Bounded PDF Parser Budgets

Document-scoped parser budgets stop hostile or damaged input before token construction, aggregate token work, array or dictionary growth, or repeated malformed tokens consume excessive resources

Compatibility defaults

Set any limit to zero to disable that individual limit

Negative values raise ERangeError

Strict policy

ApplyStrictParserBudgetPolicy selects a 1 MiB token limit, 100,000 total tokens, 10,000 container entries, and 8 malformed tokens

PDF.ApplyStrictParserBudgetPolicy;
try
  PDF.LoadFromFile(UntrustedFileName);
except
  on E: EHPDFParserBudgetExceeded do
    LogParserRejection(E.Limit, E.Observed, E.Maximum);
end;

ResetParserBudgetPolicy restores the compatibility defaults

Failure and telemetry

A breached limit raises EHPDFParserBudgetExceeded with Limit, Observed, and Maximum values

THPDFParserBudgetLimit identifies pblTokenBytes, pblTotalTokens, pblContainerItems, or pblBadTokens

GetLastParserBudgetStatistics returns a THPDFParserBudgetStatistics snapshot with configured limits, token and malformed-token counts, peak token and container sizes, breach information, and session validity

Budget exceptions remain terminal across modern parsing, traditional parsing, cross-reference recovery, and per-object failure isolation

Performance gate

The Win32 regression gate rejects a 2 MiB token in 215 ms at a 34,476,032-byte process peak and rejects a one-million-token container in 199 ms at a 36,839,424-byte process peak

See also: ApplyStrictParserBudgetPolicy, ResetParserBudgetPolicy, GetLastParserBudgetStatistics, Scalable Loading