Skip to content

SimpleXmlLoadFileUsage ​

error on by default quick-fix

Group: Probable bugs · PhpStorm name: SimpleXmlLoadFileUsageInspection

simplexml_load_file() is affected by a long-standing PHP bug (#62577) where loading fails depending on the libxml entity-loader state. Reading the file yourself and passing its contents to simplexml_load_string() avoids it.

Example ​

php
<?php
function feeds(string $dir, string $cls, int $flags, string $nsUri) {
    $empty = simplexml_load_file();
    $a = simplexml_load_file($dir . '/rss.xml');
    $b = \simplexml_load_file($dir . '/atom.xml', $cls);
    $c = simplexml_load_file(getenv('FEED'),  $cls,$flags, $nsUri, true);
    $d = $this->simplexml_load_file('x.xml');
    return [$a, $b, $c, $d, $empty];
}
php
<?php
function feeds(string $dir, string $cls, int $flags, string $nsUri) {
    $empty = simplexml_load_file();
    $a = simplexml_load_string(file_get_contents($dir . '/rss.xml'));
    $b = simplexml_load_string(file_get_contents($dir . '/atom.xml'), $cls);
    $c = simplexml_load_string(file_get_contents(getenv('FEED')), $cls, $flags, $nsUri, true);
    $d = $this->simplexml_load_file('x.xml');
    return [$a, $b, $c, $d, $empty];
}

Reported:

  • line 4: simplexml_load_file() is affected by PHP bug #62577; load the contents with file_get_contents() and parse them with simplexml_load_string().
  • line 5: simplexml_load_file() is affected by PHP bug #62577; load the contents with file_get_contents() and parse them with simplexml_load_string().
  • line 6: simplexml_load_file() is affected by PHP bug #62577; load the contents with file_get_contents() and parse them with simplexml_load_string().

Configure ​

In custos.json:

json
{
  "rules": {
    "SimpleXmlLoadFileUsage": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore SimpleXmlLoadFileUsage

/**
 * @noinspection SimpleXmlLoadFileUsageInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.