fix(rust): bump config-disassembler to 0.10.5 - #74
Merged
Merged
Conversation
Bumps the underlying config-disassembler Rust crate 0.10.4 -> 0.10.5, pulling in mcarvin8/config-disassembler#128: comment content containing a literal & no longer gains an extra & layer of escaping on every successive disassemble/reassemble cycle (& -> & -> &amp; -> ..., compounding forever rather than stabilizing). Comment content is never entity-resolved on read per the XML spec, so it must never be escaped on write either. Found via property-based fuzzing of the decompose/recompose round trip downstream in mcarvin8/sf-decomposer, as a follow-up to the #127/0.10.4 mixed-content fix. No API changes on the Node side -- pure dependency bump. Verified with `cargo build`/`cargo test` against 0.10.5, plus a full native-binding `npm test` run (94/94 passing) built for this machine's actual host arch (aarch64-pc-windows-msvc). Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C
This was referenced Sep 9, 2026
mcarvin8
added a commit
to mcarvin8/sf-decomposer
that referenced
this pull request
Sep 9, 2026
…to 3.4.7 (#602) * test: add property-based fuzz test for XML decompose/recompose round trip Adds fast-check as a devDependency and a generator that produces arbitrary nested XML shapes (mixed element/text/CDATA/comment content, unicode, whitespace-only nodes) instead of relying only on curated fixtures. Checks the same tolerance model as the perf suite's byte-retention + idempotence guards: every non-whitespace leaf value must survive one round trip, and a second round trip must be byte-identical to the first. This already found a real bug in config-disassembler (an element with both a real child and direct mixed content, e.g. <item><fullName>X</fullName> <![CDATA[..]]></item>, silently drops the CDATA/comment on disassembly -- see mcarvin8/config-disassembler#127). NOT wiring this into `npm test` yet: it currently fails against the published [email protected] until that fix lands and this repo's dependency is bumped. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * fix(deps): bump config-disassembler to 3.4.3 Pulls in mcarvin8/config-disassembler-node#72 / mcarvin8/config-disassembler#127: an XML element with both a real child element and its own direct mixed content (e.g. <item><fullName>X</fullName><![CDATA[..]]></item>) no longer silently drops the CDATA/comment/text on disassembly. Verified: [email protected] and all 9 platform binaries confirmed published on npm (tarballs inspected directly, not just version metadata). Full sf-decomposer suite re-run against the bump: 618/619 passing - the one failure is the still-open comment-double-escape bug (config-disassembler#128), unrelated to this fix and tracked separately in test/units/xmlRoundtripFuzz.test.ts, which stays out of `npm test` until that lands too. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * test: fix fuzz test false positive on quoted text leaves sanitizeText stripped <, &, > but not quote characters. A literal " or ' in plain text content is legal XML but gets entity-encoded ("/') by the writer on output - the same as <, &, >. The leaf-value substring check was comparing against the raw (unescaped) form, so any generated text leaf containing a quote produced a false "content missing" failure even though the data was fully preserved, just re-encoded. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * fix(deps): bump config-disassembler to 3.4.4 Pulls in mcarvin8/config-disassembler-node#74 / mcarvin8/config-disassembler#128: comment content containing a literal & no longer gains an extra & layer of escaping on every successive disassemble/reassemble cycle. Verified: [email protected] and all 9 platform binaries confirmed published on npm (tarballs inspected directly for win32-x64 and win32-arm64). Full sf-decomposer suite re-run against the bump: 618/619 passing - the one failure is a newly-found, distinct bug (multiple sibling XML comments under the same element: only the last one survives, since the intermediate parse representation stores #comment as a single string key rather than an array), unrelated to either fix already released and not yet reported upstream. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * fix(deps): bump config-disassembler to 3.4.5 Pulls in mcarvin8/config-disassembler-node#78 / mcarvin8/config-disassembler#130: multiple sibling XML comments under the same element are now all preserved instead of the second silently overwriting the first. Verified: [email protected] and all 9 platform binaries confirmed published on npm. Full sf-decomposer suite re-run against the bump: 618/619 passing - the one failure is a newly-found, distinct and unbounded idempotence bug (an element with both a comment and CDATA as direct mixed content grows two extra blank lines between them on every successive disassemble/reassemble cycle, forever), unrelated to the three fixes already released and not yet reported upstream. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * fix(deps): bump config-disassembler to 3.4.6 Pulls in mcarvin8/config-disassembler-node#80 / mcarvin8/config-disassembler#132: a comment immediately followed by CDATA no longer grows extra blank lines between them on every successive disassemble/reassemble cycle. Verified: [email protected] and all 9 platform binaries confirmed published on npm. Full sf-decomposer suite re-run against the bump: 618/619 passing - the one failure is a fifth, distinct bug (trailing non-whitespace text after a child element loses its own leading/trailing whitespace when concatenated onto an earlier whitespace-only text run on the same element, e.g. "( " becomes "(" - flush_text_buffer's "append" branch uses parse_text_value's trimmed output where the "first text run" branch uses the untrimmed raw value), unrelated to the four fixes already released and not yet reported upstream. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C * fix(deps): bump config-disassembler to 3.4.7 Pulls in mcarvin8/config-disassembler-node#82 / mcarvin8/config-disassembler#134: four related bugs in flush_text_buffer that lost or duplicated text mixed with child elements and CDATA (whitespace trimmed off real content on concatenation, whitespace-only prior runs permanently baked into merged values causing unbounded growth on repeated round trips, and real text silently dropped once CDATA was present on the same element). This is the fourth and final fix from the property-based fuzzing effort that started with #127 (3.4.3), #128 (3.4.4), and #130 (3.4.5). The fuzz test (test/units/xmlRoundtripFuzz.test.ts) is finally green: full suite re-run, 34/34 files, 619/619 tests passing. Confirmed stable across 4 independently-seeded runs of the fuzz test alone before running the full suite. Verified: [email protected] and all 9 platform binaries confirmed published on npm. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C --------- Co-authored-by: Claude Sonnet 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
config-disassemblerRust crate 0.10.4 -> 0.10.5, pulling in mcarvin8/config-disassembler#128: comment content containing a literal&no longer gains an extra&layer of escaping on every successive disassemble/reassemble cycle (&->&->&amp;-> ..., compounding forever rather than stabilizing). Comment content is never entity-resolved on read per the XML spec, so it must never be escaped on write either.Test plan
cargo build/cargo testagainst 0.10.5 — cleannpm run build -- --target aarch64-pc-windows-msvc(this machine's real host arch) thennpm test— 12/12 files, 94/94 tests passing against the rebuilt native binding🤖 Generated with Claude Code
https://claude.ai/code/session_011ADqqfdwfnhTPJQp17sH3C