Skip to main content

DownloadJournalGuard

Struct DownloadJournalGuard 

Source
pub struct DownloadJournalGuard<'a> { /* private fields */ }
Expand description

Exclusive local lifecycle access borrowing the stable backup layout guard.

The caller owns backend artifact completeness and fresh remote authority. These operations never invoke a transport, remove staging or release references.

Implementations§

Source§

impl DownloadJournalGuard<'_>

Source

pub fn verify_durable_artifacts<'a>( &'a self, plan: &'a OperationPlanRecord, ) -> Result<DurableDownloadView<'a>, DownloadIntegrityError>

Explicitly reverify every published artifact under the retained original plan.

Requires the exact persisted plan and unchanged held journal before and after no-follow checksumming. The returned view borrows journal/layout custody. This reads local bytes; ordinary journal reopen/resume remains effect-free and does not trigger verification. Nothing is written, pruned or released.

File checks are sequential observations, not an atomic filesystem snapshot. Integrations retain stable byte custody and qualify complete backend transfer, authentic snapshot/receipt identity and terminal/reference-release evidence.

§Errors

Rejects unusable/replaced custody, missing/changed plans or journals, incomplete exact selected coverage, non-durable entries, unsafe/missing trees and changed bytes.

Source§

impl<'a> DownloadJournalGuard<'a>

Source

pub fn create( layout: &'a BackupLayoutGuard, intent: &str, artifacts: Vec<DownloadArtifactRequest>, ) -> Result<Self, DownloadJournalError>

Exclusively create exact intent and snapshot identities without replacing evidence.

§Errors

Rejects existing/unsafe journals, locked or replaced layouts and invalid/bounded records.

Source

pub fn open( layout: &'a BackupLayoutGuard, expected_intent: &str, ) -> Result<Self, DownloadJournalError>

Open retained bounded v1 evidence under exact caller-supplied intent.

Reads only local journal evidence; it does not reverify artifacts or remote state.

§Errors

Rejects missing/unsafe/corrupt journals, intent mismatch and locked/replaced layouts.

Source

pub fn record(&self) -> Result<&DownloadJournalRecord, DownloadJournalError>

Read retained progress; failed publication requires reopening before further use.

§Errors

Rejects an indeterminate write outcome or a replaced layout.

Source

pub fn path(&self) -> PathBuf

Return the canonical journal location whose sidecar this guard owns.

Source

pub fn record_downloaded( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>

Retain the caller’s complete-download attestation for the exact snapshot.

Requires a safe existing staging directory. The caller must already have validated complete backend metadata/extent coverage and command quiescence; traversability alone does not establish IC transfer completeness.

§Errors

Rejects identity/state conflicts, unsafe or missing staging and failed persistence.

Source

pub fn verify_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>

Verify staged bytes and durably retain their canonical checksum.

§Errors

Rejects wrong identity/state, unsafe or missing bytes and failed persistence.

Source

pub fn finalize_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>

Publish exact verified bytes or adopt a matching tree after a lost response.

Leaves staging and retained intent intact on rejection. Durable state does not silently trigger fresh artifact verification; that is a distinct action.

§Errors

Rejects wrong identity/state, changed bytes, unsafe paths and uncertain publication.

Trait Implementations§

Source§

impl<'a> Debug for DownloadJournalGuard<'a>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.