pub struct InputLease { /* private fields */ }Expand description
One exclusive input lease (per PTY, window, or control target).
Implementations§
Source§impl InputLease
impl InputLease
Sourcepub fn new(name: impl Into<String>) -> Self
pub fn new(name: impl Into<String>) -> Self
In-memory lease (the default): nothing survives the process.
Sourcepub fn open(
name: impl Into<String>,
store: Arc<dyn LeaseStore>,
) -> Result<Self, LeaseError>
pub fn open( name: impl Into<String>, store: Arc<dyn LeaseStore>, ) -> Result<Self, LeaseError>
Durable lease backed by store. A first open creates a fresh record
(new ExecutionIdentity, Running, epoch 0); a later open recovers
it (see crate::lease_store): epoch fenced forward, detached,
Running becomes Unknown, unacknowledged input becomes Unknown
input. Fails closed on an unreadable/corrupt record, a record for a
different lease name, or a failed save.
Sourcepub fn open_with_identity(
name: impl Into<String>,
store: Arc<dyn LeaseStore>,
identity: ExecutionIdentity,
) -> Result<Self, LeaseError>
pub fn open_with_identity( name: impl Into<String>, store: Arc<dyn LeaseStore>, identity: ExecutionIdentity, ) -> Result<Self, LeaseError>
As Self::open, using identity when no record exists yet. An
existing record keeps its own identity; a different one is refused.
pub fn with_events(self, sink: EventSink) -> Self
pub fn name(&self) -> &str
pub fn snapshot(&self) -> LeaseSnapshot
Sourcepub fn is_durable(&self) -> bool
pub fn is_durable(&self) -> bool
True when backed by a LeaseStore.
Sourcepub fn store_degraded(&self) -> bool
pub fn store_degraded(&self) -> bool
True when the last best-effort save (after an executor ran) failed; cleared by the next successful save.
Sourcepub fn record(&self) -> LeaseRecord
pub fn record(&self) -> LeaseRecord
The durable projection (identity, execution state, epoch, holder, sequences, unknown input), whether or not a store backs this lease.
pub fn execution_identity(&self) -> ExecutionIdentity
pub fn execution_state(&self) -> ExecutionState
Sourcepub fn unknown_input(&self) -> Option<(u64, u64)>
pub fn unknown_input(&self) -> Option<(u64, u64)>
[from, to) inherited unacknowledged from a crash/restart, if any.
pub fn input_status(&self, sequence: u64) -> InputStatus
Sourcepub fn set_execution_state(
&self,
state: ExecutionState,
) -> Result<LeaseSnapshot, LeaseError>
pub fn set_execution_state( &self, state: ExecutionState, ) -> Result<LeaseSnapshot, LeaseError>
Host-side, explicit execution-state resolution (e.g. after a restart
the host verified the target is alive → Running, or observed it
ended → Exited). Exited is terminal.
Sourcepub fn acquire(&self) -> Result<LeaseGrant, LeaseError>
pub fn acquire(&self) -> Result<LeaseGrant, LeaseError>
Take the lease: bump the epoch (fencing any attached holder). Rejected
while unacknowledged input is outstanding; use
Self::acquire_reconciling. On a durable lease the new epoch is
saved before it is granted.
Sourcepub fn acquire_reconciling(
&self,
decision: UnacknowledgedInputDecision,
) -> LeaseGrant
pub fn acquire_reconciling( &self, decision: UnacknowledgedInputDecision, ) -> LeaseGrant
Resolve any unacknowledged (or crash-Unknown) range with an explicit
decision, then take the lease (bumping the epoch).
§Panics
On a durable lease whose store refuses the save (an epoch that is not
durable is never granted). Durable callers should use
Self::try_acquire_reconciling; an in-memory lease never panics.
Sourcepub fn try_acquire_reconciling(
&self,
decision: UnacknowledgedInputDecision,
) -> Result<LeaseGrant, LeaseError>
pub fn try_acquire_reconciling( &self, decision: UnacknowledgedInputDecision, ) -> Result<LeaseGrant, LeaseError>
Fallible Self::acquire_reconciling: errs only when the store
refuses the save, in which case nothing changed.
Sourcepub fn reconcile(
&self,
epoch: u64,
decision: UnacknowledgedInputDecision,
) -> Result<LeaseSnapshot, LeaseError>
pub fn reconcile( &self, epoch: u64, decision: UnacknowledgedInputDecision, ) -> Result<LeaseSnapshot, LeaseError>
The current holder resolves its own unacknowledged range in place.
Sourcepub fn acknowledge_input(
&self,
epoch: u64,
sequence: u64,
) -> Result<LeaseSnapshot, LeaseError>
pub fn acknowledge_input( &self, epoch: u64, sequence: u64, ) -> Result<LeaseSnapshot, LeaseError>
Explicitly acknowledge delivery of every sequence up to and including
sequence (CodeRight acknowledge_input). This is how a client that
observed the effect resolves unacknowledged or crash-Unknown input
one prefix at a time. epoch must be the current epoch; the lease
need not be attached (after a restart it is detached at the recovery
epoch, which only the host can read). Re-acknowledging the highest
acknowledged sequence is idempotent.
Sourcepub fn release(&self, epoch: u64) -> Result<LeaseSnapshot, LeaseError>
pub fn release(&self, epoch: u64) -> Result<LeaseSnapshot, LeaseError>
Release by the current holder only; a fenced holder cannot release.
Sourcepub fn check(&self, epoch: u64, sequence: u64) -> Result<bool, LeaseError>
pub fn check(&self, epoch: u64, sequence: u64) -> Result<bool, LeaseError>
Check fencing and sequencing without executing. Returns Ok(true) for
new input at next_input_sequence, Ok(false) for a duplicate.
Sourcepub fn submit<T>(
&self,
epoch: u64,
sequence: u64,
execute: impl FnOnce() -> Result<T, InputFailure>,
) -> Result<InputOutcome<T>, InputError>
pub fn submit<T>( &self, epoch: u64, sequence: u64, execute: impl FnOnce() -> Result<T, InputFailure>, ) -> Result<InputOutcome<T>, InputError>
Submit input (epoch, sequence). execute runs at most once, only for
new in-order input from the current holder while the execution is
Running. On a durable lease the sequence is reserved durably before
execute runs; if that save fails nothing runs (NotDelivered).