siyuan-note/siyuan · warning

checksum manifest is too large

Error message

checksum manifest is too large

What it means

The downloaded SHA256SUMS.txt is read through an io.LimitReader capped at maxChecksumManifestSize (1 MiB) plus one byte. If more than 1 MiB of data is produced, the manifest is considered corrupt or malicious and the fetch fails with this error before any parsing. The upstream caller degrades to no-checksum with a warning.

Solutions

  1. Download SHA256SUMS.txt manually and check its size/content — if it is over 1 MiB or is not a checksum list, do not trust that release and report it
  2. Retry from a different network to rule out proxy/injected content
  3. Wait for a re-published release with a correct manifest; meanwhile install manually and verify hashes yourself
  4. Note the digest check (manifestDigest vs sha256 of body) runs after this size check, so an attacker-substituted manifest will additionally fail with 'checksum manifest digest mismatch'
Defensive patterns

Strategy: validation

Validate before calling

info, _ := os.Stat("SHA256SUMS.txt")
manifestSizeOK := info != nil && info.Size() > 0 && info.Size() <= 1024*1024

Try / catch

checksum, err := getGitHubManifestChecksum(ctx, release, pkg)
if err != nil {
    logging.LogWarnf("manifest unusable: %s", err) // do NOT install unverified
}

Prevention

When it happens

Trigger: io.ReadAll on the limited reader returning maxChecksumManifestSize+1 bytes — i.e. the response body exceeds the 1 MiB manifest size cap. Requires the SHA256SUMS.txt asset served at the URL to be larger than 1 MiB or a non-manifest payload at that URL.

Common situations: A compromised or mis-packaged release containing a bloated manifest; a CDN/proxy returning an HTML error page or interstitial that inflates the body beyond the cap; man-in-the-middle injection on insecure egress.

Understand the failure class

Background: "File too large" / "file size exceeds limit" errors: why libraries cap file sizes and how to fix them — this error's family across 46 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/7886aa605fe6544b. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/updater_release.go:399

	}

	response, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)
	if err != nil {
		return "", err
	}
	if nil == response || nil == response.Response {
		return "", errors.New("checksum manifest response is empty")
	}
	defer response.Body.Close()
	if 200 != response.StatusCode {
		return "", fmt.Errorf("get checksum manifest failed: %d", response.StatusCode)
	}
	data, err := io.ReadAll(io.LimitReader(response.Body, maxChecksumManifestSize+1))
	if err != nil {
		return "", err
	}
	if maxChecksumManifestSize < int64(len(data)) {
		return "", errors.New("checksum manifest is too large")
	}
	if "" != manifestDigest {
		actualDigest := fmt.Sprintf("%x", sha256.Sum256(data))
		if manifestDigest != actualDigest {
			return "", errors.New("checksum manifest digest mismatch")
		}
	}
	manifest := string(data)
	if "" != manifestCacheKey {
		githubManifestCache.Store(manifestCacheKey, manifest)
	}
	checksum := parseChecksumManifest(manifest, pkgName)
	if "" == checksum {
		return "", errors.New("package checksum is unavailable")
	}
	return checksum, nil
}

View on GitHub (pinned to 9f775e8a12)