#[non_exhaustive]pub struct Limits {
pub max_pixels: u64,
}Expand description
Safety limits applied before any pixel memory is allocated.
See SPEC §Safety. Limits are checked at header parse time, so a hostile header that claims enormous dimensions is rejected before the engine commits memory to it.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.max_pixels: u64Maximum total pixels (width × height) in a single image.
Defaults to Limits::DEFAULT_MAX_PIXELS.
Implementations§
Source§impl Limits
impl Limits
Sourcepub const DEFAULT_MAX_PIXELS: u64 = 268_402_689
pub const DEFAULT_MAX_PIXELS: u64 = 268_402_689
The default max_pixels: 268 megapixels, matching Sharp.
Sourcepub const fn unlimited() -> Limits
pub const fn unlimited() -> Limits
Limits with every check disabled.
Only appropriate for fully trusted input.
Sourcepub const fn with_max_pixels(self, max_pixels: u64) -> Limits
pub const fn with_max_pixels(self, max_pixels: u64) -> Limits
The default limits with max_pixels replaced.
This exists because Limits is #[non_exhaustive]: downstream crates
cannot write Limits { max_pixels, .. }, so without a setter the field
would be readable but unconfigurable outside this crate.
Sourcepub fn check(&self, width: u32, height: u32) -> Result<(), PixelsError>
pub fn check(&self, width: u32, height: u32) -> Result<(), PixelsError>
Check a dimension pair against these limits.
§Errors
Returns PixelsError::LimitExceeded if the pixel count exceeds
Limits::max_pixels, or PixelsError::InvalidArgument if either
dimension is zero.