Skip to main content

ic_memory/runtime/
error.rs

1use crate::{
2    LedgerCommitError, PolicyIdentity, PolicyIdentityError, StableCellLedgerError,
3    registry::StaticMemoryDeclarationError, slot::MemoryManagerRangeAuthorityError,
4};
5
6///
7/// RuntimeGrowError
8///
9/// Failure to grow a runtime memory before assigning new manager buckets.
10/// Ordinary capacity failures preserve virtual extents and manager metadata.
11/// Backing traps and partial writes remain outside this guarantee.
12///
13
14#[non_exhaustive]
15#[derive(Clone, Copy, Debug, Eq, thiserror::Error, PartialEq)]
16pub enum RuntimeGrowError {
17    /// The requested virtual extent overflows the page count.
18    #[error("virtual memory page count overflows")]
19    ArithmeticOverflow,
20    /// The sole manager has insufficient bucket slots.
21    #[error("growth requires {required_buckets} buckets, exceeding capacity {capacity}")]
22    BucketExhausted {
23        required_buckets: u64,
24        capacity: u16,
25    },
26    /// The backing memory refused the physical capacity reservation.
27    #[error("backing memory refused growth by {additional_pages} pages")]
28    BackingRefused { additional_pages: u64 },
29    /// Growth re-entered while another handle held a capacity reservation.
30    #[error("runtime memory growth is already in progress")]
31    ReentrantAccess,
32    /// The manager refused growth despite the runtime's successful preflight.
33    #[error("memory manager refused preflighted growth")]
34    ManagerRefused,
35}
36
37///
38/// RuntimeConstructionError
39///
40/// Failure to construct a memory runtime without overwriting unrecognized
41/// backing memory.
42///
43
44#[non_exhaustive]
45#[derive(Clone, Copy, Debug, Eq, thiserror::Error, PartialEq)]
46pub enum RuntimeConstructionError {
47    /// Fresh manager metadata could not reserve physical capacity.
48    #[error(transparent)]
49    Growth(#[from] RuntimeGrowError),
50    /// Zero pages cannot form a bucket.
51    #[error("bucket size must be nonzero")]
52    InvalidBucketSize,
53    /// Explicit policy differs from the actual durable setting.
54    #[error("persisted bucket size {persisted} pages differs from requested {requested}")]
55    BucketSizeMismatch { persisted: u16, requested: u16 },
56    /// Persisted manager metadata failed bounded validation.
57    #[error(transparent)]
58    Layout(#[from] super::MemoryManagerLayoutError),
59    /// Nonempty backing memory does not contain a `MemoryManager` header.
60    #[error(
61        "nonempty backing memory is not an ic-stable-structures MemoryManager \
62         (expected magic 'MGR', found bytes {observed_magic:?})"
63    )]
64    ForeignMemory {
65        /// First three bytes found in the nonempty backing memory.
66        observed_magic: [u8; 3],
67    },
68    /// Backing memory contains an unsupported `MemoryManager` layout version.
69    #[error(
70        "unsupported ic-stable-structures MemoryManager layout version {observed}; \
71         expected {supported}"
72    )]
73    UnsupportedMemoryManagerVersion {
74        /// Version byte found after the `MemoryManager` magic.
75        observed: u8,
76        /// Version supported by the pinned `ic-stable-structures` dependency.
77        supported: u8,
78    },
79}
80
81///
82/// RuntimeStateError
83///
84/// Failure to enter or maintain one memory runtime's in-memory lifecycle.
85///
86
87#[non_exhaustive]
88#[derive(Clone, Copy, Debug, Eq, thiserror::Error, PartialEq)]
89pub enum RuntimeStateError {
90    /// This thread's default runtime could not safely claim its backing memory.
91    #[error(transparent)]
92    Construction(#[from] RuntimeConstructionError),
93    /// A default-runtime operation re-entered while that TLS runtime was borrowed.
94    #[error("ic-memory default runtime is already borrowed by an active operation")]
95    ReentrantAccess,
96    /// The thread-local default runtime is being destroyed and cannot be entered.
97    #[error("ic-memory default runtime is unavailable during thread-local destruction")]
98    Unavailable,
99}
100
101///
102/// RuntimeBootstrapError
103///
104/// Failure to bootstrap one `MemoryRuntime`.
105///
106
107#[non_exhaustive]
108#[derive(Debug, thiserror::Error)]
109pub enum RuntimeBootstrapError<P> {
110    /// A known-only historical selection failed before commitment.
111    #[error(transparent)]
112    Admission(#[from] super::BootstrapAdmissionError),
113    /// Consumer identity or key-set admission rejected this attempt.
114    #[error("bootstrap admission policy rejected recovered allocation metadata")]
115    AdmissionPolicy(P),
116    #[error(transparent)]
117    Resolution(#[from] MemoryResolutionError),
118    /// The policy did not provide a valid bounded semantic identity.
119    #[error(transparent)]
120    PolicyIdentity(#[from] PolicyIdentityError),
121    /// A bootstrapped runtime was called with a different declaration snapshot.
122    #[error("runtime bootstrap declaration snapshot differs from the established binding")]
123    DeclarationSnapshotMismatch,
124    /// A bootstrapped runtime was called with a different policy identity.
125    #[error("runtime bootstrap policy identity changed from {established:?} to {requested:?}")]
126    PolicyIdentityMismatch {
127        /// Policy identity established by successful bootstrap.
128        established: PolicyIdentity,
129        /// Policy identity supplied by the repeated call.
130        requested: PolicyIdentity,
131    },
132    /// Linked-program declaration snapshot sealing failed.
133    #[error(transparent)]
134    Registry(#[from] StaticMemoryDeclarationError),
135    /// Protected ledger recovery or commit failed.
136    #[error(transparent)]
137    LedgerCommit(#[from] crate::LedgerCommitError),
138    /// Stable-cell ledger storage is corrupt before protected recovery can run.
139    #[error(transparent)]
140    StableCellLedger(#[from] StableCellLedgerError),
141    /// The encoded stable-cell ledger record exceeds its bounded size ceiling.
142    #[error("stable-cell ledger record size {value_size} cannot be written to stable memory")]
143    StableCellLedgerWriteTooLarge {
144        /// Encoded stable-cell ledger record size in bytes.
145        value_size: usize,
146    },
147    /// Stable-cell ledger capacity reservation failed before commitment.
148    #[error(transparent)]
149    LedgerGrowth(#[from] RuntimeGrowError),
150    /// Declaration validation failed.
151    #[error(transparent)]
152    Validation(#[from] crate::AllocationValidationError<RuntimePolicyError<P>>),
153    /// Validated declarations could not be staged.
154    #[error(transparent)]
155    Staging(#[from] crate::AllocationStageError),
156    /// Runtime lifecycle or default TLS access failed.
157    #[error(transparent)]
158    State(#[from] RuntimeStateError),
159}
160
161///
162/// RuntimeOpenError
163///
164/// Failure to open an allocation through one memory runtime.
165///
166
167#[non_exhaustive]
168#[derive(Clone, Debug, Eq, thiserror::Error, PartialEq)]
169pub enum RuntimeOpenError {
170    /// This runtime has not published committed allocations.
171    #[error("ic-memory runtime has not completed bootstrap validation")]
172    NotBootstrapped,
173    /// Runtime lifecycle or default TLS access failed.
174    #[error(transparent)]
175    State(#[from] RuntimeStateError),
176    /// Stable-key grammar failure.
177    #[error(transparent)]
178    StableKey(#[from] crate::StableKeyError),
179    /// The stable key was not present in this runtime's committed declaration set.
180    #[error("stable key '{0}' was not committed by ic-memory runtime bootstrap")]
181    StableKeyNotCommitted(String),
182    /// Runtime governance stable keys are internal and cannot be opened publicly.
183    #[error("stable key '{stable_key}' is reserved for ic-memory runtime governance")]
184    ReservedStableKey {
185        /// Reserved stable key.
186        stable_key: String,
187    },
188    /// The requested memory ID does not match the committed stable-key binding.
189    #[error(
190        "stable key '{stable_key}' is committed for MemoryManager ID {committed_id}, not requested ID {requested_id}"
191    )]
192    MemoryIdMismatch {
193        /// Stable key being opened.
194        stable_key: String,
195        /// Committed MemoryManager ID.
196        committed_id: u8,
197        /// Requested MemoryManager ID.
198        requested_id: u8,
199    },
200}
201
202///
203/// RuntimeDiagnosticError
204///
205/// Failure to build diagnostics for one memory runtime.
206///
207
208#[non_exhaustive]
209#[derive(Debug, thiserror::Error)]
210pub enum RuntimeDiagnosticError {
211    /// Persisted manager metadata is invalid or unsupported.
212    #[error(transparent)]
213    Construction(#[from] RuntimeConstructionError),
214    /// No default runtime exists, or this operation requires completed bootstrap.
215    #[error("ic-memory runtime has not completed bootstrap validation")]
216    NotBootstrapped,
217    /// Linked-program declaration snapshot sealing failed.
218    #[error(transparent)]
219    Registry(#[from] StaticMemoryDeclarationError),
220    /// Runtime lifecycle or default TLS access failed.
221    #[error(transparent)]
222    State(#[from] RuntimeStateError),
223    /// The recovered allocation ledger failed protected commit validation.
224    #[error(transparent)]
225    LedgerCommit(#[from] LedgerCommitError),
226    /// Stable-cell ledger storage is corrupt before protected recovery can run.
227    #[error(transparent)]
228    StableCellLedger(#[from] StableCellLedgerError),
229}
230
231///
232/// RuntimePolicyError
233///
234/// Failure in generic runtime range policy or caller-supplied policy.
235///
236
237#[non_exhaustive]
238#[derive(Clone, Debug, Eq, thiserror::Error, PartialEq)]
239pub enum RuntimePolicyError<P> {
240    /// Runtime range authority rejected the declaration.
241    #[error(transparent)]
242    Range(#[from] MemoryManagerRangeAuthorityError),
243    /// Caller-supplied policy rejected the declaration.
244    #[error(transparent)]
245    Custom(P),
246}
247
248///
249/// MemoryResolutionError
250///
251/// Logical placement failed before publishing allocation authority.
252///
253
254#[non_exhaustive]
255#[derive(Debug, thiserror::Error)]
256pub enum MemoryResolutionError {
257    #[error("no eligible free slot for {stable_key} under authority {authority}")]
258    Exhausted {
259        stable_key: crate::StableKey,
260        authority: String,
261    },
262    #[error(transparent)]
263    Range(#[from] crate::MemoryManagerRangeAuthorityError),
264    #[error(transparent)]
265    Registry(#[from] StaticMemoryDeclarationError),
266}