Repository navigation
rtc: measure data blob keys by their content, not their text form - #4923
Merged
Merged
Conversation
boks1971
approved these changes
Sep 29, 2026
boks1971
left a comment
Contributor
There was a problem hiding this comment.
Thank you very much for these submissions.
But, please note that these cannot be merged without you signing the CLA.
Contributor
Author
|
Much obliged! I have signed accordingly. |
eleboucher
pushed a commit
to eleboucher/homelab
that referenced
this pull request
Oct 7, 2026
…7 ➔ v1.13.8) (#2275) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [docker.io/livekit/livekit-server](https://github.com/livekit/livekit) | patch | `v1.13.7` → `v1.13.8` | --- ### Release Notes <details> <summary>livekit/livekit (docker.io/livekit/livekit-server)</summary> ### [`v1.13.8`](https://github.com/livekit/livekit/releases/tag/v1.13.8) [Compare Source](livekit/livekit@v1.13.7...v1.13.8) ##### Added - agent: HTTP endpoints data plane ([#​4779](livekit/livekit#4779)) - use sender report pass through setting to forward abs-capture-time verbatim ([#​4812](livekit/livekit#4812)) - Add sdk lable to session start time and participant join ([#​4885](livekit/livekit#4885)) - Add a local participant method to get recently disconnected ([#​4911](livekit/livekit#4911)) - service: start room composite egress configured in a room preset ([#​4926](livekit/livekit#4926)) ##### Changed - Update github workflows ([#​4446](livekit/livekit#4446)) - Reduce descriptor marshal allocations on Go 1.26.4/linux-amd64 ([#​4681](livekit/livekit#4681)) - config: reject unknown send\_side\_bwe\_pacer, warn on unwired fallback ([#​4804](livekit/livekit#4804)) - Update github.com/livekit/protocol digest to [`a879e94`](livekit/livekit@a879e94) ([#​4864](livekit/livekit#4864)) - Update module github.com/gotesttools/gotestfmt/v2 to v2.5.0 ([#​4865](livekit/livekit#4865)) - Update module github.com/urfave/cli/v3 to v3.11.0 ([#​4867](livekit/livekit#4867)) - Update module golang.org/x/mod to v0.41.0 ([#​4868](livekit/livekit#4868)) - sfu: return VP8 munged header by value to avoid per-packet allocation ([#​4871](livekit/livekit#4871)) - sfu: patch pacer header extensions without per-packet allocation ([#​4872](livekit/livekit#4872)) - Update pion/sdp to get lesser SDP retention ([#​4873](livekit/livekit#4873)) - sfu: skip pacer allocation assertion under the race detector ([#​4874](livekit/livekit#4874)) - sfu: broadcast RTP to down tracks without per-packet allocations ([#​4875](livekit/livekit#4875)) - Track action versions and stop quarantining our own actions ([#​4877](livekit/livekit#4877)) - test: fix two data races in the test suites ([#​4878](livekit/livekit#4878)) - Bump go.opentelemetry.io/otel/sdk ([#​4879](livekit/livekit#4879)) - deps: update psrpc to v0.8.0 ([#​4882](livekit/livekit#4882)) - Update module github.com/moby/moby/client to v0.6.0 ([#​4883](livekit/livekit#4883)) - Update module golang.org/x/sync to v0.23.0 ([#​4884](livekit/livekit#4884)) - Propagate SIP\_TRUNK\_FAILURE ([#​4890](livekit/livekit#4890)) - ccutils: use millisecond resolution for probe interval backoff ([#​4891](livekit/livekit#4891)) - Increase receiver loadbalance threshold when batch io enabled ([#​4899](livekit/livekit#4899)) - rtc: parse each remote offer once per negotiation ([#​4904](livekit/livekit#4904)) - Bump protocol ([#​4909](livekit/livekit#4909)) - rtc: split EndSession out of MoveToRoom ([#​4917](livekit/livekit#4917)) - telemetry: drop the stats worker re-key path ([#​4918](livekit/livekit#4918)) - sfu: report forwarding latency as p90 instead of the mean ([#​4920](livekit/livekit#4920)) - rtc: accept ICE Completed in ICE-restart connect assertions ([#​4921](livekit/livekit#4921)) - rtc: measure data blob keys by their content, not their text form ([#​4923](livekit/livekit#4923)) - Remove deprecatred way of setting prometheus from the config file ([#​4928](livekit/livekit#4928)) - test: give mock participants a connection quality, close test rooms ([#​4933](livekit/livekit#4933)) - update warp dep ([#​4943](livekit/livekit#4943)) ##### Fixed - Do not add down tracks after receiver close ([#​4857](livekit/livekit#4857)) - Do not request media sections for transceivers that cannot send ([#​4892](livekit/livekit#4892)) - Deregister agent job when the server terminates it ([#​4893](livekit/livekit#4893)) - sfu: don't hold bindLock across the blank-frame flush in CloseWithFlush ([#​4895](livekit/livekit#4895)) - dynacast: re-send subscribed qualities after every publisher answer ([#​4907](livekit/livekit#4907)) - agent: release JobTerminate handler when job ends before registration ([#​4908](livekit/livekit#4908)) - Report disconnected for older disconnected participants. ([#​4910](livekit/livekit#4910)) - rtc: record a room's departure when the participant leaves it ([#​4913](livekit/livekit#4913)) - update deps to fix warp issue ([#​4916](livekit/livekit#4916)) - sfu: fix data stats active window bitrate and duration units ([#​4922](livekit/livekit#4922)) - fix: reject instead of drop for no dispatch rule ([#​4927](livekit/livekit#4927)) - fix: skip RTX/FEC when picking a fallback video codec ([#​4930](livekit/livekit#4930)) - fix: do not read invalid delta ([#​4935](livekit/livekit#4935)) - fix: use the fast debounce for the first negotiation ([#​4936](livekit/livekit#4936)) - fix: skip DTLS HelloVerifyRequest ([#​4937](livekit/livekit#4937)) - config: parse generated duration flags as durations ([#​4939](livekit/livekit#4939)) - fix: use the most common recent packet rate in connection quality ([#​4940](livekit/livekit#4940)) - fix: copy RED history packets instead of keeping pointers ([#​4941](livekit/livekit#4941)) - fix: keep one subscription when first subscribes race ([#​4944](livekit/livekit#4944)) - bump protocol to get unlock on no key fix ([#​4945](livekit/livekit#4945)) - fix: count leftover upstream loss after RTX repairs ([#​4946](livekit/livekit#4946)) - fix: switch VP8 temporal layer up only at a layer sync frame ([#​4947](livekit/livekit#4947)) - fix: reconcile everything when the reconcile queue overflows ([#​4948](livekit/livekit#4948)) - fix: enable H.264 publish for desktop Linux Firefox ([#​4949](livekit/livekit#4949)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/2275
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes data blob key validation and size accounting, which measured the text form of the key message instead of the key itself.
Problem
HandleStoreDataBlobRequestandLimitConfigcompute the key length withDataBlobKey.String(). For a generic key that returns the protobuf text form, for examplegeneric:"abc", notabc. This causes three defects:max_data_blob_key_length. With a limit of 5, the keyabcdeis refused because its text form is 15 bytes.generic:"", is not empty, so the "key is required" check never triggers.max_data_blobs_sizecounts about 10 extra bytes per blob, so participants hit the limit early.The text form of a protobuf message is also documented as unstable, so the counted length can change between builds.
Changes
config.DataBlobKeyLength, which returns the length of the generic key, or the schema name plus custom encoding for a schema ID key.CheckDataBlobKeyLength,CheckDataBlobsSize,CanAddDataBloband the store handler's empty-key check.CheckDataBlobKeyLengthnow takes a*livekit.DataBlobKeyinstead of a string. Its only caller is the store handler.Tests
Three new cases in
TestHandleStoreDataBlobRequest: empty generic key, key exactly at the length limit, and a blob whose key plus contents exactly fits the size limit.Without the fix, 3 of 11 subtests fail. With the fix, all 11 pass.
go vet ./pkg/config ./pkg/rtcandgo test ./pkg/configpass.