{"record":{"id":"7b6e4f594a7643a6","repo":"influxdata/influxdb","slug":"unknown-system-resource-identifier","errorCode":null,"errorMessage":"unknown system resource identifier","messagePattern":"unknown system resource identifier","errorType":"error_code","errorClass":"UnknownSystemResourceError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/role/actions.rs","lineNumber":86,"sourceCode":"#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]\npub enum SystemAction {\n    Read,\n}\n\n/// The set of system resources whose access is mediated by the `system` ABAC\n/// resource type.\n#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]\npub enum SystemResource {\n    Health,\n    Metrics,\n    Ping,\n    Ready,\n}\n\n/// Error returned when converting from a `SystemResourceIdentifier` bitmap value\n/// that does not correspond to a known [`SystemResource`] variant.\n#[derive(Debug, Clone, Copy, thiserror::Error)]\n#[error(\"unknown system resource identifier\")]\npub struct UnknownSystemResourceError;\n\nimpl TryFrom<SystemResourceIdentifier> for SystemResource {\n    type Error = UnknownSystemResourceError;\n\n    fn try_from(id: SystemResourceIdentifier) -> Result<Self, Self::Error> {\n        match id.as_u16() {\n            SystemResourceIdentifier::HEALTH => Ok(SystemResource::Health),\n            SystemResourceIdentifier::METRICS => Ok(SystemResource::Metrics),\n            SystemResourceIdentifier::PING => Ok(SystemResource::Ping),\n            SystemResourceIdentifier::READY => Ok(SystemResource::Ready),\n            _ => Err(UnknownSystemResourceError),\n        }\n    }\n}\n\nimpl SystemAction {\n    pub fn from_bitmap(bits: SystemActions) -> Vec<SystemAction> {","sourceCodeStart":68,"sourceCodeEnd":104,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/role/actions.rs#L68-L104","documentation":"UnknownSystemResourceError is returned by TryFrom<SystemResourceIdentifier> for SystemResource when the identifier's bitmap does not correspond to any known SystemResource variant. Unlike the Display panic, this is a checked conversion returning a proper typed error.","triggerScenarios":"Calling SystemResource::try_from(id) with a SystemResourceIdentifier whose bits match no SystemResource variant — typically from role/permission data carrying unknown resource bits.","commonSituations":"Reading role definitions persisted by a newer InfluxDB 3 version with additional system resources; bit-corrupted identifiers; manually constructed bitmap values.","solutions":["Handle the TryFrom error explicitly and skip/log the unrecognized resource instead of assuming success.","Match the data's schema version with a binary that defines all SystemResource variants in use.","Clean up stored role/permission records containing unknown identifiers."],"exampleFix":"// before\nlet res = SystemResource::try_from(id).unwrap();\n// after\nmatch SystemResource::try_from(id) {\n    Ok(res) => /* ... */,\n    Err(UnknownSystemResourceError) => eprintln!(\"skipping unknown resource {id:?}\"),\n}","handlingStrategy":"try-catch","validationCode":"fn is_known_system_resource(id: SystemResourceIdentifier, known: &[SystemResourceIdentifier]) -> bool {\n    known.contains(&id)\n}","typeGuard":"fn try_system_resource(id: SystemResourceIdentifier) -> Option<SystemResource> {\n    SystemResource::try_from(id).ok()\n}","tryCatchPattern":"match SystemResource::try_from(id) {\n    Ok(res) => handle(res),\n    Err(UnknownSystemResourceError) => log::warn!(\"unknown system resource identifier {id:?}; skipping\"),\n}","preventionTips":["Always handle the TryFrom error rather than unwrapping","Migrate stored role data when upgrading to versions with new SystemResource variants","Log and skip unknown identifiers instead of aborting batch operations"],"tags":["authz","roles","conversion"],"backgroundTag":"invalid-enum-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}