Skip to content

rtc: measure data blob keys by their content, not their text form - #4923

Merged
boks1971 merged 1 commit into
livekit:masterfrom
RaphaelFakhri:fix/data-blob-key-length
Sep 29, 2026
Merged

boks1971 merged 1 commit into
livekit:masterfrom
RaphaelFakhri:fix/data-blob-key-length

Conversation

@RaphaelFakhri

Copy link
Copy Markdown
Contributor

Fixes data blob key validation and size accounting, which measured the text form of the key message instead of the key itself.

Problem

HandleStoreDataBlobRequest and LimitConfig compute the key length with DataBlobKey.String(). For a generic key that returns the protobuf text form, for example generic:"abc", not abc. This causes three defects:

  • A key is rejected when it is within max_data_blob_key_length. With a limit of 5, the key abcde is refused because its text form is 15 bytes.
  • An empty generic key is accepted. Its text form, generic:"", is not empty, so the "key is required" check never triggers.
  • max_data_blobs_size counts about 10 extra bytes per blob, so participants hit the limit early.

The text form of a protobuf message is also documented as unstable, so the counted length can change between builds.

Changes

  • Add config.DataBlobKeyLength, which returns the length of the generic key, or the schema name plus custom encoding for a schema ID key.
  • Use it in CheckDataBlobKeyLength, CheckDataBlobsSize, CanAddDataBlob and the store handler's empty-key check.
  • CheckDataBlobKeyLength now takes a *livekit.DataBlobKey instead of a string. Its only caller is the store handler.

Tests

Three new cases in TestHandleStoreDataBlobRequest: empty generic key, key exactly at the length limit, and a blob whose key plus contents exactly fits the size limit.

go test ./pkg/rtc -run TestHandleStoreDataBlobRequest -count=1 -v

Without the fix, 3 of 11 subtests fail. With the fix, all 11 pass. go vet ./pkg/config ./pkg/rtc and go test ./pkg/config pass.

@RaphaelFakhri
RaphaelFakhri requested a review from a team as a code owner September 29, 2026 11:14
@CLAassistant

CLAassistant commented Sep 29, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@boks1971 boks1971 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you very much for these submissions.

But, please note that these cannot be merged without you signing the CLA.

@RaphaelFakhri

Copy link
Copy Markdown
Contributor Author

Much obliged! I have signed accordingly.

@boks1971
boks1971 merged commit 2d9bf12 into livekit:master Sep 29, 2026
3 of 6 checks passed
eleboucher pushed a commit to eleboucher/homelab that referenced this pull request Oct 7, 2026
…7 ➔ v1.13.8) (#2275)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/livekit/livekit-server](https://github.com/livekit/livekit) | patch | `v1.13.7` → `v1.13.8` |

---

### Release Notes

<details>
<summary>livekit/livekit (docker.io/livekit/livekit-server)</summary>

### [`v1.13.8`](https://github.com/livekit/livekit/releases/tag/v1.13.8)

[Compare Source](livekit/livekit@v1.13.7...v1.13.8)

##### Added

- agent: HTTP endpoints data plane ([#&#8203;4779](livekit/livekit#4779))
- use sender report pass through setting to forward abs-capture-time verbatim ([#&#8203;4812](livekit/livekit#4812))
- Add sdk lable to session start time and participant join ([#&#8203;4885](livekit/livekit#4885))
- Add a local participant method to get recently disconnected ([#&#8203;4911](livekit/livekit#4911))
- service: start room composite egress configured in a room preset ([#&#8203;4926](livekit/livekit#4926))

##### Changed

- Update github workflows ([#&#8203;4446](livekit/livekit#4446))
- Reduce descriptor marshal allocations on Go 1.26.4/linux-amd64 ([#&#8203;4681](livekit/livekit#4681))
- config: reject unknown send\_side\_bwe\_pacer, warn on unwired fallback ([#&#8203;4804](livekit/livekit#4804))
- Update github.com/livekit/protocol digest to [`a879e94`](livekit/livekit@a879e94) ([#&#8203;4864](livekit/livekit#4864))
- Update module github.com/gotesttools/gotestfmt/v2 to v2.5.0 ([#&#8203;4865](livekit/livekit#4865))
- Update module github.com/urfave/cli/v3 to v3.11.0 ([#&#8203;4867](livekit/livekit#4867))
- Update module golang.org/x/mod to v0.41.0 ([#&#8203;4868](livekit/livekit#4868))
- sfu: return VP8 munged header by value to avoid per-packet allocation ([#&#8203;4871](livekit/livekit#4871))
- sfu: patch pacer header extensions without per-packet allocation ([#&#8203;4872](livekit/livekit#4872))
- Update pion/sdp to get lesser SDP retention ([#&#8203;4873](livekit/livekit#4873))
- sfu: skip pacer allocation assertion under the race detector ([#&#8203;4874](livekit/livekit#4874))
- sfu: broadcast RTP to down tracks without per-packet allocations ([#&#8203;4875](livekit/livekit#4875))
- Track action versions and stop quarantining our own actions ([#&#8203;4877](livekit/livekit#4877))
- test: fix two data races in the test suites ([#&#8203;4878](livekit/livekit#4878))
- Bump go.opentelemetry.io/otel/sdk ([#&#8203;4879](livekit/livekit#4879))
- deps: update psrpc to v0.8.0 ([#&#8203;4882](livekit/livekit#4882))
- Update module github.com/moby/moby/client to v0.6.0 ([#&#8203;4883](livekit/livekit#4883))
- Update module golang.org/x/sync to v0.23.0 ([#&#8203;4884](livekit/livekit#4884))
- Propagate SIP\_TRUNK\_FAILURE ([#&#8203;4890](livekit/livekit#4890))
- ccutils: use millisecond resolution for probe interval backoff ([#&#8203;4891](livekit/livekit#4891))
- Increase receiver loadbalance threshold when batch io enabled ([#&#8203;4899](livekit/livekit#4899))
- rtc: parse each remote offer once per negotiation ([#&#8203;4904](livekit/livekit#4904))
- Bump protocol ([#&#8203;4909](livekit/livekit#4909))
- rtc: split EndSession out of MoveToRoom ([#&#8203;4917](livekit/livekit#4917))
- telemetry: drop the stats worker re-key path ([#&#8203;4918](livekit/livekit#4918))
- sfu: report forwarding latency as p90 instead of the mean ([#&#8203;4920](livekit/livekit#4920))
- rtc: accept ICE Completed in ICE-restart connect assertions ([#&#8203;4921](livekit/livekit#4921))
- rtc: measure data blob keys by their content, not their text form ([#&#8203;4923](livekit/livekit#4923))
- Remove deprecatred way of setting prometheus from the config file ([#&#8203;4928](livekit/livekit#4928))
- test: give mock participants a connection quality, close test rooms ([#&#8203;4933](livekit/livekit#4933))
- update warp dep ([#&#8203;4943](livekit/livekit#4943))

##### Fixed

- Do not add down tracks after receiver close ([#&#8203;4857](livekit/livekit#4857))
- Do not request media sections for transceivers that cannot send ([#&#8203;4892](livekit/livekit#4892))
- Deregister agent job when the server terminates it ([#&#8203;4893](livekit/livekit#4893))
- sfu: don't hold bindLock across the blank-frame flush in CloseWithFlush ([#&#8203;4895](livekit/livekit#4895))
- dynacast: re-send subscribed qualities after every publisher answer ([#&#8203;4907](livekit/livekit#4907))
- agent: release JobTerminate handler when job ends before registration ([#&#8203;4908](livekit/livekit#4908))
- Report disconnected for older disconnected participants. ([#&#8203;4910](livekit/livekit#4910))
- rtc: record a room's departure when the participant leaves it ([#&#8203;4913](livekit/livekit#4913))
- update deps to fix warp issue ([#&#8203;4916](livekit/livekit#4916))
- sfu: fix data stats active window bitrate and duration units ([#&#8203;4922](livekit/livekit#4922))
- fix: reject instead of drop for no dispatch rule ([#&#8203;4927](livekit/livekit#4927))
- fix: skip RTX/FEC when picking a fallback video codec ([#&#8203;4930](livekit/livekit#4930))
- fix: do not read invalid delta ([#&#8203;4935](livekit/livekit#4935))
- fix: use the fast debounce for the first negotiation ([#&#8203;4936](livekit/livekit#4936))
- fix: skip DTLS HelloVerifyRequest ([#&#8203;4937](livekit/livekit#4937))
- config: parse generated duration flags as durations ([#&#8203;4939](livekit/livekit#4939))
- fix: use the most common recent packet rate in connection quality ([#&#8203;4940](livekit/livekit#4940))
- fix: copy RED history packets instead of keeping pointers ([#&#8203;4941](livekit/livekit#4941))
- fix: keep one subscription when first subscribes race ([#&#8203;4944](livekit/livekit#4944))
- bump protocol to get unlock on no key fix ([#&#8203;4945](livekit/livekit#4945))
- fix: count leftover upstream loss after RTX repairs ([#&#8203;4946](livekit/livekit#4946))
- fix: switch VP8 temporal layer up only at a layer sync frame ([#&#8203;4947](livekit/livekit#4947))
- fix: reconcile everything when the reconcile queue overflows ([#&#8203;4948](livekit/livekit#4948))
- fix: enable H.264 publish for desktop Linux Firefox ([#&#8203;4949](livekit/livekit#4949))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/2275
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants