pub enum KeyCommandError {
NoProgram,
NotFound {
program: String,
},
Spawn {
program: String,
cause: Error,
},
Timeout {
program: String,
secs: u64,
},
Signal {
program: String,
},
Failed {
program: String,
code: i32,
},
NotUtf8 {
program: String,
},
Empty {
program: String,
},
Unusable {
program: String,
},
TooMuchOutput {
program: String,
limit: usize,
},
}Expand description
Why a configured api_key_command did not produce a usable credential.
Debug is derived, which is safe only because no variant carries captured
output. Adding one that did would put a credential into {:?}.
Variants§
NoProgram
Reachable only from a hand-built LlmConfig: config::load rejects
api_key_command = [] for an enabled entry. Checked anyway, because a
panic inside the commit gate is a worse failure than a message.
NotFound
Distinguished from Self::Spawn because the fix is different: this one
is a typo in argv[0] or a helper that is not installed, and reporting it
as “could not be started: No such file or directory” sends the reader
looking at file permissions instead.
Spawn
Timeout
Signal
A helper killed by a signal has no exit code, so it cannot be reported
through Self::Failed without inventing one.
Failed
The status and nothing else. See the module doc: captured output is where a credential would escape.
NotUtf8
Empty
An empty credential satisfies every “is a key present” check downstream
and then 401s, which reads as a rejected key rather than a helper that
printed nothing. AuthStore::set refuses an empty paste for the same
reason.
Unusable
The resolved value becomes an HTTP header, which cannot carry a control
character - so a helper that printed two lines, or a diagnostic banner
followed by the token, is a guaranteed transport failure. Caught here
rather than on the first file of the first push, exactly as
AuthStore::set catches it at the prompt.
TooMuchOutput
The helper printed more than any credential can be.
A ceiling rather than an unbounded read, for the reason crate::http’s
module doc gives: a bound is a safety property, and the failure it names
there is a second reader next to a bounded one that kept calling text()
with no ceiling at all. This is the third spawn site in the crate and the
first with a ceiling, so the doctrine is applied here rather than argued
about: an api_key_command pointed at the wrong program - cat on a large
file is one keystroke from cat on a token file - would otherwise allocate
whatever it printed inside the commit gate, then walk all of it twice to
trim it and scan it for control characters.
Reported rather than truncated. Truncating would hand the endpoint a prefix of something that was never a credential and turn a local misconfiguration into a 401 per file.
Trait Implementations§
Source§impl Debug for KeyCommandError
impl Debug for KeyCommandError
Source§impl Display for KeyCommandError
impl Display for KeyCommandError
Source§impl Error for KeyCommandError
impl Error for KeyCommandError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()