pub struct PostureStateMachine { /* private fields */ }Expand description
The posture state machine. Deterministic: time is monotonic ms fed by the caller.
Implementations§
Source§impl PostureStateMachine
impl PostureStateMachine
Sourcepub fn new(policy: PosturePolicy) -> Self
pub fn new(policy: PosturePolicy) -> Self
A fresh machine in FleetPosture::Nominal.
Sourcepub const fn state(&self) -> FleetPosture
pub const fn state(&self) -> FleetPosture
Current posture.
Sourcepub const fn counters(&self) -> &PostureCounters
pub const fn counters(&self) -> &PostureCounters
Loud-transition counters (metrics export surface).
Sourcepub const fn lane_death_held(&self) -> bool
pub const fn lane_death_held(&self) -> bool
The sticky lane-death hold (FF-T4): once set, no clean window can
ever lift it — the FleetHost Faulted transition (TB4QGX T6) keys on
THIS typed latch, never on elapsed cordon time.
Sourcepub const fn policy(&self) -> &PosturePolicy
pub const fn policy(&self) -> &PosturePolicy
The active policy (operator-channel re-tune reads it through here).
Sourcepub fn set_policy(&mut self, policy: PosturePolicy)
pub fn set_policy(&mut self, policy: PosturePolicy)
Swap the policy (the operator channel’s re-tune). Pure: the state
and the trailing sample window are KEPT — a retune never fabricates
samples, so the next Self::observe re-derives the posture under
the new thresholds. Semantic validation of the new policy is the
re-tune caller’s job (the JCI2FW Part B channel).
Sourcepub fn observe(&mut self, now_ms: u64, sample: ThrottleSample) -> PostureChange
pub fn observe(&mut self, now_ms: u64, sample: ThrottleSample) -> PostureChange
Feed one throttle-poll delta at now_ms. Returns whether the
posture transitioned (and why) — the caller surfaces that loudly.
Sourcepub fn observe_cause(&mut self, cause: PostureCause) -> PostureChange
pub fn observe_cause(&mut self, cause: PostureCause) -> PostureChange
Feed one typed non-throttle cause (FF-T4, Z6XTDX — the DECIDED
option (a) input). A PostureCause::LaneDeath enters the
cordon from ANY state with its OWN exit discipline: the cordon
is sticky (the clean window never lifts it — see
Self::maybe_exit), in-flight paths get terminal receipts at
the detection site, and the process stays alive under the §6
cordon effects. Idempotent while the hold is already set (the
counter still counts every cause).
Sourcepub const fn note_intake_suppressed(&mut self)
pub const fn note_intake_suppressed(&mut self)
A lease grant was denied because of the posture (counter only — the dispatcher supplies the typed error).
Sourcepub const fn admits_lease(&self, class: CordonClass) -> bool
pub const fn admits_lease(&self, class: CordonClass) -> bool
Whether the posture admits new lease intake for class right now
(§6: Never and SimPool lease freely — sim is only intake-FLOORED;
Deferrable is held while cordoned).
Sourcepub fn sim_intake_cap(&self, slot_cap: usize) -> usize
pub fn sim_intake_cap(&self, slot_cap: usize) -> usize
The sim intake cap in the current posture (§6 effect (b)).
Trait Implementations§
Auto Trait Implementations§
impl Freeze for PostureStateMachine
impl RefUnwindSafe for PostureStateMachine
impl Send for PostureStateMachine
impl Sync for PostureStateMachine
impl Unpin for PostureStateMachine
impl UnsafeUnpin for PostureStateMachine
impl UnwindSafe for PostureStateMachine
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more