Skip to main content

Error

Enum Error 

Source
pub enum Error {
    NotFound,
    CorruptedWrapper,
    MultipleWrappers,
    PayloadTooLarge(usize),
    UnrepresentableGap(usize),
    MalformedExclusion,
    HashMismatch,
    UnsupportedAlgorithm(String),
}
Expand description

Errors from locating a wrapper or validating an unstructured-text hard binding.

§Two wrapper outcomes are reportable failures

The specification defines two failure codes for wrapper location:

  • manifest.text.corruptedWrapper — a magic number was detected but the wrapper was malformed or incomplete. A candidate that does not decode is not silently ignored; it is reported.
  • manifest.text.multipleWrappers — more than one valid wrapper was found.

Only Error::NotFound means the text carries no provenance at all, and only it carries no status code. Error::is_no_manifest_located draws that line for a caller surfacing provenance state to a user: “unsigned” versus “carried provenance that was rejected”.

§A known tension in the specification

Placement rule 5 says a validator “may encounter multiple wrappers” and that “selection of the intended wrapper is governed by the exclusions field of the c2pa.hash.data assertion”, which reads as though multiple wrappers are recoverable. The Validation Status Codes section says more than one valid wrapper is a manifest.text.multipleWrappers failure. These cannot both be followed.

This crate follows the explicit failure code, because that is the normative statement a validator is judged against, and because text that accreted a second wrapper has also changed the bytes the hard binding covers — so the “recoverable” reading would let a hash pass over text the claim never described.

Variants§

§

NotFound

No valid C2PATextManifestWrapper was located and no candidate was detected either: the text simply carries no wrapper.

§

CorruptedWrapper

One or more candidates were detected (a U+FEFF followed by a variation-selector run whose leading bytes match the magic) but none fully decoded.

Reported as manifest.text.corruptedWrapper: the magic number was detected but the wrapper was malformed or incomplete. This is also the fail-safe outcome — the codec rejected a mangled carrier rather than decoding it to wrong bytes.

§

MultipleWrappers

More than one valid wrapper was located.

Reported as manifest.text.multipleWrappers. Not a disambiguation opportunity: text that accreted a second wrapper has also changed the bytes covered by the hard binding.

§

PayloadTooLarge(usize)

The payload exceeds the u32 manifestLength field of the wrapper frame.

§

UnrepresentableGap(usize)

A padding gap that is not expressible as 3a + 4b, i.e. 1, 2 or 5. The margin of 6 in the deterministic target keeps real wrappers clear of these, so this indicates a hand-built target length.

§

MalformedExclusion

The exclusion ranges are malformed: out of order, overlapping, extending past the end of the asset, splitting a UTF-8 sequence, or not matching the byte range of the located wrapper.

§

HashMismatch

The recomputed data hash did not match the value in the assertion.

§

UnsupportedAlgorithm(String)

A hash algorithm identifier outside the C2PA allowed list was requested.

Implementations§

Source§

impl Error

Source

pub fn code(&self) -> Option<&'static str>

The registered C2PA validation status code for this error, or None when the condition carries no status code.

Source

pub fn is_no_manifest_located(&self) -> bool

Whether this error means the asset carries no provenance at all, as opposed to provenance that was found and rejected. Callers that surface provenance state to a user need this distinction: the former is “unsigned”, the latter is “invalid”.

Only Error::NotFound qualifies. A corrupted or duplicated wrapper is a reportable failure, not an absence.

Trait Implementations§

Source§

impl Clone for Error

Source§

fn clone(&self) -> Error

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Error

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for Error

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Error

Source§

impl Error for Error

1.30.0 · Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl PartialEq for Error

Source§

fn eq(&self, other: &Error) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Error

Auto Trait Implementations§

§

impl Freeze for Error

§

impl RefUnwindSafe for Error

§

impl Send for Error

§

impl Sync for Error

§

impl Unpin for Error

§

impl UnsafeUnpin for Error

§

impl UnwindSafe for Error

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.