Skip to main content

PostureOwner

Struct PostureOwner 

Source
pub struct PostureOwner { /* private fields */ }
Expand description

The ONE owner of a fleet posture state machine — a shared, thread-safe shell around the pure PostureStateMachine. Every consumer (every FleetHost, the block pump’s throttle feed, tests) consults THE SAME instance, so there is exactly one posture per process (per hermetic test scope) and no host-local mirrors to drift apart.

Sync: the machine sits behind a parking_lot::Mutex — every consult is a short read-through critical section, never held across an await (the crate has none); the transition feed is the PostureWatch broadcast above.

Implementations§

Source§

impl PostureOwner

Source

pub fn new(policy: PosturePolicy) -> Self

A fresh owner in FleetPosture::Nominal. Hermetic tests build their own owner and inject it via FleetBoot::owner — NEVER the process global (process/install_process_owner); posture leaking across tests is a failure class (7KAPBB).

Source

pub fn observe_throttle( &self, now_ms: u64, sample: ThrottleSample, ) -> PostureChange

Feed one throttle-poll delta. Publishes to the feed ONLY on a real transition (Held ticks are silent — a subscriber never sees a spurious edge).

§Feeder-site contract (TB4QGX T3, ADR-044)

A BOT-side caller of this method MUST also wake the fleet hosts on a non-Held change (the degenbot-bot host waker, arb_engine::fleet_wake::wake_hosts), which emits ONE untrusted, seq-stamped PostureEdge per host. This crate cannot know about host channels (layering), so the wake is the caller’s obligation; the host’s BackstopTick bounds the damage if a feeder forgets, and the hint never carries a posture value — hosts re-read the live owner.

Source

pub fn observe_cause(&self, cause: PostureCause) -> PostureChange

Feed one typed non-throttle cause (FF-T4, Z6XTDX). Publishes to the feed on a real transition like Self::observe_throttle (an idempotent hold-upgrade returns Held and stays silent — the detection site owns the loud lane-death log).

§Feeder-site contract (TB4QGX T3, ADR-044)

A BOT-side caller of this method MUST also wake the fleet hosts on a non-Held change; see Self::observe_throttle. On the lane-death (Faulted) arm the wake still fires, and the host drains its held receipts terminally instead of parking them.

Source

pub fn current(&self) -> FleetPosture

The current posture.

Source

pub fn policy(&self) -> PosturePolicy

The active policy (read-through; the Part B operator channel reads and re-tunes through here).

Source

pub fn subscribe(&self) -> PostureWatch

Subscribe a watch: the receiver starts at the CURRENT posture with no pending edge (it observes only transitions from here on).

Source

pub fn retune(&self, new_policy: PosturePolicy)

Swap the policy (the Part B operator channel’s entry point). The swap is atomic under the machine lock and keeps the state + the trailing sample window; the feed re-publishes the current posture so it mirrors the machine post-swap (a no-op unless the posture itself changed — the feed carries only real transitions, and the next observe_throttle re-derives the posture under the new thresholds). Semantic validation of the new policy is the caller’s job.

Source

pub fn admits_lease(&self, class: CordonClass) -> bool

Whether the posture admits new lease intake for class right now (read-through — the dispatcher’s enqueue/T-table gates and the seat hosts’ admission all consult this).

Source

pub fn note_intake_suppressed(&self)

Count a lease grant denied because of the posture (read-through — the tuning loop’s suppression metric).

Source

pub fn sim_intake_cap(&self, slot_cap: usize) -> usize

The sim intake cap in the current posture (read-through).

Source

pub fn counters(&self) -> PostureCounters

Loud-transition counters snapshot (the tuning loop’s metrics).

Source

pub fn lane_death_held(&self) -> bool

The sticky lane-death hold (read-through). A host keys its Faulted transition on this TYPED latch, never on elapsed cordon time (a long recoverable EventBurst/Duty cordon must not fault).

Trait Implementations§

Source§

impl Debug for PostureOwner

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more