pchickey opened PR #14598 from pchickey:pch/wasi_http_string_limit to bytecodealliance:main.
pchickey requested rvolosatovs for a review on PR #14598.
pchickey requested wasmtime-wasi-reviewers for a review on PR #14598.
pchickey requested alexcrichton for a review on PR #14598.
pchickey requested wasmtime-core-reviewers for a review on PR #14598.
pchickey edited PR #14598:
This PR is motivated by string fields in wasip2
outgoing-requestand waspi3requestresources - specifically, thescheme(via theothervariant),method(othervariant),authority, andpath_and_query, being able to use a host allocation of up tohostcall-fuel(128M by default) size strings.This PR limits the sum those by default to 16k per request, which I picked a reasonable limit given that many http implementations limit the sum of all of these strings plus the headers anywhere from 8k (akamai), 32k (nginx), to 128k (fastly, cloudflare). The limit is tunable in the construction of
WasiHttpCtx, the C API, and the wasmtime cli (with-Smax-http-request-strings-size=).Also, this PR noticed that the http fields size limit wasn't settable in the C API, so that setting was added as well.
pchickey edited PR #14598:
This PR is motivated by string fields in wasip2
outgoing-requestand waspi3requestresources - specifically, thescheme(via theothervariant),method(othervariant),authority, andpath_and_query, being able to use a host allocation of up tohostcall-fuel(128M by default) size strings.This PR limits the sum those by default to 16k per request, which I picked a reasonable limit given that many http implementations limit the sum of all of these strings plus the headers anywhere from 8k (akamai), 32k (nginx), to 128k (fastly, cloudflare). The limit is tunable in the construction of
WasiHttpCtx, the C API, and the wasmtime cli (with-Smax-http-request-strings-size=).The limits apply to all requests that come off the wire, as well as those manipulated by the guest, so that we keep the invariant that the guest can proxy (forward) any request it is given. Requests that come off the wire exceeding the limit get rejected with 400 BAD_REQUEST. Along the way, the validation of the host header was made stricter when the request doesn't already have an authority - it now must parse as an
http::uri::Authority. These changes may end up causing embeddings to reject some requests they previously accepted, but they should be able to tweak the limit to continue accepting any valid requests.New tests demonstrate this new limit on wasip2 and wasip3. There are some incidental changes to the crate's public api for wasip3, and wasip2's HostOutgoingRequest can no longer be constructed outside the crate through the struct fields, but that one didn't strike me as an intentional aspect of the public API. If there are embedder depending on that, we can make all of the new machinery validation machinery pub, but I chose to keep it as an internal implementation detail.
Also, this PR noticed that the http fields size limit wasn't settable in the C API, so that setting was added as well.
pchickey updated PR #14598.
github-actions[bot] added the label wasmtime:c-api on PR #14598.
Last updated: Oct 11 2026 at 04:10 UTC