Extensible Markup Language (.xml)

W3C 標準

Extensible Markup Language (XML) is a versatile markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable.

XMLをオンラインで圧縮

ブラウザ内100%ローカル圧縮 — ファイルが外部サーバーに送信されることはありません

調査とメタデータ

オペレーティングシステムやファイル解析ツールは、先頭のバイナリバイトシーケンスを検査することで XML ファイルを識別します:

ファイルを選択またはドラッグ

ここにファイルを選択またはドロップ

100%プライベートなブラウザ内変換 - ファイルがデバイスから外部に出ることはありません

または貼り付け Ctrl+V
ネットワーク送信ゼロのプライバシー保証: 外部サーバーへのデータ送信は0バイトです。すべての処理はお使いのブラウザのサンドボックス内でローカルに実行されます。

バイトレベルのヘッダーシグネチャ (マジックバイト)

オペレーティングシステムやファイル解析ツールは、先頭のバイナリバイトシーケンスを検査することで XML ファイルを識別します:

16進数シグネチャ (オフセット 0):

3C 3F 78 6D

ASCII表現: <?xm

標準化: W3C Recommendation (XML 1.0 Fifth Edition)

技術仕様

コンテナアーキテクチャHierarchical text markup language with custom semantic tags and attributes
圧縮Gzip / Deflate achieves 85%-92% compression on verbose closing tags
バイトエンディアンUTF-8 / UTF-16 character stream determined by XML declaration encoding attribute
色空間Not applicable
チャンネルと構造Elements (<tag>), attributes (attr="val"), CDATA blocks, processing instructions
最大寸法Unbounded hierarchical tree structure
透過性Not applicable
ストリーミングとプログレッシブSAX (Simple API for XML) and StAX parsers enable memory-efficient stream reading

技術比較マトリックス: XML 対 競合製品

技術属性XML (現在)JSONYAMLProtocol Buffers
VerbosityHigh (closing tags and attribute syntax)Low (compact key-value format)Low (indentation-based)Ultra-low (binary serialization)
Schema ValidationMature XSD & DTD standards with compiler enforcementJSON Schema (optional)JSON Schema / Yaml schemasStrict .proto schema definitions
NamespacesNative XML namespaces (xmlns) supportNo native namespace mechanismNo native namespace mechanismPackage declarations
TransformationsXSLT declarative transformation pipelinesCustom code / jq scriptsCustom codeCustom code

一般的な破損モードと16進数リカバリガイド

⚠️ XML Parsing Error: mismatched tag or entity not defined.

根本原因: Unescaped reserved characters (like '&', '<', or '>') or case mismatch between opening and closing tags.

復旧: Replace '&' with '&amp;', '<' with '&lt;', '>' with '&gt;', or wrap arbitrary text inside '<![CDATA[ ... ]]>'' blocks.

セキュリティ分析とパーサー攻撃ベクトル

XML parsers have historically been one of the most attacked components in enterprise computing due to powerful DTD and entity expansion capabilities.

既知の攻撃ベクター

  • XML External Entity (XXE): Malicious DOCTYPE referencing local server files ('file:///etc/passwd') or internal network endpoints.
  • Billion Laughs Attack (XML Bomb): Nested entity declarations expanding exponentially in memory to cause denial of service.
  • XPath Injection: Unsanitized user inputs allowing unauthorized querying of XML databases.

防御的ベストプラクティス: Always disable external DTD resolution and external entity processing (setFeature 'disallow-doctype-decl' to true) in XML parsers.

歴史的背景とマイルストーン

2008W3C publishes XML 1.0 Fifth Edition, standardizing modern international character support.
1998W3C publishes XML 1.0 Recommendation as a simplified, web-friendly subset of SGML.

主な利点とメリット

  • Rigorous schema validation using XSD (XML Schema Definition) or DTD ensures strict data integrity.
  • Namespaces (xmlns) prevent element name collisions in complex multi-source documents.
  • Powerful querying and transformation toolchains (XPath, XSLT, XQuery).

技術的な制限とデメリット

  • Extremely verbose: closing tags repeat element names, creating large file sizes and high bandwidth consumption.
  • DOM parsing builds large memory-intensive object trees.
  • Prone to XML External Entity (XXE) and entity expansion security vulnerabilities.

興味深い技術トリビア

  • XML is a simplified subset of SGML (Standard Generalized Markup Language), designed to work seamlessly over the World Wide Web.
  • Modern office documents (.docx, .xlsx), vector images (.svg), and RSS feeds are all specialized XML dialects.

よくある技術的な質問

What is the difference between well-formed and valid XML?

'Well-formed' XML follows the basic syntax rules (matching tags, quotes around attributes, single root element). 'Valid' XML is well-formed AND adheres strictly to an external schema definition (XSD or DTD).

Why did JSON replace XML for most web APIs?

JSON maps directly to native JavaScript and programming language data structures (hash maps and arrays) with much less boilerplate, faster parsing, and smaller network payloads.