Skip to main content

Module limits

Module limits 

Source
Expand description

Resource caps (DoS limits) shared by every adapter — the single source of truth for fact size, recall limit, and why hop depth. Resource caps shared by every adapter (the MCP server and the language bindings).

These are security-relevant DoS limits. They live here — not inside any one adapter — so every transport enforces the same numbers without a manual “keep in sync” comment, and so a build without the mcp feature still sees them. Each adapter formats its own transport-native error; only the values and the clamping policy are shared.

Constants§

DEFAULT_WHY_HOPS
Default hop budget for why traversal when the caller supplies none.
MAX_FACT_BYTES
Maximum accepted fact size (1 MiB) — prevents allocating huge embeddings.
MAX_RECALL_LIMIT
Cap on a recall limit — prevents unbounded vector scans (core does not cap k, so the adapters do).
MAX_WHY_HOPS
Cap on why hop depth — prevents exponential graph fan-out.

Functions§

clamp_hops
Clamp a caller-supplied why hop budget to MAX_WHY_HOPS.
clamp_recall_limit
Clamp a caller-supplied recall limit to MAX_RECALL_LIMIT.