pub enum ServerError {
Show 23 variants
ConfigLoad {
message: String,
},
ConfigValidation {
message: String,
},
ListenerBind {
address: SocketAddr,
source: Error,
},
ListenerAccept {
message: String,
},
ParticipantIncarnation {
phase: &'static str,
message: String,
},
ParticipantServiceFatal {
fatal: ParticipantServiceFatal,
},
ConnectionFateRecoveryRequired {
open_count: usize,
first_open_sequence: u64,
},
ServerIncarnationExhausted,
ParticipantStartupRestore {
message: String,
},
ConnectionIncarnationExhausted {
attempted_server_incarnation: u64,
},
ConnectionPidCollision {
pid: u64,
},
UnsupportedOperation {
operation: String,
profile: &'static str,
},
PushReplyDisconnected {
correlation_id: u64,
},
PushReplyTimeout {
correlation_id: u64,
},
PushReplyExpired {
correlation_id: u64,
},
PushFrameExceedsOutboundCapacity {
correlation_id: u64,
needed: usize,
capacity: usize,
queued: usize,
},
ClusterJoin {
message: String,
},
ClusterSync {
message: String,
},
ShutdownTimeout {
message: String,
},
ShutdownFlush {
message: String,
},
HealthEndpoint {
message: String,
},
ConnectionLimitReached {
limit: usize,
},
ConnectionCapReached {
operation: String,
cap: &'static str,
limit: usize,
},
}Expand description
Error taxonomy for standalone liminal server deployment failures.
Variants§
ConfigLoad
The configuration file could not be read or parsed.
ConfigValidation
The configuration file was read but failed semantic validation.
ListenerBind
The server could not bind its configured listener address.
Fields
address: SocketAddrAddress the server attempted to bind.
ListenerAccept
The server listener failed while accepting an inbound connection.
ParticipantIncarnation
Durable participant-incarnation startup or allocation failed before its result could be published.
Fields
ParticipantServiceFatal
A durable connection-fate Open could not be completed in this process.
The normal runtime shutdown path returns this typed fatal only after it has stopped both listeners and run the ordinary connection drain/flush sequence.
Fields
fatal: ParticipantServiceFatalFirst process-wide post-Open failure; later failures cannot replace it.
ConnectionFateRecoveryRequired
Startup found durable connection-fate work that the Decision A/C producer must complete before listener or semantic-service publication.
Fields
ServerIncarnationExhausted
The durable server-incarnation namespace has no successor.
ParticipantStartupRestore
Production participant startup restore failed: the durable conversation streams could not be scanned or replayed, so the server-scope capacity ledger cannot be made exact and the server refuses to start over state it cannot account for.
ConnectionIncarnationExhausted
The current durable server incarnation has no collision-free connection ordinal left, so the accepted socket was not admitted.
Fields
ConnectionPidCollision
A connection registration found a record already present under its pid.
Enforces the pids-fresh-per-spawn supervision invariant loudly: a silent
replace would drop the displaced record’s teardown-held fd guard outside
the single record-removal funnel (orphaning a live connection’s stream)
and increment the liminal_connections_active gauge a second time with
no paired decrement. The whole registration is refused instead, leaving
the prior record — and its teardown route — intact.
UnsupportedOperation
A frame requested an operation the configured services profile does not serve (e.g. ordinary publish/subscribe/conversation traffic against the capability-scoped worker front door). Server-internal taxonomy, not wire vocabulary: the connection process renders it as the operation’s existing typed error frame with this error’s text as the message.
Fields
PushReplyDisconnected
A server→client push reply slot was dropped before a correlated reply
arrived — the connection closed (the prompt worker-death signal). Distinct
from Self::PushReplyTimeout so consumers can tell a worker that DIED
(fast failover) from one that is merely SLOW, by type rather than message.
PushReplyTimeout
A server→client push reply did not arrive within the awaiter’s timeout —
the worker is still connected but did not reply in this wait quantum. This
is BENIGN: the reply slot survives untouched and the caller may re-arm
PushReplyAwaiter::receive
indefinitely. It is not a worker-death signal.
PushReplyExpired
A server→client push carrying an explicit reply deadline (via
push_to_connection_with_deadline)
reached that deadline before a correlated reply arrived. Unlike
Self::PushReplyTimeout this is TERMINAL: the reply slot has been
removed and its §5 max_pending_pushes_per_connection cap admission
released. Returned PROMPTLY once the deadline is due — a receive call
does not hold a due expiry until its caller’s quantum ends, so the
terminal outcome is independent of how the caller polls. Distinct
variant so callers classify by type, not message.
PushFrameExceedsOutboundCapacity
A server→client push was never queued for the wire: its encoded frame is
larger than the WHOLE of the connection’s bounded outbound buffer, so no
amount of draining could ever make room for it. TERMINAL and CERTAIN — the
reply slot is removed, its §5 max_pending_pushes_per_connection admission
released, and the client never saw a Push frame for this correlation id.
Deliberately NARROW. A frame that would fit an empty buffer but not the
current free space is CONGESTION, not a size defect: it keeps the
connection-teardown path and its retryable
Self::PushReplyDisconnected reading, because waiting is the correct
answer there. Sharing one outcome between the certain case and the
recoverable one would leave the caller unable to tell them apart — which
is the exact fault this variant exists to end. Distinct variant so callers
classify by type, not message.
The WORDS carry the bound’s value and say the bound was chosen, because a
reader who meets this without that context blames the server for a number
an operator set. Since every outbound bound now comes from
max_connection_outbound_bytes,
that sentence is true on every occurrence rather than usually.
Fields
ClusterJoin
The server could not join the configured beamr distribution cluster.
ClusterSync
Cluster state propagation through beamr distribution failed.
ShutdownTimeout
Graceful shutdown did not drain within the configured timeout.
ShutdownFlush
Durable state could not be flushed during graceful shutdown.
HealthEndpoint
The health endpoint failed to start or serve requests.
ConnectionLimitReached
A new connection was refused because the configured max_connections
cap (§5) is already reached. The listener drops the freshly accepted
stream, refusing the connection, rather than admitting an unbounded fleet.
ConnectionCapReached
An admission-time per-connection cap (§5) refused an operation: too many subscriptions, conversations, in-flight pushes, or pending conversation replies on one connection. The connection process renders it as the operation’s existing typed error frame with this text as the message.
Trait Implementations§
Source§impl Debug for ServerError
impl Debug for ServerError
Source§impl Display for ServerError
impl Display for ServerError
Source§impl Error for ServerError
impl Error for ServerError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()