Skip to main content

ProvisionError

Enum ProvisionError 

Source
#[non_exhaustive]
pub enum ProvisionError {
Show 14 variants
#[non_exhaustive]
DestUnusable { path: PathBuf, },
#[non_exhaustive]
Io { op: &'static str, path: PathBuf, source: Error, },
#[non_exhaustive]
Archive { offset: u64, reason: String, },
#[non_exhaustive]
EntryUnsafe { path: PathBuf, reason: String, },
#[non_exhaustive]
EntryRefused { path: PathBuf, reason: String, },
#[non_exhaustive]
EntryUnsupported { path: PathBuf, kind: u8, },
#[non_exhaustive]
FormatUnrecognized { path: PathBuf, }, Cancelled,
#[non_exhaustive]
Other { source: Box<dyn Error + Send + Sync>, },
#[non_exhaustive]
RemoveUnprivileged { path: PathBuf, source: Error, reason: String, },
#[non_exhaustive]
ExportUnprivileged { path: PathBuf, reason: String, },
#[non_exhaustive]
ExportDestInside { path: PathBuf, rootfs: PathBuf, },
#[non_exhaustive]
CopyUnprivileged { path: PathBuf, reason: String, },
#[non_exhaustive]
SourceChanged { path: PathBuf, recorded: u64, },
}
Expand description

An error from provisioning a rootfs.

Provisioning is a separate act from launching a sandbox, and carries its own error type; it never appears inside Error.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

#[non_exhaustive]
DestUnusable

The destination path cannot host a rootfs directory.

The path has no final component, or something that is not a directory already exists there.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The destination as it was given.

§

#[non_exhaustive]
Io

A host I/O operation failed.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§op: &'static str

What the operation was doing.

§path: PathBuf

The path the operation concerned.

§source: Error

The underlying I/O error.

§

#[non_exhaustive]
Archive

The archive is malformed or truncated.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§offset: u64

The archive offset of the offending block, in bytes of the uncompressed stream.

§reason: String

What was wrong.

§

#[non_exhaustive]
EntryUnsafe

An archive entry attempted to reach outside the extraction root.

The entry’s path or link target is absolute, contains .., carries a NUL byte that would truncate it, or resolves through a symlink to a location outside the rootfs being extracted. Containment is enforced by the kernel during path resolution, not by inspecting the path text.

This variant asserts a containment failure and nothing else. An entry refused for any other reason is EntryRefused.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The entry’s path as recorded in the archive.

§reason: String

What was unsafe about it.

§

#[non_exhaustive]
EntryRefused

An entry cannot be handled as it stands, for a reason that is not a containment failure.

A malformed archive — a path component that is not a directory, an empty symlink target — a source tree past a limit the copy protocol can carry (its depth, an entry name, a link target), or a source id the destination’s identity map has no place for.

Distinct from EntryUnsafe, which means an entry tried to reach outside the tree it was being written into. Nothing here did.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The entry’s path: as recorded in the archive, or as it sits in the source tree.

§reason: String

Why it was refused.

§

#[non_exhaustive]
EntryUnsupported

An archive entry has a type the extractor does not support.

Sparse and multi-volume entries are not supported. (Character and block devices and GNU volume labels are not errors; they are skipped, as documented on the Tarball provisioner.)

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The entry’s path as recorded in the archive.

§kind: u8

The entry’s tar typeflag byte.

§

#[non_exhaustive]
FormatUnrecognized

The file is neither a recognized compression format nor a tar archive.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The file as it was given.

§

Cancelled

The run was cancelled through the observer.

Reported by a provisioner whose ProvisionRequest::cancelled check answered true. ensure removes the staging tree, so the destination is left absent, as it is for any other failed run.

§

#[non_exhaustive]
Other

A failure from a provisioner outside this crate.

The stable channel through which a provisioner implemented elsewhere reports its own error type; build one with ProvisionError::other.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§source: Box<dyn Error + Send + Sync>

The provisioner’s own error.

§

#[non_exhaustive]
RemoveUnprivileged

A tree could not be removed: it holds files owned through an identity map, and no delegate can establish that map to act on them.

A range-mapped sandbox writes real ownership, so its rootfs can hold files the plain calling user cannot delete. remove escalates by re-entering the same map; this error is the escalation finding no delegate, with the reason naming what the host is missing.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The tree that could not be removed.

§source: Error

The removal failure that triggered the escalation.

§reason: String

Why no delegate could establish the identity map.

§

#[non_exhaustive]
ExportUnprivileged

A tree could not be exported: it holds files owned through a range identity map, and no delegate can establish that map to read them at their intended ownership.

export_tar re-enters the map the tree was built under so a file the rootfs means as a system id is read as that id, not the host subordinate id it is stored as. This error is that re-entry finding no delegate for a range map, with the reason naming what the host is missing.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The tree that could not be exported.

§reason: String

Why no delegate could establish the identity map.

§

#[non_exhaustive]
ExportDestInside

An export’s destination file lies inside the tree being exported.

The archive would be a member of its own source: the walk reaches the file it is being written to, and what lands in the archive depends on how far the encoder had got when the walk arrived there. Reported by Export::write_to_path, which names the destination and so can see it; Export::write_to takes a sink it cannot locate, and a caller that opens a file inside the tree itself gets the archive it asked for.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The destination as it was given.

§rootfs: PathBuf

The tree it lies inside.

§

#[non_exhaustive]
CopyUnprivileged

A copy into a rootfs owned through a range map could not establish that map.

Creating an entry owned by a mapped id needs a process inside the map, and no delegate could establish one. It is the mirror of ExportUnprivileged, which arises for the same reason.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The rootfs that could not be copied into.

§reason: String

Why no delegate could establish the identity map.

§

#[non_exhaustive]
SourceChanged

A source file changed size while a CopyIn was reading it, so the copy could not reproduce it.

The copy commits a file’s length before it reads the contents, and the in-map writer reads exactly that many bytes. A file that grew or shrank in between is therefore written truncated or zero-padded, and the run reports this rather than presenting the result as a copy: a source tree changing underneath a copy is something the caller would rather hear about than discover in the rootfs later.

Fields

This variant is marked as non-exhaustive
Non-exhaustive enum variants could have additional fields added in future. Therefore, non-exhaustive enum variants cannot be constructed in external crates and cannot be matched against.
§path: PathBuf

The source file that changed.

§recorded: u64

The length the copy recorded and wrote.

Implementations§

Source§

impl ProvisionError

Source

pub fn other(source: impl Into<Box<dyn Error + Send + Sync>>) -> ProvisionError

Wraps a provisioner’s own error.

The channel for a Provisioner implemented outside this crate: its error type travels intact and is reachable through source, so a consumer can downcast to it.

§Example
use ferroday_cage::provision::ProvisionError;

let err = ProvisionError::other("the mirror rejected the request");
assert!(err.to_string().contains("the mirror rejected the request"));
Source§

impl ProvisionError

Source

pub fn io( op: &'static str, path: impl Into<PathBuf>, source: Error, ) -> ProvisionError

A host I/O failure, naming what the operation was doing and the path it concerned.

Arguments run operation, then locator, then cause, which is the order every constructor in the crate takes them in.

Source

pub fn at( op: &'static str, path: impl Into<PathBuf>, ) -> impl FnOnce(Error) -> ProvisionError

The same failure as a map_err argument: names the operation and the path now, and takes the cause when it arrives.

use std::fs;

use ferroday_cage::provision::ProvisionError;

fs::read(path).map_err(ProvisionError::at("reading", path))

Trait Implementations§

Source§

impl Debug for ProvisionError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for ProvisionError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Error for ProvisionError

Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl From<GentooError> for ProvisionError

Source§

fn from(err: GentooError) -> ProvisionError

A cancellation is the run’s own outcome rather than a layer failure, so it surfaces as the shared variant a caller matches on whichever provisioner they drove; everything else is this layer’s.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AsErrorSource for T
where T: Error + 'static,

Source§

fn as_error_source(&self) -> &(dyn Error + 'static)

For maximum effectiveness, this needs to be called as a method to benefit from Rust’s automatic dereferencing of method receivers.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> FmtForward for T

Source§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
Source§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
Source§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
Source§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
Source§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
Source§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
Source§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
Source§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
Source§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V