Reference
Undetermined, unread, not found
A scan can be healthy, low, or unable to say. The third case is three different cases, and collapsing them into “unknown” loses the part that tells you what to do next.
The three
| State | Means | What to do |
|---|---|---|
| undetermined | The check ran and cannot conclude from what it was given. Sharing seen from a single contract is the canonical case. | Give it more to look at — scan the contracts together. |
| unread | No TTL metadata came back for an entry that exists. | Retry, and treat the entry as unknown rather than fine in the meantime. |
| not found | No entry came back at all. It may never have existed, or it may already be archived. | Check whether it was archived. An archived entry needs restoring before it can be extended. |
An RPC failure is not one of these
If the network could not be reached, the check did not run. That is an error — exit 2 — and it is categorically different from a check that ran and declined. The distinction matters because a retry is the right response to one and a change of inputs is the right response to another.
How they appear in output
In the human report these arrive as issue lines under the entries, and as a summary count: Scan is PARTIAL — 2 issue(s). Absence is not health. In --json each one is an object with a code.
| Code | Raised when |
|---|---|
| sharing-undetermined | A code entry was read from a single contract, so the number of consumers is a floor of one rather than a count. |
| coverage-limited | No data keys were supplied, so persistent and temporary entries were not read at all. |
| rpc-error | The network refused or failed. The scan did not complete. |
Why sharing is always a lower bound
The chain does not index reverse dependencies. Given a contract you can find its code entry; you cannot ask the chain which other contracts point at that entry. Naming several contracts resolves it as far as is possible, and the answer still reads “at least N” — contracts you did not list may also depend on it.
So a single-contract scan reports UNDETERMINED rather than “unshared”. The difference is the whole point: unshared is a claim, undetermined is an admission.
What a clean result covers
Exactly what was asked for, and never the whole contract. Scanning reads the keys it is given and cannot enumerate storage, so a clean exit means “everything I was asked to check is healthy”. Coverage is printed with every scan for that reason, and --require-declared-scope exists to turn the silence into a failure when you own the contract and should know.
Next