Skip to content

fix(pdf): preflight content before parsing - #121

Merged
McanKul merged 1 commit into
developmentfrom
fix/33-content-preflight
Oct 4, 2026
Merged

McanKul merged 1 commit into
developmentfrom
fix/33-content-preflight

Conversation

@McanKul

@McanKul McanKul commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • bound content operations, operands, recursive containers, strings, and inline-image dictionaries before lopdf parses them
  • sanitize only inline-image payloads whose boundary is proven by length, decoded size, or a supported filter terminator
  • fail closed for malformed, oversized, or unprovable inline-image content, including DCT payload boundaries
  • keep the M4 classifier read-only; no UI, mutation, release, or main-branch changes

Verification

  • cargo test --lib source_content — 63 passed
  • cargo test --lib — 320 passed
  • cargo clippy --lib --tests — no new warnings attributable to this change

Refs #33

@McanKul
McanKul merged commit 79ed37a into development Oct 4, 2026
2 checks passed
@McanKul
McanKul deleted the fix/33-content-preflight branch October 4, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant