pub struct AccountOverage { /* private fields */ }Expand description
An account’s unfunded spend on this instance, under
EnforcementMode::Elastic.
Three atomic counters, with the total shaped exactly like LocalLease’s:
a CAS loop, no lock, no I/O, no clock. A lease counts down through units
someone already paid for; spent counts up through units nobody has.
committed distinguishes durable spend from pending reservations that can
still be refunded. commit_publications closes the otherwise torn
reservation-phase/occupancy transition, so a cap refusal never advertises
irrevocable units as refundable. The ledger settles the difference by
treating overage as a second funding term, so per-account conservation
still closes exactly (INVARIANTS.md GL-1, GL-3).
The cap is a parameter, not a field. It arrives from the snapshot the request has already read, which means two things: a republished cap takes effect on the very next request with no reconciliation step, and — the load-bearing half — the cap comparison happens inside the same compare-exchange that claims the units. Checking a cap and then claiming against it in two steps would let two cores each observe room for a request that only one of them can have.
Its lifetime is the account’s, not a lease’s. It hangs off the per-account lease slot, which is created on first use and held for the life of the process. That is deliberate and is the difference between this and the rate-limiter registry: a limiter rebuilt after eviction costs a full bucket, but an overage counter rebuilt after eviction silently resets a spend cap.
Implementations§
Source§impl AccountOverage
impl AccountOverage
Sourcepub fn new(account_id: AccountId) -> Self
pub fn new(account_id: AccountId) -> Self
An empty overage counter for one account on this instance: nothing extended, nothing committed.
Sourcepub fn contended_debits(&self) -> u64
pub fn contended_debits(&self) -> u64
Overage debits that lost a compare-exchange to another writer, since
the account’s counter was created. A lower bound, for the reasons
LocalLease::contended_debits gives. A control-plane read.
Sourcepub fn account_id(&self) -> AccountId
pub fn account_id(&self) -> AccountId
The account this counter belongs to.