commit 7d8b6e849459d6e71667da41aecd30af1f0a1272
parent 16765a8ae4cc227e1dc138e844741e6ac180cc8a
Author: triesap <tyson@radroots.org>
Date: Thu, 24 Sep 2026 17:51:42 +0000
H093: codify provider response byte limits under ADR-0026 D46
- Add hyf_runtime.provider_limits with inclusive header 65536, raw body 1048576 and decoded body 4194304 bounds
- Enforce nonnegative counts and the header min=1 lower bound; expose stable failure causes/reasons including the declared-body pair
- Add inclusive cap-1/cap/cap+1, zero, negative and failure-mapping boundary tests in the V-BOUNDARY lane
- Keep the surface pure: no allocation, pre-allocation or transport enforcement (C005/C047 retain it)
Diffstat:
2 files changed, 211 insertions(+), 0 deletions(-)
diff --git a/src/hyf_runtime/provider_limits.mojo b/src/hyf_runtime/provider_limits.mojo
@@ -0,0 +1,101 @@
+"""Codified provider response byte limits (ADR-0026 D46 H093).
+
+These are the existing D21 / policy.v2 provider response bounds transcribed as
+capsule constants with inclusive upper caps, nonnegative-count guards and the
+stable failure causes/reasons already used by the H007 bounded-response
+observer. H093 selects no new threshold: header 65536, raw body 1048576 and
+decoded body 4194304 are the frozen values.
+
+This module is a pure boundary surface. It performs no allocation, no
+pre-allocation admission and no transport enforcement; C005/C047 and the owned
+consumer/exposure slices execute those controls against these exact values.
+"""
+comptime PROVIDER_MAX_HEADER_BYTES: Int = 65536
+comptime PROVIDER_MAX_RAW_BODY_BYTES: Int = 1048576
+comptime PROVIDER_MAX_DECODED_BODY_BYTES: Int = 4194304
+
+comptime PROVIDER_HEAD_OVERFLOW_CAUSE: String = "raw_head_overflow"
+comptime PROVIDER_HEAD_OVERFLOW_REASON: String = "head_overflow"
+comptime PROVIDER_RAW_BODY_OVERFLOW_CAUSE: String = "raw_body_overflow"
+comptime PROVIDER_RAW_BODY_OVERFLOW_REASON: String = "body_overflow"
+comptime PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE: String = (
+ "raw_content_length_overflow"
+)
+comptime PROVIDER_DECLARED_BODY_OVERFLOW_REASON: String = "raw_body_overflow"
+# H093 transcription for the decoded bound; the H007 observer is raw-only, so
+# this named reason is the codified value C005/NP02 enforces rather than an
+# existing observed string.
+comptime PROVIDER_DECODED_BODY_OVERFLOW_CAUSE: String = "decoded_body_overflow"
+comptime PROVIDER_DECODED_BODY_OVERFLOW_REASON: String = "decoded_body_overflow"
+
+
+def _require_nonnegative(byte_count: Int, context: String) raises:
+ if byte_count < 0:
+ raise Error(context + " must be non-negative")
+
+
+def provider_limit_is_inclusive() -> Bool:
+ """Descriptive: the upper cap itself is accepted; only cap+1 overflows."""
+ return True
+
+
+def provider_limit_min_bytes(kind: String) raises -> Int:
+ """Policy.v2 lower bound: header min 1, raw body min 0, decoded min 0."""
+ if kind == "header":
+ return 1
+ if kind == "raw_body" or kind == "decoded_body":
+ return 0
+ raise Error("unknown provider limit kind '" + kind + "'")
+
+
+def header_byte_count_within_bound(byte_count: Int) raises -> Bool:
+ _require_nonnegative(byte_count, "provider header byte count")
+ return byte_count >= 1 and byte_count <= PROVIDER_MAX_HEADER_BYTES
+
+
+def raw_body_byte_count_within_bound(byte_count: Int) raises -> Bool:
+ _require_nonnegative(byte_count, "provider raw body byte count")
+ return byte_count <= PROVIDER_MAX_RAW_BODY_BYTES
+
+
+def decoded_body_byte_count_within_bound(byte_count: Int) raises -> Bool:
+ _require_nonnegative(byte_count, "provider decoded body byte count")
+ return byte_count <= PROVIDER_MAX_DECODED_BODY_BYTES
+
+
+def provider_limit_bound(kind: String) raises -> Int:
+ if kind == "header":
+ return PROVIDER_MAX_HEADER_BYTES
+ if kind == "raw_body":
+ return PROVIDER_MAX_RAW_BODY_BYTES
+ if kind == "decoded_body":
+ return PROVIDER_MAX_DECODED_BODY_BYTES
+ raise Error("unknown provider limit kind '" + kind + "'")
+
+
+def provider_limit_overflow_cause(kind: String) raises -> String:
+ if kind == "header":
+ return PROVIDER_HEAD_OVERFLOW_CAUSE
+ if kind == "raw_body":
+ return PROVIDER_RAW_BODY_OVERFLOW_CAUSE
+ if kind == "declared_length":
+ return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE
+ if kind == "declared_body":
+ return PROVIDER_RAW_BODY_OVERFLOW_CAUSE
+ if kind == "decoded_body":
+ return PROVIDER_DECODED_BODY_OVERFLOW_CAUSE
+ raise Error("unknown provider limit kind '" + kind + "'")
+
+
+def provider_limit_failure_reason(kind: String) raises -> String:
+ if kind == "header":
+ return PROVIDER_HEAD_OVERFLOW_REASON
+ if kind == "raw_body":
+ return PROVIDER_RAW_BODY_OVERFLOW_REASON
+ if kind == "declared_length":
+ return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE
+ if kind == "declared_body":
+ return PROVIDER_DECLARED_BODY_OVERFLOW_REASON
+ if kind == "decoded_body":
+ return PROVIDER_DECODED_BODY_OVERFLOW_REASON
+ raise Error("unknown provider limit kind '" + kind + "'")
diff --git a/tests/test_runtime_paths.mojo b/tests/test_runtime_paths.mojo
@@ -9,6 +9,27 @@ from hyf_runtime.paths import (
hyf_runtime_paths_for_unix_profile,
runtime_paths_for_namespace,
)
+from hyf_runtime.provider_limits import (
+ PROVIDER_DECLARED_BODY_OVERFLOW_REASON,
+ PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE,
+ PROVIDER_DECODED_BODY_OVERFLOW_CAUSE,
+ PROVIDER_DECODED_BODY_OVERFLOW_REASON,
+ PROVIDER_HEAD_OVERFLOW_CAUSE,
+ PROVIDER_HEAD_OVERFLOW_REASON,
+ PROVIDER_MAX_DECODED_BODY_BYTES,
+ PROVIDER_MAX_HEADER_BYTES,
+ PROVIDER_MAX_RAW_BODY_BYTES,
+ PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
+ PROVIDER_RAW_BODY_OVERFLOW_REASON,
+ decoded_body_byte_count_within_bound,
+ header_byte_count_within_bound,
+ provider_limit_bound,
+ provider_limit_failure_reason,
+ provider_limit_is_inclusive,
+ provider_limit_min_bytes,
+ provider_limit_overflow_cause,
+ raw_body_byte_count_within_bound,
+)
from hyf_runtime.roots import runtime_roots_from_base_root
from hyf_runtime.startup import RuntimeStartupInput, resolve_startup_context
@@ -845,3 +866,92 @@ def test_h092_budget_stage_cap_respects_absolute_deadline() raises:
assert_equal(configured.cap_ms, 1500)
assert_equal(budget_stage_cap_ms(configured, 1_000_000_000, 1000), 500)
assert_equal(budget_stage_cap_ms(configured, 1_500_000_000, 1000), 0)
+
+
+# ADR-0026 D46 H093: codified inclusive provider response byte limits. Pure
+# boundary surface; pre-allocation/transport enforcement remains C005/C047.
+def test_h093_provider_limit_constants_match_policy_v2() raises:
+ assert_equal(PROVIDER_MAX_HEADER_BYTES, 65536)
+ assert_equal(PROVIDER_MAX_RAW_BODY_BYTES, 1048576)
+ assert_equal(PROVIDER_MAX_DECODED_BODY_BYTES, 4194304)
+ assert_true(provider_limit_is_inclusive())
+ assert_equal(provider_limit_bound("header"), 65536)
+ assert_equal(provider_limit_bound("raw_body"), 1048576)
+ assert_equal(provider_limit_bound("decoded_body"), 4194304)
+
+
+def test_h093_provider_limit_bounds_are_inclusive() raises:
+ # header 65536
+ assert_true(header_byte_count_within_bound(65535))
+ assert_true(header_byte_count_within_bound(65536))
+ assert_true(not header_byte_count_within_bound(65537))
+ # raw body 1048576
+ assert_true(raw_body_byte_count_within_bound(1048575))
+ assert_true(raw_body_byte_count_within_bound(1048576))
+ assert_true(not raw_body_byte_count_within_bound(1048577))
+ # decoded body 4194304
+ assert_true(decoded_body_byte_count_within_bound(4194303))
+ assert_true(decoded_body_byte_count_within_bound(4194304))
+ assert_true(not decoded_body_byte_count_within_bound(4194305))
+ # zero-byte bodies are admissible at the raw/decoded bounds; the header
+ # policy lower bound is min=1, so a zero header count is below range.
+ assert_true(not header_byte_count_within_bound(0))
+ assert_true(raw_body_byte_count_within_bound(0))
+ assert_true(decoded_body_byte_count_within_bound(0))
+ assert_equal(provider_limit_min_bytes("header"), 1)
+ assert_equal(provider_limit_min_bytes("raw_body"), 0)
+ assert_equal(provider_limit_min_bytes("decoded_body"), 0)
+
+
+def test_h093_provider_limit_counts_must_be_nonnegative() raises:
+ with assert_raises():
+ _ = header_byte_count_within_bound(-1)
+ with assert_raises():
+ _ = raw_body_byte_count_within_bound(-1)
+ with assert_raises():
+ _ = decoded_body_byte_count_within_bound(-1)
+ with assert_raises():
+ _ = provider_limit_bound("unknown")
+ with assert_raises():
+ _ = provider_limit_min_bytes("unknown")
+ with assert_raises():
+ _ = provider_limit_failure_reason("unknown")
+ with assert_raises():
+ _ = provider_limit_overflow_cause("unknown")
+
+
+def test_h093_provider_limit_failures_are_stable() raises:
+ assert_equal(
+ provider_limit_overflow_cause("header"), PROVIDER_HEAD_OVERFLOW_CAUSE
+ )
+ assert_equal(
+ provider_limit_failure_reason("header"), PROVIDER_HEAD_OVERFLOW_REASON
+ )
+ assert_equal(
+ provider_limit_overflow_cause("raw_body"),
+ PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
+ )
+ assert_equal(
+ provider_limit_failure_reason("raw_body"),
+ PROVIDER_RAW_BODY_OVERFLOW_REASON,
+ )
+ assert_equal(
+ provider_limit_failure_reason("declared_length"),
+ PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE,
+ )
+ assert_equal(
+ provider_limit_overflow_cause("declared_body"),
+ PROVIDER_RAW_BODY_OVERFLOW_CAUSE,
+ )
+ assert_equal(
+ provider_limit_failure_reason("declared_body"),
+ PROVIDER_DECLARED_BODY_OVERFLOW_REASON,
+ )
+ assert_equal(
+ provider_limit_overflow_cause("decoded_body"),
+ PROVIDER_DECODED_BODY_OVERFLOW_CAUSE,
+ )
+ assert_equal(
+ provider_limit_failure_reason("decoded_body"),
+ PROVIDER_DECODED_BODY_OVERFLOW_REASON,
+ )