Skip to content

Commit c4fa79b

Browse files
[3.12] gh-115133: Fix tests for XMLPullParser with Expat 2.6.0 (GH-115164) (GH-115288)
Feeding the parser by too small chunks defers parsing to prevent CVE-2023-52425. Future versions of Expat may be more reactive. (cherry picked from commit 4a08e7b) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
1 parent 6e13e50 commit c4fa79b

File tree

2 files changed

+38
-22
lines changed

2 files changed

+38
-22
lines changed

Lib/test/test_xml_etree.py

Lines changed: 36 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
import operator
1414
import os
1515
import pickle
16+
import pyexpat
1617
import sys
1718
import textwrap
1819
import types
@@ -120,6 +121,10 @@
120121
</foo>
121122
"""
122123

124+
fails_with_expat_2_6_0 = (unittest.expectedFailure
125+
if pyexpat.version_info >= (2, 6, 0) else
126+
lambda test: test)
127+
123128
def checkwarnings(*filters, quiet=False):
124129
def decorator(test):
125130
def newtest(*args, **kwargs):
@@ -1400,28 +1405,37 @@ def assert_event_tags(self, parser, expected, max_events=None):
14001405
self.assertEqual([(action, elem.tag) for action, elem in events],
14011406
expected)
14021407

1403-
def test_simple_xml(self):
1404-
for chunk_size in (None, 1, 5):
1405-
with self.subTest(chunk_size=chunk_size):
1406-
parser = ET.XMLPullParser()
1407-
self.assert_event_tags(parser, [])
1408-
self._feed(parser, "<!-- comment -->\n", chunk_size)
1409-
self.assert_event_tags(parser, [])
1410-
self._feed(parser,
1411-
"<root>\n <element key='value'>text</element",
1412-
chunk_size)
1413-
self.assert_event_tags(parser, [])
1414-
self._feed(parser, ">\n", chunk_size)
1415-
self.assert_event_tags(parser, [('end', 'element')])
1416-
self._feed(parser, "<element>text</element>tail\n", chunk_size)
1417-
self._feed(parser, "<empty-element/>\n", chunk_size)
1418-
self.assert_event_tags(parser, [
1419-
('end', 'element'),
1420-
('end', 'empty-element'),
1421-
])
1422-
self._feed(parser, "</root>\n", chunk_size)
1423-
self.assert_event_tags(parser, [('end', 'root')])
1424-
self.assertIsNone(parser.close())
1408+
def test_simple_xml(self, chunk_size=None):
1409+
parser = ET.XMLPullParser()
1410+
self.assert_event_tags(parser, [])
1411+
self._feed(parser, "<!-- comment -->\n", chunk_size)
1412+
self.assert_event_tags(parser, [])
1413+
self._feed(parser,
1414+
"<root>\n <element key='value'>text</element",
1415+
chunk_size)
1416+
self.assert_event_tags(parser, [])
1417+
self._feed(parser, ">\n", chunk_size)
1418+
self.assert_event_tags(parser, [('end', 'element')])
1419+
self._feed(parser, "<element>text</element>tail\n", chunk_size)
1420+
self._feed(parser, "<empty-element/>\n", chunk_size)
1421+
self.assert_event_tags(parser, [
1422+
('end', 'element'),
1423+
('end', 'empty-element'),
1424+
])
1425+
self._feed(parser, "</root>\n", chunk_size)
1426+
self.assert_event_tags(parser, [('end', 'root')])
1427+
self.assertIsNone(parser.close())
1428+
1429+
@fails_with_expat_2_6_0
1430+
def test_simple_xml_chunk_1(self):
1431+
self.test_simple_xml(chunk_size=1)
1432+
1433+
@fails_with_expat_2_6_0
1434+
def test_simple_xml_chunk_5(self):
1435+
self.test_simple_xml(chunk_size=5)
1436+
1437+
def test_simple_xml_chunk_22(self):
1438+
self.test_simple_xml(chunk_size=22)
14251439

14261440
def test_feed_while_iterating(self):
14271441
parser = ET.XMLPullParser()
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
Fix tests for :class:`~xml.etree.ElementTree.XMLPullParser` with Expat
2+
2.6.0.

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy