pub struct FileContentStream<S> { /* private fields */ }Expand description
One file’s current content, read as fixed-size ranged chunks.
This is the streaming twin of the buffered content read, for a reader that must not hold what it reads: chunks are fetched one range at a time and the verifying digest is folded as they go, so a 50 GiB object costs one chunk of memory rather than 50 GiB. It verifies exactly what the buffered read verifies — the declared size, and the reference’s trusted whole-file SHA-256 when it has one, otherwise its own storage checksum, which for a provider-assembled object is the only full-object evidence there is. A reference whose checksum this build cannot recompute is refused when the stream is opened, before any byte is fetched, rather than after.
The object is immutable and named by a random content id, so nothing can rewrite it under a reader: chunk n and chunk n+1 are always from the same object, and no revalidation between them is needed or done.
Verification lands on the final Self::next_chunk call — the one that
reports the end of the content. A caller that stops early stops with
unverified bytes, which is what streaming means and why the buffered read
stays for callers that want the whole answer or none of it.
Implementations§
Source§impl<S: ObjectStore> FileContentStream<S>
impl<S: ObjectStore> FileContentStream<S>
Sourcepub fn fold_resumed_prefix(&mut self, bytes: &[u8])
pub fn fold_resumed_prefix(&mut self, bytes: &[u8])
Hands the stream part of what the caller already holds, in order, from the object’s first byte.
A resumed read still reports on the whole object, so the bytes it will never fetch have to be folded into the same digest that closes over the ones it does. Feeding the wrong bytes fails verification at the end, which is exactly right: the reference is the authority on what the object holds, not the partial copy on the caller’s disk.
Sourcepub fn entry(&self) -> &AuthoritativePathEntry
pub fn entry(&self) -> &AuthoritativePathEntry
The authoritative metadata entry the path resolved to.
Sourcepub fn size_bytes(&self) -> u64
pub fn size_bytes(&self) -> u64
Complete length of the content this stream reads.
Sourcepub async fn next_chunk(&mut self) -> Result<Option<Bytes>, CoreError>
pub async fn next_chunk(&mut self) -> Result<Option<Bytes>, CoreError>
Fetches the next chunk, or reports the end of a verified read.
Ok(None) is returned only after the folded digest and the byte count
agree with the reference; a mismatch fails this call instead. Chunks
arrive in order from wherever the stream started, and every one but
the last is exactly the chunk size this stream was opened with.
This is the method callers outside this crate hold, so it speaks the crate’s error type: a content object that disagrees with its reference is namespace corruption, and it is classified as such here rather than at every call site. A resumed stream that has not been told what it skipped is the caller’s own mistake instead, and says so before anything is fetched.
Trait Implementations§
Auto Trait Implementations§
impl<S> Freeze for FileContentStream<S>where
S: Freeze,
impl<S> RefUnwindSafe for FileContentStream<S>where
S: RefUnwindSafe,
impl<S> Send for FileContentStream<S>where
S: Send,
impl<S> Sync for FileContentStream<S>where
S: Sync,
impl<S> Unpin for FileContentStream<S>where
S: Unpin,
impl<S> UnsafeUnpin for FileContentStream<S>where
S: UnsafeUnpin,
impl<S> UnwindSafe for FileContentStream<S>where
S: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more