Error Codes
AccordError variants (verbatim from errors.rs). Anchor numeric codes are sequential from the program's error base; reference by name.
Authority / timelock (ADR-0005)
| Code |
Message |
Raised by |
Unauthorized |
Signer is not the Subaccord authority. |
propose_subaccord_update |
ImmutableSubaccord |
Subaccord is immutable (authority == default). |
propose_subaccord_update |
TimelockNotElapsed |
Timelock has not elapsed yet. |
execute_subaccord_update |
NoPendingUpdate |
No pending update to execute. |
execute_subaccord_update |
Circuit breaker (ADR-0007)
| Code |
Message |
Raised by |
NotPauseAuthority |
Signer is not the pause authority. |
pause, propose_unpause |
AlreadyPaused |
Program is already paused. |
pause |
NotPaused |
Program is not paused. |
propose_unpause |
NoPendingUnpause |
No pending unpause to execute. |
execute_unpause |
UnpauseTimelockNotElapsed |
Unpause timelock has not elapsed yet. |
execute_unpause |
ProgramPaused |
Program is paused; this instruction is halted. |
stake, create_dispute, appeal |
Staking
| Code |
Message |
Raised by |
InsufficientStake |
Staked amount is below the Subaccord minimum. |
draw_seat |
StakeLocked |
Cannot unstake while active_draws > 0 (stake is frozen until drawn disputes settle). |
unstake |
InvalidAmount |
Amount must be greater than zero. |
stake, unstake, claim_appeal_refund |
InsufficientBalance |
Withdrawal exceeds the Juror's staked balance. |
unstake |
Pool economics (ADR-0029)
| Code |
Message |
Raised by |
FeeDominatesSlash |
Same-mint pool is fee-dominated: alpha_bps·min_stake/10_000 must cover MIN_SLASH_FEE_RATIO · fee_per_juror (split-mint pools are deliberately un-gated). |
create_subaccord, propose_subaccord_update, execute_subaccord_update |
Dispute intake
| Code |
Message |
Raised by |
InsufficientJurors |
Subaccord has fewer active distinct stakers than the required panel size. |
create_dispute, appeal |
InvalidOptions |
Dispute options are invalid (need 2..=MAX_OPTIONS). |
create_dispute (Plurality: 2..=8 options; Median: 0 — ADR-0025), create_subaccord |
InvalidState |
Dispute is not in the required state for this instruction. |
draw_seat, commit, reveal, finalize_round, finalize_dispute, appeal, claim_appeal_refund |
FeeMismatch |
Tendered fee does not match the required dispute fee (jurors_per_dispute * fee_per_juror). |
create_dispute |
The snapshot-era error codes (SnapshotNotFinalized, SnapshotVoided,
SnapshotChallengeWindowOpen, SnapshotChallengeWindowExpired,
FraudProofInvalid, TreeNotSorted, OmissionProofInvalid) are removed — the
juror-set root is canonical by construction, so there is no posted root, bond,
challenge window, or fraud proof (ADR-0012).
Draw / sortition (ADR-0012)
| Code |
Message |
Raised by |
DuplicateJuror |
Draw selected a duplicate Juror. |
draw_seat |
InvalidMembershipProof |
Juror Merkle membership/weight proof is invalid. |
stake, unstake, draw_seat, finalize_dispute, claim_appeal_refund |
InvalidPanelSize |
Number of juror memberships does not match the required panel size. |
draw_seat, finalize_dispute |
InflatedStake |
Drawn juror's live stake is below the frozen leaf's claim (inflation guard). |
draw_seat |
SortitionMismatch |
Submitted membership does not match the VRF-derived sortition selection. |
draw_seat |
VrfAlreadyCommitted |
VRF result already committed for this dispute. |
request_vrf, commit_vrf_callback |
VrfNotCommitted |
No VRF result committed for this dispute; call commit_vrf first. |
draw_seat |
Voting
| Code |
Message |
Raised by |
CommitAlreadyExists |
Juror has already committed. |
commit |
CommitMissing |
No commit to reveal for this Juror. |
reveal |
RevealMismatch |
Reveal does not match the committed hash. |
reveal |
CommitWindowClosed |
Commit window is closed. |
commit |
RevealWindowClosed |
Reveal window is closed. |
reveal |
NotDrawnJuror |
Signer is not a drawn Juror for this round. |
commit, reveal |
InvalidVote |
Revealed vote index is out of range. |
reveal — per aggregation (ADR-0025): Plurality vote ≥ num_options; Median vote == u64::MAX (sentinel reserved) |
AlreadyRevealed |
Juror has already revealed. |
reveal |
Appeals / finalization (ADR-0004)
| Code |
Message |
Raised by |
AppealWindowOpen |
Appeal window has not elapsed yet. |
finalize_dispute |
MaxAppealsReached |
Maximum appeals reached for this dispute. |
appeal |
MaxAppealsLimitExceeded |
Subaccord max_appeals exceeds the program ceiling. |
create_subaccord |
AppealWindowClosed |
Appeal window has closed; the dispute can only be finalized. |
appeal |
AppealWindowTooShort |
Appeal window is below the per-Subaccord floor (MIN_APPEAL_WINDOW_SECS). |
create_subaccord |
RoundNotFinalizable |
Round cannot be finalized yet (window not elapsed). |
finalize_round |
DisputeNotFinal |
Dispute is not in a finalizable state. |
(reserved) |
Attestation-gated Subaccords (ADR-0024)
| Code |
Message |
Raised by |
AttestationMissing |
Subaccord is credential-gated but no attestation account was provided. |
stake, prune_juror |
AttestationBindingPartial |
Credential and schema must be set together (both-or-neither). |
create_subaccord |
AttestationMalformed |
Attestation account is malformed (wrong owner, discriminator, or too short). |
stake, draw_seat, prune_juror |
AttestationMismatch |
Attestation credential or schema does not match the Subaccord binding. |
stake, draw_seat, prune_juror |
AttestationSubjectMismatch |
Attestation subject wallet does not match the juror. |
stake, draw_seat, prune_juror |
AttestationExpired |
Attestation has expired or will expire before the dispute lifecycle completes. |
stake, draw_seat |
AttestationNotExpired |
Attestation has not expired; prune_juror requires an actually-expired credential. |
prune_juror |
Arithmetic
| Code |
Message |
Raised by |
ArithmeticOverflow |
Arithmetic overflow. |
any handler doing checked_* math |