hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

provider_limits.mojo (4192B)


      1 """Codified provider response byte limits (ADR-0026 D46 H093).
      2 
      3 These are the existing D21 / policy.v2 provider response bounds transcribed as
      4 capsule constants with inclusive upper caps, nonnegative-count guards and the
      5 stable failure causes/reasons already used by the H007 bounded-response
      6 observer. H093 selects no new threshold: header 65536, raw body 1048576 and
      7 decoded body 4194304 are the frozen values.
      8 
      9 This module is a pure boundary surface. It performs no allocation, no
     10 pre-allocation admission and no transport enforcement; C005/C047 and the owned
     11 consumer/exposure slices execute those controls against these exact values.
     12 """
     13 comptime PROVIDER_MAX_HEADER_BYTES: Int = 65536
     14 comptime PROVIDER_MAX_RAW_BODY_BYTES: Int = 1048576
     15 comptime PROVIDER_MAX_DECODED_BODY_BYTES: Int = 4194304
     16 
     17 comptime PROVIDER_HEAD_OVERFLOW_CAUSE: String = "raw_head_overflow"
     18 comptime PROVIDER_HEAD_OVERFLOW_REASON: String = "head_overflow"
     19 comptime PROVIDER_RAW_BODY_OVERFLOW_CAUSE: String = "raw_body_overflow"
     20 comptime PROVIDER_RAW_BODY_OVERFLOW_REASON: String = "body_overflow"
     21 comptime PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE: String = (
     22     "raw_content_length_overflow"
     23 )
     24 comptime PROVIDER_DECLARED_BODY_OVERFLOW_REASON: String = "raw_body_overflow"
     25 # H093 transcription for the decoded bound; the H007 observer is raw-only, so
     26 # this named reason is the codified value C005/NP02 enforces rather than an
     27 # existing observed string.
     28 comptime PROVIDER_DECODED_BODY_OVERFLOW_CAUSE: String = "decoded_body_overflow"
     29 comptime PROVIDER_DECODED_BODY_OVERFLOW_REASON: String = "decoded_body_overflow"
     30 
     31 
     32 def _require_nonnegative(byte_count: Int, context: String) raises:
     33     if byte_count < 0:
     34         raise Error(context + " must be non-negative")
     35 
     36 
     37 def provider_limit_is_inclusive() -> Bool:
     38     """Descriptive: the upper cap itself is accepted; only cap+1 overflows."""
     39     return True
     40 
     41 
     42 def provider_limit_min_bytes(kind: String) raises -> Int:
     43     """Policy.v2 lower bound: header min 1, raw body min 0, decoded min 0."""
     44     if kind == "header":
     45         return 1
     46     if kind == "raw_body" or kind == "decoded_body":
     47         return 0
     48     raise Error("unknown provider limit kind '" + kind + "'")
     49 
     50 
     51 def header_byte_count_within_bound(byte_count: Int) raises -> Bool:
     52     _require_nonnegative(byte_count, "provider header byte count")
     53     return byte_count >= 1 and byte_count <= PROVIDER_MAX_HEADER_BYTES
     54 
     55 
     56 def raw_body_byte_count_within_bound(byte_count: Int) raises -> Bool:
     57     _require_nonnegative(byte_count, "provider raw body byte count")
     58     return byte_count <= PROVIDER_MAX_RAW_BODY_BYTES
     59 
     60 
     61 def decoded_body_byte_count_within_bound(byte_count: Int) raises -> Bool:
     62     _require_nonnegative(byte_count, "provider decoded body byte count")
     63     return byte_count <= PROVIDER_MAX_DECODED_BODY_BYTES
     64 
     65 
     66 def provider_limit_bound(kind: String) raises -> Int:
     67     if kind == "header":
     68         return PROVIDER_MAX_HEADER_BYTES
     69     if kind == "raw_body":
     70         return PROVIDER_MAX_RAW_BODY_BYTES
     71     if kind == "decoded_body":
     72         return PROVIDER_MAX_DECODED_BODY_BYTES
     73     raise Error("unknown provider limit kind '" + kind + "'")
     74 
     75 
     76 def provider_limit_overflow_cause(kind: String) raises -> String:
     77     if kind == "header":
     78         return PROVIDER_HEAD_OVERFLOW_CAUSE
     79     if kind == "raw_body":
     80         return PROVIDER_RAW_BODY_OVERFLOW_CAUSE
     81     if kind == "declared_length":
     82         return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE
     83     if kind == "declared_body":
     84         return PROVIDER_RAW_BODY_OVERFLOW_CAUSE
     85     if kind == "decoded_body":
     86         return PROVIDER_DECODED_BODY_OVERFLOW_CAUSE
     87     raise Error("unknown provider limit kind '" + kind + "'")
     88 
     89 
     90 def provider_limit_failure_reason(kind: String) raises -> String:
     91     if kind == "header":
     92         return PROVIDER_HEAD_OVERFLOW_REASON
     93     if kind == "raw_body":
     94         return PROVIDER_RAW_BODY_OVERFLOW_REASON
     95     if kind == "declared_length":
     96         return PROVIDER_DECLARED_LENGTH_OVERFLOW_CAUSE
     97     if kind == "declared_body":
     98         return PROVIDER_DECLARED_BODY_OVERFLOW_REASON
     99     if kind == "decoded_body":
    100         return PROVIDER_DECODED_BODY_OVERFLOW_REASON
    101     raise Error("unknown provider limit kind '" + kind + "'")