pub struct DownloadJournalGuard<'a> { /* private fields */ }Expand description
Exclusive local lifecycle access borrowing the stable backup layout guard.
The caller owns backend artifact completeness and fresh remote authority. These operations never invoke a transport, remove staging or release references.
Implementations§
Source§impl<'a> DownloadJournalGuard<'a>
impl<'a> DownloadJournalGuard<'a>
Sourcepub fn create(
layout: &'a BackupLayoutGuard,
intent: &str,
artifacts: Vec<DownloadArtifactRequest>,
) -> Result<Self, DownloadJournalError>
pub fn create( layout: &'a BackupLayoutGuard, intent: &str, artifacts: Vec<DownloadArtifactRequest>, ) -> Result<Self, DownloadJournalError>
Exclusively create exact intent and snapshot identities without replacing evidence.
§Errors
Rejects existing/unsafe journals, locked or replaced layouts and invalid/bounded records.
Sourcepub fn open(
layout: &'a BackupLayoutGuard,
expected_intent: &str,
) -> Result<Self, DownloadJournalError>
pub fn open( layout: &'a BackupLayoutGuard, expected_intent: &str, ) -> Result<Self, DownloadJournalError>
Open retained bounded v1 evidence under exact caller-supplied intent.
Reads only local journal evidence; it does not reverify artifacts or remote state.
§Errors
Rejects missing/unsafe/corrupt journals, intent mismatch and locked/replaced layouts.
Sourcepub fn record(&self) -> Result<&DownloadJournalRecord, DownloadJournalError>
pub fn record(&self) -> Result<&DownloadJournalRecord, DownloadJournalError>
Read retained progress; failed publication requires reopening before further use.
§Errors
Rejects an indeterminate write outcome or a replaced layout.
Sourcepub fn path(&self) -> PathBuf
pub fn path(&self) -> PathBuf
Return the canonical journal location whose sidecar this guard owns.
Sourcepub fn record_downloaded(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn record_downloaded( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Retain the caller’s complete-download attestation for the exact snapshot.
Requires a safe existing staging directory. The caller must already have validated complete backend metadata/extent coverage and command quiescence; traversability alone does not establish IC transfer completeness.
§Errors
Rejects identity/state conflicts, unsafe or missing staging and failed persistence.
Sourcepub fn verify_artifact(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn verify_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Verify staged bytes and durably retain their canonical checksum.
§Errors
Rejects wrong identity/state, unsafe or missing bytes and failed persistence.
Sourcepub fn finalize_artifact(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn finalize_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Publish exact verified bytes or adopt a matching tree after a lost response.
Leaves staging and retained intent intact on rejection. Durable state does not silently trigger fresh artifact verification; that is a distinct action.
§Errors
Rejects wrong identity/state, changed bytes, unsafe paths and uncertain publication.