BoundaryML/baml · error
Insufficient permissions to perform this operation
Error message
Insufficient permissions to perform this operation: {:?} < {:?} What it means
TypeBuilder nodes carry a NodeRW permission level (ReadOnly vs ReadWrite). before mutating a builder node, at_least() checks the current mode grants at least the required access. Calling a mutating method on a builder that was placed in ReadOnly mode fails with this permission error.
Solutions
- Obtain the builder in ReadWrite mode (e.g. via tb.add_class / tb.add_enum / tb.class(...) with write access) before mutating
- Remove any explicit mode(NodeRW::ReadOnly) call on builders you intend to mutate
- If you only need to read, avoid calling mutating methods on read-only builders
Example fix
// before let b = tb.class(rt, "Foo")?.mode(NodeRW::ReadOnly); b.add_property(rt, "x", ...)?; // fails: insufficient permissions // after let b = tb.class(rt, "Foo")?.mode(NodeRW::ReadWrite); b.add_property(rt, "x", ...)?;
Defensive patterns
Strategy: validation
Validate before calling
// check mode before mutating
if builder.mode_level() < NodeRW::ReadWrite {
builder = builder.mode(NodeRW::ReadWrite);
} Type guard
fn is_writable(mode: &NodeRW) -> bool { matches!(mode, NodeRW::ReadWrite) } Try / catch
match builder.add_property(rt, "x", ty) {
Ok(p) => ...,
Err(e) if e.to_string().contains("Insufficient permissions") => {
let builder = builder.mode(NodeRW::ReadWrite);
builder.add_property(rt, "x", ty)?;
}
Err(e) => return Err(e),
} Prevention
- Only set ReadOnly mode on builders you never mutate
- Default to ReadWrite when constructing builders for modification
- Do not share a single builder instance between read-only and write code paths
When it happens
Trigger: Calling a mutating method (add_property, set_alias, set_description, etc.) on a ClassBuilder/EnumBuilder/TypeBuilder that was obtained or set to ReadOnly mode, e.g. a builder fetched for reading then used to modify.
Common situations: Fetching a type builder from the runtime IR (read-only context) and then attempting to mutate it; Builder::mode(NodeRW::ReadOnly) followed by an add_* call; using a stale builder whose mode was downgraded.
Understand the failure class
Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.
Related errors
- attempted to read a property that has no defined type, this…
- Class not found
- Enum not found
- Enum value already exists
- Enum value not found
AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12).
Data as JSON: /api/errors/e612768ca332cc41.
Report an issue: GitHub.
Appendix: source
Thrown at engine/language_client_cffi/src/raw_ptr_wrapper/type_builder/objects.rs:22
};
use baml_types::{BamlValue, TypeIR};
type RuntimeTypeBuilder = std::sync::Arc<_RuntimeTypeBuilder>;
#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord)]
enum NodeRW {
// Only view the data (no modifications allowed)
ReadOnly,
// View data, but can modify attributes like alias / description
LLMOnly,
// Go wild
ReadWrite,
}
impl NodeRW {
fn at_least(&self, other: NodeRW) -> anyhow::Result<()> {
if self < &other {
anyhow::bail!(
"Insufficient permissions to perform this operation: {:?} < {:?}",
self,
other
);
}
Ok(())
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn test_node_rw_at_least() {
assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadOnly).is_ok());
assert!(NodeRW::ReadOnly.at_least(NodeRW::LLMOnly).is_err());
assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadWrite).is_err());View on GitHub (pinned to bd85ce9dee)