affaan-m/ECC · error · Error
Memory roots must include a trusted boundary policy.
Error message
Memory roots must include a trusted boundary policy.
What it means
assertMemoryRootSafe throws when the roots object lacks the non-enumerable trusted-boundary metadata (roots is null, not an object, or an array). Roots must be produced by the internal createMemoryRoots, which attaches VAULT_ROOT_BOUNDARIES; a hand-built or corrupted roots object is the faulting input.
Solutions
- Obtain roots via the module's own root-creation API instead of constructing them ad hoc.
- Ensure the roots object was not cloned/spread, which drops the non-enumerable boundary property.
- Check that env-based root setup ran before any memory access.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at scripts/lib/memory-vault.js:99 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/81b3fd6720e47b25.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/lib/memory-vault.js:99
? realpathNearestExisting(projectVault)
: projectRoot,
team: env.ECC_MEMORY_PROJECT_ROOT
? realpathNearestExisting(projectVault)
: projectRoot,
user: env.ECC_MEMORY_USER_ROOT
? realpathNearestExisting(userVault)
: homeDir,
}),
enumerable: false,
configurable: false,
writable: false,
});
return Object.freeze(roots);
}
function assertMemoryRootSafe(roots, scope) {
if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {
throw new Error('Memory roots must include a trusted boundary policy.');
}
const root = roots[scope];
if (typeof root !== 'string' || root.length === 0) {
throw new Error(`No memory root is configured for scope "${scope}".`);
}
const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];
if (typeof boundary !== 'string' || boundary.length === 0) {
throw new Error(`No trusted boundary policy is configured for memory scope "${scope}".`);
}
assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');
if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {
throw new Error(`Refusing to access memory through symlink root: ${root}`);
}
return root;
}
function assertMemoryDirectorySafe(directory, root) {
assertWithinTrustedRoot(directory, root, 'access memory directory');View on GitHub (pinned to 8321021c54)