Skip to content

feat(xslt): implement standalone XSLT engine - #157

Closed
polaz wants to merge 26 commits into
mainfrom
feat/#141-xslt-engine
Closed

polaz wants to merge 26 commits into
mainfrom
feat/#141-xslt-engine

Conversation

@polaz

@polaz polaz commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

Summary

  • add a standalone safe-Rust XSLT 1.0 engine with XPath, EXSLT, serialization, resolver, clock, and typed budget contracts
  • provide the bounded XSLT capability boundary needed for XML-security policy integration while replacing the remaining quick-xml paths with shared bounded XML input handling
  • vendor the complete pinned libxslt oracle corpus and safe DOM/XPath foundations, with standards-backed strict behavior and explicit compatibility cases
  • add backend, encoding, no-std, CI, release, documentation, and reviewer fixture-scope support required by the complete feature
  • make XPath sum() deterministic in document order, enforce complete oracle-output comparisons, and bound cloned CDATA metadata
  • honor XInclude text encoding precedence and reserve terminating-message growth before allocation

Validation

  • cargo nextest run --workspace --all-features --no-fail-fast (3089 passed)
  • cargo nextest run -p xml-sec-xslt --test libxslt_oracle --no-fail-fast (26 passed)
  • cargo test --doc --workspace --all-features (15 passed)
  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo build --workspace --all-features
  • alloc-only host and wasm32-unknown-unknown checks
  • support-crate version guard fixture and shellcheck
  • 30 repeated Linux runs of the previously intermittent oracle case

Closes #141

Summary by CodeRabbit

  • New Features
    • Added XML byte parsing with strict encoding detection, transcoding, and configurable size limits.
    • Added an XSLT 1.0 engine with XML, HTML, and text output, resource budgets, and caller-controlled external resource access.
    • Added configurable namespace-binding limits and caller-controlled XInclude and clock access during transformations.
  • Bug Fixes
    • Improved certificate revocation checks and made XPath lang() comparisons case-insensitive.
    • XML parsing and transformation operations now apply consistent resource limits.
  • Documentation
    • Expanded guidance on XML capabilities, backends, interoperability, and specifications.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(xslt): implement complete XSLT 1.0 engine

1 participant