Skip to main content

AccountOverage

Struct AccountOverage 

Source
pub struct AccountOverage { /* private fields */ }
Expand description

An account’s unfunded spend on this instance, under EnforcementMode::Elastic.

Three atomic counters, with the total shaped exactly like LocalLease’s: a CAS loop, no lock, no I/O, no clock. A lease counts down through units someone already paid for; spent counts up through units nobody has. committed distinguishes durable spend from pending reservations that can still be refunded. commit_publications closes the otherwise torn reservation-phase/occupancy transition, so a cap refusal never advertises irrevocable units as refundable. The ledger settles the difference by treating overage as a second funding term, so per-account conservation still closes exactly (INVARIANTS.md GL-1, GL-3).

The cap is a parameter, not a field. It arrives from the snapshot the request has already read, which means two things: a republished cap takes effect on the very next request with no reconciliation step, and — the load-bearing half — the cap comparison happens inside the same compare-exchange that claims the units. Checking a cap and then claiming against it in two steps would let two cores each observe room for a request that only one of them can have.

Its lifetime is the account’s, not a lease’s. It hangs off the per-account lease slot, which is created on first use and held for the life of the process. That is deliberate and is the difference between this and the rate-limiter registry: a limiter rebuilt after eviction costs a full bucket, but an overage counter rebuilt after eviction silently resets a spend cap.

Implementations§

Source§

impl AccountOverage

Source

pub fn new(account_id: AccountId) -> Self

An empty overage counter for one account on this instance: nothing extended, nothing committed.

Source

pub fn contended_debits(&self) -> u64

Overage debits that lost a compare-exchange to another writer, since the account’s counter was created. A lower bound, for the reasons LocalLease::contended_debits gives. A control-plane read.

Source

pub fn account_id(&self) -> AccountId

The account this counter belongs to.

Source

pub fn spent(&self) -> CostUnits

Unfunded units extended on this instance so far.

Source

pub fn headroom(&self, cap: CostUnits) -> CostUnits

Units still extendable under cap, saturating at zero.

Read by readiness: an elastic account with headroom here is admissible even when its lease is empty or absent, which is the whole point of the mode (INVARIANTS.md GL-10).

Trait Implementations§

Source§

impl Debug for AccountOverage

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.