Skip to content

fix: validate PDF object tokens and references - #1158

Merged
andiwand merged 2 commits into
mainfrom
review/140-pdf-object-tokens
Oct 6, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/140-pdf-object-tokens

Conversation

@andiwand

@andiwand andiwand commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

PDF object parsing accepted keyword prefixes and wrong-case keywords, truncated names containing regular non-ASCII bytes, and accepted negative or oversized reference indices.

Require complete case-sensitive keywords, preserve regular name bytes, reject null name escapes, and validate reference indices consistently in arrays, dictionary values and explicit references. A repeated dictionary key keeps its first value, as Ghostscript reads it. Shorten the parser contracts. These rules follow ISO 32000-1 §§7.2.2, 7.3.5, 7.3.7, 7.3.10 and 7.5.4; object IDs retain the file parser's 32-bit implementation limit.

Validation: four focused regressions expose 19 failures on the parent implementation. All 117 targeted parser/CMap/writer tests and 50 PDF corpus HTML-generation tests pass. LLVM 22 clang-tidy passes, as do object builds with NDK 28.1, emsdk 3.1.73 and the iOS 15 deployment target.

@andiwand
andiwand force-pushed the review/139-png-test-helpers branch from d17013e to 9a676e4 Compare October 6, 2026 18:21
Base automatically changed from review/139-png-test-helpers to main October 6, 2026 18:24
andiwand and others added 2 commits October 6, 2026 20:25
A repeated key threw, which made the whole dictionary unreadable. Pages
and resources with a repeated /Type or /MediaBox occur in the wild, and
Ghostscript renders them with the first value. The parser keeps the
first value again, as it did before.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MxyTMutqSUJRGfxA8CyzMc
@andiwand
andiwand force-pushed the review/140-pdf-object-tokens branch from adf0a7b to 566cc05 Compare October 6, 2026 18:34
@andiwand
andiwand merged commit f939477 into main Oct 6, 2026
21 of 23 checks passed
@andiwand
andiwand deleted the review/140-pdf-object-tokens branch October 6, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant