1
0
mirror of https://github.com/golang/go synced 2024-11-12 00:30:22 -07:00
go/src
Katie Hockman d0b79e3513 encoding/xml: prevent infinite loop while decoding
This change properly handles a TokenReader which
returns an EOF in the middle of an open XML
element.

Thanks to Sam Whited for reporting this.

Fixes CVE-2021-27918
Fixes #44913

Change-Id: Id02a3f3def4a1b415fa2d9a8e3b373eb6cb0f433
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1004594
Reviewed-by: Russ Cox <rsc@google.com>
Reviewed-by: Roland Shoemaker <bracewell@google.com>
Reviewed-by: Filippo Valsorda <valsorda@google.com>
Reviewed-on: https://go-review.googlesource.com/c/go/+/300391
Trust: Katie Hockman <katie@golang.org>
Run-TryBot: Katie Hockman <katie@golang.org>
TryBot-Result: Go Bot <gobot@golang.org>
Reviewed-by: Alexander Rakoczy <alex@golang.org>
Reviewed-by: Filippo Valsorda <filippo@golang.org>
2021-03-10 18:19:03 +00:00
..
archive archive/zip: fix panic in Reader.Open 2021-03-10 18:18:28 +00:00
bufio bufio, bytes, strings: handle negative runes in WriteRune 2021-02-24 04:01:25 +00:00
builtin
bytes bufio, bytes, strings: handle negative runes in WriteRune 2021-02-24 04:01:25 +00:00
cmd cmd/compile: deal with helper generic types that add methods to T 2021-03-10 17:36:55 +00:00
compress
container
context context: avoid importing context package twice 2021-02-24 18:15:00 +00:00
crypto crypto/rand: supports for getrandom syscall in DragonFlyBSD 2021-03-10 09:01:05 +00:00
database/sql database/sql: close driver.Connector if it implements io.Closer 2021-02-25 19:34:27 +00:00
debug cmd/link,debug/elf: mips32, add .gnu.attributes and .MIPS.abiflags sections 2021-03-02 00:51:00 +00:00
embed
encoding encoding/xml: prevent infinite loop while decoding 2021-03-10 18:19:03 +00:00
errors
expvar
flag
fmt
go go/types: add missing build tag to api_go1.18_test.go 2021-03-10 17:09:54 +00:00
hash hash/maphash: remove duplicate from Hash documentation 2021-02-24 08:36:15 +00:00
html all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
image image: resolve the TODO of doc comment style 2021-02-24 01:35:53 +00:00
index/suffixarray all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
internal crypto/rand: supports for getrandom syscall in DragonFlyBSD 2021-03-10 09:01:05 +00:00
io io/ioutil: forward TempFile and TempDir to os package 2021-02-24 15:12:08 +00:00
log all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
math math/big: add shrVU and shlVU benchmarks 2021-03-07 23:02:35 +00:00
mime all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
net net: don't append a dot to TXT records on Plan 9 2021-03-09 19:25:34 +00:00
os os/signal: remove comments about SA_RESTART 2021-03-08 20:41:06 +00:00
path all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
plugin all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
reflect reflect: add VisibleFields function 2021-03-05 23:47:39 +00:00
regexp all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
runtime runtime/race: update dead link 2021-03-10 17:07:49 +00:00
sort all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
strconv all: faster midpoint computation in binary search 2021-02-23 01:37:31 +00:00
strings bufio, bytes, strings: handle negative runes in WriteRune 2021-02-24 04:01:25 +00:00
sync all: go fmt std cmd (but revert vendor) 2021-02-20 03:54:50 +00:00
syscall syscall: treat proc thread attribute lists as unsafe.Pointers 2021-03-04 19:59:23 +00:00
testdata
testing testing: fix typo in a comment 2021-03-10 04:06:13 +00:00
text text/template: wrap errors returned by template functions instead of stringifying them 2021-03-05 18:00:44 +00:00
time time: correct unusual extension string cases 2021-02-27 03:03:29 +00:00
unicode unicode: correctly handle negative runes 2021-02-24 04:00:46 +00:00
unsafe
vendor cmd/vendor: get golang.org/x/sys@beda7e5e158 2021-02-19 00:40:30 +00:00
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod cmd/vendor: get golang.org/x/sys@beda7e5e158 2021-02-19 00:40:30 +00:00
go.sum cmd/vendor: get golang.org/x/sys@beda7e5e158 2021-02-19 00:40:30 +00:00
make.bash
make.bat
Make.dist
make.rc
race.bash runtime: enable race detector on openbsd/amd64 2021-02-23 12:14:32 +00:00
race.bat
README.vendor
run.bash build: set GOPATH consistently in run.bash, run.bat, run.rc 2021-02-19 00:04:56 +00:00
run.bat build: set GOPATH consistently in run.bash, run.bat, run.rc 2021-02-19 00:04:56 +00:00
run.rc build: set GOPATH consistently in run.bash, run.bat, run.rc 2021-02-19 00:04:56 +00:00

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.