Skip to content

plistlib XML serialization normalizes carriage returns in keys, causing silent data loss #158737

Description

@augusto-rehfeldt

Bug report

Bug description:

Documented behaviour: The plistlib module documentation states: "Values can be strings, integers, floats, booleans, tuples, lists, dictionaries (but only with string keys), Data, bytes, bytearray, or datetime.datetime objects." Its module introduction describes dump as writing the supplied value and load as returning the unpacked root object.

Expected: {'a\rb': 1, 'a\nb': 2}

Actual: {'a\nb': 1}

import plistlib

d = {'a\rb': 1, 'a\nb': 2}
valid = all(
    isinstance(k, str)
    and all(ord(c) in (9, 10, 13) or 32 <= ord(c) <= 0xD7FF
            or 0xE000 <= ord(c) <= 0xFFFD
            or 0x10000 <= ord(c) <= 0x10FFFF for c in k)
    and type(v) is int and -(1 << 63) <= v < (1 << 64)
    for k, v in d.items()
)
if not valid:
    print('REFUTATION REJECTED:', 'input outside documented domain')
else:
    expected = d.copy()
    actual = plistlib.loads(plistlib.dumps(d, fmt=plistlib.FMT_XML))
    if actual != expected:
        print('REFUTATION CONFIRMED:', repr(d), 'actual:', repr(actual),
              'expected:', repr(expected))
    else:
        print('REFUTATION REJECTED:', 'round-trip equals input')

Output on Python 3.14.6 (Windows-11-10.0.26220-SP0), standard library plistlib:

REFUTATION CONFIRMED: {'a\rb': 1, 'a\nb': 2} actual: {'a\nb': 1} expected: {'a\rb': 1, 'a\nb': 2}

This report was found and written by an automated property-testing tool I run (bugforge). The reproducer above was executed and its output is pasted unedited; no person reviewed the report before it was filed. The search script is in https://github.com/augusto-rehfeldt/bugforge-results/tree/main/plistlib-20261003-150942-c1

CPython versions tested on:

3.14

Operating systems tested on:

Windows

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions