Skip to content

wasi-http: limit size of strings used to describe Request's non-headers,body parts - #14598

Open
pchickey wants to merge 1 commit into
bytecodealliance:mainfrom
pchickey:pch/wasi_http_string_limit
Open

pchickey wants to merge 1 commit into
bytecodealliance:mainfrom
pchickey:pch/wasi_http_string_limit

Conversation

@pchickey

@pchickey pchickey commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is motivated by string fields in wasip2 outgoing-request and waspi3 request resources - specifically, the scheme (via the other variant), method (other variant), authority, and path_and_query, being able to use a host allocation of up to hostcall-fuel (128M by default) size strings.

This PR limits the sum those by default to 16k per request, which I picked a reasonable limit given that many http implementations limit the sum of all of these strings plus the headers anywhere from 8k (akamai), 32k (nginx), to 128k (fastly, cloudflare). The limit is tunable in the construction of WasiHttpCtx, the C API, and the wasmtime cli (with -Smax-http-request-strings-size=).

The limits apply to all requests that come off the wire, as well as those manipulated by the guest, so that we keep the invariant that the guest can proxy (forward) any request it is given. Requests that come off the wire exceeding the limit get rejected with 400 BAD_REQUEST. Along the way, the validation of the host header was made stricter when the request doesn't already have an authority - it now must parse as an http::uri::Authority. These changes may end up causing embeddings to reject some requests they previously accepted, but they should be able to tweak the limit to continue accepting any valid requests.

New tests demonstrate this new limit on wasip2 and wasip3. There are some incidental changes to the crate's public api for wasip3, and wasip2's HostOutgoingRequest can no longer be constructed outside the crate through the struct fields, but that one didn't strike me as an intentional aspect of the public API. If there are embedder depending on that, we can make all of the new machinery validation machinery pub, but I chose to keep it as an internal implementation detail.

Also, this PR noticed that the http fields size limit wasn't settable in the C API, so that setting was added as well.

@pchickey
pchickey requested review from a team as code owners October 6, 2026 23:25
@pchickey
pchickey requested review from alexcrichton and rvolosatovs and removed request for a team October 6, 2026 23:25
This PR is motivated by string fields in wasip2 `outgoing-request` and waspi3 `request` resources - specifically, the `scheme` (via the `other` variant), `method` (`other` variant), `authority`, and `path_and_query`, being able to use a host allocation of up to `hostcall-fuel` (128M by default) size strings.

This PR limits the sum those by default to 16k per request, which I picked a reasonable limit given that many http implementations limit the sum of all of these strings plus the headers anywhere from 8k (akamai), 32k (nginx), to 128k (fastly, cloudflare). The limit is tunable in the construction of `WasiHttpCtx`, the C API, and the wasmtime cli (with `-Smax-http-request-strings-size=`).

The limits apply to all requests that come off the wire, as well as those manipulated by the guest, so that we keep the invariant that the guest can proxy (forward) any request it is given. Requests that come off the wire exceeding the limit get rejected with 400 BAD_REQUEST. Along the way, the validation of the host header was made stricter when the request doesn't already have an authority - it now must parse as an `http::uri::Authority`. These changes may end up causing embeddings to reject some requests they previously accepted, but they should be able to tweak the limit to continue accepting any valid requests.

New tests demonstrate this new limit on wasip2 and wasip3. There are some incidental changes to the crate's public api for wasip3, and wasip2's HostOutgoingRequest can no longer be constructed outside the crate through the struct fields, but that one didn't strike me as an intentional aspect of the public API. If there are embedder depending on that, we can make all of the new machinery validation machinery pub, but I chose to keep it as an internal implementation detail.

Also, this PR noticed that the http fields size limit wasn't settable in the C API, so that setting was added as well.
@pchickey
pchickey force-pushed the pch/wasi_http_string_limit branch from f6d2556 to 6724c40 Compare October 6, 2026 23:42
@github-actions github-actions Bot added the wasmtime:c-api Issues pertaining to the C API. label Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

wasmtime:c-api Issues pertaining to the C API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant