{"record":{"id":"e769e85e17912206","repo":"Hmbown/CodeWhale","slug":"cannot-parse-exactly-one-rust-trusted-keys-table","errorCode":null,"errorMessage":"cannot parse exactly one Rust TRUSTED_KEYS table","messagePattern":"cannot parse exactly one Rust TRUSTED_KEYS table","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"web/scripts/check-cloud-facts.mjs","lineNumber":14,"sourceCode":"#!/usr/bin/env node\n/** Local source, release, pinned-key parity and public-fixture gate. */\nimport { dirname, resolve } from \"node:path\";\nimport { fileURLToPath } from \"node:url\";\nimport { validateSource, verifyEnvelope, parseTsKeys, validateTrustedKeys, readBoundedFile } from \"./facts-publish.mjs\";\n\nconst WEB_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), \"..\");\nconst REPO_ROOT = resolve(WEB_ROOT, \"..\");\nexport { parseTsKeys };\n\nexport function parseRustKeys(text) {\n  const source = text.replace(/\\/\\*[\\s\\S]*?\\*\\//g, \"\").replace(/^\\s*\\/\\/.*$/gm, \"\");\n  const tables = [...source.matchAll(/^\\s*pub\\s+const\\s+TRUSTED_KEYS\\s*:\\s*&\\s*\\[TrustedKey\\]\\s*=\\s*&\\s*\\[([\\s\\S]*?)\\]\\s*;/gm)];\n  if (tables.length !== 1) throw new Error(\"cannot parse exactly one Rust TRUSTED_KEYS table\");\n  const table = tables[0];\n  const body = table[1].replace(/^\\s*\\/\\/.*$/gm, \"\");\n  const keys = [];\n  const remainder = body.replace(/TrustedKey\\s*\\{\\s*key_id:\\s*\"([^\"]+)\",\\s*public_key:\\s*\\[([^\\]]*)\\],\\s*status:\\s*KeyStatus::(Active|Retired)\\s*,?\\s*\\}/g, (_, keyId, encoded, status) => {\n    const pieces = encoded.split(\",\").map((piece) => piece.trim()).filter(Boolean);\n    if (pieces.length !== 32 || pieces.some((piece) => !/^(?:\\d+|0x[0-9a-fA-F]+)$/.test(piece))) throw new Error(\"Rust public key must contain 32 literal bytes\");\n    const bytes = pieces.map(Number);\n    if (bytes.some((byte) => !Number.isInteger(byte) || byte < 0 || byte > 255)) throw new Error(\"Rust public key byte out of range\");\n    keys.push({ keyId, publicKey: Buffer.from(bytes).toString(\"base64\"), status: status.toLowerCase() });\n    return \"\";\n  });\n  if (remainder.replace(/[\\s,]/g, \"\")) throw new Error(\"unparsed Rust TRUSTED_KEYS entry\");\n  return validateTrustedKeys(keys);\n}\n\nfunction text(path) { return readBoundedFile(path).toString(\"utf8\"); }\nfunction json(path) { return JSON.parse(text(path)); }\n","sourceCodeStart":1,"sourceCodeEnd":32,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/web/scripts/check-cloud-facts.mjs#L1-L32","documentation":"parseRustKeys() extracts the single `pub const TRUSTED_KEYS: &[TrustedKey] = &[...]` table from Rust source via regex. It throws when the regex matches zero or more than one table, because the checker assumes exactly one canonical trusted-keys table to diff against the TypeScript facts.","triggerScenarios":"The Rust constant was renamed, its type/signature reformatted (e.g. `&[TrustedKey; N]` or `static` instead of `pub const`), moved into a module not included in the scanned text, duplicated, or removed.","commonSituations":"A refactor changed `pub const TRUSTED_KEYS: &[TrustedKey]` to a new declaration style; a second table was accidentally added; the script reads the wrong file so it sees zero tables.","solutions":["Grep the Rust source for `TRUSTED_KEYS` and confirm exactly one `pub const ... : &[TrustedKey] = &[...]` declaration exists.","Restore the canonical declaration form the regex expects (pub const, &[TrustedKey] type, &[...] initializer, semicolon).","If the table legitimately moved, update the script to read the correct file/path.","If a second table was added by mistake, delete it."],"exampleFix":"// before (Rust)\nstatic TRUSTED_KEYS: &[TrustedKey] = &[ ... ];\n// after\npub const TRUSTED_KEYS: &[TrustedKey] = &[ ... ];","handlingStrategy":"validation","validationCode":"const count = (src.match(/pub\\s+const\\s+TRUSTED_KEYS\\s*:\\s*&\\s*\\[TrustedKey\\]/g) || []).length; if (count !== 1) throw new Error(`expected 1 TRUSTED_KEYS table, found ${count}`);","typeGuard":null,"tryCatchPattern":"try { parseRustKeys(src); } catch (e) { if (e.message.includes(\"exactly one\")) grepForTrustedKeysDeclaration(); throw e; }","preventionTips":["Keep the TRUSTED_KEYS declaration in the canonical form; lint for it.","Update the checker in the same PR as any declaration refactor.","Grep for TRUSTED_KEYS after renames/moves.","Add a CI check that runs the parser so drift is caught immediately."],"tags":["parsing","rust","regex","build-check"],"backgroundTag":"internal-invariant-violation","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}