pub enum AreevError {
Show 29 variants
NotFound(Hash),
Format(String),
Validation(String),
Serialization(String),
ToolRenderUnsupported(String),
Storage(String),
StoreBusy(String),
TlsUnavailable(String),
ReadOnly(String),
ReadOnlyOpenFailed(String),
SchemaNotProvisioned(String),
LegalHold(String),
AsyncContext(String),
LayoutMismatch(String),
SupersessionConflict(Hash),
SupersessionChainTooDeep(Hash),
AnnIndexUnsupported(String),
CryptoError(String),
AttestationInvalid(String),
AttestationRequired(String),
SigningKeyInvalid(String),
AccumulateRetryExhausted,
AccumulateInternal(String),
AccumulateBackpressureRejected,
Internal(String),
AuthzDenied(String),
AuthzUnknownPrincipal(String),
AuthzConfigInvalid(String),
AuthzTokenUnrecognized,
}Expand description
All errors in areev-core.
Variants§
NotFound(Hash)
Format(String)
Validation(String)
Serialization(String)
ToolRenderUnsupported(String)
Storage(String)
StoreBusy(String)
Another writer holds this memory (single-writer-per-memory is enforced, not advisory, on backends that can arbitrate it).
The connection to a backing store asks for transport encryption this build cannot provide. Its own code because the alternative — reporting a generic validation failure — reads as a typo in the DSN, when what actually happened is that a refusal to downgrade to plaintext saved the operator from an unencrypted connection they did not ask for.
ReadOnly(String)
A write was attempted through a handle opened with read_only: true
(AreevOptions::read_only). Refused at the store layer on BOTH
backends — on postgres this is what stands between a least-privilege
SELECT-only role and a raw 42501 permission denied; on the embedded
backend there is no privilege system to fail against, so the store
enforces the same contract itself, which is what lets one conformance
case cover both.
ReadOnlyOpenFailed(String)
A read-only open could not verify the schema/tables it expected to
find (postgres only — the embedded backend bootstraps its own file
regardless of read_only). Distinct from Storage
because the fix differs: “schema absent” needs someone to create and
migrate it; “schema present but not initialized” needs the owning
role to open it read-write once to finish bootstrap. A read-only role
can do neither itself — that is the whole point of the least-privilege
grant — so the message says which one it is rather than surfacing the
raw permission-denied Postgres gives for CREATE SCHEMA/DDL.
SchemaNotProvisioned(String)
A postgres open found the schema absent or stamped at an older schema
version, and the DSN said provision=never — so no advisory lock and
no DDL were attempted, not even CREATE SCHEMA. Distinct from
ReadOnlyOpenFailed: that one is a
read-only handle discovering it has nothing to read; this is a
read-WRITE handle that was told never to bootstrap on the request path,
which is how a deployment guarantees its runtime role holds no CREATE
and its schema changes go through a migration step. Like its sibling,
the message names WHICH of the two operator actions is needed —
create the memory, or migrate it forward — because they are different
jobs.
LegalHold(String)
A destruction was refused because the namespace it names is under a
legal hold (#278). Its own code rather than Validation
because a host has to be able to record “deferred by hold” — a
records-retention obligation, reportable and expected — without
parsing a message, and to distinguish it from a malformed request.
Carries the namespace, the hold’s owner and its stated reason, so the refusal is itself the evidence a controller needs when answering an erasure request on a retention ground.
AsyncContext(String)
A BLOCKING open was attempted from inside an async runtime (#322).
Areev drives its own
current-thread Tokio runtime and block_ons it, and Tokio refuses to
start a runtime from a runtime worker — so the open used to panic from
inside Tokio, several frames below anything the caller wrote, saying
“Cannot start a runtime from within a runtime” and naming no Areev API
at all.
A coded error instead: the message names AsyncAreev and
AsyncFacade, which are the two supported answers. Raised only on a
runtime WORKER — an open on the blocking pool (where AsyncAreev and
AsyncFacade put theirs) is legal and unaffected.
LayoutMismatch(String)
A postgres open was pointed at a memory whose on-disk layout does not
match the DSN (#353): the DSN names a metadata schema (?meta_schema=)
but the memory schema already carries its engine metadata in-schema
(the single-schema layout), or the DSN names none and the memory
schema holds memory tables without a meta table — which only a
paired-layout memory looks like. Either open would silently split the
engine’s bookkeeping (counters, the namespace registry, legal holds,
retention policies, saved queries) across two places, so it is refused
before any DDL. A layout change is an explicit migration, never an
implicit one.
SupersessionConflict(Hash)
SupersessionChainTooDeep(Hash)
A supersession-chain walk (Areev::supersession_chain) did not reach
a root within the bounded hop count. Real edit histories terminate in
a handful of hops; exceeding the bound means the supersedes links
are corrupt (e.g. cyclic) rather than merely long, so the walk fails
loudly instead of looping the process forever.
AnnIndexUnsupported(String)
An approximate-nearest-neighbour index was asked for on a backend that has none. Vector recall is an exact scan on the embedded engine — there is no ANN structure to build there, and silently doing nothing would leave a caller believing its corpus was indexed when its latency is still linear. Only the Postgres tier (pgvector HNSW) answers this.
CryptoError(String)
AttestationInvalid(String)
An attestation signed by a trusted author key does not verify over
the hash it names — the grain or the attestation was altered after
signing. Raised at bundle import (the whole bundle is refused) and by
verify --attestations.
AttestationRequired(String)
The import policy is require and a grain arrived with no valid
attestation from a trusted author.
SigningKeyInvalid(String)
A signing seed, public key, or trusted-authors document is malformed.
AccumulateRetryExhausted
AccumulateInternal(String)
AccumulateBackpressureRejected
Internal(String)
AuthzDenied(String)
A verb the session’s grants don’t cover (authz::AuthzSet::check).
AuthzUnknownPrincipal(String)
A principal name no credential authenticates.
AuthzConfigInvalid(String)
The credential map failed to load or validate (fail closed).
AuthzTokenUnrecognized
A presented bearer token matched no credential. Deliberately carries no payload: a refused secret must never reach a log line.
Implementations§
Source§impl AreevError
impl AreevError
Sourcepub fn code(&self) -> &'static str
pub fn code(&self) -> &'static str
Stable machine-readable error code in DOMAIN-Ennn form (see the
repo-root ERROR_CODES.md registry). Every Display string begins
with this code, so a user who reports the leading token points us at
the exact variant and subsystem. Codes are append-only debugging
handles — never renumber or reuse an existing one.
Trait Implementations§
Source§impl Debug for AreevError
impl Debug for AreevError
Source§impl Display for AreevError
impl Display for AreevError
Source§impl Error for AreevError
impl Error for AreevError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()