{"record":{"id":"55b6775b5aba4957","repo":"Hmbown/CodeWhale","slug":"payload-exceeds-max-payload-bytes-bytes","errorCode":null,"errorMessage":"payload exceeds ${MAX_PAYLOAD_BYTES} bytes","messagePattern":"payload exceeds (.+?) bytes","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"web/scripts/facts-publish.mjs","lineNumber":298,"sourceCode":"    published_at: publishedAt,\n    applies_to: typeof source.applies_to === \"string\" ? source.applies_to.trim() : \"*\",\n    models: source.models ?? [],\n    provider_defaults: source.provider_defaults ?? {},\n    release: source.release ?? null,\n    announcements: source.announcements ?? [],\n  };\n  if (source.not_after) payload.not_after = source.not_after;\n  const payloadErrors = validateSource(payload);\n  if (payloadErrors.length || utcTime(publishedAt) === null || !Number.isSafeInteger(factsVersion) || factsVersion <= 0 || !CHANNEL_RE.test(channel)) {\n    throw new Error(\"invalid signed payload metadata\");\n  }\n  return payload;\n}\n\nexport function buildEnvelope({ privateKey, keyId, payload }) {\n  if (!KEY_ID_RE.test(keyId)) throw new Error(`key_id must match ${KEY_ID_RE}`);\n  const payloadBytes = Buffer.from(canonicalize(payload), \"utf8\");\n  if (payloadBytes.length > MAX_PAYLOAD_BYTES) throw new Error(`payload exceeds ${MAX_PAYLOAD_BYTES} bytes`);\n  const sig = signPayload(privateKey, keyId, payloadBytes);\n  const sha256 = createHash(\"sha256\").update(payloadBytes).digest(\"hex\");\n  const envelope = {\n    envelope: ENVELOPE_VERSION,\n    channel: payload.channel,\n    facts_version: payload.facts_version,\n    schema_version: payload.schema_version,\n    key_id: keyId,\n    alg: \"ed25519\",\n    applies_to: payload.applies_to,\n    published_at: payload.published_at,\n    payload_b64: payloadBytes.toString(\"base64\"),\n    sig_b64: sig.toString(\"base64\"),\n    sigs: [],\n    sha256,\n  };\n  if (payload.not_after != null) envelope.not_after = payload.not_after;\n  const pub = rawPublicKeyFromKeyObject(createPublicKey(privateKey)).toString(\"base64\");","sourceCodeStart":280,"sourceCodeEnd":316,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/web/scripts/facts-publish.mjs#L280-L316","documentation":"buildEnvelope canonicalizes the payload to JSON bytes and enforces MAX_PAYLOAD_BYTES before signing. This error means the canonicalized payload is larger than the repository's published size budget, so the envelope is refused rather than signed and shipped. The limit keeps published facts documents bounded and verifiable cheaply.","triggerScenarios":"buildEnvelope({ privateKey, keyId, payload }) where Buffer.from(canonicalize(payload)).length > MAX_PAYLOAD_BYTES — i.e. the canonical JSON of the facts payload exceeds the byte budget.","commonSituations":"Accumulating too many facts in one publish; embedding large blobs or verbose generated data in the payload; a change in canonicalization that inflates output (e.g. more escaped unicode); forgetting to prune stale facts.","solutions":["Measure canonicalize(payload).length and trim the payload below MAX_PAYLOAD_BYTES","Split the facts into multiple payloads and publish several envelopes","Remove bulky or redundant facts (large strings, duplicated entries)","If the limit is genuinely too small, raise MAX_PAYLOAD_BYTES deliberately in the script and republish with awareness that verifiers may enforce it too"],"exampleFix":"// before\nawait buildEnvelope({ privateKey, keyId, payload: { channel, facts_version, facts: allFacts } });\n// after\nconst json = canonicalize(payload);\nif (Buffer.byteLength(json) > MAX_PAYLOAD_BYTES) {\n  payload.facts = payload.facts.slice(0, 100); // trim\n}\nawait buildEnvelope({ privateKey, keyId, payload });","handlingStrategy":"validation","validationCode":"import { canonicalize, MAX_PAYLOAD_BYTES } from './facts-publish.mjs';\nconst bytes = Buffer.from(canonicalize(payload), 'utf8');\nif (bytes.length > MAX_PAYLOAD_BYTES) throw new Error(`payload ${bytes.length}B > limit ${MAX_PAYLOAD_BYTES}B; trim facts`);","typeGuard":"const fitsPayloadLimit = (payload) => Buffer.byteLength(canonicalize(payload), 'utf8') <= MAX_PAYLOAD_BYTES;","tryCatchPattern":"try { env = buildEnvelope({ privateKey, keyId, payload }); } catch (e) { if (e.message.includes('payload exceeds')) { console.error('Shrink the facts payload or split into batches'); process.exit(2); } throw e; }","preventionTips":["Check canonicalize(payload).length in CI before publishing","Prune or archive stale facts regularly","Avoid embedding large blobs in fact entries","Split large fact sets into multiple publishes by design"],"tags":["validation","size-limit","payload"],"backgroundTag":"payload-too-large","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}