xml.sax: the content of an external entity is not checked to be well-formed

オープン
#156,796 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
25/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
停滞
技術スタック
python
領域
backend

調査の方向性

ExpatParser.close() と、レポートで説明されている外部エンティティパーサーの経路から開始し、提供された再現プログラムを使用して、終了処理が欠落していることを確認します。test_sax を実行し、不正な形式の外部エンティティが報告されたエラーを発生させる一方で、既存のテストが引き続き成功することを確認します。

索引モデルが issue の本文から書いたものです。

説明

topic-XML type-bug

Bug report

The parsing of an external entity is never finalized, so errors which are only detected at the end of the input are not reported. An external entity whose content is not well-formed is silently accepted.

import io, xml.sax
from xml.sax.handler import feature_external_ges
from xml.sax.xmlreader import InputSource

class Resolver:
    def resolveEntity(self, pubid, sysid):
        source = InputSource()
        source.setByteStream(io.BytesIO(b'<entity>'))   # no end tag
        return source

parser = xml.sax.make_parser()
parser.setFeature(feature_external_ges, True)
parser.setEntityResolver(Resolver())
parser.feed('<!DOCTYPE d [<!ENTITY e SYSTEM "x">]><d>&e;</d>')
parser.close()   # no error

ExpatParser.close() returns early when _entity_stack is not empty, so feed(b"", isFinal=True) is never called for the parser created for the entity. The check is needed to not end the document while the entity is being parsed, but it also skips finalizing the entity itself.

If the parser of the entity is finalized, the example above fails with "error in processing external entity reference", and test_sax still passes.

Errors which Expat detects while feeding data, like a mismatched tag, are reported even now. Only errors detected at the end of the input, like an unclosed element, are lost.

Linked PRs
  • gh-156828
主要言語
Python
スター
77.2k
フォーク
36k
平均マージ
1日 9時間
マージ済み PR(30日)
558

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

python/cpython のほかの issue

python/cpython の issue をすべて見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。