Skip to main content

ContentIndex

Struct ContentIndex 

Source
pub struct ContentIndex<S> { /* private fields */ }
Expand description

The ContentIndex layer over a store’s content shards. The store must accept every key class and atomic multi-key batches; otherwise every mutation fails with StoreError::Unsupported.

Implementations§

Source§

impl<S: NamespaceStore> ContentIndex<S>

Source

pub fn new(store: S) -> Self

Wrap store.

Source

pub fn store(&self) -> &S

The underlying store.

Source

pub async fn add_hold( &self, object: &Hash, hold_id: &Hash, expires_at_ms: u64, now_ms: u64, ) -> Result<HoldOutcome, StoreError>

Record GC hold hold_id on object until expires_at_ms. Re-adding keeps the later of the two expiries. Taken before the ref-shard apply that makes the object reachable (PRD §5.3). The TTL must exceed MAX_APPLY_WINDOW plus the relay-lag bound (00-plan P-21, P-23) and is capped at MAX_HOLD_TTL_MS.

§Errors

StoreError::Invalid if the hold is already expired or longer than MAX_HOLD_TTL_MS; a retryable StoreError::Unavailable while GC is deleting the object.

Source

pub async fn extend_hold( &self, object: &Hash, hold_id: &Hash, expires_at_ms: u64, now_ms: u64, ) -> Result<HoldOutcome, StoreError>

Extend hold hold_id on object to expires_at_ms, only if it is still recorded and live at now_ms. A hold that is gone or expired may already have been passed by GC, so it is not brought back: the caller redoes from the head check.

§Errors

StoreError::Invalid as for Self::add_hold; a retryable StoreError::Unavailable while GC is deleting the object or when the hold is no longer live.

Source

pub async fn protect_pending_holder( &self, object: &Hash, hold_id: &Hash, identity: &PendingHolderV1, now_ms: u64, ) -> Result<HoldOutcome, StoreError>

Establish durable queued-holder ownership before creating a source relay intent. Identical retries do not bump c; a different owner cannot replace it. No expiration or unguarded removal is supported. The value binds repository, source, verification job and intent.

Source

pub async fn release_hold( &self, object: &Hash, hold_id: &Hash, now_ms: u64, ) -> Result<(), StoreError>

Release hold hold_id. Normally the relay step that records the holder row releases it in the same batch (see Self::add_holder, WP-4.10, R-75); this standalone form is for abandoned uploads.

Source

pub async fn add_holder( &self, object: &Hash, holder: &Holder, op_id: &Hash, releases: Option<&Hash>, now_ms: u64, ) -> Result<HolderOutcome, StoreError>

Record that holder holds object (idempotent), releasing hold releases in the same batch: a dedup hold is released only when its holder row is recorded (PRD §6.7). op_id is the consuming ticket. Every call advances the object’s sequence and rewrites the row, also when the holder was already recorded (SPEC-SERVER §13.3), so the count changes only for a new holder. A blocked object is still recorded, and reported in the outcome.

§Errors

A retryable StoreError::Unavailable while GC is deleting the object, or when the batch missed its NotAfter deadline.

Source

pub async fn add_holder_unless_blocked( &self, object: &Hash, holder: &Holder, op_id: &Hash, releases: Option<&Hash>, now_ms: u64, ) -> Result<HolderOutcome, StoreError>

Like Self::add_holder, but a blocked object is not recorded: the hold releases is deleted in the same guarded batch and the outcome carries the block entry, so the caller fails the upload and the bytes fall to ordinary GC (SPEC-SERVER §14.2). Used by extraction; the relay still records blocked holders (R-75).

§Errors

As Self::add_holder.

Source

pub async fn holder_record( &self, object: &Hash, holder: &Holder, ) -> Result<Option<HolderRecord>, StoreError>

The record of holder of object, if recorded.

Source

pub async fn remove_holder( &self, object: &Hash, holder: &Holder, expected_seq: u64, now_ms: u64, ) -> Result<bool, StoreError>

Remove holder of object, only if its row still carries expected_seq (the sequence of the record the caller read). true if it was removed; false (a no-op) when the holder is absent or was written again since (SPEC-SERVER §13.3 step 4).

Source

pub async fn holders( &self, object: &Hash, after: Option<&Cursor>, limit: u32, ) -> Result<HolderPage, StoreError>

Up to limit holders of object after after.

Source

pub async fn block( &self, object: &Hash, entry: &BlockEntry, now_ms: u64, ) -> Result<(), StoreError>

Put object on the global blocklist (replacing any entry).

§Errors

StoreError::Invalid if the reason exceeds MAX_BLOCK_REASON_BYTES.

Source

pub async fn install_block_action( &self, object: &Hash, action: &BlockAction, now_ms: u64, ) -> Result<(), StoreError>

Install an independent V2 action without replacing any current V1 denial.

Source

pub async fn install_stored_block_action( &self, object: &Hash, staged: &StoredAction, now_ms: u64, ) -> Result<(), StoreError>

Activate already verified immutable metadata without reading source bytes.

Source

pub async fn unblock( &self, object: &Hash, now_ms: u64, ) -> Result<(), StoreError>

Take object off the blocklist.

Source

pub async fn blocked( &self, object: &Hash, ) -> Result<Option<BlockEntry>, StoreError>

The blocklist entry of object, if blocked.

Source

pub async fn state( &self, object: &Hash, ) -> Result<Option<ObjectState>, StoreError>

The state row of object, if it was ever indexed.

Source

pub async fn collectable( &self, object: &Hash, now_ms: u64, grace_ms: u64, ) -> Result<Option<GcPlan>, StoreError>

Step 1 of the GC ordering (module docs). Whether GC may delete object at now_ms: not already deleting, zero holders, zero live holds (a hold is live while now_ms < expires_at_ms), and now_ms - last change >= grace_ms. If so, the GcPlan that commits the decision.

Source

pub async fn commit_collect(&self, plan: GcPlan) -> Result<bool, StoreError>

Step 2 of the GC ordering: apply plan. true if it committed and the object is now deleting, so GC may delete its bytes; false if anything changed since the plan was made.

Source

pub async fn finish_collect( &self, object: &Hash, now_ms: u64, ) -> Result<(), StoreError>

Step 4 of the GC ordering: after the bytes are deleted, clear deleting so the object can be uploaded again. A no-op if it is not set.

Trait Implementations§

Source§

impl<S: Clone> Clone for ContentIndex<S>

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<S: Debug> Debug for ContentIndex<S>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl<S> Freeze for ContentIndex<S>
where S: Freeze,

§

impl<S> RefUnwindSafe for ContentIndex<S>
where S: RefUnwindSafe,

§

impl<S> Send for ContentIndex<S>
where S: Send,

§

impl<S> Sync for ContentIndex<S>
where S: Sync,

§

impl<S> Unpin for ContentIndex<S>
where S: Unpin,

§

impl<S> UnsafeUnpin for ContentIndex<S>
where S: UnsafeUnpin,

§

impl<S> UnwindSafe for ContentIndex<S>
where S: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> MaybeSend for T
where T: Send + ?Sized,

Source§

impl<T> MaybeSync for T
where T: Sync + ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more