Module std::failure

Failure-philosophy stdlib types for lifecycle hooks.

Import std.failure to name CrashInfo or CrashAction explicitly in a #[on(crash)] hook's signature. The hook observes the actor's last valid state after its handlers drain and chooses the supervisor's recovery action. Actor state is released after the hook returns.

CrashInfo carries code + message

code is an opaque integer discriminator the runtime sets per crash class (arena exhaustion, link-cascade, explicit panic, …). message is a heap-owned diagnostic string the runtime supplies (empty when no message is available); a crash hook can log or route on it.

Contents

Types

Struct CrashInfo

Diagnostic payload passed to #[on(crash)] hooks.

The integer code discriminates crash classes; the runtime sets it before invoking on_crash. message carries a heap-owned diagnostic string (empty when unavailable). Hooks may match on code to decide a CrashAction, but the canonical reading is "any non-zero code is a real fault — the hook's job is to choose between Restart, Escalate, and GiveUp".

Fields

code: i64
message: string

Enum CrashAction

Recovery action returned by a #[on(crash)] hook.

Variants

Restart
Escalate
GiveUp

Struct CrashNotification

Identity + class of a crash that propagated to a linked actor.

Delivered to a linked actor's #[on(link)] hook hook when an actor this one is linked to crashes. Carries the crashed actor's identity and the class of crash — nothing else.

WHY (shape): the linked actor must not gain access to the crashed actor's CrashInfo payload (signal number, fault address); cross- actor visibility into another actor's fault details would couple linked actors to each other's failure internals. Identity + class is sufficient for supervisor-style decisions ("the upstream link died, drop this work item and re-establish").

The runtime (hew-runtime/src/link.rs.propagate_exit_to_links enqueues HewSysMsg.Exit in the linked actor's mailbox at the crashed actor's teardown phase, before any supervisor restart decision). The user- facing hook receives this notification on a linked actor's crash.

WHAT (v0.5 shape, integer-tag only per Q45/A22): actor_id carries the crashed actor's id as a raw u64. Future widening to a typed An actor handle requires the linked actor to know A's static type — a generics-and-trait-bound enhancement deferred until the spine supports it.

Fields

actor_id: u64

Numeric identity of the actor that crashed. Raw u64 rather than an actor handle because the linked actor does not in general know the crashed actor's static type at the hook site.

kind: CrashKind

Class of the originating crash. Mirrors the runtime crash discriminator the supervisor receives.

Enum CrashKind

Class of a crash propagated to a linked actor.

Mirrors the runtime trap discriminator at the integer-tag level. Adding a variant here requires a matching variant on the runtime side; the converse is not true — the runtime may carry reason discriminators that are not surfaced to linked actors when the conservative-default tenet says they should remain private to the crashed actor and its supervisor.

v0.5 enumerates only the classes the runtime currently distinguishes at the link-cascade boundary. Future v0.5.x / v0.6 expansions are additive.

Variants

Fault

Generic crash from panic(...), hew_panic(), or an unclassified trap (SEGV / BUS / FPE / ILL / TRAP).

HeapExceeded

Per-actor arena cap exceeded.

PartitionDetected

A pipe / mailbox partition was observed on a recv path the crashed actor was awaiting.