The GitHub Actions job "CI" on grails-core.git/fix/xml-parser-hardening has 
failed.
Run started by GitHub user jamesfredley (triggered by jamesfredley).

Head commit for run:
840aea9b91b216b54b55ca5336fc22c61bd20fb7 / James Daugherty 
<[email protected]>
Share SAX feature identifiers and make DOCTYPE rejection configurable

The SAX feature identifiers were declared twice, once in SpringIOUtils and
once in the HTTP test client, as bare string literals. That duplication is
how the https:// spelling was introduced and went unnoticed: setFeature
answers an unrecognised name with SAXNotRecognizedException, and both call
sites swallow it, so the hardening silently switched off.

Collect the five identifiers in XmlParserFeature in grails-gradle-common,
which sits in the grails-gradle build alongside SpringIOUtils and is already
exposed to the root build by grails-common. The enum documents that the
values are registered identifiers rather than addresses, and carries the
reason the http scheme cannot be rewritten.

Keep rejecting DOCTYPE declarations by default, and add
grails.xml.allowDocTypeDeclaration for applications that must accept them.
SpringIOUtils reads it through Metadata, so it is set in application.yml or
as a system property. Opting in relaxes only whether a declaration is
permitted; external general entities, external parameter entities and
external DTDs stay refused either way, so it does not reopen the XXE vector.

The setting is needed because this parser factory is shared with readers of
trusted classpath descriptors -- TldReader, WebXmlTagLibraryReader and
PluginUtils -- and TLDs routinely carry a DOCTYPE.
jakarta.servlet.jsp.jstl ships eight, including c-1_0-rt.tld, which the
default grails.gsp.tldScanPattern scans, so an application resolving JSP tag
libraries from a GSP needs it enabled. Document that on the JSP tag library
page and in the upgrade notes.

Cover both modules with tests that assert observable behaviour rather than
reading feature flags back, so no test holds a second copy of the
identifiers that a rewrite could update in step with the production code.
XmlParserFeatureSpec additionally asserts every identifier is one a parser
actually registers, turning an unrecognised name into a named failure
instead of a silent no-op.

Report URL: https://github.com/apache/grails-core/actions/runs/34364072800

With regards,
GitHub Actions via GitBox

Reply via email to