ruvnet/ruflo · error

roomId exceeds 128 chars

Error message

roomId exceeds 128 chars

What it means

validateRoomId() caps room identifiers at 128 characters to keep file names and index keys bounded, since roomIds map onto storage paths. A longer roomId is rejected before any filesystem work. Shorten the identifier or use a hash if you need long logical names.

Solutions

  1. Truncate or hash long room names to <=128 chars before use, e.g. crypto.createHash('sha256').update(name).digest('hex').
  2. Enforce a maxLength=128 on the room id field at API/UI input time.
  3. Reject or quarantine oversized-roomId envelopes from peers instead of passing them to sync.
  4. If a legacy system produced long ids, migrate stored rooms to hashed ids and update all producers.

Example fix

// before
const roomId = `room-${tenant}-${user}-${session}-${payload}`; // >128 chars
// after
const raw = `room-${tenant}-${user}-${session}`;
const roomId = raw.length > 128 ? crypto.createHash('sha256').update(raw).digest('hex') : raw;
Defensive patterns

Strategy: validation

Validate before calling

if (typeof roomId === 'string' && roomId.length > 128) throw new Error('roomId exceeds 128 chars');

Try / catch

try {
  validateRoomId(roomId);
} catch (e) {
  if (/exceeds 128 chars/.test(e.message)) {
    roomId = crypto.createHash('sha256').update(roomId).digest('hex');
  } else throw e;
}

Prevention

When it happens

Trigger: Calling mergeEnvelopes, syncRoomFromPeer, or server handlers with a roomId string whose .length > 128 — e.g. a room id derived from concatenating user IDs, a UUID plus long suffixes, or an unbounded user-supplied room name.

Common situations: Generating room ids from untrusted input without length clamping; a remote peer sending envelopes with oversized roomIds (possibly probing storage); schema drift where one system uses full URLs as roomIds.

Understand the failure class

Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.

Related errors


AI-assisted analysis of ruvnet/ruflo@2602b642d9 (2026-09-15). Data as JSON: /api/errors/ad5d33f6055c5493. Report an issue: GitHub.

Appendix: source

Thrown at v3/@claude-flow/cli/src/mcp-tools/agentbbs-federation.ts:318

  if (next.length === peers.length) return false;
  writePeers(basePath, next);
  return true;
}

export function readEnvelopes(basePath: string, roomId: string): SignedEnvelope[] {
  const p = roomLogPath(basePath, roomId);
  if (!existsSync(p)) return [];
  const out: SignedEnvelope[] = [];
  for (const line of readFileSync(p, 'utf-8').split(/\r?\n/)) {
    if (!line.trim()) continue;
    try { out.push(JSON.parse(line)); } catch { /* skip malformed */ }
  }
  return out;
}

export function validateRoomId(roomId: string): string {
  if (!roomId || typeof roomId !== 'string') throw new Error('roomId is required');
  if (roomId.length > 128) throw new Error('roomId exceeds 128 chars');
  // Also blocks path traversal: `.` is allowed but `/` segments cannot form
  // `..` without tripping the explicit check below.
  if (!ROOM_ID_RE.test(roomId)) throw new Error('roomId has invalid characters');
  if (roomId.includes('..')) throw new Error('roomId must not contain ..');
  return roomId;
}

export interface MergeResult {
  merged: number;
  skippedDuplicate: number;
  skippedUnverified: number;
  skippedOversize: number;
  skippedHopLimit: number;
}

/**
 * Union-merge verified envelopes from a peer into the local room log.
 *

View on GitHub (pinned to 2602b642d9)