pub enum Error {
NotFound,
CorruptedWrapper,
MultipleWrappers,
PayloadTooLarge(usize),
UnrepresentableGap(usize),
MalformedExclusion,
HashMismatch,
UnsupportedAlgorithm(String),
}Expand description
Errors from locating a wrapper or validating an unstructured-text hard binding.
§Two wrapper outcomes are reportable failures
The specification defines two failure codes for wrapper location:
manifest.text.corruptedWrapper— a magic number was detected but the wrapper was malformed or incomplete. A candidate that does not decode is not silently ignored; it is reported.manifest.text.multipleWrappers— more than one valid wrapper was found.
Only Error::NotFound means the text carries no provenance at all, and
only it carries no status code. Error::is_no_manifest_located draws that
line for a caller surfacing provenance state to a user: “unsigned” versus
“carried provenance that was rejected”.
§A known tension in the specification
Placement rule 5 says a validator “may encounter multiple wrappers” and that
“selection of the intended wrapper is governed by the exclusions field of
the c2pa.hash.data assertion”, which reads as though multiple wrappers are
recoverable. The Validation Status Codes section says more than one valid
wrapper is a manifest.text.multipleWrappers failure. These cannot both be
followed.
This crate follows the explicit failure code, because that is the normative statement a validator is judged against, and because text that accreted a second wrapper has also changed the bytes the hard binding covers — so the “recoverable” reading would let a hash pass over text the claim never described.
Variants§
NotFound
No valid C2PATextManifestWrapper was located and no candidate was
detected either: the text simply carries no wrapper.
CorruptedWrapper
One or more candidates were detected (a U+FEFF followed by a
variation-selector run whose leading bytes match the magic) but none
fully decoded.
Reported as manifest.text.corruptedWrapper: the magic number was
detected but the wrapper was malformed or incomplete. This is also the
fail-safe outcome — the codec rejected a mangled carrier rather than
decoding it to wrong bytes.
MultipleWrappers
More than one valid wrapper was located.
Reported as manifest.text.multipleWrappers. Not a disambiguation
opportunity: text that accreted a second wrapper has also changed the
bytes covered by the hard binding.
PayloadTooLarge(usize)
The payload exceeds the u32 manifestLength field of the wrapper frame.
UnrepresentableGap(usize)
A padding gap that is not expressible as 3a + 4b, i.e. 1, 2 or 5. The
margin of 6 in the deterministic target keeps real wrappers clear of
these, so this indicates a hand-built target length.
MalformedExclusion
The exclusion ranges are malformed: out of order, overlapping, extending past the end of the asset, splitting a UTF-8 sequence, or not matching the byte range of the located wrapper.
HashMismatch
The recomputed data hash did not match the value in the assertion.
UnsupportedAlgorithm(String)
A hash algorithm identifier outside the C2PA allowed list was requested.
Implementations§
Source§impl Error
impl Error
Sourcepub fn code(&self) -> Option<&'static str>
pub fn code(&self) -> Option<&'static str>
The registered C2PA validation status code for this error, or None when
the condition carries no status code.
Sourcepub fn is_no_manifest_located(&self) -> bool
pub fn is_no_manifest_located(&self) -> bool
Whether this error means the asset carries no provenance at all, as opposed to provenance that was found and rejected. Callers that surface provenance state to a user need this distinction: the former is “unsigned”, the latter is “invalid”.
Only Error::NotFound qualifies. A corrupted or duplicated wrapper is
a reportable failure, not an absence.
Trait Implementations§
impl Eq for Error
Source§impl Error for Error
impl Error for Error
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()