Contribute one piece — the bytes src[start..end) at offset of a
total-byte payload — and return the whole payload once it is complete,
or null while bytes are still outstanding.
offset === 0 starts a payload — and resets the accumulator, so a decode
that was abandoned mid-payload (an INVALID field, a declined subtree) leaves
nothing behind to corrupt the next one.
A late piece with no payload in progress returns null rather than writing
anywhere: the accumulator has no buffer to append to, and inventing one would
fabricate a payload out of a fragment.
Joins a
string/blobpayload that arrived across several fed pieces.One per decoder, shared by every field. Exactly one payload is in flight at a time across a whole decode, however deep the nesting — a fixlen payload is atomic on the wire, so nothing can begin inside it — so one accumulator is enough.
What it returns is owned by the caller and aliases nothing: the bytes are copied into storage this accumulator allocated, on the whole-payload path exactly as on the split one (§6.7 — "there is no mode in which the destination aliases the input"). A consumer may keep the result, and a payload that arrived whole is not a special case with a different lifetime.
Sizing follows the declared
total, so a hostile length word is bounded by whatever bound the caller already applied to it — the schemamaxlenits generated guard checks, or the receiver caps of §6.2.1, both of which are enforced at the length word before a piece is ever delivered. This class enforces neither: it is handed a payload the caller has already accepted.