Skip to main content

RuntimeError

Enum RuntimeError 

Source
#[non_exhaustive]
pub enum RuntimeError { PolicyDenied(PolicyError), PlanContract(String), UnknownTenant(String), PolicyBundleChanged { recorded: Option<Digest>, configured: Option<Digest>, }, CanonicalizationChanged { recorded: u16, implemented: u16, }, NoProvider { target: String, available: Vec<String>, }, QuotaExceeded(QuotaError), ChainBroken { seq: Seq, detail: String, }, Fenced { run: String, held: u64, current: u64, }, LeaseHeld { run: String, owner: String, remaining_secs: u64, }, Store(StoreError), Encoding(Error), }
Expand description

Failures reaching the operator.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

PolicyDenied(PolicyError)

§

PlanContract(String)

§

UnknownTenant(String)

This process serves no plane for the tenant named.

Refused rather than defaulted, which is the whole point: a fallback plane would answer an unregistered tenant with somebody else’s data, and it would look exactly like working software.

§

PolicyBundleChanged

An open run would continue under policy semantics other than the bundle recorded at admission.

Fields

§recorded: Option<Digest>
§configured: Option<Digest>
§

CanonicalizationChanged

The history was written under a different canonicalization rule.

Not a divergence, and reporting it as one is the defect this exists to remove: every effect key comes out of the canonicalizer, so a rule change moves all of them at once and a healthy run replays as non-determinism. The run is unverifiable by this build, which is a different claim and the one the evidence supports.

The journal chain is unaffected — it hashes the bytes it stored rather than re-canonicalizing them — so the history is intact and readable; it simply cannot be re-derived here. Before format freeze the answer is to recreate; after it, a build that means to read old history implements the old rule and selects on this number.

Fields

§recorded: u16
§implemented: u16
§

NoProvider

Nothing on this plane answers to the name run was given.

Carries what the plane does provide, because the question a reader has next is always “then what should I have asked for?” — and the plane is the only party that can answer it. A refusal that names the missing thing and not the available ones sends somebody back to their own source to reconstruct a list this error was already holding.

Fields

§target: String

The capability (or skill name) that was asked for.

§available: Vec<String>

Every capability this plane provides, sorted. Empty means no skills.

§

QuotaExceeded(QuotaError)

The tenant is at a ceiling, so nothing was admitted.

Distinct from a policy denial, because they call for opposite responses. A denial says you may not, and retrying is pointless. A quota refusal says not right now, and the caller should come back — a concurrency ceiling clears when a run finishes. Collapsing them would teach callers to retry denials or to give up on back-pressure.

§

ChainBroken

The journal’s hash chain does not verify. Either a record was altered after the fact, or a writer produced bytes it did not hash.

Fields

§seq: Seq
§detail: String
§

Fenced

A write was rejected because another instance owns this run at a higher epoch. Not an error to retry blindly: this instance has been fenced and must drop the run.

Fields

§held: u64
§current: u64
§

LeaseHeld

Another instance holds a live lease on this run. Retryable after the lease expires — unlike Fenced, which never is.

Fields

§owner: String
§remaining_secs: u64
§

Store(StoreError)

§

Encoding(Error)

Implementations§

Source§

impl RuntimeError

Source

pub fn from_store(e: StoreError) -> Self

Lift a store error into the operator-facing taxonomy.

Two promotions matter, because both change what a human should do:

  • Fenced — “I lost ownership of this run” (drop it; another instance has it), as opposed to “the database is unhappy” (retry).
  • Corrupt → ChainBroken — the journal does not verify. That is never a retryable storage hiccup; it means the history has been altered and nothing downstream of it can be trusted. Leaving it as a generic store error would bury the one failure that must never be shrugged off.
Source

pub fn is_terminal_for_owner(&self) -> bool

Whether this run should be abandoned by this instance rather than retried. Both cases are terminal for the current owner: fencing means someone else owns it, and a broken chain means the recorded history can no longer be trusted to describe anything.

Divergence is deliberately not here. It is not a RuntimeError at all — a replay that recomputes a different key quarantines the run, through StepError::NonDeterminism, and a run status is not something an owner abandons. A second spelling of it lived on this enum, unconstructed and pointed at by the crate’s own front page, until a guard noticed.

Trait Implementations§

Source§

impl Debug for RuntimeError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for RuntimeError

Source§

fn fmt(&self, __formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Error for RuntimeError

Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl From<Error> for RuntimeError

Source§

fn from(source: Error) -> Self

Converts to this type from the input type.
Source§

impl From<PolicyError> for RuntimeError

Source§

fn from(source: PolicyError) -> Self

Converts to this type from the input type.
Source§

impl From<QuotaError> for RuntimeError

Source§

fn from(source: QuotaError) -> Self

Converts to this type from the input type.
Source§

impl From<StoreError> for RuntimeError

Source§

fn from(source: StoreError) -> Self

Converts to this type from the input type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> MaybeSend for T
where T: Send,

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToSmolStr for T
where T: Display + ?Sized,

Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more