Expand description
Runtime error types.
Structs§
- Admission
Failure Context - Structured context for a pre-execution admission failure: a finite-wait pooled writer checkout timeout, a bounded write-queue enqueue timeout, or a bounded storage-admission wait (reader/writer handle slot or pooled reader checkout). All happen before SQLite executes the request, so all are safe to classify as retryable — the request was never accepted, let alone started.
- Audit
Obligation Failure - An obligation failure preserves its typed cause and any storage source.
- Circular
Pack Dependency - Circular pack dependency detected during topological sort.
- Denial
Receipt - What a refused dispatch can cite: the
GateDeniedaudit row’s id when one committed, and where the row ended up otherwise. Boxed on the error so a refusal does not widen everyResult<_, RuntimeError>in the tree. - Dispatch
Error - An unchanged runtime error with provenance from one dispatch boundary.
- Guarded
Write Failure - A guarded edge write (
link/link_many) was refused because one or both endpoints no longer existed at write time. Names the exact endpoint(s) missing instead of a generic “source or target” message, and, for a batch write, which entry in the batch failed first. - Missing
Pack Dependencies - Multiple missing pack dependencies collected into one error.
- Missing
Pack Dependency - A single missing pack dependency.
- Receipt
Refusal - Payload of
RuntimeError::RefusedWithReceipt. - Refusal
Event Context - Original refusal and the independent evidence of recording it.
- Resolution
Facts - Repo-anchor facts established before a
git.digestingest failed. - Resolution
Failure Context - Preserve a resolved anchor’s facts while exposing the original typed error.
- Retryable
Failure Context - Structured context for a failure that is proven safe to retry.
- Writer
Pool Checkout Timeout Context - Structured context recovered from either a direct SQLite runtime error or a typed SQLite source preserved inside a storage-driver wrapper.
- Writer
Task Failure Context - Structured writer-request finality recovered from a storage error.
Enums§
- Audit
Obligation Reason - Typed cause of a post-dispatch audit or durable-receipt failure.
- Channel
Ingest Failure Class - Typed disposition for a channel message whose
comm.ingestwrite failed. - Denial
Audit Outcome - All errors produced by the khive-runtime layer.
- Domain
Disposition - What this dispatch boundary can establish about its own domain operation.
- Refusal
Event Recording - Event evidence for one eligible existing target in a refused request.
Failedmeans no confirmed event, not proof that an ambiguous append wrote nothing. - Refusal
Recording Error Class - Bounded failure evidence; never carries rejected input or a storage error string.
- Runtime
Error - Variants cover storage, query, validation, namespace isolation, and permission failures.
Callers should match on
InvalidInputfor bad arguments,NotFoundfor missing records, andNamespaceMismatch(reported as not-found) for cross-namespace access attempts.
Constants§
- READ_
TX_ AGE_ EVICTED_ STAGE - Stable wire code/stage for a cached read-only transaction proactively
rolled back after pinning a WAL snapshot past the configured
read_tx_max_agebound (#1846). Always safe to retry: the eviction only ever fires on a read-only handle, so no side effect can exist for a retry to duplicate. Shared by bothkhive_storage::StorageError::ReadTransactionAgeEvicted(clean rollback) andkhive_storage::StorageError::ReadTransactionAgeEvictionCleanupFailed(rollback denied or failed outright) — the renderedmessagefield distinguishes the two; retry behavior is identical for both. - SQLITE_
WAL_ CAPACITY_ REFUSED_ STAGE - Stable ADR-194 WAL capacity stages, shared with the SQLite error source. Stable ADR-194 capacity stages. The refusal stage is reserved for the WAL I/O limiter; this configuration-only slice emits only unavailable.
- SQLITE_
WAL_ CAPACITY_ UNAVAILABLE_ STAGE - Stable ADR-194 WAL capacity stages, shared with the SQLite error source.
- STORAGE_
ADMISSION_ TIMEOUT_ STAGE - Stable wire code/stage for a bounded storage-admission wait (a reader/writer handle slot or a pooled reader checkout) that elapsed before anything was acquired. The operation never started, so the failure is safe to retry.
- WRITER_
ADMISSION_ SCOPE - Stable ADR-131:251
scopediscriminator carried on aWRITER_QUEUE_SATURATED_STAGEfailure — distinguishes write-queue admission saturation from otherunavailablefailure kinds that share the sameretryable: trueshape but are not bounded by the admission deadline (e.g.WRITER_POOL_CHECKOUT_TIMEOUT_STAGE, which has no ADR-131-defined scope and carriesNone). - WRITER_
POOL_ CHECKOUT_ TIMEOUT_ STAGE - Stable ADR-135 F6 stage and wire code for a finite-wait pooled writer checkout that expires before SQLite executes.
- WRITER_
QUEUE_ SATURATED_ STAGE - Stable wire code/stage for a bounded write-queue enqueue that never accepted the request within its configured deadline (#1382, #1643).
- WRITER_
TASK_ BEGIN_ BUSY_ STAGE - Stable wire code/stage for SQLite write-lock contention after the writer queue accepted a request but before its operation closure ran.
- WRITER_
TASK_ REQUEST_ FAILED_ STAGE - Stable wire code/stage for an ordinary writer request whose operation or COMMIT failed after the task proved its transaction was rolled back.
- WRITER_
TASK_ TERMINATED_ STAGE - Stable wire code/stage for a request reported by a permanently retired writer seam.
Functions§
- fts_
text_ leg_ or_ err - Resolve an FTS text-leg search result, failing loud on parser syntax errors instead of silently degrading to vector-only fusion.
Type Aliases§
- Runtime
Result - Convenience alias for
Result<T, RuntimeError>.