Skip to main content

ReadOptions

Struct ReadOptions 

Source
#[non_exhaustive]
pub struct ReadOptions { pub max_bytes: Option<usize>, pub max_nodes: Option<usize>, pub max_edges: Option<usize>, pub max_nested_graphs: Option<usize>, pub version_policy: VersionPolicy, }
Expand description

Allocation and collection policy for decoding an untrusted .nir file with read_with.

Defaults are permissive: every field is None, so read stays unbounded aside from the existing hard cap of 1024 NIRGraph groups (root plus nested). That cap is a stack/alias safety bound, not a substitute for a caller-chosen collection budget.

max_bytes is a decoded-allocation budget, not an on-disk file-size limit and not a bound on the returned graph’s exact resident size. Charging is monotonic and conservative: temporary allocations stay charged after they are released. The exact rules are:

  • numeric datasets: element count times decoded width;
  • u64 datasets: both the temporary Vec<u64> and converted Vec<i64>;
  • i64 extent lists converted to Vec<usize> (e.g. Input.shape): both the source Vec<i64> and the destination Vec<usize>;
  • fixed strings: fixed-capacity HDF5 buffers, resulting String headers, and the worst-case copied payload;
  • variable-length strings: descriptor buffers, payload bytes reported by H5Dvlen_get_buf_size, resulting String headers, and copied payload. Scalar VLEN strings use the containing file size as a payload bound because H5Dvlen_get_buf_size can abort on scalar VLEN;
  • scalar metadata: its decoded width;
  • missing v_reset and w_in: the synthesized tensor payload.

max_nodes, max_edges, and max_nested_graphs are global count budgets for the whole file: nested subgraphs add to the same totals rather than resetting per group. Counts are charged from HDF5 metadata (H5Gget_info link counts, edges shape, one charge per NIRGraph group) before the corresponding Vec / map is materialized. Hard-link aliases are rejected before they can charge a second time.

All arithmetic is checked; overflow is treated as over budget. Node and link names, collection bookkeeping, allocator overhead, and libhdf5’s own caches are not charged against max_bytes.

§Untrusted inputs

Conservative starting points when the file is not from a trusted producer — tighten further for your threat model:

use nir_rs::io::ReadOptions;

let opts = ReadOptions::default()
    .with_max_bytes(Some(64 * 1024 * 1024))
    .with_max_nodes(Some(10_000))
    .with_max_edges(Some(50_000))
    .with_max_nested_graphs(Some(64));

Fields (Non-exhaustive)§

This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.
§max_bytes: Option<usize>

Maximum total bytes charged by decoded allocations, or None for no allocation budget.

§max_nodes: Option<usize>

Maximum total nodes across root and nested graphs, or None for no node-count budget.

§max_edges: Option<usize>

Maximum total edges across root and nested graphs, or None for no edge-count budget.

§max_nested_graphs: Option<usize>

Maximum total NIRGraph groups decoded from the file (root included), or None to use only the hard cap of 1024 groups.

§version_policy: VersionPolicy

How to treat the root /version dataset. Defaults to VersionPolicy::Permissive, which is the Python nir.read behaviour and keeps read byte-for-byte compatible with earlier crate versions.

Implementations§

Source§

impl ReadOptions

Source

pub fn with_max_bytes(self, max_bytes: Option<usize>) -> Self

Set the decoded-allocation budget in bytes; None makes it unbounded.

Source

pub fn with_max_nodes(self, max_nodes: Option<usize>) -> Self

Set the global node-count budget; None makes it unbounded.

Source

pub fn with_max_edges(self, max_edges: Option<usize>) -> Self

Set the global edge-count budget; None makes it unbounded.

Source

pub fn with_max_nested_graphs(self, max_nested_graphs: Option<usize>) -> Self

Set the global nested-graph budget; None keeps only the hard cap of 1024 groups.

Source

pub fn with_version_policy(self, version_policy: VersionPolicy) -> Self

Set the /version compatibility policy.

use nir_rs::io::{ReadOptions, VersionPolicy};

// Permissive tooling (default): accept missing or arbitrary versions.
let tool = ReadOptions::default();
assert_eq!(tool.version_policy, VersionPolicy::Permissive);

// Fail-closed importer: paper 0.x fixtures and 1.x writers.
let importer = ReadOptions::default()
    .with_version_policy(VersionPolicy::compatible_major([0, 1]));

Trait Implementations§

Source§

impl Clone for ReadOptions

Source§

fn clone(&self) -> ReadOptions

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ReadOptions

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ReadOptions

Source§

fn default() -> ReadOptions

Returns the “default value” for a type. Read more
Source§

impl Eq for ReadOptions

Source§

impl PartialEq for ReadOptions

Source§

fn eq(&self, other: &ReadOptions) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for ReadOptions

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.