affaan-m/ECC · critical · Error

Refusing to trust managed install-state at

Error message

Refusing to trust managed install-state at ${plan.installStatePath}: target identity does not match the current Kimi install plan.

What it means

assertPriorInstallStateMatchesPlan compares the target identity (id, target, kind) recorded inside an existing managed install-state file against the current Kimi install plan's adapter identity. A mismatch means the state file was written by a different target/adapter, so trusting its destination list could delete or overwrite unrelated files. The installer refuses to trust it.

Solutions

  1. Remove or archive the old install-state file if you are confident it belongs to a different, abandoned install
  2. Restore the original plan/target that matches the recorded identity and uninstall through it first
  3. Re-run the guided preview after cleaning up so a fresh, matching state file is created

Example fix

// before: state written for kind 'user', plan now kind 'project'
applySetup(newPlan) // throws identity mismatch
// after
fs.rmSync(oldInstallStatePath) // old install uninstalled/cleaned
const plan = previewSetup(newRequest)
applySetup(plan)
Defensive patterns

Strategy: try-catch

Validate before calling

const state = readInstallState(plan.installStatePath)
if (state && (state.target.id !== plan.adapter.id || state.target.kind !== plan.adapter.kind)) {
  throw new Error('Existing install-state belongs to a different target; clean up first')
}

Type guard

const stateMatchesPlan = (state, plan) =>
  state?.target?.id === plan.adapter?.id &&
  state?.target?.target === plan.adapter?.target &&
  state?.target?.kind === plan.adapter?.kind

Try / catch

try {
  applySetup(plan)
} catch (err) {
  if (err.message.includes('target identity does not match')) {
    // uninstall via the original target or remove the stale state file after review
    cleanupStaleInstall(plan.installStatePath)
    const fresh = previewSetup(plan.request)
    applySetup(fresh.plan)
  } else throw err
}

Prevention

When it happens

Trigger: Running a guided Kimi install whose plan (adapter id/target/kind) differs from the identity recorded in an existing install-state file at plan.installStatePath — e.g. changing install kind or target while an old state file remains.

Common situations: Upgrading or reconfiguring the installer so adapter id/kind changed; pointing the installer at a different target while the old state file persists at the same path; hand-copied state files between machines.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/ce375379b856fb4a. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/multi-harness-setup.js:155

    currentFingerprint.exists !== expectedFingerprint.exists
    || currentFingerprint.sha256 !== expectedFingerprint.sha256
  ) {
    throw new Error(
      `Refusing to overwrite an unowned or changed install-state at ${plan.installStatePath}. `
      + 'Re-run the guided preview and review the existing state before retrying.'
    );
  }
}

function assertPriorInstallStateMatchesPlan(state, plan) {
  const target = state.target || {};
  const adapter = plan.adapter || {};
  if (
    target.id !== adapter.id
    || target.target !== adapter.target
    || target.kind !== adapter.kind
  ) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'target identity does not match the current Kimi install plan.'
    );
  }
  if (!pathsMatch(target.root, plan.targetRoot)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded root does not match the current install root.'
    );
  }
  if (!pathsMatch(target.installStatePath, plan.installStatePath)) {
    throw new Error(
      `Refusing to trust managed install-state at ${plan.installStatePath}: `
      + 'recorded install-state path does not match the current install-state path.'
    );
  }
}

View on GitHub (pinned to 8321021c54)