{"thread":{"id":"12140","subject":"[PATCH] Don't open a XML tag while another one is already open","startedAt":"2008-02-16T19:16:28Z","lastAt":"2008-02-17T17:48:13Z","messageCount":2,"participants":["Robert Schiele","Jakub Narebski"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"68920","messageId":"20080216191628.GK30676@schiele.dyndns.org","threadId":"12140","inReplyTo":null,"subject":"[PATCH] Don't open a XML tag while another one is already open","fromName":"Robert Schiele","fromEmail":"rschiele@gmail.com","sentAt":"2008-02-16T19:16:28Z","receivedAt":"2008-02-16T19:16:28Z","isPatch":true,"sender":{"key":"rschiele@gmail.com","avatar":"https://gravatar.com/avatar/409473567eb2287d5f0157b51f5b703994b347f24f92172e3a0588741c27a492?d=mp&s=160"},"body":"chop_and_escape_str calls esc_html within a XML tag.  Since esc_html\nitself does escape control characters with quot_cec it could potentially\nopen another tag which leads to incorrect XML.\n\nThis patch adds an option \"intag\" to esc_html and quot_cec to indicate\nthat we are currently within a tag and thus suppresses opening another\none.  It also makes use of this option in chop_and_escape_str.\n\nSigned-off-by: Robert Schiele <rschiele@gmail.com>\n---\nThis patch should fix the bug Martin Koegler reported in his mail \"Invalid\nhtml output repo.or.cz (alt-git.git)\".\n\n gitweb/gitweb.perl |   11 ++++++++---\n 1 files changed, 8 insertions(+), 3 deletions(-)\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex 5e88637..a010c7a 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -732,7 +732,7 @@ sub esc_html ($;%) {\n \tif ($opts{'-nbsp'}) {\n \t\t$str =~ s/ /&nbsp;/g;\n \t}\n-\t$str =~ s|([[:cntrl:]])|(($1 ne \"\\t\") ? quot_cec($1) : $1)|eg;\n+\t$str =~ s|([[:cntrl:]])|(($1 ne \"\\t\") ? quot_cec($1, -intag=>$opts{'-intag'}) : $1)|eg;\n \treturn $str;\n }\n \n@@ -753,6 +753,7 @@ sub esc_path {\n # Make control characters \"printable\", using character escape codes (CEC)\n sub quot_cec {\n \tmy $cntrl = shift;\n+\tmy %opts = @_;\n \tmy %es = ( # character escape codes, aka escape sequences\n \t\t   \"\\t\" => '\\t',   # tab            (HT)\n \t\t   \"\\n\" => '\\n',   # line feed      (LF)\n@@ -767,7 +768,11 @@ sub quot_cec {\n \tmy $chr = ( (exists $es{$cntrl})\n \t\t    ? $es{$cntrl}\n \t\t    : sprintf('\\%03o', ord($cntrl)) );\n-\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\tif ($opts{'-intag'}) {\n+\t\treturn \"$chr\";\n+\t} else {\n+\t\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\t}\n }\n \n # Alternatively use unicode control pictures codepoints,\n@@ -866,7 +871,7 @@ sub chop_and_escape_str {\n \tif ($chopped eq $str) {\n \t\treturn esc_html($chopped);\n \t} else {\n-\t\treturn qq{<span title=\"} . esc_html($str) . qq{\">} .\n+\t\treturn qq{<span title=\"} . esc_html($str, -intag=>1) . qq{\">} .\n \t\t\tesc_html($chopped) . qq{</span>};\n \t}\n }\n-- \n1.5.2.4\n"},{"id":"68999","messageId":"20080217174812.30454.86822.stgit@localhost.localdomain","threadId":"12140","inReplyTo":"20080216191628.GK30676@schiele.dyndns.org","subject":"[PATCH] gitweb: Add new option -nohtml to quot_xxx subroutines","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2008-02-17T17:48:13Z","receivedAt":"2008-02-17T17:48:13Z","isPatch":true,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"\nAdd support for new option -nohtml to quot_cec and quot_upr\nsubroutines, to have output not wrapped in HTML tags.  This makes\nthose subroutines suitable to quoting attributes values, and for plain\ntext output quoting.  Currently this API is not used yet.\n\nWhile at it fix whitespace, and use ';' as delimiter, not separator.\n\n\nThe option to not wrap quot_cec output in HTML tag were proposed\noriginally in patch:\n  \"Don't open a XML tag while another one is already open\"\n  Message-ID: <20080216191628.GK30676@schiele.dyndns.org>\nby Robert Schiele.  Originally the parameter was named '-notag', was\nalso supportted by esc_html (but not esc_path) which passed it down to\nquot_cec.  Mentioned patch was meant to fix the bug Martin Koegler\nreported in his mail\n  \"Invalid html output repo.or.cz (alt-git.git)\"\n  Message-ID: <20080216130037.GA14571@auto.tuwien.ac.at>\nwhich was fixed in different way (do not use esc_html to escape and\nquote HTML attributes).\n\n\nSigned-off-by: Robert Schiele <rschiele@gmail.com>\nSigned-off-by: Jakub Narebski <jnareb@gmail.com>\n---\n\n gitweb/gitweb.perl |   37 ++++++++++++++++++++++++-------------\n 1 files changed, 24 insertions(+), 13 deletions(-)\n\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex acf155c..b598366 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -753,29 +753,40 @@ sub esc_path {\n # Make control characters \"printable\", using character escape codes (CEC)\n sub quot_cec {\n \tmy $cntrl = shift;\n+\tmy %opts = @_;\n \tmy %es = ( # character escape codes, aka escape sequences\n-\t\t   \"\\t\" => '\\t',   # tab            (HT)\n-\t\t   \"\\n\" => '\\n',   # line feed      (LF)\n-\t\t   \"\\r\" => '\\r',   # carrige return (CR)\n-\t\t   \"\\f\" => '\\f',   # form feed      (FF)\n-\t\t   \"\\b\" => '\\b',   # backspace      (BS)\n-\t\t   \"\\a\" => '\\a',   # alarm (bell)   (BEL)\n-\t\t   \"\\e\" => '\\e',   # escape         (ESC)\n-\t\t   \"\\013\" => '\\v', # vertical tab   (VT)\n-\t\t   \"\\000\" => '\\0', # nul character  (NUL)\n-\t\t   );\n+\t\t\"\\t\" => '\\t',   # tab            (HT)\n+\t\t\"\\n\" => '\\n',   # line feed      (LF)\n+\t\t\"\\r\" => '\\r',   # carrige return (CR)\n+\t\t\"\\f\" => '\\f',   # form feed      (FF)\n+\t\t\"\\b\" => '\\b',   # backspace      (BS)\n+\t\t\"\\a\" => '\\a',   # alarm (bell)   (BEL)\n+\t\t\"\\e\" => '\\e',   # escape         (ESC)\n+\t\t\"\\013\" => '\\v', # vertical tab   (VT)\n+\t\t\"\\000\" => '\\0', # nul character  (NUL)\n+\t);\n \tmy $chr = ( (exists $es{$cntrl})\n \t\t    ? $es{$cntrl}\n \t\t    : sprintf('\\%03o', ord($cntrl)) );\n-\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\tif ($opts{-nohtml}) {\n+\t\treturn $chr;\n+\t} else {\n+\t\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\t}\n }\n \n # Alternatively use unicode control pictures codepoints,\n # Unicode \"printable representation\" (PR)\n sub quot_upr {\n \tmy $cntrl = shift;\n+\tmy %opts = @_;\n+\n \tmy $chr = sprintf('&#%04d;', 0x2400+ord($cntrl));\n-\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\tif ($opts{-nohtml}) {\n+\t\treturn $chr;\n+\t} else {\n+\t\treturn \"<span class=\\\"cntrl\\\">$chr</span>\";\n+\t}\n }\n \n # git may return quoted and escaped filenames\n@@ -800,7 +811,7 @@ sub unquote {\n \t\t\treturn chr(oct($seq));\n \t\t} elsif (exists $es{$seq}) {\n \t\t\t# C escape sequence, aka character escape code\n-\t\t\treturn $es{$seq}\n+\t\t\treturn $es{$seq};\n \t\t}\n \t\t# quoted ordinary character\n \t\treturn $seq;\n"}]}