pub struct PostureOwner { /* private fields */ }Expand description
The ONE owner of a fleet posture state machine — a shared, thread-safe
shell around the pure PostureStateMachine. Every consumer (every
FleetHost, the block pump’s throttle feed, tests) consults THE SAME
instance, so there is exactly one posture per process (per hermetic
test scope) and no host-local mirrors to drift apart.
Sync: the machine sits behind a parking_lot::Mutex — every consult is
a short read-through critical section, never held across an await
(the crate has none); the transition feed is the PostureWatch
broadcast above.
Implementations§
Source§impl PostureOwner
impl PostureOwner
Sourcepub fn new(policy: PosturePolicy) -> Self
pub fn new(policy: PosturePolicy) -> Self
A fresh owner in FleetPosture::Nominal. Hermetic tests build
their own owner and inject it via FleetBoot::owner — NEVER the
process global (process/install_process_owner); posture
leaking across tests is a failure class (7KAPBB).
Sourcepub fn observe_throttle(
&self,
now_ms: u64,
sample: ThrottleSample,
) -> PostureChange
pub fn observe_throttle( &self, now_ms: u64, sample: ThrottleSample, ) -> PostureChange
Feed one throttle-poll delta. Publishes to the feed ONLY on a real
transition (Held ticks are silent — a subscriber never sees a
spurious edge).
§Feeder-site contract (TB4QGX T3, ADR-044)
A BOT-side caller of this method MUST also wake the fleet hosts on a
non-Held change (the degenbot-bot host waker,
arb_engine::fleet_wake::wake_hosts), which emits ONE untrusted,
seq-stamped PostureEdge per host. This crate cannot know about host
channels (layering), so the wake is the caller’s obligation; the
host’s BackstopTick bounds the damage if a feeder forgets, and the
hint never carries a posture value — hosts re-read the live owner.
Sourcepub fn observe_cause(&self, cause: PostureCause) -> PostureChange
pub fn observe_cause(&self, cause: PostureCause) -> PostureChange
Feed one typed non-throttle cause (FF-T4, Z6XTDX). Publishes to
the feed on a real transition like Self::observe_throttle
(an idempotent hold-upgrade returns Held and stays silent —
the detection site owns the loud lane-death log).
§Feeder-site contract (TB4QGX T3, ADR-044)
A BOT-side caller of this method MUST also wake the fleet hosts on a
non-Held change; see Self::observe_throttle. On the lane-death
(Faulted) arm the wake still fires, and the host drains its held
receipts terminally instead of parking them.
Sourcepub fn current(&self) -> FleetPosture
pub fn current(&self) -> FleetPosture
The current posture.
Sourcepub fn policy(&self) -> PosturePolicy
pub fn policy(&self) -> PosturePolicy
The active policy (read-through; the Part B operator channel reads and re-tunes through here).
Sourcepub fn subscribe(&self) -> PostureWatch
pub fn subscribe(&self) -> PostureWatch
Subscribe a watch: the receiver starts at the CURRENT posture with no pending edge (it observes only transitions from here on).
Sourcepub fn retune(&self, new_policy: PosturePolicy)
pub fn retune(&self, new_policy: PosturePolicy)
Swap the policy (the Part B operator channel’s entry point). The
swap is atomic under the machine lock and keeps the state + the
trailing sample window; the feed re-publishes the current posture
so it mirrors the machine post-swap (a no-op unless the posture
itself changed — the feed carries only real transitions, and the
next observe_throttle re-derives the posture under the new
thresholds). Semantic validation of the new policy is the caller’s
job.
Sourcepub fn admits_lease(&self, class: CordonClass) -> bool
pub fn admits_lease(&self, class: CordonClass) -> bool
Whether the posture admits new lease intake for class right now
(read-through — the dispatcher’s enqueue/T-table gates and the seat
hosts’ admission all consult this).
Sourcepub fn note_intake_suppressed(&self)
pub fn note_intake_suppressed(&self)
Count a lease grant denied because of the posture (read-through — the tuning loop’s suppression metric).
Sourcepub fn sim_intake_cap(&self, slot_cap: usize) -> usize
pub fn sim_intake_cap(&self, slot_cap: usize) -> usize
The sim intake cap in the current posture (read-through).
Sourcepub fn counters(&self) -> PostureCounters
pub fn counters(&self) -> PostureCounters
Loud-transition counters snapshot (the tuning loop’s metrics).
Sourcepub fn lane_death_held(&self) -> bool
pub fn lane_death_held(&self) -> bool
The sticky lane-death hold (read-through). A host keys its Faulted transition on this TYPED latch, never on elapsed cordon time (a long recoverable EventBurst/Duty cordon must not fault).
Trait Implementations§
Auto Trait Implementations§
impl !Freeze for PostureOwner
impl !RefUnwindSafe for PostureOwner
impl !UnwindSafe for PostureOwner
impl Send for PostureOwner
impl Sync for PostureOwner
impl Unpin for PostureOwner
impl UnsafeUnpin for PostureOwner
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more