Skip to main content

pyuppsala

Python bindings for the Uppsala XML library -- a zero-dependency, pure-Rust implementation of XML 1.0, Namespaces, XPath 1.0, and XSD validation.

pyuppsala gives you a fast, correct, and memory-safe XML toolkit from Python with no C dependencies to compile and no transitive native libraries to audit.

This release is against 0.10.1 of Uppsala library.

Features

  • XML 1.0 parsing with full well-formedness checking
  • Namespace-aware DOM with tree mutation (create, append, insert, remove, detach)
  • XPath 1.0 evaluation (all axes, functions, predicates)
  • XSD validation (structures + datatypes, 40+ built-in types, facets, complex types)
  • XSD regex pattern matching (Unicode categories, blocks, character class subtraction)
  • XSLT 1.0 transforms with bounded template recursion
  • Imperative XML builder (XmlWriter) for constructing output without a DOM
  • Serialization with pretty-printing, compact output, and streaming to files
  • Automatic encoding detection for UTF-8 and UTF-16 (LE/BE)
  • lxml.etree-compatible API via pyuppsala.etree, a near drop-in for much of lxml.etree backed by Uppsala's secure parser
  • Native batch and fast etree paths for parsing many documents and running simple large-tree aggregates without one Python object per matched node

Read the full documentation

Security defaults

pyuppsala keeps the main XML attack classes bounded by default:

  • Parser resource caps are enabled by default for element depth, entity expansion size, and entity-reference nesting.
  • DTDs and entity declarations are accepted by default for compatibility, but entity expansion is capped. Use forbid_dtd=True or forbid_entities=True when parsing untrusted XML that should not contain DTDs or entity declarations.
  • XPath evaluation is capped by expression depth and by a per-evaluation node visit budget. Do not let untrusted callers choose max_depth or max_node_visits.
  • XSD regex matching has group-depth and backtracking-step limits. Do not let untrusted callers raise max_steps.
  • XSLT template recursion is capped by default. Treat stylesheets as trusted application configuration; EXSLT compatibility is enabled by default.
  • Document mutators reject Node handles from another document. Use Document.import_subtree() for intentional cross-document copies.
  • pyuppsala.etree keeps parser caps on by default. huge_tree=True lifts those caps for lxml compatibility and should only be used with trusted XML.
  • XInclude processing is explicit. Remote includes require network_access=True; local includes are restricted to the including document's base directory and are size-limited.
  • Native fetch helpers (available only in builds with the default-on net feature; gate use on pyuppsala._HAS_NET) cap response bodies at 128 MiB by default, including file:// reads, and keep TLS verification enabled by default. Apply your own URL allowlist before fetching attacker-controlled URLs.

See the resource limits and hardening guide and the API security notes for all knobs and default values.

Installation

python3 -m pip install pyuppsala

Or with uv:

uv add pyuppsala

Wheels are compiled from Rust via maturin. Python 3.10+ is required.

Quick start

Parse and query

from pyuppsala import Document, XPathEvaluator

doc = Document("<bookstore><book><title>Moby Dick</title></book></bookstore>")
doc.prepare_xpath()

xpath = XPathEvaluator()
title = xpath.evaluate(doc, "string(//title)")
print(title)  # "Moby Dick"

Build XML

from pyuppsala import XmlWriter

w = XmlWriter()
w.write_declaration()
w.start_element("catalog", [("xmlns", "urn:example")])
w.start_element("item", [("id", "1")])
w.text("Widget")
w.end_element("item")
w.end_element("catalog")
print(w.to_string())

Validate against an XSD schema

from pyuppsala import XsdValidator

schema = """\
<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema">
  <xs:element name="greeting" type="xs:string"/>
</xs:schema>
"""

validator = XsdValidator(schema)
print(validator.is_valid_str("<greeting>Hello!</greeting>"))  # True
print(validator.is_valid_str("<greeting><bad/></greeting>"))  # False

Mutate the DOM

from pyuppsala import Document

doc = Document("<root><a/></root>")
root = doc.document_element
b = doc.create_element("b")
doc.append_child(root, b)
print(doc.to_xml())  # <root><a/><b/></root>

XSD regex

from pyuppsala import XsdRegex

regex = XsdRegex(r"[0-9]{5}")
print(regex.is_match("12345"))  # True
print(regex.is_match("abcde"))  # False

lxml-compatible etree API

Code written for lxml.etree runs after swapping the import. Elements are live views over the underlying document, with stable identity and the familiar .text/.tail/.attrib model.

from pyuppsala import etree  # instead of: from lxml import etree

root = etree.fromstring("<catalog><book id='1'>Dune</book></catalog>")
print(root.find("book").text)        # Dune
print(root[0].get("id"))             # 1

cat = etree.Element("catalog")
book = etree.SubElement(cat, "book", {"id": "2"})
book.text = "Neuromancer"
print(etree.tostring(cat, encoding="unicode"))
# <catalog><book id="2">Neuromancer</book></catalog>

See the etree documentation for the supported and unsupported feature matrix.

API overview

Class / function Purpose
Document(xml) Parse XML string into a DOM
Document.from_bytes(data) Parse XML bytes (auto-detects UTF-8/UTF-16)
Document.empty() Create an empty document for building from scratch
Node A handle to a node in the document tree
QName A qualified XML name (local name + optional namespace + prefix)
Attribute An XML attribute (name + value)
XPathEvaluator Evaluate XPath 1.0 expressions
XsdValidator(schema) Validate documents against an XSD schema
XmlWriter Imperative XML builder (no DOM needed)
XsdRegex(pattern) XSD regular expression pattern matcher
Xslt(stylesheet_xml) Compile and apply XSLT 1.0 stylesheets
parse(xml) Module-level shorthand for Document(xml)
parse_bytes(data) Module-level shorthand for Document.from_bytes(data)
parse_many(items) Parse many XML strings or byte strings in native worker threads
fetch_many(urls) Fetch many HTTP(S) or file URLs with body limits and per-item results (requires pyuppsala._HAS_NET)
fetch_and_parse_many(urls) Fetch many URLs and parse each response as XML (requires pyuppsala._HAS_NET)
pyuppsala.etree lxml.etree-compatible API (Element, SubElement, fromstring, tostring, find/findall, XPath, XMLSchema, ...)
etree.fromstring_many(items) Parse many documents into etree roots with per-item errors
_Element.fast_*() Native count/existence/attribute/text-group scans for large etree subtrees

Exceptions

Exception Raised when
XmlParseError XML is syntactically malformed
XmlWellFormednessError XML violates well-formedness constraints
XmlNamespaceError Namespace prefix is undeclared or misused
XPathError XPath expression is invalid
XsdValidationError XSD schema itself is invalid

All exceptions inherit from Exception.

Type stubs

Type stubs (pyuppsala/__init__.pyi and pyuppsala/etree.pyi, marked with py.typed) ship with the package for full IDE auto-completion and type-checking with mypy/pyright.

Development

# Clone the repository
git clone https://github.com/kushaldas/pyuppsala.git
cd pyuppsala

# Set up the environment with uv
uv sync

# Build the native extension in development mode
uv run maturin develop

# Run the test suite
uv run pytest

# Build a release wheel
uv run maturin build --release

License

BSD-2-Clause

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pyuppsala-0.11.0.tar.gz (247.5 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

pyuppsala-0.11.0-cp310-abi3-win_arm64.whl (1.8 MB view details)

Uploaded CPython 3.10+Windows ARM64

pyuppsala-0.11.0-cp310-abi3-win_amd64.whl (1.9 MB view details)

Uploaded CPython 3.10+Windows x86-64

pyuppsala-0.11.0-cp310-abi3-manylinux_2_28_x86_64.whl (1.9 MB view details)

Uploaded CPython 3.10+manylinux: glibc 2.28+ x86-64

pyuppsala-0.11.0-cp310-abi3-macosx_11_0_arm64.whl (1.7 MB view details)

Uploaded CPython 3.10+macOS 11.0+ ARM64

File details

Details for the file pyuppsala-0.11.0.tar.gz.

File metadata

  • Download URL: pyuppsala-0.11.0.tar.gz
  • Upload date:
  • Size: 247.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pyuppsala-0.11.0.tar.gz
Algorithm Hash digest
SHA256 043c640c6d984a1746def838b3690f2ce679f2512f054155e0c202f71c43a561
MD5 cbfdb44374abede3f3dbf46015dd3639
BLAKE2b-256 73a89a324fb7c5844206edcd633fb0e8d424fbc1d1d5c23806c0d50a2a1cf21e

See more details on using hashes here.

Provenance

The following attestation bundles were made for pyuppsala-0.11.0.tar.gz:

Publisher: release.yml on kushaldas/pyuppsala

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pyuppsala-0.11.0-cp310-abi3-win_arm64.whl.

File metadata

  • Download URL: pyuppsala-0.11.0-cp310-abi3-win_arm64.whl
  • Upload date:
  • Size: 1.8 MB
  • Tags: CPython 3.10+, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pyuppsala-0.11.0-cp310-abi3-win_arm64.whl
Algorithm Hash digest
SHA256 3cbea175956b3a668e053609c2e33bf1d2d9ac56f0e6ebb197a686ab86ff1817
MD5 ec360af4a281c317d7493f4b74e39ead
BLAKE2b-256 0cb2c44883d69aa1778325621e50fca416c9e4d97622de443ffd0813a5e8d273

See more details on using hashes here.

Provenance

The following attestation bundles were made for pyuppsala-0.11.0-cp310-abi3-win_arm64.whl:

Publisher: release.yml on kushaldas/pyuppsala

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pyuppsala-0.11.0-cp310-abi3-win_amd64.whl.

File metadata

  • Download URL: pyuppsala-0.11.0-cp310-abi3-win_amd64.whl
  • Upload date:
  • Size: 1.9 MB
  • Tags: CPython 3.10+, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pyuppsala-0.11.0-cp310-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 9479706c104e6f9896230215afd3fbb2c374590b7814ee3e68b23bd3152b4505
MD5 6418e05f11b72d3792a7dc01ed2b7cc9
BLAKE2b-256 26414a793a0a0571c6c8a8f1d6df7a91858d3d878833721e6d44c741a9224ee3

See more details on using hashes here.

Provenance

The following attestation bundles were made for pyuppsala-0.11.0-cp310-abi3-win_amd64.whl:

Publisher: release.yml on kushaldas/pyuppsala

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pyuppsala-0.11.0-cp310-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for pyuppsala-0.11.0-cp310-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 8555c13db4a8d4cf4503f032a69b5c22b77d216d17e5e001f37e6dfec021e964
MD5 dc28c1417a100054f5750bbf2b60a57e
BLAKE2b-256 1e69155a5130c90a5fe6c49fb2e73258bbeca88fb933cd416e76ee4f5108e397

See more details on using hashes here.

Provenance

The following attestation bundles were made for pyuppsala-0.11.0-cp310-abi3-manylinux_2_28_x86_64.whl:

Publisher: release.yml on kushaldas/pyuppsala

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pyuppsala-0.11.0-cp310-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for pyuppsala-0.11.0-cp310-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 c96b11ec5e220a1c9473a34b7b37c3c34df1e5772093ee096837195df00cfea9
MD5 b1032619df1c13c3ac549bc1e4906f1b
BLAKE2b-256 d59fca7bf543b628b63af4929ba1a42dfb7927aa30400ef832329c7185d9e915

See more details on using hashes here.

Provenance

The following attestation bundles were made for pyuppsala-0.11.0-cp310-abi3-macosx_11_0_arm64.whl:

Publisher: release.yml on kushaldas/pyuppsala

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.11.0 This release

5 files

0.10.0

5 files

0.9.1

5 files

0.9.0

5 files

0.8.0

5 files

0.7.1

5 files

0.7.0

5 files

0.6.0

5 files

0.5.1

5 files

0.4.0

5 files

0.3.1

5 files

0.3.0

5 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page