Skip to main content

InputLease

Struct InputLease 

Source
pub struct InputLease { /* private fields */ }
Expand description

One exclusive input lease (per PTY, window, or control target).

Implementations§

Source§

impl InputLease

Source

pub fn new(name: impl Into<String>) -> Self

In-memory lease (the default): nothing survives the process.

Source

pub fn open( name: impl Into<String>, store: Arc<dyn LeaseStore>, ) -> Result<Self, LeaseError>

Durable lease backed by store. A first open creates a fresh record (new ExecutionIdentity, Running, epoch 0); a later open recovers it (see crate::lease_store): epoch fenced forward, detached, Running becomes Unknown, unacknowledged input becomes Unknown input. Fails closed on an unreadable/corrupt record, a record for a different lease name, or a failed save.

Source

pub fn open_with_identity( name: impl Into<String>, store: Arc<dyn LeaseStore>, identity: ExecutionIdentity, ) -> Result<Self, LeaseError>

As Self::open, using identity when no record exists yet. An existing record keeps its own identity; a different one is refused.

Source

pub fn with_events(self, sink: EventSink) -> Self

Source

pub fn name(&self) -> &str

Source

pub fn snapshot(&self) -> LeaseSnapshot

Source

pub fn is_durable(&self) -> bool

True when backed by a LeaseStore.

Source

pub fn store_degraded(&self) -> bool

True when the last best-effort save (after an executor ran) failed; cleared by the next successful save.

Source

pub fn record(&self) -> LeaseRecord

The durable projection (identity, execution state, epoch, holder, sequences, unknown input), whether or not a store backs this lease.

Source

pub fn execution_identity(&self) -> ExecutionIdentity

Source

pub fn execution_state(&self) -> ExecutionState

Source

pub fn unknown_input(&self) -> Option<(u64, u64)>

[from, to) inherited unacknowledged from a crash/restart, if any.

Source

pub fn input_status(&self, sequence: u64) -> InputStatus

Source

pub fn set_execution_state( &self, state: ExecutionState, ) -> Result<LeaseSnapshot, LeaseError>

Host-side, explicit execution-state resolution (e.g. after a restart the host verified the target is alive → Running, or observed it ended → Exited). Exited is terminal.

Source

pub fn acquire(&self) -> Result<LeaseGrant, LeaseError>

Take the lease: bump the epoch (fencing any attached holder). Rejected while unacknowledged input is outstanding; use Self::acquire_reconciling. On a durable lease the new epoch is saved before it is granted.

Source

pub fn acquire_reconciling( &self, decision: UnacknowledgedInputDecision, ) -> LeaseGrant

Resolve any unacknowledged (or crash-Unknown) range with an explicit decision, then take the lease (bumping the epoch).

§Panics

On a durable lease whose store refuses the save (an epoch that is not durable is never granted). Durable callers should use Self::try_acquire_reconciling; an in-memory lease never panics.

Source

pub fn try_acquire_reconciling( &self, decision: UnacknowledgedInputDecision, ) -> Result<LeaseGrant, LeaseError>

Fallible Self::acquire_reconciling: errs only when the store refuses the save, in which case nothing changed.

Source

pub fn reconcile( &self, epoch: u64, decision: UnacknowledgedInputDecision, ) -> Result<LeaseSnapshot, LeaseError>

The current holder resolves its own unacknowledged range in place.

Source

pub fn acknowledge_input( &self, epoch: u64, sequence: u64, ) -> Result<LeaseSnapshot, LeaseError>

Explicitly acknowledge delivery of every sequence up to and including sequence (CodeRight acknowledge_input). This is how a client that observed the effect resolves unacknowledged or crash-Unknown input one prefix at a time. epoch must be the current epoch; the lease need not be attached (after a restart it is detached at the recovery epoch, which only the host can read). Re-acknowledging the highest acknowledged sequence is idempotent.

Source

pub fn release(&self, epoch: u64) -> Result<LeaseSnapshot, LeaseError>

Release by the current holder only; a fenced holder cannot release.

Source

pub fn check(&self, epoch: u64, sequence: u64) -> Result<bool, LeaseError>

Check fencing and sequencing without executing. Returns Ok(true) for new input at next_input_sequence, Ok(false) for a duplicate.

Source

pub fn submit<T>( &self, epoch: u64, sequence: u64, execute: impl FnOnce() -> Result<T, InputFailure>, ) -> Result<InputOutcome<T>, InputError>

Submit input (epoch, sequence). execute runs at most once, only for new in-order input from the current holder while the execution is Running. On a durable lease the sequence is reserved durably before execute runs; if that save fails nothing runs (NotDelivered).

Trait Implementations§

Source§

impl Debug for InputLease

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.