Skip to main content

LamportGateGuard

Struct LamportGateGuard 

Source
pub struct LamportGateGuard<'accounts> { /* private fields */ }
Expand description

RAII installation of the lamport gate for one bound instruction.

Returned by try_install_lamport_gate / install_lamport_gate. While this is the most recently installed still-active gate on its tier, the runtime’s lamport choke points refuse mutation on any account the installed policy does not permit; an inner (newer) gate shadows it until that inner guard drops. Dropping frees exactly this guard’s slot (matched by unique token), so guards may be dropped in any order without disturbing, or resurrecting, other gates.

§Leak behavior (mem::forget)

The gate store holds copied address values, never pointers into the account slice, so leaking the guard leaves a stale value policy installed: later checks on this tier keep being governed by it (addresses it does not know fail closed) until enough leaks exhaust the tier’s LAMPORT_GATE_DEPTH slots and further installs fail loudly. That is observable over-/stale enforcement, never memory unsafety.

The 'accounts lifetime parameter is retained for API stability (macro codegen names LamportGateGuard<'a>); it is not load-bearing for soundness, because nothing borrowed from the slice outlives the install call.

Trait Implementations§

Source§

impl<'accounts> Debug for LamportGateGuard<'accounts>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for LamportGateGuard<'_>

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more

Auto Trait Implementations§

§

impl<'accounts> Freeze for LamportGateGuard<'accounts>

§

impl<'accounts> RefUnwindSafe for LamportGateGuard<'accounts>

§

impl<'accounts> Send for LamportGateGuard<'accounts>

§

impl<'accounts> Sync for LamportGateGuard<'accounts>

§

impl<'accounts> Unpin for LamportGateGuard<'accounts>

§

impl<'accounts> UnsafeUnpin for LamportGateGuard<'accounts>

§

impl<'accounts> UnwindSafe for LamportGateGuard<'accounts>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.