{"record":{"id":"ee95066111e0b246","repo":"affaan-m/ECC","slug":"refusing-to-access-memory-through-symlink-root","errorCode":null,"errorMessage":"Refusing to access memory through symlink root: ${root}","messagePattern":"Refusing to access memory through symlink root: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/lib/memory-vault.js","lineNumber":111,"sourceCode":"  });\n  return Object.freeze(roots);\n}\n\nfunction assertMemoryRootSafe(roots, scope) {\n  if (!roots || typeof roots !== 'object' || Array.isArray(roots)) {\n    throw new Error('Memory roots must include a trusted boundary policy.');\n  }\n  const root = roots[scope];\n  if (typeof root !== 'string' || root.length === 0) {\n    throw new Error(`No memory root is configured for scope \"${scope}\".`);\n  }\n  const boundary = roots[VAULT_ROOT_BOUNDARIES]?.[scope];\n  if (typeof boundary !== 'string' || boundary.length === 0) {\n    throw new Error(`No trusted boundary policy is configured for memory scope \"${scope}\".`);\n  }\n  assertWithinTrustedRoot(root, boundary, 'access memory through a symlink');\n  if (fs.existsSync(root) && fs.lstatSync(root).isSymbolicLink()) {\n    throw new Error(`Refusing to access memory through symlink root: ${root}`);\n  }\n  return root;\n}\n\nfunction assertMemoryDirectorySafe(directory, root) {\n  assertWithinTrustedRoot(directory, root, 'access memory directory');\n  if (fs.existsSync(directory) && fs.lstatSync(directory).isSymbolicLink()) {\n    throw new Error(`Refusing to access memory through symlink directory: ${directory}`);\n  }\n  return directory;\n}\n\nfunction sameFileIdentity(left, right) {\n  // The inode is the primary identity signal and must always match.\n  if (left.ino !== right.ino) {\n    return false;\n  }\n  // libuv 1.49.0 through 1.50.x resolve path-based stat() and lstat() on Windows","sourceCodeStart":93,"sourceCodeEnd":129,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/memory-vault.js#L93-L129","documentation":"assertWithinTrustedRoot throws when the configured memory root for a scope resolves outside its trusted boundary via a symlink, refusing potential symlink-escape attacks on the memory vault. The faulting input is the symlinked root path shown in the message.","triggerScenarios":"Thrown at scripts/lib/memory-vault.js:111 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Replace the symlink with a real directory, or point the scope's root env var at the real path.","Ensure the trusted boundary directory contains the actual (resolved) root.","Do not relocate memory roots via symlinks across filesystem boundaries."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}