Skip to content

RDFC-1.0: bounded canonicalization and dataset-poisoning #1838

Description

@eljeffeg

oxrdf’s RDFC-1.0 canonicalization API has no configurable work limit:

pub fn canonicalize(&mut self, algorithm: CanonicalizationAlgorithm)

Because RDFC canonicalization can have exponential worst-case complexity, callers cannot safely process untrusted datasets or detect resource exhaustion.

This also prevents the W3C dataset-poisoning negative test test074c from being evaluated. Oxigraph currently marks negative tests successful without running them:

|_| Ok(()), // TODO: not a proper implementation

Proposal

Add a fallible canonicalization API with a configurable, deterministic work limit. Exceeding the limit should return an error such as ComplexityLimitExceeded.

Then update the test runner to execute test074c and assert that the limit is reached.

W3C test: https://w3c.github.io/rdf-canon/tests/manifest.ttl

Activity

  1. Tpt commented on Aug 2, 2026

    @Tpt
    Collaborator

    Great point! Seems like I completely forgot about this test. The open thing is to figure out a good way to define "work limit" in a not too painful way. Will investigate that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions