Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1148658 > unrolled thread
| Started by | Xan Charbonnet <xan@charbonnet.com> |
|---|---|
| First post | 2023-06-03 06:10 +0200 |
| Last post | 2023-06-05 22:00 +0200 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1037063: libxml-libxml-perl: Seemingly incorrect handling of escaped characters in patterns Xan Charbonnet <xan@charbonnet.com> - 2023-06-03 06:10 +0200
Bug#1037063: libxml-libxml-perl: Seemingly incorrect handling of escaped characters in patterns Niko Tyni <ntyni@debian.org> - 2023-06-05 21:30 +0200
Bug#1037063: libxml-libxml-perl: Seemingly incorrect handling of escaped characters in patterns Xan Charbonnet <xan@charbonnet.com> - 2023-06-05 22:00 +0200
| From | Xan Charbonnet <xan@charbonnet.com> |
|---|---|
| Date | 2023-06-03 06:10 +0200 |
| Subject | Bug#1037063: libxml-libxml-perl: Seemingly incorrect handling of escaped characters in patterns |
| Message-ID | <GCqKt-dib5-5@gated-at.bofh.it> |
Package: libxml-libxml-perl
Version: 2.0134+dfsg-2+b1
Severity: normal
Dear Maintainer,
I use XML::LibXML::Reader to work with files that validate against the Library
of Congress's MARCXML Schema, available here:
https://www.loc.gov/standards/marcxml/schema/MARC21slim.xsd
That schema includes a pattern:
[\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}
or, with the XML escaping processed:
[\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}
That regex requires a single character, any one of a long list of allowable
characters. Note how three of the characters require escaping because they
would have meaning in the regex itself: the two square brackets [ and ], and
the backslash \.
An online XML Schema validator that I found with a quick search:
https://www.liquid-technologies.com/online-xsd-validator
shows that those three characters are valid. The problem is that
XML::LibXML::Reader seems to believe that they are not.
I wrote a simple test script, validate.pl:
-------------------
#!/usr/bin/perl
use strict;
use warnings;
use File::Slurp;
use XML::LibXML::Reader;
my ($xml_path, $xsd_path) = @ARGV;
my %parameters = (
'location'=>$xml_path,
'Schema'=>XML::LibXML::Schema->new(string=>scalar(read_file($xsd_path))),
);
my $reader = XML::LibXML::Reader->new(%parameters);
while($reader->read())
{}
print "Finished reading; document must be valid.\n";
-------------------
Along with a basic XML Schema file, test.xsd:
-------------------
<?xml version="1.0" encoding="UTF-8"?>
<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="root">
<xs:complexType>
<xs:attribute name="code">
<xs:simpleType>
<xs:restriction base="xs:string">
<xs:pattern value="[\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}"/>
</xs:restriction>
</xs:simpleType>
</xs:attribute>
</xs:complexType>
</xs:element>
</xs:schema>
-------------------
and a VERY basic XML file, test.xml:
-------------------
<root code="["/>
-------------------
Running:
$ perl validate.pl test.xml test.xsd
results in:
test.xml:1: Schemas validity error : Element 'root', attribute 'code': [facet
'pattern'] The value '[' is not accepted by the pattern
'[\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}'.
I believe that value in fact should match that pattern. The online schema
validator from earlier validates this pair of files. If you replace the data
in the "code" attribute with any of the other characters, validation passes.
It only fails for the three characters that are escaped.
-- System Information:
Debian Release: 11.7
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 5.10.0-21-amd64 (SMP w/8 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages libxml-libxml-perl depends on:
ii libc6 2.31-13+deb11u6
ii libxml-namespacesupport-perl 1.12-1.1
ii libxml-sax-perl 1.02+dfsg-1
ii libxml2 2.9.10+dfsg-6.7+deb11u4
ii perl 5.32.1-4+deb11u2
ii perl-base [perlapi-5.32.0] 5.32.1-4+deb11u2
libxml-libxml-perl recommends no packages.
libxml-libxml-perl suggests no packages.
-- no debconf information
[toc] | [next] | [standalone]
| From | Niko Tyni <ntyni@debian.org> |
|---|---|
| Date | 2023-06-05 21:30 +0200 |
| Message-ID | <GDo3T-dTv1-1@gated-at.bofh.it> |
| In reply to | #1148658 |
reassign 1037063 libxml2 2.9.10+dfsg-6.7
found 1037063 2.9.10+dfsg-6.7+deb11u4
close 1037063 2.9.12+dfsg-1
forwarded 1037063 https://gitlab.gnome.org/GNOME/libxml2/-/issues/188
thanks
Hi, thanks for the report. See below for some analysis.
(TL;DR: It's a bug in libxml2 that was fixed upstream after the version
in bullseye, and the fix will be in the upcoming bookworm release.)
On Fri, Jun 02, 2023 at 10:38:02PM -0500, Xan Charbonnet wrote:
> Package: libxml-libxml-perl
> Version: 2.0134+dfsg-2+b1
> Severity: normal
>
> Dear Maintainer,
>
> I use XML::LibXML::Reader to work with files that validate against the Library
> of Congress's MARCXML Schema, available here:
> https://www.loc.gov/standards/marcxml/schema/MARC21slim.xsd
>
> That schema includes a pattern:
> [\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}
> or, with the XML escaping processed:
> [\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}
>
> That regex requires a single character, any one of a long list of allowable
> characters. Note how three of the characters require escaping because they
> would have meaning in the regex itself: the two square brackets [ and ], and
> the backslash \.
>
> An online XML Schema validator that I found with a quick search:
> https://www.liquid-technologies.com/online-xsd-validator
> shows that those three characters are valid. The problem is that
> XML::LibXML::Reader seems to believe that they are not.
[...]
> test.xml:1: Schemas validity error : Element 'root', attribute 'code': [facet
> 'pattern'] The value '[' is not accepted by the pattern
> '[\dA-Za-z!"#$%&'()*+,-./:;<=>?{}_^`~\[\]\\]{1}'.
>
> I believe that value in fact should match that pattern. The online schema
> validator from earlier validates this pair of files. If you replace the data
> in the "code" attribute with any of the other characters, validation passes.
> It only fails for the three characters that are escaped.
This last part is not quite correct: validation also fails for the
backtick (`) and the tilde (~) characters. It's not about quoting,
it's about mistreating the caret (^) in the middle of the pattern.
The fault actually lies is in libxml2 which libxml-libxml-perl uses,
as seen with `xmllint --schema test.xsd test.xml` (xmllint is in
the libxml2-utils package).
It looks like it was fixed upstream in libxml2 2.9.11 with
https://gitlab.gnome.org/GNOME/libxml2/-/commit/7d6837ba0e282e94eb8630ad791f427e44a57491
and the fix entered Debian with 2.9.12.
I'm reassigning and closing the bug as it's fixed in current versions
in unstable and testing. Not sure if it's something that should be
backported to current Debian stable (bullseye). Feel free to discuss
that with the libxml2 maintainers (cc'd) if you like.
--
Niko Tyni ntyni@debian.org
[toc] | [prev] | [next] | [standalone]
| From | Xan Charbonnet <xan@charbonnet.com> |
|---|---|
| Date | 2023-06-05 22:00 +0200 |
| Message-ID | <GDowV-dTEx-3@gated-at.bofh.it> |
| In reply to | #1148813 |
Thanks very much, and apologies for my flawed analysis. It's good to know this will be fixed in bookworm. We're not going to be able to upgrade immediately so it would be nice if it could be fixed in bullseye, but I understand if that isn't the decision.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web