Skip to content

Align configuration and test harness with server lifecycle guarantees; optimize heap footprint - #47

Merged
szeka9 merged 11 commits into
mainfrom
development
Aug 22, 2026
Merged

szeka9 merged 11 commits into
mainfrom
development

Conversation

@szeka9

@szeka9 szeka9 commented Aug 22, 2026

Copy link
Copy Markdown
Owner

This pull request formalizes the server lifecycle through
one-shot configuration. Until now, configuration was stored
in a shared cache. Because setting up the HTTP parser and
its optional features involves monkey-patching, dynamic
configuration is not viable.

Additionally, there are several changes aimed at stabilizing
heap utilization and reducing its variability under active traffic.

This pull request also includes two interoperability fixes: lenient
percent encoding and a fix for the SVG content type.

szeka9 added 10 commits August 9, 2026 13:47
This change removes redundant import statements
and adds a condition for importing the IAM module
to reduce heap usage when authentication is turnedd off.
Instead of directly reading configuration in the
logging module, configure log levels in the HTTP
server module, during server initialization.
This reduces coupling between modules and allows
code deduplication in the logging module.
- move configuration loading, TLS, and IAM initialization out of HttpServer
  into a separate application initialization module
- make configuration a one-shot, slots-based object and remove dynamic
  configuration dependencies from runtime modules
- decentralize module patching and move patch-based initialization into the
  respective modules
- remove optional-method placeholders from http.py; use attribute checks and
  generic post-hooks for optional behavior and state transitions
- optimize the import graph and reduce module coupling by passing dependencies
  explicitly
- reduce temporary allocations in hot paths, including unnecessary split()
  calls and temporary data structures
- centralize the working directory in pyrobusta/__init__.py
- remove the clock.py adapter for ticks_ms(), ticks_add(), etc.
- reduce unnecessary class and instance attributes by passing short-lived
  state as method arguments

Result: reduce runtime heap footprint by approximately 5 KB and increase the
largest free block from a few hundred to ~1,000 bytes compared to the last commit.
http.py is monkey-patched by other optionally enabled modules.
Isolate http.py only and safely reload it in the setup method
while importing other modules in a regular way, applying patches
to the isolated http module.
PyRobusta only supports one-shot configuration, requiring
a server restart for configuration changes. The current
function test harness is built on a conflicting assumption,
dynamically updating the configuration cache.

To isolate test cases, run each function test by restarting
and reconfiguring the server.
Add system test cases covering browser security, basic
authentication, and HTTP sessions.

Restructure the system test modules into a single module
instead of importing multiple modules (app_base.py and
app_multipart.py), reducing the import footprint.
Remove dependence on pyrobusta.utils.patch in the HTTP parser
to reduce idle heap usage.

Merge http_csrf.py and http_session.py as these modules are mostly
imported together.
Treat percent signs followed by non-hexadecimal characters
as literal characters rather than attempting to decode them.
This improves interoperability with clients that send literal
percent signs without percent encoding.

Create additional test cases for percent decoding
for invalid cases and hexadecimal digits.
Retain simple path concatenation by using
an empty string for the root directory while
using "/" when checking directory content.

Remove working directory argument as it is
ambiguous when the upload root and temporary
directory is already initialized. Always use absolute
paths instead.
"image/svg+xml" is the official content
type value for SVG files.
@szeka9
szeka9 force-pushed the development branch 3 times, most recently from 8af012e to 3bf68e5 Compare August 22, 2026 12:04
Reorganize imports in unit test cases and replace
relative import paths with absolute paths.

Disable R1714 (consider-using-in) for
memory optimization.

Solve R1710 (inconsistent-return-statements)
errors, and remove it from disabled rules.
@szeka9
szeka9 merged commit 68d16c9 into main Aug 22, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant