Skip to main content

WitnessSupervisor

Struct WitnessSupervisor 

Source
pub struct WitnessSupervisor<S>
where S: LastVoteStore,
{ /* private fields */ }
Expand description

A booted witness node: the control-plane supervisor with no data plane.

A witness is a Voter over a durable last-vote store plus the node’s shared NodeIdentity — and nothing else. There is intentionally no engine, no WAL, and no replication handle on this struct: a witness cannot serve data because it holds none.

The store type is generic so production uses the durable FileLastVoteStore (ADR 0030: “the supervisor needs durable per-node vote state to prevent double-voting across restarts”) while tests use an in-memory store.

Implementations§

Source§

impl<S> WitnessSupervisor<S>
where S: LastVoteStore,

Source

pub fn new(identity: NodeIdentity, store: S) -> WitnessSupervisor<S>

Boot a witness supervisor over store, identified by the shared per-node identity. The voter id is the identity’s certificate subject, so the witness votes under the same identity a data member would replicate under.

Source

pub fn profile(&self) -> RuntimeProfile

A witness always runs the witness profile.

Source

pub fn boots_data_plane(&self) -> bool

A witness never boots a data plane — invariant by construction, stated here so callers (and the boot pipeline) can assert it without reaching into the profile.

Source

pub fn identity(&self) -> &NodeIdentity

The shared per-node identity this witness authenticates with — the same NodeIdentity type a data member presents over mTLS.

Source

pub fn member(&self) -> Member

This witness’s entry in the supervisor’s membership view: a vote-only MemberKind::Witness, always VotingState::Voting. It counts toward quorum but is never electable.

Source

pub fn consider_vote( &self, req: &VoteRequest, commit_watermark: u64, ) -> Result<VoteDecision, LastVoteError>

Consider a candidate’s vote request against the current commit watermark — the only control-plane action a witness performs. The watermark rule and the durable double-vote guard live in the Voter, so a witness applies the exact same safety rule a data voter does.

Source

pub fn current_term(&self) -> Result<u64, LastVoteError>

The highest term this witness has durably recorded.

Source§

impl WitnessSupervisor<FileLastVoteStore>

Source

pub fn with_durable_store( identity: NodeIdentity, last_vote_path: impl Into<PathBuf>, ) -> WitnessSupervisor<FileLastVoteStore>

Boot a witness with a durable, on-disk last-vote store at last_vote_path — the production constructor. Survives a restart so a witness that crashes mid-term never double-votes (ADR 0030).

Auto Trait Implementations§

§

impl<S> Freeze for WitnessSupervisor<S>
where S: Freeze,

§

impl<S> RefUnwindSafe for WitnessSupervisor<S>
where S: RefUnwindSafe,

§

impl<S> Send for WitnessSupervisor<S>
where S: Send,

§

impl<S> Sync for WitnessSupervisor<S>
where S: Sync,

§

impl<S> Unpin for WitnessSupervisor<S>
where S: Unpin,

§

impl<S> UnsafeUnpin for WitnessSupervisor<S>
where S: UnsafeUnpin,

§

impl<S> UnwindSafe for WitnessSupervisor<S>
where S: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more