Skip to content

Print-interior PDF from ordered pages

publication.generate.pdf.interior consumes one explicitly ordered, immutable renderflow/v2 collection of local PNG or JPEG pages. The canonical planner and executor use a locally installed img2pdf 0.6.3 provider and independently inspect its output before admitting it to the artifact store. This route creates an interior candidate; it does not approve a print job or claim retailer acceptance.

schema: renderflow/v2
sources:
  - id: source.page001
    path: pages/001.png
    format: png
    media_type: image/png
    sha256: "<64 lowercase hex characters for the exact file bytes>"
    geometry: { width: 50, height: 50, unit: mm, bleed: 3 }
  - id: source.page002
    path: pages/002.png
    format: png
    media_type: image/png
    sha256: "<64 lowercase hex characters for the exact file bytes>"
    geometry: { width: 50, height: 50, unit: mm, bleed: 3 }
  - id: source.pages
    kind: collection
    members: [source.page001, source.page002]
targets:
  exact:
    - id: target.interior
      role: interior
      format: pdf
execution:
  print_pdf_interior:
    executable: img2pdf
    provider_version: "0.6.3"
    box_policy: media_bleed_trim_inset
    rotation: none
    scaling: fit
    color_policy: preserve_rgb_gray
    max_pages: 44
    max_input_bytes: 268435456
    max_output_bytes: 268435456
    timeout_seconds: 120
output:
  bundle_root: dist

The geometry width and height are the trim size. bleed expands the MediaBox equally on all sides; BleedBox equals MediaBox, and TrimBox is inset by the declared bleed. Zero bleed must be stated explicitly. Every page must have identical geometry and an image aspect ratio matching the full MediaBox within 0.02 PDF points. The first route uses a single homogeneous PNG or JPEG collection, no custom transform registry, no rotation, and a full-page fit without crop or stretch. PNG supports 8-bit RGB or grayscale without alpha, interlace, ICC, EXIF, or color intent metadata. JPEG supports decoded RGB or grayscale without ICC, nonidentity EXIF orientation, or nonsquare pixel aspect. The color policy proves unprofiled RGB or grayscale image bytes embedded in the corresponding PDF device space; it does not claim calibrated color reproduction. Unsupported or ambiguous inputs are refused. Each image is limited to 128 MiB of source bytes and 512 MiB of decoded data, in addition to the configured collection and PDF limits.

Use renderflow spec validate --config renderflow.yaml, then renderflow build --config renderflow.yaml --dry-run, then renderflow build --config renderflow.yaml. The executable may be an absolute path when tool installation is isolated; it must be a trusted local img2pdf 0.6.3 binary. Renderflow passes direct argv with --nodate, the internal PDF engine, explicit page/image sizes, box borders, fit and rotation. The process has a timeout, cancellation, bounded capture, input/page limits, and a monitored output-byte limit. network: deny is recorded as process intent; it is not an operating-system network sandbox. This adapter makes no network request itself.

Planning preflights every source and freezes ordered IDs, locators, source digests, geometry, decoded image properties, expected embedded image-stream digests, and the exact provider/version configuration. Execution re-imports each source and refuses changed bytes before running the provider. The PDF inspector parses the resulting document and requires exactly one drawn image per page, exact ordered stream digest, matching pixel dimensions and color space, full-page placement, explicit page boxes, zero rotation, and exact page count. It records PDF digest, page details, and ordered source lineage in run, artifact, validation, provider/toolchain, and checkpoint evidence. Failed or cancelled runs do not materialize an interior artifact.

Publication contracts, when provided, must agree on geometry and color; an interior output-role minimum image DPI is enforced. Font embedding and arbitrary additional output-role validators are unsupported for this image-only route. A separate print preflight and physical proof remain necessary before any publishing or retailer submission.