{"record":{"id":"5eacfb8cb75ba36b","repo":"affaan-m/ECC","slug":"receipt-source-is-not-a-regular-file-path","errorCode":null,"errorMessage":"receipt source is not a regular file: {path}","messagePattern":"receipt source is not a regular file: (.+?)","errorType":"validation","errorClass":"ContractError","httpStatus":null,"severity":"error","filePath":"skills/taste-application/scripts/tasteforge/contract.py","lineNumber":78,"sourceCode":"            raise ContractError(f\"{label} has invalid {field}\")\n        for value in values:\n            _validate_media_time(value, source_duration, label=f\"{label} {field}\")\n    samples = probe.get(\"style_samples\", [])\n    if not isinstance(samples, list) or any(not isinstance(sample, dict) for sample in samples):\n        raise ContractError(f\"{label} has invalid style evidence\")\n    for sample in samples:\n        _validate_media_time(sample.get(\"time\"), source_duration, label=f\"{label} style evidence\")\n\n\ndef _sha256(path: Path) -> str:\n    if not hasattr(os, \"O_NOFOLLOW\"):\n        raise ContractError(\"secure receipt validation requires O_NOFOLLOW\")\n    descriptor = os.open(path, os.O_RDONLY | os.O_NOFOLLOW)\n    digest = hashlib.sha256()\n    try:\n        metadata = os.fstat(descriptor)\n        if not stat.S_ISREG(metadata.st_mode):\n            raise ContractError(f\"receipt source is not a regular file: {path}\")\n        while True:\n            chunk = os.read(descriptor, 1024 * 1024)\n            if not chunk:\n                break\n            digest.update(chunk)\n    finally:\n        os.close(descriptor)\n    return digest.hexdigest()\n\n\ndef _semantic_signature(spec: dict[str, Any]) -> str:\n    signature = spec.get(\"signature\", {})\n    return json.dumps(signature, sort_keys=True, separators=(\",\", \":\"))\n\n\ndef _validate_output_tree(root: Path) -> None:\n    \"\"\"Reject symlinks and special files before parsing bundle content.\"\"\"\n    try:","sourceCodeStart":60,"sourceCodeEnd":96,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-application/scripts/tasteforge/contract.py#L60-L96","documentation":"_sha256 opened the receipt path with O_NOFOLLOW successfully, but fstat shows the opened file is not a regular file (e.g. a FIFO, device node, or directory-like special file). The library only accepts regular files as receipt sources so the digest corresponds to stable on-disk bytes.","triggerScenarios":"Passing a path that is a character device, FIFO/pipe, socket, or other special file as the receipt path to validate_artifact_receipt. This check runs after open+fstat, so it catches files that are special even if they passed a path lookup.","commonSituations":"Pointing the receipt argument at /dev/stdin, a named pipe used for streaming, a device file, or a directory by mistake in scripts/CI configs.","solutions":["Point the receipt argument at an actual regular file on disk","Check what the path is: ls -la <path> or stat <path> and fix the config/variable","If reading from a pipe/stdin, first write the content to a temp regular file and validate that","Regenerate the receipt file if the artifact pipeline left it as a special file"],"exampleFix":"# before\nreceipt_path = '/dev/stdin'\n# after\nimport tempfile, shutil, sys\nwith tempfile.NamedTemporaryFile(delete=False) as tmp:\n    shutil.copyfileobj(sys.stdin, tmp)\n    receipt_path = tmp.name","handlingStrategy":"validation","validationCode":"import stat, os\nmd = os.lstat(path)\nassert stat.S_ISREG(md.st_mode), f'{path} is not a regular file'","typeGuard":"def is_regular_file(path) -> bool:\n    import stat, os\n    try:\n        return stat.S_ISREG(os.lstat(path).st_mode)\n    except OSError:\n        return False","tryCatchPattern":"try:\n    validate_artifact_receipt(root)\nexcept ContractError as e:\n    if 'not a regular file' in str(e):\n        print(f'Receipt must be a regular file: {e}')\n    else:\n        raise","preventionTips":["Never point receipt paths at /dev/*, pipes, or sockets","Stat the path before validation in scripts","Write streamed receipts to a temp regular file first"],"tags":["filesystem","validation","security"],"backgroundTag":"incompatible-source-type","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}