Notarizing documentation

Limits

Developer preview. Not yet production ready. This page is rendered from docs/limits.md of the Notarizing repository at revision d23579e737f9d1e16e07b3c6b21a51282d64027e. It describes the behavior of that revision.

Contents

This page lists the limits that a user can meet, with their values and their source in the code. Every limit is fixed in this build unless the table names a flag. A command that meets a limit refuses the input with too_large or invalid_input, or it returns a partial result that says what it omits. Notarizing never cuts an input in silence.

Section numbers name sections of n0-decisions.md. Paths are below internal/.

Workspace storage

LimitValueSource
Retained report and artifact bytes of a workspace (each digest counted once)1 GiBapplication.DefaultMaxWorkspaceEvidenceBytes, section 15
Retained snapshot file bytes and target documents of a workspace1 GiBapplication.DefaultMaxWorkspaceSourceBytes, section 19
Imports that stage bytes at the same time2application.DefaultMaxConcurrentImports
SQLite busy timeout5 ssqlitestore.DefaultBusyTimeout

An import above a storage cap fails with too_large and stores nothing. Free space with retention preview and retention apply (at most 10,000 receipts for each plan, application.MaxRetentionReceipts).

Source import

LimitValueSource
OpenSpec files read for one change2,000adapters/openspec.DefaultMaxFiles
Size of one OpenSpec file1 MiBadapters/openspec.DefaultMaxFileBytes
Total OpenSpec bytes of one snapshot32 MiBadapters/openspec.DefaultMaxTotalBytes
Git tree entries listed for one snapshot10,000adapters/git.DefaultMaxEntries
Time of one Git read60 sadapters/git.DefaultTimeout
Locator (--at) length255 bytesadapters/git.MaxLocatorBytes
Requirement or declaration blocks in one file2,000adapters/openspec maxBlocksPerFile
Requirements in one target20,000maxRequirements
Declared nodes in one target20,000maxNodes
Declared edges in one target200,000maxEdges
Scenarios in one requirement block500maxScenariosPerBlock
Link items in one requirement block2,000maxLinksPerBlock
Extractor diagnostics of one target10,000maxDiagnostics
Premise group nesting16 levelsdomain.MaxGroupNesting, section 7.2
Identifier length128 characters^[A-Za-z0-9][A-Za-z0-9_.:-]{0,127}$, section 7.2
Changes listed by change list --at5,000adapters/openspec.MaxListedChanges

A block, node or edge limit is a fatal diagnostic: the import stores a target_error target. See Writing specifications.

Evidence import

LimitValueSource
Report size256 KiBadapters/reports.DefaultMaxReportBytes
JSON nesting of a report64adapters/reports.DefaultMaxDepth
Artifacts of one report64adapters/reports.DefaultMaxArtifacts
Size of one artifact16 MiBadapters/reports.DefaultMaxArtifactBytes
Report and artifacts together64 MiBadapters/reports.DefaultMaxPackageBytes
Search indexes rebuilt after one import command16cli.maxIndexRefresh, section 32.2
Reports for one evidence import command256cli.maxBatchReports, section 61.3
Input file read by the CLI (bindings, policy and other JSON files)16 MiBcli.MaxInputFileBytes

A larger report fails with, for example, too_large: report: invalid JSON at byte 262144: input is longer than 262144 bytes. --no-index skips the index rebuild. Then run search index once at the end.

The producer gotestreport reads at most 16 MiB of go test -json output, 256 checks and 4,096 tests (examples/producers/gotestreport/main.go).

Bindings, policy and assessment

LimitValueSource
Bindings assessed for one requirement revision1,000policy.MaxBindings
Required configurations of one binding32policy.MaxConfigurations
Receipts assessed for one requirement20,000policy.MaxReceipts
Reviewed supersessions10,000policy.MaxSupersessions
Receipts listed in one assessment row64application.MaxListedReceipts

Review

LimitValueSource
Review grant time to live1 minute to 8 hours, whole secondsweb/session.MinGrantTTL, review.MaxGrantTTL, http-api.md section 2.2
Browser sessions of one serve64; a new session ends the least recently used oneweb/session.DefaultMaxSessions, section 23
Failed viewer secret attempts5 each minuteweb.MaxBootstrapFailures
Review events of one target10,000application.MaxReviewEventsPerTarget, section 24
Review command body256 KiBhttp-api.md section 2
Rationale8,000 charactersreview-command schema
Wording draft (replacement block)32,000 charactersreview-command schema
Actor label64 charactersapplication.MaxActorLabelRunes
Source file of a review patch1 MiBreview.MaxPatchSourceBytes
Wording drafts in one patch32review.MaxPatchEdits

A grant outside its range fails with --ttl must be whole seconds from 1m to 8h.

Browser views

LimitValueSource
Requirements in the Review list1,000webapi.maxReviewRequirements
Assumptions, premise groups, questions, diagnostics in Review1,000, 500, 500, 500webapi/review.go
Explore graph nodes150 by default, at most 500graph.DefaultMaxNodes, session limits
Explore graph edges300 by default, at most 1,000graph.DefaultMaxEdges
Explore depth1 by default, at most 4graph.MaxDepth
Graph roots20graph.MaxRoots
Compare rows1,000webapi.maxCompareRows
Search query2,048 bytessearch.MaxQueryBytes
Search results50 by default, at most 100webapi/search.go
Source excerpt1,000 characterssession limits
HTTP request bodies1 KiB session, 8 KiB search, 16 KiB export, 256 KiB review commandhttp-api.md section 2

A cut list sets truncated and the page says so. A graph view that does not fit gives a next page. The CLI graph query has the same depth, node and edge ranges: --depth must be 0 to 4, --max-nodes 1 to 500 and --max-edges 0 to 1000.

Exports and bundles

LimitValueSource
Receipts in one bundle4,096application.MaxBundleReceipts, section 25.6
Artifacts of one bundled receipt64section 25.6
One bundle file and the manifest16 MiB eachsection 25.6
Bundle sizethe evidence cap plus 64 MiB; at most 8 GiBapplication.MaxBundleBytesCeiling, section 25.6
Review events in one bundle10,000section 36.2
Source target references in one bundle1,000section 25.6
Graph or review export document8 MiBexport.MaxDocumentBytes
Requirements and assumptions in a review export10,000 eachexport.MaxReviewRequirements

MCP

LimitValueSource
One tool response512 KiBmcp.MaxResponseBytes, section 27.4
Change report in MCP200 requirements, 16 rows each, 200 assumptions, 100 groups, 100 questions, 2,000 characters for each textmcp/tools.go
Graph50 nodes and 100 edges by default; at most 150 nodes, 300 edges, depth 2mcp/tools.go
Search20 results by default, at most 50mcp/tools.go

A larger answer is cut and says what it omits, or it fails with too_large.

Optional ka2a adapter

The adapter configuration has its own limits: handler_timeout 1 s to 10 m, drain_timeout at most 5 m, 1 to 1,000 source bindings, and a report of at most 256 KiB with at most 16 inline artifacts (section 29). See the operator guide.

Measured scale

The qualification runs of 2026-09-30 measured these values on a shared, contended 4-CPU host (measurements, soak, section 32.6). A number describes its run only. It is not a capacity figure, a service level or a performance claim.

MeasurementAt 10,000 receipts
Evidence import, p5010.7 ms
Change review of the target, p501.1 s
Lexical search index build3.1 s
Search for a requirement ID, p5048.8 ms
Bundle export of the 4,096-receipt limit0.8 s, 16 MiB

The 30-minute soak imported 9,939 reports through the control API and sent 9,943 browser queries with caps of 64 MiB. It purged 4 times and ended with an integrity check ok.

What is not measured

  • More than 10,000 receipts in one workspace.
  • A target near the source limits (20,000 requirements, 200,000 edges).
  • Several reviewers on one serve at the same time.
  • Hosts other than linux/amd64, and disks other than the local disk of the measurement host.
  • The semantic search provider under load.
  • The ka2a adapter under sustained load. Its tests check correctness, not throughput.

All Notarizing documents