Refuse a start tag with too many attributes before XmlReader reads it - #600
Merged
Merged
Conversation
XmlReader reads a whole start tag before it can report AttributeCount, and a tag with a million attributes took it about 25 seconds before the existing 1,024 limit could refuse it. CheckAttributeCounts counts each start tag's "=" signs outside quotes in one pass and throws at the first tag past the limit; comments, CDATA, processing instructions, declarations and end tags are stepped over, and malformed text is left to XmlReader. The XmlReader-side check stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019n3G844aTidqrD6A6iMgza
|
Reviewed
Optional: add a test with a DOCTYPE whose internal subset contains 🤖 Generated with Claude Code |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019n3G844aTidqrD6A6iMgza
|
Reviewed the diff. I found no correctness, untrusted-input, or convention problems, and I didn't build or run the tests.
One minor point: LGTM. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Plan XML with one start tag that has a very large number of attributes loaded slowly. XmlReader reads a whole start tag before it can say how many attributes the tag has. For a tag with one million attributes, that took about 25 seconds. Only then did the existing limit of 1,024 attributes refuse the plan. The desktop app and the web viewer both use this code, so both were slow on such a plan.
PlanXmlnow counts the attributes of each start tag in the text, before XmlReader reads it:=outside its quoted value. So the count is the number of=signs between a start tag's<and>that are not inside quotes.The attribute check in the XmlReader pass stays as a second check.
Which component(s) does this affect?
The web viewer,
PlanViewer.Web, compiles the same file, so it gets the change too.How was this tested?
PlanXmlTests:=inside a value is not counted. A>or a'inside a double-quoted value does not end the count. Single-quoted values count the same as double-quoted ones.>in its internal subset is still refused. The count stops at that>and reads the rest as text and tags. So it can only count more, and XmlReader refuses the DTD anyway.Checklist
--no-incremental)dotnet test)🤖 Generated with Claude Code
https://claude.ai/code/session_019n3G844aTidqrD6A6iMgza