Skip to main content

moq_e2ee/
limits.rs

1/// Profile string, also the HKDF salt.
2pub(crate) const PROFILE: &str = "moq-e2ee-00";
3
4/// HKDF info prefix for opaque broadcast paths.
5pub(crate) const PATH_LABEL: &[u8] = b"moq-e2ee-00 path";
6
7/// HKDF info prefix for physical names.
8pub(crate) const NAME_LABEL: &[u8] = b"moq-e2ee-00 name";
9
10/// HKDF info prefix for AEAD keys.
11pub(crate) const KEY_LABEL: &[u8] = b"moq-e2ee-00 key";
12
13/// AES-GCM tag length in bytes.
14pub(crate) const TAG_LEN: usize = 16;
15
16/// Derived AEAD key length in bytes.
17pub(crate) const KEY_LEN: usize = 16;
18
19/// Physical name and opaque path material length in bytes.
20pub(crate) const NAME_LEN: usize = 16;
21
22/// Unpadded base64url length of 16 bytes, in ASCII characters.
23pub(crate) const NAME_TEXT_LEN: usize = 22;
24
25/// Broadcast secret length in bytes.
26pub const SECRET_LEN: usize = 32;
27
28/// `Number.MAX_SAFE_INTEGER`: the group and kid bound.
29pub(crate) const MAX_U53: u64 = 9_007_199_254_740_991;
30
31/// Maximum AEAD invocations per key (`2^24`).
32pub(crate) const MAX_INVOCATIONS: u64 = 16_777_216;
33
34/// Maximum plaintext bytes per key (`2^36`).
35pub(crate) const MAX_PLAINTEXT_BYTES: u64 = 68_719_476_736;
36
37/// Interoperable grouped-frame payload cap matching moq-net: 32 MiB.
38pub(crate) const MAX_GROUPED_PAYLOAD: usize = 32 * 1024 * 1024;
39
40/// Largest plaintext a grouped frame can carry: 32 MiB minus the tag.
41pub const MAX_GROUPED_PLAINTEXT: usize = MAX_GROUPED_PAYLOAD - TAG_LEN;
42
43/// moq-lite datagram body cap, including Subscribe ID, Group Sequence, and Timestamp.
44pub(crate) const MAX_DATAGRAM_BODY: usize = 1200;
45
46/// Widest moq-lite datagram header: three 8-byte QUIC varints.
47pub(crate) const MAX_DATAGRAM_HEADER: usize = 24;
48
49/// Largest protected datagram payload: the body cap minus the widest header.
50pub(crate) const MAX_DATAGRAM_PAYLOAD: usize = MAX_DATAGRAM_BODY - MAX_DATAGRAM_HEADER;
51
52/// Largest plaintext a datagram can carry: 1160 bytes.
53pub const MAX_DATAGRAM_PLAINTEXT: usize = MAX_DATAGRAM_PAYLOAD - TAG_LEN;
54
55/// Datagram duplicate suppression window, in sequences below the greatest opened.
56pub(crate) const DATAGRAM_WINDOW: u64 = 1024;
57
58/// Maximum length of a `bytes` field: context, epoch, or semantic name.
59pub(crate) const MAX_BYTES: usize = 0xffff;
60
61pub(crate) fn check_u53(value: u64) -> crate::Result<()> {
62	if value > MAX_U53 {
63		Err(crate::Error::Identity)
64	} else {
65		Ok(())
66	}
67}
68
69pub(crate) fn check_bytes(len: usize) -> crate::Result<()> {
70	if len > MAX_BYTES {
71		Err(crate::Error::Identity)
72	} else {
73		Ok(())
74	}
75}