Skip to content

[Bug] UpdateItem and TransactWriteItems Update do not enforce the attribute-name size limit; message differs from the service #365

Description

@LeeroyHannigan

Summary

Follow-up to #347, which enforces the 64 KB attribute-name limit at every nesting depth on PutItem, BatchWriteItem PutRequest, TransactWriteItems Put, and ImportTable, and documents the remaining gap in docs/dynamodb-limits.md as Partial: UpdateItem and TransactWriteItems Update do not enforce the limit at any level. A client can store a 65,536 byte (or larger) attribute name through SET #n = :v with a long name in ExpressionAttributeNames, or through a map value carrying a long key, and the item is written.

Separately, the message ExtendDB returns where it does enforce the limit is not the service's.

Measured against the service (2026-09-16)

request service response
PutItem, top-level name of 65,536 bytes 400 ValidationException: 1 validation error detected: Attribute name is too large, must be less than 65536 bytes
PutItem, nested map key of 65,536 bytes 400 ValidationException, same message
PutItem, nested map key of 65,535 bytes 200
UpdateItem SET doc = :v, value containing a 65,536 byte nested key 400 ValidationException, same message
UpdateItem SET #n = :v, #n mapped to a 65,536 byte name 400 ValidationException: 1 validation error detected: Attribute name is too large, must be less than 65536 bytes for key #n

ExtendDB on main (after #347):

request ExtendDB response
PutItem, top-level or nested name of 65,536 bytes 400 ValidationException: One or more parameter values were invalid: Size of attribute name '...' has exceeded the maximum size limit of 65535 bytes
UpdateItem, either shape above 200, item written with the oversized name
TransactWriteItems Update, either shape 200

Expected

  1. UpdateItem and TransactWriteItems Update reject an attribute name of 65,536 bytes or more at every depth: names introduced through ExpressionAttributeNames, and map keys inside any value in ExpressionAttributeValues.
  2. The message is the service's: 1 validation error detected: Attribute name is too large, must be less than 65536 bytes, with the suffix for key #n when the offending name arrived through ExpressionAttributeNames under placeholder #n.
  3. The existing Put-path message is changed to the same text, and the docs/dynamodb-limits.md row moves from Partial to Yes.

Where

validate_attribute_name_sizes in crates/core/src/validation/mod.rs already walks M and L values; the UpdateItem paths need to call it on every ExpressionAttributeValues entry and check every ExpressionAttributeNames value. LimitsConfig::max_attribute_name_bytes carries the limit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions