git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Rss produced by git is not valid xml?

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Nov 18, 2005, 20:55 UTC
Message-ID
<437E3FC1.2040307@zytor.com>
In-Reply-To
<Pine.LNX.4.64.0511181237040.13959@g5.osdl.org>
Linus Torvalds wrote:
Show 10 quoted lines
> 
> Which is a fine option. Latin-1 is probably the right choice for the 
> kernel, but not necessarily for other projects.
> 
> Another option is to just pass them through unmodified, and encourage the 
> XML parser to handle it. Anything that takes UTF-8 and doesn't have some 
> fallback to handle malformed input is basically buggy. It simply _will_ 
> happen occasionally, quite independently of git.  You can either give up, 
> or try to handle it. And giving up is always the wrong choice.
> 

Not necessarily. If you can't guarantee that you won't do something that's bad for security, giving up is the only valid choice.

The problem, of course, comes into place when people write generic XML parsers -- or, for that matter, UTF-8 decoders -- and don't know what will happen to the data downstream. Trying to make invalid data valid has the same problems as DWIM (after all, it *is* DWIM): if done on the wrong side of a security barrier it has unpredictable consequences.

Thus, making gitweb -- a producer application -- do the guessing is probably the right thing.

Sorry, Mr. Protocol; in this malware-infested world the old adage "be liberal in what you accept, conservative in what you send" unfortunately has had to be modified.

	-hpa
Previous: Linus TorvaldsNext: Josef Weidendorfer
Message 9 of 52 in “Rss produced by git is not valid xml?”
  1. Ismail DonmezNov 18, 2005
  2. Ismail DonmezNov 18, 2005
  3. Ismail DonmezNov 18, 2005
  4. Kay SieversNov 18, 2005
  5. Ismail DonmezNov 18, 2005
  6. Linus TorvaldsNov 18, 2005
  7. H. Peter AnvinNov 18, 2005
  8. Linus TorvaldsNov 18, 2005
  9. H. Peter AnvinNov 18, 2005
  10. Josef WeidendorferNov 18, 2005
  11. Kay SieversNov 18, 2005
  12. Ismail DonmezNov 18, 2005
  13. Linus TorvaldsNov 18, 2005
  14. Ismail DonmezNov 18, 2005
  15. Junio C HamanoNov 18, 2005
  16. Ismail DonmezNov 18, 2005
  17. Junio C HamanoNov 19, 2005
  18. Kay SieversNov 18, 2005
  19. Linus TorvaldsNov 18, 2005
  20. Ismail DonmezNov 18, 2005
  21. Linus TorvaldsNov 18, 2005
  22. H. Peter AnvinNov 18, 2005
  23. Linus TorvaldsNov 18, 2005
  24. H. Peter AnvinNov 18, 2005
  25. Andreas EricssonNov 18, 2005
  26. H. Peter AnvinNov 19, 2005
  27. Andreas EricssonNov 19, 2005
  28. Johannes SchindelinNov 19, 2005
  29. Linus TorvaldsNov 18, 2005
  30. H. Peter AnvinNov 18, 2005
  31. Johannes SchindelinNov 19, 2005
  32. Linus TorvaldsNov 18, 2005
  33. Johannes SchindelinNov 19, 2005
  34. Junio C HamanoNov 19, 2005
  35. Linus TorvaldsNov 19, 2005
  36. Junio C HamanoNov 19, 2005
  37. Linus TorvaldsNov 19, 2005
  38. Johannes SchindelinNov 20, 2005
  39. Linus TorvaldsNov 20, 2005
  40. Johannes SchindelinNov 20, 2005
  41. Johannes SchindelinNov 19, 2005
  42. H. Peter AnvinNov 20, 2005
  43. Johannes SchindelinNov 21, 2005
  44. H. Peter AnvinNov 21, 2005
  45. Junio C HamanoNov 19, 2005
  46. H. Peter AnvinNov 19, 2005
  47. Junio C HamanoNov 27, 2005
  48. Linus TorvaldsNov 27, 2005
  49. 2/3 mailinfo: allow -u to fall back on latin1 to utf8 conversion.Junio C Hamano, Nov 28, 2005
  50. H. Peter AnvinNov 28, 2005
  51. Junio C HamanoNov 28, 2005
  52. Kay SieversNov 27, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.