Loading
fix(govern): cap data document size
What
Caps the data_json document at 1 MiB (MAX_DATA_BYTES, mirroring MAX_INPUT_BYTES) in both evaluation paths.
Why
input_json is capped at 1 MiB and policy_rego at 64 KiB, but the data document had no size bound anywhere: a caller could send an arbitrarily large payload that the batch path fully parsed up front. Split out of !133 (merged) per review, to keep that MR focused on the trigger-keyed lookup. Part of gitlab-org/gitlab#607650.
Changes
glaz-govern—MAX_DATA_BYTES(1 MiB) enforced in the per-policy evaluator and in the batch's up-front data validation; new caller-error variantGovernError::DataTooLarge { actual, max }, reaching hosts asGlazError::InvalidArgumentthrough the existing catch-all mapping (the glaz-module diff is a test pinning that end-to-end, plus doc updates — no behavior change there).glaz-proto— thedata_jsoncomment documents the cap.
Out of scope / unchanged
- The up-front data validation (non-object →
InvalidData, whole-call, type-summarized error) — that is part of !133 (merged)'s batch error contract, not size limiting.
Testing
-
cargo test --workspacepasses (228 on the rebased main base; 3 new: oversized data via the per-policy path →DataTooLarge, via a batch → whole-call error, via FFI bytes →InvalidArgument) -
cargo clippy --workspace --all-targetsis clean -
cargo fmt --all --checkis clean
Author checklist
- Title follows Conventional Commits and breaking changes are flagged (tightens a pre-release, unconsumed surface:
data_jsonwas previously unbounded) - Docs / comments updated where behaviour changed
- No unrelated changes swept in
Edited by Artur Fedorov