Coverage Report

Created: 2026-09-28 08:21

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/harfbuzz/src/hb-limits.hh
Line
Count
Source
1
/*
2
 * Copyright © 2022  Behdad Esfahbod
3
 *
4
 *  This is part of HarfBuzz, a text shaping library.
5
 *
6
 * Permission is hereby granted, without written agreement and without
7
 * license or royalty fees, to use, copy, modify, and distribute this
8
 * software and its documentation for any purpose, provided that the
9
 * above copyright notice and the following two paragraphs appear in
10
 * all copies of this software.
11
 *
12
 * IN NO EVENT SHALL THE COPYRIGHT HOLDER BE LIABLE TO ANY PARTY FOR
13
 * DIRECT, INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES
14
 * ARISING OUT OF THE USE OF THIS SOFTWARE AND ITS DOCUMENTATION, EVEN
15
 * IF THE COPYRIGHT HOLDER HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH
16
 * DAMAGE.
17
 *
18
 * THE COPYRIGHT HOLDER SPECIFICALLY DISCLAIMS ANY WARRANTIES, INCLUDING,
19
 * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND
20
 * FITNESS FOR A PARTICULAR PURPOSE.  THE SOFTWARE PROVIDED HEREUNDER IS
21
 * ON AN "AS IS" BASIS, AND THE COPYRIGHT HOLDER HAS NO OBLIGATION TO
22
 * PROVIDE MAINTENANCE, SUPPORT, UPDATES, ENHANCEMENTS, OR MODIFICATIONS.
23
 */
24
25
#ifndef HB_LIMITS_HH
26
#define HB_LIMITS_HH
27
28
#include "hb.hh"
29
30
31
#ifndef HB_BUFFER_MAX_LEN_FACTOR
32
#define HB_BUFFER_MAX_LEN_FACTOR 256
33
#endif
34
#ifndef HB_BUFFER_MAX_LEN_MIN
35
0
#define HB_BUFFER_MAX_LEN_MIN 65536
36
#endif
37
#ifndef HB_BUFFER_MAX_LEN_DEFAULT
38
0
#define HB_BUFFER_MAX_LEN_DEFAULT 0x3FFFFFFF /* Shaping more than a billion chars? Let us know! */
39
#endif
40
41
#ifndef HB_BUFFER_MAX_OPS_FACTOR
42
#define HB_BUFFER_MAX_OPS_FACTOR 4096
43
#endif
44
#ifndef HB_BUFFER_MAX_OPS_MIN
45
0
#define HB_BUFFER_MAX_OPS_MIN 65536
46
#endif
47
#ifndef HB_BUFFER_MAX_OPS_DEFAULT
48
0
#define HB_BUFFER_MAX_OPS_DEFAULT 0x1FFFFFFF /* Shaping more than a billion operations? Let us know! */
49
#endif
50
51
52
#ifndef HB_MAX_NESTING_LEVEL
53
0
#define HB_MAX_NESTING_LEVEL 64
54
#endif
55
56
57
#ifndef HB_MAX_CONTEXT_LENGTH
58
0
#define HB_MAX_CONTEXT_LENGTH 64
59
#endif
60
61
#ifndef HB_MAX_SYLLABLE_LENGTH
62
0
#define HB_MAX_SYLLABLE_LENGTH 64
63
#endif
64
65
#ifndef HB_CLOSURE_MAX_STAGES
66
/*
67
 * The maximum number of times a lookup can be applied during shaping.
68
 * Used to limit the number of iterations of the closure algorithm.
69
 * This must be larger than the number of times add_gsub_pause() is
70
 * called in a collect_features call of any shaper.
71
 */
72
0
#define HB_CLOSURE_MAX_STAGES 12
73
#endif
74
75
#ifndef HB_MAX_SCRIPTS
76
0
#define HB_MAX_SCRIPTS 500
77
#endif
78
79
#ifndef HB_MAX_LANGSYS
80
0
#define HB_MAX_LANGSYS 2000
81
#endif
82
83
#ifndef HB_MAX_LANGSYS_FEATURE_COUNT
84
0
#define HB_MAX_LANGSYS_FEATURE_COUNT 50000
85
#endif
86
87
#ifndef HB_MAX_FEATURE_INDICES
88
0
#define HB_MAX_FEATURE_INDICES 8000
89
#endif
90
91
#ifndef HB_MAX_LOOKUP_VISIT_COUNT
92
0
#define HB_MAX_LOOKUP_VISIT_COUNT 35000
93
#endif
94
95
#ifndef HB_MAX_GRAPH_EDGE_COUNT
96
0
#define HB_MAX_GRAPH_EDGE_COUNT 16384
97
#endif
98
99
#ifndef HB_VAR_COMPOSITE_MAX_AXES
100
0
#define HB_VAR_COMPOSITE_MAX_AXES 4096
101
#endif
102
103
#ifndef HB_GLYF_MAX_POINTS
104
0
#define HB_GLYF_MAX_POINTS 200000
105
#endif
106
107
#ifndef HB_CFF_MAX_OPS
108
0
#define HB_CFF_MAX_OPS 200000
109
#endif
110
111
#ifndef HB_MAX_COMPOSITE_OPERATIONS_PER_GLYPH
112
0
#define HB_MAX_COMPOSITE_OPERATIONS_PER_GLYPH 64
113
#endif
114
115
#ifndef HB_SVG_MAX_PATH_SEGMENTS
116
#define HB_SVG_MAX_PATH_SEGMENTS 262144
117
#endif
118
119
#ifndef HB_GPU_DRAW_MAX_CURVES
120
#define HB_GPU_DRAW_MAX_CURVES 65536
121
#endif
122
123
/* Tiles emitted by one hb_paint_sweep_gradient_tiles() call.  Also
124
 * sets the angular resolution (2π over this) below which a repeating
125
 * color line is filled with its average color instead of tiled;
126
 * a repeat/reflect color line whose stops span a tiny angle could
127
 * otherwise emit millions of patches while covering 0..2π. */
128
#ifndef HB_PAINT_MAX_SWEEP_TILES
129
0
#define HB_PAINT_MAX_SWEEP_TILES 4096
130
#endif
131
132
#ifndef HB_SVG_MAX_DOCUMENT_SIZE
133
#define HB_SVG_MAX_DOCUMENT_SIZE ((size_t) 16 << 20)
134
#endif
135
136
/* Maximum size of one serialized vector document (SVG or PDF) produced by
137
 * the vector backends.  Bounds output that is not outline-derived -- most
138
 * of a path, but especially sweep-gradient meshes and embedded bitmaps --
139
 * which the outline work budget cannot see.  vector is one glyph per
140
 * context, so a flat cap suffices.  Unsigned (not size_t like the SVG-table
141
 * limit above) to match hb_vector_buf_t's unsigned length arithmetic. */
142
#ifndef HB_VECTOR_MAX_DOCUMENT_SIZE
143
#define HB_VECTOR_MAX_DOCUMENT_SIZE ((unsigned) 16 << 20)
144
#endif
145
146
#ifndef HB_RASTER_MAX_BUFFER_SIZE
147
#define HB_RASTER_MAX_BUFFER_SIZE ((size_t) 1 << 30)
148
#endif
149
150
/* Maximum surface dimension (pixels per side) when extents are derived
151
 * from font data (glyph extents or accumulated outline bounds).  Bounds
152
 * attacker-controlled allocations; extents set explicitly through
153
 * hb_raster_{draw,paint}_set_extents() are not limited. */
154
#ifndef HB_RASTER_MAX_AUTO_DIMENSION
155
#define HB_RASTER_MAX_AUTO_DIMENSION 4096
156
#endif
157
158
/*
159
 * Cumulative work budgets.
160
 *
161
 * The limits above bound work within one subsystem: points per glyf
162
 * glyph, ops per CFF charstring, nodes in a COLR or VARC graph,
163
 * pixels per raster surface.  When one subsystem drives another --
164
 * COLR driving a paint backend, a paint backend or VARC loading
165
 * glyf/CFF outlines -- those limits multiply.  Each driving session
166
 * therefore carries one cumulative budget, initialized once per
167
 * top-level entry and only ever decremented, shared by everything
168
 * the session consumes.  Once a budget is exhausted, further work
169
 * is skipped best-effort.
170
 */
171
172
/* Fixed relative weights.  Keep the value in the name so charge sites are
173
 * easy to audit; tune the common session cap, not these values. */
174
0
#define HB_BUDGET_1 1u
175
#define HB_BUDGET_2 2u
176
#define HB_BUDGET_4 4u
177
#define HB_BUDGET_8 8u
178
#define HB_BUDGET_16  16u
179
#define HB_BUDGET_32  32u
180
#define HB_BUDGET_64  64u
181
#define HB_BUDGET_128 128u
182
#define HB_BUDGET_256 256u
183
#define HB_BUDGET_512 512u
184
#define HB_BUDGET_1024  1024u
185
186
/* The common finite default for one top-level glyph rendering session.
187
 * Nested outline and paint work shares the same live counter. */
188
#ifndef HB_BUDGET_GLYPH
189
0
#define HB_BUDGET_GLYPH ((int64_t) 1 << 24)
190
#endif
191
192
/* Precharge COST * MULT.  Callers bound COST and MULT structurally, and live
193
 * budgets are concrete non-negative values when a session starts. */
194
static HB_ALWAYS_INLINE bool
195
hb_budget_spend (int64_t &budget, unsigned int cost, unsigned int mult = 1)
196
0
{
197
0
  budget -= (int64_t) cost * mult;
198
0
  return budget >= 0;
199
0
}
Unexecuted instantiation: hb-subset-input.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-number.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-static.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-plan.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-plan-layout.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-plan-var.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-table-layout.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-table-var.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-table-cff.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-table-color.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-table-other.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: gsubgpos-context.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: VARC.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-cff1-table.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-cff2-table.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-cff1.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-cff2.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-instancer-iup.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-instancer-solver.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-subset-cff-common.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-blob.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-common.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-draw.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-face.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-face-builder.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-fallback-shape.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-font.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-map.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-face.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-font.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-outline.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-layout.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-metrics.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shape.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-tag.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-var.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-set.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-shape-plan.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-shaper.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-unicode.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ft.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-aat-layout.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-aat-map.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-buffer.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-paint.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-paint-bounded.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-paint-extents.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-map.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-arabic.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-default.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-hangul.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-hebrew.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-indic.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-khmer.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-myanmar.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-syllabic.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-thai.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-use.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-vowel-constraints.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shape-fallback.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shape-normalize.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ucd.cc:hb_budget_spend(long&, unsigned int, unsigned int)
Unexecuted instantiation: hb-ot-shaper-indic-table.cc:hb_budget_spend(long&, unsigned int, unsigned int)
200
201
/* The flat pixel-work floor for one raster paint session.  Pixel and
202
 * outline work use separate live counters, so keep this independent of
203
 * the common outline budget above. */
204
#ifndef HB_BUDGET_RASTER_PIXELS
205
#define HB_BUDGET_RASTER_PIXELS ((int64_t) 1 << 26)
206
#endif
207
208
/* Very large raster surfaces still get a few full-surface operations. */
209
#ifndef HB_BUDGET_RASTER_PAINT_PASSES
210
#define HB_BUDGET_RASTER_PAINT_PASSES 4
211
#endif
212
213
/* One raster draw session, in accumulated non-horizontal edges. */
214
#ifndef HB_RASTER_MAX_DRAW_EDGES
215
#define HB_RASTER_MAX_DRAW_EDGES ((int64_t) 1 << 20)
216
#endif
217
218
219
#ifndef HB_REPACKER_MAX_ITERATIONS
220
0
#define HB_REPACKER_MAX_ITERATIONS 500
221
#endif
222
223
#ifndef HB_REPACKER_MAX_VERTICES
224
#define HB_REPACKER_MAX_VERTICES 800000
225
#endif
226
227
#ifndef HB_REPACKER_MAX_SPACES
228
#define HB_REPACKER_MAX_SPACES 8000
229
#endif
230
231
232
#endif /* HB_LIMITS_HH */