Class PdfReaderLimits
Namespace: AdCodicem.Pdf.Documents
Assembly: AdCodicem.Pdf.dll
The reader's guards: bounds on what a file may make the reader hold, set against hostile input, which a document valid under the specification can nonetheless exceed.
public sealed record PdfReaderLimits : IEquatable<PdfReaderLimits>
Inheritance
Implements
Inherited Members
object.Equals(object?), object.Equals(object?, object?), object.GetHashCode(), object.GetType(), object.ReferenceEquals(object?, object?), object.ToString()
Remarks
Every guard is active by default, so an application that opens files it did not produce is protected without configuring anything. One that reads a sound but exceptional document — a large-format scan, a file saved incrementally a thousand times — raises the bound it reached, or chooses [PdfReaderLimits.Unbounded](AdCodicem.Pdf.Documents.PdfReaderLimits#AdCodicem_Pdf_Documents_PdfReaderLimits_Unbounded).
Reaching a guard keeps what fits within it and reports a warning under one of the limit.* codes of
[PdfDiagnosticCodes](AdCodicem.Pdf.Diagnostics.PdfDiagnosticCodes), whose message names the property that lifts it. With
[PdfReaderOptions.ThrowOnLimit](AdCodicem.Pdf.Documents.PdfReaderOptions#AdCodicem_Pdf_Documents_PdfReaderOptions_ThrowOnLimit) it throws [PdfLimitExceededException](AdCodicem.Pdf.Diagnostics.PdfLimitExceededException)
instead.
Bounds that only an invalid file can reach — how deeply containers nest, how many objects a rebuilt index holds — are not options: lifting them would let nothing more be read.
Properties
Default
The guards in force when none are supplied.
public static PdfReaderLimits Default { get; }
Property Value
MaxDecodedStreamLength
Gets the most one stream may decode to, in bytes. Defaults to 256 MB: a compressed stream of a few kilobytes can claim gigabytes, and a scanned map can hold an image of 300 MB.
public int MaxDecodedStreamLength { get; init; }
Property Value
Remarks
A decoded stream is held in one piece, so a value above MaxLength is taken as that length. Reaching it reports PdfDiagnosticCodes.LimitDecodedStream.
Exceptions
The value is zero or less.
MaxObjectLength
Gets the longest object the reader parses, in bytes, the data of a stream aside. Defaults to 16 MB, which a direct array of a million references would need.
public int MaxObjectLength { get; init; }
Property Value
Remarks
A value above MaxLength is taken as that length. Reaching it reports PdfDiagnosticCodes.LimitObject.
Exceptions
The value is zero or less.
MaxTrailerLength
Gets the longest trailer the reader parses, in bytes — a cross-reference stream's dictionary is its trailer. Defaults to 64 KB; real ones are a few hundred bytes.
public int MaxTrailerLength { get; init; }
Property Value
Remarks
A classic trailer that ends within the window its cross-reference table was read through is read whole, whatever its length: the guard bounds how far the reader follows one past that window. A value above MaxLength is taken as that length. Reaching it reports PdfDiagnosticCodes.LimitTrailer.
Exceptions
The value is zero or less.
MaxXRefSectionCount
Gets the most cross-reference sections the reader follows through a chain of updates. Defaults to 1,024; each incremental save adds one.
public int MaxXRefSectionCount { get; init; }
Property Value
Remarks
Reaching it keeps the newest sections and reports PdfDiagnosticCodes.LimitXRefSectionCount.
Exceptions
The value is zero or less.
MaxXRefSectionLength
Gets the longest classic cross-reference section the reader reads, in bytes. Defaults to 64 MB, about 3.3 million entries.
public int MaxXRefSectionLength { get; init; }
Property Value
Remarks
A value above MaxLength is taken as that length. Reaching it keeps the entries read and reports PdfDiagnosticCodes.LimitXRefSectionLength.
Exceptions
The value is zero or less.
Unbounded
Every guard at the most the implementation can hold: MaxLength for a length, MaxValue for a count. For documents the application trusts.
public static PdfReaderLimits Unbounded { get; }