Skip to content

fix(font): validate Type1 decoding and cipher arithmetic - #1059

Merged
andiwand merged 3 commits into
mainfrom
review/41-type1-decoding
Oct 5, 2026
Merged

andiwand merged 3 commits into
mainfrom
review/41-type1-decoding

Conversation

@andiwand

@andiwand andiwand commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Type1 cipher arithmetic promoted to signed int and overflowed even on a four-byte input. Compute the recurrence in uint32_t and share the two test encryption helpers. Preserve binary NUL bytes after eexec, support /lenIV -1 charstrings, reject truncated PFB segments, and reuse the shared locale-independent numeric parser. An unreadable number still reads as zero and a too-short charstring as empty, so one bad value does not refuse the font.

Validation: 46 targeted font tests and all 50 PDF corpus cases pass. Existing tests now cover three lenIV modes, a NUL-leading ciphertext and German numeric locale; one regression covers malformed numbers and PFB framing. A standalone UBSan reproducer fails on the previous cipher arithmetic and passes on the fix. Corpus warnings match the preceding branch.

@andiwand
andiwand force-pushed the review/40-cff-parser-bounds branch from f1911e3 to 7eedf8d Compare October 5, 2026 12:02
Base automatically changed from review/40-cff-parser-bounds to main October 5, 2026 12:13
andiwand and others added 2 commits October 5, 2026 14:13
A PDF falls back to a substitute font when its embedded font is refused,
so the page shows the wrong glyphs. As before this change, an unreadable
number reads as zero, an unreadable /lenIV keeps the default of 4, and a
charstring shorter than lenIV decrypts to nothing. A /lenIV below -1 and
bad PFB framing still throw. The tests include the shared helper by its
path, like the other test utilities.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand force-pushed the review/41-type1-decoding branch from 8bf12c4 to d25dc82 Compare October 5, 2026 12:17
Type1, RTF, PDF and the document color parser each decoded hex digits on
their own. util::string now has hex_digit, and the callers use it. RTF
and PDF keep their throwing wrappers. Type1 uses the PostScript white
space of ObjectParser::is_whitespace in place of its own copy. The Type1
hex loops use is_ascii_whitespace, and the eexec boundary has a named
predicate that does not skip NUL or form feed. The document color check
no longer depends on the locale.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb1fLafqqzehpqPuU6uBfn
@andiwand
andiwand merged commit e717106 into main Oct 5, 2026
23 checks passed
@andiwand
andiwand deleted the review/41-type1-decoding branch October 5, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant