Skip to content

fix: validate BIFF record and worksheet boundaries - #1054

Merged
andiwand merged 2 commits into
mainfrom
review/36-xls-record-validation
Oct 5, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/36-xls-record-validation

Conversation

@andiwand

@andiwand andiwand commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Legacy Excel now distinguishes truncated BIFF records from a clean end of stream, checks skipped bodies, and requires the right substream type in BOF. As in LibreOffice, a cell outside the BIFF8 grid is dropped, Dimensions is clamped, MulRk ignores colLast, and a string formula without its String record stays empty. SST storage grows with the strings read and does not trust the declared count. Numeric formatting uses locale-independent fmt.

Validation: 25 Excel/encryption tests pass, including six XLS corpus cases. Focused regressions cover partial headers, skipped bodies, missing terminators, count/range errors, MulRk’s final column, and a German numeric locale.

@andiwand
andiwand force-pushed the review/35-doc-table-bounds branch from 4594dc0 to c1bbcc0 Compare October 5, 2026 09:06
Base automatically changed from review/35-doc-table-bounds to main October 5, 2026 09:16
andiwand and others added 2 commits October 5, 2026 11:18
LibreOffice opens a workbook with these quirks, so the parser now accepts
them too: a cell outside the BIFF8 grid is dropped, Dimensions is clamped,
MulRk ignores colLast, a string formula without its String record stays
empty, a clean end of stream ends a substream, and cstTotal is not checked.
The record bounds stay strict. Skipped bodies use byte_stream::skip.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand force-pushed the review/36-xls-record-validation branch from ad4a373 to 916f8c4 Compare October 5, 2026 09:26
@andiwand
andiwand merged commit 49cbaf8 into main Oct 5, 2026
23 checks passed
@andiwand
andiwand deleted the review/36-xls-record-validation branch October 5, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant