- `convertRGBToRGBA` ignored the `byteOffset` of the source, which isn't zero
when e.g. the data of an uncompressed image is read directly from the file,
and it threw when the source wasn't 4-byte aligned. In that case all the
pixels are now converted one by one.
It also used `len >> 2`, which overflows for sources larger than 2 GiB.
- In `ImageResizer.#rescaleImageData`, when the image had to be converted in
several chunks:
- if the chunk height divided the image height, the last chunk was converted
with the full image height;
- the rows were sampled relatively to each chunk, hence a chunk height which
isn't a multiple of `2 ** K` shifted the sub-sampling grid and left the
last rows of the result empty. They're now sampled on the image grid;
- the chunk height is rounded to a multiple of 4 when possible, in order to
keep the RGB data aligned;
- if not even a single row fitted in the buffer, the loop never ended.
Expose function input/output counts and reject incompatible shading and
stitching functions.
Reuse interpolation buffers instead of allocating cube vertices per call.
Skip axes at integer sample coordinates, fixing invalid sample accesses
for Size=1 axes.
For functions with more than eight inputs, use simplex interpolation.
It reads at most m + 1 sample-table entries per output for m inputs,
instead of up to 2^m. It can produce different values from multilinear
interpolation.
Resizing the canvas in #getAscent reset ctx.font to 10px sans-serif
without updating #canvasCtxFonts. A subsequent 30px run using the
same family could skip setting the font and get an incorrect width.
Remove the resizing left over from the pixel-based fallback removed
in PR #19399. Add a regression test comparing 30px and 33px runs.
Reject invalid INDEX offset sizes and clamp offsets to prevent overlapping
entries and repeated parsing of the same data.
Limit FDArray parsing to the 256 entries addressable by FDSelect's Card8
indices. Reject format 3 ranges before they expand past the glyph count.
Fold rows, then columns, and cap offsets by the rendered tile dimensions.
For the 10x10 fixture with 0.001 steps at scale 1, this reduces folding
from 100,020,001 drawImage calls to 22. Descending offsets draw the origin
tile last.
Add rendering tests for tiny steps, far-corner content, and overlap order.
When the array given to `resetForm` contains the name of a non-terminal
field, only that field was reset, so its terminal descendants kept their
values. It's the sandbox counterpart of #22014.
Walk the `_kidIds` of the collected fields and add every descendant
before resetting them.
For non-embedded composite standard fonts, iterate existing `toFontChar`
entries when filtering against an incomplete /CIDToGIDMap. Deleting absent
entries is a no-op; retain entries outside the identity /ToUnicode range
to preserve the previous behavior.
Replace the Set introduced in PR #21911 with one byte per glyph.
Glyph IDs are integer indices in [0, numGlyphs).
It'll help to slightly improve performance.
PDFPageProxy._pageIndex changes when pages are reordered, so worker replies tagged with an earlier index can reach a different proxy.
Use a stable proxy ID for StartRenderPage and page-local obj messages. Keep pageIndex for WorkerTask diagnostics and GlobalImageCache.
Fixes#21954.
Use `browserTimeout` for protocol calls so Firefox's `session.new`
command gets more than 22.5 seconds to complete.
Give dedicated tests time for the protocol and close timeouts, and use
`killBrowser` for cleanup.
Fixes#21978.
Deleting an editor that contains focus schedules a zero-delay focus of the
main container. This can override a later `page.focus()` before a key press.
Wrap `page.focus` so deferred editor updates settle first.
The notification loaded moz-message-bar and its dependencies during
viewer startup. Updating --pfn-bar-height also animated
#viewerContainer's block-start offset because its transition covered all
properties.
Load and localize the notification after the first pagerendered event,
moving this work past pdfpaint's first-page timestamp. Limit the viewer
transition to inset-inline-start, and let the viewer start if
document.l10n.ready rejects in automation.
Use the 120-second browser timeout for test-page navigation and protocol calls. Retry browser startup, including page acquisition, up to three times, and initialize failed sessions before closing them.
Limit browser.close() to 15 seconds and kill the process if it remains alive. If a timed-out reftest page cannot be reloaded, try up to three replacement browsers.
Register all sessions before launch so completion waits for pending startups.
Validate PDF Name media types with RFC 6838 restricted-name syntax while
allowing MIME parameters in MediaClip /CT strings. Use normalized Blob.type
when selecting the media element.
Add tests for invalid, overlong, and parameterized values.
Content cannot load about:pdf, and the parent process already opens the
features page when the link is activated. The href only served the context
menu and middle clicks, which asked for an illegal load and crashed the
parent process on Nightly.
Without an href the <a> is neither focusable nor activated by Enter, hence
the tabindex, the role and the keydown handler.
isCanvasMonochrome read the canvas with CSS pixel coordinates, but the
canvas is scaled by the devicePixelRatio, hence the wrong area was
checked when it isn't 1.
The "must clear all" test clicked exactly on the top-left corner of the
annotation editor layer: with a fractional layer position the click can
land just outside of it, so no editor is created. Click inside the layer
instead.
Set the ClearType level to 0 and the rendering mode to natural symmetric
(5). When Windows ClearType is enabled, Firefox applies these overrides
and selects grayscale instead of subpixel antialiasing by default.
The FreeText position tests located the glyphs by binarizing the
screenshots at 50% luminance and taking the first black pixel: with
antialiasing a thin stem can be split over two light pixels and then
disappears, so the detected position jumps to the next stem. Use the
centroid of the ink instead, which doesn't depend on any threshold.
Fixing the rendering mode alone didn't make the Windows references
reproducible: the PDFs with non-embedded fonts, rendered with system fonts
through ClearType, still changed on every run.
With the default value of the pref, Firefox derives the rendering mode from
the system settings and the text rendering differs from one run to the
other on Windows, which makes hundreds of reference test pages fail in the
GitHub CI for nothing. Forcing the mode makes it reproducible.
The images are displayed at `outputScale / devicePixelRatio`, but the
magnifier used the position within the SVG as image coordinates and
multiplied the pixel offset by the device pixel ratio, so with a ratio
other than 1 (or an output scale other than 1) it showed the wrong pixels.
The path of the log is only prepended to relative image paths. An absolute
URL is accepted when it points to a reference in mozilla/pdf.js.refs
(revision, platform, browser, test id and page are checked, and the URL is
rebuilt from a constant prefix); it is then fetched with CORS so that the
pixels can be compared. This lets the reference tests report of
mozilla/pdf.js.pdfs link the references instead of copying them.
The reference images are regenerated on every push to master by the private
mozilla/pdf.js.pdfs repository, which publishes the outcome as a shields.io
endpoint on https://mozilla.github.io/pdf.js.refs/. The badge links to the
commits of mozilla/pdf.js.refs where the updates land.
Adding the `browsertest` label to a PR dispatches a run to the private
mozilla/pdf.js.pdfs repository, which runs the Firefox reference tests on
Linux and Windows, sharded across several machines, and posts the results
(with a link to the reftest analyzer hosted on mozilla/pdf.js.refs) as a
comment. Every push to master dispatches a reference update in the same way.
The test runner gets a `--shard=k/N` option to split the manifest across
machines and a `--summaryFile` option to write the final counts as JSON.
Forward GeckoView's "addsignature" DOM event to the viewer. Convert
non-empty text to contours, switch to signature mode when needed, and
create a SignatureEditor at the visible center of the current annotation
layer.
The GeckoView signature manager has no description-edit control, so the
editor toolbar accepts a missing button.
Transfer functions use SVG filters through `ctx.filter`. When those
filters are unavailable or rejected, map solid colors and raster pixels
in software.
Apply the fallback to fills, strokes, images, masks, groups, shadings,
and tiling patterns. Rasterize gradients first so nonlinear maps run
after interpolation. Include filter state in image-mask dependencies and
exclude fallback-mapped groups from backdrop copies.
Add pixel coverage with `transfer_maps.pdf`; Node.js exercises the
fallback.
The evaluator emits `null` for each /Identity entry of a four-function
/TR array, but `DOMFilterFactory.#createTables` dereferenced it, which
aborted the rendering of the whole page. A `null` map now simply gets no
`feFunc` element, i.e. the identity for that channel.
The test file also showed that the cell of a coloured tiling pattern
inherited the fill and stroke styles in effect when the pattern was
selected. Per PDF 32000-1, 8.7.3.1, it starts from the graphics state at
the beginning of the parent content stream, hence black, which is also
what Acrobat, pdfium, xpdf, Ghostscript, Foxit and mupdf paint.
setDocument() reset annotationEditorMode from DISABLE to NONE
when clearing the current PDF, so the next PDF initialized an editor
manager. Preserve DISABLE across documents.
Fixes#21899.
PDF.js creates FreeText appearances with Helvetica and WinAnsiEncoding. It
cannot generate a matching appearance when Helvetica cannot encode the text.
Add a Firefox-only `printToPDF` callback to `saveDocument`. The worker batches
serialized FreeText entries and imports one generated PDF page per appearance.
The single-PDF batch preserves resources shared across pages.
Copy each page's resources and content without reserializing retained
operators. Drop marked-content operators because their metadata belongs to the
generated PDF.
It was added in the Babel 7 update (commit b46ec5195) as the helper
library for `@babel/plugin-transform-runtime`. That plugin was removed
in commit 6e3179994, when the Babel `targets`-option was introduced,
but the runtime package itself was left behind. Nothing has used it
since.
Auto-sizing tried line counts one by one, which was very slow for long text in narrow fields and could loop forever when there was no usable height.
Search for the line count instead, and skip text or canvases when the field is too small.
When an editor is added, moved or committed, it's moved in the DOM in a
setTimeout and the focus is restored in a second one. Without the slowMo
option for Chrome, the next Puppeteer command can run in between and be
broken by the deferred focus change (e.g. a new empty FreeText editor is
removed because it loses the focus).
So wait for those timeouts after creating, committing, selecting or moving
an editor, and remove the slowMo option which isn't required anymore
(see #21885).
When a charcode has no glyph name in the encoding of a non-embedded Type1
font, it's replaced by a space (see issue 18059) and the unicode value was
overridden too, even if the /ToUnicode map had an explicit entry for it.
Consequently, the text layer contained a space instead of the expected char.
Only override the unicode value when the /ToUnicode map has no entry.
The test file comes from https://issues.chromium.org/issues/554790604.
Only two diagonal corners of the fill area were transformed into pattern
space, so with a rotated pattern matrix the area could wrongly look like it
fits within a single tile.
It fixes#21878.
Bug 2066198 lets the PDF viewer load the moz-message-bar module from a
chrome: URL. Add the required CSP and localization entries, and preserve viewer
focus on dismissal.
The sidebar top padding pushed the header down, so the title was
off-center and the header corners overlapped the rounded corner of the
panel. Remove that padding and round the header corners instead, as the
Nova build already does.
It fixes#21870.
- Scope the GitHub App tokens in `notify-pdf-sync.yml` and
`update_locales.yml` using `permission-*` inputs.
- Move the `publish_release.yml` permissions to the job level.
- Ignore the (low-confidence) `cache-poisoning` finding in
`publish_release.yml` and keep the npm cache enabled.
Firefox rounds the font size set on a canvas 2d context, once divided by
the device pixel ratio, to 7 bits of precision. Hence `measureText` can
return a width up to ~1% off the one the spans are laid out with, which
made `--scale-x` slightly wrong in a zoom dependent way.
Measure with a size left untouched by that rounding and rescale the
returned width, which is linear in the font size.
Some PDFs open a marked content section inside a text object and never
close it. Each section adds a nesting level in the text layer, so the DOM
becomes deep enough to crash Chromium with a stack overflow.
When extracting the text, the sections opened after the matching BT are
now closed on ET. The marked content level is tracked per stream in both
getTextContent and getOperatorList: the sections a stream left open are
closed when it ends, and an unbalanced EMC is ignored.
Read dimensions from supported JPEG SOF markers and request a reduced
ImageDecoder frame when the source exceeds canvas limits. Use the returned
frame size because requested dimensions are best-effort.
Try ImageDecoder before the pixel-buffer fallback and add unit tests for
dimension parsing and resize requests.