pdf_cos 5.1.1
pdf_cos: ^5.1.1 copied to clipboard
COS object layer for PDF: tokenizer, parser, filters (incl. CCITT, JBIG2, JPEG 2000), xref machinery, encryption, and serializer. Pure Dart, web-ready.
Changelog #
5.1.1 #
- Version bump to track the 5.1.1 suite.
5.1.0 #
- Verify P-521 ECDSA signatures. The P-521 order constant was 609 bits instead of the 521-bit NIST n, so every P-521 signature, OpenSSL's and our own, was rejected.
- Make ECDSA about 8-9x faster: Jacobian a=-3 arithmetic with one inversion
per scalar multiplication, Shamir's trick for
u1*G + u2*Q, and curve constants parsed once per curve. P-256 verify goes from 11.3 to 1.3 ms (AOT). Signing uses the same arithmetic and stays byte-identical (RFC 6979).verifyCertificateChainnow verifies each certificate against its issuer once instead of twice. - Stop Flate streams decoding empty on the web. On dart2js, archive's
ZLibDecoderread any bytes after the Adler-32 (a trailing EOL beforeendstream) as a second zlib header, failed it and returned nothing for the whole stream: pages rendered blank, fonts went missing, andCosCompactor(Reduce file size) re-deflated the empty result into the file. The newinflateZlibstops at the final block, as zlib does, andFlateFilteruses it.CosCompactorinflates strictly (header, length and Adler-32 checked) and never replaces a payload of more than 16 bytes with an empty one. The VM path is unchanged. - Key the loaded-object cache by object number in the low bits. The old key
(
objectNumber * 65536 + generation) clustered in the VM's int hash, so whole-graph walks spent most of their time probing:PdfCompressor.optimizeruns 0.39-0.69x andapplyRedactionsabout 0.31x on 14k-37k-object files. References the packed key cannot hold exactly (an object number of 2^32 or more, as an edit on a file with a junk /Size allocates, or a generation over 65535) are cached in a side map, which also stopsn 65536 Rresolving to object n+1. - Decode JPEG 2000 about twice as fast, byte-identical: EBCOT tier-1 keeps neighbour significance incrementally, and the inverse wavelet lifts with stride-2 parity loops.
- Run AES with word-oriented T-tables, about 7x faster, byte-identical. AES-128/256 streams decrypt faster everywhere, and an R6 (AES-256) open goes from 28.9 to 9.8 ms (AOT).
- On the web, compute Algorithm 2.B's SHA-384/512 on 32-bit halves instead of package:crypto's emulated 64-bit words, so an R6 open in the browser is about 7x faster. The VM keeps package:crypto.
applyIncrementalUpdatenow folds edits into a document opened through xref recovery instead of refusing it, so each edit no longer re-runs a full-file recovery scan. The recovery scan itself is one pass for bothobjandtrailer(0.56-0.61x on large files).- Add
CosDocument.rollbackTo(length), which takes a document back to an earlier revision it folded in withapplyIncrementalUpdate, in place, keeping the caches of objects the undone updates did not touch. It returns null, changing nothing, when that length is not journaled. CosDocument.openAppendedaccepts an earlier revision's prefix as well as an append, and takes apasswordfor revisions it cannot donate keys to. It donates the security handler only while the revision's /Encrypt matches the dictionary the keys were derived from, entry for entry, so a revision that re-keys /Encrypt under the same object number authenticates its own password.- Add
ContentOperationCursor.nextOperatorandtakeOperation, andCosTokenBuffer.keywordCode, so an interpreter can dispatch short operators on an int code and read numeric operands without allocating operation objects.nextOperationandparsekeep their contract, and materialized operands follow the same int-or-real rule on the web as on the VM. - Add
PdfPerfcounters for glyph outline builds and the overprint colorant buffer (glyphOutlinePaths,colorantBufferPages,colorantDraws,colorantRasterized,colorantBackdropReads,colorantGroups).
5.0.0 #
Breaking changes #
StandardSecurityHandler.decryptObjectGraph(andencryptObjectGraph) now leave a signature dictionary's /Contents untouched, as ISO 32000 7.6.1 requires (StandardSecurityHandler.isSignatureContents: /Type /Sig or /DocTimeStamp, or a dictionary with a /ByteRange when /Type is missing). Code that decrypted /Contents itself after loading must stop doing so - the loader now hands over the raw CMS bytes.- OCSP delegated responders are accepted only when the CA issued and signed
them and they carry id-kp-OCSPSigning (
OcspResponse.responderFor), andOcspResponse.forCertificatematches the whole CertID. Responses that used to pass on a serial match alone, or from an unauthorized responder, are now ignored. X509Certificategained members (listed below). Only classes thatimplements X509Certificateneed to add them.
Changes #
- Add
CosDocument.openAppended, which reopens a document after appended updates and reuses its already-authenticated security handler (while the /Encrypt object is unchanged), so follow-on revisions of an encrypted file do not need the password again. - Harden OCSP for revocation checking:
OcspResponse.forCertificatematches the whole CertID (serial, issuer name hash and issuer key hash) instead of the serial alone, a delegated responder must be issued and signed by the CA and carry id-kp-OCSPSigning (responderFor), and the nonce extension and revocation reason are parsed (nonce,echoesNonce,ocspNonceValue). X509CertificateexposesextendedKeyUsages,isCa,hasOcspNoCheckandisValidAt, and now reads the RSA key of an id-RSASSA-PSS certificate.issueCertificatecan add OCSP (AIA), CRL distribution point, extended key usage and ocsp-nocheck extensions, and can issue a subordinate CA (isCa).
4.5.0 #
- Align dependency constraints with the dart-pdf 4.5.0 package suite.
4.4.0 #
- Accumulate numeric values in the lexer while scanning their boundaries, removing a second byte pass over every number. Integer and decimal precision limits and malformed-input fallback behaviour are unchanged.
4.3.0 #
- Recompress Flate streams losslessly in
CosCompactor, retaining predictor data and parameters. Preserve cyclic indirect arrays and PDF 2.0 headers. - Add opt-in exact real serialization to the serializer/builder and enable it for compaction, avoiding outline changes from rounded font matrices.
- Refuse compaction of incomplete progressive sources.
- Expose immutable populated-range snapshots for transferring sparse buffers, and retain their metadata when reopening or appending a revision.
4.2.0 #
- Lockstep minor release aligned with
dart_pdf_editor4.2.0. No public COS object model, filter, or parsing changes since 4.1.0.
4.1.0 #
- Treat holes in sparse progressive byte sources as cache misses tied to the source buffer, avoiding invalid scan recovery and stale reads while remote PDFs are still arriving.
- Update
archiveto 4.2.0.
4.0.0 #
- Decode TIFF Predictor 2 streams with 16-bit samples, preserving carries between bytes and restoring high-bit-depth images correctly.
- Lockstep major release for the dart-pdf 4.0.0 package suite. The
pdf_cospublic API remains source-compatible with 3.8.0.
3.8.0 #
- Add the public monotonic
CosDocument.revision, incremented after every successful incremental update so higher layers can invalidate derived caches without comparing object identity.
3.7.0 #
- Lockstep minor release to align the dart-pdf package suite at 3.7.0. No
public
pdf_cosAPI changes since 3.6.0.
3.6.0 #
- Lockstep minor release to align the dart-pdf package suite at 3.6.0. No
public
pdf_cosAPI changes since 3.5.1.
3.5.1 #
- Decode JBIG2 refined text symbols, including refinement deltas, offsets, and shared arithmetic contexts, so scanned MRC text layers render correctly.
3.5.0 #
- Add
PdfSourceLoadOptions.completeFirstPaintPageTree. Progressive preview callers can stop the initial page-tree walk afterfirstPaintPages, avoiding one range request per leaf before page one can paint; the default remains the correctness-first complete walk for existing callers. - Reduce allocation and cache pressure in byte sources, the lexer, and content parsing while retaining the parser's lenient handling of malformed PDFs.
3.4.0 #
- Lockstep minor release to align the dart-pdf package suite at 3.4.0. No
public
pdf_cosAPI changes since 3.3.1.
3.3.1 #
- Lockstep patch release to align the dart-pdf package suite at 3.3.1. No
public
pdf_cosAPI changes since 3.3.0.
3.3.0 #
- Lockstep minor release to align the dart-pdf package suite at 3.3.0. No
public
pdf_cosAPI changes since 3.2.0.
3.2.0 #
- Lockstep minor release to align the dart-pdf package suite at 3.2.0. No
public
pdf_cosAPI changes since 3.1.1.
3.1.1 #
- Lockstep patch release to align the dart-pdf package suite at 3.1.1. No
public
pdf_cosAPI changes since 3.1.0.
3.1.0 #
- Lossless structural compaction: new
CosCompactor/CosCompactionResultrewrite a document's reachable object graph, packing non-stream objects into compressed object streams behind a PDF 1.5 xref stream and re-deflating streams stored uncompressed (kept only when smaller).CosDocumentBuildergains anobjectStreams:mode (W [1 4 2]). The user-facing entry point isPdfEditor.compress()inpdf_document(#368). - JPX (JPEG 2000) resolution-level skip: decode at a reduced
cp_reducelevel when an image is displayed far below its native size, instead of decoding full resolution and downscaling (#525). - Cache decoded JBIG2 globals dictionaries across images on the same page -
scanned books with shared
/JBIG2Globalsdecode once, not per image (#532). - Int-key the loaded-object cache so warm resolves allocate nothing (#522), and drop the double copy of every inflated stream (#533).
3.0.0 #
Lockstep major release: a breaking change in dart_pdf_editor moves the whole
suite to 3.0.0. pdf_cos's own public API is unchanged.
- Cache decoded stream bytes on
CosDocumentso a stream inflated once (xref reconstruction, content parsing, image extraction) is not re-decoded on the next access (#392). - Perf micro-batch: chunked message-digest hashing, an in-place JPX inverse DWT, and predictor/lexer/regex fast-path fixes (#407).
2.1.0 #
-
Append incremental saves to the existing bytes instead of rebuilding the whole file:
CosUpdater.saveTail()returns only the new tail (the appended objects, xref, and trailer), so an incremental revision costs the size of the change rather than the size of the document. Save cost no longer scales with the base file - a guard test pins that a 2.78x larger base does not make a same-sized edit 2.78x more expensive (#413). -
Memoise the per-object decryption key so a page's streams and strings derive it once per object rather than once per access, cutting repeated MD5/AES key derivation on encrypted documents (#400).
-
Speed up CCITT G3/G4 decoding by ~4x on dense scanned pages: a monotonic cursor for the 2-D reference-row scan (was O(transitions^2) per row), peek-once prefix tables for run and mode codes, byte-run span fills, and a byte-at-a-time bit reader. The JBIG2 MMR path, which reuses the same decoder, gains a byte-at-a-time bitmap unpack. Output is byte-identical on well-formed, malformed, and truncated input, locked by golden digests captured from the previous implementation (#398).
2.0.0 #
- Major version bump for the 2.0.0 package suite. A breaking API change in
dart_pdf_editormoves every package to 2.0.0 in lockstep; the COS object model, syntax, and (de)serialization API is source-compatible with 1.4.7. - Add an asynchronous byte-source API (
PdfByteSource) for progressive PDF loading: the reader pulls ranged slices on demand instead of requiring the whole file up front, so remote and large local files can paint their first page before the full download or read completes (#328, #359). - Decode PDF text strings as PDFDocEncoding rather than Latin-1, so document metadata and outline titles that use PDFDocEncoding-specific code points round-trip correctly (#347).
- Add the crypto primitives behind one-tap and keyless signing identities:
P-256
EcPrivateKey.generate, deterministic RFC 6979ecdsaSign, the X.509 v3 buildersbuildSelfSignedCertificate/buildCaCertificate/issueCertificate, andecSubjectPublicKeyInfo/pemEncodefor Sigstore/Fulcio (#322, #337, #355). - Internal refactors with no public API change: extract
CosXrefReaderfromCosDocument, move the encryption object-graph walk behind the security handler, share file-tail framing between the builder and updater, and dedupe ObjStm header parsing between recovery and the stream decoder.
1.4.7 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.7. No COS API changes since 1.4.6.
1.4.6 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.6. No COS API changes since 1.4.5.
1.4.5 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.5. No COS API changes since 1.4.4.
1.4.4 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.4. No COS API changes since 1.4.3.
1.4.3 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.3. No COS API changes since 1.4.2.
1.4.2 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.2. No COS API changes since 1.4.1.
1.4.1 #
- Speed up dense content parsing with byte-level real-number parsing, operator interning, and streaming content-token handling.
- Keep the low-level parser and writer compatible with the rendering and editing improvements in the 1.4.1 package suite.
1.4.0 #
- Version bump to keep the dart-pdf package suite aligned at 1.4.0. Low-level parser, writer, filter, and crypto maintenance supports the higher-level editor and document features in this release.
1.3.2 #
- Version bump to keep the dart-pdf package suite aligned at 1.3.2. No COS API changes since 1.3.1.
1.3.1 #
- Add
ContentStreamSerializerfor writing parsed content-stream operations back to PDF syntax, including inline-image (BI/ID/EI) operations.
1.2.3 #
- Version bump to keep the dart-pdf package suite aligned at 1.2.3. No COS API changes since 1.2.2.
1.2.2 #
- Version bump to keep the dart-pdf package suite aligned at 1.2.2. No COS API changes since 1.2.1.
1.2.1 #
- Add a package example for pub.dev scoring.
1.2.0 #
- Version bump to keep the dart-pdf package suite aligned at 1.2.0. No low-level COS API changes since 1.1.0.
1.1.0 #
- Performance: a faster content-stream tokenizer. This is the heart of the render-speed work that puts dart-pdf ahead of PDFium on the benchmark corpus.
- Fix: JPEG 2000 tile-part desynchronization, and indexed Lab color palettes now decode correctly.
1.0.0 #
First stable release. Changes since 0.1.0:
- JBIG2: Huffman-coded symbol dictionaries and text regions, generic refinement regions, and pattern dictionaries with halftone regions.
- JPEG 2000: reset-probabilities (RESET) code-block style support.
- Inline images: correct data-length detection for DCT-filtered streams.
0.1.0 #
Initial release.
- COS object model: dictionaries, arrays, names, strings, streams, references.
- Lenient tokenizer/parser for real-world PDFs (broken /Length, missing
endobj, junk before the header, broken xref chains with object-scan recovery). - Cross-reference tables and streams; lazy object loading; incremental updates.
- Filters: Flate, LZW, RunLength, ASCIIHex, ASCII85, DCT passthrough, CCITT G3/G4, JBIG2 (embedded profile), JPEG 2000.
- Encryption: RC4, AES-128, AES-256 decryption and encrypt-on-write.
- Crypto primitives for signing/validation: ASN.1, RSA, ECDSA, CMS, X.509 chain verification.
- Content-stream tokenizer and a from-scratch document builder.