Skip to content

Fix CDATA serialization containing embedded end markers - #1099

Open
bconnnnn wants to merge 2 commits into
leethomason:masterfrom
bconnnnn:fix/cdata-terminator-1097
Open

bconnnnn wants to merge 2 commits into
leethomason:masterfrom
bconnnnn:fix/cdata-terminator-1097

Conversation

@bconnnnn

@bconnnnn bconnnnn commented Oct 9, 2026 •

Copy link
Copy Markdown

CDATA text containing ]]> currently produces malformed XML. Split each embedded terminator across adjacent CDATA sections, preserving the complete text for both document serialization and direct XMLPrinter::PushText calls.

For example, a]]>b now serializes as <r><![CDATA[a]]]]><![CDATA[>b]]></r>.

Fixes #1097.

Validation:

  • C++11 build with -Wall -Wextra -Werror -pedantic: 576 tests passed, 0 failed.
  • The same regression suite against the original implementation: 569 passed, 6 failed.
  • Tests cover both memory and FILE-backed printers, including repeated and suffix-only CDATA terminators.
  • An independent Python XML parser preserved all text across 1,008 directed and randomized cases, including the FILE-backed printer path.
  • AddressSanitizer and UndefinedBehaviorSanitizer: 576 tests passed. Leak detection was disabled because LeakSanitizer cannot inspect processes in this environment.

AI assistance: Codex helped implement and validate the change. ByteAsk web reviewed the algorithm and helped design the FILE-backed regression tests; I adapted those suggestions and compiled and ran the tests locally.

Split embedded CDATA terminators across adjacent sections and add document/direct printer round-trip regression tests. Fixes leethomason#1097.
Adapt ByteAsk web review and test-design suggestions to exercise repeated and suffix-only CDATA terminators with the FILE-backed XMLPrinter. Local C++11 and ASan/UBSan suites pass 576 tests.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CDATA output containing ]]> is not well-formed XML

1 participant