Bug report
Bug description:
Documented behaviour: The unescape docstring states: "This function uses the rules defined by the HTML 5 standard for both valid and invalid character references, and the list of HTML 5 named character references defined in html.entities.html5." HTML5 numeric-reference rules replace values above 0x10FFFF with U+FFFD.
Expected: A single U+FFFD replacement character.
Actual: ValueError: Exceeds the limit (4300 digits) for integer string conversion: value has 4301 digits.
import html
d = '9' * 4301
s = '&#' + d + ';'
n = d.lstrip('0') or '0'
if not d or any(c not in '0123456789' for c in d):
print('REFUTATION REJECTED: invalid decimal reference')
elif (len(n), n) <= (7, '1114111'):
print('REFUTATION REJECTED: value is not above 0x10FFFF')
else:
expected = '\uFFFD'
try:
actual = html.unescape(s)
except Exception as e:
actual = ('exception', type(e).__name__, str(e))
if actual != expected:
print('REFUTATION CONFIRMED:', repr(s), 'actual =', repr(actual),
'expected =', repr(expected))
else:
print('REFUTATION REJECTED: result matches HTML5')
Output on Python 3.14.6 (Windows-11-10.0.26220-SP0), standard library html:
999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999;' actual = ('exception', 'ValueError', 'Exceeds the limit (4300 digits) for integer string conversion: value has 4301 digits; use sys.set_int_max_str_digits() to increase the limit') expected = '�'
This report was found and written by an automated property-testing tool I run (bugforge). The reproducer above was executed and its output is pasted unedited; no person reviewed the report before it was filed. The search script is in https://github.com/augusto-rehfeldt/bugforge-results/tree/main/html-20261003-020338-c2
CPython versions tested on:
3.14
Operating systems tested on:
Windows
Bug report
Bug description:
Documented behaviour: The unescape docstring states: "This function uses the rules defined by the HTML 5 standard for both valid and invalid character references, and the list of HTML 5 named character references defined in html.entities.html5." HTML5 numeric-reference rules replace values above 0x10FFFF with U+FFFD.
Expected: A single U+FFFD replacement character.
Actual: ValueError: Exceeds the limit (4300 digits) for integer string conversion: value has 4301 digits.
Output on Python 3.14.6 (Windows-11-10.0.26220-SP0), standard library
html:This report was found and written by an automated property-testing tool I run (bugforge). The reproducer above was executed and its output is pasted unedited; no person reviewed the report before it was filed. The search script is in https://github.com/augusto-rehfeldt/bugforge-results/tree/main/html-20261003-020338-c2
CPython versions tested on:
3.14
Operating systems tested on:
Windows