Skip to main content

MemoryRuntime

Struct MemoryRuntime 

Source
pub struct MemoryRuntime<M: Memory> { /* private fields */ }
Expand description

MemoryRuntime

Canonical owner of allocation bootstrap state for one backing memory.

The runtime owns its MemoryManager, allocation-ledger persistence, bootstrap lifecycle, committed allocation capability, opens, and diagnostics. Static linked-program declarations are supplied separately as one immutable SealedDeclarationSnapshot.

Each bootstrap attempt fallibly decodes its ledger record from persisted memory. Capacity-checked writes use Cell; diagnostics also read persisted memory directly.

M needs only Memory. The runtime does not require the backing memory to be Send, Sync, Clone, or 'static.

Implementations§

Source§

impl<M: Memory> MemoryRuntime<M>

Source

pub fn verify_authority( &self, requirements: &SealedDeclarationSnapshot, authority: &str, ) -> Result<(), RuntimeAdoptionError>

Verify every fixed declaration and logical request for one authority in the supplied requirements against this runtime’s current commitment.

Fixed declarations must match key, ID, label and diagnostic schema; logical requests must match key, authority and diagnostic schema while retaining the host’s assigned ID. Other authorities and additional committed keys are ignored. An authority with no requirements rejects. Grants and application schema semantics are not revalidated. Success neither grants new access nor proves application lifecycle readiness.

Source§

impl<M: Memory> MemoryRuntime<M>

Source

pub fn memory_allocations( &self, ) -> Result<MemoryAllocations, RuntimeDiagnosticError>

Measure all IDs with a fixed metadata read and bounded current bindings.

Reads at most 34,848 backing bytes. Never initializes stores, decodes the ledger, writes, grows memory, or advances a generation. Available before bootstrap; current declaration/range bindings are then unavailable.

Source

pub fn memory_allocation_summary( &self, ) -> Result<MemoryAllocationSummary, RuntimeDiagnosticError>

Measure numeric totals and binding partitions without constructing per-ID rows or copying keys, owners or range claims. Reads at most 34,848 metadata bytes; no ledger history, writes, growth, or generation changes occur.

Source§

impl<M: Memory> MemoryRuntime<M>

Source

pub fn diagnostic_export( &self, ) -> Result<DiagnosticExport, RuntimeDiagnosticError>

Export this runtime’s recovered ledger and live virtual-memory sizes.

Source

pub fn commit_recovery_diagnostic( &self, ) -> Result<CommitStoreDiagnostic, RuntimeDiagnosticError>

Diagnose protected commit recovery from this runtime’s ledger memory.

This operation is available before bootstrap when the stable-cell envelope is readable or the ledger memory is empty.

Source

pub fn doctor_report<P>( &self, declarations: &SealedDeclarationSnapshot, policy: &P, ) -> MemoryRuntimeDoctorReport

Build preflight and lifecycle diagnostics for this runtime.

Validation checks the supplied declarations and allocation policy only. It does not execute prepare_bootstrap, predict its completed set, or certify consumer admission. Diagnostics never replay preparation.

Source§

impl<M: Memory> MemoryRuntime<M>

Source

pub fn new(memory: M) -> Result<Self, RuntimeConstructionError>

Construct an unbootstrapped runtime without overwriting foreign memory.

Empty backing memory is initialized as an ic_stable_structures::MemoryManager. Nonempty memory must pass bounded validation of the current manager header, bucket table, and extents; otherwise construction returns a typed error before the manager can write its header or allocation table. A pre-grown blank memory is nonempty and is therefore rejected rather than assumed disposable.

§Errors

Returns RuntimeConstructionError::ForeignMemory for nonempty memory without MemoryManager magic, or RuntimeConstructionError::UnsupportedMemoryManagerVersion when the magic is recognized but the layout version is not current. Invalid metadata returns RuntimeConstructionError::Layout. Refused fresh metadata growth returns RuntimeConstructionError::Growth without writes, allowing the same backing memory to be retried. Reopening honors the actual persisted bucket size; only fresh memory uses 128 pages.

Source

pub fn new_with_config( memory: M, config: MemoryManagerConfig, ) -> Result<Self, RuntimeConstructionError>

Construct with an explicit immutable bucket policy. Existing memory must match exactly; mismatches fail before manager initialization or writes.

§Errors

Returns the construction errors described by Self::new, or RuntimeConstructionError::BucketSizeMismatch when existing geometry differs from config.

Source

pub fn memory_manager_config(&self) -> MemoryManagerConfig

Return the immutable bucket configuration bound to this runtime’s manager.

Source

pub const fn is_bootstrapped(&self) -> bool

Return whether this runtime has published committed allocation authority.

Source

pub fn bootstrap<P: RuntimeBootstrapPolicy>( &mut self, declarations: &SealedDeclarationSnapshot, policy: &P, ) -> Result<&CommittedAllocations, RuntimeBootstrapError<P::Error>>

Bootstrap this backing memory from one immutable declaration snapshot.

Recovery, metadata admission, logical resolution, policy evaluation, staging, persistence and capability publication are local to this runtime. A repeated call is idempotent only when the sealed declaration snapshot and RuntimeBootstrapPolicy::runtime_bootstrap_identity match the successful bootstrap. A mismatch returns a typed error without advancing the durable generation or re-evaluating policy. Independently sealed snapshots match when their canonical contents are equal.

§Panics

Panics if a private runtime or encoding invariant is broken, or backing memory or a policy callback panics.

Source

pub const fn committed_allocations( &self, ) -> Result<&CommittedAllocations, RuntimeOpenError>

Borrow this runtime’s committed allocation-open capability.

Source

pub fn open_memory_by_key( &self, stable_key: &str, ) -> Result<RuntimeMemory<M>, RuntimeOpenError>

Open by durable key using only this runtime’s persisted current capability.

Source

pub fn open_memory( &self, stable_key: &str, expected_id: u8, ) -> Result<RuntimeMemory<M>, RuntimeOpenError>

Open this runtime’s committed memory by stable key and expected ID.

Source

pub fn memory_id(&self, stable_key: &str) -> Result<u8, RuntimeOpenError>

Resolve an application key’s committed ID without opening memory, reading history, or changing the host’s policy or bucket configuration.

Auto Trait Implementations§

§

impl<M> !RefUnwindSafe for MemoryRuntime<M>

§

impl<M> !Send for MemoryRuntime<M>

§

impl<M> !Sync for MemoryRuntime<M>

§

impl<M> !UnwindSafe for MemoryRuntime<M>

§

impl<M> Freeze for MemoryRuntime<M>
where MemoryManager<Rc<M>>: Freeze, Rc<GrowthState<M>>: Freeze,

§

impl<M> Unpin for MemoryRuntime<M>
where MemoryManager<Rc<M>>: Unpin, Rc<GrowthState<M>>: Unpin,

§

impl<M> UnsafeUnpin for MemoryRuntime<M>
where MemoryManager<Rc<M>>: UnsafeUnpin, Rc<GrowthState<M>>: UnsafeUnpin,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.