From patchwork Thu Sep 3 12:11:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 97233 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 47691C61DD3 for ; Thu, 3 Sep 2026 12:12:17 +0000 (UTC) Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6163.1788437527992119915 for ; Thu, 03 Sep 2026 05:12:08 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=FH02Q+8S; spf=pass (domain: cisco.com, ip: 173.37.142.94, mailfrom: dkelaiya@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=47527; q=dns/txt; s=iport01; t=1788437528; x=1789647128; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=FXgSj1NgaMYIKaGnt6LVkByWdtSxQ2ia0IvDfPCIK1I=; b=FH02Q+8SaAZj//jgYa/99LnNlm6inPpQap4t1X+VM5ATmcGfvpVGR9yr EYbXB6T3G0Q0RYQ7sWII002BWg1wQF/5tcOWP3kRi0I0P/QYPM/IcwNlX rsVvfsC/S9UZJ3MEjot4Bz6s148FSFZYCHerAlwMHsYXerig0goGjSrQG mg+VlvvU0lzmbym+m9OufSepMXnAZCvgbl5nMuOSbZU1Q8SBYQeE7h3Y8 G1mi3JtI5USwa/zqCZJHqnNxDzWtBRXpTHelmcaMq03597UTfy6K66LR5 VX5gKLYBF/BD+qIVUlcIvQ5DUDbYTJNG+sR96I6MS720PiT6Y7WEFXYkT g==; X-CSE-ConnectionGUID: MbshruNkQdeBsyXCl0JcuQ== X-CSE-MsgGUID: z5RK2JgmR8GsEsZVK7cymg== X-IPAS-Result: A0AiAwBpY5lq/48QJK1aglkCghY/dGBDSQOWR4EWkDeMUYF+DwEBAQ9EDQQBAYUFjXkCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw1JAYlPAYV/AQIBHQEMJAEtLAMBAlojIYIqWAGCdAMRwGOBeTOBAYMoAYFU2zEBCxQBgTiFP4giXRgBhHwnGxuBcoEVgnN2gQWBXAKBJ4Z+BIINFYEMgVoeUIUIjBVIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEog0EjGTZ6gQlegSspYAESF4EJgggCglSCBQIBSUMOB0dTCScYCxgNSBEsNxUZBD5uB45gH4FiPzRZCisBKQKBQxcOIwMeEZMAFBqQFoIhoQ8KKIN2jCKVOhozhASBV5JAklILmH2OCpU0TU+EaYFoPIFZcBWDIglKGQ9XjVYBCwuDYIVkxlUnMgIJAy8BAQcCBw4DC4FoiSGGXwImB4FPAQE IronPort-Data: A9a23:D014SKIVvmOho44CFE+Rh5QlxSXFcZb7ZxGr2PjKsXjdYENShDRWz zAYC23QO/iKY2rxKdFxbIW38RkD657SzYJnSQMd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZsCCSa/kvxWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9imYvaj58B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1LBlo2J5A++d97DEtV5 MwzLGgvZQ260rfeLLKTEoGAh+wqKM3teYdasXZ6wHSBU7AtQIvIROPB4towMDUY358VW62AI ZNHL2MzN3wsYDUXUrsTIJ49keOhh2j2WzZZs1mS46Ew5gA/ySQhiui3aYGEKoLiqcN9jBuih Tjk8GHDUj4BGcet9xna+WOpibqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYVX95WVul/4waXx++MvUCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXMIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:dZl2wa8XCbjFlb3dpHxuk+DuI+orL9Y04lQ7vn2ZhyY7TiX+rb HKoB11737JYVoqNU3I+urwWpVoP0m9yXcd2+B4Vt2ftWLd1ldAQrsP0WKb+UyCJwTOsshAyK xnb69yTPf0DVR8kILGxTPQKadF/DFCm5rY49s3CBxWPGZXV50= X-Talos-CUID: 9a23:JgcNm2+nRusUyJD8ajmVv2seAcA/b1ve9XvdCVSpOU1tEJ+eVGbFrQ== X-Talos-MUID: 9a23:kIYRcAYsnyXMI+BTpWLWp2tAO8JSs4u1JVs/r7ZZsNiBOnkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,260,1779148800"; d="scan'208";a="828213986" Received: from alln-l-core-06.cisco.com ([173.36.16.143]) by alln-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 03 Sep 2026 12:12:04 +0000 Received: from sjc-ads-5675.cisco.com (sjc-ads-5675.cisco.com [10.28.88.189]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-06.cisco.com (Postfix) with ESMTPS id 395AC18001D80; Thu, 3 Sep 2026 12:11:50 +0000 (GMT) Received: by sjc-ads-5675.cisco.com (Postfix, from userid 1887444) id DEA9ACCA79B; Thu, 3 Sep 2026 05:11:47 -0700 (PDT) From: "Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: Darsh Kelaiya Subject: [OE-core][wrynose][PATCH v2] python3-lxml: fix CVE-2026-41066 Date: Thu, 3 Sep 2026 05:11:41 -0700 Message-Id: <20260903121141.2463805-1-dkelaiya@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5675.cisco.com [10.28.88.189];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.88.189, sjc-ads-5675.cisco.com X-Outbound-Node: alln-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 03 Sep 2026 12:12:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245031 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358 [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw Signed-off-by: Darsh Kelaiya --- .../python/python3-lxml/CVE-2026-41066.patch | 349 ++++++++++++++++++ .../python/python3-lxml_6.0.2.bb | 4 +- 2 files changed, 352 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch new file mode 100644 index 0000000000..b1a6f6629d --- /dev/null +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch @@ -0,0 +1,349 @@ +From 3a79355229f58e0fe51371385102dd7577bbfb26 Mon Sep 17 00:00:00 2001 +From: Stefan Behnel +Date: Fri, 10 Apr 2026 10:13:03 +0200 +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for + all parser subclasses. + +CVE: CVE-2026-41066 +Upstream-Status: Backport [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358] + +Backport Changes: +- Reformat the iterparse signature and resolve_entities documentation + without semantic changes, preserving line numbers to avoid generated + source-location churn. +- Regenerate src/lxml/etree.c with Cython 3.1.4, matching the version + recorded in the shipped file, using + "python setup.py build_ext -i --with-cython". +- Restore the shipped Cython metadata field order and omit + the environment-only "-w" compiler flag to avoid unrelated + generated changes. + +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358) +Signed-off-by: Darsh Kelaiya +--- + src/lxml/etree.c | 60 +++++++++++++++++++++--------------------- + src/lxml/iterparse.pxi | 10 +++---- + src/lxml/parser.pxi | 6 ++--- + 3 files changed, 38 insertions(+), 38 deletions(-) + +diff --git a/src/lxml/etree.c b/src/lxml/etree.c +index 29553531..f2208e43 100644 +--- a/src/lxml/etree.c ++++ b/src/lxml/etree.c +@@ -147986,7 +147986,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<< + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + */ + if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -147997,7 +147997,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<< +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + */ + if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148007,17 +148007,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + /* "src/lxml/parser.pxi":1734 + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<< ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<< + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): + */ + if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); +- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + + /* "src/lxml/parser.pxi":1735 + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<< + * target=None, compact=True): + * XMLParser.__init__(self, +@@ -148027,7 +148027,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True)); + + /* "src/lxml/parser.pxi":1736 +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): # <<<<<<<<<<<<<< + * XMLParser.__init__(self, +@@ -148054,7 +148054,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<< + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + */ + if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148065,7 +148065,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<< +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + */ + if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148075,17 +148075,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + /* "src/lxml/parser.pxi":1734 + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<< ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<< + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): + */ + if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); +- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + + /* "src/lxml/parser.pxi":1735 + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<< + * target=None, compact=True): + * XMLParser.__init__(self, +@@ -148095,7 +148095,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True)); + + /* "src/lxml/parser.pxi":1736 +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): # <<<<<<<<<<<<<< + * XMLParser.__init__(self, +@@ -195499,7 +195499,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<< + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + */ + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195508,7 +195508,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<< +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + */ + if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195518,17 +195518,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + /* "src/lxml/iterparse.pxi":71 + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<< ++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<< + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, + */ + if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True)); +- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); + + /* "src/lxml/iterparse.pxi":72 + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<< + * html=False, recover=None, huge_tree=False, collect_ids=True, + * XMLSchema schema=None): +@@ -195538,7 +195538,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None)); + + /* "src/lxml/iterparse.pxi":73 +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<< + * XMLSchema schema=None): +@@ -195588,7 +195588,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<< + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + */ + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195597,7 +195597,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<< +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + */ + if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195607,17 +195607,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + /* "src/lxml/iterparse.pxi":71 + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<< ++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<< + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, + */ + if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True)); +- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); + + /* "src/lxml/iterparse.pxi":72 + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<< + * html=False, recover=None, huge_tree=False, collect_ids=True, + * XMLSchema schema=None): +@@ -195627,7 +195627,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None)); + + /* "src/lxml/iterparse.pxi":73 +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<< + * XMLSchema schema=None): +@@ -263283,7 +263283,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_XMLParser[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser}, +- {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser}, +@@ -263326,7 +263326,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_XMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ ++ PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -263506,7 +263506,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_ETCompatXMLParser[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser}, +- {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser}, +@@ -263549,7 +263549,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_ETCompatXMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ ++ PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -266739,7 +266739,7 @@ static struct PyGetSetDef __pyx_getsets_4lxml_5etree_iterparse[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse}, +- {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse}, + {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__}, +@@ -266785,7 +266785,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_iterparse = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ ++ PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/ + 0, /*tp_richcompare*/ +diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi +index 42b75249..9319f646 100644 +--- a/src/lxml/iterparse.pxi ++++ b/src/lxml/iterparse.pxi +@@ -6,8 +6,8 @@ cdef class iterparse: + """iterparse(self, source, events=("end",), tag=None, \ + attribute_defaults=False, dtd_validation=False, \ + load_dtd=False, no_network=True, remove_blank_text=False, \ +- remove_comments=False, remove_pis=False, encoding=None, \ +- html=False, recover=None, huge_tree=False, schema=None) ++ compact=True, resolve_entities='internal', remove_comments=False, \ ++ remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None) + + Incremental parser. + +@@ -42,10 +42,10 @@ cdef class iterparse: + - remove_blank_text: discard blank text nodes + - remove_comments: discard comments + - remove_pis: discard processing instructions +- - strip_cdata: replace CDATA sections by normal text content (default: ++ - strip_cdata: replace CDATA sections by normal text content (default: + True for XML, ignored otherwise) + - compact: safe memory for short text content (default: True) +- - resolve_entities: replace entities by their text value (default: True) ++ - resolve_entities: replace entities by their text value (default: 'internal' only) + - huge_tree: disable security restrictions and support very deep trees + and very long text content (only affects libxml2 2.7+) + - html: parse input as HTML (default: XML) +@@ -68,7 +68,7 @@ cdef class iterparse: + def __init__(self, source, events=("end",), *, tag=None, + attribute_defaults=False, dtd_validation=False, + load_dtd=False, no_network=True, remove_blank_text=False, +- compact=True, resolve_entities=True, remove_comments=False, ++ compact=True, resolve_entities='internal', remove_comments=False, + remove_pis=False, strip_cdata=True, encoding=None, + html=False, recover=None, huge_tree=False, collect_ids=True, + XMLSchema schema=None): +diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi +index 3106e610..ba9875c0 100644 +--- a/src/lxml/parser.pxi ++++ b/src/lxml/parser.pxi +@@ -1584,7 +1584,7 @@ cdef class XMLParser(_FeedParser): + """XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, \ + load_dtd=False, no_network=True, decompress=False, ns_clean=False, \ + recover=False, schema: XMLSchema =None, huge_tree=False, \ +- remove_blank_text=False, resolve_entities=True, \ ++ remove_blank_text=False, resolve_entities='internal', \ + remove_comments=False, remove_pis=False, strip_cdata=True, \ + collect_ids=True, target=None, compact=True) + +@@ -1717,7 +1717,7 @@ cdef class ETCompatXMLParser(XMLParser): + """ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \ + dtd_validation=False, load_dtd=False, no_network=True, decompress=False, \ + ns_clean=False, recover=False, schema=None, \ +- huge_tree=False, remove_blank_text=False, resolve_entities=True, \ ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', \ + remove_comments=True, remove_pis=True, strip_cdata=True, \ + target=None, compact=True) + +@@ -1731,7 +1731,7 @@ cdef class ETCompatXMLParser(XMLParser): + def __init__(self, *, encoding=None, attribute_defaults=False, + dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + ns_clean=False, recover=False, schema=None, +- huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', + remove_comments=True, remove_pis=True, strip_cdata=True, + target=None, compact=True): + XMLParser.__init__(self, +-- +2.35.6 + diff --git a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb index 876fda93b6..75894460ec 100644 --- a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb +++ b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb @@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt" SRC_URI[sha256sum] = "cd79f3367bd74b317dda655dc8fcfa304d9eb6e4fb06b7168c5cf27f96e0cd62" -SRC_URI += "${PYPI_SRC_URI}" +SRC_URI += "${PYPI_SRC_URI} \ + file://CVE-2026-41066.patch" + inherit pkgconfig pypi setuptools3 # {standard input}: Assembler messages: