pub struct CheckpointTable {
pub kind: u8,
pub source_len: u64,
pub graph_crc32c: u32,
pub entries: Vec<CheckpointEntry>,
}Expand description
A decoded CHECKPOINT record payload.
Fields§
§kind: u8Checkpoint kind (only CHECKPOINT_KIND_OP_BOUNDARIES is valid here).
source_len: u64Declared total output length (must equal the source length).
graph_crc32c: u32CRC-32C of the GRAPH payload this checkpoint describes.
entries: Vec<CheckpointEntry>Per-op boundaries, in program order.
Implementations§
Source§impl CheckpointTable
impl CheckpointTable
Sourcepub fn from_program(
program: &Program,
object_lens: &[u64],
channel_lens: &[u64],
source_len: u64,
limits: Limits,
) -> Result<CheckpointTable>
pub fn from_program( program: &Program, object_lens: &[u64], channel_lens: &[u64], source_len: u64, limits: Limits, ) -> Result<CheckpointTable>
Build an OP_BOUNDARIES checkpoint from the authoritative program.
Per-op lengths come from Program::analyze_ops; the boundaries are their
running sum. graph_crc32c is the CRC-32C of program.encode() — the
exact GRAPH payload the checkpoint is bound to. No allocation is sized by
an untrusted count: the vector is bounded by Limits::max_graph_ops.
Sourcepub fn decode(bytes: &[u8], limits: Limits) -> Result<CheckpointTable>
pub fn decode(bytes: &[u8], limits: Limits) -> Result<CheckpointTable>
Decode and structurally bound a payload.
This checks the size bound, the version, the kind, the reserved field, and
that the declared entry count fits the payload. It does not check
agreement with a program; call CheckpointTable::validate for that.
Sourcepub fn validate(
&self,
program: &Program,
graph_payload: &[u8],
source_len: u64,
object_lens: &[u64],
channel_lens: &[u64],
limits: Limits,
) -> Result<()>
pub fn validate( &self, program: &Program, graph_payload: &[u8], source_len: u64, object_lens: &[u64], channel_lens: &[u64], limits: Limits, ) -> Result<()>
Validate the checkpoint against the authoritative program and graph.
Requires: the declared kind is OP_BOUNDARIES; graph_payload’s CRC-32C
equals the checkpoint’s binding; the declared source_len matches; the
entry count matches the program; the entries are contiguous and cover the
source exactly; and every entry’s out_len equals the program’s own
Program::analyze_ops view. Any disagreement is a typed rejection — the
checkpoint is never trusted.