Public declaration syntax from forge-rs/harness-runtime/src/error.rs Original source SHA-256: 361b9d95989945a863f253ca9e9bc6cf29477d77da98bc65dab84cd6ecd7548b Function bodies and constant values are omitted. This is not the complete implementation. Source line 18 #[derive(Debug, Error)] pub enum RuntimeError { /// An operation reached a plane that is not bound to a provider. #[error(transparent)] PlaneUnbound(#[from] PlaneUnbound), /// Admission denied the harness (§4.4: denied is a terminal state that /// still settles and archives). #[error(transparent)] Admission(#[from] AdmissionError), /// Child spawning violated the spawn policy or the no-amplification /// invariant (§4.5). #[error(transparent)] Spawn(#[from] SpawnError), /// The manifest selected a loop strategy the runtime has no driver /// for (§5.13: `loop.strategy` must name a registered strategy). #[error("loop strategy {strategy:?} has no registered driver in this runtime")] StrategyUnavailable { /// The strategy named by `loop.strategy`. strategy: String, }, } Source line 46 #[derive(Debug, Clone, PartialEq, Eq, Error)] #[error("plane {plane} is unbound: cannot perform {operation}")] pub struct PlaneUnbound { /// The unbound plane. pub plane: PlaneKind, /// The operation that was attempted. pub operation: &'static str } Source line 55 pub fn new(plane: PlaneKind, operation: &'static str) -> Self; Source line 65 #[derive(Debug, Clone, PartialEq, Error)] pub enum PlaneError { /// The plane has no provider bound (noop fail-closed path). #[error(transparent)] Unbound(#[from] PlaneUnbound), /// The provider is unreachable or unavailable. Per §4.6, availability /// is never disguised as success: admission denies, execution halts. #[error("provider unavailable: {message}")] Unavailable { /// Human-readable detail. message: String, }, /// The provider actively denied the request (e.g. policy miss, /// insufficient entitlement). #[error("provider denied the request: {message}")] Denied { /// Human-readable detail. message: String, }, /// The provider did not answer within the configured timeout. #[error("provider timed out after {timeout_ms} ms: {message}")] Timeout { /// The configured timeout in milliseconds. timeout_ms: u64, /// Human-readable detail. message: String, }, /// The provider answered with a response that could not be decoded or /// fails the plane's contract. #[error("invalid provider response: {message}")] InvalidResponse { /// Human-readable detail. message: String, }, /// Any other provider failure, with an optional upstream status code. #[error("provider error{status_suffix}: {message}")] Provider { /// Upstream status code when the provider is HTTP-backed. status: Option, /// Human-readable detail. message: String, /// Pre-rendered status suffix for the Display impl. status_suffix: String, }, } Source line 117 pub fn unavailable(message: impl Into) -> Self; Source line 124 pub fn denied(message: impl Into) -> Self; Source line 131 pub fn invalid_response(message: impl Into) -> Self; Source line 138 pub fn provider(status: Option, message: impl Into) -> Self; Source line 152 #[derive(Debug, Error)] pub enum AdmissionError { /// The manifest failed §5 validation when admission was invoked with /// raw TOML (§5.16: a conforming runtime must refuse to execute a /// manifest that fails validation). #[error("manifest validation failed: {0}")] ValidationFailed(#[from] SpecError), /// A plane the manifest requires is not bound to a provider. #[error("admission requires the {0}")] PlaneUnbound(#[from] PlaneUnbound), /// The identity plane rejected the lineage: the harness DID does not /// chain to the declared human root, or the provider could not verify /// it (§5.3, §4.6). #[error("identity verification failed for {did}: {reason}")] IdentityRejected { /// The harness agent DID. did: String, /// Why verification failed. reason: String, }, /// The policy plane denied the inference permission/entitlement the /// manifest requires (§5.8, §4.6: a policy engine miss denies /// in-contract). #[error("policy denied {permission}: {reason}")] PolicyDenied { /// The permission that was checked. permission: String, /// Why the policy plane denied it. reason: String, }, /// The economics plane refused or could not complete the budget /// reservation (§4.4 step 3: metering failure is denial). #[error("budget reservation failed: {0}")] ReservationFailed(#[source] PlaneError), /// The identity plane verified the lineage but returned no durable /// evidence reference (§4.4 step 3: an admission allow without a /// durable `evidenceRef` must not exist). #[error("identity verification returned no evidence reference")] MissingEvidenceRef, /// The manifest's `loop.strategy` has no registered driver in this /// runtime (§5.13: `loop.strategy` must name a registered strategy). #[error("loop strategy {strategy:?} has no registered driver in this runtime")] StrategyUnavailable { /// The strategy named by `loop.strategy`. strategy: String, }, } Source line 208 #[derive(Debug, Error)] pub enum SpawnError { /// The parent manifest declares `spawn.allowed = false`. #[error("harness {harness_id:?} does not permit child spawning ([spawn].allowed = false)")] SpawningDisabled { /// The parent harness id. harness_id: String, }, /// The child would sit deeper than the manifest bound or the runtime /// maximum derivation depth (§4.5, §5.3). #[error("child depth {child_depth} exceeds the maximum derivation depth {max}")] DepthLimitExceeded { /// The depth the child would occupy. child_depth: u32, /// The effective maximum (min of manifest bound, runtime bound). max: u32, }, /// The child manifest failed §5 validation on its own terms. #[error("child manifest invalid: {0}")] InvalidChildManifest(#[from] SpecError), /// The child would widen authority relative to its parent — the /// no-amplification invariant (§4.5). #[error("no-amplification violation: {0}")] Amplification(#[from] AmplificationViolation), /// The child's declared budgets could not be carved out of the /// parent's remaining budget (§4.5: sibling budgets must not overlap). #[error("budget carve failed: {0}")] BudgetCarve(#[from] BudgetError), } Source line 244 #[derive(Debug, Clone, PartialEq, Error)] #[error("[{rule}] {path}: {message}")] pub struct AmplificationViolation { /// Machine-checkable rule code. pub rule: AmplificationRule, /// Dotted manifest path of the offending child value. pub path: String, /// Human-readable explanation citing the governing spec section. pub message: String } Source line 255 pub fn new( rule: AmplificationRule, path: impl Into, message: impl Into, ) -> Self; Source line 270 #[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)] pub enum AmplificationRule { /// `tools.allow` is not a subset of the parent's (§4.5). ToolSuperset, /// `capabilities.act_refs` is not a subset of the parent's (§4.5). CapabilitySuperset, /// `policy.data_classes_allowed` is not a subset of the parent's /// (§4.5). DataClassSuperset, /// A declared budget exceeds `spawn.child_budget_fraction_max` of the /// parent's remaining budget (§4.5, §5.13). BudgetFractionExceeded, /// `memory.types` is not a subset of the parent's (§4.5: effective /// authority of any subtree node is bounded by the root's). MemoryTypeSuperset, /// The parent is text-only (no `[perception]`) but the child declares /// one (§4.7: perception is authority, narrowed on spawn). PerceptionIntroduced, /// `perception.modalities` is not a subset of the parent's (§4.7.5). ModalitySuperset, /// `perception.max_media_bytes` exceeds the parent's cap (§4.5: /// budgets and caps narrow, they never loosen). MediaCapLoosened, /// `identity.max_child_depth` exceeds the parent's bound (§4.5: /// derivation depth respects the manifest bound). ChildDepthSuperset, /// A parent-required tool approval was dropped by the child for a tool /// it keeps (§5.9: dropping a HITL gate widens effective authority). ApprovalGateDropped, } Source line 321 #[derive(Debug, Clone, PartialEq, Error)] pub enum BudgetError { /// A carve or charge exceeded the remaining budget. #[error( "insufficient budget: requested {requested_usd} USD / {requested_tokens} tokens, \ remaining {remaining_usd} USD / {remaining_tokens} tokens" )] Insufficient { /// Requested USD. requested_usd: f64, /// Requested tokens. requested_tokens: u64, /// Remaining USD. remaining_usd: f64, /// Remaining tokens. remaining_tokens: u64, }, /// The budget is exhausted; the configured `on_budget_exhausted` /// policy now applies (§5.8). #[error("budget exhausted ({remaining_usd} USD / {remaining_tokens} tokens remaining)")] Exhausted { /// Remaining USD (may be zero or negative after the final charge). remaining_usd: f64, /// Remaining tokens. remaining_tokens: u64, }, } Source line 352 #[derive(Debug, Clone, PartialEq, Eq, Error)] #[error("invalid W3C traceparent value {value:?}: {reason}")] pub struct TraceContextError { /// The offending header value. pub value: String, /// Why it is invalid. pub reason: String }