pub struct ContentIndex<S> { /* private fields */ }Expand description
The ContentIndex layer over a store’s content shards. The store must
accept every key class and atomic multi-key batches; otherwise every
mutation fails with StoreError::Unsupported.
Implementations§
Source§impl<S: NamespaceStore> ContentIndex<S>
impl<S: NamespaceStore> ContentIndex<S>
Sourcepub async fn add_hold(
&self,
object: &Hash,
hold_id: &Hash,
expires_at_ms: u64,
now_ms: u64,
) -> Result<HoldOutcome, StoreError>
pub async fn add_hold( &self, object: &Hash, hold_id: &Hash, expires_at_ms: u64, now_ms: u64, ) -> Result<HoldOutcome, StoreError>
Record GC hold hold_id on object until expires_at_ms.
Re-adding keeps the later of the two expiries. Taken before the
ref-shard apply that makes the object reachable (PRD §5.3). The TTL
must exceed MAX_APPLY_WINDOW plus the relay-lag bound (00-plan
P-21, P-23) and is capped at MAX_HOLD_TTL_MS.
§Errors
StoreError::Invalid if the hold is already expired or longer
than MAX_HOLD_TTL_MS; a retryable StoreError::Unavailable
while GC is deleting the object.
Sourcepub async fn extend_hold(
&self,
object: &Hash,
hold_id: &Hash,
expires_at_ms: u64,
now_ms: u64,
) -> Result<HoldOutcome, StoreError>
pub async fn extend_hold( &self, object: &Hash, hold_id: &Hash, expires_at_ms: u64, now_ms: u64, ) -> Result<HoldOutcome, StoreError>
Extend hold hold_id on object to expires_at_ms, only if it is
still recorded and live at now_ms. A hold that is gone or expired
may already have been passed by GC, so it is not brought back: the
caller redoes from the head check.
§Errors
StoreError::Invalid as for Self::add_hold; a retryable
StoreError::Unavailable while GC is deleting the object or when
the hold is no longer live.
Sourcepub async fn protect_pending_holder(
&self,
object: &Hash,
hold_id: &Hash,
identity: &PendingHolderV1,
now_ms: u64,
) -> Result<HoldOutcome, StoreError>
pub async fn protect_pending_holder( &self, object: &Hash, hold_id: &Hash, identity: &PendingHolderV1, now_ms: u64, ) -> Result<HoldOutcome, StoreError>
Establish durable queued-holder ownership before creating a source
relay intent. Identical retries do not bump c; a different owner
cannot replace it. No expiration or unguarded removal is supported.
The value binds repository, source, verification job and intent.
Sourcepub async fn release_hold(
&self,
object: &Hash,
hold_id: &Hash,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn release_hold( &self, object: &Hash, hold_id: &Hash, now_ms: u64, ) -> Result<(), StoreError>
Release hold hold_id. Normally the relay step that records the
holder row releases it in the same batch (see Self::add_holder,
WP-4.10, R-75); this standalone form is for abandoned uploads.
Sourcepub async fn add_holder(
&self,
object: &Hash,
holder: &Holder,
op_id: &Hash,
releases: Option<&Hash>,
now_ms: u64,
) -> Result<HolderOutcome, StoreError>
pub async fn add_holder( &self, object: &Hash, holder: &Holder, op_id: &Hash, releases: Option<&Hash>, now_ms: u64, ) -> Result<HolderOutcome, StoreError>
Record that holder holds object (idempotent), releasing hold
releases in the same batch: a dedup hold is released only when its
holder row is recorded (PRD §6.7). op_id is the consuming ticket.
Every call advances the object’s sequence and rewrites the row, also
when the holder was already recorded (SPEC-SERVER §13.3), so the
count changes only for a new holder. A blocked object is still
recorded, and reported in the outcome.
§Errors
A retryable StoreError::Unavailable while GC is deleting the
object, or when the batch missed its NotAfter deadline.
Sourcepub async fn add_holder_unless_blocked(
&self,
object: &Hash,
holder: &Holder,
op_id: &Hash,
releases: Option<&Hash>,
now_ms: u64,
) -> Result<HolderOutcome, StoreError>
pub async fn add_holder_unless_blocked( &self, object: &Hash, holder: &Holder, op_id: &Hash, releases: Option<&Hash>, now_ms: u64, ) -> Result<HolderOutcome, StoreError>
Like Self::add_holder, but a blocked object is not recorded: the
hold releases is deleted in the same guarded batch and the outcome
carries the block entry, so the caller fails the upload and the bytes
fall to ordinary GC (SPEC-SERVER §14.2). Used by extraction; the relay
still records blocked holders (R-75).
§Errors
As Self::add_holder.
Sourcepub async fn holder_record(
&self,
object: &Hash,
holder: &Holder,
) -> Result<Option<HolderRecord>, StoreError>
pub async fn holder_record( &self, object: &Hash, holder: &Holder, ) -> Result<Option<HolderRecord>, StoreError>
The record of holder of object, if recorded.
Sourcepub async fn remove_holder(
&self,
object: &Hash,
holder: &Holder,
expected_seq: u64,
now_ms: u64,
) -> Result<bool, StoreError>
pub async fn remove_holder( &self, object: &Hash, holder: &Holder, expected_seq: u64, now_ms: u64, ) -> Result<bool, StoreError>
Remove holder of object, only if its row still carries
expected_seq (the sequence of the record the caller read). true
if it was removed; false (a no-op) when the holder is absent or was
written again since (SPEC-SERVER §13.3 step 4).
Sourcepub async fn holders(
&self,
object: &Hash,
after: Option<&Cursor>,
limit: u32,
) -> Result<HolderPage, StoreError>
pub async fn holders( &self, object: &Hash, after: Option<&Cursor>, limit: u32, ) -> Result<HolderPage, StoreError>
Up to limit holders of object after after.
Sourcepub async fn block(
&self,
object: &Hash,
entry: &BlockEntry,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn block( &self, object: &Hash, entry: &BlockEntry, now_ms: u64, ) -> Result<(), StoreError>
Put object on the global blocklist (replacing any entry).
§Errors
StoreError::Invalid if the reason exceeds
MAX_BLOCK_REASON_BYTES.
Sourcepub async fn install_block_action(
&self,
object: &Hash,
action: &BlockAction,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn install_block_action( &self, object: &Hash, action: &BlockAction, now_ms: u64, ) -> Result<(), StoreError>
Install an independent V2 action without replacing any current V1 denial.
Sourcepub async fn install_stored_block_action(
&self,
object: &Hash,
staged: &StoredAction,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn install_stored_block_action( &self, object: &Hash, staged: &StoredAction, now_ms: u64, ) -> Result<(), StoreError>
Activate already verified immutable metadata without reading source bytes.
Sourcepub async fn unblock(
&self,
object: &Hash,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn unblock( &self, object: &Hash, now_ms: u64, ) -> Result<(), StoreError>
Take object off the blocklist.
Sourcepub async fn blocked(
&self,
object: &Hash,
) -> Result<Option<BlockEntry>, StoreError>
pub async fn blocked( &self, object: &Hash, ) -> Result<Option<BlockEntry>, StoreError>
The blocklist entry of object, if blocked.
Sourcepub async fn state(
&self,
object: &Hash,
) -> Result<Option<ObjectState>, StoreError>
pub async fn state( &self, object: &Hash, ) -> Result<Option<ObjectState>, StoreError>
The state row of object, if it was ever indexed.
Sourcepub async fn collectable(
&self,
object: &Hash,
now_ms: u64,
grace_ms: u64,
) -> Result<Option<GcPlan>, StoreError>
pub async fn collectable( &self, object: &Hash, now_ms: u64, grace_ms: u64, ) -> Result<Option<GcPlan>, StoreError>
Step 1 of the GC ordering (module docs). Whether GC may delete
object at now_ms: not already deleting, zero holders, zero
live holds (a hold is live while now_ms < expires_at_ms), and
now_ms - last change >= grace_ms. If so, the GcPlan that
commits the decision.
Sourcepub async fn commit_collect(&self, plan: GcPlan) -> Result<bool, StoreError>
pub async fn commit_collect(&self, plan: GcPlan) -> Result<bool, StoreError>
Step 2 of the GC ordering: apply plan. true if it committed and
the object is now deleting, so GC may delete its bytes; false if
anything changed since the plan was made.
Sourcepub async fn finish_collect(
&self,
object: &Hash,
now_ms: u64,
) -> Result<(), StoreError>
pub async fn finish_collect( &self, object: &Hash, now_ms: u64, ) -> Result<(), StoreError>
Step 4 of the GC ordering: after the bytes are deleted, clear
deleting so the object can be uploaded again. A no-op if it is not
set.