Skip to main content

Limits

Struct Limits 

Source
pub struct Limits {
Show 44 fields pub max_input_bytes: u64, pub max_output_bytes: u64, pub max_replay_bytes: u64, pub max_record_len: u32, pub max_record_count: u32, pub max_object_count: u32, pub max_graph_ops: u32, pub max_repeat_count: u64, pub max_channel_symbols: u64, pub max_model_count: u32, pub max_channel_count: u32, pub max_entropy_model_bytes: u32, pub max_pdf_spans: u32, pub max_index_selectors: u32, pub max_directory_bytes: u32, pub max_zip_members: u32, pub max_zip_member_compressed: u64, pub max_zip_member_uncompressed: u64, pub max_zip_aggregate_uncompressed: u64, pub max_zip_compression_ratio: u32, pub max_zip_name_bytes: u32, pub max_zip_extra_bytes: u32, pub max_zip_entry_comment_bytes: u32, pub max_zip_archive_comment_bytes: u32, pub max_zip_central_dir_bytes: u64, pub max_zip_prefix_bytes: u64, pub max_zip_trailing_bytes: u64, pub max_xml_depth: u32, pub max_xml_part_bytes: u64, pub max_xml_events: u64, pub max_xml_nodes: u64, pub max_xml_attrs_per_element: u32, pub max_xml_text_bytes: u64, pub max_xml_doctype: u32, pub max_opc_rels: u32, pub max_opc_rel_depth: u32, pub max_opc_content_types_overrides: u32, pub max_opc_part_name_bytes: u32, pub max_epub_rootfiles: u32, pub max_epub_manifest_items: u32, pub max_epub_spine_items: u32, pub max_epub_nav_depth: u32, pub max_epub_fallback_chain: u32, pub max_xhtml_nodes: u32,
}
Expand description

Hard upper bounds applied while parsing and materializing a descriptor.

Fields§

§max_input_bytes: u64

Maximum accepted source/descriptor input size.

§max_output_bytes: u64

Maximum reconstructed output size for a single materialization.

§max_replay_bytes: u64

Admission cap on the output of a single DEFLATE_REPLAY.

This is a VOLE replay-profile policy limit, not an RFC 1951 maximum. RFC 1951 permits arbitrarily many empty non-final stored blocks, so it gives no finite f(decompressed_size) bound on compressed_size; a bitstream that inflates to zero bytes may be arbitrarily large. VOLE therefore declines to replay a descriptor whose declared output exceeds this policy cap (see ADR-0016).

§max_record_len: u32

Maximum length of a single record payload.

§max_record_count: u32

Maximum number of records in a container.

§max_object_count: u32

Maximum number of distinct byte objects (OBJECT records).

§max_graph_ops: u32

Maximum number of DRA instructions in a reconstruction graph.

§max_repeat_count: u64

Maximum repeat count for a single REPEAT_LAST instruction.

§max_channel_symbols: u64

Maximum number of symbols in a single entropy channel.

§max_model_count: u32

Maximum number of distinct entropy models (MODEL records).

§max_channel_count: u32

Maximum number of entropy channels (ENTROPY_CHANNEL records).

§max_entropy_model_bytes: u32

Maximum encoded size of a single entropy model payload.

§max_pdf_spans: u32

Maximum number of lexical spans produced for a PDF input.

§max_index_selectors: u32

Maximum number of selectors in a single OBSERVATION_INDEX record.

Bounds the admissions of the optional partial-decode index (Phase 7.3) before allocation: an index whose selector table would exceed this is rejected at parse and declined by the index builder. It mirrors the object/graph scale so the table cannot dwarf the document it describes.

§max_directory_bytes: u32

Maximum accepted size of an optional DIRECTORY record payload.

Bounds the seek directory (Phase 8) before allocation: a directory larger than this is declined at decode rather than trusted. A directory is roughly 13 * record_count bytes, so this also caps the record count a directory can describe.

§max_zip_members: u32

Maximum number of ZIP members accepted in one archive (Phase 12, Z2).

§max_zip_member_compressed: u64

Maximum declared compressed size of a single ZIP member (Phase 12, Z1).

§max_zip_member_uncompressed: u64

Maximum declared uncompressed size of a single ZIP member (Phase 12, Z1).

§max_zip_aggregate_uncompressed: u64

Maximum sum of declared uncompressed sizes across all members (Z2).

§max_zip_compression_ratio: u32

Maximum declared uncompressed/compressed ratio for one member (Z1).

§max_zip_name_bytes: u32

Maximum raw name byte length of one member (Phase 12, Z13/Z14).

§max_zip_extra_bytes: u32

Maximum raw extra-field byte length of one member (Z7/Z14).

§max_zip_entry_comment_bytes: u32

Maximum per-entry comment byte length (Z14).

§max_zip_archive_comment_bytes: u32

Maximum archive comment byte length (Z14/Z15).

§max_zip_central_dir_bytes: u64

Maximum central-directory byte length (Z14).

§max_zip_prefix_bytes: u64

Maximum leading bytes before the first local header (Z14).

§max_zip_trailing_bytes: u64

Maximum trailing bytes after the EOCD record (Z14).

§max_xml_depth: u32

Maximum XML element nesting depth before a typed decline (Phase 12, §2).

§max_xml_part_bytes: u64

Maximum decoded byte length of a single XML part (Phase 12, §2).

§max_xml_events: u64

Maximum number of XML pull events in a single part (Phase 12, §2).

§max_xml_nodes: u64

Maximum number of XML element nodes in a single part (Phase 12, §2).

§max_xml_attrs_per_element: u32

Maximum number of attributes on a single XML element (Phase 12, §2).

§max_xml_text_bytes: u64

Maximum total text bytes accepted across a single XML part (Phase 12, §2).

§max_xml_doctype: u32

Maximum number of <!DOCTYPE declarations accepted (Phase 12: always 0).

§max_opc_rels: u32

Maximum relationships across all .rels parts (Phase 12, §3).

§max_opc_rel_depth: u32

Maximum internal relationship traversal depth (Phase 12 cycles, §3).

§max_opc_content_types_overrides: u32

Maximum Default+Override entries in [Content_Types].xml (Phase 12, §3).

§max_opc_part_name_bytes: u32

Maximum byte length of an OPC part name (Phase 12, §3).

§max_epub_rootfiles: u32

Maximum rootfile entries accepted in META-INF/container.xml (Phase 12, §4).

§max_epub_manifest_items: u32

Maximum Package Document manifest items accepted (Phase 12, §4).

§max_epub_spine_items: u32

Maximum Package Document spine itemrefs accepted (Phase 12, §4).

§max_epub_nav_depth: u32

Maximum navigation-document nesting depth accepted (Phase 12, §4).

§max_epub_fallback_chain: u32

Maximum manifest fallback chain length followed (Phase 12, §4).

§max_xhtml_nodes: u32

Maximum XHTML element nodes accepted in one content/nav document (Phase 12, §4).

Implementations§

Source§

impl Limits

Source

pub const DEFAULT: Limits

The default archival limits: generous, but always finite.

Source

pub const STRICT: Limits

Tight limits for hostile-input testing and fuzzing.

Trait Implementations§

Source§

impl Clone for Limits

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Limits

Source§

impl Debug for Limits

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Limits

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Eq for Limits

Source§

impl PartialEq for Limits

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Limits

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.