Bug #71592 [Csd]: External entity processing never fail regardless of handler return code

From: Date: Tue, 30 Oct 2018 17:57:12 +0000
Subject: Bug #71592 [Csd]: External entity processing never fail regardless of handler return code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217752@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71592&edit=1 ID: 71592 Updated by: cmb@php.net Reported by: anrdaemon at freemail dot ru Summary: External entity processing never fail regardless of handler return code Status: Closed Type: Bug Package: XML related Operating System: Windows PHP Version: 5.6.18 Assigned To: cmb Block user comment: N Private report: N New Comment: > It's not well-formed. (<p></nop>) This is on purpose to make sure that the parsing bails out early. > Its root tag does not match DOCTYPE declaration. Thanks! Indeed, that's a mistake. Fixed with <http://git.php.net/?p=php-src.git;a=commit;h=2816a3fdfa23cf0711251b8d1e9ffad3d281ea96>. Previous Comments: ------------------------------------------------------------------------ [2018-10-30 01:42:39] anrdaemon at freemail dot ru May I point out, that the source XML in the test case contains at least 2 issues? 1. It's not well-formed. (<p></nop>) 2. Its root tag does not match DOCTYPE declaration. ------------------------------------------------------------------------ [2018-10-27 15:32:19] cmb@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=829b0df77b20392115d75fb82c56ad94edc1e423 Log: Fix #71592: External entity processing never fails ------------------------------------------------------------------------ [2018-10-09 21:21:43] cmb@php.net <https://github.com/php/php-src/pull/3596> is supposed to solve this bug. ------------------------------------------------------------------------ [2018-03-14 17:45:41] cmb@php.net This part of the documentation refers to libexpat based ext/xml. For libxml2 based ext/xml, the external entity reference handler is effectively a void function. Not sure, whether libexpat's behavior could be implemented with libxml2. ------------------------------------------------------------------------ [2016-02-15 01:39:53] anrdaemon at freemail dot ru Description: ------------ Despite documentation[1] explicitly stating that "If the value returned from the handler is FALSE (which it will be if no value is returned), the XML parser will stop parsing and xml_get_error_code() will return XML_ERROR_EXTERNAL_ENTITY_HANDLING.", the output of the attached test script will always be "No error". phpinfo() PHP Version => 5.6.18 xml XML Support => active XML Namespace Support => active libxml2 Version => 2.9.3 [1]http://php.net/xml_set_external_entity_ref_handler Test script: --------------- <?php $parser = xml_parser_create_ns('UTF-8'); xml_set_external_entity_ref_handler($parser, function($self, $names, $base, $system_id, $public_id) { print "@{$names}: '{$system_id}' {$public_id}\n"; /* Ref: http://php.net/xml_set_external_entity_ref_handler If the value returned from the handler is FALSE (which it will be if no value is returned), the XML parser will stop parsing and xml_get_error_code() will return XML_ERROR_EXTERNAL_ENTITY_HANDLING. */ return false; } ); xml_parse($parser, '<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE p [ <!ENTITY pic PUBLIC "image.gif" "http://example.org/image.gif"> ]> <p>&pic;</p>'); print xml_error_string(xml_get_error_code($parser)) . "\n"; ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71592&edit=1

« previous php.bugs (#217752) next »