Summary
Follow-up to #347, which enforces the 64 KB attribute-name limit at every nesting depth on PutItem, BatchWriteItem PutRequest, TransactWriteItems Put, and ImportTable, and documents the remaining gap in docs/dynamodb-limits.md as Partial: UpdateItem and TransactWriteItems Update do not enforce the limit at any level. A client can store a 65,536 byte (or larger) attribute name through SET #n = :v with a long name in ExpressionAttributeNames, or through a map value carrying a long key, and the item is written.
Separately, the message ExtendDB returns where it does enforce the limit is not the service's.
Measured against the service (2026-09-16)
| request |
service response |
| PutItem, top-level name of 65,536 bytes |
400 ValidationException: 1 validation error detected: Attribute name is too large, must be less than 65536 bytes |
| PutItem, nested map key of 65,536 bytes |
400 ValidationException, same message |
| PutItem, nested map key of 65,535 bytes |
200 |
UpdateItem SET doc = :v, value containing a 65,536 byte nested key |
400 ValidationException, same message |
UpdateItem SET #n = :v, #n mapped to a 65,536 byte name |
400 ValidationException: 1 validation error detected: Attribute name is too large, must be less than 65536 bytes for key #n |
ExtendDB on main (after #347):
| request |
ExtendDB response |
| PutItem, top-level or nested name of 65,536 bytes |
400 ValidationException: One or more parameter values were invalid: Size of attribute name '...' has exceeded the maximum size limit of 65535 bytes |
| UpdateItem, either shape above |
200, item written with the oversized name |
| TransactWriteItems Update, either shape |
200 |
Expected
- UpdateItem and TransactWriteItems Update reject an attribute name of 65,536 bytes or more at every depth: names introduced through
ExpressionAttributeNames, and map keys inside any value in ExpressionAttributeValues.
- The message is the service's:
1 validation error detected: Attribute name is too large, must be less than 65536 bytes, with the suffix for key #n when the offending name arrived through ExpressionAttributeNames under placeholder #n.
- The existing Put-path message is changed to the same text, and the
docs/dynamodb-limits.md row moves from Partial to Yes.
Where
validate_attribute_name_sizes in crates/core/src/validation/mod.rs already walks M and L values; the UpdateItem paths need to call it on every ExpressionAttributeValues entry and check every ExpressionAttributeNames value. LimitsConfig::max_attribute_name_bytes carries the limit.
Summary
Follow-up to #347, which enforces the 64 KB attribute-name limit at every nesting depth on PutItem, BatchWriteItem PutRequest, TransactWriteItems Put, and ImportTable, and documents the remaining gap in
docs/dynamodb-limits.mdas Partial: UpdateItem and TransactWriteItems Update do not enforce the limit at any level. A client can store a 65,536 byte (or larger) attribute name throughSET #n = :vwith a long name inExpressionAttributeNames, or through a map value carrying a long key, and the item is written.Separately, the message ExtendDB returns where it does enforce the limit is not the service's.
Measured against the service (2026-09-16)
ValidationException:1 validation error detected: Attribute name is too large, must be less than 65536 bytesValidationException, same messageSET doc = :v, value containing a 65,536 byte nested keyValidationException, same messageSET #n = :v,#nmapped to a 65,536 byte nameValidationException:1 validation error detected: Attribute name is too large, must be less than 65536 bytes for key #nExtendDB on
main(after #347):ValidationException:One or more parameter values were invalid: Size of attribute name '...' has exceeded the maximum size limit of 65535 bytesExpected
ExpressionAttributeNames, and map keys inside any value inExpressionAttributeValues.1 validation error detected: Attribute name is too large, must be less than 65536 bytes, with the suffixfor key #nwhen the offending name arrived throughExpressionAttributeNamesunder placeholder#n.docs/dynamodb-limits.mdrow moves from Partial to Yes.Where
validate_attribute_name_sizesincrates/core/src/validation/mod.rsalready walksMandLvalues; the UpdateItem paths need to call it on everyExpressionAttributeValuesentry and check everyExpressionAttributeNamesvalue.LimitsConfig::max_attribute_name_bytescarries the limit.