Skip to content

feat(XSD): add XSD libraries from macchina.io #5450 - #5504

Merged
matejk merged 9 commits into
mainfrom
5450-xsd
Sep 29, 2026
Merged

matejk merged 9 commits into
mainfrom
5450-xsd

Conversation

@matejk

@matejk matejk commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5450.

XSD moves from macchina.io into POCO: XSD/Types (schema object model), XSD/Parser (XML Schema and
WSDL parser), XSD/CodeGen (XSDGen, used by the RemotingNG SOAP samples) and XSD/Validator
(validation on libxml2). Flat import plus the two later Applied Informatics commits with their
authorship; all files are BSL-1.0.

  • Build: Types, Parser and XSDGen on by default; ENABLE_XSD_VALIDATOR off by default and off without
    libxml2, as SSH. CodeQL also analyses the Validator.
  • Validator: per-call libxml2 contexts, the first ten errors, DOCTYPE in the document rejected; the schema
    text is parsed without entity substitution and may not declare external DTDs or entities; schemas are trusted.
  • Parser: locations naming another network host rejected; XSD elements in xs:documentation and WSDL
    extension content no longer crash it (found by fuzzing).
  • XSDGen: Remoting attribute values that would end the generated //@ comment line are rejected.
  • Imported defects fixed; C++17 throughout, the Add attributes to symbols and noexcept specifiers #5152 attributes; unusable public API removed.
  • fix(XML): ParserEngine forwarded Expat events after an aborted parse.

The CodeQL XXE alerts on SAXParser are false positives (external entities are off by default), dismissed as #752/#754/#755.

Tests: macOS and Linux, CMake and make, C++17, ASan/UBSan/TSan, fuzzing, clang-tidy/cppcheck, each commit
on its own; XSDGen output identical on the SOAP samples.

@matejk matejk added this to the Release 2.0 milestone Sep 26, 2026
@matejk matejk added the feature label Sep 26, 2026

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

obiltschnig and others added 7 commits September 28, 2026 22:06
Flat import of platform/XSD from macchina.io (state of 2026-09-21); the Applied
Informatics changes since the common base follow as separate commits.
Not imported: samples-internal, CodeGen/data and the Validator vcpkg manifests.

Co-Authored-By: Aleksandar Fabijanic <aleks-f@users.noreply.github.com>
Co-Authored-By: Matej Kenda <matejken@gmail.com>
Co-Authored-By: Lara Dzivdzanovic <dzivdzanoviclara@gmail.com>
…orted the parse #5450

Expat calls the end-element and end-namespace handlers of an empty element after XML_StopParser(); the XSD Parser content handler popped an empty stack on the forwarded event.
… builds, CI and documentation #5450

Also GCC symbol visibility, compiler warnings, per-context libxml2 error handling, testsuite conventions and the Validator in the CodeQL build.
Comment thread XSD/CodeGen/src/main.cpp Dismissed
Comment thread XSD/Parser/src/XSDContentHandler.cpp Dismissed
Comment thread XSD/Parser/testsuite/src/XSDParserTest.cpp Dismissed
Comment thread XSD/CodeGen/src/CppGen.cpp Fixed
Comment thread XSD/CodeGen/src/CppGen.cpp Fixed
Comment thread XSD/CodeGen/src/CppGen.cpp Fixed
Comment thread XSD/Parser/src/XSDContentHandler.cpp Fixed
Comment thread XSD/Parser/src/XSDContentHandler.cpp Fixed
… concise comments #5450

Also the CodeQL notes (shadowed variables, empty if, commented-out code) and a shared parser test helper.
…ons, parser crashes, XSDGen code injection #5450

The Validator parses the schema text without entity substitution; the Parser rejects locations on other network hosts and XML Schema elements in WSDL extension content, and handles XSD elements in xs:documentation; XSDGen rejects Remoting attribute values that end the comment line.
@matejk
matejk merged commit 9876c10 into main Sep 29, 2026
59 checks passed
@matejk
matejk deleted the 5450-xsd branch September 29, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(XSD): add XSD libraries from macchina.io

4 participants