commit 2703be11769c1f86f4d0dc3b276ec94bba5ac6d3
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sun Oct 4 01:32:58 2026 +0200

    poppler 26.10.0

 CMakeLists.txt         |  6 +++---
 NEWS                   | 36 ++++++++++++++++++++++++++++++++++++
 cpp/Doxyfile           |  2 +-
 qt5/src/CMakeLists.txt |  2 +-
 qt5/src/Doxyfile       |  2 +-
 qt6/src/CMakeLists.txt |  2 +-
 qt6/src/Doxyfile       |  2 +-
 7 files changed, 44 insertions(+), 8 deletions(-)

commit b8769a500322f8ef611d77fa003fc17b54f26768
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 23:39:52 2026 +0200

    Update (C)

 fofi/FoFiType1C.cc                                | 3 ++-
 glib/poppler-document.cc                          | 1 +
 glib/poppler-media.cc                             | 2 +-
 poppler/Catalog.cc                                | 1 +
 poppler/CertificateInfo.cc                        | 1 +
 poppler/CertificateInfo.h                         | 1 +
 poppler/CryptoSignBackend.h                       | 1 +
 poppler/Error.h                                   | 1 +
 poppler/Form.cc                                   | 1 +
 poppler/Form.h                                    | 1 +
 poppler/Function.cc                               | 1 +
 poppler/GPGMECryptoSignBackend.h                  | 5 ++++-
 poppler/NSSCryptoSignBackend.h                    | 3 ++-
 poppler/PDFDoc.cc                                 | 1 +
 poppler/PDFDoc.h                                  | 1 +
 poppler/Rendition.cc                              | 2 +-
 poppler/Rendition.h                               | 1 +
 qt5/src/poppler-form.cc                           | 1 +
 qt5/src/poppler-form.h                            | 3 ++-
 qt5/src/poppler-media.cc                          | 2 +-
 qt5/src/poppler-pdf-converter.cc                  | 1 +
 qt5/src/poppler-qt5.h                             | 1 +
 qt6/src/poppler-annotation.cc                     | 2 ++
 qt6/src/poppler-annotation.h                      | 2 ++
 qt6/src/poppler-form.h                            | 3 ++-
 qt6/src/poppler-media.cc                          | 2 +-
 splash/Splash.cc                                  | 2 +-
 test/font-subsetting/fontsubsetting-basic-test.cc | 1 +
 test/pdf-signing-nss.cc                           | 1 +
 29 files changed, 38 insertions(+), 10 deletions(-)

commit 8eb6111ac89bb1de6a9ae504c1a1fa27947334a6
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Feb 26 19:12:31 2026 +0100

    CI: Use clang-format 23

 .gitlab-ci.yml              | 4 ++--
 README.contributors         | 2 +-
 _clang-format               | 2 ++
 poppler/CryptoSignBackend.h | 1 -
 poppler/PSOutputDev.h       | 2 +-
 utils/pdftoppm.cc           | 2 +-
 6 files changed, 7 insertions(+), 6 deletions(-)

commit 2497397369a037bd1574289a38ad324b1d006dcc
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Sat Oct 3 19:52:52 2026 +0200

    CryptoSign: Ensure variables are set in all and every case

 poppler/GPGMECryptoSignBackend.h | 4 ++--
 poppler/NSSCryptoSignBackend.h   | 2 +-
 2 files changed, 3 insertions(+), 3 deletions(-)

commit 1feb81580a9172991746718bc9240947dde1a157
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Sat Oct 3 19:50:31 2026 +0200

    gpgme: verify context before setting it

 poppler/GPGMECryptoSignBackend.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit cf96238bcb3c268f1e4ffb776132dc28907a4733
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 17:14:14 2026 +0200

    CI: Use clang23

 .clang-tidy           |  9 +++++++++
 .gitlab-ci.yml        | 10 +++++-----
 glib/poppler-annot.cc |  9 +++++++++
 3 files changed, 23 insertions(+), 5 deletions(-)

commit 166c83e0a41e3ca70a094092977528c482416fbb
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 16:29:28 2026 +0200

    move std::vector

    clang-tidy says error: 'supported' could be moved here
    [performance-use-std-move,-warnings-as-errors]

 poppler/CertificateInfo.cc | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

commit 6841a30662fba7bf5bb56b1398578da4aad15454
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 12:47:05 2026 +0200

    ossfuzz: Update nss to 3.130

 test/ossfuzz/build_fuzzers.sh | 8 ++++----
 test/ossfuzz/prepare_build.sh | 2 +-
 2 files changed, 5 insertions(+), 5 deletions(-)

commit ae12447ab5146064c7624a10e63d42bbbbe74a93
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 12:44:54 2026 +0200

    ossfuzz: Update boost to 1.92

 test/ossfuzz/build_fuzzers.sh | 2 +-
 test/ossfuzz/prepare_build.sh | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

commit 1dcededd1a8f37696f7e011fd4961a16d63f9c8b
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 12:43:15 2026 +0200

    ossfuzz: Update glib to 2.88.3

 test/ossfuzz/build_fuzzers.sh | 2 +-
 test/ossfuzz/prepare_build.sh | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

commit e0316faa722ea21c57551d91c8696f28b1c743d4
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 12:41:11 2026 +0200

    ossfuzz: Unpin pango

 test/ossfuzz/prepare_build.sh | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

commit 283361f0afb26129961c04f47b53fea41ae62e94
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sat Oct 3 12:40:26 2026 +0200

    ossfuzz: Unpin libpng

 test/ossfuzz/prepare_build.sh | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

commit b35d70cbf33ac4e23ac2f4546c485cc87206582f
Author: Azhar Momin <azhar-momin@outlook.com>
Date:   Sat Oct 3 10:27:32 2026 +0000

    ci: Add manual job to test building OSS-Fuzz fuzzers

 .gitlab-ci.yml | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

commit 26e53b60bb099e2598a2a72a0d280d9cac9e5774
Author: William Bader <william@newspapersystems.com>
Date:   Wed Sep 30 07:51:00 2026 +0200

    Recode DeviceN images when preloading them for PostScript

    With -preload, setupImage() wrote the raw DeviceN samples, but at
    level 2
    doImageL2() declares the alternate color space, so the data had too few
    components.  bug-poppler5168.pdf pages 15, 27 and 41 showed a band
    of tiled
    copies across each photo.  Run the data through DeviceNRecoder as the
    non-preload path does, and do not pass DeviceN data through compressed,
    because doImageL2() and doImageL3() always declare their own filter
    for it.

 poppler/PSOutputDev.cc | 20 ++++++++++++--------
 poppler/PSOutputDev.h  |  4 ++--
 2 files changed, 14 insertions(+), 10 deletions(-)

commit e1838b9ac3f754e01fe8a0bac86e240a806e77e3
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Thu Oct 1 08:21:58 2026 +0200

    buildsystem: findharfbuzz: allow mismatched name

 cmake/modules/Findharfbuzz.cmake | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit 5418e9807c3f16db9642368089fb49cc14097b07
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Fri Sep 25 09:50:19 2026 +0200

    Add basic cades/eidas support to gpgme

 poppler/GPGMECryptoSignBackend.cc | 53
 +++++++++++++++++++++++++++++++++------
 1 file changed, 46 insertions(+), 7 deletions(-)

commit 711bcd7f0561fa01bc087c5065484d7a62c8a832
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Mon Sep 28 13:40:35 2026 +0200

    Find libharfbuzz via pkgconfig

    Due to <reasons>, the cmake api for harfbuzz is different depending on
    if harfbuzz was built with cmake or with meson.
    This means we either need to work around or just not use it.

    It doesn't look like upstream harfbuzz has much love for their cmake
    build system, so trying to fix that might not be that well received.
    Also, changing the cmake api for harfbuzz might upset some users.
    So just avoid it.

 cmake/modules/Findharfbuzz.cmake | 30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)

commit e8e976610e4c05296364ca580193ce708311fcb7
Author: Albert Astals Cid <aacid@kde.org>
Date:   Tue Sep 29 23:34:05 2026 +0200

    Update po[t] files

 utils/po/ca/pdfsig.po | 6 +++---
 utils/po/pdfsig.pot   | 6 +++---
 2 files changed, 6 insertions(+), 6 deletions(-)

commit 23e13d89b489421442524f8407365954ed6c9bb6
Author: William Bader <william.bader@gmail.com>
Date:   Mon Sep 7 00:19:44 2026 +0300

    Encode preloaded images once instead of twice

    setupImage() encoded each image twice: once to count the PostScript
    array
    entries and again to write them.  Buffer the encoded data instead.
    This holds
    one encoded image in memory where the old code streamed it twice.

    This also fixes blank preloaded JPEG 2000 images.  setupImage()
    called close()
    between the two passes, and JPXStream::close() destroys the decoded
    image and
    sets npixels to 0 without clearing inited, so init() never runs
    again and every
    later read returns EOF -- while JPXStream::rewind() still reports
    success.  The
    second pass therefore emitted an array declared at its full size
    holding a
    single empty entry, and the image disappeared.  Encoding once
    removes the
    dependency on the stream being re-readable.

    Test files:

      output-pdftopsbug.pdf  1.25 s -> 0.73 s  (1.71x), best of 5
      interleaved
          against master.  Its Type 3 CharProcs contain images, so
          setupImages()
          runs even without -preload.

      pdftops -preload now writes the image data instead of blank pages for
          WinterClientUpdate-poppler.pdf,
          2015SpringClientUpdate-poppler-jpeg-bug.pdf and
          Ghent_PDF-Output-Test-V50_ALL_X4.pdf.  Ghostscript renders
          the first of
          those from unpatched poppler as four byte-identical blank
          pages; with
          this commit the pages match what pdftoppm renders from the PDF.

    Over 200 files at the default level, -level1, -level3, -preload and
    -level2sep -optimizecolorspace, those three files under -preload
    are the only
    outputs that change.

 poppler/PSOutputDev.cc | 47
 ++++++++++++++++++++++++++---------------------
 1 file changed, 26 insertions(+), 21 deletions(-)

commit 0eef4605cb822dc84dfa6c3f3fe5fc8d0b57ad38
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Tue Sep 29 13:57:56 2026 +0200

    Enable subsetting unless android or generic

    foo

 CMakeLists.txt | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

commit 0909f0390c700b7afebe7d23d114fc213ed529f9
Author: William Bader <william.bader@gmail.com>
Date:   Mon Sep 7 00:19:45 2026 +0300

    Re-decode a JPEG 2000 stream after it has been closed

    close() frees the decoded image and sets npixels to 0, but left
    inited set, so
    init() never ran again and every later read returned EOF -- while
    rewind()
    still reported success.  Anything that closed a JPXStream and read
    it again got
    a silently empty stream.

    Clear inited in rewind() when the image is gone so the next read
    decodes again.
    Decoding is expensive and rewind() is called routinely, so the
    counters-only
    path is kept for the common case where the image is still there.

    Without this, pdftops -preload writes blank pages for
    WinterClientUpdate-poppler.pdf,
    2015SpringClientUpdate-poppler-jpeg-bug.pdf and
    Ghent_PDF-Output-Test-V50_ALL_X4.pdf: setupImage() closes the
    stream between
    its two encoding passes, so the second pass sees an empty stream
    and emits an
    array declared at its full size holding a single empty entry.
    Ghostscript
    renders the first of those as four byte-identical blank pages;
    with this fix
    the pages match what pdftoppm renders from the PDF.

    No measurable speed change.  pdfimages and pdftoppm output on those
    three files
    is unchanged (131 output files compared).

 poppler/JPEG2000Stream.cc | 9 +++++++++
 1 file changed, 9 insertions(+)

commit 94c499fea34991d09bf1d30e0dd50a55ebb8c8ee
Author: William Bader <william@newspapersystems.com>
Date:   Tue Sep 8 18:43:41 2026 +0300

    Fix shift overflow when a sampled function has 32-bit samples

    sampleBits is validated to be between 1 and 32, so 1 << sampleBits
    shifts
    an int by its full width:

      Function.cc:376: runtime error: shift exponent 32 is too large for
      32-bit type 'int'

    bitMask is only read in the branch that unpacks sample sizes other than
    8, 16 and 32, so the bad value was never used, but the shift itself is
    undefined.  Shift a 64-bit value instead.

    Found with -fsanitize=undefined.

 poppler/Function.cc | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

commit 00b35167540408fc5079fc594315cf9c89c4317f
Author: William Bader <william@newspapersystems.com>
Date:   Tue Sep 8 18:43:41 2026 +0300

    Fix signed integer overflow in Type 1C eexec encryption

    r1/r2 are unsigned short and the plaintext byte is unsigned char,
    so both
    promote to int and the multiplication overflows int for most inputs:

      FoFiType1C.cc:1622: signed integer overflow: 64690 * 52845 cannot be
      represented in type 'int'

    The result is immediately truncated back to unsigned short, so the
    intended arithmetic is modulo 65536.  Do the multiplication in
    unsigned,
    where the wraparound is defined, and make the truncation explicit.  The
    generated PostScript is unchanged.

    Found with -fsanitize=undefined.

 fofi/FoFiType1C.cc | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

commit f121ecc8dd4884ce99d417a403a731862096db98
Author: William Bader <william@newspapersystems.com>
Date:   Tue Sep 8 18:43:41 2026 +0300

    Fix out-of-bounds read compositing a knockout group

    The knockout result alpha

      aResult = aSrc + div255(aDest * (255 - pipe->shape))

    can reach 510, but aResult is an unsigned char, so it wraps.
    This happens
    when the pipe does not use the shape: aSrc is then pipe->aInput at full
    strength while the backdrop term still scales by pipe->shape, which
    drawAALine() sets from the antialiasing coverage.  aResult wrapping
    makes
    alphaI smaller than aSrc, so

      ((alphaI - aSrc) * cDest[i] + aSrc * cSrc[i]) / alphaI

    is no longer a weighted average of two values in [0,255] and
    leaves that
    range in both directions.  It indexes the 256-entry transfer arrays in
    SplashState, and because a wrapped alphaI can be close to zero
    the index
    can become very large, reading well outside the object:

      Splash.cc:666: runtime error: index 311 out of bounds for type
      'unsigned char [256]'
      Splash.cc:667: runtime error: index 278 out of bounds for type
      'unsigned char [256]'
      Splash.cc:668: runtime error: index -74 out of bounds for type
      'unsigned char [256]'
      ERROR: AddressSanitizer: heap-buffer-overflow, READ of size 1

    Clamp aResult, which is what the other alpha expressions here
    already do
    via clip255().  An alpha of 1 is the correct saturation, and
    clamping also
    restores alphaI >= aSrc, so the color index is in range again.

    The other two result alpha expressions were checked over all inputs and
    cannot exceed 255, so only the two knockout ones need this.

    Found with -fsanitize=address,undefined.  Of 87 test files, 86 render
    identically; the one that triggers this previously aborted under ASan
    instead of rendering.

 splash/Splash.cc | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

commit c8dc23d564f233875386b7aa1d59fc909ea58799
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Fri Sep 25 15:56:41 2026 +0200

    test: Fix build with some standard-libraries

 test/font-subsetting/fontsubsetting-basic-test.cc | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

commit 0c9cf7ce6ece57046cf8d77a0153bff661791616
Author: Albert Astals Cid <aacid@kde.org>
Date:   Fri Sep 25 08:31:59 2026 +0200

    CI: Use Fedora 45

 .gitlab-ci.yml | 14 ++++++--------
 1 file changed, 6 insertions(+), 8 deletions(-)

commit f2ef272f822f44e1fbb7fec1808aeba9edd9cb95
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Thu Sep 24 14:39:53 2026 +0000

    eidas (cades-b) support and infrastructure for more

 glib/poppler-document.cc                       | 15 +++++----
 poppler/CertificateInfo.cc                     | 10 ++++++
 poppler/CertificateInfo.h                      | 15 +++++++++
 poppler/CryptoSignBackend.h                    | 14 +++++++-
 poppler/Form.cc                                | 24 ++++++++------
 poppler/Form.h                                 |  4 +--
 poppler/GPGMECryptoSignBackend.cc              | 42
 +++++++++++++++++++-----
 poppler/GPGMECryptoSignBackend.h               |  6 ++--
 poppler/NSSCryptoSignBackend.cc                | 45
 ++++++++++++++++++++++++--
 poppler/NSSCryptoSignBackend.h                 |  8 +++--
 poppler/PDFDoc.cc                              |  4 +--
 poppler/PDFDoc.h                               |  2 +-
 qt5/src/poppler-form.cc                        | 12 +++++--
 qt5/src/poppler-form.h                         |  2 +-
 qt5/src/poppler-pdf-converter.cc               | 14 +++++---
 qt5/src/poppler-qt5.h                          |  1 +
 qt6/src/poppler-annotation.cc                  |  2 ++
 qt6/src/poppler-annotation.h                   |  1 +
 qt6/src/poppler-converter.h                    | 27 ++++++++++++++++
 qt6/src/poppler-form.cc                        | 28 ++++++++++++++--
 qt6/src/poppler-form.h                         | 12 +++++++
 qt6/src/poppler-pdf-converter.cc               | 27 +++++++++++++---
 qt6/src/poppler-private.h                      | 42
 ++++++++++++++++++++++++
 qt6/tests/check_create_pgp_signature1.cpp      | 41
 ++++++++++++++++++++---
 qt6/tests/check_signature_cross_validation.cpp | 40
 ++++++++++++++++++++++-
 test/pdf-signing-nss.cc                        |  6 +++-
 utils/pdfsig.1                                 |  4 +--
 utils/pdfsig.cc                                | 42
 ++++++++++++++----------
 28 files changed, 412 insertions(+), 78 deletions(-)

commit d363ae7996be20f576c28d42ad1b85d945e102dd
Author: Andreas Sturmlechner <asturm@gentoo.org>
Date:   Wed Dec 9 01:28:25 2020 +0100

    Conditionalise test builds/deps more effectively

    * Avoid needing to explicitly disable tests when the respective
    toolkit is
    disabled by gating subdirs for qt5/qt6.

    * Conditionalise some test dep searches on the relevant build
    option, not
      the underlying toolkit.

    * Make the test options default to whether the respective toolkit
    is on.

    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 CMakeLists.txt           | 16 ++++++++--------
 qt5/CMakeLists.txt       |  7 +++++--
 qt5/tests/CMakeLists.txt | 16 +++++++---------
 qt6/CMakeLists.txt       |  6 ++++--
 qt6/tests/CMakeLists.txt |  4 +---
 5 files changed, 25 insertions(+), 24 deletions(-)

commit e27aebe5396d402fee37e11444006dec88000a07
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Fri Aug 7 14:36:45 2026 +0200

    Fix rendition media api internally

    We were doing some optionally with pointers, but returned address of
    stack variables and checking for null; that would always fail. Do
    things
    with std::optional instead

 glib/poppler-media.cc    |  2 +-
 poppler/Rendition.cc     | 16 ++++++++++++----
 poppler/Rendition.h      |  8 ++++----
 qt5/src/poppler-media.cc |  2 +-
 qt6/src/poppler-media.cc |  2 +-
 5 files changed, 19 insertions(+), 11 deletions(-)

commit eba77c0ad7981811e1aec42611ba3a30d94f217e
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Mon Sep 21 15:05:47 2026 +0000

    Let NSS reuse request-password callback for pin

    If password callback exist, use it rather than just fail if provided
    password is bad.

    This also can help doing fewer signatures in certain cases, especially
    the case where a hardware token needs to be touched on each operation;
    here we should get fewer interactions.

 poppler/NSSCryptoSignBackend.cc | 16 ++++++++++++----
 poppler/NSSCryptoSignBackend.h  |  1 +
 qt5/src/poppler-form.cc         |  4 ++++
 qt6/src/poppler-form.cc         |  4 ++++
 qt6/src/poppler-form.h          |  2 ++
 5 files changed, 23 insertions(+), 4 deletions(-)

commit a7fa63e85835e2580be83b5f28331ddca4bad463
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 17 01:25:39 2026 +0200

    Let SEC_ERROR_UNTRUSTED_ISSUER win even if it's not the first error

    Because this is something the user can potentially fix

 poppler/NSSCryptoSignBackend.cc | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

commit 782409eded77c9467f3c76ff31bd5209d96e00bd
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Sep 21 16:26:25 2026 +0200

    NSS: Fix previous commit array size

    Apologies

 poppler/NSSCryptoSignBackend.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit 2341db9315769fdf05248e8eff6c8a0867f70bb5
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 17 01:18:41 2026 +0200

    NSS: Be a bit more lenient on what we consider valid cert usage

 poppler/NSSCryptoSignBackend.cc | 24 ++++++++++++++++++++++--
 1 file changed, 22 insertions(+), 2 deletions(-)

commit 6a9064bc4c081241e579da48e72b4e4954446d88
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Mon Sep 21 12:45:05 2026 +0000

    Qt: Map the annotation rules flags a bit closer to the spec

 qt5/src/poppler-annotation.cc | 14 +++++++++++++-
 qt6/src/poppler-annotation.cc | 11 +++++++++++
 2 files changed, 24 insertions(+), 1 deletion(-)

commit 4ea82ed4e341e54451b7fc5456a34243ea8e6b35
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Thu Jul 9 15:02:34 2026 +0200

    Qt Signatures: Deprecate publicKey function

    This is the raw public key or 'the prime(s)' or curve parameters. We
    don't have them in all cases, and there is no reason to present it to
    user anyways.

 qt5/src/poppler-form.h | 9 +++++++--
 qt6/src/poppler-form.h | 9 +++++++--
 2 files changed, 14 insertions(+), 4 deletions(-)

commit aafae2f0bd146810c636e7a4399bee4f6e347354
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 17 22:58:26 2026 +0200

    Remove unused ArgKind enum values

 utils/parseargs.cc | 8 ++------
 utils/parseargs.h  | 8 +-------
 2 files changed, 3 insertions(+), 13 deletions(-)

commit 2ec4523b1675a2723ca634eed2adf71197580062
Author: Albert Astals Cid <aacid@kde.org>
Date:   Tue Sep 15 22:51:52 2026 +0200

    XRef::getEntry: Fix limit check

    Fixes un-initialized memory read on broken files

 poppler/XRef.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit 4fc1c20f120ae93136381d7de0a68c3efe90f356
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sun Sep 13 23:21:36 2026 +0200

    ossfuzz: Build brotli

 test/ossfuzz/build_fuzzers.sh | 5 +++++
 test/ossfuzz/prepare_build.sh | 1 +
 2 files changed, 6 insertions(+)

commit 90a79db1394c8db4ce7d6223298b104551ba6089
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sun Sep 13 21:10:31 2026 +0200

    CI: Increase minimum clang macos simulation

    We don't support macos 10.4 anymore

 .gitlab-ci.yml | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

commit dca5f098698e57544b88547a702af7b9071ac02c
Author: Albert Astals Cid <aacid@kde.org>
Date:   Sun Sep 13 16:24:49 2026 +0200

    Fix crash on malformed documents

 poppler/FontSubsetter.cc | 12 ++++++++++++
 1 file changed, 12 insertions(+)

commit 11448b90a804a860a0fec93f68d3f41d983c637c
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Sun Sep 13 14:27:59 2026 +0000

    Enable brotli streams

 .gitlab-ci.yml                       |  13 ++--
 CMakeLists.txt                       |  13 ++++
 cmake/modules/Findlibbrotlidec.cmake |  17 ++++++
 config.h.cmake                       |   3 +
 poppler/BrotliStream.cc              | 115
 +++++++++++++++++++++++++++++++++++
 poppler/BrotliStream.h               |  34 +++++++++++
 poppler/Stream.cc                    |  12 ++++
 poppler/Stream.h                     |   1 +
 8 files changed, 202 insertions(+), 6 deletions(-)

commit 978549e8a1af4ed24ec4a215bfa14ca6090ea990
Author: Albert Astals Cid <aacid@kde.org>
Date:   Fri Sep 4 09:16:44 2026 +0200

    Fix rendering of some Forms

    If we are modifying the Fonts and it's a ref (as opossed to just be a
    inside the dict itself), we need to tell xref that
    we changed the object, otherwise whoever fetches the object again will
    not magically get the new data

 poppler/Annot.cc | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

commit 3e090f4e508b255f7ab478e887e14aa8de51014a
Author: ju1ius <jules.bernable@gmail.com>
Date:   Tue Sep 8 13:07:00 2026 +0200

    catalog: fix dest dict to name tree fallback when resolving named
    destination.

    Closes #1788

 poppler/Catalog.cc | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

commit be09305851e326ce189ee516788fd4a9e7d382c6
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Fri Sep 11 15:21:40 2026 +0200

    NSS: export internal error code in weird error msg

    the PORT_GetError call can give us a hint on what goes wrong

    (These are still in the area of error messages that hopefully
    dont reach
    the user, but if they do, they would need our help to figure
    things out)

 poppler/Error.h                 | 6 ++++++
 poppler/NSSCryptoSignBackend.cc | 5 +++--
 2 files changed, 9 insertions(+), 2 deletions(-)

commit 35626a614d3c1b8046177d0ccd6d50b34a5e2640
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Wed Sep 9 16:20:49 2026 +0200

    Write some error message if signing fails

 utils/pdfsig.cc | 31 +++++++++++++++++++++++++++++--
 1 file changed, 29 insertions(+), 2 deletions(-)

commit 88d9d46874e74ed986fcb312871ac6b4a8dd309f
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Thu Sep 10 09:22:03 2026 +0200

    Build system: dont scan for c++ modules

    We don't currently use or provide them, so no need to do the work to
    support it.

 CMakeLists.txt | 3 +++
 1 file changed, 3 insertions(+)

commit 557c83abb9a118c4de2e7ad872aef9e66dbc952b
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Wed Sep 9 16:11:23 2026 +0200

    Fix a format string

 poppler/GPGMECryptoSignBackend.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit eead04e06bbf9168bd995cd55a3b2509aec052fc
Author: ojasmaheshwari <ojasmaheshwari@gmail.com>
Date:   Sun Sep 6 20:43:18 2026 +0530

    Build and enable harfbuzz

 test/ossfuzz/build_fuzzers.sh | 24 ++++++++++++++++++++----
 test/ossfuzz/prepare_build.sh |  1 +
 2 files changed, 21 insertions(+), 4 deletions(-)

commit 4b6c157de6a69f0037a85c9509898aea94f5f29b
Author: William Bader <william@newspapersystems.com>
Date:   Sun Sep 6 02:20:24 2026 +0300

    Change .gitignore from /build/ to /build*/ to allow multiple builds.

 .gitignore | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit 0e61e7e6a32401590e142109616fd84fd7095c00
Author: Albert Astals Cid <aacid@kde.org>
Date:   Tue Sep 8 01:27:16 2026 +0200

    Improve code a bit when finding fonts fails

    Be verbose that finding failed and do not try to add anything if
    it does
    not have a file

 poppler/Form.cc         | 2 +-
 poppler/GlobalParams.cc | 1 +
 2 files changed, 2 insertions(+), 1 deletion(-)

commit 878669585dd3df68d958c77d5ad82ed832e0f296
Author: Sune Vuorela <sune@vuorela.dk>
Date:   Mon Sep 7 15:06:38 2026 +0200

    NSS Signatures: Mark hardware keys as such

 poppler/NSSCryptoSignBackend.cc | 3 +++
 1 file changed, 3 insertions(+)

commit f1f861a969af7fd87f17d050853fb09a45753072
Author: Funda Wang <fundawang@yeah.net>
Date:   Wed Sep 2 13:20:41 2026 +0800

    Fix intermittent glib API docs build failure

    ninja could run make-glib-api-docs in parallel with g-ir-scanner, both
    sharing the glib build dir (g-ir-scanner writes tmp-introspect* temp
    files there while gtkdoc-scan scans that dir). Depend the docs stamp
    on the gir-typelibs target when introspection is enabled to serialize
    them.

    Co-Authored-By: AtomCode (deepseek-v4-flash) <noreply@atomgit.com>

 glib/reference/CMakeLists.txt | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

commit 1ce3f34b44875b59b081dda639c242317a32b614
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 3 22:50:39 2026 +0200

    Increase version so people that track master can add ifdefs on version

 CMakeLists.txt   | 2 +-
 cpp/Doxyfile     | 2 +-
 qt5/src/Doxyfile | 2 +-
 qt6/src/Doxyfile | 2 +-
 4 files changed, 4 insertions(+), 4 deletions(-)

commit e661b7b61a1b1feeb3193e5eced6274cc03e0ffa
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 3 22:26:13 2026 +0200

    poppler 26.09.0

 CMakeLists.txt   |  6 +++---
 NEWS             | 18 ++++++++++++++++++
 cpp/Doxyfile     |  2 +-
 qt5/src/Doxyfile |  2 +-
 qt6/src/Doxyfile |  2 +-
 5 files changed, 24 insertions(+), 6 deletions(-)

commit cbf801f06fbd8b243b3011dcb0d2a78baa3b3ce0
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 3 22:42:32 2026 +0200

    Revert "Fix intermittent glib API docs build failure"

    This reverts commit ad34cc58a1a3542d10bb98b7212ac8c0314bfba9.

 glib/reference/CMakeLists.txt | 11 +----------
 1 file changed, 1 insertion(+), 10 deletions(-)

commit c1948b1d66b214c47820aedca7c0c9c53719fd91
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 3 22:08:14 2026 +0200

    Update (C)

 cpp/tests/poppler-dump.cpp                        | 2 +-
 poppler/CryptoSignBackend.cc                      | 3 ++-
 poppler/CryptoSignBackend.h                       | 2 ++
 poppler/DistinguishedNameParser.h                 | 2 +-
 poppler/Form.h                                    | 1 +
 test/font-subsetting/fontsubsetting-basic-test.cc | 1 +
 6 files changed, 8 insertions(+), 3 deletions(-)

commit 737000618edfcbc0185645d1d3169de4b3c95e57
Author: Albert Astals Cid <aacid@kde.org>
Date:   Thu Sep 3 12:40:53 2026 +0200

    Make redundant-qualified-alias from clang-tidy 23 happy

 cpp/poppler-global.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

commit ad34cc58a1a3542d10bb98b7212ac8c0314bfba9
Author: Funda Wang <fundawang@yeah.net>
Date:   Thu Sep 3 09:57:17 2026 +0000

    Fix intermittent glib API docs build failure

    Fixes #1781

 glib/reference/CMakeLists.txt | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

commit 2191210e58043db0bd8d39887aadf2279ee6ba7f
Author: Ojas Maheshwari <workonlyojas@gmail.com>
Date:   Wed Sep 2 22:38:14 2026 +0000

    Font subsetting for form fields

 poppler/Annot.cc                                  | 230
 ++++++++++++++++++----
 poppler/Annot.h                                   |  17 +-
 poppler/FontSubsetter.cc                          | 117 ++++++-----
 poppler/FontSubsetter.h                           |   4 +
 poppler/Form.h                                    |   2 +-
 test/CMakeLists.txt                               |  16 +-
 test/font-subsetting/fontsubsetting-basic-test.cc | 100 ++++++++--
 7 files changed, 378 insertions(+), 108 deletions(-)

commit 0cc3f68f435728661a7e14a9e7b0abd79f416c98
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 23:53:47 2026 +0200

    Add std::move as suggested by clang-tidy 23

 fofi/FoFiType1.cc                 | 2 +-
 poppler/DistinguishedNameParser.h | 4 ++--
 poppler/GfxState.cc               | 2 +-
 qt5/src/poppler-page.cc           | 4 ++--
 qt6/src/poppler-page.cc           | 2 +-
 splash/SplashState.cc             | 2 +-
 6 files changed, 8 insertions(+), 8 deletions(-)

commit 8bf4c5b81c686c4db78f8e1dac7748b822300c64
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 23:29:49 2026 +0200

    Use more string_view as suggested by clang-tidy 23

 cpp/tests/poppler-dump.cpp   | 4 ++--
 poppler/CryptoSignBackend.cc | 2 +-
 poppler/CryptoSignBackend.h  | 2 +-
 3 files changed, 4 insertions(+), 4 deletions(-)

commit 5e086eea01afe6fcad084843d6930523cbdee97c
Author: Albert Astals Cid <aacid@kde.org>
Date:   Tue Sep 1 01:14:10 2026 +0200

    Update (C)

 poppler/Annot.cc                                  |  1 +
 poppler/Annot.h                                   |  1 +
 poppler/AnnotStampImageHelper.h                   |  2 +-
 poppler/FontInfo.h                                |  2 +-
 poppler/FontSubsetter.cc                          | 11 +++++++++++
 poppler/FontSubsetter.h                           | 11 +++++++++++
 poppler/PDFDoc.cc                                 |  1 +
 test/font-subsetting/fontsubsetting-basic-test.cc |  9 +++++++++
 8 files changed, 36 insertions(+), 2 deletions(-)

commit b075a749b79d272214b4b3fab98cdda88224fb75
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 23:57:39 2026 +0200

    Make clang-tidy 23 performance-prefer-single-char-overloads happy

 glib/poppler-annot.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

commit 08f3940b6a67f00ec849257f7dd7b318ee1b9852
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 15:27:52 2026 +0200

    FontSubsetter: get widths from oldFont instead of freetype

 poppler/FontSubsetter.cc | 50
 ++++++++++++++----------------------------------
 poppler/FontSubsetter.h  |  2 +-
 poppler/GfxFont.h        | 10 ++++++++--
 3 files changed, 23 insertions(+), 39 deletions(-)

commit 5456d02652afd3c4c39611ba08b4c8e32cecc6d3
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 23:11:40 2026 +0200

    Add missing include

 poppler/AnnotStampImageHelper.h | 2 ++
 1 file changed, 2 insertions(+)

commit 012139aaad907892f14ae44465a477c53704f29b
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 23:05:41 2026 +0200

    Only include the needed includes

 poppler/AnnotStampImageHelper.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

commit c384465881a1a732e5dd31cfea8189592d8d3f98
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 22:51:05 2026 +0200

    test: Remove unused variables

 test/perf-test.cc | 18 +++++-------------
 1 file changed, 5 insertions(+), 13 deletions(-)

commit dec3ad15d15bfac2e527a0ef5219476793ea94c2
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 22:44:21 2026 +0200

    Add missing include

 poppler/FontInfo.h | 1 +
 1 file changed, 1 insertion(+)

commit 52fd9e36fb07da29e03a2cefc1a29662cbffc0de
Author: Albert Astals Cid <aacid@kde.org>
Date:   Mon Aug 31 15:17:08 2026 +0200

