Skip to content

Releases: jscarr64/LaTeX-Rust

latex-rust 2.0.1

Choose a tag to compare

@jscarr64 jscarr64 released this 28 Sep 04:10

A fix for the egui backend. No API changes. Upgrade with cargo update -p latex-rust. SVG and PNG output is unchanged from 2.0.0.

Fixed

  • The egui backend renders every glyph in the bundled font. Before, formulas using H, math italic t (so \partial_t u = \Delta u), π, σ, #, $, €, \dashv, \natural, bold and blackboard-bold capitals, and about 260 other glyphs failed with Error::Unsupported { what: "glyph tessellation" }. B, k, τ, ↦, and about 140 other glyphs were drawn with a stray triangle outside the glyph.
  • Cause: the ear clipper that turns glyph outlines into triangles accepted an ear whose closing diagonal ran exactly through another outline point, which happens where points line up, such as on straight stems. Its result is now checked exactly. An outline it cannot triangulate correctly is triangulated instead by exact scanline trapezoids under the non-zero rule, the rule the SVG and PNG backends fill with. Glyphs that were already drawn correctly get the same meshes as before.

The same fix is in 1.0.5.

latex-rust 1.0.5

Choose a tag to compare

@jscarr64 jscarr64 released this 28 Sep 04:10

Upgrade notice. Versions 1.0.0 through 1.0.4 abort the whole process with a stack overflow when given deeply nested input. If your program renders LaTeX from any untrusted source, upgrade to 1.0.5:

cargo update -p latex-rust

1.0.5 has no API changes. It also includes the 2.0.0 rendering fixes that fit the 1.x API and the 2.0.1 egui fix, so most formulas now draw differently from 1.0.4 (see below).

Security

  • Deeply nested input now returns an error instead of aborting the process (#6). The parser and the layout engine recursed once per nesting level with no limit. For example, 700 nested \frac{1}{…} (about 7 KB of input) overflowed an 8 MiB stack in an optimised build, and far fewer levels were enough on smaller thread stacks. A stack overflow cannot be caught with catch_unwind, so any program rendering untrusted LaTeX could be terminated.

Fixed

These fixes are backported from 2.0.0 and draw the same output as 2.0.0.

  • Superscripts, subscripts, limits, and fraction parts in text style are drawn at script size in the SVG, PNG, and egui renderers. Before, they were positioned at script size but drawn at full size. 2.0.0 added a scale field to BoxContent::Glyph for this; 1.0.5 leaves that type unchanged and works out the scale from the glyph box's size instead. (#1)
  • Unstyled Latin letters and lowercase Greek letters are set in math italic (for example x is drawn as U+1D465), as TeX does. Digits, uppercase Greek, \mathrm, \text, and operator names stay upright. (#2)
  • A math-mode - is drawn as U+2212 MINUS SIGN instead of the hyphen. (#3)
  • Font switches such as \mathbf and \mathrm reach nested subformulae (fractions, script bases, radicals), so \mathbf{\frac{a}{b}} is bold. (#4)
  • Diacritic accents (\hat, \dot, \bar, and the rest) are placed by the TeX rule. Before, they sat one accent base height too high. (#5)
  • The egui backend renders every glyph. Before, formulas using H, π, σ, math italic t (so \partial_t u), #, $, €, and a few hundred other glyphs failed with Error::Unsupported { what: "glyph tessellation" }, and B, k, τ, ↦, and about 140 others were drawn with a stray triangle outside the glyph. This is the same fix as in 2.0.1.

Changed behaviour

  • Input that nests more than 32 levels is refused. parse, parse_with_colors, and the latex_to_* functions return ParseError::Malformed("input nests deeper than 32 levels"). layout returns Error::Unsupported { what: "tree nests deeper than 32 levels" } for a tree built by hand that nests that deeply. Both are existing error variants.
  • The count is of parser recursion levels, and a braced argument costs two, so the limit admits 15 nested \frac, \sqrt, or x^{…}, and 31 nested groups, \left…\right pairs, or environments. Deeper input that 1.0.4 rendered (for example 16 to about 650 nested fractions in an optimised build) is now refused. The limit and the messages are the same as in 2.0.0.
  • Rendered output changes because of the fixes above. On our 87-input test corpus, 82 inputs draw differently from 1.0.4, and all 87 draw exactly as in 2.0.1 (SVG, PNG, egui, and box dimensions). Code that pinned 1.0.4 images, dimensions, or glyph characters will see new values.

Not in 1.0.5

These 2.0.0 changes add or change public API, so they are only in 2.0.0: Dim::as_ratio(), MathFont::face() and the ttf_parser re-export (#7), STIX_TWO_MATH_OTF as a static (#11), and ParseOptions, parse_with_options, and layout_with_max_depth for changing the depth limit.

Stack use

With the deepest input the limit admits, an optimised build needs at most about 512 KiB of stack, and an unoptimised build up to about 4 MiB (nested matrix environments). If you render on a thread with less stack than that, give the rendering thread more.

Advisory

A RustSec advisory for the crash is being requested. Its identifier will be added here once it is assigned.

Thanks

Tom Clark (IronLAB) reported all of these issues with reproductions and proposed fixes, and wrote the fix for #4 and the depth limit (#6, #10). Both are backported here under his name.

latex-rust 2.0.0

Choose a tag to compare

@jscarr64 jscarr64 released this 28 Sep 04:10

Upgrade notice. 2.0.0 fixes a crash on deeply nested input and several rendering errors in 1.x. It has breaking changes, listed below. If you cannot take breaking changes yet, use 1.0.5, which has the crash fix and the rendering fixes #1–#5 without API changes. If you use the egui backend, use 2.0.1, which fixes glyphs that failed to render there.

This release fixes the eight defects Tom Clark reported while integrating latex-rust into IronLAB (issues #1–#7 and #11). Several of them change what the renderer draws.

Breaking changes

  • BoxContent::Glyph has a new field, scale: Dim, and the variant is now #[non_exhaustive]. Match it with BoxContent::Glyph { ch, glyph_id, .. } and build it with BoxContent::glyph(ch, glyph_id, scale). (#1)
  • STIX_TWO_MATH_OTF is now a static instead of a const. It can no longer be used in a const context. (#11)
  • Parsing and layout return Err for input nested deeper than DEFAULT_MAX_NESTING_DEPTH (32 parser levels): 15 nested fractions, roots, or scripts, or 31 nested groups, \left…\right pairs, or environments. Use ParseOptions / parse_with_options and layout_with_max_depth to change the limit. (#6)
  • Output changes: variable letters are drawn in math italic, math-mode - is drawn as U+2212, script glyphs are drawn smaller, and diacritic accents sit lower. Code that pinned the old dimensions or images will see new values.

Fixed

  • Deeply nested input returns Err instead of aborting the process with a stack overflow. (#6)
  • Superscripts, subscripts, and limits are drawn at script size in the SVG, PNG, and egui renderers. Before, they were positioned at script size but drawn at full size. (#1)
  • Diacritic accents (\hat, \dot, \bar, and the rest) are placed by the TeX rule. Before, they sat one accent base height too high. (#5)
  • Font switches such as \mathrm and \mathbf reach nested subformulae (script bases, fractions, radicals). (#4)
  • Unstyled Latin letters and lowercase Greek letters are set in math italic, as TeX does. Digits, uppercase Greek, \mathrm, \text, and operator names stay upright. (#2)
  • A math-mode - is drawn as U+2212 MINUS SIGN instead of the hyphen. (#3)
  • STIX_TWO_MATH_OTF is linked into a binary once rather than once per use. (#11)

Added

  • BoxContent::glyph(ch, glyph_id, scale). (#1)
  • Dim::as_ratio() returns a Dim's exact value as a numerator and denominator. (#7)
  • MathFont::face() exposes the parsed OpenType face, and the crate re-exports ttf_parser. (#7)
  • ParseOptions, parse_with_options, layout_with_max_depth, and DEFAULT_MAX_NESTING_DEPTH. (#6)

Advisory

A RustSec advisory for the crash fixed by #6 is being requested. Its identifier will be added here once it is assigned.

Thanks

Tom Clark (IronLAB) reported all eight issues with reproductions and proposed fixes, and contributed the pull requests for #4, #7, and #11 and the first depth limit for #6.