1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
//! Typed error surface for pre-canonicalisation argument validation failures.
//!
//! [`ToolsetArgsError`] is the closed-set of all distinct refusal reasons returned
//! by [`crate::validate_toolset_tool_args`]. This is a SEPARATE error type from
//! [`crate::ToolsetFormatError`], which is the TOOLSET.md-parse error enum.
//!
//! The distinction matters: `ToolsetFormatError` covers static manifest format
//! violations detected at parse/install time; `ToolsetArgsError` covers runtime
//! argument-payload violations detected at dispatch time. They live on different
//! code paths, are returned to different callers, and carry different semantics.
//!
//! ## Redaction discipline
//!
//! No variant echoes any attacker-controlled input KEY (the input key string is
//! not included — only the matched `&'static str` denylist constant is referenced),
//! and no variant echoes any VALUE byte from the argument payload. This ensures
//! that a carefully-crafted argument payload containing secret-shaped content (e.g.
//! a key that looks like a mnemonic) can never leak through the error Display or
//! Debug output.
/// All distinct reasons [`crate::validate_toolset_tool_args`] can reject a payload.
///
/// The set is `#[non_exhaustive]` — the validator may grow new check classes in
/// future versions and callers should match with a `_ =>` fallback.
/// (Unlike [`crate::ToolsetFormatError`], which is exhaustive by design, this type
/// intentionally carries the `#[non_exhaustive]` attribute.)
///
/// # Redaction guarantee
///
/// No variant Display output ever contains:
/// - The inbound argument key string (even the rejected one).
/// - Any byte from any argument value.
///
/// Error messages reference only compile-time `&'static str` constants from the
/// denylist, ensuring that a crafted payload carrying secret-shaped values cannot
/// leak through Display.