Skip to content

AUS-1006: Document the AOT position, the deadline rule and a host-owned deadline - #167

Merged
Astn merged 4 commits into
masterfrom
aus-1006-docs
Sep 26, 2026
Merged

Astn merged 4 commits into
masterfrom
aus-1006-docs

Conversation

@Astn

@Astn Astn commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Documentation only (AUS-1001 item 4 of the 2.0.0 sequence), decided in T4 Q5 and T6 Q1.

  • README "Requirements": the WebAssembly sample validates neither PublishTrimmed nor PublishAot; both are unsupported.
  • README "Versioning and support": the bullet now names Native AOT alongside trimming.
  • README "Asynchronous methods and cancellation": a Deadlines paragraph (no per-call deadline, the request-timeouts middleware on HTTP, what observes the token, cooperative cancellation).
  • README "In-process (strings or bytes)": a host-owned deadline example (linked CancellationTokenSource with CancelAfter, transport aborted on expiry, buffers returned only after the awaited call terminates). The example was compiled against the test project on net8.0 and net10.0 and is not committed as a test.
  • CHANGELOG 2.0.0 Changed: the WebAssembly sample is not a Native AOT or full-trimming guarantee.

Based on the head of #166; once that merges, this diff is the single commit. Site build (site/build.py) passes with the new anchors.

Names beginning with rpc. and the name $/cancelRequest are refused by one check in SMDServiceCollection (Add, the indexer setter and AddBatch before any entry is copied), which every registration path reaches: BindMethod, the attribute binder and RegisterFuction through AddService, BindInterface through AddBatch. BindInterface drops its own rpc. test. An internal AddReserved keeps the duplicate rule for the library's later rpc.discover registration. README, CHANGELOG and docs/upgrading.md carry the change.
The core now bounds what it admits: a document over JsonRpcLimits.MaxDocumentBytes (4 MiB by default) or a batch with more than MaxBatchCount entries (1024) is answered with -32600 and a data object naming the limit and the configured maximum, before anything is parsed or executed. The byte check runs at every public Process and ProcessAsync entry before any copy, flattening or transcoding (string overloads measure the UTF-8 byte count); the batch check runs after a full parse and before the first dispatch, so no prefix of an over-long batch executes. Config.SetLimits sets the process-wide value or a per-session override; zero disables a field and JsonRpcLimits.Unlimited restores the 1.x behaviour. Kestrel's MaxRequestBytes stays and is met first. README, SECURITY.md, CHANGELOG and docs/upgrading.md describe the limits and the staged host-responsibility paragraph.
AUS-1004: Add JsonRpcLimits with document and batch bounds
@Astn
Astn merged commit a0762d1 into master Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant