pub struct LamportGateGuard<'accounts> { /* private fields */ }Expand description
RAII installation of the lamport gate for one bound instruction.
Returned by try_install_lamport_gate / install_lamport_gate.
While this is the most recently installed still-active gate on its
tier, the runtime’s lamport choke points refuse mutation on any
account the installed policy does not permit; an inner (newer) gate
shadows it until that inner guard drops. Dropping frees exactly this
guard’s slot (matched by unique token), so guards may be dropped in
any order without disturbing, or resurrecting, other gates.
§Leak behavior (mem::forget)
The gate store holds copied address values, never pointers into the
account slice, so leaking the guard leaves a stale value policy
installed: later checks on this tier keep being governed by it
(addresses it does not know fail closed) until enough leaks exhaust
the tier’s LAMPORT_GATE_DEPTH slots and further installs fail
loudly. That is observable over-/stale enforcement, never memory
unsafety.
The 'accounts lifetime parameter is retained for API stability
(macro codegen names LamportGateGuard<'a>); it is not load-bearing
for soundness, because nothing borrowed from the slice outlives the
install call.