fix(govern): cap data document size

What

Caps the data_json document at 1 MiB (MAX_DATA_BYTES, mirroring MAX_INPUT_BYTES) in both evaluation paths.

Why

input_json is capped at 1 MiB and policy_rego at 64 KiB, but the data document had no size bound anywhere: a caller could send an arbitrarily large payload that the batch path fully parsed up front. Split out of !133 (merged) per review, to keep that MR focused on the trigger-keyed lookup. Part of gitlab-org/gitlab#607650.

Changes

  • glaz-govern — MAX_DATA_BYTES (1 MiB) enforced in the per-policy evaluator and in the batch's up-front data validation; new caller-error variant GovernError::DataTooLarge { actual, max }, reaching hosts as GlazError::InvalidArgument through the existing catch-all mapping (the glaz-module diff is a test pinning that end-to-end, plus doc updates — no behavior change there).
  • glaz-proto — the data_json comment documents the cap.

Out of scope / unchanged

  • The up-front data validation (non-object → InvalidData, whole-call, type-summarized error) — that is part of !133 (merged)'s batch error contract, not size limiting.

Testing

  • cargo test --workspace passes (228 on the rebased main base; 3 new: oversized data via the per-policy path → DataTooLarge, via a batch → whole-call error, via FFI bytes → InvalidArgument)
  • cargo clippy --workspace --all-targets is clean
  • cargo fmt --all --check is clean

Author checklist

  • Title follows Conventional Commits and breaking changes are flagged (tightens a pre-release, unconsumed surface: data_json was previously unbounded)
  • Docs / comments updated where behaviour changed
  • No unrelated changes swept in
Edited by Artur Fedorov

Merge request reports

Loading
Loading