#[non_exhaustive]pub enum BuildError {
Show 39 variants
BlobStoreTenant {
plane: String,
store: String,
},
WitnessQuorumUnreachable {
declared: usize,
configured: usize,
},
IntervalWithoutWitnesses,
JournalStoreTenant {
plane: String,
store: String,
},
StateStoreTenant {
store: &'static str,
plane: String,
tenant: String,
},
ReservedToolServer,
PeerIsAlsoAToolServer {
server: String,
},
PeerGrantOutsideScope {
agent: String,
peer: String,
capability: String,
},
PeerGrantOnASpecialist {
agent: String,
peer: String,
},
DeclarativeToolsUnreachable {
agent: String,
kind: &'static str,
grants: String,
},
ErasureCoordinatorNotShared,
OversightUnreachable {
agent: String,
declared: String,
missing: &'static str,
remedy: &'static str,
},
MemoryWithoutStore {
agent: String,
declared: &'static str,
},
RateLimitWithoutQuotaStore {
agent: String,
grant: String,
},
EmbeddingSpaceMismatch {
embedder: String,
index: String,
},
SemanticMemoryWithoutStore,
SealedMemoryMissesIndex,
MemoryIndexedElsewhere,
UnpricedEmbedder {
embedder: String,
},
MemorySubjectUnbindable {
agent: String,
subject: String,
},
AgentToolUnknownCapability {
agent: String,
capability: String,
},
AgentToolSelfReference {
agent: String,
capability: String,
},
PolicyUnevaluable {
problems: String,
},
BudgetPermitsNothing {
field: &'static str,
},
LeaseUnrenewable {
ttl: Duration,
minimum: Duration,
},
DuplicateToolServer {
server: String,
},
ToolsWiredTwice,
ToolDrift {
agent: String,
problems: Vec<String>,
},
ToolDeclaredTwoWays {
tool: String,
first: String,
second: String,
},
ToolsWithoutDeclaration,
CatalogueLaxerThanGrant {
problems: Vec<String>,
},
DuplicateSkillName {
name: String,
},
CapabilityClaimedTwice {
capability: String,
first: String,
second: String,
},
ProvidesWhatItDoesNotAdvertise {
agent: String,
undeclared: Vec<String>,
},
ContentCheck {
agent: String,
check: String,
detail: String,
},
DeclarativeWithoutModel {
agent: String,
},
UnknownProvider {
agent: String,
provider: String,
},
DeclarativeProvidesNothing {
agent: String,
},
AdvertisesWhatItCannotProvide {
agent: String,
missing: Vec<String>,
},
}Expand description
A plane this crate will not assemble.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
BlobStoreTenant
The plane and its blob store are scoped to different tenants.
WitnessQuorumUnreachable
A witness quorum this plane could never reach.
Both directions are refused, because both spell witnessing that is on and is not. A quorum above the number of witnesses configured is a bar every round misses — so every sweep reports a shortfall, an operator learns to ignore it, and the deployment has the alerting cost of witnessing with none of the evidence. A witness list with no declared quorum is the same failure from the other side: whatever cosignatures happened to arrive become the bar they were held to.
IntervalWithoutWitnesses
A checkpoint interval declared with no witness to submit to.
JournalStoreTenant
The plane and its journal store are scoped to different tenants.
The dangerous one, because it works. Runs are written into another tenant’s keyspace while every key-scoped erasure and every policy request names the right one, so nothing at runtime looks wrong.
StateStoreTenant
The plane and one of its state stores are scoped to different tenants.
One variant for the five stores whose consequence is the same, with the store named as data rather than as five messages that differ only in a noun. When a key ring is wired, the plane seals this state under its tenant while the store writes rows under the store’s, and the two scopes are both real — so nothing fails, nothing leaks, and the state sits under a scope the tenant’s erasure does not name.
That is the failure a deletion guarantee may not have: erase destroys
the key it was asked for, reports success, and the sealed rows remain
readable under the other scope. It is invisible at runtime because
nothing about it is wrong except which of two correct scopes was used.
Fields
ReservedToolServer
A tool server took the name reserved for agents on this plane.
PeerIsAlsoAToolServer
One name is both a registered peer and a wired tool server.
A grant tool://<name>/<capability> would then dispatch to whichever
the runtime checked first — a peer hop that extends the chain and
counts against the delegation ceiling, or a tool call that does neither
— and nothing in the reviewed document would say which.
PeerGrantOutsideScope
A manifest grants a peer a capability the registry never gave it.
The chain the peer receives permits exactly the registry’s scope, so the call would be refused at the peer’s admission on every run — a grant that reads as a capability and cannot fire.
PeerGrantOnASpecialist
A specialist grants a peer, which is a hop it may never take.
Calling a peer is delegation: the chain grows by a link and the
delegation ceiling sees it. A specialist has a ceiling of zero, so
the grant would be refused at dispatch on every run.
DeclarativeToolsUnreachable
A declarative agent needs a tool catalogue and the plane has none.
Refused at build because it is knowable at build: the manifest says the
agent runs a tool loop, and the plane says nothing reaches a tool server.
Deferring it to the run would report a wiring mistake once per request
instead of once, on a plane that assembled cleanly. The one shape that is
legitimately catalogue-free is an agent whose grants are all
tool://agent/… or tool://<peer>/… for a registered peer: those
dispatch through commission and the peer wiring, and their catalogue
is derived from the declaration.
A process-local erasure lock beside a store two instances can write.
OversightUnreachable
An agent declares oversight on a plane that cannot ask anybody.
The same shape as DeclarativeToolsUnreachable,
and both facts are in hand at build: the manifest says a human must
decide, and the plane says there is nowhere to put the decision. Left to
run time it surfaces on the one code path a test suite is least likely
to reach — the first real approval — with the person already waiting.
MemoryWithoutStore
An agent reads or writes memories on a plane that has nowhere to keep them.
Knowable at build, and expensive at run time in a way most wiring mistakes are not: formation happens after the answer, so the run has already paid for its model calls, opened its approval task and waited for a person before failing on a store nobody wired.
Fields
RateLimitWithoutQuotaStore
A grant declares a rate ceiling on a plane with nothing to count it in.
The count is across runs and instances, so it lives in the quota store; without one the ceiling would be reviewed and never counted.
EmbeddingSpaceMismatch
The plane’s embedder and its index speak different languages.
The one wiring mistake in this list that would otherwise never fail —
see IndexIdentity. The two strings
differing is not itself the mistake: an index built from
…/search_document asks for …/search_query here.
SemanticMemoryWithoutStore
A semantic index on a plane with no authoritative memory.
Every search would fail at its last step, having already paid for an embedding call and a retrieval.
SealedMemoryMissesIndex
A sealed memory store whose own subject erasure misses the wired semantic index.
EncryptedMemoryStore::erase_subject runs beneath any wrapper the
plane could add, so only an index beneath the seal is told what it
removed; above it, a person’s erasure leaves their embeddings behind.
MemoryIndexedElsewhere
A memory store that already tells a semantic index other than the one
semantic_memory(..) wires.
UnpricedEmbedder
A money ceiling is stated and the embedder states no price.
MemorySubjectUnbindable
A memory subject binds to a case on a plane with no cases.
The failure this prevents is worse than an error, which is why it is one: a binding that cannot resolve leaves the operator’s fallback options as fail the run or file everybody’s memories under one key, and the second is the defect bindings exist to remove.
AgentToolUnknownCapability
An agent grant names a capability no agent on this plane provides.
AgentToolSelfReference
An agent grant names the granting agent’s own capability.
PolicyUnevaluable
The policy set cannot be evaluated against a request this plane makes.
Every rule is evaluated against every request, so a rule reading an
attribute a request does not carry does not merely fail to match — it
errors, and an unevaluable rule may be the forbid that would have
stopped the call, so the gate refuses. A rule guarded on nothing
therefore denies every effect of every run, from a policy set that
compiled cleanly and validated against its schema.
Some context attributes are conditional by design: delegation_depth,
owner and scope exist only where a delegation chain does, and
label only where a value is being sinked. A rule that reads one
unconditionally is correct exactly until the first request without it.
The remedy is Cedar’s has: context has delegation_depth && context.delegation_depth >= 1.
Found at build by evaluating the compiled set against a canonical request of each shape the runtime issues — cheap, because evaluation is total and side-effect free — rather than at the first effect of the first run, which is where a deployment discovered it as a plane that denied everything.
BudgetPermitsNothing
A ceiling set to zero, which permits nothing at all.
Zero is not a small budget; it is a budget already spent. These ceilings are checked before the work and against every effect of every kind, so a plane carrying one refuses its first operation on every run it will ever make — including a read-only tool call by an agent that declares no model.
The manifest refuses this at parse, and a plane wired in Rust reaches the same budget without passing a parser: one rule, both doors.
LeaseUnrenewable
A lease TTL shorter than the store’s expiry granularity.
Both stores keep lease expiry in whole seconds and treat
expires_at <= now as lapsed, so anything under the minimum is expired
for part of every second it exists — no renewal frequency saves it.
A plane built with one would have every run takeable by another
instance while still working, and only under load.
DuplicateToolServer
One tool server name was registered twice.
ToolsWiredTwice
Both tools(..) and toolbox(..) were wired.
Not a merge, and it must not silently become one: the stated catalogue is the operator saying something deliberate, the derived one is the agent’s declaration, and overwriting either runs a plane under grants nobody chose.
ToolDrift
The tools this binary implements and a reviewed manifest disagree.
ToolDeclaredTwoWays
Two agents grant one tool and declare it differently.
ToolsWithoutDeclaration
Tools were wired to a plane whose agents declare none.
CatalogueLaxerThanGrant
A stated catalogue is laxer than a reviewed grant.
The one direction nobody can be right about: a read-only entry exempts
the tool from the whole-value taint gate and carries Recovery::Retry,
so a timed-out money-moving call is sent again.
DuplicateSkillName
Two distinct skills share one name.
CapabilityClaimedTwice
Two agents claim one capability.
ProvidesWhatItDoesNotAdvertise
A skill answers a capability its agent’s declaration never names.
The manifest is the artifact that gets reviewed, digested and pinned, and the A2A card is built from it — so a capability served but not advertised is a door in a reviewed surface that the review could not see. The skill is still governed by the manifest, which is what makes this quiet rather than broken: budgets and grants apply, the run journals correctly, and nothing anywhere says the agent answers more than its file claims.
ContentCheck
A declared content check nothing on this plane could run as declared: its checker is not registered, or it maps a category the checker never reports.
DeclarativeWithoutModel
A declarative agent has no model to call.
UnknownProvider
A declarative agent names a provider no driver is registered for.
Named rather than defaulted: falling back to some other registered driver would run the agent on a model its own declaration does not name.
DeclarativeProvidesNothing
A declarative agent provides no capability.
AdvertisesWhatItCannotProvide
A manifest advertises capabilities none of its own skills provide.
Trait Implementations§
Source§impl Clone for BuildError
impl Clone for BuildError
Source§impl Debug for BuildError
impl Debug for BuildError
Source§impl Display for BuildError
impl Display for BuildError
impl Eq for BuildError
Source§impl Error for BuildError
impl Error for BuildError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Source§impl PartialEq for BuildError
impl PartialEq for BuildError
impl StructuralPartialEq for BuildError
Auto Trait Implementations§
impl Freeze for BuildError
impl RefUnwindSafe for BuildError
impl Send for BuildError
impl Sync for BuildError
impl Unpin for BuildError
impl UnsafeUnpin for BuildError
impl UnwindSafe for BuildError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more