Commit 6a8db47
committed
gh-155397: Raise InvalidFileException for malformed XML plists in plistlib
_PlistParser.parse() called expat's ParseFile() with no exception
translation, so two classes of malformed XML plist escaped as the
underlying exception instead of the documented InvalidFileException:
* XML that is not well-formed raised xml.parsers.expat.ExpatError.
* An <?xml ...?> declaration naming an encoding unknown to Python's
codec registry raised LookupError (this is what CIFuzz found in
gh-152211).
Neither exception type is a ValueError, so code written against the
documented contract (catching InvalidFileException, or even just
ValueError) did not catch them.1 parent 998b890 commit 6a8db47
3 files changed
Lines changed: 32 additions & 2 deletions
File tree
- Lib
- test
- Misc/NEWS.d/next/Library
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
70 | | - | |
| 70 | + | |
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| |||
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
188 | | - | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
189 | 197 | | |
190 | 198 | | |
191 | 199 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
933 | 933 | | |
934 | 934 | | |
935 | 935 | | |
| 936 | + | |
| 937 | + | |
| 938 | + | |
| 939 | + | |
| 940 | + | |
| 941 | + | |
| 942 | + | |
| 943 | + | |
| 944 | + | |
| 945 | + | |
| 946 | + | |
| 947 | + | |
| 948 | + | |
| 949 | + | |
| 950 | + | |
| 951 | + | |
| 952 | + | |
| 953 | + | |
936 | 954 | | |
937 | 955 | | |
938 | 956 | | |
| |||
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
0 commit comments