Bug #81188 [NEW]: C14N wrong namespace order
| From: | bill dot seddon at lyquidity dot com | Date: | Mon, 21 Jun 2021 23:36:22 +0000 |
| Subject: | Bug #81188 [NEW]: C14N wrong namespace order | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-234579@lists.php.net to get a copy of this message | ||
From: bill dot seddon at lyquidity dot com
Operating system: Windows 10
PHP version: 8.0.7
Package: *XML functions
Bug Type: Bug
Bug description:C14N wrong namespace order
Description:
------------
My use case is checking XmlDSig signatures. The Xml in the test script
is asnippet of the type found within a <transform> element of a
signature. The order of the canonicalized attributes and element nodes
is important because the resulting Xml is hashed. Unless the
canonicalized Xml is generated correctly the hash will be different to a
hash computed by other software. Bear in mind that this existing Xml
generated by other other application so the option to modify the input
Xml does not exist.
Note the order of the attributes in the <XPath> element:
xmlns:dsig-xpath, filter, xmlns.
When this is canonicalized using PHP 5.3 through to 8.0 using the test
script provided the result is the Xml shown in the 'actual result'.
Here the order of the attributes is: xmlns:dsig-xpath, xmlns, filter
Correctly, the namespace attributes appear before value attributes.
However namespaces are being returned in their document order.
When using any other tool to canonicalize this fragment such as xmllint,
MS Cryptography, Python lxml the namespace attributes are sorted by the
attribute node name to give the result shown in the 'expected result'.
All other canonicalization implementations I can find order the
attributes this way: xmlns, xmlns:dsig-xpath, filter. I believe this is
consistent with section 4.8 of the canonicalization specification:
https://www.w3.org/TR/2001/REC-xml-c14n-20010315#SortByNSURI
Oddly, PHP, xmllint and Python's lxml are all based on libxml. However
it's the PHP implementation that yields a different result.
Test script:
---------------
$xml = "<XPath
xmlns:dsig-xpath=\"http://www.w3.org/2002/06/xmldsig-filter2\"
Filter=\"subtract\"
xmlns=\"http://www.w3.org/2002/06/xmldsig-filter2\">some
xpath</XPath>";
$doc = new \DOMDocument();
$doc->loadXML( $xml );
$doc->C14N( false, true );
$xml = $doc->saveXML( $doc->documentElement, LIBXML_NOEMPTYTAG );
Expected result:
----------------
<XPath xmlns="http://www.w3.org/2002/06/xmldsig-filter2"
xmlns:dsig-xpath="http://www.w3.org/2002/06/xmldsig-filter2"
Filter="subtract">some xpath</XPath>
Actual result:
--------------
<XPath xmlns:dsig-xpath="http://www.w3.org/2002/06/xmldsig-filter2"
xmlns="http://www.w3.org/2002/06/xmldsig-filter2"
Filter="subtract">some
xpath</XPath>
--
Edit bug report at https://bugs.php.net/bug.php?id=81188&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81188&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81188&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81188&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81188&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81188&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81188&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81188&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81188&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81188&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81188&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81188&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81188&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81188&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81188&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81188&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81188&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81188&r=mysqlcfg