influxdata/influxdb · error · UnknownSystemResourceError
unknown system resource identifier
Error message
unknown system resource identifier
What it means
UnknownSystemResourceError is returned by TryFrom<SystemResourceIdentifier> for SystemResource when the identifier's bitmap does not correspond to any known SystemResource variant. Unlike the Display panic, this is a checked conversion returning a proper typed error.
Solutions
- Handle the TryFrom error explicitly and skip/log the unrecognized resource instead of assuming success.
- Match the data's schema version with a binary that defines all SystemResource variants in use.
- Clean up stored role/permission records containing unknown identifiers.
Example fix
// before
let res = SystemResource::try_from(id).unwrap();
// after
match SystemResource::try_from(id) {
Ok(res) => /* ... */,
Err(UnknownSystemResourceError) => eprintln!("skipping unknown resource {id:?}"),
} Defensive patterns
Strategy: try-catch
Validate before calling
fn is_known_system_resource(id: SystemResourceIdentifier, known: &[SystemResourceIdentifier]) -> bool {
known.contains(&id)
} Type guard
fn try_system_resource(id: SystemResourceIdentifier) -> Option<SystemResource> {
SystemResource::try_from(id).ok()
} Try / catch
match SystemResource::try_from(id) {
Ok(res) => handle(res),
Err(UnknownSystemResourceError) => log::warn!("unknown system resource identifier {id:?}; skipping"),
} Prevention
- Always handle the TryFrom error rather than unwrapping
- Migrate stored role data when upgrading to versions with new SystemResource variants
- Log and skip unknown identifiers instead of aborting batch operations
When it happens
Trigger: Calling SystemResource::try_from(id) with a SystemResourceIdentifier whose bits match no SystemResource variant — typically from role/permission data carrying unknown resource bits.
Common situations: Reading role definitions persisted by a newer InfluxDB 3 version with additional system resources; bit-corrupted identifiers; manually constructed bitmap values.
Understand the failure class
Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.
Related errors
- role name cannot be empty
- action not supported
- Error converting max_columns_per_table
- Error converting max_tables
- failed to construct IOx parquet metadata
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/7b6e4f594a7643a6.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/role/actions.rs:86
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
pub enum SystemAction {
Read,
}
/// The set of system resources whose access is mediated by the `system` ABAC
/// resource type.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
pub enum SystemResource {
Health,
Metrics,
Ping,
Ready,
}
/// Error returned when converting from a `SystemResourceIdentifier` bitmap value
/// that does not correspond to a known [`SystemResource`] variant.
#[derive(Debug, Clone, Copy, thiserror::Error)]
#[error("unknown system resource identifier")]
pub struct UnknownSystemResourceError;
impl TryFrom<SystemResourceIdentifier> for SystemResource {
type Error = UnknownSystemResourceError;
fn try_from(id: SystemResourceIdentifier) -> Result<Self, Self::Error> {
match id.as_u16() {
SystemResourceIdentifier::HEALTH => Ok(SystemResource::Health),
SystemResourceIdentifier::METRICS => Ok(SystemResource::Metrics),
SystemResourceIdentifier::PING => Ok(SystemResource::Ping),
SystemResourceIdentifier::READY => Ok(SystemResource::Ready),
_ => Err(UnknownSystemResourceError),
}
}
}
impl SystemAction {
pub fn from_bitmap(bits: SystemActions) -> Vec<SystemAction> {View on GitHub (pinned to 06200ef96b)