Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package jackson-dataformat-xml for
openSUSE:Factory checked in at 2026-09-24 22:56:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/jackson-dataformat-xml (Old)
and /work/SRC/openSUSE:Factory/.jackson-dataformat-xml.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "jackson-dataformat-xml"
Thu Sep 24 22:56:23 2026 rev:10 rq:1380006 version:2.18.11
Changes:
--------
---
/work/SRC/openSUSE:Factory/jackson-dataformat-xml/jackson-dataformat-xml.changes
2026-07-15 17:12:30.497394815 +0200
+++
/work/SRC/openSUSE:Factory/.jackson-dataformat-xml.new.383539/jackson-dataformat-xml.changes
2026-09-24 22:58:23.826580729 +0200
@@ -1,0 +2,13 @@
+Wed Sep 23 08:08:32 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.11
+ * Fix build to avoid past-JDK-8 bytecode generation
+
+-------------------------------------------------------------------
+Thu Sep 17 08:19:51 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.10
+ * #891: Enforce StreamReadConstraints.maxNestingDepth in
+ FromXmlParser
+
+-------------------------------------------------------------------
Old:
----
jackson-dataformat-xml-2.18.9.tar.gz
New:
----
jackson-dataformat-xml-2.18.11.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ jackson-dataformat-xml.spec ++++++
--- /var/tmp/diff_new_pack.66cwFh/_old 2026-09-24 22:58:24.415605360 +0200
+++ /var/tmp/diff_new_pack.66cwFh/_new 2026-09-24 22:58:24.416605402 +0200
@@ -17,7 +17,7 @@
Name: jackson-dataformat-xml
-Version: 2.18.9
+Version: 2.18.11
Release: 0
Summary: Jackson extension component for reading and writing XML
encoded data
License: Apache-2.0
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.66cwFh/_old 2026-09-24 22:58:24.448606740 +0200
+++ /var/tmp/diff_new_pack.66cwFh/_new 2026-09-24 22:58:24.451606866 +0200
@@ -1,6 +1,6 @@
-mtime: 1784115492
-commit: 2ce812f7f96214f1948b2a5abf3f76b97e882c2b5be8634524a266b357308fff
+mtime: 1790150977
+commit: 568d2014726f04941e9fe255e6590baaa5482f15211a4d8fc65ac80368c7a25e
url: https://src.opensuse.org/java-packages/jackson-dataformat-xml
-revision: 2ce812f7f96214f1948b2a5abf3f76b97e882c2b5be8634524a266b357308fff
+revision: 568d2014726f04941e9fe255e6590baaa5482f15211a4d8fc65ac80368c7a25e
projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-09-23 10:09:37.000000000 +0200
@@ -0,0 +1 @@
+.osc
++++++ jackson-dataformat-xml-2.18.9.tar.gz ->
jackson-dataformat-xml-2.18.11.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/CLAUDE.md
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/CLAUDE.md
--- old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/CLAUDE.md
1970-01-01 01:00:00.000000000 +0100
+++ new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/CLAUDE.md
2026-09-21 02:49:08.000000000 +0200
@@ -0,0 +1,385 @@
+# CLAUDE.md
+
+This file provides guidance to Claude Code (claude.ai/code) when working with
code in this repository.
+
+## Project Overview
+
+Jackson XML dataformat module extends Jackson to serialize/deserialize XML
using the STAX (Streaming API for XML) processing engine. The goal is to
emulate JAXB "code-first" data binding while leveraging Jackson's rich type
system and features. This is NOT a full JAXB clone or general-purpose XML
toolkit.
+
+**Key Principle:** Any XML written by this module MUST be readable by this
module (guaranteed round-trip support).
+
+## Build & Test Commands
+
+This is a Maven-based project. Use the Maven wrapper (`./mvnw`) for consistent
builds.
+
+### Basic Commands
+
+```bash
+# Clean and build
+./mvnw clean install
+
+# Run all tests
+./mvnw test
+
+# Run tests without building
+./mvnw surefire:test
+
+# Run a single test class
+./mvnw test -Dtest=XmlMapperTest
+
+# Run a single test method
+./mvnw test -Dtest=XmlMapperTest#testSimpleSerialization
+
+# Build without running tests
+./mvnw clean install -DskipTests
+
+# Generate code coverage report (JaCoCo)
+./mvnw clean test
+# Report available at: target/site/jacoco/index.html
+```
+
+### JDK Baseline & JDK-Specific Testing
+
+- Main sources compile to Java 8 bytecode (`<release>8</release>` on JDK 9+).
+- JDK 17+ specific tests live in `src/test-jdk17/java/` and are added as an
extra
+ test source root by a Maven profile activated on `[17,)`. These cover Java
Records
+ support and other modern language features; they compile/run with `release
17`.
+
+### Working with Test Files
+
+- Main test sources: `src/test/java/com/fasterxml/jackson/dataformat/xml/`
+- JDK 17+ tests: `src/test-jdk17/java/com/fasterxml/jackson/dataformat/xml/`
+- **Test base class: `XmlTestUtil`** — extend this for new tests (JUnit 5
based;
+ provides `newMapper()`, shared POJOs, and assertion helpers). All ~150 test
classes
+ now use it.
+- `XmlTestBase` is deprecated (since 2.19), JUnit 3/4 `TestCase`-based, and no
longer
+ extended by any test. Do not use it for new tests.
+- Tests use JUnit 5 (`org.junit.jupiter.api.Test`, static `Assertions`
imports).
+ JUnit 4 remains on the test classpath only as a legacy dependency.
+
+## Repository Branch Structure
+
+- `2.x` — active development branch for the next 2.x minor (currently
`2.23.0-SNAPSHOT`)
+- `2.22` — maintenance branch for the current 2.22.x patch releases (merged up
into `2.x`)
+- `master` — 3.x development (currently `3.0.0-rc3-SNAPSHOT`)
+- When creating PRs against 2.x work, target `2.x` (or the relevant
maintenance branch
+ if the fix must ship in a patch release).
+
+Version numbers are inherited from the `com.fasterxml.jackson:jackson-base`
parent POM.
+
+## High-Level Architecture
+
+### Core Components Flow
+
+```
+User Code
+ ↓
+XmlMapper (extends ObjectMapper) ← Primary API entry point
+ ↓
+XmlFactory (extends JsonFactory) ← Creates parsers/generators
+ ├→ FromXmlParser (XML → JSON token stream)
+ │ ├─ XmlTokenStream (STAX abstraction layer)
+ │ └─ XMLStreamReader (Woodstox)
+ │
+ └→ ToXmlGenerator (JSON token stream → XML)
+ └─ XMLStreamWriter (Woodstox)
+```
+
+### Builder-Style Construction
+
+Both mapper and factory support the 2.x builder API (preferred over legacy
constructors):
+
+```java
+XmlMapper mapper = XmlMapper.builder()
+ .enable(ToXmlGenerator.Feature.WRITE_XML_DECLARATION)
+ .defaultUseWrapper(false)
+ .build();
+```
+
+`XmlMapper.Builder` extends `MapperBuilder`; `XmlFactoryBuilder` configures the
+`XMLInputFactory`/`XMLOutputFactory`, the `XmlNameProcessor`, and
parser/generator
+format features.
+
+### Module Registration System
+
+`JacksonXmlModule` (a `SimpleModule`) centralizes XML-specific configuration:
+- Registers `XmlBeanSerializerModifier` - hooks into serializer creation
+- Registers `XmlBeanDeserializerModifier` - hooks into deserializer creation
+- Adds `JacksonXmlAnnotationIntrospector` - processes @JacksonXml* annotations
+- Configures text element naming conventions
+
+Module is automatically registered when creating an `XmlMapper`.
+
+### Serialization Pipeline (Object → XML)
+
+```
+Object
+ → XmlMapper.writeValue()
+ → ToXmlGenerator (implements JsonGenerator)
+ → XmlBeanSerializerModifier (customizes bean serializers)
+ → XmlBeanSerializer + XmlBeanPropertyWriter
+ ├─ Determines element vs attribute
+ ├─ Handles namespace mappings
+ └─ Manages wrapper elements for collections
+ → XmlSerializerProvider (handles root element naming)
+ → XMLStreamWriter (Woodstox STAX)
+ → XML Output
+```
+
+**Key Classes:**
+- `XmlBeanSerializerBase` / `XmlBeanSerializer` - Extend Jackson's
`BeanSerializer` with XML-specific logic
+- `XmlBeanPropertyWriter` - Determines if property is element or attribute
+- `UnwrappingXmlBeanSerializer` - Handles `@JsonUnwrapped` properties
+- `XmlRootNameLookup` - Caches root element name calculations
+- `DefaultXmlPrettyPrinter` (implements `XmlPrettyPrinter`) - XML-aware
formatting
+
+### Deserialization Pipeline (XML → Object)
+
+```
+XML Input
+ → XMLStreamReader (STAX/Woodstox)
+ → FromXmlParser (implements JsonParser)
+ → XmlTokenStream (converts XML events to JSON tokens)
+ ├─ START_ELEMENT → START_OBJECT
+ ├─ Attributes → FIELD_NAME + VALUE pairs
+ ├─ Text content → VALUE_STRING (field name = "")
+ └─ END_ELEMENT → END_OBJECT
+ → XmlBeanDeserializerModifier (customizes deserializers)
+ ├─ Renames wrapper properties
+ ├─ Handles @JacksonXmlText
+ └─ Manages collection wrapping/unwrapping
+ → Standard Jackson Deserializers
+ → Object
+```
+
+**Key Classes:**
+- `FromXmlParser` - Wraps STAX reader, exposes JSON-like token stream
+- `XmlTokenStream` - Intermediate abstraction with token replay/lookahead
+- `WrapperHandlingDeserializer` - Handles wrapped/unwrapped collections
+- `ElementWrapper` / `ElementWrappable` - Wrapper-name metadata plumbing
+- `XmlReadContext` - Tracks parsing context (current element, namespace)
+- `XmlDeserializationContext` - XML-specific `DeserializationContext` subclass
+- `XmlTextDeserializer` - Deserializes element text content
+
+### Collection Wrapping Pattern
+
+A critical XML-specific concern is how collections are represented:
+
+**Wrapped (default behavior):**
+```xml
+<items>
+ <item>A</item>
+ <item>B</item>
+</items>
+```
+
+**Unwrapped:**
+```xml
+<item>A</item>
+<item>B</item>
+```
+
+Control via:
+- `@JacksonXmlElementWrapper(useWrapping = false)` per property
+- `XmlMapper.builder().defaultUseWrapper(false)` (or
`JacksonXmlModule.setDefaultUseWrapper(false)`) globally
+- `WrapperHandlingDeserializer` implements the complex logic
+
+### Annotation System
+
+**Jackson XML Annotations**
(`com.fasterxml.jackson.dataformat.xml.annotation`):
+- `@JacksonXmlRootElement` - Set root element name/namespace
+- `@JacksonXmlProperty(isAttribute=true)` - Mark property as XML attribute
+- `@JacksonXmlElementWrapper` - Control collection wrapper elements
+- `@JacksonXmlText` - Property represents element text content (not a child
element)
+- `@JacksonXmlCData` - Wrap value in CDATA section
+
+**JAXB Support:**
+Uses optional `jackson-module-jakarta-xmlbind-annotations` dependency. The
`XmlJaxbAnnotationIntrospector` can process JAXB annotations for
interoperability.
+
+**Polymorphic Type Handling:**
+`XmlTypeResolverBuilder` and `DefaultingXmlTypeResolverBuilder` adapt
Jackson's type
+resolution (`@JsonTypeInfo`, default typing) to XML — notably making
`As.PROPERTY`
+inclusion work as an XML attribute.
+
+### STAX Integration
+
+**Woodstox** is the preferred STAX implementation (faster and more reliable
than JDK's default).
+
+**Factory Configuration:**
+- `XmlFactory` manages `XMLInputFactory` and `XMLOutputFactory`
+- Security defaults: external entities disabled, DTD processing disabled
+- `IS_REPAIRING_NAMESPACES = true` for automatic namespace handling
+- `IS_COALESCING = true` to simplify text content processing
+- `Stax2JacksonReaderAdapter` bridges non-Woodstox (Stax2-less) readers
+
+**Custom STAX Configuration Example:**
+```java
+XMLInputFactory ifactory = new WstxInputFactory();
+ifactory.setProperty(WstxInputProperties.P_MAX_ATTRIBUTE_SIZE, 32000);
+XmlFactory xf = XmlFactory.builder()
+ .xmlInputFactory(ifactory)
+ .build();
+XmlMapper mapper = new XmlMapper(xf);
+```
+
+### Name Processing
+
+`XmlNameProcessor` allows custom XML name transformations, configured via
+`XmlFactoryBuilder.nameProcessor(...)` and applied during both serialization
and
+deserialization. `XmlNameProcessors` provides ready-made implementations:
+`newPassthroughProcessor()` (default), `newReplacementProcessor()`,
+`newBase64Processor()`, and `newAlwaysOnBase64Processor()` — the latter two
encode
+names that are not valid XML names.
+
+### Feature Flags
+
+**FromXmlParser.Feature** (deserialization) — the complete set:
+- `AUTO_DETECT_XSI_TYPE` (default off) - Process `xsi:type` attributes for
polymorphism
+- `EMPTY_ELEMENT_AS_NULL` (default off) - Treat `<element/>` as null
+- `PROCESS_XSI_NIL` (default **on**) - Honor `xsi:nil="true"`
+
+(Note: `ENFORCE_VALID_ROOT_NAME` appears in the source but is commented out —
it is
+not an available feature.)
+
+**ToXmlGenerator.Feature** (serialization) — the complete set:
+- `WRITE_XML_DECLARATION` - Output `<?xml version="1.0"?>`
+- `WRITE_STANDALONE_YES_TO_XML_DECLARATION` - Add `standalone="yes"` (needs
the above)
+- `WRITE_XML_1_1` - Use XML 1.1
+- `WRITE_NULLS_AS_XSI_NIL` - Add `xsi:nil="true"` for null values
+- `UNWRAP_ROOT_OBJECT_NODE` - For a single-entry root `ObjectNode`, use its
key as
+ root element name (will default to enabled in 3.0)
+- `AUTO_DETECT_XSI_TYPE` - Add `xsi:type` for polymorphic types
+- `WRITE_XML_SCHEMA_CONFORMING_FLOATS` - Emit `INF`/`-INF`/`NaN` per XML Schema
+ (will default to enabled in 3.0)
+
+All default to disabled except `PROCESS_XSI_NIL` on the parser side.
+Configure via `XmlMapper.builder().enable(...)/.disable(...)`, or
+`XmlMapper.enable(feature)` / `XmlMapper.disable(feature)`.
+
+## Source Code Structure
+
+```
+src/main/java/com/fasterxml/jackson/dataformat/xml/
+├── XmlMapper.java - Primary API, extends ObjectMapper (has
Builder)
+├── XmlFactory.java - Creates parsers/generators
+├── XmlFactoryBuilder.java - Builder for XmlFactory (STAX factories, name
processor)
+├── JacksonXmlModule.java - Module for XML configuration
+├── JacksonXmlAnnotationIntrospector.java / XmlAnnotationIntrospector.java
+├── XmlTypeResolverBuilder.java / DefaultingXmlTypeResolverBuilder.java
+├── XmlNameProcessor.java / XmlNameProcessors.java - XML name transformation
+├── XmlPrettyPrinter.java
+├── annotation/ - @JacksonXml* annotations
+├── deser/ - Deserialization (XML → Object)
+│ ├── FromXmlParser.java - Parser implementation
+│ ├── XmlTokenStream.java - STAX abstraction layer
+│ ├── XmlBeanDeserializerModifier.java
+│ ├── WrapperHandlingDeserializer.java
+│ ├── ElementWrapper.java / ElementWrappable.java
+│ ├── XmlDeserializationContext.java / XmlReadContext.java
+│ └── XmlTextDeserializer.java
+├── ser/ - Serialization (Object → XML)
+│ ├── ToXmlGenerator.java - Generator implementation
+│ ├── XmlBeanSerializer.java / XmlBeanSerializerBase.java
+│ ├── UnwrappingXmlBeanSerializer.java
+│ ├── XmlBeanPropertyWriter.java
+│ ├── XmlBeanSerializerModifier.java
+│ └── XmlSerializerProvider.java
+├── jaxb/ - JAXB integration
+│ └── XmlJaxbAnnotationIntrospector.java
+└── util/ - Utilities
+ ├── StaxUtil.java - STAX exception handling
+ ├── XmlRootNameLookup.java - Root element naming
+ ├── DefaultXmlPrettyPrinter.java
+ ├── Stax2JacksonReaderAdapter.java
+ ├── AnnotationUtil.java / TypeUtil.java / XmlInfo.java
+ └── CaseInsensitiveNameSet.java
+
+src/test/java/.../xml/
+├── deser/ - Deserialization tests (+ builder/, convert/,
creator/)
+├── ser/ - Serialization tests (+ dos/)
+├── stream/ - Low-level parser/generator tests (+ dos/)
+├── lists/ - Collection handling tests
+├── node/ - Tree model (JsonNode) tests
+├── misc/ - Assorted feature tests
+├── adapters/, incr/, interop/, jaxb/, vld/, woodstox/
+├── fuzz/ - Regression tests from OSS-Fuzz findings
+├── tofix/ - Tests for known issues (see below)
+├── testutil/ - Test helpers (+ failure/ annotations)
+├── XmlTestUtil.java - Base test class for new tests
+└── XmlTestBase.java - Deprecated, unused legacy base class
+
+src/test-jdk17/java/.../xml/
+├── jdk17/ - JDK 17+ feature tests
+└── records/ - Java Records support tests (+ tofix/)
+```
+
+## Test Organization
+
+- Tests are organized by feature area (deser, ser, lists, stream, node, etc.)
+- Issue-specific tests named like `RootName374Test.java` (GitHub issue #374)
+- `tofix/` holds tests for known limitations/bugs. These extend `XmlTestUtil`
and are
+ annotated `@JacksonTestFailureExpected` (see `testutil/failure/`), which
inverts the
+ result: the test *fails* the build if it unexpectedly starts passing. When
you fix a
+ bug, remove the annotation and move the test into the proper package.
+- `fuzz/` holds regression tests for OSS-Fuzz reports; `*/dos/` holds
+ denial-of-service / resource-limit tests.
+- JDK 17+ tests in a separate source directory, auto-enabled by Maven profile.
+
+## Known Limitations
+
+- **Tree Model** (`JsonNode`): Does not perfectly match XML infoset
+ - Mixed content (text + elements) not fully supported
+ - Repeated elements handled specially (see #403)
+- **Root Values**: Work best with POJOs; primitives, Strings, Collections have
limitations
+- **Collection Wrapping**: Default behavior differs between Jackson and JAXB
annotations
+- **Namespace URIs**: Not verified during deserialization (only local names
matched)
+- **Polymorphic Types**: Some inclusion mechanisms unsupported (e.g.,
`WRAPPER_ARRAY`)
+
+See README.md "Known Limitations" section for complete list.
+
+## Development Notes
+
+### Release Notes
+Every user-visible change gets an entry in `release-notes/VERSION-2.x` (issue
number,
+one-line description, credit line) and, for external contributors,
`release-notes/CREDITS-2.x`.
+
+### Security
+- External entity expansion disabled by default (XXE prevention)
+- DTD processing disabled
+- These are configured in `XmlFactory` constructor
+
+### Streaming vs Databinding
+- Low-level streaming (direct `FromXmlParser`/`ToXmlGenerator` use) is
possible but not primary use case
+- Databinding layer includes necessary XML-specific workarounds
+- For incremental/partial reading/writing, combine STAX APIs with `XmlMapper`
(see `incr/` tests)
+
+### Modifying Serializers/Deserializers
+Use the Modifier pattern:
+- Extend `XmlBeanSerializerModifier` for serialization customization
+- Extend `XmlBeanDeserializerModifier` for deserialization customization
+- Register via `JacksonXmlModule` or custom module
+
+### Adding New Features
+1. Consider if it's a parser/generator feature (token stream level) or
serializer/deserializer feature (databinding level)
+2. Parser/Generator: Modify `FromXmlParser`/`ToXmlGenerator` and potentially
`XmlTokenStream`
+3. Databinding: Use Modifier pattern or custom
`JsonSerializer`/`JsonDeserializer`
+4. Add feature flag if it's optional behavior (defaults must stay
backwards-compatible in 2.x)
+5. Add tests in appropriate subdirectory, extending `XmlTestUtil`
+6. Add a release-notes entry
+
+## Dependencies
+
+**Core (compile):**
+- `jackson-core`, `jackson-databind`, `jackson-annotations` (from parent BOM)
+- `stax2-api` (enhanced STAX API)
+- `woodstox-core` (STAX implementation)
+- `stax-api` (`provided` scope only, for old JDK compatibility)
+
+**Test:**
+- JUnit 5 (`junit-jupiter`, `junit-jupiter-api`) — used by all tests
+- JUnit 4 (`junit`) — legacy, only for the deprecated `XmlTestBase`
+- `jackson-module-jakarta-xmlbind-annotations` + `jakarta.xml.bind-api` (JAXB
interop testing)
+- `sjsxp` (alternative STAX impl for testing)
+
+**Version Management:**
+Versions inherited from `com.fasterxml.jackson:jackson-base` parent POM, which
manages the Jackson BOM (bill of materials).
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/pom.xml
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/pom.xml
--- old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/pom.xml
2026-07-08 02:40:42.000000000 +0200
+++ new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/pom.xml
2026-09-21 02:49:08.000000000 +0200
@@ -9,11 +9,11 @@
<parent>
<groupId>com.fasterxml.jackson</groupId>
<artifactId>jackson-base</artifactId>
- <version>2.18.9</version>
+ <version>2.18.11</version>
</parent>
<groupId>com.fasterxml.jackson.dataformat</groupId>
<artifactId>jackson-dataformat-xml</artifactId>
- <version>2.18.9</version>
+ <version>2.18.11</version>
<name>Jackson-dataformat-XML</name>
<packaging>jar</packaging>
<description>Data format extension for Jackson to offer
@@ -24,7 +24,7 @@
<connection>scm:git:[email protected]:FasterXML/jackson-dataformat-xml.git</connection>
<developerConnection>scm:git:[email protected]:FasterXML/jackson-dataformat-xml.git</developerConnection>
<url>http://github.com/FasterXML/jackson-dataformat-xml</url>
- <tag>jackson-dataformat-xml-2.18.9</tag>
+ <tag>jackson-dataformat-xml-2.18.11</tag>
</scm>
<properties>
<packageVersion.dir>com/fasterxml/jackson/dataformat/xml</packageVersion.dir>
@@ -34,7 +34,7 @@
<!-- And presumably import too? -->
<!-- for Reproducible Builds -->
-
<project.build.outputTimestamp>2026-07-08T00:40:28Z</project.build.outputTimestamp>
+
<project.build.outputTimestamp>2026-09-21T00:48:53Z</project.build.outputTimestamp>
</properties>
<dependencies>
@@ -212,6 +212,36 @@
<profiles>
<profile>
+ <!-- Guarantee Java 8 compatible main classes even when the build runs
on a
+ later JDK: "release 8" pins both the bytecode version (52) and the
+ visible JDK API, unlike inherited source/target 1.8 which only pins
+ bytecode. Cannot be enabled unconditionally since javac 8 itself has
+ no "release" option, hence activation on JDK 9 and above.
+ -->
+ <id>java8-bytecode</id>
+ <activation>
+ <jdk>[9,)</jdk>
+ </activation>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.maven.plugins</groupId>
+ <artifactId>maven-compiler-plugin</artifactId>
+ <inherited>true</inherited>
+ <executions>
+ <execution>
+ <id>default-compile</id>
+ <configuration>
+ <release>8</release>
+ </configuration>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+
+ <profile>
<!-- And different set up for JDK 17 -->
<id>java17</id>
<activation>
@@ -241,16 +271,25 @@
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<inherited>true</inherited>
- <configuration>
- <!-- Enable Java 17 for all sources so that Intellij picks the
right language level -->
- <source>17</source>
- <release>17</release>
- <compilerArgs>
- <arg>-parameters</arg>
- <arg>--add-opens=java.base/java.lang=ALL-UNNAMED</arg>
- <arg>--add-opens=java.base/java.util=ALL-UNNAMED</arg>
- </compilerArgs>
- </configuration>
+ <executions>
+ <execution>
+ <!-- Enable Java 17 for TEST sources only (needs
"src/test-jdk17/java"
+ above); main sources must keep producing Java 8 bytecode
no matter
+ which JDK the build runs on, so this must NOT be
plugin-level
+ configuration (which would apply to "default-compile" too)
+ -->
+ <id>default-testCompile</id>
+ <configuration>
+ <source>17</source>
+ <release>17</release>
+ <compilerArgs>
+ <arg>-parameters</arg>
+ <arg>--add-opens=java.base/java.lang=ALL-UNNAMED</arg>
+ <arg>--add-opens=java.base/java.util=ALL-UNNAMED</arg>
+ </compilerArgs>
+ </configuration>
+ </execution>
+ </executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/CREDITS-2.x
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/CREDITS-2.x
---
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/CREDITS-2.x
2026-07-08 02:40:42.000000000 +0200
+++
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/CREDITS-2.x
2026-09-21 02:49:08.000000000 +0200
@@ -271,3 +271,9 @@
* Reported, contributed fix for #646: Deserializing fails when using builder
classes
with `Iterable` Collection setters
(2.17.1)
+
+Sahana (@Sahana2524)
+
+* Contributed #891: Enforce `StreamReadConstraints.maxNestingDepth` in
+ `FromXmlParser`
+ (2.18.10)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/VERSION-2.x
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/VERSION-2.x
---
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/release-notes/VERSION-2.x
2026-07-08 02:40:42.000000000 +0200
+++
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/release-notes/VERSION-2.x
2026-09-21 02:49:08.000000000 +0200
@@ -4,6 +4,15 @@
=== Releases ===
------------------------------------------------------------------------
+2.18.11 (20-Sep-2026)
+
+- Fix build to avoid past-JDK-8 bytecode generation
+
+2.18.10 (15-Aug-2026)
+
+#891: Enforce `StreamReadConstraints.maxNestingDepth` in `FromXmlParser`
+ (contributed by @Sahana2524)
+
2.18.9 (07-Jul-2026)
No changes since 2.18.8
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
---
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
2026-07-08 02:40:42.000000000 +0200
+++
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/main/java/com/fasterxml/jackson/dataformat/xml/deser/FromXmlParser.java
2026-09-21 02:49:08.000000000 +0200
@@ -715,10 +715,10 @@
switch (t) {
case START_OBJECT:
- _parsingContext = _parsingContext.createChildObjectContext(-1,
-1);
+ _createChildObjectContext();
break;
case START_ARRAY:
- _parsingContext = _parsingContext.createChildArrayContext(-1,
-1);
+ _createChildArrayContext();
break;
case END_OBJECT:
case END_ARRAY:
@@ -751,7 +751,7 @@
if (_mayBeLeaf) {
// leave _mayBeLeaf set, as we start a new context
_nextToken = JsonToken.FIELD_NAME;
- _parsingContext = _parsingContext.createChildObjectContext(-1,
-1);
+ _createChildObjectContext();
return _updateToken(JsonToken.START_OBJECT);
}
if (_parsingContext.inArray()) {
@@ -787,7 +787,7 @@
// 06-Jan-2015, tatu: as per [dataformat-xml#180],
need to
// expose as empty Object, not null
_nextToken = JsonToken.END_OBJECT;
- _parsingContext =
_parsingContext.createChildObjectContext(-1, -1);
+ _createChildObjectContext();
return _updateToken(JsonToken.START_OBJECT);
}
// 07-Sep-2019, tatu: for [dataformat-xml#353], must NOT
return second null
@@ -807,7 +807,7 @@
_mayBeLeaf = false;
_nextToken = JsonToken.FIELD_NAME;
_currText = _xmlTokens.getText();
- _parsingContext =
_parsingContext.createChildObjectContext(-1, -1);
+ _createChildObjectContext();
return _updateToken(JsonToken.START_OBJECT);
}
_parsingContext.setCurrentName(_xmlTokens.getLocalName());
@@ -837,7 +837,7 @@
// expose as empty Object, not null (or,
worse, as used to
// be done, by swallowing the token)
_nextToken = JsonToken.END_OBJECT;
- _parsingContext =
_parsingContext.createChildObjectContext(-1, -1);
+ _createChildObjectContext();
return _updateToken(JsonToken.START_OBJECT);
}
}
@@ -851,7 +851,7 @@
// fall-through, except must create new context AND push
back
// START_ELEMENT we just saw:
_xmlTokens.pushbackCurrentToken();
- _parsingContext =
_parsingContext.createChildObjectContext(-1, -1);
+ _createChildObjectContext();
}
// [dataformat-xml#177]: empty text may also need to be skipped
// but... [dataformat-xml#191]: looks like we can't short-cut,
must
@@ -945,7 +945,7 @@
while (token == XmlTokenStream.XML_START_ELEMENT) {
if (_mayBeLeaf) {
_nextToken = JsonToken.FIELD_NAME;
- _parsingContext = _parsingContext.createChildObjectContext(-1,
-1);
+ _createChildObjectContext();
_updateToken(JsonToken.START_OBJECT);
return null;
}
@@ -989,7 +989,7 @@
_mayBeLeaf = false;
_nextToken = JsonToken.FIELD_NAME;
_currText = _xmlTokens.getText();
- _parsingContext = _parsingContext.createChildObjectContext(-1,
-1);
+ _createChildObjectContext();
_updateToken(JsonToken.START_OBJECT);
} else {
_parsingContext.setCurrentName(_xmlTokens.getLocalName());
@@ -1028,14 +1028,14 @@
}
- private void _updateState(JsonToken t)
+ private void _updateState(JsonToken t) throws IOException
{
switch (t) {
case START_OBJECT:
- _parsingContext = _parsingContext.createChildObjectContext(-1, -1);
+ _createChildObjectContext();
break;
case START_ARRAY:
- _parsingContext = _parsingContext.createChildArrayContext(-1, -1);
+ _createChildArrayContext();
break;
case END_OBJECT:
case END_ARRAY:
@@ -1049,6 +1049,21 @@
}
}
+ // Enter a nested Object/Array scope, honoring the configured
+ // StreamReadConstraints.maxNestingDepth(). JsonReadContext has always
+ // tracked the depth but the read path never checked it, so a configured
+ // limit had no effect on XML input; ToXmlGenerator already does the
+ // equivalent check on the write side.
+ private void _createChildObjectContext() throws IOException {
+ _parsingContext = _parsingContext.createChildObjectContext(-1, -1);
+
streamReadConstraints().validateNestingDepth(_parsingContext.getNestingDepth());
+ }
+
+ private void _createChildArrayContext() throws IOException {
+ _parsingContext = _parsingContext.createChildArrayContext(-1, -1);
+
streamReadConstraints().validateNestingDepth(_parsingContext.getNestingDepth());
+ }
+
/*
/**********************************************************
/* Public API, access to token information, text
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
---
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
2026-07-08 02:40:42.000000000 +0200
+++
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/stream/dos/DeepNestingParserTest.java
2026-09-21 02:49:08.000000000 +0200
@@ -1,8 +1,11 @@
package com.fasterxml.jackson.dataformat.xml.stream.dos;
import com.fasterxml.jackson.core.JsonParser;
+import com.fasterxml.jackson.core.StreamReadConstraints;
+import com.fasterxml.jackson.core.exc.StreamConstraintsException;
import com.fasterxml.jackson.core.exc.StreamReadException;
+import com.fasterxml.jackson.dataformat.xml.XmlFactory;
import com.fasterxml.jackson.dataformat.xml.XmlMapper;
import com.fasterxml.jackson.dataformat.xml.XmlTestBase;
@@ -20,6 +23,26 @@
}
}
+ // jackson-core's StreamReadConstraints.maxNestingDepth is now enforced on
the
+ // XML read path (previously ignored); verify with a low configured limit
that
+ // stays well within the default Stax element-depth limit (1000), so the
+ // rejection is unambiguously due to the nesting-depth check.
+ public void testDeepDocWithLowNestingLimit() throws Exception
+ {
+ final XmlMapper xmlMapper = mapperBuilder(XmlFactory.builder()
+ .streamReadConstraints(StreamReadConstraints.builder()
+ .maxNestingDepth(10).build())
+ .build()).build();
+ final String XML = createDeepNestedDoc(50);
+ try (JsonParser p = xmlMapper.createParser(XML)) {
+ while (p.nextToken() != null) { }
+ fail("expected StreamConstraintsException");
+ } catch (StreamConstraintsException e) {
+ assertTrue("Unexpected message: " + e.getMessage(),
+ e.getMessage().contains("nesting depth"));
+ }
+ }
+
private String createDeepNestedDoc(final int depth) {
StringBuilder sb = new StringBuilder();
sb.append("<root>");
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
---
old/jackson-dataformat-xml-jackson-dataformat-xml-2.18.9/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
2026-07-08 02:40:42.000000000 +0200
+++
new/jackson-dataformat-xml-jackson-dataformat-xml-2.18.11/src/test/java/com/fasterxml/jackson/dataformat/xml/woodstox/DeepNestingWoodstoxParserTest.java
2026-09-21 02:49:08.000000000 +0200
@@ -3,7 +3,9 @@
import com.ctc.wstx.stax.WstxInputFactory;
import com.fasterxml.jackson.core.JsonParser;
+import com.fasterxml.jackson.core.StreamReadConstraints;
+import com.fasterxml.jackson.dataformat.xml.XmlFactory;
import com.fasterxml.jackson.dataformat.xml.XmlMapper;
import com.fasterxml.jackson.dataformat.xml.XmlTestBase;
@@ -15,7 +17,14 @@
{
final WstxInputFactory wstxInputFactory = new WstxInputFactory();
wstxInputFactory.getConfig().setMaxElementDepth(2000);
- final XmlMapper xmlMapper = new XmlMapper(wstxInputFactory);
+ // match the raised Stax element-depth limit so the jackson-core
+ // nesting-depth limit does not reject this deliberately deep doc
+ final XmlFactory factory = XmlFactory.builder()
+ .xmlInputFactory(wstxInputFactory)
+ .streamReadConstraints(StreamReadConstraints.builder()
+ .maxNestingDepth(2000).build())
+ .build();
+ final XmlMapper xmlMapper = new XmlMapper(factory);
final String XML = createDeepNestedDoc(1050);
try (JsonParser p = xmlMapper.createParser(XML)) {
while (p.nextToken() != null) { }