Skip to content

map the null code point to U+FFFD when decoding CSS escapes - #189

Merged
AdrianAtZyte merged 1 commit into
scrapy:masterfrom
itecz26:null-codepoint-fffd
Sep 14, 2026
Merged

AdrianAtZyte merged 1 commit into
scrapy:masterfrom
itecz26:null-codepoint-fffd

Conversation

@itecz26

@itecz26 itecz26 commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

the escape decoder _replace_unicode folds surrogate halves and out-of-range code points to U+FFFD but not the null code point, so a \0 escape (or literal \0 in an identifier/string) decodes to a NUL that leaks into decoded names, string values and the generated XPath; the CSS Syntax spec (§4.3.7) treats zero the same as surrogates, so this adds codepoint == 0 to the same guard #164 introduced.

@codecov

codecov Bot commented Sep 14, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.79%. Comparing base (9790903) to head (440813d).

Additional details and impacted files
@@             Coverage Diff             @@
##            master     #189      +/-   ##
===========================================
- Coverage   100.00%   99.79%   -0.21%     
===========================================
  Files            3        3              
  Lines          966      966              
  Branches       155      155              
===========================================
- Hits           966      964       -2     
- Misses           0        1       +1     
- Partials         0        1       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@AdrianAtZyte
AdrianAtZyte merged commit 4f6a271 into scrapy:master Sep 14, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants