Skip to content

Serialize HTML non-recursively - #1644

Merged
waylan merged 6 commits into
Python-Markdown:masterfrom
facelessuser:non-recursive-serialize
Sep 30, 2026
Merged

waylan merged 6 commits into
Python-Markdown:masterfrom
facelessuser:non-recursive-serialize

Conversation

@facelessuser

@facelessuser facelessuser commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Description

AI Assistance Disclosure

  • No AI tools were used in preparing this PR.
  • If AI tools were used, I have disclosed which ones, and fully reviewed and verified their output.

Checklist

@facelessuser
facelessuser force-pushed the non-recursive-serialize branch from 211d6f9 to ad808e7 Compare September 28, 2026 23:55
@facelessuser

Copy link
Copy Markdown
Collaborator Author

Hmm, seems to be a weird difference in behavior for versions <= 3.12.

Serializer only takes elements, so handle strings before calling instead
of purposely feeding it in and capturing failure
@facelessuser

Copy link
Copy Markdown
Collaborator Author

Turns out we were purposely feeding in the wrong type (string) and waiting for it to fail. The non-recursive approach handles strings in the loop, but still requires the initial element to be an Element. We need to just check and handle strings now before we call the serializer.

@facelessuser
facelessuser marked this pull request as ready for review September 29, 2026 01:09
@waylan

waylan commented Sep 29, 2026

Copy link
Copy Markdown
Member

What problem are you trying to solve with this?

@facelessuser

Copy link
Copy Markdown
Collaborator Author

What problem are you trying to solve with this?

Serializer failing with deep processing of HTML.

Someone crafted a deeply nested case that couldn't be serialized and would throw a recursive error. Granted, it was a nonsense case, but there is no reason the serializer can't handle such cases. Granted, this isn't the only place a recursion error could happen, and I'm also okay if we just like the idea of recursive errors preventing excessive nesting.

To be honest, I'm okay either way. I'm not against RecursionErrors. I think in most practical cases, we would never hit them, and if we did, it would probably be reasonable.

@waylan

waylan commented Sep 29, 2026

Copy link
Copy Markdown
Member

That's a good reason for the change. Based on your explanation, it sounds like a user could crash someone's server with a Markdown comment designed to encounter the recursion limit error.

Comment thread markdown/serializers.py Outdated
Comment thread markdown/serializers.py Outdated
@waylan
waylan merged commit b2125da into Python-Markdown:master Sep 30, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants