paperclipai/paperclip · error · Error
Migrator producer identity mismatch.
Error message
Migrator producer identity mismatch.
What it means
Each returned workflow run must match the expected producer identity exactly: same head_sha, head_branch 'master', workflow path cloud-migrator-artifacts.yml, head repository id 1170821064 and full_name paperclipai/paperclip, and event push or workflow_dispatch. Any run failing this check throws immediately — the script refuses to trust runs from forks or other commit sources.
Solutions
- Trigger the migrator workflow via push to master or workflow_dispatch on master for the exact commit SHA.
- If the repository was renamed/transferred, update the hardcoded repository name and head_repository id (1170821064) in scripts/cloud-readiness.mjs.
- If the workflow file moved, update the `workflow` constant at the top of scripts/cloud-readiness.mjs.
- Never bless a run from a fork; run publication from the canonical repository.
Example fix
// before run.path = ".github/workflows/migrator.yml" // renamed workflow // after // restore or update: const workflow = ".github/workflows/cloud-migrator-artifacts.yml";
Defensive patterns
Strategy: validation
Validate before calling
// ensure the publisher run is the trusted producer
if (run.head_repository?.full_name !== "paperclipai/paperclip" || run.head_branch !== "master") {
throw new Error("Run is not a canonical master push — refusing to treat as publisher.");
} Try / catch
try {
await waitForCloudArtifacts(sha);
} catch (error) {
if (error.message === "Migrator producer identity mismatch.") {
console.error("A non-producer run for this SHA was found; re-publish from paperclipai/paperclip@master.");
} else throw error;
} Prevention
- Only run the migrator publish workflow via push to master or workflow_dispatch
- Never rename the workflow file without updating the constant in cloud-readiness.mjs
- Keep repository ownership/transfer decisions synced with the hardcoded id/name
When it happens
Trigger: A run in the listing was triggered on the same SHA but from a fork (different head_repository id/name), on a non-master branch, by a different event type (e.g. pull_request), or the workflow file was moved/renamed so run.path differs.
Common situations: Running the workflow from a pull_request event in CI; repo was transferred (head_repository.id changed); workflow file renamed in .github/workflows; someone re-ran a run whose head_branch is not master; test fixtures using fabricated run objects.
Understand the failure class
Background: "invalid response format", "malformed payload", "missing data field": when an API returns 200 but the response shape is wrong — this error's family across 23 libraries.
Related errors
- ACPX runtime omitted its verified platform executable…
- Artifact bytes do not match their immutable pin.
- Cloud readiness workflow identity does not match.
- GitHub Actions read failed
- GitHub Actions read failed
AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-09-18).
Data as JSON: /api/errors/8695e0d2495db445.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/cloud-readiness.mjs:29
const workflow = ".github/workflows/cloud-migrator-artifacts.yml";
export async function migratorPublished(sha, fetchImpl, token) {
let pending = false;
const failures = [];
for (let page = 1; page <= 10; page++) {
const response = await fetchImpl(`https://api.github.com/repos/${repository}/actions/workflows/cloud-migrator-artifacts.yml/runs?branch=master&head_sha=${sha}&per_page=100&page=${page}`, {
headers: { Accept: "application/vnd.github+json", ...(token ? { Authorization: `Bearer ${token}` } : {}) },
redirect: "error", signal: AbortSignal.timeout(30_000),
});
if (!response.ok) throw new Error(`Migrator producer lookup failed: HTTP ${response.status}`);
const body = await response.json();
if (!Array.isArray(body.workflow_runs) || !Number.isSafeInteger(body.total_count) || body.total_count < 0 ||
(page === 1 && (body.total_count === 0) !== (body.workflow_runs.length === 0))) throw new Error("Invalid migrator producer response.");
if (body.total_count === 0) return false;
for (const run of body.workflow_runs) {
if (run.head_sha !== sha || run.head_branch !== "master" || run.path !== workflow ||
run.head_repository?.id !== 1170821064 || run.head_repository.full_name !== repository ||
!["push", "workflow_dispatch"].includes(run.event)) throw new Error("Migrator producer identity mismatch.");
// Publication is immutable. A later failed manual run must not hide a
// successful exact-source publisher; the signed bundle is checked next.
if (run.status === "completed" && run.conclusion === "success") return true;
if (run.status !== "completed") pending = true;
else failures.push(`${run.id}: ${run.conclusion}`);
}
if (page * 100 >= body.total_count) {
if (pending) return false;
throw new Error(`Migrator producers failed: ${failures.join(", ")}.`);
}
}
throw new Error("Too many migrator producer runs to establish publication.");
}
export function verifyManifestProvenance(bytes, sha, { exec = execFileSync } = {}) {
versionFor(sha);
const scratch = mkdtempSync(path.join(os.tmpdir(), "cloud-readiness-attestation-"));
try {View on GitHub (pinned to 3f1d897a7c)