mozilla/pdf.js · error · Error

doc.hostContainer is read-only

Error message

doc.hostContainer is read-only

What it means

PDF.js's scripting sandbox (src/scripting_api) implements the Acrobat JavaScript `doc` object inside a QuickJS sandbox. Per the Acrobat API specification this property is read-only, so the class defines a getter that returns the current value and a setter that unconditionally throws `Error("doc.<prop> is read-only")`. The throw aborts the currently executing sandboxed script event and is reported back to the host. `hostContainer` is the host-container object for message passing; pdf.js returns `undefined` (not implemented) and forbids writes.

Source

Thrown at src/scripting_api/doc.js:386

  set filesize(_) {
    throw new Error("doc.filesize is read-only");
  }

  get hidden() {
    return false;
  }

  set hidden(_) {
    throw new Error("doc.hidden is read-only");
  }

  get hostContainer() {
    return undefined;
  }

  set hostContainer(_) {
    throw new Error("doc.hostContainer is read-only");
  }

  get icons() {
    return undefined;
  }

  set icons(_) {
    throw new Error("doc.icons is read-only");
  }

  get info() {
    return this._info;
  }

  set info(_) {
    throw new Error("doc.info is read-only");
  }

View on GitHub (pinned to 5903d58d58)

Solutions

  1. Remove the assignment to `doc.hostContainer`; read it through the getter instead.
  2. Use the host page's postMessage API outside the sandbox instead; pdf.js does not implement hostContainer.
  3. If you cannot edit the PDF's embedded script, wrap the statement in try/catch so the rest of the form logic still runs.

Example fix

// before
doc.hostContainer = {};
// after
// hostContainer is read-only — drop the assignment; read via doc.hostContainer
Defensive patterns

Strategy: validation

Validate before calling

// Known read-only doc properties (PDF.js scripting_api/doc.js)
const READONLY_DOC_PROPS = new Set([
  'author','bookmarkRoot','creator','dataObjects','docID',
  'documentFileName','dynamicXFAForm','external','filesize','hidden',
  'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',
  'isModal','keywords','modDate'
]);
if (READONLY_DOC_PROPS.has('hostContainer')) {
  // skip the write; hostContainer is read-only in pdf.js
  console.warn('doc.hostContainer is read-only in pdf.js');
} else {
  doc.hostContainer = value;
}

Type guard

// Known read-only doc properties (PDF.js scripting_api/doc.js)
const READONLY_DOC_PROPS = new Set([
  'author','bookmarkRoot','creator','dataObjects','docID',
  'documentFileName','dynamicXFAForm','external','filesize','hidden',
  'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',
  'isModal','keywords','modDate'
]);
const isReadOnlyDocProp = (name) => READONLY_DOC_PROPS.has(name);
// usage: if (!isReadOnlyDocProp('keywords')) doc.keywords = v;

Try / catch

try {
  doc.hostContainer = value;
} catch (e) {
  // pdf.js throws Error('doc.hostContainer is read-only')
  if (/is read-only/.test(e.message)) { /* swallow, expected */ }
  else { throw e; }
}

Prevention

When it happens

Trigger: A sandboxed PDF form/script executes an assignment to the property, e.g. `doc.hostContainer = value;` or `doc.hostContainer++`. Because the setter always throws (there is no condition), any write attempt triggers it.

Common situations: Scripts ported from desktop Acrobat where hostContainer was set; forms that try to stamp runtime state into document metadata on save/open; and PDFs generated by tools that emit non-spec-compliant JavaScript.

Related errors


AI-assisted analysis of mozilla/pdf.js@5903d58d58 (2026-08-13). Data as JSON: /api/errors/5c41cc4b5a1ef756. Report an issue: GitHub.