Repository navigation
fix(xml): decode namespace URI entities before resolution - #141
Closed
nth-bailey wants to merge 2 commits into
Closed
nth-bailey wants to merge 2 commits into
nth-bailey wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Namespace declarations were stored as escaped XML source text. A valid URI containing an ampersand therefore failed strict-root matching and xsi:type dispatch, including inherited bindings in streamed records.
Decode predefined and numeric references once before storing namespace URIs, and propagate decoding failures through document, nested and stream paths. Preserve already-decoded inherited bindings. New regressions cover default/prefixed roots, round trips, local/inherited xsi:type declarations, streamed Start/Empty records, double-decoding prevention and undefined entity errors.
The new tests reproduce all three primary failures on the baseline and pass with the fix. This change addresses namespace URI decoding; it does not claim full namespace conformance.
Stacked on #137; keep this draft until the runtime investigation is reviewed.
Validation: full quality gate passes with 325 Rust tests, strict fmt/Clippy, Ruff, and 112 Python tests at 100% statement/branch coverage. Worktree-owned build artifacts; one Cargo worker under the systemd memory cap.
Report and raw evidence.