Sigil documentation
ReferenceRust referencesigil-node

sigil-node · rpc_middleware

Source declarations, signatures and documentation for rpc_middleware.

Source: sigil/node/sigil-node/src/rpc_middleware.rs. SHA-256: 8755b619728b188efb35ba9400439c077a6f4127ed3eb8d89099178815076bb8.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

rpc_middleware::RpcProfile

RPC profile — public read-only or full validator.

Default: Validator so existing single-binary deployments are unchanged. Public-RPC pods set --rpc-profile public explicitly in 30-rpc-service.yaml.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Default)]
pub enum RpcProfile {
    /// Public, read-only profile served at `rpc.sigil.ml`. Rejects
    /// validator-internal methods (`sigil_consensus_*`,
    /// `sigil_tower_attestation`) with `MethodNotFound`.
    Public,
    /// Full validator profile — every dispatched method is callable.
    #[default]
    Validator,
}

Source line: 39.

rpc_middleware::RpcProfile::allows

Returns true if the given canonical method name is allowed to be served on this profile. Methods not in the canonical table are caller-checked elsewhere.

pub fn allows(self, method: &str) -> bool;

Source line: 53.

rpc_middleware::RPC_BODY_LIMIT_BYTES

Application-layer body cap on the JSON-RPC envelope.

4 MiB. The per-method tightening (64 KiB default, 4 MiB only on sigil_sendTransaction) is enforced inside the handlers in rpc_server.rs — once the request body has been parsed we know the method, so we can reject oversized non-write requests with a JSON-RPC error rather than an HTTP 413.

Why 4 MiB at the envelope: MAX_CODE_SIZE = 2 MiB (sigil-wasm/engine.rs:11); a contract-deploy sigil_sendTransaction is MAX_CODE_SIZE plus envelope plus signature, ~2.3 MiB worst case. Doubling that gives 4 MiB of headroom before the request is rejected at the HTTP layer.

pub const RPC_BODY_LIMIT_BYTES: usize;

Source line: 113.

rpc_middleware::RPC_DEFAULT_REQUEST_LIMIT_BYTES

Default per-request body cap when the method is not sigil_sendTransaction. Enforced inside handlers, not at the HTTP layer (which only sees the outer envelope).

pub const RPC_DEFAULT_REQUEST_LIMIT_BYTES: usize;

Source line: 118.

rpc_middleware::RPC_BATCH_LIMIT_BYTES

Per-batch envelope cap. Matches the dispatched D4.3 batch size cap (32 requests × 4 MiB / 8 = 16 MiB).

pub const RPC_BATCH_LIMIT_BYTES: usize;

Source line: 122.

rpc_middleware::RateLimitConfig

Rate-limit configuration for the public RPC surface.

Defaults reject the dispatched 100/500 (botnet ceiling) per counterargument CA-1; benchmarked against Alchemy 25 req/s, Infura ~10 req/s, QuickNode 25 req/s, Solana public RPC ~4 req/s.

#[derive(Debug, Clone, Copy)]
pub struct RateLimitConfig {
/// Sustained requests per second per IP.

pub per_ip_rps: u32,
/// Burst capacity per IP.

pub per_ip_burst: u32
}

Source line: 134.

rpc_middleware::RateLimitConfig::PUBLIC_DEFAULT

Public unauth defaults from CA-1.

pub const PUBLIC_DEFAULT: Self;

Source line: 143.

rpc_middleware::RateLimitConfig::VALIDATOR_DEFAULT

Validator profile default — effectively unlimited inside the k8s control plane. Operators can override via env if needed.

pub const VALIDATOR_DEFAULT: Self;

Source line: 150.

rpc_middleware::RateLimitConfig::from_env

Resolve from env vars, falling back to the profile default.

pub fn from_env(profile: RpcProfile) -> Self;

Source line: 156.

rpc_middleware::RateLimitConfig::replenish_period

Convert requests-per-second into tower-governor's token replenishment period.

tower_governor::GovernorConfigBuilder::per_second(n) means "add one token every n seconds", not "allow n requests per second". Keep the env/config model expressed as RPS and convert explicitly before wiring the layer.

pub fn replenish_period(self) -> Duration;

Source line: 182.

rpc_middleware::cors_layer

The hosts allowed to make cross-origin RPC calls.

Replaces tower_http::cors::CorsLayer::permissive(). Configured via SIGIL_RPC_CORS_ORIGINS env var (comma-separated). When unset, the public profile uses the canonical Sigil hosts; the validator profile defaults to permissive because validator-to-validator traffic is on the cluster's private network anyway.

pub fn cors_layer(profile: RpcProfile) -> tower_http::cors::CorsLayer;

Source line: 199.

rpc_middleware::sanitize_error_message

Strip likely-internal substrings from a JSON-RPC error message before it leaves the process.

Heuristic, not a security boundary on its own — handlers must also be careful what they put in error messages. This is the last-line defence per docs/launch/agent-05/DESIGN.md §2.4.7.

pub fn sanitize_error_message(message: &str) -> String;

Source line: 249.

On this page