oxrdf’s RDFC-1.0 canonicalization API has no configurable work limit:
pub fn canonicalize(&mut self, algorithm: CanonicalizationAlgorithm)
Because RDFC canonicalization can have exponential worst-case complexity, callers cannot safely process untrusted datasets or detect resource exhaustion.
This also prevents the W3C dataset-poisoning negative test test074c from being evaluated. Oxigraph currently marks negative tests successful without running them:
|_| Ok(()), // TODO: not a proper implementation
Proposal
Add a fallible canonicalization API with a configurable, deterministic work limit. Exceeding the limit should return an error such as ComplexityLimitExceeded.
Then update the test runner to execute test074c and assert that the limit is reached.
W3C test: https://w3c.github.io/rdf-canon/tests/manifest.ttl
oxrdf’s RDFC-1.0 canonicalization API has no configurable work limit:Because RDFC canonicalization can have exponential worst-case complexity, callers cannot safely process untrusted datasets or detect resource exhaustion.
This also prevents the W3C dataset-poisoning negative test
test074cfrom being evaluated. Oxigraph currently marks negative tests successful without running them:Proposal
Add a fallible canonicalization API with a configurable, deterministic work limit. Exceeding the limit should return an error such as
ComplexityLimitExceeded.Then update the test runner to execute
test074cand assert that the limit is reached.W3C test: https://w3c.github.io/rdf-canon/tests/manifest.ttl