paperclipai/paperclip · error · Error

Migrator producer identity mismatch.

Error message

Migrator producer identity mismatch.

What it means

Each returned workflow run must match the expected producer identity exactly: same head_sha, head_branch 'master', workflow path cloud-migrator-artifacts.yml, head repository id 1170821064 and full_name paperclipai/paperclip, and event push or workflow_dispatch. Any run failing this check throws immediately — the script refuses to trust runs from forks or other commit sources.

Solutions

  1. Trigger the migrator workflow via push to master or workflow_dispatch on master for the exact commit SHA.
  2. If the repository was renamed/transferred, update the hardcoded repository name and head_repository id (1170821064) in scripts/cloud-readiness.mjs.
  3. If the workflow file moved, update the `workflow` constant at the top of scripts/cloud-readiness.mjs.
  4. Never bless a run from a fork; run publication from the canonical repository.

Example fix

// before
run.path = ".github/workflows/migrator.yml" // renamed workflow
// after
// restore or update: const workflow = ".github/workflows/cloud-migrator-artifacts.yml";
Defensive patterns

Strategy: validation

Validate before calling

// ensure the publisher run is the trusted producer
if (run.head_repository?.full_name !== "paperclipai/paperclip" || run.head_branch !== "master") {
  throw new Error("Run is not a canonical master push — refusing to treat as publisher.");
}

Try / catch

try {
  await waitForCloudArtifacts(sha);
} catch (error) {
  if (error.message === "Migrator producer identity mismatch.") {
    console.error("A non-producer run for this SHA was found; re-publish from paperclipai/paperclip@master.");
  } else throw error;
}

Prevention

When it happens

Trigger: A run in the listing was triggered on the same SHA but from a fork (different head_repository id/name), on a non-master branch, by a different event type (e.g. pull_request), or the workflow file was moved/renamed so run.path differs.

Common situations: Running the workflow from a pull_request event in CI; repo was transferred (head_repository.id changed); workflow file renamed in .github/workflows; someone re-ran a run whose head_branch is not master; test fixtures using fabricated run objects.

Understand the failure class

Background: "invalid response format", "malformed payload", "missing data field": when an API returns 200 but the response shape is wrong — this error's family across 23 libraries.

Related errors


AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-09-18). Data as JSON: /api/errors/8695e0d2495db445. Report an issue: GitHub.

Appendix: source

Thrown at scripts/cloud-readiness.mjs:29

const workflow = ".github/workflows/cloud-migrator-artifacts.yml";

export async function migratorPublished(sha, fetchImpl, token) {
  let pending = false;
  const failures = [];
  for (let page = 1; page <= 10; page++) {
    const response = await fetchImpl(`https://api.github.com/repos/${repository}/actions/workflows/cloud-migrator-artifacts.yml/runs?branch=master&head_sha=${sha}&per_page=100&page=${page}`, {
      headers: { Accept: "application/vnd.github+json", ...(token ? { Authorization: `Bearer ${token}` } : {}) },
      redirect: "error", signal: AbortSignal.timeout(30_000),
    });
    if (!response.ok) throw new Error(`Migrator producer lookup failed: HTTP ${response.status}`);
    const body = await response.json();
    if (!Array.isArray(body.workflow_runs) || !Number.isSafeInteger(body.total_count) || body.total_count < 0 ||
        (page === 1 && (body.total_count === 0) !== (body.workflow_runs.length === 0))) throw new Error("Invalid migrator producer response.");
    if (body.total_count === 0) return false;
    for (const run of body.workflow_runs) {
      if (run.head_sha !== sha || run.head_branch !== "master" || run.path !== workflow ||
          run.head_repository?.id !== 1170821064 || run.head_repository.full_name !== repository ||
          !["push", "workflow_dispatch"].includes(run.event)) throw new Error("Migrator producer identity mismatch.");
      // Publication is immutable. A later failed manual run must not hide a
      // successful exact-source publisher; the signed bundle is checked next.
      if (run.status === "completed" && run.conclusion === "success") return true;
      if (run.status !== "completed") pending = true;
      else failures.push(`${run.id}: ${run.conclusion}`);
    }
    if (page * 100 >= body.total_count) {
      if (pending) return false;
      throw new Error(`Migrator producers failed: ${failures.join(", ")}.`);
    }
  }
  throw new Error("Too many migrator producer runs to establish publication.");
}

export function verifyManifestProvenance(bytes, sha, { exec = execFileSync } = {}) {
  versionFor(sha);
  const scratch = mkdtempSync(path.join(os.tmpdir(), "cloud-readiness-attestation-"));
  try {

View on GitHub (pinned to 3f1d897a7c)