JBIG2 Segment-Graph Validation

HotPDF validates embedded JBIG2 image and JBIG2Globals streams before a native or external decoder receives them

The validator performs one bounded segment walk followed by an iterative dependency-graph traversal, using indexed segment-number lookup instead of repeated scans

Validate before custom processing

Options := DefaultJBIG2SegmentGraphValidationOptions;
Options.MaxSegments := 32768;
Options.MaxTotalReferences := 131072;
Options.MaxReferenceDepth := 512;
Options.MaxSymbols := 500000;

if not HPDFValidateJBIG2SegmentGraph(ImageData, GlobalData,
  Options, Info) then
  raise Exception.Create(string(
    HPDFJBIG2SegmentGraphValidationStatusName(Info.Status)));

TJBIG2SegmentGraphValidationInfo reports segment and edge counts, declared new symbols, maximum dependency depth, and the stream, byte offset, segment number, and reference number associated with the first failure

Budgets live in a TJBIG2SegmentGraphValidationOptions record whose MaxSegments, MaxReferencesPerSegment, MaxTotalReferences, MaxReferenceDepth, and MaxSymbols fields bound every walk

The terminal state is a TJBIG2SegmentGraphValidationStatus value from not-checked and valid through options rejection, header and reference failures, cycles, and symbol-dictionary violations, and HPDFJBIG2SegmentGraphValidationStatusName renders it as text

FailureStreamKind uses TJBIG2SegmentStreamKind to say whether the first failure was found in the globals stream (jbsskGlobals) or the image stream (jbsskImage)

THPDFJBIG2Decoder.LastSegmentGraphValidationInfo retains the same report after LoadFromByteArray or LoadRegionFromByteArray

Fail-closed conditions

Validation rejects malformed or truncated headers, standalone file headers in embedded streams, forbidden short and oversized long reference tables, duplicate or missing segment identifiers, physically forward dependencies, dependency cycles, excessive depth, and configured segment or edge budget overruns

Image segments must use page association 1, global segments must use page association 0, and a global segment cannot depend on an image segment

Embedded end-of-page, end-of-file, and color-palette segments are rejected, as are page-only region and page-information segments placed in JBIG2Globals

Symbol-dictionary headers are inspected before decoding so declared new and exported symbol counts, aggregate input symbol pools, and impossible export totals fail before bitmap allocation

Decoder and globals-cache boundary

THPDFJBIG2Decoder, HPDFJBIG2NativeMMRDecode, HPDFJBIG2NativeRegionDecode, and embedded HPDFJBIG2DecDecodeEx calls share the same policy

The registered native and external backends use already-validated internal paths, avoiding a duplicate graph walk on normal decoding

THPDFJBIG2GlobalsPool.Register accepts only a valid global-only segment stream, preventing malformed shared dictionaries from entering document-level reuse

Standalone JBIG2 files passed with Embedded = False retain their separate file-oriented decode path

See JBIG2 compression support, THPDFJBIG2Decoder.LoadFromByteArray, and THPDFJBIG2Decoder.LoadRegionFromByteArray