Skip to main content

ic_backup/
lib.rs

1//! Host-side snapshot backup and same-release recovery for Internet Computer canisters.
2//!
3//! The library provides artifact checksums, no-follow traversal and staging,
4//! verified durable directory publication, bounded JSON persistence and journal
5//! locking, layout lifetime exclusion, durable restore dependencies and
6//! inherited command custody. Local download journals retain exact snapshot
7//! identity and verified publication progress. Local attempt journals bind exact
8//! declared identity and finite mutation/observation allowances, retaining durable
9//! reservations and qualified receipts. These mechanisms do not authorize canister
10//! effects.
11//! Explicit fresh download integrity checks bind the retained original plan and
12//! exact selected set to published directory bytes without changing journals,
13//! replenishing allowances or releasing dependencies. Stable byte custody and
14//! backend transfer completeness remain integration-owned.
15//! Bounded physical inventories retain canonical declared parent forests; pure
16//! selection policy expands exact principals without live discovery or authority.
17//! Explicit effect graphs retain validated operation dependencies and project
18//! deterministic planning order/readiness without authorizing dispatch.
19//! Immutable operation plans bind these declarations to exact target/request digests
20//! and original attempt allowances, deriving journal authority under the full plan digest.
21//! Pure execution progress joins exact retained journals to the original plan and
22//! projects causal Applied evidence, pending attempts and exhaustion without dispatch.
23//! The IC request boundary encodes closed host-ingress management operations and
24//! binds exact method/routing/Candid bytes to original mutation or observation digests.
25//! Codec qualification does not establish IC effects or fresh execution authority.
26//! Bounded capture/inventory reply decoding preserves raw snapshot identity and
27//! exact request/reply evidence without authenticating origin or settling effects.
28//! Pure inventory comparison exposes new candidates and rejects baseline drift;
29//! candidate cardinality never attributes or settles a lost capture.
30//! Bounded lifecycle replies retain exact empty acknowledgements and required
31//! status/controller projections without converting them into fresh authority.
32//! A separate membership port binds ephemeral provider results to original intent,
33//! exact current context/full inventory and an integration-owned challenge.
34//! Pure matching views grant neither controller authority nor application continuity.
35//! The separate control port checks direct caller-controller evidence for exact
36//! IC mutation payloads; its matching views still grant no dispatch or restore safety.
37//! A separate snapshot-read port checks current snapshot-list visibility and exact
38//! caller read paths, without granting mutation control or settling lost replies.
39//! Immutable consistency requirements retain the original requested guarantee;
40//! current target/fence checks acquire or release no application obligations.
41//!
42//! Applications own membership, release identity, control routing, quiescence
43//! and external-effect settlement. Capture/restore runners and an IC transport
44//! have not been extracted yet. Filesystem access and credentials remain on the
45//! operator host.
46
47mod hash;
48pub mod model;
49pub mod ops;
50pub mod policy;
51pub mod ports;
52
53#[cfg(test)]
54mod test_support;