pg.ddx.io  pgsql-bugs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Robin Haberkorn <haberkorn@b1-systems.de>
To: Michael Paquier <michael@paquier.xyz>
To: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Jim Jones <jim.jones@uni-muenster.de>
Cc: pgsql-bugs@lists.postgresql.org
Cc: maralist86@mail.ru
Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
Date: Wed, 09 Jul 2025 11:28:58 +0000
Message-ID: <DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de> (raw)
In-Reply-To: <aG27k8a2y9fvak40@paquier.xyz>
References: <aEEingzOta_S_Nu7@paquier.xyz>
	<CAPLXN34Dr3Gbi+xJ6BgCeTyBJkMVe3cn7qxoADV72rC9ZHeBtQ@mail.gmail.com>
	<d2410ca0-c0dd-4f63-9e70-3d7a62a5d705@uni-muenster.de>
	<b35e2342-0f02-4365-94cf-55052ac9bda1@uni-muenster.de>
	<aEKCoNIfLxjyKY3r@paquier.xyz>
	<31f3480e-cd7d-4021-b392-87922572cc37@uni-muenster.de>
	<aETzMep2fGfB0AIp@paquier.xyz>
	<DB6KVQ60OJ8X.A8LWANY82NLG@b1-systems.de>
	<aGz_ssvep-q7oM-M@paquier.xyz>
	<689495.1751981797@sss.pgh.pa.us>
	<aG27k8a2y9fvak40@paquier.xyz>

On Wed Jul 9, 2025 at 03:45:07 GMT +03, Michael Paquier wrote:
> Yes, I don't see a huge advantage in doing the switch for this module.
> If the gain in information in the error states grabbed from libxml2
> makes it a win, that may be a different argument (I am fine to be
> proved wrong), but I cannot get excited about that without more
> data to claim it so.
>
Once switching to PG_XML_STRICTNESS_ALL, we should also theoretically
be able to receive warnings and notices, that would be silent otherwise.
I believe that getting rid of PG_XML_STRICTNESS_LEGACY might also be
desirable if we ever want to get xml2 into core.

But I notice that you did already change lots of PG_XML_STRICTNESS_LEGACY
into PG_XML_STRICTNESS_ALL.

> I have quickly tested the change, and the xpath_string() path was one
> area that immediately stood out, and we may report an incorrect error.

You are right. The test suite fails or hangs at least. We are probably
still missing some checks. So it wouldn't just be a matter of
replacing all remaining PG_XML_STRICTNESS_LEGACY.

-- 
Robin Haberkorn
Software Engineer

B1 Systems GmbH
Osterfeldstraße 7 / 85088 Vohburg / https://www.b1-systems.de
GF: Ralph Dehner / Unternehmenssitz: Vohburg / AG: Ingolstadt, HRB 3537

Attachments:

  [application/pgp-signature] signature.asc (259B, ../DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de/2-signature.asc)
  download

view thread (27+ messages)  latest in thread

Message-ID: <DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de>
Permalink:  ../DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de/
Also on:    postgresql.org/message-id/DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: haberkorn@b1-systems.de, michael@paquier.xyz, tgl@sss.pgh.pa.us, jim.jones@uni-muenster.de, pgsql-bugs@lists.postgresql.org, maralist86@mail.ru
  Subject: Re: BUG #18943: Return value of a function 'xmlBufferCreate' is dereferenced at xpath.c:177 without checking for NUL
  In-Reply-To: <DB7HMJRSBSFO.4KVUIX0D1N6H@b1-systems.de>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox