pg.ddx.io  pgsql-bugs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Tom Lane <tgl@sss.pgh.pa.us>
To: Michael Paquier <michael@paquier.xyz>
Cc: Robin Haberkorn <haberkorn@b1-systems.de>
Cc: Jim Jones <jim.jones@uni-muenster.de>
Cc: pgsql-bugs@lists.postgresql.org
Cc: maralist86@mail.ru
Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
Date: Tue, 08 Jul 2025 09:36:37 -0400
Message-ID: <689495.1751981797@sss.pgh.pa.us> (raw)
In-Reply-To: <aGz_ssvep-q7oM-M@paquier.xyz>
References: <aD53hVjiW-9C29VT@paquier.xyz>
	<861593.1748970933@sss.pgh.pa.us>
	<aEEingzOta_S_Nu7@paquier.xyz>
	<CAPLXN34Dr3Gbi+xJ6BgCeTyBJkMVe3cn7qxoADV72rC9ZHeBtQ@mail.gmail.com>
	<d2410ca0-c0dd-4f63-9e70-3d7a62a5d705@uni-muenster.de>
	<b35e2342-0f02-4365-94cf-55052ac9bda1@uni-muenster.de>
	<aEKCoNIfLxjyKY3r@paquier.xyz>
	<31f3480e-cd7d-4021-b392-87922572cc37@uni-muenster.de>
	<aETzMep2fGfB0AIp@paquier.xyz>
	<DB6KVQ60OJ8X.A8LWANY82NLG@b1-systems.de>
	<aGz_ssvep-q7oM-M@paquier.xyz>

Michael Paquier <michael@paquier.xyz> writes:
> On Tue, Jul 08, 2025 at 09:49:20AM +0000, Robin Haberkorn wrote:
>> I know this has already been committed, but why are we still using
>> PG_XML_STRICTNESS_LEGACY in xpath.c? As we are always checking
>> pg_xml_error_occurred() this should no longer be necessary.

> Are you sure that you can do that?

The comment in xml_errorHandler() argues

     * Legacy error handling mode.  err_occurred is never set, we just add the
     * message to err_buf.  This mode exists because the xml2 contrib module
     * uses our error-handling infrastructure, but we don't want to change its
     * behaviour since it's deprecated anyway.  This is also why we don't
     * distinguish between notices, warnings and errors here --- the old-style
     * generic error handler wouldn't have done that either.

So switching to _ALL (or even _WELL_FORMED) mode would result in
nontrivial differences in the behavior of xpath.c's functions with
bad input.  Maybe that's a reasonable thing to do, but it's a
question of user-visible behavior not just code cleanliness.

			regards, tom lane





view thread (27+ messages)  latest in thread

Message-ID: <689495.1751981797@sss.pgh.pa.us>
Permalink:  ../689495.1751981797@sss.pgh.pa.us/
Also on:    postgresql.org/message-id/689495.1751981797@sss.pgh.pa.us

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: tgl@sss.pgh.pa.us, michael@paquier.xyz, haberkorn@b1-systems.de, jim.jones@uni-muenster.de, pgsql-bugs@lists.postgresql.org, maralist86@mail.ru
  Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
  In-Reply-To: <689495.1751981797@sss.pgh.pa.us>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox