{"record":{"id":"e612768ca332cc41","repo":"BoundaryML/baml","slug":"insufficient-permissions-to-perform-this-operation","errorCode":null,"errorMessage":"Insufficient permissions to perform this operation: {:?} < {:?}","messagePattern":"Insufficient permissions to perform this operation: (.+?) < (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"engine/language_client_cffi/src/raw_ptr_wrapper/type_builder/objects.rs","lineNumber":22,"sourceCode":"};\nuse baml_types::{BamlValue, TypeIR};\n\ntype RuntimeTypeBuilder = std::sync::Arc<_RuntimeTypeBuilder>;\n\n#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord)]\nenum NodeRW {\n    // Only view the data (no modifications allowed)\n    ReadOnly,\n    // View data, but can modify attributes like alias / description\n    LLMOnly,\n    // Go wild\n    ReadWrite,\n}\n\nimpl NodeRW {\n    fn at_least(&self, other: NodeRW) -> anyhow::Result<()> {\n        if self < &other {\n            anyhow::bail!(\n                \"Insufficient permissions to perform this operation: {:?} < {:?}\",\n                self,\n                other\n            );\n        }\n        Ok(())\n    }\n}\n\n#[cfg(test)]\nmod tests {\n    use super::*;\n\n    #[test]\n    fn test_node_rw_at_least() {\n        assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadOnly).is_ok());\n        assert!(NodeRW::ReadOnly.at_least(NodeRW::LLMOnly).is_err());\n        assert!(NodeRW::ReadOnly.at_least(NodeRW::ReadWrite).is_err());","sourceCodeStart":4,"sourceCodeEnd":40,"githubUrl":"https://github.com/BoundaryML/baml/blob/bd85ce9dee1463ff04d27efd20531013a4ff46c1/engine/language_client_cffi/src/raw_ptr_wrapper/type_builder/objects.rs#L4-L40","documentation":"TypeBuilder nodes carry a NodeRW permission level (ReadOnly vs ReadWrite). before mutating a builder node, at_least() checks the current mode grants at least the required access. Calling a mutating method on a builder that was placed in ReadOnly mode fails with this permission error.","triggerScenarios":"Calling a mutating method (add_property, set_alias, set_description, etc.) on a ClassBuilder/EnumBuilder/TypeBuilder that was obtained or set to ReadOnly mode, e.g. a builder fetched for reading then used to modify.","commonSituations":"Fetching a type builder from the runtime IR (read-only context) and then attempting to mutate it; Builder::mode(NodeRW::ReadOnly) followed by an add_* call; using a stale builder whose mode was downgraded.","solutions":["Obtain the builder in ReadWrite mode (e.g. via tb.add_class / tb.add_enum / tb.class(...) with write access) before mutating","Remove any explicit mode(NodeRW::ReadOnly) call on builders you intend to mutate","If you only need to read, avoid calling mutating methods on read-only builders"],"exampleFix":"// before\nlet b = tb.class(rt, \"Foo\")?.mode(NodeRW::ReadOnly);\nb.add_property(rt, \"x\", ...)?; // fails: insufficient permissions\n// after\nlet b = tb.class(rt, \"Foo\")?.mode(NodeRW::ReadWrite);\nb.add_property(rt, \"x\", ...)?;","handlingStrategy":"validation","validationCode":"// check mode before mutating\nif builder.mode_level() < NodeRW::ReadWrite {\n    builder = builder.mode(NodeRW::ReadWrite);\n}","typeGuard":"fn is_writable(mode: &NodeRW) -> bool { matches!(mode, NodeRW::ReadWrite) }","tryCatchPattern":"match builder.add_property(rt, \"x\", ty) {\n    Ok(p) => ...,\n    Err(e) if e.to_string().contains(\"Insufficient permissions\") => {\n        let builder = builder.mode(NodeRW::ReadWrite);\n        builder.add_property(rt, \"x\", ty)?;\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Only set ReadOnly mode on builders you never mutate","Default to ReadWrite when constructing builders for modification","Do not share a single builder instance between read-only and write code paths"],"tags":["permissions","type-builder","read-only","rust"],"backgroundTag":"insufficient-permissions","analyzedSha":"bd85ce9dee1463ff04d27efd20531013a4ff46c1","analyzedAt":"2026-09-12T03:38:25.718Z","contentChangedAt":"2026-09-12T03:38:25.718Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}