tollgate-core
The zero-I/O domain layer of Tollgate: cost tables, compiled account snapshots, fenced local leases, and the reservation state machine that decides what a request is charged.
Every operation is a function of its arguments. There is no I/O, no clock read
(callers pass now), no blocking lock, and cost arithmetic is checked, never
wrapping. Unknown, expired, exhausted, or overflowing states deny; there is no
slower path to fall back to. That is what lets the layer sit inside a request
whose whole budget is a few microseconds.
Where it sits
Tollgate has two planes. The request path is this crate and
tollgate-admission; the
control plane is tollgate-client,
tollgate-server, and a
tollgate-store backend. Most
services embed Tollgate through tollgate-admission and tollgate-client;
this crate is the vocabulary they share.
Charging a request
A snapshot admits the account, a cost table quotes the work, a lease reserves the units, and the reservation either commits at execution start, charging the full quote whatever the outcome, or is cancelled before execution for zero.
use Arc;
use Timestamp;
use ;
// The embedder's operations, as dense indexes into the cost table.
let now = from_second.unwrap;
let expires = from_second.unwrap;
// One unit fixed per request, plus a per-item weight per operation.
let table = new;
let snapshot = builder
.build;
// A lease the control plane granted: 100 units, spent locally.
let lease = new;
snapshot.admit.expect;
let quote = table.quote.expect;
assert_eq!; // 1 fixed + 5 per item × 4
// Admission debits the lease, but the charge is only pending.
let reservation = reserve.expect;
assert_eq!;
// Execution start commits the full quote, for success, failure or timeout.
let charged = reservation
.commit_at_execution_start
.expect;
assert_eq!;
// A request that ends before execution is released for zero instead.
let early = reserve.expect;
assert!;
assert_eq!;
Commit and cancel race on one atomic transition, so exactly one wins.
Features
serde:Serialize/Deserializefor the wire-visible types: snapshots and cost tables, lease grants, usage events, deny reasons, budgets, identifiers, and units. Off by default.
Contract
The behaviour above is specified in
INVARIANTS.md,
where each invariant names the tests that enforce it, and parts are modelled in
Lean under formal/lean.
Rationale and history are in
docs/DESIGN.md.
License
MIT OR Apache-2.0, at your option. Tollgate is a product of MorphIQ Labs, a trade name of Prophetizo LLC.