[buffer] Set content_type only for the format actually being parsed (#6092)

hb_buffer_deserialize_unicode() and hb_buffer_deserialize_glyphs() each
mutated the buffer's content_type unconditionally before checking
whether the caller-supplied format was recognized, then returned false
without rolling that back for an invalid format. A buffer left with
content_type set but len == 0 fails the assert_glyphs() /
assert_unicode() invariant on a later, independent call that expects
a clean buffer, aborting the process:

  - deserialize_unicode(INVALID) -> deserialize_glyphs() aborts in
    assert_glyphs().
  - deserialize_glyphs(INVALID) -> add_codepoints() aborts in
    assert_unicode().

Move each hb_buffer_set_content_type() call into the TEXT/JSON case
bodies of the existing format switch, instead of guarding it with a
separate validity check ahead of the switch. The switch's own case
list is already the single source of truth for which formats are
supported, so this avoids duplicating that knowledge in a second
condition that could drift out of sync with the switch.

Testing:
  - Built with -Db_sanitize=address,undefined.
  - Reproduced both original aborts against the unfixed code
    (SIGABRT via assert_glyphs()/assert_unicode()).
  - Rebuilt with the fix and reran both reproducers: clean exit, no
    assertion failure.
  - Ran the full test suite (meson test, sanitizer build, FreeType +
    ICU enabled) before and after: 71/75 pass in both, with the same
    4 pre-existing failures unrelated to buffer serialization
    (check-libstdc++, and the experimental vector/raster/gpu-fuzzer
    chunk 2 targets) - confirmed to fail identically on the
    unmodified baseline, so no regressions from this change.

Assisted-by: Claude Sonnet 5 <noreply@anthropic.com>
1 file changed
tree: 854e51c5d08ebe698498e6591271498a64a55e34
  1. .ci/
  2. .github/
  3. docs/
  4. perf/
  5. src/
  6. subprojects/
  7. test/
  8. util/
  9. .clang-format
  10. .codecov.yml
  11. .editorconfig
  12. AGENTS.md
  13. AUTHORS
  14. BUILD.md
  15. CMakeLists.txt
  16. CODE_OF_AI_CONDUCT.md
  17. CONFIG.md
  18. COPYING
  19. harfbuzz.doap
  20. HarfBuzz.png
  21. meson.build
  22. meson_options.txt
  23. NEWS
  24. README.md
  25. README.mingw.md
  26. README.python.md
  27. RELEASING.md
  28. replace-enum-strings.cmake
  29. SECURITY.md
  30. TESTING.md
  31. THANKS
  32. xkcd.png
README.md

HarfBuzz

Linux CI Status macoOS CI Status Windows CI Status OSS-Fuzz Status Coverity Scan Build Status Packaging status OpenSSF Scorecard

HarfBuzz started as a text shaping engine but has grown into a full font platform — the ffmpeg of text shaping. It primarily supports OpenType, but also Apple Advanced Typography.

HarfBuzz shapes the majority of text on modern screens.

HarfBuzz is optimized for robustness, correctness, and performance — in that order. Achieve all.

Try it live at harfbuzz-world.cc — an interactive playground for shaping, subsetting, rasterization, vector output, and GPU rendering, all running in your browser.

Here is a quick map of its components:

Core libraries

LibraryDescription
libharfbuzzText shaping, draw API, paint API. Highly configurable (see CONFIG.md). Optional integration backends compiled in: hb-ft (FreeType), hb-coretext (macOS), hb-uniscribe (Windows), hb-directwrite (Windows), hb-gdi (Windows), hb-glib, hb-graphite2.
libharfbuzz-subsetFont subsetting and variable-font instancing.

Auxiliary libraries

LibraryDescription
libharfbuzz-icuICU Unicode integration.
libharfbuzz-cairoCairo rendering integration.
libharfbuzz-gobjectGObject/GI bindings.

Experimental libraries

LibraryDescription
libharfbuzz-rasterGlyph rasterization to bitmaps, including color fonts. Uses hb-draw and hb-paint.
libharfbuzz-vectorGlyph output to vector formats (currently SVG), including color fonts. Uses hb-draw and hb-paint.
libharfbuzz-gpuEncodes glyph outlines for GPU rasterization (Slug algorithm). Provides shader sources in GLSL, WGSL, MSL, and HLSL. Live demo.

Notable missing feature: font hinting (including autohinting) is not implemented. For hinted rasterization, use FreeType or Skrifa.

For simplified builds, amalgamated sources are available: harfbuzz.cc (just libharfbuzz), harfbuzz-subset.cc (just libharfbuzz-subset), or harfbuzz-world.cc (everything, driven by a custom hb-features.h). For a live in-browser playground plus a worked example of the world.cc single-file build, see harfbuzz-world.cc.

Command-line tools

ToolDescription
hb-shapeShape text and display glyph output.
hb-viewRender shaped text to an image.
hb-subsetSubset and optimize fonts.
hb-infoDisplay font metadata.
hb-rasterRender glyphs to bitmap images.
hb-vectorRender glyphs to vector formats (SVG).
hb-gpuInteractive GPU text rendering.

The canonical source tree and bug trackers are available on github. Both development and user support discussion around HarfBuzz happen on github as well.

For license information, see COPYING.

API stability

The API that comes with hb.h will not change incompatibly. Other, peripheral, headers are more likely to go through minor modifications, but again, we do our best to never change API in an incompatible way. We will never break the ABI.

The API and ABI are stable even across major version number jumps. In fact, current HarfBuzz is API/ABI compatible all the way back to the 0.9.x series. If one day we need to break the API/ABI, that would be called a new library.

As such, we bump the major version number only when we add major new features, the minor version when there is new API, and the micro version when there are bug fixes.

Documentation

For user manual as well as API documentation, check: https://harfbuzz.github.io

Download

Tarball releases and Win32/Win64 binary bundles are available on the github releases page.

Development

For build information, see BUILD.md.

For custom configurations, see CONFIG.md.

For testing and profiling, see TESTING.md.

For using with Python, see README.python.md. There is also uharfbuzz.

For cross-compiling to Windows from Linux or macOS, see README.mingw.md.

To report bugs or submit patches please use github issues and pull-requests.

Developer documents

To get a better idea of where HarfBuzz stands in the text rendering stack you may want to read State of Text Rendering 2024. Here are a few presentation slides about HarfBuzz over the years:

More presentations and papers are available on behdad's website. In particular, the following studies are relevant to HarfBuzz development:

Name

HarfBuzz /hærfˈbɒːz/

From Persian حرف (Harf: letter) and باز (Buzz: open). Transliteration of the Persian calque for OpenType.

As a noun: The Open Source text shaping engine.

As an adjective: Insincerely talkative; glib. A nod to the GNOME project where HarfBuzz originates from.

The logo shows حرف‌باز in the IranNastaliq font, on a Damascus steel background.

Background: Originally there was this font format called TrueType. People and companies started calling their type engines all things ending in Type: FreeType, CoolType, ClearType, etc. And then came OpenType, which is the successor of TrueType. So, for my OpenType implementation, I decided to stick with the concept but use the Persian translation. Which is fitting given that Persian is written in the Arabic script, and OpenType is an extension of TrueType that adds support for complex script rendering, and HarfBuzz is an implementation of OpenType text shaping.

Users

HarfBuzz is used in Android, Chrome, ChromeOS, Firefox, Flutter, GNOME, GTK+, KDE, Qt, LibreOffice, OpenJDK, XeTeX, Adobe Photoshop, Illustrator, InDesign, Microsoft Edge, Amazon Kindle, PlayStation, Godot Engine, Unreal Engine, Figma, Canva, QuarkXPress, Scribus, smart TVs, car displays, and many other places.

Distribution

Packaging status