BoundaryML/baml · error

Insufficient permissions to perform this operation

Error message

Insufficient permissions to perform this operation: {:?} < {:?}

What it means

TypeBuilder nodes carry a NodeRW permission level (ReadOnly vs ReadWrite). before mutating a builder node, at_least() checks the current mode grants at least the required access. Calling a mutating method on a builder that was placed in ReadOnly mode fails with this permission error.

Solutions

  1. Obtain the builder in ReadWrite mode (e.g. via tb.add_class / tb.add_enum / tb.class(...) with write access) before mutating
  2. Remove any explicit mode(NodeRW::ReadOnly) call on builders you intend to mutate
  3. If you only need to read, avoid calling mutating methods on read-only builders

Example fix

// before
let b = tb.class(rt, "Foo")?.mode(NodeRW::ReadOnly);
b.add_property(rt, "x", ...)?; // fails: insufficient permissions
// after
let b = tb.class(rt, "Foo")?.mode(NodeRW::ReadWrite);
b.add_property(rt, "x", ...)?;
Defensive patterns

Strategy: validation

Validate before calling

// check mode before mutating
if builder.mode_level() < NodeRW::ReadWrite {
    builder = builder.mode(NodeRW::ReadWrite);
}

Type guard

fn is_writable(mode: &NodeRW) -> bool { matches!(mode, NodeRW::ReadWrite) }

Try / catch

match builder.add_property(rt, "x", ty) {
    Ok(p) => ...,
    Err(e) if e.to_string().contains("Insufficient permissions") => {
        let builder = builder.mode(NodeRW::ReadWrite);
        builder.add_property(rt, "x", ty)?;
    }
    Err(e) => return Err(e),
}

Prevention

When it happens

Trigger: Calling a mutating method (add_property, set_alias, set_description, etc.) on a ClassBuilder/EnumBuilder/TypeBuilder that was obtained or set to ReadOnly mode, e.g. a builder fetched for reading then used to modify.

Common situations: Fetching a type builder from the runtime IR (read-only context) and then attempting to mutate it; Builder::mode(NodeRW::ReadOnly) followed by an add_* call; using a stale builder whose mode was downgraded.

Understand the failure class

Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.

Related errors


AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12). Data as JSON: /api/errors/e612768ca332cc41. Report an issue: GitHub.

Appendix: source

Thrown at engine/language_client_cffi/src/raw_ptr_wrapper/type_builder/objects.rs:22

};
use baml_types::{BamlValue, TypeIR};

type RuntimeTypeBuilder = std::sync::Arc<_RuntimeTypeBuilder>;

#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord)]
enum NodeRW {
    // Only view the data (no modifications allowed)
    ReadOnly,
    // View data, but can modify attributes like alias / description
    LLMOnly,
    // Go wild
    ReadWrite,
}

impl NodeRW {
    fn at_least(&self, other: NodeRW) -> anyhow::Result<()> {
        if self < &other {
            anyhow::bail!(
                "Insufficient permissions to perform this operation: {:?} < {:?}",
                self,
                other
            );
        }
        Ok(())
    }
}

#[cfg(test)]
mod tests {
    use super::*;

    #[test]
    fn test_node_rw_at_least() {
        assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadOnly).is_ok());
        assert!(NodeRW::ReadOnly.at_least(NodeRW::LLMOnly).is_err());
        assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadWrite).is_err());

View on GitHub (pinned to bd85ce9dee)