#[non_exhaustive]pub enum Error {
Show 42 variants
UnexpectedEof,
BufferTooSmall,
TrailingData,
NameTooLong,
LabelTooLong,
EmptyLabel,
BadLabelType,
BadPointer,
TooManyPointers,
UnexpectedPointer,
InvalidRdata,
WrongType,
UnsupportedAlgorithm,
InvalidKey,
BadSignature,
SignatureExpired,
SignatureNotYetValid,
KeyMismatch,
RrsetMismatch,
InvalidText,
UnknownMnemonic,
CharStringTooLong,
NoTextFormat,
MissingTtl,
BadInclude,
SectionOrder,
CountOverflow,
MessageTooLong,
InvalidOption,
DuplicateOpt,
OptNotRoot,
MisplacedSignature,
BadMacSize,
BadKey,
BadTime,
BadTrunc,
Unsigned,
TsigErrorResponse,
InvalidUpdate,
InvalidXfr,
ErrorResponse,
InvalidDso,
}Expand description
Errors produced while parsing or building DNS messages.
dnsbox has one error type for everything that can fail — wire and
text parsing, building, DNSSEC, TSIG, SIG(0), UPDATE, XFR, DSO. It is a
one-byte, Copy, allocation-free enum, so returning it costs nothing
on the hot path and it works without alloc. The variants name what
was wrong rather than where: Invalid* for malformed input of some kind
(InvalidRdata, InvalidText,
InvalidOption, InvalidUpdate,
…), Bad* for failed checks (compression pointers, signatures, and the
TSIG error codes of RFC 8945), the rest for specific conditions.
Two error types add context and convert into Error with ?:
ZoneError (the position of a zone-file
error) and dnssec::ZonemdFailure (which RFC 8976 §4 check failed).
Outcomes that are answers rather than failures of the call — a DNSSEC
DenialStatus, a truncated
Outcome — are ordinary return values.
The enum is #[non_exhaustive]: new variants are added as new parts of
the protocol are implemented. Match on the variants you care about and
keep a wildcard arm.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
UnexpectedEof
The input ended before a complete structure could be read. Also returned when a section count in the header promises more entries than the message contains (RFC 1035 §4.1.1).
BufferTooSmall
The output buffer (or the configured size limit) is too small for the data being written.
TrailingData
Bytes were left over after a structure that must fill its container exactly (e.g. RDATA shorter than its RDLENGTH, RFC 1035 §3.2.1).
NameTooLong
A domain name exceeds 255 octets in wire form (RFC 1035 §2.3.4).
LabelTooLong
A label exceeds 63 octets (RFC 1035 §2.3.4).
EmptyLabel
A presentation-format name contains an empty label (a..b).
BadLabelType
A label uses a reserved or extended label type (0b01 / 0b10 top
bits), which is rejected (RFC 6891 §5, RFC 2673 is historic).
BadPointer
A compression pointer points forward, at itself, or into the name it is part of (RFC 1035 §4.1.4; rejected to guarantee termination).
TooManyPointers
A name follows more compression pointers than
MAX_POINTERS.
UnexpectedPointer
A compression pointer appeared where only uncompressed names are allowed (RFC 3597 §4, RFC 4034 §3.1.7).
InvalidRdata
RDATA is malformed for its record type (bad length, invalid field).
WrongType
A typed RDATA parse was requested for a record of another type.
UnsupportedAlgorithm
A DNSSEC algorithm or digest type is not supported by the crypto backend (RFC 4035 §5.2: unsupported algorithms leave data insecure).
InvalidKey
A DNSSEC public or private key is malformed for its algorithm (e.g. RFC 3110 §2, RFC 6605 §4, RFC 8080 §3).
BadSignature
A signature, digest or MAC does not verify: DNSSEC RRSIG or DS (RFC 4035 §5.3.3), TSIG (error BADSIG, RFC 8945 §5.2.2) or SIG(0) (RFC 2931 §3.1).
SignatureExpired
An RRSIG’s validity period has ended (RFC 4035 §5.3.1).
SignatureNotYetValid
An RRSIG’s validity period has not started yet (RFC 4035 §5.3.1).
KeyMismatch
An RRSIG does not match the DNSKEY it is checked against: signer name, algorithm, key tag, protocol or zone flag (RFC 4035 §5.3.1).
RrsetMismatch
An RRSIG does not cover the RRset it is checked against: type covered, labels, signer zone or record types (RFC 4035 §5.3.1).
InvalidText
Presentation-format text is malformed (bad escape, bad number, …).
UnknownMnemonic
A mnemonic (type, class, …) is not recognised.
CharStringTooLong
A character-string exceeds 255 octets (RFC 1035 §3.3).
NoTextFormat
The record type has no type-specific presentation format (or none
is implemented, or its format is not defined for the record’s
class): only the generic \# <length> <hex> form of RFC 3597 §5 is
accepted.
MissingTtl
A zone-file record has no TTL and none can be inferred: no $TTL
directive (RFC 2308 §4) and no earlier explicit TTL (RFC 1035 §5.1).
BadInclude
A zone-file $INCLUDE directive (RFC 1035 §5.1) could not be
processed: includes are unsupported here (no resolver, or no std),
the nesting or count limit was reached, or the file failed to load.
SectionOrder
A builder section was written out of order: question → answer → authority → additional (RFC 1035 §4.1).
CountOverflow
A section would hold more than 65535 entries.
MessageTooLong
A message exceeds 65535 octets, the most the TCP length prefix can describe (RFC 1035 §4.2.2).
InvalidOption
An EDNS(0) option is malformed: bad length or invalid field value (RFC 6891 §6.1.2 and the option’s own RFC).
DuplicateOpt
A message carries more than one OPT record (RFC 6891 §6.1.1).
OptNotRoot
An OPT record’s owner name is not the root (RFC 6891 §6.1.2).
MisplacedSignature
A TSIG or SIG(0) record is not the last record of the additional section, or appears more than once (RFC 8945 §5.1, RFC 2931 §3). Servers answer FORMERR.
BadMacSize
A TSIG MAC size is longer than the algorithm’s output or shorter than the truncation floor (RFC 8945 §5.2.2.1). Servers answer FORMERR.
BadKey
The TSIG key or algorithm is unknown (TSIG error BADKEY, RFC 8945 §5.2.1).
BadTime
The signature time is outside the allowed window (TSIG error BADTIME, RFC 8945 §5.2.3; SIG(0) validity period, RFC 2931 §3.1).
BadTrunc
A TSIG MAC is truncated below local policy (TSIG error BADTRUNC, RFC 8945 §5.2.4).
Unsigned
A message that must be signed carries no TSIG, or too many unsigned messages follow each other in a TSIG stream (RFC 8945 §5.3.1, §5.4).
TsigErrorResponse
The peer reported a TSIG error (BADKEY, BADSIG, …) in an unsigned response; it cannot be authenticated and must be discarded (RFC 8945 §5.3.2, §5.4.1).
InvalidUpdate
A dynamic-update prerequisite or update RR has an invalid class/type/TTL/RDATA combination (RFC 2136 §3.2.4, §3.4.1.3), or the zone section is malformed (RFC 2136 §3.1.1). Servers answer FORMERR.
InvalidXfr
A zone-transfer response stream violates RFC 5936 §2.2 / RFC 1995 §4 (bad SOA sequence, records after the end, question mismatch).
ErrorResponse
A response carries an error RCODE where success was required (e.g. a refused zone transfer, RFC 5936 §2.2.1).
InvalidDso
A DNS Stateful Operations message is malformed: non-zero section counts, bad TLV framing or placement (RFC 8490 §5.4, §7.3).
Trait Implementations§
impl Copy for Error
impl Eq for Error
Source§impl Error for Error
impl Error for Error
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Source§impl From<ZonemdFailure> for Error
Available on crate features alloc and dnssec-digest only.
impl From<ZonemdFailure> for Error
alloc and dnssec-digest only.Source§fn from(f: ZonemdFailure) -> Error
fn from(f: ZonemdFailure) -> Error
The closest Error: the collation error for
Malformed,
BadSignature for a digest mismatch,
UnsupportedAlgorithm for an
unsupported scheme or hash algorithm, and
InvalidRdata otherwise.