sigil-node · rpc_middleware
Source declarations, signatures and documentation for rpc_middleware.
Source: sigil/node/sigil-node/src/rpc_middleware.rs. SHA-256: 8755b619728b188efb35ba9400439c077a6f4127ed3eb8d89099178815076bb8.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
rpc_middleware::RpcProfile
RPC profile — public read-only or full validator.
Default: Validator so existing single-binary deployments are
unchanged. Public-RPC pods set --rpc-profile public explicitly
in 30-rpc-service.yaml.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Default)]
pub enum RpcProfile {
/// Public, read-only profile served at `rpc.sigil.ml`. Rejects
/// validator-internal methods (`sigil_consensus_*`,
/// `sigil_tower_attestation`) with `MethodNotFound`.
Public,
/// Full validator profile — every dispatched method is callable.
#[default]
Validator,
}Source line: 39.
rpc_middleware::RpcProfile::allows
Returns true if the given canonical method name is allowed
to be served on this profile. Methods not in the canonical
table are caller-checked elsewhere.
pub fn allows(self, method: &str) -> bool;Source line: 53.
rpc_middleware::RPC_BODY_LIMIT_BYTES
Application-layer body cap on the JSON-RPC envelope.
4 MiB. The per-method tightening (64 KiB default, 4 MiB only on
sigil_sendTransaction) is enforced inside the handlers in
rpc_server.rs — once the request body has been parsed we know
the method, so we can reject oversized non-write requests with a
JSON-RPC error rather than an HTTP 413.
Why 4 MiB at the envelope: MAX_CODE_SIZE = 2 MiB
(sigil-wasm/engine.rs:11); a contract-deploy sigil_sendTransaction
is MAX_CODE_SIZE plus envelope plus signature, ~2.3 MiB worst case.
Doubling that gives 4 MiB of headroom before the request is
rejected at the HTTP layer.
pub const RPC_BODY_LIMIT_BYTES: usize;Source line: 113.
rpc_middleware::RPC_DEFAULT_REQUEST_LIMIT_BYTES
Default per-request body cap when the method is not
sigil_sendTransaction. Enforced inside handlers, not at the HTTP
layer (which only sees the outer envelope).
pub const RPC_DEFAULT_REQUEST_LIMIT_BYTES: usize;Source line: 118.
rpc_middleware::RPC_BATCH_LIMIT_BYTES
Per-batch envelope cap. Matches the dispatched D4.3 batch size cap (32 requests × 4 MiB / 8 = 16 MiB).
pub const RPC_BATCH_LIMIT_BYTES: usize;Source line: 122.
rpc_middleware::RateLimitConfig
Rate-limit configuration for the public RPC surface.
Defaults reject the dispatched 100/500 (botnet ceiling) per counterargument CA-1; benchmarked against Alchemy 25 req/s, Infura ~10 req/s, QuickNode 25 req/s, Solana public RPC ~4 req/s.
#[derive(Debug, Clone, Copy)]
pub struct RateLimitConfig {
/// Sustained requests per second per IP.
pub per_ip_rps: u32,
/// Burst capacity per IP.
pub per_ip_burst: u32
}Source line: 134.
rpc_middleware::RateLimitConfig::PUBLIC_DEFAULT
Public unauth defaults from CA-1.
pub const PUBLIC_DEFAULT: Self;Source line: 143.
rpc_middleware::RateLimitConfig::VALIDATOR_DEFAULT
Validator profile default — effectively unlimited inside the k8s control plane. Operators can override via env if needed.
pub const VALIDATOR_DEFAULT: Self;Source line: 150.
rpc_middleware::RateLimitConfig::from_env
Resolve from env vars, falling back to the profile default.
pub fn from_env(profile: RpcProfile) -> Self;Source line: 156.
rpc_middleware::RateLimitConfig::replenish_period
Convert requests-per-second into tower-governor's token replenishment period.
tower_governor::GovernorConfigBuilder::per_second(n) means
"add one token every n seconds", not "allow n requests per
second". Keep the env/config model expressed as RPS and convert
explicitly before wiring the layer.
pub fn replenish_period(self) -> Duration;Source line: 182.
rpc_middleware::cors_layer
The hosts allowed to make cross-origin RPC calls.
Replaces tower_http::cors::CorsLayer::permissive(). Configured
via SIGIL_RPC_CORS_ORIGINS env var (comma-separated). When unset,
the public profile uses the canonical Sigil hosts; the validator
profile defaults to permissive because validator-to-validator
traffic is on the cluster's private network anyway.
pub fn cors_layer(profile: RpcProfile) -> tower_http::cors::CorsLayer;Source line: 199.
rpc_middleware::sanitize_error_message
Strip likely-internal substrings from a JSON-RPC error message before it leaves the process.
Heuristic, not a security boundary on its own — handlers must
also be careful what they put in error messages. This is the
last-line defence per docs/launch/agent-05/DESIGN.md §2.4.7.
pub fn sanitize_error_message(message: &str) -> String;Source line: 249.