{"record":{"id":"926789182a1251fe","repo":"affaan-m/ECC","slug":"unknown-argument-arg","errorCode":null,"errorMessage":"Unknown argument: ${arg}","messagePattern":"Unknown argument: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/auto-update.js","lineNumber":48,"sourceCode":"  };\n\n  for (let index = 0; index < args.length; index += 1) {\n    const arg = args[index];\n\n    if (arg === '--target') {\n      parsed.targets.push(args[index + 1] || null);\n      index += 1;\n    } else if (arg === '--repo-root') {\n      parsed.repoRoot = args[index + 1] || null;\n      index += 1;\n    } else if (arg === '--dry-run') {\n      parsed.dryRun = true;\n    } else if (arg === '--json') {\n      parsed.json = true;\n    } else if (arg === '--help' || arg === '-h') {\n      parsed.help = true;\n    } else {\n      throw new Error(`Unknown argument: ${arg}`);\n    }\n  }\n\n  return parsed;\n}\n\nfunction deriveRepoRootFromState(state) {\n  const operations = Array.isArray(state && state.operations) ? state.operations : [];\n\n  for (const operation of operations) {\n    if (typeof operation.sourcePath !== 'string' || !operation.sourcePath.trim()) {\n      continue;\n    }\n\n    if (typeof operation.sourceRelativePath !== 'string' || !operation.sourceRelativePath.trim()) {\n      continue;\n    }\n","sourceCodeStart":30,"sourceCodeEnd":66,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/auto-update.js#L30-L66","documentation":"Each scope root must be paired with a trusted boundary policy string under roots[VAULT_ROOT_BOUNDARIES][scope]; that boundary defines the trusted filesystem region the root must stay inside. If the boundary is missing, empty, or not a string, assertMemoryRootSafe throws this error. The library refuses to operate without an explicit trust boundary so symlink and path-escape attacks cannot bypass containment.","triggerScenarios":"Providing a roots object that maps scope -> path but omits the corresponding entry in the VAULT_ROOT_BOUNDARIES map, sets it to '' or null, or builds the boundaries object dynamically and the scope key never got inserted.","commonSituations":"Hand-writing the roots config and adding a new scope path without adding its boundary entry; a migration that renamed VAULT_ROOT_BOUNDARIES or restructured the config; copying a scope entry without its boundary counterpart; programmatically generated config where a loop skipped one scope.","solutions":["Add a trusted boundary path for the scope under roots[VAULT_ROOT_BOUNDARIES][scope] (the boundary must contain the scope root).","Set the boundary to the same directory as the root (or a parent of it) if the whole root directory is trusted.","Validate the roots object on startup with a check that iterates all scopes and asserts each has a non-empty boundary.","Regenerate the config from the installer/template that emits both roots and boundaries together."],"exampleFix":"// before\nconst roots = { project: '/vault/project' };\n\n// after\nconst roots = {\n  project: '/vault/project',\n  [VAULT_ROOT_BOUNDARIES]: { project: '/vault/project' }\n};","handlingStrategy":"validation","validationCode":"const VAULT_ROOT_BOUNDARIES = '__boundaries'; // match the library's key\nfunction assertBoundariesPresent(roots, scopes) {\n  for (const scope of scopes) {\n    const b = roots?.[VAULT_ROOT_BOUNDARIES]?.[scope];\n    if (typeof b !== 'string' || b.length === 0) {\n      throw new Error(`Scope \"${scope}\" is missing its trusted boundary policy in ${VAULT_ROOT_BOUNDARIES}.`);\n    }\n  }\n}","typeGuard":"const hasBoundary = (roots, scope) => typeof roots?.[VAULT_ROOT_BOUNDARIES]?.[scope] === 'string' && roots[VAULT_ROOT_BOUNDARIES][scope].length > 0;","tryCatchPattern":"try {\n  const root = resolveMemoryRoot(roots, scope);\n} catch (err) {\n  if (err.message.includes('trusted boundary policy is configured')) {\n    throw new Error(`Add ${scope} to the boundary map in your memory roots config.`);\n  }\n  throw err;\n}","preventionTips":["Always add the root and its boundary entry together — never edit one without the other.","Generate roots config from a template/installer that emits both maps.","Validate every configured scope has a boundary at startup.","Document the boundary requirement wherever root configuration is documented."],"tags":["configuration","memory-vault","security","trust-boundary"],"backgroundTag":"missing-required-config-field","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}