hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

commit 7d8b6e849459d6e71667da41aecd30af1f0a1272
parent 16765a8ae4cc227e1dc138e844741e6ac180cc8a
Author: triesap <tyson@radroots.org>
Date:   Thu, 24 Sep 2026 17:51:42 +0000

H093: codify provider response byte limits under ADR-0026 D46

- Add hyf_runtime.provider_limits with inclusive header 65536, raw body 1048576 and decoded body 4194304 bounds
- Enforce nonnegative counts and the header min=1 lower bound; expose stable failure causes/reasons including the declared-body pair
- Add inclusive cap-1/cap/cap+1, zero, negative and failure-mapping boundary tests in the V-BOUNDARY lane
- Keep the surface pure: no allocation, pre-allocation or transport enforcement (C005/C047 retain it)

Diffstat:
Asrc/hyf_runtime/provider_limits.mojo | 101+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mtests/test_runtime_paths.mojo | 110+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 211 insertions(+), 0 deletions(-)

diff --git a/src/hyf_runtime/provider_limits.mojo b/src/hyf_runtime/provider_limits.mojo @@ -0,0 +1,101 @@ +"""Codified provider response byte limits (ADR-0026 D46 H093). + +These are the existing D21 / policy.v2 provider response bounds transcribed as +capsule constants with inclusive upper caps, nonnegative-count guards and the +stable failure causes/reasons already used by the H007 bounded-response +observer. H093 selects no new threshold: header 65536, raw body 1048576 and +decoded body 4194304 are the frozen values. + +This module is a pure boundary surface. It performs no allocation, no +pre-allocation admission and no transport enforcement; C005/C047 and the owned +consumer/exposure slices execute those controls against these exact values. +""" +comptime PROVIDER_MAX_HEADER_BYTES: Int = 65536 +comptime PROVIDER_MAX_RAW_BODY_BYTES: Int = 1048576 +comptime PROVIDER_MAX_DECODED_BODY_BYTES: Int = 4194304 + +comptime PROVIDER_HEAD_OVERFLOW_CAUSE: String = "raw_head_overflow" +comptime PROVIDER_HEAD_OVERFLOW_REASON: String = "head_overflow" +comptime PROVIDER_RAW_BODY_OVERFLOW_CAUSE: String = "raw_body_overflow" +comptime PROVIDER_RAW_BODY_OVERFLOW_REASON: String = "body_overflow" +comptime PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE: String = ( + "raw_content_length_overflow" +) +comptime PROVIDER_DECLARED_BODY_OVERFLOW_REASON: String = "raw_body_overflow" +# H093 transcription for the decoded bound; the H007 observer is raw-only, so +# this named reason is the codified value C005/NP02 enforces rather than an +# existing observed string. +comptime PROVIDER_DECODED_BODY_OVERFLOW_CAUSE: String = "decoded_body_overflow" +comptime PROVIDER_DECODED_BODY_OVERFLOW_REASON: String = "decoded_body_overflow" + + +def _require_nonnegative(byte_count: Int, context: String) raises: + if byte_count < 0: + raise Error(context + " must be non-negative") + + +def provider_limit_is_inclusive() -> Bool: + """Descriptive: the upper cap itself is accepted; only cap+1 overflows.""" + return True + + +def provider_limit_min_bytes(kind: String) raises -> Int: + """Policy.v2 lower bound: header min 1, raw body min 0, decoded min 0.""" + if kind == "header": + return 1 + if kind == "raw_body" or kind == "decoded_body": + return 0 + raise Error("unknown provider limit kind '" + kind + "'") + + +def header_byte_count_within_bound(byte_count: Int) raises -> Bool: + _require_nonnegative(byte_count, "provider header byte count") + return byte_count >= 1 and byte_count <= PROVIDER_MAX_HEADER_BYTES + + +def raw_body_byte_count_within_bound(byte_count: Int) raises -> Bool: + _require_nonnegative(byte_count, "provider raw body byte count") + return byte_count <= PROVIDER_MAX_RAW_BODY_BYTES + + +def decoded_body_byte_count_within_bound(byte_count: Int) raises -> Bool: + _require_nonnegative(byte_count, "provider decoded body byte count") + return byte_count <= PROVIDER_MAX_DECODED_BODY_BYTES + + +def provider_limit_bound(kind: String) raises -> Int: + if kind == "header": + return PROVIDER_MAX_HEADER_BYTES + if kind == "raw_body": + return PROVIDER_MAX_RAW_BODY_BYTES + if kind == "decoded_body": + return PROVIDER_MAX_DECODED_BODY_BYTES + raise Error("unknown provider limit kind '" + kind + "'") + + +def provider_limit_overflow_cause(kind: String) raises -> String: + if kind == "header": + return PROVIDER_HEAD_OVERFLOW_CAUSE + if kind == "raw_body": + return PROVIDER_RAW_BODY_OVERFLOW_CAUSE + if kind == "declared_length": + return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE + if kind == "declared_body": + return PROVIDER_RAW_BODY_OVERFLOW_CAUSE + if kind == "decoded_body": + return PROVIDER_DECODED_BODY_OVERFLOW_CAUSE + raise Error("unknown provider limit kind '" + kind + "'") + + +def provider_limit_failure_reason(kind: String) raises -> String: + if kind == "header": + return PROVIDER_HEAD_OVERFLOW_REASON + if kind == "raw_body": + return PROVIDER_RAW_BODY_OVERFLOW_REASON + if kind == "declared_length": + return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE + if kind == "declared_body": + return PROVIDER_DECLARED_BODY_OVERFLOW_REASON + if kind == "decoded_body": + return PROVIDER_DECODED_BODY_OVERFLOW_REASON + raise Error("unknown provider limit kind '" + kind + "'") diff --git a/tests/test_runtime_paths.mojo b/tests/test_runtime_paths.mojo @@ -9,6 +9,27 @@ from hyf_runtime.paths import ( hyf_runtime_paths_for_unix_profile, runtime_paths_for_namespace, ) +from hyf_runtime.provider_limits import ( + PROVIDER_DECLARED_BODY_OVERFLOW_REASON, + PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE, + PROVIDER_DECODED_BODY_OVERFLOW_CAUSE, + PROVIDER_DECODED_BODY_OVERFLOW_REASON, + PROVIDER_HEAD_OVERFLOW_CAUSE, + PROVIDER_HEAD_OVERFLOW_REASON, + PROVIDER_MAX_DECODED_BODY_BYTES, + PROVIDER_MAX_HEADER_BYTES, + PROVIDER_MAX_RAW_BODY_BYTES, + PROVIDER_RAW_BODY_OVERFLOW_CAUSE, + PROVIDER_RAW_BODY_OVERFLOW_REASON, + decoded_body_byte_count_within_bound, + header_byte_count_within_bound, + provider_limit_bound, + provider_limit_failure_reason, + provider_limit_is_inclusive, + provider_limit_min_bytes, + provider_limit_overflow_cause, + raw_body_byte_count_within_bound, +) from hyf_runtime.roots import runtime_roots_from_base_root from hyf_runtime.startup import RuntimeStartupInput, resolve_startup_context @@ -845,3 +866,92 @@ def test_h092_budget_stage_cap_respects_absolute_deadline() raises: assert_equal(configured.cap_ms, 1500) assert_equal(budget_stage_cap_ms(configured, 1_000_000_000, 1000), 500) assert_equal(budget_stage_cap_ms(configured, 1_500_000_000, 1000), 0) + + +# ADR-0026 D46 H093: codified inclusive provider response byte limits. Pure +# boundary surface; pre-allocation/transport enforcement remains C005/C047. +def test_h093_provider_limit_constants_match_policy_v2() raises: + assert_equal(PROVIDER_MAX_HEADER_BYTES, 65536) + assert_equal(PROVIDER_MAX_RAW_BODY_BYTES, 1048576) + assert_equal(PROVIDER_MAX_DECODED_BODY_BYTES, 4194304) + assert_true(provider_limit_is_inclusive()) + assert_equal(provider_limit_bound("header"), 65536) + assert_equal(provider_limit_bound("raw_body"), 1048576) + assert_equal(provider_limit_bound("decoded_body"), 4194304) + + +def test_h093_provider_limit_bounds_are_inclusive() raises: + # header 65536 + assert_true(header_byte_count_within_bound(65535)) + assert_true(header_byte_count_within_bound(65536)) + assert_true(not header_byte_count_within_bound(65537)) + # raw body 1048576 + assert_true(raw_body_byte_count_within_bound(1048575)) + assert_true(raw_body_byte_count_within_bound(1048576)) + assert_true(not raw_body_byte_count_within_bound(1048577)) + # decoded body 4194304 + assert_true(decoded_body_byte_count_within_bound(4194303)) + assert_true(decoded_body_byte_count_within_bound(4194304)) + assert_true(not decoded_body_byte_count_within_bound(4194305)) + # zero-byte bodies are admissible at the raw/decoded bounds; the header + # policy lower bound is min=1, so a zero header count is below range. + assert_true(not header_byte_count_within_bound(0)) + assert_true(raw_body_byte_count_within_bound(0)) + assert_true(decoded_body_byte_count_within_bound(0)) + assert_equal(provider_limit_min_bytes("header"), 1) + assert_equal(provider_limit_min_bytes("raw_body"), 0) + assert_equal(provider_limit_min_bytes("decoded_body"), 0) + + +def test_h093_provider_limit_counts_must_be_nonnegative() raises: + with assert_raises(): + _ = header_byte_count_within_bound(-1) + with assert_raises(): + _ = raw_body_byte_count_within_bound(-1) + with assert_raises(): + _ = decoded_body_byte_count_within_bound(-1) + with assert_raises(): + _ = provider_limit_bound("unknown") + with assert_raises(): + _ = provider_limit_min_bytes("unknown") + with assert_raises(): + _ = provider_limit_failure_reason("unknown") + with assert_raises(): + _ = provider_limit_overflow_cause("unknown") + + +def test_h093_provider_limit_failures_are_stable() raises: + assert_equal( + provider_limit_overflow_cause("header"), PROVIDER_HEAD_OVERFLOW_CAUSE + ) + assert_equal( + provider_limit_failure_reason("header"), PROVIDER_HEAD_OVERFLOW_REASON + ) + assert_equal( + provider_limit_overflow_cause("raw_body"), + PROVIDER_RAW_BODY_OVERFLOW_CAUSE, + ) + assert_equal( + provider_limit_failure_reason("raw_body"), + PROVIDER_RAW_BODY_OVERFLOW_REASON, + ) + assert_equal( + provider_limit_failure_reason("declared_length"), + PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE, + ) + assert_equal( + provider_limit_overflow_cause("declared_body"), + PROVIDER_RAW_BODY_OVERFLOW_CAUSE, + ) + assert_equal( + provider_limit_failure_reason("declared_body"), + PROVIDER_DECLARED_BODY_OVERFLOW_REASON, + ) + assert_equal( + provider_limit_overflow_cause("decoded_body"), + PROVIDER_DECODED_BODY_OVERFLOW_CAUSE, + ) + assert_equal( + provider_limit_failure_reason("decoded_body"), + PROVIDER_DECODED_BODY_OVERFLOW_REASON, + )