affaan-m/ECC · error · Error

The canonical ito-compute-cli is unpublished and ECC will…

Error message

The canonical ito-compute-cli is unpublished and ECC will not resolve a credential-bearing "ito" executable from PATH. Build it from ${CANONICAL_REPOSITORY.replace(/\.git$/, "")}/${CANONICAL_PACKAGE_PATH}, run npm ci and npm run check, then set ${EXECUTABLE_OVERRIDE} to the explicit absolute dist/bin/ito.js path.

What it means

resolveItoExecutable refuses to resolve an "ito" executable from PATH because the canonical ito-compute-cli package is unpublished and PATH resolution could pick up an untrusted, credential-bearing binary. It throws unless ECC_ITO_CLI_EXECUTABLE is set to an explicit path. The message explains how to build the CLI from the canonical repository and set the override.

Solutions

  1. Clone the canonical repository from the path given in the error (CANONICAL_REPOSITORY/CANONICAL_PACKAGE_PATH), run npm ci && npm run check, build dist/bin/ito.js
  2. Set ECC_ITO_CLI_EXECUTABLE to the absolute dist/bin/ito.js path, e.g. export ECC_ITO_CLI_EXECUTABLE=/opt/ito-compute-cli/dist/bin/ito.js
  3. Verify the variable is set and non-empty in the environment that runs the command (echo "$ECC_ITO_CLI_EXECUTABLE")
  4. Do not put the built binary on PATH and expect it to be used — the override is mandatory

Example fix

// before
spawn('ecc', ['ito', 'status']) // executable unset
// after
process.env.ECC_ITO_CLI_EXECUTABLE = '/opt/ito-compute-cli/dist/bin/ito.js';
spawn('ecc', ['ito', 'status'])
Defensive patterns

Strategy: try-catch

Validate before calling

if (!process.env.ECC_ITO_CLI_EXECUTABLE || !process.env.ECC_ITO_CLI_EXECUTABLE.trim()) {
  throw new Error('set ECC_ITO_CLI_EXECUTABLE to the built dist/bin/ito.js absolute path');
}

Try / catch

try {
  const exe = resolveItoExecutable(process.env);
} catch (e) {
  if (e.message.includes('unpublished')) {
    console.error('Build the CLI from the canonical repo and export ECC_ITO_CLI_EXECUTABLE=/path/to/dist/bin/ito.js');
  } else throw e;
}

Prevention

When it happens

Trigger: Calling any ecc ito command (which later resolves the executable) without ECC_ITO_CLI_EXECUTABLE set in the environment, or with it set to an empty/whitespace-only string.

Common situations: Fresh clones or CI runners where the override env var was never configured; switching machines and forgetting to port the env var; expecting the CLI to be found via npm global install or PATH.

Understand the failure class

Background: "environment variable is not set" and "Missing keys in environment" errors: what missing required env var messages mean and how to fix them — this error's family across 28 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/b971dfdf27ed4d44. Report an issue: GitHub.

Appendix: source

Thrown at scripts/ito.js:190

  }
  if (command === "evals") {
    validateNodeQualificationArgs(withoutJson, environment);
  }

  return Object.freeze({
    help: false,
    invocationArgs: Object.freeze([
      ...(jsonIndexes.length === 1 ? ["--json"] : []),
      command,
      ...withoutJson,
    ]),
  });
}

function resolveItoExecutable(environment = process.env) {
  const configured = environment[EXECUTABLE_OVERRIDE]?.trim();
  if (!configured) {
    throw new Error([
      "The canonical ito-compute-cli is unpublished and ECC will not resolve",
      `a credential-bearing "ito" executable from PATH. Build it from`,
      `${CANONICAL_REPOSITORY.replace(/\.git$/, "")}/${CANONICAL_PACKAGE_PATH},`,
      "run npm ci and npm run check, then set",
      `${EXECUTABLE_OVERRIDE} to the explicit absolute dist/bin/ito.js path.`,
    ].join(" "));
  }

  if (!path.isAbsolute(configured)) {
    throw new Error(
      `${EXECUTABLE_OVERRIDE} must be an absolute path explicitly configured by the operator.`
    );
  }
  return assertUsableExecutable(configured);
}

function assertUsableExecutable(candidate) {
  let canonicalCandidate;

View on GitHub (pinned to 8321021c54)