pub struct ClientResumeRecord { /* private fields */ }Expand description
Private-field, inert, canonical client persistence record.
This type proves only that bytes are a canonical committed-record envelope;
the storage owner remains responsible for admitting bytes from exactly one
cold process epoch. Preventing two processes from restoring the same bytes
is intentionally outside this no_std protocol crate, matching the server
precedent in lifecycle/storage.rs, whose joint validation likewise does
not prevent storage-owner double restore. Issuance flags are nevertheless
preserved for token-bearing operations, so a record that testifies an
authority was already issued never silently re-mints it. Tokenless
ObserverRecovery is the deliberate exception and resolves to typed abandonment
on every restore because replay cannot be made
at-most-once without an outbound attempt token.
Implementations§
Source§impl ClientResumeRecord
impl ClientResumeRecord
Sourcepub fn encode_canonical(&self) -> Vec<u8> ⓘ
pub fn encode_canonical(&self) -> Vec<u8> ⓘ
Encodes this already-validated record in canonical v1 form.
Sourcepub fn decode_canonical(
input: &[u8],
) -> Result<Self, ClientResumeRecordDecodeError>
pub fn decode_canonical( input: &[u8], ) -> Result<Self, ClientResumeRecordDecodeError>
Decodes one exact canonical v1 client record without minting authority.
§Errors
Returns typed truncation, magic, version, tag, length, nested-codec, or trailing-byte errors.
Sourcepub fn restore(
self,
) -> Result<ClientParticipantAggregate, ClientResumeRestoreError>
pub fn restore( self, ) -> Result<ClientParticipantAggregate, ClientResumeRestoreError>
Validates cross-fact invariants and cold-restores executable client state.
§Errors
Returns a typed invariant error before any aggregate or reconnect authority escapes.