{"record":{"id":"8302a1e8967c532e","repo":"affaan-m/ECC","slug":"refusing-to-trust-non-managed-ownership-from-insta","errorCode":null,"errorMessage":"Refusing to trust non-managed ownership from install-state at ${plan.installStatePath}.","messagePattern":"Refusing to trust non-managed ownership from install-state at (.+?)\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/lib/multi-harness-setup.js","lineNumber":206,"sourceCode":"  const state = readState(plan.installStatePath);\n  const validatedFingerprint = fingerprintFile(plan.installStatePath);\n  if (\n    initialFingerprint.exists !== validatedFingerprint.exists\n    || initialFingerprint.sha256 !== validatedFingerprint.sha256\n  ) {\n    throw new Error(\n      `Refusing to trust install-state that changed during validation: ${plan.installStatePath}.`\n    );\n  }\n  assertPriorInstallStateMatchesPlan(state, plan);\n  const plannedByDestination = new Map(plan.operations.map(operation => [\n    canonicalPath(operation.destinationPath),\n    operation,\n  ]));\n  const destinations = new Set();\n  for (const operation of state.operations || []) {\n    if (operation.ownership !== 'managed') {\n      throw new Error(\n        `Refusing to trust non-managed ownership from install-state at ${plan.installStatePath}.`\n      );\n    }\n    const destinationPath = operation.destinationPath;\n    assertWithinTrustedRoot(destinationPath, plan.targetRoot, 'trust install-state ownership');\n    const canonicalDestination = canonicalPath(destinationPath);\n    const plannedOperation = plannedByDestination.get(canonicalDestination);\n    if (!plannedOperation) continue;\n    if (!operationIdentityMatches(operation, plannedOperation)) {\n      throw new Error(\n        `Refusing unverified ownership from install-state at ${plan.installStatePath}: `\n        + `operation identity does not match the current plan for ${destinationPath}.`\n      );\n    }\n    const currentFingerprint = fingerprintFile(destinationPath);\n    if (\n      !currentFingerprint.exists\n      || !/^[a-f0-9]{64}$/i.test(operation.contentSha256 || '')","sourceCodeStart":188,"sourceCodeEnd":224,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/multi-harness-setup.js#L188-L224","documentation":"Every operation recorded in the install-state file must have ownership === 'managed'; readOwnedDestinations throws this error the moment it encounters a state operation with any other ownership value. Non-managed entries are user-owned files the library never claimed, so trusting them as owned destinations would allow overwriting user content.","triggerScenarios":"state.operations contains an entry with a missing or non-'managed' ownership field while iterating state.operations in readOwnedDestinations — typically from a hand-edited, older-format, or corrupted install-state file.","commonSituations":"User manually edited the install-state JSON to add their own files; a state file from an older schema version lacking the ownership field; a corrupted or truncated state write.","solutions":["Open the install-state file and remove entries whose ownership is not 'managed', or restore the file from a known-good version.","Regenerate the install-state by deleting it and re-running the guided install.","Do not hand-add custom files to install-state; track user-owned files outside this state file."],"exampleFix":"// before (state.operations entry)\n{ \"destinationPath\": \"/repo/my-file\", \"ownership\": \"user\" }\n// after\n{ \"destinationPath\": \"/repo/my-file\", \"ownership\": \"managed\" } // only if truly ECC-managed; otherwise delete the entry","handlingStrategy":"validation","validationCode":"const state = JSON.parse(fs.readFileSync(plan.installStatePath, 'utf8'));\nconst bad = (state.operations || []).filter(op => op.ownership !== 'managed');\nif (bad.length) throw new Error(`Non-managed entries in install-state: ${bad.map(o => o.destinationPath).join(', ')}`);","typeGuard":"function allManaged(state) {\n  return (state?.operations || []).every(op => op.ownership === 'managed');\n}","tryCatchPattern":"try {\n  readOwnedDestinations(plan, deps);\n} catch (err) {\n  if (String(err.message).includes('non-managed ownership')) {\n    fs.rmSync(plan.installStatePath); // regenerate state via guided install\n  } else throw err;\n}","preventionTips":["Never hand-edit install-state files.","Keep user-owned files out of install-state; track them elsewhere.","Validate state schema after upgrading ECC versions.","Restore state from a known-good copy rather than patching entries manually."],"tags":["install-state","validation","integrity"],"backgroundTag":"invalid-argument-value","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}