Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package jackson-dataformat-xml for 
openSUSE:Factory checked in at 2026-09-24 22:56:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/jackson-dataformat-xml (Old)
 and      /work/SRC/openSUSE:Factory/.jackson-dataformat-xml.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "jackson-dataformat-xml"

Thu Sep 24 22:56:23 2026 rev:10 rq:1380006 version:2.18.11

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/jackson-dataformat-xml/jackson-dataformat-xml.changes
    2026-07-15 17:12:30.497394815 +0200
+++ 
/work/SRC/openSUSE:Factory/.jackson-dataformat-xml.new.383539/jackson-dataformat-xml.changes
        2026-09-24 22:58:23.826580729 +0200
@@ -1,0 +2,13 @@
+Wed Sep 23 08:08:32 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.11
+  * Fix build to avoid past-JDK-8 bytecode generation
+
+-------------------------------------------------------------------
+Thu Sep 17 08:19:51 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.10
+  * #891: Enforce StreamReadConstraints.maxNestingDepth in
+    FromXmlParser
+
+-------------------------------------------------------------------

Old:
----
  jackson-dataformat-xml-2.18.9.tar.gz

New:
----
  jackson-dataformat-xml-2.18.11.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ jackson-dataformat-xml.spec ++++++
--- /var/tmp/diff_new_pack.66cwFh/_old  2026-09-24 22:58:24.415605360 +0200
+++ /var/tmp/diff_new_pack.66cwFh/_new  2026-09-24 22:58:24.416605402 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           jackson-dataformat-xml
-Version:        2.18.9
+Version:        2.18.11
 Release:        0
 Summary:        Jackson extension component for reading and writing XML 
encoded data
 License:        Apache-2.0

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.66cwFh/_old  2026-09-24 22:58:24.448606740 +0200
+++ /var/tmp/diff_new_pack.66cwFh/_new  2026-09-24 22:58:24.451606866 +0200
@@ -1,6 +1,6 @@
-mtime: 1784115492
-commit: 2ce812f7f96214f1948b2a5abf3f76b97e882c2b5be8634524a266b357308fff
+mtime: 1790150977
+commit: 568d2014726f04941e9fe255e6590baaa5482f15211a4d8fc65ac80368c7a25e
 url: https://src.opensuse.org/java-packages/jackson-dataformat-xml
-revision: 2ce812f7f96214f1948b2a5abf3f76b97e882c2b5be8634524a266b357308fff
+revision: 568d2014726f04941e9fe255e6590baaa5482f15211a4d8fc65ac80368c7a25e
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-23 10:09:37.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ jackson-dataformat-xml-2.18.9.tar.gz -> 
jackson-dataformat-xml-2.18.11.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/CLAUDE.md 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/CLAUDE.md
--- old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/CLAUDE.md  
1970-01-01 01:00:00.000000000 +0100
+++ new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/CLAUDE.md 
2026-09-21 02:49:08.000000000 +0200
@@ -0,0 +1,385 @@
+# CLAUDE.md
+
+This file provides guidance to Claude Code (claude.ai/code) when working with 
code in this repository.
+
+## Project Overview
+
+Jackson XML dataformat module extends Jackson to serialize/deserialize XML 
using the STAX (Streaming API for XML) processing engine. The goal is to 
emulate JAXB "code-first" data binding while leveraging Jackson's rich type 
system and features. This is NOT a full JAXB clone or general-purpose XML 
toolkit.
+
+**Key Principle:** Any XML written by this module MUST be readable by this 
module (guaranteed round-trip support).
+
+## Build & Test Commands
+
+This is a Maven-based project. Use the Maven wrapper (`./mvnw`) for consistent 
builds.
+
+### Basic Commands
+
+```bash
+# Clean and build
+./mvnw clean install
+
+# Run all tests
+./mvnw test
+
+# Run tests without building
+./mvnw surefire:test
+
+# Run a single test class
+./mvnw test -Dtest=XmlMapperTest
+
+# Run a single test method
+./mvnw test -Dtest=XmlMapperTest#testSimpleSerialization
+
+# Build without running tests
+./mvnw clean install -DskipTests
+
+# Generate code coverage report (JaCoCo)
+./mvnw clean test
+# Report available at: target/site/jacoco/index.html
+```
+
+### JDK Baseline & JDK-Specific Testing
+
+- Main sources compile to Java 8 bytecode (`<release>8</release>` on JDK 9+).
+- JDK 17+ specific tests live in `src/test-jdk17/java/` and are added as an 
extra
+  test source root by a Maven profile activated on `[17,)`. These cover Java 
Records
+  support and other modern language features; they compile/run with `release 
17`.
+
+### Working with Test Files
+
+- Main test sources: `src/test/java/com/fasterxml/jackson/dataformat/xml/`
+- JDK 17+ tests: `src/test-jdk17/java/com/fasterxml/jackson/dataformat/xml/`
+- **Test base class: `XmlTestUtil`** — extend this for new tests (JUnit 5 
based;
+  provides `newMapper()`, shared POJOs, and assertion helpers). All ~150 test 
classes
+  now use it.
+- `XmlTestBase` is deprecated (since 2.19), JUnit 3/4 `TestCase`-based, and no 
longer
+  extended by any test. Do not use it for new tests.
+- Tests use JUnit 5 (`org.junit.jupiter.api.Test`, static `Assertions` 
imports).
+  JUnit 4 remains on the test classpath only as a legacy dependency.
+
+## Repository Branch Structure
+
+- `2.x` — active development branch for the next 2.x minor (currently 
`2.23.0-SNAPSHOT`)
+- `2.22` — maintenance branch for the current 2.22.x patch releases (merged up 
into `2.x`)
+- `master` — 3.x development (currently `3.0.0-rc3-SNAPSHOT`)
+- When creating PRs against 2.x work, target `2.x` (or the relevant 
maintenance branch
+  if the fix must ship in a patch release).
+
+Version numbers are inherited from the `com.fasterxml.jackson:jackson-base` 
parent POM.
+
+## High-Level Architecture
+
+### Core Components Flow
+
+```
+User Code
+    ↓
+XmlMapper (extends ObjectMapper) ← Primary API entry point
+    ↓
+XmlFactory (extends JsonFactory) ← Creates parsers/generators
+    ├→ FromXmlParser (XML → JSON token stream)
+    │    ├─ XmlTokenStream (STAX abstraction layer)
+    │    └─ XMLStreamReader (Woodstox)
+    │
+    └→ ToXmlGenerator (JSON token stream → XML)
+         └─ XMLStreamWriter (Woodstox)
+```
+
+### Builder-Style Construction
+
+Both mapper and factory support the 2.x builder API (preferred over legacy 
constructors):
+
+```java
+XmlMapper mapper = XmlMapper.builder()
+    .enable(ToXmlGenerator.Feature.WRITE_XML_DECLARATION)
+    .defaultUseWrapper(false)
+    .build();
+```
+
+`XmlMapper.Builder` extends `MapperBuilder`; `XmlFactoryBuilder` configures the
+`XMLInputFactory`/`XMLOutputFactory`, the `XmlNameProcessor`, and 
parser/generator
+format features.
+
+### Module Registration System
+
+`JacksonXmlModule` (a `SimpleModule`) centralizes XML-specific configuration:
+- Registers `XmlBeanSerializerModifier` - hooks into serializer creation
+- Registers `XmlBeanDeserializerModifier` - hooks into deserializer creation
+- Adds `JacksonXmlAnnotationIntrospector` - processes @JacksonXml* annotations
+- Configures text element naming conventions
+
+Module is automatically registered when creating an `XmlMapper`.
+
+### Serialization Pipeline (Object → XML)
+
+```
+Object
+  → XmlMapper.writeValue()
+  → ToXmlGenerator (implements JsonGenerator)
+  → XmlBeanSerializerModifier (customizes bean serializers)
+  → XmlBeanSerializer + XmlBeanPropertyWriter
+     ├─ Determines element vs attribute
+     ├─ Handles namespace mappings
+     └─ Manages wrapper elements for collections
+  → XmlSerializerProvider (handles root element naming)
+  → XMLStreamWriter (Woodstox STAX)
+  → XML Output
+```
+
+**Key Classes:**
+- `XmlBeanSerializerBase` / `XmlBeanSerializer` - Extend Jackson's 
`BeanSerializer` with XML-specific logic
+- `XmlBeanPropertyWriter` - Determines if property is element or attribute
+- `UnwrappingXmlBeanSerializer` - Handles `@JsonUnwrapped` properties
+- `XmlRootNameLookup` - Caches root element name calculations
+- `DefaultXmlPrettyPrinter` (implements `XmlPrettyPrinter`) - XML-aware 
formatting
+
+### Deserialization Pipeline (XML → Object)
+
+```
+XML Input
+  → XMLStreamReader (STAX/Woodstox)
+  → FromXmlParser (implements JsonParser)
+  → XmlTokenStream (converts XML events to JSON tokens)
+     ├─ START_ELEMENT → START_OBJECT
+     ├─ Attributes → FIELD_NAME + VALUE pairs
+     ├─ Text content → VALUE_STRING (field name = "")
+     └─ END_ELEMENT → END_OBJECT
+  → XmlBeanDeserializerModifier (customizes deserializers)
+     ├─ Renames wrapper properties
+     ├─ Handles @JacksonXmlText
+     └─ Manages collection wrapping/unwrapping
+  → Standard Jackson Deserializers
+  → Object
+```
+
+**Key Classes:**
+- `FromXmlParser` - Wraps STAX reader, exposes JSON-like token stream
+- `XmlTokenStream` - Intermediate abstraction with token replay/lookahead
+- `WrapperHandlingDeserializer` - Handles wrapped/unwrapped collections
+- `ElementWrapper` / `ElementWrappable` - Wrapper-name metadata plumbing
+- `XmlReadContext` - Tracks parsing context (current element, namespace)
+- `XmlDeserializationContext` - XML-specific `DeserializationContext` subclass
+- `XmlTextDeserializer` - Deserializes element text content
+
+### Collection Wrapping Pattern
+
+A critical XML-specific concern is how collections are represented:
+
+**Wrapped (default behavior):**
+```xml
+<items>
+  <item>A</item>
+  <item>B</item>
+</items>
+```
+
+**Unwrapped:**
+```xml
+<item>A</item>
+<item>B</item>
+```
+
+Control via:
+- `@JacksonXmlElementWrapper(useWrapping = false)` per property
+- `XmlMapper.builder().defaultUseWrapper(false)` (or 
`JacksonXmlModule.setDefaultUseWrapper(false)`) globally
+- `WrapperHandlingDeserializer` implements the complex logic
+
+### Annotation System
+
+**Jackson XML Annotations** 
(`com.fasterxml.jackson.dataformat.xml.annotation`):
+- `@JacksonXmlRootElement` - Set root element name/namespace
+- `@JacksonXmlProperty(isAttribute=true)` - Mark property as XML attribute
+- `@JacksonXmlElementWrapper` - Control collection wrapper elements
+- `@JacksonXmlText` - Property represents element text content (not a child 
element)
+- `@JacksonXmlCData` - Wrap value in CDATA section
+
+**JAXB Support:**
+Uses optional `jackson-module-jakarta-xmlbind-annotations` dependency. The 
`XmlJaxbAnnotationIntrospector` can process JAXB annotations for 
interoperability.
+
+**Polymorphic Type Handling:**
+`XmlTypeResolverBuilder` and `DefaultingXmlTypeResolverBuilder` adapt 
Jackson's type
+resolution (`@JsonTypeInfo`, default typing) to XML — notably making 
`As.PROPERTY`
+inclusion work as an XML attribute.
+
+### STAX Integration
+
+**Woodstox** is the preferred STAX implementation (faster and more reliable 
than JDK's default).
+
+**Factory Configuration:**
+- `XmlFactory` manages `XMLInputFactory` and `XMLOutputFactory`
+- Security defaults: external entities disabled, DTD processing disabled
+- `IS_REPAIRING_NAMESPACES = true` for automatic namespace handling
+- `IS_COALESCING = true` to simplify text content processing
+- `Stax2JacksonReaderAdapter` bridges non-Woodstox (Stax2-less) readers
+
+**Custom STAX Configuration Example:**
+```java
+XMLInputFactory ifactory = new WstxInputFactory();
+ifactory.setProperty(WstxInputProperties.P_MAX_ATTRIBUTE_SIZE, 32000);
+XmlFactory xf = XmlFactory.builder()
+    .xmlInputFactory(ifactory)
+    .build();
+XmlMapper mapper = new XmlMapper(xf);
+```
+
+### Name Processing
+
+`XmlNameProcessor` allows custom XML name transformations, configured via
+`XmlFactoryBuilder.nameProcessor(...)` and applied during both serialization 
and
+deserialization. `XmlNameProcessors` provides ready-made implementations:
+`newPassthroughProcessor()` (default), `newReplacementProcessor()`,
+`newBase64Processor()`, and `newAlwaysOnBase64Processor()` — the latter two 
encode
+names that are not valid XML names.
+
+### Feature Flags
+
+**FromXmlParser.Feature** (deserialization) — the complete set:
+- `AUTO_DETECT_XSI_TYPE` (default off) - Process `xsi:type` attributes for 
polymorphism
+- `EMPTY_ELEMENT_AS_NULL` (default off) - Treat `<element/>` as null
+- `PROCESS_XSI_NIL` (default **on**) - Honor `xsi:nil="true"`
+
+(Note: `ENFORCE_VALID_ROOT_NAME` appears in the source but is commented out — 
it is
+not an available feature.)
+
+**ToXmlGenerator.Feature** (serialization) — the complete set:
+- `WRITE_XML_DECLARATION` - Output `<?xml version="1.0"?>`
+- `WRITE_STANDALONE_YES_TO_XML_DECLARATION` - Add `standalone="yes"` (needs 
the above)
+- `WRITE_XML_1_1` - Use XML 1.1
+- `WRITE_NULLS_AS_XSI_NIL` - Add `xsi:nil="true"` for null values
+- `UNWRAP_ROOT_OBJECT_NODE` - For a single-entry root `ObjectNode`, use its 
key as
+  root element name (will default to enabled in 3.0)
+- `AUTO_DETECT_XSI_TYPE` - Add `xsi:type` for polymorphic types
+- `WRITE_XML_SCHEMA_CONFORMING_FLOATS` - Emit `INF`/`-INF`/`NaN` per XML Schema
+  (will default to enabled in 3.0)
+
+All default to disabled except `PROCESS_XSI_NIL` on the parser side.
+Configure via `XmlMapper.builder().enable(...)/.disable(...)`, or
+`XmlMapper.enable(feature)` / `XmlMapper.disable(feature)`.
+
+## Source Code Structure
+
+```
+src/main/java/com/fasterxml/jackson/dataformat/xml/
+├── XmlMapper.java              - Primary API, extends ObjectMapper (has 
Builder)
+├── XmlFactory.java             - Creates parsers/generators
+├── XmlFactoryBuilder.java      - Builder for XmlFactory (STAX factories, name 
processor)
+├── JacksonXmlModule.java       - Module for XML configuration
+├── JacksonXmlAnnotationIntrospector.java / XmlAnnotationIntrospector.java
+├── XmlTypeResolverBuilder.java / DefaultingXmlTypeResolverBuilder.java
+├── XmlNameProcessor.java / XmlNameProcessors.java  - XML name transformation
+├── XmlPrettyPrinter.java
+├── annotation/                 - @JacksonXml* annotations
+├── deser/                      - Deserialization (XML → Object)
+│   ├── FromXmlParser.java      - Parser implementation
+│   ├── XmlTokenStream.java     - STAX abstraction layer
+│   ├── XmlBeanDeserializerModifier.java
+│   ├── WrapperHandlingDeserializer.java
+│   ├── ElementWrapper.java / ElementWrappable.java
+│   ├── XmlDeserializationContext.java / XmlReadContext.java
+│   └── XmlTextDeserializer.java
+├── ser/                        - Serialization (Object → XML)
+│   ├── ToXmlGenerator.java     - Generator implementation
+│   ├── XmlBeanSerializer.java / XmlBeanSerializerBase.java
+│   ├── UnwrappingXmlBeanSerializer.java
+│   ├── XmlBeanPropertyWriter.java
+│   ├── XmlBeanSerializerModifier.java
+│   └── XmlSerializerProvider.java
+├── jaxb/                       - JAXB integration
+│   └── XmlJaxbAnnotationIntrospector.java
+└── util/                       - Utilities
+    ├── StaxUtil.java                  - STAX exception handling
+    ├── XmlRootNameLookup.java         - Root element naming
+    ├── DefaultXmlPrettyPrinter.java
+    ├── Stax2JacksonReaderAdapter.java
+    ├── AnnotationUtil.java / TypeUtil.java / XmlInfo.java
+    └── CaseInsensitiveNameSet.java
+
+src/test/java/.../xml/
+├── deser/                      - Deserialization tests (+ builder/, convert/, 
creator/)
+├── ser/                        - Serialization tests (+ dos/)
+├── stream/                     - Low-level parser/generator tests (+ dos/)
+├── lists/                      - Collection handling tests
+├── node/                       - Tree model (JsonNode) tests
+├── misc/                       - Assorted feature tests
+├── adapters/, incr/, interop/, jaxb/, vld/, woodstox/
+├── fuzz/                       - Regression tests from OSS-Fuzz findings
+├── tofix/                      - Tests for known issues (see below)
+├── testutil/                   - Test helpers (+ failure/ annotations)
+├── XmlTestUtil.java            - Base test class for new tests
+└── XmlTestBase.java            - Deprecated, unused legacy base class
+
+src/test-jdk17/java/.../xml/
+├── jdk17/                      - JDK 17+ feature tests
+└── records/                    - Java Records support tests (+ tofix/)
+```
+
+## Test Organization
+
+- Tests are organized by feature area (deser, ser, lists, stream, node, etc.)
+- Issue-specific tests named like `RootName374Test.java` (GitHub issue #374)
+- `tofix/` holds tests for known limitations/bugs. These extend `XmlTestUtil` 
and are
+  annotated `@JacksonTestFailureExpected` (see `testutil/failure/`), which 
inverts the
+  result: the test *fails* the build if it unexpectedly starts passing. When 
you fix a
+  bug, remove the annotation and move the test into the proper package.
+- `fuzz/` holds regression tests for OSS-Fuzz reports; `*/dos/` holds
+  denial-of-service / resource-limit tests.
+- JDK 17+ tests in a separate source directory, auto-enabled by Maven profile.
+
+## Known Limitations
+
+- **Tree Model** (`JsonNode`): Does not perfectly match XML infoset
+  - Mixed content (text + elements) not fully supported
+  - Repeated elements handled specially (see #403)
+- **Root Values**: Work best with POJOs; primitives, Strings, Collections have 
limitations
+- **Collection Wrapping**: Default behavior differs between Jackson and JAXB 
annotations
+- **Namespace URIs**: Not verified during deserialization (only local names 
matched)
+- **Polymorphic Types**: Some inclusion mechanisms unsupported (e.g., 
`WRAPPER_ARRAY`)
+
+See README.md "Known Limitations" section for complete list.
+
+## Development Notes
+
+### Release Notes
+Every user-visible change gets an entry in `release-notes/VERSION-2.x` (issue 
number,
+one-line description, credit line) and, for external contributors, 
`release-notes/CREDITS-2.x`.
+
+### Security
+- External entity expansion disabled by default (XXE prevention)
+- DTD processing disabled
+- These are configured in `XmlFactory` constructor
+
+### Streaming vs Databinding
+- Low-level streaming (direct `FromXmlParser`/`ToXmlGenerator` use) is 
possible but not primary use case
+- Databinding layer includes necessary XML-specific workarounds
+- For incremental/partial reading/writing, combine STAX APIs with `XmlMapper` 
(see `incr/` tests)
+
+### Modifying Serializers/Deserializers
+Use the Modifier pattern:
+- Extend `XmlBeanSerializerModifier` for serialization customization
+- Extend `XmlBeanDeserializerModifier` for deserialization customization
+- Register via `JacksonXmlModule` or custom module
+
+### Adding New Features
+1. Consider if it's a parser/generator feature (token stream level) or 
serializer/deserializer feature (databinding level)
+2. Parser/Generator: Modify `FromXmlParser`/`ToXmlGenerator` and potentially 
`XmlTokenStream`
+3. Databinding: Use Modifier pattern or custom 
`JsonSerializer`/`JsonDeserializer`
+4. Add feature flag if it's optional behavior (defaults must stay 
backwards-compatible in 2.x)
+5. Add tests in appropriate subdirectory, extending `XmlTestUtil`
+6. Add a release-notes entry
+
+## Dependencies
+
+**Core (compile):**
+- `jackson-core`, `jackson-databind`, `jackson-annotations` (from parent BOM)
+- `stax2-api` (enhanced STAX API)
+- `woodstox-core` (STAX implementation)
+- `stax-api` (`provided` scope only, for old JDK compatibility)
+
+**Test:**
+- JUnit 5 (`junit-jupiter`, `junit-jupiter-api`) — used by all tests
+- JUnit 4 (`junit`) — legacy, only for the deprecated `XmlTestBase`
+- `jackson-module-jakarta-xmlbind-annotations` + `jakarta.xml.bind-api` (JAXB 
interop testing)
+- `sjsxp` (alternative STAX impl for testing)
+
+**Version Management:**
+Versions inherited from `com.fasterxml.jackson:jackson-base` parent POM, which 
manages the Jackson BOM (bill of materials).
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/pom.xml 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/pom.xml
--- old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/pom.xml    
2026-07-08 02:40:42.000000000 +0200
+++ new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/pom.xml   
2026-09-21 02:49:08.000000000 +0200
@@ -9,11 +9,11 @@
   <parent>
     <groupId>com.fasterxml.jackson</groupId>
     <artifactId>jackson-base</artifactId>
-    <version>2.18.9</version>
+    <version>2.18.11</version>
   </parent>
   <groupId>com.fasterxml.jackson.dataformat</groupId>
   <artifactId>jackson-dataformat-xml</artifactId>
-  <version>2.18.9</version>
+  <version>2.18.11</version>
   <name>Jackson-dataformat-XML</name>
   <packaging>jar</packaging>
   <description>Data format extension for Jackson to offer
@@ -24,7 +24,7 @@
     
<connection>scm:git:[email protected]:FasterXML/jackson-dataformat-xml.git</connection>
     
<developerConnection>scm:git:[email protected]:FasterXML/jackson-dataformat-xml.git</developerConnection>
     <url>http://github.com/FasterXML/jackson-dataformat-xml</url>    
-    <tag>jackson-dataformat-xml-2.18.9</tag>
+    <tag>jackson-dataformat-xml-2.18.11</tag>
   </scm>
   <properties>
     
<packageVersion.dir>com/fasterxml/jackson/dataformat/xml</packageVersion.dir>
@@ -34,7 +34,7 @@
     <!-- And presumably import too? -->
 
     <!-- for Reproducible Builds -->
-    
<project.build.outputTimestamp>2026-07-08T00:40:28Z</project.build.outputTimestamp>
+    
<project.build.outputTimestamp>2026-09-21T00:48:53Z</project.build.outputTimestamp>
   </properties>
 
   <dependencies>
@@ -212,6 +212,36 @@
 
   <profiles>
     <profile>
+      <!-- Guarantee Java 8 compatible main classes even when the build runs 
on a
+           later JDK: "release 8" pins both the bytecode version (52) and the
+           visible JDK API, unlike inherited source/target 1.8 which only pins
+           bytecode. Cannot be enabled unconditionally since javac 8 itself has
+           no "release" option, hence activation on JDK 9 and above.
+        -->
+      <id>java8-bytecode</id>
+      <activation>
+        <jdk>[9,)</jdk>
+      </activation>
+      <build>
+        <plugins>
+          <plugin>
+            <groupId>org.apache.maven.plugins</groupId>
+            <artifactId>maven-compiler-plugin</artifactId>
+            <inherited>true</inherited>
+            <executions>
+              <execution>
+                <id>default-compile</id>
+                <configuration>
+                  <release>8</release>
+                </configuration>
+              </execution>
+            </executions>
+          </plugin>
+        </plugins>
+      </build>
+    </profile>
+
+    <profile>
       <!-- And different set up for JDK 17 -->
       <id>java17</id>
       <activation>
@@ -241,16 +271,25 @@
             <groupId>org.apache.maven.plugins</groupId>
             <artifactId>maven-compiler-plugin</artifactId>
             <inherited>true</inherited>
-            <configuration>
-              <!-- Enable Java 17 for all sources so that Intellij picks the 
right language level -->
-              <source>17</source>
-              <release>17</release>
-              <compilerArgs>
-                <arg>-parameters</arg>
-                <arg>--add-opens=java.base/java.lang=ALL-UNNAMED</arg>
-                <arg>--add-opens=java.base/java.util=ALL-UNNAMED</arg>
-              </compilerArgs>
-            </configuration>
+            <executions>
+              <execution>
+                <!-- Enable Java 17 for TEST sources only (needs 
"src/test-jdk17/java"
+                     above); main sources must keep producing Java 8 bytecode 
no matter
+                     which JDK the build runs on, so this must NOT be 
plugin-level
+                     configuration (which would apply to "default-compile" too)
+                  -->
+                <id>default-testCompile</id>
+                <configuration>
+                  <source>17</source>
+                  <release>17</release>
+                  <compilerArgs>
+                    <arg>-parameters</arg>
+                    <arg>--add-opens=java.base/java.lang=ALL-UNNAMED</arg>
+                    <arg>--add-opens=java.base/java.util=ALL-UNNAMED</arg>
+                  </compilerArgs>
+                </configuration>
+              </execution>
+            </executions>
           </plugin>
           <plugin>
             <groupId>org.apache.maven.plugins</groupId>
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/CREDITS-2.x
 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/CREDITS-2.x
--- 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/CREDITS-2.x
  2026-07-08 02:40:42.000000000 +0200
+++ 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/CREDITS-2.x
 2026-09-21 02:49:08.000000000 +0200
@@ -271,3 +271,9 @@
 * Reported, contributed fix for #646: Deserializing fails when using builder 
classes
   with `Iterable` Collection setters
  (2.17.1)
+
+Sahana (@Sahana2524)
+
+* Contributed #891: Enforce `StreamReadConstraints.maxNestingDepth` in
+  `FromXmlParser`
+ (2.18.10)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/VERSION-2.x
 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/VERSION-2.x
--- 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/VERSION-2.x
  2026-07-08 02:40:42.000000000 +0200
+++ 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/VERSION-2.x
 2026-09-21 02:49:08.000000000 +0200
@@ -4,6 +4,15 @@
 === Releases ===
 ------------------------------------------------------------------------
 
+2.18.11 (20-Sep-2026)
+
+- Fix build to avoid past-JDK-8 bytecode generation
+
+2.18.10 (15-Aug-2026)
+
+#891: Enforce `StreamReadConstraints.maxNestingDepth` in `FromXmlParser`
+ (contributed by @Sahana2524)
+
 2.18.9 (07-Jul-2026)
 
 No changes since 2.18.8
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
--- 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
        2026-07-08 02:40:42.000000000 +0200
+++ 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
       2026-09-21 02:49:08.000000000 +0200
@@ -715,10 +715,10 @@
 
             switch (t) {
             case START_OBJECT:
-                _parsingContext = _parsingContext.createChildObjectContext(-1, 
-1);
+                _createChildObjectContext();
                 break;
             case START_ARRAY:
-                _parsingContext = _parsingContext.createChildArrayContext(-1, 
-1);
+                _createChildArrayContext();
                 break;
             case END_OBJECT:
             case END_ARRAY:
@@ -751,7 +751,7 @@
             if (_mayBeLeaf) {
                 // leave _mayBeLeaf set, as we start a new context
                 _nextToken = JsonToken.FIELD_NAME;
-                _parsingContext = _parsingContext.createChildObjectContext(-1, 
-1);
+                _createChildObjectContext();
                 return _updateToken(JsonToken.START_OBJECT);
             }
             if (_parsingContext.inArray()) {
@@ -787,7 +787,7 @@
                         // 06-Jan-2015, tatu: as per [dataformat-xml#180], 
need to
                         //    expose as empty Object, not null
                         _nextToken = JsonToken.END_OBJECT;
-                        _parsingContext = 
_parsingContext.createChildObjectContext(-1, -1);
+                        _createChildObjectContext();
                         return _updateToken(JsonToken.START_OBJECT);
                     }
                     // 07-Sep-2019, tatu: for [dataformat-xml#353], must NOT 
return second null
@@ -807,7 +807,7 @@
                     _mayBeLeaf = false;
                     _nextToken = JsonToken.FIELD_NAME;
                     _currText = _xmlTokens.getText();
-                    _parsingContext = 
_parsingContext.createChildObjectContext(-1, -1);
+                    _createChildObjectContext();
                     return _updateToken(JsonToken.START_OBJECT);
                 }
                 _parsingContext.setCurrentName(_xmlTokens.getLocalName());
@@ -837,7 +837,7 @@
                                 //    expose as empty Object, not null (or, 
worse, as used to
                                 //    be done, by swallowing the token)
                                 _nextToken = JsonToken.END_OBJECT;
-                                _parsingContext = 
_parsingContext.createChildObjectContext(-1, -1);
+                                _createChildObjectContext();
                                 return _updateToken(JsonToken.START_OBJECT);
                             }
                         }
@@ -851,7 +851,7 @@
                     // fall-through, except must create new context AND push 
back
                     // START_ELEMENT we just saw:
                     _xmlTokens.pushbackCurrentToken();
-                    _parsingContext = 
_parsingContext.createChildObjectContext(-1, -1);
+                    _createChildObjectContext();
                 }
                 // [dataformat-xml#177]: empty text may also need to be skipped
                 // but... [dataformat-xml#191]: looks like we can't short-cut, 
must
@@ -945,7 +945,7 @@
         while (token == XmlTokenStream.XML_START_ELEMENT) {
             if (_mayBeLeaf) {
                 _nextToken = JsonToken.FIELD_NAME;
-                _parsingContext = _parsingContext.createChildObjectContext(-1, 
-1);
+                _createChildObjectContext();
                 _updateToken(JsonToken.START_OBJECT);
                 return null;
             }
@@ -989,7 +989,7 @@
                 _mayBeLeaf = false;
                 _nextToken = JsonToken.FIELD_NAME;
                 _currText = _xmlTokens.getText();
-                _parsingContext = _parsingContext.createChildObjectContext(-1, 
-1);
+                _createChildObjectContext();
                 _updateToken(JsonToken.START_OBJECT);
             } else {
                 _parsingContext.setCurrentName(_xmlTokens.getLocalName());
@@ -1028,14 +1028,14 @@
     }
 
 
-    private void _updateState(JsonToken t)
+    private void _updateState(JsonToken t) throws IOException
     {
         switch (t) {
         case START_OBJECT:
-            _parsingContext = _parsingContext.createChildObjectContext(-1, -1);
+            _createChildObjectContext();
             break;
         case START_ARRAY:
-            _parsingContext = _parsingContext.createChildArrayContext(-1, -1);
+            _createChildArrayContext();
             break;
         case END_OBJECT:
         case END_ARRAY:
@@ -1049,6 +1049,21 @@
         }
     }
 
+    // Enter a nested Object/Array scope, honoring the configured
+    // StreamReadConstraints.maxNestingDepth(). JsonReadContext has always
+    // tracked the depth but the read path never checked it, so a configured
+    // limit had no effect on XML input; ToXmlGenerator already does the
+    // equivalent check on the write side.
+    private void _createChildObjectContext() throws IOException {
+        _parsingContext = _parsingContext.createChildObjectContext(-1, -1);
+        
streamReadConstraints().validateNestingDepth(_parsingContext.getNestingDepth());
+    }
+
+    private void _createChildArrayContext() throws IOException {
+        _parsingContext = _parsingContext.createChildArrayContext(-1, -1);
+        
streamReadConstraints().validateNestingDepth(_parsingContext.getNestingDepth());
+    }
+
     /*
     /**********************************************************
     /* Public API, access to token information, text
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
--- 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
   2026-07-08 02:40:42.000000000 +0200
+++ 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
  2026-09-21 02:49:08.000000000 +0200
@@ -1,8 +1,11 @@
 package com.fasterxml.jackson.dataformat.xml.stream.dos;
 
 import com.fasterxml.jackson.core.JsonParser;
+import com.fasterxml.jackson.core.StreamReadConstraints;
+import com.fasterxml.jackson.core.exc.StreamConstraintsException;
 import com.fasterxml.jackson.core.exc.StreamReadException;
 
+import com.fasterxml.jackson.dataformat.xml.XmlFactory;
 import com.fasterxml.jackson.dataformat.xml.XmlMapper;
 import com.fasterxml.jackson.dataformat.xml.XmlTestBase;
 
@@ -20,6 +23,26 @@
         }
     }
 
+    // jackson-core's StreamReadConstraints.maxNestingDepth is now enforced on 
the
+    // XML read path (previously ignored); verify with a low configured limit 
that
+    // stays well within the default Stax element-depth limit (1000), so the
+    // rejection is unambiguously due to the nesting-depth check.
+    public void testDeepDocWithLowNestingLimit() throws Exception
+    {
+        final XmlMapper xmlMapper = mapperBuilder(XmlFactory.builder()
+                .streamReadConstraints(StreamReadConstraints.builder()
+                        .maxNestingDepth(10).build())
+                .build()).build();
+        final String XML = createDeepNestedDoc(50);
+        try (JsonParser p = xmlMapper.createParser(XML)) {
+            while (p.nextToken() != null) { }
+            fail("expected StreamConstraintsException");
+        } catch (StreamConstraintsException e) {
+            assertTrue("Unexpected message: " + e.getMessage(),
+                    e.getMessage().contains("nesting depth"));
+        }
+    }
+
     private String createDeepNestedDoc(final int depth) {
         StringBuilder sb = new StringBuilder();
         sb.append("<root>");
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
--- 
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
     2026-07-08 02:40:42.000000000 +0200
+++ 
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
    2026-09-21 02:49:08.000000000 +0200
@@ -3,7 +3,9 @@
 import com.ctc.wstx.stax.WstxInputFactory;
 
 import com.fasterxml.jackson.core.JsonParser;
+import com.fasterxml.jackson.core.StreamReadConstraints;
 
+import com.fasterxml.jackson.dataformat.xml.XmlFactory;
 import com.fasterxml.jackson.dataformat.xml.XmlMapper;
 import com.fasterxml.jackson.dataformat.xml.XmlTestBase;
 
@@ -15,7 +17,14 @@
     {
         final WstxInputFactory wstxInputFactory = new WstxInputFactory();
         wstxInputFactory.getConfig().setMaxElementDepth(2000);
-        final XmlMapper xmlMapper = new XmlMapper(wstxInputFactory);
+        // match the raised Stax element-depth limit so the jackson-core
+        // nesting-depth limit does not reject this deliberately deep doc
+        final XmlFactory factory = XmlFactory.builder()
+                .xmlInputFactory(wstxInputFactory)
+                .streamReadConstraints(StreamReadConstraints.builder()
+                        .maxNestingDepth(2000).build())
+                .build();
+        final XmlMapper xmlMapper = new XmlMapper(factory);
         final String XML = createDeepNestedDoc(1050);
         try (JsonParser p = xmlMapper.createParser(XML)) {
             while (p.nextToken() != null) { }

Reply via email to