{"record":{"id":"bada7d71c9cd9457","repo":"affaan-m/ECC","slug":"refusing-to-run-install-from-untrusted-repo-root","errorCode":null,"errorMessage":"Refusing to run install from untrusted repo root ${normalized}: package.json name '${pkgName}' is not an official ECC package.","messagePattern":"Refusing to run install from untrusted repo root (.+?): package\\.json name '(.+?)' is not an official ECC package\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/auto-update.js","lineNumber":158,"sourceCode":"  const packageJsonPath = path.join(normalized, 'package.json');\n  const installApplyPath = path.join(normalized, 'scripts', 'install-apply.js');\n\n  if (!fs.existsSync(packageJsonPath)) {\n    throw new Error(`Invalid ECC repo root: missing package.json at ${packageJsonPath}`);\n  }\n\n  if (!fs.existsSync(installApplyPath)) {\n    throw new Error(`Invalid ECC repo root: missing install script at ${installApplyPath}`);\n  }\n\n  let pkgName = null;\n  try {\n    pkgName = JSON.parse(fs.readFileSync(packageJsonPath, 'utf8')).name;\n  } catch {\n    throw new Error(`Invalid ECC repo root: unreadable package.json at ${packageJsonPath}`);\n  }\n  if (!ECC_PACKAGE_NAMES.has(pkgName)) {\n    throw new Error(`Refusing to run install from untrusted repo root ${normalized}: package.json name '${pkgName}' is not an official ECC package.`);\n  }\n\n  return normalized;\n}\n\nfunction runExternalCommand(command, args, options = {}) {\n  const result = spawnSync(command, args, {\n    cwd: options.cwd,\n    env: options.env || process.env,\n    encoding: 'utf8',\n    maxBuffer: 10 * 1024 * 1024\n  });\n\n  if (result.error) {\n    throw result.error;\n  }\n\n  if (typeof result.status === 'number' && result.status !== 0) {","sourceCodeStart":140,"sourceCodeEnd":176,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/auto-update.js#L140-L176","documentation":"readRegularTextFile enforces a maximum byte size (maxBytes). After confirming the file is a safe regular file, it compares the opened file's size (from fstat, as BigInt) against BigInt(maxBytes) and throws this error if it exceeds the limit. Reading is also bounded chunk-by-chunk as a second guard. The library throws this to prevent unbounded memory consumption from a huge or maliciously grown memory document.","triggerScenarios":"Reading a memory document (via existing, source, or readBody) whose on-disk size exceeds the caller's maxBytes option — e.g. a huge accumulated log-like memory file, a binary accidentally placed in the vault, or a very small maxBytes configured for a legitimately large document.","commonSituations":"A memory file grew unbounded because writes kept appending without compaction; a user dropped a large export/archive into the vault directory; default size limits encountered when migrating bigger documents from another tool; corruption producing a pathologically large file.","solutions":["Increase the maxBytes option to a value above the file's actual size if the document is legitimately large.","Split or compact the memory document into smaller files, or prune stale entries.","Remove any non-memory/binary files accidentally placed at the path.","Investigate why the file grew that large (runaway appends, corruption) before simply raising the limit."],"exampleFix":"// before\nreadBody(file, { maxBytes: 64 * 1024 }); // file is 200 KB\n\n// after\nreadBody(file, { maxBytes: 1024 * 1024 }); // or compact the document below the limit","handlingStrategy":"validation","validationCode":"const fs = require('fs');\nfunction assertWithinReadLimit(path, maxBytes) {\n  const size = fs.statSync(path).size;\n  if (size > maxBytes) {\n    throw new Error(`File ${path} is ${size} bytes; exceeds read limit ${maxBytes}. Compact or raise maxBytes.`);\n  }\n}","typeGuard":"const fitsReadLimit = (p, maxBytes) => { try { return fs.statSync(p).size <= maxBytes; } catch { return false; } };","tryCatchPattern":"try {\n  const text = readRegularTextFile(file, { label: 'memory document', maxBytes });\n} catch (err) {\n  const m = err.message.match(/is too large \\((\\d+) bytes\\)/);\n  if (m) throw new Error(`Memory document exceeds the ${maxBytes}-byte limit (${m[1]} bytes). Compact it or raise maxBytes.`);\n  throw err;\n}","preventionTips":["Compact/prune memory documents regularly so they stay well under the limit.","Check file sizes with fs.statSync before reading large or unknown files.","Set maxBytes explicitly per use case instead of relying on defaults.","Alert on anomalous vault file growth (runaway appends or corruption)."],"tags":["filesystem","size-limit","memory-vault","resource-limits"],"backgroundTag":"file-size-limit-exceeded","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}