Documentation
¶
Index ¶
- Constants
- type Input
- type Manager
- func (manager Manager) Apply(ctx context.Context, input Input) (result Receipt, resultErr error)
- func (manager Manager) Commit(ctx context.Context, receipt Receipt) (resultErr error)
- func (manager Manager) ListOpen() ([]Receipt, error)
- func (manager Manager) Load(operationID string) (Receipt, error)
- func (manager Manager) Recover(ctx context.Context, operationID string, stateCommitted bool) error
- func (manager Manager) Rollback(ctx context.Context, receipt Receipt) (resultErr error)
- func (manager Manager) VerifyPending(receipt Receipt) (resultErr error)
- type Receipt
Constants ¶
View Source
const ( OperationSwap = "swap" OperationRemove = "remove" PhaseIntent = "intent" PhaseBackupPending = "backup_pending" PhaseOldBackedUp = "old_backed_up" PhaseActivationPending = "activation_pending" PhaseActivated = "activated" PhaseCommitPending = "commit_pending" PhaseCommitted = "committed" PhaseRollbackPending = "rollback_pending" PhaseRolledBack = "rolled_back" FaultBackupRenamed = "backup_renamed" FaultActivationApplied = "activation_applied" FaultBackupRemoved = "backup_removed" FaultRollbackRemoved = "rollback_active_removed" )
View Source
const FaultCommitQuarantined = "commit_quarantined"
View Source
const FaultRollbackQuarantined = "rollback_quarantined"
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Input ¶
type Input struct {
OperationID string
ClientBindingID string
Sequence int
OwnedBase string
ActivePath string
StagingPath string
Remove bool
// RequireAbsent rejects the whole operation, before any journal write or
// filesystem mutation, if ActivePath already exists. It exists for a caller
// reconstructing a target it has independently confirmed absent: an earlier
// absence check can go stale before this call runs, and normal Apply
// semantics would otherwise treat newly appeared content as an existing
// directory to back up and later discard on Commit. Publication also uses
// an exclusive rename so a newly appeared target is never overwritten.
RequireAbsent bool
// VerifyActive authorizes replacement/removal using the caller's ownership
// or reviewed digest. It must verify the supplied physical path, including
// after the directory has moved to backup. Logical locators stay unchanged.
VerifyActive func(context.Context, string) error
}
type Manager ¶
type Manager struct {
JournalDir string
// Fault is a test seam around durable phases and otherwise unreachable
// crash windows. Production callers leave it nil.
Fault func(phase string) error
}
func (Manager) VerifyPending ¶
VerifyPending checks the original physical backup and the publication before the caller makes its state commit decision. Package/data digests are separate caller proofs; neither substitutes for these physical ownership proofs.
type Receipt ¶
type Receipt struct {
SchemaVersion int `json:"schema_version"`
Operation string `json:"operation"`
OperationID string `json:"operation_id"`
ClientBindingID string `json:"client_binding_id"`
Sequence int `json:"sequence"`
OwnedBaseIdentity string `json:"owned_base_identity"`
StagingParentIdentity string `json:"staging_parent_identity,omitempty"`
OwnedBase string `json:"owned_base"`
ActivePath string `json:"active_path"`
StagingPath string `json:"staging_path,omitempty"`
BackupPath string `json:"backup_path"`
HadActive bool `json:"had_active"`
Phase string `json:"phase"`
BackupIdentity string `json:"backup_identity,omitempty"`
BackupDigest string `json:"backup_digest,omitempty"`
QuarantinePath string `json:"quarantine_path"`
PublishedIdentity string `json:"published_identity,omitempty"`
PublishedDigest string `json:"published_digest,omitempty"`
}
Click to show internal directories.
Click to hide internal directories.