JBIG2 Segment-Graph Validation
HotPDF validates embedded JBIG2 image and JBIG2Globals streams before a native or external decoder receives them
The validator performs one bounded segment walk followed by an iterative dependency-graph traversal, using indexed segment-number lookup instead of repeated scans
Validate before custom processing
Options := DefaultJBIG2SegmentGraphValidationOptions;
Options.MaxSegments := 32768;
Options.MaxTotalReferences := 131072;
Options.MaxReferenceDepth := 512;
Options.MaxSymbols := 500000;
if not HPDFValidateJBIG2SegmentGraph(ImageData, GlobalData,
Options, Info) then
raise Exception.Create(string(
HPDFJBIG2SegmentGraphValidationStatusName(Info.Status)));
TJBIG2SegmentGraphValidationInfo reports segment and edge counts, declared new symbols, maximum dependency depth, and the stream, byte offset, segment number, and reference number associated with the first failure
Budgets live in a TJBIG2SegmentGraphValidationOptions record whose MaxSegments, MaxReferencesPerSegment, MaxTotalReferences, MaxReferenceDepth, and MaxSymbols fields bound every walk
The terminal state is a TJBIG2SegmentGraphValidationStatus value from not-checked and valid through options rejection, header and reference failures, cycles, and symbol-dictionary violations, and HPDFJBIG2SegmentGraphValidationStatusName renders it as text
FailureStreamKind uses TJBIG2SegmentStreamKind to say whether the first failure was found in the globals stream (jbsskGlobals) or the image stream (jbsskImage)
THPDFJBIG2Decoder.LastSegmentGraphValidationInfo retains the same report after LoadFromByteArray or LoadRegionFromByteArray
Fail-closed conditions
Validation rejects malformed or truncated headers, standalone file headers in embedded streams, forbidden short and oversized long reference tables, duplicate or missing segment identifiers, physically forward dependencies, dependency cycles, excessive depth, and configured segment or edge budget overruns
Image segments must use page association 1, global segments must use page association 0, and a global segment cannot depend on an image segment
Embedded end-of-page, end-of-file, and color-palette segments are rejected, as are page-only region and page-information segments placed in JBIG2Globals
Symbol-dictionary headers are inspected before decoding so declared new and exported symbol counts, aggregate input symbol pools, and impossible export totals fail before bitmap allocation
Decoder and globals-cache boundary
THPDFJBIG2Decoder, HPDFJBIG2NativeMMRDecode, HPDFJBIG2NativeRegionDecode, and embedded HPDFJBIG2DecDecodeEx calls share the same policy
The registered native and external backends use already-validated internal paths, avoiding a duplicate graph walk on normal decoding
THPDFJBIG2GlobalsPool.Register accepts only a valid global-only segment stream, preventing malformed shared dictionaries from entering document-level reuse
Standalone JBIG2 files passed with Embedded = False retain their separate file-oriented decode path
See JBIG2 compression support, THPDFJBIG2Decoder.LoadFromByteArray, and THPDFJBIG2Decoder.LoadRegionFromByteArray