Skip to main content

docling_pdf/
pdfium_backend.rs

1//! pdfium-based text extraction and page rendering.
2//!
3//! Text is reconstructed the way docling's `docling-parse` does it, so the
4//! output spacing matches the groundtruth: the page's **character** stream is
5//! grouped into **words** (split at a horizontal gap wider than a fraction of
6//! the font height — font-relative, so letter-tracking in display titles does
7//! not split a word) and words into **lines** (by baseline). pdfium-render's
8//! safe API only exposes whole style runs / `GetBoundedText`, so the character
9//! loop is driven through the raw `PdfiumLibraryBindings` FFI on a second handle
10//! to the same bytes (no fork; stays publishable).
11
12#[cfg(feature = "ocr-prep")]
13use image::RgbImage;
14#[cfg(feature = "ml")]
15use pdfium_render::prelude::*;
16
17/// A run of text with its bounding box, in PDF points with a **top-left** origin
18/// (pdfium's native origin is bottom-left; we flip it to match docling's
19/// `BoundingBox(..., origin=TOPLEFT)`).
20#[derive(Debug, Clone)]
21pub struct TextCell {
22    pub text: String,
23    pub l: f32,
24    pub t: f32,
25    pub r: f32,
26    pub b: f32,
27}
28
29/// Pixels-per-point used to render page images. Layout is scale-invariant (it
30/// scales normalized boxes by the page point size), but OCR benefits from the
31/// extra resolution.
32pub const RENDER_SCALE: f32 = 2.0;
33
34/// One page's geometry, extracted text cells, and a rendered RGB image. The
35/// image is rendered at [`RENDER_SCALE`] pixels per PDF point; `image px =
36/// page point × scale`.
37#[derive(Clone)]
38pub struct PdfPage {
39    pub width: f32,
40    pub height: f32,
41    pub scale: f32,
42    pub cells: Vec<TextCell>,
43    /// Same text grouped for code regions: split only at pdfium space glyphs, so
44    /// monospace runs keep their source spacing instead of the prose heuristic's.
45    pub code_cells: Vec<TextCell>,
46    /// Per-word cells (one per word, not joined into lines) for TableFormer cell
47    /// matching.
48    pub word_cells: Vec<TextCell>,
49    /// The rendered page bitmap. Present whenever pixels are available at all
50    /// (`ocr-prep` ⊂ `ml`): the native pipeline renders it with pdfium, the
51    /// browser pipeline receives it from the host canvas. Picture regions are
52    /// cropped out of it.
53    #[cfg(feature = "ocr-prep")]
54    pub image: RgbImage,
55    /// The **scale-1.0** page image the layout model runs on (docling parity:
56    /// its layout stage calls `page.get_image(scale=1.0)` — pdfium at 1.5×,
57    /// PIL-BICUBIC down to point size — a *different* image from the 2×
58    /// OCR/crop bitmap above, and a different resampling regime than
59    /// stretching that bitmap). `None` on paths without a pdfium renderer
60    /// (browser, METS/TIFF), which fall back to stretching [`Self::image`].
61    #[cfg(feature = "ocr-prep")]
62    pub image_layout: Option<RgbImage>,
63    /// Hyperlink annotations on the page (rect in top-left page coords + target
64    /// URI), restricted to web/mail/tel schemes. Used only by strict Markdown.
65    pub links: Vec<LinkAnnot>,
66    /// The page's `/Rotate` value (0/90/180/270) when it was normalized away
67    /// before inference: a scanned page with `/Rotate` displays its raster
68    /// rotated, which turns OCR into garbage — so extraction un-rotates the
69    /// bitmaps (and swaps `width`/`height`) and records the display rotation
70    /// here. Assembly rotates the finished geometry *back* by this many
71    /// degrees clockwise, so emitted locations and the page size stay in
72    /// display space (matching docling and every PDF viewer). Always 0 for
73    /// text-layer pages (their cells live in display space already) and on
74    /// paths without a pdfium renderer.
75    pub rotation: u16,
76}
77
78impl PdfPage {
79    /// A page built from recognized cells alone — the browser pipeline's
80    /// shape (#157), where the bitmap lives on the JS side. Exists so callers
81    /// compile identically with and without the `ml` feature: under a
82    /// feature-unified workspace build the struct carries the `image` field,
83    /// which a plain literal in a non-`ml` consumer can't spell.
84    #[cfg(feature = "ocr-prep")]
85    pub fn from_cells(width: f32, height: f32, scale: f32, cells: Vec<TextCell>) -> Self {
86        Self {
87            width,
88            height,
89            scale,
90            cells,
91            code_cells: Vec::new(),
92            word_cells: Vec::new(),
93            #[cfg(feature = "ocr-prep")]
94            image: RgbImage::new(0, 0),
95            #[cfg(feature = "ocr-prep")]
96            image_layout: None,
97            links: Vec::new(),
98            rotation: 0,
99        }
100    }
101
102    /// Same as [`from_cells`](Self::from_cells) but carrying the rendered page
103    /// bitmap, so picture regions can be cropped out of it (#157: the browser
104    /// pipeline gets the same figure bytes the native one does).
105    #[cfg(feature = "ocr-prep")]
106    pub fn from_cells_with_image(
107        width: f32,
108        height: f32,
109        scale: f32,
110        cells: Vec<TextCell>,
111        image: RgbImage,
112    ) -> Self {
113        Self {
114            image,
115            ..Self::from_cells(width, height, scale, cells)
116        }
117    }
118
119    /// Un-rotate the page's bitmaps by `deg` (clockwise 90° steps) and record
120    /// the compensating display rotation, composing with any rotation already
121    /// recorded: the raster becomes upright for inference while assembly
122    /// still maps the finished geometry back into display space. Handles both
123    /// `/Rotate` normalization (extraction) and content-detected orientation
124    /// (#225) — the two compose additively (axis-aligned 90° rotations
125    /// commute through the dimension swaps). Link rectangles follow the
126    /// raster; `width`/`height` swap on odd quarter-turns.
127    #[cfg(feature = "ocr-prep")]
128    pub(crate) fn unrotate(&mut self, deg: u16) {
129        if deg == 0 {
130            return;
131        }
132        use image::imageops::{rotate180, rotate270, rotate90};
133        // Display = upright rotated `deg`° clockwise, so upright = display
134        // rotated the complementary amount clockwise.
135        let un = |img: &RgbImage| match deg {
136            90 => rotate270(img),
137            180 => rotate180(img),
138            _ => rotate90(img),
139        };
140        if self.image.width() > 1 {
141            self.image = un(&self.image);
142        }
143        self.image_layout = self.image_layout.as_ref().map(&un);
144        let (width, height) = (self.width, self.height);
145        // Link rects follow the raster from display into upright space (the
146        // inverse of the geometry rotation assembly applies at the end).
147        for l in &mut self.links {
148            let (nl, nt, nr, nb) = match deg {
149                90 => (l.t, width - l.r, l.b, width - l.l),
150                180 => (width - l.r, height - l.b, width - l.l, height - l.t),
151                _ => (height - l.b, l.l, height - l.t, l.r),
152            };
153            (l.l, l.t, l.r, l.b) = (nl, nt, nr, nb);
154        }
155        if deg != 180 {
156            (self.width, self.height) = (height, width);
157        }
158        self.rotation = (self.rotation + deg) % 360;
159    }
160}
161
162/// A PDF link annotation: its rectangle (top-left page coordinates, matching
163/// [`TextCell`]) and target URI.
164#[derive(Debug, Clone)]
165pub struct LinkAnnot {
166    pub l: f32,
167    pub t: f32,
168    pub r: f32,
169    pub b: f32,
170    pub uri: String,
171}
172
173#[cfg(feature = "ml")]
174/// A parsed PDF: per-page text cells and page images.
175pub struct PdfDocument {
176    pub pages: Vec<PdfPage>,
177}
178
179/// Whether to use the docling-parse line sanitizer ([`crate::dp_lines`]) for prose
180/// reconstruction — the default. Set `DOCLING_LEGACY_LINES` to fall back to the
181/// older gap-heuristic `lines_from_glyphs`.
182pub(crate) fn use_dp_lines() -> bool {
183    !docling_core::env::flag("DOCLING_LEGACY_LINES")
184}
185
186/// Whether to source **word** cells from the pure-Rust parser (roadmap item 6),
187/// the default. The parser's `word_cells` reproduce docling-parse's word grouping
188/// byte-for-byte — the per-word tokens TableFormer matches table-grid cells
189/// against — which moves table extraction closer to docling on the heavy
190/// multi-column fixtures. Set `DOCLING_PDFIUM_WORDS` to keep pdfium's word cells,
191/// or `DOCLING_PDFIUM_TEXT` to fall back to pdfium for all text.
192pub(crate) fn use_parser_words() -> bool {
193    !docling_core::env::flag("DOCLING_PDFIUM_WORDS")
194        && !docling_core::env::flag("DOCLING_PDFIUM_TEXT")
195}
196
197/// Whether to source **code** cells from the parser too (the default) — the last
198/// text layer to leave pdfium, fully retiring its text path. The parser's
199/// gap-based code grouping ([`code_cells_from_glyphs`]) reconstructs monospace
200/// spacing from positioning gaps (`function add(a, b) { … }`), so it no longer
201/// drops the inter-token spaces the old space-glyph-only grouping lost
202/// (`functionadd`). Reverts to pdfium with `DOCLING_PDFIUM_WORDS` (alongside word
203/// cells) or `DOCLING_PDFIUM_TEXT` (all text).
204pub(crate) fn use_parser_code() -> bool {
205    use_parser_words()
206}
207
208#[cfg(feature = "ml")]
209/// Try binding pdfium from a directory (or a literal library file path):
210/// `<dir>/<platform library name>` first, else `<dir>` itself as the file.
211fn try_bind_dir(path: &str) -> Option<Box<dyn pdfium_render::prelude::PdfiumLibraryBindings>> {
212    let name = Pdfium::pdfium_platform_library_name_at_path(path);
213    if let Ok(b) = Pdfium::bind_to_library(&name) {
214        return Some(b);
215    }
216    Pdfium::bind_to_library(path).ok()
217}
218
219#[cfg(feature = "ml")]
220/// Bind to the pdfium dynamic library. Honors `PDFIUM_DYNAMIC_LIB_PATH` (a
221/// directory or file) first; else falls back to `.pdfium/lib` relative to the
222/// current directory (the layout `scripts/install/download_dependencies.sh` and
223/// `scripts/install/pdf_setup.sh` both produce); else the system library.
224fn bind() -> Result<Pdfium, PdfiumError> {
225    if let Some(path) = docling_core::env::nonempty("PDFIUM_DYNAMIC_LIB_PATH") {
226        if let Some(b) = try_bind_dir(&path) {
227            return Ok(Pdfium::new(b));
228        }
229    }
230    // No env var (or it didn't resolve): fall back to `.pdfium/lib` relative to
231    // the current directory — mirroring `layout.rs`/`ocr.rs`'s `.models/…`
232    // defaults — the layout `scripts/install/download_dependencies.sh` (and
233    // `scripts/install/pdf_setup.sh`) produce, so a checkout with the dependencies
234    // downloaded next to it needs no env var at all.
235    if let Some(b) = try_bind_dir(&crate::resolve_asset(".pdfium/lib")) {
236        return Ok(Pdfium::new(b));
237    }
238    Pdfium::bind_to_system_library().map(Pdfium::new)
239}
240
241#[cfg(feature = "ml")]
242impl PdfDocument {
243    /// Parse a PDF from bytes, optionally decrypting with `password`.
244    ///
245    /// Note: this materialises **every** page's rendered bitmap in memory at
246    /// once. For large documents prefer [`for_each_page`], which streams.
247    pub fn open(bytes: &[u8], password: Option<&str>) -> Result<Self, PdfiumError> {
248        let pdfium = bind()?;
249        let ffi = FfiText::load(pdfium.bindings(), bytes, password);
250        let doc = pdfium.load_pdf_from_byte_slice(bytes, password)?;
251        let mut rust = rust_parser_cells(bytes);
252        let mut pages = Vec::new();
253        for (i, page) in doc.pages().iter().enumerate() {
254            let rc = rust.as_mut().map(|p| p.cells_timed(i));
255            pages.push(extract_page(&page, &ffi, i as i32, rc, true, true)?);
256        }
257        Ok(PdfDocument { pages })
258    }
259}
260
261#[cfg(feature = "ml")]
262/// Per-page prose line cells from the pure-Rust text parser. This is the
263/// **default** text layer (it matches docling-parse's char geometry and is a
264/// strict improvement on byte-conformance — e.g. it recovers the Arabic
265/// sentence-period attachment in `right_to_left_01`). Set `DOCLING_PDFIUM_TEXT`
266/// to fall back to pdfium's text layer. The parser returns an empty page when a
267/// PDF (or a page) has no parseable text layer; the caller keeps pdfium's cells
268/// in that case, so scanned/edge-case pages are unaffected.
269fn rust_parser_cells(bytes: &[u8]) -> Option<crate::textparse::PageTextParser> {
270    if docling_core::env::flag("DOCLING_PDFIUM_TEXT") {
271        return None;
272    }
273    // Only the document load happens here; pages are parsed as the walk
274    // reaches them (`cells_timed`), so nothing is decoded for pages outside
275    // a `--pages` window and the parse overlaps the workers' inference.
276    crate::timing::timed("textparse.open", || {
277        crate::textparse::PageTextParser::open(bytes)
278    })
279}
280
281impl crate::textparse::PageTextParser {
282    /// [`cells`](Self::cells) under the `textparse` timing stage (per page).
283    fn cells_timed(&mut self, index: usize) -> crate::textparse::PageParserCells {
284        crate::timing::timed("textparse", || self.cells(index))
285    }
286}
287
288#[cfg(feature = "ml")]
289/// Number of pages in a PDF, without rendering any of them — used to decide
290/// whether a document is worth spinning up the parallel worker pool.
291pub fn page_count(bytes: &[u8], password: Option<&str>) -> Result<usize, PdfiumError> {
292    crate::timing::timed("pdfium.page_count", || {
293        let pdfium = bind()?;
294        let doc = pdfium.load_pdf_from_byte_slice(bytes, password)?;
295        Ok(doc.pages().len() as usize)
296    })
297}
298
299#[cfg(feature = "ml")]
300/// Render + extract pages one at a time, handing each (owned) [`PdfPage`] to `f`.
301/// Only one page bitmap is resident at a time — a rendered page is ~5 MB, so a
302/// large PDF would otherwise hold gigabytes of bitmaps at once. `f` receives the
303/// zero-based page index and the total page count.
304///
305/// `render_image` controls whether the page bitmap is rasterized at all: layout,
306/// OCR, TableFormer, and picture cropping all need it, but a caller that skips
307/// every one of those (the `no_ocr` fast path) doesn't, and rasterizing +
308/// downsampling a page is by far the most expensive step per page — skipping it
309/// is most of `no_ocr`'s speedup. `PdfPage::image` is a 1×1 placeholder when
310/// `false`; do not read it.
311///
312/// `extract_text` decodes the page's text layer (parser or pdfium cells); pass
313/// `false` when full-page OCR is forced and the cells would be discarded
314/// unread (docling#4061).
315///
316/// `range` restricts the walk to a **0-based inclusive** page window (issue
317/// #80's `--pages`); out-of-window pages are skipped *before* text extraction
318/// and rasterization, so a 3-page window over a 500-page PDF costs three
319/// pages, not five hundred. `f` still receives the absolute page index, so
320/// downstream page numbering refers to the source document.
321///
322/// `E` is the caller's error type; pdfium errors convert into it via `From`.
323pub fn for_each_page<E, F>(
324    bytes: &[u8],
325    password: Option<&str>,
326    render_image: bool,
327    extract_text: bool,
328    range: Option<(usize, usize)>,
329    mut f: F,
330) -> Result<(), E>
331where
332    E: From<PdfiumError>,
333    F: FnMut(usize, usize, PdfPage) -> Result<(), E>,
334{
335    let pdfium = bind()?;
336    let (ffi, doc) = crate::timing::timed("pdfium.open", || {
337        let ffi = FfiText::load(pdfium.bindings(), bytes, password);
338        pdfium
339            .load_pdf_from_byte_slice(bytes, password)
340            .map(|doc| (ffi, doc))
341    })?;
342    // `extract_text = false` (full-page OCR forced, docling#4061 / 2.122):
343    // the text layer would be cleared unread, so neither the pure-Rust parser
344    // nor pdfium's text page is decoded at all — on vector-dense pages (CAD
345    // drawings as 100k+ path segments) that decode is most of the page cost.
346    let mut rust = if extract_text {
347        rust_parser_cells(bytes)
348    } else {
349        None
350    };
351    let pages = doc.pages();
352    let total = pages.len() as usize;
353    let (first, last) = range.unwrap_or((0, total.saturating_sub(1)));
354    // Index the window directly: iterating `pages.iter()` from page 0 and
355    // skipping to `first` loads (and closes) every page before the window —
356    // ~0.7 ms each, 1.3 s of pure overhead for a one-page window over the
357    // 1913-page .NET reference.
358    for i in first..=last {
359        if i >= total {
360            break;
361        }
362        let page = pages.get(i as pdfium_render::prelude::PdfPageIndex)?;
363        let rc = rust.as_mut().map(|p| p.cells_timed(i));
364        let extracted = extract_page(&page, &ffi, i as i32, rc, render_image, extract_text)?;
365        f(i, total, extracted)?;
366    }
367    // Tearing down the parsed document (hundreds of thousands of lopdf
368    // objects on a long PDF — 250 ms for the 1913-page .NET reference) is
369    // nobody's business but the allocator's: hand it to a detached thread so
370    // the last page's output isn't held up by it. `Arc`, not `Rc`, in the
371    // caches is what makes the parser `Send`.
372    if let Some(parser) = rust {
373        std::thread::spawn(move || crate::timing::timed("textparse.close", || drop(parser)));
374    }
375    Ok(())
376}
377
378/// One rasterized page from [`render_pages`] (#243): the absolute 1-based page
379/// number in the source document, the pixel dimensions, and the PNG bytes.
380#[cfg(feature = "ml")]
381#[derive(Debug, Clone)]
382pub struct RenderedPage {
383    pub page_no: usize,
384    pub width: u32,
385    pub height: u32,
386    pub png: Vec<u8>,
387}
388
389#[cfg(feature = "ml")]
390/// Rasterize a PDF's pages to PNG (#243) — the lean path behind serve's
391/// `to=images`: pdfium render only, no text extraction, no models, and only
392/// one page bitmap resident at a time (each is PNG-encoded and dropped before
393/// the next renders). `scale` is pixels per PDF point — 2.0 matches the
394/// pipeline's [`RENDER_SCALE`] (144 dpi). Unlike the pipeline's render there
395/// is no 1.5× supersample + downsample pass: that dance exists only because
396/// TableFormer is pixel-pinned to docling's bitmaps, and nothing downstream
397/// of this output is — a single render is nearly twice as fast.
398///
399/// `range` is a **1-based** inclusive page window (issue #80's `pages`
400/// semantics: the end clamps to the document, a start past the end errors).
401///
402/// pdfium is not thread-safe — callers must serialize this against any other
403/// pdfium use (docling-serve holds its pipeline mutex around this call for
404/// exactly that reason).
405pub fn render_pages(
406    bytes: &[u8],
407    password: Option<&str>,
408    range: Option<(usize, usize)>,
409    scale: f32,
410) -> Result<Vec<RenderedPage>, crate::PdfError> {
411    let pdfium = bind()?;
412    let doc = pdfium.load_pdf_from_byte_slice(bytes, password)?;
413    let pages = doc.pages();
414    let total = pages.len() as usize;
415    let (first, last) = match range {
416        None => (0, total.saturating_sub(1)),
417        Some((first, last)) => {
418            if first == 0 || last < first {
419                return Err(crate::PdfError::Pdfium(format!(
420                    "invalid page range {first}-{last} (pages are 1-based, first <= last)"
421                )));
422            }
423            if first > total {
424                return Err(crate::PdfError::Pdfium(format!(
425                    "page range {first}-{last} is outside the document ({total} page(s))"
426                )));
427            }
428            (first - 1, last.min(total) - 1)
429        }
430    };
431    let mut out = Vec::with_capacity(last.saturating_sub(first) + 1);
432    for i in first..=last {
433        if i >= total {
434            break;
435        }
436        let page = pages.get(i as pdfium_render::prelude::PdfPageIndex)?;
437        // pdfium applies /Rotate itself, so the bitmap is the page as a viewer
438        // shows it — no orientation handling needed (the pipeline's scanned-page
439        // un-rotation is an OCR-conformance concern, not a display one).
440        let tw = (page.width().value * scale).round().max(1.0) as i32;
441        let th = (page.height().value * scale).round().max(1.0) as i32;
442        let cfg = PdfRenderConfig::new()
443            .set_target_width(tw)
444            .set_target_height(th);
445        let bitmap = crate::timing::timed("pdfium.rasterize", || {
446            page.render_with_config(&cfg)
447                .map(|b| b.as_image().into_rgb8())
448        })?;
449        let mut png = Vec::new();
450        bitmap
451            .write_to(&mut std::io::Cursor::new(&mut png), image::ImageFormat::Png)
452            .map_err(|e| crate::PdfError::Pdfium(format!("PNG-encoding page {}: {e}", i + 1)))?;
453        out.push(RenderedPage {
454            page_no: i + 1,
455            width: bitmap.width(),
456            height: bitmap.height(),
457            png,
458        });
459    }
460    Ok(out)
461}
462
463#[cfg(feature = "ml")]
464fn extract_page(
465    page: &pdfium_render::prelude::PdfPage<'_>,
466    ffi: &FfiText<'_>,
467    index: i32,
468    rust_cells: Option<crate::textparse::PageParserCells>,
469    render_image: bool,
470    extract_text: bool,
471) -> Result<PdfPage, PdfiumError> {
472    // pdfium reports the page size (and renders) in the *display* frame —
473    // `/Rotate` applied — while every text coordinate (its own text page, the
474    // pure-Rust parser's MediaBox-based glyphs, link annotation rects) lives
475    // in the unrotated frame (docling#4008, 2.121). Keep the unrotated box
476    // around for the y-flips and bring every rect into the display frame.
477    let width = page.width().value;
478    let height = page.height().value;
479    let rotation = match page.rotation() {
480        Ok(PdfPageRenderRotation::Degrees90) => 90u16,
481        Ok(PdfPageRenderRotation::Degrees180) => 180,
482        Ok(PdfPageRenderRotation::Degrees270) => 270,
483        _ => 0,
484    };
485    let (unrot_w, unrot_h) = if rotation == 90 || rotation == 270 {
486        (height, width)
487    } else {
488        (width, height)
489    };
490
491    // Default: use the pure-Rust text parser instead of pdfium's text layer
492    // (override with `DOCLING_PDFIUM_TEXT`). Prose line cells always come from the
493    // parser; word and code cells do too unless `DOCLING_PDFIUM_WORDS` keeps them
494    // on pdfium (the parser's word grouping reproduces docling-parse's, which
495    // TableFormer matches against — roadmap item 6). A page the parser couldn't
496    // read (no text layer) keeps pdfium's cells.
497    let rc = rust_cells.unwrap_or_default();
498    let need_pdfium_prose = extract_text && rc.prose.is_empty();
499    let need_pdfium_words = extract_text && (!use_parser_words() || rc.words.is_empty());
500    let need_pdfium_code = extract_text && (!use_parser_code() || rc.code.is_empty());
501
502    // The parser covers prose/words/code from one shared glyph pass, so on the
503    // common (parser-succeeded) page all three are already satisfied and this
504    // pdfium FFI call — otherwise fully discarded below — is skipped outright.
505    let (mut cells, mut code_cells, mut word_cells) =
506        if need_pdfium_prose || need_pdfium_words || need_pdfium_code {
507            let (mut cells, code_cells, word_cells) =
508                crate::timing::timed("ffi.page_cells", || ffi.page_cells(index, unrot_h));
509            if cells.is_empty() {
510                cells = segment_cells(&page.text()?, unrot_h);
511            }
512            (cells, code_cells, word_cells)
513        } else {
514            (Vec::new(), Vec::new(), Vec::new())
515        };
516    if !rc.prose.is_empty() {
517        cells = rc.prose;
518    }
519    if use_parser_words() && !rc.words.is_empty() {
520        word_cells = rc.words;
521    }
522    if use_parser_code() && !rc.code.is_empty() {
523        code_cells = rc.code;
524    }
525    if rotation != 0 {
526        for c in cells
527            .iter_mut()
528            .chain(word_cells.iter_mut())
529            .chain(code_cells.iter_mut())
530        {
531            let (l, t, r, b) = to_display_frame((c.l, c.t, c.r, c.b), rotation, unrot_w, unrot_h);
532            (c.l, c.t, c.r, c.b) = (l, t, r, b);
533        }
534    }
535
536    let image = if render_image {
537        // docling renders at 1.5× the target scale and downsamples "to make it
538        // sharper" (pypdfium2 → PIL BICUBIC). Replicate exactly: the TableFormer
539        // model is pixel-sensitive, so the page bitmap must match byte-for-byte.
540        // `CatmullRom` is the same a=-0.5 cubic kernel as PIL's BICUBIC.
541        const SUPERSAMPLE: f32 = 1.5;
542        let tw = (width * RENDER_SCALE * SUPERSAMPLE).round().max(1.0) as i32;
543        let th = (height * RENDER_SCALE * SUPERSAMPLE).round().max(1.0) as i32;
544        let cfg = PdfRenderConfig::new()
545            .set_target_width(tw)
546            .set_target_height(th);
547        let big = crate::timing::timed("pdfium.render", || {
548            page.render_with_config(&cfg)
549                .map(|b| b.as_image().into_rgb8())
550        })?;
551        let dw = (width * RENDER_SCALE).round().max(1.0) as u32;
552        let dh = (height * RENDER_SCALE).round().max(1.0) as u32;
553        crate::timing::timed("image.resize", || fast_downscale(&big, dw, dh))
554    } else {
555        RgbImage::new(1, 1)
556    };
557    // The layout model's input image, built exactly like docling's
558    // `get_page_image(scale=1.0)`: a pdfium render at 1.5× (pypdfium2 sizes
559    // with `ceil`), PIL-BICUBIC down to the point-size image (PIL `resize`'s
560    // default kernel; Python `round` = ties-to-even). Distinct from the 2×
561    // bitmap above — resampling 1224→640 and 612→640 are different regimes,
562    // and the heron model's borderline scores follow the pixels.
563    let image_layout = if render_image {
564        let tw = f64::from(width * 1.5).ceil().max(1.0) as i32;
565        let th = f64::from(height * 1.5).ceil().max(1.0) as i32;
566        let cfg = PdfRenderConfig::new()
567            .set_target_width(tw)
568            .set_target_height(th);
569        let big = crate::timing::timed("pdfium.render_layout", || {
570            page.render_with_config(&cfg)
571                .map(|b| b.as_image().into_rgb8())
572        })?;
573        let dw = f64::from(width).round_ties_even().max(1.0) as u32;
574        let dh = f64::from(height).round_ties_even().max(1.0) as u32;
575        Some(crate::timing::timed("image.resize_layout", || {
576            crate::resample::pil_resize(&big, dw, dh, crate::resample::PilFilter::Bicubic)
577        }))
578    } else {
579        None
580    };
581
582    let mut links = extract_links(page, unrot_h);
583    if rotation != 0 {
584        for l in &mut links {
585            let (a, t, r, b) = to_display_frame((l.l, l.t, l.r, l.b), rotation, unrot_w, unrot_h);
586            (l.l, l.t, l.r, l.b) = (a, t, r, b);
587        }
588    }
589
590    // `/Rotate` normalization for scanned pages: pdfium renders the page as a
591    // viewer displays it — `/Rotate` applied — so a rotated scan hands layout
592    // and OCR a sideways/upside-down raster and the recognition output is
593    // garbage. A page with a text layer needs none of this (its cells carry
594    // the geometry; the models never see its pixels decide text), so the
595    // normalization is gated to pages with no cells at all — exactly the set
596    // the OCR path fires on. The bitmaps are un-rotated to upright (lossless
597    // 90° steps), `width`/`height` swap to the upright box, and the display
598    // rotation is recorded so assembly can rotate the finished geometry back
599    // into display space (docling reports rotated pages in display coords).
600    let scanned = cells.is_empty() && word_cells.is_empty() && code_cells.is_empty();
601    let mut page = PdfPage {
602        width,
603        height,
604        scale: RENDER_SCALE,
605        image_layout,
606        cells,
607        code_cells,
608        word_cells,
609        image,
610        links,
611        rotation: 0,
612    };
613    if rotation != 0 && scanned && render_image {
614        page.unrotate(rotation);
615    }
616    Ok(page)
617}
618
619#[cfg(feature = "ml")]
620/// The supersample→target downscale via `fast_image_resize` (SIMD convolution;
621/// the same a=-0.5 Catmull-Rom kernel as `image::imageops::resize(...,
622/// CatmullRom)` and PIL BICUBIC — see the render comment above). Set
623/// `DOCLING_RS_SLOW_RESIZE=1` to fall back to the `image`-crate scalar resize
624/// (byte-parity with the pre-SIMD pipeline, several times slower).
625fn fast_downscale(big: &RgbImage, dw: u32, dh: u32) -> RgbImage {
626    use fast_image_resize as fir;
627    static SLOW: std::sync::OnceLock<bool> = std::sync::OnceLock::new();
628    let slow = *SLOW.get_or_init(|| docling_core::env::flag("DOCLING_RS_SLOW_RESIZE"));
629    if !slow {
630        if let Some(out) = (|| {
631            let src = fir::images::ImageRef::new(
632                big.width(),
633                big.height(),
634                big.as_raw(),
635                fir::PixelType::U8x3,
636            )
637            .ok()?;
638            let mut dst = fir::images::Image::new(dw, dh, fir::PixelType::U8x3);
639            fir::Resizer::new()
640                .resize(
641                    &src,
642                    &mut dst,
643                    &fir::ResizeOptions::new()
644                        .resize_alg(fir::ResizeAlg::Convolution(fir::FilterType::CatmullRom)),
645                )
646                .ok()?;
647            RgbImage::from_raw(dw, dh, dst.into_vec())
648        })() {
649            return out;
650        }
651        // Unreachable in practice; fall through to the scalar path on any error.
652    }
653    image::imageops::resize(big, dw, dh, image::imageops::FilterType::CatmullRom)
654}
655
656#[cfg(feature = "ml")]
657/// Collect web/mail/tel hyperlink annotations on a page, mapping each link's
658/// rectangle into top-left page coordinates (like [`TextCell`]). `file://` and
659/// in-document destinations are skipped — only externally meaningful targets are
660/// rendered. pdfium occasionally lists a link twice; rects are kept as-is and the
661/// caller dedupes by resolved anchor text.
662fn extract_links(page: &pdfium_render::prelude::PdfPage<'_>, page_h: f32) -> Vec<LinkAnnot> {
663    let mut out = Vec::new();
664    for link in page.links().iter() {
665        let Some(uri) = link
666            .action()
667            .and_then(|a| a.as_uri_action().and_then(|u| u.uri().ok()))
668        else {
669            continue;
670        };
671        let scheme_ok = ["http://", "https://", "mailto:", "tel:"]
672            .iter()
673            .any(|s| uri.starts_with(s));
674        if !scheme_ok {
675            continue;
676        }
677        if let Ok(rect) = link.rect() {
678            out.push(LinkAnnot {
679                l: rect.left().value,
680                t: page_h - rect.top().value,
681                r: rect.right().value,
682                b: page_h - rect.bottom().value,
683                uri,
684            });
685        }
686    }
687    out
688}
689
690/// Map a top-left-origin rect from a page's unrotated (MediaBox) frame into its
691/// `/Rotate`d display frame — the counterpart of docling's pypdfium2
692/// `_rect_to_display_frame` (docling#4008) for our y-down coordinates.
693/// `unrot_w`/`unrot_h` are the unrotated page box; the display box is the same
694/// for 180° and swapped for 90°/270°.
695pub(crate) fn to_display_frame(
696    (l, t, r, b): (f32, f32, f32, f32),
697    rotation: u16,
698    unrot_w: f32,
699    unrot_h: f32,
700) -> (f32, f32, f32, f32) {
701    match rotation {
702        // Page turned 90° clockwise for display: the unrotated top edge becomes
703        // the display right edge, so x' runs from the old bottom edge up.
704        90 => (unrot_h - b, l, unrot_h - t, r),
705        180 => (unrot_w - r, unrot_h - b, unrot_w - l, unrot_h - t),
706        270 => (t, unrot_w - r, b, unrot_w - l),
707        _ => (l, t, r, b),
708    }
709}
710
711#[cfg(feature = "ml")]
712/// Fallback line cells from pdfium-render's style segments (one cell per
713/// segment). Used only when the raw-FFI text page can't be loaded.
714fn segment_cells(text: &PdfPageText, page_h: f32) -> Vec<TextCell> {
715    text.segments()
716        .iter()
717        .filter_map(|seg| {
718            let s = seg.text();
719            if s.trim().is_empty() {
720                return None;
721            }
722            let r = seg.bounds();
723            Some(TextCell {
724                text: s,
725                l: r.left().value,
726                t: page_h - r.top().value,
727                r: r.right().value,
728                b: page_h - r.bottom().value,
729            })
730        })
731        .collect()
732}
733
734#[cfg(feature = "ml")]
735/// A second, raw-FFI handle on the same PDF used to drive the character loop
736/// (`FPDFText_GetUnicode`/`GetCharBox`) that pdfium-render's safe API doesn't
737/// expose. Closes the document on drop.
738struct FfiText<'a> {
739    bindings: &'a dyn PdfiumLibraryBindings,
740    doc: FPDF_DOCUMENT,
741}
742
743/// One glyph: codepoint + native (y-up) box edges. `l/b/r/t` is pdfium's *tight*
744/// ink box (used by the legacy `lines_from_glyphs`); `ll/lb/lr/lt` is the *loose*
745/// box (font ascent/descent + advance — uniform per font/size), which the
746/// docling-parse-style sanitizer needs so adjacent glyphs share a top edge.
747pub(crate) struct Glyph {
748    pub(crate) ch: char,
749    pub(crate) l: f32,
750    pub(crate) b: f32,
751    pub(crate) r: f32,
752    pub(crate) t: f32,
753    pub(crate) ll: f32,
754    pub(crate) lb: f32,
755    pub(crate) lr: f32,
756    pub(crate) lt: f32,
757    /// Hash of the PDF font name + flags (0 when not fetched). The sanitizer uses
758    /// it for docling-parse's `enforce_same_font` (keeps a bold label and regular
759    /// value as separate line cells, e.g. `LABEL : value`).
760    pub(crate) font: u64,
761}
762
763#[cfg(feature = "ml")]
764impl<'a> FfiText<'a> {
765    fn load(bindings: &'a dyn PdfiumLibraryBindings, bytes: &[u8], password: Option<&str>) -> Self {
766        let doc = bindings.FPDF_LoadMemDocument(bytes, password);
767        FfiText { bindings, doc }
768    }
769
770    /// Reconstruct line cells for page `index` (zero-based) via the
771    /// chars→words→lines grouping. Returns `(prose_cells, code_cells)` — the same
772    /// glyphs grouped two ways (gap-heuristic for prose, space-glyph-only for
773    /// code). Both empty on any failure (caller falls back).
774    fn page_cells(&self, index: i32, page_h: f32) -> (Vec<TextCell>, Vec<TextCell>, Vec<TextCell>) {
775        let empty = || (Vec::new(), Vec::new(), Vec::new());
776        if self.doc.is_null() {
777            return empty();
778        }
779        let b = self.bindings;
780        let page = b.FPDF_LoadPage(self.doc, index);
781        if page.is_null() {
782            return empty();
783        }
784        let tp = b.FPDFText_LoadPage(page);
785        let out = if tp.is_null() {
786            empty()
787        } else {
788            let dp = use_dp_lines();
789            let g = glyphs(b, tp, dp);
790            b.FPDFText_ClosePage(tp);
791            // Prose line cells: the docling-parse-style sanitizer (behind a flag
792            // while it's validated) or the legacy gap-heuristic reconstruction.
793            let prose = if dp {
794                crate::dp_lines::line_cells(&g, page_h, false)
795            } else {
796                lines_from_glyphs(&g, page_h, Grouping::Prose)
797            };
798            (
799                prose,
800                lines_from_glyphs(&g, page_h, Grouping::CodeSpaceOnly),
801                words_from_glyphs(&g, page_h),
802            )
803        };
804        b.FPDF_ClosePage(page);
805        out
806    }
807}
808
809#[cfg(feature = "ml")]
810impl Drop for FfiText<'_> {
811    fn drop(&mut self) {
812        if !self.doc.is_null() {
813            self.bindings.FPDF_CloseDocument(self.doc);
814        }
815    }
816}
817
818#[cfg(feature = "ml")]
819/// Read every glyph (codepoint + native box) from the text page, in document
820/// order. A space glyph is kept as a word-boundary marker (NaN box, char `' '`);
821/// pdfium emits these on most lines and they pin word splits exactly. Hard line
822/// breaks are dropped (line structure comes from geometry); the gap heuristic in
823/// [`lines_from_glyphs`] is the fallback for the lines pdfium leaves space-less.
824/// Debug helper: the raw pdfium glyph stream (codepoint + native bottom-left
825/// box) for a page, in pdfium's character order. For comparing against
826/// docling-parse's char cells.
827pub fn debug_glyphs(bytes: &[u8], index: i32) -> Vec<(char, f32, f32)> {
828    let Ok(pdfium) = bind() else {
829        return Vec::new();
830    };
831    let ffi = FfiText::load(pdfium.bindings(), bytes, None);
832    if ffi.doc.is_null() {
833        return Vec::new();
834    }
835    let b = ffi.bindings;
836    let page = b.FPDF_LoadPage(ffi.doc, index);
837    if page.is_null() {
838        return Vec::new();
839    }
840    let tp = b.FPDFText_LoadPage(page);
841    let mut out = Vec::new();
842    if !tp.is_null() {
843        for g in glyphs(b, tp, true) {
844            out.push((g.ch, g.ll, g.lr));
845        }
846        b.FPDFText_ClosePage(tp);
847    }
848    b.FPDF_ClosePage(page);
849    out
850}
851
852#[cfg(feature = "ml")]
853/// One text object on a page, for the hidden-layer diagnostic.
854#[derive(Debug, Clone)]
855pub struct DebugTextObject {
856    /// True when the object is drawn invisibly (text render mode 3) — the marker of
857    /// a hidden duplicate text layer.
858    pub invisible: bool,
859    /// Bounding box in native PDF points (bottom-left origin).
860    pub l: f32,
861    pub b: f32,
862    pub r: f32,
863    pub t: f32,
864    /// The object's text (best-effort; empty if it could not be read).
865    pub text: String,
866}
867
868#[cfg(feature = "ml")]
869/// Diagnostic: every text object on page `index`, each tagged visible/invisible
870/// (via the object-level [`FPDFTextObj_GetTextRenderMode`], which — unlike the
871/// per-character render-mode API — is available on the default pdfium binding).
872/// A hidden duplicate text layer shows up as invisible objects repeating the
873/// visible text. Used by the `dump_render_modes` example.
874///
875/// [`FPDFTextObj_GetTextRenderMode`]: pdfium_render::prelude::PdfiumLibraryBindings::FPDFTextObj_GetTextRenderMode
876pub fn debug_text_objects(bytes: &[u8], index: i32) -> Vec<DebugTextObject> {
877    let Ok(pdfium) = bind() else {
878        return Vec::new();
879    };
880    let ffi = FfiText::load(pdfium.bindings(), bytes, None);
881    if ffi.doc.is_null() {
882        return Vec::new();
883    }
884    let b = ffi.bindings;
885    let page = b.FPDF_LoadPage(ffi.doc, index);
886    if page.is_null() {
887        return Vec::new();
888    }
889    let tp = b.FPDFText_LoadPage(page);
890    let mut out = Vec::new();
891    let n = b.FPDFPage_CountObjects(page);
892    for i in 0..n {
893        let obj = b.FPDFPage_GetObject(page, i);
894        if obj.is_null() || b.FPDFPageObj_GetType(obj) != FPDF_PAGEOBJ_TEXT as i32 {
895            continue;
896        }
897        let (mut l, mut bot, mut r, mut top) = (0f32, 0f32, 0f32, 0f32);
898        if b.FPDFPageObj_GetBounds(obj, &mut l, &mut bot, &mut r, &mut top) == 0 {
899            continue;
900        }
901        let invisible = b.FPDFTextObj_GetTextRenderMode(obj) == INVISIBLE_RENDER_MODE;
902        let text = if tp.is_null() {
903            String::new()
904        } else {
905            // FPDFTextObj_GetText returns the count of UTF-16 code units, including
906            // the trailing NUL; call once for the size, once to fill.
907            let need = b.FPDFTextObj_GetText(obj, tp, std::ptr::null_mut(), 0);
908            if need <= 1 {
909                String::new()
910            } else {
911                let mut buf = vec![0u16; need as usize];
912                b.FPDFTextObj_GetText(obj, tp, buf.as_mut_ptr(), need);
913                if let Some(&0) = buf.last() {
914                    buf.pop();
915                }
916                String::from_utf16_lossy(&buf)
917            }
918        };
919        out.push(DebugTextObject {
920            invisible,
921            l,
922            b: bot,
923            r,
924            t: top,
925            text,
926        });
927    }
928    if !tp.is_null() {
929        b.FPDFText_ClosePage(tp);
930    }
931    b.FPDF_ClosePage(page);
932    out
933}
934
935#[cfg(feature = "ml")]
936/// Hash a glyph's PDF font name + flags, for `enforce_same_font`. 0 if unavailable.
937fn font_hash(b: &dyn PdfiumLibraryBindings, tp: FPDF_TEXTPAGE, i: i32) -> u64 {
938    use std::hash::{Hash, Hasher};
939    let mut flags: std::os::raw::c_int = 0;
940    let len = b.FPDFText_GetFontInfo(tp, i, std::ptr::null_mut(), 0, &mut flags);
941    if len == 0 {
942        return 0;
943    }
944    let mut buf = vec![0u8; len as usize];
945    b.FPDFText_GetFontInfo(
946        tp,
947        i,
948        buf.as_mut_ptr() as *mut std::os::raw::c_void,
949        len,
950        &mut flags,
951    );
952    let mut h = std::collections::hash_map::DefaultHasher::new();
953    buf.hash(&mut h);
954    flags.hash(&mut h);
955    h.finish()
956}
957
958#[cfg(feature = "ml")]
959/// A glyph's PDF font name (NUL-trimmed), or empty if unavailable.
960fn font_name_bytes(b: &dyn PdfiumLibraryBindings, tp: FPDF_TEXTPAGE, i: i32) -> Vec<u8> {
961    let mut flags: std::os::raw::c_int = 0;
962    let len = b.FPDFText_GetFontInfo(tp, i, std::ptr::null_mut(), 0, &mut flags);
963    if len == 0 {
964        return Vec::new();
965    }
966    let mut buf = vec![0u8; len as usize];
967    b.FPDFText_GetFontInfo(
968        tp,
969        i,
970        buf.as_mut_ptr() as *mut std::os::raw::c_void,
971        len,
972        &mut flags,
973    );
974    while buf.last() == Some(&0) {
975        buf.pop();
976    }
977    buf
978}
979
980#[cfg(feature = "ml")]
981/// Read the text layer's glyph boxes and font styles for the given **1-based**
982/// pages — the heading-hierarchy stage's style signal (#302). A separate,
983/// on-demand pass over the text pages (no rendering), so the extraction
984/// pipeline itself stays byte-identical whether or not the stage runs; pages
985/// without a text layer (scans) simply yield no glyphs and the stage falls
986/// back to its other signals. Boxes are the *loose* char boxes (font ascent +
987/// descent — the font-size proxy), converted to top-left origin.
988pub(crate) fn glyph_styles(
989    bytes: &[u8],
990    password: Option<&str>,
991    pages: &[usize],
992) -> std::collections::HashMap<usize, Vec<crate::heading_hierarchy::GlyphStyle>> {
993    use crate::heading_hierarchy::GlyphStyle;
994    let mut out = std::collections::HashMap::new();
995    let Ok(pdfium) = bind() else {
996        return out;
997    };
998    let ffi = FfiText::load(pdfium.bindings(), bytes, password);
999    if ffi.doc.is_null() {
1000        return out;
1001    }
1002    let b = ffi.bindings;
1003    // Each distinct font name parses once per document.
1004    let mut cache: std::collections::HashMap<Vec<u8>, crate::font_style::FontStyle> =
1005        std::collections::HashMap::new();
1006    for &page_no in pages {
1007        if page_no == 0 {
1008            continue;
1009        }
1010        let page = b.FPDF_LoadPage(ffi.doc, (page_no - 1) as i32);
1011        if page.is_null() {
1012            continue;
1013        }
1014        let page_h = b.FPDF_GetPageHeightF(page);
1015        let tp = b.FPDFText_LoadPage(page);
1016        if !tp.is_null() {
1017            let n = b.FPDFText_CountChars(tp);
1018            let mut styles = Vec::with_capacity(n.max(0) as usize);
1019            for i in 0..n {
1020                let ch = match char::from_u32(b.FPDFText_GetUnicode(tp, i)) {
1021                    Some(c) => c,
1022                    None => continue,
1023                };
1024                if ch.is_whitespace() {
1025                    continue;
1026                }
1027                let mut lr = FS_RECTF {
1028                    left: 0.0,
1029                    top: 0.0,
1030                    right: 0.0,
1031                    bottom: 0.0,
1032                };
1033                if b.FPDFText_GetLooseCharBox(tp, i, &mut lr) == 0 {
1034                    continue;
1035                }
1036                let name = font_name_bytes(b, tp, i);
1037                let style = *cache.entry(name).or_insert_with_key(|n| {
1038                    crate::font_style::parse_font_style(&String::from_utf8_lossy(n))
1039                });
1040                styles.push(GlyphStyle {
1041                    l: lr.left,
1042                    t: page_h - lr.top,
1043                    r: lr.right,
1044                    b: page_h - lr.bottom,
1045                    height: lr.top - lr.bottom,
1046                    weight_cls: crate::font_style::weight_class(style.weight),
1047                    italic: style.italic,
1048                    styled: style.known,
1049                });
1050            }
1051            b.FPDFText_ClosePage(tp);
1052            out.insert(page_no, styles);
1053        }
1054        b.FPDF_ClosePage(page);
1055    }
1056    out
1057}
1058
1059#[cfg(feature = "ml")]
1060/// pdfium text render mode 3: the glyph is drawn with neither fill nor stroke —
1061/// an invisible glyph. Web-to-PDF exporters put a hidden plain-text copy of
1062/// syntax-highlighted code (and other "copy"/accessibility layers) in this mode,
1063/// which the char-level text API then extracts as a duplicate of the visible text.
1064const INVISIBLE_RENDER_MODE: i32 = 3;
1065
1066#[cfg(feature = "ml")]
1067fn glyphs(b: &dyn PdfiumLibraryBindings, tp: FPDF_TEXTPAGE, fetch_font: bool) -> Vec<Glyph> {
1068    let n = b.FPDFText_CountChars(tp);
1069    let mut out = Vec::with_capacity(n.max(0) as usize);
1070    for i in 0..n {
1071        let ch = match char::from_u32(b.FPDFText_GetUnicode(tp, i)) {
1072            Some(c) => c,
1073            None => continue,
1074        };
1075        if ch == '\r' || ch == '\n' {
1076            continue;
1077        }
1078        // Spaces are font-neutral (0): pdfium's generated spaces carry a default
1079        // font that would otherwise block every word↔space merge under
1080        // enforce_same_font; docling-parse's spaces inherit the run's font.
1081        let font = if fetch_font && !ch.is_whitespace() {
1082            font_hash(b, tp, i)
1083        } else {
1084            0
1085        };
1086        let (mut l, mut r, mut bot, mut top) = (0f64, 0f64, 0f64, 0f64);
1087        let has_box = b.FPDFText_GetCharBox(tp, i, &mut l, &mut r, &mut bot, &mut top) != 0;
1088        // Loose box: font ascent/descent + glyph advance, uniform per font/size.
1089        let mut lr = FS_RECTF {
1090            left: 0.0,
1091            top: 0.0,
1092            right: 0.0,
1093            bottom: 0.0,
1094        };
1095        let (ll, lb, lrt, ltop) = if b.FPDFText_GetLooseCharBox(tp, i, &mut lr) != 0 {
1096            (lr.left, lr.bottom, lr.right, lr.top)
1097        } else if has_box {
1098            (l as f32, bot as f32, r as f32, top as f32)
1099        } else {
1100            (f32::NAN, 0.0, 0.0, 0.0)
1101        };
1102        if ch.is_whitespace() {
1103            // Keep the space *with its box* (the docling-parse-style line sanitizer
1104            // needs literal space glyphs); NaN `l` if pdfium reports no box (the
1105            // legacy `lines_from_glyphs` ignores the box and only flags a space).
1106            out.push(Glyph {
1107                ch: ' ',
1108                l: if has_box { l as f32 } else { f32::NAN },
1109                b: if has_box { bot as f32 } else { 0.0 },
1110                r: if has_box { r as f32 } else { 0.0 },
1111                t: if has_box { top as f32 } else { 0.0 },
1112                ll,
1113                lb,
1114                lr: lrt,
1115                lt: ltop,
1116                font,
1117            });
1118            continue;
1119        }
1120        if !has_box {
1121            continue;
1122        }
1123        out.push(Glyph {
1124            ch,
1125            l: l as f32,
1126            b: bot as f32,
1127            r: r as f32,
1128            t: top as f32,
1129            ll,
1130            lb,
1131            lr: lrt,
1132            lt: ltop,
1133            font,
1134        });
1135    }
1136    // pdfium splits the Arabic lam-alef ligature into two chars at the *same* x
1137    // (it's one glyph) in visual order — `alef-variant, lam`. docling-parse and
1138    // logical order are `lam, alef-variant`. Detect the ligature by the shared x
1139    // and swap. The shared-x test reliably distinguishes a true ligature from a
1140    // genuine `alef + lam` sequence (the article `ال`, or `فعالة`), whose two
1141    // glyphs sit at different x and must NOT be reordered.
1142    for i in 0..out.len().saturating_sub(1) {
1143        let same_x = out[i].l.is_finite()
1144            && out[i + 1].l.is_finite()
1145            && (out[i].l - out[i + 1].l).abs() < 1.0;
1146        if same_x
1147            && matches!(out[i].ch, '\u{0622}' | '\u{0623}' | '\u{0625}' | '\u{0627}')
1148            && out[i + 1].ch == '\u{0644}'
1149        {
1150            out.swap(i, i + 1);
1151        }
1152    }
1153    // Reconstruct degenerate (zero-width) loose space boxes by spanning the gap to
1154    // the next glyph on the same line, so the sanitizer keeps them as word
1155    // separators rather than dropping them (which would merge `Information systems`
1156    // → `Informationsystems`). pdfium gives generated spaces a zero-width box at a
1157    // wrong baseline; a wrap (different baseline) or a touching gap is left alone.
1158    for i in 0..out.len() {
1159        if out[i].ch != ' ' || (out[i].lr - out[i].ll).abs() >= 0.5 {
1160            continue;
1161        }
1162        let prev = out[..i]
1163            .iter()
1164            .rev()
1165            .find(|g| g.ch != ' ' && g.ll.is_finite())
1166            .map(|g| (g.lr, g.lb, g.lt));
1167        let next = out[i + 1..]
1168            .iter()
1169            .find(|g| g.ch != ' ' && g.ll.is_finite())
1170            .map(|g| (g.ll, g.lb));
1171        if let (Some((plr, plb, plt)), Some((nll, nlb))) = (prev, next) {
1172            let line_h = (plt - plb).abs().max(1.0);
1173            if (plb - nlb).abs() < line_h * 0.5 && nll > plr + 0.5 {
1174                out[i].ll = plr;
1175                out[i].lr = nll;
1176                out[i].lb = plb;
1177                out[i].lt = plt;
1178            }
1179        }
1180    }
1181    out
1182}
1183
1184/// How [`lines_from_glyphs`] splits a line into words.
1185#[derive(Clone, Copy, PartialEq)]
1186enum Grouping {
1187    /// Gap heuristic + punctuation glue (`engines,`, `[37`, `98.5`) — prose.
1188    Prose,
1189    /// Split only at literal space glyphs, never glue — pdfium code cells.
1190    /// pdfium's monospace listings carry a real space glyph at every source space,
1191    /// and its overhanging loose boxes would make the gap heuristic over-split
1192    /// (`f un c t i o n`), so honouring just the spaces reproduces the spacing.
1193    CodeSpaceOnly,
1194    /// Split on the inter-glyph **gap** (or a space glyph), but never glue — for
1195    /// the parser's code cells: the parser emits no space glyphs (a source space
1196    /// is a positioning gap), and its clean advance boxes make the gap reliable.
1197    /// Unlike [`Grouping::Prose`] there is no punctuation glue, so a real gap
1198    /// always splits (`et al. 2000`, not `et al.2000`) while genuinely touching
1199    /// tokens stay joined (`add(a,` / `b)`).
1200    CodeGap,
1201}
1202
1203/// Group glyphs (document order) into words then lines, the way docling-parse
1204/// does: a new **word** starts where the horizontal gap to the previous glyph
1205/// exceeds ~0.2 × the font height (a real space is ~0.3 × height; letter
1206/// tracking is smaller, so titles don't shatter); a new **line** starts where
1207/// the baseline drops by ~half the font height (a superscript rises without
1208/// dropping, so it stays on its line). Coordinates are flipped to top-left.
1209/// See [`Grouping`] for how each mode decides word boundaries.
1210fn lines_from_glyphs(gs: &[Glyph], page_h: f32, mode: Grouping) -> Vec<TextCell> {
1211    let mut cells: Vec<TextCell> = Vec::new();
1212    let mut words: Vec<String> = Vec::new(); // words on the current line
1213    let mut word = String::new();
1214    // current line bounding box, native
1215    let (mut ll, mut lb, mut lr, mut lt) = (
1216        f32::INFINITY,
1217        f32::INFINITY,
1218        f32::NEG_INFINITY,
1219        f32::NEG_INFINITY,
1220    );
1221    // Tallest glyph seen on the current line: the word-gap threshold is relative
1222    // to it, so a small-font run on the line (a superscript citation) isn't split
1223    // at its tight digit gaps, while a big display title isn't split at its wider
1224    // letter tracking. A real inter-word space is ~0.3× the font height.
1225    let mut line_h: f32 = 0.0;
1226    let mut prev: Option<&Glyph> = None;
1227    // A space glyph between non-space glyphs pins a word split the gap heuristic
1228    // can miss (tight justified spacing); it carries no geometry.
1229    let mut pending_space = false;
1230
1231    for g in gs {
1232        if g.ch == ' ' {
1233            pending_space = true;
1234            continue;
1235        }
1236        let h = (g.t - g.b).abs().max(1.0);
1237        let (mut new_word, mut new_line) = (false, false);
1238        if let Some(p) = prev {
1239            // A new line drops the baseline *and* resets x leftward; requiring the
1240            // x-reset avoids a descending comma/semicolon faking a line break. A
1241            // *large* drop (≥1.5× the line height — a skipped line, e.g. a centered
1242            // page-number footer below a short last word) is always a new line,
1243            // even without the x-reset.
1244            // LTR wraps reset x leftward (`g.l < p.r`); RTL (Arabic) wraps reset
1245            // rightward (the new line begins at the far right). A large drop
1246            // (≥1.5× line height) is a new line regardless of x.
1247            let x_reset = if is_arabic(g.ch) || is_arabic(p.ch) {
1248                g.l > p.r
1249            } else {
1250                g.l < p.r
1251            };
1252            new_line = (p.b - g.b > h * 0.5 && x_reset) || (p.b - g.b > line_h.max(h) * 1.5);
1253            // Don't split before closing punctuation, after opening punctuation, or
1254            // after a period that runs into a digit/lowercase letter — docling
1255            // keeps `engines,` / `[37` / `i.e.` / `98.5` together even across a
1256            // space or gap.
1257            let glued = is_close_punct(g.ch)
1258                || is_open_punct(p.ch)
1259                || (p.ch.is_ascii_digit() && g.ch.is_ascii_digit())
1260                || (p.ch == '.'
1261                    && !pending_space
1262                    && (g.ch.is_ascii_digit() || g.ch.is_ascii_lowercase()));
1263            let word_gap = line_h.max(h) * 0.25;
1264            new_word = if mode == Grouping::CodeSpaceOnly {
1265                new_line || pending_space
1266            } else if mode == Grouping::CodeGap {
1267                // Gap-based, no glue: a real gap always splits, touching tokens join.
1268                new_line || pending_space || g.l - p.r > word_gap
1269            } else if is_arabic(g.ch) || is_arabic(p.ch) {
1270                // RTL runs right-to-left, so the inter-word gap is `p.l - g.r`. A
1271                // real word space has a gap; pdfium also emits spurious zero-gap
1272                // space glyphs inside words (`التي`), so require the gap rather
1273                // than trusting a bare space glyph.
1274                new_line || (p.l - g.r > word_gap && !glued)
1275            } else {
1276                new_line || ((pending_space || g.l - p.r > word_gap) && !glued)
1277            };
1278        }
1279        pending_space = false;
1280        if new_line {
1281            push_word(&mut word, &mut words);
1282            push_line(&mut words, (ll, lb, lr, lt), page_h, &mut cells);
1283            (ll, lb, lr, lt) = (
1284                f32::INFINITY,
1285                f32::INFINITY,
1286                f32::NEG_INFINITY,
1287                f32::NEG_INFINITY,
1288            );
1289            line_h = 0.0;
1290        } else if new_word {
1291            push_word(&mut word, &mut words);
1292        }
1293        word.push(g.ch);
1294        ll = ll.min(g.l);
1295        lb = lb.min(g.b);
1296        lr = lr.max(g.r);
1297        lt = lt.max(g.t);
1298        line_h = line_h.max(h);
1299        prev = Some(g);
1300    }
1301    push_word(&mut word, &mut words);
1302    push_line(&mut words, (ll, lb, lr, lt), page_h, &mut cells);
1303    cells
1304}
1305
1306/// Code line cells from the **parser**'s glyph stream. Unlike pdfium — whose
1307/// monospace listings carry explicit space glyphs (so [`Grouping::CodeSpaceOnly`]
1308/// keeps their spacing) — the parser emits no space glyphs: a source space is a
1309/// positioning gap. So code cells use [`Grouping::CodeGap`], which splits on the
1310/// inter-glyph gap (a space wherever it exceeds ~0.25× the line height) but never
1311/// glues punctuation, so `et al. 2000` keeps its space while `add(a,` / `b)` stay
1312/// joined. The parser's clean advance boxes make the gap heuristic reliable here,
1313/// where pdfium's overhanging loose boxes would over-split (`f un c t i o n`).
1314pub(crate) fn code_cells_from_glyphs(gs: &[Glyph], page_h: f32) -> Vec<TextCell> {
1315    lines_from_glyphs(gs, page_h, Grouping::CodeGap)
1316}
1317
1318/// Per-word cells (each word's text + top-left bbox), using the same word/line
1319/// splitting as [`lines_from_glyphs`] but emitting one cell per word instead of
1320/// joining into lines — the legacy gap-heuristic word grouping, kept for the
1321/// pdfium word path (`DOCLING_PDFIUM_WORDS`). The default parser path uses
1322/// [`crate::dp_lines::word_cells`] instead.
1323pub(crate) fn words_from_glyphs(gs: &[Glyph], page_h: f32) -> Vec<TextCell> {
1324    let mut cells = Vec::new();
1325    let mut word = String::new();
1326    let inf = (
1327        f32::INFINITY,
1328        f32::INFINITY,
1329        f32::NEG_INFINITY,
1330        f32::NEG_INFINITY,
1331    );
1332    let (mut wl, mut wb, mut wr, mut wt) = inf;
1333    let mut line_h: f32 = 0.0;
1334    let mut prev: Option<&Glyph> = None;
1335    let mut pending_space = false;
1336    for g in gs {
1337        if g.ch == ' ' {
1338            pending_space = true;
1339            continue;
1340        }
1341        let h = (g.t - g.b).abs().max(1.0);
1342        let mut new_line = false;
1343        let mut new_word = false;
1344        if let Some(p) = prev {
1345            // LTR wraps reset x leftward (`g.l < p.r`); RTL (Arabic) wraps reset
1346            // rightward (the new line begins at the far right). A large drop
1347            // (≥1.5× line height) is a new line regardless of x.
1348            let x_reset = if is_arabic(g.ch) || is_arabic(p.ch) {
1349                g.l > p.r
1350            } else {
1351                g.l < p.r
1352            };
1353            new_line = (p.b - g.b > h * 0.5 && x_reset) || (p.b - g.b > line_h.max(h) * 1.5);
1354            // No digit-digit glue here (unlike the prose grouping): table cells in
1355            // adjacent columns are numeric and a column gap must still split them
1356            // (`0.965` `0.934`, not `0.9650.934`). Intra-number digits have no gap
1357            // so they stay together regardless.
1358            let glued = is_close_punct(g.ch)
1359                || is_open_punct(p.ch)
1360                || (p.ch == '.'
1361                    && !pending_space
1362                    && (g.ch.is_ascii_digit() || g.ch.is_ascii_lowercase()));
1363            let word_gap = line_h.max(h) * 0.25;
1364            new_word = new_line || ((pending_space || g.l - p.r > word_gap) && !glued);
1365        }
1366        pending_space = false;
1367        if new_word && !word.is_empty() {
1368            cells.push(TextCell {
1369                text: std::mem::take(&mut word),
1370                l: wl,
1371                t: page_h - wt,
1372                r: wr,
1373                b: page_h - wb,
1374            });
1375            (wl, wb, wr, wt) = inf;
1376        }
1377        if new_line {
1378            line_h = 0.0;
1379        }
1380        word.push(g.ch);
1381        wl = wl.min(g.l);
1382        wb = wb.min(g.b);
1383        wr = wr.max(g.r);
1384        wt = wt.max(g.t);
1385        line_h = line_h.max(h);
1386        prev = Some(g);
1387    }
1388    if !word.is_empty() {
1389        cells.push(TextCell {
1390            text: word,
1391            l: wl,
1392            t: page_h - wt,
1393            r: wr,
1394            b: page_h - wb,
1395        });
1396    }
1397    cells
1398}
1399
1400fn is_arabic(c: char) -> bool {
1401    ('\u{0600}'..='\u{06FF}').contains(&c)
1402}
1403
1404fn is_close_punct(c: char) -> bool {
1405    matches!(
1406        c,
1407        ',' | '.' | ';' | '!' | '?' | ')' | ']' | '}' | '%' | '\'' | '\u{2019}' | '\u{2018}'
1408    )
1409}
1410
1411fn is_open_punct(c: char) -> bool {
1412    // `@` glues to what follows (`mAP @0.5`, `bpf@zurich`, `@decorator`).
1413    matches!(c, '(' | '[' | '{' | '@')
1414}
1415
1416fn push_word(word: &mut String, words: &mut Vec<String>) {
1417    if !word.is_empty() {
1418        words.push(std::mem::take(word));
1419    }
1420}
1421
1422fn push_line(
1423    words: &mut Vec<String>,
1424    bbox: (f32, f32, f32, f32),
1425    page_h: f32,
1426    cells: &mut Vec<TextCell>,
1427) {
1428    if words.is_empty() {
1429        return;
1430    }
1431    let text = std::mem::take(words).join(" ");
1432    let (l, b, r, t) = bbox;
1433    cells.push(TextCell {
1434        text,
1435        l,
1436        t: page_h - t,
1437        r,
1438        b: page_h - b,
1439    });
1440}
1441
1442#[cfg(test)]
1443mod tests {
1444    use super::to_display_frame;
1445
1446    /// A 612×792 portrait page displayed under `/Rotate`: a rect near the
1447    /// unrotated top-left lands where a viewer shows it (docling#4008).
1448    #[test]
1449    fn display_frame_follows_the_page_rotation() {
1450        let r = (72.0, 63.0, 387.0, 74.0); // top-left origin, unrotated
1451        assert_eq!(to_display_frame(r, 0, 612.0, 792.0), r);
1452        // 90° clockwise: the page becomes 792×612; the old top edge is the
1453        // display right edge, old left edge the display top.
1454        assert_eq!(
1455            to_display_frame(r, 90, 612.0, 792.0),
1456            (718.0, 72.0, 729.0, 387.0)
1457        );
1458        // 180°: both axes mirror inside the same box.
1459        assert_eq!(
1460            to_display_frame(r, 180, 612.0, 792.0),
1461            (225.0, 718.0, 540.0, 729.0)
1462        );
1463        // 270°: the old top edge is the display left edge, old right edge the
1464        // display top.
1465        assert_eq!(
1466            to_display_frame(r, 270, 612.0, 792.0),
1467            (63.0, 225.0, 74.0, 540.0)
1468        );
1469    }
1470
1471    #[test]
1472    fn display_frame_rotations_compose_to_identity() {
1473        let r = (10.0, 20.0, 110.0, 40.0);
1474        // 90° then 270° from the intermediate (792×612) box round-trips.
1475        let once = to_display_frame(r, 90, 612.0, 792.0);
1476        assert_eq!(to_display_frame(once, 270, 792.0, 612.0), r);
1477        let twice = to_display_frame(to_display_frame(r, 180, 612.0, 792.0), 180, 612.0, 792.0);
1478        assert_eq!(twice, r);
1479    }
1480}