Skip to content

Fix full-size authenticated HTTP binary requests - #653

Merged
ty-everett merged 2 commits into
mainfrom
codex/authfetch-http-payload-budget-20260927
Sep 27, 2026
Merged

ty-everett merged 2 commits into
mainfrom
codex/authfetch-http-payload-budget-20260927

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

AuthFetch rejects a valid 4 MiB CHIRP chunk before HTTP dispatch because the generic authentication envelope charges each binary byte as four JSON characters. This patch gives its Peer a finite binary-byte payload budget matching the HTTP request and configured response capacity. The real authenticated CHIRP upload test now covers both non-text bytes and a complete chunk, including exact bytes, object hashes, caller identity and root commit.

Program and scope

  • Tracker: BotBoard #644.
  • SDK patch candidate: @bsv/sdk 2.8.9. CHIRP's test changes are excluded from its published artifact, so its version remains 0.1.3.
  • Custom Peer transports retain their existing default policy. HTTP framing remains capped at 16 MiB; configured response, handshake, certificate, signature, nonce and redirect checks remain enforced.
  • No public API, encoding, persistence or dependency graph change. Publication and deployment remain separate protected operations.
  • Local reviewed head: 6eb34251bf5b31c1d990ea181b8433e0a8361080.

Verification

Hosted final-head runs: CI, CodeQL, Conformance.

Commands include pnpm health:check, pnpm lint, pnpm format:check, pnpm build, pnpm typecheck, pnpm audit:security, SDK test:coverage, pack:check, test:browser, CHIRP authenticated tests and package/browser checks, pnpm test:mutation --target sdk-auth-http, documentation examples, test governance, conformance, and protected-artifact staging/verification/publication dry run.

  • Root frozen install, health, lint, formatting, all workspace builds, typecheck and high/critical audit pass; audit has zero known vulnerabilities.
  • Node 24 SDK coverage: 212 suites / 7,513 tests pass; 94.29% statements, 88.01% branches, 96.06% functions, 95.43% lines.
  • Node 22 full SDK: 212 suites / 7,513 tests pass (all 212 governed deterministic test files under the source root). Node 22 SDK authentication: 22 suites / 461 tests pass. Actual authenticated CHIRP small/full-chunk tests pass on Node 22 and 24; the full-chunk test fails before this fix.
  • CHIRP coverage: 10 suites / 150 tests pass. SDK and CHIRP exact-tarball browser and clean-consumer checks pass, with existing bundle ceilings unchanged.
  • Authentication mutation: 323 mutants, 88.54% (238 killed, 48 timed out, 37 survived); zero uncovered/invalid mutants. Required 80% threshold unchanged.
  • All 6,700 conformance vectors pass; 8 documentation examples compile against 21 exact package tarballs. Test governance passes.
  • Node 24.18 release artifact staging, CycloneDX verification and publication dry run pass for exactly SDK 2.8.9. No npm publication was performed from the workstation.
  • New transport regression rejects a framed request above 16 MiB before HTTP dispatch. Peer construction tests cover a small response limit, the default limit plus frame overhead, and safe-integer clamping. Existing request/response framing and authentication negative tests remain.

Security, release and completion

  • Complete diff reviewed for trust boundaries, compatibility, artifacts, dependencies, documentation and operations.
  • Version, changelog, migration notes and owning generated facts updated. Only version metadata changed in the health baseline; findings and thresholds are unchanged.
  • No new override, advisory dismissal, suppression, exception or skipped test.
  • All 40 hosted checks are terminal and successful or validated scope skips on the exact head; merge gate passes.
  • Both exact-source CodeQL categories have zero results and zero open alerts; Sonar reports zero new findings and unreviewed hotspots.
  • Qualified maintainer review accepted the complete exact-head diff; zero open review conversations.

Protected SDK publication must complete before the separate UHRP service binary-parser fix pins this release and exercises its full chunk boundary in frozen service installs. Existing open PR #569 changes payment preparation elsewhere in AuthFetch and does not change this Peer construction; its branch and ownership are preserved.

@codecov

codecov Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Qualified maintainer review accepted exact head 6eb34251bf5b31c1d990ea181b8433e0a8361080: 40 terminal successful or governed-skip checks, exact-head zero new Sonar findings/unreviewed hotspots and zero CodeQL alerts; no open review threads. Complete diff reviewed: finite binary-byte Peer capacity matches existing HTTP request and configured response framing, with safe-integer clamping and small-response request compatibility. Custom Peer defaults, public declarations, signatures, nonce/certificate/handshake bounds, redirect policy, wire encodings and persistence remain unchanged. Synthetic real authenticated CHIRP consumer tests exercise non-text bytes and complete 4 MiB chunks with exact bytes, caller identity, object hashes and root commit. Oversized HTTP frames still reject before dispatch. Only SDK published bytes change, requiring 2.8.9; the CHIRP test is excluded from its artifact. Existing dependency graph, security findings/thresholds/overrides and test classifications are unchanged. Node22/24, coverage, governed mutation, conformance, exact-tarball consumers/browser and documentation checks accepted. Protected publication and full live acceptance remain separate prerequisites.

@ty-everett
ty-everett marked this pull request as ready for review September 27, 2026 05:34
@ty-everett
ty-everett merged commit d4cf902 into main Sep 27, 2026
40 checks passed
@ty-everett
ty-everett deleted the codex/authfetch-http-payload-budget-20260927 branch September 27, 2026 05:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant