Skip to main content

Limits

Struct Limits 

Source
pub struct Limits {
Show 97 fields pub max_input_bytes: u64, pub max_output_bytes: u64, pub max_replay_bytes: u64, pub max_record_len: u32, pub max_record_count: u32, pub max_object_count: u32, pub max_graph_ops: u32, pub max_repeat_count: u64, pub max_channel_symbols: u64, pub max_model_count: u32, pub max_channel_count: u32, pub max_entropy_model_bytes: u32, pub max_pdf_spans: u32, pub max_index_selectors: u32, pub max_directory_bytes: u32, pub max_checkpoint_bytes: u32, pub max_zip_members: u32, pub max_zip_member_compressed: u64, pub max_zip_member_uncompressed: u64, pub max_zip_aggregate_uncompressed: u64, pub max_zip_compression_ratio: u32, pub max_zip_name_bytes: u32, pub max_zip_extra_bytes: u32, pub max_zip_entry_comment_bytes: u32, pub max_zip_archive_comment_bytes: u32, pub max_zip_central_dir_bytes: u64, pub max_zip_prefix_bytes: u64, pub max_zip_trailing_bytes: u64, pub max_xml_depth: u32, pub max_xml_part_bytes: u64, pub max_xml_events: u64, pub max_xml_nodes: u64, pub max_xml_attrs_per_element: u32, pub max_xml_text_bytes: u64, pub max_opc_rels: u32, pub max_opc_rel_depth: u32, pub max_opc_content_types_overrides: u32, pub max_opc_part_name_bytes: u32, pub max_epub_rootfiles: u32, pub max_epub_manifest_items: u32, pub max_epub_spine_items: u32, pub max_epub_nav_depth: u32, pub max_epub_fallback_chain: u32, pub max_xhtml_nodes: u32, pub max_odt_manifest_entries: u32, pub max_odt_blocks: u32, pub max_odt_notes: u32, pub max_ods_sheets: u32, pub max_ods_cells: u64, pub max_ods_repeated_span: u32, pub max_ods_merges: u32, pub max_ods_named_expressions: u32, pub max_ods_styles: u32, pub max_ods_comments: u32, pub max_xlsx_sheets: u32, pub max_xlsx_cells: u64, pub max_xlsx_shared_strings: u32, pub max_xlsx_merges: u32, pub max_xlsx_hyperlinks: u32, pub max_xlsx_comments: u32, pub max_xlsx_tables: u32, pub max_xlsx_table_columns: u32, pub max_xlsx_defined_names: u32, pub max_xlsx_drawings: u32, pub max_xlsx_style_records: u32, pub max_xlsx_col: u32, pub max_xlsx_row: u32, pub max_pptx_slides: u32, pub max_pptx_shapes_per_slide: u32, pub max_pptx_text_runs: u32, pub max_pptx_group_depth: u32, pub max_pptx_media: u32, pub max_pptx_tables: u32, pub max_pptx_table_cells: u32, pub max_pptx_notes: u32, pub max_pptx_layouts: u32, pub max_pptx_masters: u32, pub max_odp_slides: u32, pub max_odp_shapes_per_slide: u32, pub max_odp_text_runs: u32, pub max_odp_group_depth: u32, pub max_odp_media: u32, pub max_odp_tables: u32, pub max_odp_table_cells: u32, pub max_odp_notes: u32, pub max_odp_masters: u32, pub max_json_depth: u32, pub max_json_nodes: u32, pub max_json_string_bytes: u64, pub max_json_document_bytes: u64, pub max_yaml_depth: u32, pub max_yaml_nodes: u32, pub max_yaml_scalars: u32, pub max_yaml_anchors: u32, pub max_yaml_documents: u32, pub max_yaml_string_bytes: u64, pub max_yaml_document_bytes: u64,
}
Expand description

Hard upper bounds applied while parsing and materializing a descriptor.

Fields§

§max_input_bytes: u64

Maximum accepted source/descriptor input size.

§max_output_bytes: u64

Maximum reconstructed output size for a single materialization.

§max_replay_bytes: u64

Admission cap on the output of a single DEFLATE_REPLAY.

This is a VOLE replay-profile policy limit, not an RFC 1951 maximum. RFC 1951 permits arbitrarily many empty non-final stored blocks, so it gives no finite f(decompressed_size) bound on compressed_size; a bitstream that inflates to zero bytes may be arbitrarily large. VOLE therefore declines to replay a descriptor whose declared output exceeds this policy cap (see ADR-0016).

§max_record_len: u32

Maximum length of a single record payload.

§max_record_count: u32

Maximum number of records in a container.

§max_object_count: u32

Maximum number of distinct byte objects (OBJECT records).

§max_graph_ops: u32

Maximum number of DRA instructions in a reconstruction graph.

§max_repeat_count: u64

Maximum repeat count for a single REPEAT_LAST instruction.

§max_channel_symbols: u64

Maximum number of symbols in a single entropy channel.

§max_model_count: u32

Maximum number of distinct entropy models (MODEL records).

§max_channel_count: u32

Maximum number of entropy channels (ENTROPY_CHANNEL records).

§max_entropy_model_bytes: u32

Maximum encoded size of a single entropy model payload.

§max_pdf_spans: u32

Maximum number of lexical spans produced for a PDF input.

§max_index_selectors: u32

Maximum number of selectors in a single OBSERVATION_INDEX record.

Bounds the admissions of the optional partial-decode index (Phase 7.3) before allocation: an index whose selector table would exceed this is rejected at parse and declined by the index builder. It mirrors the object/graph scale so the table cannot dwarf the document it describes.

§max_directory_bytes: u32

Maximum accepted size of an optional DIRECTORY record payload.

Bounds the seek directory (Phase 8) before allocation: a directory larger than this is declined at decode rather than trusted. A directory is roughly 13 * record_count bytes, so this also caps the record count a directory can describe.

§max_checkpoint_bytes: u32

Maximum accepted size of an optional CHECKPOINT record payload.

Bounds the byte-level partial-materialization checkpoint (Phase 13.4) before allocation: a checkpoint larger than this is declined at decode rather than trusted. A checkpoint is 20 + 16 * op_count bytes, so this also caps the op count a checkpoint can describe.

§max_zip_members: u32

Maximum number of ZIP members accepted in one archive (Phase 12, Z2).

§max_zip_member_compressed: u64

Maximum declared compressed size of a single ZIP member (Phase 12, Z1).

§max_zip_member_uncompressed: u64

Maximum declared uncompressed size of a single ZIP member (Phase 12, Z1).

§max_zip_aggregate_uncompressed: u64

Maximum sum of declared uncompressed sizes across all members (Z2).

§max_zip_compression_ratio: u32

Maximum declared uncompressed/compressed ratio for one member (Z1).

§max_zip_name_bytes: u32

Maximum raw name byte length of one member (Phase 12, Z13/Z14).

§max_zip_extra_bytes: u32

Maximum raw extra-field byte length of one member (Z7/Z14).

§max_zip_entry_comment_bytes: u32

Maximum per-entry comment byte length (Z14).

§max_zip_archive_comment_bytes: u32

Maximum archive comment byte length (Z14/Z15).

§max_zip_central_dir_bytes: u64

Maximum central-directory byte length (Z14).

§max_zip_prefix_bytes: u64

Maximum leading bytes before the first local header (Z14).

§max_zip_trailing_bytes: u64

Maximum trailing bytes after the EOCD record (Z14).

§max_xml_depth: u32

Maximum XML element nesting depth before a typed decline (Phase 12, §2).

§max_xml_part_bytes: u64

Maximum decoded byte length of a single XML part (Phase 12, §2).

§max_xml_events: u64

Maximum number of XML pull events in a single part (Phase 12, §2).

§max_xml_nodes: u64

Maximum number of XML element nodes in a single part (Phase 12, §2).

§max_xml_attrs_per_element: u32

Maximum number of attributes on a single XML element (Phase 12, §2).

§max_xml_text_bytes: u64

Maximum total text bytes accepted across a single XML part (Phase 12, §2).

§max_opc_rels: u32

Maximum relationships across all .rels parts (Phase 12, §3).

§max_opc_rel_depth: u32

Maximum internal relationship traversal depth (Phase 12 cycles, §3).

§max_opc_content_types_overrides: u32

Maximum Default+Override entries in [Content_Types].xml (Phase 12, §3).

§max_opc_part_name_bytes: u32

Maximum byte length of an OPC part name (Phase 12, §3).

§max_epub_rootfiles: u32

Maximum rootfile entries accepted in META-INF/container.xml (Phase 12, §4).

§max_epub_manifest_items: u32

Maximum Package Document manifest items accepted (Phase 12, §4).

§max_epub_spine_items: u32

Maximum Package Document spine itemrefs accepted (Phase 12, §4).

§max_epub_nav_depth: u32

Maximum navigation-document nesting depth accepted (Phase 12, §4).

§max_epub_fallback_chain: u32

Maximum manifest fallback chain length followed (Phase 12, §4).

§max_xhtml_nodes: u32

Maximum XHTML element nodes accepted in one content/nav document (Phase 12, §4).

§max_odt_manifest_entries: u32

Maximum file-entry elements accepted in META-INF/manifest.xml (Phase 13.3).

§max_odt_blocks: u32

Maximum block elements accepted in one OpenDocument content part (Phase 13.3).

§max_odt_notes: u32

Maximum notes accepted in one OpenDocument content part (Phase 13.3).

§max_ods_sheets: u32

Maximum table:table sheets accepted in one OpenDocument spreadsheet content part (Phase 21.3.1).

§max_ods_cells: u64

Maximum expanded grid slots accepted across one spreadsheet, after table:number-rows-repeated/table:number-columns-repeated expansion (Phase 21.3.1). Each expanded row charges at least one slot even when it declares no cells, so an empty-row repeat bomb still declines. This is the ODS analogue of the XLSX coordinate bound (ADR-0059): a repeated span is bounded and the expanded count declines typed rather than allocating.

§max_ods_repeated_span: u32

Maximum repeat count admitted for a single table:number-columns-repeated/table:number-rows-repeated attribute (Phase 21.3.1). A declaration above this bound is a typed resource-limit decline, never an allocation.

§max_ods_merges: u32

Maximum merged spans (table:number-columns-spanned>1 or table:number-rows-spanned>1) accepted across one spreadsheet (Phase 21.3.1).

§max_ods_named_expressions: u32

Maximum named expressions (table:named-range/table:named-expression) accepted across one spreadsheet (Phase 21.3.1).

§max_ods_styles: u32

Maximum style:style cell-style records accepted in one spreadsheet’s automatic styles or styles part (Phase 21.3.1).

§max_ods_comments: u32

Maximum office:annotation cell comments accepted across one spreadsheet (Phase 21.3.1).

§max_xlsx_sheets: u32

Maximum <sheet> declarations accepted in one workbook (Phase 21.1.1).

§max_xlsx_cells: u64

Maximum cells accepted in one worksheet part (Phase 21.1.1).

§max_xlsx_shared_strings: u32

Maximum shared strings accepted in xl/sharedStrings.xml (Phase 21.1.1).

§max_xlsx_merges: u32

Maximum merged ranges accepted in one worksheet (Phase 21.1.1).

§max_xlsx_hyperlinks: u32

Maximum hyperlinks accepted in one worksheet (Phase 21.1.2).

§max_xlsx_comments: u32

Maximum comments accepted in one comments part (Phase 21.1.2).

§max_xlsx_tables: u32

Maximum table parts accepted across a workbook (Phase 21.1.2).

§max_xlsx_table_columns: u32

Maximum columns accepted in one table part (Phase 21.1.2).

§max_xlsx_defined_names: u32

Maximum defined/named ranges accepted in one workbook (Phase 21.1.2).

§max_xlsx_drawings: u32

Maximum drawing parts accepted across a workbook (Phase 21.1.2).

§max_xlsx_style_records: u32

Maximum style records (fonts/fills/cellXfs) accepted in styles.xml (Phase 21.1.2).

§max_xlsx_col: u32

Maximum 0-based column index accepted in a cell reference (Phase 21.1.2).

The Excel-conformant grid is 16,384 columns wide (A..XFD), so a valid 0-based column is < 16384; a coordinate at or beyond this bound is a typed resource-limit decline. Bounding the coordinate here keeps a single hostile reference from driving an unbounded projection downstream.

§max_xlsx_row: u32

Maximum 0-based row index accepted in a cell/row reference (Phase 21.1.2).

The Excel-conformant grid is 1,048,576 rows tall (1..1048576), so a valid 0-based row is < 1 << 20; a coordinate at or beyond this bound is a typed resource-limit decline.

§max_pptx_slides: u32

Maximum slides accepted in one presentation (Phase 21.2.1).

§max_pptx_shapes_per_slide: u32

Maximum shapes accepted in one slide’s shape tree, including group descendants (Phase 21.2.1).

§max_pptx_text_runs: u32

Maximum text runs (a:t) accepted in one slide (Phase 21.2.1).

§max_pptx_group_depth: u32

Maximum group-shape nesting depth accepted in one slide (Phase 21.2.1).

§max_pptx_media: u32

Maximum media parts (images/audio/video) exposed by one presentation (Phase 21.2.1).

§max_pptx_tables: u32

Maximum embedded tables accepted in one slide (Phase 21.2.1).

§max_pptx_table_cells: u32

Maximum table cells accepted across one slide’s tables (Phase 21.2.1).

§max_pptx_notes: u32

Maximum notes-slide parts accepted in one presentation (Phase 21.2.1).

§max_pptx_layouts: u32

Maximum slide-layout parts accepted in one presentation (Phase 21.2.1).

§max_pptx_masters: u32

Maximum slide-master parts accepted in one presentation, and the bound applied to theme parts (Phase 21.2.1).

§max_odp_slides: u32

Maximum draw:page slides accepted in one OpenDocument presentation content part (Phase 21.4.1).

§max_odp_shapes_per_slide: u32

Maximum shapes accepted in one slide, including group descendants (Phase 21.4.1).

§max_odp_text_runs: u32

Maximum text runs (text:span) accepted in one slide (Phase 21.4.1).

§max_odp_group_depth: u32

Maximum draw:g group nesting depth accepted in one slide (Phase 21.4.1).

§max_odp_media: u32

Maximum Pictures/* media parts exposed by one presentation (Phase 21.4.1).

§max_odp_tables: u32

Maximum embedded tables (table:table) accepted in one slide (Phase 21.4.1).

§max_odp_table_cells: u32

Maximum table cells accepted across one slide’s tables, after table:number-columns-repeated/table:number-rows-repeated expansion (Phase 21.4.1). An over-large repeat declines typed rather than allocating.

§max_odp_notes: u32

Maximum notes pages (presentation:notes) accepted in one presentation (Phase 21.4.1).

§max_odp_masters: u32

Maximum style:master-page master pages accepted, and the bound applied to style:style records, in one presentation (Phase 21.4.1).

§max_json_depth: u32

Maximum JSON container nesting depth accepted (objects/arrays). A deeper document is not detected as JSON (and any direct parse declines typed) rather than risking unbounded recursion (Phase 21.5.1).

§max_json_nodes: u32

Maximum JSON nodes (values plus object member keys) accepted in one document. An over-large document declines typed rather than allocating (Phase 21.5.1).

§max_json_string_bytes: u64

Maximum total raw string-token bytes accepted across one JSON document (the bytes between the quotes, escapes included). A conservative upper bound on the decoded text (Phase 21.5.1).

§max_json_document_bytes: u64

Maximum source length admitted for byte-based JSON detection. Larger inputs fall back to crate::field::document_format::DocumentFormat::Opaque (Phase 21.5.1).

§max_yaml_depth: u32

Maximum YAML container nesting depth accepted (mappings/sequences). A deeper document is not detected as YAML (and any direct parse declines typed) rather than risking unbounded recursion (Phase 21.6.1).

§max_yaml_nodes: u32

Maximum YAML nodes (containers, scalars, aliases, empties) accepted in one stream. An over-large document declines typed rather than allocating (Phase 21.6.1).

§max_yaml_scalars: u32

Maximum YAML scalar nodes accepted in one stream (Phase 21.6.1).

§max_yaml_anchors: u32

Maximum YAML anchors (&a) accepted in one stream (Phase 21.6.1).

§max_yaml_documents: u32

Maximum documents accepted in one YAML stream (Phase 21.6.1).

§max_yaml_string_bytes: u64

Maximum total raw scalar-token bytes accepted across one YAML stream. A conservative upper bound on the decoded text (Phase 21.6.1).

§max_yaml_document_bytes: u64

Maximum source length admitted for byte-based YAML detection. Larger inputs fall back to crate::field::document_format::DocumentFormat::Opaque (Phase 21.6.1).

Implementations§

Source§

impl Limits

Source

pub const DEFAULT: Limits

The default archival limits: generous, but always finite.

Source

pub const STRICT: Limits

Tight limits for hostile-input testing and fuzzing.

Trait Implementations§

Source§

impl Clone for Limits

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Limits

Source§

impl Debug for Limits

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Limits

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Eq for Limits

Source§

impl PartialEq for Limits

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Limits

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.