mTokens = null; $this->mUniqPrefix = null; } /** * @param string $text * @return string */ public function getWrapped( $text ) { $this->mTokens = new ReplacementArray; $this->mUniqPrefix = "\x7fUNIQ" . dechex( mt_rand( 0, 0x7fffffff ) ) . dechex( mt_rand( 0, 0x7fffffff ) ); $this->mMarkerIndex = 0; // Replace elements with placeholders $wrappedtext = preg_replace_callback( ParserOutput::EDITSECTION_REGEX, array( &$this, 'replaceCallback' ), $text ); // ...and markers $wrappedtext = preg_replace_callback( '/\<\\/?mw:toc\>/', array( &$this, 'replaceCallback' ), $wrappedtext ); // ... and tags $wrappedtext = preg_replace_callback( '/\/s', array( &$this, 'replaceCallback' ), $wrappedtext ); // Modify inline Microdata and elements so they say and so // we can trick Tidy into not stripping them out by including them in tidy's new-empty-tags config $wrappedtext = preg_replace( '!<(link|meta)([^>]*?)(/{0,1}>)!', '' . 'test' . $wrappedtext . ''; return $wrappedtext; } /** * @param array $m * * @return string */ public function replaceCallback( $m ) { $marker = "{$this->mUniqPrefix}-item-{$this->mMarkerIndex}" . Parser::MARKER_SUFFIX; $this->mMarkerIndex++; $this->mTokens->setPair( $marker, $m[0] ); return $marker; } /** * @param string $text * @return string */ public function postprocess( $text ) { // Revert back to <{link,meta}> $text = preg_replace( '!]*?)(/{0,1}>)!', '<$1$2$3', $text ); // Restore the contents of placeholder tokens $text = $this->mTokens->replace( $text ); return $text; } } /** * Class to interact with HTML tidy * * Either the external tidy program or the in-process tidy extension * will be used depending on availability. Override the default * $wgTidyInternal setting to disable the internal if it's not working. * * @ingroup Parser */ class MWTidy { /** * Interface with html tidy, used if $wgUseTidy = true. * If tidy isn't able to correct the markup, the original will be * returned in all its glory with a warning comment appended. * * @param string $text Hideous HTML input * @return string Corrected HTML output */ public static function tidy( $text ) { $wrapper = new MWTidyWrapper; $wrappedtext = $wrapper->getWrapped( $text ); $retVal = null; $correctedtext = self::clean( $wrappedtext, false, $retVal ); if ( $retVal < 0 ) { wfDebug( "Possible tidy configuration error!\n" ); return $text . "\n\n"; } elseif ( is_null( $correctedtext ) ) { wfDebug( "Tidy error detected!\n" ); return $text . "\n\n"; } $correctedtext = $wrapper->postprocess( $correctedtext ); // restore any hidden tokens return $correctedtext; } /** * Check HTML for errors, used if $wgValidateAllHtml = true. * * @param string $text * @param string &$errorStr Return the error string * @return bool Whether the HTML is valid */ public static function checkErrors( $text, &$errorStr = null ) { $retval = 0; $errorStr = self::clean( $text, true, $retval ); return ( $retval < 0 && $errorStr == '' ) || $retval == 0; } /** * Perform a clean/repair operation * @param string $text HTML to check * @param bool $stderr Whether to read result from STDERR rather than STDOUT * @param int &$retval Exit code (-1 on internal error) * @return null|string * @throws MWException */ private static function clean( $text, $stderr = false, &$retval = null ) { global $wgTidyInternal; if ( $wgTidyInternal ) { if ( wfIsHHVM() ) { if ( $stderr ) { throw new MWException( __METHOD__ . ": error text return from HHVM tidy is not supported" ); } return self::hhvmClean( $text, $retval ); } else { return self::phpClean( $text, $stderr, $retval ); } } else { return self::externalClean( $text, $stderr, $retval ); } } /** * Spawn an external HTML tidy process and get corrected markup back from it. * Also called in OutputHandler.php for full page validation * * @param string $text HTML to check * @param bool $stderr Whether to read result from STDERR rather than STDOUT * @param int &$retval Exit code (-1 on internal error) * @return string|null */ private static function externalClean( $text, $stderr = false, &$retval = null ) { global $wgTidyConf, $wgTidyBin, $wgTidyOpts; $cleansource = ''; $opts = ' -utf8'; if ( $stderr ) { $descriptorspec = array( 0 => array( 'pipe', 'r' ), 1 => array( 'file', wfGetNull(), 'a' ), 2 => array( 'pipe', 'w' ) ); } else { $descriptorspec = array( 0 => array( 'pipe', 'r' ), 1 => array( 'pipe', 'w' ), 2 => array( 'file', wfGetNull(), 'a' ) ); } $readpipe = $stderr ? 2 : 1; $pipes = array(); $process = proc_open( "$wgTidyBin -config $wgTidyConf $wgTidyOpts$opts", $descriptorspec, $pipes ); //NOTE: At least on linux, the process will be created even if tidy is not installed. // This means that missing tidy will be treated as a validation failure. if ( is_resource( $process ) ) { // Theoretically, this style of communication could cause a deadlock // here. If the stdout buffer fills up, then writes to stdin could // block. This doesn't appear to happen with tidy, because tidy only // writes to stdout after it's finished reading from stdin. Search // for tidyParseStdin and tidySaveStdout in console/tidy.c fwrite( $pipes[0], $text ); fclose( $pipes[0] ); while ( !feof( $pipes[$readpipe] ) ) { $cleansource .= fgets( $pipes[$readpipe], 1024 ); } fclose( $pipes[$readpipe] ); $retval = proc_close( $process ); } else { wfWarn( "Unable to start external tidy process" ); $retval = -1; } if ( !$stderr && $cleansource == '' && $text != '' ) { // Some kind of error happened, so we couldn't get the corrected text. // Just give up; we'll use the source text and append a warning. $cleansource = null; } return $cleansource; } /** * Use the HTML tidy extension to use the tidy library in-process, * saving the overhead of spawning a new process. * * @param string $text HTML to check * @param bool $stderr Whether to read result from error status instead of output * @param int &$retval Exit code (-1 on internal error) * @return string|null */ private static function phpClean( $text, $stderr = false, &$retval = null ) { global $wgTidyConf, $wgDebugTidy; if ( ( !wfIsHHVM() && !class_exists( 'tidy' ) ) || ( wfIsHHVM() && !function_exists( 'tidy_repair_string' ) ) ) { wfWarn( "Unable to load internal tidy class." ); $retval = -1; return null; } $tidy = new tidy; $tidy->parseString( $text, $wgTidyConf, 'utf8' ); if ( $stderr ) { $retval = $tidy->getStatus(); return $tidy->errorBuffer; } $tidy->cleanRepair(); $retval = $tidy->getStatus(); if ( $retval == 2 ) { // 2 is magic number for fatal error // http://www.php.net/manual/en/function.tidy-get-status.php $cleansource = null; } else { $cleansource = tidy_get_output( $tidy ); if ( $wgDebugTidy && $retval > 0 ) { $cleansource .= "', '-->', $tidy->errorBuffer ) . "\n-->"; } } return $cleansource; } /** * Use the tidy extension for HHVM from * https://github.com/wikimedia/mediawiki-php-tidy * * This currently does not support the object-oriented interface, but * tidy_repair_string() can be used for the most common tasks. * * @param string $text HTML to check * @param int &$retval Exit code (-1 on internal error) * @return string|null */ private static function hhvmClean( $text, &$retval ) { global $wgTidyConf; $cleansource = tidy_repair_string( $text, $wgTidyConf, 'utf8' ); if ( $cleansource === false ) { $cleansource = null; $retval = -1; } else { $retval = 0; } return $cleansource; } }