pub enum Stop {
End(&'static str),
Damaged {
offset: u64,
why: &'static str,
},
}Expand description
Why scan stopped walking, as a type rather than as a comment.
scan had EIGHT break statements, four of which meant “the log
genuinely ends here” and four of which meant “something is wrong here” –
and all eight left through the same Ok((end, ..)) return, which
open_impl then handed to set_len(end). So an injected EIO on a single
header read returned a clean end and erased 640 of 1,280 bytes, and one
flipped bit at the midpoint of a 3,000-row log destroyed 1,499 committed
rows while open() returned Ok. Both measured (Task 17 final review,
F4).
The distinction is now in the type system, so no exit can join the wrong one by accident:
Endis the ONLY variantopen_implwill truncate on.Damagedrefuses the open, touching nothing – and, because a refusal with no way out is its own Law 5 violation,recover()clears it by setting the whole log aside intact and reconstructing independently verified committed regions.- An I/O error is neither: it is not an answer about the log’s content
at all, so it leaves
scanasErrand never reaches this enum.
Variants§
End(&'static str)
The log genuinely ends at end. Everything from there to EOF is
either a writer-shaped header whose bounded frame crosses physical
EOF, or an all-zero extension. why names which proof was established.
Damaged
Something is wrong at offset. The remaining bytes may include
committed frames regardless of how short they are. Nothing here may
be discarded.