Expand description
The storage contract (PRD §5.3): the key-level NamespaceStore, the
content-addressed BlobStore, and the key layouts, value codecs and
typed readers every backend shares. Nothing here needs SQL: a
single-writer key-value store implements the whole contract.
Layers over the contract that work on any backend: the global
ContentIndex, the portable logical export and import, and the
optional StoreMaintenance and StateCommitment hooks.
The contract types are also re-exported at the crate root; keys,
codec and read stay namespaced.
Modules§
- codec
- Value codecs. Structured values are
serde_jsonbehind a leading version byte (CODEC_V1); refs are the raw 32-byte id and integers are raw big-endian. Decoding an unknown version, a wrong length or a value that fails validation isStoreError::Corrupt. - index
- Repository-scoped, write-once object index rows. A row becomes visible only when its pack’s repository membership row exists. Production writers are installed by WP-4.7 and WP-4.8.
- inspection_
flags - Repository flags and their monotonic version share the canonical zero-id object-index partition.
- inspection_
holds - Repository-wide inspection holds; kind-14 work writes content rows after advance commit.
- inspection_
mode - One-way deployment inspection marker, checked before other startup writes.
- keys
- Key layouts: the registry of every row and index the server stores (reconciliation R-17). Indexes are layouts, not queries.
- outbox
- Pure reservation and outbox fragments. One guarded
orow arbitrates Ticketed or Pending -> terminal; delivery removes that row only after acknowledgement. - publication
RefShardauthority for paired publication and retained inspection obligations.- read
- Typed readers over any
NamespaceStore: thestore::keyslayouts andstore::codecvalues in one place, so no backend reimplements them. - restore
- Restore portable partition exports into a quiesced, fresh store.
- tickets
- Pure ticket/counter and ref-shard membership fragments. Callers supply time and read snapshots, compose these fragments with their ref/replay writes, and apply the complete batch in one partition.
- view
- Request-local read view. Every batched read remains one underlying store call.
- watermark
- Coordinator relay watermark and shard enumeration. The value is a lower
bound on the commit time of every undelivered relay row. Consumers compare
it against
T + MAX_APPLY_WINDOW + margin. A new shard’s first report may be stale-low, so the namespace result can decrease without recovery; recovery can reset maxima too.
Structs§
- Batch
- One atomic, declarative write: preconditions, then puts and deletes in order (a later write to the same key wins). A batch with no writes only checks.
- BlobKey
- A blob’s content hash and storage namespace. Pack RPCs construct only
Packkeys, so an upload marker cannot be fetched as a pack. - Blob
Meta - A blob’s metadata.
- Block
Entry - A blocklist entry (PRD §6.7 takedown).
- Byte
Range - An inclusive byte range, as in HTTP
Range. - Content
Index - The
ContentIndexlayer over a store’s content shards. The store must accept every key class and atomic multi-key batches; otherwise every mutation fails withStoreError::Unsupported. - Cursor
- An opaque scan cursor. Callers only pass back one that a
NamespaceStore::scanreturned for the same range. - Export
Header - What an export was taken from.
- Export
Page - One page of
export_page. - Export
Reader - Reads an export’s records from its bytes; see
encode_export_record. - Export
Record - One exported row.
- Export
Stream - The record stream of
export_partition. - GcPlan
- A GC delete plan from
ContentIndex::collectable: one batch in the object’s shard, guarded on the state row it checked, that prunes the expired holds and setsdeleting. Apply it withContentIndex::commit_collect. - Holder
- A repository that holds an object.
- Holder
Outcome - The result of
ContentIndex::add_holder. - Holder
Page - One page of
ContentIndex::holders. - Holder
Record - A holder row’s value (R-131).
- Importer
- Restores exported records into a store, in batches within
MAX_BATCH_OPSandMAX_BATCH_BYTES(so they fit Durable Object limits), one partition per batch; one write per batch on a store withoutatomic_multi_key. A partition’s records must be contiguous, as an export writes them. - Key
- A key. Keys order by raw bytes;
store::keysowns every layout. - Object
State - An object’s state row. Absent means never indexed: no holders, no holds, last change at 0, not deleting.
- PartRef
- A stored part reference recovered from a server-authenticated receipt.
- Partition
Stats - Storage used by one partition.
- Pending
Holder V1 - Identity of a pending extraction holder intent, stored under
gp. - Range
Scan - One ordered range in a batched scan. Its cursor belongs to this exact
range, just as for
NamespaceStore::scan. - Scan
Page - One page of a
NamespaceStore::scan. - Store
Capabilities - What a store supports. The pipeline plans around it. Start from
StoreCapabilities::fullorStoreCapabilities::refs_onlyand set fields: the struct is#[non_exhaustive], so later fields default safely. - Unsupported
Part Sink - The sink type for backends whose multipart support arrives later.
- Value
- An opaque value. A backend never interprets it.
Enums§
- Batch
Outcome - The result of
NamespaceStore::apply. - Blob
Body - A blob’s bytes, whole or streamed.
- Blob
Namespace - The physical namespace of a content-addressed blob.
- Commit
Outcome - How a
PackSink::commitended. - Hold
Outcome - The result of
ContentIndex::add_hold. - Import
Mode - How an
Importertreats a partition that already holds rows. - KeyClasses
- Which key classes (
store::keys) a store accepts. - Membership
Mode - How repo membership of a pack is decided (overview Q16).
- Partition
- A storage partition: one D34 shard. Everything that must commit
atomically lives in one partition. The core computes the partition of
every operation; a backend maps partitions to whatever it likes (a
Durable Object each, rows keyed by partition in
SQLite, a qmdb instance each). - Precondition
- A condition a
Batchchecks before it writes: raw key/byte checks, not the ref CAS. A planner decides a ref write withcrate::refs::evaluate_conditionon the value it read, then guards that read here (AbsentorEqualson the ref key) so the decision still holds at commit. - Store
Error - Why a storage call failed. A failed precondition is not an error: it is
crate::BatchOutcome::PreconditionFailed. - Write
- A write in a
Batch.
Constants§
- CONTENT_
APPLY_ WINDOW_ MS - How long a hold or holder batch may take to reach the store, from the
now_msits plan was made at (NotAfter, SPEC-WRITE-GRANTS §5.5). The same bound asMAX_APPLY_WINDOW. - EXPORT_
END - End marker: a record whose partition length is 0. A reader requires it, so a truncated export never imports as a shorter one.
- EXPORT_
FORMAT_ V1 - The export byte format this binary writes and reads.
- EXPORT_
MAGIC - First bytes of every export.
- INDEX_
FANOUT - Object-id prefix fan-out of the content shards (and repo index shards): a fixed deployment constant, never resharded (PRD §5.3, D34).
- MAX_
BATCH_ BYTES - Most key and value bytes, summed over a
Batch’s preconditions and writes. - MAX_
BATCH_ OPS - Most preconditions plus writes in one
Batch. - MAX_
BLOB_ PIECE_ BYTES - Largest piece of a streamed
BlobBody, and the longest body aBlobStore::getmay return as one buffer. - MAX_
BLOCK_ REASON_ BYTES - Longest
BlockEntry::reason, in bytes. - MAX_
HOLD_ TTL_ MS - Longest hold, from
now_msto its expiry: 24 hours. A hold must outliveMAX_APPLY_WINDOWplus the relay-lag bound (00-plan P-21, P-23); the cap stops a caller from pinning an object indefinitely. - MAX_
KEY_ BYTES - Longest accepted key, in bytes.
- MAX_
SCAN_ RANGES - Most ranges accepted by one
NamespaceStore::scan_manycall. - MAX_
VALUE_ BYTES - Longest accepted value, in bytes; below
MAX_BATCH_BYTES. - REF_
INDEX_ FANOUT - Ref-name hash fan-out: a fixed deployment constant, never resharded (PRD §5.3, D34).
Traits§
- Blob
Store - A content-addressed, immutable blob store. Writes are put-if-absent;
rewriting a present key with identical bytes is
AlreadyPresent. - Multipart
Blob Store - A resumable blob store with opaque storage sessions and verified parts.
- Namespace
Store - The metadata store: a partitioned, ordered key-value store. Any backend that can do an atomic conditional multi-key write per partition and an ordered range read can implement it: SQL is not required.
- Pack
Sink - An in-progress blob upload.
- Part
Sink - A verified, staged part.
commitmakes only this part durable; the pack remains invisible untilMultipartBlobStore::complete. - State
Commitment - A future verifiable state root over a partition (R-21). Optional and unimplemented in the epic; the pipeline never requires it.
- Store
Maintenance - Backend-defined maintenance (R-19). Optional: the pipeline never calls
it.
SQLiteimplements it with versioned physical migrations andVACUUM INTO(M0-09); another backend may implement it however it likes, and every backend still has the portable export above.
Functions§
- content_
shard - The content shard of
object: its top 12 bits. - content_
shards - Every content shard, by construction (the
Partitionenumeration rule 5). - encode_
export_ header - The export header bytes:
EXPORT_MAGIC,EXPORT_FORMAT_V1, the layout version (be32) and the export time (be64). - encode_
export_ record - One record’s bytes: partition length (be16, never 0) and
Partition::encodebytes, key length (be16) and key, value length (be32) and value. An export is the header, its records, thenEXPORT_END. - export_
header - The header of an export of
ptaken atnow_ms. - export_
page - Up to
limitrows ofpafterafter, in key order: one stateless step of an export (a Durable Object serves it per call). - export_
partition - Portable logical backup of one partition: its header and a stream of every row in key order. The stream is not a snapshot: rows written while it runs may or may not appear, so export a quiesced partition.
- import_
stream - Import a record stream (such as an
ExportStream) taken underheader; the number of records imported. Records carry their partition, so one stream may restore several partitions. - is_
reserved_ pack_ keyspace - Whether
keyspace(a pack keyspace, possibly with a deployment prefix) would alias a sibling namespace directory: its last segment isobjects,object-offsetsorupload-markers, or its last two areobject-offsets/v1orupload-markers/v1. Segments compare case-insensitively and ignoring trailing dots and spaces, since a case-folding or Windows-style filesystem maps them onto the same directory. Backends refuse such a keyspace at construction and inBlobKey::relative_path.
Type Aliases§
- BoxError
- A boxed backend error:
Send + Syncon native targets only, because Workers errors are!Send.