fix(http): count batch orders without copying or over-reading the body - #67
Merged
Merged
Conversation
Reddimus
added a commit
that referenced
this pull request
Sep 25, 2026
## Summary Releases 0.6.2: sets the CMake version, moves the `[Unreleased]` notes into a `[0.6.2]` section, adds its compare links, and points the README's FetchContent example at `v0.6.2`. 0.6.2 contains #65 (allocation and instruction counters in the benchmarks, with realistic fixtures), #67 (`RateLimitedTransport` stays inside the batch body and no longer copies each order: 26 allocations down to 6 for 20 orders), and #68 (SIGPIPE protection, macOS build fixes, and the shorter README). No public API changes. After this merges, tagging `v0.6.2` on the merge commit runs `release.yml`. It checks the tag against the CMake version and the CHANGELOG section, waits for CI on that commit, publishes the release, and dispatches the API reference deploy to GitHub Pages. ## Checks - [x] `tools/project_version.sh` prints 0.6.2 - [x] `release.yml`'s extraction of the `[0.6.2]` section yields the notes - [x] `make lint-docs` and `./tools/test_consumers.sh` pass - [x] SemVer impact: this is the 0.6.2 patch release
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RateLimitedTransportcounts a batch's orders by reading the request body as JSON, and it read past the end of that body. It used Glaze's default options, which assume a null terminator follows the text, on astd::string_viewthat promises no such thing. A view over the start of a longer buffer was counted from the bytes after it, and a truncated body at the end of its buffer was read one byte beyond it. Counting also copied every order into a string just to count it.std::vector<glz::skip>withnull_terminated = false, so it stays inside the view and stores nothing per order. This works with Glaze 8.3 and 9.0.RateLimitedTransport::cost()andrequest()both change; nothing else does.Closes #66
Benchmarks
BM_RateLimitCost/20counts a 20-order batch. Main (15ff8ca) against this branch; heap counts are exact, and instructions come from the suite's macOS counter, which varies by well under 1% between runs even on a loaded machine.BM_SerializeBatchCreateand every other benchmark are unchanged. This runs once per batch order request, before it goes out.Checks
make format lint test(macOS, 284/284)make sanitize(macOS, 275/275) and./tools/test_consumers.sh-DKALSHI_WARNINGS_AS_ERRORS=ON -DKALSHI_BUILD_BENCHMARKS=ON: 284/284 and the benchmark smoke run.make tidywith clang 18 and libc++ is clean.CountsOnlyTheBodyItIsGiven(a prefix view counts 2 orders on main),CountsBatchItemsWithoutReadingPastTheBody(ASan catches the one-byte over-read), andAllocationBudget.CountingABatchDoesNotCopyItsOrders(26 against 6 allocations).CountsBatchItemsWhateverTheyContaincovers quotes, brackets, and nesting inside orders.{"orders":[1 2,3]}now count their elements instead of falling back to one.CHANGELOG.mdupdated under[Unreleased]