Skip to main content

Scope

Struct Scope 

Source
pub struct Scope { /* private fields */ }
Expand description

A read scope: what a handle may see, as a descriptor rather than a mask.

A Scope names its legs — a role, a namespace, an explicit key allow-list — and resolves them to a NodeMask per read. It is the live-read analogue of AsOfScope, and resolves its role leg through the same GraphDb::mask_for_role, so a role name means one thing on both.

§Never widens

Present legs are intersected; an absent leg contributes nothing. A scope with no legs at all is refused by Scope::new rather than treated as unscoped — an empty scope must never be the accident that widens a caller to everything.

§Never stale

Resolution happens on every read, not once at construction. The role leg goes through RoleMaskCache, keyed on commit_seq; the keys leg is cached on this Scope under a [StoreStamp], which is commit_seq plus the identity of the store that commit belongs to — a Scope is the caller’s and can be carried to another store or held across a reload, neither of which a sequence number can detect. Either way a read after a write rebuilds, so a scoped handle held across a write cannot serve the allow-list it had before — a key created since is visible, a key deleted since is not. That is a security property, not a freshness nicety.

Mode is hard-coded MaskMode::Omit. MaskMode::Stub discloses node existence and belongs only to full-token client masks.

Implementations§

Source§

impl Scope

Source

pub fn new( role: Option<String>, namespace: Option<String>, keys: Option<Vec<String>>, ) -> Result<Scope>

Build a scope from the legs that are present.

At least one leg is required: Scope::new(None, None, None) is GraphError::QueryError, never an unscoped handle.

keys: Some(vec![]) is a leg — it narrows to nothing, which is safe. An unknown role is not detected here; it surfaces from Scope::resolve, which is where a store exists to check it against.

Source

pub fn resolve<F: Fs>(&self, db: &GraphDb<F>) -> Result<NodeMask>

Resolve every present leg against db and intersect the results.

Returns Err when a role leg names no defined role, or when roles.json was corrupt at open — the same refusals GraphDb::mask_for_role makes, unchanged.

Source

pub fn intersect(&self, other: &Scope) -> Scope

Return a scope seeing only what both self and other see.

Legs accumulate rather than replace: two role legs are both resolved and intersected, and two key lists are intersected as strings. The result starts with a cold cache, which costs one rebuild and cannot be wrong.

Trait Implementations§

Source§

impl Clone for Scope

Source§

fn clone(&self) -> Scope

Carries the resolved keys leg across, cache included: it is stamped with the store and the commit it was built against, so a clone can serve it only against that same store while that commit is still current.

1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Scope

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Omits the resolved cache: it is a derived value, and printing a 50,000-id mask in a log line helps nobody.

Auto Trait Implementations§

§

impl !Freeze for Scope

§

impl RefUnwindSafe for Scope

§

impl Send for Scope

§

impl Sync for Scope

§

impl Unpin for Scope

§

impl UnsafeUnpin for Scope

§

impl UnwindSafe for Scope

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> ArchivePointee for T

Source§

type ArchivedMetadata = ()

The archived version of the pointer metadata for this type.
Source§

fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata

Converts some archived metadata to the pointer metadata for itself.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> LayoutRaw for T

Source§

fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>

Returns the layout of the type.
Source§

impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
where T: SharedNiching<N1, N2>, N1: Niching<T>, N2: Niching<T>,

Source§

unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool

Returns whether the given value has been niched. Read more
Source§

fn resolve_niched(out: Place<NichedOption<T, N1>>)

Writes data to out indicating that a T is niched.
Source§

impl<T> Pointee for T

Source§

type Metadata = ()

The metadata type for pointers and references to this type.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.