Bug #64938 [Com]: libxml_disable_entity_loader setting is shared between threads

From: Date: Wed, 25 Nov 2015 08:52:56 +0000
Subject: Bug #64938 [Com]: libxml_disable_entity_loader setting is shared between threads
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197409@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64938&edit=1

 ID:                 64938
 Comment by:         kaplan@php.net
 Reported by:        Sjon at hortensius dot net
 Summary:            libxml_disable_entity_loader setting is shared
                     between threads
 Status:             Closed
 Type:               Bug
 Package:            *XML functions
 Operating System:   Archlinux
 PHP Version:        5.4.15
 Block user comment: N
 Private report:     N

 New Comment:

Also fixed in 5.5.22 (per the commits above).


Previous Comments:
------------------------------------------------------------------------
[2015-10-16 12:46:00] mark at netalico dot com

Any suggested workarounds for this issue? This bug is pretty critical because it can basically take
down sites running something like Magento. It appears to only be fixed in PHP 5.6, which a lot of
codebases aren't ready for yet.

------------------------------------------------------------------------
[2015-04-29 11:57:41] freitsabes at gmail dot com

Sorry, but I would like to ask for clarification:
For php-cgi I see the following behaviour:
1. I issue a request that has a call of libxml_disable_entity_loader()
2. A subsequent request to a different script that is NOT calling libxml_disable_entity_loader is
affected by the first request because the setting is shared between subsequent requests on the same
process.

Is this a bug or working as intended?

PHP 5.4.39 with libxml 2.9.2

------------------------------------------------------------------------
[2015-02-01 08:10:11] stas@php.net

Automatic comment on behalf of martin@divbyzero.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c1eb87ab1a2e2df1868b70cd7b8016c6147092c5
Log: Fix bug #64938: libxml_disable_entity_loader setting is shared between threads

------------------------------------------------------------------------
[2015-02-01 08:10:08] stas@php.net

Automatic comment on behalf of martin@divbyzero.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=de31324c221c1791b26350ba106cc26bad23ace9
Log: Fix bug #64938: libxml_disable_entity_loader setting is shared between threads

------------------------------------------------------------------------
[2015-01-29 16:44:50] stefan dot behninger at nasdaq dot com

Seems like this is a much bigger issue. We discovered that disabling the loader does not only affect
the current thread but obviously changes the setting globally on the entire server. Plus, it seems
to be persisted in a way that only restarting the server got us back to normal.

Planning to do some more tests tomorrow to eliminate any kind of caching that might have been
involved.

We're on PHP 5.3.3 on CentOS, strictly single-threaded.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=64938


--
Edit this bug report at https://bugs.php.net/bug.php?id=64938&edit=1


Thread (16 messages)

« previous php.bugs (#197409) next »