<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>40659</bug_id>
          
          <creation_ts>2010-06-16 01:12:37 -0700</creation_ts>
          <short_desc>Switch XSSAuditor over to using new entity parser</short_desc>
          <delta_ts>2011-05-23 10:15:19 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Other</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>39259</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Adam Barth">abarth</reporter>
          <assigned_to name="Adam Barth">abarth</assigned_to>
          <cc>eric</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>238716</commentid>
    <comment_count>0</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-16 01:12:37 -0700</bug_when>
    <thetext>Switch XSSAuditor over to using new entity parser</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238717</commentid>
    <comment_count>1</comment_count>
      <attachid>58858</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-16 01:14:13 -0700</bug_when>
    <thetext>Created attachment 58858
wip</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238721</commentid>
    <comment_count>2</comment_count>
      <attachid>58860</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-16 01:27:14 -0700</bug_when>
    <thetext>Created attachment 58860
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238724</commentid>
    <comment_count>3</comment_count>
      <attachid>58860</attachid>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2010-06-16 01:30:44 -0700</bug_when>
    <thetext>Comment on attachment 58860
Patch

So this is not reflected in the tests in any way?  There are certainly many more entities supported in HTML5 than in our old parser.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238728</commentid>
    <comment_count>4</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-16 01:37:12 -0700</bug_when>
    <thetext>Yeah, but the two backend to the same entity list.  Maybe we could use surrogate pairs?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238730</commentid>
    <comment_count>5</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2010-06-16 01:38:35 -0700</bug_when>
    <thetext>Does HTML5 support different entities in terms of &amp;#x0000; style?  I thought it supported longer or shorter lists of digits there?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>238733</commentid>
    <comment_count>6</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-16 01:48:20 -0700</bug_when>
    <thetext>Another possibility is CR, which think the old entity parser converted to LF.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>243506</commentid>
    <comment_count>7</comment_count>
      <attachid>58860</attachid>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2010-06-27 14:52:03 -0700</bug_when>
    <thetext>Comment on attachment 58860
Patch

no tests.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>408027</commentid>
    <comment_count>8</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-05-23 10:15:19 -0700</bug_when>
    <thetext>This happened a while ago!</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>58858</attachid>
            <date>2010-06-16 01:14:13 -0700</date>
            <delta_ts>2010-06-16 01:27:10 -0700</delta_ts>
            <desc>wip</desc>
            <filename>bug-40659-20100616011412.patch</filename>
            <type>text/plain</type>
            <size>1747</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYkNvcmUvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvQ2hhbmdlTG9n
CShyZXZpc2lvbiA2MTI0MCkKKysrIFdlYkNvcmUvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBA
IC0xLDMgKzEsMTggQEAKKzIwMTAtMDYtMTYgIEFkYW0gQmFydGggIDxhYmFydGhAd2Via2l0Lm9y
Zz4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBTd2l0
Y2ggWFNTQXVkaXRvciBvdmVyIHRvIHVzaW5nIG5ldyBlbnRpdHkgcGFyc2VyCisgICAgICAgIGh0
dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD00MDY1OQorCisgICAgICAgIFRo
ZSBYU1NBdWRpdG9yIG5lZWRzIHRvIHVzZSBhbiBlbnRpdHkgcGFyc2VyIHRoYXQgbWF0Y2hlcyB0
aGUgcmVhbAorICAgICAgICBwYXNlci4gIE5vdyB0aGF0IHdlJ3ZlIHN3aXRjaGVkIHRvIHVzaW5n
IHRoZSBuZXcgcGFzZXIsIHdlIGNhbiBzd2l0Y2gKKyAgICAgICAgdGhlIGF1ZGl0b3IgdG9vLiAg
SSdkIHJhdGhlciBtYWtlIHRoaXMgY29uZGl0aW9uYWwgb24gdGhlCisgICAgICAgIFdlYkNvcmU6
OlNldHRpbmcsIGJ1dCBJIGRvbid0IHNlZSBhIGNsZWFuIHdheSBvZiBkb2luZyB0aGF0LgorCisg
ICAgICAgICogcGFnZS9YU1NBdWRpdG9yLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OlhTU0F1ZGl0
b3I6OmRlY29kZUhUTUxFbnRpdGllcyk6CisKIDIwMTAtMDYtMTYgIEFkYW0gQmFydGggIDxhYmFy
dGhAd2Via2l0Lm9yZz4KIAogICAgICAgICBSZXZpZXdlZCBieSBFcmljIFNlaWRlbC4KSW5kZXg6
IFdlYkNvcmUvcGFnZS9YU1NBdWRpdG9yLmNwcAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBXZWJDb3JlL3BhZ2Uv
WFNTQXVkaXRvci5jcHAJKHJldmlzaW9uIDYxMjM4KQorKysgV2ViQ29yZS9wYWdlL1hTU0F1ZGl0
b3IuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0zNCw2ICszNCw3IEBACiAjaW5jbHVkZSAiRG9jdW1l
bnRMb2FkZXIuaCIKICNpbmNsdWRlICJET01XaW5kb3cuaCIKICNpbmNsdWRlICJGcmFtZS5oIgor
I2luY2x1ZGUgIkhUTUw1RW50aXR5UGFzZXIuaCIKICNpbmNsdWRlICJLVVJMLmgiCiAjaW5jbHVk
ZSAiUHJlbG9hZFNjYW5uZXIuaCIKICNpbmNsdWRlICJSZXNvdXJjZVJlc3BvbnNlQmFzZS5oIgpA
QCAtMjc3LDcgKzI3OCw3IEBAIFN0cmluZyBYU1NBdWRpdG9yOjpkZWNvZGVIVE1MRW50aXRpZXMo
Y28KICAgICAgICAgaWYgKGxlYXZlVW5kZWNvZGFibGVFbnRpdGllc1VudG91Y2hlZCkKICAgICAg
ICAgICAgIHNvdXJjZVNoYWRvdyA9IHNvdXJjZTsKICAgICAgICAgYm9vbCBub3RFbm91Z2hDaGFy
YWN0ZXJzID0gZmFsc2U7Ci0gICAgICAgIHVuc2lnbmVkIGVudGl0eSA9IFByZWxvYWRTY2FubmVy
Ojpjb25zdW1lRW50aXR5KHNvdXJjZSwgbm90RW5vdWdoQ2hhcmFjdGVycyk7CisgICAgICAgIHVu
c2lnbmVkIGVudGl0eSA9IGNvbnN1bWVIVE1MNUVudGl0eShzb3VyY2UsIG5vdEVub3VnaENoYXJh
Y3RlcnMpOwogICAgICAgICAvLyBXZSBpZ25vcmUgbm90RW5vdWdoQ2hhcmFjdGVycyBiZWNhdXNl
IHdlIG1pZ2h0IGFzIHdlbGwgdXNlIHRoaXMgbG9vcAogICAgICAgICAvLyB0byBjb3B5IHRoZSBy
ZW1haW5pbmcgY2hhcmFjdGVycyBpbnRvIHxyZXN1bHR8LgogCg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>58860</attachid>
            <date>2010-06-16 01:27:14 -0700</date>
            <delta_ts>2010-06-27 14:52:03 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-40659-20100616012713.patch</filename>
            <type>text/plain</type>
            <size>2058</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1dlYkNvcmUvQ2hhbmdlTG9nIGIvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXgg
NzkwZTNhZmQyM2U4MmI0ZTJhNTViMjVmMmMxMGE5MDA1ZGM2YjI2YS4uYjM3MjZhOTI0NThkMjM2
YmIxZWU3ZGMyODQ5YTFkZmUzYTAyZDI0YyAxMDA2NDQKLS0tIGEvV2ViQ29yZS9DaGFuZ2VMb2cK
KysrIGIvV2ViQ29yZS9DaGFuZ2VMb2cKQEAgLTIsNiArMiwyNCBAQAogCiAgICAgICAgIFJldmll
d2VkIGJ5IE5PQk9EWSAoT09QUyEpLgogCisgICAgICAgIFN3aXRjaCBYU1NBdWRpdG9yIG92ZXIg
dG8gdXNpbmcgbmV3IGVudGl0eSBwYXJzZXIKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5v
cmcvc2hvd19idWcuY2dpP2lkPTQwNjU5CisKKyAgICAgICAgVGhlIFhTU0F1ZGl0b3IgbmVlZHMg
dG8gdXNlIGFuIGVudGl0eSBwYXJzZXIgdGhhdCBtYXRjaGVzIHRoZSByZWFsCisgICAgICAgIHBh
c2VyLiAgTm93IHRoYXQgd2UndmUgc3dpdGNoZWQgdG8gdXNpbmcgdGhlIG5ldyBwYXNlciwgd2Ug
Y2FuIHN3aXRjaAorICAgICAgICB0aGUgYXVkaXRvciB0b28uICBJJ2QgcmF0aGVyIG1ha2UgdGhp
cyBjb25kaXRpb25hbCBvbiB0aGUKKyAgICAgICAgV2ViQ29yZTo6U2V0dGluZywgYnV0IEkgZG9u
J3Qgc2VlIGEgY2xlYW4gd2F5IG9mIGRvaW5nIHRoYXQuCisKKyAgICAgICAgSWYgSSB3ZXJlIGNs
ZXZlciwgSSdkIGZpbmQgYSB3YXkgb2YgdGVzdGluZyB0aGlzIGJ5IGZpZ3VyaW5nIG91dCBhCisg
ICAgICAgIGRpZmZlcmVuY2UgYmV0d2VlbiB0aGVzZSB0d28gZW50aXR5IHBhcnNlcnMuLi4KKwor
ICAgICAgICAqIHBhZ2UvWFNTQXVkaXRvci5jcHA6CisgICAgICAgIChXZWJDb3JlOjpYU1NBdWRp
dG9yOjpkZWNvZGVIVE1MRW50aXRpZXMpOgorCisyMDEwLTA2LTE2ICBBZGFtIEJhcnRoICA8YWJh
cnRoQHdlYmtpdC5vcmc+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisK
ICAgICAgICAgRG9uJ3QgY3Jhc2ggd2hlbiBhIGRvY3VtZW50IGVuZHMgd2l0aCBhbiBlbnRpdHkK
ICAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTQwNjU4CiAK
ZGlmZiAtLWdpdCBhL1dlYkNvcmUvcGFnZS9YU1NBdWRpdG9yLmNwcCBiL1dlYkNvcmUvcGFnZS9Y
U1NBdWRpdG9yLmNwcAppbmRleCBiNWFiYTc5ZDJiMThhNDM0N2E3MDBmN2YwMWU5NDg1YTQwZWMw
ZWVlLi45MTNlMzI0YTYzZDFhNzNmNjgxNWM5MWRlOTY2Zjg1NGZjM2JmYTBiIDEwMDY0NAotLS0g
YS9XZWJDb3JlL3BhZ2UvWFNTQXVkaXRvci5jcHAKKysrIGIvV2ViQ29yZS9wYWdlL1hTU0F1ZGl0
b3IuY3BwCkBAIC0zNCw2ICszNCw3IEBACiAjaW5jbHVkZSAiRG9jdW1lbnRMb2FkZXIuaCIKICNp
bmNsdWRlICJET01XaW5kb3cuaCIKICNpbmNsdWRlICJGcmFtZS5oIgorI2luY2x1ZGUgIkhUTUw1
RW50aXR5UGFyc2VyLmgiCiAjaW5jbHVkZSAiS1VSTC5oIgogI2luY2x1ZGUgIlByZWxvYWRTY2Fu
bmVyLmgiCiAjaW5jbHVkZSAiUmVzb3VyY2VSZXNwb25zZUJhc2UuaCIKQEAgLTI3Nyw3ICsyNzgs
NyBAQCBTdHJpbmcgWFNTQXVkaXRvcjo6ZGVjb2RlSFRNTEVudGl0aWVzKGNvbnN0IFN0cmluZyYg
c3RyaW5nLCBib29sIGxlYXZlVW5kZWNvZGFibAogICAgICAgICBpZiAobGVhdmVVbmRlY29kYWJs
ZUVudGl0aWVzVW50b3VjaGVkKQogICAgICAgICAgICAgc291cmNlU2hhZG93ID0gc291cmNlOwog
ICAgICAgICBib29sIG5vdEVub3VnaENoYXJhY3RlcnMgPSBmYWxzZTsKLSAgICAgICAgdW5zaWdu
ZWQgZW50aXR5ID0gUHJlbG9hZFNjYW5uZXI6OmNvbnN1bWVFbnRpdHkoc291cmNlLCBub3RFbm91
Z2hDaGFyYWN0ZXJzKTsKKyAgICAgICAgdW5zaWduZWQgZW50aXR5ID0gY29uc3VtZUhUTUw1RW50
aXR5KHNvdXJjZSwgbm90RW5vdWdoQ2hhcmFjdGVycyk7CiAgICAgICAgIC8vIFdlIGlnbm9yZSBu
b3RFbm91Z2hDaGFyYWN0ZXJzIGJlY2F1c2Ugd2UgbWlnaHQgYXMgd2VsbCB1c2UgdGhpcyBsb29w
CiAgICAgICAgIC8vIHRvIGNvcHkgdGhlIHJlbWFpbmluZyBjaGFyYWN0ZXJzIGludG8gfHJlc3Vs
dHwuCiAK
</data>
<flag name="review"
          id="45368"
          type_id="1"
          status="-"
          setter="eric"
    />
          </attachment>
      

    </bug>

</bugzilla>