influxdata/influxdb · error · UnknownSystemResourceError

unknown system resource identifier

Error message

unknown system resource identifier

What it means

UnknownSystemResourceError is returned by TryFrom<SystemResourceIdentifier> for SystemResource when the identifier's bitmap does not correspond to any known SystemResource variant. Unlike the Display panic, this is a checked conversion returning a proper typed error.

Solutions

  1. Handle the TryFrom error explicitly and skip/log the unrecognized resource instead of assuming success.
  2. Match the data's schema version with a binary that defines all SystemResource variants in use.
  3. Clean up stored role/permission records containing unknown identifiers.

Example fix

// before
let res = SystemResource::try_from(id).unwrap();
// after
match SystemResource::try_from(id) {
    Ok(res) => /* ... */,
    Err(UnknownSystemResourceError) => eprintln!("skipping unknown resource {id:?}"),
}
Defensive patterns

Strategy: try-catch

Validate before calling

fn is_known_system_resource(id: SystemResourceIdentifier, known: &[SystemResourceIdentifier]) -> bool {
    known.contains(&id)
}

Type guard

fn try_system_resource(id: SystemResourceIdentifier) -> Option<SystemResource> {
    SystemResource::try_from(id).ok()
}

Try / catch

match SystemResource::try_from(id) {
    Ok(res) => handle(res),
    Err(UnknownSystemResourceError) => log::warn!("unknown system resource identifier {id:?}; skipping"),
}

Prevention

When it happens

Trigger: Calling SystemResource::try_from(id) with a SystemResourceIdentifier whose bits match no SystemResource variant — typically from role/permission data carrying unknown resource bits.

Common situations: Reading role definitions persisted by a newer InfluxDB 3 version with additional system resources; bit-corrupted identifiers; manually constructed bitmap values.

Understand the failure class

Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/7b6e4f594a7643a6. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/role/actions.rs:86

#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
pub enum SystemAction {
    Read,
}

/// The set of system resources whose access is mediated by the `system` ABAC
/// resource type.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
pub enum SystemResource {
    Health,
    Metrics,
    Ping,
    Ready,
}

/// Error returned when converting from a `SystemResourceIdentifier` bitmap value
/// that does not correspond to a known [`SystemResource`] variant.
#[derive(Debug, Clone, Copy, thiserror::Error)]
#[error("unknown system resource identifier")]
pub struct UnknownSystemResourceError;

impl TryFrom<SystemResourceIdentifier> for SystemResource {
    type Error = UnknownSystemResourceError;

    fn try_from(id: SystemResourceIdentifier) -> Result<Self, Self::Error> {
        match id.as_u16() {
            SystemResourceIdentifier::HEALTH => Ok(SystemResource::Health),
            SystemResourceIdentifier::METRICS => Ok(SystemResource::Metrics),
            SystemResourceIdentifier::PING => Ok(SystemResource::Ping),
            SystemResourceIdentifier::READY => Ok(SystemResource::Ready),
            _ => Err(UnknownSystemResourceError),
        }
    }
}

impl SystemAction {
    pub fn from_bitmap(bits: SystemActions) -> Vec<SystemAction> {

View on GitHub (pinned to 06200ef96b)