affaan-m/ECC · error · Error

Memory roots must include a trusted boundary policy.

Error message

Memory roots must include a trusted boundary policy.

What it means

assertMemoryRootSafe throws when the roots object lacks the non-enumerable trusted-boundary metadata (roots is null, not an object, or an array). Roots must be produced by the internal createMemoryRoots, which attaches VAULT_ROOT_BOUNDARIES; a hand-built or corrupted roots object is the faulting input.

Solutions

  1. Obtain roots via the module's own root-creation API instead of constructing them ad hoc.
  2. Ensure the roots object was not cloned/spread, which drops the non-enumerable boundary property.
  3. Check that env-based root setup ran before any memory access.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at scripts/lib/memory-vault.js:99 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/81b3fd6720e47b25. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/memory-vault.js:99

        ? realpathNearestExisting(projectVault)
        : projectRoot,
      team: env.ECC_MEMORY_PROJECT_ROOT
        ? realpathNearestExisting(projectVault)
        : projectRoot,
      user: env.ECC_MEMORY_USER_ROOT
        ? realpathNearestExisting(userVault)
        : homeDir,
    }),
    enumerable: false,
    configurable: false,
    writable: false,
  });
  return Object.freeze(roots);
}

function assertMemoryRootSafe(roots, scope) {
  if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {
    throw new Error('Memory roots must include a trusted boundary policy.');
  }
  const root = roots[scope];
  if (typeof root !== 'string' || root.length === 0) {
    throw new Error(`No memory root is configured for scope "${scope}".`);
  }
  const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];
  if (typeof boundary !== 'string' || boundary.length === 0) {
    throw new Error(`No trusted boundary policy is configured for memory scope "${scope}".`);
  }
  assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');
  if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {
    throw new Error(`Refusing to access memory through symlink root: ${root}`);
  }
  return root;
}

function assertMemoryDirectorySafe(directory, root) {
  assertWithinTrustedRoot(directory, root, 'access memory directory');

View on GitHub (pinned to 8321021c54)