ic_backup/policy/fence_obligation/mod.rs
1//! Read retained acquisition spending under an exact original fence obligation.
2
3use crate::model::{
4 attempt_journal::{AttemptJournalRecord, AttemptJournalView},
5 fence_obligation::{FenceObligationError, FenceObligationRecord},
6 operation_plan::{OperationPlanError, OperationPlanRecord},
7};
8use thiserror::Error;
9
10/// Join the original obligation to its exact acquisition journal without IO or effects.
11///
12/// Missing journals are not accepted as zero consumption. Applied is a retained
13/// acquisition receipt projection, never current Active custody or permission to
14/// release. A pending observation remains pending even when allowances are exhausted.
15/// Full dependency admission remains owned by `execution_progress`; this view does
16/// not prove prerequisite completion, chronology, authenticity or dispatch safety.
17/// Original requirement/fence matching is separately admitted by the record and
18/// guarded persistence boundary; this projection checks plan and journal identity.
19/// # Errors
20/// Rejects another plan, operation, context, request or original budget.
21pub fn acquisition_progress(
22 plan: &OperationPlanRecord,
23 obligation: &FenceObligationRecord,
24 journal: &AttemptJournalRecord,
25) -> Result<AttemptJournalView, FenceObligationProgressError> {
26 obligation.validate_plan(plan)?;
27 let original = plan.attempt_authority(obligation.acquisition_operation())?;
28 if journal.authority() != &original {
29 return Err(FenceObligationProgressError::AuthorityMismatch);
30 }
31 Ok(journal.view())
32}
33
34/// Typed denial of an original acquisition spending projection.
35#[derive(Debug, Error)]
36pub enum FenceObligationProgressError {
37 /// Journal does not retain the exact original operation and allowances.
38 #[error("fence acquisition original journal authority mismatch")]
39 AuthorityMismatch,
40 /// Obligation does not bind the original plan.
41 #[error(transparent)]
42 Obligation(#[from] FenceObligationError),
43 /// Original authority cannot be derived.
44 #[error(transparent)]
45 Plan(#[from] OperationPlanError),
46}
47
48#[cfg(test)]
49mod tests;