Skip to main content

ic_backup/policy/fence_acquisition/
mod.rs

1//! Pure update acknowledgement association; never effect settlement or dispatch admission.
2
3use crate::model::{
4    attempt_journal::AttemptJournalRecord,
5    fence_acquisition::{
6        FenceAcquisitionAcknowledgement, FenceAcquisitionError, FenceAcquisitionRequest,
7    },
8};
9use thiserror::Error;
10
11/// Match a passive reply to the exact original still pending reservation.
12///
13/// This authenticates neither network/caller/reply nor whole-unit acquisition or
14/// current fence custody. Success does not produce any mutation outcome, write a
15/// receipt, invoke a provider, authorize retry or release obligations/references.
16/// Actual integrations must separately qualify any direct effect settlement;
17/// uncertain effects use the existing reserved reconciliation contract.
18/// # Errors
19/// Rejects changed/settled/recovering reservations, other authority or attempt.
20pub fn validate_acknowledgement<'a>(
21    request: &FenceAcquisitionRequest<'_>,
22    journal: &AttemptJournalRecord,
23    acknowledgement: &'a FenceAcquisitionAcknowledgement,
24) -> Result<&'a FenceAcquisitionAcknowledgement, FenceAcquisitionAcknowledgementError> {
25    request.validate_journal(journal)?;
26    if acknowledgement.authority != request.authority().digest() {
27        return Err(FenceAcquisitionAcknowledgementError::AuthorityMismatch);
28    }
29    if acknowledgement.mutation_attempt != request.mutation_attempt() {
30        return Err(FenceAcquisitionAcknowledgementError::AttemptMismatch);
31    }
32    Ok(acknowledgement)
33}
34
35/// Typed passive association denial, without settlement or spending changes.
36#[derive(Debug, Error)]
37pub enum FenceAcquisitionAcknowledgementError {
38    /// Current reservation does not match the original request.
39    #[error(transparent)]
40    Reservation(#[from] FenceAcquisitionError),
41    /// Reply association names another full original authority.
42    #[error("fence acquisition acknowledgement authority mismatch")]
43    AuthorityMismatch,
44    /// Reply association names another mutation attempt.
45    #[error("fence acquisition acknowledgement attempt mismatch")]
46    AttemptMismatch,
47}
48
49#[cfg(test)]
50mod tests;