pub struct OutboxBuilder { /* private fields */ }Expand description
One batch’s outbox edits, using a single snapshot of os and oc.
The fixed infallible fragment methods defer malformed inputs/overflow
until finish. try_finish reports these errors without changing its
output vectors. finish instead appends mutually exclusive guards,
making the entire caller batch fail closed with no writes applied.
Use one builder per batch, finishing it before any acknowledgements.
Implementations§
Source§impl OutboxBuilder
impl OutboxBuilder
Sourcepub fn new(os: Option<&Value>, oc: Option<&Value>) -> Result<Self, StoreError>
pub fn new(os: Option<&Value>, oc: Option<&Value>) -> Result<Self, StoreError>
Read sequence/backlog once. Missing rows mean zero.
Sourcepub fn reserve(&mut self, rid: &str, ticket_id: [u8; 32], prior: Option<&Value>)
pub fn reserve(&mut self, rid: &str, ticket_id: [u8; 32], prior: Option<&Value>)
Reserve a unique id. An existing row fails Absent at commit even when it contains the same ticket; callers resolve replay beforehand.
Sourcepub fn pending(
&mut self,
rid: &str,
prior: Option<&Value>,
record: &ReservationV1,
)
pub fn pending( &mut self, rid: &str, prior: Option<&Value>, record: &ReservationV1, )
Durably record an admitted reservation before any guarded apply. A present prior is an invalid admission decision, not a replay.
Sourcepub fn outcome(&mut self, rid: &str, prior: &Value, terminal: Terminal)
pub fn outcome(&mut self, rid: &str, prior: &Value, terminal: Terminal)
Replace still-Ticketed or Pending with exactly one terminal outcome, queued for delivery. A terminal prior is rejected rather than replaced.
Sourcepub fn abort_direct(&mut self, rid: &str, terminal: Terminal)
pub fn abort_direct(&mut self, rid: &str, terminal: Terminal)
Fail a ticketless streaming reservation in one guarded Absent unit.
Sourcepub fn relay_at(&mut self, now_ms: u64)
pub fn relay_at(&mut self, now_ms: u64)
Stamp relay rows and schedule their immediate source-side kick.
Sourcepub fn relay(&mut self, target: &Partition, puts: Vec<(Key, Value)>)
pub fn relay(&mut self, target: &Partition, puts: Vec<(Key, Value)>)
Group idempotent upserts by target, sorting keys deterministically. Conflicting values for one target/key invalidate the whole fragment.
Sourcepub fn relay_delete(&mut self, target: &Partition, keys: Vec<Key>)
pub fn relay_delete(&mut self, target: &Partition, keys: Vec<Key>)
Group idempotent deletes by target. A key cannot be both put and deleted in the same source batch.
Sourcepub fn try_finish(
self,
pre: &mut Vec<Precondition>,
writes: &mut Vec<Write>,
) -> Result<(), StoreError>
pub fn try_finish( self, pre: &mut Vec<Precondition>, writes: &mut Vec<Write>, ) -> Result<(), StoreError>
Finish with error reporting. Errors leave output vectors unchanged.
Sourcepub fn finish(self, pre: &mut Vec<Precondition>, writes: &mut Vec<Write>)
pub fn finish(self, pre: &mut Vec<Precondition>, writes: &mut Vec<Write>)
Finish the fixed fragment API; malformed input makes the caller’s
complete batch uncommittable, which looks like a retryable conflict.
Wiring code (WP-1.9, 1.10, 1.14, 3.3) MUST call try_finish so the
error is reported instead.