pub struct BlobHydrator { /* private fields */ }Expand description
Runtime-owned bounded blob hydration with weighted raw-byte admission.
Implementations§
Source§impl BlobHydrator
impl BlobHydrator
Sourcepub fn for_mode(
store: Arc<dyn BlobStore>,
budget_bytes: u64,
read_only: bool,
) -> RuntimeResult<Self>
pub fn for_mode( store: Arc<dyn BlobStore>, budget_bytes: u64, read_only: bool, ) -> RuntimeResult<Self>
Pair a raw store with a budget under an explicitly declared
blob-runtime mode. read_only = true wraps the store so every
physical mutator refuses while the bounded read surface stays
available; false is Self::new. Boot paths that decide the blob
mode from configuration (the blob pack’s backend mode, ADR-160 D3)
construct through this so the decision travels with the hydrator —
the install seam can then hold hydrator mode against runtime mode
instead of trusting the caller’s pairing.
Sourcepub fn resolve_for_governing_backend(
cfg: &KhiveConfig,
resolve_backend: &StorageBackend,
governing_backend: &StorageBackend,
budget_bytes: u64,
) -> Result<Self, GovernedBlobError>
pub fn resolve_for_governing_backend( cfg: &KhiveConfig, resolve_backend: &StorageBackend, governing_backend: &StorageBackend, budget_bytes: u64, ) -> Result<Self, GovernedBlobError>
Resolve the configured store and pair it with the budget under the mode of the backend that GOVERNS blob mutability — the backend the blob pack maps to (ADR-160 D3), which on single-backend boots is the runtime’s own backend.
The mode is derived here from governing_backend’s own access mode,
never accepted as a caller-declared flag, and the hydrator is stamped
as governed. crate::KhiveRuntime::install_shared_blob_hydrator
accepts only governed hydrators.
Trust model (explicit policy): which backend governs blob mutability is a deployment-topology assertion made by the host that wires boot (the blob pack’s backend, ADR-160 D3), and this seam takes the caller’s word for it. What the derivation defends against is the ACCIDENTAL mode mismatch — a hand-paired writable hydrator drifting onto a read-only handle through the shared seam. It does not defend against an in-process caller who deliberately misdeclares the governing backend, because no runtime seam can: any such caller can already open the configured blob root directly (the same config and store constructors are public) and mutate it without touching a runtime handle. Read-only runtime handles are a wrong-wiring guard, not an in-process sandbox.
Sourcepub fn new(store: Arc<dyn BlobStore>, budget_bytes: u64) -> RuntimeResult<Self>
pub fn new(store: Arc<dyn BlobStore>, budget_bytes: u64) -> RuntimeResult<Self>
Pair one store with one aggregate byte budget.
Sourcepub fn budget_bytes(&self) -> u64
pub fn budget_bytes(&self) -> u64
Return the resolved aggregate admission budget.
Sourcepub async fn hydrate_verified(
&self,
content_ref: &ContentRef,
max_bytes: u64,
) -> RuntimeResult<VerifiedBlob>
pub async fn hydrate_verified( &self, content_ref: &ContentRef, max_bytes: u64, ) -> RuntimeResult<VerifiedBlob>
Hydrate one complete digest-verified object under weighted admission.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for BlobHydrator
impl !UnwindSafe for BlobHydrator
impl Freeze for BlobHydrator
impl Send for BlobHydrator
impl Sync for BlobHydrator
impl Unpin for BlobHydrator
impl UnsafeUnpin for BlobHydrator
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more