Bug #80559 [Nab->ReO]: xmlrpc has no PECL releases to download
| From: | requinix@php.net | Date: | Tue, 29 Dec 2020 19:21:55 +0000 |
| Subject: | Bug #80559 [Nab->ReO]: xmlrpc has no PECL releases to download | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231298@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80559&edit=1
ID: 80559
Updated by: requinix@php.net
Reported by: giunta dot gaetano at gmail dot com
-Summary: xmlrpc_encode creates bad xml entities for chars 200
to 209
+Summary: xmlrpc has no PECL releases to download
-Status: Not a bug
+Status: Re-Opened
Type: Bug
Package: XMLRPC-EPI related
Operating System: ubuntu
PHP Version: 7.4.13
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> I know that the xmlrpc extension has been removed from php 8 and is thus
> probably in a strict 'maintenance only' mode, but would it make sense to try to
> make it easier for end users to install the non-buggy version from PECL?
@cmb?
Previous Comments:
------------------------------------------------------------------------
[2020-12-29 10:16:50] giunta dot gaetano at gmail dot com
Indeed I experienced this bug on Ubuntu's native php version, which uses a shared library for
libxmlrpc-epi.
The problem has been reported upstream to Debian, and has been lingering in their bug tracker for a
while :-( see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883747
Also, I managed to dig out the original bug report which led to this issue being fixed within
php's source code: https://bugs.php.net/bug.php?id=28597
I know that the xmlrpc extension has been removed from php 8 and is thus probably in a strict
'maintenance only' mode, but would it make sense to try to make it easier for end users to
install the non-buggy version from PECL?
------------------------------------------------------------------------
[2020-12-28 22:25:33] requinix@php.net
*does not work (note the if c >= 10)
------------------------------------------------------------------------
[2020-12-28 22:25:03] requinix@php.net
Upstream bug.
Bundled libxmlrpc-epi is good
http://git.php.net/?p=pecl/networking/xmlrpc.git;a=blob;f=libxmlrpc/xml_element.c;h=16787593516d492fcf720b0d3eea22934bae02f0;hb=refs/heads/master#l279
but this version on SourceForge does
https://sourceforge.net/p/xmlrpc-epi/git/ci/master/tree/src/xml_element.c#l290
------------------------------------------------------------------------
[2020-12-28 20:17:43] giunta dot gaetano at gmail dot com
Description:
------------
Function xmlrpc_encode and xmlrpc_encode_request do encode all characters above 127 to their numeric
entity representation, eg: chr(129) => ''
However there seems to be a bug for characters between 200 and 209 - for those the numeric entities
generated are '' to ''.
The code in the source library, file 'xml_element.c' seems to have a bug in function
create_xml_escape. The same bug would apply for characters 100 to 109, however that does not happen
because those characters are not encoded as entities in the first place.
Test script:
---------------
echo xmlrpc_encode(chr(199).chr(200).chr(209).chr(210);
Expected result:
----------------
<?xml version="1.0"
encoding="utf-8"?><params><param><value><string>ÇÈÑÒ</string></value></param></params>
Actual result:
--------------
<?xml version="1.0"
encoding="utf-8"?><params><param><value><string>ÇÒ</string></value></param></params>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80559&edit=1