1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
//! Centralized resource bounds.
//!
//! Every decode and encode path takes a [`Limits`]. Untrusted descriptors must
//! be rejected *before* catastrophic work is performed, so all arithmetic on
//! declared lengths and offsets is checked against these bounds and uses
//! checked integer operations.
/// Hard upper bounds applied while parsing and materializing a descriptor.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub struct Limits {
/// Maximum accepted source/descriptor input size.
pub max_input_bytes: u64,
/// Maximum reconstructed output size for a single materialization.
pub max_output_bytes: u64,
/// Admission cap on the output of a single `DEFLATE_REPLAY`.
///
/// This is a **VOLE replay-profile policy limit**, not an RFC 1951 maximum.
/// RFC 1951 permits arbitrarily many empty non-final stored blocks, so it
/// gives no finite `f(decompressed_size)` bound on `compressed_size`; a
/// bitstream that inflates to zero bytes may be arbitrarily large. VOLE
/// therefore declines to replay a descriptor whose declared output exceeds
/// this policy cap (see ADR-0016).
pub max_replay_bytes: u64,
/// Maximum length of a single record payload.
pub max_record_len: u32,
/// Maximum number of records in a container.
pub max_record_count: u32,
/// Maximum number of distinct byte objects (`OBJECT` records).
pub max_object_count: u32,
/// Maximum number of DRA instructions in a reconstruction graph.
pub max_graph_ops: u32,
/// Maximum repeat count for a single `REPEAT_LAST` instruction.
pub max_repeat_count: u64,
/// Maximum number of symbols in a single entropy channel.
pub max_channel_symbols: u64,
/// Maximum number of distinct entropy models (`MODEL` records).
pub max_model_count: u32,
/// Maximum number of entropy channels (`ENTROPY_CHANNEL` records).
pub max_channel_count: u32,
/// Maximum encoded size of a single entropy model payload.
pub max_entropy_model_bytes: u32,
/// Maximum number of lexical spans produced for a PDF input.
pub max_pdf_spans: u32,
/// Maximum number of selectors in a single `OBSERVATION_INDEX` record.
///
/// Bounds the admissions of the optional partial-decode index (Phase 7.3)
/// before allocation: an index whose selector table would exceed this is
/// rejected at parse and declined by the index builder. It mirrors the
/// object/graph scale so the table cannot dwarf the document it describes.
pub max_index_selectors: u32,
/// Maximum accepted size of an optional `DIRECTORY` record payload.
///
/// Bounds the seek directory (Phase 8) before allocation: a directory larger
/// than this is declined at decode rather than trusted. A directory is roughly
/// `13 * record_count` bytes, so this also caps the record count a directory
/// can describe.
pub max_directory_bytes: u32,
/// Maximum accepted size of an optional `CHECKPOINT` record payload.
///
/// Bounds the byte-level partial-materialization checkpoint (Phase 13.4)
/// before allocation: a checkpoint larger than this is declined at decode
/// rather than trusted. A checkpoint is `20 + 16 * op_count` bytes, so this
/// also caps the op count a checkpoint can describe.
pub max_checkpoint_bytes: u32,
// The ZIP caps below mirror the threat model and DEFAULT/STRICT values frozen
// in `research/subagents/phase-12/I-security.md` §6 (threat ids Z1–Z15), as
// required by plan §DEC-3/§DEC-9.
/// Maximum number of ZIP members accepted in one archive (Phase 12, Z2).
pub max_zip_members: u32,
/// Maximum declared compressed size of a single ZIP member (Phase 12, Z1).
pub max_zip_member_compressed: u64,
/// Maximum declared uncompressed size of a single ZIP member (Phase 12, Z1).
pub max_zip_member_uncompressed: u64,
/// Maximum sum of declared uncompressed sizes across all members (Z2).
pub max_zip_aggregate_uncompressed: u64,
/// Maximum declared uncompressed/compressed ratio for one member (Z1).
pub max_zip_compression_ratio: u32,
/// Maximum raw name byte length of one member (Phase 12, Z13/Z14).
pub max_zip_name_bytes: u32,
/// Maximum raw extra-field byte length of one member (Z7/Z14).
pub max_zip_extra_bytes: u32,
/// Maximum per-entry comment byte length (Z14).
pub max_zip_entry_comment_bytes: u32,
/// Maximum archive comment byte length (Z14/Z15).
pub max_zip_archive_comment_bytes: u32,
/// Maximum central-directory byte length (Z14).
pub max_zip_central_dir_bytes: u64,
/// Maximum leading bytes before the first local header (Z14).
pub max_zip_prefix_bytes: u64,
/// Maximum trailing bytes after the EOCD record (Z14).
pub max_zip_trailing_bytes: u64,
// The XML/OPC caps below mirror the threat model and DEFAULT/STRICT values
// frozen in `research/subagents/phase-12/I-security.md` §6 (§2 XML, §3 OPC),
// as required by plan §DEC-4/§DEC-9. XML is derived (`Q_gen`) state only.
/// Maximum XML element nesting depth before a typed decline (Phase 12, §2).
pub max_xml_depth: u32,
/// Maximum decoded byte length of a single XML part (Phase 12, §2).
pub max_xml_part_bytes: u64,
/// Maximum number of XML pull events in a single part (Phase 12, §2).
pub max_xml_events: u64,
/// Maximum number of XML element nodes in a single part (Phase 12, §2).
pub max_xml_nodes: u64,
/// Maximum number of attributes on a single XML element (Phase 12, §2).
pub max_xml_attrs_per_element: u32,
/// Maximum total text bytes accepted across a single XML part (Phase 12, §2).
pub max_xml_text_bytes: u64,
/// Maximum relationships across all `.rels` parts (Phase 12, §3).
pub max_opc_rels: u32,
/// Maximum internal relationship traversal depth (Phase 12 cycles, §3).
pub max_opc_rel_depth: u32,
/// Maximum `Default`+`Override` entries in `[Content_Types].xml` (Phase 12, §3).
pub max_opc_content_types_overrides: u32,
/// Maximum byte length of an OPC part name (Phase 12, §3).
pub max_opc_part_name_bytes: u32,
// The EPUB/OCF caps below mirror the threat model and DEFAULT/STRICT values
// frozen in `research/subagents/phase-12/I-security.md` §6 (§4 EPUB), as
// required by plan §DEC-5/§DEC-9. EPUB semantics are derived (`Q_gen`) only.
/// Maximum `rootfile` entries accepted in `META-INF/container.xml` (Phase 12, §4).
pub max_epub_rootfiles: u32,
/// Maximum Package Document manifest items accepted (Phase 12, §4).
pub max_epub_manifest_items: u32,
/// Maximum Package Document spine `itemref`s accepted (Phase 12, §4).
pub max_epub_spine_items: u32,
/// Maximum navigation-document nesting depth accepted (Phase 12, §4).
pub max_epub_nav_depth: u32,
/// Maximum manifest `fallback` chain length followed (Phase 12, §4).
pub max_epub_fallback_chain: u32,
/// Maximum XHTML element nodes accepted in one content/nav document (Phase 12, §4).
pub max_xhtml_nodes: u32,
// The ODT/ODF caps below mirror the EPUB caps above (Phase 13.3 applies the same
// bounded-XML policy to the OpenDocument content model). ODT semantics are derived
// (`Q_gen`) only.
/// Maximum `file-entry` elements accepted in `META-INF/manifest.xml` (Phase 13.3).
pub max_odt_manifest_entries: u32,
/// Maximum block elements accepted in one OpenDocument content part (Phase 13.3).
pub max_odt_blocks: u32,
/// Maximum notes accepted in one OpenDocument content part (Phase 13.3).
pub max_odt_notes: u32,
// The ODS/OpenDocument-Spreadsheet caps below bound the derived spreadsheet
// model (Phase 21.3.1). ODS semantics are derived (`Q_gen`) only.
/// Maximum `table:table` sheets accepted in one OpenDocument spreadsheet
/// content part (Phase 21.3.1).
pub max_ods_sheets: u32,
/// Maximum *expanded* grid slots accepted across one spreadsheet, after
/// `table:number-rows-repeated`/`table:number-columns-repeated` expansion
/// (Phase 21.3.1). Each expanded row charges at least one slot even when it
/// declares no cells, so an empty-row repeat bomb still declines. This is the
/// ODS analogue of the XLSX coordinate bound (ADR-0059): a repeated span is
/// bounded and the *expanded* count declines typed rather than allocating.
pub max_ods_cells: u64,
/// Maximum repeat count admitted for a single
/// `table:number-columns-repeated`/`table:number-rows-repeated` attribute
/// (Phase 21.3.1). A declaration above this bound is a typed resource-limit
/// decline, never an allocation.
pub max_ods_repeated_span: u32,
/// Maximum merged spans (`table:number-columns-spanned`>1 or
/// `table:number-rows-spanned`>1) accepted across one spreadsheet
/// (Phase 21.3.1).
pub max_ods_merges: u32,
/// Maximum named expressions
/// (`table:named-range`/`table:named-expression`) accepted across one
/// spreadsheet (Phase 21.3.1).
pub max_ods_named_expressions: u32,
/// Maximum `style:style` cell-style records accepted in one spreadsheet's
/// automatic styles or styles part (Phase 21.3.1).
pub max_ods_styles: u32,
/// Maximum `office:annotation` cell comments accepted across one spreadsheet
/// (Phase 21.3.1).
pub max_ods_comments: u32,
// The XLSX/SpreadsheetML caps below bound the derived semantic model
// (Phase 21.1.1). XLSX semantics are derived (`Q_gen`) only.
/// Maximum `<sheet>` declarations accepted in one workbook (Phase 21.1.1).
pub max_xlsx_sheets: u32,
/// Maximum cells accepted in one worksheet part (Phase 21.1.1).
pub max_xlsx_cells: u64,
/// Maximum shared strings accepted in `xl/sharedStrings.xml` (Phase 21.1.1).
pub max_xlsx_shared_strings: u32,
/// Maximum merged ranges accepted in one worksheet (Phase 21.1.1).
pub max_xlsx_merges: u32,
/// Maximum hyperlinks accepted in one worksheet (Phase 21.1.2).
pub max_xlsx_hyperlinks: u32,
/// Maximum comments accepted in one comments part (Phase 21.1.2).
pub max_xlsx_comments: u32,
/// Maximum table parts accepted across a workbook (Phase 21.1.2).
pub max_xlsx_tables: u32,
/// Maximum columns accepted in one table part (Phase 21.1.2).
pub max_xlsx_table_columns: u32,
/// Maximum defined/named ranges accepted in one workbook (Phase 21.1.2).
pub max_xlsx_defined_names: u32,
/// Maximum drawing parts accepted across a workbook (Phase 21.1.2).
pub max_xlsx_drawings: u32,
/// Maximum style records (fonts/fills/`cellXfs`) accepted in `styles.xml` (Phase 21.1.2).
pub max_xlsx_style_records: u32,
/// Maximum 0-based column index accepted in a cell reference (Phase 21.1.2).
///
/// The Excel-conformant grid is 16,384 columns wide (A..XFD), so a valid
/// 0-based column is `< 16384`; a coordinate at or beyond this bound is a
/// typed resource-limit decline. Bounding the coordinate here keeps a single
/// hostile reference from driving an unbounded projection downstream.
pub max_xlsx_col: u32,
/// Maximum 0-based row index accepted in a cell/row reference (Phase 21.1.2).
///
/// The Excel-conformant grid is 1,048,576 rows tall (1..1048576), so a valid
/// 0-based row is `< 1 << 20`; a coordinate at or beyond this bound is a
/// typed resource-limit decline.
pub max_xlsx_row: u32,
// The PPTX/PresentationML caps below bound the derived semantic model
// (Phase 21.2.1). PPTX semantics are derived (`Q_gen`) only.
/// Maximum slides accepted in one presentation (Phase 21.2.1).
pub max_pptx_slides: u32,
/// Maximum shapes accepted in one slide's shape tree, including group
/// descendants (Phase 21.2.1).
pub max_pptx_shapes_per_slide: u32,
/// Maximum text runs (`a:t`) accepted in one slide (Phase 21.2.1).
pub max_pptx_text_runs: u32,
/// Maximum group-shape nesting depth accepted in one slide (Phase 21.2.1).
pub max_pptx_group_depth: u32,
/// Maximum media parts (images/audio/video) exposed by one presentation
/// (Phase 21.2.1).
pub max_pptx_media: u32,
/// Maximum embedded tables accepted in one slide (Phase 21.2.1).
pub max_pptx_tables: u32,
/// Maximum table cells accepted across one slide's tables (Phase 21.2.1).
pub max_pptx_table_cells: u32,
/// Maximum notes-slide parts accepted in one presentation (Phase 21.2.1).
pub max_pptx_notes: u32,
/// Maximum slide-layout parts accepted in one presentation (Phase 21.2.1).
pub max_pptx_layouts: u32,
/// Maximum slide-master parts accepted in one presentation, and the bound
/// applied to theme parts (Phase 21.2.1).
pub max_pptx_masters: u32,
// The ODP/OpenDocument-Presentation caps below bound the derived presentation
// model (Phase 21.4.1). ODP semantics are derived (`Q_gen`) only.
/// Maximum `draw:page` slides accepted in one OpenDocument presentation
/// content part (Phase 21.4.1).
pub max_odp_slides: u32,
/// Maximum shapes accepted in one slide, including group descendants
/// (Phase 21.4.1).
pub max_odp_shapes_per_slide: u32,
/// Maximum text runs (`text:span`) accepted in one slide (Phase 21.4.1).
pub max_odp_text_runs: u32,
/// Maximum `draw:g` group nesting depth accepted in one slide (Phase 21.4.1).
pub max_odp_group_depth: u32,
/// Maximum `Pictures/*` media parts exposed by one presentation (Phase 21.4.1).
pub max_odp_media: u32,
/// Maximum embedded tables (`table:table`) accepted in one slide
/// (Phase 21.4.1).
pub max_odp_tables: u32,
/// Maximum table cells accepted across one slide's tables, after
/// `table:number-columns-repeated`/`table:number-rows-repeated` expansion
/// (Phase 21.4.1). An over-large repeat declines typed rather than allocating.
pub max_odp_table_cells: u32,
/// Maximum notes pages (`presentation:notes`) accepted in one presentation
/// (Phase 21.4.1).
pub max_odp_notes: u32,
/// Maximum `style:master-page` master pages accepted, and the bound applied to
/// `style:style` records, in one presentation (Phase 21.4.1).
pub max_odp_masters: u32,
// The JSON caps below bound the derived, span-preserving structured-tree model
// (Phase 21.5.1). JSON is not a package: the whole source parses as exactly one
// JSON value beneath these caps, and everything derived is `Q_gen` only.
/// Maximum JSON container nesting depth accepted (objects/arrays). A deeper
/// document is not detected as JSON (and any direct parse declines typed)
/// rather than risking unbounded recursion (Phase 21.5.1).
pub max_json_depth: u32,
/// Maximum JSON nodes (values plus object member keys) accepted in one
/// document. An over-large document declines typed rather than allocating
/// (Phase 21.5.1).
pub max_json_nodes: u32,
/// Maximum total raw string-token bytes accepted across one JSON document
/// (the bytes between the quotes, escapes included). A conservative upper
/// bound on the decoded text (Phase 21.5.1).
pub max_json_string_bytes: u64,
/// Maximum source length admitted for byte-based JSON detection. Larger inputs
/// fall back to [`crate::field::document_format::DocumentFormat::Opaque`]
/// (Phase 21.5.1).
pub max_json_document_bytes: u64,
// The YAML caps below bound the derived, span-preserving structured-tree model
// (Phase 21.6.1). Like JSON, YAML is not a package: the whole source parses as a
// bounded stream of documents beneath these caps, and everything derived is
// `Q_gen` only.
/// Maximum YAML container nesting depth accepted (mappings/sequences). A deeper
/// document is not detected as YAML (and any direct parse declines typed) rather
/// than risking unbounded recursion (Phase 21.6.1).
pub max_yaml_depth: u32,
/// Maximum YAML nodes (containers, scalars, aliases, empties) accepted in one
/// stream. An over-large document declines typed rather than allocating
/// (Phase 21.6.1).
pub max_yaml_nodes: u32,
/// Maximum YAML scalar nodes accepted in one stream (Phase 21.6.1).
pub max_yaml_scalars: u32,
/// Maximum YAML anchors (`&a`) accepted in one stream (Phase 21.6.1).
pub max_yaml_anchors: u32,
/// Maximum documents accepted in one YAML stream (Phase 21.6.1).
pub max_yaml_documents: u32,
/// Maximum total raw scalar-token bytes accepted across one YAML stream. A
/// conservative upper bound on the decoded text (Phase 21.6.1).
pub max_yaml_string_bytes: u64,
/// Maximum source length admitted for byte-based YAML detection. Larger inputs
/// fall back to [`crate::field::document_format::DocumentFormat::Opaque`]
/// (Phase 21.6.1).
pub max_yaml_document_bytes: u64,
}
impl Limits {
/// The default archival limits: generous, but always finite.
pub const DEFAULT: Limits = Limits {
max_input_bytes: 1 << 40, // 1 TiB
max_output_bytes: 1 << 40, // 1 TiB
max_replay_bytes: 1 << 34, // 16 GiB
max_record_len: 1 << 31, // 2 GiB
max_record_count: 1 << 20, // ~1M records
max_object_count: 1 << 20,
max_graph_ops: 1 << 20,
max_repeat_count: 1 << 32,
max_channel_symbols: 1 << 40,
max_model_count: 1 << 16,
max_channel_count: 1 << 16,
max_entropy_model_bytes: 4096,
max_pdf_spans: 1 << 26,
max_index_selectors: 1 << 20,
max_directory_bytes: 1 << 20,
max_checkpoint_bytes: 1 << 20,
max_zip_members: 1 << 20,
max_zip_member_compressed: 1 << 34,
max_zip_member_uncompressed: 1 << 34,
max_zip_aggregate_uncompressed: 1 << 36,
max_zip_compression_ratio: 1024,
max_zip_name_bytes: 1 << 16,
max_zip_extra_bytes: 1 << 16,
max_zip_entry_comment_bytes: 1 << 16,
max_zip_archive_comment_bytes: 1 << 16,
max_zip_central_dir_bytes: 1 << 28,
max_zip_prefix_bytes: 1 << 20,
max_zip_trailing_bytes: 1 << 20,
max_xml_depth: 256,
max_xml_part_bytes: 1 << 28,
max_xml_events: 1 << 24,
max_xml_nodes: 1 << 24,
max_xml_attrs_per_element: 4096,
max_xml_text_bytes: 1 << 28,
max_opc_rels: 1 << 20,
max_opc_rel_depth: 64,
max_opc_content_types_overrides: 1 << 20,
max_opc_part_name_bytes: 1 << 16,
max_epub_rootfiles: 16,
max_epub_manifest_items: 1 << 20,
max_epub_spine_items: 1 << 20,
max_epub_nav_depth: 64,
max_epub_fallback_chain: 32,
max_xhtml_nodes: 1 << 24,
max_odt_manifest_entries: 1 << 20,
max_odt_blocks: 1 << 20,
max_odt_notes: 1 << 20,
max_ods_sheets: 4096,
max_ods_cells: 1 << 24,
max_ods_repeated_span: 1 << 20,
max_ods_merges: 1 << 20,
max_ods_named_expressions: 1 << 20,
max_ods_styles: 1 << 16,
max_ods_comments: 1 << 20,
max_xlsx_sheets: 4096,
max_xlsx_cells: 1 << 24,
max_xlsx_shared_strings: 1 << 20,
max_xlsx_merges: 1 << 20,
max_xlsx_hyperlinks: 1 << 20,
max_xlsx_comments: 1 << 20,
max_xlsx_tables: 1 << 20,
max_xlsx_table_columns: 1 << 16,
max_xlsx_defined_names: 1 << 20,
max_xlsx_drawings: 1 << 14,
max_xlsx_style_records: 1 << 16,
max_xlsx_col: 16384,
max_xlsx_row: 1 << 20,
max_pptx_slides: 4096,
max_pptx_shapes_per_slide: 1 << 20,
max_pptx_text_runs: 1 << 22,
max_pptx_group_depth: 64,
max_pptx_media: 1 << 14,
max_pptx_tables: 1 << 14,
max_pptx_table_cells: 1 << 20,
max_pptx_notes: 1 << 16,
max_pptx_layouts: 1 << 14,
max_pptx_masters: 1 << 14,
max_odp_slides: 4096,
max_odp_shapes_per_slide: 1 << 20,
max_odp_text_runs: 1 << 22,
max_odp_group_depth: 64,
max_odp_media: 1 << 14,
max_odp_tables: 1 << 14,
max_odp_table_cells: 1 << 20,
max_odp_notes: 1 << 16,
max_odp_masters: 1 << 14,
max_json_depth: 256,
max_json_nodes: 1 << 24,
max_json_string_bytes: 1 << 28,
max_json_document_bytes: 1 << 34,
max_yaml_depth: 256,
max_yaml_nodes: 1 << 24,
max_yaml_scalars: 1 << 24,
max_yaml_anchors: 1 << 20,
max_yaml_documents: 1 << 16,
max_yaml_string_bytes: 1 << 28,
max_yaml_document_bytes: 1 << 34,
};
/// Tight limits for hostile-input testing and fuzzing.
pub const STRICT: Limits = Limits {
max_input_bytes: 1 << 26, // 64 MiB
max_output_bytes: 1 << 26, // 64 MiB
max_replay_bytes: 1 << 26, // 64 MiB
max_record_len: 1 << 24, // 16 MiB
max_record_count: 1 << 16, // 65536
max_object_count: 1 << 16,
max_graph_ops: 1 << 16,
max_repeat_count: 1 << 24,
max_channel_symbols: 1 << 26,
max_model_count: 1 << 12,
max_channel_count: 1 << 12,
max_entropy_model_bytes: 4096,
max_pdf_spans: 1 << 16,
max_index_selectors: 1 << 16,
max_directory_bytes: 1 << 18,
max_checkpoint_bytes: 1 << 18,
max_zip_members: 1 << 16,
max_zip_member_compressed: 1 << 26,
max_zip_member_uncompressed: 1 << 26,
max_zip_aggregate_uncompressed: 1 << 27,
max_zip_compression_ratio: 256,
max_zip_name_bytes: 4096,
max_zip_extra_bytes: 4096,
max_zip_entry_comment_bytes: 4096,
max_zip_archive_comment_bytes: 4096,
max_zip_central_dir_bytes: 1 << 20,
max_zip_prefix_bytes: 1 << 16,
max_zip_trailing_bytes: 1 << 16,
max_xml_depth: 64,
max_xml_part_bytes: 1 << 20,
max_xml_events: 1 << 16,
max_xml_nodes: 1 << 16,
max_xml_attrs_per_element: 256,
max_xml_text_bytes: 1 << 20,
max_opc_rels: 1 << 14,
max_opc_rel_depth: 16,
max_opc_content_types_overrides: 1 << 12,
max_opc_part_name_bytes: 4096,
max_epub_rootfiles: 4,
max_epub_manifest_items: 1 << 14,
max_epub_spine_items: 1 << 14,
max_epub_nav_depth: 16,
max_epub_fallback_chain: 8,
max_xhtml_nodes: 1 << 16,
max_odt_manifest_entries: 1 << 14,
max_odt_blocks: 1 << 14,
max_odt_notes: 1 << 12,
max_ods_sheets: 64,
max_ods_cells: 1 << 16,
max_ods_repeated_span: 1 << 14,
max_ods_merges: 1 << 14,
max_ods_named_expressions: 1 << 14,
max_ods_styles: 1 << 12,
max_ods_comments: 1 << 14,
max_xlsx_sheets: 64,
max_xlsx_cells: 1 << 16,
max_xlsx_shared_strings: 1 << 14,
max_xlsx_merges: 1 << 14,
max_xlsx_hyperlinks: 1 << 14,
max_xlsx_comments: 1 << 14,
max_xlsx_tables: 1 << 14,
max_xlsx_table_columns: 1 << 12,
max_xlsx_defined_names: 1 << 14,
max_xlsx_drawings: 1 << 12,
max_xlsx_style_records: 1 << 12,
max_xlsx_col: 16384,
max_xlsx_row: 1 << 20,
max_pptx_slides: 64,
max_pptx_shapes_per_slide: 1 << 16,
max_pptx_text_runs: 1 << 18,
max_pptx_group_depth: 16,
max_pptx_media: 1 << 12,
max_pptx_tables: 1 << 12,
max_pptx_table_cells: 1 << 16,
max_pptx_notes: 1 << 12,
max_pptx_layouts: 1 << 12,
max_pptx_masters: 1 << 12,
max_odp_slides: 64,
max_odp_shapes_per_slide: 1 << 16,
max_odp_text_runs: 1 << 18,
max_odp_group_depth: 16,
max_odp_media: 1 << 12,
max_odp_tables: 1 << 12,
max_odp_table_cells: 1 << 16,
max_odp_notes: 1 << 12,
max_odp_masters: 1 << 12,
max_json_depth: 64,
max_json_nodes: 1 << 16,
max_json_string_bytes: 1 << 20,
max_json_document_bytes: 1 << 26,
max_yaml_depth: 64,
max_yaml_nodes: 1 << 16,
max_yaml_scalars: 1 << 16,
max_yaml_anchors: 1 << 12,
max_yaml_documents: 1 << 10,
max_yaml_string_bytes: 1 << 20,
max_yaml_document_bytes: 1 << 26,
};
}
impl Default for Limits {
fn default() -> Self {
Limits::DEFAULT
}
}