Native Linux and macOS

The native FPC backend supports headless library workflows on Linux x64 and macOS ARM64, producing actual ELF and Mach-O programs

Use the existing TPDFlib API for PDF creation, saving/loading, text extraction and editing, structured extraction, portable OCR callbacks, bitmap rendering, metadata, encryption, network range access, and native PFX signing

Runtime dependencies

ProviderLibraryPurpose
OpenSSL 3libcryptoAES CBC/GCM, digests, PKCS12 identities, CMS signatures, integrity, and explicit trust-anchor chains
libcurllibcurl with asynchronous DNSHTTP/HTTPS, bounded binary transport, range access, and RFC 3161 requests
CairolibcairoBitmap image surfaces, paths, clipping, glyph outlines, and images
FontconfiglibfontconfigActual native font-file matching, including explicit family substitution
OpenJPEG 2libopenjp2JPEG 2000 decoding and encoding

Linux loads the corresponding system SONAMEs; macOS uses ARM64 libraries under /opt/homebrew and the system libcurl

Missing libraries, symbols, or unsupported operations produce explicit failures; no Windows device-context substitute is used

Signing and time stamps

The default PFX provider supports actual RSA and EC identities, detached CMS, CAdES, and legacy attached SHA1 profiles; verification checks PDF ByteRange bytes and the CMS signature

Certificate-chain verification requires explicit trust anchors; embedded certificates do not grant trust, and integrity alone does not imply trust

ApplyPAdESSignatureTimeStamp uses the configured default native HTTP transport to fetch and attach a real RFC 3161 token; reserve enough /Contents capacity before the original signature

Time-stamp verification checks the signed token, message imprint, exclusive critical timeStamping EKU, TSA name, optional expected policy/nonce, and the trusted certificate chain at token generation time

Document time stamps also verify the actual PDF ByteRange imprint; the caller can use the existing DocTimeStamp passthrough workflow and supply the token

Metadata and rendering

XMP uses a real namespace-aware DOM and preserves unrelated properties during edits

DTD declarations are rejected by the XML reader regardless of source encoding; input and decoded characters are bounded, and a streaming pass limits depth and node events before DOM construction

Rendering uses real native bitmap storage and Cairo image surfaces; banded rendering preserves device-space coordinates and uses guard rows to keep boundary antialiasing consistent

Native family-font embedding resolves an actual Fontconfig file and embeds a complete standalone TrueType program with CIDFontType2, Identity CIDToGIDMap, initialized metrics, and Unicode widths; BMP text and portable OCR layers survive PDF save/reload

The entry rejects unembedded family fonts, collections, CFF programs, and bitmap-only embedding rights; restricted embedding requires the existing explicit rights override, and fonts that prohibit subsetting remain complete programs

Limits

Build and verify

python3 Tests/Native/run_native_tests.py --compiler /path/to/fpc --output /tmp/pdflib-native-tests

Pass --config /path/to/fpc.cfg for an explicit compiler configuration; the runner does not change global compiler settings or add -FcUTF8

The suite checks actual native executable formats and writes a JSON report with compiler/dependency versions, source hashes, executable hashes, results, and limits

The checked-in Tests/Native fixtures cover PDF save/reload/rendering, text workflows, encryption, metadata, signatures, real HTTP/TSA traffic, and negative security cases

macOS C ABI dynamic library

The existing 880-entry dynamic-library export surface can be built with native Free Pascal on macOS ARM64, using the same headless backend and capability limits described above

export FPC=/path/to/aarch64-darwin/fpc
export PDFLIB_FPC_CONFIG=/path/to/fpc.cfg
bash Dylib/Build-native.sh release full
python3 Tests/Dylib/test_native_dylib.py Dylib/OSXARM64/FPC-release-full/libPDFlibDylib.dylib /tmp/dylib-smoke.pdf

Omit PDFLIB_FPC_CONFIG when the compiler already has a valid configuration; use debug trial for the separate trial build, or set PDFLIB_DYLIB_OUTPUT to an external output directory

The C ABI uses 32-bit opaque instance handles and UTF-16 PWideChar strings on both Intel and ARM64 systems; foreign-language bindings must supply UTF-16 code units rather than the host's native wchar_t representation

DLCreateBuffer returns writable data owned by its instance, including embedded zero bytes; DLReleaseBuffer returns 1 on success and 0 for an unknown or already released buffer, and releasing an instance invalidates all its buffers and returned strings

Instance 0 remains the default instance alias; explicit positive handles are not reused during the loaded library's lifetime, and unloading frees outstanding instances and buffers

Serialize calls that use the same instance, and serialize instance creation or release against other C ABI calls; the registry lock does not protect an instance after lookup

Delphi cross-compilation status

The Windows build scripts select dccosx64 or dccosxarm64, require a local macOS SDK cache, separate full and trial output, and validate the produced Mach-O header before publishing the build output

Set PDFLIBPAS_MACOS_SDK or pass sdk path; PDFLIBPAS_MACOS_LINKER can select a Mach-O LLVM linker named ld64.lld.exe when the installed default linker cannot read the SDK's .tbd files

The current Delphi/macOS library build is blocked by compatibility declarations in PDFlibWindows.pas, including TSystemTime and the FPC-only BaseUnix import; a successful SDK probe does not establish that this Delphi route builds the library

Reference index