pub struct AllocationLedger { /* private fields */ }Expand description
AllocationLedger
Durable ownership and current metadata, bounded by the usable memory-ID domain. Omitted and retired identities retain their slots; no per-upgrade or schema audit trail is stored.
The counter binds validation proofs to physical commits. Decoded DTOs remain untrusted until integrity validation and protected recovery succeed.
Implementations§
Source§impl AllocationLedger
impl AllocationLedger
Sourcepub fn validate_integrity(&self) -> Result<(), LedgerIntegrityError>
pub fn validate_integrity(&self) -> Result<(), LedgerIntegrityError>
Validate count, unique ownership and empty genesis before recovery or commit. Checked field types already enforce key, slot and schema invariants.
Source§impl AllocationLedger
impl AllocationLedger
Sourcepub fn new(
current_generation: u64,
records: Vec<AllocationRecord>,
) -> Result<Self, LedgerIntegrityError>
pub fn new( current_generation: u64, records: Vec<AllocationRecord>, ) -> Result<Self, LedgerIntegrityError>
Build a ledger DTO after validating count, ownership and genesis rules. Recovery must still establish the persisted format and physical binding.
Sourcepub const fn current_generation(&self) -> u64
pub const fn current_generation(&self) -> u64
Return the current commit counter; this is not retained upgrade history.
Sourcepub fn records(&self) -> &[AllocationRecord]
pub fn records(&self) -> &[AllocationRecord]
Borrow retained ownership records, including omitted and retired stores.
Source§impl AllocationLedger
impl AllocationLedger
Sourcepub fn stage_validated_generation(
&self,
validated: &ValidatedAllocations,
) -> Result<Self, AllocationStageError>
pub fn stage_validated_generation( &self, validated: &ValidatedAllocations, ) -> Result<Self, AllocationStageError>
Return a copy of the ledger with validated recorded as the next generation.
This is a pure logical update. Physical atomicity is the responsibility of the substrate commit protocol.
Empty validated commits are valid. They advance the counter even when no allocation records changed, without retaining an event.
§Panics
Panics only if an internal validated-allocation invariant is broken.
Sourcepub fn stage_reservation_generation(
&self,
reservations: &[AllocationDeclaration],
) -> Result<Self, AllocationReservationError>
pub fn stage_reservation_generation( &self, reservations: &[AllocationDeclaration], ) -> Result<Self, AllocationReservationError>
Return a copy of the ledger with reservations recorded as the next generation.
This is a pure logical update. The caller is responsible for applying framework policy before staging reservations.
Empty reservation commits are valid. They advance the counter without retaining an event.
Sourcepub fn stage_retirement_generation(
&self,
retirement: &AllocationRetirement,
) -> Result<Self, AllocationRetirementError>
pub fn stage_retirement_generation( &self, retirement: &AllocationRetirement, ) -> Result<Self, AllocationRetirementError>
Return a copy of the ledger with one explicit retirement committed.
Retirement tombstones any known non-retired allocation identity, including reserved records that never became active.