This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 10 · Mar 3 – 9, 2025

encoding/xml: add flag for stricter XML char parsing

Worth knowingstdlib

What changed
The xml.Decoder type now has a Check field and the Strict field is redefined. Strict defaults to true and is equivalent to setting Check.EndTag and Check.Entities to true. The new Checks struct allows finer control over end‑tag and entity validation.
Production impact
The source does not say.
Try it
Create an xml.Decoder with Strict: false and parse an XML document that contains an unmatched end tag to observe how the parser invents tags.
Source
github.com/golang/go/issues/69503

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the current behavior of xml.Decoder in Go 1.27.1.
// The Decoder has a Strict field but no Check field. Setting Strict to false
// allows the parser to invent missing end tags and ignore malformed entities.
package main

import (
	"encoding/xml"
	"fmt"
	"strings"
)

func main() {
	// XML with a missing end tag and an unknown entity.
	data := `<root><child>Some &unknown; text</child><empty></root>`

	// Create a decoder that does not enforce strict validation.
	dec := xml.NewDecoder(strings.NewReader(data))
	dec.Strict = false

	for {
		tok, err := dec.Token()
		if err != nil {
			break
		}
		switch v := tok.(type) {
		case xml.StartElement:
			fmt.Printf("Start: %s\n", v.Name.Local)
		case xml.EndElement:
			fmt.Printf("End: %s\n", v.Name.Local)
		case xml.CharData:
			fmt.Printf("Char: %s\n", strings.TrimSpace(string(v)))
		}
	}
}

What it printed when we ran it on Go 1.27.1

Start: root
Start: child
Char: Some &unknown; text
End: child
Start: empty
End: empty
End: root

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed