Skip to main content

Provenance

Struct Provenance 

Source
pub struct Provenance {
    pub source: Source,
    pub observed_at_ns: i64,
    pub status: Status,
}
Expand description

Everything a consumer needs to decide how far to trust one value.

A view type, built on demand rather than stored: the index keeps one Source byte per entry and its observation timestamps once, because on a tree of millions of entries the timestamps are shared by nearly all of them and a per-entry struct would cost more memory than the information is worth.

The three facts are independent on purpose, because they answer different questions. Status asks how much of the subtree the number covers; Source asks how far to trust what it covers; observed_at_ns asks when. A Status::Complete but Source::Cached value is a point estimate that may move either way and reads as “about 3.2 GB, as of two minutes ago”, while a Status::Partial value is missing part of its subtree and reads as “3.2 GB so far”. Collapsing them would make a shrinking number look like a defect.

Note that “3.2 GB so far” is only a lower bound that grows while an additive walk is running. See Status::Partial: the status records coverage, not direction.

Fields§

§source: Source

Where the value came from.

§observed_at_ns: i64

When the underlying filesystem observation was made, in nanoseconds since the Unix epoch. For Source::Cached this is when the snapshot captured it — the “as of” a consumer displays. Zero when unknown.

§status: Status

How settled the value is.

Implementations§

Source§

impl Provenance

Source

pub const fn scanned(observed_at_ns: i64) -> Self

Freshly observed by this process, complete.

Source

pub fn combine(self, other: Self) -> Self

Combine with another value’s provenance, taking the less trustworthy of each fact.

This is what makes a directory only as trustworthy as its least trustworthy descendant: the weakest source, the oldest observation, and the worst status.

Every fact fails closed, including time: an unknown observed_at_ns is absorbing rather than skipped, so a subtree with one contributor of unknown age reports an unknown age instead of a precise time it cannot prove.

There is deliberately no identity element. Because unknown is absorbing, it cannot double as the seed of a fold, and a caller aggregating a possibly-empty set must represent emptiness separately (Option<Provenance>) rather than seeding with a zero timestamp — otherwise every roll-up would come out unknown.

Source

pub const fn is_verified(self) -> bool

Whether this value was checked against the filesystem during this session.

Trait Implementations§

Source§

impl Clone for Provenance

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Provenance

Source§

impl Debug for Provenance

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Provenance

Source§

impl PartialEq for Provenance

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Provenance

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.