Skip to main content

BuildError

Enum BuildError 

Source
#[non_exhaustive]
pub enum BuildError {
Show 39 variants BlobStoreTenant { plane: String, store: String, }, WitnessQuorumUnreachable { declared: usize, configured: usize, }, IntervalWithoutWitnesses, JournalStoreTenant { plane: String, store: String, }, StateStoreTenant { store: &'static str, plane: String, tenant: String, }, ReservedToolServer, PeerIsAlsoAToolServer { server: String, }, PeerGrantOutsideScope { agent: String, peer: String, capability: String, }, PeerGrantOnASpecialist { agent: String, peer: String, }, DeclarativeToolsUnreachable { agent: String, kind: &'static str, grants: String, }, ErasureCoordinatorNotShared, OversightUnreachable { agent: String, declared: String, missing: &'static str, remedy: &'static str, }, MemoryWithoutStore { agent: String, declared: &'static str, }, RateLimitWithoutQuotaStore { agent: String, grant: String, }, EmbeddingSpaceMismatch { embedder: String, index: String, }, SemanticMemoryWithoutStore, SealedMemoryMissesIndex, MemoryIndexedElsewhere, UnpricedEmbedder { embedder: String, }, MemorySubjectUnbindable { agent: String, subject: String, }, AgentToolUnknownCapability { agent: String, capability: String, }, AgentToolSelfReference { agent: String, capability: String, }, PolicyUnevaluable { problems: String, }, BudgetPermitsNothing { field: &'static str, }, LeaseUnrenewable { ttl: Duration, minimum: Duration, }, DuplicateToolServer { server: String, }, ToolsWiredTwice, ToolDrift { agent: String, problems: Vec<String>, }, ToolDeclaredTwoWays { tool: String, first: String, second: String, }, ToolsWithoutDeclaration, CatalogueLaxerThanGrant { problems: Vec<String>, }, DuplicateSkillName { name: String, }, CapabilityClaimedTwice { capability: String, first: String, second: String, }, ProvidesWhatItDoesNotAdvertise { agent: String, undeclared: Vec<String>, }, ContentCheck { agent: String, check: String, detail: String, }, DeclarativeWithoutModel { agent: String, }, UnknownProvider { agent: String, provider: String, }, DeclarativeProvidesNothing { agent: String, }, AdvertisesWhatItCannotProvide { agent: String, missing: Vec<String>, },
}
Expand description

A plane this crate will not assemble.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

BlobStoreTenant

The plane and its blob store are scoped to different tenants.

Fields

§plane: String
§store: String
§

WitnessQuorumUnreachable

A witness quorum this plane could never reach.

Both directions are refused, because both spell witnessing that is on and is not. A quorum above the number of witnesses configured is a bar every round misses — so every sweep reports a shortfall, an operator learns to ignore it, and the deployment has the alerting cost of witnessing with none of the evidence. A witness list with no declared quorum is the same failure from the other side: whatever cosignatures happened to arrive become the bar they were held to.

Fields

§declared: usize
§configured: usize
§

IntervalWithoutWitnesses

A checkpoint interval declared with no witness to submit to.

§

JournalStoreTenant

The plane and its journal store are scoped to different tenants.

The dangerous one, because it works. Runs are written into another tenant’s keyspace while every key-scoped erasure and every policy request names the right one, so nothing at runtime looks wrong.

Fields

§plane: String
§store: String
§

StateStoreTenant

The plane and one of its state stores are scoped to different tenants.

One variant for the five stores whose consequence is the same, with the store named as data rather than as five messages that differ only in a noun. When a key ring is wired, the plane seals this state under its tenant while the store writes rows under the store’s, and the two scopes are both real — so nothing fails, nothing leaks, and the state sits under a scope the tenant’s erasure does not name.

That is the failure a deletion guarantee may not have: erase destroys the key it was asked for, reports success, and the sealed rows remain readable under the other scope. It is invisible at runtime because nothing about it is wrong except which of two correct scopes was used.

Fields

§store: &'static str

Which store disagreed: case, event, task, memory, quota, timer, batch, authority or push.

§plane: String
§tenant: String
§

ReservedToolServer

A tool server took the name reserved for agents on this plane.

§

PeerIsAlsoAToolServer

One name is both a registered peer and a wired tool server.

A grant tool://<name>/<capability> would then dispatch to whichever the runtime checked first — a peer hop that extends the chain and counts against the delegation ceiling, or a tool call that does neither — and nothing in the reviewed document would say which.

Fields

§server: String
§

PeerGrantOutsideScope

A manifest grants a peer a capability the registry never gave it.

The chain the peer receives permits exactly the registry’s scope, so the call would be refused at the peer’s admission on every run — a grant that reads as a capability and cannot fire.

Fields

§agent: String
§peer: String
§capability: String
§

PeerGrantOnASpecialist

A specialist grants a peer, which is a hop it may never take.

Calling a peer is delegation: the chain grows by a link and the delegation ceiling sees it. A specialist has a ceiling of zero, so the grant would be refused at dispatch on every run.

Fields

§agent: String
§peer: String
§

DeclarativeToolsUnreachable

A declarative agent needs a tool catalogue and the plane has none.

Refused at build because it is knowable at build: the manifest says the agent runs a tool loop, and the plane says nothing reaches a tool server. Deferring it to the run would report a wiring mistake once per request instead of once, on a plane that assembled cleanly. The one shape that is legitimately catalogue-free is an agent whose grants are all tool://agent/… or tool://<peer>/… for a registered peer: those dispatch through commission and the peer wiring, and their catalogue is derived from the declaration.

Fields

§agent: String
§kind: &'static str
§grants: String
§

ErasureCoordinatorNotShared

A process-local erasure lock beside a store two instances can write.

§

OversightUnreachable

An agent declares oversight on a plane that cannot ask anybody.

The same shape as DeclarativeToolsUnreachable, and both facts are in hand at build: the manifest says a human must decide, and the plane says there is nowhere to put the decision. Left to run time it surfaces on the one code path a test suite is least likely to reach — the first real approval — with the person already waiting.

Fields

§agent: String
§declared: String
§missing: &'static str
§remedy: &'static str
§

MemoryWithoutStore

An agent reads or writes memories on a plane that has nowhere to keep them.

Knowable at build, and expensive at run time in a way most wiring mistakes are not: formation happens after the answer, so the run has already paid for its model calls, opened its approval task and waited for a person before failing on a store nobody wired.

Fields

§agent: String
§declared: &'static str

The declaration that needs a store: spec.memory.recall or spec.memory.formation.

§

RateLimitWithoutQuotaStore

A grant declares a rate ceiling on a plane with nothing to count it in.

The count is across runs and instances, so it lives in the quota store; without one the ceiling would be reviewed and never counted.

Fields

§agent: String
§grant: String
§

EmbeddingSpaceMismatch

The plane’s embedder and its index speak different languages.

The one wiring mistake in this list that would otherwise never fail — see IndexIdentity. The two strings differing is not itself the mistake: an index built from …/search_document asks for …/search_query here.

Fields

§embedder: String
§index: String
§

SemanticMemoryWithoutStore

A semantic index on a plane with no authoritative memory.

Every search would fail at its last step, having already paid for an embedding call and a retrieval.

§

SealedMemoryMissesIndex

A sealed memory store whose own subject erasure misses the wired semantic index.

EncryptedMemoryStore::erase_subject runs beneath any wrapper the plane could add, so only an index beneath the seal is told what it removed; above it, a person’s erasure leaves their embeddings behind.

§

MemoryIndexedElsewhere

A memory store that already tells a semantic index other than the one semantic_memory(..) wires.

§

UnpricedEmbedder

A money ceiling is stated and the embedder states no price.

Fields

§embedder: String
§

MemorySubjectUnbindable

A memory subject binds to a case on a plane with no cases.

The failure this prevents is worse than an error, which is why it is one: a binding that cannot resolve leaves the operator’s fallback options as fail the run or file everybody’s memories under one key, and the second is the defect bindings exist to remove.

Fields

§agent: String
§subject: String
§

AgentToolUnknownCapability

An agent grant names a capability no agent on this plane provides.

Fields

§agent: String
§capability: String
§

AgentToolSelfReference

An agent grant names the granting agent’s own capability.

Fields

§agent: String
§capability: String
§

PolicyUnevaluable

The policy set cannot be evaluated against a request this plane makes.

Every rule is evaluated against every request, so a rule reading an attribute a request does not carry does not merely fail to match — it errors, and an unevaluable rule may be the forbid that would have stopped the call, so the gate refuses. A rule guarded on nothing therefore denies every effect of every run, from a policy set that compiled cleanly and validated against its schema.

Some context attributes are conditional by design: delegation_depth, owner and scope exist only where a delegation chain does, and label only where a value is being sinked. A rule that reads one unconditionally is correct exactly until the first request without it. The remedy is Cedar’s has: context has delegation_depth && context.delegation_depth >= 1.

Found at build by evaluating the compiled set against a canonical request of each shape the runtime issues — cheap, because evaluation is total and side-effect free — rather than at the first effect of the first run, which is where a deployment discovered it as a plane that denied everything.

Fields

§problems: String
§

BudgetPermitsNothing

A ceiling set to zero, which permits nothing at all.

Zero is not a small budget; it is a budget already spent. These ceilings are checked before the work and against every effect of every kind, so a plane carrying one refuses its first operation on every run it will ever make — including a read-only tool call by an agent that declares no model.

The manifest refuses this at parse, and a plane wired in Rust reaches the same budget without passing a parser: one rule, both doors.

Fields

§field: &'static str
§

LeaseUnrenewable

A lease TTL shorter than the store’s expiry granularity.

Both stores keep lease expiry in whole seconds and treat expires_at <= now as lapsed, so anything under the minimum is expired for part of every second it exists — no renewal frequency saves it. A plane built with one would have every run takeable by another instance while still working, and only under load.

Fields

§minimum: Duration
§

DuplicateToolServer

One tool server name was registered twice.

Fields

§server: String
§

ToolsWiredTwice

Both tools(..) and toolbox(..) were wired.

Not a merge, and it must not silently become one: the stated catalogue is the operator saying something deliberate, the derived one is the agent’s declaration, and overwriting either runs a plane under grants nobody chose.

§

ToolDrift

The tools this binary implements and a reviewed manifest disagree.

Fields

§agent: String
§problems: Vec<String>
§

ToolDeclaredTwoWays

Two agents grant one tool and declare it differently.

Fields

§tool: String
§first: String
§second: String
§

ToolsWithoutDeclaration

Tools were wired to a plane whose agents declare none.

§

CatalogueLaxerThanGrant

A stated catalogue is laxer than a reviewed grant.

The one direction nobody can be right about: a read-only entry exempts the tool from the whole-value taint gate and carries Recovery::Retry, so a timed-out money-moving call is sent again.

Fields

§problems: Vec<String>
§

DuplicateSkillName

Two distinct skills share one name.

Fields

§name: String
§

CapabilityClaimedTwice

Two agents claim one capability.

Fields

§capability: String
§first: String
§second: String
§

ProvidesWhatItDoesNotAdvertise

A skill answers a capability its agent’s declaration never names.

The manifest is the artifact that gets reviewed, digested and pinned, and the A2A card is built from it — so a capability served but not advertised is a door in a reviewed surface that the review could not see. The skill is still governed by the manifest, which is what makes this quiet rather than broken: budgets and grants apply, the run journals correctly, and nothing anywhere says the agent answers more than its file claims.

Fields

§agent: String
§undeclared: Vec<String>
§

ContentCheck

A declared content check nothing on this plane could run as declared: its checker is not registered, or it maps a category the checker never reports.

Fields

§agent: String
§check: String
§detail: String
§

DeclarativeWithoutModel

A declarative agent has no model to call.

Fields

§agent: String
§

UnknownProvider

A declarative agent names a provider no driver is registered for.

Named rather than defaulted: falling back to some other registered driver would run the agent on a model its own declaration does not name.

Fields

§agent: String
§provider: String
§

DeclarativeProvidesNothing

A declarative agent provides no capability.

Fields

§agent: String
§

AdvertisesWhatItCannotProvide

A manifest advertises capabilities none of its own skills provide.

Fields

§agent: String
§missing: Vec<String>

Trait Implementations§

Source§

impl Clone for BuildError

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for BuildError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for BuildError

Source§

fn fmt(&self, __formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for BuildError

Source§

impl Error for BuildError

1.30.0 · Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl PartialEq for BuildError

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for BuildError

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> MaybeSend for T
where T: Send,

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToSmolStr for T
where T: Display + ?Sized,

Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more