affaan-m/ECC · critical · Error
Refusing to trust managed install-state at
Error message
Refusing to trust managed install-state at ${plan.installStatePath}: recorded root does not match the current install root. What it means
assertPriorInstallStateMatchesPlan verifies that the root directory recorded in the existing install-state matches plan.targetRoot (via pathsMatch). A mismatch means the state file's owned-destination list is rooted elsewhere, so applying the new plan could clobber files outside the current install root. The installer refuses to trust the recorded state.
Solutions
- Uninstall using the original root/state, then run a fresh preview and apply with the new target root
- Delete the stale install-state file only after confirming the old install is gone
- Set plan.targetRoot back to the recorded root if you intended to keep installing there
Example fix
// before: state records /home/alice/.kimi, plan targets /opt/kimi
applySetup(planWithNewRoot) // throws root mismatch
// after
// clean up old install & its state, then:
const plan = previewSetup({ targetRoot: '/opt/kimi', ... })
applySetup(plan) Defensive patterns
Strategy: try-catch
Validate before calling
const state = readInstallState(plan.installStatePath)
if (state && !pathsMatch(state.target.root, plan.targetRoot)) {
throw new Error('Install root changed since last install; clean up old install first')
} Type guard
const rootMatchesPlan = (state, plan) => pathsMatch(state?.target?.root, plan?.targetRoot)
Try / catch
try {
applySetup(plan)
} catch (err) {
if (err.message.includes('recorded root does not match')) {
uninstallAt(oldRecordedRoot) // remove old install using its recorded root
const fresh = previewSetup(plan.request)
applySetup(fresh.plan)
} else throw err
} Prevention
- After moving the install directory, uninstall from the old location before installing at the new one
- Keep targetRoot stable in config; change it only through a clean uninstall/reinstall cycle
- Never copy install-state files between machines or paths
When it happens
Trigger: Re-running a guided Kimi install after the target root moved (different install directory, renamed home, changed XDG dir) while the old install-state file still records the previous root.
Common situations: Migrating the install to a new directory without uninstalling first; moving a checkout or changing targetRoot config; restoring a state file from another machine with a different absolute path.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- Refusing to overwrite an unowned or changed install-state at
- Refusing to trust managed install-state at
- Refusing to trust managed install-state at
- A managed install-state path is required before preflight.
- Failed to read
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/cdae627986f8d40b.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/lib/multi-harness-setup.js:161
);
}
}
function assertPriorInstallStateMatchesPlan(state, plan) {
const target = state.target || {};
const adapter = plan.adapter || {};
if (
target.id !== adapter.id
|| target.target !== adapter.target
|| target.kind !== adapter.kind
) {
throw new Error(
`Refusing to trust managed install-state at ${plan.installStatePath}: `
+ 'target identity does not match the current Kimi install plan.'
);
}
if (!pathsMatch(target.root, plan.targetRoot)) {
throw new Error(
`Refusing to trust managed install-state at ${plan.installStatePath}: `
+ 'recorded root does not match the current install root.'
);
}
if (!pathsMatch(target.installStatePath, plan.installStatePath)) {
throw new Error(
`Refusing to trust managed install-state at ${plan.installStatePath}: `
+ 'recorded install-state path does not match the current install-state path.'
);
}
}
function readOwnedDestinations(plan, dependencies) {
if (!plan.installStatePath) {
return { destinations: new Set(), stateFingerprint: { exists: false, sha256: null } };
}
try {
assertSafeInstallOperation(plan, { destinationPath: plan.installStatePath });View on GitHub (pinned to 8321021c54)