{"record":{"id":"6a1eca588e450606","repo":"affaan-m/ECC","slug":"remote-import-exceeds-max-bytes-bytes","errorCode":null,"errorMessage":"remote import exceeds {max_bytes} bytes","messagePattern":"remote import exceeds (.+?) bytes","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/continuous-learning-v2/scripts/instinct-cli.py","lineNumber":234,"sourceCode":"            raise ValueError(f\"remote import host resolves to a non-public address: {host}\")\n\n    return urllib.parse.urlunparse(parsed)\n\n\ndef _fetch_import_url(source: str, *, max_bytes: int = 2 * 1024 * 1024) -> str:\n    \"\"\"Fetch a validated remote instinct file with bounded size and timeout.\"\"\"\n    url = _validate_import_url(source)\n    req = urllib.request.Request(url, headers={\"User-Agent\": \"ECC-instinct-import/2\"})\n    with urllib.request.urlopen(req, timeout=15) as response:\n        content_type = response.headers.get(\"Content-Type\", \"\")\n        if content_type and not any(\n            allowed in content_type.lower()\n            for allowed in (\"text/\", \"markdown\", \"yaml\", \"json\", \"octet-stream\")\n        ):\n            raise ValueError(f\"unsupported remote content type: {content_type}\")\n        data = response.read(max_bytes + 1)\n    if len(data) > max_bytes:\n        raise ValueError(f\"remote import exceeds {max_bytes} bytes\")\n    return data.decode(\"utf-8\")\n\n\ndef _yaml_quote(value: str) -> str:\n    \"\"\"Quote a string for safe YAML frontmatter serialization.\n\n    Uses double quotes and escapes embedded double-quote characters to\n    prevent malformed YAML when the value contains quotes.\n    \"\"\"\n    escaped = value.replace('\\\\', '\\\\\\\\').replace('\"', '\\\\\"')\n    return f'\"{escaped}\"'\n\n\n# ─────────────────────────────────────────────\n# Project Detection (Python equivalent of detect-project.sh)\n# ─────────────────────────────────────────────\n\ndef _git_repo_root(cwd: Optional[str] = None) -> Optional[str]:","sourceCodeStart":216,"sourceCodeEnd":252,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/continuous-learning-v2/scripts/instinct-cli.py#L216-L252","documentation":"Raised by _fetch_import_url when the downloaded body exceeds max_bytes (default 2 MiB). The function reads at most max_bytes+1 bytes and rejects anything longer, so oversized remote files are never fully buffered or parsed. It is a bounded-download safeguard against huge or hostile payloads.","triggerScenarios":"Importing from a URL whose body is larger than 2 MiB — a very large instincts file, an accidentally linked archive/dump, or a server streaming an unbounded response.","commonSituations":"Exported instinct library grew past 2 MB over time; link points to a full data dump instead of the curated file; attacker-controlled URL used to push a large payload.","solutions":["Trim or split the remote file so it is under the size limit (default 2 MiB).","Serve only the needed instincts and import them in multiple smaller files.","If larger imports are legitimately required, pass/increase max_bytes when calling _fetch_import_url (with care).","Check Content-Length with a HEAD request before fetching to warn users early."],"exampleFix":"# before\ncontent = _fetch_import_url(url)  # file is 5 MB -> raises\n# after\ncontent = _fetch_import_url(url, max_bytes=10 * 1024 * 1024)  # explicit larger bound\n# or split the source file into <2 MiB chunks","handlingStrategy":"validation","validationCode":"import urllib.request\nreq = urllib.request.Request(source, method=\"HEAD\")\nwith urllib.request.urlopen(req, timeout=15) as r:\n    size = int(r.headers.get(\"Content-Length\", 0))\nif size > 2 * 1024 * 1024:\n    raise ValueError(\"remote file exceeds 2 MiB import limit\")","typeGuard":null,"tryCatchPattern":"try:\n    cli_import(url=source)\nexcept ValueError as e:\n    if \"exceeds\" in str(e):\n        print(\"remote file too large; split or trim it\")","preventionTips":["Keep exported instinct libraries under 2 MiB or split them","HEAD-check Content-Length before importing","Point at curated files, not raw data dumps","Raise max_bytes explicitly only when the source is trusted"],"tags":["python","network","size-limit","security"],"backgroundTag":"file-size-limit-exceeded","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}