#[non_exhaustive]pub enum FailurePoint {
AfterInteractionPersistence,
BeforeJournalInsert,
AfterJournalInsertBeforeCommit,
AfterCommitBeforeEventReadback,
BeforeOutboxDispatch,
AfterOutboxDispatch,
BeforeResponsePersistence,
}Expand description
A boundary at which the in-memory store can be made to fail (spec §27.7).
The names describe the moment in a turn, not the method: one point may be reached from more than one method, and the variant documentation names them.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
AfterInteractionPersistence
The card was written and the caller is told it was not.
Fires in InteractionWriter::insert
and
insert_replacing_blocking
after the insert: the interaction (and any invalidation the insert
performed) stays visible. Spec §15.5 requires interaction persistence to
succeed before the response mentions the card, so the truthful reaction
is to omit the card, not to claim it.
Inside a commit bundle it fires after stage 5 (interaction inserts) and aborts the bundle.
BeforeJournalInsert
The command was never admitted.
Fires in CommandJournalWriter::begin
before anything is written, so the key stays free and the command
may be admitted again from scratch.
AfterJournalInsertBeforeCommit
The command was admitted and then the process died before the domain commit.
Fires in CommandJournalWriter::begin
after the entry is persisted: the entry survives in Pending, which
is exactly the state
pending_for_turn
exists to find, and recovery must resume it by idempotency key rather
than admitting a second command (spec §23.1).
Inside a commit bundle it fires after stage 1 (journal completions) and aborts the bundle.
AfterCommitBeforeEventReadback
The events were appended and the caller could not read them back.
Fires in EventJournalWriter::append
after the batch is appended: the events are in the ledger, so a
recovery that re-reads by command finds them and must not append them a
second time.
Inside a commit bundle it fires after stage 2 (event batches) and aborts the bundle.
BeforeOutboxDispatch
The dispatcher never got the work.
Fires in OutboxWriter::claim_due
before anything is claimed: no row moves to Dispatching and the
next sweep picks the same rows up.
AfterOutboxDispatch
The external call was made and its result could not be recorded.
Fires in mark_completed,
mark_failed and
mark_outcome_unknown
before the write: the row stays Dispatching with its claim, which
is the state
release_expired_claims
exists to reap. It is the worst case of spec §16.5 — an effect may exist
and nothing local says so — so a retry is only safe when the remote
guarantees idempotency.
BeforeResponsePersistence
The answer was composed and never stored.
Fires in
append_assistant_turn
before the write. The turn keeps its user side and its phase marker,
so recovery regenerates the response from committed events and stored
answer tasks instead of re-executing anything (spec §23.1).
Implementations§
Source§impl FailurePoint
impl FailurePoint
Sourcepub const fn as_str(self) -> &'static str
pub const fn as_str(self) -> &'static str
The boundary’s stable name, matching the crash boundaries the specification enumerates.
Stable across releases: test kits and fixtures address a boundary by this string, so renaming one is a breaking change.
Sourcepub fn parse(name: &str) -> Result<Self, UnknownFailurePoint>
pub fn parse(name: &str) -> Result<Self, UnknownFailurePoint>
Sourcepub fn leaves_write_visible(self) -> bool
pub fn leaves_write_visible(self) -> bool
Returns true when the write that precedes the boundary stays visible
after the injected failure (outside a commit bundle, which is always
all-or-nothing).
Trait Implementations§
Source§impl Clone for FailurePoint
impl Clone for FailurePoint
impl Copy for FailurePoint
Source§impl Debug for FailurePoint
impl Debug for FailurePoint
Source§impl Display for FailurePoint
impl Display for FailurePoint
impl Eq for FailurePoint
Source§impl Hash for FailurePoint
impl Hash for FailurePoint
Source§impl Ord for FailurePoint
impl Ord for FailurePoint
1.21.0 (const: unstable) · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
1.21.0 (const: unstable) · Source§fn min(self, other: Self) -> Selfwhere
Self: Sized,
fn min(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl PartialEq for FailurePoint
impl PartialEq for FailurePoint
Source§impl PartialOrd for FailurePoint
impl PartialOrd for FailurePoint
impl StructuralPartialEq for FailurePoint
Auto Trait Implementations§
impl Freeze for FailurePoint
impl RefUnwindSafe for FailurePoint
impl Send for FailurePoint
impl Sync for FailurePoint
impl Unpin for FailurePoint
impl UnsafeUnpin for FailurePoint
impl UnwindSafe for FailurePoint
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Comparable<K> for Q
impl<Q, K> Comparable<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.