A route says the largest body its proxy may carry, and both proxies honour it #48
Closed
jschoubben
wants to merge 2 commits from
feat/registry-public-route into main
pull from: feat/registry-public-route
merge into: :main
:main
:fix/an-older-merge-does-not-move-a-source
:fix/a-mirrored-base-is-not-pulled-twice
:fix/a-module-hears-what-it-consumes
:fix/the-controller-may-ask-a-tool
:fix/a-module-serves-its-own-namespace
:fix/the-check-dials-as-the-mesh-does
:fix/an-edge-is-recorded-by-path
:feat/build-edges-are-recorded
:feat/one-bus
:fix/the-controller-follows-what-it-decodes
:feat/a-merge-on-the-forge-builds-what-it-moved
:feat/rollout-hand
:fix/store-seats-keep-their-protocol
:feat/the-build-machine-takes-work-on-nats
:fix/a-principal-may-hear-its-consumer
:fix/the-bus-account-has-jetstream
:fix/the-controller-pins-the-bus-certificate
:feat/the-controller-serves-on-nats
:fix/a-node-may-bind-its-consumer
:fix/mint-leaves-the-control-planes-old-secret-alone
:fix/the-controller-mounts-its-bus-secret
:fix/the-network-map-knows-the-holders
:fix/mint-bare-host-and-again
:fix/mint-finds-the-bus-on-the-hub
:switch/the-controller-speaks-nats
:feat/the-move-mints-and-delivers
:fix/seat-usage-lines
:fix/record-the-standing-holder
:feat/amqp-is-not-a-provision
:feat/seat-handover
:fix/rollout-retires-the-old-broker
:fix/the-store-owns-the-seat-set
:fix/go-126-base
:feat/nats-genesis
:fix/a-taken-tunnel-brings-its-port
2
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
b48572bdfc |
A null body limit is refused, not read as no limit; the gate on the wrong machine is refused
Review of the registry hand-over. The proxy's bodyLimit treated an absent key and a JSON null alike, so a `max-request-body: null` was served unlimited here while the adapter skipped it and the catalogue refused it — one provider carrying what the others refuse. Presence is now checked before the value is read. The catalogue-backed test asserted the gate pulling the store in beside it as the feature. It was the fault: a node-scoped requirement with one candidate installs that candidate, so a gate assigned to a machine without the store raised a second, empty one there behind the real credentials and the public name. The store's seat is one per mesh now (mesh-catalog), and the test asserts the refusal by name. Delete is asserted only behind the lock. hq ADR 0082/0104, the registry hand-over. |
||
|
|
01d57b629f |
A route says the largest body its proxy may carry, and both proxies honour it
The registry's public name is served by the predecessor with a twenty-gigabyte buffering middleware, because a registry takes image layers in single requests of gigabytes and a proxy's default turns every push into a 413 the registry never sees. A route contribution had no way to say so, so the mesh could not take the name over without losing what made it usable. The contribution now carries `max-request-body`, a whole positive number of bytes, and the catalogue holds every route to an agreed vocabulary — label or name, port, and the limit — refusing a key no proxy reads (a field that parses cleanly and does nothing is a promise nobody keeps) and a route with no port (unreachable by the proxy it just asked for, found at parse time rather than in a proxy's log). The mesh's own proxy reads the limit as written, refuses a body past it as 413 rather than the 502 the transport would have reported, and skips a route whose limit it cannot read rather than carrying what the module said not to. The registry's hand-over itself is read from the catalogue beside this checkout: the store still resolves with no proxy, the gate beside it pulls the store in, contributes the predecessor's name on the port the node gave it, and locks only the door that faces the world. hq ADR 0082/0104, the registry hand-over. |