affaan-m/ECC · error · Error

Refusing to trust managed install-state at

Error message

Refusing to trust managed install-state at ${plan.installStatePath}: recorded install-state path does not match the current install-state path.

What it means

readOwnedDestinations validates a previously recorded install-state file before trusting it to define which destinations ECC 'owns'. This error is thrown by assertPriorInstallStateMatchesPlan when the installStatePath recorded inside the state file does not match (after path canonicalization) the plan.installStatePath currently being read. It guards against a state file being copied, moved, or symlinked to a different location, which would make its recorded ownership claims untrustworthy.

Solutions

  1. Delete the stale install-state file at plan.installStatePath and re-run the guided install so a fresh state is recorded.
  2. Ensure the install is run from the same install root/path that produced the state file (check the installStatePath recorded inside the state JSON).
  3. If the location legitimately changed, remove the old state and regenerate the plan rather than hand-editing the state file.

Example fix

// before: reusing copied state
const plan = buildPlan({ targetRoot: '/new/location' }); // state copied from /old/location
// after: start clean at the new location
fs.rmSync('/new/location/.ecc/install-state.json');
const plan = buildPlan({ targetRoot: '/new/location' });
Defensive patterns

Strategy: validation

Validate before calling

const state = JSON.parse(fs.readFileSync(plan.installStatePath, 'utf8'));
if (state.target && !pathMatches(state.target.installStatePath, plan.installStatePath)) {
  throw new Error(`Stale install-state at ${plan.installStatePath}; delete it and re-run the guided install.`);
}

Type guard

function isStatePathCurrent(state, plan) {
  return Boolean(state?.target?.installStatePath) && pathsMatch(state.target.installStatePath, plan.installStatePath);
}

Try / catch

try {
  const { destinations } = readOwnedDestinations(plan, deps);
} catch (err) {
  if (String(err.message).includes('install-state path does not match')) {
    fs.rmSync(plan.installStatePath); // reset stale state, then re-run guided install
  } else throw err;
}

Prevention

When it happens

Trigger: Calling readOwnedDestinations (via the ownership step of a managed install) where state.target.installStatePath differs from plan.installStatePath — e.g. the state file was copied to a new path, the repo/package was relocated so the state path changed, or the plan was built with a different install-state location than the recorded one.

Common situations: Developer clones a project including .ecc install-state and runs an install from a different working directory; user moves the ECC install directory; a harness migration script renames the state file; a symlinked setup causes canonical path mismatch.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/40ffd609a3392aba. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/multi-harness-setup.js:167

  const adapter = plan.adapter || {};
  if (
    target.id !== adapter.id
    || target.target !== adapter.target
    || target.kind !== adapter.kind
  ) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'target identity does not match the current Kimi install plan.'
    );
  }
  if (!pathsMatch(target.root, plan.targetRoot)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded root does not match the current install root.'
    );
  }
  if (!pathsMatch(target.installStatePath, plan.installStatePath)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded install-state path does not match the current install-state path.'
    );
  }
}

function readOwnedDestinations(plan, dependencies) {
  if (!plan.installStatePath) {
    return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };
  }
  try {
    assertSafeInstallOperation(plan, { destinationPath: plan.installStatePath });
  } catch (error) {
    throw new Error(`Refusing to trust managed install-state path: ${error.message}`);
  }
  const initialFingerprint = fingerprintFile(plan.installStatePath);
  if (!initialFingerprint.exists) {
    return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };

View on GitHub (pinned to 8321021c54)