Console View
|
|
|
|||
| 0909f0390c70... |
William Bader
william.bader@gmail.com |
|
|
|
Re-decode a JPEG 2000 stream after it has been closed close() frees the decoded image and sets npixels to 0, but left inited set, so init() never ran again and every later read returned EOF -- while rewind() still reported success. Anything that closed a JPXStream and read it again got a silently empty stream. Clear inited in rewind() when the image is gone so the next read decodes again. Decoding is expensive and rewind() is called routinely, so the counters-only path is kept for the common case where the image is still there. Without this, pdftops -preload writes blank pages for WinterClientUpdate-poppler.pdf, 2015SpringClientUpdate-poppler-jpeg-bug.pdf and Ghent_PDF-Output-Test-V50_ALL_X4.pdf: setupImage() closes the stream between its two encoding passes, so the second pass sees an empty stream and emits an array declared at its full size holding a single empty entry. Ghostscript renders the first of those as four byte-identical blank pages; with this fix the pages match what pdftoppm renders from the PDF. No measurable speed change. pdfimages and pdftoppm output on those three files is unchanged (131 output files compared). |
|||
| 94c499fea349... |
William Bader
william@newspapersystems.com |
|
|
|
Fix shift overflow when a sampled function has 32-bit samples sampleBits is validated to be between 1 and 32, so 1 << sampleBits shifts an int by its full width: Function.cc:376: runtime error: shift exponent 32 is too large for 32-bit type 'int' bitMask is only read in the branch that unpacks sample sizes other than 8, 16 and 32, so the bad value was never used, but the shift itself is undefined. Shift a 64-bit value instead. Found with -fsanitize=undefined. |
|||
| 00b351675404... |
William Bader
william@newspapersystems.com |
|
|
|
Fix signed integer overflow in Type 1C eexec encryption r1/r2 are unsigned short and the plaintext byte is unsigned char, so both promote to int and the multiplication overflows int for most inputs: FoFiType1C.cc:1622: signed integer overflow: 64690 * 52845 cannot be represented in type 'int' The result is immediately truncated back to unsigned short, so the intended arithmetic is modulo 65536. Do the multiplication in unsigned, where the wraparound is defined, and make the truncation explicit. The generated PostScript is unchanged. Found with -fsanitize=undefined. |
|||
| f121ecc8dd48... |
William Bader
william@newspapersystems.com |
|
|
|
Fix out-of-bounds read compositing a knockout group The knockout result alpha aResult = aSrc + div255(aDest * (255 - pipe->shape)) can reach 510, but aResult is an unsigned char, so it wraps. This happens when the pipe does not use the shape: aSrc is then pipe->aInput at full strength while the backdrop term still scales by pipe->shape, which drawAALine() sets from the antialiasing coverage. aResult wrapping makes alphaI smaller than aSrc, so ((alphaI - aSrc) * cDest[i] + aSrc * cSrc[i]) / alphaI is no longer a weighted average of two values in [0,255] and leaves that range in both directions. It indexes the 256-entry transfer arrays in SplashState, and because a wrapped alphaI can be close to zero the index can become very large, reading well outside the object: Splash.cc:666: runtime error: index 311 out of bounds for type 'unsigned char [256]' Splash.cc:667: runtime error: index 278 out of bounds for type 'unsigned char [256]' Splash.cc:668: runtime error: index -74 out of bounds for type 'unsigned char [256]' ERROR: AddressSanitizer: heap-buffer-overflow, READ of size 1 Clamp aResult, which is what the other alpha expressions here already do via clip255(). An alpha of 1 is the correct saturation, and clamping also restores alphaI >= aSrc, so the color index is in range again. The other two result alpha expressions were checked over all inputs and cannot exceed 255, so only the two knockout ones need this. Found with -fsanitize=address,undefined. Of 87 test files, 86 render identically; the one that triggers this previously aborted under ASan instead of rendering. |
|||
|
|||
| c8dc23d564f2... |
Sune Vuorela
sune@vuorela.dk |
|
|
| test: Fix build with some standard-libraries | |||
| 0c9cf7ce6ece... |
Albert Astals Cid
aacid@kde.org |
|
|
| CI: Use Fedora 45 | |||
| f2ef272f822f... |
Sune Vuorela
sune@vuorela.dk |
|
|
| eidas (cades-b) support and infrastructure for more | |||
| d363ae7996be... |
Andreas Sturmlechner
asturm@gentoo.org |
|
|
|
Conditionalise test builds/deps more effectively * Avoid needing to explicitly disable tests when the respective toolkit is disabled by gating subdirs for qt5/qt6. * Conditionalise some test dep searches on the relevant build option, not the underlying toolkit. * Make the test options default to whether the respective toolkit is on. Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> Signed-off-by: Sam James <sam@gentoo.org> |
|||
| e27aebe5396d... |
Sune Vuorela
sune@vuorela.dk |
|
|
|
Fix rendition media api internally We were doing some optionally with pointers, but returned address of stack variables and checking for null; that would always fail. Do things with std::optional instead |
|||
| eba77c0ad798... |
Sune Vuorela
sune@vuorela.dk |
|
|
|
Let NSS reuse request-password callback for pin If password callback exist, use it rather than just fail if provided password is bad. This also can help doing fewer signatures in certain cases, especially the case where a hardware token needs to be touched on each operation; here we should get fewer interactions. |
|||
| a7fa63e85835... |
Albert Astals Cid
aacid@kde.org |
|
|
|
Let SEC_ERROR_UNTRUSTED_ISSUER win even if it's not the first error Because this is something the user can potentially fix |
|||
| 782409eded77... |
Albert Astals Cid
aacid@kde.org |
|
|
|
NSS: Fix previous commit array size Apologies |
|||
| 2341db931576... |
Albert Astals Cid
aacid@kde.org |
|
|
| NSS: Be a bit more lenient on what we consider valid cert usage | |||
| 6a9064bc4c08... |
Sune Vuorela
sune@vuorela.dk |
|
|
| Qt: Map the annotation rules flags a bit closer to the spec | |||
| 4ea82ed4e341... |
Sune Vuorela
sune@vuorela.dk |
|
|
|
Qt Signatures: Deprecate publicKey function This is the raw public key or 'the prime(s)' or curve parameters. We don't have them in all cases, and there is no reason to present it to user anyways. |
|||
| aafae2f0bd14... |
Albert Astals Cid
aacid@kde.org |
|
|
| Remove unused ArgKind enum values | |||
| 2ec4523b1675... |
Albert Astals Cid
aacid@kde.org |
|
|
|
XRef::getEntry: Fix limit check Fixes un-initialized memory read on broken files |
|||
| 4fc1c20f120a... |
Albert Astals Cid
aacid@kde.org |
|
|
| ossfuzz: Build brotli | |||
| 90a79db1394c... |
Albert Astals Cid
aacid@kde.org |
|
|
|
CI: Increase minimum clang macos simulation We don't support macos 10.4 anymore |
|||
| dca5f098698e... |
Albert Astals Cid
aacid@kde.org |
|
|
| Fix crash on malformed documents | |||
| 11448b90a804... |
Sune Vuorela
sune@vuorela.dk |
|
|
| Enable brotli streams | |||
| 978549e8a1af... |
Albert Astals Cid
aacid@kde.org |
|
|
|
Fix rendering of some Forms If we are modifying the Fonts and it's a ref (as opossed to just be a inside the dict itself), we need to tell xref that we changed the object, otherwise whoever fetches the object again will not magically get the new data |
|||
| 3e090f4e508b... |
ju1ius
jules.bernable@gmail.com |
|
|
|
catalog: fix dest dict to name tree fallback when resolving named destination. Closes #1788 |
|||
| be09305851e3... |
Sune Vuorela
sune@vuorela.dk |
|
|
|
NSS: export internal error code in weird error msg the PORT_GetError call can give us a hint on what goes wrong (These are still in the area of error messages that hopefully dont reach the user, but if they do, they would need our help to figure things out) |
|||
| 35626a614d3c... |
Sune Vuorela
sune@vuorela.dk |
|
|
| Write some error message if signing fails | |||
| 88d9d46874e7... |
Sune Vuorela
sune@vuorela.dk |
|
|
|
Build system: dont scan for c++ modules We don't currently use or provide them, so no need to do the work to support it. |
|||
| 557c83abb9a1... |
Sune Vuorela
sune@vuorela.dk |
|
|
| Fix a format string | |||
| eead04e06bbf... |
ojasmaheshwari
ojasmaheshwari@gmail.com |
|
|
| Build and enable harfbuzz | |||
| 4b6c157de6a6... |
William Bader
william@newspapersystems.com |
|
|
| Change .gitignore from /build/ to /build*/ to allow multiple builds. | |||
| 0e61e7e6a324... |
Albert Astals Cid
aacid@kde.org |
|
|
|
Improve code a bit when finding fonts fails Be verbose that finding failed and do not try to add anything if it does not have a file |
|||
| 878669585dd3... |
Sune Vuorela
sune@vuorela.dk |
|
|
| NSS Signatures: Mark hardware keys as such | |||
| f1f861a969af... |
Funda Wang
fundawang@yeah.net |
|
|
|
Fix intermittent glib API docs build failure ninja could run make-glib-api-docs in parallel with g-ir-scanner, both sharing the glib build dir (g-ir-scanner writes tmp-introspect* temp files there while gtkdoc-scan scans that dir). Depend the docs stamp on the gir-typelibs target when introspection is enabled to serialize them. Co-Authored-By: AtomCode (deepseek-v4-flash) <noreply@atomgit.com> |
|||
| 1ce3f34b4487... |
Albert Astals Cid
aacid@kde.org |
|
|
| Increase version so people that track master can add ifdefs on version | |||
| e661b7b61a1b... |
Albert Astals Cid
aacid@kde.org |
|
|
| poppler 26.09.0 | |||
| cbf801f06fbd... |
Albert Astals Cid
aacid@kde.org |
|
|
|
Revert "Fix intermittent glib API docs build failure" This reverts commit ad34cc58a1a3542d10bb98b7212ac8c0314bfba9. |
|||
| c1948b1d66b2... |
Albert Astals Cid
aacid@kde.org |
|
|
| Update (C) | |||
| 737000618edf... |
Albert Astals Cid
aacid@kde.org |
|
|
| Make redundant-qualified-alias from clang-tidy 23 happy | |||
| ad34cc58a1a3... |
Funda Wang
fundawang@yeah.net |
|
|
|
Fix intermittent glib API docs build failure Fixes #1781 |
|||
| 2191210e5804... |
Ojas Maheshwari
workonlyojas@gmail.com |
|
|
| Font subsetting for form fields | |||
| 0cc3f68f4357... |
Albert Astals Cid
aacid@kde.org |
|
|
| Add std::move as suggested by clang-tidy 23 | |||