Repository navigation
fix(pdf): validate incremental writes and restore input state - #1163
Merged
Merged
Conversation
andiwand
force-pushed
the
review/144-pdf-color-ranges
branch
from
October 6, 2026 18:57
7ddc641 to
32d0291
Compare
InputPosition kept a reference member. Members here are pointers, so it holds the stream through one. The bare position() call before the copy only checks that the finished file fits the 32-bit xref offsets, and a comment says so. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxyTMutqSUJRGfxA8CyzMc
andiwand
force-pushed
the
review/145-pdf-writer-validation
branch
from
October 6, 2026 19:01
8189159 to
28db6be
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Generated with Claude Code
PDF incremental writes could silently succeed after an append failure and leave the parser at EOF after a failed copy. Restore its position on success and failure, check output errors and file-size limits, and reject reserved, oversized or conflicting object references before staging them. Both stream and ordinary objects share the reference checks.
Validation: both regression tests fail on the parent; 83 writer, annotation and parser tests pass after the fix. clang-tidy and Android, WebAssembly and iOS object builds pass. Adds two focused tests, including retry after failure and object-ID exhaustion.