Skip to content

fix: enforce PowerPoint record and formatting bounds - #1051

Merged
andiwand merged 3 commits into
mainfrom
review/33-ppt-record-bounds
Oct 5, 2026
Merged

andiwand merged 3 commits into
mainfrom
review/33-ppt-record-bounds

Conversation

@andiwand

@andiwand andiwand commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Legacy PowerPoint now rejects truncated records and skipped payloads, incomplete persist/property arrays, and pictures extending beyond their store entry. A formatting run past the end of its text is cut, as LibreOffice does. Text-container nesting is bounded, and frame dimensions widen coordinates before subtraction.

Picture decoding now has one shared body reader for direct, embedded, and delayed images. Formatting consumes a remaining-character budget instead of accumulating potentially overflowing counts.

Validation: 15 PowerPoint and legacy-encryption tests pass, including both existing PPT corpus fixtures and four focused synthetic regressions. The fixtures cover record boundaries, nesting, formatting coverage, and extreme anchor coordinates.

@andiwand
andiwand force-pushed the review/32-parser-boundaries branch from e70f246 to c759c79 Compare October 5, 2026 08:29
Base automatically changed from review/32-parser-boundaries to main October 5, 2026 08:39
andiwand and others added 2 commits October 5, 2026 10:39
A formatting run past the end of its text now threw, and the exception
refused the whole presentation. Writers do not always get the counts
exactly right, so the run is now cut to the remaining text, as
LibreOffice does. style_pending already gives characters after the last
run the default style. A body that ends inside a run still throws.

The embedded-BLIP check required the BLIP to fill its store entry
exactly, although it reports a BLIP that exceeds it. It now refuses only
a larger BLIP, and the cursor consumes the bytes that were read, so
padding is skipped.

ppt_style.cpp also includes <algorithm> and <stdexcept>, which it uses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand force-pushed the review/33-ppt-record-bounds branch from e8d8950 to 856d022 Compare October 5, 2026 08:45
The ppt reader had its own skip_bytes. A skip that stops short is the
same failure as a short read, so byte_stream::skip now sits next to
read and throws the same error. It skips a count above streamsize in
steps, so the caller needs no range check. The ppt reader uses it in all
four places.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand merged commit a173659 into main Oct 5, 2026
23 checks passed
@andiwand
andiwand deleted the review/33-ppt-record-bounds branch October 5, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant