Bug #66084 [ReO]: simplexml_load_string() mangles empty node name

From: Date: Tue, 26 May 2015 19:06:18 +0000
Subject: Bug #66084 [ReO]: simplexml_load_string() mangles empty node name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192898@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66084&edit=1

 ID:                 66084
 Updated by:         cmb@php.net
 Reported by:        php at kenman dot net
 Summary:            simplexml_load_string() mangles empty node name
 Status:             Re-Opened
 Type:               Bug
 Package:            SimpleXML related
 Operating System:   Win7
 PHP Version:        5.5Git-2013-11-12 (snap)
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Thanks, Anatol, for the quick reply. I've already committed tests
for four closely related bug reports (actually, they're duplicates)
to my sxe-var-dump branch[1]. However, I've noticed that bug #68946
and bug #67572, which I deemed related to this one, won't be fixed
with the given patch. I'll investigate.

With regard to older libxml versions: it seems very reasonable to
test with these. I'll see if I can build the mentionend versions
of libxml2 on Windows (some preliminary tests were successful).

[1] <https://github.com/cmb69/php-src/tree/sxe-var-dump>


Previous Comments:
------------------------------------------------------------------------
[2015-05-26 15:59:25] ab@php.net

Hi Christoph,

thanks for following on this. I don't have all the details in my head, however you go into the
same direction. Whether the check you've found works better only the tests can decide, i'd
say. If it is - so lets take it.

One note though. The trickiness of this ticket is - we deal not only with PHP itself actually, but
with the behavior change in libxml and the previous fix might have been not 100% sufficient. 

IMHO what should be done - we should ensure that this fix doesn't break things when PHP is
linked with 2.7.x to 2.9.x. Probably the easiest done on Linux when fetching particular libxml
version, installing into some prefix and compiling PHP with it.

Are you in the mood to do this? If it's ok under say PHP-5.5 and libxml 2.7.7 2.7.8 2.8.0 2.9.1
2.9.2 - then please create a PR with all the aggregated tests from the tickets you've found
related and ping me so i'll test it as well. Does it sound eligible to you?

Thanks.

------------------------------------------------------------------------
[2015-05-26 14:27:20] cmb@php.net

The following patch has been added/updated:

Patch Name: sxe-var-dump
Revision:   1432650439
URL:        https://bugs.php.net/patch-display.php?bug=66084&patch=sxe-var-dump&revision=1432650439

------------------------------------------------------------------------
[2015-05-26 14:26:36] cmb@php.net

Re-opened because of evgeniy's comment. This bug seems to be
closely related to bug #62639.

Adding the check for !node->next in the commit apparently only
solves some issues. It seems to me that instead it has to be
checked for sxe->iter.type, because when this is SXE_ITER_NONE it
doesn't make sense to execute the else clause.

With the attached patch sxe-var-dump.patch all ext/simplexml/tests
run fine, as well as the test script of bug #69491.

Anantol, can you please have a look at the issue. If useful, I can
make a pull request with some further tests regarding whitespace
issues.

------------------------------------------------------------------------
[2014-10-07 23:26:47] stas@php.net

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src-security.git;a=commit;h=a0beddf5e9ab3c6feaf0921be72a7f430597abea
Log: Fixed bug #66084 simplexml_load_string() mangles empty node name

------------------------------------------------------------------------
[2014-10-07 23:15:40] stas@php.net

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src-security.git;a=commit;h=a0beddf5e9ab3c6feaf0921be72a7f430597abea
Log: Fixed bug #66084 simplexml_load_string() mangles empty node name

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66084


--
Edit this bug report at https://bugs.php.net/bug.php?id=66084&edit=1


Thread (23 messages)

« previous php.bugs (#192898) next »