Bounded QuickJS Runtime

HPDFQuickJS and HPDFQuickJSStatic expose the same application-controlled JavaScript evaluation API on Win32 and Win64

Choose a deployment mode

The DLL binding accepts an explicit path, the HOTPDF_QUICKJS_DLL environment value, or the platform directory found below an executable ancestor

Default builds place the bridge at Lib\thirdparty\QuickJS\bin\Win32\quickjs.dll or Lib\thirdparty\QuickJS\bin\Win64\quickjs.dll

Evaluate a script

uses
  HPDFQuickJS;

var
  Engine: THPDFQuickJS;
  EvalResult: THPDFQuickJSResult;
begin
  Engine := THPDFQuickJS.Create;
  try
    if not Engine.Available then
      raise Exception.Create(Engine.LoadError);
    EvalResult := Engine.Eval('JSON.stringify([1, 2, 3].map(x => x * 2))');
    if not EvalResult.Success then
      raise Exception.Create(EvalResult.Error);
  finally
    Engine.Free;
  end;
end;

Eval converts the final JavaScript value to UTF-8 text and preserves Unicode when returning a Delphi string

EvalInt and EvalFloat add strict numeric conversion without exposing engine values across the ABI boundary

Execution limits

Limits := THPDFQuickJSLimits.CreateDefault;
Limits.MemoryBytes := 32 * 1024 * 1024;
Limits.StackBytes := 64 * 1024;
Limits.MaxScriptBytes := 256 * 1024;
Limits.TimeoutMs := 250;
Limits.MaxInterruptChecks := 250000;
Engine := THPDFQuickJS.Create(Limits);

The defaults allow 64 MiB of engine memory, a 64 KiB stack, a 1 MiB UTF-8 script, one second of wall time, and one million interrupt checks

The Win32 static runtime caps a zero or larger requested stack budget at 48 KiB to stay inside the compiler-safe recursion boundary; DLL and Win64 modes honor the requested value directly

Memory and stack limits are runtime-wide while script, time, and interrupt limits are applied to each evaluation

Status and recovery

A rejected or interrupted evaluation clears its pending exception and buffers, so the same engine instance can execute a later valid script

One engine instance is not reentrant; use one instance per concurrent worker

XFA form scripting

The XFA flattening engine reuses this runtime only when THotPDF.XFAJavaScriptEnabled is explicitly set; it supplies a restricted data facade, native typed arrays, validated instance requests, and no file, process, browser, or network objects

TXFAFormScriptOptions.JavaScriptEvaluator can adapt the static runtime without forcing static QuickJS objects into every HotPDF application

See Bounded XFA FormCalc and JavaScript

Reproducible runtime build

powershell -ExecutionPolicy Bypass -File Lib\thirdparty\build-quickjs-runtime.ps1

The build script produces both static object sets and both bridge DLLs from the bundled source, then the runtime matrix compiles and exercises static and DLL probes for Win32 and Win64