Skip to content

fix(pdf): bound cross-reference parsing - #120

Merged
McanKul merged 1 commit into
developmentfrom
fix/33-xref-preflight
Oct 4, 2026
Merged

McanKul merged 1 commit into
developmentfrom
fix/33-xref-preflight

Conversation

@McanKul

@McanKul McanKul commented Oct 4, 2026

Copy link
Copy Markdown
Owner

What

  • follow the startxref, /Prev, and /XRefStm chain with a hard hop limit
  • parse trailer/xref dictionaries iteratively with token, nesting, name, and string limits
  • cap decoded xref streams and validate /W, /Index, /Size, and PNG predictor row allocations before lopdf runs
  • match lopdf last-key behavior and ignore fake trailer text inside comments

Why

Malformed xref streams can otherwise trigger large allocations before the read-only text classifier reaches its existing object and content-stream limits.

Verification

  • cargo test --manifest-path src-tauri/Cargo.toml --lib (310 passed)
  • cargo test --manifest-path src-tauri/Cargo.toml --lib source_content (55 passed)
  • 10 focused xref tests, including classic tables, Flate streams, duplicate fields, chained sections, overflow, and predictor limits
  • cargo clippy --lib --tests completed; only existing repository warnings remain
  • rustfmt --check and git diff --check

Scope

Read-only classifier only: no command, UI, mutation, release, or main changes. Bounded content-operator parsing remains a separate follow-up PR.

Refs #33

@McanKul
McanKul merged commit 3e80df5 into development Oct 4, 2026
2 checks passed
@McanKul
McanKul deleted the fix/33-xref-preflight branch October 4, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant