#[non_exhaustive]pub enum Error {
Io(Error),
Escape(PathBuf),
Drifted(PathBuf),
InvalidJournalName(String),
InvalidJournalHome(PathBuf),
NonUtf8Path(PathBuf),
Corrupt(String),
Recovery(String),
StaleJournal(PathBuf),
Torn {
cause: String,
rollback: String,
},
}Expand description
Everything applying or recovering a ChangeSet can fail
with.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Io(Error)
The backend refused an operation. The staged set is unwound before this surfaces, so the tree is as it was.
Escape(PathBuf)
A staged path resolved outside the root it was applied against — either
absolute, or climbing past the root with ... Refused before anything is
written or journaled, because a set assembled from untrusted data must
not be able to reach out of the tree it was pointed at.
Drifted(PathBuf)
An expectation the set staged did not hold
when it was applied: the tree at this path is not what the caller read
when it computed the set — something else wrote in between. Refused
before the commit point, so nothing has been written, journaled, or
unwound; the caller re-reads, restages, and retries. This is drift
detection, not a lock — see change on the single
writer.
InvalidJournalName(String)
A Journal was asked for under a name that
is not a single path component. Refused at construction, because the
name is joined onto a caller-supplied root and one containing .. or a
separator would write outside the very tree an apply clamps into.
InvalidJournalHome(PathBuf)
A Journal was asked to live
(kept_in) in a directory that is
not absolute. Refused at construction: a relative home resolves against
the process’s current directory, which the apply that writes the
journal and the recovery that must find it have no reason to share —
and a journal sought where it was never written strands its change
half-applied.
NonUtf8Path(PathBuf)
A staged path could not be encoded into the journal because it is not UTF-8. The journal stores paths as UTF-8 so that a set written on one platform replays identically on another; a path that cannot round-trip is refused at the commit point rather than silently mangled.
Corrupt(String)
A journal was found that could not be trusted: a bad magic, a checksum mismatch, a truncated record, an unknown op tag. Refused rather than partially replayed — a journal exists to prevent invented states, so one that cannot be read is never guessed at.
Recovery(String)
A journal was read successfully but could not be replayed to completion:
a CopyFrom whose source has gone, or a
rename with neither side present. Distinct from
Corrupt — the intent was legible, the tree just
could not be brought to it. The journal is left in place so a later
recovery can finish once the missing piece is back.
StaleJournal(PathBuf)
A set was applied while a previous set’s journal was still on disk: an
earlier change was interrupted and never recovered. Landing this set
would overwrite the record needed to finish that one, so the apply
refuses. Call recover first, then retry.
Torn
The apply could not deliver either of its two durable answers. The classic case: a staged op failed and the rollback that should have undone it failed too. Two rarer ones share the shape — a rollback that completed but whose certification (or the journal’s retirement) could not be made durable, and a set that applied and certified cleanly but whose journal could not be removed. In every case the crate says exactly what it can and cannot promise, rather than reporting a clean endpoint it cannot stand behind.
The journal is left in place wherever possible, so the next
recover resolves the tree — rolling an uncertified
set forward to the applied state, or no-op replaying an applied one
and clearing the journal. Either way the tree lands somewhere
nameable.
Trait Implementations§
Source§impl Error for Error
impl Error for Error
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()