pub enum DatabaseOp {
Show 19 variants
ResolveStoreState {
request: StoreStateRequest,
},
BeginStoreStateStaging {
request: StoreStateRequest,
},
StageStoreStateRecords {
token: String,
chunk_id: u64,
records: WireRecordMutations,
},
PublishStoreState {
token: String,
},
AbortStoreState {
token: String,
},
StoreStateRecordGet {
view: String,
key: Vec<u8>,
},
StoreStateRecordScan {
view: String,
range: RecordRange,
after: Option<Vec<u8>>,
max_records: u32,
max_encoded_bytes: u32,
},
BeginTransaction {
stores: Vec<String>,
scope: ReadScope,
},
SubmitSignedEntry {
entry: Box<Entry>,
},
GetVerifiedTips,
GetStoreState {
store: String,
},
GetStoreEntries {
store: String,
tips: Vec<ID>,
scope: ReadScope,
},
GetStoreTipsUpToEntries {
store: String,
up_to: Vec<ID>,
},
ComputeMergeState {
store: String,
entry_ids: Vec<ID>,
},
GetEntry {
id: ID,
},
SetInstanceMetadata {
metadata: Box<InstanceMetadata>,
},
SubscribeWrites {
tips: Snapshot,
},
UnsubscribeWrites,
CreateTicket,
}Expand description
Database-level operations the server runs on its local Database.
The target database (root_id) and identity claim travel in
AuthenticatedDbRequest; the per-tree gate runs against root_id
(Read for begin/get*, Write for submit, Admin-on-_databases for
set-metadata) before dispatch.
Variants§
ResolveStoreState
Resolve cached state through an opaque view onto one published record set.
Fields
request: StoreStateRequestBeginStoreStateStaging
Begin a private build.
Fields
request: StoreStateRequestStageStoreStateRecords
Upload one idempotent chunk into the private build.
PublishStoreState
Publish the private build and return a view onto the published record set.
AbortStoreState
Discard an unfinished private build.
StoreStateRecordGet
Fetch one record from a published record set.
StoreStateRecordScan
Fetch one bounded page from a published record set.
Fields
range: RecordRangeBeginTransaction
Acquire everything needed to build+sign a transaction locally for the
given stores, with parents drawn from scope’s snapshot. Gate Read.
SubmitSignedEntry
Submit a finished, client-signed entry. The server stores it
Unverified and runs its own verification pass — it never trusts
a submitted entry’s claimed validity. Submit is verification-gated,
not session-gated: it requires only an authenticated connection, and
the per-tree permission gate is not applied (the server’s
verification pass against the tree’s pinned auth is the boundary). The
required_permission() value below is advisory only for this variant.
GetVerifiedTips
The database’s Verified-frontier tips (server runs Database::snapshot
on its local instance). Gate Read.
GetStoreState
Server-materialized merged state of an unencrypted store, against the server’s own Verified frontier. Gate Read.
GetStoreEntries
Ordered (by subtree height), verified, opaque store entries reachable
from tips in scope — the universal primitive, incl. encrypted
stores (client decrypts+merges locally). Gate Read.
GetStoreTipsUpToEntries
Subtree tips reachable from given main-tree entry IDs. Used by Transaction internals to discover store entries.
ComputeMergeState
Lowest common ancestor + path to tip entries in a store DAG. Fused to one RPC so base and path resolve against a single server view; answered from separate requests they can straddle a sync ingest and disagree.
GetEntry
Fetch a single entry by id (gated post-fetch by its owning tree). Gate Read.
SetInstanceMetadata
Rewrite the daemon’s instance metadata (system-DB pointers). Gated by
Admin on _databases (a daemon-global system tree, resolved
server-side — not the request’s root_id), so the per-tree gate is
special-cased for this variant in the dispatcher. Boxed to keep the
enum’s stack footprint small — InstanceMetadata dominates its size.
Fields
metadata: Box<InstanceMetadata>SubscribeWrites
Subscribe this connection to write notifications for the request’s
root_id, with an explicit initial cursor (tips).
After the server returns Ok, every write the daemon observes on
that tree (local commits via SubmitSignedEntry, sync ingest via
put_remote_entries, etc.) is pushed back to this connection as a
Notification::DatabaseWrite frame. The frame’s previous_tips
is computed from the daemon-side subscription cursor — initially
the tips supplied here, and advanced to each event’s post_tips
as the daemon fires.
Cursor semantics: pass the tips you just read your initial
state at. The first notification’s previous_tips will exactly
equal tips, so the client can diff tips → notification.post_tips
to discover anything that happened between the initial read and
the daemon recognising the subscription. An empty tips means
“I have no initial state; start from the daemon’s current view”
(the first notification’s previous_tips will be the daemon’s
tips at subscribe-time, captured under the per-tree lock).
Idempotent: re-subscribing a tree this connection already
subscribed to is a no-op (tips on the re-call is ignored;
the cursor stays at whatever it was). Gate Read on root_id.
Subscriptions are cleared automatically when the connection
drops.
UnsubscribeWrites
Stop pushing write notifications for the request’s root_id to this
connection. Idempotent: unsubscribing a tree that wasn’t subscribed
is a no-op. Gate Read on root_id.
CreateTicket
Return a point-in-time locator for the request’s root_id.
Gate Read.
Implementations§
Source§impl DatabaseOp
impl DatabaseOp
Sourcepub fn required_permission(&self) -> Permission
pub fn required_permission(&self) -> Permission
Minimum permission the caller needs against the target database.
Only SubmitSignedEntry mutates; everything else is a read. Every
read variant is tree-scoped via the request’s root_id, so the
per-tree gate always runs for reads — there is no tree-less
fall-through. SubmitSignedEntry is the exception: the server skips
the per-tree gate for submit and relies on its own verification pass,
so the Write(0) returned here is advisory only for that variant
(kept for completeness / non-submit callers that inspect it).
Trait Implementations§
Source§impl Clone for DatabaseOp
impl Clone for DatabaseOp
Source§fn clone(&self) -> DatabaseOp
fn clone(&self) -> DatabaseOp
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for DatabaseOp
impl Debug for DatabaseOp
Source§impl<'de> Deserialize<'de> for DatabaseOp
impl<'de> Deserialize<'de> for DatabaseOp
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for DatabaseOp
impl RefUnwindSafe for DatabaseOp
impl Send for DatabaseOp
impl Sync for DatabaseOp
impl Unpin for DatabaseOp
impl UnsafeUnpin for DatabaseOp
impl UnwindSafe for DatabaseOp
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more