Cross-platform native desktop PDF editor with full content editing
Go to file
ai-ad4 1d5372f140 fix(spike-A): adapt to installed QPDF 12.2 API; fix use-after-free
The QPDF 12.2 API differs from the initially-written calls:
- processInputFile → processFile
- getArrayAsArray → getArrayAsVector
- setOutputFile(string) → setOutputFilename(const char*)
- setQDF → setQDFMode

The spike CMakeLists now finds QPDF via either a CMake config target
(qpdf::libqpdf for system packages, QPDF::qpdf for vcpkg) or a pkg-config
fallback (PkgConfig::QPDF), so it builds against the Debian libqpdf-dev
package as well as a vcpkg manifest install.

The contract test target was missing SpikeRunner.cpp from its sources,
causing a link error; added it with the spike/ include directory.

ASan caught a heap-use-after-free in the initial write path: QPDFWriter
retains the const char* passed to setOutputFilename and dereferences it
during write(), after the temporary std::string from output.string() is
destroyed. Both the input and output filename strings are now kept alive
across the QPDF calls that retain them. This is exactly the bug class the
§7.2 sanitizers-in-CI posture exists to catch.

Builds and passes under GCC 14.2 + Qt 6.8.2 + QPDF 12.2, both Release and
ASan+UBSan configurations.

Signed-off-by: ai-ad4 <ai-ad4@users.noreply.gitea.lm.je>
2026-07-25 20:30:37 +00:00
.gitea/workflows chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.reuse chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
LICENSES chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
ci chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
cmake chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
docs chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
packaging chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
spike fix(spike-A): adapt to installed QPDF 12.2 API; fix use-after-free 2026-07-25 20:30:37 +00:00
src chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
test fix(spike-A): adapt to installed QPDF 12.2 API; fix use-after-free 2026-07-25 20:30:37 +00:00
.clang-format chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.clang-tidy chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.editorconfig chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitattributes chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitignore chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitleaks.toml chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.pre-commit-config.yaml chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CMakeLists.txt chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CMakePresets.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CODEOWNERS chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CONTRIBUTING.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
README.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
SECURITY.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
TRADEMARK.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
reuse.toml chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
vcpkg-configuration.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
vcpkg.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00

README.md

FreePDFEditor

A cross-platform native desktop PDF editor with a true WYSIWYG interface and full content editing: edit existing text with reflow, replace images, manipulate vector objects, plus annotations, forms, signatures, and page assembly.

  • Stack: C++20, Qt 6.7 (Widgets shell, custom canvas), CMake, vcpkg.
  • License: GPL-3.0-or-later (see LICENSES/GPL-3.0-or-later.txt). Qt is dynamically linked under LGPL-3.0.
  • Targets: Windows 10+, macOS 12+ (Intel + Apple Silicon), Linux (X11/Wayland).

This repository contains the source and build infrastructure. The full engineering plan and roadmap live in docs/plan.md; architecture decision records are under docs/adr/.

Status

Pre-M0. This is the initial repository scaffold described in §14 of the plan: CMake + vcpkg skeleton, governance docs, CI matrix, packaging pipeline, an empty-window application shell, the pixel-diff harness scaffolding, and the Spike A (QPDF verbatim round-trip) harness. The feasibility spikes that gate the project run on top of this scaffolding.

Building

cmake --preset default
cmake --build --preset default
ctest --preset default

See CONTRIBUTING.md for the full build setup, gate matrix, and coding standard.

Source control

All code is developed on the project Gitea instance at https://gitea.lm.je/ai-ad4/freepdfeditor per docs/plan.md §13. See SECURITY.md for vulnerability reporting.