{"record":{"id":"d76c031f2b12f344","repo":"affaan-m/ECC","slug":"artifact-relative-permits-provider-execution","errorCode":null,"errorMessage":"artifact {relative} permits provider execution","messagePattern":"artifact (.+?) permits provider execution","errorType":"validation","errorClass":"ContractError","httpStatus":null,"severity":"error","filePath":"skills/taste-application/scripts/tasteforge/contract.py","lineNumber":395,"sourceCode":"    if len(bound_paths) != len(set(bound_paths)):\n        raise ContractError(\"receipt contains duplicate artifact paths\")\n    missing = emitted - set(bound_paths)\n    extra = set(bound_paths) - emitted\n    if missing:\n        raise ContractError(f\"unbound emitted artifact: {sorted(missing)}\")\n    if extra:\n        raise ContractError(f\"receipt binds missing artifact: {sorted(extra)}\")\n\n    for entry in entries:\n        relative = entry.get(\"path\")\n        assert isinstance(relative, str)\n        path = (out_dir / relative).resolve()\n        try:\n            path.relative_to(out_dir)\n        except ValueError as error:\n            raise ContractError(f\"artifact path escapes output directory: {relative}\") from error\n        if entry.get(\"provider_execution\") is not False:\n            raise ContractError(f\"artifact {relative} permits provider execution\")\n        if not isinstance(entry.get(\"genre_numbers\"), list):\n            raise ContractError(f\"artifact {relative} lacks genre binding\")\n        modalities = entry.get(\"modalities\")\n        if (not isinstance(modalities, list)\n                or any(modality not in _REQUIRED_MODALITIES for modality in modalities)):\n            raise ContractError(f\"artifact {relative} has invalid modality binding\")\n        if entry.get(\"bytes\") != path.stat().st_size:\n            raise ContractError(f\"artifact {relative} byte size does not match receipt\")\n        if entry.get(\"sha256\") != _sha256(path):\n            raise ContractError(f\"artifact {relative} SHA-256 does not match receipt\")\n        provenance = entry.get(\"provenance\")\n        if not isinstance(provenance, list) or not provenance:\n            raise ContractError(f\"artifact {relative} lacks exact reference/time provenance\")\n        for source in provenance:\n            if not isinstance(source.get(\"reference_path\"), str) or not source[\"reference_path\"]:\n                raise ContractError(f\"artifact {relative} has invalid reference path\")\n            digest = source.get(\"reference_sha256\")\n            if not isinstance(digest, str) or len(digest) != 64:","sourceCodeStart":377,"sourceCodeEnd":413,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-application/scripts/tasteforge/contract.py#L377-L413","documentation":"Every artifact entry in the receipt must explicitly declare provider_execution: false. This ContractError is raised when the field is missing, null, or set to anything other than the literal boolean false — the library refuses artifacts that do not affirmatively assert they were not produced by provider (LLM) execution.","triggerScenarios":"Calling validate_artifact_receipt()/validate_bundle() with receipt entries lacking 'provider_execution' or having it set to true / a truthy non-boolean value (e.g. \"false\" as a string).","commonSituations":"Hand-edited receipts missing the field; a custom generator writing provider_execution: true; schema drift where an older receipt format omitted the field; typing the flag as a string instead of a boolean.","solutions":["Set provider_execution to the boolean false in each artifact entry.","Regenerate the receipt with tasteforge, which writes the correct strict provenance flags.","Ensure any custom receipt-writing code emits JSON booleans, not strings, for this field."],"exampleFix":"// before\n{\"path\": \"a.png\", \"provider_execution\": \"false\"}\n// after\n{\"path\": \"a.png\", \"provider_execution\": false}","handlingStrategy":"validation","validationCode":"for i, e in enumerate(receipt['artifacts']):\n    if e.get('provider_execution') is not False:\n        raise SystemExit(f'artifact[{i}] must set provider_execution to boolean false')","typeGuard":"def forbids_provider_execution(entry: dict) -> bool:\n    return entry.get('provider_execution') is False","tryCatchPattern":"try:\n    validate_artifact_receipt(out_dir, entries)\nexcept ContractError as e:\n    if 'permits provider execution' in str(e):\n        regenerate_receipt(receipt_path)  # strict flag must come from the generator\n    else:\n        raise","preventionTips":["Never hand-write the provider_execution flag; let the generator emit it.","Use strict equality (is False) in your own checks to catch string \"false\" mistakes.","Keep custom receipt writers in sync with the library's strict field requirements."],"tags":["security","validation","provenance"],"backgroundTag":"schema-validation-failed","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}