affaan-m/ECC · error · SavedWorkflowClaimError
record for provider claims saved workflow state; a local…
Error message
record for provider {record.get('provider')!r} claims saved workflow state; a local reference is never a saved provider workflow What it means
assert_no_saved_provider_workflow enforces TasteForge's provenance guarantee that records describe only local references, never persisted provider workflow state. If any record's 'persisted_workflow_state' key is truthy it raises SavedWorkflowClaimError naming the offending provider, since a local reference can never constitute a saved provider workflow.
Solutions
- Remove the persisted_workflow_state field from the offending record and re-run validation
- Regenerate the records through TasteForge's offline workflow so they contain only local references
- Investigate the producer of the record — the claim indicates a non-offline provenance chain that must not be trusted
Example fix
// before
records[0]["persisted_workflow_state"] = {"run_id": "abc"}
assert_no_saved_provider_workflow(records) # raises
// after
records[0].pop("persisted_workflow_state", None)
assert_no_saved_provider_workflow(records) # passes Defensive patterns
Strategy: try-catch
Validate before calling
bad = [r.get('provider') for r in records if r.get('persisted_workflow_state')]
assert not bad, f"records claim saved provider state: {bad}" Try / catch
try:
assert_no_saved_provider_workflow(records)
except SavedWorkflowClaimError as e:
log.error("Untrusted provenance record: %s", e)
records = [r for r in records if not r.get("persisted_workflow_state")] Prevention
- Never hand-edit provenance records to add workflow state
- Validate records produced by external tools before importing
- Treat persisted_workflow_state as a tamper signal, not data
When it happens
Trigger: Calling assert_no_saved_provider_workflow(records) where at least one dict contains persisted_workflow_state set to a truthy value (True, a non-empty dict/string) — typically records produced by an external tool or hand-edited provenance file.
Common situations: Importing provenance exported by another (networked) tool; hand-editing records.json and adding workflow state; a third-party integration writing extra fields; schema drift after upgrading from a different pipeline.
Understand the failure class
Background: Schema validation failed / invalid input schema: payload rejected because its shape doesn't match the expected schema — this error's family across 28 libraries.
Related errors
- artifact permits provider execution
- a generated candidate cannot claim original-source identity
- anchor evidence source duration is not bound to its receipt…
- artifact path escapes output directory
- artifact cites an unknown provenance source
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/9a4e3740c18d05b8.
Report an issue: GitHub.
Appendix: source
Thrown at skills/taste-application/scripts/tasteforge/provenance.py:145
Constructed so that no field can be misread as \"a Fal workflow was
saved\": the record is explicitly ``reference_only`` and denies both
persisted provider state and execution authority.
"""
return {
"kind": "provider-workflow-reference",
"provider": provider,
"reference_only": True,
"persisted_workflow_state": False,
"authorizes_execution": False,
}
def assert_no_saved_provider_workflow(records: list[dict[str, Any]]) -> None:
"""Raise if any record claims persisted provider workflow state."""
for record in records:
if record.get("persisted_workflow_state"):
raise SavedWorkflowClaimError(
f"record for provider {record.get('provider')!r} claims saved "
"workflow state; a local reference is never a saved provider "
"workflow"
)
View on GitHub (pinned to 8321021c54)