Public declaration syntax from forge-rs/crates/forge-code-safety/src/error.rs Original source SHA-256: 9a6d7c0f17f960a2ce9d6d6f5972be6c5e7108ce8048e0c73ca9a45fb962d92e Function bodies and constant values are omitted. This is not the complete implementation. Source line 32 #[derive(Debug, Error)] pub enum CodeSafetyError { /// The agent attempted to write to a file outside its assigned write scope. /// /// Every coding agent is assigned an explicit write scope (a set of paths /// and glob patterns). Writes to files outside that scope are denied. #[error("write denied: agent '{agent_did}' attempted to write '{path}' which is outside assigned scope '{scope}'")] WriteOutsideScope { /// The path the agent tried to write to. path: PathBuf, /// The assigned write scope that was violated. scope: PathBuf, /// The DID of the agent that attempted the write. agent_did: String, }, /// The agent attempted to delete a file, which is forbidden by default. /// /// Delete operations require explicit escalation and approval. The default /// policy is deny-all for deletes. #[error("delete denied: agent '{agent_did}' attempted to delete '{path}'; delete operations require explicit escalation (set escalation_policy to allow)")] DeleteDenied { /// The path the agent tried to delete. path: PathBuf, /// The DID of the agent that attempted the delete. agent_did: String, }, /// The worktree does not exist or is not accessible. #[error( "worktree '{worktree_path}' not found or not accessible for agent '{agent_did}': {reason}" )] WorktreeNotFound { /// The worktree path that was expected. worktree_path: PathBuf, /// The DID of the agent that tried to use the worktree. agent_did: String, /// Why the worktree was not found. reason: String, }, /// The worktree has already been leased to another agent. #[error("worktree '{worktree_path}' is already leased to agent '{existing_lessee}'; agent '{requesting_agent}' cannot acquire a concurrent lease")] WorktreeAlreadyLeased { /// The path of the contested worktree. worktree_path: PathBuf, /// The DID of the agent that currently holds the lease. existing_lessee: String, /// The DID of the agent that tried to acquire the lease. requesting_agent: String, }, /// The agent does not hold a valid lease for the requested repo. #[error("no active lease: agent '{agent_did}' does not hold a lease for repo '{repo_path}'; acquire a lease with RepoLeaseManager::acquire() first")] NoActiveLease { /// The DID of the agent missing a lease. agent_did: String, /// The repo path that required a lease. repo_path: PathBuf, }, /// The lease has expired. #[error("lease expired: agent '{agent_did}' lease for worktree '{worktree_path}' expired at {expired_at}; renew or release the lease")] LeaseExpired { /// The DID of the agent whose lease expired. agent_did: String, /// The worktree path with the expired lease. worktree_path: PathBuf, /// When the lease expired (ISO 8601 string). expired_at: String, }, /// An approval was required but not granted. #[error("approval required: operation '{operation}' on '{path}' by agent '{agent_did}' requires approval (risk_level={risk_level})")] ApprovalRequired { /// The operation that required approval. operation: String, /// The path the operation targets. path: PathBuf, /// The DID of the agent requesting the operation. agent_did: String, /// The risk level of the operation. risk_level: String, }, /// An approval was explicitly denied. #[error("approval denied: operation '{operation}' on '{path}' by agent '{agent_did}' was denied by reviewer '{reviewer}': {reason}")] ApprovalDenied { /// The operation that was denied. operation: String, /// The path the operation targets. path: PathBuf, /// The DID of the agent whose request was denied. agent_did: String, /// The reviewer who denied the request. reviewer: String, /// Why the approval was denied. reason: String, }, /// A file operation was attempted on the main/default branch directly. #[error("direct main branch modification denied: agent '{agent_did}' attempted to modify '{path}' on branch '{branch}'; all modifications must be made in worktrees")] MainBranchModification { /// The DID of the agent that attempted the modification. agent_did: String, /// The path that was targeted. path: PathBuf, /// The protected branch name. branch: String, }, /// The audit log write failed. #[error("audit log write failed for operation '{operation}' by agent '{agent_did}': {reason}")] AuditLogFailed { /// The operation that was being audited. operation: String, /// The DID of the agent. agent_did: String, /// Why the audit log write failed. reason: String, }, /// I/O error during file operations. #[error("file I/O error at '{path}': {reason}")] IoError { /// The path where the I/O error occurred. path: PathBuf, /// What went wrong. reason: String, }, /// Git operation failed. #[error("git operation failed in '{repo_path}': {reason}")] GitError { /// The repository where the git operation failed. repo_path: PathBuf, /// What went wrong. reason: String, }, } Source line 173 pub type CodeSafetyResult = Result;