Skip to content

verify: a served bundle over a pipe buffer fails with EAGAIN (the D9 workaround sends it on stdin) #6

Description

@npstorey

What

In 0.1.0, typedstandards.verify fails with UsageError (exit 2) on a bundle that
@typedstandards/host-core serves under a registry, once the bundle is larger than a pipe buffer
holds:

typedstandards.errors.UsageError: typedstandards verify exited 2: typedstandards verify: --input - cannot be read: EAGAIN: resource temporarily unavailable, read

Why

verify removes a bundle's top-level trustRegistry before the CLI sees it (G0 D9,
npstorey/typedstandards#136). _without_trust_registry (src/typedstandards/_commands.py:113-131
at 7513583) turns a path into a mapping when it removes the key, and _input_args
(_commands.py:28-33) sends every mapping to the CLI on standard input (--input -). CLI 0.2.0
reads standard input with a synchronous readFileSync(0), which throws EAGAIN on a large piped
input (npstorey/typedstandards#138). So every served bundle above the threshold fails, although
the same bundle given to the CLI as a file verifies.

Measured (2026-10-04, typedstandards 0.1.0 from PyPI, Node 24.21.0, macOS 26)

On a host built by host-core 0.1.1 with four records, ts.verify(<bundle path>) returned
ok: True for two bundles of 5,006 and 3,676 bytes, and raised the error above for a
693,954-byte bundle (a notebook-sized file signed inline). The CLI's threshold on macOS from
Python's subprocess.run(input=...) lies between 16,000 and 65,536 bytes. On Linux the CLI fails
the same way at 692,380 bytes; npstorey/typedstandards#138 has the table.

The wrapper's tests did not catch it because every document they send on standard input is small.

Fix shape (a hypothesis, to be measured)

Pass every mapping input to the CLI as a file rather than through a pipe: write it to a
temporary file, as view already does, or hand the child a regular file as its standard input.
Keep D9's rule that the CLI receives the same document minus trustRegistry. A test that
verifies a served bundle over 1 MiB through verify, and one that signs from an input mapping
over 1 MiB, would hold it.

Activity

  1. added a commit that references this issue on Oct 5, 2026
  2. npstorey commented on Oct 5, 2026

    @npstorey
    OwnerAuthor

    Shipped in 0.1.1, published to PyPI on 2026-10-05 from the merge 6c0c20c (PR #7).

    Every mapping input to sign, withdraw, attest and verify now reaches the CLI as a
    temporary file, and no input travels on a pipe. The CLI's own --input - is still
    npstorey/typedstandards#138.

    Read back from PyPI:

    • wheel 55c650135c4531b628aa174f3db9919e0a74f9f81c7bc12f505206112990dcf3
    • sdist 0d23dc9906ec2261d2264c492c8e1bcff43c299df9c1aa99fea587343ff499b2

    In a fresh environment, typedstandards==0.1.1 (CLI_VERSION 0.2.0) verified host-core 0.1.1
    bundles of 693,954 and 10,096,113 bytes as ok. 0.1.0 failed on the first.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions