[XMLSCHEMA-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: [xml-dev] New release (2.8) of XSV

From: Daniel Veillard <daniel@veillard.com>
Date: Sat, 9 Oct 2004 14:40:18 +0200
To: "Henry S. Thompson" <ht@inf.ed.ac.uk>
Cc: Jeff Rafter <lists@jeffrafter.com>, xmlschema-dev@w3.org, xml-dev@lists.xml.org
Message-ID: <20041009124018.GD11758@daniel.veillard.com>
xsv rpm

On Fri, Oct 08, 2004 at 05:30:50PM +0100, Henry S. Thompson wrote:
> The really good news is that this approach doesn't require XSV to punt
> in the face of large exponents, which it used to do (i.e. treated all
> numbers > 100 in min/maxOccurs as if they _were_ 100).  All other
> existing processors do something similar (that is, punt above some
> number), I believe.

libxml2 regexps used counters since day 1 for min/maxoccurs implementation.
The explosion didn't look a supportable alternative to me as it opens
the door to trivial DoS attacks or forces to break the schemas validation
which is also a big problem if you consider schemas as a contract between
two communicating parties.

Daniel

-- 
Daniel Veillard      | libxml Gnome XML XSLT toolkit  http://xmlsoft.org/
daniel@v...  | Rpmfind RPM search engine http://rpmfind.net/
http://veillard.com/ | 
Received on Saturday, 9 October 2004 12:41:18 GMT

Subscribe to the Stylus Scoop newsletter for helpful XML tips and tutorials.
Email
First Name
Last Name
Company

Download Stylus Studio 6 XML Enterprise Edition

Subscribe in XML format
RSS 2.0
Atom 0.3
Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2007 All Rights Reserved.