Expand description
Resource caps (DoS limits) shared by every adapter — the single source of
truth for fact size, recall limit, and why hop depth.
Resource caps shared by every adapter (the MCP server and the language
bindings).
These are security-relevant DoS limits. They live here — not inside any one
adapter — so every transport enforces the same numbers without a manual
“keep in sync” comment, and so a build without the mcp feature still sees
them. Each adapter formats its own transport-native error; only the values
and the clamping policy are shared.
Constants§
- DEFAULT_
WHY_ HOPS - Default hop budget for
whytraversal when the caller supplies none. - MAX_
FACT_ BYTES - Maximum accepted fact size (1 MiB) — prevents allocating huge embeddings.
- MAX_
FRAGMENTS - Cap on the number of fragments in one compile request — bounds the work a single call can demand across every adapter.
- MAX_
FRAGMENT_ BYTES - Maximum accepted size of a single context-compiler fragment (1 MiB, the
same ceiling as
MAX_FACT_BYTES) — prevents a single fragment from forcing huge allocations in the compile pipeline. - MAX_
RECALL_ LIMIT - Cap on a
recalllimit — prevents unbounded vector scans (core does not capk, so the adapters do). - MAX_
TOKEN_ BUDGET - Cap on a caller-supplied token budget. A budget cannot force allocations by itself, but an absurd value would make the savings arithmetic meaningless, so adapters clamp to this ceiling instead of erroring.
- MAX_
WHY_ HOPS - Cap on
whyhop depth — prevents exponential graph fan-out.
Functions§
- clamp_
hops - Clamp a caller-supplied
whyhop budget toMAX_WHY_HOPS. - clamp_
recall_ limit - Clamp a caller-supplied recall limit to
MAX_RECALL_LIMIT. - clamp_
token_ budget - Clamp a caller-supplied token budget to
MAX_TOKEN_BUDGET.