chore: low-severity sweep — import session cap, full compile-error lists, leaf-name-fallback validation warning
#05-T24. Three low-severity cleanups, each TDD'd: - TransportOptions.MaxConcurrentImportSessions (8): BundleSessionStore.Open rejects a new session past the cap (evicting expired entries first), bounding the N×~200 MB decrypted-content footprint. Soft cap (count/add not atomic). - ScriptCompiler.TryCompile now joins ALL forbidden-API violations / compile errors (string.Join instead of [0]) so an operator sees every problem at once; the T15 verdict cache stores the joined string. - SemanticValidator emits an advisory warning when a CallScript target resolves ONLY via the composed leaf-name fallback (dynamic child path, not statically verified) instead of silently accepting it. Claude-Session: https://claude.ai/code/session_01MtdgwpEeCUn6cUA5f1LMPj
This commit is contained in:
@@ -28,6 +28,13 @@ public sealed class TransportOptions
|
||||
/// generous headroom for unusually compressible bundles.
|
||||
/// </summary>
|
||||
public int MaxBundleEntryCompressionRatio { get; set; } = 50;
|
||||
/// <summary>
|
||||
/// #05-T24: maximum number of concurrently-open import sessions. Each open
|
||||
/// session pins a fully-decrypted bundle (up to <see cref="MaxBundleSizeMb"/>
|
||||
/// of plaintext) in memory until it expires or is applied/cancelled, so this
|
||||
/// bounds the N×~200 MB decrypted-content footprint the central node can hold.
|
||||
/// </summary>
|
||||
public int MaxConcurrentImportSessions { get; set; } = 8;
|
||||
/// <summary>Gets or sets the maximum number of failed passphrase unlock attempts before a session is locked.</summary>
|
||||
public int MaxUnlockAttemptsPerSession { get; set; } = 3;
|
||||
/// <summary>Gets or sets the maximum number of unlock attempts allowed per IP address per hour.</summary>
|
||||
|
||||
Reference in New Issue
Block a user