{"record":{"id":"433b018d6181f6ad","repo":"JuliusBrussee/caveman","slug":"bundle-completeness-cannot-be-attested-by-unsigned","errorCode":null,"errorMessage":"bundle completeness cannot be attested by unsigned export metadata","messagePattern":"bundle completeness cannot be attested by unsigned export metadata","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/cli/src/index.ts","lineNumber":17413,"sourceCode":"  const raw = Buffer.from(info.key, \"base64\");\n  if (raw.length !== 32 || raw.toString(\"base64\") !== info.key) throw new Error(`${label} must be a canonical base64 Ed25519 public key`);\n  return { info, raw, key: ed25519PublicKey(raw) };\n}\n\nfunction decodeUniqueKeyring(infos: ReceiptPublicKey[], label: string): Map<string, DecodedReceiptKey> {\n  const keys = new Map<string, DecodedReceiptKey>();\n  for (const [index, info] of infos.entries()) {\n    const decoded = decodeReceiptKey(info, `${label}[${index}]`);\n    if (keys.has(decoded.info.key_id)) throw new Error(`${label} contains duplicate key_id ${decoded.info.key_id}`);\n    keys.set(decoded.info.key_id, decoded);\n  }\n  return keys;\n}\n\nfunction embeddedReceiptKeys(bundle: ReceiptBundle): { current: DecodedReceiptKey; keys: Map<string, DecodedReceiptKey> } {\n  if (bundle.schema !== RECEIPT_BUNDLE_V1 && bundle.schema !== RECEIPT_BUNDLE_V2) throw new Error(`unsupported bundle schema ${String(bundle.schema)}`);\n  if (bundle.verification_coverage !== undefined && bundle.verification_coverage !== INCLUDED_RECEIPTS_ONLY) throw new Error(`unsupported unsigned verification coverage ${String(bundle.verification_coverage)}`);\n  if (bundle.completeness_attested === true) throw new Error(\"bundle completeness cannot be attested by unsigned export metadata\");\n  const current = decodeReceiptKey(bundle.public_key, \"public_key\");\n  if (bundle.public_keys !== undefined && !Array.isArray(bundle.public_keys)) throw new Error(\"public_keys must be an array\");\n  if (bundle.schema === RECEIPT_BUNDLE_V2 && (!Array.isArray(bundle.public_keys) || bundle.public_keys.length === 0)) throw new Error(\"v2 bundle requires public_keys\");\n  const keys = decodeUniqueKeyring(bundle.public_keys ?? [], \"public_keys\");\n  const currentInRing = keys.get(current.info.key_id);\n  if (currentInRing && !currentInRing.raw.equals(current.raw)) throw new Error(`public_key conflicts with public_keys entry ${current.info.key_id}`);\n  if (bundle.schema === RECEIPT_BUNDLE_V2 && !currentInRing) throw new Error(\"v2 public_keys must include public_key\");\n  if (!currentInRing) keys.set(current.info.key_id, current);\n  return { current, keys };\n}\n\nasync function pinnedReceiptKeys(file: string, current: DecodedReceiptKey): Promise<{ keys: Map<string, DecodedReceiptKey>; trust: string }> {\n  const source = (await readFile(file, \"utf8\")).trim();\n  if (!source.startsWith(\"{\")) {\n    const pinned = decodeReceiptKey({ ...current.info, key: source }, \"--pubkey\");\n    if (!pinned.raw.equals(current.raw)) throw new Error(\"bundle public key does not match the published --pubkey\");\n    return { keys: new Map([[current.info.key_id, pinned]]), trust: \"pinned_public_key\" };\n  }","sourceCodeStart":17395,"sourceCodeEnd":17431,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/5184b3d11ac6a1acb7d44b9bfaa31698157cff97/packages/cli/src/index.ts#L17395-L17431","documentation":"A receipt bundle is unsigned export metadata, so it cannot carry a trustworthy completeness claim; completeness is attested by a separately trusted head manifest. A bundle with completeness_attested === true is treated as a forged attestation and rejected outright.","triggerScenarios":"Any bundle JSON with \"completeness_attested\": true reaching embeddedReceiptKeys, typically a hand-edited bundle or a producer bug that copied the field from the signed head manifest into the export.","commonSituations":"Downstream tooling tries to mark bundles as complete for audit purposes; producer refactors move signed-manifest fields into the unsigned export; test fixtures reuse signed-manifest JSON.","solutions":["Remove completeness_attested (or set it to false) in the exported bundle","Rely on the separately trusted head manifest for completeness statements, as the design intends","Fix the producer so it never writes this flag into unsigned export metadata"],"exampleFix":"// before\n{ \"completeness_attested\": true, ... }\n\n// after\n{ \"completeness_attested\": false, ... }","handlingStrategy":"validation","validationCode":"if (bundle.completeness_attested === true) {\n  throw new Error(\"refusing bundle: unsigned export metadata claims completeness\");\n}","typeGuard":"function makesNoCompletenessClaim(b: { completeness_attested?: unknown }): boolean {\n  return b.completeness_attested !== true;\n}","tryCatchPattern":"try { execSync(`caveman receipts verify ${bundle}`); }\ncatch (e) {\n  if (/completeness cannot be attested/.test(String((e as Error).message))) {\n    fail(\"strip completeness_attested; use the trusted head manifest instead\");\n  }\n  throw e;\n}","preventionTips":["Keep signed-manifest fields out of unsigned export code paths","Get completeness statements only from the separately trusted head manifest","Add a fixture test asserting exports never contain completeness_attested: true"],"tags":["receipts","security","metadata","completeness","validation"],"backgroundTag":"untrusted-metadata-claim","analyzedSha":"5184b3d11ac6a1acb7d44b9bfaa31698157cff97","analyzedAt":"2026-08-18T03:14:35.516Z","contentChangedAt":"2026-08-18T03:14:35.516Z","schemaVersion":2},"datasetVersion":"2026-09-14T05:17:10.506Z"}