async fn walk(
services: &Services,
tokenexpires: &Arc<Map>,
mode: Mode,
) -> Result<Tally>Expand description
Walks the origin column once, applying the mode to every row.
One row at a time: each is read before it is rewritten, so a concurrent walk could let two rows naming one token both clear the provenance guard. A cursor error ends the walk rather than being counted, because the status is sticky and the iterator cannot advance past it. An unreadable row fails the walk too, since leaving the marker unstamped is what makes an engine failure recoverable: the pass is idempotent, so the next boot retries it whole.