PDFFence 1.17.0
Signature ByteRange current-file boundary
- Counts signature dictionaries only when a catalog-reachable AcroForm signature field (including inherited
/FT) or catalog/PermsDocMDP, UR, or UR3 entry reaches/Type /Sig. - Separates aggregate ByteRange presence from well-formed layout and current physical-file-end counts, without publishing byte offsets or signature material.
- Adds opt-in
no_signature_coverage_regressions(PFP009), which reports a decrease in semantic ByteRanges reaching the current stored file end. - Keeps private
/PieceInfosignature-shaped dictionaries outside signature inventory evidence.
This is static structure and boundary evidence only. It does not validate signatures, certificates, transforms, permissions, or trust.
Verification
233 tests and Ruff passed; PDFCAB 1.17 scored 154/154 pairs. Two fixed-timestamp builds produced identical wheel and source archives; clean Python 3.12/3.13 wheel installs and a Python 3.12 source-archive install passed pip check, fixture verification, and the full score.