ic_backup/lib.rs
1//! Host-side snapshot backup and same-release recovery for Internet Computer canisters.
2//!
3//! The library provides artifact checksums, no-follow traversal and staging,
4//! verified durable directory publication, bounded JSON persistence and journal
5//! locking, layout lifetime exclusion, durable restore dependencies and
6//! inherited command custody. Local download journals retain exact snapshot
7//! identity and verified publication progress. Local attempt journals bind exact
8//! declared identity and finite mutation/observation allowances, retaining durable
9//! reservations and qualified receipts. These mechanisms do not authorize canister
10//! effects.
11//! Explicit fresh download integrity checks bind the retained original plan and
12//! exact selected set to published directory bytes without changing journals,
13//! replenishing allowances or releasing dependencies. Stable byte custody and
14//! backend transfer completeness remain integration-owned.
15//! Immutable local download manifests reuse that exact v1 journal schema after
16//! fresh byte verification. Exact replay reads original retained records only,
17//! preserving snapshot/checksum provenance even when artifact trees are absent.
18//! Explicit local restore-source verification joins both original plans, retained
19//! safety requirement and exact local manifest before checking every source tree.
20//! Borrowed same-ID selection views grant no upload/load, application or release authority.
21//! Private operation-bound artifact copies check original and copied checksums;
22//! explicit retained-copy verification recovers without re-reading source trees.
23//! Failed copies and drop retain evidence, spending and source references without cleanup.
24//! Bounded physical inventories retain canonical declared parent forests; pure
25//! selection policy expands exact principals without live discovery or authority.
26//! Explicit effect graphs retain validated operation dependencies and project
27//! deterministic planning order/readiness without authorizing dispatch.
28//! Immutable operation plans bind these declarations to exact target/request digests
29//! and original attempt allowances, deriving journal authority under the full plan digest.
30//! Pure execution progress joins exact retained journals to the original plan and
31//! projects causal Applied evidence, pending attempts and exhaustion without dispatch.
32//! Original-plan-bound local progress reopens every retained journal. Planned
33//! reservations require complete original evidence and Applied mutation prerequisites,
34//! retaining the existing spending owner without dispatching or resetting allowance.
35//! The IC request boundary encodes closed host-ingress management operations and
36//! binds exact method/routing/Candid bytes to original mutation or observation digests.
37//! Codec qualification does not establish IC effects or fresh execution authority.
38//! Bounded capture/inventory reply decoding preserves raw snapshot identity and
39//! exact request/reply evidence without authenticating origin or settling effects.
40//! Bounded snapshot metadata reads preserve ordered globals, optional timer/hook
41//! values and exact chunk identities, without attesting complete data transfer.
42//! Metadata-bound data reads admit checked ranges, exact reply lengths and chunk
43//! hashes while retaining original evidence without effects. Incremental coverage
44//! checks reject gaps and repeated chunks without retaining or publishing bytes.
45//! Snapshot upload payloads preserve representable metadata and bind exact bounded
46//! source slices to a distinct new ID. Explicit local preparation checks retained
47//! source bytes; passive original-attempt reply admission supplies no dispatch,
48//! settlement, complete upload or new spending. A single-update upload provider
49//! contract reuses original accounting and passive replies; no provider is installed.
50//! Local verification/upload preparation expose per-guard host duration and chunk-size
51//! summaries using registry ic-metrics arithmetic. Metrics are diagnostic in-memory
52//! samples, start empty on reopen and change no retained progress or spending.
53//! Pure inventory comparison exposes new candidates and rejects baseline drift;
54//! candidate cardinality never attributes or settles a lost capture.
55//! Bounded lifecycle replies retain exact empty acknowledgements and required
56//! status/controller projections without converting them into fresh authority.
57//! Exact IC mutation envelopes bind already reserved original updates; a single-call
58//! provider contract and bounded passive reply association preserve pending spending.
59//! Existing codecs decode replies without automatic settlement, retries or release.
60//! Exact staged restore copies have separate durable publication/recovery and fresh
61//! canonical-copy verification, retaining original accounting and source references.
62//! Exact reserved status/list observations also retain both original attempt identities;
63//! passive association leaves lost observations pending and proves no effect outcome.
64//! A separate membership port binds ephemeral provider results to original intent,
65//! exact current context/full inventory and an integration-owned challenge.
66//! Pure matching views grant neither controller authority nor application continuity.
67//! The separate control port checks direct caller-controller evidence for exact
68//! IC mutation payloads; its matching views still grant no dispatch or restore safety.
69//! A separate snapshot-read port checks current snapshot-list visibility and exact
70//! caller read paths, without granting mutation control or settling lost replies.
71//! Immutable consistency requirements retain the original requested guarantee;
72//! current target/fence checks acquire or release no application obligations.
73//! Immutable restore safety requirements bind exact original source and same-release
74//! targets; fresh application evidence checks load/start safety without effects,
75//! lost-load settlement or fence/reference release.
76//! Immutable fence obligations retain original scope and acquisition identity;
77//! recovery joins their exact original attempt journals without new accounting,
78//! automatic release or a claim of current Active custody.
79//! Reserved fence-acquisition reconciliation matches original-request attribution
80//! under exact pending mutation and observation identities. Passive claims and
81//! late-reply admission perform no automatic settlement, redispatch or release;
82//! authenticated providers and actual application effects remain integration-owned.
83//! Exact application acquisition envelopes bind receiver, update mode, method and
84//! opaque bytes to already reserved original mutations. Passive acknowledgement
85//! association establishes no acquisition outcome or fresh dispatch permission.
86//! Immutable execution settlement checkpoints bind complete original Applied
87//! journals and their exact chronological histories for local replay. They prove
88//! no full backup/restore completion, command quiescence or fence/reference release.
89//!
90//! Applications own membership, release identity, control routing, quiescence
91//! and external-effect settlement. Capture/restore runners and an IC transport
92//! have not been extracted yet. Filesystem access and credentials remain on the
93//! operator host.
94//! Bounded Unix record reads reuse ic-host-fs regular-file admission while
95//! publication, record validation, confinement and command custody remain local.
96
97mod hash;
98pub mod model;
99pub mod ops;
100pub mod policy;
101pub mod ports;
102
103#[cfg(test)]
104mod test_support;