Skip to content

DocFence 0.58.0

Choose a tag to compare

@SybilGambleyyu SybilGambleyyu released this 06 Aug 11:01

DocFence 0.58.0 enforces the OPC relationship-selector shape everywhere in a recognized package XML signature.

An opc:RelationshipReference must be a direct child of a Relationship Transform with exactly SourceId and no child elements. An opc:RelationshipsGroupReference must likewise be a direct child with exactly SourceType and no child elements. Standalone selectors, wrong parents, missing/wrong/extra attributes, and nested selector markup now fail the recognized signature shape closed.

This is a stored-markup boundary applied before the bounded declaration-coverage audit. It does not resolve or interpret a selector value, execute a transform, recompute a digest, verify XMLDSIG, or make a trust decision. A present but empty selector value remains an aggregate coverage concern rather than a global selector-shape rejection.

Validation:

  • 69 tests passed locally and in tagged CI on Python 3.11 and 3.13.
  • A 0.57-versus-0.58 comparison shows 0.57 accepted standalone, missing-attribute, extra-attribute, nested, and wrong-selector-attribute forms; 0.58 rejects each. The standards-shaped declaration remains accepted.
  • The public OOXML Signature Security corpus has 29 DOCX files, 22 XML signature parts, and 21 parseable signature parts. Its 38 Relationship Transforms contain 106 direct relationship selectors, all with the expected parent, attribute, and child-free shape; public profiles are unchanged from 0.57.
  • Two independent tagged builds were byte-identical.

SHA-256:

  • docfence-0.58.0-py3-none-any.whl: 73459b477d2ca7a1a02cebbdd31ade40df4f1e4b53d34b1872b430b1022b5415
  • docfence-0.58.0.tar.gz: 0c8a3105cdd1401aec93079332a5a4542842b8d30e24136acc162072a6525f42