#[non_exhaustive]pub enum ProvisionError {
Show 14 variants
#[non_exhaustive] DestUnusable {
path: PathBuf,
},
#[non_exhaustive] Io {
op: &'static str,
path: PathBuf,
source: Error,
},
#[non_exhaustive] Archive {
offset: u64,
reason: String,
},
#[non_exhaustive] EntryUnsafe {
path: PathBuf,
reason: String,
},
#[non_exhaustive] EntryRefused {
path: PathBuf,
reason: String,
},
#[non_exhaustive] EntryUnsupported {
path: PathBuf,
kind: u8,
},
#[non_exhaustive] FormatUnrecognized {
path: PathBuf,
},
Cancelled,
#[non_exhaustive] Other {
source: Box<dyn Error + Send + Sync>,
},
#[non_exhaustive] RemoveUnprivileged {
path: PathBuf,
source: Error,
reason: String,
},
#[non_exhaustive] ExportUnprivileged {
path: PathBuf,
reason: String,
},
#[non_exhaustive] ExportDestInside {
path: PathBuf,
rootfs: PathBuf,
},
#[non_exhaustive] CopyUnprivileged {
path: PathBuf,
reason: String,
},
#[non_exhaustive] SourceChanged {
path: PathBuf,
recorded: u64,
},
}Expand description
An error from provisioning a rootfs.
Provisioning is a separate act from launching a sandbox, and carries its
own error type; it never appears inside Error.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
#[non_exhaustive]DestUnusable
The destination path cannot host a rootfs directory.
The path has no final component, or something that is not a directory already exists there.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]Io
A host I/O operation failed.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]Archive
The archive is malformed or truncated.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]EntryUnsafe
An archive entry attempted to reach outside the extraction root.
The entry’s path or link target is absolute, contains .., carries a
NUL byte that would truncate it, or resolves through a symlink to a
location outside the rootfs being extracted. Containment is enforced by
the kernel during path resolution, not by inspecting the path text.
This variant asserts a containment failure and nothing else. An entry
refused for any other reason is EntryRefused.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]EntryRefused
An entry cannot be handled as it stands, for a reason that is not a containment failure.
A malformed archive — a path component that is not a directory, an empty symlink target — a source tree past a limit the copy protocol can carry (its depth, an entry name, a link target), or a source id the destination’s identity map has no place for.
Distinct from EntryUnsafe, which means an entry
tried to reach outside the tree it was being written into. Nothing here
did.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]EntryUnsupported
An archive entry has a type the extractor does not support.
Sparse and multi-volume entries are not supported. (Character and
block devices and GNU volume labels are not errors; they are skipped,
as documented on the Tarball provisioner.)
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]FormatUnrecognized
The file is neither a recognized compression format nor a tar archive.
Fields
This variant is marked as non-exhaustive
Cancelled
The run was cancelled through the observer.
Reported by a provisioner whose ProvisionRequest::cancelled check
answered true. ensure removes the staging tree, so the
destination is left absent, as it is for any other failed run.
#[non_exhaustive]Other
A failure from a provisioner outside this crate.
The stable channel through which a provisioner implemented elsewhere
reports its own error type; build one with ProvisionError::other.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]RemoveUnprivileged
A tree could not be removed: it holds files owned through an identity map, and no delegate can establish that map to act on them.
A range-mapped sandbox writes real ownership, so its rootfs can hold
files the plain calling user cannot delete. remove escalates by
re-entering the same map; this error is the escalation finding no
delegate, with the reason naming what the host is missing.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]ExportUnprivileged
A tree could not be exported: it holds files owned through a range identity map, and no delegate can establish that map to read them at their intended ownership.
export_tar re-enters the map the tree was built under so a file the
rootfs means as a system id is read as that id, not the host
subordinate id it is stored as. This error is that re-entry finding no
delegate for a range map, with the reason naming what the host is
missing.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]ExportDestInside
An export’s destination file lies inside the tree being exported.
The archive would be a member of its own source: the walk reaches the
file it is being written to, and what lands in the archive depends on
how far the encoder had got when the walk arrived there. Reported by
Export::write_to_path, which names the destination and so can see
it; Export::write_to takes a sink it cannot locate, and a caller
that opens a file inside the tree itself gets the archive it asked for.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]CopyUnprivileged
A copy into a rootfs owned through a range map could not establish that map.
Creating an entry owned by a mapped id needs a process inside the map,
and no delegate could establish one.
It is the mirror of ExportUnprivileged,
which arises for the same reason.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]SourceChanged
A source file changed size while a CopyIn was reading it, so the
copy could not reproduce it.
The copy commits a file’s length before it reads the contents, and the in-map writer reads exactly that many bytes. A file that grew or shrank in between is therefore written truncated or zero-padded, and the run reports this rather than presenting the result as a copy: a source tree changing underneath a copy is something the caller would rather hear about than discover in the rootfs later.
Fields
This variant is marked as non-exhaustive
Implementations§
Source§impl ProvisionError
impl ProvisionError
Sourcepub fn other(source: impl Into<Box<dyn Error + Send + Sync>>) -> ProvisionError
pub fn other(source: impl Into<Box<dyn Error + Send + Sync>>) -> ProvisionError
Wraps a provisioner’s own error.
The channel for a Provisioner implemented outside this crate: its
error type travels intact and is reachable through
source, so a consumer can downcast to it.
§Example
use ferroday_cage::provision::ProvisionError;
let err = ProvisionError::other("the mirror rejected the request");
assert!(err.to_string().contains("the mirror rejected the request"));Source§impl ProvisionError
impl ProvisionError
Sourcepub fn io(
op: &'static str,
path: impl Into<PathBuf>,
source: Error,
) -> ProvisionError
pub fn io( op: &'static str, path: impl Into<PathBuf>, source: Error, ) -> ProvisionError
A host I/O failure, naming what the operation was doing and the path it concerned.
Arguments run operation, then locator, then cause, which is the order every constructor in the crate takes them in.
Sourcepub fn at(
op: &'static str,
path: impl Into<PathBuf>,
) -> impl FnOnce(Error) -> ProvisionError
pub fn at( op: &'static str, path: impl Into<PathBuf>, ) -> impl FnOnce(Error) -> ProvisionError
The same failure as a map_err argument:
names the operation and the path now, and takes the cause when
it arrives.
use std::fs;
use ferroday_cage::provision::ProvisionError;
fs::read(path).map_err(ProvisionError::at("reading", path))Trait Implementations§
Source§impl Debug for ProvisionError
impl Debug for ProvisionError
Source§impl Display for ProvisionError
impl Display for ProvisionError
Source§impl Error for ProvisionError
impl Error for ProvisionError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Source§impl From<GentooError> for ProvisionError
impl From<GentooError> for ProvisionError
Source§fn from(err: GentooError) -> ProvisionError
fn from(err: GentooError) -> ProvisionError
A cancellation is the run’s own outcome rather than a layer failure, so it surfaces as the shared variant a caller matches on whichever provisioner they drove; everything else is this layer’s.
Auto Trait Implementations§
impl !RefUnwindSafe for ProvisionError
impl !UnwindSafe for ProvisionError
impl Freeze for ProvisionError
impl Send for ProvisionError
impl Sync for ProvisionError
impl Unpin for ProvisionError
impl UnsafeUnpin for ProvisionError
Blanket Implementations§
Source§impl<T> AsErrorSource for Twhere
T: Error + 'static,
impl<T> AsErrorSource for Twhere
T: Error + 'static,
Source§fn as_error_source(&self) -> &(dyn Error + 'static)
fn as_error_source(&self) -> &(dyn Error + 'static)
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.