Skip to content

fix(pdf): fail closed on unsafe content streams - #118

Merged
McanKul merged 1 commit into
developmentfrom
fix/33-classifier-fail-closed
Oct 4, 2026
Merged

McanKul merged 1 commit into
developmentfrom
fix/33-classifier-fail-closed

Conversation

@McanKul

@McanKul McanKul commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • Replace the classifier's decode-or-raw fallback with a bounded decoder for Flate, ASCIIHex, ASCII85, and short filter chains.
  • Reject corrupt streams, predictors, external-file filters, unsupported filters, and output above the 32 MB stream cap with explicit errors.
  • Reject graphics-state nesting above 64 levels instead of silently ignoring extra q operators.
  • Keep this change read-only: no Tauri command, UI, mutation, or save path.

LZW remains intentionally unsupported in this research classifier and fails closed as UNSUPPORTED_FILTER.

Refs #33

Validation

  • cargo check --manifest-path src-tauri/Cargo.toml
  • cargo test --manifest-path src-tauri/Cargo.toml --lib source_content -- --nocapture (41 passed)
  • rustfmt --edition 2021 --check src-tauri/src/pdf_engine/source_content_decode.rs
  • git diff --check

Privacy checklist

  • PDF data remains local.
  • No source or destination file is written by the classifier.
  • Filter errors never fall back to interpreting encoded bytes as PDF operators.

@McanKul
McanKul force-pushed the fix/33-classifier-fail-closed branch from 7859250 to 77ccca9 Compare October 4, 2026 11:14
@McanKul
McanKul merged commit 3d8a15b into development Oct 4, 2026
2 checks passed
@McanKul
McanKul deleted the fix/33-classifier-fail-closed branch October 4, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant