Repository navigation
fix(sourcemap): crash finalizing bundles with more than 65,535 files (CLI-39Q) - #1654
Draft
cursor[bot] wants to merge 2 commits into
Draft
cursor[bot] wants to merge 2 commits into
cursor[bot] wants to merge 2 commits into
Conversation
…(Sentry CLI-39Q) ZipWriter.finalize() wrote the entry count straight into the classic end-of-central-directory record's 16-bit fields, so `sourcemap upload` threw `RangeError: The value of "value" is out of range` for any upload directory with more than 65,535 bundle entries (e.g. a large Next.js `.next/server` build). When the count overflows, write the ZIP64 end-of-central-directory record and locator before the classic record and saturate the classic count fields at 0xFFFF, as APPNOTE 4.4.1.4 prescribes. Archives at or below the limit are byte-for-byte unchanged. Fixes CLI-39Q Co-authored-by: Miguel Betegón <miguelbetegongarcia@gmail.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CLI-39Q
Sentry issue: CLI-39Q:
RangeError: The value of "value" is out of range. It must be >= 0 and <= 65535. Received 72983(escalating, ~250 events, all on 0.45.0,sourcemap upload).Root cause:
ZipWriter.finalize()insrc/lib/sourcemap/zip.tswritesthis.entries.lengthdirectly into the classic end-of-central-directory record's 16-bit entry-count fields, soBuffer.writeUInt16LEthrows once an artifact bundle has more than 65,535 entries.Reproduction: run
sentry sourcemap upload <dir>on a directory with more than ~32.7k JS + sourcemap pairs (each pair is two bundle entries, plusmanifest.json). In the reported events this was a large Next.js.next/serverbuild. A direct repro isZipWriter.create(), then 65,536addEntry()calls, thenfinalize(); 65,535 entries still work.Fix: when the entry count exceeds
0xFFFF,finalize()now writes the ZIP64 end-of-central-directory record and locator right before the classic record, and caps the classic count fields at0xFFFF(APPNOTE 4.4.1.4). The legacy Rust CLI'szipcrate does the same thing. Archives at or below the limit come out byte-for-byte unchanged.Verification
test/lib/sourcemap/zip.test.tswrites 65,536 entries and checks the ZIP64 record, the locator offset, the capped classic fields, andunzip -t. Without the fix it fails with the exact CLI-39QRangeError.SYSBprefix) by hand usingunzip -t/unzip -land Python'szipfile(the reader Sentry's artifact-bundle assembly uses). Both list every entry and read back the content, and the locator offset points exactly at the ZIP64 record.biome checkandtsc --noEmitare clean. The full Vitest unit suite passes (10,163 tests) apart fromtest/lib/delta-upgrade.mocked.test.ts, which fails the same way onmainwithout this change.Out of scope:
src/lib/build/zip-writer.ts(build upload) has the same 16-bit limit, but it's a separate code path with no reported events, so it belongs in its own PR.