Hmbown/CodeWhale · warning · Error

The update service exceeded its response size limit.

Error message

The update service exceeded its response size limit.

What it means

responseBytes streams an HTTP response body while enforcing a maximum byte size; when the accumulated size exceeds the limit (1 MiB for the release metadata check), it throws immediately without buffering the rest. This protects against a malicious or malfunctioning update service returning an oversized payload.

Solutions

  1. Retry later — the official release metadata should be well under 1 MiB, so this usually indicates a transient or intermediary problem
  2. Check for proxies/VPNs intercepting api.github.com and returning injected content
  3. If releases legitimately grow, raise the 1024*1024 maximum passed to responseBytes

Example fix

// before (fixed 1 MiB cap)
return releaseUpdate(JSON.parse((await responseBytes(response, 1024 * 1024)).toString("utf8")));
// after (raise cap if release metadata legitimately grows)
return releaseUpdate(JSON.parse((await responseBytes(response, 4 * 1024 * 1024)).toString("utf8")));
Defensive patterns

Strategy: try-catch

Validate before calling

const cl = response.headers.get("content-length");
if (cl && Number(cl) > 1024 * 1024) throw new Error("release metadata too large");

Try / catch

try {
  await checkForUpdate();
} catch (e) {
  if (e.message.includes("response size limit")) {
    log.warn("Update service returned oversized payload; skipping check");
  } else throw e;
}

Prevention

When it happens

Trigger: checkForUpdate receiving a GitHub API response larger than 1 MiB — e.g. a release with thousands of assets, a proxy injecting content, or a hostile response impersonating the API.

Common situations: Extremely large release metadata; corporate proxy or captive portal returning bloated HTML instead of JSON; attacker-controlled response in a MitM scenario.

Understand the failure class

Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/ee474943cf4ec102. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/plugins/computer-use/app/updates.mjs:25

import { inflateRawSync } from "node:zlib";
import { replaceMacBundle, verifyReleaseBundle } from "./install-macos.mjs";
import { APP_VERSION, APP_NAME } from "../src/app-socket.mjs";
import { stateDir } from "../src/registry.mjs";

const repository="https://github.com/Hmbown/codewhale-cu-plugin";
const limit=256*1024*1024;
const updateResultPath=()=>path.join(stateDir(),"update-result.json");
export function readUpdateResult() {
  try {
    if(fs.statSync(updateResultPath()).size>4096) return null;
    const result=JSON.parse(fs.readFileSync(updateResultPath(),"utf8"));
    if(typeof result.ok!=="boolean"||typeof result.message!=="string"||result.message.length>1000) return null;
    return {available:false,message:result.message};
  } catch { return null; }
}
async function responseBytes(response, maximum) {
  const chunks=[]; let size=0;
  for await(const chunk of response.body) { size+=chunk.length; if(size>maximum) throw new Error("The update service exceeded its response size limit."); chunks.push(chunk); }
  return Buffer.concat(chunks);
}
export function newerVersion(candidate,current) {
  const parse=value=>/^\d+\.\d+\.\d+$/.test(value)?value.split(".").map(Number):null;
  const a=parse(candidate),b=parse(current); if(!a||!b) return false;
  for(let i=0;i<3;i++) { if(a[i]!==b[i]) return a[i]>b[i]; } return false;
}
export function releaseUpdate(release,current=APP_VERSION) {
  const version=release?.tag_name?.replace(/^v/,"");
  if(!version||release.draft||release.prerelease||!newerVersion(version,current)) return {available:false,message:`You have Computer Use ${current}. No newer stable installer is available.`};
  const name=`Codewhale-Computer-Use-${version}-macos-universal.zip`;
  const asset=release.assets?.find(asset=>asset.name===name);
  const url=`${repository}/releases/download/v${version}/${name}`;
  if(!asset||asset.browser_download_url!==url||!/^sha256:[a-f0-9]{64}$/.test(asset.digest)||!Number.isSafeInteger(asset.size)||asset.size<=0||asset.size>limit) return {available:false,message:`Version ${version} has no verified macOS installer yet.`};
  return {available:true,version,url,sha256:asset.digest.slice(7),size:asset.size,message:`Computer Use ${version} is available. Install it to restart the helper; existing computer sessions will stop.`};
}
export async function checkForUpdate() {
  const response=await fetch("https://api.github.com/repos/Hmbown/codewhale-cu-plugin/releases/latest",{redirect:"error",headers:{Accept:"application/vnd.github+json","X-GitHub-Api-Version":"2022-11-28"},signal:AbortSignal.timeout(10_000)});

View on GitHub (pinned to 73e0f67d83)