pub struct IcSnapshotArtifactWriter<'journal, 'layout, 'metadata> { /* private fields */ }Expand description
Exclusive ephemeral writer for one original journal artifact and exact IC metadata.
Each successful append retains decoded bytes in private descriptor-opened files. It reuses the model’s coverage owner and keeps only three hash states plus at most 1,024 chunk checksums. It borrows the original layout/journal for its whole lifetime. Appends consume the writer: any rejection or partial IO failure closes it and retains the partial tree, without a completion transition or permission to repeat reads. There is no partial-transfer reconstruction or automatic cleanup.
The integration must qualify the generic token’s association with the raw IC ID, authentic capture/metadata/data, original per-call spending, fresh read permission, complete backend transfer and stable noncooperating byte/command custody. This writer performs no provider calls and grants no upload/load/start, settlement or release.
Implementations§
Source§impl<'layout> IcSnapshotArtifactWriter<'_, 'layout, '_>
impl<'layout> IcSnapshotArtifactWriter<'_, 'layout, '_>
Sourcepub const fn coverage(&self) -> &IcSnapshotDataCoverage<'_>
pub const fn coverage(&self) -> &IcSnapshotDataCoverage<'_>
Read the original declared coverage without changing it.
Sourcepub fn path(&self) -> &Path
pub fn path(&self) -> &Path
Read the fixed private staging path; stable external custody remains required.
Sourcepub fn append(
self,
reply: &IcSnapshotDataReply<'_, '_>,
) -> Result<Self, IcSnapshotArtifactError>
pub fn append( self, reply: &IcSnapshotDataReply<'_, '_>, ) -> Result<Self, IcSnapshotArtifactError>
Append one exact admitted reply without retaining its memory buffer.
Regions may interleave; each region must remain contiguous from zero. Chunk files use exact metadata hash names and exclusive creation. No fsync or journal transition occurs until explicit finish. Any error consumes this owner and retains all bytes.
§Errors
Rejects changed custody, coverage conflicts and filesystem failures.
Sourcepub fn finish(self) -> Result<ArtifactChecksumRecord, IcSnapshotArtifactError>
pub fn finish(self) -> Result<ArtifactChecksumRecord, IcSnapshotArtifactError>
Verify complete local bytes, retain their exact checksum and durably publish them.
Complete declared coverage is required. The fixed closed tree must match hashes
computed from the actual admitted bytes, including original metadata and request.
Existing model transitions derive Downloaded and ChecksumVerified together; their
exact checksum is persisted atomically before the existing durable publisher runs.
On interruption, reopen the journal and use its ordinary ChecksumVerified publication
recovery without another read or transfer. Created partial trees cannot be resumed
through this writer; preserve them for operator-owned disposition. Ordinary Durable
replay reads only retained progress, without fresh byte verification.
The caller still owns authentic backend completeness, token/raw-ID association and stable custody. A returned checksum is local evidence, not a terminal/effect permit.
§Errors
Rejects incomplete coverage, extra/changed/unsafe bytes, replaced custody and failed
persistence/publication. Failure can leave a verified or published tree; retain it.
Closing directory-custody rejection can follow a retained Durable transition.