pub struct Meta {
pub format_version: u16,
pub roots: [u32; 8],
pub next_lsn: u64,
pub generation: u64,
}Fields§
§format_version: u16§roots: [u32; 8]§next_lsn: u64LSN high-water mark, persisted so a rotation followed by a restart does
not renumber log records from 1. Nothing today compares a page’s lsn
against a record’s, but a later idempotence check would be silently
wrong if LSNs repeated, and that is not a defect worth discovering from
a corrupted store.
generation: u64Monotone publication counter (2f). Chooses the live slot on open and the victim slot on write. 0 = the create-time publication.
Implementations§
Source§impl Meta
impl Meta
pub fn write(&self, pool: &BufferPool) -> Result<()>
Sourcepub fn write_slot(&self, pool: &BufferPool) -> Result<()>
pub fn write_slot(&self, pool: &BufferPool) -> Result<()>
Write this Meta into the slot its generation selects (2f). The caller flushes data pages and BARRIERS before calling, and flushes again after: the flip must reach the medium only once everything it names is already there.
Sourcepub fn from_page(p: &PageRef<'_>) -> Result<Meta>
pub fn from_page(p: &PageRef<'_>) -> Result<Meta>
Decode a Meta from an already-verified page. Pure – no
BufferPool involved – so a caller holding a raw, already-CRC-
checked PageRef over a single buffer can read it without needing a
whole pool wrapped around one page. read below is a thin wrapper
over this.
Fallible (Task 17 re-review, R2): a page can CRC-verify – its own
bytes are exactly what was last written – while still holding zero
slots, which Meta::write’s own error path can produce (see its doc
comment) and nothing stops a future writer from producing another
way. PageRef::slot(0) on such a page returns an EMPTY slice, not an
error – verification and “has a slot 0 at all” are different
questions – so the previous, infallible version of this function
indexed straight into it and panicked. A malformed superblock is
exactly the kind of damage this crate’s own recover() exists to
repair; a decoder that panics on it instead of returning Err takes
that repair path down with it, which is precisely what R2 measured.
pub fn read(pool: &BufferPool) -> Result<Meta>
Sourcepub fn read_latest(pool: &BufferPool) -> Result<Meta>
pub fn read_latest(pool: &BufferPool) -> Result<Meta>
2f: read BOTH slots, adopt the newest valid one. A slot that fails its page checksum or does not parse is normally the loser – a torn flip leaves the previous publication standing. An intact unsupported logical version must refuse instead of falling back to stale metadata. A page-1 slot that is a valid page of any OTHER kind is a pre-2f file and is refused outright: silently adopting slot 0 would let the next checkpoint overwrite a live tree page.
Sourcepub fn init_slot_b(pool: &BufferPool) -> Result<()>
pub fn init_slot_b(pool: &BufferPool) -> Result<()>
Initialise slot B as an EMPTY Meta page (valid page, no record):
recognisably a slot – so read_latest never mistakes this for a
pre-2f file – but never adoptable until a real flip writes it.