#[non_exhaustive]pub enum ToolsetRuntimeError {
UnknownToolsetAction {
action: String,
},
CapabilityNotDeclared {
action: String,
capability: String,
},
ToolNotAllowed {
tool: String,
action: String,
},
ToolsetNotInstalled {
name: String,
},
Io(String),
ContentDigestMismatch {
name: String,
},
FirstInvokeApprovalRequired {
approval_nonce: String,
toolset_name: String,
capability: String,
},
GrantStoreError {
detail: String,
},
InvalidAuthoritativeAmount {
amount_stroops: i64,
},
}Expand description
Typed refusal errors for toolset capability enforcement.
Closed set: one variant per failure mode in the four-part check.
All author-controlled string fields are pre-sanitised by callers via
stellar_agent_toolsets::sanitise_display before being stored here.
§Variants
| Variant | Four-part step | Description |
|---|---|---|
ToolsetRuntimeError::UnknownToolsetAction | (a) | Action not in matrix. |
ToolsetRuntimeError::CapabilityNotDeclared | (c) | Granting capability not in toolset’s CapabilitySet. |
ToolsetRuntimeError::ToolNotAllowed | (d) | Tool excluded by toolset’s allowed_tools narrowing. |
ToolsetRuntimeError::ToolsetNotInstalled | pre-check | Toolset name has no pin record. |
ToolsetRuntimeError::Io | pre-check | I/O error reading the pin. |
ToolsetRuntimeError::ContentDigestMismatch | pre-check | On-disk TOOLSET.md hash differs from install-time digest. |
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
UnknownToolsetAction
Part (a): the action name is not in the capability→tool matrix.
The action is either a signing/key/policy tool (explicitly excluded),
a dispatcher tool (stellar_toolset_list / stellar_toolset_invoke), or
simply not a recognised wallet tool name.
§Security note
This variant fires before any capability check — a toolset cannot probe whether a signing tool “would be allowed” by its capabilities.
CapabilityNotDeclared
Part (c): the action’s granting capability is not in the toolset’s
declared stellar_agent_toolsets::CapabilitySet.
The toolset would need to declare the named capability to invoke this action.
Fields
ToolNotAllowed
Part (d): the resolved tool is not in the toolset’s allowed_tools list.
The toolset’s allowed_tools narrows the capability grant — it can only
subtract, never add. The tool is grantable by the toolset’s declared
capabilities but has been excluded by the intersective narrowing.
ToolsetNotInstalled
Pre-check: the toolset name has no pin record in the toolsets directory.
The toolset is not installed, or has been uninstalled since the invocation was queued.
Io(String)
Pre-check: an I/O error occurred while reading the pin record.
ContentDigestMismatch
Pre-check: the on-disk TOOLSET.md SHA-256 digest does not match the
digest recorded in the pin at install time.
Fires when the pin’s toolset_md_shasum field is Some and the current
file’s hash differs. This indicates post-install modification of the
manifest file.
§Recovery
Reinstall the toolset from the signed package:
stellar-agent toolset install <package> --force§Security note
The capability-source invariant (capabilities are read from the pin,
never re-parsed from the on-disk TOOLSET.md) ensures that a tampered
manifest CANNOT escalate capabilities even before this check fires.
This check adds tamper-evidence for the manifest text and refuses
dispatch to surface the incident rather than silently continuing with
stale metadata.
FirstInvokeApprovalRequired
Gated path: the first-invoke gate requires out-of-band approval.
The gated resolver (resolve_toolset_sign_payment_gated) returns
Ok(GatedResolveOutcome::FirstInvokeApprovalRequired { .. }) when the
gate fires. Production never constructs this error variant; the MCP
match arm must fail closed.
§Recovery
- The operator reviews the wallet-rendered summary.
stellar-agent approve --id <approval_nonce> --profile <name>is run.- The toolset re-invokes the same
sign-paymentaction.
Fields
GrantStoreError
Gated path: an I/O error occurred accessing the toolset grant store.
InvalidAuthoritativeAmount
Gated path: the authoritative payment amount is not positive.
authoritative_amount_stroops must be greater than zero. A zero or
negative value from the decoded envelope is rejected here before any
grant-store lookup or approval queuing occurs.
Trait Implementations§
Source§impl Debug for ToolsetRuntimeError
impl Debug for ToolsetRuntimeError
Source§impl Display for ToolsetRuntimeError
impl Display for ToolsetRuntimeError
Source§impl Error for ToolsetRuntimeError
impl Error for ToolsetRuntimeError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Auto Trait Implementations§
impl Freeze for ToolsetRuntimeError
impl RefUnwindSafe for ToolsetRuntimeError
impl Send for ToolsetRuntimeError
impl Sync for ToolsetRuntimeError
impl Unpin for ToolsetRuntimeError
impl UnsafeUnpin for ToolsetRuntimeError
impl UnwindSafe for ToolsetRuntimeError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> Paint for Twhere
T: ?Sized,
impl<T> Paint for Twhere
T: ?Sized,
Source§fn fg(&self, value: Color) -> Painted<&T>
fn fg(&self, value: Color) -> Painted<&T>
Returns a styled value derived from self with the foreground set to
value.
This method should be used rarely. Instead, prefer to use color-specific
builder methods like red() and
green(), which have the same functionality but are
pithier.
§Example
Set foreground color to white using fg():
use yansi::{Paint, Color};
painted.fg(Color::White);Set foreground color to white using white().
use yansi::Paint;
painted.white();Source§fn bright_black(&self) -> Painted<&T>
fn bright_black(&self) -> Painted<&T>
Source§fn bright_red(&self) -> Painted<&T>
fn bright_red(&self) -> Painted<&T>
Source§fn bright_green(&self) -> Painted<&T>
fn bright_green(&self) -> Painted<&T>
Source§fn bright_yellow(&self) -> Painted<&T>
fn bright_yellow(&self) -> Painted<&T>
Source§fn bright_blue(&self) -> Painted<&T>
fn bright_blue(&self) -> Painted<&T>
Source§fn bright_magenta(&self) -> Painted<&T>
fn bright_magenta(&self) -> Painted<&T>
Source§fn bright_cyan(&self) -> Painted<&T>
fn bright_cyan(&self) -> Painted<&T>
Source§fn bright_white(&self) -> Painted<&T>
fn bright_white(&self) -> Painted<&T>
Source§fn bg(&self, value: Color) -> Painted<&T>
fn bg(&self, value: Color) -> Painted<&T>
Returns a styled value derived from self with the background set to
value.
This method should be used rarely. Instead, prefer to use color-specific
builder methods like on_red() and
on_green(), which have the same functionality but
are pithier.
§Example
Set background color to red using fg():
use yansi::{Paint, Color};
painted.bg(Color::Red);Set background color to red using on_red().
use yansi::Paint;
painted.on_red();Source§fn on_primary(&self) -> Painted<&T>
fn on_primary(&self) -> Painted<&T>
Source§fn on_magenta(&self) -> Painted<&T>
fn on_magenta(&self) -> Painted<&T>
Source§fn on_bright_black(&self) -> Painted<&T>
fn on_bright_black(&self) -> Painted<&T>
Source§fn on_bright_red(&self) -> Painted<&T>
fn on_bright_red(&self) -> Painted<&T>
Source§fn on_bright_green(&self) -> Painted<&T>
fn on_bright_green(&self) -> Painted<&T>
Source§fn on_bright_yellow(&self) -> Painted<&T>
fn on_bright_yellow(&self) -> Painted<&T>
Source§fn on_bright_blue(&self) -> Painted<&T>
fn on_bright_blue(&self) -> Painted<&T>
Source§fn on_bright_magenta(&self) -> Painted<&T>
fn on_bright_magenta(&self) -> Painted<&T>
Source§fn on_bright_cyan(&self) -> Painted<&T>
fn on_bright_cyan(&self) -> Painted<&T>
Source§fn on_bright_white(&self) -> Painted<&T>
fn on_bright_white(&self) -> Painted<&T>
Source§fn attr(&self, value: Attribute) -> Painted<&T>
fn attr(&self, value: Attribute) -> Painted<&T>
Enables the styling Attribute value.
This method should be used rarely. Instead, prefer to use
attribute-specific builder methods like bold() and
underline(), which have the same functionality
but are pithier.
§Example
Make text bold using attr():
use yansi::{Paint, Attribute};
painted.attr(Attribute::Bold);Make text bold using using bold().
use yansi::Paint;
painted.bold();Source§fn rapid_blink(&self) -> Painted<&T>
fn rapid_blink(&self) -> Painted<&T>
Source§fn quirk(&self, value: Quirk) -> Painted<&T>
fn quirk(&self, value: Quirk) -> Painted<&T>
Enables the yansi Quirk value.
This method should be used rarely. Instead, prefer to use quirk-specific
builder methods like mask() and
wrap(), which have the same functionality but are
pithier.
§Example
Enable wrapping using .quirk():
use yansi::{Paint, Quirk};
painted.quirk(Quirk::Wrap);Enable wrapping using wrap().
use yansi::Paint;
painted.wrap();Source§fn clear(&self) -> Painted<&T>
👎Deprecated since 1.0.1: renamed to resetting() due to conflicts with Vec::clear().
The clear() method will be removed in a future release.
fn clear(&self) -> Painted<&T>
renamed to resetting() due to conflicts with Vec::clear().
The clear() method will be removed in a future release.
Source§fn whenever(&self, value: Condition) -> Painted<&T>
fn whenever(&self, value: Condition) -> Painted<&T>
Conditionally enable styling based on whether the Condition value
applies. Replaces any previous condition.
See the crate level docs for more details.
§Example
Enable styling painted only when both stdout and stderr are TTYs:
use yansi::{Paint, Condition};
painted.red().on_yellow().whenever(Condition::STDOUTERR_ARE_TTY);