std::failureFailure-philosophy stdlib types for lifecycle hooks.
Import std.failure to name CrashInfo or CrashAction explicitly
in a #[on(crash)] hook's signature. The hook observes the actor's last
valid state after its handlers drain and chooses the supervisor's recovery
action. Actor state is released after the hook returns.
CrashInfo carries code + messagecode is an opaque integer discriminator the runtime sets per crash
class (arena exhaustion, link-cascade, explicit panic, …). message
is a heap-owned diagnostic string the runtime supplies (empty when no
message is available); a crash hook can log or route on it.
CrashInfoDiagnostic payload passed to #[on(crash)] hooks.
The integer code discriminates crash classes; the runtime sets it
before invoking on_crash. message carries a heap-owned diagnostic
string (empty when unavailable). Hooks may match on code to decide a
CrashAction, but the canonical reading is "any non-zero code is a
real fault — the hook's job is to choose between Restart, Escalate,
and GiveUp".
CrashActionRecovery action returned by a #[on(crash)] hook.
Restart: apply the child's ordinary restart policy, budget and circuit
breaker. A temporary child is not restarted.Escalate: transfer the failure to the parent supervisor instead of
restarting locally. At the root the failure remains unrecovered.GiveUp: permanently spend the child's role and leave the failure
unrecovered.RestartEscalateGiveUpCrashNotificationIdentity + class of a crash that propagated to a linked actor.
Delivered to a linked actor's #[on(link)] hook
hook when an actor this one is linked to crashes. Carries the
crashed actor's identity and the class of crash — nothing else.
WHY (shape): the linked actor must not gain access to the crashed
actor's CrashInfo payload (signal number, fault address); cross-
actor visibility into another actor's fault details would couple
linked actors to each other's failure internals. Identity + class
is sufficient for supervisor-style decisions ("the upstream link
died, drop this work item and re-establish").
The runtime
(hew-runtime/src/link.rs.propagate_exit_to_links enqueues
HewSysMsg.Exit in the linked actor's mailbox at the crashed actor's
teardown phase, before any supervisor restart decision). The user-
facing hook receives this notification on a linked actor's crash.
WHAT (v0.5 shape, integer-tag only per Q45/A22): actor_id carries the
crashed actor's id as a raw u64. Future widening to a typed
An actor handle requires the linked actor to know A's static type — a
generics-and-trait-bound enhancement deferred until the spine
supports it.
Numeric identity of the actor that crashed. Raw u64 rather
than an actor handle because the linked actor does not in general
know the crashed actor's static type at the hook site.
Class of the originating crash. Mirrors the runtime crash discriminator the supervisor receives.
CrashKindClass of a crash propagated to a linked actor.
Mirrors the runtime trap discriminator at the integer-tag level. Adding a variant here requires a matching variant on the runtime side; the converse is not true — the runtime may carry reason discriminators that are not surfaced to linked actors when the conservative-default tenet says they should remain private to the crashed actor and its supervisor.
v0.5 enumerates only the classes the runtime currently distinguishes at the link-cascade boundary. Future v0.5.x / v0.6 expansions are additive.
FaultGeneric crash from panic(...), hew_panic(), or an
unclassified trap (SEGV / BUS / FPE / ILL / TRAP).
HeapExceededPer-actor arena cap exceeded.
PartitionDetectedA pipe / mailbox partition was observed on a recv path the crashed actor was awaiting.