"""Parsers for input the repo does not control. Upstream DATs and scraped documents are data, never instructions, and the parsers here are the boundary that keeps it that way.""" from __future__ import annotations import xml.etree.ElementTree as ET try: import yaml except ImportError: # optional at import time yaml = None def parse_untrusted_xml(content: str | bytes, label: str = "XML") -> ET.Element: """Parse XML fetched from a third party. ElementTree expands internal entities, so a document that declares them can make the parser build a payload far larger than the bytes downloaded. Nothing this project reads (DAT packs, es_bios.xml, Emulators.xml) ever declares one, so a declaration is grounds to refuse the document rather than something to expand carefully. The check targets