Length bombs test values

Values sized against common limits and against the gap between a character and a byte. 12 values, each with what it breaks and what a correct application does instead.

length-bombs version 1.0, updated 2026-09-08 CC-BY-4.0

Type them one at a time with AltShiftN in the palette, or take them all into a script with nkb emit length-bombs.

Empty value

length-bombs/len-0
  • 0 graphemes
  • 0 code points
  • 0 bytes
  • 0 UTF-16 units
What it breaks
An empty value tests the boundary between not filled in and filled in with nothing.
What a correct application does
Required fields reject it with a clear message, optional fields store it as empty.

255 characters

length-bombs/len-255
255 × a
  • 255 graphemes
  • 255 code points
  • 255 bytes
  • 255 UTF-16 units
What it breaks
The classic column width: one character short of the limit, exactly at it, and one over it are three different code paths.
What a correct application does
Accepted at the limit and rejected above it, with the limit stated in the message.

256 characters

length-bombs/len-256
256 × a
  • 256 graphemes
  • 256 code points
  • 256 bytes
  • 256 UTF-16 units
What it breaks
One character over the classic limit, which is where silent truncation usually happens.
What a correct application does
Rejected with a message, never silently cut down to 255.

254 characters

length-bombs/len-254
254 × a
  • 254 graphemes
  • 254 code points
  • 254 bytes
  • 254 UTF-16 units
What it breaks
The value just under the limit, used to prove the limit is off by one in either direction.
What a correct application does
Accepted without complaint.

1000 characters

length-bombs/len-1000
1,000 × a
  • 1,000 graphemes
  • 1,000 code points
  • 1,000 bytes
  • 1,000 UTF-16 units
What it breaks
Comment and description fields sized for a sentence and used for an essay.
What a correct application does
Accepted, or rejected with the limit stated - not accepted and truncated.

4000 characters

length-bombs/len-4000
4,000 × a
  • 4,000 graphemes
  • 4,000 code points
  • 4,000 bytes
  • 4,000 UTF-16 units
What it breaks
A limit common in older database columns, and the first size at which text fields start failing quietly.
What a correct application does
The same rule as above, applied consistently between the interface and storage.

65535 characters

length-bombs/len-65535
65,535 × a
  • 65,535 graphemes
  • 65,535 code points
  • 65,535 bytes
  • 65,535 UTF-16 units
What it breaks
The limit of the most common text column type, where crossing it usually produces a raw database error.
What a correct application does
A readable message instead of a database error page.

100000 characters

length-bombs/len-100000
100,000 × a
  • 100,000 graphemes
  • 100,000 code points
  • 100,000 bytes
  • 100,000 UTF-16 units
What it breaks
Character counters, layout, logs and every downstream export, all at once.
What a correct application does
Rejected early, before the value travels through the whole system.

128 characters, 256 bytes

length-bombs/bytes-vs-chars
128 × ą
  • 128 graphemes
  • 128 code points
  • 256 bytes
  • 128 UTF-16 units
What it breaks
128 characters but 256 bytes: a field limited in bytes rejects a value the interface said was fine.
What a correct application does
The same unit used for the limit on both sides, and stated in the message.

64 emoji

length-bombs/emoji-truncation
64 × 😀
  • 64 graphemes
  • 64 code points
  • 256 bytes
  • 128 UTF-16 units
What it breaks
Truncation by bytes cuts the last character in half and produces a value that is no longer valid text.
What a correct application does
Truncation, if it happens at all, happens on character boundaries - never mid-character.

200 characters without a space

length-bombs/one-word-200
200 × a
  • 200 graphemes
  • 200 code points
  • 200 bytes
  • 200 UTF-16 units
What it breaks
200 characters without a space: layouts that wrap on spaces push the value outside its container.
What a correct application does
Wrapped or clipped inside the container, never overflowing the surrounding interface.

One character

length-bombs/len-1
a a
  • 1 grapheme
  • 1 code point
  • 1 byte
  • 1 UTF-16 unit
What it breaks
The shortest non-empty value, used against minimum-length rules that are rarely tested.
What a correct application does
Accepted or rejected according to a stated minimum, not silently accepted where a minimum exists.