Length bombs test values
Values sized against common limits and against the gap between a character and a byte. 12 values, each with what it breaks and what a correct application does instead.
Type them one at a time with AltShiftN
in the palette, or take them all into a script with nkb emit length-bombs.
Empty value
length-bombs/len-0- 0 graphemes
- 0 code points
- 0 bytes
- 0 UTF-16 units
- What it breaks
- An empty value tests the boundary between not filled in and filled in with nothing.
- What a correct application does
- Required fields reject it with a clear message, optional fields store it as empty.
255 characters
length-bombs/len-255
255 × a
- 255 graphemes
- 255 code points
- 255 bytes
- 255 UTF-16 units
- What it breaks
- The classic column width: one character short of the limit, exactly at it, and one over it are three different code paths.
- What a correct application does
- Accepted at the limit and rejected above it, with the limit stated in the message.
256 characters
length-bombs/len-256
256 × a
- 256 graphemes
- 256 code points
- 256 bytes
- 256 UTF-16 units
- What it breaks
- One character over the classic limit, which is where silent truncation usually happens.
- What a correct application does
- Rejected with a message, never silently cut down to 255.
254 characters
length-bombs/len-254
254 × a
- 254 graphemes
- 254 code points
- 254 bytes
- 254 UTF-16 units
- What it breaks
- The value just under the limit, used to prove the limit is off by one in either direction.
- What a correct application does
- Accepted without complaint.
1000 characters
length-bombs/len-1000
1,000 × a
- 1,000 graphemes
- 1,000 code points
- 1,000 bytes
- 1,000 UTF-16 units
- What it breaks
- Comment and description fields sized for a sentence and used for an essay.
- What a correct application does
- Accepted, or rejected with the limit stated - not accepted and truncated.
4000 characters
length-bombs/len-4000
4,000 × a
- 4,000 graphemes
- 4,000 code points
- 4,000 bytes
- 4,000 UTF-16 units
- What it breaks
- A limit common in older database columns, and the first size at which text fields start failing quietly.
- What a correct application does
- The same rule as above, applied consistently between the interface and storage.
65535 characters
length-bombs/len-65535
65,535 × a
- 65,535 graphemes
- 65,535 code points
- 65,535 bytes
- 65,535 UTF-16 units
- What it breaks
- The limit of the most common text column type, where crossing it usually produces a raw database error.
- What a correct application does
- A readable message instead of a database error page.
100000 characters
length-bombs/len-100000
100,000 × a
- 100,000 graphemes
- 100,000 code points
- 100,000 bytes
- 100,000 UTF-16 units
- What it breaks
- Character counters, layout, logs and every downstream export, all at once.
- What a correct application does
- Rejected early, before the value travels through the whole system.
128 characters, 256 bytes
length-bombs/bytes-vs-chars
128 × ą
- 128 graphemes
- 128 code points
- 256 bytes
- 128 UTF-16 units
- What it breaks
- 128 characters but 256 bytes: a field limited in bytes rejects a value the interface said was fine.
- What a correct application does
- The same unit used for the limit on both sides, and stated in the message.
64 emoji
length-bombs/emoji-truncation
64 × 😀
- 64 graphemes
- 64 code points
- 256 bytes
- 128 UTF-16 units
- What it breaks
- Truncation by bytes cuts the last character in half and produces a value that is no longer valid text.
- What a correct application does
- Truncation, if it happens at all, happens on character boundaries - never mid-character.
200 characters without a space
length-bombs/one-word-200
200 × a
- 200 graphemes
- 200 code points
- 200 bytes
- 200 UTF-16 units
- What it breaks
- 200 characters without a space: layouts that wrap on spaces push the value outside its container.
- What a correct application does
- Wrapped or clipped inside the container, never overflowing the surrounding interface.
One character
length-bombs/len-1
a
a
- 1 grapheme
- 1 code point
- 1 byte
- 1 UTF-16 unit
- What it breaks
- The shortest non-empty value, used against minimum-length rules that are rarely tested.
- What a correct application does
- Accepted or rejected according to a stated minimum, not silently accepted where a minimum exists.