Hmbown/CodeWhale · warning · Error
The update service exceeded its response size limit.
Error message
The update service exceeded its response size limit.
What it means
responseBytes streams an HTTP response body while enforcing a maximum byte size; when the accumulated size exceeds the limit (1 MiB for the release metadata check), it throws immediately without buffering the rest. This protects against a malicious or malfunctioning update service returning an oversized payload.
Solutions
- Retry later — the official release metadata should be well under 1 MiB, so this usually indicates a transient or intermediary problem
- Check for proxies/VPNs intercepting api.github.com and returning injected content
- If releases legitimately grow, raise the 1024*1024 maximum passed to responseBytes
Example fix
// before (fixed 1 MiB cap)
return releaseUpdate(JSON.parse((await responseBytes(response, 1024 * 1024)).toString("utf8")));
// after (raise cap if release metadata legitimately grows)
return releaseUpdate(JSON.parse((await responseBytes(response, 4 * 1024 * 1024)).toString("utf8"))); Defensive patterns
Strategy: try-catch
Validate before calling
const cl = response.headers.get("content-length");
if (cl && Number(cl) > 1024 * 1024) throw new Error("release metadata too large"); Try / catch
try {
await checkForUpdate();
} catch (e) {
if (e.message.includes("response size limit")) {
log.warn("Update service returned oversized payload; skipping check");
} else throw e;
} Prevention
- Keep release metadata lean (few assets, no giant release notes)
- Inspect proxy/VPN behavior that may inflate API responses
- Raise the size cap deliberately if release metadata legitimately grows
- Prefer authenticated, pinned API endpoints over intercepting proxies
When it happens
Trigger: checkForUpdate receiving a GitHub API response larger than 1 MiB — e.g. a release with thousands of assets, a proxy injecting content, or a hostile response impersonating the API.
Common situations: Extremely large release metadata; corporate proxy or captive portal returning bloated HTML instead of JSON; attacker-controlled response in a MitM scenario.
Understand the failure class
Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.
Related errors
- bundle redirects may not change URL scheme
- Refusing insecure base URL
- building bundle fetch client failed
- bundle fetch failed with HTTP status
- bundle fetch request failed
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/ee474943cf4ec102.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/plugins/computer-use/app/updates.mjs:25
import { inflateRawSync } from "node:zlib";
import { replaceMacBundle, verifyReleaseBundle } from "./install-macos.mjs";
import { APP_VERSION, APP_NAME } from "../src/app-socket.mjs";
import { stateDir } from "../src/registry.mjs";
const repository="https://github.com/Hmbown/codewhale-cu-plugin";
const limit=256*1024*1024;
const updateResultPath=()=>path.join(stateDir(),"update-result.json");
export function readUpdateResult() {
try {
if(fs.statSync(updateResultPath()).size>4096) return null;
const result=JSON.parse(fs.readFileSync(updateResultPath(),"utf8"));
if(typeof result.ok!=="boolean"||typeof result.message!=="string"||result.message.length>1000) return null;
return {available:false,message:result.message};
} catch { return null; }
}
async function responseBytes(response, maximum) {
const chunks=[]; let size=0;
for await(const chunk of response.body) { size+=chunk.length; if(size>maximum) throw new Error("The update service exceeded its response size limit."); chunks.push(chunk); }
return Buffer.concat(chunks);
}
export function newerVersion(candidate,current) {
const parse=value=>/^\d+\.\d+\.\d+$/.test(value)?value.split(".").map(Number):null;
const a=parse(candidate),b=parse(current); if(!a||!b) return false;
for(let i=0;i<3;i++) { if(a[i]!==b[i]) return a[i]>b[i]; } return false;
}
export function releaseUpdate(release,current=APP_VERSION) {
const version=release?.tag_name?.replace(/^v/,"");
if(!version||release.draft||release.prerelease||!newerVersion(version,current)) return {available:false,message:`You have Computer Use ${current}. No newer stable installer is available.`};
const name=`Codewhale-Computer-Use-${version}-macos-universal.zip`;
const asset=release.assets?.find(asset=>asset.name===name);
const url=`${repository}/releases/download/v${version}/${name}`;
if(!asset||asset.browser_download_url!==url||!/^sha256:[a-f0-9]{64}$/.test(asset.digest)||!Number.isSafeInteger(asset.size)||asset.size<=0||asset.size>limit) return {available:false,message:`Version ${version} has no verified macOS installer yet.`};
return {available:true,version,url,sha256:asset.digest.slice(7),size:asset.size,message:`Computer Use ${version} is available. Install it to restart the helper; existing computer sessions will stop.`};
}
export async function checkForUpdate() {
const response=await fetch("https://api.github.com/repos/Hmbown/codewhale-cu-plugin/releases/latest",{redirect:"error",headers:{Accept:"application/vnd.github+json","X-GitHub-Api-Version":"2022-11-28"},signal:AbortSignal.timeout(10_000)});View on GitHub (pinned to 73e0f67d83)