Bug #71592 [Csd]: External entity processing never fail regardless of handler return code
| From: | cmb@php.net | Date: | Tue, 30 Oct 2018 17:57:12 +0000 |
| Subject: | Bug #71592 [Csd]: External entity processing never fail regardless of handler return code | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217752@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71592&edit=1
ID: 71592
Updated by: cmb@php.net
Reported by: anrdaemon at freemail dot ru
Summary: External entity processing never fail regardless of
handler return code
Status: Closed
Type: Bug
Package: XML related
Operating System: Windows
PHP Version: 5.6.18
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> It's not well-formed. (<p></nop>)
This is on purpose to make sure that the parsing bails out early.
> Its root tag does not match DOCTYPE declaration.
Thanks! Indeed, that's a mistake.
Fixed with <http://git.php.net/?p=php-src.git;a=commit;h=2816a3fdfa23cf0711251b8d1e9ffad3d281ea96>.
Previous Comments:
------------------------------------------------------------------------
[2018-10-30 01:42:39] anrdaemon at freemail dot ru
May I point out, that the source XML in the test case contains at least 2 issues?
1. It's not well-formed. (<p></nop>)
2. Its root tag does not match DOCTYPE declaration.
------------------------------------------------------------------------
[2018-10-27 15:32:19] cmb@php.net
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=829b0df77b20392115d75fb82c56ad94edc1e423
Log: Fix #71592: External entity processing never fails
------------------------------------------------------------------------
[2018-10-09 21:21:43] cmb@php.net
<https://github.com/php/php-src/pull/3596> is
supposed to solve this bug.
------------------------------------------------------------------------
[2018-03-14 17:45:41] cmb@php.net
This part of the documentation refers to libexpat based ext/xml.
For libxml2 based ext/xml, the external entity reference handler
is effectively a void function. Not sure, whether libexpat's
behavior could be implemented with libxml2.
------------------------------------------------------------------------
[2016-02-15 01:39:53] anrdaemon at freemail dot ru
Description:
------------
Despite documentation[1] explicitly stating that "If the value returned from the handler is
FALSE (which it will be if no value is returned), the XML parser will stop parsing and
xml_get_error_code() will return XML_ERROR_EXTERNAL_ENTITY_HANDLING.", the output of the
attached test script will always be "No error".
phpinfo()
PHP Version => 5.6.18
xml
XML Support => active
XML Namespace Support => active
libxml2 Version => 2.9.3
[1]http://php.net/xml_set_external_entity_ref_handler
Test script:
---------------
<?php
$parser = xml_parser_create_ns('UTF-8');
xml_set_external_entity_ref_handler($parser, function($self, $names, $base, $system_id, $public_id)
{
print "@{$names}: '{$system_id}' {$public_id}\n";
/* Ref: http://php.net/xml_set_external_entity_ref_handler
If the value returned from the handler is FALSE (which it will be if no
value is returned), the XML parser will stop parsing and
xml_get_error_code() will return XML_ERROR_EXTERNAL_ENTITY_HANDLING.
*/
return false;
}
);
xml_parse($parser, '<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE p [
<!ENTITY pic PUBLIC "image.gif" "http://example.org/image.gif">
]>
<p>&pic;</p>');
print xml_error_string(xml_get_error_code($parser)) . "\n";
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71592&edit=1