Hello,
I'm designing a local macOS helper service (minimum deployment target: macOS 13) that performs one fixed syntax-validation operation. The submitted source is never executed.
The security contract requires:
A maximum incoming transport request size of 327,680 bytes.
Immediate rejection when the 327,681st byte is encountered, without an allocation proportional to an unbounded sender-controlled payload.
No application-level response for an oversized transport request, followed by termination of the affected connection.
Complete application responses limited to 65,536 bytes, without treating truncated output as successful.
I've reviewed the public XPC APIs, including xpc_data_get_length, xpc_connection_cancel, and xpc_connection_set_peer_code_signing_requirement.
The remaining uncertainty is whether XPC can enforce a receiver-side message-size limit before materializing the incoming payload.
My questions are:
Does any public XPC API on macOS 13+ provide a documented maximum incoming message size that is enforced before payload materialization or proportional allocation?
If not, is the entire incoming XPC message necessarily materialized before the application event handler receives it?
Is there a supported XPC design for guaranteeing bounded receiver memory with untrusted input, or should this requirement use a different local transport, such as an AF_UNIX SOCK_STREAM socket?
What guarantees does xpc_connection_cancel provide regarding connection termination, pending messages, and prevention of connection reuse after detecting malformed or oversized input?
I'm specifically looking for documented platform guarantees rather than behavior that happens to work in testing.
Thank you!
0
0
35