|
59 | 59 |
|
60 | 60 | ## Remote configuration (ECS client) |
61 | 61 |
|
| 62 | +## Device-ID collection |
| 63 | + |
| 64 | +`MATSDK_ENABLE_DEVICE_ID` defaults to `ON`. Configure with |
| 65 | +`-DMATSDK_ENABLE_DEVICE_ID=OFF` to compile out the SDK's native device-ID |
| 66 | +collectors, including machine-ID reads, fallback shell commands, adapter |
| 67 | +queries, host UUIDs, and vendor/Android identifiers. Other system and device |
| 68 | +metadata remain enabled. The macOS build also stops linking the ID-specific |
| 69 | +IOKit framework; dependencies still used by other features remain. |
| 70 | + |
| 71 | +Without a supplied ID, `DeviceInfo.Id` is omitted rather than replaced with a |
| 72 | +placeholder. Applications can still supply their own ID through |
| 73 | +`ISemanticContext::SetDeviceId`; registration does not overwrite it with an |
| 74 | +empty automatically collected ID. Android's Java bridge consults the native |
| 75 | +build setting before accessing `ANDROID_ID`; use the matching Java bridge |
| 76 | +sources with the native SDK. For Android Gradle builds, pass |
| 77 | +`-PMATSDK_ENABLE_DEVICE_ID=OFF` to apply the setting to both the SDK AAR and |
| 78 | +the test application. The Gradle property takes precedence over the |
| 79 | +`MATSDK_ENABLE_DEVICE_ID` environment variable; both default to `ON` when |
| 80 | +unspecified. |
| 81 | + |
| 82 | +This option does not disable session/SDK identifiers or control device IDs |
| 83 | +added independently by the operating system's UTC telemetry pipeline. |
| 84 | + |
| 85 | +## Targeted input safeguards |
| 86 | + |
| 87 | +The SDK bounds the command-line input involved in initialization and buffered |
| 88 | +HTTP responses. It does not impose a blanket metadata limit on system, |
| 89 | +device, application, or network-provider strings, additional limits on |
| 90 | +OS-reported buffer sizes, or a size limit on persisted session files. |
| 91 | + |
| 92 | +| Input | Limit | Oversize behavior | |
| 93 | +| --- | --- | --- | |
| 94 | +| POSIX application identifier | 4 KiB, stopping at the first NUL in `/proc/self/cmdline` | Truncate the executable name; never collect arguments or run a regex | |
| 95 | +| HTTP response body | 16 MiB | Fail the request rather than retain an oversized response | |
| 96 | +| HTTP response headers | 64 KiB | Fail the request rather than retain oversized headers | |
| 97 | + |
| 98 | +POSIX OS release values use exact line-key matching rather than recursive |
| 99 | +regular expressions. Curl response headers are also parsed without regex. |
| 100 | +Command-line truncation preserves UTF-8 boundaries. Other metadata is not |
| 101 | +truncated by these safeguards. Session files retain the existing platform |
| 102 | +text-read behavior; session parsing accepts both LF and CRLF line endings. |
| 103 | +The header budget includes framing for native raw headers or a minimum |
| 104 | +four-byte allowance per name/value pair. Windows native queries measure raw |
| 105 | +UTF-16/ANSI buffer bytes; WinRT conservatively budgets up to three UTF-8 bytes |
| 106 | +per UTF-16 unit. Android counts JNI modified UTF-8 bytes without allocating |
| 107 | +encoded strings, including two bytes for NUL and three per surrogate, before |
| 108 | +JNI additionally checks their encoded byte sizes. OS networking frameworks may |
| 109 | +have their own internal limits; the SDK limits its own copies and streaming |
| 110 | +body reads. |
| 111 | + |
| 112 | +Caller-provided events retain the existing configured serialized-event, |
| 113 | +upload, and offline-cache size policies; no new per-property limit is applied. |
| 114 | +See [decoder limits](CsProtocol-decoding.md#decoder-input-limits) for the |
| 115 | +separate diagnostic decoding budget. |
| 116 | + |
62 | 117 | ## Bandwidth manager (Resource manager) |
63 | 118 |
|
64 | 119 | - Get available bandwidth |
|
0 commit comments