{"record":{"id":"19a7481e64704b6c","repo":"affaan-m/ECC","slug":"application-bundle-differs-from-its-bound-evidence","errorCode":null,"errorMessage":"application bundle differs from its bound evidence","messagePattern":"application bundle differs from its bound evidence","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/taste-application/scripts/tasteforge/integration.py","lineNumber":397,"sourceCode":"              \"provider_input\": copy.deepcopy(compiled_input), \"compiled_input_sha256\": input_hash,\n              \"edit_context_sha256\": edit_hash,\n              \"protected_stack\": stack, \"insert_policy\": \"new_video_track_preserve_baseline_audio\",\n              \"evidence_scope\": \"verified_local_bytes_and_supplied_metadata_only\"}\n    if local_only:\n        result = {**result, \"local_only\": True, \"provider_input_status\": \"not_prepared_local_only\",\n                  \"insert_policy\": \"none_preserve_baseline\"}\n    return {**result, \"bundle_sha256\": _digest(result)}\n\n\ndef validate_application_bundle(bundle: dict) -> None:\n    \"\"\"Recheck all files, derived state and exact flags; no mutation or execution.\"\"\"\n    if not isinstance(bundle, dict) or not (_REQUIRED | _OPTIONAL | {\"provider_input\"}) <= bundle.keys():\n        raise ValueError(\"incomplete application bundle\")\n    cfg = {key: bundle[key] for key in _REQUIRED | _OPTIONAL}\n    expected = build_application_bundle(cfg, bundle[\"provider_input\"],\n                                        local_only=bundle.get(\"local_only\", False))\n    if _canonical(bundle) != _canonical(expected):\n        raise ValueError(\"application bundle differs from its bound evidence\")\n","sourceCodeStart":379,"sourceCodeEnd":398,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-application/scripts/tasteforge/integration.py#L379-L398","documentation":"validate_application_bundle rebuilds the expected bundle from the bundle's own config and provider_input via build_application_bundle and compares canonical serializations. If the submitted bundle's bytes do not exactly match the recomputed bundle, its contents no longer correspond to the evidence it claims to be bound to. This guards against hand-edited or tampered application bundles.","triggerScenarios":"Calling validate_application_bundle with a dict whose keys were modified after generation: added/removed/renamed fields (e.g. injecting provider fields into a local_only bundle), changed values in required/optional keys, or a bundle produced with a different local_only flag than the one stored in the bundle.","commonSituations":"Manually editing a compiled bundle to 'fix' a field; copying a bundle between local-only and hosted modes; a schema/tool upgrade changing field naming so older bundles no longer recompute; programmatic post-processing that mutates the bundle before validation.","solutions":["Regenerate the bundle from source inputs using build_application_bundle (or the CLI compile command) instead of editing it","Diff _canonical(bundle) against _canonical(expected) to see exactly which fields diverged","Ensure the local_only flag and provider_input used at validation match those used at compile time","Verify the bundle was not round-tripped through a format that renames or drops fields"],"exampleFix":"// before: editing a compiled bundle\nbundle['provider_input'] = my_new_payload\nvalidate_application_bundle(bundle)\n\n// after: recompile from config\nbundle = build_application_bundle(cfg, provider_input, local_only=True)\nvalidate_application_bundle(bundle)","handlingStrategy":"validation","validationCode":"from tasteforge.integration import validate_application_bundle, build_application_bundle\ndef ensure_bundle_matches_evidence(bundle):\n    if not isinstance(bundle, dict):\n        raise TypeError('bundle must be a dict')\n    expected = build_application_bundle(\n        {k: bundle[k] for k in _REQUIRED | _OPTIONAL},\n        bundle['provider_input'],\n        local_only=bundle.get('local_only', False),\n    )\n    if _canonical(bundle) != _canonical(expected):\n        raise ValueError('bundle would fail validation; recompile it')","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat compiled bundles as immutable artifacts; never hand-edit them","Always regenerate bundles via build_application_bundle or the CLI after any input change","Keep the same local_only flag and provider_input across compile and validate","Run validation immediately after compilation, before storage or transport"],"tags":["python","integrity","tampering","validation"],"backgroundTag":"checksum-mismatch","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}