pub struct Limits {Show 15 fields
pub max_header_bytes: u64,
pub max_concurrent_uni_streams: u32,
pub max_concurrent_bidi_streams: u32,
pub stream_receive_window: u64,
pub connection_receive_window: u64,
pub keep_alive: Duration,
pub idle_timeout: Duration,
pub hello_timeout_ms: u64,
pub max_subscriptions: usize,
pub subscriber_buffer_bytes: usize,
pub max_sequence_scopes: usize,
pub max_reorder_hold: usize,
pub max_local_streams: usize,
pub max_parked_reverse: usize,
pub max_dedup_entries: usize,
}Expand description
Resource limits applied to one connection.
Fields§
§max_header_bytes: u64Largest frame header this side will accept, in bytes. Checked against the preamble length before any allocation.
max_concurrent_uni_streams: u32QUIC concurrent inbound unidirectional streams. Bounds the number of live per-stream parse tasks for one-way transfers.
max_concurrent_bidi_streams: u32QUIC concurrent inbound bidirectional streams; bounds live request
exchanges per connection and, with max_header_bytes, worst-case
header memory.
stream_receive_window: u64QUIC per-stream receive window in bytes. Bounds buffered payload for one transfer and provides backpressure to the sender.
connection_receive_window: u64QUIC per-connection receive window in bytes.
keep_alive: DurationQUIC keep-alive interval. Sent by the dialling side only, so a binding’s value is not used.
idle_timeout: DurationQUIC idle timeout, applied in both directions.
hello_timeout_ms: u64How long to wait for the peer HELLO before closing the connection with
NEGOTIATION_FAILED, in milliseconds.
max_subscriptions: usizeSubscription filters one peer connection may hold at once, summed over
every path. Exceeding it closes the connection with LIMIT_EXCEEDED:
SUBSCRIBE has no stream to answer with an ERROR frame.
subscriber_buffer_bytes: usizePayload bytes a publisher may hold queued for one subscriber. A message that does not fit is dropped for that subscriber and counted; the publisher never blocks on a slow consumer.
max_sequence_scopes: usizeProducer scopes — paths and topics — a receiver tracks per connection
for gap detection or reassembly, when PerProducer ordering is
negotiated. The peer chooses the scope names, so the table needs a
ceiling; at the cap a new scope is simply not tracked, no gap is
reported for it and nothing is held back for it.
max_reorder_hold: usizeTransfers a receiver may hold back at once, summed over scopes, when
PerProducer(reassemble) ordering is negotiated. A held transfer is
an unread stream, so the bytes it pins are quinn’s — up to
stream_receive_window for it and connection_receive_window for the
hold as a whole. At the cap the oldest held transfer is released out
of order with its gap reported, never held in a growing buffer.
max_local_streams: usizeLive transfers on one local connection, where the OS connection
is the stream and there is no multiplexing
(decisions/0010
§4.2). Windows caps named-pipe instances at 1-255, which is the
tightest platform limit and therefore the one the default respects;
an open at the cap waits for a live transfer to end, exactly as a
QUIC open waits on the peer’s stream budget, rather than refusing.
A peer configured with zero can therefore open nothing and waits
until its caller’s deadline, exactly as one granted no QUIC streams.
max_parked_reverse: usizeConnections a subscriber parks toward a peer it dialled, so that peer
can open a stream back
(decisions/0012
§4.4). An accepted socket cannot be dialled, so fan-out over a local
socket transport rides connections the subscriber opened and left
waiting; each is a file descriptor held for a copy that may never
come, and each counts against max_local_streams on both sides. A
publisher that finds none parked drops that copy and counts it, the
same answer fan-out already gives an exhausted subscriber budget. Zero
disables the pool, which makes a subscription over such a transport an
error at subscribe time rather than a silence.
max_dedup_entries: usizeIdentities a receiver remembers per connection for Bounded
deduplication. The window bounds how long an identity is kept, not
how many arrive within it, so the count needs its own ceiling; at the
cap the oldest entry is evicted, which costs suppression rather than
memory.