ReadonlyaccReadonlycapReadonlyelemReadonlynameReadonlyoutReadonlyreceiverReadonlyreceiverThe element's fixlen length word (Visitor.fixlenBegin).
The bounds are decided by this word, so they are checked here — before any payload byte — and again in element below.
That is not redundancy for its own sake: a message that ends inside an
over-long element must still be INVALID, and only this event runs early
enough to say so. Without it the verdict would degrade to INCOMPLETE, which
§5.2.3 forbids for input already known to be malformed and which §6.4 forbids
a chunk boundary from changing.
An element of the wrong fixlen subtype is left alone: §7.3 requires it to be skipped, not rejected, and it is skipped by this class simply ignoring it.
One payload piece of element id (Visitor.string).
Collects the elements of a
stringwrapper-sequence array intoout.Param: out
The destination, placed at
out[id]; grown as elements arrive, with gaps filled by the element default"".Param: acc
The decoder's shared PayloadAcc — one per decode, since only one payload is ever in flight.
Param: cap
The schema
count, an index capacity: an element id at or above it isINVALID(§7.1/§5.1) — a statement about validity. Pass UNBOUNDED (-1) for an array the schema left unbounded, wherereceiverCapgoverns instead.Param: elemMax
The element
maxlenin bytes, or UNBOUNDED (-1) for an element the schema left open, wherereceiverElemMaxgoverns instead.Param: name
The schema field name, used only in the rejection message.
Param: receiverCap
The receiver-side index cap that applies only when the schema left the array unbounded (§6.2.1): exceeding it is
LIMIT_EXCEEDED, a policy rejection, notINVALID. There is no unlimited setting — a wrapper array announces no count, so the index is the only place a receiver can bound it. Required, with no default (§6.2.1).Param: receiverElemMax
The receiver-side
max_dyn_string_lenfor an element the schema left unbounded (§6.2.1), checked at the length word and answered withLIMIT_EXCEEDED. A wrapper array'sstringelements never reach the generated visitor — their length words come here — so this is where that cap belongs, and it is why the decoder needs no module-wide limit object at all. Required, with no default:FIXLEN_MAXis the format's bound, not a receiver cap, and §6.2.1 forbids presenting it as one.