mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-26 15:40:18 +00:00
* feat: port NPA psychographic profiling system into IronClaw
Port the complete psychographic profiling system from NPA into IronClaw,
including enriched profile schema, conversational onboarding, profile
evolution, and three-tier prompt augmentation.
Personal onboarding moved from wizard Step 9 to first assistant
interaction per maintainer feedback — the First Contact system prompt
block now instructs the LLM to conduct a natural onboarding conversation
that builds the psychographic profile via memory_write.
Changes:
- Enrich profile.rs with 5 new structs, 9-dimension analysis framework,
custom deserializers for backward compatibility, and rendering methods
- Add conversational onboarding engine with one-step-removed questioning
technique, personality framework, and confidence-scored profile generation
- Add profile evolution with confidence gating, analysis metadata tracking,
and weekly update routine
- Replace thin interaction style injection with three-tier system gated on
confidence > 0.6 and profile recency
- Replace wizard Step 9 with First Contact system prompt block that drives
conversational onboarding during the user's first interaction
- Add autonomy progression to SOUL.md seed and personality framework to
AGENTS.md seed
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* feat: replace chat-based onboarding with bootstrap greeting and workspace seeds
Remove the interactive onboarding_chat.rs engine in favor of a simpler
bootstrap flow: fresh workspaces get a proactive LLM greeting that
naturally profiles the user. Identity files are now seeded from
src/workspace/seeds/ instead of being hardcoded. Also removes the
identity-file write protection (seeds are now managed), adds routine
advisor integration, and includes an e2e trace for bootstrap greeting.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* feat(safety): sanitize identity file writes via Sanitizer to prevent prompt injection
Identity files (SOUL.md, AGENTS.md, USER.md, IDENTITY.md) are injected into
every system prompt. Rather than hard-blocking writes (which broke onboarding),
scan content through the existing Sanitizer and reject writes with High/Critical
severity injection patterns. Medium/Low warnings are logged but allowed.
Also clarifies AGENTS.md identity file roles (USER.md = user info, IDENTITY.md =
agent identity) and adds IDENTITY.md setup as an explicit bootstrap step.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* docs: update profile_onboarding_completed comment to reflect current wiring
The field is now actively used by the agent loop to suppress BOOTSTRAP.md
injection — remove the stale "not yet wired" TODO.
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(setup): use env_or_override for NEARAI_API_KEY in model fetch config
When the user authenticates via NEAR AI Cloud API key (option 4),
api_key_login() stores the key via set_runtime_env(). But
build_nearai_model_fetch_config() was using std::env::var() which
doesn't check the runtime overlay — so model listing fell back to
session-token auth and re-triggered the interactive NEAR AI
authentication menu.
Switch to env_or_override() which checks both real env vars and the
runtime overlay.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(agent): correct channel/user_id in bootstrap greeting persist call
persist_assistant_response was called with channel="default",
user_id="system" but the assistant thread was created via
get_or_create_assistant_conversation("default", "gateway") which owns
the conversation as user_id="default", channel="gateway". The mismatch
caused ensure_writable_conversation to reject the write with:
WARN Rejected write for unavailable thread id user=system channel=default
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(web): remove all inline event handlers for CSP compliance
The Content-Security-Policy header (added in f48fe95) blocks inline JS
via script-src 'self'. All onclick/onchange attributes in index.html
are replaced with getElementById().addEventListener() calls. Dynamic
inline handlers in app.js (jobs, routines, memory breadcrumb, code
blocks, TEE report) are replaced with data-action attributes and a
single delegated click handler on document.
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(agent): align bootstrap message user/channel and update fixture schema field
- Bootstrap IncomingMessage now uses ("default", "gateway") consistently
with persist and session registration calls
- Update bootstrap_greeting.json fixture: schema_version → version to
match current PROFILE_JSON_SCHEMA
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* style: cargo fmt
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(safety): address PR review — expand injection scanning and harden profile sync
- BOOTSTRAP.md: fix target "profile" → "context/profile.json" so the
write hits the correct path and triggers profile sync
- IDENTITY_FILES: add context/assistant-directives.md to the scanned
set since it is also injected into the system prompt
- sync_profile_documents(): scan derived USER.md and assistant-directives
content through Sanitizer before writing, rejecting High/Critical
injection patterns
- profile_evolution_prompt(): wrap recent_messages_summary in <user_data>
delimiters with untrusted-data instruction to mitigate indirect
prompt injection
- routine-advisor skill: update cron examples from 6-field to standard
5-field format for consistency with routine_create tool docs
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* style: cargo fmt
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* fix(setup): detect env-provided LLM keys during quick-mode onboarding
Quick-mode wizard now checks LLM_BACKEND, NEARAI_API_KEY,
ANTHROPIC_API_KEY, and OPENAI_API_KEY env vars to pre-populate
the provider setting, so users aren't re-prompted for credentials
they already supplied. Also teaches setup_nearai() to recognize
NEARAI_API_KEY from env (previously only checked session tokens).
Includes web UI cleanup (remove duplicate event listeners) and
e2e test response count adjustment.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix(test): update routine_create_list to expect 7-field normalized cron
The cron normalizer now always expands to 7-field format, so the
stored schedule is "0 0 9 * * * *" not "0 0 9 * * *".
[skip-regression-check]
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* feat(setup): skip LLM provider prompts when NEARAI_API_KEY is present
In quick mode, if NEARAI_API_KEY is set in the environment and the
backend was auto-detected as nearai, skip the interactive inference
provider and model selection steps. The API key is persisted to the
secrets store and a default model is set automatically.
Also simplify the static fallback model list for nearai to a single
default entry.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: unify default model, static bootstrap greeting, and web UI cleanup
- Add DEFAULT_MODEL const and default_models() fallback list in
llm/nearai_chat.rs; use from config, wizard, and .env.example so the
default model is defined in one place
- Restore multi-model fallback list in setup wizard (was reduced to 1)
- Move BOOTSTRAP_GREETING to module-level const (out of run() body)
- Replace LLM-based bootstrap with static greeting (persist to DB before
channels start, then broadcast — eliminates startup LLM call and race)
- Fix double env::var read for NEARAI_API_KEY in quick setup path
- Move thread sidebar buttons into threads-section-header (web UI)
- Remove orphaned .thread-sidebar-header CSS and fix double blank line
- Update bootstrap e2e test for static greeting (no LLM trace needed)
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix(safety): move prompt injection scanning into Workspace write/append
Addresses PR #927 review comments (#1, #3) — identity file write
protection and unsanitized profile fields in system prompt.
Instead of scanning at the tool layer (memory.rs) or the sync layer
(sync_profile_documents), injection scanning now lives in
Workspace::write() and Workspace::append() for all files that are
injected into the system prompt. This ensures every code path that
writes to these files is protected, including future ones.
- Add SYSTEM_PROMPT_FILES const and reject_if_injected() in workspace
- Add WorkspaceError::InjectionRejected variant
- Add map_write_err() in memory.rs to convert InjectionRejected to
ToolError::NotAuthorized
- Remove redundant IDENTITY_FILES/Sanitizer from memory.rs
- Remove redundant sanitizer calls from sync_profile_documents()
- Move sanitization tests to workspace::tests
- Existing integration test (test_memory_write_rejects_injection)
continues to pass through the new path
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — merge marker order, orphan thread, stale fixture
- merge_profile_section: search for END marker after BEGIN position to
avoid matching a stray END earlier in the file
- Bootstrap phase 2: use get_or_create_session + Thread::with_id instead
of resolve_thread(None) to avoid creating an orphan thread
- setup_nearai: use env_or_override for NEARAI_API_KEY consistency with
runtime overlay
- Delete orphaned bootstrap_greeting.json fixture (no test references it)
- Add test_merge_end_marker_must_follow_begin regression test
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: fmt agent_loop.rs (CI stable rustfmt)
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: lazy-init sanitizer, check profile non-empty before skipping bootstrap
Address Copilot review:
- Use LazyLock<Sanitizer> to avoid rebuilding Aho-Corasick + regexes
on every workspace write
- has_profile check now requires non-empty content, not just file
existence, to prevent empty profile.json from suppressing onboarding
- Add seed_tests integration tests (libsql-backed) verifying:
- Empty profile.json does not suppress BOOTSTRAP.md seeding
- Non-empty profile.json correctly suppresses bootstrap for upgrades
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: duplicate language handler, empty LLM_BACKEND, test_rig style
Address Copilot review on PR #927:
- Remove duplicate language-option click listeners (delegated
data-action handler already covers them)
- Guard LLM_BACKEND env prefill against empty string to prevent
suppressing API-key-based auto-detection
- Use destructured local `keep_bootstrap` instead of `self.keep_bootstrap`
in test_rig for consistency after destructure
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: update stale BOOTSTRAP.md write-protection comment [skip-regression-check]
BOOTSTRAP.md is now in SYSTEM_PROMPT_FILES and gets injection scanning
on write. The old comment incorrectly stated it was not write-protected.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: replace debug_assert panics with graceful error returns [skip-regression-check]
debug_assert! in execute_tool_with_safety and JobContext::transition_to
panicked in test builds before the graceful error path could run.
Existing tests (test_cancel_job_completed, test_execute_empty_tool_name_returns_not_found)
already cover these paths — they were the ones failing.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — schema label, env var check, path normalization, profile validation
1. Label ANALYSIS_FRAMEWORK and PROFILE_JSON_SCHEMA sections separately
in bootstrap prompt so the LLM knows which blob is the target structure.
2. Wizard quick-mode backend auto-detection now rejects empty env vars
(std::env::var().is_ok_and(|v| !v.is_empty())) to avoid selecting the
wrong backend when e.g. NEARAI_API_KEY="" is set.
3. Normalize the target path before comparing with paths::PROFILE in
memory_write so non-canonical variants like "context//profile.json"
still trigger profile sync.
4. seed_if_empty now requires valid JSON parse of context/profile.json
before treating it as a populated profile. Corrupted content no longer
permanently suppresses bootstrap seeding.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* style: cargo fmt
* fix: address Copilot review — append scan, profile validation, env_or_override
1. Workspace::append() now scans the combined content (existing + new)
for prompt injection, not just the appended chunk. Prevents split-
injection evasion across multiple appends.
2. seed_if_empty() now deserializes into PsychographicProfile instead of
serde_json::Value for profile validation. Stray/legacy JSON that
doesn't match the expected schema no longer suppresses bootstrap.
3. Wizard quick-mode backend auto-detection now uses env_or_override()
to honor runtime overlays and injected secrets. LLM_BACKEND value
is trimmed before storage.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* test: add bootstrap_onboarding_clears_bootstrap E2E trace test
Exercises the full onboarding flow end-to-end:
1. Bootstrap greeting fires automatically on fresh workspace
2. User converses for 3 turns (name, tools, work style)
3. Agent writes psychographic profile to context/profile.json
4. Profile sync generates USER.md and assistant-directives.md
5. Agent writes IDENTITY.md (chosen persona)
6. Agent clears BOOTSTRAP.md via memory_write(target: "bootstrap")
Verifies:
- BOOTSTRAP.md is non-empty before onboarding, empty after
- bootstrap_completed flag is set
- Profile contains expected user data (name, profession, interests)
- USER.md contains profile-derived content (name, tone, profession)
- Assistant-directives.md references user and communication style
- IDENTITY.md contains agent's chosen persona name
- All memory_write calls succeed
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
* fix: address Copilot review — slash collapse, env_or_override, cron trim [skip-regression-check]
1. memory.rs path normalization now uses the same char-by-char loop as
Workspace::normalize_path() to fully collapse consecutive slashes
(e.g. "context///profile.json" → "context/profile.json").
2. Quick-mode NEARAI_API_KEY check (line 239) now uses env_or_override()
consistently with the backend auto-detection block above it.
3. normalize_cron_expression() trims input before field counting so the
passthrough branch (7+ fields) also strips whitespace.
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
---------
Co-authored-by: Jay Zalowitz <[email protected]>
Co-authored-by: Claude Opus 4.6 <[email protected]>
523 lines
15 KiB
Rust
523 lines
15 KiB
Rust
//! Error types for IronClaw.
|
|
|
|
use std::time::Duration;
|
|
|
|
use uuid::Uuid;
|
|
|
|
/// Top-level error type for the agent.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum Error {
|
|
#[error("Configuration error: {0}")]
|
|
Config(#[from] ConfigError),
|
|
|
|
#[error("Database error: {0}")]
|
|
Database(#[from] DatabaseError),
|
|
|
|
#[error("Channel error: {0}")]
|
|
Channel(#[from] ChannelError),
|
|
|
|
#[error("LLM error: {0}")]
|
|
Llm(#[from] LlmError),
|
|
|
|
#[error("Tool error: {0}")]
|
|
Tool(#[from] ToolError),
|
|
|
|
#[error("Safety error: {0}")]
|
|
Safety(#[from] SafetyError),
|
|
|
|
#[error("Job error: {0}")]
|
|
Job(#[from] JobError),
|
|
|
|
#[error("Estimation error: {0}")]
|
|
Estimation(#[from] EstimationError),
|
|
|
|
#[error("Evaluation error: {0}")]
|
|
Evaluation(#[from] EvaluationError),
|
|
|
|
#[error("Repair error: {0}")]
|
|
Repair(#[from] RepairError),
|
|
|
|
#[error("Workspace error: {0}")]
|
|
Workspace(#[from] WorkspaceError),
|
|
|
|
#[error("Hook error: {0}")]
|
|
Hook(#[from] crate::hooks::HookError),
|
|
|
|
#[error("Orchestrator error: {0}")]
|
|
Orchestrator(#[from] OrchestratorError),
|
|
|
|
#[error("Worker error: {0}")]
|
|
Worker(#[from] WorkerError),
|
|
|
|
#[error("Routine error: {0}")]
|
|
Routine(#[from] RoutineError),
|
|
}
|
|
|
|
/// Configuration-related errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum ConfigError {
|
|
#[error("Missing required environment variable: {0}")]
|
|
MissingEnvVar(String),
|
|
|
|
#[error("Missing required configuration: {key}. {hint}")]
|
|
MissingRequired { key: String, hint: String },
|
|
|
|
#[error("Invalid configuration value for {key}: {message}")]
|
|
InvalidValue { key: String, message: String },
|
|
|
|
#[error("Failed to parse configuration: {0}")]
|
|
ParseError(String),
|
|
|
|
#[error("IO error: {0}")]
|
|
Io(#[from] std::io::Error),
|
|
}
|
|
|
|
/// Database-related errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum DatabaseError {
|
|
#[error("Connection pool error: {0}")]
|
|
Pool(String),
|
|
|
|
#[error("Query failed: {0}")]
|
|
Query(String),
|
|
|
|
#[error("Entity not found: {entity} with id {id}")]
|
|
NotFound { entity: String, id: String },
|
|
|
|
#[error("Constraint violation: {0}")]
|
|
Constraint(String),
|
|
|
|
#[error("Migration failed: {0}")]
|
|
Migration(String),
|
|
|
|
#[error("Serialization error: {0}")]
|
|
Serialization(String),
|
|
|
|
#[cfg(feature = "postgres")]
|
|
#[error("PostgreSQL error: {0}")]
|
|
Postgres(#[from] tokio_postgres::Error),
|
|
|
|
#[cfg(feature = "postgres")]
|
|
#[error("Pool build error: {0}")]
|
|
PoolBuild(#[from] deadpool_postgres::BuildError),
|
|
|
|
#[cfg(feature = "postgres")]
|
|
#[error("Pool runtime error: {0}")]
|
|
PoolRuntime(#[from] deadpool_postgres::PoolError),
|
|
|
|
#[cfg(feature = "libsql")]
|
|
#[error("LibSQL error: {0}")]
|
|
LibSql(#[from] libsql::Error),
|
|
}
|
|
|
|
/// Channel-related errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum ChannelError {
|
|
#[error("Channel {name} failed to start: {reason}")]
|
|
StartupFailed { name: String, reason: String },
|
|
|
|
#[error("Channel {name} disconnected: {reason}")]
|
|
Disconnected { name: String, reason: String },
|
|
|
|
#[error("Failed to send response on channel {name}: {reason}")]
|
|
SendFailed { name: String, reason: String },
|
|
|
|
#[error("Channel {name} is missing a routing target: {reason}")]
|
|
MissingRoutingTarget { name: String, reason: String },
|
|
|
|
#[error("Invalid message format: {0}")]
|
|
InvalidMessage(String),
|
|
|
|
#[error("Authentication failed for channel {name}: {reason}")]
|
|
AuthFailed { name: String, reason: String },
|
|
|
|
#[error("Rate limited on channel {name}")]
|
|
RateLimited { name: String },
|
|
|
|
#[error("HTTP error: {0}")]
|
|
Http(String),
|
|
|
|
#[error("Channel health check failed: {name}")]
|
|
HealthCheckFailed { name: String },
|
|
}
|
|
|
|
// LlmError lives in src/llm/error.rs; re-exported here for backward compatibility.
|
|
pub use crate::llm::error::LlmError;
|
|
|
|
/// Tool execution errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum ToolError {
|
|
#[error("Tool {name} not found")]
|
|
NotFound { name: String },
|
|
|
|
#[error("Tool {name} execution failed: {reason}")]
|
|
ExecutionFailed { name: String, reason: String },
|
|
|
|
#[error("Tool {name} timed out after {timeout:?}")]
|
|
Timeout { name: String, timeout: Duration },
|
|
|
|
#[error("Invalid parameters for tool {name}: {reason}")]
|
|
InvalidParameters { name: String, reason: String },
|
|
|
|
#[error("Tool {name} is disabled: {reason}")]
|
|
Disabled { name: String, reason: String },
|
|
|
|
#[error("Sandbox error for tool {name}: {reason}")]
|
|
Sandbox { name: String, reason: String },
|
|
|
|
#[error("Tool {name} requires authentication")]
|
|
AuthRequired { name: String },
|
|
|
|
#[error("Tool {name} is rate limited, retry after {retry_after:?}")]
|
|
RateLimited {
|
|
name: String,
|
|
retry_after: Option<Duration>,
|
|
},
|
|
|
|
#[error("Tool builder failed: {0}")]
|
|
BuilderFailed(String),
|
|
}
|
|
|
|
/// Safety/sanitization errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum SafetyError {
|
|
#[error("Potential prompt injection detected: {pattern}")]
|
|
InjectionDetected { pattern: String },
|
|
|
|
#[error("Output exceeded maximum length: {length} > {max}")]
|
|
OutputTooLarge { length: usize, max: usize },
|
|
|
|
#[error("Blocked content pattern detected: {pattern}")]
|
|
BlockedContent { pattern: String },
|
|
|
|
#[error("Validation failed: {reason}")]
|
|
ValidationFailed { reason: String },
|
|
|
|
#[error("Policy violation: {rule}")]
|
|
PolicyViolation { rule: String },
|
|
}
|
|
|
|
/// Job-related errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum JobError {
|
|
#[error("Job {id} not found")]
|
|
NotFound { id: Uuid },
|
|
|
|
#[error("Job {id} already in state {state}, cannot transition to {target}")]
|
|
InvalidTransition {
|
|
id: Uuid,
|
|
state: String,
|
|
target: String,
|
|
},
|
|
|
|
#[error("Job {id} failed: {reason}")]
|
|
Failed { id: Uuid, reason: String },
|
|
|
|
#[error("Job {id} stuck for {duration:?}")]
|
|
Stuck { id: Uuid, duration: Duration },
|
|
|
|
#[error("Maximum parallel jobs ({max}) exceeded")]
|
|
MaxJobsExceeded { max: usize },
|
|
|
|
#[error("Job {id} context error: {reason}")]
|
|
ContextError { id: Uuid, reason: String },
|
|
}
|
|
|
|
/// Estimation errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum EstimationError {
|
|
#[error("Insufficient data for estimation: need {needed} samples, have {have}")]
|
|
InsufficientData { needed: usize, have: usize },
|
|
|
|
#[error("Estimation calculation failed: {reason}")]
|
|
CalculationFailed { reason: String },
|
|
|
|
#[error("Invalid estimation parameters: {reason}")]
|
|
InvalidParameters { reason: String },
|
|
}
|
|
|
|
/// Evaluation errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum EvaluationError {
|
|
#[error("Evaluation failed for job {job_id}: {reason}")]
|
|
Failed { job_id: Uuid, reason: String },
|
|
|
|
#[error("Missing required evaluation data: {field}")]
|
|
MissingData { field: String },
|
|
|
|
#[error("Invalid evaluation criteria: {reason}")]
|
|
InvalidCriteria { reason: String },
|
|
}
|
|
|
|
/// Self-repair errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum RepairError {
|
|
#[error("Repair failed for {target_type} {target_id}: {reason}")]
|
|
Failed {
|
|
target_type: String,
|
|
target_id: Uuid,
|
|
reason: String,
|
|
},
|
|
|
|
#[error("Maximum repair attempts ({max}) exceeded for {target_type} {target_id}")]
|
|
MaxAttemptsExceeded {
|
|
target_type: String,
|
|
target_id: Uuid,
|
|
max: u32,
|
|
},
|
|
|
|
#[error("Cannot diagnose issue for {target_type} {target_id}: {reason}")]
|
|
DiagnosisFailed {
|
|
target_type: String,
|
|
target_id: Uuid,
|
|
reason: String,
|
|
},
|
|
}
|
|
|
|
/// Workspace/memory errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum WorkspaceError {
|
|
#[error("Document not found: {doc_type} for user {user_id}")]
|
|
DocumentNotFound { doc_type: String, user_id: String },
|
|
|
|
#[error("Search failed: {reason}")]
|
|
SearchFailed { reason: String },
|
|
|
|
#[error("Embedding generation failed: {reason}")]
|
|
EmbeddingFailed { reason: String },
|
|
|
|
#[error("Document chunking failed: {reason}")]
|
|
ChunkingFailed { reason: String },
|
|
|
|
#[error("Invalid document type: {doc_type}")]
|
|
InvalidDocType { doc_type: String },
|
|
|
|
#[error("Workspace not initialized for user {user_id}")]
|
|
NotInitialized { user_id: String },
|
|
|
|
#[error("Heartbeat error: {reason}")]
|
|
HeartbeatError { reason: String },
|
|
|
|
#[error("I/O error: {reason}")]
|
|
IoError { reason: String },
|
|
|
|
#[error("Write rejected for '{path}': prompt injection detected ({reason})")]
|
|
InjectionRejected { path: String, reason: String },
|
|
}
|
|
|
|
/// Orchestrator errors (internal API, container management).
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum OrchestratorError {
|
|
#[error("Container creation failed for job {job_id}: {reason}")]
|
|
ContainerCreationFailed { job_id: Uuid, reason: String },
|
|
|
|
#[error("Container not found for job {job_id}")]
|
|
ContainerNotFound { job_id: Uuid },
|
|
|
|
#[error("Container for job {job_id} is in unexpected state: {state}")]
|
|
InvalidContainerState { job_id: Uuid, state: String },
|
|
|
|
#[error("Internal API error: {reason}")]
|
|
ApiError { reason: String },
|
|
|
|
#[error("Docker error: {reason}")]
|
|
Docker { reason: String },
|
|
}
|
|
|
|
/// Worker errors (container-side execution).
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum WorkerError {
|
|
#[error("Failed to connect to orchestrator at {url}: {reason}")]
|
|
ConnectionFailed { url: String, reason: String },
|
|
|
|
#[error("LLM proxy request failed: {reason}")]
|
|
LlmProxyFailed { reason: String },
|
|
|
|
#[error("Secret resolution failed for {secret_name}: {reason}")]
|
|
SecretResolveFailed { secret_name: String, reason: String },
|
|
|
|
#[error("Orchestrator returned error for job {job_id}: {reason}")]
|
|
OrchestratorRejected { job_id: Uuid, reason: String },
|
|
|
|
#[error("Worker execution failed: {reason}")]
|
|
ExecutionFailed { reason: String },
|
|
|
|
#[error("Missing worker token (IRONCLAW_WORKER_TOKEN not set)")]
|
|
MissingToken,
|
|
}
|
|
|
|
/// Routine-related errors.
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum RoutineError {
|
|
#[error("Unknown trigger type: {trigger_type}")]
|
|
UnknownTriggerType { trigger_type: String },
|
|
|
|
#[error("Unknown action type: {action_type}")]
|
|
UnknownActionType { action_type: String },
|
|
|
|
#[error("Missing field in {context}: {field}")]
|
|
MissingField { context: String, field: String },
|
|
|
|
#[error("Invalid cron expression: {reason}")]
|
|
InvalidCron { reason: String },
|
|
|
|
#[error("Unknown run status: {status}")]
|
|
UnknownRunStatus { status: String },
|
|
|
|
#[error("Routine {name} is disabled")]
|
|
Disabled { name: String },
|
|
|
|
#[error("Routine not found: {id}")]
|
|
NotFound { id: Uuid },
|
|
|
|
#[error("Not authorized to trigger routine {id}")]
|
|
NotAuthorized { id: Uuid },
|
|
|
|
#[error("Routine {name} at max concurrent runs")]
|
|
MaxConcurrent { name: String },
|
|
|
|
#[error("Database error: {reason}")]
|
|
Database { reason: String },
|
|
|
|
#[error("LLM call failed: {reason}")]
|
|
LlmFailed { reason: String },
|
|
|
|
#[error("Failed to dispatch full job: {reason}")]
|
|
JobDispatchFailed { reason: String },
|
|
|
|
#[error("LLM returned empty content")]
|
|
EmptyResponse,
|
|
|
|
#[error("LLM response truncated (finish_reason=length) with no content")]
|
|
TruncatedResponse,
|
|
}
|
|
|
|
/// Result type alias for the agent.
|
|
pub type Result<T> = std::result::Result<T, Error>;
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
|
|
#[test]
|
|
fn config_error_display() {
|
|
let err = ConfigError::MissingEnvVar("DATABASE_URL".to_string());
|
|
let msg = err.to_string();
|
|
assert!(
|
|
msg.contains("DATABASE_URL"),
|
|
"Should mention the variable name: {msg}"
|
|
);
|
|
|
|
let err = ConfigError::MissingRequired {
|
|
key: "llm.model".to_string(),
|
|
hint: "Set LLM_MODEL env var".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("llm.model"), "Should mention the key: {msg}");
|
|
assert!(
|
|
msg.contains("Set LLM_MODEL"),
|
|
"Should include the hint: {msg}"
|
|
);
|
|
|
|
let err = ConfigError::InvalidValue {
|
|
key: "port".to_string(),
|
|
message: "must be a number".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("port"), "Should mention the key: {msg}");
|
|
}
|
|
|
|
#[test]
|
|
fn database_error_display() {
|
|
let err = DatabaseError::NotFound {
|
|
entity: "conversation".to_string(),
|
|
id: "abc-123".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("conversation"), "Should mention entity: {msg}");
|
|
assert!(msg.contains("abc-123"), "Should mention id: {msg}");
|
|
|
|
let err = DatabaseError::Query("syntax error near SELECT".to_string());
|
|
assert!(err.to_string().contains("syntax error"));
|
|
}
|
|
|
|
#[test]
|
|
fn channel_error_display() {
|
|
let err = ChannelError::StartupFailed {
|
|
name: "telegram".to_string(),
|
|
reason: "invalid token".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("telegram"), "Should mention channel: {msg}");
|
|
assert!(
|
|
msg.contains("invalid token"),
|
|
"Should mention reason: {msg}"
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn job_error_display() {
|
|
let err = JobError::MaxJobsExceeded { max: 5 };
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("5"), "Should mention max: {msg}");
|
|
|
|
let id = Uuid::new_v4();
|
|
let err = JobError::NotFound { id };
|
|
let msg = err.to_string();
|
|
assert!(
|
|
msg.contains(&id.to_string()),
|
|
"Should mention job id: {msg}"
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn safety_error_display() {
|
|
let err = SafetyError::InjectionDetected {
|
|
pattern: "SYSTEM:".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("SYSTEM:"), "Should mention pattern: {msg}");
|
|
}
|
|
|
|
#[test]
|
|
fn workspace_error_display() {
|
|
let err = WorkspaceError::DocumentNotFound {
|
|
doc_type: "notes".to_string(),
|
|
user_id: "user1".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("notes"), "Should mention doc_type: {msg}");
|
|
assert!(msg.contains("user1"), "Should mention user_id: {msg}");
|
|
}
|
|
|
|
#[test]
|
|
fn routine_error_display() {
|
|
let err = RoutineError::InvalidCron {
|
|
reason: "bad format".to_string(),
|
|
};
|
|
let msg = err.to_string();
|
|
assert!(msg.contains("bad format"), "Should mention reason: {msg}");
|
|
}
|
|
|
|
#[test]
|
|
fn top_level_error_from_conversions() {
|
|
let config_err = ConfigError::MissingEnvVar("TEST".to_string());
|
|
let err: Error = config_err.into();
|
|
assert!(matches!(err, Error::Config(_)));
|
|
|
|
let db_err = DatabaseError::Query("test".to_string());
|
|
let err: Error = db_err.into();
|
|
assert!(matches!(err, Error::Database(_)));
|
|
|
|
let job_err = JobError::MaxJobsExceeded { max: 1 };
|
|
let err: Error = job_err.into();
|
|
assert!(matches!(err, Error::Job(_)));
|
|
|
|
let safety_err = SafetyError::ValidationFailed {
|
|
reason: "test".to_string(),
|
|
};
|
|
let err: Error = safety_err.into();
|
|
assert!(matches!(err, Error::Safety(_)));
|
|
}
|
|
}
|