Skip to content
Prev Previous commit
Next Next commit
merge revision(s) r48402:
	* lib/rexml/document.rb: add REXML::Document#document.
	  reported by Tomas Hoger <[email protected]> and patched by nahi.


git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/branches/ruby_2_1@48404 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
  • Loading branch information
nagachika committed Nov 13, 2014
commit eac759b97638fccd6ac693d0129f02a48c0e5555
5 changes: 5 additions & 0 deletions ChangeLog
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
Thu Nov 13 22:32:34 2014 CHIKANAGA Tomoyuki <[email protected]>

* lib/rexml/document.rb: add REXML::Document#document.
reported by Tomas Hoger <[email protected]> and patched by nahi.

Thu Nov 6 22:57:43 2014 Naohisa Goto <[email protected]>

* bignum.c (absint_numwords_generic): set an array element after
Expand Down
4 changes: 4 additions & 0 deletions lib/rexml/document.rb
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,10 @@ def record_entity_expansion
end
end

def document
self
end

private
def build( source )
Parsers::TreeParser.new( source, self ).parse
Expand Down
1 change: 1 addition & 0 deletions lib/rexml/entity.rb
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,7 @@ def value

# This is a set of entity constants -- the ones defined in the XML
# specification. These are +gt+, +lt+, +amp+, +quot+ and +apos+.
# CAUTION: these entities does not have parent and document
module EntityConst
# +>+
GT = Entity.new( 'gt', '>' )
Expand Down
53 changes: 52 additions & 1 deletion test/rexml/test_document.rb
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,23 @@ def test_new
</member>
EOF

XML_WITH_NESTED_PARAMETER_ENTITY = <<EOF
XML_WITH_NESTED_EMPTY_ENTITY = <<EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE member [
<!ENTITY a "&b;&b;&b;&b;&b;&b;&b;&b;&b;&b;">
<!ENTITY b "&c;&c;&c;&c;&c;&c;&c;&c;&c;&c;">
<!ENTITY c "&d;&d;&d;&d;&d;&d;&d;&d;&d;&d;">
<!ENTITY d "&e;&e;&e;&e;&e;&e;&e;&e;&e;&e;">
<!ENTITY e "&f;&f;&f;&f;&f;&f;&f;&f;&f;&f;">
<!ENTITY f "&g;&g;&g;&g;&g;&g;&g;&g;&g;&g;">
<!ENTITY g "">
]>
<member>
&a;
</member>
EOF

XML_WITH_NESTED_PARAMETER_ENTITY = <<EOF
<!DOCTYPE root [
<!ENTITY % a "BOOM.BOOM.BOOM.BOOM.BOOM.BOOM.BOOM.BOOM.BOOM.">
<!ENTITY % b "%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;">
Expand All @@ -59,6 +75,20 @@ def test_new
<!ENTITY test "test %g;">
]>
<cd></cd>
EOF

XML_WITH_NESTED_EMPTY_PARAMETER_ENTITY = <<EOF
<!DOCTYPE root [
<!ENTITY % a "">
<!ENTITY % b "%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;%a;">
<!ENTITY % c "%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;%b;">
<!ENTITY % d "%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;%c;">
<!ENTITY % e "%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;%d;">
<!ENTITY % f "%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;%e;">
<!ENTITY % g "%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;%f;">
<!ENTITY test "test %g;">
]>
<cd></cd>
EOF

XML_WITH_4_ENTITY_EXPANSION = <<EOF
Expand Down Expand Up @@ -87,6 +117,18 @@ def test_entity_expansion_limit
end
assert_equal(101, doc.entity_expansion_count)

doc = REXML::Document.new(XML_WITH_NESTED_EMPTY_ENTITY)
assert_raise(RuntimeError) do
doc.root.children.first.value
end
REXML::Security.entity_expansion_limit = 100
assert_equal(100, REXML::Security.entity_expansion_limit)
doc = REXML::Document.new(XML_WITH_NESTED_EMPTY_ENTITY)
assert_raise(RuntimeError) do
doc.root.children.first.value
end
assert_equal(101, doc.entity_expansion_count)

REXML::Security.entity_expansion_limit = 4
doc = REXML::Document.new(XML_WITH_4_ENTITY_EXPANSION)
assert_equal("\na\na a\n<\n", doc.root.children.first.value)
Expand All @@ -108,6 +150,15 @@ def test_entity_expansion_limit_for_parameter_entity
assert_raise(REXML::ParseException) do
REXML::Document.new(XML_WITH_NESTED_PARAMETER_ENTITY)
end

assert_raise(REXML::ParseException) do
REXML::Document.new(XML_WITH_NESTED_EMPTY_PARAMETER_ENTITY)
end
REXML::Security.entity_expansion_limit = 100
assert_equal(100, REXML::Security.entity_expansion_limit)
assert_raise(REXML::ParseException) do
REXML::Document.new(XML_WITH_NESTED_EMPTY_PARAMETER_ENTITY)
end
ensure
REXML::Security.entity_expansion_limit = 10000
end
Expand Down
6 changes: 3 additions & 3 deletions version.h
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
#define RUBY_VERSION "2.1.5"
#define RUBY_RELEASE_DATE "2014-11-06"
#define RUBY_PATCHLEVEL 272
#define RUBY_RELEASE_DATE "2014-11-13"
#define RUBY_PATCHLEVEL 273

#define RUBY_RELEASE_YEAR 2014
#define RUBY_RELEASE_MONTH 11
#define RUBY_RELEASE_DAY 6
#define RUBY_RELEASE_DAY 13

#include "ruby/version.h"

Expand Down