ppkarwasz commented on code in PR #12309:
URL: https://github.com/apache/seatunnel/pull/12309#discussion_r4003380256
##########
docs/zh/connectors/source/CosFile.md:
##########
@@ -367,7 +367,10 @@ POI 引擎允许读取的最大 Excel 文件大小,单位为字节。默认值
:::caution
-出于安全考虑(XXE 加固), 包含 `<!DOCTYPE ...>` 声明的 XML 文件(`file_format_type =
xml`)——即使是仅定义内部实体、不引用外部资源的良性声明——现在会被拒绝并抛出 `FILE_READ_FAILED`
错误。该行为没有配置项可以恢复为旧版本的处理方式。如果您的 XML 文件由某些工具导出并带有 `DOCTYPE` 头,请在使用 SeaTunnel
读取前将其移除或做预处理。
+FIXME: translation pending, English text follows.
+External resources referenced by XML files (`file_format_type = xml`), such as
external DTDs and external entities, are never resolved and are replaced with
empty content.
+XML files with a `<!DOCTYPE ...>` declaration are tolerated as long as they do
not rely on any external content.
+There is no configuration option to enable external resource resolution.
Review Comment:
Claude proposed this translation, but I don't read Chinese, so this should
be checked by somebody that does:
```suggestion
XML 文件(`file_format_type = xml`)中引用的外部资源(如外部 DTD 和外部实体)不会被解析,而是被替换为空内容。
带有 `<!DOCTYPE ...>` 声明的 XML 文件仍可读取,只要文件不依赖任何外部内容。
该行为没有配置项可以开启外部资源解析。
```
If approved, I can copy it to the other files.
##########
docs/zh/introduction/concepts/incompatible-changes.md:
##########
@@ -162,11 +162,16 @@
- 只有在使用 `--check` / `--dry-run=static` / `--dry-run=connect` 校验配置时(会执行
`validateUnknownKeys`),`Prometheus` sink 中残留的 `flush_interval`
键才会被拒绝。直接提交的作业会静默忽略该残留键;连接器会在每个 Sink 写入器启动时各打印一次告警作为替代提示(因此并行度为
N、多表或多副本的作业会多次打印)。
- **迁移指南**:从 `Prometheus` sink 中移除 `flush_interval`。如需在 Zeta 上继续使用定时刷新,请在作业
`env` 中设置 `sink.flush.interval`(毫秒)。在 Spark 和 Flink
上,缓存会在每个检查点被刷新;如需降低检查点之间的延迟,请调整 `batch_size`。`batch_size`
触发和写入器关闭时的最后一次刷新在所有引擎上保持不变。
-- **破坏性变更:File 连接器拒绝 XML 输入中的 `DOCTYPE` 声明(XXE 加固)**
- -
**影响范围**:`seatunnel-connectors-v2/connector-file/connector-file-base`(`XmlReadStrategy`),以及所有基于该模块构建的
File
Source:LocalFile、HdfsFile、S3File、OssFile、OssJindoFile、CosFile、FtpFile、SftpFile(`file_format_type
= xml`)
- - **变更说明**:此前 XML 读取器使用默认的 dom4j `SAXReader` 解析用户提供的文件,DTD 处理和外部实体解析均保持 JAXP
默认行为。精心构造的 `DOCTYPE`/外部实体载荷可能导致 worker 节点本地文件泄露、SSRF 式请求,或通过实体展开("billion
laughs")耗尽内存。现在 `XmlReadStrategy` 的所有解析都会经过加固后的 reader:启用 JAXP 安全处理特性、彻底拒绝任何
`<!DOCTYPE ...>` 声明、禁用外部通用/参数实体及外部 DTD 加载,并额外安装一个拒绝一切解析请求的 `EntityResolver`
作为与具体解析器实现无关的兜底防护。
- - **影响**:此前仅因携带 `<!DOCTYPE ...>` 声明才能被解析的 XML 文件——即使该声明是不引用任何外部
`SYSTEM`/`PUBLIC` 资源的良性声明——现在会以 `FileConnectorException(FILE_READ_FAILED)`
失败。该行为没有配置项可以恢复为旧版本的处理方式。
- - **迁移指南**:在使用 SeaTunnel 读取前,移除 XML 文件中的 `DOCTYPE` 声明,或对文件做预处理/重新导出。不带
`DOCTYPE` 声明的合法 XML 文件不受影响。(#11250)
+- **FIXME: translation pending, English text follows.**
+- **Behavior change: File connectors no longer resolve external resources in
XML input**
+ - **Affected component**:
`seatunnel-connectors-v2/connector-file/connector-file-base`
(`XmlReadStrategy`), and every file source built on it: LocalFile, HdfsFile,
S3File, OssFile, OssJindoFile, CosFile, FtpFile, SftpFile (`file_format_type =
xml`)
+ - **Description**: The XML reader now parses every file with a reader
obtained from [Apache Commons Secure
XML](https://commons.apache.org/proper/commons-secure-xml/).
+ External DTDs and external entities are never fetched and resolve to empty
content, and entity expansion is bounded.
+ - **Impact**: XML files that rely on external content (an external DTD
subset, or entities declared with `SYSTEM`/`PUBLIC` identifiers) are parsed as
if that content were empty.
+ Files that do not depend on external content are unaffected.
+ This includes the common case of a `<!DOCTYPE ...>` declaration that
merely points to an external DTD used for validation, as well as declarations
that only define internal entities.
+ There is no configuration option to enable external resource resolution.
+ - **Migration Guide**: Inline the content of external DTDs and entities into
the XML file before ingesting it with SeaTunnel. (#11250)
Review Comment:
Same as above: this proposal need to be checked by a Chinese speaker.
```suggestion
- **行为变更:File 连接器不再解析 XML 输入中的外部资源**
-
**影响范围**:`seatunnel-connectors-v2/connector-file/connector-file-base`(`XmlReadStrategy`),以及所有基于该模块构建的
File
Source:LocalFile、HdfsFile、S3File、OssFile、OssJindoFile、CosFile、FtpFile、SftpFile(`file_format_type
= xml`)
- **变更说明**:XML 读取器现在使用来自 [Apache Commons Secure
XML](https://commons.apache.org/proper/commons-secure-xml/) 的 reader 解析所有文件。
外部 DTD 和外部实体永远不会被获取,而是被解析为空内容,并且实体展开受到限制。
- **影响**:依赖外部内容(外部 DTD 子集,或使用 `SYSTEM`/`PUBLIC` 标识符声明的实体)的 XML
文件会按这些内容为空进行解析。
不依赖外部内容的文件不受影响。
这包括最常见的情况,即 `<!DOCTYPE ...>` 声明仅指向用于校验的外部 DTD,以及仅定义内部实体的声明。
该行为没有配置项可以开启外部资源解析。
- **迁移指南**:在使用 SeaTunnel 读取前,将外部 DTD 和实体的内容内联到 XML 文件中。(#11250)
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]