siyuan-note/siyuan · warning
checksum manifest is too large
Error message
checksum manifest is too large
What it means
The downloaded SHA256SUMS.txt is read through an io.LimitReader capped at maxChecksumManifestSize (1 MiB) plus one byte. If more than 1 MiB of data is produced, the manifest is considered corrupt or malicious and the fetch fails with this error before any parsing. The upstream caller degrades to no-checksum with a warning.
Solutions
- Download SHA256SUMS.txt manually and check its size/content — if it is over 1 MiB or is not a checksum list, do not trust that release and report it
- Retry from a different network to rule out proxy/injected content
- Wait for a re-published release with a correct manifest; meanwhile install manually and verify hashes yourself
- Note the digest check (manifestDigest vs sha256 of body) runs after this size check, so an attacker-substituted manifest will additionally fail with 'checksum manifest digest mismatch'
Defensive patterns
Strategy: validation
Validate before calling
info, _ := os.Stat("SHA256SUMS.txt")
manifestSizeOK := info != nil && info.Size() > 0 && info.Size() <= 1024*1024 Try / catch
checksum, err := getGitHubManifestChecksum(ctx, release, pkg)
if err != nil {
logging.LogWarnf("manifest unusable: %s", err) // do NOT install unverified
} Prevention
- Treat an over-1MiB or non-text SHA256SUMS.txt as a tampered/mis-packaged release and report it
- Download the manifest manually and inspect its content when this error appears
- Use a trusted network path — injected HTML interstitials inflate the body past the cap
- Remember the digest check also guards integrity; a substituted manifest fails with 'checksum manifest digest mismatch'
When it happens
Trigger: io.ReadAll on the limited reader returning maxChecksumManifestSize+1 bytes — i.e. the response body exceeds the 1 MiB manifest size cap. Requires the SHA256SUMS.txt asset served at the URL to be larger than 1 MiB or a non-manifest payload at that URL.
Common situations: A compromised or mis-packaged release containing a bloated manifest; a CDN/proxy returning an HTML error page or interstitial that inflates the body beyond the cap; man-in-the-middle injection on insecure egress.
Understand the failure class
Background: "File too large" / "file size exceeds limit" errors: why libraries cap file sizes and how to fix them — this error's family across 46 libraries.
Related errors
- Access to encrypted notebook data is not supported via this…
- access to private/internal IP is prohibited
- access to private/internal IP is prohibited
- access to sensitive workspace file is forbidden
- Agent capability name and description are required
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/7886aa605fe6544b.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/updater_release.go:399
}
response, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)
if err != nil {
return "", err
}
if nil == response || nil == response.Response {
return "", errors.New("checksum manifest response is empty")
}
defer response.Body.Close()
if 200 != response.StatusCode {
return "", fmt.Errorf("get checksum manifest failed: %d", response.StatusCode)
}
data, err := io.ReadAll(io.LimitReader(response.Body, maxChecksumManifestSize+1))
if err != nil {
return "", err
}
if maxChecksumManifestSize < int64(len(data)) {
return "", errors.New("checksum manifest is too large")
}
if "" != manifestDigest {
actualDigest := fmt.Sprintf("%x", sha256.Sum256(data))
if manifestDigest != actualDigest {
return "", errors.New("checksum manifest digest mismatch")
}
}
manifest := string(data)
if "" != manifestCacheKey {
githubManifestCache.Store(manifestCacheKey, manifest)
}
checksum := parseChecksumManifest(manifest, pkgName)
if "" == checksum {
return "", errors.New("package checksum is unavailable")
}
return checksum, nil
}
View on GitHub (pinned to 9f775e8a12)