Skip to content

fix: validate PDF color-space recursion and dimensions - #1150

Merged
andiwand merged 2 commits into
mainfrom
review/132-pdf-color-validation
Oct 6, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/132-pdf-color-validation

Conversation

@andiwand

@andiwand andiwand commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Recursive PDF color-space arrays and resource aliases could exhaust the stack. ICC component counts were narrowed without validation, and Indexed palette values were rounded before clipping. The shared parser now carries a 64-level limit through named resolution, checks ICC counts, validates the palette range, and rejects missing bases. An ICC alternate with another component count is dropped for the device space N names, and a short palette reads its missing bytes as 0, so a usable space is never rejected for these. Finite palette indices clip before conversion.

Separation and DeviceN share their common parse path; DeviceN requires nonempty colorant names. Uncolored patterns inherit the base component count. Validation follows ISO 32000-1 §§8.6.5.5 and 8.6.6.

Validation: parent fails the large-index and malformed-definition regressions; 176 focused color, parser, image, shading and extraction tests pass. All 50 PDF corpus metadata/HTML-generation cases pass (no visual comparison). LLVM 22 clang-tidy passes for the three changed implementation files; the color parser compiles to objects for NDK 28.1, emsdk 3.1.73 and iOS 15.

@andiwand
andiwand force-pushed the review/131-formatting-scripts branch from f9f2f49 to 71a68f5 Compare October 6, 2026 17:02
Base automatically changed from review/131-formatting-scripts to main October 6, 2026 17:16
andiwand and others added 2 commits October 6, 2026 19:16
…ette

An ICCBased space whose Alternate has another component count, or does
not parse, now drops the alternate and uses the device space N names,
where it rejected the whole space. An Indexed palette shorter than HiVal
asks for keeps its entries and reads the missing bytes as 0, as before.
A rejected space made scn read an Indexed colour as a grey index, so the
valid entries showed wrong colours too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MxyTMutqSUJRGfxA8CyzMc
@andiwand
andiwand force-pushed the review/132-pdf-color-validation branch from c17a83d to 0df3144 Compare October 6, 2026 17:24
@andiwand
andiwand merged commit 0caa11d into main Oct 6, 2026
25 of 27 checks passed
@andiwand
andiwand deleted the review/132-pdf-color-validation branch October 6, 2026 17:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant