pub struct Limits {Show 97 fields
pub max_input_bytes: u64,
pub max_output_bytes: u64,
pub max_replay_bytes: u64,
pub max_record_len: u32,
pub max_record_count: u32,
pub max_object_count: u32,
pub max_graph_ops: u32,
pub max_repeat_count: u64,
pub max_channel_symbols: u64,
pub max_model_count: u32,
pub max_channel_count: u32,
pub max_entropy_model_bytes: u32,
pub max_pdf_spans: u32,
pub max_index_selectors: u32,
pub max_directory_bytes: u32,
pub max_checkpoint_bytes: u32,
pub max_zip_members: u32,
pub max_zip_member_compressed: u64,
pub max_zip_member_uncompressed: u64,
pub max_zip_aggregate_uncompressed: u64,
pub max_zip_compression_ratio: u32,
pub max_zip_name_bytes: u32,
pub max_zip_extra_bytes: u32,
pub max_zip_entry_comment_bytes: u32,
pub max_zip_archive_comment_bytes: u32,
pub max_zip_central_dir_bytes: u64,
pub max_zip_prefix_bytes: u64,
pub max_zip_trailing_bytes: u64,
pub max_xml_depth: u32,
pub max_xml_part_bytes: u64,
pub max_xml_events: u64,
pub max_xml_nodes: u64,
pub max_xml_attrs_per_element: u32,
pub max_xml_text_bytes: u64,
pub max_opc_rels: u32,
pub max_opc_rel_depth: u32,
pub max_opc_content_types_overrides: u32,
pub max_opc_part_name_bytes: u32,
pub max_epub_rootfiles: u32,
pub max_epub_manifest_items: u32,
pub max_epub_spine_items: u32,
pub max_epub_nav_depth: u32,
pub max_epub_fallback_chain: u32,
pub max_xhtml_nodes: u32,
pub max_odt_manifest_entries: u32,
pub max_odt_blocks: u32,
pub max_odt_notes: u32,
pub max_ods_sheets: u32,
pub max_ods_cells: u64,
pub max_ods_repeated_span: u32,
pub max_ods_merges: u32,
pub max_ods_named_expressions: u32,
pub max_ods_styles: u32,
pub max_ods_comments: u32,
pub max_xlsx_sheets: u32,
pub max_xlsx_cells: u64,
pub max_xlsx_shared_strings: u32,
pub max_xlsx_merges: u32,
pub max_xlsx_hyperlinks: u32,
pub max_xlsx_comments: u32,
pub max_xlsx_tables: u32,
pub max_xlsx_table_columns: u32,
pub max_xlsx_defined_names: u32,
pub max_xlsx_drawings: u32,
pub max_xlsx_style_records: u32,
pub max_xlsx_col: u32,
pub max_xlsx_row: u32,
pub max_pptx_slides: u32,
pub max_pptx_shapes_per_slide: u32,
pub max_pptx_text_runs: u32,
pub max_pptx_group_depth: u32,
pub max_pptx_media: u32,
pub max_pptx_tables: u32,
pub max_pptx_table_cells: u32,
pub max_pptx_notes: u32,
pub max_pptx_layouts: u32,
pub max_pptx_masters: u32,
pub max_odp_slides: u32,
pub max_odp_shapes_per_slide: u32,
pub max_odp_text_runs: u32,
pub max_odp_group_depth: u32,
pub max_odp_media: u32,
pub max_odp_tables: u32,
pub max_odp_table_cells: u32,
pub max_odp_notes: u32,
pub max_odp_masters: u32,
pub max_json_depth: u32,
pub max_json_nodes: u32,
pub max_json_string_bytes: u64,
pub max_json_document_bytes: u64,
pub max_yaml_depth: u32,
pub max_yaml_nodes: u32,
pub max_yaml_scalars: u32,
pub max_yaml_anchors: u32,
pub max_yaml_documents: u32,
pub max_yaml_string_bytes: u64,
pub max_yaml_document_bytes: u64,
}Expand description
Hard upper bounds applied while parsing and materializing a descriptor.
Fields§
§max_input_bytes: u64Maximum accepted source/descriptor input size.
max_output_bytes: u64Maximum reconstructed output size for a single materialization.
max_replay_bytes: u64Admission cap on the output of a single DEFLATE_REPLAY.
This is a VOLE replay-profile policy limit, not an RFC 1951 maximum.
RFC 1951 permits arbitrarily many empty non-final stored blocks, so it
gives no finite f(decompressed_size) bound on compressed_size; a
bitstream that inflates to zero bytes may be arbitrarily large. VOLE
therefore declines to replay a descriptor whose declared output exceeds
this policy cap (see ADR-0016).
max_record_len: u32Maximum length of a single record payload.
max_record_count: u32Maximum number of records in a container.
max_object_count: u32Maximum number of distinct byte objects (OBJECT records).
max_graph_ops: u32Maximum number of DRA instructions in a reconstruction graph.
max_repeat_count: u64Maximum repeat count for a single REPEAT_LAST instruction.
max_channel_symbols: u64Maximum number of symbols in a single entropy channel.
max_model_count: u32Maximum number of distinct entropy models (MODEL records).
max_channel_count: u32Maximum number of entropy channels (ENTROPY_CHANNEL records).
max_entropy_model_bytes: u32Maximum encoded size of a single entropy model payload.
max_pdf_spans: u32Maximum number of lexical spans produced for a PDF input.
max_index_selectors: u32Maximum number of selectors in a single OBSERVATION_INDEX record.
Bounds the admissions of the optional partial-decode index (Phase 7.3) before allocation: an index whose selector table would exceed this is rejected at parse and declined by the index builder. It mirrors the object/graph scale so the table cannot dwarf the document it describes.
max_directory_bytes: u32Maximum accepted size of an optional DIRECTORY record payload.
Bounds the seek directory (Phase 8) before allocation: a directory larger
than this is declined at decode rather than trusted. A directory is roughly
13 * record_count bytes, so this also caps the record count a directory
can describe.
max_checkpoint_bytes: u32Maximum accepted size of an optional CHECKPOINT record payload.
Bounds the byte-level partial-materialization checkpoint (Phase 13.4)
before allocation: a checkpoint larger than this is declined at decode
rather than trusted. A checkpoint is 20 + 16 * op_count bytes, so this
also caps the op count a checkpoint can describe.
max_zip_members: u32Maximum number of ZIP members accepted in one archive (Phase 12, Z2).
max_zip_member_compressed: u64Maximum declared compressed size of a single ZIP member (Phase 12, Z1).
max_zip_member_uncompressed: u64Maximum declared uncompressed size of a single ZIP member (Phase 12, Z1).
max_zip_aggregate_uncompressed: u64Maximum sum of declared uncompressed sizes across all members (Z2).
max_zip_compression_ratio: u32Maximum declared uncompressed/compressed ratio for one member (Z1).
max_zip_name_bytes: u32Maximum raw name byte length of one member (Phase 12, Z13/Z14).
max_zip_extra_bytes: u32Maximum raw extra-field byte length of one member (Z7/Z14).
max_zip_entry_comment_bytes: u32Maximum per-entry comment byte length (Z14).
max_zip_archive_comment_bytes: u32Maximum archive comment byte length (Z14/Z15).
max_zip_central_dir_bytes: u64Maximum central-directory byte length (Z14).
max_zip_prefix_bytes: u64Maximum leading bytes before the first local header (Z14).
max_zip_trailing_bytes: u64Maximum trailing bytes after the EOCD record (Z14).
max_xml_depth: u32Maximum XML element nesting depth before a typed decline (Phase 12, §2).
max_xml_part_bytes: u64Maximum decoded byte length of a single XML part (Phase 12, §2).
max_xml_events: u64Maximum number of XML pull events in a single part (Phase 12, §2).
max_xml_nodes: u64Maximum number of XML element nodes in a single part (Phase 12, §2).
max_xml_attrs_per_element: u32Maximum number of attributes on a single XML element (Phase 12, §2).
max_xml_text_bytes: u64Maximum total text bytes accepted across a single XML part (Phase 12, §2).
max_opc_rels: u32Maximum relationships across all .rels parts (Phase 12, §3).
max_opc_rel_depth: u32Maximum internal relationship traversal depth (Phase 12 cycles, §3).
max_opc_content_types_overrides: u32Maximum Default+Override entries in [Content_Types].xml (Phase 12, §3).
max_opc_part_name_bytes: u32Maximum byte length of an OPC part name (Phase 12, §3).
max_epub_rootfiles: u32Maximum rootfile entries accepted in META-INF/container.xml (Phase 12, §4).
max_epub_manifest_items: u32Maximum Package Document manifest items accepted (Phase 12, §4).
max_epub_spine_items: u32Maximum Package Document spine itemrefs accepted (Phase 12, §4).
Maximum navigation-document nesting depth accepted (Phase 12, §4).
max_epub_fallback_chain: u32Maximum manifest fallback chain length followed (Phase 12, §4).
max_xhtml_nodes: u32Maximum XHTML element nodes accepted in one content/nav document (Phase 12, §4).
max_odt_manifest_entries: u32Maximum file-entry elements accepted in META-INF/manifest.xml (Phase 13.3).
max_odt_blocks: u32Maximum block elements accepted in one OpenDocument content part (Phase 13.3).
max_odt_notes: u32Maximum notes accepted in one OpenDocument content part (Phase 13.3).
max_ods_sheets: u32Maximum table:table sheets accepted in one OpenDocument spreadsheet
content part (Phase 21.3.1).
max_ods_cells: u64Maximum expanded grid slots accepted across one spreadsheet, after
table:number-rows-repeated/table:number-columns-repeated expansion
(Phase 21.3.1). Each expanded row charges at least one slot even when it
declares no cells, so an empty-row repeat bomb still declines. This is the
ODS analogue of the XLSX coordinate bound (ADR-0059): a repeated span is
bounded and the expanded count declines typed rather than allocating.
max_ods_repeated_span: u32Maximum repeat count admitted for a single
table:number-columns-repeated/table:number-rows-repeated attribute
(Phase 21.3.1). A declaration above this bound is a typed resource-limit
decline, never an allocation.
max_ods_merges: u32Maximum merged spans (table:number-columns-spanned>1 or
table:number-rows-spanned>1) accepted across one spreadsheet
(Phase 21.3.1).
max_ods_named_expressions: u32Maximum named expressions
(table:named-range/table:named-expression) accepted across one
spreadsheet (Phase 21.3.1).
max_ods_styles: u32Maximum style:style cell-style records accepted in one spreadsheet’s
automatic styles or styles part (Phase 21.3.1).
max_ods_comments: u32Maximum office:annotation cell comments accepted across one spreadsheet
(Phase 21.3.1).
max_xlsx_sheets: u32Maximum <sheet> declarations accepted in one workbook (Phase 21.1.1).
max_xlsx_cells: u64Maximum cells accepted in one worksheet part (Phase 21.1.1).
Maximum shared strings accepted in xl/sharedStrings.xml (Phase 21.1.1).
max_xlsx_merges: u32Maximum merged ranges accepted in one worksheet (Phase 21.1.1).
max_xlsx_hyperlinks: u32Maximum hyperlinks accepted in one worksheet (Phase 21.1.2).
max_xlsx_comments: u32Maximum comments accepted in one comments part (Phase 21.1.2).
max_xlsx_tables: u32Maximum table parts accepted across a workbook (Phase 21.1.2).
max_xlsx_table_columns: u32Maximum columns accepted in one table part (Phase 21.1.2).
max_xlsx_defined_names: u32Maximum defined/named ranges accepted in one workbook (Phase 21.1.2).
max_xlsx_drawings: u32Maximum drawing parts accepted across a workbook (Phase 21.1.2).
max_xlsx_style_records: u32Maximum style records (fonts/fills/cellXfs) accepted in styles.xml (Phase 21.1.2).
max_xlsx_col: u32Maximum 0-based column index accepted in a cell reference (Phase 21.1.2).
The Excel-conformant grid is 16,384 columns wide (A..XFD), so a valid
0-based column is < 16384; a coordinate at or beyond this bound is a
typed resource-limit decline. Bounding the coordinate here keeps a single
hostile reference from driving an unbounded projection downstream.
max_xlsx_row: u32Maximum 0-based row index accepted in a cell/row reference (Phase 21.1.2).
The Excel-conformant grid is 1,048,576 rows tall (1..1048576), so a valid
0-based row is < 1 << 20; a coordinate at or beyond this bound is a
typed resource-limit decline.
max_pptx_slides: u32Maximum slides accepted in one presentation (Phase 21.2.1).
max_pptx_shapes_per_slide: u32Maximum shapes accepted in one slide’s shape tree, including group descendants (Phase 21.2.1).
max_pptx_text_runs: u32Maximum text runs (a:t) accepted in one slide (Phase 21.2.1).
max_pptx_group_depth: u32Maximum group-shape nesting depth accepted in one slide (Phase 21.2.1).
max_pptx_media: u32Maximum media parts (images/audio/video) exposed by one presentation (Phase 21.2.1).
max_pptx_tables: u32Maximum embedded tables accepted in one slide (Phase 21.2.1).
max_pptx_table_cells: u32Maximum table cells accepted across one slide’s tables (Phase 21.2.1).
max_pptx_notes: u32Maximum notes-slide parts accepted in one presentation (Phase 21.2.1).
max_pptx_layouts: u32Maximum slide-layout parts accepted in one presentation (Phase 21.2.1).
max_pptx_masters: u32Maximum slide-master parts accepted in one presentation, and the bound applied to theme parts (Phase 21.2.1).
max_odp_slides: u32Maximum draw:page slides accepted in one OpenDocument presentation
content part (Phase 21.4.1).
max_odp_shapes_per_slide: u32Maximum shapes accepted in one slide, including group descendants (Phase 21.4.1).
max_odp_text_runs: u32Maximum text runs (text:span) accepted in one slide (Phase 21.4.1).
max_odp_group_depth: u32Maximum draw:g group nesting depth accepted in one slide (Phase 21.4.1).
max_odp_media: u32Maximum Pictures/* media parts exposed by one presentation (Phase 21.4.1).
max_odp_tables: u32Maximum embedded tables (table:table) accepted in one slide
(Phase 21.4.1).
max_odp_table_cells: u32Maximum table cells accepted across one slide’s tables, after
table:number-columns-repeated/table:number-rows-repeated expansion
(Phase 21.4.1). An over-large repeat declines typed rather than allocating.
max_odp_notes: u32Maximum notes pages (presentation:notes) accepted in one presentation
(Phase 21.4.1).
max_odp_masters: u32Maximum style:master-page master pages accepted, and the bound applied to
style:style records, in one presentation (Phase 21.4.1).
max_json_depth: u32Maximum JSON container nesting depth accepted (objects/arrays). A deeper document is not detected as JSON (and any direct parse declines typed) rather than risking unbounded recursion (Phase 21.5.1).
max_json_nodes: u32Maximum JSON nodes (values plus object member keys) accepted in one document. An over-large document declines typed rather than allocating (Phase 21.5.1).
max_json_string_bytes: u64Maximum total raw string-token bytes accepted across one JSON document (the bytes between the quotes, escapes included). A conservative upper bound on the decoded text (Phase 21.5.1).
max_json_document_bytes: u64Maximum source length admitted for byte-based JSON detection. Larger inputs
fall back to crate::field::document_format::DocumentFormat::Opaque
(Phase 21.5.1).
max_yaml_depth: u32Maximum YAML container nesting depth accepted (mappings/sequences). A deeper document is not detected as YAML (and any direct parse declines typed) rather than risking unbounded recursion (Phase 21.6.1).
max_yaml_nodes: u32Maximum YAML nodes (containers, scalars, aliases, empties) accepted in one stream. An over-large document declines typed rather than allocating (Phase 21.6.1).
max_yaml_scalars: u32Maximum YAML scalar nodes accepted in one stream (Phase 21.6.1).
max_yaml_anchors: u32Maximum YAML anchors (&a) accepted in one stream (Phase 21.6.1).
max_yaml_documents: u32Maximum documents accepted in one YAML stream (Phase 21.6.1).
max_yaml_string_bytes: u64Maximum total raw scalar-token bytes accepted across one YAML stream. A conservative upper bound on the decoded text (Phase 21.6.1).
max_yaml_document_bytes: u64Maximum source length admitted for byte-based YAML detection. Larger inputs
fall back to crate::field::document_format::DocumentFormat::Opaque
(Phase 21.6.1).