Skip to main content

Module error_codes

Module error_codes 

Source
Expand description

Canonical error codes emitted by subc.

Error frames remain extensible strings, but these daemon-owned route-open outcomes need identical spelling across the daemon and SDK retry policies.

Constants§

INVALID_REQUEST
A request field is malformed. The error’s detail.field names the field (for a route.open, role_versions). TERMINAL: the same request will be refused the same way every time, so only a corrected request can succeed.
MODULE_NO_PROTOCOL
The target module is declared as speaking no subc wire protocol (protocol: "none" in daemon config), so it has no control lane and can never accept a route. The daemon supervises its process and nothing else.
MODULE_RELOADING
The target module’s endpoint is draining for a reload, restart or disable.
MODULE_REMOVED
MODULE_TIMEOUT
MODULE_WARMING
OPERATOR_DECLINED
An operator.confirm was declined or withdrawn. detail.reason is person, backoff, route_closed, module_closed or caller_cancelled.
OPERATOR_PRESENCE_UNAVAILABLE
An operator.confirm could not prompt or complete. detail.reason is no_presence, timeout, module_limit, queue_full, queue_wait, provider_stuck, unsupported_platform or provider_error.
OPERATOR_REQUEST_NOT_PERMITTED
An operator.confirm is not from a nonce-proven module connection for an open route with a verified opener on that connection.
OPERATOR_SUMMARY_INVALID
The summary of an operator.confirm breaks the daemon’s summary rules.
SCOPE_ATTRIBUTES_TOO_LARGE
One record in a scope.sync or scope.apply carried more attribute bytes than a scope may hold. The whole call is refused and nothing changes.
SCOPE_ATTRIBUTE_NOT_PERMITTED
The record sets agent_id, delegates, flow_id or run_id and its owner is not listed in the daemon’s scope_authority_owners.
SCOPE_CARRIER_TARGETS_INVALID
A targeted carrier entry lists no target modules, or more than scope::MAX_CARRIER_TARGETS.
SCOPE_CHANGED
A scoped route.open was admitted, but the scope record changed before the module’s bind committed. Nothing was sent on the route, so the caller may re-open against the current record: RETRYABLE.
SCOPE_DELEGATES_WITHOUT_AGENT
The record sets delegates without an agent_id to delegate.
SCOPE_ENDED
A scoped route.open named a scope_epoch that is not the live one, or the scope ended between admission and commit. TERMINAL.
SCOPE_EPOCH_ENDED
The record names an (owner, ref, scope_epoch) that already ended in this daemon incarnation; an ended session cannot come back.
SCOPE_EPOCH_REGRESSED
The record lowers the scope_epoch the daemon holds for its ref.
SCOPE_EPOCH_REQUIRED
A scoped route.open named no scope_epoch. Every opener names one, the owner included, so an old call can never be carried into a newer session that reused the ref. TERMINAL.
SCOPE_EXPIRED
The record’s deadline has passed, or this ref at this epoch was ended by expiry and its tombstone is still held. The same session epoch cannot return.
SCOPE_EXPIRY_IMMUTABLE
The record adds, removes or changes the deadline of a live scope at the same epoch. A different deadline requires a new session epoch.
SCOPE_EXPIRY_TOO_FAR
The record’s deadline is more than scope::MAX_SCOPE_EXPIRY_AHEAD_MS ahead of the daemon’s current Unix wall clock.
SCOPE_KIND_CHANGED
The record changes kind at the same scope_epoch.
SCOPE_LIVE_LIMIT_EXCEEDED
scope.sync or scope.apply exceeds the owner’s live-scope limit. The whole call is refused and nothing changes.
SCOPE_NOT_CARRIER
The opener of a scoped route.open is neither the scope’s owner nor a listed carrier, or it is a targeted carrier and the target module is not in its list. TERMINAL.
SCOPE_NOT_LIVE
A scoped route.open named a ref the owner’s synced set does not hold, or an owner that is not a configured module. TERMINAL.
SCOPE_NOT_SYNCED
A route.open named a scope whose owner is configured but has not synced since this daemon incarnation started. RETRYABLE: after a daemon restart a carrier’s open can arrive before the owner re-syncs, and the carrier waits within its own deadline. See docs/designs/daemon-scopes.md.
SCOPE_PARENT_NOT_PERMITTED
The record’s parent link is not permitted: the parent’s owner has synced and the parent is not live at the named epoch, the syncing owner is neither the parent’s owner nor in its child_owners, or the link would close a cycle.
SCOPE_RUN_ID_DELEGATES
The record sets run_id with delegates; an agent-run scope cannot delegate the agent’s authority.
SCOPE_RUN_ID_WITHOUT_AGENT
The record sets run_id without agent_id, the agent this run is on behalf of.
SCOPE_RUN_ID_WITH_FLOW_ID
The record sets both run_id and flow_id; a run scope is not a flow scope.
SCOPE_SYNC_NOT_AUTHORITY
scope.sync or scope.apply came from a connection that is not the owner’s sync authority: another connection of the same launch holds it, or this connection’s launch is no longer the owner’s current one (a blue/green swap candidate before cutover, or an incumbent after it).
SCOPE_SYNC_REQUIRED
scope.apply came from a connection that has not taken sync authority through an accepted full scope.sync. The whole call changes nothing.
SCOPE_SYNC_STALE
scope.sync or scope.apply carried a generation no larger than the last one the authority accepted. The whole call is refused and nothing changes.
SCOPE_UNSUPPORTED
Raised by a carrier, never by the daemon: the daemon does not advertise scopes/v1, so the carrier fails the call instead of opening an unscoped route.
STALE_ROUTE_EPOCH
TARGET_AGENT_RUN_UNSUPPORTED
An agent-run-scoped route targets a module that does not provide agent-run-scopes/v1. TERMINAL: removing run_id would silently change the identity under which the route acts.
TARGET_FLOW_UNSUPPORTED
A flow-scoped route targets a module that does not provide flow-scopes/v1. TERMINAL: decoding flow_id alone does not promise flow behaviour, and removing it would silently change the identity.
TARGET_UNAVAILABLE
UNKNOWN_CHANNEL
UNKNOWN_MODULE

Functions§

is_established_route_dead
Whether the caller should evict this established route, reopen it, and resend the request once. Consumers mapping route death to their own custody, provider, or suspect verdict keep their own named code lists; sharing this predicate for those meanings can change a verdict on a protocol bump (prefrontal#59).
is_retryable_route_open
Whether a route.open refusal carrying code may be retried in place within the caller’s deadline, or is terminal for the target as named.