diff --git a/.gitattributes b/.gitattributes
index 809e6bf..6fbfe04 100644
--- a/.gitattributes
+++ b/.gitattributes
@@ -1,4 +1,5 @@
# Vendored protocol test vectors are byte-exact artifacts, sha256-pinned by
-# tests/wire_format_vectors.rs — never let git rewrite their line endings
-# (windows runners set core.autocrlf=true and would break the pin).
+# tests/wire_format_vectors.rs and tests/decode_bounds_vectors.rs — never let
+# git rewrite their line endings (windows runners set core.autocrlf=true and
+# would break the pin).
tests/vectors/* -text
diff --git a/README.md b/README.md
index 24332fe..02647ed 100644
--- a/README.md
+++ b/README.md
@@ -247,6 +247,19 @@ Malicious payloads claiming `original_size: 500GB` with 100 bytes of data are re
+
+Envelope Decode Bounds
+
+`retrieve()` and `validate()` run a header-only structural pre-scan over the
+envelope bytes **before** MessagePack decoding: nesting deeper than 100 levels,
+headers declaring more elements or bytes than the input can back, the reserved
+marker `0xc1` and truncated input are all rejected before decoding, without
+allocating in proportion to any declared length. A rejection is
+`ByteStorageError::DeserializationFailed` with the message prefix
+`decode pre-scan: `. See [`SECURITY.md`](SECURITY.md#envelope-decode-bounds).
+
+
+
---
## Architecture
@@ -256,6 +269,7 @@ cachekit-core/
├── src/
│ ├── lib.rs # Public API exports
│ ├── byte_storage.rs # LZ4 + xxHash3 storage envelope
+│ ├── msgpack_bounds.rs # Structural pre-scan run before the envelope decode
│ ├── checksum.rs # Standalone xxHash3 checksum/verify primitive (feature = "checksum")
│ ├── metrics.rs # Operation timing & statistics
│ │
@@ -351,6 +365,12 @@ including bin16/bin32 width headers. The fixture is vendored at
it, re-copy from the protocol repo and change the pinned hash in the same
commit.
+`tests/decode_bounds_vectors.rs` drives every reject and accept vector in the
+protocol's `test-vectors/decode-bounds.json` (vendored the same way, at
+`tests/vectors/decode-bounds.json`) through `retrieve()`. Each reject vector
+must fail with the pre-scan's `decode pre-scan: ` message prefix; failing
+somewhere inside the decoder does not count.
+
---
## Minimum Supported Rust Version
diff --git a/SECURITY.md b/SECURITY.md
index f0191a1..11eed3c 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -120,6 +120,38 @@ from an empty corpus. The Kani harnesses never run on pull requests, never
execute `StorageEnvelope::extract`, and cannot detect a wrong predicate. Treat both as
smoke checks, not as verification of the bound.
+### Envelope decode bounds
+
+`ByteStorage::retrieve` and `ByteStorage::validate` decode envelope bytes that
+come from a backend the caller may not control. Before `rmp_serde` materialises
+a `StorageEnvelope`, both run a header-only structural pre-scan over those bytes
+(protocol `spec/wire-format.md` → Retrieve Flow, step 2; the bounds themselves
+are `spec/interop-mode.md` → Decode bounds). The pre-scan rejects:
+
+| Rule | Bound |
+|:-----|:------|
+| Nesting depth | 100 levels; every array or map header on a path counts, an empty one included |
+| Declared slots | pending collection elements never exceed the bytes left to back them; str/bin/ext lengths never exceed the bytes left |
+| Framing | the reserved marker `0xc1`, and input that ends before the document is complete |
+
+A legitimate envelope nests two levels deep, so the depth bound only ever
+rejects forged input. It still matters: serde's derive skips an unknown map key
+with a recursive `IgnoredAny`, so without the pre-scan the input, not this
+crate, would set how deep the decode recurses. All counts are `u64`, and the
+walk skips str/bin/ext payloads by offset: it allocates one `u64` per open
+collection and nothing proportional to a declared length.
+
+A rejection is `ByteStorageError::DeserializationFailed` with a message that
+starts with `decode pre-scan: `, the same variant as any other bytes that do
+not decode as an envelope, so bindings that map on the variant see no change.
+Trailing bytes after the envelope are still ignored, as before.
+
+`tests/decode_bounds_vectors.rs` drives every vector in the protocol's
+`test-vectors/decode-bounds.json` (vendored sha256-pinned in `tests/vectors/`)
+through `retrieve`, and asserts the pre-scan's message prefix, not merely that
+the call fails. As with the size bound above, a caller that deserializes
+`StorageEnvelope` directly bypasses the pre-scan and must impose its own.
+
### Dependencies
Security-critical dependencies are audited via `cargo-deny`:
diff --git a/src/byte_storage.rs b/src/byte_storage.rs
index 2029b55..aa7ba9c 100644
--- a/src/byte_storage.rs
+++ b/src/byte_storage.rs
@@ -218,6 +218,15 @@ impl ByteStorage {
/// Retrieve and validate stored bytes
///
/// Returns (original_data, format_identifier)
+ ///
+ /// # Errors
+ ///
+ /// `envelope_bytes` is untrusted. Before it is decoded, a structural
+ /// pre-scan bounds its nesting depth and rejects any header that declares
+ /// more than the input can back (protocol Retrieve Flow, step 2). A
+ /// pre-scan rejection is `DeserializationFailed` whose message starts with
+ /// `decode pre-scan: `, the same variant as any other bytes that do not
+ /// decode as a `StorageEnvelope`.
#[cfg(all(feature = "compression", feature = "checksum", feature = "messagepack"))]
pub fn retrieve(&self, envelope_bytes: &[u8]) -> Result<(Vec, String), ByteStorageError> {
// Security: Check envelope size before deserializing
@@ -225,9 +234,7 @@ impl ByteStorage {
return Err(ByteStorageError::InputTooLarge);
}
- // Deserialize envelope
- let envelope: StorageEnvelope = rmp_serde::from_slice(envelope_bytes)
- .map_err(|e| ByteStorageError::DeserializationFailed(e.to_string()))?;
+ let envelope = decode_envelope(envelope_bytes)?;
// Time decompression and checksum operations (wasm32: Instant unavailable, use 0)
#[cfg(not(target_arch = "wasm32"))]
@@ -282,7 +289,7 @@ impl ByteStorage {
return false; // Invalid due to size limit
}
- match rmp_serde::from_slice::(envelope_bytes) {
+ match decode_envelope(envelope_bytes) {
Ok(envelope) => envelope.extract().is_ok(),
Err(_) => false,
}
@@ -318,6 +325,20 @@ impl Default for ByteStorage {
}
}
+/// Decode untrusted envelope bytes: structural pre-scan first, then the typed
+/// decode. Serde's derive skips an unknown map key with `IgnoredAny`, which
+/// recurses, so the depth bound has to hold before `rmp_serde` sees the bytes.
+#[cfg(all(feature = "compression", feature = "checksum", feature = "messagepack"))]
+fn decode_envelope(envelope_bytes: &[u8]) -> Result {
+ use crate::msgpack_bounds::{check_msgpack_structure, MAX_DEPTH};
+
+ check_msgpack_structure(envelope_bytes, MAX_DEPTH).map_err(|what| {
+ ByteStorageError::DeserializationFailed(format!("decode pre-scan: {what}"))
+ })?;
+ rmp_serde::from_slice(envelope_bytes)
+ .map_err(|e| ByteStorageError::DeserializationFailed(e.to_string()))
+}
+
#[cfg(all(
test,
feature = "compression",
diff --git a/src/lib.rs b/src/lib.rs
index 24d8645..7f97dcf 100644
--- a/src/lib.rs
+++ b/src/lib.rs
@@ -73,6 +73,8 @@ pub use checksum::{checksum, verify_checksum};
// Core byte storage layer
pub mod byte_storage;
+#[cfg(all(feature = "compression", feature = "checksum", feature = "messagepack"))]
+mod msgpack_bounds;
pub use byte_storage::{ByteStorage, StorageEnvelope};
// Encryption module (feature-gated)
diff --git a/src/msgpack_bounds.rs b/src/msgpack_bounds.rs
new file mode 100644
index 0000000..7a89b9d
--- /dev/null
+++ b/src/msgpack_bounds.rs
@@ -0,0 +1,255 @@
+//! Structural pre-scan for untrusted MessagePack.
+//!
+//! `ByteStorage::retrieve` runs this over the envelope bytes before
+//! `rmp_serde` materialises a `StorageEnvelope` (protocol `spec/wire-format.md`
+//! → Retrieve Flow, step 2; the bounds are `spec/interop-mode.md` → Decode
+//! bounds, pinned by `tests/vectors/decode-bounds.json`). The opcode table
+//! matches cachekit-py's `check_msgpack_structure` and cachekit-rs's
+//! `check_structure`. Unlike cachekit-py's walk, this one counts an empty
+//! collection as a nesting level, which is how the spec defines depth;
+//! cachekit-rs bounds depth in `rmp_serde` rather than in its walk.
+
+/// Nesting bound for the envelope decode. The protocol requires 32..=1024; 100
+/// matches cachekit-rs and cachekit-ts. A legitimate envelope nests 2 deep.
+pub(crate) const MAX_DEPTH: usize = 100;
+
+/// Header-only walk over one MessagePack document: str/bin/ext payloads are
+/// skipped by offset, never read, and nothing is allocated beyond one `u64`
+/// per open collection (at most `max_depth`).
+///
+/// Trailing bytes after the root element are left to the decoder.
+///
+/// # Errors
+///
+/// Names the violated bound, before any decoder pre-allocates a container, for:
+/// - nesting deeper than `max_depth`, counting every array or map header on
+/// the path (an empty one included);
+/// - a header declaring more payload bytes than the input holds;
+/// - more pending elements (across every open collection) than the remaining
+/// bytes can back. Every element costs at least one byte, so a decoder's
+/// total container pre-allocation is bounded by the input length rather
+/// than by `depth × declared length`;
+/// - the reserved marker `0xc1`, and input that ends mid-document.
+pub(crate) fn check_msgpack_structure(bytes: &[u8], max_depth: usize) -> Result<(), String> {
+ fn be(bytes: &[u8], pos: usize, width: usize) -> Result {
+ let end = pos
+ .checked_add(width)
+ .filter(|e| *e <= bytes.len())
+ .ok_or_else(|| "ends inside a length prefix".to_owned())?;
+ Ok(bytes[pos..end]
+ .iter()
+ .fold(0u64, |acc, b| (acc << 8) | u64::from(*b)))
+ }
+
+ let mut pos = 0usize;
+ let mut pending: u64 = 1; // elements owed across all open collections (the root is one)
+ let mut open: Vec = Vec::new(); // elements still owed per open collection = depth
+ while pending > 0 {
+ while open.last() == Some(&0) {
+ open.pop();
+ }
+ let marker = *bytes
+ .get(pos)
+ .ok_or_else(|| "ends before the document is complete".to_owned())?;
+ pos += 1;
+ pending -= 1;
+ if let Some(innermost) = open.last_mut() {
+ *innermost -= 1;
+ }
+ // (length-prefix bytes, payload bytes after the prefix, child elements)
+ let (prefix, payload, children): (usize, u64, u64) = match marker {
+ 0x00..=0x7f | 0xc0 | 0xc2 | 0xc3 | 0xe0..=0xff => (0, 0, 0),
+ 0x80..=0x8f => (0, 0, 2 * u64::from(marker & 0x0f)),
+ 0x90..=0x9f => (0, 0, u64::from(marker & 0x0f)),
+ 0xa0..=0xbf => (0, u64::from(marker & 0x1f), 0),
+ 0xc1 => return Err("contains the reserved marker 0xc1".to_owned()),
+ 0xc4 | 0xd9 => (1, be(bytes, pos, 1)?, 0),
+ 0xc5 | 0xda => (2, be(bytes, pos, 2)?, 0),
+ 0xc6 | 0xdb => (4, be(bytes, pos, 4)?, 0),
+ 0xc7 => (1, be(bytes, pos, 1)? + 1, 0), // ext: length prefix, then type byte + data
+ 0xc8 => (2, be(bytes, pos, 2)? + 1, 0),
+ 0xc9 => (4, be(bytes, pos, 4)? + 1, 0),
+ 0xca..=0xd3 => (0, 1u64 << (marker & 0x03), 0), // f32/f64/u8..u64/i8..i64: 4,8,1,2,4,8,1,2,4,8
+ 0xd4..=0xd8 => (0, 1 + (1u64 << (marker - 0xd4)), 0), // fixext: type byte + 1/2/4/8/16
+ 0xdc => (2, 0, be(bytes, pos, 2)?),
+ 0xdd => (4, 0, be(bytes, pos, 4)?),
+ 0xde => (2, 0, 2 * be(bytes, pos, 2)?),
+ 0xdf => (4, 0, 2 * be(bytes, pos, 4)?),
+ };
+ // An empty collection is still a level (spec: depth counts collection
+ // headers), so the bound is checked before the `children > 0` push.
+ if matches!(marker, 0x80..=0x9f | 0xdc..=0xdf) && open.len() >= max_depth {
+ return Err(format!("nests deeper than {max_depth} levels"));
+ }
+ pos += prefix;
+ let remaining = (bytes.len() - pos) as u64;
+ if payload > remaining {
+ return Err("declares more bytes than the input holds".to_owned());
+ }
+ // Unreachable while the check above holds (`remaining` came from a
+ // usize); checked rather than cast so a future edit cannot truncate.
+ pos += usize::try_from(payload)
+ .map_err(|_| "declares more bytes than the input holds".to_owned())?;
+ if children > 0 {
+ open.push(children);
+ }
+ pending += children;
+ if pending > remaining - payload {
+ return Err("declares more elements than the input can back".to_owned());
+ }
+ }
+ Ok(())
+}
+
+#[cfg(test)]
+mod tests {
+ use super::*;
+
+ fn check(bytes: &[u8]) -> Result<(), String> {
+ check_msgpack_structure(bytes, MAX_DEPTH)
+ }
+
+ /// `count` copies of a collection header, then `tail`.
+ fn nested(header: &[u8], count: usize, tail: &[u8]) -> Vec {
+ [header.repeat(count), tail.to_vec()].concat()
+ }
+
+ /// (one level of nesting: fixarray(1) or fixmap(1) with key "", its empty form)
+ const LEVELS: [(&[u8], u8); 2] = [(&[0x91], 0x90), (&[0x81, 0xa0], 0x80)];
+
+ #[test]
+ fn accepts_every_scalar_marker_class() {
+ let docs: &[&[u8]] = &[
+ &[0x00],
+ &[0x7f],
+ &[0xe0],
+ &[0xff],
+ &[0xc0],
+ &[0xc2],
+ &[0xc3],
+ &[0xa3, b'a', b'b', b'c'],
+ &[0xd9, 0x01, b'x'],
+ &[0xda, 0x00, 0x01, b'x'],
+ &[0xdb, 0x00, 0x00, 0x00, 0x01, b'x'],
+ &[0xc4, 0x02, 0x01, 0x02],
+ &[0xc5, 0x00, 0x00],
+ &[0xc6, 0x00, 0x00, 0x00, 0x00],
+ &[0xc7, 0x01, 0x05, 0xaa],
+ &[0xc8, 0x00, 0x00, 0x05],
+ &[0xc9, 0x00, 0x00, 0x00, 0x00, 0x05],
+ &[0xca, 0, 0, 0, 0],
+ &[0xcb, 0, 0, 0, 0, 0, 0, 0, 0],
+ &[0xcc, 0],
+ &[0xcd, 0, 0],
+ &[0xce, 0, 0, 0, 0],
+ &[0xcf, 0, 0, 0, 0, 0, 0, 0, 0],
+ &[0xd0, 0],
+ &[0xd1, 0, 0],
+ &[0xd2, 0, 0, 0, 0],
+ &[0xd3, 0, 0, 0, 0, 0, 0, 0, 0],
+ &[0xd4, 0x05, 0],
+ &[0xd8, 0x05, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0],
+ &[0xdc, 0x00, 0x01, 0xc0],
+ &[0xdd, 0x00, 0x00, 0x00, 0x01, 0xc0],
+ &[0xde, 0x00, 0x01, 0xa0, 0xc0],
+ &[0xdf, 0x00, 0x00, 0x00, 0x01, 0xa0, 0xc0],
+ ];
+ for doc in docs {
+ assert_eq!(check(doc), Ok(()), "{doc:02x?}");
+ }
+ }
+
+ #[test]
+ fn rejects_every_truncation_of_a_fixed_width_marker() {
+ let docs: &[&[u8]] = &[
+ &[0xd9],
+ &[0xda, 0x00],
+ &[0xdb, 0x00, 0x00, 0x00],
+ &[0xc7],
+ &[0xcb, 0, 0, 0, 0, 0, 0, 0],
+ &[0xd8, 0x05, 0],
+ &[0xdd, 0x00, 0x00],
+ &[0xa3, b'a', b'b'],
+ &[],
+ ];
+ for doc in docs {
+ assert!(check(doc).is_err(), "{doc:02x?}");
+ }
+ }
+
+ #[test]
+ fn rejects_the_reserved_marker() {
+ assert_eq!(
+ check(&[0x91, 0xc1]),
+ Err("contains the reserved marker 0xc1".to_owned())
+ );
+ }
+
+ #[test]
+ fn leaves_trailing_bytes_to_the_decoder() {
+ assert_eq!(check(&[0xc0, 0xc1, 0xff]), Ok(()));
+ }
+
+ #[test]
+ fn depth_bound_is_inclusive_for_arrays_and_maps() {
+ let too_deep = Err(format!("nests deeper than {MAX_DEPTH} levels"));
+ for (header, _) in LEVELS {
+ assert_eq!(check(&nested(header, MAX_DEPTH, &[0xc0])), Ok(()));
+ assert_eq!(check(&nested(header, MAX_DEPTH + 1, &[0xc0])), too_deep);
+ }
+ }
+
+ #[test]
+ fn an_empty_innermost_collection_counts_as_a_level() {
+ let too_deep = Err(format!("nests deeper than {MAX_DEPTH} levels"));
+ for (header, empty) in LEVELS {
+ assert_eq!(check(&nested(header, MAX_DEPTH - 1, &[empty])), Ok(()));
+ assert_eq!(check(&nested(header, MAX_DEPTH, &[empty])), too_deep);
+ }
+ }
+
+ #[test]
+ fn map_pairs_cost_two_slots() {
+ assert_eq!(check(&[0x81, 0xa0, 0xc0]), Ok(()));
+ assert!(check(&[0x81, 0xa0]).is_err());
+ }
+
+ #[test]
+ fn widest_claims_do_not_overflow() {
+ // 2^32 − 1 pairs (2 × (2^32 − 1) slots) and a u32::MAX ext length,
+ // computed in u64.
+ assert_eq!(
+ check(&[0xdf, 0xff, 0xff, 0xff, 0xff]),
+ Err("declares more elements than the input can back".to_owned())
+ );
+ assert_eq!(
+ check(&[0xc9, 0xff, 0xff, 0xff, 0xff, 0x05]),
+ Err("declares more bytes than the input holds".to_owned())
+ );
+ }
+
+ #[test]
+ fn every_real_envelope_and_every_strict_prefix_of_one() {
+ // The walk admits what writers emit, and nothing that ends early:
+ // every strict prefix of a complete document is incomplete.
+ let storage = crate::ByteStorage::new(None);
+ let bin = storage
+ .store(b"pre-scan admits real envelopes", None)
+ .unwrap();
+ let e: crate::StorageEnvelope = rmp_serde::from_slice(&bin).unwrap();
+ // Legacy writers encoded `compressed_data` as an array of ints.
+ let legacy =
+ rmp_serde::to_vec(&(&e.compressed_data, e.checksum, e.original_size, &e.format))
+ .unwrap();
+ assert!(storage.retrieve(&legacy).is_ok());
+ for doc in [bin, legacy] {
+ assert_eq!(check(&doc), Ok(()));
+ for end in 0..doc.len() {
+ assert!(
+ check(&doc[..end]).is_err(),
+ "prefix of {end} bytes admitted"
+ );
+ }
+ }
+ }
+}
diff --git a/tests/decode_bounds_vectors.rs b/tests/decode_bounds_vectors.rs
new file mode 100644
index 0000000..8ccbf5e
--- /dev/null
+++ b/tests/decode_bounds_vectors.rs
@@ -0,0 +1,187 @@
+//! Decode-bounds vectors through `ByteStorage::retrieve`.
+//!
+//! `retrieve` is the untrusted envelope decode that cachekit-py and cachekit-ts
+//! (NAPI and wasm) reach, so the protocol requires it to pre-scan the envelope
+//! bytes before materialising a `StorageEnvelope` (`protocol/spec/wire-format.md`
+//! → Retrieve Flow, step 2; the bounds are `spec/interop-mode.md` → Decode
+//! bounds). Asserting only that a reject vector fails would not show that: a
+//! bare decoder fails on every one of them too, after it has started
+//! materialising. Each reject vector must therefore fail with the message
+//! prefix that only the pre-scan produces.
+//!
+//! Fixture provenance: vendored from
+//! `test-vectors/decode-bounds.json`
+//! at commit `1729eb7e94909e2df4e22d1da090de0001cc7bdf`, integrity-pinned by
+//! sha256 below. To update: copy the file from a newer protocol ref, update
+//! `FIXTURE_SHA256` and this comment's commit hash together.
+
+#![cfg(all(feature = "compression", feature = "checksum", feature = "messagepack"))]
+
+use cachekit_core::byte_storage::ByteStorageError;
+use cachekit_core::{ByteStorage, StorageEnvelope};
+use sha2::{Digest, Sha256};
+
+/// Compiled-in fixture: no runtime path resolution, so the test can never be
+/// silently skipped by a missing file.
+const FIXTURE: &str = include_str!("vectors/decode-bounds.json");
+
+/// sha256 of the vendored fixture — must match the protocol repo's copy.
+const FIXTURE_SHA256: &str = "907b025d2b270a0f60abd9296a8a1c864e69057c553ac7a70206b44256558916"; // pragma: allowlist secret
+
+/// Prefix of every pre-scan rejection. A decoder error can echo attacker
+/// bytes (a string value in an "invalid type" message), but never at the start
+/// of the message, so only a `starts_with` match is unforgeable.
+const PRE_SCAN: &str = "decode pre-scan: ";
+
+/// The crate's nesting bound, pinned here so a change to it is deliberate.
+const MAX_DEPTH: usize = 100;
+
+#[derive(serde::Deserialize)]
+struct Fixture {
+ version: String,
+ reject_vectors: Vec,
+ accept_vectors: Vec,
+}
+
+#[derive(serde::Deserialize)]
+struct Vector {
+ name: String,
+ input_hex: String,
+ input_len: usize,
+ #[serde(default)]
+ reject_reasons: Vec,
+}
+
+impl Vector {
+ fn input(&self) -> Vec {
+ let bytes = hex::decode(&self.input_hex).expect("input_hex must be hex");
+ assert_eq!(bytes.len(), self.input_len, "[{}] input_len", self.name);
+ bytes
+ }
+}
+
+fn load_fixture() -> Fixture {
+ serde_json::from_str(FIXTURE).expect("decode-bounds.json fixture must parse")
+}
+
+fn pre_scan_message(result: &Result<(Vec, String), ByteStorageError>) -> Option<&str> {
+ match result {
+ Err(ByteStorageError::DeserializationFailed(msg)) => msg.strip_prefix(PRE_SCAN),
+ _ => None,
+ }
+}
+
+#[test]
+fn fixture_integrity_pinned_sha256() {
+ let digest = hex::encode(Sha256::digest(FIXTURE.as_bytes()));
+ assert_eq!(
+ digest, FIXTURE_SHA256,
+ "vendored decode-bounds.json drifted from its pinned sha256 — \
+ re-vendor from the protocol repo and update FIXTURE_SHA256 deliberately"
+ );
+}
+
+#[test]
+fn fixture_is_current_version_with_vectors() {
+ let fixture = load_fixture();
+ assert_eq!(fixture.version, "1.1.0");
+ assert_eq!(fixture.reject_vectors.len(), 17);
+ assert_eq!(fixture.accept_vectors.len(), 3);
+}
+
+#[test]
+fn every_reject_vector_is_rejected_by_the_pre_scan() {
+ let storage = ByteStorage::new(None);
+ for vector in load_fixture().reject_vectors {
+ let result = storage.retrieve(&vector.input());
+ let reason = pre_scan_message(&result).unwrap_or_else(|| {
+ panic!("[{}] not rejected by the pre-scan: {result:?}", vector.name)
+ });
+ // A depth-only vector is structurally complete, so nothing but the
+ // depth bound can reject it. An overclaim-only vector must trip the
+ // slot budget, not merely run out of input at the end: a walk that
+ // checks each header against the bytes after it alone still reaches
+ // end of input on `nested_array16_each_header_fits_sum_overclaims`.
+ match vector.reject_reasons.as_slice() {
+ [r] if r == "depth" => assert_eq!(
+ reason,
+ format!("nests deeper than {MAX_DEPTH} levels"),
+ "[{}]",
+ vector.name
+ ),
+ [r] if r == "overclaim" => {
+ assert!(
+ reason.starts_with("declares more "),
+ "[{}] {reason}",
+ vector.name
+ )
+ }
+ _ => {}
+ }
+ assert!(!storage.validate(&vector.input()), "[{}]", vector.name);
+ }
+}
+
+#[test]
+fn every_accept_vector_passes_the_pre_scan() {
+ // Not envelopes, so the typed decode still rejects them; the pre-scan must not.
+ let storage = ByteStorage::new(None);
+ for vector in load_fixture().accept_vectors {
+ let result = storage.retrieve(&vector.input());
+ assert_eq!(
+ pre_scan_message(&result),
+ None,
+ "[{}] {result:?}",
+ vector.name
+ );
+ }
+}
+
+/// A real envelope in map form with one extra, unknown key whose value nests
+/// `depth - 1` arrays, so the whole document nests `depth` deep (the root map
+/// is one level). Serde's derive skips the unknown key with `IgnoredAny`,
+/// which recurses once per level.
+fn map_form_envelope_nested(storage: &ByteStorage, payload: &[u8], depth: usize) -> Vec {
+ let envelope: StorageEnvelope =
+ rmp_serde::from_slice(&storage.store(payload, None).unwrap()).unwrap();
+ let mut doc = rmp_serde::to_vec_named(&envelope).unwrap();
+ assert_eq!(
+ doc[0], 0x84,
+ "to_vec_named must emit a fixmap of the 4 fields"
+ );
+ doc[0] = 0x85;
+ doc.push(0xa0); // key ""
+ doc.extend(std::iter::repeat_n(0x91, depth - 1));
+ doc.push(0xc0);
+ doc
+}
+
+#[test]
+fn complete_envelope_at_the_depth_bound_decodes_on_small_stacks() {
+ // The pre-scan admits a document nested exactly MAX_DEPTH deep, so the
+ // typed decode must survive that nesting. 1 MiB is wasm32's default stack.
+ for stack in [2 << 20, 1 << 20] {
+ let result = std::thread::Builder::new()
+ .stack_size(stack)
+ .spawn(|| {
+ let storage = ByteStorage::new(None);
+ let at_bound = map_form_envelope_nested(&storage, b"at the bound", MAX_DEPTH);
+ let past_bound = map_form_envelope_nested(&storage, b"at the bound", MAX_DEPTH + 1);
+ (storage.retrieve(&at_bound), storage.retrieve(&past_bound))
+ })
+ .unwrap()
+ .join()
+ .expect("retrieve panicked");
+ let (at_bound, past_bound) = result;
+ assert_eq!(
+ at_bound,
+ Ok((b"at the bound".to_vec(), "msgpack".to_owned())),
+ "stack {stack}"
+ );
+ assert_eq!(
+ pre_scan_message(&past_bound),
+ Some(format!("nests deeper than {MAX_DEPTH} levels").as_str()),
+ "stack {stack}"
+ );
+ }
+}
diff --git a/tests/vectors/decode-bounds.json b/tests/vectors/decode-bounds.json
new file mode 100644
index 0000000..a995dad
--- /dev/null
+++ b/tests/vectors/decode-bounds.json
@@ -0,0 +1,335 @@
+{
+ "version": "1.1.0",
+ "spec": "spec/interop-mode.md#decode-bounds",
+ "generator": "tools/decode-bounds-reference.py generate (CPython stdlib)",
+ "scope": "Any untrusted MessagePack decode in any SDK: interop/v1 values, the ByteStorage envelope bytes before StorageEnvelope is materialised, auto-mode payloads after the envelope is unwrapped, invalidation events. The bytes are plain MessagePack with no envelope.",
+ "rules": {
+ "depth": "Readers MUST bound nesting depth. The bound MUST be >= 32 and MUST be <= 1024; every reject vector tagged 'depth' nests deeper than 1024.",
+ "overclaim": "Readers MUST NOT pre-allocate beyond what the input can back (each element or byte needs >= 1 input byte): declared slots summed over the whole document MUST NOT exceed input_len - 1, checked before anything is materialised. Checking each header against the remaining input does not satisfy this. Readers MUST reject a structurally incomplete document. Every reject vector tagged 'overclaim' has declared_slots > input_len - 1 (the root header is the only byte that is not an element). A map pair counts as two slots (key + value). Every per-header term and the running sum MUST be computed in >= 64 bits or with checked/saturating arithmetic; an overflow is itself a rejection.",
+ "failure_mode": "Rejection MUST surface as a catchable decode error that the SDK read path turns into a cache miss (fail-closed), never an uncaught crash or an OOM abort."
+ },
+ "field_notes": {
+ "construction": "input = bytes.fromhex(repeat_hex) * count + bytes.fromhex(suffix_hex)",
+ "nesting_depth": "collection headers along the deepest spine; a map counts one level, like an array (str/bin/ext and scalars count as 0)",
+ "declared_slots": "sum of every header's declared element/byte count (collections, str, bin, ext; fixext declares none); a map pair counts as two slots (key + value); a nested header counts as one element of its parent",
+ "reject_reasons": "which rule(s) the vector violates; a maintainer note, not a normative message"
+ },
+ "reject_vectors": [
+ {
+ "name": "nested_array16_depth_2048",
+ "description": "2048 nested array16 headers each claiming 2000 elements, 0 backing bytes. The measured amplifier shape: an eager decoder pre-allocates 2000 slots per level before hitting EOF. 2000 < input_len, so a per-collection cap of len(input) does NOT reject it.",
+ "construction": {
+ "repeat_hex": "dc07d0",
+ "count": 2048,
+ "suffix_hex": ""
+ },
+ "input_hex": "dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0",
+ "input_len": 6144,
+ "nesting_depth": 2048,
+ "declared_slots": 4096000,
+ "reject_reasons": [
+ "depth",
+ "overclaim"
+ ]
+ },
+ {
+ "name": "nested_array32_input_len_depth_1100",
+ "description": "1100 nested array32 headers each claiming exactly len(input)=5500 elements. Defeats a per-collection cap of len(input): peak pre-allocation is depth x len(input) x slot size.",
+ "construction": {
+ "repeat_hex": "dd0000157c",
+ "count": 1100,
+ "suffix_hex": ""
+ },
+ "input_hex": "dd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157cdd0000157c",
+ "input_len": 5500,
+ "nesting_depth": 1100,
+ "declared_slots": 6050000,
+ "reject_reasons": [
+ "depth",
+ "overclaim"
+ ]
+ },
+ {
+ "name": "nested_map16_depth_2048",
+ "description": "Map twin of nested_array16_depth_2048 (map pre-allocation is typically larger per slot).",
+ "construction": {
+ "repeat_hex": "de07d0",
+ "count": 2048,
+ "suffix_hex": ""
+ },
+ "input_hex": "de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0de07d0",
+ "input_len": 6144,
+ "nesting_depth": 2048,
+ "declared_slots": 8192000,
+ "reject_reasons": [
+ "depth",
+ "overclaim"
+ ]
+ },
+ {
+ "name": "nested_array16_each_header_fits_sum_overclaims",
+ "description": "30 nested array16 headers each claiming 2000 elements, then 2000 nils. Every header fits the bytes that follow it and the nesting is below the depth floor, so of the structural rules only the sum over the whole document (60 000 > input_len - 1) catches it. A reader with per-header checks alone pre-allocates 30 x 2000 slots and then rejects at end of input, so the verdict cannot tell the two apart: only an SDK test asserting its guard's rejection can.",
+ "construction": {
+ "repeat_hex": "dc07d0",
+ "count": 30,
+ "suffix_hex": "c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0"
+ },
+ "input_hex": "dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0dc07d0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0",
+ "input_len": 2090,
+ "nesting_depth": 30,
+ "declared_slots": 60000,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "nested_fixarray_depth_1025_complete",
+ "description": "Structurally COMPLETE document nested 1025 deep, one level past the ceiling: only the depth bound rejects it, and a reader whose bound exceeds 1024 accepts it.",
+ "construction": {
+ "repeat_hex": "91",
+ "count": 1025,
+ "suffix_hex": "c0"
+ },
+ "input_hex": "9191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191919191c0",
+ "input_len": 1026,
+ "nesting_depth": 1025,
+ "declared_slots": 1025,
+ "reject_reasons": [
+ "depth"
+ ]
+ },
+ {
+ "name": "nested_fixmap_depth_1025_complete",
+ "description": "Map twin of nested_fixarray_depth_1025_complete ({\"\": {\"\": ... null}}): a guard that counts depth on array headers only accepts it.",
+ "construction": {
+ "repeat_hex": "81a0",
+ "count": 1025,
+ "suffix_hex": "c0"
+ },
+ "input_hex": "81a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a0c0",
+ "input_len": 2051,
+ "nesting_depth": 1025,
+ "declared_slots": 2050,
+ "reject_reasons": [
+ "depth"
+ ]
+ },
+ {
+ "name": "array16_overclaim_shallow",
+ "description": "One array16 header claiming 10 000 elements with 3 backing bytes.",
+ "construction": {
+ "repeat_hex": "dc2710",
+ "count": 1,
+ "suffix_hex": "010203"
+ },
+ "input_hex": "dc2710010203",
+ "input_len": 6,
+ "nesting_depth": 1,
+ "declared_slots": 10000,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "array32_max_claim_alone",
+ "description": "A lone 5-byte array32 header claiming 2^32-1 elements.",
+ "construction": {
+ "repeat_hex": "ddffffffff",
+ "count": 1,
+ "suffix_hex": ""
+ },
+ "input_hex": "ddffffffff",
+ "input_len": 5,
+ "nesting_depth": 1,
+ "declared_slots": 4294967295,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "map32_max_claim_alone",
+ "description": "A lone 5-byte map32 header claiming 2^32-1 pairs (2^33-2 slots: each pair is a key and a value).",
+ "construction": {
+ "repeat_hex": "dfffffffff",
+ "count": 1,
+ "suffix_hex": ""
+ },
+ "input_hex": "dfffffffff",
+ "input_len": 5,
+ "nesting_depth": 1,
+ "declared_slots": 8589934590,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "array32_sum_wraps_u32",
+ "description": "array32 claiming 2^32-1 elements whose first element is an array32 claiming 1: the declared slots sum to exactly 2^32, which a 32-bit accumulator checked only once the sum is complete wraps to 0 and passes. One checked after every add rejects it at the first header; see array32_sum_wraps_u32_small_first.",
+ "construction": {
+ "repeat_hex": "ddffffffff",
+ "count": 1,
+ "suffix_hex": "dd00000001"
+ },
+ "input_hex": "ddffffffffdd00000001",
+ "input_len": 10,
+ "nesting_depth": 2,
+ "declared_slots": 4294967296,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "array32_sum_wraps_u32_small_first",
+ "description": "fixarray claiming 1 element that is an array32 claiming 2^32-1: the running sum is 1, then exactly 2^32, so a 32-bit accumulator checked after every add sees 1 and then 0 and passes both checks.",
+ "construction": {
+ "repeat_hex": "91",
+ "count": 1,
+ "suffix_hex": "ddffffffff"
+ },
+ "input_hex": "91ddffffffff",
+ "input_len": 6,
+ "nesting_depth": 2,
+ "declared_slots": 4294967296,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "map32_half_claim_wraps_u32_mul",
+ "description": "A lone map32 header claiming 2^31 pairs: the per-header term 2 x pairs is exactly 2^32, which a 32-bit multiply wraps to 0 before it is ever added to the budget.",
+ "construction": {
+ "repeat_hex": "df80000000",
+ "count": 1,
+ "suffix_hex": ""
+ },
+ "input_hex": "df80000000",
+ "input_len": 5,
+ "nesting_depth": 1,
+ "declared_slots": 4294967296,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "fixmap_short_by_one",
+ "description": "fixmap claiming 1 pair with the key present and the value missing: the map twin of fixarray_short_by_one. Counting one slot per pair (instead of two) accepts it.",
+ "construction": {
+ "repeat_hex": "81",
+ "count": 1,
+ "suffix_hex": "c0"
+ },
+ "input_hex": "81c0",
+ "input_len": 2,
+ "nesting_depth": 1,
+ "declared_slots": 2,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "bin32_overclaim",
+ "description": "bin32 header claiming 2^32-1 bytes with 1 backing byte (a 6-byte document declaring a 4 GiB buffer).",
+ "construction": {
+ "repeat_hex": "c6ffffffff",
+ "count": 1,
+ "suffix_hex": "41"
+ },
+ "input_hex": "c6ffffffff41",
+ "input_len": 6,
+ "nesting_depth": 0,
+ "declared_slots": 4294967295,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "str32_overclaim",
+ "description": "str32 twin of bin32_overclaim.",
+ "construction": {
+ "repeat_hex": "dbffffffff",
+ "count": 1,
+ "suffix_hex": "41"
+ },
+ "input_hex": "dbffffffff41",
+ "input_len": 6,
+ "nesting_depth": 0,
+ "declared_slots": 4294967295,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "ext32_overclaim",
+ "description": "ext32 twin of bin32_overclaim (type 5, 1 backing byte): ext lengths count as slots too.",
+ "construction": {
+ "repeat_hex": "c9ffffffff",
+ "count": 1,
+ "suffix_hex": "0541"
+ },
+ "input_hex": "c9ffffffff0541",
+ "input_len": 7,
+ "nesting_depth": 0,
+ "declared_slots": 4294967295,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ },
+ {
+ "name": "fixarray_short_by_one",
+ "description": "fixarray claiming 5 elements with 4 present: the minimal truncated document.",
+ "construction": {
+ "repeat_hex": "95",
+ "count": 1,
+ "suffix_hex": "c0c0c0c0"
+ },
+ "input_hex": "95c0c0c0c0",
+ "input_len": 5,
+ "nesting_depth": 1,
+ "declared_slots": 5,
+ "reject_reasons": [
+ "overclaim"
+ ]
+ }
+ ],
+ "accept_vectors": [
+ {
+ "name": "nested_fixarray_depth_32",
+ "description": "[[...[null]...]] nested 32 deep, complete. A conforming reader MUST accept it: the depth bound may not be tighter than 32.",
+ "construction": {
+ "repeat_hex": "91",
+ "count": 32,
+ "suffix_hex": "c0"
+ },
+ "input_hex": "9191919191919191919191919191919191919191919191919191919191919191c0",
+ "input_len": 33,
+ "nesting_depth": 32,
+ "declared_slots": 32
+ },
+ {
+ "name": "nested_fixmap_depth_32",
+ "description": "Map twin of nested_fixarray_depth_32: a map counts one level, and a pair two slots.",
+ "construction": {
+ "repeat_hex": "81a0",
+ "count": 32,
+ "suffix_hex": "c0"
+ },
+ "input_hex": "81a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a081a0c0",
+ "input_len": 65,
+ "nesting_depth": 32,
+ "declared_slots": 64
+ },
+ {
+ "name": "array16_256_backed_nils",
+ "description": "array16 header claiming 256 elements with all 256 present. A *16 header that is fully backed by input is legitimate; the allocation rule is about backing, not header width.",
+ "construction": {
+ "repeat_hex": "dc0100",
+ "count": 1,
+ "suffix_hex": "c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0"
+ },
+ "input_hex": "dc0100c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0",
+ "input_len": 259,
+ "nesting_depth": 1,
+ "declared_slots": 256
+ }
+ ]
+}