From: Tom Lane <tgl@sss.pgh.pa.us>
To: Michael Paquier <michael@paquier.xyz>
Cc: Robin Haberkorn <haberkorn@b1-systems.de>
Cc: Jim Jones <jim.jones@uni-muenster.de>
Cc: pgsql-bugs@lists.postgresql.org
Cc: maralist86@mail.ru
Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
Date: Tue, 08 Jul 2025 09:36:37 -0400
Message-ID: <689495.1751981797@sss.pgh.pa.us> (raw)
In-Reply-To: <aGz_ssvep-q7oM-M@paquier.xyz>
References: <aD53hVjiW-9C29VT@paquier.xyz>
<861593.1748970933@sss.pgh.pa.us>
<aEEingzOta_S_Nu7@paquier.xyz>
<CAPLXN34Dr3Gbi+xJ6BgCeTyBJkMVe3cn7qxoADV72rC9ZHeBtQ@mail.gmail.com>
<d2410ca0-c0dd-4f63-9e70-3d7a62a5d705@uni-muenster.de>
<b35e2342-0f02-4365-94cf-55052ac9bda1@uni-muenster.de>
<aEKCoNIfLxjyKY3r@paquier.xyz>
<31f3480e-cd7d-4021-b392-87922572cc37@uni-muenster.de>
<aETzMep2fGfB0AIp@paquier.xyz>
<DB6KVQ60OJ8X.A8LWANY82NLG@b1-systems.de>
<aGz_ssvep-q7oM-M@paquier.xyz>
Michael Paquier <michael@paquier.xyz> writes:
> On Tue, Jul 08, 2025 at 09:49:20AM +0000, Robin Haberkorn wrote:
>> I know this has already been committed, but why are we still using
>> PG_XML_STRICTNESS_LEGACY in xpath.c? As we are always checking
>> pg_xml_error_occurred() this should no longer be necessary.
> Are you sure that you can do that?
The comment in xml_errorHandler() argues
* Legacy error handling mode. err_occurred is never set, we just add the
* message to err_buf. This mode exists because the xml2 contrib module
* uses our error-handling infrastructure, but we don't want to change its
* behaviour since it's deprecated anyway. This is also why we don't
* distinguish between notices, warnings and errors here --- the old-style
* generic error handler wouldn't have done that either.
So switching to _ALL (or even _WELL_FORMED) mode would result in
nontrivial differences in the behavior of xpath.c's functions with
bad input. Maybe that's a reasonable thing to do, but it's a
question of user-visible behavior not just code cleanliness.
regards, tom lane
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-bugs@postgresql.org
Cc: tgl@sss.pgh.pa.us, michael@paquier.xyz, haberkorn@b1-systems.de, jim.jones@uni-muenster.de, pgsql-bugs@lists.postgresql.org, maralist86@mail.ru
Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
In-Reply-To: <689495.1751981797@sss.pgh.pa.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox