Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 3 additions & 4 deletions src-tauri/src/pdf_engine/source_content.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,9 @@
//! Research prototype only; no Tauri command or UI invokes this module. The
//! source is read once through a hard cap, then both fingerprinted and parsed
//! from that same snapshot. Object values, object streams, and content stream
//! decoding are bounded. Raw xref validation, bounded operator parsing, and
//! font/geometry support are still incomplete. Complete #33's remaining resource
//! bounds and compatibility evaluation before exposing this API to user files or
//! enabling editing.
//! decoding are bounded. Bounded operator parsing and font/geometry support are
//! still incomplete. Complete #33's remaining resource bounds and compatibility
//! evaluation before exposing this API to user files or enabling editing.

use crate::error::AppError;
use crate::pdf_engine::crop;
Expand Down
6 changes: 3 additions & 3 deletions src-tauri/src/pdf_engine/source_content_decode.rs
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ fn check_decode_parms(parms: Option<&Object>) -> Result<(), DecodeError> {
}
}

fn inflate_capped(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
pub(super) fn inflate_capped(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
let mut decoder = Decompress::new(true);
let mut output = Vec::new();
let mut step = vec![0u8; 64 * 1024];
Expand Down Expand Up @@ -145,7 +145,7 @@ fn hex_value(byte: u8) -> Option<u8> {
}
}

fn ascii_hex_decode(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
pub(super) fn ascii_hex_decode(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
let mut output = Vec::new();
let mut high = None;
for &byte in data {
Expand All @@ -167,7 +167,7 @@ fn ascii_hex_decode(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
Ok(output)
}

fn ascii85_decode(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
pub(super) fn ascii85_decode(data: &[u8], cap: usize) -> Result<Vec<u8>, DecodeError> {
let body = data.strip_prefix(b"<~").unwrap_or(data);
let mut output = Vec::new();
let mut group = [0u8; 5];
Expand Down
8 changes: 5 additions & 3 deletions src-tauri/src/pdf_engine/source_content_preflight.rs
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
//! Resource bounds applied before lopdf parses source content.
//!
//! This is deliberately limited to object values and object streams. Raw xref
//! validation and bounded content-operator parsing are separate follow-up work.
//! This bounds raw cross-reference data, object values, and object streams.
//! Bounded content-operator parsing remains separate follow-up work.

mod headers;
mod xref;

use self::headers::Headers;
use crate::error::AppError;
Expand All @@ -13,7 +14,7 @@ use std::ops::Range;
use std::sync::atomic::{AtomicBool, AtomicUsize, Ordering};
use std::sync::Mutex;

const MAX_OBJECTS: usize = 2_000_000;
pub(super) const MAX_OBJECTS: usize = 2_000_000;
const MAX_OBJECT_NESTING: usize = 100;
const OBJECT_SCAN_FACTOR: usize = 2;
const OBJECT_SCAN_SLACK_BYTES: usize = 1 << 20;
Expand All @@ -31,6 +32,7 @@ static OBJSTM_REJECTED: AtomicBool = AtomicBool::new(false);
const REJECTED_OBJSTM: &[u8] = b"OffPdfRejectedObjStm";

pub(super) fn load_document(bytes: &[u8], path: &str) -> Result<Document, AppError> {
xref::check(bytes)?;
check_objects(bytes)?;

// lopdf's object-stream filter is a function pointer. Serialize loads so
Expand Down
Loading
Loading