What
In 0.1.0, typedstandards.verify fails with UsageError (exit 2) on a bundle that
@typedstandards/host-core serves under a registry, once the bundle is larger than a pipe buffer
holds:
typedstandards.errors.UsageError: typedstandards verify exited 2: typedstandards verify: --input - cannot be read: EAGAIN: resource temporarily unavailable, read
Why
verify removes a bundle's top-level trustRegistry before the CLI sees it (G0 D9,
npstorey/typedstandards#136). _without_trust_registry (src/typedstandards/_commands.py:113-131
at 7513583) turns a path into a mapping when it removes the key, and _input_args
(_commands.py:28-33) sends every mapping to the CLI on standard input (--input -). CLI 0.2.0
reads standard input with a synchronous readFileSync(0), which throws EAGAIN on a large piped
input (npstorey/typedstandards#138). So every served bundle above the threshold fails, although
the same bundle given to the CLI as a file verifies.
Measured (2026-10-04, typedstandards 0.1.0 from PyPI, Node 24.21.0, macOS 26)
On a host built by host-core 0.1.1 with four records, ts.verify(<bundle path>) returned
ok: True for two bundles of 5,006 and 3,676 bytes, and raised the error above for a
693,954-byte bundle (a notebook-sized file signed inline). The CLI's threshold on macOS from
Python's subprocess.run(input=...) lies between 16,000 and 65,536 bytes. On Linux the CLI fails
the same way at 692,380 bytes; npstorey/typedstandards#138 has the table.
The wrapper's tests did not catch it because every document they send on standard input is small.
Fix shape (a hypothesis, to be measured)
Pass every mapping input to the CLI as a file rather than through a pipe: write it to a
temporary file, as view already does, or hand the child a regular file as its standard input.
Keep D9's rule that the CLI receives the same document minus trustRegistry. A test that
verifies a served bundle over 1 MiB through verify, and one that signs from an input mapping
over 1 MiB, would hold it.
What
In 0.1.0,
typedstandards.verifyfails withUsageError(exit 2) on a bundle that@typedstandards/host-coreserves under a registry, once the bundle is larger than a pipe bufferholds:
Why
verifyremoves a bundle's top-leveltrustRegistrybefore the CLI sees it (G0 D9,npstorey/typedstandards#136).
_without_trust_registry(src/typedstandards/_commands.py:113-131at
7513583) turns a path into a mapping when it removes the key, and_input_args(
_commands.py:28-33) sends every mapping to the CLI on standard input (--input -). CLI 0.2.0reads standard input with a synchronous
readFileSync(0), which throwsEAGAINon a large pipedinput (npstorey/typedstandards#138). So every served bundle above the threshold fails, although
the same bundle given to the CLI as a file verifies.
Measured (2026-10-04,
typedstandards0.1.0 from PyPI, Node 24.21.0, macOS 26)On a host built by host-core 0.1.1 with four records,
ts.verify(<bundle path>)returnedok: Truefor two bundles of 5,006 and 3,676 bytes, and raised the error above for a693,954-byte bundle (a notebook-sized file signed inline). The CLI's threshold on macOS from
Python's
subprocess.run(input=...)lies between 16,000 and 65,536 bytes. On Linux the CLI failsthe same way at 692,380 bytes; npstorey/typedstandards#138 has the table.
The wrapper's tests did not catch it because every document they send on standard input is small.
Fix shape (a hypothesis, to be measured)
Pass every mapping input to the CLI as a file rather than through a pipe: write it to a
temporary file, as
viewalready does, or hand the child a regular file as its standard input.Keep D9's rule that the CLI receives the same document minus
trustRegistry. A test thatverifies a served bundle over 1 MiB through
verify, and one that signs from an input mappingover 1 MiB, would hold it.