Skip to main content

FsBlobStore

Struct FsBlobStore 

Source
pub struct FsBlobStore { /* private fields */ }
Expand description

A BlobStore over <root>/<keyspace>/<64-hex> for packs (packs by default), <root>/upload-markers/v1/<64-hex> for upload markers, <root>/objects/<64-hex> for extracted objects and <root>/object-offsets/v1/<64-hex> for their offset sidecars. An upload streams into a temp file in its destination directory (named like FileTransport’s own, .<hex>.tmp.<pid>.<seq>) while hashing it, and becomes visible only once its BLAKE3 and length verify: fsync, rename over the destination, fsync the directory. A failed, aborted or dropped upload removes its temp file and never touches an existing blob. A new directory’s entry is fsynced into its parent before anything is published in it. A full disk or quota is StoreError::Full.

A process that crashes mid-upload leaves its temp file, <keyspace>/.<64-hex>.tmp.<pid>.<seq> or a corresponding marker temp file, behind. Neither is visible as a blob; FsBlobStore::sweep_stale_uploads removes old ones.

Implementations§

Source§

impl FsBlobStore

Source

pub fn new(root: impl Into<PathBuf>) -> Self

The packs keyspace under root, the directory FileTransport uploads to.

Source

pub fn with_keyspace(root: impl Into<PathBuf>, keyspace: &'static str) -> Self

The keyspace directory under root. keyspace is one plain path component; objects, object-offsets and upload-markers are the sibling namespaces’ own directories, so a pack keyspace cannot use them (its keys are refused).

§Panics

If keyspace is empty, starts with . or holds a path separator.

Source

pub fn root(&self) -> &Path

The root directory.

Source

pub fn keyspace(&self) -> &'static str

The keyspace this store serves.

Source

pub fn sweep_stale_uploads(&self, min_age: Duration) -> Result<usize>

Remove temp files crashed uploads left in the pack and marker directories: regular files named exactly .<64-hex>.tmp.<pid>.<seq> (the names temp_path gives an upload, from this store or FileTransport::upload_pack) last modified at least min_age ago. Nothing else is touched: no blob, no symlink, no other name, no file modified in the future. It also removes server-uploads session directories whose immutable meta file’s mtime is at least seven days plus one hour old, independently of min_age. An incomplete session without meta uses the directory mtime. Returns how many entries were removed; an entry that cannot be inspected or removed is skipped.

A live upload keeps its temp file’s modification time fresh as it writes, so a min_age well above any pause between two writes of one upload is safe against FileTransport writers, which take no lock. The caller must also rule out a live writer that can pause for longer, a stalled streaming upload: mkit serve sweeps only while it holds serve.lock exclusively, which no other mkit serve or mkit-server (each holds it shared) can then hold.

§Errors

I/O listing the directory; a missing directory sweeps nothing.

Trait Implementations§

Source§

impl BlobStore for FsBlobStore

Source§

type Sink = FsPackSink

The upload handle Self::begin returns.
Source§

async fn begin(&self, key: BlobKey, len: u64) -> Result<FsPackSink, StoreError>

Start writing blob key of len bytes.
Source§

async fn get( &self, key: &BlobKey, range: Option<ByteRange>, ) -> Result<Option<BlobBody>, StoreError>

The blob’s bytes, or range of them. A body longer than MAX_BLOB_PIECE_BYTES MUST be a BlobBody::Stream whose pieces are each at most MAX_BLOB_PIECE_BYTES (an adapter re-chunks its backend’s stream); a backend never buffers a whole pack. A range starting at or past the end is StoreError::RangeNotSatisfiable.
Source§

async fn head(&self, key: &BlobKey) -> Result<Option<BlobMeta>, StoreError>

The blob’s metadata, if present.
Source§

async fn probe(&self) -> Result<(), StoreError>

A cheap health check.
Source§

async fn delete(&self, key: &BlobKey) -> Result<bool, StoreError>

Remove a blob; returns whether it existed. Never called by the M0 pipeline: reserved for GC and takedown (WP-5.3b, WP-5.6).
Source§

impl Clone for FsBlobStore

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for FsBlobStore

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl MultipartBlobStore for FsBlobStore

Source§

const MAX_PARTS: u32 = u32::MAX

Maximum part count accepted by this backend.
Source§

type PartSink = FsPartSink

The upload handle returned by Self::begin_part.
Source§

fn supports_multipart(&self) -> bool

Whether this backend can start a multipart upload now.
Source§

async fn begin_multipart( &self, key: BlobKey, len: u64, part_size: u64, ) -> Result<Vec<u8>, StoreError>

Open a new storage session for a pack.
Source§

async fn begin_multipart_for_ticket( &self, key: BlobKey, len: u64, part_size: u64, ticket_id: [u8; 32], ) -> Result<Vec<u8>, StoreError>

Open a session for a known ticket. Backends that do not use the ticket id as their storage session keep their existing session format.
Source§

async fn begin_part( &self, key: BlobKey, session: &[u8], plan: &PartPlan, index: u32, expected_cv: [u8; 32], ) -> Result<FsPartSink, StoreError>

Start one part in an existing storage session.
Source§

async fn complete( &self, key: BlobKey, session: &[u8], plan: &PartPlan, parts: &[PartRef], ) -> Result<CommitOutcome, StoreError>

Atomically make the verified pack visible.
Source§

async fn complete_with_root( &self, key: BlobKey, session: &[u8], plan: &PartPlan, parts: &[PartRef], content_root: Hash, ) -> Result<CommitOutcome, StoreError>

Atomically make a verified object visible: the parts’ merged BLAKE3 root must equal content_root (the object key is an object id, not a content hash). Plain Self::complete refuses object keys, as PackSink::commit does. WP-4.10.
Source§

async fn abort(&self, key: BlobKey, session: &[u8]) -> Result<(), StoreError>

Reclaim an incomplete session. Repeated aborts succeed.
Source§

fn single_put_limit(&self) -> Option<u64>

The most bytes one BlobStore::begin upload can carry, or None when unbounded. Objects longer than this are extracted in parts.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> MaybeSend for T
where T: Send + ?Sized,

Source§

impl<T> MaybeSync for T
where T: Sync + ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more