#[non_exhaustive]pub struct ParseLimits {
pub max_depth: u32,
pub max_items: u32,
pub max_expanded_bytes: u64,
}Expand description
Ceilings a handler applies while parsing.
Separate from crate::io::Limits, which bounds how much is read. These bound what a
parser will do with what it read — the difference between refusing a 4 GB file and
refusing a 4 KB file that describes four billion objects.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.max_depth: u32Maximum nesting depth.
Stack overflow aborts the process; it is not a catchable panic, so it cannot be
handled after the fact and must be prevented by construction
(docs/ARCHITECTURE.md §5.1).
max_items: u32Maximum number of structural items — objects, segments, chunks — in one file.
max_expanded_bytes: u64Maximum bytes a single compressed structure may expand to.
Load-bearing as of the OOXML handler. It was reserved through Phase 1, because no handler decompressed anything: PNG’s compressed text chunks are removed without being inflated (ADR-0022), and the PDF handler declines to inflate a filtered metadata stream for the same reason. The ZIP container layer is the first code here to inflate, and it spends this ceiling as an allowance shared across a whole archive — so that a hundred entries each individually within it cannot collectively exceed it, which is the shape of every archive bomb that gets past a naive limit (ADR-0028, ADR-0029).
The ceiling is enforced as output is produced, never checked afterwards. A limit tested after decompressing is not a limit — the memory is already committed by the time it fails.
Trait Implementations§
Source§impl Clone for ParseLimits
impl Clone for ParseLimits
impl Copy for ParseLimits
Source§impl Debug for ParseLimits
impl Debug for ParseLimits
Source§impl Default for ParseLimits
impl Default for ParseLimits
impl Eq for ParseLimits
Source§impl PartialEq for ParseLimits
impl PartialEq for ParseLimits
impl StructuralPartialEq for ParseLimits
Auto Trait Implementations§
impl Freeze for ParseLimits
impl RefUnwindSafe for ParseLimits
impl Send for ParseLimits
impl Sync for ParseLimits
impl Unpin for ParseLimits
impl UnsafeUnpin for ParseLimits
impl UnwindSafe for ParseLimits
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.