pub struct RuntimeStore { /* private fields */ }Expand description
SQLite-backed durable runtime state.
Implementations§
Source§impl RuntimeStore
impl RuntimeStore
Sourcepub fn open_default() -> Result<Self>
pub fn open_default() -> Result<Self>
Open the store at its default location under the app data dir, creating and (best-effort) locking down that dir first.
§Errors
Resolving the data dir, creating it, and everything Self::open
reports. Tightening permissions is best-effort on both platforms and
never fails the open, so an Ok store is not proof the data dir is
owner-only.
Sourcepub fn open(path: impl AsRef<Path>) -> Result<Self>
pub fn open(path: impl AsRef<Path>) -> Result<Self>
Open (creating if needed) the SQLite store at path, then apply the
connection pragmas and run the schema migration.
§Errors
Creating the parent directory, opening the database — a corrupt file or
a directory the process cannot write — setting the connection pragmas,
and the schema migration. A concurrent opener is not among them: WAL
plus the busy timeout is exactly what keeps a second process from
failing here with SQLITE_BUSY.
pub fn path(&self) -> &Path
pub fn sessions(&self) -> SessionsRepo<'_>
pub fn messages(&self) -> MessagesRepo<'_>
pub fn tasks(&self) -> TasksRepo<'_>
pub fn tool_runs(&self) -> ToolRunsRepo<'_>
pub fn approvals(&self) -> ApprovalsRepo<'_>
pub fn processes(&self) -> ProcessesRepo<'_>
pub fn checkpoints(&self) -> CheckpointsRepo<'_>
pub fn compactions(&self) -> CompactionsRepo<'_>
pub fn plugins(&self) -> PluginsRepo<'_>
pub fn provider_probes(&self) -> ProviderProbesRepo<'_>
pub fn pairing_tokens(&self) -> PairingTokensRepo<'_>
pub fn outcomes(&self) -> OutcomesRepo<'_>
Sourcepub fn reconcile_after_restart(&self) -> Result<(usize, usize)>
pub fn reconcile_after_restart(&self) -> Result<(usize, usize)>
Recover state stranded by a previous daemon’s crash/stop (#120, #118).
A Running task’s worker died with the daemon, so it can never finish —
mark it failed with an event. An approval left in the transient
approving claim state (a replay that crashed mid-effect, #118) is reset
to undecided so it reappears as pending and stays re-runnable. Call once
on daemon startup, before serving. Returns (tasks_reset, claims_released).
F18 (RC-E): only daemon-owned running tasks are reset. The store is
shared with interactive mermaid CLI runs; their tasks are created with a
NULL owner_kind and are LEFT RUNNING here, so a live CLI session isn’t
wrongly flipped to failed (with a spurious “interrupted” event) just
because the daemon restarted. The daemon tags the tasks it runs in-process
via NewTask::daemon_owned.
§Errors
Taking the BEGIN IMMEDIATE write lock — which waits out a concurrent
writer for busy_timeout before giving up — and any statement in the
pass. Every failure rolls the transaction back, so recovery is
all-or-nothing: no task is left flipped to failed without its
interrupted event, and no claim is released without the tasks beside
it. The caller may simply run it again.
Sourcepub fn gc(
&self,
retention_days: i64,
outcomes_retention_days: i64,
) -> Result<u64>
pub fn gc( &self, retention_days: i64, outcomes_retention_days: i64, ) -> Result<u64>
Best-effort retention GC (#130, F22/RC-F): prune archived
approvals/checkpoints, the events of long-finished tasks, terminal tasks,
and the high-churn / old rows of the remaining tables, all older than
retention_days. The append-only outcomes reward table — the
self-improving-loop training corpus — is pruned on its own, longer
outcomes_retention_days window so a large training history survives the
shorter task/session window. Deletes only archived, finished, or
terminal-and-old rows — active data is never touched (a running task,
a still-open tool run, a live process, or a recently-updated session all
survive). Returns the number of rows removed.
§Errors
Opening the transaction and any DELETE in it. The whole pass is one
transaction, so a failure prunes nothing and the returned count is
never partial. Having nothing to prune is Ok(0).