Skip to main content

ic_memory/
capability.rs

1use crate::{declaration::AllocationDeclaration, key::StableKey, slot::MemoryManagerSlot};
2use std::sync::Arc;
3
4///
5/// ValidatedAllocations
6///
7/// Pre-commit allocation declarations accepted by policy and historical ledger
8/// validation.
9///
10/// This value is produced by [`crate::validate_allocations`] and may be staged
11/// into the next ledger generation. It cannot open storage. Only a
12/// [`CommittedAllocations`] capability confirmed after persistence can do that.
13///
14/// This is an in-memory capability, not a serde DTO. It has no public
15/// constructor and should only be produced by validation or bootstrap paths.
16/// Its declarations have valid schema metadata and at most 255 unique keys and
17/// slots. These facts are established before the proof is constructed.
18/// The base generation has passed bounded ownership validation.
19///
20
21#[derive(Clone, Debug, Eq, PartialEq)]
22pub struct ValidatedAllocations {
23    inner: Arc<ValidatedState>,
24}
25
26#[derive(Clone, Debug, Eq, PartialEq)]
27struct ValidatedState {
28    /// Recovered generation against which these declarations were validated.
29    base_generation: u64,
30    /// Validated declarations.
31    declarations: Vec<AllocationDeclaration>,
32}
33
34impl ValidatedAllocations {
35    pub(crate) fn new(base_generation: u64, declarations: Vec<AllocationDeclaration>) -> Self {
36        Self {
37            inner: Arc::new(ValidatedState {
38                base_generation,
39                declarations,
40            }),
41        }
42    }
43
44    /// Return the recovered generation used as the validation base.
45    #[must_use]
46    pub fn base_generation(&self) -> u64 {
47        self.inner.base_generation
48    }
49
50    /// Borrow the validated declarations.
51    #[must_use]
52    pub fn declarations(&self) -> &[AllocationDeclaration] {
53        &self.inner.declarations
54    }
55
56    /// Find a validated slot by stable key.
57    #[must_use]
58    pub fn slot_for(&self, key: &StableKey) -> Option<&MemoryManagerSlot> {
59        declaration_for_key(self.declarations(), key.as_str()).map(AllocationDeclaration::slot)
60    }
61
62    pub(crate) const fn confirm_persisted(self, generation: u64) -> CommittedAllocations {
63        CommittedAllocations {
64            validated: self,
65            generation,
66        }
67    }
68}
69
70// Typed capability callers and the runtime's validated borrowed input share
71// one lookup. Comparing text needs no temporary owned StableKey or second index.
72pub fn declaration_for_key<'a>(
73    declarations: &'a [AllocationDeclaration],
74    key: &str,
75) -> Option<&'a AllocationDeclaration> {
76    declarations
77        .iter()
78        .find(|declaration| declaration.stable_key.as_str() == key)
79}
80
81///
82/// CommittedAllocations
83///
84/// Allocation-open capability confirmed after the validated ledger generation
85/// was persisted.
86///
87/// This type is not serializable, default-constructible, or publicly
88/// constructible. Generic persistence owners obtain it only by explicitly
89/// confirming a successful [`crate::PendingBootstrapCommit`]. A
90/// [`crate::MemoryRuntime`] stores it only after that runtime's stable-cell write
91/// succeeds.
92///
93/// Its immutable declarations have validated keys, slots and diagnostic
94/// metadata, with unique keys and slots. Consumers may rely on those invariants
95/// without rebuilding uniqueness sets. The capability does not validate live
96/// store bytes, application schemas, journals or lifecycle readiness.
97///
98
99#[derive(Clone, Debug, Eq, PartialEq)]
100pub struct CommittedAllocations {
101    validated: ValidatedAllocations,
102    generation: u64,
103}
104
105impl CommittedAllocations {
106    /// Return the persisted ledger generation that grants this capability.
107    #[must_use]
108    pub const fn generation(&self) -> u64 {
109        self.generation
110    }
111
112    /// Borrow the committed allocation declarations.
113    #[must_use]
114    pub fn declarations(&self) -> &[AllocationDeclaration] {
115        self.validated.declarations()
116    }
117
118    /// Find a committed slot by stable key.
119    #[must_use]
120    pub fn slot_for(&self, key: &StableKey) -> Option<&MemoryManagerSlot> {
121        self.validated.slot_for(key)
122    }
123
124    // Runtime publication exposes application allocations only. Manual commit
125    // owners retain the complete capability returned by persistence confirmation.
126    pub(crate) fn into_application_allocations(mut self) -> Self {
127        Arc::make_mut(&mut self.validated.inner)
128            .declarations
129            .retain(|declaration| !crate::is_ic_memory_stable_key(declaration.stable_key.as_str()));
130        self
131    }
132}
133
134#[cfg(test)]
135mod tests {
136    use super::*;
137
138    #[test]
139    fn filtering_governance_does_not_change_shared_capabilities() {
140        let validated = ValidatedAllocations::new(
141            1,
142            vec![
143                AllocationDeclaration::memory_manager(
144                    crate::IC_MEMORY_LEDGER_STABLE_KEY,
145                    0,
146                    "ledger",
147                )
148                .unwrap(),
149                AllocationDeclaration::memory_manager("app.rows.v1", 100, "rows").unwrap(),
150            ],
151        );
152        let committed = validated.clone().confirm_persisted(2);
153        let filtered = committed.clone().into_application_allocations();
154
155        assert_eq!(validated.declarations().len(), 2);
156        assert_eq!(committed.declarations().len(), 2);
157        assert_eq!(filtered.declarations().len(), 1);
158        assert_eq!(
159            filtered.declarations()[0].stable_key().as_str(),
160            "app.rows.v1"
161        );
162        assert_eq!(filtered.generation(), committed.generation());
163    }
164}