Bug #78279 [Opn->Csd]: libxml_disable_entity_loader settings is shared between requests (cgi-fcgi)

From: Date: Fri, 12 Jul 2019 14:31:09 +0000
Subject: Bug #78279 [Opn->Csd]: libxml_disable_entity_loader settings is shared between requests (cgi-fcgi)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221719@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78279&edit=1

 ID:                 78279
 Updated by:         nikic@php.net
 Reported by:        athanasius dot kirchner at gmail dot com
 Summary:            libxml_disable_entity_loader settings is shared
                     between requests (cgi-fcgi)
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            *XML functions
 Operating System:   Ubuntu 18.04.2 LTS
 PHP Version:        7.2.20
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=4a91f66b8f528e6d09e2c7fa04d87e2dc981bd34
Log: Fixed bug #78279


Previous Comments:
------------------------------------------------------------------------
[2019-07-12 14:24:57] nikic@php.net

This is because of https://github.com/php/php-src/blob/d68abef804cdd69d8e4d301d1755efd7a6189c2b/ext/libxml/libxml.c#L842.
I don't really understand why some sapis are handled differently...

------------------------------------------------------------------------
[2019-07-12 10:02:48] athanasius dot kirchner at gmail dot com

chg

------------------------------------------------------------------------
[2019-07-12 09:13:34] athanasius dot kirchner at gmail dot com

Description:
------------
The problem that the function libxml_disable_entity_loader shares its state between requests, that
was reported and fixed for fpm in https://bugs.php.net/bug.php?id=64938, does also
effect the sapi „cgi-fcgi“(php fastcgi). Our hoster uses this sapi in connection with
apache2 and we have noticed the same behaviour. To reproduce that, use the following two scripts.
First call Script 1 and than immediately call Script 2.

Test script:
---------------
#Script 1
<?php

libxml_disable_entity_loader(true);

#Script 2
<?php

die(var_dump(libxml_disable_entity_loader(false)));

Expected result:
----------------
Script 2 should always return false.

Actual result:
--------------
Script 2 returns true. (if other processes running on the server influencing
libxml_disable_entity_loader the test has to been repeated a few times)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78279&edit=1


Thread (4 messages)

« previous php.bugs (#221719) next »