{"record":{"id":"b971dfdf27ed4d44","repo":"affaan-m/ECC","slug":"the-canonical-ito-compute-cli-is-unpublished-and-e","errorCode":null,"errorMessage":"The canonical ito-compute-cli is unpublished and ECC will not resolve a credential-bearing \"ito\" executable from PATH. Build it from ${CANONICAL_REPOSITORY.replace(/\\.git$/, \"\")}/${CANONICAL_PACKAGE_PATH}, run npm ci and npm run check, then set ${EXECUTABLE_OVERRIDE} to the explicit absolute dist/bin/ito.js path.","messagePattern":"The canonical ito-compute-cli is unpublished and ECC will not resolve a credential-bearing \"ito\" executable from PATH\\. Build it from (.+?)/(.+?), run npm ci and npm run check, then set (.+?) to the explicit absolute dist/bin/ito\\.js path\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/ito.js","lineNumber":190,"sourceCode":"  }\n  if (command === \"evals\") {\n    validateNodeQualificationArgs(withoutJson, environment);\n  }\n\n  return Object.freeze({\n    help: false,\n    invocationArgs: Object.freeze([\n      ...(jsonIndexes.length === 1 ? [\"--json\"] : []),\n      command,\n      ...withoutJson,\n    ]),\n  });\n}\n\nfunction resolveItoExecutable(environment = process.env) {\n  const configured = environment[EXECUTABLE_OVERRIDE]?.trim();\n  if (!configured) {\n    throw new Error([\n      \"The canonical ito-compute-cli is unpublished and ECC will not resolve\",\n      `a credential-bearing \"ito\" executable from PATH. Build it from`,\n      `${CANONICAL_REPOSITORY.replace(/\\.git$/, \"\")}/${CANONICAL_PACKAGE_PATH},`,\n      \"run npm ci and npm run check, then set\",\n      `${EXECUTABLE_OVERRIDE} to the explicit absolute dist/bin/ito.js path.`,\n    ].join(\" \"));\n  }\n\n  if (!path.isAbsolute(configured)) {\n    throw new Error(\n      `${EXECUTABLE_OVERRIDE} must be an absolute path explicitly configured by the operator.`\n    );\n  }\n  return assertUsableExecutable(configured);\n}\n\nfunction assertUsableExecutable(candidate) {\n  let canonicalCandidate;","sourceCodeStart":172,"sourceCodeEnd":208,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/ito.js#L172-L208","documentation":"resolveItoExecutable refuses to resolve an \"ito\" executable from PATH because the canonical ito-compute-cli package is unpublished and PATH resolution could pick up an untrusted, credential-bearing binary. It throws unless ECC_ITO_CLI_EXECUTABLE is set to an explicit path. The message explains how to build the CLI from the canonical repository and set the override.","triggerScenarios":"Calling any ecc ito command (which later resolves the executable) without ECC_ITO_CLI_EXECUTABLE set in the environment, or with it set to an empty/whitespace-only string.","commonSituations":"Fresh clones or CI runners where the override env var was never configured; switching machines and forgetting to port the env var; expecting the CLI to be found via npm global install or PATH.","solutions":["Clone the canonical repository from the path given in the error (CANONICAL_REPOSITORY/CANONICAL_PACKAGE_PATH), run npm ci && npm run check, build dist/bin/ito.js","Set ECC_ITO_CLI_EXECUTABLE to the absolute dist/bin/ito.js path, e.g. export ECC_ITO_CLI_EXECUTABLE=/opt/ito-compute-cli/dist/bin/ito.js","Verify the variable is set and non-empty in the environment that runs the command (echo \"$ECC_ITO_CLI_EXECUTABLE\")","Do not put the built binary on PATH and expect it to be used — the override is mandatory"],"exampleFix":"// before\nspawn('ecc', ['ito', 'status']) // executable unset\n// after\nprocess.env.ECC_ITO_CLI_EXECUTABLE = '/opt/ito-compute-cli/dist/bin/ito.js';\nspawn('ecc', ['ito', 'status'])","handlingStrategy":"try-catch","validationCode":"if (!process.env.ECC_ITO_CLI_EXECUTABLE || !process.env.ECC_ITO_CLI_EXECUTABLE.trim()) {\n  throw new Error('set ECC_ITO_CLI_EXECUTABLE to the built dist/bin/ito.js absolute path');\n}","typeGuard":null,"tryCatchPattern":"try {\n  const exe = resolveItoExecutable(process.env);\n} catch (e) {\n  if (e.message.includes('unpublished')) {\n    console.error('Build the CLI from the canonical repo and export ECC_ITO_CLI_EXECUTABLE=/path/to/dist/bin/ito.js');\n  } else throw e;\n}","preventionTips":["Add ECC_ITO_CLI_EXECUTABLE setup (clone, npm ci, build, export) to onboarding/CI bootstrap scripts","Assert the env var is set in pre-flight before any ecc ito invocation","Never rely on PATH lookup for ito — the override is mandatory by design"],"tags":["cli","environment","security","executable"],"backgroundTag":"missing-env-var","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}