pub struct Journal { /* private fields */ }Expand description
Write-ahead restore journal: crash-safe record of freeze/cap interventions.
Implementations§
Source§impl Journal
impl Journal
Sourcepub fn read_entries(path: &Path, boot_id: &str) -> Vec<JournalEntry>
pub fn read_entries(path: &Path, boot_id: &str) -> Vec<JournalEntry>
Read journal entries straight off disk without opening a Journal
handle, safe to call from a second process (e.g. the CLI) while
the daemon holds its own live Journal and may be appending.
Unlike Journal::open/Journal::entries, this never truncates,
rewrites, or performs WAL tail recovery: open()’s recovery path
(set_len from a stale read, or a boot-mismatch truncate) is a
TOCTOU race against the daemon’s own writes when run from an
unrelated process with no cross-process lock: a daemon append
landing between this function’s read and a hypothetical fix-up would
be silently discarded, losing a crash-restore record. This function
only ever reads: a torn trailing line or any other unparseable line
is skipped in memory, the file on disk is left byte-for-byte as it
was found.
Returns an empty vec if the file is missing/unreadable, the header is
missing/invalid, or the header’s boot_id doesn’t match boot_id
(stale entries from a prior boot are not “current”, but reading them
is not this function’s job to discard on disk).
Sourcepub fn open(path: PathBuf, boot_id: String) -> Result<Self>
pub fn open(path: PathBuf, boot_id: String) -> Result<Self>
Opens the journal file, creating parent directories if needed.
If the file exists and its boot_id header differs from the provided boot_id,
the file is truncated (entries from a prior boot are discarded).
§Arguments
path- Path to the journal fileboot_id- Current boot identifier (passed by caller, not read from cgfs)
Sourcepub fn append(&self, e: &JournalEntry) -> Result<()>
pub fn append(&self, e: &JournalEntry) -> Result<()>
Append a journal entry (write-ahead: fsyncs before returning).
Sourcepub fn entries(&self) -> Vec<JournalEntry>
pub fn entries(&self) -> Vec<JournalEntry>
Retrieve all valid entries from the current boot.
Sourcepub fn remove(&self, cgroup: &str) -> Result<()>
pub fn remove(&self, cgroup: &str) -> Result<()>
Remove all entries matching the given cgroup (atomic rewrite: temp file + rename + fsync).
Sourcepub fn clear(&self) -> Result<()>
pub fn clear(&self) -> Result<()>
Clear all entries, leaving only the header (clean shutdown compaction).
Sourcepub fn replace(&self, cgroup: &str, entries: &[JournalEntry]) -> Result<()>
pub fn replace(&self, cgroup: &str, entries: &[JournalEntry]) -> Result<()>
Atomically swap all entries for cgroup with entries (an empty
slice removes them), in a single rewrite; every other cgroup’s
entries are preserved untouched. Unlike a separate remove followed
by append, there is no window where the on-disk journal has fewer
(or zero) records for cgroup than reality: the old and new entries
for cgroup are swapped in one write_entries call under the
mutation lock, so a crash either lands before (old entries intact)
or after (new entries intact), never in between.