Skip to content

Reject invalid raw HTML tags, attributes and email autolinks - #154

Merged
bobzhang merged 1 commit into
mainfrom
conformance/reject-invalid-raw-html
Oct 2, 2026
Merged

bobzhang merged 1 commit into
mainfrom
conformance/reject-invalid-raw-html

Conversation

@bobzhang

@bobzhang bobzhang commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Split out of #152.

Bugs: invalid raw HTML and email autolinks were accepted.

Repro Was Rule
<33>, < a>, </1a> raw HTML tag names start with an ASCII letter
<b 1=c> raw HTML attribute names start with a letter, _ or :
<a b=>c>, <a b=`c> raw HTML unquoted attribute values are non-empty and can't start with "'=<>`
<foo\+@bar.example.com> email autolink the atext set had \ where ' belongs

Fix: tag_name checks the first character, attribute_name no longer accepts a digit first, attribute_value rejects an empty unquoted value, and char_is_atext_plus_dot has ' instead of \.

Spec examples fixed: 606, 618. Example 621 also needs #156 (the last line of the example is dropped without it).

Tests: src/cmark_html/invalid_raw_html_test.mbt. Updated raw_html_test.mbt (</1div>, <.div>) and raw_html_wbtest.mbt (tag_name on 1div), which encoded the old behaviour.

Depends on: nothing, independent of the other PRs.

- Tag names must start with an ASCII letter: <33>, < a> and </1a> are
  not raw HTML (spec examples 618 and 621).
- Attribute names must start with an ASCII letter, _ or :, not a digit.
- Unquoted attribute values must be non-empty: <a b=>c> and <a b=`c>
  are not raw HTML.
- The atext set of email autolinks had \ where ' belongs:
  <foo\+@bar.example.com> is not an autolink (spec example 606).
@bobzhang

bobzhang commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Automated review: Codex CLI (codex exec, model reasoning effort high, read-only sandbox), 1 round, on git diff against the base branch.

Verdict: signed off, no changes requested.

I sign off on the code review. No concrete correctness, regression, or code-quality problems found.

The changes match CommonMark 0.31.2’s raw HTML grammar and email autolink rules. Tests cover all four fixes with valid counterparts. No unnecessary helpers were introduced.

Codex could not run moon test in its read-only sandbox. The tests were run separately on native, js and wasm-gc and pass.

@bobzhang
bobzhang merged commit ae7b189 into main Oct 2, 2026
9 checks passed
@bobzhang
bobzhang deleted the conformance/reject-invalid-raw-html branch October 2, 2026 01:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant