pub struct LimitsConfig {
pub max_connections: usize,
pub max_subscriptions_per_connection: usize,
pub max_conversations_per_connection: usize,
pub max_pending_pushes_per_connection: usize,
pub max_pending_conversation_replies_per_connection: usize,
pub max_pending_replies_per_conversation: usize,
pub max_connection_inbox_bytes: usize,
pub max_subscription_inbox_depth: usize,
pub max_channels: Option<usize>,
}Expand description
Operational bounds (§5, scout Q4 — rule-2 items).
Each field is a hard per-scope cap with a typed refusal and a
certifying-pair-signed default (the numbers below are §5’s). The struct is
the single wire surface for [limits]; [LimitsConfig::validate] rejects any
zero value as a typed config error (a zero cap would gate nothing — the exact
unlimited-by-silence state §5 outlaws). Defaults come from the default_*
free functions so an absent key resolves to the signed number, not zero.
Fields§
§max_connections: usizeTotal live connections the listener admits before refusing (§5: 256 — a worker-bus, an order of magnitude above any observed fleet).
max_subscriptions_per_connection: usizeSubscriptions one connection may hold (§5: 32).
max_conversations_per_connection: usizeOpen conversations one connection may hold (§5: 32).
max_pending_pushes_per_connection: usizeIn-flight server→client correlated pushes per connection (§5: 32).
max_pending_conversation_replies_per_connection: usizeEntries in the per-connection pending-reply table (§1.2(3b)/§5: 32 — distinct from server-push slots).
max_pending_replies_per_conversation: usizePer-conversation sub-cap that confines tombstone ambiguity to its own conversation (§1.2(3b)/§5: 8). Pending entries count against BOTH this and the connection table; tombstones against THIS alone.
max_connection_inbox_bytes: usizeOne shared inbox-byte budget per connection, spent across ALL its subscription inboxes (§5: 4 MiB — deliberately mirroring the outbound 4 MiB bound). Accounting unit: serialized envelope bytes as admitted, charged at enqueue and released at dequeue.
max_subscription_inbox_depth: usizePer-inbox envelope-count secondary fairness trip (§5: 256) — stops one subscription starving its siblings inside the shared byte budget; no longer load-bearing for the signed bound.
max_channels: Option<usize>Runtime-registered channels this deployment admits.
§Why this cap departs the uniform pattern
Every other field here carries #[serde(default = "…")] naming a §5
constant, because each of those numbers is a signed §5 bound. There is
no signed §5 bound for channel count, and inventing one is barred: a
number nobody certified, presented in the same shape as eight numbers
somebody did, is a forged citation. So the type is Option<usize> and
the serde default is the ABSENCE itself (None), never a value —
#[serde(default)] here resolves a missing key to “no bound declared”,
which is a different statement from any number.
Nor may this be a usize with a large default: unbounded-by-default is
not a bound, it is the gap wearing a number.
None refuses every runtime channel registration with a typed error
naming this key, so a deployment that wants runtime registration declares
its own bound and a deployment that never registers needs no config
change at all. The cap bounds RUNTIME-registered channels only:
[[channels]] entries are the bound the operator already wrote.
Some(0) is a validation error like every other zero cap here — see
LimitsConfig::collect_errors.
Implementations§
Source§impl LimitsConfig
impl LimitsConfig
Sourcepub const DEFAULT_MAX_CONNECTIONS: usize = 256
pub const DEFAULT_MAX_CONNECTIONS: usize = 256
§5 default: total live connections before the listener refuses.
Sourcepub const DEFAULT_MAX_SUBSCRIPTIONS_PER_CONNECTION: usize = 32
pub const DEFAULT_MAX_SUBSCRIPTIONS_PER_CONNECTION: usize = 32
§5 default: subscriptions per connection.
Sourcepub const DEFAULT_MAX_CONVERSATIONS_PER_CONNECTION: usize = 32
pub const DEFAULT_MAX_CONVERSATIONS_PER_CONNECTION: usize = 32
§5 default: open conversations per connection.
Sourcepub const DEFAULT_MAX_PENDING_PUSHES_PER_CONNECTION: usize = 32
pub const DEFAULT_MAX_PENDING_PUSHES_PER_CONNECTION: usize = 32
§5 default: in-flight server pushes per connection.
Sourcepub const DEFAULT_MAX_PENDING_CONVERSATION_REPLIES_PER_CONNECTION: usize = 32
pub const DEFAULT_MAX_PENDING_CONVERSATION_REPLIES_PER_CONNECTION: usize = 32
§5 default: pending-reply table entries per connection.
Sourcepub const DEFAULT_MAX_PENDING_REPLIES_PER_CONVERSATION: usize = 8
pub const DEFAULT_MAX_PENDING_REPLIES_PER_CONVERSATION: usize = 8
§5 default: per-conversation pending-reply sub-cap.
Sourcepub const DEFAULT_MAX_CONNECTION_INBOX_BYTES: usize
pub const DEFAULT_MAX_CONNECTION_INBOX_BYTES: usize
§5 default: shared per-connection inbox byte budget (4 MiB).
Sourcepub const DEFAULT_MAX_SUBSCRIPTION_INBOX_DEPTH: usize = 256
pub const DEFAULT_MAX_SUBSCRIPTION_INBOX_DEPTH: usize = 256
§5 default: per-inbox envelope-count fairness trip.
Trait Implementations§
Source§impl Clone for LimitsConfig
impl Clone for LimitsConfig
Source§fn clone(&self) -> LimitsConfig
fn clone(&self) -> LimitsConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more