A route may say the largest body it carries #68

Merged
jschoubben merged 1 commits from feat/a-route-may-limit-the-body-it-carries into main 2026-09-26 14:01:58 +00:00
Owner

The one thing worth keeping from feat/registry-public-route, rebuilt on the current proxy. Pairs with mesh-catalog #70, which teaches the adapter the same setting for the predecessor's proxy; either lands alone without breaking anything.

It is configuration, not a fifth policy. ADR 0108 closed that set at four, and a maximum body sits beside insecure for the same reason insecure is not a policy: both tune how this proxy carries a request to a backend, rather than deciding what a name admits or who may reach it. That is written into the field's comment so the next reader does not have to re-derive it. A registry is the case that needs it — image layers arrive as single requests of gigabytes, and a proxy's own default refuses them long before the workload is reached.

Behaviour:

  • Absent is no limit, which is what every route already gets. This proxy has never limited a body, and a default arriving with the field would change every route that never asked.
  • A limit that is not a whole positive number of bytes takes the route with it, named in the log exactly like a port that is not a port. Serving it without the limit would carry what the module said not to carry, and report success doing it.
  • Enforced on the declared length where there is one — so an upload that cannot succeed is refused before it is carried, with the limit named in a 413 — and while reading for a chunked body, which declares no length. Without the second, a limit is advice.

Four new tests: the limit survives a contribution, silence stays unlimited, four shapes of unusable limit are each skipped, and a request over the limit gets 413 while one under it reaches the workload. go build ./... clean, go test ./... 19 packages, exit 0.

What is not here, deliberately: the old branch's central route vocabulary. It is a closed allowlist written before ADR 0108, so it refuses deny, redirect, authenticate and path — importing it would reject every policy-bearing route in the catalogue. And the distribution-gate module is not being built at all; hq issue 108 records why (the seat-holding store does not get a second, public door over the same filesystem).

The one thing worth keeping from `feat/registry-public-route`, rebuilt on the current proxy. Pairs with **mesh-catalog #70**, which teaches the adapter the same setting for the predecessor's proxy; either lands alone without breaking anything. **It is configuration, not a fifth policy.** ADR 0108 closed that set at four, and a maximum body sits beside `insecure` for the same reason `insecure` is not a policy: both tune how this proxy carries a request to a backend, rather than deciding what a name admits or who may reach it. That is written into the field's comment so the next reader does not have to re-derive it. A registry is the case that needs it — image layers arrive as single requests of gigabytes, and a proxy's own default refuses them long before the workload is reached. Behaviour: - **Absent is no limit**, which is what every route already gets. This proxy has never limited a body, and a default arriving with the field would change every route that never asked. - **A limit that is not a whole positive number of bytes takes the route with it**, named in the log exactly like a port that is not a port. Serving it without the limit would carry what the module said not to carry, and report success doing it. - **Enforced on the declared length where there is one** — so an upload that cannot succeed is refused before it is carried, with the limit named in a 413 — **and while reading for a chunked body**, which declares no length. Without the second, a limit is advice. Four new tests: the limit survives a contribution, silence stays unlimited, four shapes of unusable limit are each skipped, and a request over the limit gets 413 while one under it reaches the workload. `go build ./...` clean, `go test ./...` **19 packages, exit 0**. What is *not* here, deliberately: the old branch's central route vocabulary. It is a closed allowlist written before ADR 0108, so it refuses `deny`, `redirect`, `authenticate` and `path` — importing it would reject every policy-bearing route in the catalogue. And the `distribution-gate` module is not being built at all; hq issue 108 records why (the seat-holding store does not get a second, public door over the same filesystem).
jschoubben added 1 commit 2026-09-26 14:01:38 +00:00
Proxy configuration beside insecure, not a fifth policy — ADR 0108 closed that set at four, and both
of these tune how a request is carried rather than deciding what a name admits. A registry is the
case that needs it: image layers arrive as single requests of gigabytes and a proxy's own default
refuses them long before the workload is reached.

Absent is no limit, which is what every route already got. A limit that is not a whole positive
number of bytes takes the route with it, named in the log like a port that is not one — serving it
without the limit would carry exactly what the module said not to carry. Enforced on the declared
length where there is one, and while reading for a chunked body, which declares none: without the
second, a limit is advice.
jschoubben merged commit e88d3bd485 into main 2026-09-26 14:01:58 +00:00
jschoubben deleted branch feat/a-route-may-limit-the-body-it-carries 2026-09-26 14:01:58 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#68