Skip to main content

PostureStateMachine

Struct PostureStateMachine 

Source
pub struct PostureStateMachine { /* private fields */ }
Expand description

The posture state machine. Deterministic: time is monotonic ms fed by the caller.

Implementations§

Source§

impl PostureStateMachine

Source

pub fn new(policy: PosturePolicy) -> Self

A fresh machine in FleetPosture::Nominal.

Source

pub const fn state(&self) -> FleetPosture

Current posture.

Source

pub const fn counters(&self) -> &PostureCounters

Loud-transition counters (metrics export surface).

Source

pub const fn lane_death_held(&self) -> bool

The sticky lane-death hold (FF-T4): once set, no clean window can ever lift it — the FleetHost Faulted transition (TB4QGX T6) keys on THIS typed latch, never on elapsed cordon time.

Source

pub const fn policy(&self) -> &PosturePolicy

The active policy (operator-channel re-tune reads it through here).

Source

pub fn set_policy(&mut self, policy: PosturePolicy)

Swap the policy (the operator channel’s re-tune). Pure: the state and the trailing sample window are KEPT — a retune never fabricates samples, so the next Self::observe re-derives the posture under the new thresholds. Semantic validation of the new policy is the re-tune caller’s job (the JCI2FW Part B channel).

Source

pub fn observe(&mut self, now_ms: u64, sample: ThrottleSample) -> PostureChange

Feed one throttle-poll delta at now_ms. Returns whether the posture transitioned (and why) — the caller surfaces that loudly.

Source

pub fn observe_cause(&mut self, cause: PostureCause) -> PostureChange

Feed one typed non-throttle cause (FF-T4, Z6XTDX — the DECIDED option (a) input). A PostureCause::LaneDeath enters the cordon from ANY state with its OWN exit discipline: the cordon is sticky (the clean window never lifts it — see Self::maybe_exit), in-flight paths get terminal receipts at the detection site, and the process stays alive under the §6 cordon effects. Idempotent while the hold is already set (the counter still counts every cause).

Source

pub const fn note_intake_suppressed(&mut self)

A lease grant was denied because of the posture (counter only — the dispatcher supplies the typed error).

Source

pub const fn admits_lease(&self, class: CordonClass) -> bool

Whether the posture admits new lease intake for class right now (§6: Never and SimPool lease freely — sim is only intake-FLOORED; Deferrable is held while cordoned).

Source

pub fn sim_intake_cap(&self, slot_cap: usize) -> usize

The sim intake cap in the current posture (§6 effect (b)).

Trait Implementations§

Source§

impl Debug for PostureStateMachine

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more