siyuan-note/siyuan · error

marketplace package is too large

Error message

marketplace package is too large

What it means

While summing declared entry sizes, if adding an entry's UncompressedSize64 would overflow uint64 (i.e. the total exceeds the maximum representable value), extractLocalPackageArchive immediately rejects the archive. This catches absurdly large declarations and prevents overflow-based bypasses of the size checks.

Solutions

  1. Do not use the archive; rebuild it with a trusted zip tool
  2. Verify sizes with unzip -l; absurd sizes indicate a forged/corrupt archive
  3. Re-export the package normally; no legitimate package approaches this size

Example fix

// before: header-crafted zip with entries declaring ~2^63 bytes each
// after: rebuild with: zip -r plugin.json package files...
// (repackage with a standard tool so headers are truthful)
Defensive patterns

Strategy: validation

Validate before calling

// Only occurs with forged/corrupt headers; pre-check with a trusted tool:
execSync(`unzip -t ${zipPath}`); // throws if the central directory is inconsistent

Try / catch

try { await installLocalPackage(zipPath); } catch (e) { if (String(e).includes("too large")) { /* reject source; repackage with a trusted tool */ } }

Prevention

When it happens

Trigger: Calling ExtractLocalPackage with a zip whose cumulative declared uncompressed sizes overflow uint64 (headers summing past 2^64-1).

Common situations: Maliciously crafted zip-bomb headers claiming near-maximum sizes to overflow naive total-size checks; corrupted zip central directory.

Understand the failure class

Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/cf049a432ca3e00a. Report an issue: GitHub.

Appendix: source

Thrown at kernel/bazaar/local.go:109

	if err != nil {
		return errors.New("invalid marketplace package archive")
	}
	defer reader.Close()

	if len(reader.File) == 0 {
		return errors.New("marketplace package archive is empty")
	}
	if len(reader.File) > maxLocalPackageFileCount {
		return errors.New("marketplace package contains too many files")
	}

	var declaredTotal uint64
	for _, item := range reader.File {
		if item.UncompressedSize64 > maxLocalPackageFileSize {
			return errors.New("marketplace package contains a file that is too large")
		}
		if ^uint64(0)-declaredTotal < item.UncompressedSize64 {
			return errors.New("marketplace package is too large")
		}
		declaredTotal += item.UncompressedSize64
		if declaredTotal > maxLocalPackageExtractSize {
			return errors.New("marketplace package is too large")
		}
	}

	if err = os.MkdirAll(destination, 0755); err != nil {
		return err
	}
	var extractedTotal uint64
	for _, item := range reader.File {
		if err = extractLocalPackageItem(item, destination, &extractedTotal); err != nil {
			return err
		}
	}
	return nil
}

View on GitHub (pinned to 9f775e8a12)