
❌ This issue is not open for contribution. Visit Contributing guidelines to learn about the contributing process and how to find suitable issues.

Target branch: unstable
Observed behavior
validate_qti_item raises lxml.etree.XMLSchemaValidateError: Internal error in XML Schema validation. on an item with an internal-subset entity declaration that the body references.
QTIExerciseGenerator._create_native_qti_item does not catch it, and create_exercise_archive runs the item loop without a try, so it propagates out of the publish.
Every other invalid item is logged and excluded from the package.
Errors and logs
>>> validate_qti_item('<!DOCTYPE qti-assessment-item [<!ENTITY e "zz">]><qti-assessment-item xmlns="http://www.imsglobal.org/xsd/imsqtiasi_v3p0" identifier="i" title="t" adaptive="false" time-dependent="false"><qti-item-body><p>&e;</p></qti-item-body></qti-assessment-item>')
lxml.etree.XMLSchemaValidateError: Internal error in XML Schema validation.
Expected behavior
The item is reported invalid, logged, and left out of the package like any other schema failure. The rest of the channel publishes.
User-facing consequences
One stored type == qti item (ricecooker upload or direct sync write; the parser comment in validation.py treats this input as untrusted) blocks publishing the whole channel.
Steps to reproduce
- Store the XML above as
raw_data of a qti AssessmentItem on an exercise.
- Publish the channel.
- Publish fails with
XMLSchemaValidateError.
Context
AI usage
I used Claude Code to review the #6223 branch and reproduce this against upstream/unstable with validate_qti_item. I did not run a full publish; the propagation through create_exercise_archive is read from the code.
❌ This issue is not open for contribution. Visit Contributing guidelines to learn about the contributing process and how to find suitable issues.
Target branch: unstable
Observed behavior
validate_qti_itemraiseslxml.etree.XMLSchemaValidateError: Internal error in XML Schema validation.on an item with an internal-subset entity declaration that the body references.QTIExerciseGenerator._create_native_qti_itemdoes not catch it, andcreate_exercise_archiveruns the item loop without atry, so it propagates out of the publish.Every other invalid item is logged and excluded from the package.
Errors and logs
Expected behavior
The item is reported invalid, logged, and left out of the package like any other schema failure. The rest of the channel publishes.
User-facing consequences
One stored
type == qtiitem (ricecooker upload or direct sync write; the parser comment invalidation.pytreats this input as untrusted) blocks publishing the whole channel.Steps to reproduce
raw_dataof aqtiAssessmentItemon an exercise.XMLSchemaValidateError.Context
contentcuration/contentcuration/utils/assessment/qti/validation.pyvalidate_qti_itemupstream/unstableand is not caused by that branch.AI usage
I used Claude Code to review the #6223 branch and reproduce this against
upstream/unstablewithvalidate_qti_item. I did not run a full publish; the propagation throughcreate_exercise_archiveis read from the code.