affaan-m/ECC · error · ContractError
artifact permits provider execution
Error message
artifact {relative} permits provider execution What it means
Every artifact entry in the receipt must explicitly declare provider_execution: false. This ContractError is raised when the field is missing, null, or set to anything other than the literal boolean false — the library refuses artifacts that do not affirmatively assert they were not produced by provider (LLM) execution.
Solutions
- Set provider_execution to the boolean false in each artifact entry.
- Regenerate the receipt with tasteforge, which writes the correct strict provenance flags.
- Ensure any custom receipt-writing code emits JSON booleans, not strings, for this field.
Example fix
// before
{"path": "a.png", "provider_execution": "false"}
// after
{"path": "a.png", "provider_execution": false} Defensive patterns
Strategy: validation
Validate before calling
for i, e in enumerate(receipt['artifacts']):
if e.get('provider_execution') is not False:
raise SystemExit(f'artifact[{i}] must set provider_execution to boolean false') Type guard
def forbids_provider_execution(entry: dict) -> bool:
return entry.get('provider_execution') is False Try / catch
try:
validate_artifact_receipt(out_dir, entries)
except ContractError as e:
if 'permits provider execution' in str(e):
regenerate_receipt(receipt_path) # strict flag must come from the generator
else:
raise Prevention
- Never hand-write the provider_execution flag; let the generator emit it.
- Use strict equality (is False) in your own checks to catch string "false" mistakes.
- Keep custom receipt writers in sync with the library's strict field requirements.
When it happens
Trigger: Calling validate_artifact_receipt()/validate_bundle() with receipt entries lacking 'provider_execution' or having it set to true / a truthy non-boolean value (e.g. "false" as a string).
Common situations: Hand-edited receipts missing the field; a custom generator writing provider_execution: true; schema drift where an older receipt format omitted the field; typing the flag as a string instead of a boolean.
Understand the failure class
Background: Schema validation failed / invalid input schema: payload rejected because its shape doesn't match the expected schema — this error's family across 28 libraries.
Related errors
- record for provider claims saved workflow state; a local…
- a generated candidate cannot claim original-source identity
- anchor evidence source duration is not bound to its receipt…
- artifact path escapes output directory
- artifact cites an unknown provenance source
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/d76c031f2b12f344.
Report an issue: GitHub.
Appendix: source
Thrown at skills/taste-application/scripts/tasteforge/contract.py:395
if len(bound_paths) != len(set(bound_paths)):
raise ContractError("receipt contains duplicate artifact paths")
missing = emitted - set(bound_paths)
extra = set(bound_paths) - emitted
if missing:
raise ContractError(f"unbound emitted artifact: {sorted(missing)}")
if extra:
raise ContractError(f"receipt binds missing artifact: {sorted(extra)}")
for entry in entries:
relative = entry.get("path")
assert isinstance(relative, str)
path = (out_dir / relative).resolve()
try:
path.relative_to(out_dir)
except ValueError as error:
raise ContractError(f"artifact path escapes output directory: {relative}") from error
if entry.get("provider_execution") is not False:
raise ContractError(f"artifact {relative} permits provider execution")
if not isinstance(entry.get("genre_numbers"), list):
raise ContractError(f"artifact {relative} lacks genre binding")
modalities = entry.get("modalities")
if (not isinstance(modalities, list)
or any(modality not in _REQUIRED_MODALITIES for modality in modalities)):
raise ContractError(f"artifact {relative} has invalid modality binding")
if entry.get("bytes") != path.stat().st_size:
raise ContractError(f"artifact {relative} byte size does not match receipt")
if entry.get("sha256") != _sha256(path):
raise ContractError(f"artifact {relative} SHA-256 does not match receipt")
provenance = entry.get("provenance")
if not isinstance(provenance, list) or not provenance:
raise ContractError(f"artifact {relative} lacks exact reference/time provenance")
for source in provenance:
if not isinstance(source.get("reference_path"), str) or not source["reference_path"]:
raise ContractError(f"artifact {relative} has invalid reference path")
digest = source.get("reference_sha256")
if not isinstance(digest, str) or len(digest) != 64:View on GitHub (pinned to 8321021c54)