summaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_NODE_PROTOCOL.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md13
1 files changed, 9 insertions, 4 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 9e51dc9..676b96f 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -102,7 +102,8 @@ Identical on every transport:
| Bound | Value | Where |
|---|---|---|
| Max frame **before** the client's group-key proof | 64 KiB | `PRE_HANDSHAKE_MAX_MSG` |
-| Max frame **after** the proof | 64 MiB | `MAX_MSG` |
+| Max frame **after** the proof | 8 MiB | `MAX_MSG` — eight times the largest message a client sends (a sealed playlist blob, 1 MiB) |
+| Decoding a frame | arrays 100 000, maps 10 000, strings 1 MiB, binaries 8 MiB, no extension types | `UNPACK_LIMITS` |
| File chunk (plaintext) | 1 MiB | `CHUNK_SIZE` |
| Video segment (plaintext, before encryption) | 256 KiB | `STREAM_SEGMENT_SIZE` |
| Upload chunk sent by the browser | 48 KiB | fits the aiortc SCTP limit after msgpack overhead |
@@ -115,6 +116,10 @@ into it, holding that much memory per connection for as long as it liked; a hund
such connections is the node's memory, from peers that have proved nothing. Exceeding
the limit is a hard protocol error and the buffer raises rather than truncating —
truncating would hand a parser a valid-looking prefix of something it never received.
+A frame refused for its size or its decoding ends the session: the buffer still starts
+with it, so nothing after it could be read. The decoding bounds exist because a frame of
+many tiny elements decodes to many times its size in memory; with them, an 8 MiB frame
+costs tens of megabytes at worst.
### 3.3 Versioning field
@@ -245,7 +250,7 @@ answer, and a discriminator of the message's own (`file_id`, `url`, `upload_id`,
v
+-------------------------+
| AUTHENTICATED | `_user_id` / `_group_id` set,
- | full message set | frame limit raised to 64 MiB
+ | full message set | frame limit raised to 8 MiB
+-----------+-------------+
| channel closes
v
@@ -416,7 +421,7 @@ fails if a transport skips a step.
| compare_digest(proof); |
| roster admits the user |
| 9. session authenticated: |
- | frame limit -> 64 MiB, |
+ | frame limit -> 8 MiB, |
| peer registry, audit |
| |
| 10. handshake_ack |
@@ -2422,7 +2427,7 @@ LP(x) = uint32be(len(x)) || x every field, no exceptions
| Device attempts | 5 per connection | ” |
| `MAX_DEVICES_PER_USER` | 5 | `roster.py` |
| `MAX_LINK_INVITES_PER_GROUP` | 20 unredeemed invitation links | `roster.py` |
-| `PRE_HANDSHAKE_MAX_MSG` / `MAX_MSG` | 64 KiB / 64 MiB | `webrtc/core.py` / `webrtc/limits.py` |
+| `PRE_HANDSHAKE_MAX_MSG` / `MAX_MSG` | 64 KiB / 8 MiB | `webrtc/core.py` / `webrtc/limits.py` |
| `CHUNK_SIZE` | 1 MiB | `webrtc/limits.py` |
| `DOWNLOAD_BUFFER_HIGH` | 2 MiB | `webrtc/files.py` |
| `MAX_UPLOAD_BYTES` | 8 GiB, default only — `max_upload_gb` overrides it per node | `webrtc/upload_handlers.py` |