Edit report at https://bugs.php.net/bug.php?id=66084&edit=1
ID: 66084
Updated by: ab@php.net
Reported by: php at kenman dot net
Summary: simplexml_load_string() mangles empty node name
Status: Re-Opened
Type: Bug
Package: SimpleXML related
Operating System: Win7
PHP Version: 5.5Git-2013-11-12 (snap)
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Christoph,
building older libxml on Windows doesn't make sense, so you can spare the work. libxml 2.9.2 is
used now from 5.5 to 7 and people usually use our dep builds, thus the firm versions we've
tested. Thus testing 2.9.2 which is provided on Windows is enough.
But the change will most likely affect Linux as the variety of libxml versions is used in the
distributions while the code in PHP is the same (fe see the description of this report) and is also
shared across PHP versions. On Linux it's done using say ./configure=/install/to/libxml-x.y.z
&& make install and then pointing PHP to there --with-libxml-dir.
Thanks
Previous Comments:
------------------------------------------------------------------------
[2015-05-26 19:06:17] cmb@php.net
Thanks, Anatol, for the quick reply. I've already committed tests
for four closely related bug reports (actually, they're duplicates)
to my sxe-var-dump branch[1]. However, I've noticed that bug #68946
and bug #67572, which I deemed related to this one, won't be fixed
with the given patch. I'll investigate.
With regard to older libxml versions: it seems very reasonable to
test with these. I'll see if I can build the mentionend versions
of libxml2 on Windows (some preliminary tests were successful).
[1] <https://github.com/cmb69/php-src/tree/sxe-var-dump>
------------------------------------------------------------------------
[2015-05-26 15:59:25] ab@php.net
Hi Christoph,
thanks for following on this. I don't have all the details in my head, however you go into the
same direction. Whether the check you've found works better only the tests can decide, i'd
say. If it is - so lets take it.
One note though. The trickiness of this ticket is - we deal not only with PHP itself actually, but
with the behavior change in libxml and the previous fix might have been not 100% sufficient.
IMHO what should be done - we should ensure that this fix doesn't break things when PHP is
linked with 2.7.x to 2.9.x. Probably the easiest done on Linux when fetching particular libxml
version, installing into some prefix and compiling PHP with it.
Are you in the mood to do this? If it's ok under say PHP-5.5 and libxml 2.7.7 2.7.8 2.8.0 2.9.1
2.9.2 - then please create a PR with all the aggregated tests from the tickets you've found
related and ping me so i'll test it as well. Does it sound eligible to you?
Thanks.
------------------------------------------------------------------------
[2015-05-26 14:27:20] cmb@php.net
The following patch has been added/updated:
Patch Name: sxe-var-dump
Revision: 1432650439
URL: https://bugs.php.net/patch-display.php?bug=66084&patch=sxe-var-dump&revision=1432650439
------------------------------------------------------------------------
[2015-05-26 14:26:36] cmb@php.net
Re-opened because of evgeniy's comment. This bug seems to be
closely related to bug #62639.
Adding the check for !node->next in the commit apparently only
solves some issues. It seems to me that instead it has to be
checked for sxe->iter.type, because when this is SXE_ITER_NONE it
doesn't make sense to execute the else clause.
With the attached patch sxe-var-dump.patch all ext/simplexml/tests
run fine, as well as the test script of bug #69491.
Anantol, can you please have a look at the issue. If useful, I can
make a pull request with some further tests regarding whitespace
issues.
------------------------------------------------------------------------
[2014-10-07 23:26:47] stas@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src-security.git;a=commit;h=a0beddf5e9ab3c6feaf0921be72a7f430597abea
Log: Fixed bug #66084 simplexml_load_string() mangles empty node name
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66084
--
Edit this bug report at https://bugs.php.net/bug.php?id=66084&edit=1