PhoenixmlDb.XQuery 2.5.0

There is a newer version of this package available.
See the version list below for details.
dotnet add package PhoenixmlDb.XQuery --version 2.5.0
                    
NuGet\Install-Package PhoenixmlDb.XQuery -Version 2.5.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="PhoenixmlDb.XQuery" Version="2.5.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="PhoenixmlDb.XQuery" Version="2.5.0" />
                    
Directory.Packages.props
<PackageReference Include="PhoenixmlDb.XQuery" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add PhoenixmlDb.XQuery --version 2.5.0
                    
#r "nuget: PhoenixmlDb.XQuery, 2.5.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package PhoenixmlDb.XQuery@2.5.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=PhoenixmlDb.XQuery&version=2.5.0
                    
Install as a Cake Addin
#tool nuget:?package=PhoenixmlDb.XQuery&version=2.5.0
                    
Install as a Cake Tool

PhoenixmlDb.XQuery

XQuery 4.0 query engine for PhoenixmlDb — query XML and JSON documents with the full power of XQuery.

Features

  • Full XQuery 4.0 — FLWOR expressions, constructors, modules, user-defined functions
  • XPath 4.0 — complete XPath implementation with 240+ built-in functions
  • JSON support — json-doc(), parse-json(), maps, arrays — query JSON natively
  • Full-text search — contains text with stemming, wildcards, proximity, scoring
  • Update Facility — insert, delete, replace, rename, transform expressions
  • Type system — records, enums, union types (XQuery 4.0)

Quick example

using PhoenixmlDb.XQuery.Execution;

var engine = new QueryEngine();

// Simple query
var results = engine.ExecuteToListAsync(
    "for $x in 1 to 10 where $x mod 2 = 0 return $x * $x");

// Query XML documents
var books = engine.ExecuteAsync(
    "//book[price > 30]/title",
    containerId);
Package Description
PhoenixmlDb.Core Core types and XDM data model (dependency)
PhoenixmlDb.Xslt XSLT 4.0 transformation engine
PhoenixmlDb.XQuery.Cli xquery command-line tool

Documentation

Full documentation at phoenixml.dev

License

Apache 2.0

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on PhoenixmlDb.XQuery:

Package Downloads
PhoenixmlDb.Xslt

XSLT 4.0 transformation engine for PhoenixmlDb

Phoenixml.Platform.Editor.Xml

XML/XSD vocabulary binding for Phoenixml.Platform — concrete IDocument and ITreeNodeProvider implementations against PhoenixmlDb.Core's XDM, XSD schema validation pipeline.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.8.0 0 10/9/2026
2.7.0 83 10/7/2026
2.6.0 129 10/6/2026
2.5.1 354 10/1/2026
2.5.0 92 10/1/2026
2.4.1 405 9/28/2026
2.4.0 137 9/28/2026
2.3.0 125 9/28/2026
2.2.0 186 9/24/2026
2.1.0 332 9/17/2026
2.0.0 355 9/15/2026
1.8.0 298 9/14/2026
1.7.0 684 9/11/2026
1.6.15 205 9/9/2026
1.6.14 192 9/7/2026
1.6.13 158 9/4/2026
1.6.12 182 9/1/2026
1.6.11 154 8/29/2026
1.6.10 177 8/29/2026
1.6.9 241 8/27/2026
Loading failed

Takes **PhoenixmlDb.Core 2.0.0** (unchanged). PhoenixmlDb.Xslt 2.5.0 requires this release.

### Security: `ResourcePolicy` is enforced on every read (GHSA-wjxc-7p24-xf7w)

`ResourcePolicy`, `ServerDefault` included, was enforced only on the document resolver that
`XQueryFacade` wrapped, so only `fn:doc` and `fn:collection` were checked. A query running under a
restrictive policy could still read local files and reach the network through other functions.
Every URI or path dereference now goes through one check, `ResourcePolicy.Authorize`, and the
reader opens the URI it returns:

- **Text and JSON:** `fn:unparsed-text`, `-lines` and `-available`, and `fn:json-doc` → `FOUT1170`.
- **Modules:** `import module … at` and `fn:load-xquery-module` location hints → `XQST0059`.
- **`fn:parse-xml`:** external entities and external DTD subsets are fetched only when the policy
 allows DTD processing, and then only from allowed locations.
- **Schemas:** `import schema … at`, and every document a schema includes or imports.
- **HTTP:** redirects are re-authorised at every hop. The process-wide remote-module cache
 serves only compilations without a policy.

The policy rules are stricter:

- Read access no longer implies import access.
- An empty rule list denies.
- A host rule admits only the default port unless one is given (`UriRule.Port`, `UriRule.AnyPort`).
- Path prefixes match whole segments, case-sensitively where the file system is, and are compared
 with the canonical path (symbolic links resolved).
- A rooted path (`/etc/x`) is a `file:` URI, not a relative reference.

New API:

- `QueryEngine.ResourcePolicy`.
- Public `ResourcePolicy.IsAllowed`, `Authorize`, `TryAuthorize`, `Resolve` and `CanonicalPath`.
- `PolicyEnforcingResolver` (now public) and `PolicyXmlResolver`.
- `ISchemaProvider.ImportSchema(…, ResourcePolicy?)`.

**With no policy configured, nothing changes.** `ResourcePolicy.Unrestricted` is not the same as
no policy: it disables external entities and DTDs, and like any policy it re-checks redirects and
does not use the remote-module cache. Hosts that run untrusted queries should upgrade.

### Added

- **Schema-defined simple types** work as item types and as constructor functions.
- **`fn:json-to-xml`** has a built-in schema for its output, and supports the `validate` option.
 Schema types are allowed in `element(*, T)` tests.
- **XSD 1.1:** conditional inclusion (`vc:minVersion` / `vc:maxVersion`), and the 1.1 built-in
 types resolve in imported schemas.
- **`XQueryFunction.BindCreationContext`:** a function item can capture the context of the
 expression that created it.
- **`CompilationOptions.AllowNamespaceAxis`.**

### Fixed

- **Deep documents** no longer crash the process: descendant navigation and `fn:parse-xml` are
 iterative (#95, #102).
- **External functions** bind to the host's implementation; an unbound one is `XPST0017` (#18).
- **Full text:** each match option controls its own analysis stage (#70, #29, #30), and
 `phx:score` returns the relevance of a `contains text` match (#71).
- **Comparison:** `fn:atomic-equal` follows `op:same-key`; untypedAtomic range operands raise
 `FORG0001` (#5).
- **Maps and arrays:** calling one with an empty value returns the empty sequence.
- **Error codes:** errors that leaked raw .NET exceptions now raise the codes the specifications
 assign. That covers casts, out-of-range durations and dates, array positions, `fn:avg` and
 `fn:abs` on non-numerics, `format-date`/`-time`/`-number`, constructor functions, library-module
 context items, and node-test static errors.
- **Schemas:**
 - Casts to schema types derived from `xs:QName` resolve their prefix.
 - Validated documents are distinct trees.
 - `ISchemaProvider.Validate(node)` validates the node's markup (#40).
 - An unreadable schema location hint is `XQST0059`.
- **`fn:load-xquery-module`** resolves modules the host mapped.

### Conformance

QT3: **1484 failing at 2.4.0 → 708 at 2.5.0.** Much of that drop came from fixing the
conformance harness rather than the engine: it had misjudged correct results (permutation,
`normalize-space`, decimal formats, `assert-xml` on documents, environment parameters and
namespaces). A guard test (`HarnessVocabularyTests`) now requires every catalog element and
attribute to be handled, ignored on purpose, or listed as a known gap.