Skip to main content

FailurePoint

Enum FailurePoint 

Source
#[non_exhaustive]
pub enum FailurePoint { AfterInteractionPersistence, BeforeJournalInsert, AfterJournalInsertBeforeCommit, AfterCommitBeforeEventReadback, BeforeOutboxDispatch, AfterOutboxDispatch, BeforeResponsePersistence, }
Expand description

A boundary at which the in-memory store can be made to fail (spec §27.7).

The names describe the moment in a turn, not the method: one point may be reached from more than one method, and the variant documentation names them.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

AfterInteractionPersistence

The card was written and the caller is told it was not.

Fires in InteractionWriter::insert and insert_replacing_blocking after the insert: the interaction (and any invalidation the insert performed) stays visible. Spec §15.5 requires interaction persistence to succeed before the response mentions the card, so the truthful reaction is to omit the card, not to claim it.

Inside a commit bundle it fires after stage 5 (interaction inserts) and aborts the bundle.

§

BeforeJournalInsert

The command was never admitted.

Fires in CommandJournalWriter::begin before anything is written, so the key stays free and the command may be admitted again from scratch.

§

AfterJournalInsertBeforeCommit

The command was admitted and then the process died before the domain commit.

Fires in CommandJournalWriter::begin after the entry is persisted: the entry survives in Pending, which is exactly the state pending_for_turn exists to find, and recovery must resume it by idempotency key rather than admitting a second command (spec §23.1).

Inside a commit bundle it fires after stage 1 (journal completions) and aborts the bundle.

§

AfterCommitBeforeEventReadback

The events were appended and the caller could not read them back.

Fires in EventJournalWriter::append after the batch is appended: the events are in the ledger, so a recovery that re-reads by command finds them and must not append them a second time.

Inside a commit bundle it fires after stage 2 (event batches) and aborts the bundle.

§

BeforeOutboxDispatch

The dispatcher never got the work.

Fires in OutboxWriter::claim_due before anything is claimed: no row moves to Dispatching and the next sweep picks the same rows up.

§

AfterOutboxDispatch

The external call was made and its result could not be recorded.

Fires in mark_completed, mark_failed and mark_outcome_unknown before the write: the row stays Dispatching with its claim, which is the state release_expired_claims exists to reap. It is the worst case of spec §16.5 — an effect may exist and nothing local says so — so a retry is only safe when the remote guarantees idempotency.

§

BeforeResponsePersistence

The answer was composed and never stored.

Fires in append_assistant_turn before the write. The turn keeps its user side and its phase marker, so recovery regenerates the response from committed events and stored answer tasks instead of re-executing anything (spec §23.1).

Implementations§

Source§

impl FailurePoint

Source

pub const ALL: [Self; 7]

Every point, in declaration order.

Source

pub const fn as_str(self) -> &'static str

The boundary’s stable name, matching the crash boundaries the specification enumerates.

Stable across releases: test kits and fixtures address a boundary by this string, so renaming one is a breaking change.

Source

pub fn parse(name: &str) -> Result<Self, UnknownFailurePoint>

Parses a boundary from the name as_str renders.

§Errors

Returns the unknown name when it matches no boundary.

Source

pub fn leaves_write_visible(self) -> bool

Returns true when the write that precedes the boundary stays visible after the injected failure (outside a commit bundle, which is always all-or-nothing).

Trait Implementations§

Source§

impl Clone for FailurePoint

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for FailurePoint

Source§

impl Debug for FailurePoint

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for FailurePoint

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for FailurePoint

Source§

impl Hash for FailurePoint

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for FailurePoint

Source§

fn cmp(&self, other: &Self) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for FailurePoint

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for FailurePoint

Source§

fn partial_cmp(&self, other: &Self) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for FailurePoint

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AsOut<T> for T
where T: Copy,

Source§

fn as_out(&mut self) -> Out<'_, T>

Returns an out reference to self.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Comparable<K> for Q
where Q: Ord + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn compare(&self, key: &K) -> Ordering

Compare self to key and return their ordering.
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.