pub struct DownloadJournalGuard<'a> { /* private fields */ }Expand description
Exclusive local lifecycle access borrowing the stable backup layout guard.
The caller owns backend artifact completeness and fresh remote authority. These operations never invoke a transport, remove staging or release references.
Implementations§
Source§impl DownloadJournalGuard<'_>
impl DownloadJournalGuard<'_>
Sourcepub fn verify_durable_artifacts<'a>(
&'a self,
plan: &'a OperationPlanRecord,
) -> Result<DurableDownloadView<'a>, DownloadIntegrityError>
pub fn verify_durable_artifacts<'a>( &'a self, plan: &'a OperationPlanRecord, ) -> Result<DurableDownloadView<'a>, DownloadIntegrityError>
Explicitly reverify every published artifact under the retained original plan.
Requires the exact persisted plan and unchanged held journal before and after no-follow checksumming. The returned view borrows journal/layout custody. This reads local bytes; ordinary journal reopen/resume remains effect-free and does not trigger verification. Nothing is written, pruned or released.
File checks are sequential observations, not an atomic filesystem snapshot. Integrations retain stable byte custody and qualify complete backend transfer, authentic snapshot/receipt identity and terminal/reference-release evidence.
§Errors
Rejects unusable/replaced custody, missing/changed plans or journals, incomplete exact selected coverage, non-durable entries, unsafe/missing trees and changed bytes.
Source§impl<'a> DownloadJournalGuard<'a>
impl<'a> DownloadJournalGuard<'a>
Sourcepub fn create(
layout: &'a BackupLayoutGuard,
intent: &str,
artifacts: Vec<DownloadArtifactRequest>,
) -> Result<Self, DownloadJournalError>
pub fn create( layout: &'a BackupLayoutGuard, intent: &str, artifacts: Vec<DownloadArtifactRequest>, ) -> Result<Self, DownloadJournalError>
Exclusively create exact intent and snapshot identities without replacing evidence.
§Errors
Rejects existing/unsafe journals, locked or replaced layouts and invalid/bounded records.
Sourcepub fn open(
layout: &'a BackupLayoutGuard,
expected_intent: &str,
) -> Result<Self, DownloadJournalError>
pub fn open( layout: &'a BackupLayoutGuard, expected_intent: &str, ) -> Result<Self, DownloadJournalError>
Open retained bounded v1 evidence under exact caller-supplied intent.
Reads only local journal evidence; it does not reverify artifacts or remote state.
§Errors
Rejects missing/unsafe/corrupt journals, intent mismatch and locked/replaced layouts.
Sourcepub fn record(&self) -> Result<&DownloadJournalRecord, DownloadJournalError>
pub fn record(&self) -> Result<&DownloadJournalRecord, DownloadJournalError>
Read retained progress; failed publication requires reopening before further use.
§Errors
Rejects an indeterminate write outcome or a replaced layout.
Sourcepub fn path(&self) -> PathBuf
pub fn path(&self) -> PathBuf
Return the canonical journal location whose sidecar this guard owns.
Sourcepub fn record_downloaded(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn record_downloaded( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Retain the caller’s complete-download attestation for the exact snapshot.
Requires a safe existing staging directory. The caller must already have validated complete backend metadata/extent coverage and command quiescence; traversability alone does not establish IC transfer completeness.
§Errors
Rejects identity/state conflicts, unsafe or missing staging and failed persistence.
Sourcepub fn verify_artifact(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn verify_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Verify staged bytes and durably retain their canonical checksum.
§Errors
Rejects wrong identity/state, unsafe or missing bytes and failed persistence.
Sourcepub fn finalize_artifact(
&mut self,
canister: &str,
snapshot: &str,
) -> Result<(), DownloadJournalError>
pub fn finalize_artifact( &mut self, canister: &str, snapshot: &str, ) -> Result<(), DownloadJournalError>
Publish exact verified bytes or adopt a matching tree after a lost response.
Leaves staging and retained intent intact on rejection. Durable state does not silently trigger fresh artifact verification; that is a distinct action.
§Errors
Rejects wrong identity/state, changed bytes, unsafe paths and uncertain publication.