Repository navigation
Bound the metrics response body size - #305
Open
benthecarman wants to merge 1 commit into
Open
benthecarman wants to merge 1 commit into
benthecarman wants to merge 1 commit into
Conversation
get_metrics_with_auth read the whole metrics response with no size limit, so a malicious or impersonated server could send an endless body and run the client out of memory. The extra to_vec() copy also doubled peak memory. Cap the metrics body at 10 MiB. The response is rejected early if its Content-Length is too large, and the read stops as soon as the streamed total goes over the cap. The collected bytes are decoded as UTF-8 without another copy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
I've assigned @TheBlueMatt as a reviewer! |
Anyitechs
reviewed
Oct 7, 2026
Anyitechs
left a comment
Contributor
There was a problem hiding this comment.
Looks good, thank you!
| // constrained by this limit. | ||
| const MAX_GRPC_STREAM_MESSAGE_LEN: usize = 4 * 1024 * 1024; | ||
|
|
||
| // Applies to the complete Prometheus metrics response body. |
Contributor
There was a problem hiding this comment.
Should we update the docs for this as well? Prometheus exposes a body_size_limit field in the config file that users can use to limit the number of bytes acceptable in the response body per scrape. Given that this change supersedes that, I believe it's worth documenting.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
get_metrics_with_authread the full metrics response withresponse.bytes()and no size limit, so a malicious or impersonated server could exhaust client memory with an endless body. The extrato_vec()copy also doubled peak memory.This caps the metrics body at 10 MiB, matching the unary gRPC limit. The response is rejected early if its
Content-Lengthis over the cap, and the chunked read stops as soon as the running total goes over it. The collected bytes are decoded withString::from_utf8without another copy.Found by Project Loupe