#[non_exhaustive]pub enum ErrorKind {
InvalidLength,
InvalidParameter,
AuthenticationFailed,
Unsupported,
NotApprovedInFipsMode,
SelfTestFailed,
ModuleErrorState,
EntropyFailure,
CounterExhausted,
MalformedEncoding,
Internal,
}Expand description
Machine-actionable classification of a failure.
The discriminants are stable and are mirrored verbatim into the ontology
(ic-ontology::error_catalog) so an agent can reason about recovery
strategy without parsing English prose.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
InvalidLength
A buffer was too short or too long for the algorithm’s contract.
InvalidParameter
A key, nonce, or parameter was structurally unacceptable.
AuthenticationFailed
Authentication (MAC / AEAD tag / signature) failed to verify.
Unsupported
The requested algorithm exists but is not implemented in this build.
NotApprovedInFipsMode
The operation is not permitted while the module is in FIPS approved mode.
SelfTestFailed
A FIPS 140-3 self-test failed; the module has entered the error state.
ModuleErrorState
The module is in a hard error state and refuses all cryptographic service.
EntropyFailure
The entropy source failed or did not pass its health tests.
CounterExhausted
A counter (DRBG reseed, GCM invocation, sequence number) was exhausted.
MalformedEncoding
Input could not be decoded (hex, base64, DER, point encoding).
Internal
An internal invariant was violated — always a library bug.
Implementations§
Source§impl ErrorKind
impl ErrorKind
Sourcepub const ALL: &'static [ErrorKind]
pub const ALL: &'static [ErrorKind]
Every kind, for callers that enumerate them.
This type is #[non_exhaustive], so no other crate can match on it
exhaustively and none can tell whether it has seen them all. That is
deliberate — it lets a variant be added without breaking callers — but
it also means a list like the ontology’s error catalog cannot check its
own completeness. This crate can, so the list is published from here and
a test keeps it honest.
Sourcepub const fn id(self) -> &'static str
pub const fn id(self) -> &'static str
Stable kebab-case identifier used in ontology exports and CLI/MCP output.
Sourcepub const fn retryable(self) -> bool
pub const fn retryable(self) -> bool
Whether retrying the identical call could plausibly succeed.
Agents use this to decide between retry, re-parameterize, and abort.
Sourcepub const fn caller_correctable(self) -> bool
pub const fn caller_correctable(self) -> bool
Whether the caller should change inputs and try again.