affaan-m/ECC · error · Error

No trusted boundary policy is configured for memory scope

Error message

No trusted boundary policy is configured for memory scope "${scope}".

What it means

assertMemoryRootSafe throws when the non-enumerable trusted boundary path for the requested scope is missing or empty. This internal metadata is required to confine all memory I/O within a trusted root; the faulting input is the boundary entry for `scope`, normally attached only by the internal root factory.

Solutions

  1. Use the module's root-creation API so boundaries are attached; do not hand-assemble roots.
  2. Avoid spreading/cloning the roots object, which strips non-enumerable properties.
  3. Ensure the memory-vault module initialization completed before use.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at scripts/lib/memory-vault.js:107 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/6df8ad946346e872. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/memory-vault.js:107

    }),
    enumerable: false,
    configurable: false,
    writable: false,
  });
  return Object.freeze(roots);
}

function assertMemoryRootSafe(roots, scope) {
  if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {
    throw new Error('Memory roots must include a trusted boundary policy.');
  }
  const root = roots[scope];
  if (typeof root !== 'string' || root.length === 0) {
    throw new Error(`No memory root is configured for scope "${scope}".`);
  }
  const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];
  if (typeof boundary !== 'string' || boundary.length === 0) {
    throw new Error(`No trusted boundary policy is configured for memory scope "${scope}".`);
  }
  assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');
  if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {
    throw new Error(`Refusing to access memory through symlink root: ${root}`);
  }
  return root;
}

function assertMemoryDirectorySafe(directory, root) {
  assertWithinTrustedRoot(directory, root, 'access memory directory');
  if (fs.existsSync(directory) && fs.lstatSync(directory).isSymbolicLink()) {
    throw new Error(`Refusing to access memory through symlink directory: ${directory}`);
  }
  return directory;
}

function sameFileIdentity(left, right) {
  // The inode is the primary identity signal and must always match.

View on GitHub (pinned to 8321021c54)