QueryViolation
The error catalog (design §5.9): every rule a query can break, as structured facts. Each violation names its stable code, renders its message from its facts, and belongs to a Kind that decides the error it becomes (rejection): the one place a rejection is rendered. Codes are a contract (added, never renamed); texts are not.
Server faults (a failing mask strategy, a result that breaks integrity, a storage that timed out) are not violations: they are me.ahoo.wow.query.QueryExecutionExceptions.
Inheritors
Types
EQ / NE on field names an array operand, and the storage cannot compare a whole array.
A counting query (count, paged total) matches every record, and the entry does not allow expensive operators.
A cursor sort names field twice once the identity tie-breaker is appended.
A cursor sort has more than max fields once the identity tie-breaker is appended.
Two sort fields (field is the later one) are bound to the same physical field, so one of them sorts nothing.
An event projection that keeps payloads must keep their type, so each payload can be read.
construct (e.g. query operator[CONTAINS]) is expensive, and the entry does not allow expensive operators.
The gateway requires every query to state its entry, and this one ran under UNSPECIFIED.
The filter (and HAVING) of a query has more nodes or values (subject) than the entry allows.
A FIRST / LAST metric inside an element, or on a model without an event time, names no orderBy.
FIRST / LAST need a single value per record, both for the value and for its ordering field.
An identity filter or a cursor (whose tie-breaker is the identity) on a model that defines no identity.
A cursor token that does not decode for this model and effective sort.
Which error a violation renders as.
A filter or sort compares a sensitive field whose raw value must not be compared.
An aggregation whose HAVING or metric sort the core computes read more than max groups, dense fill rows included. Metered while the rows arrive, so it can fail after the response started streaming.
A sort names more fields than any storage supports.
A date group or date difference names a field whose values do not store instants as a date or an epoch, so no backend can read them as instants.
The field grants none of capabilities.
A filter value falls outside the field's declared domain; field is the name as the request wrote it.