Bug #68437 [NEW]: saveXML produces invalid xml
| From: | lphp-bug at thax dot hardliners dot org | Date: | Mon, 17 Nov 2014 18:50:45 +0000 |
| Subject: | Bug #68437 [NEW]: saveXML produces invalid xml | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188642@lists.php.net to get a copy of this message | ||
From: lphp-bug at thax dot hardliners dot org
Operating system:
PHP version: master-Git-2014-11-17 (Git)
Package: DOM XML related
Bug Type: Bug
Bug description:saveXML produces invalid xml
Description:
------------
Bug #54214 has been closed as Bogus, but gets the facts wrong:
1. XML (even the 1998 working drafts) defines valid chars as:
Char ::= #x9 | #xA | #xD | [#x20-#xD7FF] | [#xE000-#xFFFD] |
[#x10000-#x10FFFF]
This contradicts #54214 that Char ::= [#x1-#xD7FF] | ...
Thus, 0x0b (or 0x06) are actually not in the valid Range.
2. libxml2 "problem" is not saving low-ascii chars, but loading them:
loadXML(saveXML()) ALWAYS fails, when e.g. DOMText with low-ascii is
present:
DOMDocument::loadXML(): xmlParseCharRef: invalid xmlChar value 11 in
Entity
3. saveXML() does not always warn.
More specifically, it only warns when
(*) $doc has no encoding AND
(**) saveXML() is called without arguments.
4. When saveXML() does warn, it will remove the offending character
(good), but not when it does not warn.
Background:
- saveXML() uses xmlDocDumpFormatMemory(), which uses document encoding,
when given. Otherwise ascii encoding (0x00 ... 0x7f only) is assumed,
and xmlEscapeEntities (libxml2/tree/xmlsave.c, line 208) is used as
escape-function.
This function warns and ignores the offending character
- saveXML($el) uses xmlNodeDump(), which passes encoding==NULL to
xmlNodeDumpOuput, which converts NULL to "UTF-8". Then xmlSaveCtxtInit()
will not set the escape-function.
When the escape-function is not set on the xmlSaveCtxt,
xmlOutputBufferWriteEscape will use xmlEscapeContent
(libxml2/tree/xmlIO.c, line 3536) instead. This function does not warn,
and happily includes 0x0b in the output (where finally loadXML chokes on
it).
Libxml never says that it will warn for low-ascii chars. Thus
php-developers can't depend on it.
OTOH, it's unfeasible to force every php-programmer to pre-sanitize
strings sent into DOMText, or post-check the saved xml string. Therefore
php has to provide the necessary means to avoid invalid xmls -- i.e. at
the very least warn, or even better: throw already in DOMText.
Test script:
---------------
$doc=new DOMDocument('1.0','utf-8'); // or: $doc=new
DOMDocument('1.0');
(*)
$el=$doc->createElement('root');
$doc->appendChild($el);
$el->appendChild(new DOMText("\x0b asdf"));
$str=$doc->saveXML($el); // or: $doc->saveXML() (**)
var_dump($str);
$doc->loadXML($str);
Expected result:
----------------
loadXML shall load the saved xml, or throw an exception earlier.
Actual result:
--------------
loadXML only works when (*) and (**) are used, i.e. when saveXML outputs
a warning.
--
Edit bug report at https://bugs.php.net/bug.php?id=68437&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68437&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68437&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68437&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68437&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68437&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68437&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68437&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68437&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68437&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68437&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68437&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68437&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68437&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68437&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68437&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68437&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68437&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68437&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68437&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68437&r=mysqlcfg