Hardens the bounded OPC package-signature shape around XMLDSIG SignedInfo method declarations.
- Requires direct
ds:CanonicalizationMethodandds:SignatureMethodelements to carry exactly their requiredAlgorithmattribute. - Preserves schema-permitted method parameter child markup; this is structural hardening, not XMLDSIG parameter, transform, schema, or cryptographic validation.
- Validated by 73 tests, successful main and tag CI matrices, and exact unchanged profiles across the 29-document OOXML Signature Security corpus. Its 21 parseable signature parts use only
Algorithmon both method kinds. - Independently reproducible artifacts: wheel SHA-256
b5ae20ee7164ce323a77776d42d8568e71b1b7ea7a0d31694e84bb6cb7b7ad42; source SHA-256a4a23e70d3e0ee419ebedfc57f3f4b447f72e55541bcd61f841480db1ba1a8ba.