affaan-m/ECC · critical · Error

Refusing to trust managed install-state at

Error message

Refusing to trust managed install-state at ${plan.installStatePath}: recorded root does not match the current install root.

What it means

assertPriorInstallStateMatchesPlan verifies that the root directory recorded in the existing install-state matches plan.targetRoot (via pathsMatch). A mismatch means the state file's owned-destination list is rooted elsewhere, so applying the new plan could clobber files outside the current install root. The installer refuses to trust the recorded state.

Solutions

  1. Uninstall using the original root/state, then run a fresh preview and apply with the new target root
  2. Delete the stale install-state file only after confirming the old install is gone
  3. Set plan.targetRoot back to the recorded root if you intended to keep installing there

Example fix

// before: state records /home/alice/.kimi, plan targets /opt/kimi
applySetup(planWithNewRoot) // throws root mismatch
// after
// clean up old install & its state, then:
const plan = previewSetup({ targetRoot: '/opt/kimi', ... })
applySetup(plan)
Defensive patterns

Strategy: try-catch

Validate before calling

const state = readInstallState(plan.installStatePath)
if (state && !pathsMatch(state.target.root, plan.targetRoot)) {
  throw new Error('Install root changed since last install; clean up old install first')
}

Type guard

const rootMatchesPlan = (state, plan) => pathsMatch(state?.target?.root, plan?.targetRoot)

Try / catch

try {
  applySetup(plan)
} catch (err) {
  if (err.message.includes('recorded root does not match')) {
    uninstallAt(oldRecordedRoot) // remove old install using its recorded root
    const fresh = previewSetup(plan.request)
    applySetup(fresh.plan)
  } else throw err
}

Prevention

When it happens

Trigger: Re-running a guided Kimi install after the target root moved (different install directory, renamed home, changed XDG dir) while the old install-state file still records the previous root.

Common situations: Migrating the install to a new directory without uninstalling first; moving a checkout or changing targetRoot config; restoring a state file from another machine with a different absolute path.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/cdae627986f8d40b. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/multi-harness-setup.js:161

    );
  }
}

function assertPriorInstallStateMatchesPlan(state, plan) {
  const target = state.target || {};
  const adapter = plan.adapter || {};
  if (
    target.id !== adapter.id
    || target.target !== adapter.target
    || target.kind !== adapter.kind
  ) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'target identity does not match the current Kimi install plan.'
    );
  }
  if (!pathsMatch(target.root, plan.targetRoot)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded root does not match the current install root.'
    );
  }
  if (!pathsMatch(target.installStatePath, plan.installStatePath)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded install-state path does not match the current install-state path.'
    );
  }
}

function readOwnedDestinations(plan, dependencies) {
  if (!plan.installStatePath) {
    return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };
  }
  try {
    assertSafeInstallOperation(plan, { destinationPath: plan.installStatePath });

View on GitHub (pinned to 8321021c54)