pub struct ImportAncestryPage {
pub thread: Option<ThreadRef>,
pub tip: Option<StateId>,
pub signed_operation_digest: Vec<u8>,
pub coverage: i32,
pub page_index: u32,
pub page_count: u32,
pub member_count: u32,
pub states: Vec<ImportAncestorState>,
pub floor_tiers: Option<ImportFloorTierSummary>,
}Expand description
Imported Git ancestry of one delegated import tip, paged (alpha.42).
A HYBRID import is ONE signed native operation per branch result slot; the converted Git ancestors are States in that tip State’s parent closure (the “import floor”), not native operations, so ReplicationOperations cannot carry them and a source pack carries only the selected State. This frame carries the floor’s States. The floor is already bound by signature: the import operation’s resulting_content_digest commits to the exact tip Capture, the tip State commits to its parent StateIds, and every member commits to its own parents, so the whole set is a Merkle closure rooted at the signed tip. No additional signed floor digest or count exists or is needed; member_count and page_count are endpoint bookkeeping that let the receiver refuse early and detect truncation, never a source of trust.
Receiver checks, all before installing anything:
- TransferReady.import_authority is present and was authenticated
independently (descriptor root, owner, witness); signed_operation_digest
is the digest of one of its
operations, whose resulting frontier selects a carried ReplicationOperations original whose Capture State istip. A page for any other operation, Thread or tip is rejected. - Every page of one floor repeats identical thread, tip, signed_operation_digest, coverage, page_count, member_count and floor_tiers; pages may arrive in any order; after sorting by page_index they are contiguous 0..page_count-1 with no gap or repeat; the sum of carried States equals member_count.
- Every carried State decodes canonically and its content-derived
StateId equals
id(address check). A duplicate id within one page set is rejected; different floors may share converted Git States. - Every carried State is reachable from
tipthrough carried States by State parents. A State outside the floor is rejected, whatever it is. - COVERAGE_FLOOR: the closure is complete. Every parent named by
tipor by a carried State is either carried or is the source State of one of the tip operation’s causal parent operations (the signed frontier; a continuation import’s parents are exactly those, so its floor is empty). A missing middle State fails here. This set is exactly the signed floor, and it is what a fresh clone must install. - COVERAGE_PATH: TransferReady.current names a carried State (an older imported commit); completeness below it is not required. The endpoint uses this to prove FetchOpen.revision lies inside the floor.
- The receiver installs the States only after the whole Fetch verified (the Complete frame), together with the selected revision’s closure, and records the floor and floor_tiers. The local visibility walk stops at floor MEMBERS, applying the whole floor tier summary to each member. The tip’s causal parents (its frontier) are still walked.
Every delegated import operation in the carried causal ancestry whose tip has parents outside the signed frontier MUST be covered by exactly one page set; an uncovered floor fails the Fetch (a clone that installs only the tip shows nothing but an embargo placeholder).
Paging and limits. A page carries at most 4096 States and, like every frame, fits ReadBudget.max_frame_bytes. Pages are charged against the receiver’s separate ancestry budget, apart from the 100000-object source pack limit, because they are States, not pack objects. A receiver MUST accept at least 131072 States and 256 MiB per Fetch so the largest known HYBRID history (boost, 94794 commits) fits with headroom; endpoints refuse larger imports at Prepare rather than truncating a floor.
Fields§
§thread: Option<ThreadRef>§tip: Option<StateId>§signed_operation_digest: Vec<u8>Digest of the exact SignedDelegatedImportOperationV1 in TransferReady.import_authority.operations (heddle-signed-delegated-import-operation-v1).
coverage: i32§page_index: u32§page_count: u32§member_count: u32Total States across all pages of this floor or path.
states: Vec<ImportAncestorState>§floor_tiers: Option<ImportFloorTierSummary>Required-present, whole-floor current disclosure summary, even for PATH.
Implementations§
Trait Implementations§
Source§impl Clone for ImportAncestryPage
impl Clone for ImportAncestryPage
Source§fn clone(&self) -> ImportAncestryPage
fn clone(&self) -> ImportAncestryPage
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for ImportAncestryPage
impl Debug for ImportAncestryPage
Source§impl Default for ImportAncestryPage
impl Default for ImportAncestryPage
Source§fn default() -> ImportAncestryPage
fn default() -> ImportAncestryPage
Source§impl Message for ImportAncestryPage
impl Message for ImportAncestryPage
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.Source§impl PartialEq for ImportAncestryPage
impl PartialEq for ImportAncestryPage
impl StructuralPartialEq for ImportAncestryPage
Auto Trait Implementations§
impl Freeze for ImportAncestryPage
impl RefUnwindSafe for ImportAncestryPage
impl Send for ImportAncestryPage
impl Sync for ImportAncestryPage
impl Unpin for ImportAncestryPage
impl UnsafeUnpin for ImportAncestryPage
impl UnwindSafe for ImportAncestryPage
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more