Bug #81188 [NEW]: C14N wrong namespace order

From: Date: Mon, 21 Jun 2021 23:36:22 +0000
Subject: Bug #81188 [NEW]: C14N wrong namespace order
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234579@lists.php.net to get a copy of this message
From: bill dot seddon at lyquidity dot com Operating system: Windows 10 PHP version: 8.0.7 Package: *XML functions Bug Type: Bug Bug description:C14N wrong namespace order Description: ------------ My use case is checking XmlDSig signatures. The Xml in the test script is asnippet of the type found within a <transform> element of a signature. The order of the canonicalized attributes and element nodes is important because the resulting Xml is hashed. Unless the canonicalized Xml is generated correctly the hash will be different to a hash computed by other software. Bear in mind that this existing Xml generated by other other application so the option to modify the input Xml does not exist. Note the order of the attributes in the <XPath> element: xmlns:dsig-xpath, filter, xmlns. When this is canonicalized using PHP 5.3 through to 8.0 using the test script provided the result is the Xml shown in the 'actual result'. Here the order of the attributes is: xmlns:dsig-xpath, xmlns, filter Correctly, the namespace attributes appear before value attributes. However namespaces are being returned in their document order. When using any other tool to canonicalize this fragment such as xmllint, MS Cryptography, Python lxml the namespace attributes are sorted by the attribute node name to give the result shown in the 'expected result'. All other canonicalization implementations I can find order the attributes this way: xmlns, xmlns:dsig-xpath, filter. I believe this is consistent with section 4.8 of the canonicalization specification: https://www.w3.org/TR/2001/REC-xml-c14n-20010315#SortByNSURI Oddly, PHP, xmllint and Python's lxml are all based on libxml. However it's the PHP implementation that yields a different result. Test script: --------------- $xml = "<XPath xmlns:dsig-xpath=\"http://www.w3.org/2002/06/xmldsig-filter2\" Filter=\"subtract\" xmlns=\"http://www.w3.org/2002/06/xmldsig-filter2\">some xpath</XPath>"; $doc = new \DOMDocument(); $doc->loadXML( $xml ); $doc->C14N( false, true ); $xml = $doc->saveXML( $doc->documentElement, LIBXML_NOEMPTYTAG ); Expected result: ---------------- <XPath xmlns="http://www.w3.org/2002/06/xmldsig-filter2" xmlns:dsig-xpath="http://www.w3.org/2002/06/xmldsig-filter2" Filter="subtract">some xpath</XPath> Actual result: -------------- <XPath xmlns:dsig-xpath="http://www.w3.org/2002/06/xmldsig-filter2" xmlns="http://www.w3.org/2002/06/xmldsig-filter2" Filter="subtract">some xpath</XPath> -- Edit bug report at https://bugs.php.net/bug.php?id=81188&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81188&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81188&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81188&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81188&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81188&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81188&r=support Expected behavior: https://bugs.php.net/fix.php?id=81188&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81188&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81188&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81188&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81188&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81188&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81188&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81188&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81188&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81188&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81188&r=mysqlcfg

« previous php.bugs (#234579) next »