Align configuration and test harness with server lifecycle guarantees; optimize heap footprint - #47
Merged
Merged
Conversation
This change removes redundant import statements and adds a condition for importing the IAM module to reduce heap usage when authentication is turnedd off.
Instead of directly reading configuration in the logging module, configure log levels in the HTTP server module, during server initialization. This reduces coupling between modules and allows code deduplication in the logging module.
- move configuration loading, TLS, and IAM initialization out of HttpServer into a separate application initialization module - make configuration a one-shot, slots-based object and remove dynamic configuration dependencies from runtime modules - decentralize module patching and move patch-based initialization into the respective modules - remove optional-method placeholders from http.py; use attribute checks and generic post-hooks for optional behavior and state transitions - optimize the import graph and reduce module coupling by passing dependencies explicitly - reduce temporary allocations in hot paths, including unnecessary split() calls and temporary data structures - centralize the working directory in pyrobusta/__init__.py - remove the clock.py adapter for ticks_ms(), ticks_add(), etc. - reduce unnecessary class and instance attributes by passing short-lived state as method arguments Result: reduce runtime heap footprint by approximately 5 KB and increase the largest free block from a few hundred to ~1,000 bytes compared to the last commit.
http.py is monkey-patched by other optionally enabled modules. Isolate http.py only and safely reload it in the setup method while importing other modules in a regular way, applying patches to the isolated http module.
PyRobusta only supports one-shot configuration, requiring a server restart for configuration changes. The current function test harness is built on a conflicting assumption, dynamically updating the configuration cache. To isolate test cases, run each function test by restarting and reconfiguring the server.
Add system test cases covering browser security, basic authentication, and HTTP sessions. Restructure the system test modules into a single module instead of importing multiple modules (app_base.py and app_multipart.py), reducing the import footprint.
Remove dependence on pyrobusta.utils.patch in the HTTP parser to reduce idle heap usage. Merge http_csrf.py and http_session.py as these modules are mostly imported together.
Treat percent signs followed by non-hexadecimal characters as literal characters rather than attempting to decode them. This improves interoperability with clients that send literal percent signs without percent encoding. Create additional test cases for percent decoding for invalid cases and hexadecimal digits.
Retain simple path concatenation by using an empty string for the root directory while using "/" when checking directory content. Remove working directory argument as it is ambiguous when the upload root and temporary directory is already initialized. Always use absolute paths instead.
"image/svg+xml" is the official content type value for SVG files.
szeka9
force-pushed
the
development
branch
3 times, most recently
from
August 22, 2026 12:04
8af012e to
3bf68e5
Compare
Reorganize imports in unit test cases and replace relative import paths with absolute paths. Disable R1714 (consider-using-in) for memory optimization. Solve R1710 (inconsistent-return-statements) errors, and remove it from disabled rules.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request formalizes the server lifecycle through
one-shot configuration. Until now, configuration was stored
in a shared cache. Because setting up the HTTP parser and
its optional features involves monkey-patching, dynamic
configuration is not viable.
Additionally, there are several changes aimed at stabilizing
heap utilization and reducing its variability under active traffic.
This pull request also includes two interoperability fixes: lenient
percent encoding and a fix for the SVG content type.