Skip to main content

Module memory_limit

Module memory_limit 

Source
Expand description

Middleware for limiting total memory usage of concurrent HTTP request bodies.

Admission works in two stages:

  1. Upfront, the request’s Content-Length (if present) is charged to the shared ServerMemoryLimiter, preserving the configured wait/fail policy for regular requests.
  2. While the body is streamed, AccountedBody charges every byte beyond the upfront reservation. This closes two gaps of a header-only reservation: HTTP/1.1 chunked requests carry no Content-Length (and would otherwise be admitted for free), and a client can understate the header while sending a much larger body.

Permits acquired while streaming are held by BodyMemoryAccounting, which is also inserted into the request extensions so they stay alive until the whole request is finished (extractors collect the body into owned buffers that outlive the body stream itself).

StructsΒ§

AccountedBody πŸ”’
A request body wrapper that charges the shared limiter for every byte streamed beyond pre_charged (the upfront Content-Length reservation).
BodyMemoryAccounting πŸ”’
Holds the memory guards acquired while a request body is streamed. Shared between the AccountedBody wrapper, the request extensions and the middleware itself, so the permits are only released when the request (including any collected body buffers and the handler still using them) is finished.
ContentEncoded πŸ”’
Marker inserted by memory_limit_middleware when the request arrives with a non-identity Content-Encoding header. Route-local decoded_body_accounting_middleware uses it to account the decompressed body: only such requests expand during request decompression.

EnumsΒ§

ChargeOutcome πŸ”’

FunctionsΒ§

decoded_body_accounting_middleware πŸ”’
Route-local counterpart of memory_limit_middleware for routes that install RequestDecompressionLayer: it must be layered inside the decompression layer, so the body it wraps is the decompressed stream.
limit_exceeded_error πŸ”’
memory_limit_middleware
quota_exceeded_response πŸ”’
Rewrites the response of a request whose body accounting hit the quota: the failure aborts the body mid-stream, so the extractors reject the request with a generic body error (mapped to 400). Quota exhaustion must surface as 429, matching the upfront admission path, so clients can tell backpressure apart from malformed input.

Type AliasesΒ§

AcquireFuture πŸ”’