Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for ARC-1

Pod holds 12 of 12 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to ARC-1.

Most discussed

BTP Audit Log sink logs 'enabled' with a non-x509 binding and then fails silently — no event is ever written

Summary

When the auditlog (plan premium) service instance is created without X.509 parameters, the binding carries uaa.clientid / uaa.clientsecret but no uaa.certurl / uaa.certificate / uaa.key. parseBTPAuditLogConfig() accepts that binding without validation, the startup log prints INFO: BTP Audit Log sink enabled {"url": …}, and every subsequent send fails inside .catch(). No event is ever written, and nothing tells the operator.

Environment

Read the thread · 2026-09-17 · closed · outside contributor · 2 comments

[Feature]: Protect user changes from being overwritten

Preflight

Problem / use case

As someone wanting to use arc-1 to develop productive code I am very likely to change code manually during a agent session.

Currently it can easily happen that an agent using arc-1 overwrites my changes in between prompts.

Proposed solution

SAPWrite with update/edit_unit needs some kind of mechanism that stops this behavior. Some different ideas from me: Option 1:…

Read the thread · 2026-09-25 · closed · external user · 1 comment

[Bug]: Pre-write lint blocks a valid edit_unit because of unchanged surrounding code

Preflight checks

ARC-1 version

1.0.2

SAP system

SAP S/4HANA (on-premise…

Read the thread · 2026-09-10 · open · external user · 1 comment

bug: preserve tool-call IDs in multi-turn Anthropic evals

Multi-turn evaluations with EVAL_PROVIDER=anthropic build an invalid tool-result conversation on the second model request. The replayed tool_use.id and its tool_result.tool_use_id differ. This prevents reliable evaluation of workflows that consume tool results; the new maxToolCalls: 1 scenarios do not expose it.

Reproduced on main 202ad5668e00f8cd8c9c828dd56d54dbb7c1d9f5, Node 22.21.1, through the real eval harness and Anthropic adapter with intercepted fetch. **No Anthropic API or…

Read the thread · 2026-09-25 · closed · 0 comments

[Feature]: Mixed read/write SAPDiagnose actions cause approval overhead for read-only syntax checks

Preflight

Problem / use case

SAPDiagnose intentionally exposes readOnlyHint=false because it contains both read-only diagnostic actions and actions with side effects.

In my Codex setup (approval_policy=on-request, approvals_reviewer=auto_review), this means that high-frequency read-only calls such as SAPDiagnose(action="syntax", ...) also go through approval review.

I measured the local…

Read the thread · 2026-09-23 · closed · external user · 0 comments

[Feature]: CSRF token fetch is hardcoded to /sap/bc/adt/core/discovery — every write/SQL call fails on ABAP backends that implement /sap/bc/adt/discovery but not /sap/bc/adt/core/discovery

Preflight

Problem / use case

Hi Marian

Thanks for your work in this space. We stand on the shoulders of giants.

We have a very old ECC system (and some of our clients do too hence the need to maintain this system, and sometimes generate code for these older systems). when working with this system, I cannot utilise ARC1 like I would with our S4 system(s) (where it works very well!).

My Claude…

Read the thread · 2026-09-21 · closed · external user · 0 comments

[Bug]: xs-security.json ships redirect URIs that XSUAA now rejects — cf create-service fails with "Malformed redirect URIs detected"

Preflight checks

Environment

ARC-1 version: 1.3.0 — origin/main @ 2940971f; xs-security.json unchanged since #212 (v0.8.0) **SAP…

Read the thread · 2026-09-20 · closed · outside contributor · 0 comments

1.2.0: 304 from ADT crashes the process — unhandled UND_ERR_ABORTED in connectivityProxyResponse

Summary

On 1.2.0, a 304 Not Modified from ADT crashes the process with exit status 1. connectivityProxyResponse drops the undici response body with destroy() before anything listens for error; undici then raises UND_ERR_ABORTED on that stream, and because the server registers no uncaughtException/unhandledRejection handler, Node terminates the process.

We hit this on two BTP Cloud Foundry landscapes (NetWeaver 7.50 and S/4 816, both http-streamable with XSUAA + principal…

Read the thread · 2026-09-17 · closed · external user · 0 comments

Most recent

SAP_BLOCKED_DATA_SOURCES denies every data request on SAP_BASIS 7.50 — lineage resolver reads /ddic/tables//source/main (absent before 7.52), no release gate

Summary

With a non-empty SAP_BLOCKED_DATA_SOURCES, every data request on a SAP_BASIS 7.50 system is denied with DATA_LINEAGE_UNRESOLVED — including tables that are not on the list, and including SAPRead(TABLE_QUERY) / SAPRead(TABLE_CONTENTS). The lineage resolver reads /sap/bc/adt/ddic/tables/<NAME>/source/main for every direct source; that resource does not exist before SAP_BASIS 7.52, SAP answers 404, and the policy fails closed as designed.

The blocklist itself behaves…

Read the thread · 2026-09-17 · closed · outside contributor · 0 comments

[Feature]: Make the user-agent string configurable

Preflight

Problem / use case

There is barely no possibility to identify in the SAP system whether a request to /sap/bc/adt/* has been sent from ADT or via MCP or by any other means.

Proposed solution

A configurable user-agent string could be used to log calls from arc-1 in the ICM log, e.g., by using a custom logging configuration which includes %{user-agent}i (icm/HTTP/logging_<xx>).…

Read the thread · 2026-09-16 · closed · external user · 0 comments

[Bug]: SAPWrite leaves one stateful HTTP application session in SM04 until server timeout

Preflight checks

ARC-1 version

1.2.0

SAP system

SAP S/4HANA (on-premise…

Read the thread · 2026-09-16 · closed · external user · 0 comments

[Feature]: Accept a server-readable source file path for large writes

Preflight

Problem / use case

Related: #558 — its motivation is precisely that inlining a large program as a JSON source string makes the client time out generating the payload; #558 solved the replace-a-unit case. A file-path input addresses the cases edit_unit doesn't cover (adding a unit per Enhancement A, or a genuine whole-file rewrite).

Problem / use case: SAPWrite accepts…

Read the thread · 2026-09-10 · open · external user · 0 comments

The remaining reports are on the project's issue tracker.