{"record":{"id":"7886aa605fe6544b","repo":"siyuan-note/siyuan","slug":"checksum-manifest-is-too-large","errorCode":null,"errorMessage":"checksum manifest is too large","messagePattern":"checksum manifest is too large","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"kernel/model/updater_release.go","lineNumber":399,"sourceCode":"\t}\n\n\tresponse, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\tif nil == response || nil == response.Response {\n\t\treturn \"\", errors.New(\"checksum manifest response is empty\")\n\t}\n\tdefer response.Body.Close()\n\tif 200 != response.StatusCode {\n\t\treturn \"\", fmt.Errorf(\"get checksum manifest failed: %d\", response.StatusCode)\n\t}\n\tdata, err := io.ReadAll(io.LimitReader(response.Body, maxChecksumManifestSize+1))\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\tif maxChecksumManifestSize < int64(len(data)) {\n\t\treturn \"\", errors.New(\"checksum manifest is too large\")\n\t}\n\tif \"\" != manifestDigest {\n\t\tactualDigest := fmt.Sprintf(\"%x\", sha256.Sum256(data))\n\t\tif manifestDigest != actualDigest {\n\t\t\treturn \"\", errors.New(\"checksum manifest digest mismatch\")\n\t\t}\n\t}\n\tmanifest := string(data)\n\tif \"\" != manifestCacheKey {\n\t\tgithubManifestCache.Store(manifestCacheKey, manifest)\n\t}\n\tchecksum := parseChecksumManifest(manifest, pkgName)\n\tif \"\" == checksum {\n\t\treturn \"\", errors.New(\"package checksum is unavailable\")\n\t}\n\treturn checksum, nil\n}\n","sourceCodeStart":381,"sourceCodeEnd":417,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/updater_release.go#L381-L417","documentation":"The downloaded SHA256SUMS.txt is read through an io.LimitReader capped at maxChecksumManifestSize (1 MiB) plus one byte. If more than 1 MiB of data is produced, the manifest is considered corrupt or malicious and the fetch fails with this error before any parsing. The upstream caller degrades to no-checksum with a warning.","triggerScenarios":"io.ReadAll on the limited reader returning maxChecksumManifestSize+1 bytes — i.e. the response body exceeds the 1 MiB manifest size cap. Requires the SHA256SUMS.txt asset served at the URL to be larger than 1 MiB or a non-manifest payload at that URL.","commonSituations":"A compromised or mis-packaged release containing a bloated manifest; a CDN/proxy returning an HTML error page or interstitial that inflates the body beyond the cap; man-in-the-middle injection on insecure egress.","solutions":["Download SHA256SUMS.txt manually and check its size/content — if it is over 1 MiB or is not a checksum list, do not trust that release and report it","Retry from a different network to rule out proxy/injected content","Wait for a re-published release with a correct manifest; meanwhile install manually and verify hashes yourself","Note the digest check (manifestDigest vs sha256 of body) runs after this size check, so an attacker-substituted manifest will additionally fail with 'checksum manifest digest mismatch'"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"info, _ := os.Stat(\"SHA256SUMS.txt\")\nmanifestSizeOK := info != nil && info.Size() > 0 && info.Size() <= 1024*1024","typeGuard":null,"tryCatchPattern":"checksum, err := getGitHubManifestChecksum(ctx, release, pkg)\nif err != nil {\n    logging.LogWarnf(\"manifest unusable: %s\", err) // do NOT install unverified\n}","preventionTips":["Treat an over-1MiB or non-text SHA256SUMS.txt as a tampered/mis-packaged release and report it","Download the manifest manually and inspect its content when this error appears","Use a trusted network path — injected HTML interstitials inflate the body past the cap","Remember the digest check also guards integrity; a substituted manifest fails with 'checksum manifest digest mismatch'"],"tags":["checksum","size-limit","security"],"backgroundTag":"file-size-limit-exceeded","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}