the error register
NIKA-SEC-001
exec refused before the child spawns — either the shell floor (a destructive/privilege pattern · always-on · independent of permits:) or the mock plane under `nika test`, which refuses EVERY command by design (it simulates the model, not effects) · under test the exit is `nika run` for real effects, or an `on_error: recover` rehearsal on the task. A typed refusal, one of 103 the registry names: stable code, spec category, the transient flag the retry machinery reads. The engine stamps this page's address on the finding itself. Route on the code, never on prose. Machines read the catalog.
- security_errorcategorya security policy refused the effect
- stablea retry cannot helpfix the file, not the timing
- 1of 14 in NIKA-SECprev / next walk the registry
- 103registered codesthe normative floor · versioned
hear it from the binary
nika explain NIKA-SEC-001 answers offline with the failure, the fix shape and this page's address: the same text the check finding carries. A code is a contract: never renamed, never repurposed, safe to route on in on_codes and retry policy.
cross-references
the family it sits in
the NIKA-SEC codes
14 codesBreak a file on purpose in the playground and watch the code arrive typed. The boundary teaches the security family. Read the spec →