affaan-m/ECC · error · ValueError

application bundle differs from its bound evidence

Error message

application bundle differs from its bound evidence

What it means

validate_application_bundle rebuilds the expected bundle from the bundle's own config and provider_input via build_application_bundle and compares canonical serializations. If the submitted bundle's bytes do not exactly match the recomputed bundle, its contents no longer correspond to the evidence it claims to be bound to. This guards against hand-edited or tampered application bundles.

Solutions

  1. Regenerate the bundle from source inputs using build_application_bundle (or the CLI compile command) instead of editing it
  2. Diff _canonical(bundle) against _canonical(expected) to see exactly which fields diverged
  3. Ensure the local_only flag and provider_input used at validation match those used at compile time
  4. Verify the bundle was not round-tripped through a format that renames or drops fields

Example fix

// before: editing a compiled bundle
bundle['provider_input'] = my_new_payload
validate_application_bundle(bundle)

// after: recompile from config
bundle = build_application_bundle(cfg, provider_input, local_only=True)
validate_application_bundle(bundle)
Defensive patterns

Strategy: validation

Validate before calling

from tasteforge.integration import validate_application_bundle, build_application_bundle
def ensure_bundle_matches_evidence(bundle):
    if not isinstance(bundle, dict):
        raise TypeError('bundle must be a dict')
    expected = build_application_bundle(
        {k: bundle[k] for k in _REQUIRED | _OPTIONAL},
        bundle['provider_input'],
        local_only=bundle.get('local_only', False),
    )
    if _canonical(bundle) != _canonical(expected):
        raise ValueError('bundle would fail validation; recompile it')

Prevention

When it happens

Trigger: Calling validate_application_bundle with a dict whose keys were modified after generation: added/removed/renamed fields (e.g. injecting provider fields into a local_only bundle), changed values in required/optional keys, or a bundle produced with a different local_only flag than the one stored in the bundle.

Common situations: Manually editing a compiled bundle to 'fix' a field; copying a bundle between local-only and hosted modes; a schema/tool upgrade changing field naming so older bundles no longer recompute; programmatic post-processing that mutates the bundle before validation.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/19a7481e64704b6c. Report an issue: GitHub.

Appendix: source

Thrown at skills/taste-application/scripts/tasteforge/integration.py:397

              "provider_input": copy.deepcopy(compiled_input), "compiled_input_sha256": input_hash,
              "edit_context_sha256": edit_hash,
              "protected_stack": stack, "insert_policy": "new_video_track_preserve_baseline_audio",
              "evidence_scope": "verified_local_bytes_and_supplied_metadata_only"}
    if local_only:
        result = {**result, "local_only": True, "provider_input_status": "not_prepared_local_only",
                  "insert_policy": "none_preserve_baseline"}
    return {**result, "bundle_sha256": _digest(result)}


def validate_application_bundle(bundle: dict) -> None:
    """Recheck all files, derived state and exact flags; no mutation or execution."""
    if not isinstance(bundle, dict) or not (_REQUIRED | _OPTIONAL | {"provider_input"}) <= bundle.keys():
        raise ValueError("incomplete application bundle")
    cfg = {key: bundle[key] for key in _REQUIRED | _OPTIONAL}
    expected = build_application_bundle(cfg, bundle["provider_input"],
                                        local_only=bundle.get("local_only", False))
    if _canonical(bundle) != _canonical(expected):
        raise ValueError("application bundle differs from its bound evidence")

View on GitHub (pinned to 8321021c54)