ADR 0115 (proposed): a route may state the largest request body it carries

ADR 0108 closed the policy set at four and priced a fifth: earned by a dependent that exists. The
registry's public door is one. A registry takes layers in single requests of gigabytes, the
predecessor served that name with a body-size middleware, and without one the proxy refuses the push
at its own default before the registry sees it — so a public name that cannot state its limit is a
public name nothing can be pushed to.

Rejects the cheap merge deliberately: the implementation waiting on feat/registry-public-route could
carry the limit beside certificate verification as a transport detail, but a body limit refuses
requests, and a closed set with an exception written next to it is not a closed set.
This commit is contained in:
jochen
2026-09-26 15:10:26 +02:00
parent 859ff49ff2
commit 81bdf8df56
2 changed files with 82 additions and 0 deletions
+1
View File
@@ -125,6 +125,7 @@ python3 00-META/checks/index.py fail if stale
- **0098** — [A fact a provider makes at first start is fetched from it, not carried in its manifest](0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md)
- **0108** — [A route carries the policy applied to a request, and names a secret rather than holding one](0108-a-route-carries-the-policy-applied-to-a-request.md)
- **0109** — [A package registry seat is one per ecosystem, not one for all of them](0109-a-package-registry-seat-is-one-per-ecosystem.md)
- **0115** — [A route may state the largest request body it carries, which is the fifth policy](0115-a-route-may-limit-the-body-it-carries.md) *(proposed)*
### What runs on them, and how it gets there