Skip to main content

FileContentStream

Struct FileContentStream 

Source
pub struct FileContentStream<S> { /* private fields */ }
Expand description

One file’s current content, read as fixed-size ranged chunks.

This is the streaming twin of the buffered content read, for a reader that must not hold what it reads: chunks are fetched one range at a time and the verifying digest is folded as they go, so a 50 GiB object costs one chunk of memory rather than 50 GiB. It verifies exactly what the buffered read verifies — the declared size, and the reference’s trusted whole-file SHA-256 when it has one, otherwise its own storage checksum, which for a provider-assembled object is the only full-object evidence there is. A reference whose checksum this build cannot recompute is refused when the stream is opened, before any byte is fetched, rather than after.

The object is immutable and named by a random content id, so nothing can rewrite it under a reader: chunk n and chunk n+1 are always from the same object, and no revalidation between them is needed or done.

Verification lands on the final Self::next_chunk call — the one that reports the end of the content. A caller that stops early stops with unverified bytes, which is what streaming means and why the buffered read stays for callers that want the whole answer or none of it.

Implementations§

Source§

impl<S: ObjectStore> FileContentStream<S>

Source

pub fn fold_resumed_prefix(&mut self, bytes: &[u8])

Hands the stream part of what the caller already holds, in order, from the object’s first byte.

A resumed read still reports on the whole object, so the bytes it will never fetch have to be folded into the same digest that closes over the ones it does. Feeding the wrong bytes fails verification at the end, which is exactly right: the reference is the authority on what the object holds, not the partial copy on the caller’s disk.

Source

pub fn entry(&self) -> &AuthoritativePathEntry

The authoritative metadata entry the path resolved to.

Source

pub fn size_bytes(&self) -> u64

Complete length of the content this stream reads.

Source

pub async fn next_chunk(&mut self) -> Result<Option<Bytes>, CoreError>

Fetches the next chunk, or reports the end of a verified read.

Ok(None) is returned only after the folded digest and the byte count agree with the reference; a mismatch fails this call instead. Chunks arrive in order from wherever the stream started, and every one but the last is exactly the chunk size this stream was opened with.

This is the method callers outside this crate hold, so it speaks the crate’s error type: a content object that disagrees with its reference is namespace corruption, and it is classified as such here rather than at every call site. A resumed stream that has not been told what it skipped is the caller’s own mistake instead, and says so before anything is fetched.

Trait Implementations§

Source§

impl<S> Debug for FileContentStream<S>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl<S> Freeze for FileContentStream<S>
where S: Freeze,

§

impl<S> RefUnwindSafe for FileContentStream<S>
where S: RefUnwindSafe,

§

impl<S> Send for FileContentStream<S>
where S: Send,

§

impl<S> Sync for FileContentStream<S>
where S: Sync,

§

impl<S> Unpin for FileContentStream<S>
where S: Unpin,

§

impl<S> UnsafeUnpin for FileContentStream<S>
where S: UnsafeUnpin,

§

impl<S> UnwindSafe for FileContentStream<S>
where S: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more