Expand description
Resource caps (DoS limits) shared by every adapter — the single source of
truth for fact size, recall limit, and why hop depth.
Resource caps shared by every adapter (the MCP server and the language
bindings).
These are security-relevant DoS limits. They live here — not inside any one
adapter — so every transport enforces the same numbers without a manual
“keep in sync” comment, and so a build without the mcp feature still sees
them. Each adapter formats its own transport-native error; only the values
and the clamping policy are shared.
Constants§
- DEFAULT_
WHY_ HOPS - Default hop budget for
whytraversal when the caller supplies none. - MAX_
FACT_ BYTES - Maximum accepted fact size (1 MiB) — prevents allocating huge embeddings.
- MAX_
FRAGMENTS - Cap on the number of fragments in one compile request — bounds the work a single call can demand across every adapter.
- MAX_
FRAGMENT_ BYTES - Maximum accepted size of a single context-compiler fragment (1 MiB, the
same ceiling as
MAX_FACT_BYTES) — prevents a single fragment from forcing huge allocations in the compile pipeline. - MAX_
INGEST_ FILES - Maximum number of
path-referenced fragments accepted in one compile request — bounds the filesystem work (and open-file churn) a single call can demand, symmetric toMAX_FRAGMENTSfor inline fragments. - MAX_
INGEST_ FILE_ BYTES - Maximum accepted size of a single file read through a
path-referenced context fragment (V2b-1 path ingestion) — 1 MiB, the same ceiling asMAX_FRAGMENT_BYTES: an ingested file becomes an ordinary fragment’scontent, so it must not exceed what a fragment is allowed to carry. Checked fromfs::metadataBEFORE the file is read, and re-checked after (fs::readcan race a concurrent write) — never clamped, always refused, so a truncated read can never silently masquerade as the whole file. - MAX_
MEDIA_ BYTES - Maximum accepted size of a fragment’s base64-encoded media payload
(US-009, PR1: inline images) — 4 MiB of base64 text, roughly 3 MiB of raw
bytes once decoded. Deliberately separate from
MAX_FRAGMENT_BYTES, which only ever measurescrate::context::model::ContextFragment::content(the caption): a screenshot is not text, and capping it at the 1 MiB text ceiling would reject ordinary screenshots outright. Measured againstbytes_b64.len()(the encoded string), so the cap can reject an oversized payload before any base64 decoding is attempted. - MAX_
METADATA_ BYTES - Maximum accepted size of caller-supplied
metadata(64 KiB), measured as its serialized JSON form. Metadata is a keyed lookup facet (project, author, status, …) — a porte-clés, not a payload — so it gets a much tighter ceiling thanMAX_FACT_BYTES: without one, a caller could smuggle an arbitrarily large JSON blob throughmetadataon every write path (remember,remember_with_ttl,remember_extracted, and each context-compiler fragment’s ownmetadata) and force the same unbounded allocation and storage growth the fact-size cap exists to prevent. - MAX_
RECALL_ LIMIT - Cap on a
recalllimit — prevents unbounded vector scans (core does not capk, so the adapters do). - MAX_
TOKEN_ BUDGET - Cap on a caller-supplied token budget. A budget cannot force allocations by itself, but an absurd value would make the savings arithmetic meaningless, so adapters clamp to this ceiling instead of erroring.
- MAX_
TOTAL_ INGEST_ BYTES - Aggregate cap on the bytes read across every
path-referenced fragment of one request (64 MiB) — symmetric toMAX_TOTAL_MEDIA_BYTES. Without it,MAX_INGEST_FILESfragments each atMAX_INGEST_FILE_BYTESwould still admit 64 MiB (the two caps happen to coincide at these values), but this cap is checked independently and first — a future change to either per-item constant must not silently loosen the aggregate ceiling. - MAX_
TOTAL_ MEDIA_ BYTES - Aggregate cap on ALL media payloads of one request (base64 length,
summed). Without it,
MAX_FRAGMENTSfragments each atMAX_MEDIA_BYTESwould let a single request carry 4 GiB of media — far past the ~1 GiB worst case the text caps allow. 64 MiB comfortably fits a real screenshot-heavy session while bounding decode work. - MAX_
TRANSCRIPT_ BYTES - Maximum accepted size of a
compile_transcripttranscript (V2b-2), inline orpath-referenced — 8 MiB. The ONE caller-facing shape allowed to read past the ordinaryMAX_INGEST_FILE_BYTES/MAX_FRAGMENT_BYTES1 MiB ceiling: a transcript is segmented into sub-1-MiB pieces immediately after being read (seecontext::segment), so it is never itself compiled as one oversized fragment — only the raw pre-segmentation read gets the wider cap. - MAX_
WHY_ HOPS - Cap on
whyhop depth — prevents exponential graph fan-out.
Functions§
- clamp_
hops - Clamp a caller-supplied
whyhop budget toMAX_WHY_HOPS. - clamp_
recall_ limit - Clamp a caller-supplied recall limit to
MAX_RECALL_LIMIT. - clamp_
token_ budget - Clamp a caller-supplied token budget to
MAX_TOKEN_BUDGET. - metadata_
bytes - The serialized JSON size of
meta, in bytes. Returnsusize::MAXif the map somehow fails to serialize (it never should —Metadatais always valid JSON), so a serialization hiccup fails a size check closed rather than silently passing an unmeasured payload.