{"record":{"id":"8ef5a378117d57b4","repo":"Hmbown/CodeWhale","slug":"self-verify-failed-check-errors-join","errorCode":null,"errorMessage":"self-verify failed: ${check.errors.join(\"; \")}","messagePattern":"self-verify failed: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"critical","filePath":"web/scripts/facts-publish.mjs","lineNumber":318,"sourceCode":"  const sha256 = createHash(\"sha256\").update(payloadBytes).digest(\"hex\");\n  const envelope = {\n    envelope: ENVELOPE_VERSION,\n    channel: payload.channel,\n    facts_version: payload.facts_version,\n    schema_version: payload.schema_version,\n    key_id: keyId,\n    alg: \"ed25519\",\n    applies_to: payload.applies_to,\n    published_at: payload.published_at,\n    payload_b64: payloadBytes.toString(\"base64\"),\n    sig_b64: sig.toString(\"base64\"),\n    sigs: [],\n    sha256,\n  };\n  if (payload.not_after != null) envelope.not_after = payload.not_after;\n  const pub = rawPublicKeyFromKeyObject(createPublicKey(privateKey)).toString(\"base64\");\n  const check = verifyEnvelope(envelope, pub);\n  if (!check.ok) throw new Error(`self-verify failed: ${check.errors.join(\"; \")}`);\n  return envelope;\n}\n\n// ---------------------------------------------------------------------------\n// CLI helpers\n// ---------------------------------------------------------------------------\n\nfunction parseArgs(argv) {\n  const positional = [];\n  const flags = {};\n  for (let i = 0; i < argv.length; i += 1) {\n    const arg = argv[i];\n    if (arg.startsWith(\"--\")) {\n      const key = arg.slice(2);\n      const next = argv[i + 1];\n      if (next === undefined || next.startsWith(\"--\")) flags[key] = true;\n      else { flags[key] = next; i += 1; }\n    } else positional.push(arg);","sourceCodeStart":300,"sourceCodeEnd":336,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/web/scripts/facts-publish.mjs#L300-L336","documentation":"After constructing the envelope, buildEnvelope immediately verifies it against the derived public key via verifyEnvelope. If that self-verification fails, this error aggregates the verifier's error list. It is an internal safety net: a produced envelope that cannot be verified is never returned to the caller.","triggerScenarios":"buildEnvelope produced an envelope that verifyEnvelope rejects — e.g. signature mismatch (wrong/unsupported private key), a payload field the verifier considers invalid, or the not_after/version fields breaking verification invariants.","commonSituations":"Passing a corrupted or wrong-format private key whose derived public key does not match the signature; tampered buildEnvelope/verifyEnvelope code after local edits; key object that is not a usable Ed25519 private key despite parsing.","solutions":["Read the joined check.errors in the message to see which verification rule failed","Regenerate or re-export the signing key and confirm createPrivateKey yields an Ed25519 key","Sign a trivial payload to isolate whether the problem is the key or the payload fields","If you modified this script, diff buildEnvelope and verifyEnvelope against git HEAD"],"exampleFix":"// before\nconst key = createPrivateKey(fs.readFileSync(process.env.KEY_PATH));\nawait buildEnvelope({ privateKey: key, keyId, payload });\n// after\nconst key = createPrivateKey({ key: fs.readFileSync(process.env.KEY_PATH), format: 'pem' });\nif (key.asymmetricKeyType !== 'ed25519') throw new Error('need Ed25519 key');\nawait buildEnvelope({ privateKey: key, keyId, payload });","handlingStrategy":"try-catch","validationCode":"const key = createPrivateKey({ key: pem, format: 'pem' });\nif (key.asymmetricKeyType !== 'ed25519') throw new Error('signing key must be Ed25519 before envelope build');","typeGuard":"const isEd25519Private = (k) => { try { return createPrivateKey(k).asymmetricKeyType === 'ed25519'; } catch { return false; } };","tryCatchPattern":"try { env = buildEnvelope({ privateKey, keyId, payload }); } catch (e) { if (e.message.startsWith('self-verify failed')) { console.error('Envelope failed self-verify:', e.message); process.exit(3); } throw e; }","preventionTips":["Verify your private key parses as Ed25519 before every publish run","Do not modify buildEnvelope/verifyEnvelope locally without running the script's tests","Sign a canary payload after key rotation to confirm key health","Treat any self-verify failure as a bug, not retryable input"],"tags":["signing","self-verify","invariant"],"backgroundTag":"signature-verification-failed","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}