{"record":{"id":"35556c7626a1d379","repo":"ruvnet/ruflo","slug":"manifest-not-found-localpath","errorCode":null,"errorMessage":"Manifest not found: ${localPath}","messagePattern":"Manifest not found: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/verify.ts","lineNumber":70,"sourceCode":"  };\n}\n\nconst DEFAULT_MANIFEST_URL = 'https://raw.githubusercontent.com/ruvnet/ruflo/{branch}/verification.md.json';\n\nasync function fetchWitness(branch: string): Promise<Witness> {\n  const url = DEFAULT_MANIFEST_URL.replace('{branch}', branch);\n  // audit_1776853149979: bare fetch had no timeout — a hung GitHub CDN would\n  // pin the verify command indefinitely. 30s is generous for a sub-MB JSON.\n  const res = await fetch(url, { signal: AbortSignal.timeout(30000) });\n  if (!res.ok) {\n    throw new Error(`Failed to fetch manifest from ${url}: ${res.status} ${res.statusText}`);\n  }\n  return await res.json() as Witness;\n}\n\nfunction loadLocalWitness(localPath: string): Witness {\n  if (!existsSync(localPath)) {\n    throw new Error(`Manifest not found: ${localPath}`);\n  }\n  return JSON.parse(readFileSync(localPath, 'utf-8')) as Witness;\n}\n\n/**\n * Locate the user's installed package root.\n *\n * The witness manifest paths are repo-relative (e.g.\n * \"v3/@claude-flow/cli/dist/src/mcp-tools/hooks-tools.js\"). For\n * end users, only the dist/ subtree ships in node_modules. We map\n * the repo path → the installed equivalent by stripping the\n * \"v3/@claude-flow/<pkg>/\" prefix and looking up node_modules/<pkg>/.\n */\nfunction repoPathToInstalledPath(repoPath: string): string | null {\n  // Match v3/@claude-flow/<pkg>/<rest>\n  const match = repoPath.match(/^v3\\/(@claude-flow\\/[^/]+)\\/(.+)$/);\n  if (match) {\n    const pkg = match[1];","sourceCodeStart":52,"sourceCodeEnd":88,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/commands/verify.ts#L52-L88","documentation":"loadLocalWitness() throws when the --manifest path passed to `ruflo verify` does not exist on disk. The local path is the offline/air-gapped alternative to fetching the manifest from GitHub, and this guard reports the missing file before any parsing or signature verification begins.","triggerScenarios":"Running `ruflo verify --manifest ./verification.md.json` when the file was never downloaded, the path has a typo, or a relative path was resolved against a different working directory.","commonSituations":"Air-gapped verification where the download step was skipped; scripts running from a different cwd than expected; the manifest saved under a slightly different filename.","solutions":["Check the path spelling and use an absolute path to rule out cwd issues","ls the file from the exact directory the CLI runs in","Download or copy the manifest first (e.g. curl -fsSL -o verification.md.json <url>) then re-run verify --manifest"],"exampleFix":"# before\nruflo verify --manifest verif.json\n\n# after\ncurl -fsSL -o /abs/path/verification.md.json https://raw.githubusercontent.com/ruvnet/ruflo/main/verification.md.json\nruflo verify --manifest /abs/path/verification.md.json","handlingStrategy":"validation","validationCode":"import { existsSync, resolve } from 'node:fs';\nconst manifest = resolve(manifestPath);\nif (!existsSync(manifest)) {\n  throw new Error(`manifest missing at ${manifest} — download it before running verify`);\n}\nawait runVerify({ manifest });","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use absolute paths for --manifest so cwd changes cannot break resolution","Make manifest download a separate, checked step in CI before verify runs","Verify the filename exactly — verification.md.json, not verification.json or verif.md.json"],"tags":["cli","verification","file-not-found","manifest"],"backgroundTag":"file-not-found","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}