{"record":{"id":"02a0f3e3ed567b73","repo":"siyuan-note/siyuan","slug":"marketplace-package-contains-a-file-that-is-too-la","errorCode":null,"errorMessage":"marketplace package contains a file that is too large","messagePattern":"marketplace package contains a file that is too large","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/bazaar/local.go","lineNumber":106,"sourceCode":"\nfunc extractLocalPackageArchive(archivePath, destination string) error {\n\treader, err := zip.OpenReader(archivePath)\n\tif err != nil {\n\t\treturn errors.New(\"invalid marketplace package archive\")\n\t}\n\tdefer reader.Close()\n\n\tif len(reader.File) == 0 {\n\t\treturn errors.New(\"marketplace package archive is empty\")\n\t}\n\tif len(reader.File) > maxLocalPackageFileCount {\n\t\treturn errors.New(\"marketplace package contains too many files\")\n\t}\n\n\tvar declaredTotal uint64\n\tfor _, item := range reader.File {\n\t\tif item.UncompressedSize64 > maxLocalPackageFileSize {\n\t\t\treturn errors.New(\"marketplace package contains a file that is too large\")\n\t\t}\n\t\tif ^uint64(0)-declaredTotal < item.UncompressedSize64 {\n\t\t\treturn errors.New(\"marketplace package is too large\")\n\t\t}\n\t\tdeclaredTotal += item.UncompressedSize64\n\t\tif declaredTotal > maxLocalPackageExtractSize {\n\t\t\treturn errors.New(\"marketplace package is too large\")\n\t\t}\n\t}\n\n\tif err = os.MkdirAll(destination, 0755); err != nil {\n\t\treturn err\n\t}\n\tvar extractedTotal uint64\n\tfor _, item := range reader.File {\n\t\tif err = extractLocalPackageItem(item, destination, &extractedTotal); err != nil {\n\t\t\treturn err\n\t\t}","sourceCodeStart":88,"sourceCodeEnd":124,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/bazaar/local.go#L88-L124","documentation":"Each zip entry's declared uncompressed size (UncompressedSize64) is checked against maxLocalPackageFileSize (256 MiB). A single entry declaring more than this is rejected before extraction, since legitimately no marketplace package needs such a file.","triggerScenarios":"Calling ExtractLocalPackage with a zip where one entry's header UncompressedSize64 exceeds 256 MiB.","commonSituations":"Bundling a huge video/model/database dump inside the package; a malicious zip with a lying header is caught here before extraction; accidentally zipping a large build artifact.","solutions":["Remove oversized assets from the package or host them externally (CDN/asset store)","Compress or split large data files","Check entry sizes with unzip -l before uploading"],"exampleFix":"// before: package includes assets/model.bin (400 MB)\n// after: remove model.bin; download it at runtime or shrink below 256 MiB","handlingStrategy":"validation","validationCode":"const sizes = execSync(`unzip -l ${zipPath}`).toString().split(\"\\n\");\nconst oversized = sizes.some(l => parseInt(l.trim().split(/\\s+/)[0], 10) > 256 * 1024 * 1024);\nif (oversized) throw new Error(\"an entry exceeds the 256 MiB per-file limit\");","typeGuard":null,"tryCatchPattern":"try { await installLocalPackage(zipPath); } catch (e) { if (String(e).includes(\"file that is too large\")) { /* remove or shrink the big entry */ } }","preventionTips":["Check the largest entry with unzip -l","Keep individual assets well under 256 MiB","Host very large assets externally"],"tags":["bazaar","zip","limit","file-size"],"backgroundTag":"file-size-limit-exceeded","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}