pub fn validate<'a>(
restore: &'a OperationPlanRecord,
source: &'a OperationPlanRecord,
requirement: &'a RestoreSafetyRequirementRecord,
manifest: &'a DownloadJournalRecord,
) -> Result<LocalRestoreSourceView<'a>, LocalRestoreSourcePolicyError>Expand description
Admit exact original plans and the local manifest digest retained in their requirement.
This opt-in local manifest binding does not reinterpret generic opaque integration artifact digests. The existing requirement owner checks same network/release/IDs; the durable download owner checks full original source intent and complete coverage. A restore subset needs separate application qualification. No IO, transitions, serialization, remote observations or new spending occur here.
ยงErrors
Rejects changed originals, another artifact binding or incomplete/non-durable source evidence.