pub enum WitnessError {
Shrank {
origin: String,
seen: u64,
offered: u64,
},
Forked {
origin: String,
seen: u64,
offered: u64,
},
Stale {
origin: String,
witness_size: u64,
},
ProofMissing {
origin: String,
seen: u64,
},
Inconsistent {
origin: String,
old_size: u64,
offered: u64,
},
Unsigned(SignError),
Unavailable(String),
}Expand description
Why a witness would not cosign.
Variants§
Shrank
The log is smaller than when this witness last saw it.
Runs were removed. The single most important thing a witness catches, and the one an operator auditing itself structurally cannot.
Forked
The new checkpoint does not extend the one this witness last cosigned.
Either history was rewritten, or this is a different history of the same log — the split view. A witness cannot tell which, and does not need to: both are refusals.
Stale
The witness is at a different size than the proof starts from.
A stale client, not an integrity event, and the distinction is the whole reason this is its own variant. The witness has simply moved past the checkpoint this proof was built from, and it says where it is, so the fix is to build a proof from there and retry.
Collapsing it into Forked would report a routine
cursor mismatch as a history that does not extend — and a team paged
twice for that stops believing the alert that matters.
ProofMissing
A proof was required and none was usable.
Inconsistent
The witness could not verify the growth this submission claimed, and which side is at fault is not decidable from the answer.
Its own variant rather than Forked, because the two
send an operator to different places. A witness answering this
consistency proof does not verify is either looking at a proof this
log built wrongly — a bug on this side, permanent until the code
changes — or at a history that genuinely no longer extends what it
remembers. Forked is reserved for the answer where the witness
removes the ambiguity itself: equal sizes with unequal roots, which no
proof-building mistake can produce.
Classified with the integrity refusals all the same, and deliberately: resubmitting reproduces it, so filing it as routine would leave a plane whose evidence silently stopped accumulating.
Unsigned(SignError)
This log could not sign its own checkpoint.
The fault is local, and saying so is the point: a witness cannot cosign
a checkpoint it cannot attribute, so an unsigned submission is refused
with 403 by every conformant witness — which reads as the witness
does not trust us rather than as our signer is down.
The witness could not be reached or refused for its own reasons.
Trait Implementations§
Source§impl Debug for WitnessError
impl Debug for WitnessError
Source§impl Display for WitnessError
impl Display for WitnessError
Source§impl Error for WitnessError
impl Error for WitnessError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Auto Trait Implementations§
impl Freeze for WitnessError
impl RefUnwindSafe for WitnessError
impl Send for WitnessError
impl Sync for WitnessError
impl Unpin for WitnessError
impl UnsafeUnpin for WitnessError
impl UnwindSafe for WitnessError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more