pub enum NodeFailureCode {
Show 95 variants
InvalidRequest,
UnsupportedCapability,
SpawnProfileRevisionMismatch,
HarnessMcpUnavailable,
ReservationNotFound,
ReservationConflict,
ReservationExpired,
BindingMismatch,
NotActivated,
CallNotFound,
ChunkOutOfOrder,
ResponseTooLarge,
DeliveryManifestInvalid,
UnknownDeliveryStage,
DeliveryStageConflict,
DeliveryBlobUnexpected,
DeliveryChunkOutOfOrder,
DeliveryBlobDigestMismatch,
DeliveryBundleDigestMismatch,
DeliveryStageIncomplete,
DeliveryStageStorageFailed,
Unauthorized,
ObserverReadOnly,
ControllerBusy,
ControllerRequired,
UnknownWorkspace,
HostDirectoryInvalid,
HostDirectoryReadFailed,
HostDirectoryReadTimedOut,
InvalidRepositoryPath,
RepositoryFileNotFound,
RepositoryFileNotRegular,
RepositoryPathUnsafe,
RepositoryFileReadTimedOut,
RepositoryFileReadFailed,
RepositoryFileWriteTimedOut,
RepositoryFileWriteFailed,
RepositoryFileRevisionConflict,
RepositoryEntryAlreadyExists,
RepositoryParentNotFound,
RepositoryParentNotDirectory,
RepositoryEntryCreateTimedOut,
RepositoryEntryCreateFailed,
GitReadTimedOut,
GitReadFailed,
InvalidWorkspaceRoot,
DuplicateWorkspaceId,
DuplicateWorkspaceRoot,
WorkspaceBusy,
LastWorkspace,
NotGitRepository,
WorktreeConflict,
WorktreeProtected,
WorktreeDirty,
WorktreeLocked,
UnknownManagedWorktreeLease,
ManagedWorktreeBusy,
ManagedWorktreeOwnershipConflict,
ManagedWorktreeProfileRevisionMismatch,
ManagedWorktreeRecoveryRequired,
StandaloneWorkspaceRecoveryRequired,
UnknownSpawnProfile,
UnknownBundle,
UnknownContextPack,
ContextPackBusy,
ContextPackMaterializationFailed,
UnknownEnvironmentProfile,
UnknownNetworkAllowlist,
UnsupportedNetworkAllowlistMapping,
BrowserStationProbeUnavailable,
BrowserStationUnreachable,
BrowserStationProfileBusy,
BundleBindingMismatch,
EnvironmentProfileBindingMismatch,
BundleMaterializationFailed,
SpawnTargetMismatch,
SpawnIdempotencyConflict,
SpawnIdempotencyCapacity,
SpawnDeadlineExceeded,
UnsupportedSpawnCapability,
UnsupportedTransport,
TurnInFlight,
UnknownSession,
UnknownSessionRecord,
SessionRecordNotResumable,
SessionRecordBusy,
SessionRecordConflict,
SessionWorkspaceMismatch,
WorkspaceRegistrationRequired,
StaleNativeSessionCatalog,
StaleGeneration,
BackendBusy,
BackendDisconnected,
BackendOperationFailed,
ShuttingDown,
}Variants§
InvalidRequest
UnsupportedCapability
SpawnProfileRevisionMismatch
ReservationNotFound
ReservationConflict
ReservationExpired
BindingMismatch
NotActivated
CallNotFound
ChunkOutOfOrder
ResponseTooLarge
DeliveryManifestInvalid
UnknownDeliveryStage
DeliveryStageConflict
DeliveryBlobUnexpected
DeliveryChunkOutOfOrder
DeliveryBlobDigestMismatch
DeliveryBundleDigestMismatch
DeliveryStageIncomplete
DeliveryStageStorageFailed
ObserverReadOnly
ControllerBusy
ControllerRequired
UnknownWorkspace
HostDirectoryInvalid
HostDirectoryReadFailed
HostDirectoryReadTimedOut
InvalidRepositoryPath
RepositoryFileNotFound
RepositoryFileNotRegular
RepositoryPathUnsafe
RepositoryFileReadTimedOut
RepositoryFileReadFailed
RepositoryFileWriteTimedOut
RepositoryFileWriteFailed
RepositoryFileRevisionConflict
RepositoryEntryAlreadyExists
RepositoryParentNotFound
RepositoryParentNotDirectory
RepositoryEntryCreateTimedOut
RepositoryEntryCreateFailed
GitReadTimedOut
GitReadFailed
InvalidWorkspaceRoot
DuplicateWorkspaceId
DuplicateWorkspaceRoot
WorkspaceBusy
LastWorkspace
NotGitRepository
WorktreeConflict
WorktreeProtected
WorktreeDirty
WorktreeLocked
UnknownManagedWorktreeLease
ManagedWorktreeBusy
ManagedWorktreeOwnershipConflict
ManagedWorktreeProfileRevisionMismatch
ManagedWorktreeRecoveryRequired
StandaloneWorkspaceRecoveryRequired
UnknownSpawnProfile
UnknownBundle
UnknownContextPack
ContextPackBusy
ContextPackMaterializationFailed
UnknownEnvironmentProfile
UnknownNetworkAllowlist
Station network allowlist policy id is not registered in this node’s
empty-default catalog (NodeShared::network_allowlist_catalog).
Plan station-network-and-browser-profile-knobs-2026-10-02.md §2.1 /
§4 — refuse unknown ids rather than silent ambient. Opaque id only;
never credentials on C2.
UnsupportedNetworkAllowlistMapping
Catalog entry carries a provider-native network mapping this spawn’s
provider cannot honor (e.g. codex_network_access for Claude / Kimi).
Plan dig2browser-station-probe-and-network-permit-set-2026-10-02.md
Track B — refuse rather than silent ambient. Never secrets on C2.
browser_profile_id set while feature dig2-station-probe is on, but
the cheap station probe cannot run on this platform (dig2browser
named-pipe IPC is Windows-first; no unix socket path yet) or the
configured pipe suffix is invalid. Plan
dig2browser-station-probe-and-network-permit-set-2026-10-02.md Track A.
Never cookies / OAuth on C2.
BrowserStationUnreachable
browser_profile_id set, probe feature on, and the local
dig2browser-station named-pipe path is missing or not connectable.
Path reachability only — no session import / cookie frames.
BrowserStationProfileBusy
Feature dig2-station-probe: another live session already holds an
exclusive node-local lease on this opaque browser_profile_id.
Never cookies / ImportSession on C2 — lease is node bookkeeping only.
Sketch: dig2-station-bind-lease-sketch-2026-10-02.md.
BundleBindingMismatch
EnvironmentProfileBindingMismatch
BundleMaterializationFailed
SpawnTargetMismatch
SpawnIdempotencyConflict
SpawnIdempotencyCapacity
SpawnDeadlineExceeded
UnsupportedSpawnCapability
UnsupportedTransport
The requested provider does not declare the requested transport
(the kernel’s own UnsupportedTransport rejection, named rather
than folded into BackendOperationFailed/UnsupportedCapability so
a caller several layers up can carry the same “provider + transport”
specificity all the way to the operator instead of collapsing it
into a generic backend failure or – if the underlying rejection
arrives asynchronously and is caught only by a blind commit-deadline
poll – a SpawnDeadlineExceeded that names neither).
TurnInFlight
The addressed session already has a provider turn in flight –
TurnStarted observed with no matching TurnCompleted yet – and a
Prompt/Paste against it was refused by name rather than handed to
the agent. Applies to the two transports that admit exactly one turn
at a time (ACP, and Pipe/inline): what a provider does with an
overlapping second prompt is vendor-specific and unobservable here
(queue it, drop it, interleave it into the running turn), so the node
authors its own refusal instead of gambling on that behaviour. PTY
sessions never produce this code – they are still gated by
ProviderRuntimePolicy’s PTY-terminal-text-inference flags, which
answer UnsupportedCapability instead.