Coverage Report

Created: 2025-10-12 07:05

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/qpdf/libqpdf/QPDFParser.cc
Line
Count
Source
1
#include <qpdf/QPDFParser.hh>
2
3
#include <qpdf/QPDF.hh>
4
#include <qpdf/QPDFObjGen.hh>
5
#include <qpdf/QPDFObjectHandle.hh>
6
#include <qpdf/QPDFObject_private.hh>
7
#include <qpdf/QPDFTokenizer_private.hh>
8
#include <qpdf/QTC.hh>
9
#include <qpdf/QUtil.hh>
10
11
#include <memory>
12
13
using namespace std::literals;
14
using namespace qpdf;
15
16
using ObjectPtr = std::shared_ptr<QPDFObject>;
17
18
// The ParseGuard class allows QPDFParser to detect re-entrant parsing. It also provides
19
// special access to allow the parser to create unresolved objects and dangling references.
20
class QPDF::Doc::ParseGuard
21
{
22
  public:
23
    ParseGuard(QPDF* qpdf) :
24
125k
        objects(qpdf ? &qpdf->m->objects : nullptr)
25
125k
    {
26
125k
        if (objects) {
27
117k
            objects->inParse(true);
28
117k
        }
29
125k
    }
30
31
    static std::shared_ptr<QPDFObject>
32
    getObject(QPDF* qpdf, int id, int gen, bool parse_pdf)
33
178k
    {
34
178k
        return qpdf->m->objects.getObjectForParser(id, gen, parse_pdf);
35
178k
    }
36
37
    ~ParseGuard()
38
125k
    {
39
125k
        if (objects) {
40
117k
            objects->inParse(false);
41
117k
        }
42
125k
    }
43
    QPDF::Doc::Objects* objects;
44
};
45
46
using ParseGuard = QPDF::Doc::ParseGuard;
47
48
QPDFObjectHandle
49
QPDFParser::parse(InputSource& input, std::string const& object_description, QPDF* context)
50
7.78k
{
51
7.78k
    qpdf::Tokenizer tokenizer;
52
7.78k
    bool empty = false;
53
7.78k
    return QPDFParser(
54
7.78k
               input,
55
7.78k
               make_description(input.getName(), object_description),
56
7.78k
               object_description,
57
7.78k
               tokenizer,
58
7.78k
               nullptr,
59
7.78k
               context,
60
7.78k
               false)
61
7.78k
        .parse(empty, false);
62
7.78k
}
63
64
QPDFObjectHandle
65
QPDFParser::parse_content(
66
    InputSource& input,
67
    std::shared_ptr<QPDFObject::Description> sp_description,
68
    qpdf::Tokenizer& tokenizer,
69
    QPDF* context)
70
0
{
71
0
    bool empty = false;
72
0
    return QPDFParser(
73
0
               input,
74
0
               std::move(sp_description),
75
0
               "content",
76
0
               tokenizer,
77
0
               nullptr,
78
0
               context,
79
0
               true,
80
0
               0,
81
0
               0,
82
0
               context && context->doc().reconstructed_xref())
83
0
        .parse(empty, true);
84
0
}
85
86
QPDFObjectHandle
87
QPDFParser::parse(
88
    InputSource& input,
89
    std::string const& object_description,
90
    QPDFTokenizer& tokenizer,
91
    bool& empty,
92
    QPDFObjectHandle::StringDecrypter* decrypter,
93
    QPDF* context)
94
0
{
95
0
    return QPDFParser(
96
0
               input,
97
0
               make_description(input.getName(), object_description),
98
0
               object_description,
99
0
               *tokenizer.m,
100
0
               decrypter,
101
0
               context,
102
0
               false)
103
0
        .parse(empty, false);
104
0
}
105
106
std::pair<QPDFObjectHandle, bool>
107
QPDFParser::parse(
108
    InputSource& input,
109
    std::string const& object_description,
110
    qpdf::Tokenizer& tokenizer,
111
    QPDFObjectHandle::StringDecrypter* decrypter,
112
    QPDF& context,
113
    bool sanity_checks)
114
96.3k
{
115
96.3k
    bool empty{false};
116
96.3k
    auto result = QPDFParser(
117
96.3k
                      input,
118
96.3k
                      make_description(input.getName(), object_description),
119
96.3k
                      object_description,
120
96.3k
                      tokenizer,
121
96.3k
                      decrypter,
122
96.3k
                      &context,
123
96.3k
                      true,
124
96.3k
                      0,
125
96.3k
                      0,
126
96.3k
                      sanity_checks)
127
96.3k
                      .parse(empty, false);
128
96.3k
    return {result, empty};
129
96.3k
}
130
131
std::pair<QPDFObjectHandle, bool>
132
QPDFParser::parse(
133
    is::OffsetBuffer& input, int stream_id, int obj_id, qpdf::Tokenizer& tokenizer, QPDF& context)
134
21.1k
{
135
21.1k
    bool empty{false};
136
21.1k
    auto result = QPDFParser(
137
21.1k
                      input,
138
21.1k
                      std::make_shared<QPDFObject::Description>(
139
21.1k
                          QPDFObject::ObjStreamDescr(stream_id, obj_id)),
140
21.1k
                      "",
141
21.1k
                      tokenizer,
142
21.1k
                      nullptr,
143
21.1k
                      &context,
144
21.1k
                      true,
145
21.1k
                      stream_id,
146
21.1k
                      obj_id)
147
21.1k
                      .parse(empty, false);
148
21.1k
    return {result, empty};
149
21.1k
}
150
151
QPDFObjectHandle
152
QPDFParser::parse(bool& empty, bool content_stream)
153
125k
{
154
    // This method must take care not to resolve any objects. Don't check the type of any object
155
    // without first ensuring that it is a direct object. Otherwise, doing so may have the side
156
    // effect of reading the object and changing the file pointer. If you do this, it will cause a
157
    // logic error to be thrown from QPDF::inParse().
158
159
125k
    ParseGuard pg(context);
160
125k
    empty = false;
161
125k
    start = input.tell();
162
163
125k
    if (!tokenizer.nextToken(input, object_description)) {
164
1.58k
        warn(tokenizer.getErrorMessage());
165
1.58k
    }
166
167
125k
    switch (tokenizer.getType()) {
168
916
    case QPDFTokenizer::tt_eof:
169
916
        if (content_stream) {
170
            // In content stream mode, leave object uninitialized to indicate EOF
171
0
            return {};
172
0
        }
173
916
        QTC::TC("qpdf", "QPDFParser eof in parse");
174
916
        warn("unexpected EOF");
175
916
        return {QPDFObject::create<QPDF_Null>()};
176
177
1.92k
    case QPDFTokenizer::tt_bad:
178
1.92k
        QTC::TC("qpdf", "QPDFParser bad token in parse");
179
1.92k
        return {QPDFObject::create<QPDF_Null>()};
180
181
131
    case QPDFTokenizer::tt_brace_open:
182
206
    case QPDFTokenizer::tt_brace_close:
183
206
        QTC::TC("qpdf", "QPDFParser bad brace");
184
206
        warn("treating unexpected brace token as null");
185
206
        return {QPDFObject::create<QPDF_Null>()};
186
187
292
    case QPDFTokenizer::tt_array_close:
188
292
        QTC::TC("qpdf", "QPDFParser bad array close");
189
292
        warn("treating unexpected array close token as null");
190
292
        return {QPDFObject::create<QPDF_Null>()};
191
192
318
    case QPDFTokenizer::tt_dict_close:
193
318
        QTC::TC("qpdf", "QPDFParser bad dictionary close");
194
318
        warn("unexpected dictionary close token");
195
318
        return {QPDFObject::create<QPDF_Null>()};
196
197
9.42k
    case QPDFTokenizer::tt_array_open:
198
94.2k
    case QPDFTokenizer::tt_dict_open:
199
94.2k
        stack.clear();
200
94.2k
        stack.emplace_back(
201
94.2k
            input,
202
94.2k
            (tokenizer.getType() == QPDFTokenizer::tt_array_open) ? st_array : st_dictionary_key);
203
94.2k
        frame = &stack.back();
204
94.2k
        return parseRemainder(content_stream);
205
206
431
    case QPDFTokenizer::tt_bool:
207
431
        return withDescription<QPDF_Bool>(tokenizer.getValue() == "true");
208
209
110
    case QPDFTokenizer::tt_null:
210
110
        return {QPDFObject::create<QPDF_Null>()};
211
212
8.94k
    case QPDFTokenizer::tt_integer:
213
8.94k
        return withDescription<QPDF_Integer>(QUtil::string_to_ll(tokenizer.getValue().c_str()));
214
215
796
    case QPDFTokenizer::tt_real:
216
796
        return withDescription<QPDF_Real>(tokenizer.getValue());
217
218
9.51k
    case QPDFTokenizer::tt_name:
219
9.51k
        return withDescription<QPDF_Name>(tokenizer.getValue());
220
221
6.95k
    case QPDFTokenizer::tt_word:
222
6.95k
        {
223
6.95k
            auto const& value = tokenizer.getValue();
224
6.95k
            if (content_stream) {
225
0
                return withDescription<QPDF_Operator>(value);
226
6.95k
            } else if (value == "endobj") {
227
                // We just saw endobj without having read anything.  Treat this as a null and do
228
                // not move the input source's offset.
229
323
                input.seek(input.getLastOffset(), SEEK_SET);
230
323
                empty = true;
231
323
                return {QPDFObject::create<QPDF_Null>()};
232
6.63k
            } else {
233
6.63k
                QTC::TC("qpdf", "QPDFParser treat word as string");
234
6.63k
                warn("unknown token while reading object; treating as string");
235
6.63k
                return withDescription<QPDF_String>(value);
236
6.63k
            }
237
6.95k
        }
238
239
595
    case QPDFTokenizer::tt_string:
240
595
        if (decrypter) {
241
125
            std::string s{tokenizer.getValue()};
242
125
            decrypter->decryptString(s);
243
125
            return withDescription<QPDF_String>(s);
244
470
        } else {
245
470
            return withDescription<QPDF_String>(tokenizer.getValue());
246
470
        }
247
248
0
    default:
249
0
        warn("treating unknown token type as null while reading object");
250
0
        return {QPDFObject::create<QPDF_Null>()};
251
125k
    }
252
125k
}
253
254
QPDFObjectHandle
255
QPDFParser::parseRemainder(bool content_stream)
256
94.2k
{
257
    // This method must take care not to resolve any objects. Don't check the type of any object
258
    // without first ensuring that it is a direct object. Otherwise, doing so may have the side
259
    // effect of reading the object and changing the file pointer. If you do this, it will cause a
260
    // logic error to be thrown from QPDF::inParse().
261
262
94.2k
    bad_count = 0;
263
94.2k
    bool b_contents = false;
264
265
7.87M
    while (true) {
266
7.87M
        if (!tokenizer.nextToken(input, object_description)) {
267
28.8k
            warn(tokenizer.getErrorMessage());
268
28.8k
        }
269
7.87M
        ++good_count; // optimistically
270
271
7.87M
        if (int_count != 0) {
272
            // Special handling of indirect references. Treat integer tokens as part of an indirect
273
            // reference until proven otherwise.
274
3.70M
            if (tokenizer.getType() == QPDFTokenizer::tt_integer) {
275
3.36M
                if (++int_count > 2) {
276
                    // Process the oldest buffered integer.
277
3.14M
                    addInt(int_count);
278
3.14M
                }
279
3.36M
                last_offset_buffer[int_count % 2] = input.getLastOffset();
280
3.36M
                int_buffer[int_count % 2] = QUtil::string_to_ll(tokenizer.getValue().c_str());
281
3.36M
                continue;
282
283
3.36M
            } else if (
284
333k
                int_count >= 2 && tokenizer.getType() == QPDFTokenizer::tt_word &&
285
196k
                tokenizer.getValue() == "R") {
286
180k
                if (context == nullptr) {
287
0
                    QTC::TC("qpdf", "QPDFParser indirect without context");
288
0
                    throw std::logic_error(
289
0
                        "QPDFParser::parse called without context on an object "
290
0
                        "with indirect references");
291
0
                }
292
180k
                auto id = QIntC::to_int(int_buffer[(int_count - 1) % 2]);
293
180k
                auto gen = QIntC::to_int(int_buffer[(int_count) % 2]);
294
180k
                if (!(id < 1 || gen < 0 || gen >= 65535)) {
295
178k
                    add(ParseGuard::getObject(context, id, gen, parse_pdf));
296
178k
                } else {
297
2.52k
                    QTC::TC("qpdf", "QPDFParser invalid objgen");
298
2.52k
                    addNull();
299
2.52k
                }
300
180k
                int_count = 0;
301
180k
                continue;
302
303
180k
            } else if (int_count > 0) {
304
                // Process the buffered integers before processing the current token.
305
152k
                if (int_count > 1) {
306
44.4k
                    addInt(int_count - 1);
307
44.4k
                }
308
152k
                addInt(int_count);
309
152k
                int_count = 0;
310
152k
            }
311
3.70M
        }
312
313
4.32M
        switch (tokenizer.getType()) {
314
7.89k
        case QPDFTokenizer::tt_eof:
315
7.89k
            warn("parse error while reading object");
316
7.89k
            if (content_stream) {
317
                // In content stream mode, leave object uninitialized to indicate EOF
318
0
                return {};
319
0
            }
320
7.89k
            QTC::TC("qpdf", "QPDFParser eof in parseRemainder");
321
7.89k
            warn("unexpected EOF");
322
7.89k
            return {QPDFObject::create<QPDF_Null>()};
323
324
23.2k
        case QPDFTokenizer::tt_bad:
325
23.2k
            QTC::TC("qpdf", "QPDFParser bad token in parseRemainder");
326
23.2k
            if (tooManyBadTokens()) {
327
807
                return {QPDFObject::create<QPDF_Null>()};
328
807
            }
329
22.4k
            addNull();
330
22.4k
            continue;
331
332
2.55k
        case QPDFTokenizer::tt_brace_open:
333
4.60k
        case QPDFTokenizer::tt_brace_close:
334
4.60k
            QTC::TC("qpdf", "QPDFParser bad brace in parseRemainder");
335
4.60k
            warn("treating unexpected brace token as null");
336
4.60k
            if (tooManyBadTokens()) {
337
332
                return {QPDFObject::create<QPDF_Null>()};
338
332
            }
339
4.26k
            addNull();
340
4.26k
            continue;
341
342
48.5k
        case QPDFTokenizer::tt_array_close:
343
48.5k
            if ((bad_count || sanity_checks) && !max_bad_count) {
344
                // Trigger warning.
345
111
                (void)tooManyBadTokens();
346
111
                return {QPDFObject::create<QPDF_Null>()};
347
111
            }
348
48.4k
            if (frame->state == st_array) {
349
46.9k
                auto object = frame->null_count > 100
350
46.9k
                    ? QPDFObject::create<QPDF_Array>(std::move(frame->olist), true)
351
46.9k
                    : QPDFObject::create<QPDF_Array>(std::move(frame->olist));
352
46.9k
                setDescription(object, frame->offset - 1);
353
                // The `offset` points to the next of "[".  Set the rewind offset to point to the
354
                // beginning of "[". This has been explicitly tested with whitespace surrounding the
355
                // array start delimiter. getLastOffset points to the array end token and therefore
356
                // can't be used here.
357
46.9k
                if (stack.size() <= 1) {
358
903
                    return object;
359
903
                }
360
46.0k
                stack.pop_back();
361
46.0k
                frame = &stack.back();
362
46.0k
                add(std::move(object));
363
46.0k
            } else {
364
1.46k
                QTC::TC("qpdf", "QPDFParser bad array close in parseRemainder");
365
1.46k
                if (sanity_checks) {
366
                    // During sanity checks, assume nesting of containers is corrupt and object is
367
                    // unusable.
368
830
                    warn("unexpected array close token; giving up on reading object");
369
830
                    return {QPDFObject::create<QPDF_Null>()};
370
830
                }
371
635
                warn("treating unexpected array close token as null");
372
635
                if (tooManyBadTokens()) {
373
37
                    return {QPDFObject::create<QPDF_Null>()};
374
37
                }
375
598
                addNull();
376
598
            }
377
46.6k
            continue;
378
379
102k
        case QPDFTokenizer::tt_dict_close:
380
102k
            if ((bad_count || sanity_checks) && !max_bad_count) {
381
                // Trigger warning.
382
178
                (void)tooManyBadTokens();
383
178
                return {QPDFObject::create<QPDF_Null>()};
384
178
            }
385
102k
            if (frame->state <= st_dictionary_value) {
386
                // Attempt to recover more or less gracefully from invalid dictionaries.
387
101k
                auto& dict = frame->dict;
388
389
101k
                if (frame->state == st_dictionary_value) {
390
5.93k
                    QTC::TC("qpdf", "QPDFParser no val for last key");
391
5.93k
                    warn(
392
5.93k
                        frame->offset,
393
5.93k
                        "dictionary ended prematurely; using null as value for last key");
394
5.93k
                    dict[frame->key] = QPDFObject::create<QPDF_Null>();
395
5.93k
                }
396
101k
                if (!frame->olist.empty()) {
397
31.1k
                    if (sanity_checks) {
398
28.5k
                        warn(
399
28.5k
                            frame->offset,
400
28.5k
                            "expected dictionary keys but found non-name objects; ignoring");
401
28.5k
                    } else {
402
2.62k
                        fixMissingKeys();
403
2.62k
                    }
404
31.1k
                }
405
406
101k
                if (!frame->contents_string.empty() && dict.contains("/Type") &&
407
97
                    dict["/Type"].isNameAndEquals("/Sig") && dict.contains("/ByteRange") &&
408
6
                    dict.contains("/Contents") && dict["/Contents"].isString()) {
409
6
                    dict["/Contents"] = QPDFObjectHandle::newString(frame->contents_string);
410
6
                    dict["/Contents"].setParsedOffset(frame->contents_offset);
411
6
                }
412
101k
                auto object = QPDFObject::create<QPDF_Dictionary>(std::move(dict));
413
101k
                setDescription(object, frame->offset - 2);
414
                // The `offset` points to the next of "<<". Set the rewind offset to point to the
415
                // beginning of "<<". This has been explicitly tested with whitespace surrounding
416
                // the dictionary start delimiter. getLastOffset points to the dictionary end token
417
                // and therefore can't be used here.
418
101k
                if (stack.size() <= 1) {
419
73.5k
                    return object;
420
73.5k
                }
421
27.8k
                stack.pop_back();
422
27.8k
                frame = &stack.back();
423
27.8k
                add(std::move(object));
424
27.8k
            } else {
425
950
                if (sanity_checks) {
426
                    // During sanity checks, assume nesting of containers is corrupt and object is
427
                    // unusable.
428
694
                    warn("unexpected dictionary close token; giving up on reading object");
429
694
                    return {QPDFObject::create<QPDF_Null>()};
430
694
                }
431
256
                warn("unexpected dictionary close token");
432
256
                if (tooManyBadTokens()) {
433
36
                    return {QPDFObject::create<QPDF_Null>()};
434
36
                }
435
220
                addNull();
436
220
            }
437
28.0k
            continue;
438
439
130k
        case QPDFTokenizer::tt_array_open:
440
209k
        case QPDFTokenizer::tt_dict_open:
441
209k
            if (stack.size() > 499) {
442
138
                QTC::TC("qpdf", "QPDFParser too deep");
443
138
                warn("ignoring excessively deeply nested data structure");
444
138
                return {QPDFObject::create<QPDF_Null>()};
445
209k
            } else {
446
209k
                b_contents = false;
447
209k
                stack.emplace_back(
448
209k
                    input,
449
209k
                    (tokenizer.getType() == QPDFTokenizer::tt_array_open) ? st_array
450
209k
                                                                          : st_dictionary_key);
451
209k
                frame = &stack.back();
452
209k
                continue;
453
209k
            }
454
455
3.59k
        case QPDFTokenizer::tt_bool:
456
3.59k
            addScalar<QPDF_Bool>(tokenizer.getValue() == "true");
457
3.59k
            continue;
458
459
50.2k
        case QPDFTokenizer::tt_null:
460
50.2k
            addNull();
461
50.2k
            continue;
462
463
333k
        case QPDFTokenizer::tt_integer:
464
333k
            if (!content_stream) {
465
                // Buffer token in case it is part of an indirect reference.
466
333k
                last_offset_buffer[1] = input.getLastOffset();
467
333k
                int_buffer[1] = QUtil::string_to_ll(tokenizer.getValue().c_str());
468
333k
                int_count = 1;
469
333k
            } else {
470
0
                addScalar<QPDF_Integer>(QUtil::string_to_ll(tokenizer.getValue().c_str()));
471
0
            }
472
333k
            continue;
473
474
19.3k
        case QPDFTokenizer::tt_real:
475
19.3k
            addScalar<QPDF_Real>(tokenizer.getValue());
476
19.3k
            continue;
477
478
3.28M
        case QPDFTokenizer::tt_name:
479
3.28M
            if (frame->state == st_dictionary_key) {
480
391k
                frame->key = tokenizer.getValue();
481
391k
                frame->state = st_dictionary_value;
482
391k
                b_contents = decrypter && frame->key == "/Contents";
483
391k
                continue;
484
2.89M
            } else {
485
2.89M
                addScalar<QPDF_Name>(tokenizer.getValue());
486
2.89M
            }
487
2.89M
            continue;
488
489
2.89M
        case QPDFTokenizer::tt_word:
490
159k
            if (content_stream) {
491
0
                addScalar<QPDF_Operator>(tokenizer.getValue());
492
0
                continue;
493
0
            }
494
495
159k
            if (sanity_checks) {
496
154k
                if (tokenizer.getValue() == "endobj" || tokenizer.getValue() == "endstream") {
497
                    // During sanity checks, assume an unexpected endobj or endstream indicates that
498
                    // we are parsing past the end of the object.
499
997
                    warn(
500
997
                        "unexpected 'endobj' or 'endstream' while reading object; giving up on "
501
997
                        "reading object");
502
997
                    return {QPDFObject::create<QPDF_Null>()};
503
997
                }
504
505
153k
                warn("unknown token while reading object; treating as null");
506
153k
                if (tooManyBadTokens()) {
507
5.18k
                    return {QPDFObject::create<QPDF_Null>()};
508
5.18k
                }
509
148k
                addNull();
510
148k
                continue;
511
153k
            }
512
513
5.21k
            QTC::TC("qpdf", "QPDFParser treat word as string in parseRemainder");
514
5.21k
            warn("unknown token while reading object; treating as string");
515
5.21k
            if (tooManyBadTokens()) {
516
158
                return {QPDFObject::create<QPDF_Null>()};
517
158
            }
518
5.05k
            addScalar<QPDF_String>(tokenizer.getValue());
519
520
5.05k
            continue;
521
522
78.3k
        case QPDFTokenizer::tt_string:
523
78.3k
            {
524
78.3k
                auto const& val = tokenizer.getValue();
525
78.3k
                if (decrypter) {
526
11.2k
                    if (b_contents) {
527
394
                        frame->contents_string = val;
528
394
                        frame->contents_offset = input.getLastOffset();
529
394
                        b_contents = false;
530
394
                    }
531
11.2k
                    std::string s{val};
532
11.2k
                    decrypter->decryptString(s);
533
11.2k
                    addScalar<QPDF_String>(s);
534
67.1k
                } else {
535
67.1k
                    addScalar<QPDF_String>(val);
536
67.1k
                }
537
78.3k
            }
538
78.3k
            continue;
539
540
0
        default:
541
0
            warn("treating unknown token type as null while reading object");
542
0
            if (tooManyBadTokens()) {
543
0
                return {QPDFObject::create<QPDF_Null>()};
544
0
            }
545
0
            addNull();
546
4.32M
        }
547
4.32M
    }
548
94.2k
}
549
550
void
551
QPDFParser::add(std::shared_ptr<QPDFObject>&& obj)
552
5.59M
{
553
5.59M
    if (frame->state != st_dictionary_value) {
554
        // If state is st_dictionary_key then there is a missing key. Push onto olist for
555
        // processing once the tt_dict_close token has been found.
556
5.24M
        frame->olist.emplace_back(std::move(obj));
557
5.24M
    } else {
558
351k
        if (auto res = frame->dict.insert_or_assign(frame->key, std::move(obj)); !res.second) {
559
38.8k
            warnDuplicateKey();
560
38.8k
        }
561
351k
        frame->state = st_dictionary_key;
562
351k
    }
563
5.59M
}
564
565
void
566
QPDFParser::addNull()
567
227k
{
568
227k
    const static ObjectPtr null_obj = QPDFObject::create<QPDF_Null>();
569
570
227k
    if (frame->state != st_dictionary_value) {
571
        // If state is st_dictionary_key then there is a missing key. Push onto olist for
572
        // processing once the tt_dict_close token has been found.
573
199k
        frame->olist.emplace_back(null_obj);
574
199k
    } else {
575
27.7k
        if (auto res = frame->dict.insert_or_assign(frame->key, null_obj); !res.second) {
576
6.12k
            warnDuplicateKey();
577
6.12k
        }
578
27.7k
        frame->state = st_dictionary_key;
579
27.7k
    }
580
227k
    ++frame->null_count;
581
227k
}
582
583
void
584
QPDFParser::addInt(int count)
585
3.33M
{
586
3.33M
    auto obj = QPDFObject::create<QPDF_Integer>(int_buffer[count % 2]);
587
3.33M
    obj->setDescription(context, description, last_offset_buffer[count % 2]);
588
3.33M
    add(std::move(obj));
589
3.33M
}
590
591
template <typename T, typename... Args>
592
void
593
QPDFParser::addScalar(Args&&... args)
594
2.99M
{
595
2.99M
    if ((bad_count || sanity_checks) &&
596
2.95M
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
992k
        max_bad_count = 0;
600
992k
        return;
601
992k
    }
602
2.00M
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
2.00M
    obj->setDescription(context, description, input.getLastOffset());
604
2.00M
    add(std::move(obj));
605
2.00M
}
void QPDFParser::addScalar<QPDF_Bool, bool>(bool&&)
Line
Count
Source
594
3.59k
{
595
3.59k
    if ((bad_count || sanity_checks) &&
596
3.29k
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
201
        max_bad_count = 0;
600
201
        return;
601
201
    }
602
3.39k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
3.39k
    obj->setDescription(context, description, input.getLastOffset());
604
3.39k
    add(std::move(obj));
605
3.39k
}
Unexecuted instantiation: void QPDFParser::addScalar<QPDF_Integer, long long>(long long&&)
void QPDFParser::addScalar<QPDF_Real, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
594
19.3k
{
595
19.3k
    if ((bad_count || sanity_checks) &&
596
18.9k
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
428
        max_bad_count = 0;
600
428
        return;
601
428
    }
602
18.9k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
18.9k
    obj->setDescription(context, description, input.getLastOffset());
604
18.9k
    add(std::move(obj));
605
18.9k
}
void QPDFParser::addScalar<QPDF_Name, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
594
2.89M
{
595
2.89M
    if ((bad_count || sanity_checks) &&
596
2.84M
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
991k
        max_bad_count = 0;
600
991k
        return;
601
991k
    }
602
1.89M
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
1.89M
    obj->setDescription(context, description, input.getLastOffset());
604
1.89M
    add(std::move(obj));
605
1.89M
}
Unexecuted instantiation: void QPDFParser::addScalar<QPDF_Operator, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
void QPDFParser::addScalar<QPDF_String, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
594
72.1k
{
595
72.1k
    if ((bad_count || sanity_checks) &&
596
70.6k
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
250
        max_bad_count = 0;
600
250
        return;
601
250
    }
602
71.9k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
71.9k
    obj->setDescription(context, description, input.getLastOffset());
604
71.9k
    add(std::move(obj));
605
71.9k
}
void QPDFParser::addScalar<QPDF_String, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >&)
Line
Count
Source
594
11.2k
{
595
11.2k
    if ((bad_count || sanity_checks) &&
596
11.1k
        (frame->olist.size() > 5'000 || frame->dict.size() > 5'000)) {
597
        // Stop adding scalars. We are going to abort when the close token or a bad token is
598
        // encountered.
599
201
        max_bad_count = 0;
600
201
        return;
601
201
    }
602
11.0k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
603
11.0k
    obj->setDescription(context, description, input.getLastOffset());
604
11.0k
    add(std::move(obj));
605
11.0k
}
606
607
template <typename T, typename... Args>
608
QPDFObjectHandle
609
QPDFParser::withDescription(Args&&... args)
610
26.3k
{
611
26.3k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
26.3k
    obj->setDescription(context, description, start);
613
26.3k
    return {obj};
614
26.3k
}
QPDFObjectHandle QPDFParser::withDescription<QPDF_Bool, bool>(bool&&)
Line
Count
Source
610
431
{
611
431
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
431
    obj->setDescription(context, description, start);
613
431
    return {obj};
614
431
}
QPDFObjectHandle QPDFParser::withDescription<QPDF_Integer, long long>(long long&&)
Line
Count
Source
610
8.87k
{
611
8.87k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
8.87k
    obj->setDescription(context, description, start);
613
8.87k
    return {obj};
614
8.87k
}
QPDFObjectHandle QPDFParser::withDescription<QPDF_Real, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
610
796
{
611
796
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
796
    obj->setDescription(context, description, start);
613
796
    return {obj};
614
796
}
QPDFObjectHandle QPDFParser::withDescription<QPDF_Name, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
610
9.51k
{
611
9.51k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
9.51k
    obj->setDescription(context, description, start);
613
9.51k
    return {obj};
614
9.51k
}
Unexecuted instantiation: QPDFObjectHandle QPDFParser::withDescription<QPDF_Operator, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
QPDFObjectHandle QPDFParser::withDescription<QPDF_String, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&)
Line
Count
Source
610
6.65k
{
611
6.65k
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
6.65k
    obj->setDescription(context, description, start);
613
6.65k
    return {obj};
614
6.65k
}
QPDFObjectHandle QPDFParser::withDescription<QPDF_String, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >&>(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >&)
Line
Count
Source
610
124
{
611
124
    auto obj = QPDFObject::create<T>(std::forward<Args>(args)...);
612
124
    obj->setDescription(context, description, start);
613
124
    return {obj};
614
124
}
615
616
void
617
QPDFParser::setDescription(ObjectPtr& obj, qpdf_offset_t parsed_offset)
618
148k
{
619
148k
    if (obj) {
620
148k
        obj->setDescription(context, description, parsed_offset);
621
148k
    }
622
148k
}
623
624
void
625
QPDFParser::fixMissingKeys()
626
2.62k
{
627
2.62k
    std::set<std::string> names;
628
7.33k
    for (auto& obj: frame->olist) {
629
7.33k
        if (obj.getObj()->getTypeCode() == ::ot_name) {
630
311
            names.insert(obj.getObj()->getStringValue());
631
311
        }
632
7.33k
    }
633
2.62k
    int next_fake_key = 1;
634
7.32k
    for (auto const& item: frame->olist) {
635
7.39k
        while (true) {
636
7.39k
            const std::string key = "/QPDFFake" + std::to_string(next_fake_key++);
637
7.39k
            const bool found_fake = !frame->dict.contains(key) && !names.contains(key);
638
7.39k
            QTC::TC("qpdf", "QPDFParser found fake", (found_fake ? 0 : 1));
639
7.39k
            if (found_fake) {
640
7.32k
                warn(
641
7.32k
                    frame->offset,
642
7.32k
                    "expected dictionary key but found non-name object; inserting key " + key);
643
7.32k
                frame->dict[key] = item;
644
7.32k
                break;
645
7.32k
            }
646
7.39k
        }
647
7.32k
    }
648
2.62k
}
649
650
bool
651
QPDFParser::tooManyBadTokens()
652
186k
{
653
186k
    if (frame->olist.size() > 5'000 || frame->dict.size() > 5'000) {
654
228
        if (bad_count) {
655
188
            warn(
656
188
                "encountered errors while parsing an array or dictionary with more than 5000 "
657
188
                "elements; giving up on reading object");
658
188
            return true;
659
188
        }
660
40
        warn(
661
40
            "encountered an array or dictionary with more than 5000 elements during xref recovery; "
662
40
            "giving up on reading object");
663
40
    }
664
186k
    if (max_bad_count && --max_bad_count > 0 && good_count > 4) {
665
61.1k
        good_count = 0;
666
61.1k
        bad_count = 1;
667
61.1k
        return false;
668
61.1k
    }
669
125k
    if (++bad_count > 5 ||
670
121k
        (frame->state != st_array && QIntC::to_size(max_bad_count) < frame->olist.size())) {
671
        // Give up after 5 errors in close proximity or if the number of missing dictionary keys
672
        // exceeds the remaining number of allowable total errors.
673
6.55k
        warn("too many errors; giving up on reading object");
674
6.55k
        return true;
675
6.55k
    }
676
119k
    good_count = 0;
677
119k
    return false;
678
125k
}
679
680
void
681
QPDFParser::warn(QPDFExc const& e) const
682
315k
{
683
    // If parsing on behalf of a QPDF object and want to give a warning, we can warn through the
684
    // object. If parsing for some other reason, such as an explicit creation of an object from a
685
    // string, then just throw the exception.
686
315k
    if (context) {
687
315k
        context->warn(e);
688
315k
    } else {
689
0
        throw e;
690
0
    }
691
315k
}
692
693
void
694
QPDFParser::warnDuplicateKey()
695
45.0k
{
696
45.0k
    QTC::TC("qpdf", "QPDFParser duplicate dict key");
697
45.0k
    warn(
698
45.0k
        frame->offset,
699
45.0k
        "dictionary has duplicated key " + frame->key + "; last occurrence overrides earlier ones");
700
45.0k
}
701
702
void
703
QPDFParser::warn(qpdf_offset_t offset, std::string const& msg) const
704
315k
{
705
315k
    if (stream_id) {
706
13.0k
        std::string descr = "object "s + std::to_string(obj_id) + " 0";
707
13.0k
        std::string name = context->getFilename() + " object stream " + std::to_string(stream_id);
708
13.0k
        warn(QPDFExc(qpdf_e_damaged_pdf, name, descr, offset, msg));
709
302k
    } else {
710
302k
        warn(QPDFExc(qpdf_e_damaged_pdf, input.getName(), object_description, offset, msg));
711
302k
    }
712
315k
}
713
714
void
715
QPDFParser::warn(std::string const& msg) const
716
228k
{
717
228k
    warn(input.getLastOffset(), msg);
718
228k
}