Skip to content

Lift the request body limit on the transfer route so large pushes go through [patch] - #101

Merged
matt-edmondson merged 1 commit into
mainfrom
fix/92-lift-upload-body-limit
Oct 9, 2026
Merged

matt-edmondson merged 1 commit into
mainfrom
fix/92-lift-upload-body-limit

Conversation

@matt-edmondson

Copy link
Copy Markdown
Contributor

Fixes #92

What was wrong

Kestrel refuses request bodies over 30,000,000 bytes by default, and nothing in the library or the tool's host lifted that limit. Every PUT of an LFS object larger than about 28.6 MB failed part way through the upstream relay. Because the refusal happened inside HttpClient's content copy, the client saw a 500 instead of a 413.

Change

  • ObjectRouteHandler.UploadAsync sets IHttpMaxRequestBodySizeFeature.MaxRequestBodySize = null when the feature is present and not read-only. This happens in the library, so every host is covered.
  • The limit is lifted only after the upload token has been checked. A request without a valid token never gets an unbounded body, and batch and locks/batch bodies keep the server's bound.

Tests

TestServer doesn't enforce Kestrel's limit, so the new tests install a stand-in IHttpMaxRequestBodySizeFeature on the request context, as the issue suggests:

  • Upload_LiftsTheServersRequestBodyLimit: the upload succeeds, is relayed upstream, and leaves the limit at null. With the fix reverted this test fails with Expected value to be null.
  • Batch_KeepsTheServersRequestBodyLimit: a batch POST leaves the 30,000,000 bound in place.

The full suite passes locally: 356 tests, 0 failed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Md2Tr7FWcbqPdwq2BjeG79


Generated by Claude Code

…through [patch]

Kestrel refuses request bodies over 30,000,000 bytes by default, and nothing
lifted that for uploads. Every PUT of an LFS object larger than ~28.6 MB
failed part way through the upstream relay and surfaced as a 500.

UploadAsync now clears IHttpMaxRequestBodySizeFeature.MaxRequestBodySize once
the upload token has been checked, so every host is covered while batch and
lock bodies keep the server's bound.

Fixes #92

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Md2Tr7FWcbqPdwq2BjeG79
@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pushing any LFS object larger than ~28.6 MB through the proxy fails with 500: Kestrel's default 30,000,000-byte request body limit is never lifted

2 participants