Skip to content

Resolving conflicts with upstream. - #18

Merged
siqpush merged 6 commits into
masterfrom
pr559
Jan 24, 2026
Merged

siqpush merged 6 commits into
masterfrom
pr559

Conversation

@siqpush

@siqpush siqpush commented Jan 24, 2026

Copy link
Copy Markdown
Owner

No description provided.

jmcnamara and others added 6 commits November 20, 2025 19:31
Fix an issue for xlsx files with absolute reference ids like
"/xl/tables/table1.xml" instead of the Excel generated
"../tables/table1.xml"

Closes tafia#587
Fixed an issue where xlsx files with tables that have the
insertRow attribute set returned a Dimensions object with the end
row less than the start row. This caused an assert/panic when
trying to create a Range object to return the table range.

This issue was caused by an misinterpretation of the insertRow
attribute to mean that table had one row less than the reported
range. This is not the case. The insertRow attribute is used to
report to consuming applications that the table has one empty row
that is ready for data.

See ECMA-376 Part1 Section 18.5.1.2 "table (Table)".

Closes tafia#589
Add limits to prevent memory exhaustion from malicious ODS files that
declare billions of repeated cells via table:number-rows-repeated and
table:number-columns-repeated attributes.

Protection layers:
- Cap columns per row at MAX_COLUMNS (16,384)
- Cap total row repeats at MAX_ROWS (1,048,576)
- Cap total cells at MAX_CELLS (100 million) in get_range()

These limits match XLSX's existing row/column limits and prevent a 7KB
malicious file from attempting to allocate memory for 17+ billion cells.

When MAX_CELLS is exceeded, return OdsError::CellLimitExceeded instead
of silently returning an empty range. This ensures callers are properly
informed of truncation rather than receiving silent data loss.
@siqpush
siqpush merged commit 7ca4a3b into master Jan 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants