affaan-m/ECC · error · Error
No trusted boundary policy is configured for memory scope
Error message
No trusted boundary policy is configured for memory scope "${scope}". What it means
assertMemoryRootSafe throws when the non-enumerable trusted boundary path for the requested scope is missing or empty. This internal metadata is required to confine all memory I/O within a trusted root; the faulting input is the boundary entry for `scope`, normally attached only by the internal root factory.
Solutions
- Use the module's root-creation API so boundaries are attached; do not hand-assemble roots.
- Avoid spreading/cloning the roots object, which strips non-enumerable properties.
- Ensure the memory-vault module initialization completed before use.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at scripts/lib/memory-vault.js:107 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/6df8ad946346e872.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/lib/memory-vault.js:107
}),
enumerable: false,
configurable: false,
writable: false,
});
return Object.freeze(roots);
}
function assertMemoryRootSafe(roots, scope) {
if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {
throw new Error('Memory roots must include a trusted boundary policy.');
}
const root = roots[scope];
if (typeof root !== 'string' || root.length === 0) {
throw new Error(`No memory root is configured for scope "${scope}".`);
}
const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];
if (typeof boundary !== 'string' || boundary.length === 0) {
throw new Error(`No trusted boundary policy is configured for memory scope "${scope}".`);
}
assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');
if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {
throw new Error(`Refusing to access memory through symlink root: ${root}`);
}
return root;
}
function assertMemoryDirectorySafe(directory, root) {
assertWithinTrustedRoot(directory, root, 'access memory directory');
if (fs.existsSync(directory) && fs.lstatSync(directory).isSymbolicLink()) {
throw new Error(`Refusing to access memory through symlink directory: ${directory}`);
}
return directory;
}
function sameFileIdentity(left, right) {
// The inode is the primary identity signal and must always match.View on GitHub (pinned to 8321021c54)