Skip to main content

BlobHydrator

Struct BlobHydrator 

Source
pub struct BlobHydrator { /* private fields */ }
Expand description

Runtime-owned bounded blob hydration with weighted raw-byte admission.

Implementations§

Source§

impl BlobHydrator

Source

pub fn for_mode( store: Arc<dyn BlobStore>, budget_bytes: u64, read_only: bool, ) -> RuntimeResult<Self>

Pair a raw store with a budget under an explicitly declared blob-runtime mode. read_only = true wraps the store so every physical mutator refuses while the bounded read surface stays available; false is Self::new. Boot paths that decide the blob mode from configuration (the blob pack’s backend mode, ADR-160 D3) construct through this so the decision travels with the hydrator — the install seam can then hold hydrator mode against runtime mode instead of trusting the caller’s pairing.

Source

pub fn resolve_for_governing_backend( cfg: &KhiveConfig, resolve_backend: &StorageBackend, governing_backend: &StorageBackend, budget_bytes: u64, ) -> Result<Self, GovernedBlobError>

Resolve the configured store and pair it with the budget under the mode of the backend that GOVERNS blob mutability — the backend the blob pack maps to (ADR-160 D3), which on single-backend boots is the runtime’s own backend.

The mode is derived here from governing_backend’s own access mode, never accepted as a caller-declared flag, and the hydrator is stamped as governed. crate::KhiveRuntime::install_shared_blob_hydrator accepts only governed hydrators.

Trust model (explicit policy): which backend governs blob mutability is a deployment-topology assertion made by the host that wires boot (the blob pack’s backend, ADR-160 D3), and this seam takes the caller’s word for it. What the derivation defends against is the ACCIDENTAL mode mismatch — a hand-paired writable hydrator drifting onto a read-only handle through the shared seam. It does not defend against an in-process caller who deliberately misdeclares the governing backend, because no runtime seam can: any such caller can already open the configured blob root directly (the same config and store constructors are public) and mutate it without touching a runtime handle. Read-only runtime handles are a wrong-wiring guard, not an in-process sandbox.

Source

pub fn new(store: Arc<dyn BlobStore>, budget_bytes: u64) -> RuntimeResult<Self>

Pair one store with one aggregate byte budget.

Source

pub fn budget_bytes(&self) -> u64

Return the resolved aggregate admission budget.

Source

pub async fn hydrate_verified( &self, content_ref: &ContentRef, max_bytes: u64, ) -> RuntimeResult<VerifiedBlob>

Hydrate one complete digest-verified object under weighted admission.

Trait Implementations§

Source§

impl Debug for BlobHydrator

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more