From 0892e3aa5cd46e43b0bb0ac10f47d2ee4f500409 Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Thu, 1 Oct 2026 12:42:48 -0300 Subject: A PDF with a JPEG image no longer crashes ReleaseSafe and Debug builds: libjpeg and jbig2dec are built without UBSan, as the rest of MuPDF is libjpeg calls filter-dct.c's source manager through a function pointer; with -fsanitize=function on the caller and no type hash on the uninstrumented callee, the call trapped (Illegal instruction in jpeg_fill_bit_buffer). The Intel SDM vol. 2 crashed pardes on its first page. Co-Authored-By: Claude Opus 5.5 --- mupdf.zig | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'mupdf.zig') diff --git a/mupdf.zig b/mupdf.zig index a157e850..eeadaa5d 100644 --- a/mupdf.zig +++ b/mupdf.zig @@ -98,13 +98,19 @@ pub fn add(b: *std.Build, io: std.Io, dependency: *std.Build.Dependency, options module.addCSourceFiles(.{ .root = dependency.path(""), .files = makeSources(b, makelists, "LIBJPEG_SRC"), - .flags = &.{"-std=gnu11"}, + // libjpeg calls back into source/fitz (filter-dct.c's source + // manager), which is built without UBSan: -fsanitize=function at + // such a call finds no type hash on the callee and traps, so any + // PDF with a DCT image crashed ReleaseSafe and Debug builds in + // jpeg_fill_bit_buffer. The same holds for jbig2dec below. + .flags = &.{ "-std=gnu11", "-fno-sanitize=undefined" }, }); module.addCSourceFiles(.{ .root = dependency.path(""), .files = makeSources(b, makelists, "JBIG2DEC_SRC"), .flags = &.{ "-std=gnu11", + "-fno-sanitize=undefined", "-DHAVE_STDINT_H", "-DJBIG_EXTERNAL_MEMENTO_H=\"mupdf/memento.h\"", }, -- cgit v1.3