affaan-m/ECC · error · Error

Refusing unverified ownership from install-state at

Error message

Refusing unverified ownership from install-state at ${plan.installStatePath}: content digest does not match ${destinationPath}.

What it means

To accept a state-recorded operation as owned, the current on-disk file's sha256 must exist and exactly match the contentSha256 recorded in install-state (which must itself be a valid 64-hex digest). If the file is missing, its digest is absent/malformed, or it differs, this error is thrown — the file was modified, replaced, or deleted since the install, so blindly treating it as ECC-owned would destroy user changes.

Solutions

  1. Re-run the guided install/preview to rebuild install-state fingerprints against the current files.
  2. If you intentionally modified the file, back up your changes, let the install refresh it, then reapply your edits (or move customizations to a non-managed file).
  3. Check git/editor line-ending settings (core.autocrlf) that alter managed files and invalidate hashes; normalize and regenerate state.

Example fix

// before: user-edited managed file keeps stale hash
// after: refresh state for current files
fs.rmSync(plan.installStatePath);
const plan = buildPlan(adapter); // preview shows the file will be overwritten
Defensive patterns

Strategy: validation

Validate before calling

const crypto = require('crypto');
const actual = crypto.createHash('sha256').update(fs.readFileSync(dest)).digest('hex');
if (actual !== recorded.contentSha256) throw new Error(`${dest} changed since install; refresh install-state or reapply your edits after update.`);

Type guard

function digestIsValidAndCurrent(recorded, dest) {
  return /^[a-f0-9]{64}$/i.test(recorded?.contentSha256 || '')
    && crypto.createHash('sha256').update(fs.readFileSync(dest)).digest('hex') === recorded.contentSha256.toLowerCase();
}

Try / catch

try {
  readOwnedDestinations(plan, deps);
} catch (err) {
  if (String(err.message).includes('content digest does not match')) {
    // file changed since install: back up user edits, re-run guided install
    console.error('A managed file changed since install; run the guided install to refresh.');
  } else throw err;
}

Prevention

When it happens

Trigger: The destination file was edited by the user or another tool after install; the file was deleted; operation.contentSha256 is missing or not a 64-char hex string; newline/encoding conversion (e.g. git autocrlf) changed file bytes.

Common situations: User customized an ECC-managed file locally; a formatter or line-ending setting rewrote the file; git checkout normalized line endings changing the hash; partial/failed install left a file without a recorded digest.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/56d250e09cf8eb63. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/multi-harness-setup.js:227

    }
    const destinationPath = operation.destinationPath;
    assertWithinTrustedRoot(destinationPath, plan.targetRoot, 'trust install-state ownership');
    const canonicalDestination = canonicalPath(destinationPath);
    const plannedOperation = plannedByDestination.get(canonicalDestination);
    if (!plannedOperation) continue;
    if (!operationIdentityMatches(operation, plannedOperation)) {
      throw new Error(
        `Refusing unverified ownership from install-state at ${plan.installStatePath}: `
        + `operation identity does not match the current plan for ${destinationPath}.`
      );
    }
    const currentFingerprint = fingerprintFile(destinationPath);
    if (
      !currentFingerprint.exists
      || !/^[a-f0-9]{64}$/i.test(operation.contentSha256 || '')
      || currentFingerprint.sha256 !== operation.contentSha256.toLowerCase()
    ) {
      throw new Error(
        `Refusing unverified ownership from install-state at ${plan.installStatePath}: `
        + `content digest does not match ${destinationPath}.`
      );
    }
    destinations.add(canonicalDestination);
  }
  return { destinations, stateFingerprint: validatedFingerprint };
}

function assertMergeDestination(destinationPath, existingSnapshot = null) {
  const snapshot = existingSnapshot || readRegularFileSnapshot(destinationPath);
  if (!snapshot) return null;
  let current;
  try {
    current = JSON.parse(snapshot.content.toString('utf8'));
  } catch (error) {
    throw new Error(`Cannot merge ECC configuration into invalid JSON at ${destinationPath}: ${error.message}`);
  }

View on GitHub (pinned to 8321021c54)