CMS Placeholder Auto-Sizing
HotPDF can estimate a detached CMS container without invoking a private-key operation, timestamp authority, or counter-signer, then rebuild an undersized unsigned PDF before the irreversible signing boundary
Side-effect-free estimation
HPDFCMSEstimatePlaceholder selects the signature length from EstimatedSignatureBytes, a provider that advertises spcEstimateSignatureSize, or the RSA modulus in the signing certificate, in that order
The estimator builds the exact static CMS shape with a synthetic signature of that length, retains configured certificates and static counter-signatures, and replaces dynamic callbacks with caller-configurable payload reserves
THPDFCMSPlaceholderEstimateOptions.Default applies a 50 percent margin, a 1,024-byte minimum, 256-byte alignment, and a 16 MiB maximum; timestamp and counter-signature estimates remain explicit because their response sizes depend on external services
THPDFCMSPlaceholderEstimateInfo reports the selected source, signature length, static CMS length, dynamic reserve, estimated CMS length, and recommended aligned /Contents capacity
Rebuild before signing
The auto-size functions inspect the existing /Contents capacity after preparing /ByteRange
If capacity is below the recommendation, THPDFCMSRebuildUnsignedPDFCallback receives the required byte count and writes a fresh unsigned PDF to the supplied destination stream; the rebuilt placeholder is validated before any signing callback runs
EstimateOptions := THPDFCMSPlaceholderEstimateOptions.Default;
AutoOptions := THPDFCMSAutoSizeOptions.Default;
AutoOptions.Estimate := EstimateOptions;
HPDFCMSSignPDFStreamWithProviderAutoSize(
InputStream, OutputStream, CertificateDER, Provider, KeyIdentifier,
SignOptions, AutoOptions,
procedure(ContentsBytes: Integer; Destination: TStream)
begin
BuildUnsignedPDF(ContentsBytes, Destination);
end,
AutoSizeInfo);
Retry safety contract
HPDFCMSSignPDFStreamWithExternalSignerAutoSize never calls the external signer again after it returns a signature; an unexpected overflow restores the unsigned placeholder and raises an error containing the actual and available sizes
HPDFCMSSignPDFStreamWithProviderAutoSize may retry only when the provider advertises spcSafeSignRetry, a rebuild callback is available, and MaximumSigningRetries has not been exhausted
If content timestamps, signature timestamps, or dynamic counter-signatures are enabled, retry additionally requires DynamicCallbacksSafeToRetry=True
The callback provider exposes ConfigureSizeEstimation, remote providers accept an optional estimator and safe-retry declaration, and PKCS#11 or Windows key-storage providers infer RSA output length from the certificate without touching the private key
Diagnostics and limits
THPDFCMSAutoSizeInfo reports initial and final capacities, the actual CMS length, rebuild count, signing attempts, and whether a post-sign retry occurred
Recommended and retry sizes are checked with wide arithmetic, aligned within the configured maximum, and reject invalid percentages, retry counts, zero lengths, malformed certificates, unsupported keys, and rebuild callbacks that reserve less than requested