Skip to content

AUS-1003, AUS-1004: Reserved names and limits to master - #166

Merged
Astn merged 3 commits into
masterfrom
aus-1003-reserved-names
Sep 26, 2026
Merged

Astn merged 3 commits into
masterfrom
aus-1003-reserved-names

Conversation

@Astn

@Astn Astn commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Pulls 164 (AUS-1003) and 165 (AUS-1004) were stacked and merged into their base branches, so their commits reached aus-1002-remove-inprocessclient and aus-1003-reserved-names but not master. This pull request brings both to master; the diff against master is exactly the two reviewed commits plus their merge commits.

Verification on the branch head: Release build, full test run on net8.0 and net10.0, request-path sync checker (23 listed uses, none unlisted), chart render check, and the paired benchmark gate recorded on AUS-1004.

Names beginning with rpc. and the name $/cancelRequest are refused by one check in SMDServiceCollection (Add, the indexer setter and AddBatch before any entry is copied), which every registration path reaches: BindMethod, the attribute binder and RegisterFuction through AddService, BindInterface through AddBatch. BindInterface drops its own rpc. test. An internal AddReserved keeps the duplicate rule for the library's later rpc.discover registration. README, CHANGELOG and docs/upgrading.md carry the change.
The core now bounds what it admits: a document over JsonRpcLimits.MaxDocumentBytes (4 MiB by default) or a batch with more than MaxBatchCount entries (1024) is answered with -32600 and a data object naming the limit and the configured maximum, before anything is parsed or executed. The byte check runs at every public Process and ProcessAsync entry before any copy, flattening or transcoding (string overloads measure the UTF-8 byte count); the batch check runs after a full parse and before the first dispatch, so no prefix of an over-long batch executes. Config.SetLimits sets the process-wide value or a per-session override; zero disables a field and JsonRpcLimits.Unlimited restores the 1.x behaviour. Kestrel's MaxRequestBytes stays and is met first. README, SECURITY.md, CHANGELOG and docs/upgrading.md describe the limits and the staged host-responsibility paragraph.
AUS-1004: Add JsonRpcLimits with document and batch bounds
@Astn
Astn merged commit fbe18a4 into master Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant