{"record":{"id":"49c8fd05d3c6fdaf","repo":"influxdata/influxdb","slug":"unrecognized-system-resource-identifier","errorCode":null,"errorMessage":"unrecognized system resource identifier","messagePattern":"unrecognized system resource identifier","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"influxdb3_authz/src/permissions.rs","lineNumber":228,"sourceCode":"        self.0\n    }\n\n    pub fn name(&self) -> Option<&'static str> {\n        match self.0 {\n            Self::HEALTH => Some(Self::HEALTH_NAME),\n            Self::METRICS => Some(Self::METRICS_NAME),\n            Self::PING => Some(Self::PING_NAME),\n            Self::READY => Some(Self::READY_NAME),\n            _ => None,\n        }\n    }\n}\n\nimpl Display for SystemResourceIdentifier {\n    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {\n        let Some(stringified) = self.name() else {\n            error!(identifier = ?self.0, \"cannot map system resource identifier\");\n            panic!(\"unrecognized system resource identifier\")\n        };\n        write!(f, \"{stringified}\")\n    }\n}\n\nimpl From<u16> for SystemResourceIdentifier {\n    fn from(value: u16) -> Self {\n        SystemResourceIdentifier(value)\n    }\n}\n\n#[derive(Debug, Clone, Copy, Default)]\npub struct PermissionAttributes {\n    actions: ActionsBitmap,\n}\n\nimpl PermissionAttributes {\n    pub fn new(actions: ActionsBitmap) -> Self {","sourceCodeStart":210,"sourceCodeEnd":246,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/permissions.rs#L210-L246","documentation":"A panic raised in Display for SystemResourceIdentifier when name() returns None, i.e. the internal bitmap value does not map to any known system resource identifier. This is an internal invariant violation: Display formatting assumes every identifier is mappable, so the code panics instead of returning an error.","triggerScenarios":"Formatting a SystemResourceIdentifier whose u16 bitmap contains bits that no SystemResource variant corresponds to — e.g. a bitmap built from unrecognized/combined flags or from a newer schema than this binary understands.","commonSituations":"Loading token/permission data persisted by a newer InfluxDB 3 version that defines system resources this binary does not know; corrupted bitmaps in stored permissions.","solutions":["Inspect the logged identifier (error! with identifier = ?self.0) to see the bad bitmap value.","Align versions: use a binary of influxdb3 that knows all system resources present in the stored data.","Replace with non-panicking handling: change name()/Display to return a Result or fall back to printing the raw number."],"exampleFix":"// before\npanic!(\"unrecognized system resource identifier\")\n// after\nreturn write!(f, \"unrecognized({:#06x})\", self.0.bits());","handlingStrategy":"try-catch","validationCode":"fn is_known_identifier(bits: u16, known: &[u16]) -> bool { known.contains(&bits) }","typeGuard":"fn as_known_system_resource(bits: u16) -> Option<SystemResourceIdentifier> {\n    SystemResourceIdentifier::from_bits(bits).filter(|id| id.name().is_some())\n}","tryCatchPattern":"// Display panics; avoid it for untrusted identifiers:\nmatch id.name() {\n    Some(n) => println!(\"{n}\"),\n    None => eprintln!(\"unknown system resource identifier bits={:#06x}\", id.bits()),\n}","preventionTips":["Never format identifiers from data written by a newer schema version without validating bits first","Prefer try_from/checked conversion over Display for untrusted input","Run migrations when upgrading binaries across versions with new system resources"],"tags":["panic","authz","invariant"],"backgroundTag":"internal-invariant-violation","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}