block/buzz · error · anyhow::Error

--max-objects must be at most

Error message

--max-objects must be at most {}

What it means

buzz-admin validates the --max-objects CLI flag before running a storage snapshot. The value is parsed as u64 but the database column it feeds (save_snapshot's max_objects) is i64, so on a 64-bit platform the only failing conversion is beyond i64::MAX. The command aborts rather than silently clamping or overflowing the persisted limit.

Solutions

  1. Pass a value <= 9223372036854775807 (i64::MAX) for --max-objects.
  2. If the intent is 'unlimited', use a large-but-valid bound (e.g. 9223372036854775807) instead of a u64 sentinel.
  3. If a wrapper script computes the value, clamp it: min(value, i64::MAX) before invoking the CLI.

Example fix

// before
buzz-admin storage-snapshot --max-objects 18446744073709551615
// after
buzz-admin storage-snapshot --max-objects 9223372036854775807
Defensive patterns

Strategy: validation

Validate before calling

const I64_MAX: u64 = 9223372036854775807;
if max_objects == 0 || max_objects > I64_MAX {
    return Err(format!("--max-objects must be in 1..={}", I64_MAX));
}

Type guard

fn valid_max_objects(v: u64) -> bool {
    v > 0 && v <= i64::MAX as u64
}

Prevention

When it happens

Trigger: Running `buzz-admin storage-snapshot --max-objects` with a u64 value greater than i64::MAX (9223372036854775807), i.e. any value from 9223372036854775808 to 18446744073709551615. i64::try_from(u64) fails and the map_err converts it into this anyhow error.

Common situations: Typing an absurdly large cap by hand (pasted digit string, scripted value meant as bytes with an off-by-scale), or a wrapper script substituting a sentinel like u64::MAX to mean 'unlimited'.

Understand the failure class

Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.

Related errors


AI-assisted analysis of block/buzz@ef2aa1ae38 (2026-09-20). Data as JSON: /api/errors/f7d8a4e3dfbad651. Report an issue: GitHub.

Appendix: source

Thrown at crates/buzz-admin/src/main.rs:184

        }
        Command::StorageSnapshot { max_objects } => cmd_storage_snapshot(max_objects).await,
        Command::AddMember { pubkey, role } => cmd_add_member(pubkey, role).await,
        Command::RemoveMember { pubkey, role } => cmd_remove_member(pubkey, role).await,
        Command::ListMembers => cmd_list_members().await,
        Command::ProductFeedback {
            command: ProductFeedbackCommand::List { limit },
        } => cmd_list_product_feedback(limit).await,
        Command::Deletions { command } => deletions::run(command).await,
        Command::ReconcileChannels { channel, relay_key } => {
            reconcile_channels(channel, relay_key).await?;
            Ok(0)
        }
    }
}

async fn cmd_storage_snapshot(max_objects: u64) -> Result<i32> {
    let max_objects_db = i64::try_from(max_objects)
        .map_err(|_| anyhow::anyhow!("--max-objects must be at most {}", i64::MAX))?;
    if max_objects == 0 {
        return Err(anyhow::anyhow!("--max-objects must be greater than zero"));
    }

    let db = connect_db().await?;
    let mut leader = db.try_lock_storage_accounting().await?.ok_or_else(|| {
        anyhow::anyhow!("another storage-snapshot worker already holds the lease")
    })?;
    let storage = Arc::new(MediaStorage::new(&storage_config_from_env()?)?);
    let code_sha =
        std::env::var("BUZZ_STORAGE_SNAPSHOT_CODE_SHA").unwrap_or_else(|_| "unknown".to_string());
    if code_sha.is_empty() || code_sha.len() > 128 {
        return Err(anyhow::anyhow!(
            "BUZZ_STORAGE_SNAPSHOT_CODE_SHA must contain 1 to 128 bytes"
        ));
    }

    println!(

View on GitHub (pinned to ef2aa1ae38)