Sigil documentation
ReferenceRust referencesigil-state

sigil-state · dao_validators::error

Source declarations, signatures and documentation for dao_validators::error.

Source: sigil/node/sigil-state/src/dao_validators/error.rs. SHA-256: 2eb10ae5402f05e77fcab461aaadf6943660488d93e5c52430cde012779d384c.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

Module condition:

#[cfg(any(feature = "dao-validators", test))]

dao_validators::error::DaoValidatorError

Structured rejection reasons for DAO state-transition validators.

#[cfg(any(feature = "dao-validators", test))]
#[derive(Debug, Clone, PartialEq, Eq, Error)]
pub enum DaoValidatorError {
    // -- GAL trust path failures (consumed via `IssuerVerifier`) --------
    /// The mandate issuer (or another DID required by the validator) has
    /// no `HmrAnchor` / `MhrAnchor` / `EnrAnchor` on the GAL. Issuer
    /// lineage cannot be GAL-verified.
    #[error("missing GAL root for '{did}'")]
    MissingGalRoot {
        /// The DID whose GAL root is missing.
        did: String,
    },

    /// The DID itself, or one of its ancestors in `human_root_chain`, is
    /// revoked on Sigil. Cascade revocation rejects all descendants.
    #[error("revoked GAL subject or ancestor: '{did}'")]
    Revoked {
        /// The revoked DID (which may be an ancestor of the queried DID).
        did: String,
    },

    /// The `AgentLineageProof2025` parent signature on a non-root entity
    /// did not verify against the parent DID document's declared
    /// `verificationMethod`. Bound to the specific DID whose proof
    /// failed.
    #[error("invalid parent signature for '{did}': {reason}")]
    InvalidParentSignature {
        /// The DID whose lineage proof failed.
        did: String,
        /// Detail string from the GAL trust path.
        reason: String,
    },

    /// The GAL has an `OrgLineageRoot` for the entity's creator, but the
    /// entity's `lineage` carried no `org_inclusion_proof`.
    #[error("missing org inclusion proof for '{did}'")]
    MissingOrgInclusionProof {
        /// The DID whose org inclusion proof is missing.
        did: String,
    },

    /// An `org_inclusion_proof` was presented but did not verify against
    /// the on-chain `OrgLineageRoot.merkle_root` (tampered / wrong
    /// subject / wrong path).
    #[error("invalid org inclusion proof for '{did}': {reason}")]
    InvalidOrgInclusionProof {
        /// The DID whose proof failed verification.
        did: String,
        /// Detail string from the GAL trust path.
        reason: String,
    },

    /// The Sigil GAL backend was unreachable during snapshot
    /// construction. Validators fail closed: an unreachable GAL means
    /// the trust path cannot be exercised, and the state transition
    /// MUST be rejected rather than silently degrade.
    #[error("Sigil GAL unreachable for '{did}': {reason}")]
    GalUnreachable {
        /// The DID whose GAL query failed.
        did: String,
        /// Underlying transport / RPC failure detail.
        reason: String,
    },

    // -- Mandate-layer failures -----------------------------------------
    /// The mandate's recorded `issuer_did` was not GAL-verified by the
    /// snapshot — either the issuer is not a recognised root, or the
    /// snapshot's verifier did not classify it as a trusted issuer.
    /// This is distinct from `MissingGalRoot` because it accounts for
    /// the case where the GAL has an anchor but the issuer's role
    /// (HMR/MHR/ENR) is wrong for the mandate.
    #[error("unauthorized mandate issuer '{issuer_did}': {reason}")]
    UnauthorizedMandateIssuer {
        /// The DID stored in the mandate's `issuer_did` field.
        issuer_did: String,
        /// Detail.
        reason: String,
    },

    /// The mandate did not authorize the requested spend (insufficient
    /// budget, scope mismatch, expired, wrong token, wrong actor,
    /// wrong counterparty, or any other condition surfaced by
    /// `Mandate::authorize_spend`).
    #[error("insufficient spend authority: {reason}")]
    InsufficientSpendAuthority {
        /// Detail string. Wraps `sigil_core::MandateError`.
        reason: String,
    },

    // -- Labor-contract failures ----------------------------------------
    /// A precondition on milestone payment release was not met —
    /// milestone not yet attested, attestation policy not satisfied,
    /// escrow unfunded, contract in the wrong state, etc.
    #[error("labor release condition unmet: {reason}")]
    LaborReleaseConditionUnmet {
        /// Detail string identifying which precondition failed.
        reason: String,
    },

    // -- Cascade-revoke failures ----------------------------------------
    /// A `RevocationRecord` with cascade kind targets a DID that is
    /// not a root, or its `parent_root_did` field is inconsistent with
    /// the declared cascade kind.
    #[error("cascade revoke violation: {reason}")]
    CascadeRevokeViolation {
        /// Detail string.
        reason: String,
    },

    // -- Catch-all -------------------------------------------------------
    /// An unexpected internal error inside a validator. Reserved for
    /// programming-error surfaces; consensus paths should never hit
    /// this in practice.
    #[error("internal validator error: {reason}")]
    Internal {
        /// Detail.
        reason: String,
    },
}

Source line: 13.

dao_validators::error::DaoValidatorError::code

Stable error code string for telemetry / replay logs.

#[cfg(any(feature = "dao-validators", test))]
pub fn code(&self) -> &'static str;

Source line: 133.

On this page