{"record":{"id":"81b3fd6720e47b25","repo":"affaan-m/ECC","slug":"memory-roots-must-include-a-trusted-boundary-polic","errorCode":null,"errorMessage":"Memory roots must include a trusted boundary policy.","messagePattern":"Memory roots must include a trusted boundary policy\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/lib/memory-vault.js","lineNumber":99,"sourceCode":"        ? realpathNearestExisting(projectVault)\n        : projectRoot,\n      team: env.ECC_MEMORY_PROJECT_ROOT\n        ? realpathNearestExisting(projectVault)\n        : projectRoot,\n      user: env.ECC_MEMORY_USER_ROOT\n        ? realpathNearestExisting(userVault)\n        : homeDir,\n    }),\n    enumerable: false,\n    configurable: false,\n    writable: false,\n  });\n  return Object.freeze(roots);\n}\n\nfunction assertMemoryRootSafe(roots, scope) {\n  if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {\n    throw new Error('Memory roots must include a trusted boundary policy.');\n  }\n  const root = roots[scope];\n  if (typeof root !== 'string' || root.length === 0) {\n    throw new Error(`No memory root is configured for scope \"${scope}\".`);\n  }\n  const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];\n  if (typeof boundary !== 'string' || boundary.length === 0) {\n    throw new Error(`No trusted boundary policy is configured for memory scope \"${scope}\".`);\n  }\n  assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');\n  if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {\n    throw new Error(`Refusing to access memory through symlink root: ${root}`);\n  }\n  return root;\n}\n\nfunction assertMemoryDirectorySafe(directory, root) {\n  assertWithinTrustedRoot(directory, root, 'access memory directory');","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/memory-vault.js#L81-L117","documentation":"assertMemoryRootSafe throws when the roots object lacks the non-enumerable trusted-boundary metadata (roots is null, not an object, or an array). Roots must be produced by the internal createMemoryRoots, which attaches VAULT_ROOT_BOUNDARIES; a hand-built or corrupted roots object is the faulting input.","triggerScenarios":"Thrown at scripts/lib/memory-vault.js:99 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Obtain roots via the module's own root-creation API instead of constructing them ad hoc.","Ensure the roots object was not cloned/spread, which drops the non-enumerable boundary property.","Check that env-based root setup ran before any memory access."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}