abhigyanpatwari/GitNexus · error
Analyzer runtime payload scan exceeded depth
Error message
Analyzer runtime payload scan exceeded depth ${limits.runtimeDepth}: ${absolutePath} What it means
During the runtime payload scan, a subdirectory found at depth >= limits.runtimeDepth (default 64) triggers this abort instead of a silent skip. Depth is per package root, and node_modules is pruned by name and traversed separately via manifest resolution, so this measures genuinely nested payload directories. Truncating deep trees would let changes below the cutoff escape the receipt, so it fails closed.
Solutions
- Find the deep chain: 'find node_modules/<pkg> -mindepth 64 -type d' and inspect what generated it.
- Remove or flatten the offending nested tree; reinstall the package if its install script created the recursion.
- In tests, keep traversalLimits.runtimeDepth at/above the fixture's actual nesting (default cap 64).
Defensive patterns
Strategy: try-catch
Type guard
function isRuntimeDepthLimitError(error: unknown): boolean {
return error instanceof Error && /^Analyzer runtime payload scan exceeded depth \d+:/.test(error.message);
} Try / catch
try {
identity = resolveAnalyzerRunnerIdentity(import.meta.url);
} catch (error) {
if (isRuntimeDepthLimitError(error)) {
reportUserError('A dependency nests deeper than 64 levels; flatten or reinstall the offending package.');
}
throw error;
} Prevention
- Audit generated vendor trees for runaway nesting: find node_modules/<pkg> -mindepth 64 -type d.
- Avoid package postinstall scripts that mirror structures recursively.
- Keep runtimeDepth at the default in tests unless the fixture is provably shallow.
When it happens
Trigger: A dependency package contains >64 levels of nested directories (outside node_modules/.git/.hg/.svn) — typically recursively generated code or a tool that mirrors deep structures inside its package — or a test set runtimeDepth below the fixture's nesting.
Common situations: Generated source trees with pathological nesting vendored inside a package; test fixtures with tight runtimeDepth; broken packages whose install scripts created recursive directory structures.
Related errors
- Analyzer build scan exceeded depth
- Analyzer dependency graph exceeded
- Analyzer dependency resolution exceeded
- Analyzer runtime payload scan exceeded
- Analyzer runtime payload scan exceeded
AI-assisted analysis of abhigyanpatwari/GitNexus@52924ef12c (2026-08-20).
Data as JSON: /api/errors/ab32440166cfda69.
Report an issue: GitHub.
Appendix: source
Thrown at gitnexus/src/core/analyzer-identity.ts:1352
const stat = lstatSync(absolutePath);
// Nested dependencies are collected from their manifests as separate
// packages. Only prune those separately traversed trees and VCS
// metadata; generic cache/model directories can contain loadable code,
// native addons, Wasm modules, or data consumed by the runtime.
//
// Pruning is decided by NAME alone. These four names never carry analyzer
// payload in any form: `node_modules` is traversed separately through
// `resolveDependencyPackageRoot` (which follows links and guards each
// hop), and a `.git`/`.hg`/`.svn` entry is VCS metadata whether it is a
// directory, a symbolic link into a shared store, or — inside a submodule
// or linked worktree checkout — a regular file holding a gitdir pointer.
// Hashing that pointer would make analyzer identity depend on where the
// checkout happens to live, which is a false-stale source, not a
// semantic input.
if (PRUNED_RUNTIME_DIRECTORIES.has(entry.name)) continue;
if (stat.isDirectory()) {
if (depth >= limits.runtimeDepth) {
throw new Error(
`Analyzer runtime payload scan exceeded depth ${limits.runtimeDepth}: ${absolutePath}`,
);
}
pending.push({ absoluteDir: absolutePath, depth: depth + 1 });
} else if (stat.isSymbolicLink() && !isFile(absolutePath)) {
// A symbolic link that does not resolve to a regular file must never
// reach the payload branch below: `snapshotReadableFile` stats the
// target, and a directory (or a dangling link) makes it throw, aborting
// the entire analyze. Workspace-linked checkouts made this reachable
// for every name, not just the pruned four — `dist -> build`, a
// vendored-grammar link, anything a sibling checkout ships.
//
// Such links are RECORDED by their link text rather than followed.
// Following them would (a) recurse without cycle protection — this
// traversal has none, so `self -> .` would ride the depth limit, which
// THROWS, trading one hard abort for another; (b) re-scan trees already
// reached by their real path, inflating the entry/byte budgets that
// also throw; and (c) need a whole containment/TOCTOU trust boundaryView on GitHub (pinned to 52924ef12c)