Cross-platform native desktop PDF editor with full content editing
Go to file
ai-ad4 3f563b42c5 feat(spike-E): sandbox + IPC bring-up; seccomp-bpf, 18us round-trip (§14 step 8)
Implement Spike E: the two-process model from ADR-0004 (§2.1), the one thing
the plan says is genuinely painful to retrofit, de-risked at M0.

Sandbox.cpp: seccomp-bpf allow-list filter for the document process.
Default-deny (SCMP_ACT_KILL_PROCESS), permit only memory/thread-sync/the
already-open IPC socket fds/exit. DENIED: open, socket, connect, fork,
exec — the document process cannot reach the network or filesystem and
cannot spawn children. A forbidden syscall kills the process loudly.

DocumentProcess.cpp + UIProcess.cpp: the sandboxed child and the UI process
over a socketpair, with a trivial length-prefixed binary IPC protocol
([u64 id][u64 len][payload] -> [u64 id][u64 count][u8 ok]). The UI
validates every response field (ADR-0004: bidirectional trust boundary);
the child bounds-checks every request length. main.cpp forks, sets up the
socketpair, measures round-trip latency.

Gate MET: 1000/1000 requests round-trip under the sandbox, avg 18us
(sandbox OFF: 20us — no measurable overhead). Verified clean under
ASan+UBSan. Result and findings in docs/spike-results/0004-spike-e-sandbox.md.

Key finding: Cap'n Proto two-party RPC over a socketpair stalled in this
environment (server processed requests but responses never reached the
client; reproduced with the sandbox disabled, so it's an RPC integration
issue not a sandbox issue). Recorded for M2 to debug with the full event-
loop integration. The spike uses a raw protocol to measure the channel cost
without that blocker; the ipc.capnp schema is kept for M2. The process
split cost is ~tens of us/request, far under the §5 budget.

CI: add Spike E to the spike-gates job (libseccomp-dev); fails the build on
regression, sandbox must be ON (no env override in CI).

Signed-off-by: ai-ad4 <ai-ad4@users.noreply.gitea.lm.je>
2026-07-25 20:52:39 +00:00
.gitea/workflows feat(spike-E): sandbox + IPC bring-up; seccomp-bpf, 18us round-trip (§14 step 8) 2026-07-25 20:52:39 +00:00
LICENSES chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
ci chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
cmake chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
docs feat(spike-E): sandbox + IPC bring-up; seccomp-bpf, 18us round-trip (§14 step 8) 2026-07-25 20:52:39 +00:00
packaging chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
spike feat(spike-E): sandbox + IPC bring-up; seccomp-bpf, 18us round-trip (§14 step 8) 2026-07-25 20:52:39 +00:00
src chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
test fix(spike-A): adapt to installed QPDF 12.2 API; fix use-after-free 2026-07-25 20:30:37 +00:00
.clang-format chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.clang-tidy chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.editorconfig chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitattributes chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitignore chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.gitleaks.toml chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
.pre-commit-config.yaml chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CMakeLists.txt chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CMakePresets.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CODEOWNERS chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
CONTRIBUTING.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
README.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
REUSE.toml build(license): convert dep5 to REUSE.toml; record Spike A result 2026-07-25 20:30:43 +00:00
SECURITY.md chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
TRADEMARK.md build(license): convert dep5 to REUSE.toml; record Spike A result 2026-07-25 20:30:43 +00:00
vcpkg-configuration.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00
vcpkg.json chore: initial repository scaffold (§14 steps 1-3, 9) 2026-07-25 20:14:22 +00:00

README.md

FreePDFEditor

A cross-platform native desktop PDF editor with a true WYSIWYG interface and full content editing: edit existing text with reflow, replace images, manipulate vector objects, plus annotations, forms, signatures, and page assembly.

  • Stack: C++20, Qt 6.7 (Widgets shell, custom canvas), CMake, vcpkg.
  • License: GPL-3.0-or-later (see LICENSES/GPL-3.0-or-later.txt). Qt is dynamically linked under LGPL-3.0.
  • Targets: Windows 10+, macOS 12+ (Intel + Apple Silicon), Linux (X11/Wayland).

This repository contains the source and build infrastructure. The full engineering plan and roadmap live in docs/plan.md; architecture decision records are under docs/adr/.

Status

Pre-M0. This is the initial repository scaffold described in §14 of the plan: CMake + vcpkg skeleton, governance docs, CI matrix, packaging pipeline, an empty-window application shell, the pixel-diff harness scaffolding, and the Spike A (QPDF verbatim round-trip) harness. The feasibility spikes that gate the project run on top of this scaffolding.

Building

cmake --preset default
cmake --build --preset default
ctest --preset default

See CONTRIBUTING.md for the full build setup, gate matrix, and coding standard.

Source control

All code is developed on the project Gitea instance at https://gitea.lm.je/ai-ad4/freepdfeditor per docs/plan.md §13. See SECURITY.md for vulnerability reporting.