use fastmcp_core::{Sha256Digest, sha256_bounded};
const MAX_MANIFEST_BYTES: usize = 64 * 1024;
pub const LEGACY_ERA_VERSION: &str = "2024-11-05";
pub const UNSUPPORTED_ERA_VERSION: &str = "2025-11-25";
pub const LEG_HTTP_01_B_EVALUATOR_MANIFEST_V1: &str = concat!(
"LEG-HTTP-01-B evaluator manifest v1\n",
"entrypoint fastmcp_client::http_executor::LegacySseHttpClient\n",
"transport legacy-http-get-sse\n",
"era 2024-11-05\n",
"row 01 same-origin-uri-admission\n",
"row 02 authentication-credential-binding\n",
"row 03 malformed-sse-framing\n",
"row 04 redirect-denial\n",
"row 05 server-error-denial\n",
"row 06 size-and-queue-backpressure\n",
"row 07 endpoint-mutation-denial\n",
"row 08 bounded-reconnect\n",
"row 09 bidirectional-frames-after-reconnect\n",
"row 10 cancellation\n",
"row 11 deterministic-close\n",
"limit sse-line floor-guarded=8388616 floor-hard=33554440 unit=bytes\n",
"limit sse-event floor-guarded=9437184 floor-hard=37748736 unit=bytes\n",
"limit sse-data-lines-per-event floor-guarded=4096 floor-hard=65536 unit=lines\n",
"limit outbound-queue-events floor-guarded=256 floor-hard=4096 unit=events\n",
"limit outbound-queue-bytes floor-guarded=9437184 floor-hard=37748736 unit=bytes\n",
"limit guarded-idle-lifetime floor-guarded=60 floor-hard=600 unit=seconds\n",
"limit absolute-lifetime floor-guarded=900 floor-hard=7200 unit=seconds\n",
"invariant first-endpoint-count=1 per stream generation\n",
"invariant same-origin-uri precedes credential use\n",
"invariant no cross-generation endpoint mutation\n",
);
#[must_use]
pub fn leg_http_01_b_manifest_digest() -> Sha256Digest {
sha256_bounded(
LEG_HTTP_01_B_EVALUATOR_MANIFEST_V1.as_bytes(),
MAX_MANIFEST_BYTES,
)
.expect("the fixed LEG-HTTP-01 B manifest is within its exact byte bound")
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct FrozenLimit {
name: String,
guarded: u64,
hard: u64,
unit: String,
}
impl FrozenLimit {
#[must_use]
pub fn name(&self) -> &str {
&self.name
}
#[must_use]
pub const fn guarded(&self) -> u64 {
self.guarded
}
#[must_use]
pub const fn hard(&self) -> u64 {
self.hard
}
#[must_use]
pub fn unit(&self) -> &str {
&self.unit
}
}
#[must_use]
pub fn frozen_limits() -> Vec<FrozenLimit> {
let mut limits = Vec::new();
for line in LEG_HTTP_01_B_EVALUATOR_MANIFEST_V1.lines() {
let Some(rest) = line.strip_prefix("limit ") else {
continue;
};
let mut fields = rest.split(' ');
let name = fields
.next()
.expect("a limit row names its limit")
.to_owned();
let mut guarded = None;
let mut hard = None;
let mut unit = None;
for field in fields {
if let Some(value) = field.strip_prefix("floor-guarded=") {
guarded = value.parse::<u64>().ok();
} else if let Some(value) = field.strip_prefix("floor-hard=") {
hard = value.parse::<u64>().ok();
} else if let Some(value) = field.strip_prefix("unit=") {
unit = Some(value.to_owned());
}
}
limits.push(FrozenLimit {
name,
guarded: guarded.expect("a limit row declares floor-guarded"),
hard: hard.expect("a limit row declares floor-hard"),
unit: unit.expect("a limit row declares its unit"),
});
}
limits
}
#[must_use]
pub fn ordered_rows() -> Vec<(u8, String)> {
LEG_HTTP_01_B_EVALUATOR_MANIFEST_V1
.lines()
.filter_map(|line| {
let rest = line.strip_prefix("row ")?;
let (ordinal, name) = rest.split_once(' ')?;
Some((ordinal.parse::<u8>().ok()?, name.to_owned()))
})
.collect()
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub struct ObservedLimit {
accepted: u64,
refused: u64,
}
impl ObservedLimit {
#[must_use]
pub fn new(accepted: u64, refused: u64) -> Self {
assert!(
accepted > 0,
"an observed boundary needs at least one admitted size; accepted == 0 means the \
probe measured nothing, and {refused} is only the size it happened to try first"
);
assert!(
accepted < refused,
"an observed boundary needs accepted < refused, got {accepted} and {refused}"
);
Self { accepted, refused }
}
#[must_use]
pub const fn accepted(&self) -> u64 {
self.accepted
}
#[must_use]
pub const fn refused(&self) -> u64 {
self.refused
}
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct LimitConflict {
limit: String,
unit: String,
frozen_guarded: u64,
observed: ObservedLimit,
}
impl LimitConflict {
#[must_use]
pub fn detect(frozen: &FrozenLimit, observed: ObservedLimit) -> Option<Self> {
if observed.accepted() >= frozen.guarded() {
return None;
}
Some(Self {
limit: frozen.name().to_owned(),
unit: frozen.unit().to_owned(),
frozen_guarded: frozen.guarded(),
observed,
})
}
#[must_use]
pub fn limit(&self) -> &str {
&self.limit
}
#[must_use]
pub fn factor(&self) -> u64 {
self.frozen_guarded / self.observed.refused().max(1)
}
#[must_use]
pub fn render(&self) -> String {
format!(
"LIMIT CONFLICT on `{}`: the frozen acceptance floor demands >= {} {} but the shipped \
transport admitted at most {} and refused {} ({}x). The LIMIT-01 floor is the \
contract, so the shipped bound regressed below it; restore the product bound rather \
than lowering the floor.",
self.limit,
self.frozen_guarded,
self.unit,
self.observed.accepted(),
self.observed.refused(),
self.factor(),
)
}
}