#pdflite/core

    moonbitlang/pdflite/core contains the byte primitives and shared error type used by the rest of pdflite. It deliberately treats PDF data as Bytes and BytesView; callers should decode text only at explicit text-decoding boundaries.

    flowchart LR Ints[integer byte values] --> Guard[pdf_byte_of_int] Guard --> Bytes[pdf_bytes_of_int_array] Bytes --> Views[BytesView APIs] Views --> Names[PdfName] Guard --> Errors[PdfError]

    #Checked Examples

    ///|
    test "byte helpers preserve raw PDF bytes" {
    let bytes = try! @core.pdf_bytes_of_int_array([37, 80, 68, 70])
    if @core.pdf_int_array_of_bytes(bytes) != [37, 80, 68, 70] {
    fail("expected raw PDF header bytes to be preserved")
    }
    inspect(@core.pdf_is_whitespace_byte(32), content="true")
    inspect(@core.pdf_is_delimiter_byte(47), content="true")
    }

    ///|
    test "byte validation raises PdfError" {
    let result : Result[Byte, Error] = try @core.pdf_byte_of_int(300) catch {
    err => Err(err)
    } noraise {
    value => Ok(value)
    }
    guard result is Err(@core.PdfError::InvalidByte(300)) else {
    fail("expected InvalidByte for values outside 0..=255")
    }
    }

    #Package Notes

    • PdfBytes is an alias for Bytes to make byte ownership visible at API boundaries.
    • PdfName stores raw name bytes and exposes owned bytes and borrowed views.
    • PdfError is shared by parsing, writing, filtering, text, page, and encryption APIs so higher packages can keep precise failure cases.

    #Pedantic Boundaries

    • This package owns raw PDF byte validation. Values outside 0..=255 must be rejected before they become Byte.
    • This package does not parse PDF objects, streams, pages, fonts, or encryption dictionaries. It only supplies shared primitives for those packages.
    • BytesView parameters are borrowed. Functions returning PdfBytes return owned data that can outlive the caller's source buffer.
    • PdfName does not normalize, unescape, or Unicode-decode names. Higher layers decide when a name has semantic meaning.

    #Verification Notes

    • README examples are blackbox tests for the public core API.
    • Add assertion tests for exact byte arrays and exact PdfError variants.
    • Run moon test core/README.mbt.md after editing this file.
    • Run moon info before review; this README should not change core/pkg.generated.mbti.

    PdfBytes

    type PdfBytes = Bytes

    PDF byte strings and byte streams.

    This is an alias for MoonBit Bytes because PDF strings and streams are byte sequences, not Unicode text. Use String only after an explicit PDF text decoding step.

    PdfError

    pub(all) suberror PdfError {
    InvalidByte(Int)
    InvalidCursorPosition(Int)
    InvalidReadLength(Int)
    InvalidBit(Int)
    InvalidBitCount(Int)
    MatrixNotInvertable
    DictionaryExpected
    DictionaryKeyNotFound(PdfName)
    NumberExpected
    RectangleExpected
    BadRectangle
    MatrixMalformed
    InvalidHexEscape
    InvalidASCII85Data
    FilterNotSupported(PdfName)
    FilterExpected
    CCITTDecodeParmsExpected
    CCITTNotSupported(String)
    InvalidCCITTData
    PredictorExpected
    PredictorNotSupported(Int)
    InvalidLZWData
    InvalidFlateData
    FlateOutputLimitExceeded(Int)
    BadJPEGHeader
    BadJPEGString
    InvalidJPEGBlock
    JPEGDimensionsExpected
    BadPNG(String)
    BadJPEG2000Header
    JPEG2000DimensionsExpected
    ParseObjectExpected
    ParseArrayMalformed
    ParseSingleObjectExpected
    ParseIndirectObjectExpected
    ParseEndObjectExpected
    ParseStreamExpected
    ParseEndStreamExpected
    StreamLengthExpected
    StreamDataExpected
    ParsedObjectExpected
    PageTreeExpected
    PageRotationExpected(Int)
    BadPageSpecification(String)
    BadCoordinateSpecification(String)
    BadRectangleSpecification(String)
    BadNumberArgument(String)
    BadPresentationEffect(String)
    SoftError(String)
    HardError(String)
    InsecurePathName(String)
    ContentOperatorExpected
    ContentOperandExpected
    FunctionExpected
    FunctionNotSupported(Int)
    BadFunctionEvaluation(String)
    StartXRefExpected
    XRefExpected
    XRefEntryExpected
    TrailerExpected
    RootExpected
    BadRevision
    InvalidObjectNumber(Int)
    BadDate
    InvalidUnicodeCodepoint(Int)
    InvalidUTF16BE
    InvalidUTF8
    InvalidPDFDocEncoding(Int)
    CryptoKeyExpected
    InvalidCryptoDataLength(Int)
    EncryptionExpected
    EncryptionMethodExpected
    EncryptionDictionaryEntryExpected(PdfName)
    EncryptionDictionaryEntryTooShort(PdfName)
    EncryptionIDExpected
    EncryptionAuthenticationUnsupported(PdfCryptType)
    EncryptionObjectCryptUnsupported(PdfCryptType)
    EncryptionSavedStateExpected
    EncryptionRecryptUnsupported(PdfCryptType)
    EncryptionRecryptFailed
    EncryptionPermissionsCorrupt
    EncryptionPermissionsMismatch(Int, Int)
    RandomBytesUnavailable
    EncodingExpected
    EncodingDifferencesMalformed
    EncodingWriteUnsupported
    FontSubtypeExpected
    FontFlagsExpected
    StandardFontExpected
    BaseFontExpected
    FontFirstCharExpected
    FontLastCharExpected
    FontWidthsExpected
    FontWidthExpected
    FontCharProcsExpected
    FontTypeExpected
    FontWriteUnsupported
    AfmExpected
    ColourSpaceExpected
    BadText
    TitleExpected
    CIDSystemInfoExpected
    CIDRegistryExpected
    CIDOrderingExpected
    CIDSupplementExpected
    CIDBaseFontExpected
    CIDFontDescriptorExpected
    CIDWidthsExpected
    CIDWidths2Expected
    DescendantFontExpected
    CMapEncodingExpected
    PageLabelStyleExpected(String)
    EndOfInput
    } derive(Eq, ToJson,
    Debug
    )

    Error variants raised by pdflite parsing, writing, filtering, text, and encryption APIs.

    The variants intentionally stay specific enough for tests and callers to distinguish malformed input classes, while most public APIs expose them through the ordinary raise PdfError flow.

    PdfError::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfError::equal(PdfError, PdfError) -> Bool

    PdfError::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfError::not_equal(x : PdfError, y : PdfError) -> Bool

    PdfError::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfError::to_json(PdfError) -> Json

    PdfError::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfError::to_repr(PdfError) ->
    Repr

    BitStream

    pub struct BitStream {
    input : ByteCursor
    current_byte : Int
    bit_mask : Int
    bits_read : Int
    } derive(Eq, ToJson,
    Debug
    )

    A big-endian bit reader over a ByteCursor.

    The stream reads the most-significant bit of each byte first, matching the bit order used by PDF filters such as CCITT and Flate Huffman tables. align discards any unread bits in the current byte and resumes at the next byte boundary.

    BitStream::align

    fn BitStream::align(self : BitStream) -> Unit

    Discards unread bits in the current byte and moves to the next byte boundary.

    BitStream::bits_read

    fn BitStream::bits_read(self : BitStream) -> Int

    Returns the number of bits consumed from this stream.

    The count includes bits skipped by align.

    BitStream::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStream::equal(BitStream, BitStream) -> Bool

    BitStream::get_bit

    fn BitStream::get_bit(self : BitStream) -> Bool raise PdfError

    Reads one bit and returns it as a boolean.

    The return value is true for bit 1 and false for bit 0. Raises PdfError::EndOfInput if there is no byte available for the next bit.

    BitStream::get_bit_int

    fn BitStream::get_bit_int(self : BitStream) -> Int raise PdfError

    Reads one bit and returns it as integer 0 or 1.

    Raises PdfError::EndOfInput if there is no byte available for the next bit.

    BitStream::get_value_int

    fn BitStream::get_value_int(self : BitStream, width : Int) -> Int raise PdfError

    Reads up to 31 bits as a big-endian signed Int payload.

    This function only assembles the bit pattern; it does not sign-extend the result. Raises PdfError::InvalidBitCount for widths outside 0..=31 and PdfError::EndOfInput if the stream ends early.

    BitStream::get_value_int64

    fn BitStream::get_value_int64(self : BitStream, width : Int) -> Int64 raise PdfError

    Reads up to 32 bits as a big-endian Int64 payload.

    This is useful for PDF filter fields whose packed value may not fit the positive range of Int. Raises PdfError::InvalidBitCount for widths outside 0..=32 and PdfError::EndOfInput if the stream ends early.

    BitStream::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStream::not_equal(x : BitStream, y : BitStream) -> Bool

    BitStream::position

    fn BitStream::position(self : BitStream) -> BitStreamPosition

    Returns a restorable snapshot of the current bit position.

    BitStream::seek

    fn BitStream::seek(self : BitStream, position : BitStreamPosition) -> Unit

    Restores this bit stream to a previously captured position.

    Raises PdfError::InvalidCursorPosition if the saved byte position is not valid for the underlying cursor.

    BitStream::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStream::to_json(BitStream) -> Json

    BitStream::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStream::to_repr(BitStream) ->
    Repr

    BitStreamPosition

    pub struct BitStreamPosition {
    input_position : Int
    current_byte : Int
    bit_mask : Int
    bits_read : Int
    } derive(Eq, ToJson,
    Debug
    )

    A restorable snapshot of a BitStream position.

    The snapshot captures both the underlying byte cursor position and the partially consumed current byte, so seeking back to it is safe even in the middle of a byte.

    BitStreamPosition::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStreamPosition::equal(BitStreamPosition, BitStreamPosition) -> Bool

    BitStreamPosition::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStreamPosition::not_equal(x : BitStreamPosition, y : BitStreamPosition) -> Bool

    BitStreamPosition::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStreamPosition::to_json(BitStreamPosition) -> Json

    BitStreamPosition::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitStreamPosition::to_repr(BitStreamPosition) ->
    Repr

    BitWriter

    pub struct BitWriter {
    current_byte : Int
    bit_index : Int
    bytes : Array[Byte]
    } derive(Eq, ToJson,
    Debug
    )

    A big-endian bit writer that accumulates PDF bytes.

    Bits are packed most-significant first in each output byte. The final byte is zero-padded when align or to_bytes flushes a partially filled byte.

    BitWriter::align

    fn BitWriter::align(self : BitWriter) -> Unit

    Flushes any partial output byte, padding its unread low bits with zero.

    BitWriter::append_aligned

    fn BitWriter::append_aligned(self : BitWriter, other : BitWriter) -> BitWriter

    Appends another writer's bits after aligning this writer to a byte boundary.

    The returned writer is a copy; neither input writer is mutated.

    BitWriter::bit_length

    fn BitWriter::bit_length(self : BitWriter) -> Int

    Returns the number of bits currently written, including an unflushed partial byte.

    BitWriter::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitWriter::equal(BitWriter, BitWriter) -> Bool

    BitWriter::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitWriter::not_equal(x : BitWriter, y : BitWriter) -> Bool

    BitWriter::put_bit

    fn BitWriter::put_bit(self : BitWriter, bit : Int) -> Unit raise PdfError

    Writes one bit, accepting only integer values 0 and 1.

    Raises PdfError::InvalidBit for any other value.

    BitWriter::put_value_int

    fn BitWriter::put_value_int(self : BitWriter, width : Int, value : Int) -> Unit raise PdfError

    Writes the low width bits of an Int in big-endian bit order.

    Raises PdfError::InvalidBitCount for widths outside 0..=31.

    BitWriter::put_value_int64

    fn BitWriter::put_value_int64(self : BitWriter, width : Int, value : Int64) -> Unit raise PdfError

    Writes the low width bits of an Int64 in big-endian bit order.

    Raises PdfError::InvalidBitCount for widths outside 0..=32.

    BitWriter::to_bytes

    fn BitWriter::to_bytes(self : BitWriter) -> Bytes

    Returns the accumulated bytes, flushing a partial final byte if needed.

    BitWriter::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitWriter::to_json(BitWriter) -> Json

    BitWriter::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn BitWriter::to_repr(BitWriter) ->
    Repr

    ByteCursor

    pub struct ByteCursor {
    data : BytesView
    position : Int
    offset : Int
    source : String
    } derive(Eq, ToJson,
    Debug
    )

    A mutable read cursor over a PDF byte view.

    ByteCursor keeps a source label for diagnostics and supports an optional logical offset. After set_offset, public positions are relative to that offset while absolute positions still refer to the underlying byte view.

    ByteCursor::absolute_position

    fn ByteCursor::absolute_position(self : ByteCursor) -> Int

    Returns the current absolute position in the underlying byte view.

    ByteCursor::byte_at_absolute

    fn ByteCursor::byte_at_absolute(self : ByteCursor, position : Int) -> Byte?

    Returns the byte at an absolute input position without advancing.

    ByteCursor::byte_int_at_absolute

    fn ByteCursor::byte_int_at_absolute(self : ByteCursor, position : Int) -> Int

    Returns the byte at an absolute input position as an integer.

    Returns pdf_no_more when position is outside the underlying byte view.

    ByteCursor::deep_copy

    fn ByteCursor::deep_copy(self : ByteCursor) -> ByteCursor

    Returns a cursor copy with the same input, source label, offset, and position.

    ByteCursor::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteCursor::equal(ByteCursor, ByteCursor) -> Bool

    ByteCursor::ignore_until

    fn ByteCursor::ignore_until(self : ByteCursor, stop : (Int) -> Bool, eof_is_delimiter? : Bool) -> Unit raise PdfError

    Advances until stop matches the next byte.

    The delimiter byte is left unread. EOF handling follows read_until_view.

    ByteCursor::input_byte

    fn ByteCursor::input_byte(self : ByteCursor) -> Int

    Reads one byte as an integer and advances the cursor.

    Returns pdf_no_more when reading past the end. This method always advances by one position, matching the historical parser cursor behavior.

    ByteCursor::input_pdf_error

    fn ByteCursor::input_pdf_error(self : ByteCursor, message : String) -> String

    Formats an input error message with the source label and current logical position.

    ByteCursor::length

    fn ByteCursor::length(self : ByteCursor) -> Int

    Returns the total length of the underlying byte view.

    ByteCursor::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteCursor::not_equal(x : ByteCursor, y : ByteCursor) -> Bool

    ByteCursor::nudge

    fn ByteCursor::nudge(self : ByteCursor) -> Unit

    Advances the cursor by one byte, ignoring the value read.

    ByteCursor::peek

    fn ByteCursor::peek(self : ByteCursor) -> Byte?

    Returns the next byte without consuming it, or None at end of input.

    ByteCursor::peek_byte

    fn ByteCursor::peek_byte(self : ByteCursor) -> Int

    Returns the next byte as an integer without consuming it.

    Returns pdf_no_more at end of input.

    ByteCursor::peek_bytes

    fn ByteCursor::peek_bytes(self : ByteCursor, length : Int) -> Bytes raise PdfError

    Copies the next length bytes without advancing.

    Raises the same errors as peek_view.

    ByteCursor::peek_view

    fn ByteCursor::peek_view(self : ByteCursor, length : Int) -> BytesView raise PdfError

    Returns a read-only view of the next length bytes without advancing.

    Raises PdfError::InvalidReadLength for negative lengths and PdfError::EndOfInput if the requested range extends past the input.

    ByteCursor::position

    fn ByteCursor::position(self : ByteCursor) -> Int

    Returns the current logical position, relative to the configured offset.

    ByteCursor::read_byte

    fn ByteCursor::read_byte(self : ByteCursor) -> Byte?

    Reads one byte and advances the cursor, returning None at end of input.

    ByteCursor::read_byte_back

    fn ByteCursor::read_byte_back(self : ByteCursor) -> Byte?

    Reads the previous byte and moves the cursor backward.

    Returns None when the cursor is at the logical start or when the resulting position is outside the underlying view.

    ByteCursor::read_bytes

    fn ByteCursor::read_bytes(self : ByteCursor, length : Int) -> Bytes raise PdfError

    Reads length bytes into owned PDF bytes and advances past them.

    Raises the same errors as read_view.

    ByteCursor::read_bytes_at

    fn ByteCursor::read_bytes_at(self : ByteCursor, position : Int, length : Int) -> Bytes raise PdfError

    Seeks to position, reads length bytes into owned PDF bytes, and advances past them.

    ByteCursor::read_line

    fn ByteCursor::read_line(self : ByteCursor) -> Bytes raise PdfError

    Reads one line into owned PDF bytes.

    Raises PdfError::EndOfInput if called at EOF.

    ByteCursor::read_line_view

    fn ByteCursor::read_line_view(self : ByteCursor) -> BytesView raise PdfError

    Reads one line as a view, including the line-ending bytes when present.

    Both LF and CRLF are recognized. Raises PdfError::EndOfInput if called at EOF.

    ByteCursor::read_line_views

    fn ByteCursor::read_line_views(self : ByteCursor) -> Array[BytesView]

    Reads all remaining lines as borrowed views.

    Each line view includes the line-ending bytes when they were present in the input.

    ByteCursor::read_lines

    fn ByteCursor::read_lines(self : ByteCursor) -> Array[Bytes]

    Reads all remaining lines as owned PDF bytes.

    ByteCursor::read_remaining_bytes

    fn ByteCursor::read_remaining_bytes(self : ByteCursor) -> Bytes

    Reads all remaining bytes into owned PDF bytes and advances to EOF.

    ByteCursor::read_until_view

    fn ByteCursor::read_until_view(self : ByteCursor, stop : (Int) -> Bool, eof_is_delimiter? : Bool) -> BytesView raise PdfError

    Reads until stop matches the next byte and returns the bytes before it.

    The delimiter byte is not consumed. If EOF is reached and eof_is_delimiter is true, the remaining bytes are returned; otherwise PdfError::EndOfInput is raised.

    ByteCursor::read_view

    fn ByteCursor::read_view(self : ByteCursor, length : Int) -> BytesView raise PdfError

    Reads length bytes as a view and advances past them.

    Raises PdfError::InvalidReadLength for negative lengths and PdfError::EndOfInput if the requested range extends past the input.

    ByteCursor::read_view_at

    fn ByteCursor::read_view_at(self : ByteCursor, position : Int, length : Int) -> BytesView raise PdfError

    Seeks to position, then reads length bytes as a view.

    The returned view borrows the cursor input; use read_bytes_at when owned bytes are required.

    ByteCursor::remaining_length

    fn ByteCursor::remaining_length(self : ByteCursor) -> Int

    Returns the number of unread bytes remaining from the absolute cursor position.

    ByteCursor::remaining_view

    fn ByteCursor::remaining_view(self : ByteCursor) -> BytesView

    Returns a view of all bytes from the current position to the end of input.

    ByteCursor::rewind

    fn ByteCursor::rewind(self : ByteCursor) -> Unit raise PdfError

    Moves the cursor one byte backward.

    Raises PdfError::InvalidCursorPosition if the cursor is already at the logical start position.

    ByteCursor::seek

    fn ByteCursor::seek(self : ByteCursor, position : Int) -> Unit raise PdfError

    Moves the cursor to a logical position.

    The supplied position is interpreted relative to the configured offset. Seeking past the end is allowed so callers can probe EOF behavior; negative absolute positions raise PdfError::InvalidCursorPosition.

    ByteCursor::seek_absolute

    fn ByteCursor::seek_absolute(self : ByteCursor, position : Int) -> Unit raise PdfError

    Moves the cursor to an absolute position in the underlying byte view.

    ByteCursor::set_offset

    fn ByteCursor::set_offset(self : ByteCursor, offset : Int) -> Unit raise PdfError

    Sets the logical position offset used by position and seek.

    The offset can only be set once and must be non-negative. This is used when parsing substreams whose local position should start at zero while retaining absolute positions for diagnostics.

    ByteCursor::source

    fn ByteCursor::source(self : ByteCursor) -> String

    Returns the diagnostic source label associated with this cursor.

    ByteCursor::to_bytes

    fn ByteCursor::to_bytes(self : ByteCursor) -> Bytes

    Copies the underlying byte view into owned PDF bytes.

    ByteCursor::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteCursor::to_json(ByteCursor) -> Json

    ByteCursor::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteCursor::to_repr(ByteCursor) ->
    Repr

    ByteCursor::view

    fn ByteCursor::view(self : ByteCursor) -> BytesView

    Returns the underlying read-only byte view without copying.

    ByteCursor::view_at

    fn ByteCursor::view_at(self : ByteCursor, position : Int, length : Int) -> BytesView raise PdfError

    Returns a read-only view at a logical position without advancing.

    ByteCursor::view_at_absolute

    fn ByteCursor::view_at_absolute(self : ByteCursor, position : Int, length : Int) -> BytesView raise PdfError

    Returns a read-only view at an absolute position without advancing.

    ByteOutput

    pub struct ByteOutput {
    data : Array[Byte]
    position : Int
    written_length : Int
    } derive(Eq, ToJson,
    Debug
    )

    A growable byte sink with seekable overwrite support.

    ByteOutput tracks the current write position separately from the highest position written, so callers may seek backward to patch bytes and then obtain only the initialized prefix with to_bytes.

    ByteOutput::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteOutput::equal(ByteOutput, ByteOutput) -> Bool

    ByteOutput::length

    fn ByteOutput::length(self : ByteOutput) -> Int

    Returns the highest written byte position.

    This is the length of the byte sequence returned by to_bytes.

    ByteOutput::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteOutput::not_equal(x : ByteOutput, y : ByteOutput) -> Bool

    ByteOutput::position

    fn ByteOutput::position(self : ByteOutput) -> Int

    Returns the current write position.

    ByteOutput::seek

    fn ByteOutput::seek(self : ByteOutput, position : Int) -> Unit raise PdfError

    Moves the write position.

    Seeking beyond the current length is allowed; unwritten gaps are filled with zero when data is later written. Negative positions raise PdfError::InvalidCursorPosition.

    ByteOutput::to_bytes

    fn ByteOutput::to_bytes(self : ByteOutput) -> Bytes

    Returns the written prefix as owned PDF bytes.

    Bytes beyond length that were only preallocated are not included.

    ByteOutput::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteOutput::to_json(ByteOutput) -> Json

    ByteOutput::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn ByteOutput::to_repr(ByteOutput) ->
    Repr

    ByteOutput::write_ascii

    fn ByteOutput::write_ascii(self : ByteOutput, text : String) -> Unit raise PdfError

    Encodes an ASCII string and writes the resulting bytes.

    The underlying @ascii.encode function is used intentionally; callers should pass bytes directly for non-ASCII PDF payloads.

    ByteOutput::write_byte

    fn ByteOutput::write_byte(self : ByteOutput, value : Int) -> Unit raise PdfError

    Writes one byte at the current position and advances by one.

    Raises PdfError::InvalidByte if value is outside the byte range 0..=255.

    ByteOutput::write_byte_at

    fn ByteOutput::write_byte_at(self : ByteOutput, position : Int, value : Int) -> Unit raise PdfError

    Seeks to position, writes one byte, and advances by one.

    Raises the same errors as seek and write_byte.

    ByteOutput::write_repeated_byte

    fn ByteOutput::write_repeated_byte(self : ByteOutput, length : Int, value? : Int) -> Unit raise PdfError

    Writes length copies of value and advances past them.

    The default value is zero. Raises PdfError::InvalidReadLength for invalid lengths and PdfError::InvalidByte for values outside 0..=255.

    ByteOutput::write_view

    fn ByteOutput::write_view(self : ByteOutput, bytes : BytesView) -> Unit raise PdfError

    Writes a byte view at the current position and advances past it.

    Raises PdfError::InvalidReadLength if the computed end position overflows.

    ByteOutput::write_view_at

    fn ByteOutput::write_view_at(self : ByteOutput, position : Int, bytes : BytesView) -> Unit raise PdfError

    Seeks to position, writes a byte view, and advances past it.

    Raises the same errors as seek and write_view.

    ByteOutput::write_view_slice

    fn ByteOutput::write_view_slice(self : ByteOutput, bytes : BytesView, offset : Int, length : Int) -> Unit raise PdfError

    Writes a slice of a byte view at the current position.

    Raises PdfError::InvalidCursorPosition for a negative offset, PdfError::InvalidReadLength for a negative or overflowing length, and PdfError::EndOfInput if the requested slice exceeds the input view.

    PdfCryptType

    pub(all) enum PdfCryptType {
    PdfCryptARC4(Int, Int)
    PdfCryptAESV2
    PdfCryptAESV3(Bool)
    } derive(Eq, ToJson,
    Debug
    )

    Object encryption algorithm used by the PDF security handlers.

    ARC4 carries key length in bits and security-handler revision. AESV3 carries whether the ISO/PDF 2.0 hash variant is in use.

    PdfCryptType::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfCryptType::equal(PdfCryptType, PdfCryptType) -> Bool

    PdfCryptType::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfCryptType::not_equal(x : PdfCryptType, y : PdfCryptType) -> Bool

    PdfCryptType::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfCryptType::to_json(PdfCryptType) -> Json

    PdfCryptType::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfCryptType::to_repr(PdfCryptType) ->
    Repr

    PdfName

    pub(all) struct PdfName(Bytes) derive(Eq, ToJson,
    Debug
    )

    A PDF name token stored as its raw bytes without the leading slash.

    Names are byte-oriented in the PDF file format. Keeping the original bytes avoids accidental UTF-16 or UTF-8 interpretation while still allowing explicit views and owned-byte access.

    PdfName::byte_length

    fn PdfName::byte_length(self : PdfName) -> Int

    Returns the byte length of this PDF name.

    PdfName::bytes

    fn PdfName::bytes(self : PdfName) -> Bytes

    Returns the owned bytes backing this PDF name.

    PdfName::equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfName::equal(PdfName, PdfName) -> Bool

    PdfName::not_equal

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfName::not_equal(x : PdfName, y : PdfName) -> Bool

    PdfName::to_json

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfName::to_json(PdfName) -> Json

    PdfName::to_repr

    #deprecated("implicit trait-method promotion is being removed; call via the trait")
    fn PdfName::to_repr(PdfName) ->
    Repr

    PdfName::view

    fn PdfName::view(self : PdfName) -> BytesView

    Returns a read-only view of the bytes backing this PDF name.

    PdfNumberSet

    pub struct PdfNumberSet {
    values :
    HashMap
    [Int, Bool]
    }

    Mutable set of PDF object numbers used to de-duplicate traversal results.

    PdfNumberSet::add

    fn PdfNumberSet::add(self : PdfNumberSet, number : Int) -> Unit

    Add number to the set.

    PdfNumberSet::contains

    fn PdfNumberSet::contains(self : PdfNumberSet, number : Int) -> Bool

    Return whether the set already contains number.

    bit_writer_new

    fn bit_writer_new() -> BitWriter

    Creates an empty bit writer.

    bitstream_of_bytes

    fn bitstream_of_bytes(data : Bytes, source? : String) -> BitStream

    Creates a bit stream over owned PDF bytes.

    The optional source label is forwarded to the underlying cursor and is used in parse error messages.

    bitstream_of_cursor

    fn bitstream_of_cursor(input : ByteCursor) -> BitStream

    Creates a bit stream that reads from an existing byte cursor.

    bitstream_of_view

    fn bitstream_of_view(data : BytesView, source? : String) -> BitStream

    Creates a bit stream over a read-only byte view.

    The returned reader does not copy data; callers that need ownership should pass owned bytes explicitly.

    byte_cursor_of_bytes

    fn byte_cursor_of_bytes(data : Bytes, source? : String) -> ByteCursor

    Creates a cursor over owned PDF bytes.

    The cursor borrows the byte storage through a view and does not copy it.

    byte_cursor_of_view

    fn byte_cursor_of_view(data : BytesView, source? : String) -> ByteCursor

    Creates a cursor over a byte view.

    The optional source label appears in parse error messages.

    byte_output_new

    fn byte_output_new(initial_size? : Int) -> ByteOutput raise PdfError

    Creates an empty output buffer.

    initial_size preallocates zero-filled capacity but does not count as written output. Raises PdfError::InvalidReadLength for negative sizes.

    pdf_byte_of_int

    fn pdf_byte_of_int(value : Int) -> Byte raise PdfError

    Converts an integer to a byte.

    Raises PdfError::InvalidByte when value is outside 0..=255.

    pdf_bytes_concat_views

    fn pdf_bytes_concat_views(parts : ArrayView[BytesView]) -> Bytes

    Concatenates byte views into one owned PDF byte sequence.

    pdf_bytes_copy

    fn pdf_bytes_copy(values : BytesView) -> Bytes

    Copies a byte view into owned PDF bytes using indexed construction.

    This is useful when the input may alias data that will be mutated elsewhere.

    pdf_bytes_get

    fn pdf_bytes_get(bytes : Bytes, index : Int) -> Byte?

    Returns the byte at index, or None when the index is out of bounds.

    pdf_bytes_length

    fn pdf_bytes_length(bytes : Bytes) -> Int

    Returns the length of a PDF byte sequence.

    pdf_bytes_make

    fn pdf_bytes_make(length : Int, value? : Int) -> Bytes raise PdfError

    Creates owned PDF bytes of length filled with value.

    The default value is zero. Raises PdfError::InvalidReadLength for negative lengths and PdfError::InvalidByte for values outside 0..=255.

    pdf_bytes_map_int

    fn pdf_bytes_map_int(bytes : BytesView, f : (Int) -> Int) -> Bytes raise PdfError

    Maps every byte through an integer transformation and returns owned bytes.

    The callback receives each input byte as an Int. Raises PdfError::InvalidByte if a mapped value is outside 0..=255.

    pdf_bytes_of_array_view

    fn pdf_bytes_of_array_view(values : ArrayView[Byte]) -> Bytes

    Copies an array view of bytes into owned PDF bytes.

    pdf_bytes_of_int_array

    fn pdf_bytes_of_int_array(values : ArrayView[Int]) -> Bytes raise PdfError

    Converts integer byte values to owned PDF bytes.

    Raises PdfError::InvalidByte if any value is outside 0..=255.

    pdf_bytes_of_int_arrays

    fn pdf_bytes_of_int_arrays(values : ArrayView[ArrayView[Int]]) -> Bytes raise PdfError

    Flattens arrays of integer byte values into owned PDF bytes.

    Raises PdfError::InvalidByte if any value is outside 0..=255.

    pdf_bytes_of_view

    fn pdf_bytes_of_view(values : BytesView) -> Bytes

    Copies a byte view into owned PDF bytes.

    pdf_bytes_to_array

    fn pdf_bytes_to_array(bytes : Bytes) -> Array[Byte]

    Copies PDF bytes into a resizable Array[Byte].

    pdf_bytes_to_fixed_array

    fn pdf_bytes_to_fixed_array(bytes : Bytes) -> FixedArray[Byte]

    Copies PDF bytes into a fixed-size byte array.

    pdf_count_whitespace_tokens

    fn pdf_count_whitespace_tokens(view : BytesView) -> Int

    Count non-empty tokens separated by PDF whitespace bytes.

    pdf_error

    fn pdf_error(message : String) -> Unit raise PdfError

    Raise a cpdf-style soft error.

    This mirrors Cpdferror.error, which raises SoftError.

    pdf_error_summary

    fn pdf_error_summary(error : PdfError) -> String

    Return a concise, user-facing summary for a PdfError.

    The suffix keeps the precise variant visible for tests and callers that use CLI output while replacing raw constructor-only messages with useful text.

    pdf_find_ascii_from

    fn pdf_find_ascii_from(view : BytesView, start : Int, values : ArrayView[Int]) -> Int

    Find the first occurrence of the ASCII byte sequence at or after start.

    Returns -1 when the sequence is absent.

    pdf_find_last_ascii

    fn pdf_find_last_ascii(view : BytesView, values : ArrayView[Int]) -> Int

    Find the last occurrence of the ASCII byte sequence in view.

    Returns -1 when the sequence is absent. An empty sequence matches at view.length().

    pdf_hard_error

    fn pdf_hard_error(message : String) -> Unit raise PdfError

    Raise a cpdf-style hard error.

    pdf_int_array_of_bytes

    fn pdf_int_array_of_bytes(bytes : BytesView) -> Array[Int]

    Converts bytes to an array of integer byte values.

    pdf_is_delimiter_byte

    fn pdf_is_delimiter_byte(value : Int) -> Bool

    Return whether a byte is a PDF token delimiter.

    Delimiters are parentheses, slash, angle brackets, square brackets, braces, and percent.

    pdf_is_digit_byte

    fn pdf_is_digit_byte(value : Int) -> Bool

    Return whether a byte is an ASCII digit.

    pdf_is_newline_byte

    fn pdf_is_newline_byte(value : Int) -> Bool

    Return whether a byte is a PDF line break byte.

    pdf_is_not_whitespace_byte

    fn pdf_is_not_whitespace_byte(value : Int) -> Bool

    Return whether a byte is not PDF white space.

    pdf_is_whitespace_byte

    fn pdf_is_whitespace_byte(value : Int) -> Bool

    Return whether a byte is PDF white space.

    Recognized values are NUL, horizontal tab, line feed, form feed, carriage return, and space.

    pdf_is_whitespace_or_delimiter_byte

    fn pdf_is_whitespace_or_delimiter_byte(value : Int) -> Bool

    Return whether a byte terminates a regular PDF token.

    pdf_name_of_bytes

    fn pdf_name_of_bytes(bytes : Bytes) -> PdfName

    Wraps owned bytes as a PDF name without copying.

    The bytes are expected to be the name payload without the leading slash.

    pdf_name_of_view

    fn pdf_name_of_view(bytes : BytesView) -> PdfName

    Copies a byte view and wraps it as a PDF name.

    The bytes are expected to be the name payload without the leading slash.

    pdf_no_more

    let pdf_no_more : Int

    Sentinel returned by legacy byte-reading helpers when the cursor is past the end of input.

    Newer APIs usually return Byte?, but this value preserves the CamlPDF-style integer cursor contract used by parser code.

    pdf_number_set

    fn pdf_number_set(numbers : ArrayView[Int]) -> PdfNumberSet

    Build a number set pre-populated with the given object numbers.

    pdf_parse_ascii_int_view

    fn pdf_parse_ascii_int_view(view : BytesView) -> Int raise PdfError

    Parse an unsigned 32-bit signed-range decimal integer from ASCII bytes.

    Raises PdfError::NumberExpected for empty, non-digit, or overflow input.

    pdf_push_unique_number

    fn pdf_push_unique_number(numbers : Array[Int], seen : PdfNumberSet, number : Int) -> Unit

    Push number into numbers only when it has not been seen before.

    pdf_soft_error

    fn pdf_soft_error(message : String) -> Unit raise PdfError

    Raise a cpdf-style soft error.

    pdf_split_whitespace_tokens

    fn pdf_split_whitespace_tokens(view : BytesView) -> Array[BytesView]

    Split a byte view into non-empty slices separated by PDF whitespace bytes.

    The returned token views borrow from the input view.

    pdf_startxref_search_view

    fn pdf_startxref_search_view(data : BytesView) -> BytesView

    Return the portion of data before the last %%EOF marker.

    If no EOF marker is present, returns the original view.

    pdf_string_of_int_array

    fn pdf_string_of_int_array(values : ArrayView[Int]) -> Bytes raise PdfError

    Compatibility alias for converting one integer byte array to PDF bytes.

    pdf_string_of_int_arrays

    fn pdf_string_of_int_arrays(values : ArrayView[ArrayView[Int]]) -> Bytes raise PdfError

    Compatibility alias for pdf_bytes_of_int_arrays.

    CamlPDF models many byte strings as integer lists; this helper preserves that shape for callers ported from OCaml.

    pdf_view_equals_ascii

    fn pdf_view_equals_ascii(view : BytesView, values : ArrayView[Int]) -> Bool

    Return whether view has exactly the ASCII byte values in values.

    pdf_view_matches_ascii_at

    fn pdf_view_matches_ascii_at(view : BytesView, position : Int, values : ArrayView[Int]) -> Bool

    Return whether values matches view starting at position.

    Negative positions and ranges beyond the end of view return false.