pub struct Registry { /* private fields */ }Expand description
Control-plane registry for module manifests and supervision ownership.
Duplicate active module_ids are rejected rather than replaced. Rejection is
the safer v1 behavior because replacing a still-connected module could hijack
in-flight routes. Stale registrations are removed by connection cleanup; a
reconnect after the old connection drops can then register the same id again.
A blue/green swap is the one sanctioned way two processes hold the same id.
The replacement registers into a separate candidate slot, which every by-id
lookup ignores, so it stays unroutable until Registry::promote_candidate
swaps it in. The old incumbent is then kept as “superseded” until its
connection deregisters. Lookups keyed by connection id search all three
slots, because a connection must be able to update and remove its own
registration whichever slot it currently sits in.
Implementations§
Source§impl Registry
impl Registry
Sourcepub fn register_with_control_ops(
&self,
manifest: ModuleManifest,
negotiated_ver: u8,
connection_id: ConnectionId,
control_ops: Vec<String>,
) -> Result<ModuleRegistration, RegistryError>
pub fn register_with_control_ops( &self, manifest: ModuleManifest, negotiated_ver: u8, connection_id: ConnectionId, control_ops: Vec<String>, ) -> Result<ModuleRegistration, RegistryError>
Register a module manifest with the module’s effective granted control op set.
Sourcepub fn register_candidate_with_control_ops(
&self,
manifest: ModuleManifest,
negotiated_ver: u8,
connection_id: ConnectionId,
control_ops: Vec<String>,
) -> Result<ModuleRegistration, RegistryError>
pub fn register_candidate_with_control_ops( &self, manifest: ModuleManifest, negotiated_ver: u8, connection_id: ConnectionId, control_ops: Vec<String>, ) -> Result<ModuleRegistration, RegistryError>
Register a swap candidate for manifest.module_id into the candidate slot.
The candidate is invisible to Self::get_module, Self::list_modules
and every other by-id lookup until Self::promote_candidate. An active
registration for the id is not required, because the incumbent may die
while the swap is open; deciding whether a candidate may register at all
belongs to the caller that admits it. A second candidate for the same id
is refused.
Sourcepub fn promote_candidate(
&self,
module_id: &str,
) -> Result<Option<RegistryCutover>, RegistryError>
pub fn promote_candidate( &self, module_id: &str, ) -> Result<Option<RegistryCutover>, RegistryError>
Move the candidate for module_id into the active slot and demote the
previous active registration, in one registry critical section.
Returns Ok(None) when there is no candidate to promote. Bumps the
catalog generation, because the listed registration for the id changed.
Sourcepub fn get_module(
&self,
module_id: &str,
) -> Result<Option<ModuleRegistration>, RegistryError>
pub fn get_module( &self, module_id: &str, ) -> Result<Option<ModuleRegistration>, RegistryError>
The ACTIVE registration for module_id. Candidates and superseded
incumbents are never returned: this is the lookup routing decisions use.
Sourcepub fn get_candidate(
&self,
module_id: &str,
) -> Result<Option<ModuleRegistration>, RegistryError>
pub fn get_candidate( &self, module_id: &str, ) -> Result<Option<ModuleRegistration>, RegistryError>
The swap candidate registered for module_id, if any.
Sourcepub fn registration(
&self,
slot: RegistrationSlot<'_>,
) -> Result<Option<ModuleRegistration>, RegistryError>
pub fn registration( &self, slot: RegistrationSlot<'_>, ) -> Result<Option<ModuleRegistration>, RegistryError>
The registration held in one specific slot. See RegistrationSlot.
pub fn active_registration_count(&self) -> Result<usize, RegistryError>
pub fn list_modules( &self, ) -> Result<(u64, Vec<ModuleRegistration>), RegistryError>
pub fn generation(&self) -> Result<u64, RegistryError>
Sourcepub fn get_module_by_connection(
&self,
connection_id: ConnectionId,
) -> Result<Option<ModuleRegistration>, RegistryError>
pub fn get_module_by_connection( &self, connection_id: ConnectionId, ) -> Result<Option<ModuleRegistration>, RegistryError>
The registration owned by connection_id, searching the active,
candidate and superseded slots in that order.
Sourcepub fn replace_catalog_for_connection(
&self,
connection_id: ConnectionId,
provides: Vec<ProviderRole>,
capabilities: Option<CapabilityDeclarations>,
ready: Option<bool>,
) -> Result<Option<ModuleRegistration>, RegistryError>
pub fn replace_catalog_for_connection( &self, connection_id: ConnectionId, provides: Vec<ProviderRole>, capabilities: Option<CapabilityDeclarations>, ready: Option<bool>, ) -> Result<Option<ModuleRegistration>, RegistryError>
Replace the provider role list and, when supplied, the attested capability
declaration for the module owned by connection_id.
Searches every slot: a swap candidate declares itself ready through this call, and if only the active slot were searched its update would find nothing and the candidate would never become ready. Only a change to the active slot bumps the catalog generation, because only the active slot is listed.
Sourcepub fn deregister_connection(
&self,
connection_id: ConnectionId,
) -> Result<Vec<ModuleRegistration>, RegistryError>
pub fn deregister_connection( &self, connection_id: ConnectionId, ) -> Result<Vec<ModuleRegistration>, RegistryError>
Deregister every module owned by a dropped connection, in any slot.