Bug #78279 [Opn]: libxml_disable_entity_loader settings is shared between requests (cgi-fcgi)
| From: | athanasius dot kirchner at gmail dot com | Date: | Fri, 12 Jul 2019 10:02:48 +0000 |
| Subject: | Bug #78279 [Opn]: libxml_disable_entity_loader settings is shared between requests (cgi-fcgi) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221717@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78279&edit=1
ID: 78279
User updated by: athanasius dot kirchner at gmail dot com
Reported by: athanasius dot kirchner at gmail dot com
Summary: libxml_disable_entity_loader settings is shared
between requests (cgi-fcgi)
Status: Open
Type: Bug
Package: *XML functions
Operating System: Ubuntu 18.04.2 LTS
PHP Version: 7.2.20
Block user comment: N
Private report: N
New Comment:
chg
Previous Comments:
------------------------------------------------------------------------
[2019-07-12 09:13:34] athanasius dot kirchner at gmail dot com
Description:
------------
The problem that the function libxml_disable_entity_loader shares its state between requests, that
was reported and fixed for fpm in https://bugs.php.net/bug.php?id=64938, does also
effect the sapi âcgi-fcgiâ(php fastcgi). Our hoster uses this sapi in connection with
apache2 and we have noticed the same behaviour. To reproduce that, use the following two scripts.
First call Script 1 and than immediately call Script 2.
Test script:
---------------
#Script 1
<?php
libxml_disable_entity_loader(true);
#Script 2
<?php
die(var_dump(libxml_disable_entity_loader(false)));
Expected result:
----------------
Script 2 should always return false.
Actual result:
--------------
Script 2 returns true. (if other processes running on the server influencing
libxml_disable_entity_loader the test has to been repeated a few times)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78279&edit=1