Native Linux and macOS
The native FPC backend supports headless library workflows on Linux x64 and macOS ARM64, producing actual ELF and Mach-O programs
Use the existing TPDFlib API for PDF creation, saving/loading, text extraction and editing, structured extraction, portable OCR callbacks, bitmap rendering, metadata, encryption, network range access, and native PFX signing
Runtime dependencies
| Provider | Library | Purpose |
|---|---|---|
| OpenSSL 3 | libcrypto | AES CBC/GCM, digests, PKCS12 identities, CMS signatures, integrity, and explicit trust-anchor chains |
| libcurl | libcurl with asynchronous DNS | HTTP/HTTPS, bounded binary transport, range access, and RFC 3161 requests |
| Cairo | libcairo | Bitmap image surfaces, paths, clipping, glyph outlines, and images |
| Fontconfig | libfontconfig | Actual native font-file matching, including explicit family substitution |
| OpenJPEG 2 | libopenjp2 | JPEG 2000 decoding and encoding |
Linux loads the corresponding system SONAMEs; macOS uses ARM64 libraries under /opt/homebrew and the system libcurl
Missing libraries, symbols, or unsupported operations produce explicit failures; no Windows device-context substitute is used
Signing and time stamps
The default PFX provider supports actual RSA and EC identities, detached CMS, CAdES, and legacy attached SHA1 profiles; verification checks PDF ByteRange bytes and the CMS signature
Certificate-chain verification requires explicit trust anchors; embedded certificates do not grant trust, and integrity alone does not imply trust
ApplyPAdESSignatureTimeStamp uses the configured default native HTTP transport to fetch and attach a real RFC 3161 token; reserve enough /Contents capacity before the original signature
Time-stamp verification checks the signed token, message imprint, exclusive critical timeStamping EKU, TSA name, optional expected policy/nonce, and the trusted certificate chain at token generation time
Document time stamps also verify the actual PDF ByteRange imprint; the caller can use the existing DocTimeStamp passthrough workflow and supply the token
Metadata and rendering
XMP uses a real namespace-aware DOM and preserves unrelated properties during edits
DTD declarations are rejected by the XML reader regardless of source encoding; input and decoded characters are bounded, and a streaming pass limits depth and node events before DOM construction
Rendering uses real native bitmap storage and Cairo image surfaces; banded rendering preserves device-space coordinates and uses guard rows to keep boundary antialiasing consistent
Native family-font embedding resolves an actual Fontconfig file and embeds a complete standalone TrueType program with CIDFontType2, Identity CIDToGIDMap, initialized metrics, and Unicode widths; BMP text and portable OCR layers survive PDF save/reload
The entry rejects unembedded family fonts, collections, CFF programs, and bitmap-only embedding rights; restricted embedding requires the existing explicit rights override, and fonts that prohibit subsetting remain complete programs
Limits
- Windows device contexts, EMF, GUI, clipboard, and printing are outside the native headless backend
- Complex native text shaping and Windows system certificate-store identities are unavailable
- The standalone TrueType embedding entry currently supports BMP text; supplementary-plane text, TTC face extraction, and CFF embedding are outside this entry
- Online OCSP/CRL revocation is unavailable; requests for revocation verification report an unknown result
- The default native PFX provider rejects RSA-PSS and extra policy, commitment, or revocation signing attributes
- Native CMYK/ICC transforms and indexed one-bit BMP writing are unavailable
- HTTP requires asynchronous DNS support in libcurl to honor DNS lookup timeouts
Build and verify
python3 Tests/Native/run_native_tests.py --compiler /path/to/fpc --output /tmp/pdflib-native-tests
Pass --config /path/to/fpc.cfg for an explicit compiler configuration; the runner does not change global compiler settings or add -FcUTF8
The suite checks actual native executable formats and writes a JSON report with compiler/dependency versions, source hashes, executable hashes, results, and limits
The checked-in Tests/Native fixtures cover PDF save/reload/rendering, text workflows, encryption, metadata, signatures, real HTTP/TSA traffic, and negative security cases
macOS C ABI dynamic library
The existing 880-entry dynamic-library export surface can be built with native Free Pascal on macOS ARM64, using the same headless backend and capability limits described above
export FPC=/path/to/aarch64-darwin/fpc
export PDFLIB_FPC_CONFIG=/path/to/fpc.cfg
bash Dylib/Build-native.sh release full
python3 Tests/Dylib/test_native_dylib.py Dylib/OSXARM64/FPC-release-full/libPDFlibDylib.dylib /tmp/dylib-smoke.pdf
Omit PDFLIB_FPC_CONFIG when the compiler already has a valid configuration; use debug trial for the separate trial build, or set PDFLIB_DYLIB_OUTPUT to an external output directory
The C ABI uses 32-bit opaque instance handles and UTF-16 PWideChar strings on both Intel and ARM64 systems; foreign-language bindings must supply UTF-16 code units rather than the host's native wchar_t representation
DLCreateBuffer returns writable data owned by its instance, including embedded zero bytes; DLReleaseBuffer returns 1 on success and 0 for an unknown or already released buffer, and releasing an instance invalidates all its buffers and returned strings
Instance 0 remains the default instance alias; explicit positive handles are not reused during the loaded library's lifetime, and unloading frees outstanding instances and buffers
Serialize calls that use the same instance, and serialize instance creation or release against other C ABI calls; the registry lock does not protect an instance after lookup
Delphi cross-compilation status
The Windows build scripts select dccosx64 or dccosxarm64, require a local macOS SDK cache, separate full and trial output, and validate the produced Mach-O header before publishing the build output
Set PDFLIBPAS_MACOS_SDK or pass sdk path; PDFLIBPAS_MACOS_LINKER can select a Mach-O LLVM linker named ld64.lld.exe when the installed default linker cannot read the SDK's .tbd files
The current Delphi/macOS library build is blocked by compatibility declarations in PDFlibWindows.pas, including TSystemTime and the FPC-only BaseUnix import; a successful SDK probe does not establish that this Delphi route builds the library