affaan-m/ECC · error · ValueError

Invalid supplied provenance declaration

Error message

Invalid supplied provenance declaration

What it means

For assets with origin external_result, _provenance recomputes the provenance record (provider, identifiers, evidence fingerprint) from the local evidence file and compares it to the 'provider_provenance' stored in the receipt. A mismatch means the declared provenance does not match the evidence bound on disk — the claim was altered, the evidence file changed, or the evidence binding is stale.

Solutions

  1. Re-run ingest_assets to produce a fresh receipt that re-fingerprints current evidence files.
  2. Diff receipt['provider_provenance'] against the evidence file at the bound path to identify the changed field.
  3. If only the evidence file changed, restore the original bytes or re-ingest with the new evidence.
  4. Do not edit provider/request_id/workflow_id in a receipt; re-ingest with corrected config instead.

Example fix

# before: evidence file replaced after ingest -> validate_assets raises
validate_assets('receipt.json')
# after: re-bind current evidence into a new receipt
receipt = ingest_assets('config.json', 'receipt.v2.json')
validate_assets('receipt.v2.json')
Defensive patterns

Strategy: try-catch

Validate before calling

# re-fingerprint evidence and compare to receipt before validating
import json, hashlib
ev = r['assets'][i]['provider_provenance']['evidence']
d = hashlib.sha256(open(ev['path'],'rb').read()).hexdigest()
assert d == ev['sha256'], 'evidence changed; re-ingest'

Try / catch

try:
    validate_assets(p)
except ValueError as e:
    if 'Invalid supplied provenance declaration' in str(e):
        fresh = ingest_assets(cfg, new_receipt_path())
    else:
        raise

Prevention

When it happens

Trigger: Calling validate_assets where an external_result asset's provider_provenance dict differs from the recomputed record (edited provider/request_id/workflow_id, replaced or modified evidence file, stale path/bytes/sha256 in the receipt).

Common situations: Manual edits to the provenance block; the evidence file was regenerated or moved after ingest; copying receipts between machines where relative evidence paths resolve differently; swapping evidence files with same-name different-content files.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/26191663801f31d2. Report an issue: GitHub.

Appendix: source

Thrown at skills/taste-application/scripts/tasteforge/assets.py:235

def validate_assets(receipt_path: str | Path) -> dict[str, Any]:
    """Re-hash every bound file and validate receipt semantics; no remote calls."""
    path = _path(receipt_path, Path.cwd())
    receipt = _load(path)
    if receipt.get('schema') != SCHEMA:
        raise ValueError('Unsupported asset receipt schema')
    if type(receipt.get('provider_calls')) is not int or receipt['provider_calls'] != 0:
        raise ValueError('Local ingestion must have zero provider calls')
    if receipt.get('provider_execution') is not False:
        raise ValueError('Local ingestion cannot claim provider execution')
    _, requests = (_bundle(receipt['bundle_receipt'], path.parent, True)
                   if 'bundle_receipt' in receipt else (None, {}))
    for asset in _assets(receipt.get('assets')):
        _taste(asset, requests, True)
        _verify_binding(asset, path.parent, asset['modality'])
        provenance = _provenance(asset, path.parent, True)
        if provenance is not None and provenance != asset['provider_provenance']:
            raise ValueError('Invalid supplied provenance declaration')
    inputs = receipt.get('input_artifacts')
    if not isinstance(inputs, list):
        raise ValueError('input_artifacts must be a list')
    for artifact in inputs:
        _verify_binding(artifact, path.parent)
    if 'genre_spec' in receipt:
        _verify_binding(receipt['genre_spec'], path.parent)
    return receipt

View on GitHub (pinned to 8321021c54)