Skip to main content

systemprompt_loader/bundle/
error.rs

1//! Error surface for fetching, verifying, extracting and composing bundles.
2//!
3//! Every variant is a hard failure: a bundle that cannot be proven is never
4//! installed. `Display` renders source names, paths and digests only — an
5//! auth token or registry credential never reaches a log line through here.
6//!
7//! Copyright (c) systemprompt.io — Business Source License 1.1.
8//! See <https://systemprompt.io> for licensing details.
9
10use std::path::PathBuf;
11
12use thiserror::Error;
13
14#[derive(Debug, Error)]
15pub enum VerifyFailure {
16    #[error("archive digest is {actual}, profile pins {expected}")]
17    DigestMismatch { expected: String, actual: String },
18
19    #[error("manifest signature does not verify against any pinned key")]
20    BadSignature,
21
22    #[error("manifest is signed by unpinned key {key_id}")]
23    UnknownKey { key_id: String },
24
25    #[error("checksum mismatch for {path}")]
26    FileChecksum { path: String },
27
28    #[error("recomputed content hash does not match the manifest")]
29    ContentHash,
30
31    #[error("bundle requires core {required}, this build is {actual}")]
32    RequiresCore { required: String, actual: String },
33
34    #[error("bundle claims non-marketplace directory {dir}")]
35    NotMarketplaceOnly { dir: String },
36
37    #[error("bundle is unsigned but the profile pins ed25519 keys")]
38    MissingSignature,
39
40    #[error("unsupported signature algorithm {alg}")]
41    UnsupportedAlgorithm { alg: String },
42
43    #[error("bundle declares format {format}, this build reads {supported}")]
44    UnsupportedFormat { format: u32, supported: u32 },
45
46    #[error("extracted tree has {count} file(s) not listed in the manifest")]
47    UnexpectedFiles { count: usize },
48
49    #[error("bundle is missing bundle.json")]
50    MissingManifest,
51
52    #[error("the source pins neither a sha256 digest nor an ed25519 key")]
53    NoVerification,
54}
55
56pub type BundleCause = Box<dyn std::error::Error + Send + Sync + 'static>;
57
58#[derive(Debug, Error)]
59pub enum BundleError {
60    #[error("source {source_name}: fetch failed: {}", describe(detail, cause.as_deref()))]
61    Fetch {
62        source_name: String,
63        detail: String,
64        #[source]
65        cause: Option<BundleCause>,
66    },
67
68    #[error("source {source_name}: registry rejected the credentials")]
69    Auth { source_name: String },
70
71    #[error("verification failed: {0}")]
72    Verify(#[from] VerifyFailure),
73
74    #[error("extract failed at {path}: {}", describe(detail, cause.as_deref()))]
75    Extract {
76        path: PathBuf,
77        detail: String,
78        #[source]
79        cause: Option<BundleCause>,
80    },
81
82    #[error("io error: {0}")]
83    Io(#[from] std::io::Error),
84
85    #[error("policy: {}", describe(detail, cause.as_deref()))]
86    Policy {
87        detail: String,
88        #[source]
89        cause: Option<BundleCause>,
90    },
91
92    #[error("{kind} {id} is claimed by both {first} and {second}")]
93    Ownership {
94        id: String,
95        kind: String,
96        first: String,
97        second: String,
98    },
99
100    #[error("no cached bundle for source {name} and no usable fallback")]
101    SourceMissing { name: String },
102
103    #[error("bundle exceeds the {bytes} byte limit")]
104    TooLarge { bytes: u64 },
105}
106
107pub type BundleResult<T> = Result<T, BundleError>;
108
109fn describe(
110    detail: &str,
111    cause: Option<&(dyn std::error::Error + Send + Sync + 'static)>,
112) -> String {
113    match cause {
114        Some(cause) if detail.is_empty() => cause.to_string(),
115        Some(cause) => format!("{detail}: {cause}"),
116        None => detail.to_owned(),
117    }
118}
119
120impl BundleError {
121    #[must_use]
122    pub fn fetch(source_name: &str, detail: impl Into<String>) -> Self {
123        Self::Fetch {
124            source_name: source_name.to_owned(),
125            detail: detail.into(),
126            cause: None,
127        }
128    }
129
130    #[must_use]
131    pub fn fetch_cause(source_name: &str, cause: impl Into<BundleCause>) -> Self {
132        Self::fetch_context(source_name, String::new(), cause)
133    }
134
135    #[must_use]
136    pub fn fetch_context(
137        source_name: &str,
138        context: impl Into<String>,
139        cause: impl Into<BundleCause>,
140    ) -> Self {
141        Self::Fetch {
142            source_name: source_name.to_owned(),
143            detail: context.into(),
144            cause: Some(cause.into()),
145        }
146    }
147
148    #[must_use]
149    pub fn policy(detail: impl Into<String>) -> Self {
150        Self::Policy {
151            detail: detail.into(),
152            cause: None,
153        }
154    }
155
156    #[must_use]
157    pub fn policy_context(context: impl Into<String>, cause: impl Into<BundleCause>) -> Self {
158        Self::Policy {
159            detail: context.into(),
160            cause: Some(cause.into()),
161        }
162    }
163
164    #[must_use]
165    pub fn extract(path: impl Into<PathBuf>, detail: impl Into<String>) -> Self {
166        Self::Extract {
167            path: path.into(),
168            detail: detail.into(),
169            cause: None,
170        }
171    }
172
173    #[must_use]
174    pub fn extract_cause(path: impl Into<PathBuf>, cause: impl Into<BundleCause>) -> Self {
175        Self::Extract {
176            path: path.into(),
177            detail: String::new(),
178            cause: Some(cause.into()),
179        }
180    }
181}