Skip to main content

ic_backup/ports/restore_safety/
mod.rs

1//! Fresh application-owned restore safety; no installed provider or fence lifecycle effects.
2
3use crate::model::restore_safety::{RestoreSafetyObservation, RestoreSafetyRequest};
4use thiserror::Error;
5
6/// Application-owned actual same-release source and irreversible-work safety qualification.
7///
8/// Providers qualify source authenticity/completeness/stable custody, actual
9/// target-local load snapshot ID and complete metadata/data association to the
10/// original source, current context/inventory/lifecycle, a fresh unique challenge and prior per-call
11/// accounting. The no-irreversible-effects lane requires application knowledge
12/// about restored intent and timers, never a generic standalone default. The
13/// fenced lane requires continuous exact whole-selection custody outside the
14/// rewindable source, original membership/external-obligation revisions and
15/// qualified settlement/replay prevention. Before start, qualify source-specific
16/// restored-state acceptance and isolated execution under the retained fence.
17///
18/// No provider is installed. This observes existing obligations, never acquires/
19/// releases fences, signs/dispatches loads or starts, settles lost load replies,
20/// refunds spending or releases source references. Failure, timeout, death or
21/// dropping values retains original obligations. Terminal replay never invokes
22/// this provider; fresh verification is a distinct operation.
23pub trait RestoreSafetyProvider {
24    /// Observe current safety for the exact original load/start, source and retained requirement.
25    /// # Errors
26    /// Unavailable/unsupported deny before effects; indeterminate retains consumed
27    /// authority/evidence/obligations and stops without retry or release.
28    fn observe_restore_safety(
29        &mut self,
30        request: &RestoreSafetyRequest<'_>,
31    ) -> Result<RestoreSafetyObservation, RestoreSafetyProviderError>;
32}
33/// Redacted provider failure; never changes original allowance or obligation custody.
34#[derive(Clone, Copy, Debug, Eq, Error, PartialEq)]
35pub enum RestoreSafetyProviderError {
36    /// Required qualified provider is absent.
37    #[error("restore safety provider unavailable")]
38    Unavailable,
39    /// Integration cannot qualify this original safety requirement.
40    #[error("restore safety contract unsupported")]
41    Unsupported,
42    /// Actual state, evidence, custody, reply or prior accounting is unresolved.
43    #[error("restore safety observation indeterminate")]
44    Indeterminate,
45}