Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1 +1 @@
Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.4.
Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
8 changes: 7 additions & 1 deletion Modules/expat/expat.h
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@
Copyright (c) 2023 Sony Corporation / Snild Dolkow <snild@sony.com>
Copyright (c) 2024 Taichi Haradaguchi <20001722@ymail.ne.jp>
Copyright (c) 2025 Matthew Fernandez <matthew.fernandez@gmail.com>
Copyright (c) 2026 Braian Plaku <braianplaku@gmail.com>
Licensed under the MIT license:

Permission is hereby granted, free of charge, to any person obtaining
Expand Down Expand Up @@ -921,7 +922,9 @@ XML_SetParamEntityParsing(XML_Parser parser,
Returns 1 if successful, 0 when called after parsing has started.
Note: If parser == NULL, the function will do nothing and return 0.
DEPRECATED since Expat 2.8.0.
Please use XML_SetHashSalt16Bytes instead.
*/
XML_ATTR_DEPRECATED("please use XML_SetHashSalt16Bytes instead")
XMLPARSEAPI(int)
XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt);

Expand Down Expand Up @@ -1040,8 +1043,11 @@ enum XML_FeatureEnum {
XML_FEATURE_MIN_SIZE,
XML_FEATURE_SIZEOF_XML_CHAR,
XML_FEATURE_SIZEOF_XML_LCHAR,
/* Added in Expat 2.0.0. */
XML_FEATURE_NS,
/* Added in Expat 2.0.1. */
XML_FEATURE_LARGE_SIZE,
/* Added in Expat 2.1.0. */
XML_FEATURE_ATTR_INFO,
/* Added in Expat 2.4.0. */
XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT,
Expand Down Expand Up @@ -1096,7 +1102,7 @@ XML_SetReparseDeferralEnabled(XML_Parser parser, XML_Bool enabled);
*/
# define XML_MAJOR_VERSION 2
# define XML_MINOR_VERSION 8
# define XML_MICRO_VERSION 4
# define XML_MICRO_VERSION 5

# ifdef __cplusplus
}
Expand Down
12 changes: 12 additions & 0 deletions Modules/expat/expat_external.h
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@
Copyright (c) 2017 Rhodri James <rhodri@wildebeest.org.uk>
Copyright (c) 2018 Yury Gribov <tetra2005@gmail.com>
Copyright (c) 2026 Matthew Fernandez <matthew.fernandez@gmail.com>
Copyright (c) 2026 Braian Plaku <braianplaku@gmail.com>
Licensed under the MIT license:

Permission is hereby granted, free of charge, to any person obtaining
Expand Down Expand Up @@ -128,6 +129,17 @@
# define XML_ATTR_ALLOC_SIZE(x)
# endif

/* Marks a function that Expat still provides but that callers should move off
of. */
# if defined(__clang__) || defined(__GNUC__)
# define XML_ATTR_DEPRECATED(message) \
__attribute__((__deprecated__(message)))
# elif defined(_MSC_VER)
# define XML_ATTR_DEPRECATED(message) __declspec(deprecated(message))
# else
# define XML_ATTR_DEPRECATED(message) // empty i.e. no deprecation
# endif

# define XMLPARSEAPI(type) XMLIMPORT type XMLCALL

# ifdef __cplusplus
Expand Down
78 changes: 78 additions & 0 deletions Modules/expat/hash_table.h
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
/* Hash table related internal API
__ __ _
___\ \/ /_ __ __ _| |_
/ _ \\ /| '_ \ / _` | __|
| __// \| |_) | (_| | |_
\___/_/\_\ .__/ \__,_|\__|
|_| XML parser
Copyright (c) 2026 Sebastian Pipping <sebastian@pipping.org>
Licensed under the MIT license:
Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the
"Software"), to deal in the Software without restriction, including
without limitation the rights to use, copy, modify, merge, publish,
distribute, sublicense, and/or sell copies of the Software, and to permit
persons to whom the Software is furnished to do so, subject to the
following conditions:
The above copyright notice and this permission notice shall be included
in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
USE OR OTHER DEALINGS IN THE SOFTWARE.
SPDX-License-Identifier: MIT
*/

#if ! defined(HASH_TABLE_H)
# define HASH_TABLE_H 1

# include "expat.h" // for XML_Bool, XML_Parser
# include "internal.h" // for XML_NONTESTING_STATIC

# include <stddef.h> // for size_t

typedef const XML_Char *KEY;

typedef struct {
KEY name;
} NAMED;

typedef struct {
NAMED **v;
unsigned char power;
size_t size;
size_t used;
XML_Parser parser;
} HASH_TABLE;

typedef struct {
NAMED **p;
NAMED **end;
} HASH_TABLE_ITER;

XML_NONTESTING_STATIC NAMED *lookupWithLength(XML_Parser parser,
HASH_TABLE *table, KEY name,
size_t nameLen,
size_t createSize);
XML_NONTESTING_STATIC NAMED *lookup(XML_Parser parser, HASH_TABLE *table,
KEY name, size_t createSize);

XML_NONTESTING_STATIC void hashTableInit(HASH_TABLE *table, XML_Parser parser);
XML_NONTESTING_STATIC void hashTableClear(HASH_TABLE *table);
XML_NONTESTING_STATIC void hashTableDestroy(HASH_TABLE *table);
XML_NONTESTING_STATIC void hashTableIterInit(HASH_TABLE_ITER *iter,
const HASH_TABLE *table);
XML_NONTESTING_STATIC NAMED *hashTableIterNext(HASH_TABLE_ITER *iter);

XML_NONTESTING_STATIC XML_Bool keyeq(KEY s1, size_t s1len, KEY s2);
XML_NONTESTING_STATIC size_t keylen(KEY s);

#endif // ! defined(HASH_TABLE_H)
169 changes: 68 additions & 101 deletions Modules/expat/internal.h
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,6 @@
The following calling convention macros are defined for frequently
called functions:

FASTCALL - Used for those internal functions that have a simple
body and a low number of arguments and local variables.

PTRCALL - Used for functions called though function pointers.

PTRFASTCALL - Like PTRCALL, but for low number of arguments.

inline - Used for selected internal functions for which inlining
may improve performance on some platforms.

Expand All @@ -34,6 +27,8 @@
Copyright (c) 2023-2024 Sony Corporation / Snild Dolkow <snild@sony.com>
Copyright (c) 2024 Taichi Haradaguchi <20001722@ymail.ne.jp>
Copyright (c) 2026 Matthew Wozniczka <mattheww@simba.com>
Copyright (c) 2026 Braian Plaku <braianplaku@gmail.com>
Copyright (c) 2026 Florian Schmaus <florian.schmaus@codasip.com>
Licensed under the MIT license:

Permission is hereby granted, free of charge, to any person obtaining
Expand All @@ -58,132 +53,104 @@
SPDX-License-Identifier: MIT
*/

#if defined(__GNUC__) && defined(__i386__) && ! defined(__MINGW32__)
/* We'll use this version by default only where we know it helps.

regparm() generates warnings on Solaris boxes. See SF bug #692878.

Instability reported with egcs on a RedHat Linux 7.3.
Let's comment out:
#define FASTCALL __attribute__((stdcall, regparm(3)))
and let's try this:
*/
# define FASTCALL __attribute__((regparm(3)))
# define PTRFASTCALL __attribute__((regparm(3)))
#endif

/* Using __fastcall seems to have an unexpected negative effect under
MS VC++, especially for function pointers, so we won't use it for
now on that platform. It may be reconsidered for a future release
if it can be made more effective.
Likely reason: __fastcall on Windows is like stdcall, therefore
the compiler cannot perform stack optimizations for call clusters.
*/

/* Make sure all of these are defined if they aren't already. */

#ifndef FASTCALL
# define FASTCALL
#endif
#if ! defined(INTERNAL_H)
# define INTERNAL_H 1

#ifndef PTRCALL
# define PTRCALL
#endif

#ifndef PTRFASTCALL
# define PTRFASTCALL
#endif

#ifndef XML_MIN_SIZE
# if ! defined(__cplusplus) && ! defined(inline)
# ifdef __GNUC__
# define inline __inline
# endif /* __GNUC__ */
# endif
#endif /* XML_MIN_SIZE */
# ifndef XML_MIN_SIZE
# if ! defined(inline)
# ifdef __GNUC__
# define inline __inline
# endif /* __GNUC__ */
# endif
# endif /* XML_MIN_SIZE */

#ifdef __cplusplus
# define inline inline
#else
# ifndef inline
# define inline
# endif
#endif

#include <limits.h> // ULONG_MAX
#include <stddef.h> // size_t

#if defined(_WIN32) \
&& (! defined(__USE_MINGW_ANSI_STDIO) \
|| (1 - __USE_MINGW_ANSI_STDIO - 1 == 0))
# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x"
# define EXPAT_FMT_ULL(midpart) "%" midpart "I64u"
# if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d"
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart "I64u"

# if ! defined(XML_NONTESTING_STATIC)
# if defined(XML_TESTING)
# define XML_NONTESTING_STATIC // empty i.e. not static
# else
# define XML_NONTESTING_STATIC static
# endif
# endif

# include <limits.h> // ULONG_MAX
# include <stddef.h> // size_t

# if defined(_WIN32) \
&& (! defined(__USE_MINGW_ANSI_STDIO) \
|| (1 - __USE_MINGW_ANSI_STDIO - 1 == 0))
# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x"
# define EXPAT_FMT_ULL(midpart) "%" midpart "I64u"
# if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d"
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart "I64u"
# else
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "d"
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u"
# endif
# else
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "d"
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u"
# include <inttypes.h> // PRIdPTR, PRIuPTR
# define EXPAT_FMT_LLX(midpart) "%" midpart "llx"
# define EXPAT_FMT_ULL(midpart) "%" midpart "llu"
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart PRIdPTR
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart PRIuPTR
# endif

# ifndef UNUSED_P
# define UNUSED_P(p) (void)p
# endif
#else
# include <inttypes.h> // PRIdPTR, PRIuPTR
# define EXPAT_FMT_LLX(midpart) "%" midpart "llx"
# define EXPAT_FMT_ULL(midpart) "%" midpart "llu"
# define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart PRIdPTR
# define EXPAT_FMT_SIZE_T(midpart) "%" midpart PRIuPTR
#endif

#ifndef UNUSED_P
# define UNUSED_P(p) (void)p
#endif

/* NOTE BEGIN If you ever patch these defaults to greater values
for non-attack XML payload in your environment,
please file a bug report with libexpat. Thank you!
*/
#define EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT \
100.0f
#define EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT \
8388608 // 8 MiB, 2^23
# define EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT \
100.0f
# define EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT \
8388608 // 8 MiB, 2^23

#define EXPAT_ALLOC_TRACKER_MAXIMUM_AMPLIFICATION_DEFAULT 100.0f
#define EXPAT_ALLOC_TRACKER_ACTIVATION_THRESHOLD_DEFAULT \
67108864 // 64 MiB, 2^26
# define EXPAT_ALLOC_TRACKER_MAXIMUM_AMPLIFICATION_DEFAULT 100.0f
# define EXPAT_ALLOC_TRACKER_ACTIVATION_THRESHOLD_DEFAULT \
67108864 // 64 MiB, 2^26

// NOTE: If function expat_alloc was user facing, EXPAT_MALLOC_ALIGNMENT would
// have to take sizeof(long double) into account
#define EXPAT_MALLOC_ALIGNMENT sizeof(long long) // largest parser (sub)member
#define EXPAT_MALLOC_PADDING ((EXPAT_MALLOC_ALIGNMENT) - sizeof(size_t))
union expat_align {
long long l;
void *p;
};
# define EXPAT_MALLOC_ALIGNMENT sizeof(union expat_align)
# define EXPAT_MALLOC_PADDING ((EXPAT_MALLOC_ALIGNMENT) - sizeof(size_t))

/* NOTE END */

#include "expat.h" // so we can use type XML_Parser below

#ifdef __cplusplus
extern "C" {
#endif
# include "expat.h" // so we can use type XML_Parser below

void _INTERNAL_trim_to_complete_utf8_characters(const char *from,
const char **fromLimRef);

#if defined(XML_GE) && XML_GE == 1
# if defined(XML_GE) && XML_GE == 1
unsigned long long testingAccountingGetCountBytesDirect(XML_Parser parser);
unsigned long long testingAccountingGetCountBytesIndirect(XML_Parser parser);
const char *unsignedCharToPrintable(unsigned char c);
#endif
# endif

extern
#if ! defined(XML_TESTING)
# if ! defined(XML_TESTING)
const
#endif
# endif
XML_Bool g_reparseDeferralEnabledDefault; // written ONLY in runtests.c
#if defined(XML_TESTING)
# if defined(XML_TESTING)

int xmlSetHashSalt(XML_Parser parser, unsigned long hash_salt);

void *expat_malloc(XML_Parser parser, size_t size, int sourceLine);
void expat_free(XML_Parser parser, void *ptr, int sourceLine);
void *expat_realloc(XML_Parser parser, void *ptr, size_t size, int sourceLine);
extern unsigned int g_bytesScanned; // used for testing only
#endif
# endif

#ifdef __cplusplus
}
#endif
#endif // not defined INTERNAL_H
7 changes: 4 additions & 3 deletions Modules/expat/refresh.sh
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@ fi

# Update this when updating to a new version after verifying that the changes
# the update brings in are good. These values are used for verifying the SBOM, too.
expected_libexpat_tag="R_2_8_4"
expected_libexpat_version="2.8.4"
expected_libexpat_sha256="b8ece2437692dad44d851c4532723390a5a330990007706be9c8d2b90d294f36"
expected_libexpat_tag="R_2_8_5"
expected_libexpat_version="2.8.5"
expected_libexpat_sha256="920dde485e15eda0cce8d2310b41d492c534e5e3d89ad407a0b4176dd2ff88fe"

expat_dir="$(realpath "$(dirname -- "${BASH_SOURCE[0]}")")"
cd ${expat_dir}
Expand All @@ -34,6 +34,7 @@ lib_files=(
expat.h
expat_external.h
fallthrough.h
hash_table.h
iasciitab.h
internal.h
latin1tab.h
Expand Down
Loading
Loading