{"record":{"id":"7e8cb788062871d0","repo":"abhigyanpatwari/GitNexus","slug":"analyzer-runtime-payload-scan-exceeded-limits-ru-7e8cb7","errorCode":null,"errorMessage":"Analyzer runtime payload scan exceeded ${limits.runtimePayloads} payloads: ${root}","messagePattern":"Analyzer runtime payload scan exceeded (.+?) payloads: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"gitnexus/src/core/analyzer-identity.ts","lineNumber":1380,"sourceCode":"        // for every name, not just the pruned four — `dist -> build`, a\n        // vendored-grammar link, anything a sibling checkout ships.\n        //\n        // Such links are RECORDED by their link text rather than followed.\n        // Following them would (a) recurse without cycle protection — this\n        // traversal has none, so `self -> .` would ride the depth limit, which\n        // THROWS, trading one hard abort for another; (b) re-scan trees already\n        // reached by their real path, inflating the entry/byte budgets that\n        // also throw; and (c) need a whole containment/TOCTOU trust boundary\n        // for targets outside the package. Recording the text is cycle-free,\n        // costs one `readlink`, and still moves the receipt when the link is\n        // retargeted. The trade-off is that a link's target contributes no\n        // content of its own: when it points outside the package, only the\n        // link text is covered. Links that DO resolve to a regular file keep\n        // their content digest below, unchanged.\n        if (shouldHashRuntimePayload(relativePath)) {\n          budget.artifacts += 1;\n          if (budget.artifacts > limits.runtimePayloads) {\n            throw new Error(\n              `Analyzer runtime payload scan exceeded ${limits.runtimePayloads} payloads: ${root}`,\n            );\n          }\n          artifacts.push({\n            absolutePath,\n            canonicalPath: `${canonicalPrefix}/${relativePath}`,\n            kind: 'unfollowed-symlink',\n          });\n        }\n      } else if (\n        (stat.isFile() || stat.isSymbolicLink()) &&\n        shouldHashRuntimePayload(relativePath)\n      ) {\n        const readableState = snapshotReadableFile(absolutePath);\n        const payloadBytes = stateSize(readableState.target, absolutePath);\n        budget.artifacts += 1;\n        if (budget.artifacts > limits.runtimePayloads) {\n          throw new Error(","sourceCodeStart":1362,"sourceCodeEnd":1398,"githubUrl":"https://github.com/abhigyanpatwari/GitNexus/blob/52924ef12c2290ceee4612526a828ec4cdf2047f/gitnexus/src/core/analyzer-identity.ts#L1362-L1398","documentation":"Every runtime payload eligible for hashing (per shouldHashRuntimePayload) increments budget.artifacts, capped by limits.runtimePayloads (default 100,000); this branch counts unfollowed symlinks whose link text must be recorded (cycle-free retarget detection). Exceeding the cap aborts because a partially covered payload set would produce a receipt blind to some runtime changes. Note symlink targets outside the package contribute link text only — that is a documented trade-off, not an error.","triggerScenarios":"A runtime package tree contains more than 100,000 hashable payloads — including unfollowed symlinks recorded by name (linked directories like dist -> build in workspace checkouts count) — or tests tightened runtimePayloads below the fixture's payload count.","commonSituations":"Workspace-linked checkouts where many symlinked directories each count as one payload; dependencies shipping enormous numbers of small loadable files (Wasm/native addons); test overrides set too low.","solutions":["Reduce payload count in the offending package (dedupe symlinked directories, remove caches/generated files).","Reinstall dependency packages cleanly to drop accumulated artifacts.","In tests, keep traversalLimits.runtimePayloads above the fixture's real payload count (default cap 100,000)."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":"function isRuntimePayloadsLimitError(error: unknown): boolean {\n  return error instanceof Error && /^Analyzer runtime payload scan exceeded \\d+ payloads:/.test(error.message);\n}","tryCatchPattern":"try {\n  identity = resolveAnalyzerRunnerIdentity(import.meta.url);\n} catch (error) {\n  if (isRuntimePayloadsLimitError(error)) {\n    reportUserError('A dependency tree exceeds 100k hashable payloads; dedupe linked directories or reinstall.');\n  }\n  throw error;\n}","preventionTips":["Materialize workspace-linked directories instead of shipping thousands of symlinks inside dependency trees.","Remove generated file floods (per-file build outputs) from package directories.","Size test runtimePayloads overrides above the fixture's payload count."],"tags":["gitnexus","analyzer-identity","limits","node-modules","symlink","budget"],"backgroundTag":"traversal-limit-exceeded","analyzedSha":"52924ef12c2290ceee4612526a828ec4cdf2047f","analyzedAt":"2026-08-20T23:29:22.980Z","contentChangedAt":"2026-08-20T23:29:22.980Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}