Skip to main content

ReassemblyLimits

Struct ReassemblyLimits 

Source
pub struct ReassemblyLimits {
    pub max_pending_messages: usize,
    pub max_chunk_data_len: usize,
    pub max_message_bytes: usize,
    pub max_chunks_per_message: usize,
    pub max_total_buffered_cost: usize,
    pub slot_overhead: usize,
    pub max_completed_ids: usize,
}
Expand description

The limits a super::MessageReassembler enforces on incoming chunks, as an explicit value rather than module globals. This keeps the core admission rule independent of where the numbers come from: the shell supplies them (see ReassemblyLimits::production), the reassembler only enforces what it is given, and tests can use small limits instead of giant synthetic payloads.

Fields§

§max_pending_messages: usize

Max number of distinct in-flight message ids (a cheap first-line cap; the byte budgets are the real memory guard).

§max_chunk_data_len: usize

Max data bytes a single chunk may carry.

§max_message_bytes: usize

Max buffered data bytes for one in-flight message.

§max_chunks_per_message: usize

Max number of slots (chunks) one in-flight message may have - i.e. the largest total a chunk may claim. Caps the slot/BTreeMap count of a single message so a hostile peer cannot use one id with a huge total and tiny chunks to allocate millions of slots while staying under max_message_bytes (which only counts data bytes).

§max_total_buffered_cost: usize

Max buffered cost (data bytes + per-slot overhead) summed across all in-flight messages.

§slot_overhead: usize

Bookkeeping charge per slot - a conservative estimate (not an exact measurement) of the BTreeMap node plus Bytes header/refcount a slot costs, so a flood of tiny chunks is bounded by slot count, not only by summed data bytes. Real per-slot heap use may differ; this is deliberately generous so the budget over- rather than under-counts.

§max_completed_ids: usize

Max number of recently-completed message ids remembered as tombstones, to suppress a re-delivery if a message is fully retransmitted after it already completed (within its TTL window). The same number separately caps invalid-terminal ids and ids rejected before local capacity could retain state. Invalid ids fail open without peer attribution when their set is full, with a bounded saturation horizon preserving that decision while tombstones drain; capacity-history saturation temporarily rejects all new ids for that peer. Thus terminal bookkeeping retains at most three times this many ids across the independent completed, invalid, and capacity sets, plus two scalar saturation horizons. NOTE: past this many concurrent live completion tombstones the oldest is dropped even if its TTL has not elapsed, so the “no post-completion redelivery” guarantee holds only for the most recent max_completed_ids completions within a TTL window.

Implementations§

Source§

impl ReassemblyLimits

Source

pub fn production() -> ReassemblyLimits

The limits used in production, derived from the transport / message ceilings. This is the one place that reaches for transport-specific constants; the reassembler itself does not.

Source

pub fn constrained() -> ReassemblyLimits

Lower-concurrency limits for constrained deployments.

The per-message ceiling remains protocol-compatible with production. Constrained nodes instead admit fewer simultaneous messages and only one maximum-size reassembly, including its contiguous output copy.

Trait Implementations§

Source§

impl Clone for ReassemblyLimits

Source§

fn clone(&self) -> ReassemblyLimits

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for ReassemblyLimits

Source§

impl Debug for ReassemblyLimits

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for ReassemblyLimits

Source§

fn default() -> ReassemblyLimits

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> ArchivePointee for T

Source§

type ArchivedMetadata = ()

The archived version of the pointer metadata for this type.
Source§

fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata

Converts some archived metadata to the pointer metadata for itself.
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> LayoutRaw for T

Source§

fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>

Returns the layout of the type.
Source§

impl<T> MaybeSend for T
where T: Send + Sync,

Source§

impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
where T: SharedNiching<N1, N2>, N1: Niching<T>, N2: Niching<T>,

Source§

unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool

Returns whether the given value has been niched. Read more
Source§

fn resolve_niched(out: Place<NichedOption<T, N1>>)

Writes data to out indicating that a T is niched.
Source§

impl<T> Pointee for T

Source§

type Metadata = ()

The metadata type for pointers and references to this type.
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more