Skip to content

feat: bound in-memory response resources - #25

Merged
zuudevs merged 15 commits into
mainfrom
hardening/response-limits
Sep 15, 2026
Merged

zuudevs merged 15 commits into
mainfrom
hardening/response-limits

Conversation

@zuudevs

@zuudevs zuudevs commented Sep 15, 2026

Copy link
Copy Markdown
Owner

Summary

Completes the final v0.8 hardening substep by adding explicit finite resource bounds to the in-memory HTTP/1.1 response path.

Public API

  • adds ResponseLimits
  • adds Client::set_response_limits() and Client::response_limits()
  • keeps limit state inline/by-value with no PImpl or heap-owned configuration state
  • preserves configured limits across Client move construction and assignment

Default limits

  • response head: 64 KiB
  • decoded body: 64 MiB
  • chunk-size line: 8 KiB
  • chunked trailer section: 64 KiB

Zero is a real limit rather than an unlimited sentinel.

Enforcement

  • rejects oversized response heads before header parsing can grow without bound
  • rejects oversized Content-Length before reserving declared body capacity
  • bounds close-delimited body growth before append
  • checks chunk size against remaining decoded-body budget before chunk payload append
  • bounds pathological/unterminated chunk-size lines
  • bounds aggregate trailer bytes including CRLF delimiters

Error model

  • adds ErrorCode::ResponseLimitExceeded
  • keeps resource-budget failures separate from malformed HTTP syntax/framing errors
  • a limit failure never yields a partial successful Response and the active connection is not retained for reuse

Tests

Adds deterministic coverage for:

  • finite defaults
  • client configuration and move preservation
  • oversized response heads
  • declared Content-Length above budget
  • exact body-boundary acceptance
  • close-delimited overflow
  • chunked body overflow
  • chunk-line overflow
  • trailer-section overflow

Documentation

  • adds docs/api/response-limits.md
  • updates public API and error-model contracts
  • marks Result, URL/query, and HTTP correctness hardening complete in the roadmap
  • records response resource bounds as the final v0.8 substep

Scope

This does not add response streaming, compression, retry behavior, pooling, TLS, or async I/O. The frozen v1 response model remains fully memory-resident.

@zuudevs
zuudevs merged commit 91cc5bf into main Sep 15, 2026
6 checks passed
@zuudevs
zuudevs deleted the hardening/response-limits branch September 15, 2026 01:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant