Coverage Report

Created: 2026-07-30 06:08

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/valid.c
Line
Count
Source
1
/*
2
 * valid.c : part of the code use to do the DTD handling and the validity
3
 *           checking
4
 *
5
 * See Copyright for the status of this software.
6
 *
7
 * Author: Daniel Veillard
8
 */
9
10
#define IN_LIBXML
11
#include "libxml.h"
12
13
#include <string.h>
14
#include <stdlib.h>
15
16
#include <libxml/xmlmemory.h>
17
#include <libxml/hash.h>
18
#include <libxml/uri.h>
19
#include <libxml/valid.h>
20
#include <libxml/parser.h>
21
#include <libxml/parserInternals.h>
22
#include <libxml/xmlerror.h>
23
#include <libxml/list.h>
24
#include <libxml/xmlsave.h>
25
26
#include "private/error.h"
27
#include "private/memory.h"
28
#include "private/parser.h"
29
#include "private/regexp.h"
30
#include "private/save.h"
31
#include "private/tree.h"
32
33
static xmlElementPtr
34
xmlGetDtdElementDesc2(xmlValidCtxtPtr ctxt, xmlDtdPtr dtd, const xmlChar *name);
35
36
#ifdef LIBXML_VALID_ENABLED
37
static int
38
xmlValidateAttributeValueInternal(xmlDocPtr doc, xmlAttributeType type,
39
                                  const xmlChar *value);
40
#endif
41
/************************************************************************
42
 *                  *
43
 *      Error handling routines       *
44
 *                  *
45
 ************************************************************************/
46
47
/**
48
 * Handle an out of memory error
49
 *
50
 * @param ctxt  an XML validation parser context
51
 */
52
static void
53
xmlVErrMemory(xmlValidCtxtPtr ctxt)
54
2.08k
{
55
2.08k
    if (ctxt != NULL) {
56
2.08k
        if (ctxt->flags & XML_VCTXT_USE_PCTXT) {
57
2.08k
            xmlCtxtErrMemory(ctxt->userData);
58
2.08k
        } else {
59
0
            xmlRaiseMemoryError(NULL, ctxt->error, ctxt->userData,
60
0
                                XML_FROM_VALID, NULL);
61
0
        }
62
2.08k
    } else {
63
0
        xmlRaiseMemoryError(NULL, NULL, NULL, XML_FROM_VALID, NULL);
64
0
    }
65
2.08k
}
66
67
/*
68
 * @returns 0 on success, -1 if a memory allocation failed
69
 */
70
static int
71
xmlDoErrValid(xmlValidCtxtPtr ctxt, xmlNodePtr node,
72
              xmlParserErrors code, int level,
73
              const xmlChar *str1, const xmlChar *str2, const xmlChar *str3,
74
              int int1,
75
543k
              const char *msg, ...) {
76
543k
    xmlParserCtxtPtr pctxt = NULL;
77
543k
    va_list ap;
78
543k
    int ret = 0;
79
80
543k
    if (ctxt == NULL)
81
0
        return -1;
82
543k
    if (ctxt->flags & XML_VCTXT_USE_PCTXT)
83
543k
        pctxt = ctxt->userData;
84
85
543k
    va_start(ap, msg);
86
543k
    if (pctxt != NULL) {
87
543k
        xmlCtxtVErr(pctxt, node, XML_FROM_VALID, code, level,
88
543k
                    str1, str2, str3, int1, msg, ap);
89
543k
        if (pctxt->errNo == XML_ERR_NO_MEMORY)
90
31.1k
            ret = -1;
91
543k
    } else {
92
0
        xmlGenericErrorFunc channel = NULL;
93
0
        void *data = NULL;
94
0
        int res;
95
96
0
        if (ctxt != NULL) {
97
0
            channel = ctxt->error;
98
0
            data = ctxt->userData;
99
0
        }
100
0
        res = xmlVRaiseError(NULL, channel, data, NULL, node,
101
0
                             XML_FROM_VALID, code, level, NULL, 0,
102
0
                             (const char *) str1, (const char *) str2,
103
0
                             (const char *) str2, int1, 0,
104
0
                             msg, ap);
105
0
        if (res < 0) {
106
0
            xmlVErrMemory(ctxt);
107
0
            ret = -1;
108
0
        }
109
0
    }
110
543k
    va_end(ap);
111
112
543k
    return ret;
113
543k
}
114
115
/**
116
 * Handle a validation error, provide contextual information
117
 *
118
 * @param ctxt  an XML validation parser context
119
 * @param node  the node raising the error
120
 * @param error  the error number
121
 * @param msg  the error message
122
 * @param str1  extra information
123
 * @param str2  extra information
124
 * @param str3  extra information
125
 */
126
static void LIBXML_ATTR_FORMAT(4,0)
127
xmlErrValidNode(xmlValidCtxtPtr ctxt,
128
                xmlNodePtr node, xmlParserErrors error,
129
                const char *msg, const xmlChar * str1,
130
                const xmlChar * str2, const xmlChar * str3)
131
508k
{
132
508k
    xmlDoErrValid(ctxt, node, error, XML_ERR_ERROR, str1, str2, str3, 0,
133
508k
                  msg, str1, str2, str3);
134
508k
}
135
136
#ifdef LIBXML_VALID_ENABLED
137
/**
138
 * Handle a validation error
139
 *
140
 * @param ctxt  an XML validation parser context
141
 * @param error  the error number
142
 * @param msg  the error message
143
 * @param extra  extra information
144
 */
145
static void LIBXML_ATTR_FORMAT(3,0)
146
xmlErrValid(xmlValidCtxtPtr ctxt, xmlParserErrors error,
147
            const char *msg, const char *extra)
148
10.3k
{
149
10.3k
    xmlDoErrValid(ctxt, NULL, error, XML_ERR_ERROR, (const xmlChar *) extra,
150
10.3k
                  NULL, NULL, 0, msg, extra);
151
10.3k
}
152
153
/**
154
 * Handle a validation error, provide contextual information
155
 *
156
 * @param ctxt  an XML validation parser context
157
 * @param node  the node raising the error
158
 * @param error  the error number
159
 * @param msg  the error message
160
 * @param str1  extra information
161
 * @param int2  extra information
162
 * @param str3  extra information
163
 */
164
static void LIBXML_ATTR_FORMAT(4,0)
165
xmlErrValidNodeNr(xmlValidCtxtPtr ctxt,
166
                xmlNodePtr node, xmlParserErrors error,
167
                const char *msg, const xmlChar * str1,
168
                int int2, const xmlChar * str3)
169
594
{
170
594
    xmlDoErrValid(ctxt, node, error, XML_ERR_ERROR, str1, str3, NULL, int2,
171
594
                  msg, str1, int2, str3);
172
594
}
173
174
/**
175
 * Handle a validation error, provide contextual information
176
 *
177
 * @param ctxt  an XML validation parser context
178
 * @param node  the node raising the error
179
 * @param error  the error number
180
 * @param msg  the error message
181
 * @param str1  extra information
182
 * @param str2  extra information
183
 * @param str3  extra information
184
 * @returns 0 on success, -1 if a memory allocation failed
185
 */
186
static int LIBXML_ATTR_FORMAT(4,0)
187
xmlErrValidWarning(xmlValidCtxtPtr ctxt,
188
                xmlNodePtr node, xmlParserErrors error,
189
                const char *msg, const xmlChar * str1,
190
                const xmlChar * str2, const xmlChar * str3)
191
24.4k
{
192
24.4k
    return xmlDoErrValid(ctxt, node, error, XML_ERR_WARNING, str1, str2, str3,
193
24.4k
                         0, msg, str1, str2, str3);
194
24.4k
}
195
196
197
198
#ifdef LIBXML_REGEXP_ENABLED
199
/*
200
 * If regexp are enabled we can do continuous validation without the
201
 * need of a tree to validate the content model. this is done in each
202
 * callbacks.
203
 * Each xmlValidState represent the validation state associated to the
204
 * set of nodes currently open from the document root to the current element.
205
 */
206
207
208
typedef struct _xmlValidState {
209
    xmlElementPtr  elemDecl;  /* pointer to the content model */
210
    xmlNodePtr           node;    /* pointer to the current node */
211
    xmlRegExecCtxtPtr    exec;    /* regexp runtime */
212
} _xmlValidState;
213
214
215
static int
216
0
vstateVPush(xmlValidCtxtPtr ctxt, xmlElementPtr elemDecl, xmlNodePtr node) {
217
0
    if (ctxt->vstateNr >= ctxt->vstateMax) {
218
0
        xmlValidState *tmp;
219
0
        int newSize;
220
221
0
        newSize = xmlGrowCapacity(ctxt->vstateMax, sizeof(tmp[0]),
222
0
                                  10, XML_MAX_ITEMS);
223
0
        if (newSize < 0) {
224
0
      xmlVErrMemory(ctxt);
225
0
      return(-1);
226
0
  }
227
0
  tmp = xmlRealloc(ctxt->vstateTab, newSize * sizeof(tmp[0]));
228
0
        if (tmp == NULL) {
229
0
      xmlVErrMemory(ctxt);
230
0
      return(-1);
231
0
  }
232
0
  ctxt->vstateTab = tmp;
233
0
  ctxt->vstateMax = newSize;
234
0
    }
235
0
    ctxt->vstate = &ctxt->vstateTab[ctxt->vstateNr];
236
0
    ctxt->vstateTab[ctxt->vstateNr].elemDecl = elemDecl;
237
0
    ctxt->vstateTab[ctxt->vstateNr].node = node;
238
0
    if ((elemDecl != NULL) && (elemDecl->etype == XML_ELEMENT_TYPE_ELEMENT)) {
239
0
  if (elemDecl->contModel == NULL)
240
0
      xmlValidBuildContentModel(ctxt, elemDecl);
241
0
  if (elemDecl->contModel != NULL) {
242
0
      ctxt->vstateTab[ctxt->vstateNr].exec =
243
0
    xmlRegNewExecCtxt(elemDecl->contModel, NULL, NULL);
244
0
            if (ctxt->vstateTab[ctxt->vstateNr].exec == NULL) {
245
0
                xmlVErrMemory(ctxt);
246
0
                return(-1);
247
0
            }
248
0
  } else {
249
0
      ctxt->vstateTab[ctxt->vstateNr].exec = NULL;
250
0
      xmlErrValidNode(ctxt, (xmlNodePtr) elemDecl,
251
0
                      XML_ERR_INTERNAL_ERROR,
252
0
          "Failed to build content model regexp for %s\n",
253
0
          node->name, NULL, NULL);
254
0
  }
255
0
    }
256
0
    return(ctxt->vstateNr++);
257
0
}
258
259
static int
260
0
vstateVPop(xmlValidCtxtPtr ctxt) {
261
0
    xmlElementPtr elemDecl;
262
263
0
    if (ctxt->vstateNr < 1) return(-1);
264
0
    ctxt->vstateNr--;
265
0
    elemDecl = ctxt->vstateTab[ctxt->vstateNr].elemDecl;
266
0
    ctxt->vstateTab[ctxt->vstateNr].elemDecl = NULL;
267
0
    ctxt->vstateTab[ctxt->vstateNr].node = NULL;
268
0
    if ((elemDecl != NULL) && (elemDecl->etype == XML_ELEMENT_TYPE_ELEMENT)) {
269
0
  xmlRegFreeExecCtxt(ctxt->vstateTab[ctxt->vstateNr].exec);
270
0
    }
271
0
    ctxt->vstateTab[ctxt->vstateNr].exec = NULL;
272
0
    if (ctxt->vstateNr >= 1)
273
0
  ctxt->vstate = &ctxt->vstateTab[ctxt->vstateNr - 1];
274
0
    else
275
0
  ctxt->vstate = NULL;
276
0
    return(ctxt->vstateNr);
277
0
}
278
279
#else /* not LIBXML_REGEXP_ENABLED */
280
/*
281
 * If regexp are not enabled, it uses a home made algorithm less
282
 * complex and easier to
283
 * debug/maintain than a generic NFA -> DFA state based algo. The
284
 * only restriction is on the deepness of the tree limited by the
285
 * size of the occurs bitfield
286
 *
287
 * this is the content of a saved state for rollbacks
288
 */
289
290
#define ROLLBACK_OR 0
291
#define ROLLBACK_PARENT 1
292
293
typedef struct _xmlValidState {
294
    xmlElementContentPtr cont;  /* pointer to the content model subtree */
295
    xmlNodePtr           node;  /* pointer to the current node in the list */
296
    long                 occurs;/* bitfield for multiple occurrences */
297
    unsigned char        depth; /* current depth in the overall tree */
298
    unsigned char        state; /* ROLLBACK_XXX */
299
} _xmlValidState;
300
301
#define MAX_RECURSE 25000
302
#define MAX_DEPTH ((sizeof(_xmlValidState.occurs)) * 8)
303
#define CONT ctxt->vstate->cont
304
#define NODE ctxt->vstate->node
305
#define DEPTH ctxt->vstate->depth
306
#define OCCURS ctxt->vstate->occurs
307
#define STATE ctxt->vstate->state
308
309
#define OCCURRENCE (ctxt->vstate->occurs & (1 << DEPTH))
310
#define PARENT_OCCURRENCE (ctxt->vstate->occurs & ((1 << DEPTH) - 1))
311
312
#define SET_OCCURRENCE ctxt->vstate->occurs |= (1 << DEPTH)
313
#define RESET_OCCURRENCE ctxt->vstate->occurs &= ((1 << DEPTH) - 1)
314
315
static int
316
vstateVPush(xmlValidCtxtPtr ctxt, xmlElementContentPtr cont,
317
      xmlNodePtr node, unsigned char depth, long occurs,
318
      unsigned char state) {
319
    int i = ctxt->vstateNr - 1;
320
321
    if (ctxt->vstateNr >= ctxt->vstateMax) {
322
        xmlValidState *tmp;
323
        int newSize;
324
325
        newSize = xmlGrowCapacity(ctxt->vstateMax, sizeof(tmp[0]),
326
                                  8, MAX_RECURSE);
327
        if (newSize < 0) {
328
            xmlVErrMemory(ctxt);
329
            return(-1);
330
        }
331
        tmp = xmlRealloc(ctxt->vstateTab, newSize * sizeof(tmp[0]));
332
        if (tmp == NULL) {
333
      xmlVErrMemory(ctxt);
334
      return(-1);
335
  }
336
  ctxt->vstateTab = tmp;
337
  ctxt->vstateMax = newSize;
338
  ctxt->vstate = &ctxt->vstateTab[0];
339
    }
340
    /*
341
     * Don't push on the stack a state already here
342
     */
343
    if ((i >= 0) && (ctxt->vstateTab[i].cont == cont) &&
344
  (ctxt->vstateTab[i].node == node) &&
345
  (ctxt->vstateTab[i].depth == depth) &&
346
  (ctxt->vstateTab[i].occurs == occurs) &&
347
  (ctxt->vstateTab[i].state == state))
348
  return(ctxt->vstateNr);
349
    ctxt->vstateTab[ctxt->vstateNr].cont = cont;
350
    ctxt->vstateTab[ctxt->vstateNr].node = node;
351
    ctxt->vstateTab[ctxt->vstateNr].depth = depth;
352
    ctxt->vstateTab[ctxt->vstateNr].occurs = occurs;
353
    ctxt->vstateTab[ctxt->vstateNr].state = state;
354
    return(ctxt->vstateNr++);
355
}
356
357
static int
358
vstateVPop(xmlValidCtxtPtr ctxt) {
359
    if (ctxt->vstateNr <= 1) return(-1);
360
    ctxt->vstateNr--;
361
    ctxt->vstate = &ctxt->vstateTab[0];
362
    ctxt->vstate->cont =  ctxt->vstateTab[ctxt->vstateNr].cont;
363
    ctxt->vstate->node = ctxt->vstateTab[ctxt->vstateNr].node;
364
    ctxt->vstate->depth = ctxt->vstateTab[ctxt->vstateNr].depth;
365
    ctxt->vstate->occurs = ctxt->vstateTab[ctxt->vstateNr].occurs;
366
    ctxt->vstate->state = ctxt->vstateTab[ctxt->vstateNr].state;
367
    return(ctxt->vstateNr);
368
}
369
370
#endif /* LIBXML_REGEXP_ENABLED */
371
372
static int
373
nodeVPush(xmlValidCtxtPtr ctxt, xmlNodePtr value)
374
58.5k
{
375
58.5k
    if (ctxt->nodeNr >= ctxt->nodeMax) {
376
1.02k
        xmlNodePtr *tmp;
377
1.02k
        int newSize;
378
379
1.02k
        newSize = xmlGrowCapacity(ctxt->nodeMax, sizeof(tmp[0]),
380
1.02k
                                  4, XML_MAX_ITEMS);
381
1.02k
        if (newSize < 0) {
382
0
      xmlVErrMemory(ctxt);
383
0
            return (-1);
384
0
        }
385
1.02k
        tmp = xmlRealloc(ctxt->nodeTab, newSize * sizeof(tmp[0]));
386
1.02k
        if (tmp == NULL) {
387
13
      xmlVErrMemory(ctxt);
388
13
            return (-1);
389
13
        }
390
1.01k
  ctxt->nodeTab = tmp;
391
1.01k
        ctxt->nodeMax = newSize;
392
1.01k
    }
393
58.5k
    ctxt->nodeTab[ctxt->nodeNr] = value;
394
58.5k
    ctxt->node = value;
395
58.5k
    return (ctxt->nodeNr++);
396
58.5k
}
397
static xmlNodePtr
398
nodeVPop(xmlValidCtxtPtr ctxt)
399
73.9k
{
400
73.9k
    xmlNodePtr ret;
401
402
73.9k
    if (ctxt->nodeNr <= 0)
403
15.7k
        return (NULL);
404
58.2k
    ctxt->nodeNr--;
405
58.2k
    if (ctxt->nodeNr > 0)
406
57.5k
        ctxt->node = ctxt->nodeTab[ctxt->nodeNr - 1];
407
669
    else
408
669
        ctxt->node = NULL;
409
58.2k
    ret = ctxt->nodeTab[ctxt->nodeNr];
410
58.2k
    ctxt->nodeTab[ctxt->nodeNr] = NULL;
411
58.2k
    return (ret);
412
73.9k
}
413
414
/* TODO: use hash table for accesses to elem and attribute definitions */
415
416
417
#define CHECK_DTD           \
418
645k
   if (doc == NULL) return(0);         \
419
645k
   else if ((doc->intSubset == NULL) &&       \
420
645k
      (doc->extSubset == NULL)) return(0)
421
422
#ifdef LIBXML_REGEXP_ENABLED
423
424
/************************************************************************
425
 *                  *
426
 *    Content model validation based on the regexps   *
427
 *                  *
428
 ************************************************************************/
429
430
/**
431
 * Generate the automata sequence needed for that type
432
 *
433
 * @param content  the content model
434
 * @param ctxt  the schema parser context
435
 * @param name  the element name whose content is being built
436
 * @returns 1 if successful or 0 in case of error.
437
 */
438
static int
439
xmlValidBuildAContentModel(xmlElementContentPtr content,
440
               xmlValidCtxtPtr ctxt,
441
1.28M
               const xmlChar *name) {
442
1.28M
    if (content == NULL) {
443
0
  xmlErrValidNode(ctxt, NULL, XML_ERR_INTERNAL_ERROR,
444
0
      "Found NULL content in content model of %s\n",
445
0
      name, NULL, NULL);
446
0
  return(0);
447
0
    }
448
1.28M
    switch (content->type) {
449
0
  case XML_ELEMENT_CONTENT_PCDATA:
450
0
      xmlErrValidNode(ctxt, NULL, XML_ERR_INTERNAL_ERROR,
451
0
          "Found PCDATA in content model of %s\n",
452
0
                name, NULL, NULL);
453
0
      return(0);
454
0
      break;
455
1.26M
  case XML_ELEMENT_CONTENT_ELEMENT: {
456
1.26M
      xmlAutomataStatePtr oldstate = ctxt->state;
457
1.26M
      xmlChar fn[50];
458
1.26M
      xmlChar *fullname;
459
460
1.26M
      fullname = xmlBuildQName(content->name, content->prefix, fn, 50);
461
1.26M
      if (fullname == NULL) {
462
35
          xmlVErrMemory(ctxt);
463
35
    return(0);
464
35
      }
465
466
1.26M
      switch (content->ocur) {
467
1.16M
    case XML_ELEMENT_CONTENT_ONCE:
468
1.16M
        ctxt->state = xmlAutomataNewTransition(ctxt->am,
469
1.16M
          ctxt->state, NULL, fullname, NULL);
470
1.16M
        break;
471
79.7k
    case XML_ELEMENT_CONTENT_OPT:
472
79.7k
        ctxt->state = xmlAutomataNewTransition(ctxt->am,
473
79.7k
          ctxt->state, NULL, fullname, NULL);
474
79.7k
        xmlAutomataNewEpsilon(ctxt->am, oldstate, ctxt->state);
475
79.7k
        break;
476
13.9k
    case XML_ELEMENT_CONTENT_PLUS:
477
13.9k
        ctxt->state = xmlAutomataNewTransition(ctxt->am,
478
13.9k
          ctxt->state, NULL, fullname, NULL);
479
13.9k
        xmlAutomataNewTransition(ctxt->am, ctxt->state,
480
13.9k
                           ctxt->state, fullname, NULL);
481
13.9k
        break;
482
5.32k
    case XML_ELEMENT_CONTENT_MULT:
483
5.32k
        ctxt->state = xmlAutomataNewEpsilon(ctxt->am,
484
5.32k
              ctxt->state, NULL);
485
5.32k
        xmlAutomataNewTransition(ctxt->am,
486
5.32k
          ctxt->state, ctxt->state, fullname, NULL);
487
5.32k
        break;
488
1.26M
      }
489
1.26M
      if ((fullname != fn) && (fullname != content->name))
490
115k
    xmlFree(fullname);
491
1.26M
      break;
492
1.26M
  }
493
4.75k
  case XML_ELEMENT_CONTENT_SEQ: {
494
4.75k
      xmlAutomataStatePtr oldstate, oldend;
495
4.75k
      xmlElementContentOccur ocur;
496
497
      /*
498
       * Simply iterate over the content
499
       */
500
4.75k
      oldstate = ctxt->state;
501
4.75k
      ocur = content->ocur;
502
4.75k
      if (ocur != XML_ELEMENT_CONTENT_ONCE) {
503
3.54k
    ctxt->state = xmlAutomataNewEpsilon(ctxt->am, oldstate, NULL);
504
3.54k
    oldstate = ctxt->state;
505
3.54k
      }
506
1.06M
      do {
507
1.06M
    if (xmlValidBuildAContentModel(content->c1, ctxt, name) == 0)
508
18
                    return(0);
509
1.06M
    content = content->c2;
510
1.06M
      } while ((content->type == XML_ELEMENT_CONTENT_SEQ) &&
511
1.06M
         (content->ocur == XML_ELEMENT_CONTENT_ONCE));
512
4.73k
      if (xmlValidBuildAContentModel(content, ctxt, name) == 0)
513
12
                return(0);
514
4.72k
      oldend = ctxt->state;
515
4.72k
      ctxt->state = xmlAutomataNewEpsilon(ctxt->am, oldend, NULL);
516
4.72k
      switch (ocur) {
517
1.19k
    case XML_ELEMENT_CONTENT_ONCE:
518
1.19k
        break;
519
1.97k
    case XML_ELEMENT_CONTENT_OPT:
520
1.97k
        xmlAutomataNewEpsilon(ctxt->am, oldstate, ctxt->state);
521
1.97k
        break;
522
354
    case XML_ELEMENT_CONTENT_MULT:
523
354
        xmlAutomataNewEpsilon(ctxt->am, oldstate, ctxt->state);
524
354
        xmlAutomataNewEpsilon(ctxt->am, oldend, oldstate);
525
354
        break;
526
1.19k
    case XML_ELEMENT_CONTENT_PLUS:
527
1.19k
        xmlAutomataNewEpsilon(ctxt->am, oldend, oldstate);
528
1.19k
        break;
529
4.72k
      }
530
4.72k
      break;
531
4.72k
  }
532
8.14k
  case XML_ELEMENT_CONTENT_OR: {
533
8.14k
      xmlAutomataStatePtr oldstate, oldend;
534
8.14k
      xmlElementContentOccur ocur;
535
536
8.14k
      ocur = content->ocur;
537
8.14k
      if ((ocur == XML_ELEMENT_CONTENT_PLUS) ||
538
6.88k
    (ocur == XML_ELEMENT_CONTENT_MULT)) {
539
3.09k
    ctxt->state = xmlAutomataNewEpsilon(ctxt->am,
540
3.09k
      ctxt->state, NULL);
541
3.09k
      }
542
8.14k
      oldstate = ctxt->state;
543
8.14k
      oldend = xmlAutomataNewState(ctxt->am);
544
545
      /*
546
       * iterate over the subtypes and remerge the end with an
547
       * epsilon transition
548
       */
549
200k
      do {
550
200k
    ctxt->state = oldstate;
551
200k
    if (xmlValidBuildAContentModel(content->c1, ctxt, name) == 0)
552
10
                    return(0);
553
200k
    xmlAutomataNewEpsilon(ctxt->am, ctxt->state, oldend);
554
200k
    content = content->c2;
555
200k
      } while ((content->type == XML_ELEMENT_CONTENT_OR) &&
556
192k
         (content->ocur == XML_ELEMENT_CONTENT_ONCE));
557
8.13k
      ctxt->state = oldstate;
558
8.13k
      if (xmlValidBuildAContentModel(content, ctxt, name) == 0)
559
6
                return(0);
560
8.13k
      xmlAutomataNewEpsilon(ctxt->am, ctxt->state, oldend);
561
8.13k
      ctxt->state = xmlAutomataNewEpsilon(ctxt->am, oldend, NULL);
562
8.13k
      switch (ocur) {
563
1.54k
    case XML_ELEMENT_CONTENT_ONCE:
564
1.54k
        break;
565
3.50k
    case XML_ELEMENT_CONTENT_OPT:
566
3.50k
        xmlAutomataNewEpsilon(ctxt->am, oldstate, ctxt->state);
567
3.50k
        break;
568
1.83k
    case XML_ELEMENT_CONTENT_MULT:
569
1.83k
        xmlAutomataNewEpsilon(ctxt->am, oldstate, ctxt->state);
570
1.83k
        xmlAutomataNewEpsilon(ctxt->am, oldend, oldstate);
571
1.83k
        break;
572
1.25k
    case XML_ELEMENT_CONTENT_PLUS:
573
1.25k
        xmlAutomataNewEpsilon(ctxt->am, oldend, oldstate);
574
1.25k
        break;
575
8.13k
      }
576
8.13k
      break;
577
8.13k
  }
578
8.13k
  default:
579
0
      xmlErrValid(ctxt, XML_ERR_INTERNAL_ERROR,
580
0
                  "ContentModel broken for element %s\n",
581
0
      (const char *) name);
582
0
      return(0);
583
1.28M
    }
584
1.28M
    return(1);
585
1.28M
}
586
/**
587
 * (Re)Build the automata associated to the content model of this
588
 * element
589
 *
590
 * @deprecated Internal function, don't use.
591
 *
592
 * @param ctxt  a validation context
593
 * @param elem  an element declaration node
594
 * @returns 1 in case of success, 0 in case of error
595
 */
596
int
597
3.27k
xmlValidBuildContentModel(xmlValidCtxt *ctxt, xmlElement *elem) {
598
3.27k
    int ret = 0;
599
600
3.27k
    if ((ctxt == NULL) || (elem == NULL))
601
0
  return(0);
602
3.27k
    if (elem->type != XML_ELEMENT_DECL)
603
0
  return(0);
604
3.27k
    if (elem->etype != XML_ELEMENT_TYPE_ELEMENT)
605
0
  return(1);
606
    /* TODO: should we rebuild in this case ? */
607
3.27k
    if (elem->contModel != NULL) {
608
0
  if (!xmlRegexpIsDeterminist(elem->contModel)) {
609
0
      ctxt->valid = 0;
610
0
      return(0);
611
0
  }
612
0
  return(1);
613
0
    }
614
615
3.27k
    ctxt->am = xmlNewAutomata();
616
3.27k
    if (ctxt->am == NULL) {
617
28
        xmlVErrMemory(ctxt);
618
28
  return(0);
619
28
    }
620
3.24k
    ctxt->state = xmlAutomataGetInitState(ctxt->am);
621
3.24k
    if (xmlValidBuildAContentModel(elem->content, ctxt, elem->name) == 0)
622
35
        goto done;
623
3.21k
    xmlAutomataSetFinalState(ctxt->am, ctxt->state);
624
3.21k
    elem->contModel = xmlAutomataCompile(ctxt->am);
625
3.21k
    if (elem->contModel == NULL) {
626
767
        xmlVErrMemory(ctxt);
627
767
        goto done;
628
767
    }
629
2.44k
    if (xmlRegexpIsDeterminist(elem->contModel) != 1) {
630
360
  char expr[5000];
631
360
  expr[0] = 0;
632
360
  xmlSnprintfElementContent(expr, 5000, elem->content, 1);
633
360
  xmlErrValidNode(ctxt, (xmlNodePtr) elem,
634
360
                  XML_DTD_CONTENT_NOT_DETERMINIST,
635
360
         "Content model of %s is not deterministic: %s\n",
636
360
         elem->name, BAD_CAST expr, NULL);
637
360
        ctxt->valid = 0;
638
360
  goto done;
639
360
    }
640
641
2.08k
    ret = 1;
642
643
3.24k
done:
644
3.24k
    ctxt->state = NULL;
645
3.24k
    xmlFreeAutomata(ctxt->am);
646
3.24k
    ctxt->am = NULL;
647
3.24k
    return(ret);
648
2.08k
}
649
650
#endif /* LIBXML_REGEXP_ENABLED */
651
652
/****************************************************************
653
 *                *
654
 *  Util functions for data allocation/deallocation   *
655
 *                *
656
 ****************************************************************/
657
658
/**
659
 * Allocate a validation context structure.
660
 *
661
 * @returns the new validation context or NULL if a memory
662
 * allocation failed.
663
 */
664
0
xmlValidCtxt *xmlNewValidCtxt(void) {
665
0
    xmlValidCtxtPtr ret;
666
667
0
    ret = xmlMalloc(sizeof (xmlValidCtxt));
668
0
    if (ret == NULL)
669
0
  return (NULL);
670
671
0
    (void) memset(ret, 0, sizeof (xmlValidCtxt));
672
0
    ret->flags |= XML_VCTXT_VALIDATE;
673
674
0
    return (ret);
675
0
}
676
677
/**
678
 * Free a validation context structure.
679
 *
680
 * @param cur  the validation context to free
681
 */
682
void
683
0
xmlFreeValidCtxt(xmlValidCtxt *cur) {
684
0
    if (cur == NULL)
685
0
        return;
686
0
    if (cur->vstateTab != NULL)
687
0
        xmlFree(cur->vstateTab);
688
0
    if (cur->nodeTab != NULL)
689
0
        xmlFree(cur->nodeTab);
690
0
    xmlFree(cur);
691
0
}
692
693
#endif /* LIBXML_VALID_ENABLED */
694
695
/**
696
 * Allocate an element content structure for the document.
697
 *
698
 * @deprecated Internal function, don't use.
699
 *
700
 * @param doc  the document
701
 * @param name  the subelement name or NULL
702
 * @param type  the type of element content decl
703
 * @returns the new element content structure or NULL on
704
 * error.
705
 */
706
xmlElementContent *
707
xmlNewDocElementContent(xmlDoc *doc, const xmlChar *name,
708
3.67M
                        xmlElementContentType type) {
709
3.67M
    xmlElementContentPtr ret;
710
3.67M
    xmlDictPtr dict = NULL;
711
712
3.67M
    if (doc != NULL)
713
3.67M
        dict = doc->dict;
714
715
3.67M
    ret = (xmlElementContentPtr) xmlMalloc(sizeof(xmlElementContent));
716
3.67M
    if (ret == NULL)
717
164
  return(NULL);
718
3.67M
    memset(ret, 0, sizeof(xmlElementContent));
719
3.67M
    ret->type = type;
720
3.67M
    ret->ocur = XML_ELEMENT_CONTENT_ONCE;
721
3.67M
    if (name != NULL) {
722
1.84M
        int l;
723
1.84M
  const xmlChar *tmp;
724
725
1.84M
  tmp = xmlSplitQName3(name, &l);
726
1.84M
  if (tmp == NULL) {
727
1.00M
      if (dict == NULL)
728
411k
    ret->name = xmlStrdup(name);
729
591k
      else
730
591k
          ret->name = xmlDictLookup(dict, name, -1);
731
1.00M
  } else {
732
837k
      if (dict == NULL) {
733
458k
    ret->prefix = xmlStrndup(name, l);
734
458k
    ret->name = xmlStrdup(tmp);
735
458k
      } else {
736
379k
          ret->prefix = xmlDictLookup(dict, name, l);
737
379k
    ret->name = xmlDictLookup(dict, tmp, -1);
738
379k
      }
739
837k
            if (ret->prefix == NULL)
740
8
                goto error;
741
837k
  }
742
1.84M
        if (ret->name == NULL)
743
32
            goto error;
744
1.84M
    }
745
3.67M
    return(ret);
746
747
40
error:
748
40
    xmlFreeDocElementContent(doc, ret);
749
40
    return(NULL);
750
3.67M
}
751
752
/**
753
 * Allocate an element content structure.
754
 * Deprecated in favor of #xmlNewDocElementContent
755
 *
756
 * @deprecated Internal function, don't use.
757
 *
758
 * @param name  the subelement name or NULL
759
 * @param type  the type of element content decl
760
 * @returns the new element content structure or NULL on
761
 * error.
762
 */
763
xmlElementContent *
764
0
xmlNewElementContent(const xmlChar *name, xmlElementContentType type) {
765
0
    return(xmlNewDocElementContent(NULL, name, type));
766
0
}
767
768
/**
769
 * Build a copy of an element content description.
770
 *
771
 * @deprecated Internal function, don't use.
772
 *
773
 * @param doc  the document owning the element declaration
774
 * @param cur  An element content pointer.
775
 * @returns the new xmlElementContent or NULL in case of error.
776
 */
777
xmlElementContent *
778
0
xmlCopyDocElementContent(xmlDoc *doc, xmlElementContent *cur) {
779
0
    xmlElementContentPtr ret = NULL, prev = NULL, tmp;
780
0
    xmlDictPtr dict = NULL;
781
782
0
    if (cur == NULL) return(NULL);
783
784
0
    if (doc != NULL)
785
0
        dict = doc->dict;
786
787
0
    ret = (xmlElementContentPtr) xmlMalloc(sizeof(xmlElementContent));
788
0
    if (ret == NULL)
789
0
  return(NULL);
790
0
    memset(ret, 0, sizeof(xmlElementContent));
791
0
    ret->type = cur->type;
792
0
    ret->ocur = cur->ocur;
793
0
    if (cur->name != NULL) {
794
0
  if (dict)
795
0
      ret->name = xmlDictLookup(dict, cur->name, -1);
796
0
  else
797
0
      ret->name = xmlStrdup(cur->name);
798
0
        if (ret->name == NULL)
799
0
            goto error;
800
0
    }
801
802
0
    if (cur->prefix != NULL) {
803
0
  if (dict)
804
0
      ret->prefix = xmlDictLookup(dict, cur->prefix, -1);
805
0
  else
806
0
      ret->prefix = xmlStrdup(cur->prefix);
807
0
        if (ret->prefix == NULL)
808
0
            goto error;
809
0
    }
810
0
    if (cur->c1 != NULL) {
811
0
        ret->c1 = xmlCopyDocElementContent(doc, cur->c1);
812
0
        if (ret->c1 == NULL)
813
0
            goto error;
814
0
  ret->c1->parent = ret;
815
0
    }
816
0
    if (cur->c2 != NULL) {
817
0
        prev = ret;
818
0
  cur = cur->c2;
819
0
  while (cur != NULL) {
820
0
      tmp = (xmlElementContentPtr) xmlMalloc(sizeof(xmlElementContent));
821
0
      if (tmp == NULL)
822
0
                goto error;
823
0
      memset(tmp, 0, sizeof(xmlElementContent));
824
0
      tmp->type = cur->type;
825
0
      tmp->ocur = cur->ocur;
826
0
      prev->c2 = tmp;
827
0
      tmp->parent = prev;
828
0
      if (cur->name != NULL) {
829
0
    if (dict)
830
0
        tmp->name = xmlDictLookup(dict, cur->name, -1);
831
0
    else
832
0
        tmp->name = xmlStrdup(cur->name);
833
0
                if (tmp->name == NULL)
834
0
                    goto error;
835
0
      }
836
837
0
      if (cur->prefix != NULL) {
838
0
    if (dict)
839
0
        tmp->prefix = xmlDictLookup(dict, cur->prefix, -1);
840
0
    else
841
0
        tmp->prefix = xmlStrdup(cur->prefix);
842
0
                if (tmp->prefix == NULL)
843
0
                    goto error;
844
0
      }
845
0
      if (cur->c1 != NULL) {
846
0
          tmp->c1 = xmlCopyDocElementContent(doc,cur->c1);
847
0
          if (tmp->c1 == NULL)
848
0
                    goto error;
849
0
    tmp->c1->parent = tmp;
850
0
            }
851
0
      prev = tmp;
852
0
      cur = cur->c2;
853
0
  }
854
0
    }
855
0
    return(ret);
856
857
0
error:
858
0
    xmlFreeElementContent(ret);
859
0
    return(NULL);
860
0
}
861
862
/**
863
 * Build a copy of an element content description.
864
 * Deprecated, use #xmlCopyDocElementContent instead
865
 *
866
 * @deprecated Internal function, don't use.
867
 *
868
 * @param cur  An element content pointer.
869
 * @returns the new xmlElementContent or NULL in case of error.
870
 */
871
xmlElementContent *
872
0
xmlCopyElementContent(xmlElementContent *cur) {
873
0
    return(xmlCopyDocElementContent(NULL, cur));
874
0
}
875
876
/**
877
 * Free an element content structure. The whole subtree is removed.
878
 *
879
 * @deprecated Internal function, don't use.
880
 *
881
 * @param doc  the document owning the element declaration
882
 * @param cur  the element content tree to free
883
 */
884
void
885
49.2k
xmlFreeDocElementContent(xmlDoc *doc, xmlElementContent *cur) {
886
49.2k
    xmlDictPtr dict = NULL;
887
49.2k
    size_t depth = 0;
888
889
49.2k
    if (cur == NULL)
890
18.7k
        return;
891
30.5k
    if (doc != NULL)
892
30.0k
        dict = doc->dict;
893
894
3.67M
    while (1) {
895
3.67M
        xmlElementContentPtr parent;
896
897
5.50M
        while ((cur->c1 != NULL) || (cur->c2 != NULL)) {
898
1.82M
            cur = (cur->c1 != NULL) ? cur->c1 : cur->c2;
899
1.82M
            depth += 1;
900
1.82M
        }
901
902
3.67M
  if (dict) {
903
1.93M
      if ((cur->name != NULL) && (!xmlDictOwns(dict, cur->name)))
904
0
          xmlFree((xmlChar *) cur->name);
905
1.93M
      if ((cur->prefix != NULL) && (!xmlDictOwns(dict, cur->prefix)))
906
0
          xmlFree((xmlChar *) cur->prefix);
907
1.93M
  } else {
908
1.73M
      if (cur->name != NULL) xmlFree((xmlChar *) cur->name);
909
1.73M
      if (cur->prefix != NULL) xmlFree((xmlChar *) cur->prefix);
910
1.73M
  }
911
3.67M
        parent = cur->parent;
912
3.67M
        if ((depth == 0) || (parent == NULL)) {
913
30.5k
            xmlFree(cur);
914
30.5k
            break;
915
30.5k
        }
916
3.64M
        if (cur == parent->c1)
917
1.82M
            parent->c1 = NULL;
918
1.82M
        else
919
1.82M
            parent->c2 = NULL;
920
3.64M
  xmlFree(cur);
921
922
3.64M
        if (parent->c2 != NULL) {
923
1.82M
      cur = parent->c2;
924
1.82M
        } else {
925
1.82M
            depth -= 1;
926
1.82M
            cur = parent;
927
1.82M
        }
928
3.64M
    }
929
30.5k
}
930
931
/**
932
 * Free an element content structure. The whole subtree is removed.
933
 * Deprecated, use #xmlFreeDocElementContent instead
934
 *
935
 * @deprecated Internal function, don't use.
936
 *
937
 * @param cur  the element content tree to free
938
 */
939
void
940
0
xmlFreeElementContent(xmlElementContent *cur) {
941
0
    xmlFreeDocElementContent(NULL, cur);
942
0
}
943
944
#ifdef LIBXML_OUTPUT_ENABLED
945
/**
946
 * Deprecated, unsafe, use #xmlSnprintfElementContent
947
 *
948
 * @deprecated Internal function, don't use.
949
 *
950
 * @param buf  an output buffer
951
 * @param content  An element table
952
 * @param englob  1 if one must print the englobing parenthesis, 0 otherwise
953
 */
954
void
955
xmlSprintfElementContent(char *buf ATTRIBUTE_UNUSED,
956
                   xmlElementContent *content ATTRIBUTE_UNUSED,
957
0
       int englob ATTRIBUTE_UNUSED) {
958
0
}
959
#endif /* LIBXML_OUTPUT_ENABLED */
960
961
/**
962
 * This will dump the content of the element content definition
963
 * Intended just for the debug routine
964
 *
965
 * @deprecated Internal function, don't use.
966
 *
967
 * @param buf  an output buffer
968
 * @param size  the buffer size
969
 * @param content  An element table
970
 * @param englob  1 if one must print the englobing parenthesis, 0 otherwise
971
 */
972
void
973
1.23M
xmlSnprintfElementContent(char *buf, int size, xmlElementContent *content, int englob) {
974
1.23M
    int len;
975
976
1.23M
    if (content == NULL) return;
977
1.23M
    len = strlen(buf);
978
1.23M
    if (size - len < 50) {
979
265
  if ((size - len > 4) && (buf[len - 1] != '.'))
980
265
      strcat(buf, " ...");
981
265
  return;
982
265
    }
983
1.23M
    if (englob) strcat(buf, "(");
984
1.23M
    switch (content->type) {
985
0
        case XML_ELEMENT_CONTENT_PCDATA:
986
0
            strcat(buf, "#PCDATA");
987
0
      break;
988
623k
  case XML_ELEMENT_CONTENT_ELEMENT: {
989
623k
            int qnameLen = xmlStrlen(content->name);
990
991
623k
      if (content->prefix != NULL)
992
186k
                qnameLen += xmlStrlen(content->prefix) + 1;
993
623k
      if (size - len < qnameLen + 10) {
994
443
    strcat(buf, " ...");
995
443
    return;
996
443
      }
997
623k
      if (content->prefix != NULL) {
998
185k
    strcat(buf, (char *) content->prefix);
999
185k
    strcat(buf, ":");
1000
185k
      }
1001
623k
      if (content->name != NULL)
1002
623k
    strcat(buf, (char *) content->name);
1003
623k
      break;
1004
623k
        }
1005
387k
  case XML_ELEMENT_CONTENT_SEQ:
1006
387k
      if ((content->c1->type == XML_ELEMENT_CONTENT_OR) ||
1007
386k
          (content->c1->type == XML_ELEMENT_CONTENT_SEQ))
1008
2.51k
    xmlSnprintfElementContent(buf, size, content->c1, 1);
1009
384k
      else
1010
384k
    xmlSnprintfElementContent(buf, size, content->c1, 0);
1011
387k
      len = strlen(buf);
1012
387k
      if (size - len < 50) {
1013
529
    if ((size - len > 4) && (buf[len - 1] != '.'))
1014
287
        strcat(buf, " ...");
1015
529
    return;
1016
529
      }
1017
386k
            strcat(buf, " , ");
1018
386k
      if (((content->c2->type == XML_ELEMENT_CONTENT_OR) ||
1019
385k
     (content->c2->ocur != XML_ELEMENT_CONTENT_ONCE)) &&
1020
2.58k
    (content->c2->type != XML_ELEMENT_CONTENT_ELEMENT))
1021
1.07k
    xmlSnprintfElementContent(buf, size, content->c2, 1);
1022
385k
      else
1023
385k
    xmlSnprintfElementContent(buf, size, content->c2, 0);
1024
386k
      break;
1025
220k
  case XML_ELEMENT_CONTENT_OR:
1026
220k
      if ((content->c1->type == XML_ELEMENT_CONTENT_OR) ||
1027
218k
          (content->c1->type == XML_ELEMENT_CONTENT_SEQ))
1028
2.11k
    xmlSnprintfElementContent(buf, size, content->c1, 1);
1029
218k
      else
1030
218k
    xmlSnprintfElementContent(buf, size, content->c1, 0);
1031
220k
      len = strlen(buf);
1032
220k
      if (size - len < 50) {
1033
663
    if ((size - len > 4) && (buf[len - 1] != '.'))
1034
332
        strcat(buf, " ...");
1035
663
    return;
1036
663
      }
1037
219k
            strcat(buf, " | ");
1038
219k
      if (((content->c2->type == XML_ELEMENT_CONTENT_SEQ) ||
1039
219k
     (content->c2->ocur != XML_ELEMENT_CONTENT_ONCE)) &&
1040
1.74k
    (content->c2->type != XML_ELEMENT_CONTENT_ELEMENT))
1041
344
    xmlSnprintfElementContent(buf, size, content->c2, 1);
1042
219k
      else
1043
219k
    xmlSnprintfElementContent(buf, size, content->c2, 0);
1044
219k
      break;
1045
1.23M
    }
1046
1.23M
    if (size - strlen(buf) <= 2) return;
1047
1.22M
    if (englob)
1048
23.1k
        strcat(buf, ")");
1049
1.22M
    switch (content->ocur) {
1050
1.14M
        case XML_ELEMENT_CONTENT_ONCE:
1051
1.14M
      break;
1052
56.0k
        case XML_ELEMENT_CONTENT_OPT:
1053
56.0k
      strcat(buf, "?");
1054
56.0k
      break;
1055
9.90k
        case XML_ELEMENT_CONTENT_MULT:
1056
9.90k
      strcat(buf, "*");
1057
9.90k
      break;
1058
12.9k
        case XML_ELEMENT_CONTENT_PLUS:
1059
12.9k
      strcat(buf, "+");
1060
12.9k
      break;
1061
1.22M
    }
1062
1.22M
}
1063
1064
/****************************************************************
1065
 *                *
1066
 *  Registration of DTD declarations      *
1067
 *                *
1068
 ****************************************************************/
1069
1070
/**
1071
 * Deallocate the memory used by an element definition
1072
 *
1073
 * @param elem  an element
1074
 */
1075
static void
1076
35.1k
xmlFreeElement(xmlElementPtr elem) {
1077
35.1k
    if (elem == NULL) return;
1078
35.0k
    xmlUnlinkNode((xmlNodePtr) elem);
1079
35.0k
    xmlFreeDocElementContent(elem->doc, elem->content);
1080
35.0k
    if (elem->name != NULL)
1081
35.0k
  xmlFree((xmlChar *) elem->name);
1082
35.0k
    if (elem->prefix != NULL)
1083
1.58k
  xmlFree((xmlChar *) elem->prefix);
1084
35.0k
#ifdef LIBXML_REGEXP_ENABLED
1085
35.0k
    if (elem->contModel != NULL)
1086
2.44k
  xmlRegFreeRegexp(elem->contModel);
1087
35.0k
#endif
1088
35.0k
    xmlFree(elem);
1089
35.0k
}
1090
1091
1092
/**
1093
 * Register a new element declaration.
1094
 *
1095
 * @param ctxt  the validation context (optional)
1096
 * @param dtd  pointer to the DTD
1097
 * @param name  the entity name
1098
 * @param type  the element type
1099
 * @param content  the element content tree or NULL
1100
 * @returns the entity or NULL on error.
1101
 */
1102
xmlElement *
1103
xmlAddElementDecl(xmlValidCtxt *ctxt,
1104
                  xmlDtd *dtd, const xmlChar *name,
1105
                  xmlElementTypeVal type,
1106
25.5k
      xmlElementContent *content) {
1107
25.5k
    xmlElementPtr ret;
1108
25.5k
    xmlElementTablePtr table;
1109
25.5k
    xmlAttributePtr oldAttributes = NULL;
1110
25.5k
    const xmlChar *localName;
1111
25.5k
    xmlChar *prefix = NULL;
1112
1113
25.5k
    if ((dtd == NULL) || (name == NULL))
1114
0
  return(NULL);
1115
1116
25.5k
    switch (type) {
1117
4.23k
        case XML_ELEMENT_TYPE_EMPTY:
1118
5.38k
        case XML_ELEMENT_TYPE_ANY:
1119
5.38k
            if (content != NULL)
1120
0
                return(NULL);
1121
5.38k
            break;
1122
7.72k
        case XML_ELEMENT_TYPE_MIXED:
1123
20.1k
        case XML_ELEMENT_TYPE_ELEMENT:
1124
20.1k
            if (content == NULL)
1125
0
                return(NULL);
1126
20.1k
            break;
1127
20.1k
        default:
1128
0
            return(NULL);
1129
25.5k
    }
1130
1131
    /*
1132
     * check if name is a QName
1133
     */
1134
25.5k
    localName = xmlSplitQName4(name, &prefix);
1135
25.5k
    if (localName == NULL)
1136
12
        goto mem_error;
1137
1138
    /*
1139
     * Create the Element table if needed.
1140
     */
1141
25.5k
    table = (xmlElementTablePtr) dtd->elements;
1142
25.5k
    if (table == NULL) {
1143
8.24k
  xmlDictPtr dict = NULL;
1144
1145
8.24k
  if (dtd->doc != NULL)
1146
8.24k
      dict = dtd->doc->dict;
1147
8.24k
        table = xmlHashCreateDict(0, dict);
1148
8.24k
        if (table == NULL)
1149
19
            goto mem_error;
1150
8.22k
  dtd->elements = (void *) table;
1151
8.22k
    }
1152
1153
    /*
1154
     * lookup old attributes inserted on an undefined element in the
1155
     * internal subset.
1156
     */
1157
25.5k
    if ((dtd->doc != NULL) && (dtd->doc->intSubset != NULL)) {
1158
25.5k
  ret = xmlHashLookup2(dtd->doc->intSubset->elements, localName, prefix);
1159
25.5k
  if ((ret != NULL) && (ret->etype == XML_ELEMENT_TYPE_UNDEFINED)) {
1160
437
      oldAttributes = ret->attributes;
1161
437
      ret->attributes = NULL;
1162
437
      xmlHashRemoveEntry2(dtd->doc->intSubset->elements, localName, prefix,
1163
437
                                NULL);
1164
437
      xmlFreeElement(ret);
1165
437
  }
1166
25.5k
    }
1167
1168
    /*
1169
     * The element may already be present if one of its attribute
1170
     * was registered first
1171
     */
1172
25.5k
    ret = xmlHashLookup2(table, localName, prefix);
1173
25.5k
    if (ret != NULL) {
1174
5.02k
  if (ret->etype != XML_ELEMENT_TYPE_UNDEFINED) {
1175
4.98k
#ifdef LIBXML_VALID_ENABLED
1176
      /*
1177
       * The element is already defined in this DTD.
1178
       */
1179
4.98k
            if ((ctxt != NULL) && (ctxt->flags & XML_VCTXT_VALIDATE))
1180
2.38k
                xmlErrValidNode(ctxt, (xmlNodePtr) dtd, XML_DTD_ELEM_REDEFINED,
1181
2.38k
                                "Redefinition of element %s\n",
1182
2.38k
                                name, NULL, NULL);
1183
4.98k
#endif /* LIBXML_VALID_ENABLED */
1184
4.98k
            if (prefix != NULL)
1185
261
          xmlFree(prefix);
1186
4.98k
      return(NULL);
1187
4.98k
  }
1188
34
  if (prefix != NULL) {
1189
12
      xmlFree(prefix);
1190
12
      prefix = NULL;
1191
12
  }
1192
20.4k
    } else {
1193
20.4k
        int res;
1194
1195
20.4k
  ret = (xmlElementPtr) xmlMalloc(sizeof(xmlElement));
1196
20.4k
  if (ret == NULL)
1197
13
            goto mem_error;
1198
20.4k
  memset(ret, 0, sizeof(xmlElement));
1199
20.4k
  ret->type = XML_ELEMENT_DECL;
1200
1201
  /*
1202
   * fill the structure.
1203
   */
1204
20.4k
  ret->name = xmlStrdup(localName);
1205
20.4k
  if (ret->name == NULL) {
1206
15
      xmlFree(ret);
1207
15
      goto mem_error;
1208
15
  }
1209
20.4k
  ret->prefix = prefix;
1210
20.4k
        prefix = NULL;
1211
1212
  /*
1213
   * Validity Check:
1214
   * Insertion must not fail
1215
   */
1216
20.4k
        res = xmlHashAdd2(table, localName, ret->prefix, ret);
1217
20.4k
        if (res <= 0) {
1218
58
      xmlFreeElement(ret);
1219
58
            goto mem_error;
1220
58
  }
1221
  /*
1222
   * For new element, may have attributes from earlier
1223
   * definition in internal subset
1224
   */
1225
20.4k
  ret->attributes = oldAttributes;
1226
20.4k
    }
1227
1228
    /*
1229
     * Finish to fill the structure.
1230
     */
1231
20.4k
    ret->etype = type;
1232
    /*
1233
     * Avoid a stupid copy when called by the parser
1234
     * and flag it by setting a special parent value
1235
     * so the parser doesn't unallocate it.
1236
     */
1237
20.4k
    if (content != NULL) {
1238
16.6k
        if ((ctxt != NULL) && (ctxt->flags & XML_VCTXT_USE_PCTXT)) {
1239
16.6k
            ret->content = content;
1240
16.6k
            content->parent = (xmlElementContentPtr) 1;
1241
16.6k
        } else if (content != NULL){
1242
0
            ret->content = xmlCopyDocElementContent(dtd->doc, content);
1243
0
            if (ret->content == NULL)
1244
0
                goto mem_error;
1245
0
        }
1246
16.6k
    }
1247
1248
    /*
1249
     * Link it to the DTD
1250
     */
1251
20.4k
    ret->parent = dtd;
1252
20.4k
    ret->doc = dtd->doc;
1253
20.4k
    if (dtd->last == NULL) {
1254
6.83k
  dtd->children = dtd->last = (xmlNodePtr) ret;
1255
13.6k
    } else {
1256
13.6k
        dtd->last->next = (xmlNodePtr) ret;
1257
13.6k
  ret->prev = dtd->last;
1258
13.6k
  dtd->last = (xmlNodePtr) ret;
1259
13.6k
    }
1260
20.4k
    if (prefix != NULL)
1261
0
  xmlFree(prefix);
1262
20.4k
    return(ret);
1263
1264
117
mem_error:
1265
117
    xmlVErrMemory(ctxt);
1266
117
    if (prefix != NULL)
1267
7
        xmlFree(prefix);
1268
117
    return(NULL);
1269
20.4k
}
1270
1271
static void
1272
34.5k
xmlFreeElementTableEntry(void *elem, const xmlChar *name ATTRIBUTE_UNUSED) {
1273
34.5k
    xmlFreeElement((xmlElementPtr) elem);
1274
34.5k
}
1275
1276
/**
1277
 * Deallocate the memory used by an element hash table.
1278
 *
1279
 * @deprecated Internal function, don't use.
1280
 *
1281
 * @param table  An element table
1282
 */
1283
void
1284
21.1k
xmlFreeElementTable(xmlElementTable *table) {
1285
21.1k
    xmlHashFree(table, xmlFreeElementTableEntry);
1286
21.1k
}
1287
1288
/**
1289
 * Build a copy of an element.
1290
 *
1291
 * @param payload  an element
1292
 * @param name  unused
1293
 * @returns the new xmlElement or NULL in case of error.
1294
 */
1295
static void *
1296
0
xmlCopyElement(void *payload, const xmlChar *name ATTRIBUTE_UNUSED) {
1297
0
    xmlElementPtr elem = (xmlElementPtr) payload;
1298
0
    xmlElementPtr cur;
1299
1300
0
    cur = (xmlElementPtr) xmlMalloc(sizeof(xmlElement));
1301
0
    if (cur == NULL)
1302
0
  return(NULL);
1303
0
    memset(cur, 0, sizeof(xmlElement));
1304
0
    cur->type = XML_ELEMENT_DECL;
1305
0
    cur->etype = elem->etype;
1306
0
    if (elem->name != NULL) {
1307
0
  cur->name = xmlStrdup(elem->name);
1308
0
        if (cur->name == NULL)
1309
0
            goto error;
1310
0
    }
1311
0
    if (elem->prefix != NULL) {
1312
0
  cur->prefix = xmlStrdup(elem->prefix);
1313
0
        if (cur->prefix == NULL)
1314
0
            goto error;
1315
0
    }
1316
0
    if (elem->content != NULL) {
1317
0
        cur->content = xmlCopyElementContent(elem->content);
1318
0
        if (cur->content == NULL)
1319
0
            goto error;
1320
0
    }
1321
    /* TODO : rebuild the attribute list on the copy */
1322
0
    cur->attributes = NULL;
1323
0
    return(cur);
1324
1325
0
error:
1326
0
    xmlFreeElement(cur);
1327
0
    return(NULL);
1328
0
}
1329
1330
/**
1331
 * Build a copy of an element table.
1332
 *
1333
 * @deprecated Internal function, don't use.
1334
 *
1335
 * @param table  An element table
1336
 * @returns the new xmlElementTable or NULL in case of error.
1337
 */
1338
xmlElementTable *
1339
0
xmlCopyElementTable(xmlElementTable *table) {
1340
0
    return(xmlHashCopySafe(table, xmlCopyElement, xmlFreeElementTableEntry));
1341
0
}
1342
1343
#ifdef LIBXML_OUTPUT_ENABLED
1344
/**
1345
 * This will dump the content of the element declaration as an XML
1346
 * DTD definition.
1347
 *
1348
 * @deprecated Use #xmlSaveTree.
1349
 *
1350
 * @param buf  the XML buffer output
1351
 * @param elem  An element table
1352
 */
1353
void
1354
0
xmlDumpElementDecl(xmlBuffer *buf, xmlElement *elem) {
1355
0
    xmlSaveCtxtPtr save;
1356
1357
0
    if ((buf == NULL) || (elem == NULL))
1358
0
        return;
1359
1360
0
    save = xmlSaveToBuffer(buf, NULL, 0);
1361
0
    xmlSaveTree(save, (xmlNodePtr) elem);
1362
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
1363
0
        xmlFree(xmlBufferDetach(buf));
1364
0
}
1365
1366
/**
1367
 * This routine is used by the hash scan function.  It just reverses
1368
 * the arguments.
1369
 *
1370
 * @param elem  an element declaration
1371
 * @param save  a save context
1372
 * @param name  unused
1373
 */
1374
static void
1375
xmlDumpElementDeclScan(void *elem, void *save,
1376
0
                       const xmlChar *name ATTRIBUTE_UNUSED) {
1377
0
    xmlSaveTree(save, elem);
1378
0
}
1379
1380
/**
1381
 * This will dump the content of the element table as an XML DTD
1382
 * definition.
1383
 *
1384
 * @deprecated Don't use.
1385
 *
1386
 * @param buf  the XML buffer output
1387
 * @param table  An element table
1388
 */
1389
void
1390
0
xmlDumpElementTable(xmlBuffer *buf, xmlElementTable *table) {
1391
0
    xmlSaveCtxtPtr save;
1392
1393
0
    if ((buf == NULL) || (table == NULL))
1394
0
        return;
1395
1396
0
    save = xmlSaveToBuffer(buf, NULL, 0);
1397
0
    xmlHashScan(table, xmlDumpElementDeclScan, save);
1398
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
1399
0
        xmlFree(xmlBufferDetach(buf));
1400
0
}
1401
#endif /* LIBXML_OUTPUT_ENABLED */
1402
1403
/**
1404
 * Create and initialize an enumeration attribute node.
1405
 *
1406
 * @deprecated Internal function, don't use.
1407
 *
1408
 * @param name  the enumeration name or NULL
1409
 * @returns the xmlEnumeration just created or NULL in case
1410
 * of error.
1411
 */
1412
xmlEnumeration *
1413
42.9k
xmlCreateEnumeration(const xmlChar *name) {
1414
42.9k
    xmlEnumerationPtr ret;
1415
1416
42.9k
    ret = (xmlEnumerationPtr) xmlMalloc(sizeof(xmlEnumeration));
1417
42.9k
    if (ret == NULL)
1418
12
        return(NULL);
1419
42.9k
    memset(ret, 0, sizeof(xmlEnumeration));
1420
1421
42.9k
    if (name != NULL) {
1422
42.9k
        ret->name = xmlStrdup(name);
1423
42.9k
        if (ret->name == NULL) {
1424
34
            xmlFree(ret);
1425
34
            return(NULL);
1426
34
        }
1427
42.9k
    }
1428
1429
42.9k
    return(ret);
1430
42.9k
}
1431
1432
/**
1433
 * Free an enumeration attribute node (recursive).
1434
 *
1435
 * @param cur  the tree to free.
1436
 */
1437
void
1438
34.4k
xmlFreeEnumeration(xmlEnumeration *cur) {
1439
77.3k
    while (cur != NULL) {
1440
42.9k
        xmlEnumerationPtr next = cur->next;
1441
1442
42.9k
        xmlFree((xmlChar *) cur->name);
1443
42.9k
        xmlFree(cur);
1444
1445
42.9k
        cur = next;
1446
42.9k
    }
1447
34.4k
}
1448
1449
/**
1450
 * Copy an enumeration attribute node (recursive).
1451
 *
1452
 * @deprecated Internal function, don't use.
1453
 *
1454
 * @param cur  the tree to copy.
1455
 * @returns the xmlEnumeration just created or NULL in case
1456
 * of error.
1457
 */
1458
xmlEnumeration *
1459
0
xmlCopyEnumeration(xmlEnumeration *cur) {
1460
0
    xmlEnumerationPtr ret = NULL;
1461
0
    xmlEnumerationPtr last = NULL;
1462
1463
0
    while (cur != NULL) {
1464
0
        xmlEnumerationPtr copy = xmlCreateEnumeration(cur->name);
1465
1466
0
        if (copy == NULL) {
1467
0
            xmlFreeEnumeration(ret);
1468
0
            return(NULL);
1469
0
        }
1470
1471
0
        if (ret == NULL) {
1472
0
            ret = last = copy;
1473
0
        } else {
1474
0
            last->next = copy;
1475
0
            last = copy;
1476
0
        }
1477
1478
0
        cur = cur->next;
1479
0
    }
1480
1481
0
    return(ret);
1482
0
}
1483
1484
#ifdef LIBXML_VALID_ENABLED
1485
/**
1486
 * Verify that the element doesn't have too many ID attributes
1487
 * declared.
1488
 *
1489
 * @param ctxt  the validation context
1490
 * @param elem  the element name
1491
 * @param err  whether to raise errors here
1492
 * @returns the number of ID attributes found.
1493
 */
1494
static int
1495
7.15k
xmlScanIDAttributeDecl(xmlValidCtxtPtr ctxt, xmlElementPtr elem, int err) {
1496
7.15k
    xmlAttributePtr cur;
1497
7.15k
    int ret = 0;
1498
1499
7.15k
    if (elem == NULL) return(0);
1500
7.15k
    cur = elem->attributes;
1501
18.8k
    while (cur != NULL) {
1502
11.6k
        if (cur->atype == XML_ATTRIBUTE_ID) {
1503
9.61k
      ret ++;
1504
9.61k
      if ((ret > 1) && (err))
1505
0
    xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_MULTIPLE_ID,
1506
0
         "Element %s has too many ID attributes defined : %s\n",
1507
0
           elem->name, cur->name, NULL);
1508
9.61k
  }
1509
11.6k
  cur = cur->nexth;
1510
11.6k
    }
1511
7.15k
    return(ret);
1512
7.15k
}
1513
#endif /* LIBXML_VALID_ENABLED */
1514
1515
/**
1516
 * Deallocate the memory used by an attribute definition.
1517
 *
1518
 * @param attr  an attribute
1519
 */
1520
static void
1521
100k
xmlFreeAttribute(xmlAttributePtr attr) {
1522
100k
    xmlDictPtr dict;
1523
1524
100k
    if (attr == NULL) return;
1525
100k
    if (attr->doc != NULL)
1526
100k
  dict = attr->doc->dict;
1527
466
    else
1528
466
  dict = NULL;
1529
100k
    xmlUnlinkNode((xmlNodePtr) attr);
1530
100k
    if (attr->tree != NULL)
1531
24.7k
        xmlFreeEnumeration(attr->tree);
1532
100k
    if (dict) {
1533
68.2k
        if ((attr->elem != NULL) && (!xmlDictOwns(dict, attr->elem)))
1534
0
      xmlFree((xmlChar *) attr->elem);
1535
68.2k
        if ((attr->name != NULL) && (!xmlDictOwns(dict, attr->name)))
1536
0
      xmlFree((xmlChar *) attr->name);
1537
68.2k
        if ((attr->prefix != NULL) && (!xmlDictOwns(dict, attr->prefix)))
1538
0
      xmlFree((xmlChar *) attr->prefix);
1539
68.2k
    } else {
1540
32.2k
  if (attr->elem != NULL)
1541
32.2k
      xmlFree((xmlChar *) attr->elem);
1542
32.2k
  if (attr->name != NULL)
1543
32.1k
      xmlFree((xmlChar *) attr->name);
1544
32.2k
  if (attr->prefix != NULL)
1545
2.79k
      xmlFree((xmlChar *) attr->prefix);
1546
32.2k
    }
1547
100k
    if (attr->defaultValue != NULL)
1548
56.3k
        xmlFree(attr->defaultValue);
1549
100k
    xmlFree(attr);
1550
100k
}
1551
1552
1553
/**
1554
 * Register a new attribute declaration.
1555
 *
1556
 * @param ctxt  the validation context (optional)
1557
 * @param dtd  pointer to the DTD
1558
 * @param elem  the element name
1559
 * @param name  the attribute name
1560
 * @param ns  the attribute namespace prefix
1561
 * @param type  the attribute type
1562
 * @param def  the attribute default type
1563
 * @param defaultValue  the attribute default value
1564
 * @param tree  if it's an enumeration, the associated list
1565
 * @returns the attribute decl or NULL on error.
1566
 */
1567
xmlAttribute *
1568
xmlAddAttributeDecl(xmlValidCtxt *ctxt,
1569
                    xmlDtd *dtd, const xmlChar *elem,
1570
                    const xmlChar *name, const xmlChar *ns,
1571
        xmlAttributeType type, xmlAttributeDefault def,
1572
104k
        const xmlChar *defaultValue, xmlEnumeration *tree) {
1573
104k
    xmlAttributePtr ret = NULL;
1574
104k
    xmlAttributeTablePtr table;
1575
104k
    xmlElementPtr elemDef;
1576
104k
    xmlDictPtr dict = NULL;
1577
104k
    int res;
1578
1579
104k
    if (dtd == NULL) {
1580
0
  xmlFreeEnumeration(tree);
1581
0
  return(NULL);
1582
0
    }
1583
104k
    if (name == NULL) {
1584
27
  xmlFreeEnumeration(tree);
1585
27
  return(NULL);
1586
27
    }
1587
104k
    if (elem == NULL) {
1588
0
  xmlFreeEnumeration(tree);
1589
0
  return(NULL);
1590
0
    }
1591
104k
    if (dtd->doc != NULL)
1592
104k
  dict = dtd->doc->dict;
1593
1594
104k
#ifdef LIBXML_VALID_ENABLED
1595
104k
    if ((ctxt != NULL) && (ctxt->flags & XML_VCTXT_VALIDATE) &&
1596
70.7k
        (defaultValue != NULL) &&
1597
42.9k
        (!xmlValidateAttributeValueInternal(dtd->doc, type, defaultValue))) {
1598
7.48k
  xmlErrValidNode(ctxt, (xmlNodePtr) dtd, XML_DTD_ATTRIBUTE_DEFAULT,
1599
7.48k
                  "Attribute %s of %s: invalid default value\n",
1600
7.48k
                  elem, name, defaultValue);
1601
7.48k
  defaultValue = NULL;
1602
7.48k
  if (ctxt != NULL)
1603
7.48k
      ctxt->valid = 0;
1604
7.48k
    }
1605
104k
#endif /* LIBXML_VALID_ENABLED */
1606
1607
    /*
1608
     * Check first that an attribute defined in the external subset wasn't
1609
     * already defined in the internal subset
1610
     */
1611
104k
    if ((dtd->doc != NULL) && (dtd->doc->extSubset == dtd) &&
1612
38.1k
  (dtd->doc->intSubset != NULL) &&
1613
38.1k
  (dtd->doc->intSubset->attributes != NULL)) {
1614
7.24k
        ret = xmlHashLookup3(dtd->doc->intSubset->attributes, name, ns, elem);
1615
7.24k
  if (ret != NULL) {
1616
3.57k
      xmlFreeEnumeration(tree);
1617
3.57k
      return(NULL);
1618
3.57k
  }
1619
7.24k
    }
1620
1621
    /*
1622
     * Create the Attribute table if needed.
1623
     */
1624
100k
    table = (xmlAttributeTablePtr) dtd->attributes;
1625
100k
    if (table == NULL) {
1626
15.1k
        table = xmlHashCreateDict(0, dict);
1627
15.1k
  dtd->attributes = (void *) table;
1628
15.1k
    }
1629
100k
    if (table == NULL)
1630
28
        goto mem_error;
1631
1632
100k
    ret = (xmlAttributePtr) xmlMalloc(sizeof(xmlAttribute));
1633
100k
    if (ret == NULL)
1634
40
        goto mem_error;
1635
100k
    memset(ret, 0, sizeof(xmlAttribute));
1636
100k
    ret->type = XML_ATTRIBUTE_DECL;
1637
1638
    /*
1639
     * fill the structure.
1640
     */
1641
100k
    ret->atype = type;
1642
    /*
1643
     * doc must be set before possible error causes call
1644
     * to xmlFreeAttribute (because it's used to check on
1645
     * dict use)
1646
     */
1647
100k
    ret->doc = dtd->doc;
1648
100k
    if (dict) {
1649
68.2k
  ret->name = xmlDictLookup(dict, name, -1);
1650
68.2k
  ret->elem = xmlDictLookup(dict, elem, -1);
1651
68.2k
    } else {
1652
32.2k
  ret->name = xmlStrdup(name);
1653
32.2k
  ret->elem = xmlStrdup(elem);
1654
32.2k
    }
1655
100k
    if ((ret->name == NULL) || (ret->elem == NULL))
1656
33
        goto mem_error;
1657
100k
    if (ns != NULL) {
1658
8.89k
        if (dict)
1659
6.09k
            ret->prefix = xmlDictLookup(dict, ns, -1);
1660
2.79k
        else
1661
2.79k
            ret->prefix = xmlStrdup(ns);
1662
8.89k
        if (ret->prefix == NULL)
1663
6
            goto mem_error;
1664
8.89k
    }
1665
100k
    ret->def = def;
1666
100k
    ret->tree = tree;
1667
100k
    tree = NULL;
1668
100k
    if (defaultValue != NULL) {
1669
56.3k
  ret->defaultValue = xmlStrdup(defaultValue);
1670
56.3k
        if (ret->defaultValue == NULL)
1671
20
            goto mem_error;
1672
56.3k
    }
1673
1674
100k
    elemDef = xmlGetDtdElementDesc2(ctxt, dtd, elem);
1675
100k
    if (elemDef == NULL)
1676
91
        goto mem_error;
1677
1678
    /*
1679
     * Validity Check:
1680
     * Search the DTD for previous declarations of the ATTLIST
1681
     */
1682
100k
    res = xmlHashAdd3(table, ret->name, ret->prefix, ret->elem, ret);
1683
100k
    if (res <= 0) {
1684
35.1k
        if (res < 0)
1685
65
            goto mem_error;
1686
35.0k
#ifdef LIBXML_VALID_ENABLED
1687
        /*
1688
         * The attribute is already defined in this DTD.
1689
         */
1690
35.0k
        if ((ctxt != NULL) && (ctxt->flags & XML_VCTXT_VALIDATE))
1691
23.3k
            xmlErrValidWarning(ctxt, (xmlNodePtr) dtd,
1692
23.3k
                    XML_DTD_ATTRIBUTE_REDEFINED,
1693
23.3k
                    "Attribute %s of element %s: already defined\n",
1694
23.3k
                    name, elem, NULL);
1695
35.0k
#endif /* LIBXML_VALID_ENABLED */
1696
35.0k
  xmlFreeAttribute(ret);
1697
35.0k
  return(NULL);
1698
35.1k
    }
1699
1700
    /*
1701
     * Insert namespace default def first they need to be
1702
     * processed first.
1703
     */
1704
65.2k
    if ((xmlStrEqual(ret->name, BAD_CAST "xmlns")) ||
1705
62.7k
        ((ret->prefix != NULL &&
1706
7.20k
         (xmlStrEqual(ret->prefix, BAD_CAST "xmlns"))))) {
1707
6.01k
        ret->nexth = elemDef->attributes;
1708
6.01k
        elemDef->attributes = ret;
1709
59.2k
    } else {
1710
59.2k
        xmlAttributePtr tmp = elemDef->attributes;
1711
1712
60.1k
        while ((tmp != NULL) &&
1713
40.3k
               ((xmlStrEqual(tmp->name, BAD_CAST "xmlns")) ||
1714
39.1k
                ((ret->prefix != NULL &&
1715
1.17k
                 (xmlStrEqual(ret->prefix, BAD_CAST "xmlns")))))) {
1716
1.17k
            if (tmp->nexth == NULL)
1717
210
                break;
1718
960
            tmp = tmp->nexth;
1719
960
        }
1720
59.2k
        if (tmp != NULL) {
1721
39.3k
            ret->nexth = tmp->nexth;
1722
39.3k
            tmp->nexth = ret;
1723
39.3k
        } else {
1724
19.8k
            ret->nexth = elemDef->attributes;
1725
19.8k
            elemDef->attributes = ret;
1726
19.8k
        }
1727
59.2k
    }
1728
1729
    /*
1730
     * Link it to the DTD
1731
     */
1732
65.2k
    ret->parent = dtd;
1733
65.2k
    if (dtd->last == NULL) {
1734
11.0k
  dtd->children = dtd->last = (xmlNodePtr) ret;
1735
54.1k
    } else {
1736
54.1k
        dtd->last->next = (xmlNodePtr) ret;
1737
54.1k
  ret->prev = dtd->last;
1738
54.1k
  dtd->last = (xmlNodePtr) ret;
1739
54.1k
    }
1740
65.2k
    return(ret);
1741
1742
283
mem_error:
1743
283
    xmlVErrMemory(ctxt);
1744
283
    xmlFreeEnumeration(tree);
1745
283
    xmlFreeAttribute(ret);
1746
283
    return(NULL);
1747
100k
}
1748
1749
static void
1750
65.2k
xmlFreeAttributeTableEntry(void *attr, const xmlChar *name ATTRIBUTE_UNUSED) {
1751
65.2k
    xmlFreeAttribute((xmlAttributePtr) attr);
1752
65.2k
}
1753
1754
/**
1755
 * Deallocate the memory used by an entities hash table.
1756
 *
1757
 * @deprecated Internal function, don't use.
1758
 *
1759
 * @param table  An attribute table
1760
 */
1761
void
1762
15.0k
xmlFreeAttributeTable(xmlAttributeTable *table) {
1763
15.0k
    xmlHashFree(table, xmlFreeAttributeTableEntry);
1764
15.0k
}
1765
1766
/**
1767
 * Build a copy of an attribute declaration.
1768
 *
1769
 * @param payload  an attribute declaration
1770
 * @param name  unused
1771
 * @returns the new xmlAttribute or NULL in case of error.
1772
 */
1773
static void *
1774
0
xmlCopyAttribute(void *payload, const xmlChar *name ATTRIBUTE_UNUSED) {
1775
0
    xmlAttributePtr attr = (xmlAttributePtr) payload;
1776
0
    xmlAttributePtr cur;
1777
1778
0
    cur = (xmlAttributePtr) xmlMalloc(sizeof(xmlAttribute));
1779
0
    if (cur == NULL)
1780
0
  return(NULL);
1781
0
    memset(cur, 0, sizeof(xmlAttribute));
1782
0
    cur->type = XML_ATTRIBUTE_DECL;
1783
0
    cur->atype = attr->atype;
1784
0
    cur->def = attr->def;
1785
0
    if (attr->tree != NULL) {
1786
0
        cur->tree = xmlCopyEnumeration(attr->tree);
1787
0
        if (cur->tree == NULL)
1788
0
            goto error;
1789
0
    }
1790
0
    if (attr->elem != NULL) {
1791
0
  cur->elem = xmlStrdup(attr->elem);
1792
0
        if (cur->elem == NULL)
1793
0
            goto error;
1794
0
    }
1795
0
    if (attr->name != NULL) {
1796
0
  cur->name = xmlStrdup(attr->name);
1797
0
        if (cur->name == NULL)
1798
0
            goto error;
1799
0
    }
1800
0
    if (attr->prefix != NULL) {
1801
0
  cur->prefix = xmlStrdup(attr->prefix);
1802
0
        if (cur->prefix == NULL)
1803
0
            goto error;
1804
0
    }
1805
0
    if (attr->defaultValue != NULL) {
1806
0
  cur->defaultValue = xmlStrdup(attr->defaultValue);
1807
0
        if (cur->defaultValue == NULL)
1808
0
            goto error;
1809
0
    }
1810
0
    return(cur);
1811
1812
0
error:
1813
0
    xmlFreeAttribute(cur);
1814
0
    return(NULL);
1815
0
}
1816
1817
/**
1818
 * Build a copy of an attribute table.
1819
 *
1820
 * @deprecated Internal function, don't use.
1821
 *
1822
 * @param table  An attribute table
1823
 * @returns the new xmlAttributeTable or NULL in case of error.
1824
 */
1825
xmlAttributeTable *
1826
0
xmlCopyAttributeTable(xmlAttributeTable *table) {
1827
0
    return(xmlHashCopySafe(table, xmlCopyAttribute,
1828
0
                           xmlFreeAttributeTableEntry));
1829
0
}
1830
1831
#ifdef LIBXML_OUTPUT_ENABLED
1832
/**
1833
 * This will dump the content of the attribute declaration as an XML
1834
 * DTD definition.
1835
 *
1836
 * @deprecated Use #xmlSaveTree.
1837
 *
1838
 * @param buf  the XML buffer output
1839
 * @param attr  An attribute declaration
1840
 */
1841
void
1842
0
xmlDumpAttributeDecl(xmlBuffer *buf, xmlAttribute *attr) {
1843
0
    xmlSaveCtxtPtr save;
1844
1845
0
    if ((buf == NULL) || (attr == NULL))
1846
0
        return;
1847
1848
0
    save = xmlSaveToBuffer(buf, NULL, 0);
1849
0
    xmlSaveTree(save, (xmlNodePtr) attr);
1850
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
1851
0
        xmlFree(xmlBufferDetach(buf));
1852
0
}
1853
1854
/**
1855
 * This is used with the hash scan function - just reverses
1856
 * arguments.
1857
 *
1858
 * @param attr  an attribute declaration
1859
 * @param save  a save context
1860
 * @param name  unused
1861
 */
1862
static void
1863
xmlDumpAttributeDeclScan(void *attr, void *save,
1864
0
                         const xmlChar *name ATTRIBUTE_UNUSED) {
1865
0
    xmlSaveTree(save, attr);
1866
0
}
1867
1868
/**
1869
 * This will dump the content of the attribute table as an XML
1870
 * DTD definition.
1871
 *
1872
 * @deprecated Don't use.
1873
 *
1874
 * @param buf  the XML buffer output
1875
 * @param table  an attribute table
1876
 */
1877
void
1878
0
xmlDumpAttributeTable(xmlBuffer *buf, xmlAttributeTable *table) {
1879
0
    xmlSaveCtxtPtr save;
1880
1881
0
    if ((buf == NULL) || (table == NULL))
1882
0
        return;
1883
1884
0
    save = xmlSaveToBuffer(buf, NULL, 0);
1885
0
    xmlHashScan(table, xmlDumpAttributeDeclScan, save);
1886
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
1887
0
        xmlFree(xmlBufferDetach(buf));
1888
0
}
1889
#endif /* LIBXML_OUTPUT_ENABLED */
1890
1891
/************************************************************************
1892
 *                  *
1893
 *        NOTATIONs       *
1894
 *                  *
1895
 ************************************************************************/
1896
/**
1897
 * Deallocate the memory used by an notation definition.
1898
 *
1899
 * @param nota  a notation
1900
 */
1901
static void
1902
2.53k
xmlFreeNotation(xmlNotationPtr nota) {
1903
2.53k
    if (nota == NULL) return;
1904
2.51k
    if (nota->name != NULL)
1905
2.50k
  xmlFree((xmlChar *) nota->name);
1906
2.51k
    if (nota->PublicID != NULL)
1907
1.84k
  xmlFree((xmlChar *) nota->PublicID);
1908
2.51k
    if (nota->SystemID != NULL)
1909
677
  xmlFree((xmlChar *) nota->SystemID);
1910
2.51k
    xmlFree(nota);
1911
2.51k
}
1912
1913
1914
/**
1915
 * Register a new notation declaration.
1916
 *
1917
 * @param ctxt  the validation context (optional)
1918
 * @param dtd  pointer to the DTD
1919
 * @param name  the entity name
1920
 * @param publicId  the public identifier or NULL
1921
 * @param systemId  the system identifier or NULL
1922
 * @returns the notation or NULL on error.
1923
 */
1924
xmlNotation *
1925
xmlAddNotationDecl(xmlValidCtxt *ctxt, xmlDtd *dtd, const xmlChar *name,
1926
2.53k
                   const xmlChar *publicId, const xmlChar *systemId) {
1927
2.53k
    xmlNotationPtr ret = NULL;
1928
2.53k
    xmlNotationTablePtr table;
1929
2.53k
    int res;
1930
1931
2.53k
    if (dtd == NULL) {
1932
0
  return(NULL);
1933
0
    }
1934
2.53k
    if (name == NULL) {
1935
0
  return(NULL);
1936
0
    }
1937
2.53k
    if ((publicId == NULL) && (systemId == NULL)) {
1938
0
  return(NULL);
1939
0
    }
1940
1941
    /*
1942
     * Create the Notation table if needed.
1943
     */
1944
2.53k
    table = (xmlNotationTablePtr) dtd->notations;
1945
2.53k
    if (table == NULL) {
1946
508
  xmlDictPtr dict = NULL;
1947
508
  if (dtd->doc != NULL)
1948
508
      dict = dtd->doc->dict;
1949
1950
508
        dtd->notations = table = xmlHashCreateDict(0, dict);
1951
508
        if (table == NULL)
1952
7
            goto mem_error;
1953
508
    }
1954
1955
2.52k
    ret = (xmlNotationPtr) xmlMalloc(sizeof(xmlNotation));
1956
2.52k
    if (ret == NULL)
1957
9
        goto mem_error;
1958
2.51k
    memset(ret, 0, sizeof(xmlNotation));
1959
1960
    /*
1961
     * fill the structure.
1962
     */
1963
2.51k
    ret->name = xmlStrdup(name);
1964
2.51k
    if (ret->name == NULL)
1965
9
        goto mem_error;
1966
2.50k
    if (systemId != NULL) {
1967
685
        ret->SystemID = xmlStrdup(systemId);
1968
685
        if (ret->SystemID == NULL)
1969
8
            goto mem_error;
1970
685
    }
1971
2.50k
    if (publicId != NULL) {
1972
1.85k
        ret->PublicID = xmlStrdup(publicId);
1973
1.85k
        if (ret->PublicID == NULL)
1974
11
            goto mem_error;
1975
1.85k
    }
1976
1977
    /*
1978
     * Validity Check:
1979
     * Check the DTD for previous declarations of the ATTLIST
1980
     */
1981
2.48k
    res = xmlHashAdd(table, name, ret);
1982
2.48k
    if (res <= 0) {
1983
1.98k
        if (res < 0)
1984
14
            goto mem_error;
1985
1.97k
#ifdef LIBXML_VALID_ENABLED
1986
1.97k
        if ((ctxt != NULL) && (ctxt->flags & XML_VCTXT_VALIDATE))
1987
1.18k
            xmlErrValid(ctxt, XML_DTD_NOTATION_REDEFINED,
1988
1.18k
                        "xmlAddNotationDecl: %s already defined\n",
1989
1.18k
                        (const char *) name);
1990
1.97k
#endif /* LIBXML_VALID_ENABLED */
1991
1.97k
  xmlFreeNotation(ret);
1992
1.97k
  return(NULL);
1993
1.98k
    }
1994
504
    return(ret);
1995
1996
58
mem_error:
1997
58
    xmlVErrMemory(ctxt);
1998
58
    xmlFreeNotation(ret);
1999
58
    return(NULL);
2000
2.48k
}
2001
2002
static void
2003
504
xmlFreeNotationTableEntry(void *nota, const xmlChar *name ATTRIBUTE_UNUSED) {
2004
504
    xmlFreeNotation((xmlNotationPtr) nota);
2005
504
}
2006
2007
/**
2008
 * Deallocate the memory used by an entities hash table.
2009
 *
2010
 * @deprecated Internal function, don't use.
2011
 *
2012
 * @param table  An notation table
2013
 */
2014
void
2015
501
xmlFreeNotationTable(xmlNotationTable *table) {
2016
501
    xmlHashFree(table, xmlFreeNotationTableEntry);
2017
501
}
2018
2019
/**
2020
 * Build a copy of a notation.
2021
 *
2022
 * @param payload  a notation
2023
 * @param name  unused
2024
 * @returns the new xmlNotation or NULL in case of error.
2025
 */
2026
static void *
2027
0
xmlCopyNotation(void *payload, const xmlChar *name ATTRIBUTE_UNUSED) {
2028
0
    xmlNotationPtr nota = (xmlNotationPtr) payload;
2029
0
    xmlNotationPtr cur;
2030
2031
0
    cur = (xmlNotationPtr) xmlMalloc(sizeof(xmlNotation));
2032
0
    if (cur == NULL)
2033
0
  return(NULL);
2034
0
    memset(cur, 0, sizeof(*cur));
2035
0
    if (nota->name != NULL) {
2036
0
  cur->name = xmlStrdup(nota->name);
2037
0
        if (cur->name == NULL)
2038
0
            goto error;
2039
0
    }
2040
0
    if (nota->PublicID != NULL) {
2041
0
  cur->PublicID = xmlStrdup(nota->PublicID);
2042
0
        if (cur->PublicID == NULL)
2043
0
            goto error;
2044
0
    }
2045
0
    if (nota->SystemID != NULL) {
2046
0
  cur->SystemID = xmlStrdup(nota->SystemID);
2047
0
        if (cur->SystemID == NULL)
2048
0
            goto error;
2049
0
    }
2050
0
    return(cur);
2051
2052
0
error:
2053
0
    xmlFreeNotation(cur);
2054
0
    return(NULL);
2055
0
}
2056
2057
/**
2058
 * Build a copy of a notation table.
2059
 *
2060
 * @deprecated Internal function, don't use.
2061
 *
2062
 * @param table  A notation table
2063
 * @returns the new xmlNotationTable or NULL in case of error.
2064
 */
2065
xmlNotationTable *
2066
0
xmlCopyNotationTable(xmlNotationTable *table) {
2067
0
    return(xmlHashCopySafe(table, xmlCopyNotation, xmlFreeNotationTableEntry));
2068
0
}
2069
2070
#ifdef LIBXML_OUTPUT_ENABLED
2071
/**
2072
 * This will dump the content the notation declaration as an XML
2073
 * DTD definition.
2074
 *
2075
 * @deprecated Don't use.
2076
 *
2077
 * @param buf  the XML buffer output
2078
 * @param nota  A notation declaration
2079
 */
2080
void
2081
0
xmlDumpNotationDecl(xmlBuffer *buf, xmlNotation *nota) {
2082
0
    xmlSaveCtxtPtr save;
2083
2084
0
    if ((buf == NULL) || (nota == NULL))
2085
0
        return;
2086
2087
0
    save = xmlSaveToBuffer(buf, NULL, 0);
2088
0
    xmlSaveNotationDecl(save, nota);
2089
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
2090
0
        xmlFree(xmlBufferDetach(buf));
2091
0
}
2092
2093
/**
2094
 * This will dump the content of the notation table as an XML
2095
 * DTD definition.
2096
 *
2097
 * @deprecated Don't use.
2098
 *
2099
 * @param buf  the XML buffer output
2100
 * @param table  A notation table
2101
 */
2102
void
2103
0
xmlDumpNotationTable(xmlBuffer *buf, xmlNotationTable *table) {
2104
0
    xmlSaveCtxtPtr save;
2105
2106
0
    if ((buf == NULL) || (table == NULL))
2107
0
        return;
2108
2109
0
    save = xmlSaveToBuffer(buf, NULL, 0);
2110
0
    xmlSaveNotationTable(save, table);
2111
0
    if (xmlSaveFinish(save) != XML_ERR_OK)
2112
0
        xmlFree(xmlBufferDetach(buf));
2113
0
}
2114
#endif /* LIBXML_OUTPUT_ENABLED */
2115
2116
/************************************************************************
2117
 *                  *
2118
 *        IDs         *
2119
 *                  *
2120
 ************************************************************************/
2121
2122
/**
2123
 * Free a string if it is not owned by the dictionary in the
2124
 * current scope
2125
 *
2126
 * @param str  a string
2127
 */
2128
#define DICT_FREE(str)            \
2129
0
  if ((str) && ((!dict) ||       \
2130
0
      (xmlDictOwns(dict, (const xmlChar *)(str)) == 0)))  \
2131
0
      xmlFree((char *)(str));
2132
2133
static int
2134
15.1k
xmlIsStreaming(xmlValidCtxtPtr ctxt) {
2135
15.1k
    xmlParserCtxtPtr pctxt;
2136
2137
15.1k
    if (ctxt == NULL)
2138
0
        return(0);
2139
15.1k
    if ((ctxt->flags & XML_VCTXT_USE_PCTXT) == 0)
2140
0
        return(0);
2141
15.1k
    pctxt = ctxt->userData;
2142
15.1k
    return(pctxt->parseMode == XML_PARSE_READER);
2143
15.1k
}
2144
2145
/**
2146
 * Deallocate the memory used by an id definition.
2147
 *
2148
 * @param id  an id
2149
 */
2150
static void
2151
4.36k
xmlFreeID(xmlIDPtr id) {
2152
4.36k
    xmlDictPtr dict = NULL;
2153
2154
4.36k
    if (id == NULL) return;
2155
2156
4.36k
    if (id->doc != NULL)
2157
4.36k
        dict = id->doc->dict;
2158
2159
4.36k
    if (id->value != NULL)
2160
4.34k
  xmlFree(id->value);
2161
4.36k
    if (id->name != NULL)
2162
0
  DICT_FREE(id->name)
2163
4.36k
    if (id->attr != NULL) {
2164
4.31k
        id->attr->id = NULL;
2165
4.31k
        id->attr->atype = 0;
2166
4.31k
    }
2167
2168
4.36k
    xmlFree(id);
2169
4.36k
}
2170
2171
2172
/**
2173
 * Add an attribute to the docment's ID table.
2174
 *
2175
 * @param attr  the attribute holding the ID
2176
 * @param value  the attribute (ID) value
2177
 * @param idPtr  pointer to resulting ID
2178
 * @returns 1 on success, 0 if the ID already exists, -1 if a memory
2179
 * allocation fails.
2180
 */
2181
static int
2182
39.9k
xmlAddIDInternal(xmlAttrPtr attr, const xmlChar *value, xmlIDPtr *idPtr) {
2183
39.9k
    xmlDocPtr doc;
2184
39.9k
    xmlIDPtr id;
2185
39.9k
    xmlIDTablePtr table;
2186
39.9k
    int ret;
2187
2188
39.9k
    if (idPtr != NULL)
2189
30.5k
        *idPtr = NULL;
2190
39.9k
    if ((value == NULL) || (value[0] == 0))
2191
6.14k
  return(0);
2192
33.7k
    if (attr == NULL)
2193
0
  return(0);
2194
2195
33.7k
    doc = attr->doc;
2196
33.7k
    if (doc == NULL)
2197
0
        return(0);
2198
2199
    /*
2200
     * Create the ID table if needed.
2201
     */
2202
33.7k
    table = (xmlIDTablePtr) doc->ids;
2203
33.7k
    if (table == NULL)  {
2204
1.74k
        doc->ids = table = xmlHashCreate(0);
2205
1.74k
        if (table == NULL)
2206
16
            return(-1);
2207
32.0k
    } else {
2208
32.0k
        id = xmlHashLookup(table, value);
2209
32.0k
        if (id != NULL)
2210
29.3k
            return(0);
2211
32.0k
    }
2212
2213
4.38k
    id = (xmlIDPtr) xmlMalloc(sizeof(xmlID));
2214
4.38k
    if (id == NULL)
2215
19
  return(-1);
2216
4.36k
    memset(id, 0, sizeof(*id));
2217
2218
    /*
2219
     * fill the structure.
2220
     */
2221
4.36k
    id->doc = doc;
2222
4.36k
    id->value = xmlStrdup(value);
2223
4.36k
    if (id->value == NULL) {
2224
18
        xmlFreeID(id);
2225
18
        return(-1);
2226
18
    }
2227
2228
4.34k
    if (attr->id != NULL)
2229
0
        xmlRemoveID(doc, attr);
2230
2231
4.34k
    if (xmlHashAddEntry(table, value, id) < 0) {
2232
30
  xmlFreeID(id);
2233
30
  return(-1);
2234
30
    }
2235
2236
4.31k
    ret = 1;
2237
4.31k
    if (idPtr != NULL)
2238
3.15k
        *idPtr = id;
2239
2240
4.31k
    id->attr = attr;
2241
4.31k
    id->lineno = xmlGetLineNo(attr->parent);
2242
4.31k
    attr->atype = XML_ATTRIBUTE_ID;
2243
4.31k
    attr->id = id;
2244
2245
4.31k
    return(ret);
2246
4.34k
}
2247
2248
/**
2249
 * Add an attribute to the docment's ID table.
2250
 *
2251
 * @since 2.13.0
2252
 *
2253
 * @param attr  the attribute holding the ID
2254
 * @param value  the attribute (ID) value
2255
 * @returns 1 on success, 0 if the ID already exists, -1 if a memory
2256
 * allocation fails.
2257
 */
2258
int
2259
9.42k
xmlAddIDSafe(xmlAttr *attr, const xmlChar *value) {
2260
9.42k
    return(xmlAddIDInternal(attr, value, NULL));
2261
9.42k
}
2262
2263
/**
2264
 * Add an attribute to the docment's ID table.
2265
 *
2266
 * @param ctxt  the validation context (optional)
2267
 * @param doc  pointer to the document, must equal `attr->doc`
2268
 * @param value  the attribute (ID) value
2269
 * @param attr  the attribute holding the ID
2270
 * @returns the new xmlID or NULL on error.
2271
 */
2272
xmlID *
2273
xmlAddID(xmlValidCtxt *ctxt, xmlDoc *doc, const xmlChar *value,
2274
30.5k
         xmlAttr *attr) {
2275
30.5k
    xmlIDPtr id;
2276
30.5k
    int res;
2277
2278
30.5k
    if ((attr == NULL) || (doc != attr->doc))
2279
0
        return(NULL);
2280
2281
30.5k
    res = xmlAddIDInternal(attr, value, &id);
2282
30.5k
    if (res < 0) {
2283
61
        xmlVErrMemory(ctxt);
2284
61
    }
2285
30.4k
    else if (res == 0) {
2286
27.2k
        if (ctxt != NULL) {
2287
            /*
2288
             * The id is already defined in this DTD.
2289
             */
2290
27.2k
            xmlErrValidNode(ctxt, attr->parent, XML_DTD_ID_REDEFINED,
2291
27.2k
                            "ID %s already defined\n", value, NULL, NULL);
2292
27.2k
        }
2293
27.2k
    }
2294
2295
30.5k
    return(id);
2296
30.5k
}
2297
2298
static void
2299
4.31k
xmlFreeIDTableEntry(void *id, const xmlChar *name ATTRIBUTE_UNUSED) {
2300
4.31k
    xmlFreeID((xmlIDPtr) id);
2301
4.31k
}
2302
2303
/**
2304
 * Deallocate the memory used by an ID hash table.
2305
 *
2306
 * @param table  An id table
2307
 */
2308
void
2309
1.73k
xmlFreeIDTable(xmlIDTable *table) {
2310
1.73k
    xmlHashFree(table, xmlFreeIDTableEntry);
2311
1.73k
}
2312
2313
/**
2314
 * Determine whether an attribute is of type ID. In case we have DTD(s)
2315
 * then this is done if DTD loading has been requested. In case
2316
 * of HTML documents parsed with the HTML parser, ID detection is
2317
 * done systematically.
2318
 *
2319
 * @param doc  the document
2320
 * @param elem  the element carrying the attribute
2321
 * @param attr  the attribute
2322
 * @returns 0 or 1 depending on the lookup result or -1 if a memory
2323
 * allocation failed.
2324
 */
2325
int
2326
336k
xmlIsID(xmlDoc *doc, xmlNode *elem, xmlAttr *attr) {
2327
336k
    if ((attr == NULL) || (attr->name == NULL))
2328
30
        return(0);
2329
2330
336k
    if ((doc != NULL) && (doc->type == XML_HTML_DOCUMENT_NODE)) {
2331
0
        if (xmlStrEqual(BAD_CAST "id", attr->name))
2332
0
            return(1);
2333
2334
0
        if ((elem == NULL) || (elem->type != XML_ELEMENT_NODE))
2335
0
            return(0);
2336
2337
0
        if ((xmlStrEqual(BAD_CAST "name", attr->name)) &&
2338
0
      (xmlStrEqual(elem->name, BAD_CAST "a")))
2339
0
      return(1);
2340
336k
    } else {
2341
336k
  xmlAttributePtr attrDecl = NULL;
2342
336k
  xmlChar felem[50];
2343
336k
  xmlChar *fullelemname;
2344
336k
        const xmlChar *aprefix;
2345
2346
336k
        if ((attr->ns != NULL) && (attr->ns->prefix != NULL) &&
2347
19.0k
            (!strcmp((char *) attr->name, "id")) &&
2348
1.05k
            (!strcmp((char *) attr->ns->prefix, "xml")))
2349
648
            return(1);
2350
2351
335k
        if ((doc == NULL) ||
2352
335k
            ((doc->intSubset == NULL) && (doc->extSubset == NULL)))
2353
36.1k
            return(0);
2354
2355
299k
        if ((elem == NULL) ||
2356
299k
            (elem->type != XML_ELEMENT_NODE) ||
2357
299k
            (elem->name == NULL))
2358
0
            return(0);
2359
2360
299k
  fullelemname = (elem->ns != NULL && elem->ns->prefix != NULL) ?
2361
4.18k
      xmlBuildQName(elem->name, elem->ns->prefix, felem, 50) :
2362
299k
      (xmlChar *)elem->name;
2363
299k
        if (fullelemname == NULL)
2364
18
            return(-1);
2365
2366
299k
        aprefix = (attr->ns != NULL) ? attr->ns->prefix : NULL;
2367
2368
299k
  if (fullelemname != NULL) {
2369
299k
      attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, fullelemname,
2370
299k
                              attr->name, aprefix);
2371
299k
      if ((attrDecl == NULL) && (doc->extSubset != NULL))
2372
4.46k
    attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, fullelemname,
2373
4.46k
                attr->name, aprefix);
2374
299k
  }
2375
2376
299k
  if ((fullelemname != felem) && (fullelemname != elem->name))
2377
1.06k
      xmlFree(fullelemname);
2378
2379
299k
        if ((attrDecl != NULL) && (attrDecl->atype == XML_ATTRIBUTE_ID))
2380
22.5k
      return(1);
2381
299k
    }
2382
2383
277k
    return(0);
2384
336k
}
2385
2386
/**
2387
 * Remove the given attribute from the document's ID table.
2388
 *
2389
 * @param doc  the document
2390
 * @param attr  the attribute
2391
 * @returns -1 if the lookup failed and 0 otherwise.
2392
 */
2393
int
2394
505
xmlRemoveID(xmlDoc *doc, xmlAttr *attr) {
2395
505
    xmlIDTablePtr table;
2396
2397
505
    if (doc == NULL) return(-1);
2398
505
    if ((attr == NULL) || (attr->id == NULL)) return(-1);
2399
2400
505
    table = (xmlIDTablePtr) doc->ids;
2401
505
    if (table == NULL)
2402
0
        return(-1);
2403
2404
505
    if (xmlHashRemoveEntry(table, attr->id->value, xmlFreeIDTableEntry) < 0)
2405
0
        return(-1);
2406
2407
505
    return(0);
2408
505
}
2409
2410
/**
2411
 * Search the document's ID table for the attribute with the
2412
 * given ID.
2413
 *
2414
 * @param doc  pointer to the document
2415
 * @param ID  the ID value
2416
 * @returns the attribute or NULL if not found.
2417
 */
2418
xmlAttr *
2419
27.2k
xmlGetID(xmlDoc *doc, const xmlChar *ID) {
2420
27.2k
    xmlIDTablePtr table;
2421
27.2k
    xmlIDPtr id;
2422
2423
27.2k
    if (doc == NULL) {
2424
0
  return(NULL);
2425
0
    }
2426
2427
27.2k
    if (ID == NULL) {
2428
0
  return(NULL);
2429
0
    }
2430
2431
27.2k
    table = (xmlIDTablePtr) doc->ids;
2432
27.2k
    if (table == NULL)
2433
23.3k
        return(NULL);
2434
2435
3.96k
    id = xmlHashLookup(table, ID);
2436
3.96k
    if (id == NULL)
2437
2.68k
  return(NULL);
2438
1.28k
    if (id->attr == NULL) {
2439
  /*
2440
   * We are operating on a stream, return a well known reference
2441
   * since the attribute node doesn't exist anymore
2442
   */
2443
0
  return((xmlAttrPtr) doc);
2444
0
    }
2445
1.28k
    return(id->attr);
2446
1.28k
}
2447
2448
/************************************************************************
2449
 *                  *
2450
 *        Refs          *
2451
 *                  *
2452
 ************************************************************************/
2453
typedef struct xmlRemoveMemo_t
2454
{
2455
  xmlListPtr l;
2456
  xmlAttrPtr ap;
2457
} xmlRemoveMemo;
2458
2459
typedef xmlRemoveMemo *xmlRemoveMemoPtr;
2460
2461
typedef struct xmlValidateMemo_t
2462
{
2463
    xmlValidCtxtPtr ctxt;
2464
    const xmlChar *name;
2465
} xmlValidateMemo;
2466
2467
typedef xmlValidateMemo *xmlValidateMemoPtr;
2468
2469
/**
2470
 * Deallocate the memory used by a ref definition.
2471
 *
2472
 * @param lk  A list link
2473
 */
2474
static void
2475
15.1k
xmlFreeRef(xmlLinkPtr lk) {
2476
15.1k
    xmlRefPtr ref = (xmlRefPtr)xmlLinkGetData(lk);
2477
15.1k
    if (ref == NULL) return;
2478
15.1k
    if (ref->value != NULL)
2479
15.1k
        xmlFree((xmlChar *)ref->value);
2480
15.1k
    if (ref->name != NULL)
2481
0
        xmlFree((xmlChar *)ref->name);
2482
15.1k
    xmlFree(ref);
2483
15.1k
}
2484
2485
/**
2486
 * Deallocate the memory used by a list of references.
2487
 *
2488
 * @param payload  A list of references.
2489
 * @param name  unused
2490
 */
2491
static void
2492
2.29k
xmlFreeRefTableEntry(void *payload, const xmlChar *name ATTRIBUTE_UNUSED) {
2493
2.29k
    xmlListPtr list_ref = (xmlListPtr) payload;
2494
2.29k
    if (list_ref == NULL) return;
2495
2.29k
    xmlListDelete(list_ref);
2496
2.29k
}
2497
2498
/**
2499
 * @param data  Contents of current link
2500
 * @param user  Value supplied by the user
2501
 * @returns 0 to abort the walk or 1 to continue.
2502
 */
2503
static int
2504
xmlWalkRemoveRef(const void *data, void *user)
2505
0
{
2506
0
    xmlAttrPtr attr0 = ((xmlRefPtr)data)->attr;
2507
0
    xmlAttrPtr attr1 = ((xmlRemoveMemoPtr)user)->ap;
2508
0
    xmlListPtr ref_list = ((xmlRemoveMemoPtr)user)->l;
2509
2510
0
    if (attr0 == attr1) { /* Matched: remove and terminate walk */
2511
0
        xmlListRemoveFirst(ref_list, (void *)data);
2512
0
        return 0;
2513
0
    }
2514
0
    return 1;
2515
0
}
2516
2517
/**
2518
 * Do nothing. Used to create unordered lists.
2519
 *
2520
 * @param data0  Value supplied by the user
2521
 * @param data1  Value supplied by the user
2522
 * @returns 0
2523
 */
2524
static int
2525
xmlDummyCompare(const void *data0 ATTRIBUTE_UNUSED,
2526
                const void *data1 ATTRIBUTE_UNUSED)
2527
12.8k
{
2528
12.8k
    return (0);
2529
12.8k
}
2530
2531
/**
2532
 * Register a new ref declaration.
2533
 *
2534
 * @deprecated Don't use. This function will be removed from the
2535
 * public API.
2536
 *
2537
 * @param ctxt  the validation context
2538
 * @param doc  pointer to the document
2539
 * @param value  the value name
2540
 * @param attr  the attribute holding the Ref
2541
 * @returns the new xmlRef or NULL o error.
2542
 */
2543
xmlRef *
2544
xmlAddRef(xmlValidCtxt *ctxt, xmlDoc *doc, const xmlChar *value,
2545
15.1k
    xmlAttr *attr) {
2546
15.1k
    xmlRefPtr ret = NULL;
2547
15.1k
    xmlRefTablePtr table;
2548
15.1k
    xmlListPtr ref_list;
2549
2550
15.1k
    if (doc == NULL) {
2551
0
        return(NULL);
2552
0
    }
2553
15.1k
    if (value == NULL) {
2554
5
        return(NULL);
2555
5
    }
2556
15.1k
    if (attr == NULL) {
2557
0
        return(NULL);
2558
0
    }
2559
2560
    /*
2561
     * Create the Ref table if needed.
2562
     */
2563
15.1k
    table = (xmlRefTablePtr) doc->refs;
2564
15.1k
    if (table == NULL) {
2565
866
        doc->refs = table = xmlHashCreate(0);
2566
866
        if (table == NULL)
2567
8
            goto failed;
2568
866
    }
2569
2570
15.1k
    ret = (xmlRefPtr) xmlMalloc(sizeof(xmlRef));
2571
15.1k
    if (ret == NULL)
2572
14
        goto failed;
2573
15.1k
    memset(ret, 0, sizeof(*ret));
2574
2575
    /*
2576
     * fill the structure.
2577
     */
2578
15.1k
    ret->value = xmlStrdup(value);
2579
15.1k
    if (ret->value == NULL)
2580
8
        goto failed;
2581
15.1k
    if (xmlIsStreaming(ctxt)) {
2582
  /*
2583
   * Operating in streaming mode, attr is gonna disappear
2584
   */
2585
0
  ret->name = xmlStrdup(attr->name);
2586
0
        if (ret->name == NULL)
2587
0
            goto failed;
2588
0
  ret->attr = NULL;
2589
15.1k
    } else {
2590
15.1k
  ret->name = NULL;
2591
15.1k
  ret->attr = attr;
2592
15.1k
    }
2593
15.1k
    ret->lineno = xmlGetLineNo(attr->parent);
2594
2595
    /* To add a reference :-
2596
     * References are maintained as a list of references,
2597
     * Lookup the entry, if no entry create new nodelist
2598
     * Add the owning node to the NodeList
2599
     * Return the ref
2600
     */
2601
2602
15.1k
    ref_list = xmlHashLookup(table, value);
2603
15.1k
    if (ref_list == NULL) {
2604
2.31k
        int res;
2605
2606
2.31k
        ref_list = xmlListCreate(xmlFreeRef, xmlDummyCompare);
2607
2.31k
        if (ref_list == NULL)
2608
13
      goto failed;
2609
2.29k
        res = xmlHashAdd(table, value, ref_list);
2610
2.29k
        if (res <= 0) {
2611
7
            xmlListDelete(ref_list);
2612
7
      goto failed;
2613
7
        }
2614
2.29k
    }
2615
15.1k
    if (xmlListAppend(ref_list, ret) != 0)
2616
10
        goto failed;
2617
15.1k
    return(ret);
2618
2619
60
failed:
2620
60
    xmlVErrMemory(ctxt);
2621
60
    if (ret != NULL) {
2622
38
        if (ret->value != NULL)
2623
30
      xmlFree((char *)ret->value);
2624
38
        if (ret->name != NULL)
2625
0
      xmlFree((char *)ret->name);
2626
38
        xmlFree(ret);
2627
38
    }
2628
60
    return(NULL);
2629
15.1k
}
2630
2631
/**
2632
 * Deallocate the memory used by an Ref hash table.
2633
 *
2634
 * @deprecated Don't use. This function will be removed from the
2635
 * public API.
2636
 *
2637
 * @param table  a ref table
2638
 */
2639
void
2640
858
xmlFreeRefTable(xmlRefTable *table) {
2641
858
    xmlHashFree(table, xmlFreeRefTableEntry);
2642
858
}
2643
2644
/**
2645
 * Determine whether an attribute is of type Ref. In case we have DTD(s)
2646
 * then this is simple, otherwise we use an heuristic: name Ref (upper
2647
 * or lowercase).
2648
 *
2649
 * @deprecated Don't use. This function will be removed from the
2650
 * public API.
2651
 *
2652
 * @param doc  the document
2653
 * @param elem  the element carrying the attribute
2654
 * @param attr  the attribute
2655
 * @returns 0 or 1 depending on the lookup result.
2656
 */
2657
int
2658
292k
xmlIsRef(xmlDoc *doc, xmlNode *elem, xmlAttr *attr) {
2659
292k
    if (attr == NULL)
2660
0
        return(0);
2661
292k
    if (doc == NULL) {
2662
0
        doc = attr->doc;
2663
0
  if (doc == NULL) return(0);
2664
0
    }
2665
2666
292k
    if ((doc->intSubset == NULL) && (doc->extSubset == NULL)) {
2667
36.1k
        return(0);
2668
256k
    } else if (doc->type == XML_HTML_DOCUMENT_NODE) {
2669
        /* TODO @@@ */
2670
0
        return(0);
2671
256k
    } else {
2672
256k
        xmlAttributePtr attrDecl;
2673
256k
        const xmlChar *aprefix;
2674
2675
256k
        if (elem == NULL) return(0);
2676
256k
        aprefix = (attr->ns != NULL) ? attr->ns->prefix : NULL;
2677
256k
        attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, elem->name, attr->name,
2678
256k
                                      aprefix);
2679
256k
        if ((attrDecl == NULL) && (doc->extSubset != NULL))
2680
4.05k
            attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, elem->name, attr->name,
2681
4.05k
                                          aprefix);
2682
2683
256k
  if ((attrDecl != NULL) &&
2684
238k
      (attrDecl->atype == XML_ATTRIBUTE_IDREF ||
2685
232k
       attrDecl->atype == XML_ATTRIBUTE_IDREFS))
2686
8.15k
  return(1);
2687
256k
    }
2688
248k
    return(0);
2689
292k
}
2690
2691
/**
2692
 * Remove the given attribute from the Ref table maintained internally.
2693
 *
2694
 * @deprecated Don't use. This function will be removed from the
2695
 * public API.
2696
 *
2697
 * @param doc  the document
2698
 * @param attr  the attribute
2699
 * @returns -1 if the lookup failed and 0 otherwise.
2700
 */
2701
int
2702
0
xmlRemoveRef(xmlDoc *doc, xmlAttr *attr) {
2703
0
    xmlListPtr ref_list;
2704
0
    xmlRefTablePtr table;
2705
0
    xmlChar *ID;
2706
0
    xmlRemoveMemo target;
2707
2708
0
    if (doc == NULL) return(-1);
2709
0
    if (attr == NULL) return(-1);
2710
2711
0
    table = (xmlRefTablePtr) doc->refs;
2712
0
    if (table == NULL)
2713
0
        return(-1);
2714
2715
0
    ID = xmlNodeListGetString(doc, attr->children, 1);
2716
0
    if (ID == NULL)
2717
0
        return(-1);
2718
2719
0
    ref_list = xmlHashLookup(table, ID);
2720
0
    if(ref_list == NULL) {
2721
0
        xmlFree(ID);
2722
0
        return (-1);
2723
0
    }
2724
2725
    /* At this point, ref_list refers to a list of references which
2726
     * have the same key as the supplied attr. Our list of references
2727
     * is ordered by reference address and we don't have that information
2728
     * here to use when removing. We'll have to walk the list and
2729
     * check for a matching attribute, when we find one stop the walk
2730
     * and remove the entry.
2731
     * The list is ordered by reference, so that means we don't have the
2732
     * key. Passing the list and the reference to the walker means we
2733
     * will have enough data to be able to remove the entry.
2734
     */
2735
0
    target.l = ref_list;
2736
0
    target.ap = attr;
2737
2738
    /* Remove the supplied attr from our list */
2739
0
    xmlListWalk(ref_list, xmlWalkRemoveRef, &target);
2740
2741
    /*If the list is empty then remove the list entry in the hash */
2742
0
    if (xmlListEmpty(ref_list))
2743
0
        xmlHashRemoveEntry(table, ID, xmlFreeRefTableEntry);
2744
0
    xmlFree(ID);
2745
0
    return(0);
2746
0
}
2747
2748
/**
2749
 * Find the set of references for the supplied ID.
2750
 *
2751
 * @deprecated Don't use. This function will be removed from the
2752
 * public API.
2753
 *
2754
 * @param doc  pointer to the document
2755
 * @param ID  the ID value
2756
 * @returns the list of nodes matching the ID or NULL on error.
2757
 */
2758
xmlList *
2759
0
xmlGetRefs(xmlDoc *doc, const xmlChar *ID) {
2760
0
    xmlRefTablePtr table;
2761
2762
0
    if (doc == NULL) {
2763
0
        return(NULL);
2764
0
    }
2765
2766
0
    if (ID == NULL) {
2767
0
        return(NULL);
2768
0
    }
2769
2770
0
    table = (xmlRefTablePtr) doc->refs;
2771
0
    if (table == NULL)
2772
0
        return(NULL);
2773
2774
0
    return (xmlHashLookup(table, ID));
2775
0
}
2776
2777
/************************************************************************
2778
 *                  *
2779
 *    Routines for validity checking        *
2780
 *                  *
2781
 ************************************************************************/
2782
2783
/**
2784
 * Search the DTD for the description of this element.
2785
 *
2786
 * NOTE: A NULL return value can also mean that a memory allocation failed.
2787
 *
2788
 * @param dtd  a pointer to the DtD to search
2789
 * @param name  the element name
2790
 * @returns the xmlElement or NULL if not found.
2791
 */
2792
2793
xmlElement *
2794
0
xmlGetDtdElementDesc(xmlDtd *dtd, const xmlChar *name) {
2795
0
    xmlElementTablePtr table;
2796
0
    xmlElementPtr cur;
2797
0
    const xmlChar *localname;
2798
0
    xmlChar *prefix;
2799
2800
0
    if ((dtd == NULL) || (dtd->elements == NULL) ||
2801
0
        (name == NULL))
2802
0
        return(NULL);
2803
2804
0
    table = (xmlElementTablePtr) dtd->elements;
2805
0
    if (table == NULL)
2806
0
  return(NULL);
2807
2808
0
    localname = xmlSplitQName4(name, &prefix);
2809
0
    if (localname == NULL)
2810
0
        return(NULL);
2811
0
    cur = xmlHashLookup2(table, localname, prefix);
2812
0
    if (prefix != NULL)
2813
0
        xmlFree(prefix);
2814
0
    return(cur);
2815
0
}
2816
2817
/**
2818
 * Search the DTD for the description of this element.
2819
 *
2820
 * @param ctxt  a validation context
2821
 * @param dtd  a pointer to the DtD to search
2822
 * @param name  the element name
2823
 * @returns the xmlElement or NULL if not found.
2824
 */
2825
2826
static xmlElementPtr
2827
100k
xmlGetDtdElementDesc2(xmlValidCtxtPtr ctxt, xmlDtdPtr dtd, const xmlChar *name) {
2828
100k
    xmlElementTablePtr table;
2829
100k
    xmlElementPtr cur = NULL;
2830
100k
    const xmlChar *localName;
2831
100k
    xmlChar *prefix = NULL;
2832
2833
100k
    if (dtd == NULL) return(NULL);
2834
2835
    /*
2836
     * Create the Element table if needed.
2837
     */
2838
100k
    if (dtd->elements == NULL) {
2839
12.9k
  xmlDictPtr dict = NULL;
2840
2841
12.9k
  if (dtd->doc != NULL)
2842
12.9k
      dict = dtd->doc->dict;
2843
2844
12.9k
  dtd->elements = xmlHashCreateDict(0, dict);
2845
12.9k
  if (dtd->elements == NULL)
2846
15
            goto mem_error;
2847
12.9k
    }
2848
100k
    table = (xmlElementTablePtr) dtd->elements;
2849
2850
100k
    localName = xmlSplitQName4(name, &prefix);
2851
100k
    if (localName == NULL)
2852
6
        goto mem_error;
2853
100k
    cur = xmlHashLookup2(table, localName, prefix);
2854
100k
    if (cur == NULL) {
2855
14.6k
  cur = (xmlElementPtr) xmlMalloc(sizeof(xmlElement));
2856
14.6k
  if (cur == NULL)
2857
17
            goto mem_error;
2858
14.6k
  memset(cur, 0, sizeof(xmlElement));
2859
14.6k
  cur->type = XML_ELEMENT_DECL;
2860
14.6k
        cur->doc = dtd->doc;
2861
2862
  /*
2863
   * fill the structure.
2864
   */
2865
14.6k
  cur->name = xmlStrdup(localName);
2866
14.6k
        if (cur->name == NULL)
2867
22
            goto mem_error;
2868
14.5k
  cur->prefix = prefix;
2869
14.5k
        prefix = NULL;
2870
14.5k
  cur->etype = XML_ELEMENT_TYPE_UNDEFINED;
2871
2872
14.5k
  if (xmlHashAdd2(table, localName, cur->prefix, cur) <= 0)
2873
31
            goto mem_error;
2874
14.5k
    }
2875
2876
100k
    if (prefix != NULL)
2877
1.56k
        xmlFree(prefix);
2878
100k
    return(cur);
2879
2880
91
mem_error:
2881
91
    xmlVErrMemory(ctxt);
2882
91
    xmlFree(prefix);
2883
91
    xmlFreeElement(cur);
2884
91
    return(NULL);
2885
100k
}
2886
2887
/**
2888
 * Search the DTD for the description of this element.
2889
 *
2890
 * @param dtd  a pointer to the DtD to search
2891
 * @param name  the element name
2892
 * @param prefix  the element namespace prefix
2893
 * @returns the xmlElement or NULL if not found.
2894
 */
2895
2896
xmlElement *
2897
xmlGetDtdQElementDesc(xmlDtd *dtd, const xmlChar *name,
2898
615k
                const xmlChar *prefix) {
2899
615k
    xmlElementTablePtr table;
2900
2901
615k
    if (dtd == NULL) return(NULL);
2902
440k
    if (dtd->elements == NULL) return(NULL);
2903
333k
    table = (xmlElementTablePtr) dtd->elements;
2904
2905
333k
    return(xmlHashLookup2(table, name, prefix));
2906
440k
}
2907
2908
/**
2909
 * Search the DTD for the description of this attribute on
2910
 * this element.
2911
 *
2912
 * @param dtd  a pointer to the DtD to search
2913
 * @param elem  the element name
2914
 * @param name  the attribute name
2915
 * @returns the xmlAttribute or NULL if not found.
2916
 */
2917
2918
xmlAttribute *
2919
0
xmlGetDtdAttrDesc(xmlDtd *dtd, const xmlChar *elem, const xmlChar *name) {
2920
0
    xmlAttributeTablePtr table;
2921
0
    xmlAttributePtr cur;
2922
0
    const xmlChar *localname;
2923
0
    xmlChar *prefix = NULL;
2924
2925
0
    if ((dtd == NULL) || (dtd->attributes == NULL) ||
2926
0
        (elem == NULL) || (name == NULL))
2927
0
        return(NULL);
2928
2929
0
    table = (xmlAttributeTablePtr) dtd->attributes;
2930
0
    if (table == NULL)
2931
0
  return(NULL);
2932
2933
0
    localname = xmlSplitQName4(name, &prefix);
2934
0
    if (localname == NULL)
2935
0
        return(NULL);
2936
0
    cur = xmlHashLookup3(table, localname, prefix, elem);
2937
0
    if (prefix != NULL)
2938
0
        xmlFree(prefix);
2939
0
    return(cur);
2940
0
}
2941
2942
/**
2943
 * Search the DTD for the description of this qualified attribute on
2944
 * this element.
2945
 *
2946
 * @param dtd  a pointer to the DtD to search
2947
 * @param elem  the element name
2948
 * @param name  the attribute name
2949
 * @param prefix  the attribute namespace prefix
2950
 * @returns the xmlAttribute or NULL if not found.
2951
 */
2952
2953
xmlAttribute *
2954
xmlGetDtdQAttrDesc(xmlDtd *dtd, const xmlChar *elem, const xmlChar *name,
2955
921k
            const xmlChar *prefix) {
2956
921k
    xmlAttributeTablePtr table;
2957
2958
921k
    if (dtd == NULL) return(NULL);
2959
921k
    if (dtd->attributes == NULL) return(NULL);
2960
870k
    table = (xmlAttributeTablePtr) dtd->attributes;
2961
2962
870k
    return(xmlHashLookup3(table, name, prefix, elem));
2963
921k
}
2964
2965
/**
2966
 * Search the DTD for the description of this notation.
2967
 *
2968
 * @param dtd  a pointer to the DtD to search
2969
 * @param name  the notation name
2970
 * @returns the xmlNotation or NULL if not found.
2971
 */
2972
2973
xmlNotation *
2974
15.3k
xmlGetDtdNotationDesc(xmlDtd *dtd, const xmlChar *name) {
2975
15.3k
    xmlNotationTablePtr table;
2976
2977
15.3k
    if (dtd == NULL) return(NULL);
2978
11.8k
    if (dtd->notations == NULL) return(NULL);
2979
2.10k
    table = (xmlNotationTablePtr) dtd->notations;
2980
2981
2.10k
    return(xmlHashLookup(table, name));
2982
11.8k
}
2983
2984
#ifdef LIBXML_VALID_ENABLED
2985
/**
2986
 * Validate that the given name match a notation declaration.
2987
 * [ VC: Notation Declared ]
2988
 *
2989
 * @deprecated Internal function, don't use.
2990
 *
2991
 * @param ctxt  the validation context
2992
 * @param doc  the document
2993
 * @param notationName  the notation name to check
2994
 * @returns 1 if valid or 0 otherwise.
2995
 */
2996
2997
int
2998
xmlValidateNotationUse(xmlValidCtxt *ctxt, xmlDoc *doc,
2999
176
                       const xmlChar *notationName) {
3000
176
    xmlNotationPtr notaDecl;
3001
176
    if ((doc == NULL) || (doc->intSubset == NULL) ||
3002
175
        (notationName == NULL)) return(-1);
3003
3004
175
    notaDecl = xmlGetDtdNotationDesc(doc->intSubset, notationName);
3005
175
    if ((notaDecl == NULL) && (doc->extSubset != NULL))
3006
43
  notaDecl = xmlGetDtdNotationDesc(doc->extSubset, notationName);
3007
3008
175
    if (notaDecl == NULL) {
3009
144
  xmlErrValidNode(ctxt, (xmlNodePtr) doc, XML_DTD_UNKNOWN_NOTATION,
3010
144
                  "NOTATION %s is not declared\n",
3011
144
            notationName, NULL, NULL);
3012
144
  return(0);
3013
144
    }
3014
31
    return(1);
3015
175
}
3016
#endif /* LIBXML_VALID_ENABLED */
3017
3018
/**
3019
 * Search in the DTDs whether an element accepts mixed content
3020
 * or ANY (basically if it is supposed to accept text children).
3021
 *
3022
 * @deprecated Internal function, don't use.
3023
 *
3024
 * @param doc  the document
3025
 * @param name  the element name
3026
 * @returns 0 if no, 1 if yes, and -1 if no element description
3027
 * is available.
3028
 */
3029
3030
int
3031
0
xmlIsMixedElement(xmlDoc *doc, const xmlChar *name) {
3032
0
    xmlElementPtr elemDecl;
3033
3034
0
    if ((doc == NULL) || (doc->intSubset == NULL)) return(-1);
3035
3036
0
    elemDecl = xmlGetDtdElementDesc(doc->intSubset, name);
3037
0
    if ((elemDecl == NULL) && (doc->extSubset != NULL))
3038
0
  elemDecl = xmlGetDtdElementDesc(doc->extSubset, name);
3039
0
    if (elemDecl == NULL) return(-1);
3040
0
    switch (elemDecl->etype) {
3041
0
  case XML_ELEMENT_TYPE_UNDEFINED:
3042
0
      return(-1);
3043
0
  case XML_ELEMENT_TYPE_ELEMENT:
3044
0
      return(0);
3045
0
        case XML_ELEMENT_TYPE_EMPTY:
3046
      /*
3047
       * return 1 for EMPTY since we want VC error to pop up
3048
       * on <empty>     </empty> for example
3049
       */
3050
0
  case XML_ELEMENT_TYPE_ANY:
3051
0
  case XML_ELEMENT_TYPE_MIXED:
3052
0
      return(1);
3053
0
    }
3054
0
    return(1);
3055
0
}
3056
3057
#ifdef LIBXML_VALID_ENABLED
3058
3059
/**
3060
 * Normalize a string in-place.
3061
 *
3062
 * @param str  a string
3063
 */
3064
static void
3065
3.04k
xmlValidNormalizeString(xmlChar *str) {
3066
3.04k
    xmlChar *dst;
3067
3.04k
    const xmlChar *src;
3068
3069
3.04k
    if (str == NULL)
3070
0
        return;
3071
3.04k
    src = str;
3072
3.04k
    dst = str;
3073
3074
3.49k
    while (*src == 0x20) src++;
3075
12.6k
    while (*src != 0) {
3076
9.57k
  if (*src == 0x20) {
3077
2.21k
      while (*src == 0x20) src++;
3078
1.03k
      if (*src != 0)
3079
832
    *dst++ = 0x20;
3080
8.54k
  } else {
3081
8.54k
      *dst++ = *src++;
3082
8.54k
  }
3083
9.57k
    }
3084
3.04k
    *dst = 0;
3085
3.04k
}
3086
3087
/**
3088
 * Validate that the given value matches the Name production.
3089
 *
3090
 * @param value  an Name value
3091
 * @param flags  scan flags
3092
 * @returns 1 if valid or 0 otherwise.
3093
 */
3094
3095
static int
3096
174k
xmlValidateNameValueInternal(const xmlChar *value, int flags) {
3097
174k
    if ((value == NULL) || (value[0] == 0))
3098
118k
        return(0);
3099
3100
56.0k
    value = xmlScanName(value, SIZE_MAX, flags);
3101
56.0k
    return((value != NULL) && (*value == 0));
3102
174k
}
3103
3104
/**
3105
 * Validate that the given value matches the Name production.
3106
 *
3107
 * @param value  an Name value
3108
 * @returns 1 if valid or 0 otherwise.
3109
 */
3110
3111
int
3112
0
xmlValidateNameValue(const xmlChar *value) {
3113
0
    return(xmlValidateNameValueInternal(value, 0));
3114
0
}
3115
3116
/**
3117
 * Validate that the given value matches the Names production.
3118
 *
3119
 * @param value  an Names value
3120
 * @param flags  scan flags
3121
 * @returns 1 if valid or 0 otherwise.
3122
 */
3123
3124
static int
3125
19.4k
xmlValidateNamesValueInternal(const xmlChar *value, int flags) {
3126
19.4k
    const xmlChar *cur;
3127
3128
19.4k
    if (value == NULL)
3129
8
        return(0);
3130
3131
19.4k
    cur = xmlScanName(value, SIZE_MAX, flags);
3132
19.4k
    if ((cur == NULL) || (cur == value))
3133
2.49k
        return(0);
3134
3135
    /* Should not test IS_BLANK(val) here -- see erratum E20*/
3136
18.4k
    while (*cur == 0x20) {
3137
4.18k
  while (*cur == 0x20)
3138
2.09k
      cur += 1;
3139
3140
2.09k
        value = cur;
3141
2.09k
        cur = xmlScanName(value, SIZE_MAX, flags);
3142
2.09k
        if ((cur == NULL) || (cur == value))
3143
603
            return(0);
3144
2.09k
    }
3145
3146
16.3k
    return(*cur == 0);
3147
16.9k
}
3148
3149
/**
3150
 * Validate that the given value matches the Names production.
3151
 *
3152
 * @param value  an Names value
3153
 * @returns 1 if valid or 0 otherwise.
3154
 */
3155
3156
int
3157
0
xmlValidateNamesValue(const xmlChar *value) {
3158
0
    return(xmlValidateNamesValueInternal(value, 0));
3159
0
}
3160
3161
/**
3162
 * Validate that the given value matches the Nmtoken production.
3163
 *
3164
 * [ VC: Name Token ]
3165
 *
3166
 * @param value  an Nmtoken value
3167
 * @param flags  scan flags
3168
 * @returns 1 if valid or 0 otherwise.
3169
 */
3170
3171
static int
3172
1.86k
xmlValidateNmtokenValueInternal(const xmlChar *value, int flags) {
3173
1.86k
    if ((value == NULL) || (value[0] == 0))
3174
495
        return(0);
3175
3176
1.37k
    value = xmlScanName(value, SIZE_MAX, flags | XML_SCAN_NMTOKEN);
3177
1.37k
    return((value != NULL) && (*value == 0));
3178
1.86k
}
3179
3180
/**
3181
 * Validate that the given value matches the Nmtoken production.
3182
 *
3183
 * [ VC: Name Token ]
3184
 *
3185
 * @param value  an Nmtoken value
3186
 * @returns 1 if valid or 0 otherwise.
3187
 */
3188
3189
int
3190
0
xmlValidateNmtokenValue(const xmlChar *value) {
3191
0
    return(xmlValidateNmtokenValueInternal(value, 0));
3192
0
}
3193
3194
/**
3195
 * Validate that the given value matches the Nmtokens production.
3196
 *
3197
 * [ VC: Name Token ]
3198
 *
3199
 * @param value  an Nmtokens value
3200
 * @param flags  scan flags
3201
 * @returns 1 if valid or 0 otherwise.
3202
 */
3203
3204
static int
3205
103k
xmlValidateNmtokensValueInternal(const xmlChar *value, int flags) {
3206
103k
    const xmlChar *cur;
3207
3208
103k
    if (value == NULL)
3209
3
        return(0);
3210
3211
103k
    cur = value;
3212
103k
    while (IS_BLANK_CH(*cur))
3213
436
  cur += 1;
3214
3215
103k
    value = cur;
3216
103k
    cur = xmlScanName(value, SIZE_MAX, flags | XML_SCAN_NMTOKEN);
3217
103k
    if ((cur == NULL) || (cur == value))
3218
4.64k
        return(0);
3219
3220
    /* Should not test IS_BLANK(val) here -- see erratum E20*/
3221
99.7k
    while (*cur == 0x20) {
3222
1.60k
  while (*cur == 0x20)
3223
803
      cur += 1;
3224
803
        if (*cur == 0)
3225
221
            return(1);
3226
3227
582
        value = cur;
3228
582
        cur = xmlScanName(value, SIZE_MAX, flags | XML_SCAN_NMTOKEN);
3229
582
        if ((cur == NULL) || (cur == value))
3230
203
            return(0);
3231
582
    }
3232
3233
98.9k
    return(*cur == 0);
3234
99.3k
}
3235
3236
/**
3237
 * Validate that the given value matches the Nmtokens production.
3238
 *
3239
 * [ VC: Name Token ]
3240
 *
3241
 * @param value  an Nmtokens value
3242
 * @returns 1 if valid or 0 otherwise.
3243
 */
3244
3245
int
3246
0
xmlValidateNmtokensValue(const xmlChar *value) {
3247
0
    return(xmlValidateNmtokensValueInternal(value, 0));
3248
0
}
3249
3250
/**
3251
 * Try to validate a single notation definition.
3252
 *
3253
 * @deprecated Internal function, don't use.
3254
 *
3255
 * It seems that no validity constraint exists on notation declarations.
3256
 * But this function gets called anyway ...
3257
 *
3258
 * @param ctxt  the validation context
3259
 * @param doc  a document instance
3260
 * @param nota  a notation definition
3261
 * @returns 1 if valid or 0 otherwise.
3262
 */
3263
3264
int
3265
xmlValidateNotationDecl(xmlValidCtxt *ctxt ATTRIBUTE_UNUSED, xmlDoc *doc ATTRIBUTE_UNUSED,
3266
188
                         xmlNotation *nota ATTRIBUTE_UNUSED) {
3267
188
    int ret = 1;
3268
3269
188
    return(ret);
3270
188
}
3271
3272
/**
3273
 * Validate that the given attribute value matches the proper production.
3274
 *
3275
 * @param doc  the document
3276
 * @param type  an attribute type
3277
 * @param value  an attribute value
3278
 * @returns 1 if valid or 0 otherwise.
3279
 */
3280
3281
static int
3282
xmlValidateAttributeValueInternal(xmlDocPtr doc, xmlAttributeType type,
3283
309k
                                  const xmlChar *value) {
3284
309k
    int flags = 0;
3285
3286
309k
    if ((doc != NULL) && (doc->properties & XML_DOC_OLD10))
3287
146k
        flags |= XML_SCAN_OLD10;
3288
3289
309k
    switch (type) {
3290
1.81k
  case XML_ATTRIBUTE_ENTITIES:
3291
19.4k
  case XML_ATTRIBUTE_IDREFS:
3292
19.4k
      return(xmlValidateNamesValueInternal(value, flags));
3293
16.2k
  case XML_ATTRIBUTE_ENTITY:
3294
21.5k
  case XML_ATTRIBUTE_IDREF:
3295
168k
  case XML_ATTRIBUTE_ID:
3296
174k
  case XML_ATTRIBUTE_NOTATION:
3297
174k
      return(xmlValidateNameValueInternal(value, flags));
3298
521
  case XML_ATTRIBUTE_NMTOKENS:
3299
103k
  case XML_ATTRIBUTE_ENUMERATION:
3300
103k
      return(xmlValidateNmtokensValueInternal(value, flags));
3301
1.86k
  case XML_ATTRIBUTE_NMTOKEN:
3302
1.86k
      return(xmlValidateNmtokenValueInternal(value, flags));
3303
9.99k
        case XML_ATTRIBUTE_CDATA:
3304
9.99k
      break;
3305
309k
    }
3306
9.99k
    return(1);
3307
309k
}
3308
3309
/**
3310
 * Validate that the given attribute value matches the proper production.
3311
 *
3312
 * @deprecated Internal function, don't use.
3313
 *
3314
 * [ VC: ID ]
3315
 * Values of type ID must match the Name production....
3316
 *
3317
 * [ VC: IDREF ]
3318
 * Values of type IDREF must match the Name production, and values
3319
 * of type IDREFS must match Names ...
3320
 *
3321
 * [ VC: Entity Name ]
3322
 * Values of type ENTITY must match the Name production, values
3323
 * of type ENTITIES must match Names ...
3324
 *
3325
 * [ VC: Name Token ]
3326
 * Values of type NMTOKEN must match the Nmtoken production; values
3327
 * of type NMTOKENS must match Nmtokens.
3328
 *
3329
 * @param type  an attribute type
3330
 * @param value  an attribute value
3331
 * @returns 1 if valid or 0 otherwise.
3332
 */
3333
int
3334
0
xmlValidateAttributeValue(xmlAttributeType type, const xmlChar *value) {
3335
0
    return(xmlValidateAttributeValueInternal(NULL, type, value));
3336
0
}
3337
3338
/**
3339
 * Validate that the given attribute value matches a given type.
3340
 * This typically cannot be done before having finished parsing
3341
 * the subsets.
3342
 *
3343
 * [ VC: IDREF ]
3344
 * Values of type IDREF must match one of the declared IDs.
3345
 * Values of type IDREFS must match a sequence of the declared IDs
3346
 * each Name must match the value of an ID attribute on some element
3347
 * in the XML document; i.e. IDREF values must match the value of
3348
 * some ID attribute.
3349
 *
3350
 * [ VC: Entity Name ]
3351
 * Values of type ENTITY must match one declared entity.
3352
 * Values of type ENTITIES must match a sequence of declared entities.
3353
 *
3354
 * [ VC: Notation Attributes ]
3355
 * all notation names in the declaration must be declared.
3356
 *
3357
 * @param ctxt  the validation context
3358
 * @param doc  the document
3359
 * @param name  the attribute name (used for error reporting only)
3360
 * @param type  the attribute type
3361
 * @param value  the attribute value
3362
 * @returns 1 if valid or 0 otherwise.
3363
 */
3364
3365
static int
3366
xmlValidateAttributeValue2(xmlValidCtxtPtr ctxt, xmlDocPtr doc,
3367
256k
      const xmlChar *name, xmlAttributeType type, const xmlChar *value) {
3368
256k
    int ret = 1;
3369
256k
    switch (type) {
3370
3.18k
  case XML_ATTRIBUTE_IDREFS:
3371
7.89k
  case XML_ATTRIBUTE_IDREF:
3372
144k
  case XML_ATTRIBUTE_ID:
3373
144k
  case XML_ATTRIBUTE_NMTOKENS:
3374
227k
  case XML_ATTRIBUTE_ENUMERATION:
3375
228k
  case XML_ATTRIBUTE_NMTOKEN:
3376
234k
        case XML_ATTRIBUTE_CDATA:
3377
234k
      break;
3378
15.3k
  case XML_ATTRIBUTE_ENTITY: {
3379
15.3k
      xmlEntityPtr ent;
3380
3381
15.3k
      ent = xmlGetDocEntity(doc, value);
3382
      /* yeah it's a bit messy... */
3383
15.3k
      if ((ent == NULL) && (doc->standalone == 1)) {
3384
30
    doc->standalone = 0;
3385
30
    ent = xmlGetDocEntity(doc, value);
3386
30
      }
3387
15.3k
      if (ent == NULL) {
3388
14.8k
    xmlErrValidNode(ctxt, (xmlNodePtr) doc,
3389
14.8k
        XML_DTD_UNKNOWN_ENTITY,
3390
14.8k
   "ENTITY attribute %s reference an unknown entity \"%s\"\n",
3391
14.8k
           name, value, NULL);
3392
14.8k
    ret = 0;
3393
14.8k
      } else if (ent->etype != XML_EXTERNAL_GENERAL_UNPARSED_ENTITY) {
3394
242
    xmlErrValidNode(ctxt, (xmlNodePtr) doc,
3395
242
        XML_DTD_ENTITY_TYPE,
3396
242
   "ENTITY attribute %s reference an entity \"%s\" of wrong type\n",
3397
242
           name, value, NULL);
3398
242
    ret = 0;
3399
242
      }
3400
15.3k
      break;
3401
228k
        }
3402
1.60k
  case XML_ATTRIBUTE_ENTITIES: {
3403
1.60k
      xmlChar *dup, *nam = NULL, *cur, save;
3404
1.60k
      xmlEntityPtr ent;
3405
3406
1.60k
      dup = xmlStrdup(value);
3407
1.60k
      if (dup == NULL) {
3408
12
                xmlVErrMemory(ctxt);
3409
12
    return(0);
3410
12
            }
3411
1.59k
      cur = dup;
3412
6.19k
      while (*cur != 0) {
3413
5.68k
    nam = cur;
3414
9.39M
    while ((*cur != 0) && (!IS_BLANK_CH(*cur))) cur++;
3415
5.68k
    save = *cur;
3416
5.68k
    *cur = 0;
3417
5.68k
    ent = xmlGetDocEntity(doc, nam);
3418
5.68k
    if (ent == NULL) {
3419
5.24k
        xmlErrValidNode(ctxt, (xmlNodePtr) doc,
3420
5.24k
            XML_DTD_UNKNOWN_ENTITY,
3421
5.24k
       "ENTITIES attribute %s reference an unknown entity \"%s\"\n",
3422
5.24k
         name, nam, NULL);
3423
5.24k
        ret = 0;
3424
5.24k
    } else if (ent->etype != XML_EXTERNAL_GENERAL_UNPARSED_ENTITY) {
3425
237
        xmlErrValidNode(ctxt, (xmlNodePtr) doc,
3426
237
            XML_DTD_ENTITY_TYPE,
3427
237
       "ENTITIES attribute %s reference an entity \"%s\" of wrong type\n",
3428
237
         name, nam, NULL);
3429
237
        ret = 0;
3430
237
    }
3431
5.68k
    if (save == 0)
3432
1.07k
        break;
3433
4.60k
    *cur = save;
3434
6.69k
    while (IS_BLANK_CH(*cur)) cur++;
3435
4.60k
      }
3436
1.59k
      xmlFree(dup);
3437
1.59k
      break;
3438
1.60k
  }
3439
4.83k
  case XML_ATTRIBUTE_NOTATION: {
3440
4.83k
      xmlNotationPtr nota;
3441
3442
4.83k
      nota = xmlGetDtdNotationDesc(doc->intSubset, value);
3443
4.83k
      if ((nota == NULL) && (doc->extSubset != NULL))
3444
974
    nota = xmlGetDtdNotationDesc(doc->extSubset, value);
3445
3446
4.83k
      if (nota == NULL) {
3447
4.11k
    xmlErrValidNode(ctxt, (xmlNodePtr) doc,
3448
4.11k
                    XML_DTD_UNKNOWN_NOTATION,
3449
4.11k
       "NOTATION attribute %s reference an unknown notation \"%s\"\n",
3450
4.11k
           name, value, NULL);
3451
4.11k
    ret = 0;
3452
4.11k
      }
3453
4.83k
      break;
3454
1.60k
        }
3455
256k
    }
3456
256k
    return(ret);
3457
256k
}
3458
3459
/**
3460
 * Performs the validation-related extra step of the normalization
3461
 * of attribute values:
3462
 *
3463
 * @deprecated Internal function, don't use.
3464
 *
3465
 * If the declared value is not CDATA, then the XML processor must further
3466
 * process the normalized attribute value by discarding any leading and
3467
 * trailing space (\#x20) characters, and by replacing sequences of space
3468
 * (\#x20) characters by single space (\#x20) character.
3469
 *
3470
 * Also  check VC: Standalone Document Declaration in P32, and update
3471
 * `ctxt->valid` accordingly
3472
 *
3473
 * @param ctxt  the validation context
3474
 * @param doc  the document
3475
 * @param elem  the parent
3476
 * @param name  the attribute name
3477
 * @param value  the attribute value
3478
 * @returns a new normalized string if normalization is needed, NULL
3479
 * otherwise. The caller must free the returned value.
3480
 */
3481
3482
xmlChar *
3483
xmlValidCtxtNormalizeAttributeValue(xmlValidCtxt *ctxt, xmlDoc *doc,
3484
5.04k
       xmlNode *elem, const xmlChar *name, const xmlChar *value) {
3485
5.04k
    xmlChar *ret;
3486
5.04k
    xmlAttributePtr attrDecl = NULL;
3487
5.04k
    const xmlChar *localName;
3488
5.04k
    xmlChar *prefix = NULL;
3489
5.04k
    int extsubset = 0;
3490
3491
5.04k
    if (doc == NULL) return(NULL);
3492
5.04k
    if (elem == NULL) return(NULL);
3493
5.04k
    if (name == NULL) return(NULL);
3494
5.04k
    if (value == NULL) return(NULL);
3495
3496
5.04k
    localName = xmlSplitQName4(name, &prefix);
3497
5.04k
    if (localName == NULL)
3498
9
        goto mem_error;
3499
3500
5.03k
    if ((elem->ns != NULL) && (elem->ns->prefix != NULL)) {
3501
834
  xmlChar buf[50];
3502
834
  xmlChar *elemname;
3503
3504
834
  elemname = xmlBuildQName(elem->name, elem->ns->prefix, buf, 50);
3505
834
  if (elemname == NULL)
3506
7
      goto mem_error;
3507
827
        if (doc->intSubset != NULL)
3508
827
            attrDecl = xmlHashLookup3(doc->intSubset->attributes, localName,
3509
827
                                      prefix, elemname);
3510
827
  if ((attrDecl == NULL) && (doc->extSubset != NULL)) {
3511
238
      attrDecl = xmlHashLookup3(doc->extSubset->attributes, localName,
3512
238
                                      prefix, elemname);
3513
238
      if (attrDecl != NULL)
3514
0
    extsubset = 1;
3515
238
  }
3516
827
  if ((elemname != buf) && (elemname != elem->name))
3517
435
      xmlFree(elemname);
3518
827
    }
3519
5.02k
    if ((attrDecl == NULL) && (doc->intSubset != NULL))
3520
4.83k
  attrDecl = xmlHashLookup3(doc->intSubset->attributes, localName,
3521
4.83k
                                  prefix, elem->name);
3522
5.02k
    if ((attrDecl == NULL) && (doc->extSubset != NULL)) {
3523
1.31k
  attrDecl = xmlHashLookup3(doc->extSubset->attributes, localName,
3524
1.31k
                                  prefix, elem->name);
3525
1.31k
  if (attrDecl != NULL)
3526
852
      extsubset = 1;
3527
1.31k
    }
3528
3529
5.02k
    if (attrDecl == NULL)
3530
1.12k
  goto done;
3531
3.90k
    if (attrDecl->atype == XML_ATTRIBUTE_CDATA)
3532
829
  goto done;
3533
3534
3.07k
    ret = xmlStrdup(value);
3535
3.07k
    if (ret == NULL)
3536
24
  goto mem_error;
3537
3.04k
    xmlValidNormalizeString(ret);
3538
3.04k
    if ((doc->standalone) && (extsubset == 1) && (!xmlStrEqual(value, ret))) {
3539
201
  xmlErrValidNode(ctxt, elem, XML_DTD_NOT_STANDALONE,
3540
201
"standalone: %s on %s value had to be normalized based on external subset declaration\n",
3541
201
         name, elem->name, NULL);
3542
201
  ctxt->valid = 0;
3543
201
    }
3544
3545
3.04k
    xmlFree(prefix);
3546
3.04k
    return(ret);
3547
3548
40
mem_error:
3549
40
    xmlVErrMemory(ctxt);
3550
3551
1.99k
done:
3552
1.99k
    xmlFree(prefix);
3553
1.99k
    return(NULL);
3554
40
}
3555
3556
/**
3557
 * Performs the validation-related extra step of the normalization
3558
 * of attribute values:
3559
 *
3560
 * @deprecated Internal function, don't use.
3561
 *
3562
 * If the declared value is not CDATA, then the XML processor must further
3563
 * process the normalized attribute value by discarding any leading and
3564
 * trailing space (\#x20) characters, and by replacing sequences of space
3565
 * (\#x20) characters by single space (\#x20) character.
3566
 *
3567
 * @param doc  the document
3568
 * @param elem  the parent
3569
 * @param name  the attribute name
3570
 * @param value  the attribute value
3571
 * @returns a new normalized string if normalization is needed, NULL
3572
 * otherwise. The caller must free the returned value.
3573
 */
3574
3575
xmlChar *
3576
xmlValidNormalizeAttributeValue(xmlDoc *doc, xmlNode *elem,
3577
0
              const xmlChar *name, const xmlChar *value) {
3578
0
    xmlChar *ret;
3579
0
    xmlAttributePtr attrDecl = NULL;
3580
3581
0
    if (doc == NULL) return(NULL);
3582
0
    if (elem == NULL) return(NULL);
3583
0
    if (name == NULL) return(NULL);
3584
0
    if (value == NULL) return(NULL);
3585
3586
0
    if ((elem->ns != NULL) && (elem->ns->prefix != NULL)) {
3587
0
  xmlChar fn[50];
3588
0
  xmlChar *fullname;
3589
3590
0
  fullname = xmlBuildQName(elem->name, elem->ns->prefix, fn, 50);
3591
0
  if (fullname == NULL)
3592
0
      return(NULL);
3593
0
  if ((fullname != fn) && (fullname != elem->name))
3594
0
      xmlFree(fullname);
3595
0
    }
3596
0
    attrDecl = xmlGetDtdAttrDesc(doc->intSubset, elem->name, name);
3597
0
    if ((attrDecl == NULL) && (doc->extSubset != NULL))
3598
0
  attrDecl = xmlGetDtdAttrDesc(doc->extSubset, elem->name, name);
3599
3600
0
    if (attrDecl == NULL)
3601
0
  return(NULL);
3602
0
    if (attrDecl->atype == XML_ATTRIBUTE_CDATA)
3603
0
  return(NULL);
3604
3605
0
    ret = xmlStrdup(value);
3606
0
    if (ret == NULL)
3607
0
  return(NULL);
3608
0
    xmlValidNormalizeString(ret);
3609
0
    return(ret);
3610
0
}
3611
3612
static void
3613
xmlValidateAttributeIdCallback(void *payload, void *data,
3614
73
                         const xmlChar *name ATTRIBUTE_UNUSED) {
3615
73
    xmlAttributePtr attr = (xmlAttributePtr) payload;
3616
73
    int *count = (int *) data;
3617
73
    if (attr->atype == XML_ATTRIBUTE_ID) (*count)++;
3618
73
}
3619
3620
/**
3621
 * Try to validate a single attribute definition.
3622
 * Performs the following checks as described by the
3623
 * XML-1.0 recommendation:
3624
 *
3625
 * @deprecated Internal function, don't use.
3626
 *
3627
 * - [ VC: Attribute Default Legal ]
3628
 * - [ VC: Enumeration ]
3629
 * - [ VC: ID Attribute Default ]
3630
 *
3631
 * The ID/IDREF uniqueness and matching are done separately.
3632
 *
3633
 * @param ctxt  the validation context
3634
 * @param doc  a document instance
3635
 * @param attr  an attribute definition
3636
 * @returns 1 if valid or 0 otherwise.
3637
 */
3638
3639
int
3640
xmlValidateAttributeDecl(xmlValidCtxt *ctxt, xmlDoc *doc,
3641
28.9k
                         xmlAttribute *attr) {
3642
28.9k
    int ret = 1;
3643
28.9k
    int val;
3644
28.9k
    CHECK_DTD;
3645
28.9k
    if(attr == NULL) return(1);
3646
3647
    /* Attribute Default Legal */
3648
    /* Enumeration */
3649
28.9k
    if (attr->defaultValue != NULL) {
3650
10.1k
  val = xmlValidateAttributeValueInternal(doc, attr->atype,
3651
10.1k
                                          attr->defaultValue);
3652
10.1k
  if (val == 0) {
3653
0
      xmlErrValidNode(ctxt, (xmlNodePtr) attr, XML_DTD_ATTRIBUTE_DEFAULT,
3654
0
         "Syntax of default value for attribute %s of %s is not valid\n",
3655
0
             attr->name, attr->elem, NULL);
3656
0
  }
3657
10.1k
        ret &= val;
3658
10.1k
    }
3659
3660
    /* ID Attribute Default */
3661
28.9k
    if ((attr->atype == XML_ATTRIBUTE_ID)&&
3662
6.74k
        (attr->def != XML_ATTRIBUTE_IMPLIED) &&
3663
1.77k
  (attr->def != XML_ATTRIBUTE_REQUIRED)) {
3664
1.19k
  xmlErrValidNode(ctxt, (xmlNodePtr) attr, XML_DTD_ID_FIXED,
3665
1.19k
          "ID attribute %s of %s is not valid must be #IMPLIED or #REQUIRED\n",
3666
1.19k
         attr->name, attr->elem, NULL);
3667
1.19k
  ret = 0;
3668
1.19k
    }
3669
3670
    /* One ID per Element Type */
3671
28.9k
    if (attr->atype == XML_ATTRIBUTE_ID) {
3672
6.74k
        xmlElementPtr elem = NULL;
3673
6.74k
        const xmlChar *elemLocalName;
3674
6.74k
        xmlChar *elemPrefix;
3675
6.74k
        int nbId;
3676
3677
6.74k
        elemLocalName = xmlSplitQName4(attr->elem, &elemPrefix);
3678
6.74k
        if (elemLocalName == NULL) {
3679
4
            xmlVErrMemory(ctxt);
3680
4
            return(0);
3681
4
        }
3682
3683
  /* the trick is that we parse DtD as their own internal subset */
3684
6.73k
        if (doc->intSubset != NULL)
3685
6.73k
            elem = xmlHashLookup2(doc->intSubset->elements,
3686
6.73k
                                  elemLocalName, elemPrefix);
3687
6.73k
  if (elem != NULL) {
3688
4.43k
      nbId = xmlScanIDAttributeDecl(ctxt, elem, 0);
3689
4.43k
  } else {
3690
2.30k
      xmlAttributeTablePtr table;
3691
3692
      /*
3693
       * The attribute may be declared in the internal subset and the
3694
       * element in the external subset.
3695
       */
3696
2.30k
      nbId = 0;
3697
2.30k
      if (doc->intSubset != NULL) {
3698
2.30k
    table = (xmlAttributeTablePtr) doc->intSubset->attributes;
3699
2.30k
    xmlHashScan3(table, NULL, NULL, attr->elem,
3700
2.30k
           xmlValidateAttributeIdCallback, &nbId);
3701
2.30k
      }
3702
2.30k
  }
3703
6.73k
  if (nbId > 1) {
3704
3705
248
      xmlErrValidNodeNr(ctxt, (xmlNodePtr) attr, XML_DTD_ID_SUBSET,
3706
248
       "Element %s has %d ID attribute defined in the internal subset : %s\n",
3707
248
       attr->elem, nbId, attr->name);
3708
248
            ret = 0;
3709
6.48k
  } else if (doc->extSubset != NULL) {
3710
2.72k
      int extId = 0;
3711
2.72k
      elem = xmlHashLookup2(doc->extSubset->elements,
3712
2.72k
                                  elemLocalName, elemPrefix);
3713
2.72k
      if (elem != NULL) {
3714
2.72k
    extId = xmlScanIDAttributeDecl(ctxt, elem, 0);
3715
2.72k
      }
3716
2.72k
      if (extId > 1) {
3717
346
    xmlErrValidNodeNr(ctxt, (xmlNodePtr) attr, XML_DTD_ID_SUBSET,
3718
346
       "Element %s has %d ID attribute defined in the external subset : %s\n",
3719
346
           attr->elem, extId, attr->name);
3720
346
                ret = 0;
3721
2.37k
      } else if (extId + nbId > 1) {
3722
10
    xmlErrValidNode(ctxt, (xmlNodePtr) attr, XML_DTD_ID_SUBSET,
3723
10
"Element %s has ID attributes defined in the internal and external subset : %s\n",
3724
10
           attr->elem, attr->name, NULL);
3725
10
                ret = 0;
3726
10
      }
3727
2.72k
  }
3728
3729
6.73k
        xmlFree(elemPrefix);
3730
6.73k
    }
3731
3732
    /* Validity Constraint: Enumeration */
3733
28.9k
    if ((attr->defaultValue != NULL) && (attr->tree != NULL)) {
3734
7.74k
        xmlEnumerationPtr tree = attr->tree;
3735
8.61k
  while (tree != NULL) {
3736
7.95k
      if (xmlStrEqual(tree->name, attr->defaultValue)) break;
3737
874
      tree = tree->next;
3738
874
  }
3739
7.74k
  if (tree == NULL) {
3740
666
      xmlErrValidNode(ctxt, (xmlNodePtr) attr, XML_DTD_ATTRIBUTE_VALUE,
3741
666
"Default value \"%s\" for attribute %s of %s is not among the enumerated set\n",
3742
666
       attr->defaultValue, attr->name, attr->elem);
3743
666
      ret = 0;
3744
666
  }
3745
7.74k
    }
3746
3747
28.9k
    return(ret);
3748
28.9k
}
3749
3750
/**
3751
 * Try to validate a single element definition.
3752
 * Performs the following checks as described by the
3753
 * XML-1.0 recommendation:
3754
 *
3755
 * @deprecated Internal function, don't use.
3756
 *
3757
 * - [ VC: One ID per Element Type ]
3758
 * - [ VC: No Duplicate Types ]
3759
 * - [ VC: Unique Element Type Declaration ]
3760
 *
3761
 * @param ctxt  the validation context
3762
 * @param doc  a document instance
3763
 * @param elem  an element definition
3764
 * @returns 1 if valid or 0 otherwise.
3765
 */
3766
3767
int
3768
xmlValidateElementDecl(xmlValidCtxt *ctxt, xmlDoc *doc,
3769
11.2k
                       xmlElement *elem) {
3770
11.2k
    int ret = 1;
3771
11.2k
    xmlElementPtr tst;
3772
11.2k
    const xmlChar *localName;
3773
11.2k
    xmlChar *prefix;
3774
3775
11.2k
    CHECK_DTD;
3776
3777
11.2k
    if (elem == NULL) return(1);
3778
3779
    /* No Duplicate Types */
3780
10.8k
    if (elem->etype == XML_ELEMENT_TYPE_MIXED) {
3781
3.88k
  xmlElementContentPtr cur, next;
3782
3.88k
        const xmlChar *name;
3783
3784
3.88k
  cur = elem->content;
3785
19.8k
  while (cur != NULL) {
3786
19.8k
      if (cur->type != XML_ELEMENT_CONTENT_OR) break;
3787
15.9k
      if (cur->c1 == NULL) break;
3788
15.9k
      if (cur->c1->type == XML_ELEMENT_CONTENT_ELEMENT) {
3789
14.3k
    name = cur->c1->name;
3790
14.3k
    next = cur->c2;
3791
170k
    while (next != NULL) {
3792
170k
        if (next->type == XML_ELEMENT_CONTENT_ELEMENT) {
3793
14.3k
            if ((xmlStrEqual(next->name, name)) &&
3794
925
          (xmlStrEqual(next->prefix, cur->c1->prefix))) {
3795
560
          if (cur->c1->prefix == NULL) {
3796
342
        xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_CONTENT_ERROR,
3797
342
       "Definition of %s has duplicate references of %s\n",
3798
342
               elem->name, name, NULL);
3799
342
          } else {
3800
218
        xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_CONTENT_ERROR,
3801
218
       "Definition of %s has duplicate references of %s:%s\n",
3802
218
               elem->name, cur->c1->prefix, name);
3803
218
          }
3804
560
          ret = 0;
3805
560
      }
3806
14.3k
      break;
3807
14.3k
        }
3808
156k
        if (next->c1 == NULL) break;
3809
156k
        if (next->c1->type != XML_ELEMENT_CONTENT_ELEMENT) break;
3810
156k
        if ((xmlStrEqual(next->c1->name, name)) &&
3811
19.2k
            (xmlStrEqual(next->c1->prefix, cur->c1->prefix))) {
3812
16.5k
      if (cur->c1->prefix == NULL) {
3813
11.9k
          xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_CONTENT_ERROR,
3814
11.9k
         "Definition of %s has duplicate references to %s\n",
3815
11.9k
           elem->name, name, NULL);
3816
11.9k
      } else {
3817
4.60k
          xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_CONTENT_ERROR,
3818
4.60k
         "Definition of %s has duplicate references to %s:%s\n",
3819
4.60k
           elem->name, cur->c1->prefix, name);
3820
4.60k
      }
3821
16.5k
      ret = 0;
3822
16.5k
        }
3823
156k
        next = next->c2;
3824
156k
    }
3825
14.3k
      }
3826
15.9k
      cur = cur->c2;
3827
15.9k
  }
3828
3.88k
    }
3829
3830
10.8k
    localName = xmlSplitQName4(elem->name, &prefix);
3831
10.8k
    if (localName == NULL) {
3832
10
        xmlVErrMemory(ctxt);
3833
10
        return(0);
3834
10
    }
3835
3836
    /* VC: Unique Element Type Declaration */
3837
10.8k
    if (doc->intSubset != NULL) {
3838
10.8k
        tst = xmlHashLookup2(doc->intSubset->elements, localName, prefix);
3839
3840
10.8k
        if ((tst != NULL ) && (tst != elem) &&
3841
757
            ((tst->prefix == elem->prefix) ||
3842
27
             (xmlStrEqual(tst->prefix, elem->prefix))) &&
3843
747
            (tst->etype != XML_ELEMENT_TYPE_UNDEFINED)) {
3844
744
            xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_ELEM_REDEFINED,
3845
744
                            "Redefinition of element %s\n",
3846
744
                           elem->name, NULL, NULL);
3847
744
            ret = 0;
3848
744
        }
3849
10.8k
    }
3850
10.8k
    if (doc->extSubset != NULL) {
3851
3.14k
        tst = xmlHashLookup2(doc->extSubset->elements, localName, prefix);
3852
3853
3.14k
        if ((tst != NULL ) && (tst != elem) &&
3854
9
            ((tst->prefix == elem->prefix) ||
3855
9
             (xmlStrEqual(tst->prefix, elem->prefix))) &&
3856
6
            (tst->etype != XML_ELEMENT_TYPE_UNDEFINED)) {
3857
3
            xmlErrValidNode(ctxt, (xmlNodePtr) elem, XML_DTD_ELEM_REDEFINED,
3858
3
                            "Redefinition of element %s\n",
3859
3
                           elem->name, NULL, NULL);
3860
3
            ret = 0;
3861
3
        }
3862
3.14k
    }
3863
3864
10.8k
    xmlFree(prefix);
3865
10.8k
    return(ret);
3866
10.8k
}
3867
3868
/**
3869
 * Try to validate a single attribute for an element.
3870
 * Performs the following checks as described by the
3871
 * XML-1.0 recommendation:
3872
 *
3873
 * @deprecated Internal function, don't use.
3874
 *
3875
 * - [ VC: Attribute Value Type ]
3876
 * - [ VC: Fixed Attribute Default ]
3877
 * - [ VC: Entity Name ]
3878
 * - [ VC: Name Token ]
3879
 * - [ VC: ID ]
3880
 * - [ VC: IDREF ]
3881
 * - [ VC: Entity Name ]
3882
 * - [ VC: Notation Attributes ]
3883
 *
3884
 * ID/IDREF uniqueness and matching are handled separately.
3885
 *
3886
 * @param ctxt  the validation context
3887
 * @param doc  a document instance
3888
 * @param elem  an element instance
3889
 * @param attr  an attribute instance
3890
 * @param value  the attribute value (without entities processing)
3891
 * @returns 1 if valid or 0 otherwise.
3892
 */
3893
3894
int
3895
xmlValidateOneAttribute(xmlValidCtxt *ctxt, xmlDoc *doc,
3896
                        xmlNode *elem, xmlAttr *attr, const xmlChar *value)
3897
122k
{
3898
122k
    xmlAttributePtr attrDecl =  NULL;
3899
122k
    const xmlChar *aprefix;
3900
122k
    int val;
3901
122k
    int ret = 1;
3902
3903
122k
    CHECK_DTD;
3904
122k
    if ((elem == NULL) || (elem->name == NULL)) return(0);
3905
122k
    if ((attr == NULL) || (attr->name == NULL)) return(0);
3906
3907
122k
    aprefix = (attr->ns != NULL) ? attr->ns->prefix : NULL;
3908
3909
122k
    if ((elem->ns != NULL) && (elem->ns->prefix != NULL)) {
3910
3.29k
  xmlChar fn[50];
3911
3.29k
  xmlChar *fullname;
3912
3913
3.29k
  fullname = xmlBuildQName(elem->name, elem->ns->prefix, fn, 50);
3914
3.29k
  if (fullname == NULL) {
3915
13
            xmlVErrMemory(ctxt);
3916
13
      return(0);
3917
13
        }
3918
3.28k
        attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, fullname,
3919
3.28k
                                      attr->name, aprefix);
3920
3.28k
        if ((attrDecl == NULL) && (doc->extSubset != NULL))
3921
665
            attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, fullname,
3922
665
                                          attr->name, aprefix);
3923
3.28k
  if ((fullname != fn) && (fullname != elem->name))
3924
1.17k
      xmlFree(fullname);
3925
3.28k
    }
3926
122k
    if (attrDecl == NULL) {
3927
121k
        attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, elem->name,
3928
121k
                                      attr->name, aprefix);
3929
121k
        if ((attrDecl == NULL) && (doc->extSubset != NULL))
3930
5.45k
            attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, elem->name,
3931
5.45k
                                          attr->name, aprefix);
3932
121k
    }
3933
3934
3935
    /* Validity Constraint: Attribute Value Type */
3936
122k
    if (attrDecl == NULL) {
3937
11.1k
  xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_ATTRIBUTE,
3938
11.1k
         "No declaration for attribute %s of element %s\n",
3939
11.1k
         attr->name, elem->name, NULL);
3940
11.1k
  return(0);
3941
11.1k
    }
3942
111k
    if (attr->id != NULL)
3943
0
        xmlRemoveID(doc, attr);
3944
111k
    attr->atype = attrDecl->atype;
3945
3946
111k
    val = xmlValidateAttributeValueInternal(doc, attrDecl->atype, value);
3947
111k
    if (val == 0) {
3948
17.6k
      xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_VALUE,
3949
17.6k
     "Syntax of value for attribute %s of %s is not valid\n",
3950
17.6k
         attr->name, elem->name, NULL);
3951
17.6k
        ret = 0;
3952
17.6k
    }
3953
3954
    /* Validity constraint: Fixed Attribute Default */
3955
111k
    if (attrDecl->def == XML_ATTRIBUTE_FIXED) {
3956
4.23k
  if (!xmlStrEqual(value, attrDecl->defaultValue)) {
3957
897
      xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_DEFAULT,
3958
897
     "Value for attribute %s of %s is different from default \"%s\"\n",
3959
897
       attr->name, elem->name, attrDecl->defaultValue);
3960
897
      ret = 0;
3961
897
  }
3962
4.23k
    }
3963
3964
    /* Validity Constraint: ID uniqueness */
3965
111k
    if (attrDecl->atype == XML_ATTRIBUTE_ID &&
3966
14.0k
        (ctxt == NULL || (ctxt->flags & XML_VCTXT_IN_ENTITY) == 0)) {
3967
13.9k
        if (xmlAddID(ctxt, doc, value, attr) == NULL)
3968
12.5k
      ret = 0;
3969
13.9k
    }
3970
3971
111k
    if ((attrDecl->atype == XML_ATTRIBUTE_IDREF) ||
3972
107k
  (attrDecl->atype == XML_ATTRIBUTE_IDREFS)) {
3973
7.04k
        if (xmlAddRef(ctxt, doc, value, attr) == NULL)
3974
30
      ret = 0;
3975
7.04k
    }
3976
3977
    /* Validity Constraint: Notation Attributes */
3978
111k
    if (attrDecl->atype == XML_ATTRIBUTE_NOTATION) {
3979
3.45k
        xmlEnumerationPtr tree = attrDecl->tree;
3980
3.45k
        xmlNotationPtr nota;
3981
3982
        /* First check that the given NOTATION was declared */
3983
3.45k
  nota = xmlGetDtdNotationDesc(doc->intSubset, value);
3984
3.45k
  if (nota == NULL)
3985
3.25k
      nota = xmlGetDtdNotationDesc(doc->extSubset, value);
3986
3987
3.45k
  if (nota == NULL) {
3988
3.07k
      xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_NOTATION,
3989
3.07k
       "Value \"%s\" for attribute %s of %s is not a declared Notation\n",
3990
3.07k
       value, attr->name, elem->name);
3991
3.07k
      ret = 0;
3992
3.07k
        }
3993
3994
  /* Second, verify that it's among the list */
3995
6.69k
  while (tree != NULL) {
3996
3.74k
      if (xmlStrEqual(tree->name, value)) break;
3997
3.23k
      tree = tree->next;
3998
3.23k
  }
3999
3.45k
  if (tree == NULL) {
4000
2.95k
      xmlErrValidNode(ctxt, elem, XML_DTD_NOTATION_VALUE,
4001
2.95k
"Value \"%s\" for attribute %s of %s is not among the enumerated notations\n",
4002
2.95k
       value, attr->name, elem->name);
4003
2.95k
      ret = 0;
4004
2.95k
  }
4005
3.45k
    }
4006
4007
    /* Validity Constraint: Enumeration */
4008
111k
    if (attrDecl->atype == XML_ATTRIBUTE_ENUMERATION) {
4009
80.7k
        xmlEnumerationPtr tree = attrDecl->tree;
4010
87.8k
  while (tree != NULL) {
4011
80.7k
      if (xmlStrEqual(tree->name, value)) break;
4012
7.13k
      tree = tree->next;
4013
7.13k
  }
4014
80.7k
  if (tree == NULL) {
4015
7.12k
      xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_VALUE,
4016
7.12k
       "Value \"%s\" for attribute %s of %s is not among the enumerated set\n",
4017
7.12k
       value, attr->name, elem->name);
4018
7.12k
      ret = 0;
4019
7.12k
  }
4020
80.7k
    }
4021
4022
    /* Fixed Attribute Default */
4023
111k
    if ((attrDecl->def == XML_ATTRIBUTE_FIXED) &&
4024
4.23k
        (!xmlStrEqual(attrDecl->defaultValue, value))) {
4025
897
  xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_VALUE,
4026
897
     "Value for attribute %s of %s must be \"%s\"\n",
4027
897
         attr->name, elem->name, attrDecl->defaultValue);
4028
897
        ret = 0;
4029
897
    }
4030
4031
    /* Extra check for the attribute value */
4032
111k
    ret &= xmlValidateAttributeValue2(ctxt, doc, attr->name,
4033
111k
              attrDecl->atype, value);
4034
4035
111k
    return(ret);
4036
122k
}
4037
4038
/**
4039
 * Try to validate a single namespace declaration for an element.
4040
 * Performs the following checks as described by the
4041
 * XML-1.0 recommendation:
4042
 *
4043
 * @deprecated Internal function, don't use.
4044
 *
4045
 * - [ VC: Attribute Value Type ]
4046
 * - [ VC: Fixed Attribute Default ]
4047
 * - [ VC: Entity Name ]
4048
 * - [ VC: Name Token ]
4049
 * - [ VC: ID ]
4050
 * - [ VC: IDREF ]
4051
 * - [ VC: Entity Name ]
4052
 * - [ VC: Notation Attributes ]
4053
 *
4054
 * ID/IDREF uniqueness and matching are handled separately.
4055
 *
4056
 * @param ctxt  the validation context
4057
 * @param doc  a document instance
4058
 * @param elem  an element instance
4059
 * @param prefix  the namespace prefix
4060
 * @param ns  an namespace declaration instance
4061
 * @param value  the attribute value (without entities processing)
4062
 * @returns 1 if valid or 0 otherwise.
4063
 */
4064
4065
int
4066
xmlValidateOneNamespace(xmlValidCtxt *ctxt, xmlDoc *doc,
4067
151k
xmlNode *elem, const xmlChar *prefix, xmlNs *ns, const xmlChar *value) {
4068
    /* xmlElementPtr elemDecl; */
4069
151k
    xmlAttributePtr attrDecl =  NULL;
4070
151k
    int val;
4071
151k
    int ret = 1;
4072
4073
151k
    CHECK_DTD;
4074
151k
    if ((elem == NULL) || (elem->name == NULL)) return(0);
4075
151k
    if ((ns == NULL) || (ns->href == NULL)) return(0);
4076
4077
150k
    if (prefix != NULL) {
4078
3.53k
  xmlChar fn[50];
4079
3.53k
  xmlChar *fullname;
4080
4081
3.53k
  fullname = xmlBuildQName(elem->name, prefix, fn, 50);
4082
3.53k
  if (fullname == NULL) {
4083
4
      xmlVErrMemory(ctxt);
4084
4
      return(0);
4085
4
  }
4086
3.53k
  if (ns->prefix != NULL) {
4087
2.24k
      attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, fullname,
4088
2.24k
                              ns->prefix, BAD_CAST "xmlns");
4089
2.24k
      if ((attrDecl == NULL) && (doc->extSubset != NULL))
4090
453
    attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, fullname,
4091
453
            ns->prefix, BAD_CAST "xmlns");
4092
2.24k
  } else {
4093
1.28k
      attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, fullname,
4094
1.28k
                                          BAD_CAST "xmlns", NULL);
4095
1.28k
      if ((attrDecl == NULL) && (doc->extSubset != NULL))
4096
388
    attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, fullname,
4097
388
                                              BAD_CAST "xmlns", NULL);
4098
1.28k
  }
4099
3.53k
  if ((fullname != fn) && (fullname != elem->name))
4100
314
      xmlFree(fullname);
4101
3.53k
    }
4102
150k
    if (attrDecl == NULL) {
4103
150k
  if (ns->prefix != NULL) {
4104
141k
      attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, elem->name,
4105
141k
                              ns->prefix, BAD_CAST "xmlns");
4106
141k
      if ((attrDecl == NULL) && (doc->extSubset != NULL))
4107
1.19k
    attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, elem->name,
4108
1.19k
                ns->prefix, BAD_CAST "xmlns");
4109
141k
  } else {
4110
8.83k
      attrDecl = xmlGetDtdQAttrDesc(doc->intSubset, elem->name,
4111
8.83k
                                          BAD_CAST "xmlns", NULL);
4112
8.83k
      if ((attrDecl == NULL) && (doc->extSubset != NULL))
4113
832
    attrDecl = xmlGetDtdQAttrDesc(doc->extSubset, elem->name,
4114
832
                                              BAD_CAST "xmlns", NULL);
4115
8.83k
  }
4116
150k
    }
4117
4118
4119
    /* Validity Constraint: Attribute Value Type */
4120
150k
    if (attrDecl == NULL) {
4121
5.41k
  if (ns->prefix != NULL) {
4122
3.25k
      xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_ATTRIBUTE,
4123
3.25k
       "No declaration for attribute xmlns:%s of element %s\n",
4124
3.25k
       ns->prefix, elem->name, NULL);
4125
3.25k
  } else {
4126
2.15k
      xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_ATTRIBUTE,
4127
2.15k
       "No declaration for attribute xmlns of element %s\n",
4128
2.15k
       elem->name, NULL, NULL);
4129
2.15k
  }
4130
5.41k
  return(0);
4131
5.41k
    }
4132
4133
145k
    val = xmlValidateAttributeValueInternal(doc, attrDecl->atype, value);
4134
145k
    if (val == 0) {
4135
131k
  if (ns->prefix != NULL) {
4136
130k
      xmlErrValidNode(ctxt, elem, XML_DTD_INVALID_DEFAULT,
4137
130k
         "Syntax of value for attribute xmlns:%s of %s is not valid\n",
4138
130k
       ns->prefix, elem->name, NULL);
4139
130k
  } else {
4140
1.24k
      xmlErrValidNode(ctxt, elem, XML_DTD_INVALID_DEFAULT,
4141
1.24k
         "Syntax of value for attribute xmlns of %s is not valid\n",
4142
1.24k
       elem->name, NULL, NULL);
4143
1.24k
  }
4144
131k
        ret = 0;
4145
131k
    }
4146
4147
    /* Validity constraint: Fixed Attribute Default */
4148
145k
    if (attrDecl->def == XML_ATTRIBUTE_FIXED) {
4149
6.29k
  if (!xmlStrEqual(value, attrDecl->defaultValue)) {
4150
715
      if (ns->prefix != NULL) {
4151
334
    xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_DEFAULT,
4152
334
       "Value for attribute xmlns:%s of %s is different from default \"%s\"\n",
4153
334
           ns->prefix, elem->name, attrDecl->defaultValue);
4154
381
      } else {
4155
381
    xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_DEFAULT,
4156
381
       "Value for attribute xmlns of %s is different from default \"%s\"\n",
4157
381
           elem->name, attrDecl->defaultValue, NULL);
4158
381
      }
4159
715
      ret = 0;
4160
715
  }
4161
6.29k
    }
4162
4163
    /* Validity Constraint: Notation Attributes */
4164
145k
    if (attrDecl->atype == XML_ATTRIBUTE_NOTATION) {
4165
1.37k
        xmlEnumerationPtr tree = attrDecl->tree;
4166
1.37k
        xmlNotationPtr nota;
4167
4168
        /* First check that the given NOTATION was declared */
4169
1.37k
  nota = xmlGetDtdNotationDesc(doc->intSubset, value);
4170
1.37k
  if (nota == NULL)
4171
1.17k
      nota = xmlGetDtdNotationDesc(doc->extSubset, value);
4172
4173
1.37k
  if (nota == NULL) {
4174
1.04k
      if (ns->prefix != NULL) {
4175
452
    xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_NOTATION,
4176
452
       "Value \"%s\" for attribute xmlns:%s of %s is not a declared Notation\n",
4177
452
           value, ns->prefix, elem->name);
4178
588
      } else {
4179
588
    xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_NOTATION,
4180
588
       "Value \"%s\" for attribute xmlns of %s is not a declared Notation\n",
4181
588
           value, elem->name, NULL);
4182
588
      }
4183
1.04k
      ret = 0;
4184
1.04k
        }
4185
4186
  /* Second, verify that it's among the list */
4187
3.10k
  while (tree != NULL) {
4188
1.99k
      if (xmlStrEqual(tree->name, value)) break;
4189
1.72k
      tree = tree->next;
4190
1.72k
  }
4191
1.37k
  if (tree == NULL) {
4192
1.11k
      if (ns->prefix != NULL) {
4193
430
    xmlErrValidNode(ctxt, elem, XML_DTD_NOTATION_VALUE,
4194
430
"Value \"%s\" for attribute xmlns:%s of %s is not among the enumerated notations\n",
4195
430
           value, ns->prefix, elem->name);
4196
681
      } else {
4197
681
    xmlErrValidNode(ctxt, elem, XML_DTD_NOTATION_VALUE,
4198
681
"Value \"%s\" for attribute xmlns of %s is not among the enumerated notations\n",
4199
681
           value, elem->name, NULL);
4200
681
      }
4201
1.11k
      ret = 0;
4202
1.11k
  }
4203
1.37k
    }
4204
4205
    /* Validity Constraint: Enumeration */
4206
145k
    if (attrDecl->atype == XML_ATTRIBUTE_ENUMERATION) {
4207
2.38k
        xmlEnumerationPtr tree = attrDecl->tree;
4208
4.33k
  while (tree != NULL) {
4209
2.46k
      if (xmlStrEqual(tree->name, value)) break;
4210
1.95k
      tree = tree->next;
4211
1.95k
  }
4212
2.38k
  if (tree == NULL) {
4213
1.87k
      if (ns->prefix != NULL) {
4214
872
    xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_VALUE,
4215
872
"Value \"%s\" for attribute xmlns:%s of %s is not among the enumerated set\n",
4216
872
           value, ns->prefix, elem->name);
4217
998
      } else {
4218
998
    xmlErrValidNode(ctxt, elem, XML_DTD_ATTRIBUTE_VALUE,
4219
998
"Value \"%s\" for attribute xmlns of %s is not among the enumerated set\n",
4220
998
           value, elem->name, NULL);
4221
998
      }
4222
1.87k
      ret = 0;
4223
1.87k
  }
4224
2.38k
    }
4225
4226
    /* Fixed Attribute Default */
4227
145k
    if ((attrDecl->def == XML_ATTRIBUTE_FIXED) &&
4228
6.29k
        (!xmlStrEqual(attrDecl->defaultValue, value))) {
4229
715
  if (ns->prefix != NULL) {
4230
334
      xmlErrValidNode(ctxt, elem, XML_DTD_ELEM_NAMESPACE,
4231
334
       "Value for attribute xmlns:%s of %s must be \"%s\"\n",
4232
334
       ns->prefix, elem->name, attrDecl->defaultValue);
4233
381
  } else {
4234
381
      xmlErrValidNode(ctxt, elem, XML_DTD_ELEM_NAMESPACE,
4235
381
       "Value for attribute xmlns of %s must be \"%s\"\n",
4236
381
       elem->name, attrDecl->defaultValue, NULL);
4237
381
  }
4238
715
        ret = 0;
4239
715
    }
4240
4241
    /* Extra check for the attribute value */
4242
145k
    if (ns->prefix != NULL) {
4243
138k
  ret &= xmlValidateAttributeValue2(ctxt, doc, ns->prefix,
4244
138k
            attrDecl->atype, value);
4245
138k
    } else {
4246
6.87k
  ret &= xmlValidateAttributeValue2(ctxt, doc, BAD_CAST "xmlns",
4247
6.87k
            attrDecl->atype, value);
4248
6.87k
    }
4249
4250
145k
    return(ret);
4251
150k
}
4252
4253
#ifndef  LIBXML_REGEXP_ENABLED
4254
/**
4255
 * Skip ignorable elements w.r.t. the validation process
4256
 *
4257
 * @param ctxt  the validation context
4258
 * @param child  the child list
4259
 * @returns the first element to consider for validation of the content model
4260
 */
4261
4262
static xmlNodePtr
4263
xmlValidateSkipIgnorable(xmlNodePtr child) {
4264
    while (child != NULL) {
4265
  switch (child->type) {
4266
      /* These things are ignored (skipped) during validation.  */
4267
      case XML_PI_NODE:
4268
      case XML_COMMENT_NODE:
4269
      case XML_XINCLUDE_START:
4270
      case XML_XINCLUDE_END:
4271
    child = child->next;
4272
    break;
4273
      case XML_TEXT_NODE:
4274
    if (xmlIsBlankNode(child))
4275
        child = child->next;
4276
    else
4277
        return(child);
4278
    break;
4279
      /* keep current node */
4280
      default:
4281
    return(child);
4282
  }
4283
    }
4284
    return(child);
4285
}
4286
4287
/**
4288
 * Try to validate the content model of an element internal function
4289
 *
4290
 * @param ctxt  the validation context
4291
 * @returns 1 if valid or 0 ,-1 in case of error, -2 if an entity
4292
 *           reference is found and -3 if the validation succeeded but
4293
 *           the content model is not determinist.
4294
 */
4295
4296
static int
4297
xmlValidateElementType(xmlValidCtxtPtr ctxt) {
4298
    int ret = -1;
4299
    int determinist = 1;
4300
4301
    NODE = xmlValidateSkipIgnorable(NODE);
4302
    if ((NODE == NULL) && (CONT == NULL))
4303
  return(1);
4304
    if ((NODE == NULL) &&
4305
  ((CONT->ocur == XML_ELEMENT_CONTENT_MULT) ||
4306
   (CONT->ocur == XML_ELEMENT_CONTENT_OPT))) {
4307
  return(1);
4308
    }
4309
    if (CONT == NULL) return(-1);
4310
    if ((NODE != NULL) && (NODE->type == XML_ENTITY_REF_NODE))
4311
  return(-2);
4312
4313
    /*
4314
     * We arrive here when more states need to be examined
4315
     */
4316
cont:
4317
4318
    /*
4319
     * We just recovered from a rollback generated by a possible
4320
     * epsilon transition, go directly to the analysis phase
4321
     */
4322
    if (STATE == ROLLBACK_PARENT) {
4323
  ret = 1;
4324
  goto analyze;
4325
    }
4326
4327
    /*
4328
     * we may have to save a backup state here. This is the equivalent
4329
     * of handling epsilon transition in NFAs.
4330
     */
4331
    if ((CONT != NULL) &&
4332
  ((CONT->parent == NULL) ||
4333
   (CONT->parent == (xmlElementContentPtr) 1) ||
4334
   (CONT->parent->type != XML_ELEMENT_CONTENT_OR)) &&
4335
  ((CONT->ocur == XML_ELEMENT_CONTENT_MULT) ||
4336
   (CONT->ocur == XML_ELEMENT_CONTENT_OPT) ||
4337
   ((CONT->ocur == XML_ELEMENT_CONTENT_PLUS) && (OCCURRENCE)))) {
4338
  if (vstateVPush(ctxt, CONT, NODE, DEPTH, OCCURS, ROLLBACK_PARENT) < 0)
4339
      return(0);
4340
    }
4341
4342
4343
    /*
4344
     * Check first if the content matches
4345
     */
4346
    switch (CONT->type) {
4347
  case XML_ELEMENT_CONTENT_PCDATA:
4348
      if (NODE == NULL) {
4349
    ret = 0;
4350
    break;
4351
      }
4352
      if (NODE->type == XML_TEXT_NODE) {
4353
    /*
4354
     * go to next element in the content model
4355
     * skipping ignorable elems
4356
     */
4357
    do {
4358
        NODE = NODE->next;
4359
        NODE = xmlValidateSkipIgnorable(NODE);
4360
        if ((NODE != NULL) &&
4361
      (NODE->type == XML_ENTITY_REF_NODE))
4362
      return(-2);
4363
    } while ((NODE != NULL) &&
4364
       ((NODE->type != XML_ELEMENT_NODE) &&
4365
        (NODE->type != XML_TEXT_NODE) &&
4366
        (NODE->type != XML_CDATA_SECTION_NODE)));
4367
                ret = 1;
4368
    break;
4369
      } else {
4370
    ret = 0;
4371
    break;
4372
      }
4373
      break;
4374
  case XML_ELEMENT_CONTENT_ELEMENT:
4375
      if (NODE == NULL) {
4376
    ret = 0;
4377
    break;
4378
      }
4379
      ret = ((NODE->type == XML_ELEMENT_NODE) &&
4380
       (xmlStrEqual(NODE->name, CONT->name)));
4381
      if (ret == 1) {
4382
    if ((NODE->ns == NULL) || (NODE->ns->prefix == NULL)) {
4383
        ret = (CONT->prefix == NULL);
4384
    } else if (CONT->prefix == NULL) {
4385
        ret = 0;
4386
    } else {
4387
        ret = xmlStrEqual(NODE->ns->prefix, CONT->prefix);
4388
    }
4389
      }
4390
      if (ret == 1) {
4391
    /*
4392
     * go to next element in the content model
4393
     * skipping ignorable elems
4394
     */
4395
    do {
4396
        NODE = NODE->next;
4397
        NODE = xmlValidateSkipIgnorable(NODE);
4398
        if ((NODE != NULL) &&
4399
      (NODE->type == XML_ENTITY_REF_NODE))
4400
      return(-2);
4401
    } while ((NODE != NULL) &&
4402
       ((NODE->type != XML_ELEMENT_NODE) &&
4403
        (NODE->type != XML_TEXT_NODE) &&
4404
        (NODE->type != XML_CDATA_SECTION_NODE)));
4405
      } else {
4406
    ret = 0;
4407
    break;
4408
      }
4409
      break;
4410
  case XML_ELEMENT_CONTENT_OR:
4411
      /*
4412
       * Small optimization.
4413
       */
4414
      if (CONT->c1->type == XML_ELEMENT_CONTENT_ELEMENT) {
4415
    if ((NODE == NULL) ||
4416
        (!xmlStrEqual(NODE->name, CONT->c1->name))) {
4417
        DEPTH++;
4418
        CONT = CONT->c2;
4419
        goto cont;
4420
    }
4421
    if ((NODE->ns == NULL) || (NODE->ns->prefix == NULL)) {
4422
        ret = (CONT->c1->prefix == NULL);
4423
    } else if (CONT->c1->prefix == NULL) {
4424
        ret = 0;
4425
    } else {
4426
        ret = xmlStrEqual(NODE->ns->prefix, CONT->c1->prefix);
4427
    }
4428
    if (ret == 0) {
4429
        DEPTH++;
4430
        CONT = CONT->c2;
4431
        goto cont;
4432
    }
4433
      }
4434
4435
      /*
4436
       * save the second branch 'or' branch
4437
       */
4438
      if (vstateVPush(ctxt, CONT->c2, NODE, DEPTH + 1,
4439
          OCCURS, ROLLBACK_OR) < 0)
4440
    return(-1);
4441
      DEPTH++;
4442
      CONT = CONT->c1;
4443
      goto cont;
4444
  case XML_ELEMENT_CONTENT_SEQ:
4445
      /*
4446
       * Small optimization.
4447
       */
4448
      if ((CONT->c1->type == XML_ELEMENT_CONTENT_ELEMENT) &&
4449
    ((CONT->c1->ocur == XML_ELEMENT_CONTENT_OPT) ||
4450
     (CONT->c1->ocur == XML_ELEMENT_CONTENT_MULT))) {
4451
    if ((NODE == NULL) ||
4452
        (!xmlStrEqual(NODE->name, CONT->c1->name))) {
4453
        DEPTH++;
4454
        CONT = CONT->c2;
4455
        goto cont;
4456
    }
4457
    if ((NODE->ns == NULL) || (NODE->ns->prefix == NULL)) {
4458
        ret = (CONT->c1->prefix == NULL);
4459
    } else if (CONT->c1->prefix == NULL) {
4460
        ret = 0;
4461
    } else {
4462
        ret = xmlStrEqual(NODE->ns->prefix, CONT->c1->prefix);
4463
    }
4464
    if (ret == 0) {
4465
        DEPTH++;
4466
        CONT = CONT->c2;
4467
        goto cont;
4468
    }
4469
      }
4470
      DEPTH++;
4471
      CONT = CONT->c1;
4472
      goto cont;
4473
    }
4474
4475
    /*
4476
     * At this point handle going up in the tree
4477
     */
4478
    if (ret == -1) {
4479
  return(ret);
4480
    }
4481
analyze:
4482
    while (CONT != NULL) {
4483
  /*
4484
   * First do the analysis depending on the occurrence model at
4485
   * this level.
4486
   */
4487
  if (ret == 0) {
4488
      switch (CONT->ocur) {
4489
    xmlNodePtr cur;
4490
4491
    case XML_ELEMENT_CONTENT_ONCE:
4492
        cur = ctxt->vstate->node;
4493
        if (vstateVPop(ctxt) < 0 ) {
4494
      return(0);
4495
        }
4496
        if (cur != ctxt->vstate->node)
4497
      determinist = -3;
4498
        goto cont;
4499
    case XML_ELEMENT_CONTENT_PLUS:
4500
        if (OCCURRENCE == 0) {
4501
      cur = ctxt->vstate->node;
4502
      if (vstateVPop(ctxt) < 0 ) {
4503
          return(0);
4504
      }
4505
      if (cur != ctxt->vstate->node)
4506
          determinist = -3;
4507
      goto cont;
4508
        }
4509
        ret = 1;
4510
        break;
4511
    case XML_ELEMENT_CONTENT_MULT:
4512
        ret = 1;
4513
        break;
4514
    case XML_ELEMENT_CONTENT_OPT:
4515
        ret = 1;
4516
        break;
4517
      }
4518
  } else {
4519
      switch (CONT->ocur) {
4520
    case XML_ELEMENT_CONTENT_OPT:
4521
        ret = 1;
4522
        break;
4523
    case XML_ELEMENT_CONTENT_ONCE:
4524
        ret = 1;
4525
        break;
4526
    case XML_ELEMENT_CONTENT_PLUS:
4527
        if (STATE == ROLLBACK_PARENT) {
4528
      ret = 1;
4529
      break;
4530
        }
4531
        if (NODE == NULL) {
4532
      ret = 1;
4533
      break;
4534
        }
4535
        SET_OCCURRENCE;
4536
        goto cont;
4537
    case XML_ELEMENT_CONTENT_MULT:
4538
        if (STATE == ROLLBACK_PARENT) {
4539
      ret = 1;
4540
      break;
4541
        }
4542
        if (NODE == NULL) {
4543
      ret = 1;
4544
      break;
4545
        }
4546
        /* SET_OCCURRENCE; */
4547
        goto cont;
4548
      }
4549
  }
4550
  STATE = 0;
4551
4552
  /*
4553
   * Then act accordingly at the parent level
4554
   */
4555
  RESET_OCCURRENCE;
4556
  if ((CONT->parent == NULL) ||
4557
            (CONT->parent == (xmlElementContentPtr) 1))
4558
      break;
4559
4560
  switch (CONT->parent->type) {
4561
      case XML_ELEMENT_CONTENT_PCDATA:
4562
    return(-1);
4563
      case XML_ELEMENT_CONTENT_ELEMENT:
4564
    return(-1);
4565
      case XML_ELEMENT_CONTENT_OR:
4566
    if (ret == 1) {
4567
        CONT = CONT->parent;
4568
        DEPTH--;
4569
    } else {
4570
        CONT = CONT->parent;
4571
        DEPTH--;
4572
    }
4573
    break;
4574
      case XML_ELEMENT_CONTENT_SEQ:
4575
    if (ret == 0) {
4576
        CONT = CONT->parent;
4577
        DEPTH--;
4578
    } else if (CONT == CONT->parent->c1) {
4579
        CONT = CONT->parent->c2;
4580
        goto cont;
4581
    } else {
4582
        CONT = CONT->parent;
4583
        DEPTH--;
4584
    }
4585
  }
4586
    }
4587
    if (NODE != NULL) {
4588
  xmlNodePtr cur;
4589
4590
  cur = ctxt->vstate->node;
4591
  if (vstateVPop(ctxt) < 0 ) {
4592
      return(0);
4593
  }
4594
  if (cur != ctxt->vstate->node)
4595
      determinist = -3;
4596
  goto cont;
4597
    }
4598
    if (ret == 0) {
4599
  xmlNodePtr cur;
4600
4601
  cur = ctxt->vstate->node;
4602
  if (vstateVPop(ctxt) < 0 ) {
4603
      return(0);
4604
  }
4605
  if (cur != ctxt->vstate->node)
4606
      determinist = -3;
4607
  goto cont;
4608
    }
4609
    return(determinist);
4610
}
4611
#endif
4612
4613
/**
4614
 * This will dump the list of elements to the buffer
4615
 * Intended just for the debug routine
4616
 *
4617
 * @param buf  an output buffer
4618
 * @param size  the size of the buffer
4619
 * @param node  an element
4620
 * @param glob  1 if one must print the englobing parenthesis, 0 otherwise
4621
 */
4622
static void
4623
17.0k
xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) {
4624
17.0k
    xmlNodePtr cur;
4625
17.0k
    int len;
4626
4627
17.0k
    if (node == NULL) return;
4628
14.0k
    len = strlen(buf);
4629
14.0k
    if (glob) {
4630
14.0k
        if (size - len < 50) {
4631
0
            if ((size - len > 4) && (buf[len - 1] != '.'))
4632
0
                strcat(buf, " ...");
4633
0
            return;
4634
0
        }
4635
14.0k
        strcat(buf, "(");
4636
14.0k
    }
4637
14.0k
    cur = node;
4638
295k
    while (cur != NULL) {
4639
281k
  len = strlen(buf);
4640
281k
  if (size - len < 50) {
4641
205
      if ((size - len > 4) && (buf[len - 1] != '.'))
4642
205
    strcat(buf, " ...");
4643
205
      return;
4644
205
  }
4645
281k
        switch (cur->type) {
4646
218k
            case XML_ELEMENT_NODE: {
4647
218k
                int qnameLen = xmlStrlen(cur->name);
4648
4649
218k
                if ((cur->ns != NULL) && (cur->ns->prefix != NULL))
4650
1.18k
                    qnameLen += xmlStrlen(cur->ns->prefix) + 1;
4651
218k
                if (size - len < qnameLen + 10) {
4652
207
                    if ((size - len > 4) && (buf[len - 1] != '.'))
4653
207
                        strcat(buf, " ...");
4654
207
                    return;
4655
207
                }
4656
217k
    if ((cur->ns != NULL) && (cur->ns->prefix != NULL)) {
4657
1.18k
        strcat(buf, (char *) cur->ns->prefix);
4658
1.18k
        strcat(buf, ":");
4659
1.18k
    }
4660
217k
                if (cur->name != NULL)
4661
217k
              strcat(buf, (char *) cur->name);
4662
217k
    if (cur->next != NULL)
4663
206k
        strcat(buf, " ");
4664
217k
    break;
4665
218k
            }
4666
60.2k
            case XML_TEXT_NODE:
4667
60.2k
    if (xmlIsBlankNode(cur))
4668
51.2k
        break;
4669
                /* Falls through. */
4670
10.3k
            case XML_CDATA_SECTION_NODE:
4671
11.6k
            case XML_ENTITY_REF_NODE:
4672
11.6k
          strcat(buf, "CDATA");
4673
11.6k
    if (cur->next != NULL)
4674
9.72k
        strcat(buf, " ");
4675
11.6k
    break;
4676
0
            case XML_ATTRIBUTE_NODE:
4677
0
            case XML_DOCUMENT_NODE:
4678
0
      case XML_HTML_DOCUMENT_NODE:
4679
0
            case XML_DOCUMENT_TYPE_NODE:
4680
0
            case XML_DOCUMENT_FRAG_NODE:
4681
0
            case XML_NOTATION_NODE:
4682
0
      case XML_NAMESPACE_DECL:
4683
0
          strcat(buf, "???");
4684
0
    if (cur->next != NULL)
4685
0
        strcat(buf, " ");
4686
0
    break;
4687
0
            case XML_ENTITY_NODE:
4688
235
            case XML_PI_NODE:
4689
235
            case XML_DTD_NODE:
4690
723
            case XML_COMMENT_NODE:
4691
723
      case XML_ELEMENT_DECL:
4692
723
      case XML_ATTRIBUTE_DECL:
4693
723
      case XML_ENTITY_DECL:
4694
723
      case XML_XINCLUDE_START:
4695
723
      case XML_XINCLUDE_END:
4696
723
    break;
4697
281k
  }
4698
281k
  cur = cur->next;
4699
281k
    }
4700
13.6k
    if (glob) {
4701
13.6k
        len = strlen(buf);
4702
13.6k
        if (size - len > 1)
4703
13.6k
            strcat(buf, ")");
4704
13.6k
    }
4705
13.6k
}
4706
4707
/**
4708
 * Try to validate the content model of an element
4709
 *
4710
 * @param ctxt  the validation context
4711
 * @param child  the child list
4712
 * @param elemDecl  pointer to the element declaration
4713
 * @param warn  emit the error message
4714
 * @param parent  the parent element (for error reporting)
4715
 * @returns 1 if valid or 0 if not and -1 in case of error
4716
 */
4717
4718
static int
4719
xmlValidateElementContent(xmlValidCtxtPtr ctxt, xmlNodePtr child,
4720
23.5k
       xmlElementPtr elemDecl, int warn, xmlNodePtr parent) {
4721
23.5k
    int ret = 1;
4722
#ifndef  LIBXML_REGEXP_ENABLED
4723
    xmlNodePtr repl = NULL, last = NULL, tmp;
4724
#endif
4725
23.5k
    xmlNodePtr cur;
4726
23.5k
    xmlElementContentPtr cont;
4727
23.5k
    const xmlChar *name;
4728
4729
23.5k
    if ((elemDecl == NULL) || (parent == NULL) || (ctxt == NULL))
4730
0
  return(-1);
4731
23.5k
    cont = elemDecl->content;
4732
23.5k
    name = elemDecl->name;
4733
4734
23.5k
#ifdef LIBXML_REGEXP_ENABLED
4735
    /* Build the regexp associated to the content model */
4736
23.5k
    if (elemDecl->contModel == NULL)
4737
3.27k
  ret = xmlValidBuildContentModel(ctxt, elemDecl);
4738
23.5k
    if (elemDecl->contModel == NULL) {
4739
830
  return(-1);
4740
22.7k
    } else {
4741
22.7k
  xmlRegExecCtxtPtr exec;
4742
4743
22.7k
  if (!xmlRegexpIsDeterminist(elemDecl->contModel)) {
4744
932
      return(-1);
4745
932
  }
4746
21.7k
  ctxt->nodeMax = 0;
4747
21.7k
  ctxt->nodeNr = 0;
4748
21.7k
  ctxt->nodeTab = NULL;
4749
21.7k
  exec = xmlRegNewExecCtxt(elemDecl->contModel, NULL, NULL);
4750
21.7k
  if (exec == NULL) {
4751
32
            xmlVErrMemory(ctxt);
4752
32
            return(-1);
4753
32
        }
4754
21.7k
        cur = child;
4755
50.1k
        while (cur != NULL) {
4756
32.7k
            switch (cur->type) {
4757
1.50k
                case XML_ENTITY_REF_NODE:
4758
                    /*
4759
                     * Push the current node to be able to roll back
4760
                     * and process within the entity
4761
                     */
4762
1.50k
                    if ((cur->children != NULL) &&
4763
1.21k
                        (cur->children->children != NULL)) {
4764
1.00k
                        if (nodeVPush(ctxt, cur) < 0) {
4765
7
                            ret = -1;
4766
7
                            goto fail;
4767
7
                        }
4768
997
                        cur = cur->children->children;
4769
997
                        continue;
4770
1.00k
                    }
4771
498
                    break;
4772
8.44k
                case XML_TEXT_NODE:
4773
8.44k
                    if (xmlIsBlankNode(cur))
4774
4.47k
                        break;
4775
3.97k
                    ret = 0;
4776
3.97k
                    goto fail;
4777
371
                case XML_CDATA_SECTION_NODE:
4778
                    /* TODO */
4779
371
                    ret = 0;
4780
371
                    goto fail;
4781
22.0k
                case XML_ELEMENT_NODE:
4782
22.0k
                    if ((cur->ns != NULL) && (cur->ns->prefix != NULL)) {
4783
1.04k
                        xmlChar fn[50];
4784
1.04k
                        xmlChar *fullname;
4785
4786
1.04k
                        fullname = xmlBuildQName(cur->name,
4787
1.04k
                                                 cur->ns->prefix, fn, 50);
4788
1.04k
                        if (fullname == NULL) {
4789
8
                            xmlVErrMemory(ctxt);
4790
8
                            ret = -1;
4791
8
                            goto fail;
4792
8
                        }
4793
1.03k
                        ret = xmlRegExecPushString(exec, fullname, NULL);
4794
1.03k
                        if ((fullname != fn) && (fullname != cur->name))
4795
659
                            xmlFree(fullname);
4796
21.0k
                    } else {
4797
21.0k
                        ret = xmlRegExecPushString(exec, cur->name, NULL);
4798
21.0k
                    }
4799
22.0k
                    break;
4800
22.0k
                default:
4801
359
                    break;
4802
32.7k
            }
4803
27.4k
            if (ret == XML_REGEXP_OUT_OF_MEMORY)
4804
294
                xmlVErrMemory(ctxt);
4805
            /*
4806
             * Switch to next element
4807
             */
4808
27.4k
            cur = cur->next;
4809
28.1k
            while (cur == NULL) {
4810
14.0k
                cur = nodeVPop(ctxt);
4811
14.0k
                if (cur == NULL)
4812
13.3k
                    break;
4813
686
                cur = cur->next;
4814
686
            }
4815
27.4k
        }
4816
17.3k
        ret = xmlRegExecPushString(exec, NULL, NULL);
4817
17.3k
        if (ret == XML_REGEXP_OUT_OF_MEMORY)
4818
24
            xmlVErrMemory(ctxt);
4819
21.7k
fail:
4820
21.7k
        xmlRegFreeExecCtxt(exec);
4821
21.7k
    }
4822
#else  /* LIBXML_REGEXP_ENABLED */
4823
    /*
4824
     * Allocate the stack
4825
     */
4826
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
4827
    ctxt->vstateMax = 8;
4828
#else
4829
    ctxt->vstateMax = 1;
4830
#endif
4831
    ctxt->vstateTab = xmlMalloc(ctxt->vstateMax * sizeof(ctxt->vstateTab[0]));
4832
    if (ctxt->vstateTab == NULL) {
4833
  xmlVErrMemory(ctxt);
4834
  return(-1);
4835
    }
4836
    /*
4837
     * The first entry in the stack is reserved to the current state
4838
     */
4839
    ctxt->nodeMax = 0;
4840
    ctxt->nodeNr = 0;
4841
    ctxt->nodeTab = NULL;
4842
    ctxt->vstate = &ctxt->vstateTab[0];
4843
    ctxt->vstateNr = 1;
4844
    CONT = cont;
4845
    NODE = child;
4846
    DEPTH = 0;
4847
    OCCURS = 0;
4848
    STATE = 0;
4849
    ret = xmlValidateElementType(ctxt);
4850
    if ((ret == -3) && (warn)) {
4851
  char expr[5000];
4852
  expr[0] = 0;
4853
  xmlSnprintfElementContent(expr, 5000, elemDecl->content, 1);
4854
  xmlErrValidNode(ctxt, (xmlNodePtr) elemDecl,
4855
                XML_DTD_CONTENT_NOT_DETERMINIST,
4856
          "Content model of %s is not deterministic: %s\n",
4857
          name, BAD_CAST expr, NULL);
4858
    } else if (ret == -2) {
4859
  /*
4860
   * An entities reference appeared at this level.
4861
   * Build a minimal representation of this node content
4862
   * sufficient to run the validation process on it
4863
   */
4864
  cur = child;
4865
  while (cur != NULL) {
4866
      switch (cur->type) {
4867
    case XML_ENTITY_REF_NODE:
4868
        /*
4869
         * Push the current node to be able to roll back
4870
         * and process within the entity
4871
         */
4872
        if ((cur->children != NULL) &&
4873
      (cur->children->children != NULL)) {
4874
      if (nodeVPush(ctxt, cur) < 0) {
4875
                            xmlFreeNodeList(repl);
4876
                            ret = -1;
4877
                            goto done;
4878
                        }
4879
      cur = cur->children->children;
4880
      continue;
4881
        }
4882
        break;
4883
    case XML_TEXT_NODE:
4884
        if (xmlIsBlankNode(cur))
4885
      break;
4886
        /* falls through */
4887
    case XML_CDATA_SECTION_NODE:
4888
    case XML_ELEMENT_NODE:
4889
        /*
4890
         * Allocate a new node and minimally fills in
4891
         * what's required
4892
         */
4893
        tmp = (xmlNodePtr) xmlMalloc(sizeof(xmlNode));
4894
        if (tmp == NULL) {
4895
      xmlVErrMemory(ctxt);
4896
      xmlFreeNodeList(repl);
4897
      ret = -1;
4898
      goto done;
4899
        }
4900
        tmp->type = cur->type;
4901
        tmp->name = cur->name;
4902
        tmp->ns = cur->ns;
4903
        tmp->next = NULL;
4904
        tmp->content = NULL;
4905
        if (repl == NULL)
4906
      repl = last = tmp;
4907
        else {
4908
      last->next = tmp;
4909
      last = tmp;
4910
        }
4911
        if (cur->type == XML_CDATA_SECTION_NODE) {
4912
      /*
4913
       * E59 spaces in CDATA does not match the
4914
       * nonterminal S
4915
       */
4916
      tmp->content = xmlStrdup(BAD_CAST "CDATA");
4917
        }
4918
        break;
4919
    default:
4920
        break;
4921
      }
4922
      /*
4923
       * Switch to next element
4924
       */
4925
      cur = cur->next;
4926
      while (cur == NULL) {
4927
    cur = nodeVPop(ctxt);
4928
    if (cur == NULL)
4929
        break;
4930
    cur = cur->next;
4931
      }
4932
  }
4933
4934
  /*
4935
   * Relaunch the validation
4936
   */
4937
  ctxt->vstate = &ctxt->vstateTab[0];
4938
  ctxt->vstateNr = 1;
4939
  CONT = cont;
4940
  NODE = repl;
4941
  DEPTH = 0;
4942
  OCCURS = 0;
4943
  STATE = 0;
4944
  ret = xmlValidateElementType(ctxt);
4945
    }
4946
#endif /* LIBXML_REGEXP_ENABLED */
4947
21.7k
    if ((warn) && ((ret != 1) && (ret != -3))) {
4948
17.0k
  if (ctxt != NULL) {
4949
17.0k
      char expr[5000];
4950
17.0k
      char list[5000];
4951
4952
17.0k
      expr[0] = 0;
4953
17.0k
      xmlSnprintfElementContent(&expr[0], 5000, cont, 1);
4954
17.0k
      list[0] = 0;
4955
#ifndef LIBXML_REGEXP_ENABLED
4956
      if (repl != NULL)
4957
    xmlSnprintfElements(&list[0], 5000, repl, 1);
4958
      else
4959
#endif /* LIBXML_REGEXP_ENABLED */
4960
17.0k
    xmlSnprintfElements(&list[0], 5000, child, 1);
4961
4962
17.0k
      if (name != NULL) {
4963
17.0k
    xmlErrValidNode(ctxt, parent, XML_DTD_CONTENT_MODEL,
4964
17.0k
     "Element %s content does not follow the DTD, expecting %s, got %s\n",
4965
17.0k
           name, BAD_CAST expr, BAD_CAST list);
4966
17.0k
      } else {
4967
0
    xmlErrValidNode(ctxt, parent, XML_DTD_CONTENT_MODEL,
4968
0
     "Element content does not follow the DTD, expecting %s, got %s\n",
4969
0
           BAD_CAST expr, BAD_CAST list, NULL);
4970
0
      }
4971
17.0k
  } else {
4972
0
      if (name != NULL) {
4973
0
    xmlErrValidNode(ctxt, parent, XML_DTD_CONTENT_MODEL,
4974
0
           "Element %s content does not follow the DTD\n",
4975
0
           name, NULL, NULL);
4976
0
      } else {
4977
0
    xmlErrValidNode(ctxt, parent, XML_DTD_CONTENT_MODEL,
4978
0
           "Element content does not follow the DTD\n",
4979
0
                    NULL, NULL, NULL);
4980
0
      }
4981
0
  }
4982
17.0k
  ret = 0;
4983
17.0k
    }
4984
21.7k
    if (ret == -3)
4985
0
  ret = 1;
4986
4987
#ifndef  LIBXML_REGEXP_ENABLED
4988
done:
4989
    /*
4990
     * Deallocate the copy if done, and free up the validation stack
4991
     */
4992
    while (repl != NULL) {
4993
  tmp = repl->next;
4994
  xmlFree(repl);
4995
  repl = tmp;
4996
    }
4997
    ctxt->vstateMax = 0;
4998
    if (ctxt->vstateTab != NULL) {
4999
  xmlFree(ctxt->vstateTab);
5000
  ctxt->vstateTab = NULL;
5001
    }
5002
#endif
5003
21.7k
    ctxt->nodeMax = 0;
5004
21.7k
    ctxt->nodeNr = 0;
5005
21.7k
    if (ctxt->nodeTab != NULL) {
5006
356
  xmlFree(ctxt->nodeTab);
5007
356
  ctxt->nodeTab = NULL;
5008
356
    }
5009
21.7k
    return(ret);
5010
5011
23.5k
}
5012
5013
/**
5014
 * Check that an element follows \#CDATA.
5015
 *
5016
 * @param ctxt  the validation context
5017
 * @param doc  a document instance
5018
 * @param elem  an element instance
5019
 * @returns 1 if valid or 0 otherwise.
5020
 */
5021
static int
5022
xmlValidateOneCdataElement(xmlValidCtxtPtr ctxt, xmlDocPtr doc,
5023
3.35k
                           xmlNodePtr elem) {
5024
3.35k
    int ret = 1;
5025
3.35k
    xmlNodePtr cur, child;
5026
5027
3.35k
    if ((ctxt == NULL) || (doc == NULL) || (elem == NULL) ||
5028
3.35k
        (elem->type != XML_ELEMENT_NODE))
5029
0
  return(0);
5030
5031
3.35k
    child = elem->children;
5032
5033
3.35k
    cur = child;
5034
191k
    while (cur != NULL) {
5035
189k
  switch (cur->type) {
5036
60.5k
      case XML_ENTITY_REF_NODE:
5037
    /*
5038
     * Push the current node to be able to roll back
5039
     * and process within the entity
5040
     */
5041
60.5k
    if ((cur->children != NULL) &&
5042
60.1k
        (cur->children->children != NULL)) {
5043
57.5k
        if (nodeVPush(ctxt, cur) < 0) {
5044
6
                        ret = 0;
5045
6
                        goto done;
5046
6
                    }
5047
57.5k
        cur = cur->children->children;
5048
57.5k
        continue;
5049
57.5k
    }
5050
3.02k
    break;
5051
3.02k
      case XML_COMMENT_NODE:
5052
22.9k
      case XML_PI_NODE:
5053
118k
      case XML_TEXT_NODE:
5054
127k
      case XML_CDATA_SECTION_NODE:
5055
127k
    break;
5056
620
      default:
5057
620
    ret = 0;
5058
620
    goto done;
5059
189k
  }
5060
  /*
5061
   * Switch to next element
5062
   */
5063
130k
  cur = cur->next;
5064
188k
  while (cur == NULL) {
5065
59.9k
      cur = nodeVPop(ctxt);
5066
59.9k
      if (cur == NULL)
5067
2.38k
    break;
5068
57.5k
      cur = cur->next;
5069
57.5k
  }
5070
130k
    }
5071
3.35k
done:
5072
3.35k
    ctxt->nodeMax = 0;
5073
3.35k
    ctxt->nodeNr = 0;
5074
3.35k
    if (ctxt->nodeTab != NULL) {
5075
295
  xmlFree(ctxt->nodeTab);
5076
295
  ctxt->nodeTab = NULL;
5077
295
    }
5078
3.35k
    return(ret);
5079
3.35k
}
5080
5081
#ifdef LIBXML_REGEXP_ENABLED
5082
/**
5083
 * Check if the given node is part of the content model.
5084
 *
5085
 * @param ctxt  the validation context
5086
 * @param cont  the mixed content model
5087
 * @param qname  the qualified name as appearing in the serialization
5088
 * @returns 1 if yes, 0 if no, -1 in case of error
5089
 */
5090
static int
5091
xmlValidateCheckMixed(xmlValidCtxtPtr ctxt,
5092
0
                xmlElementContentPtr cont, const xmlChar *qname) {
5093
0
    const xmlChar *name;
5094
0
    int plen;
5095
0
    name = xmlSplitQName3(qname, &plen);
5096
5097
0
    if (name == NULL) {
5098
0
  while (cont != NULL) {
5099
0
      if (cont->type == XML_ELEMENT_CONTENT_ELEMENT) {
5100
0
    if ((cont->prefix == NULL) && (xmlStrEqual(cont->name, qname)))
5101
0
        return(1);
5102
0
      } else if ((cont->type == XML_ELEMENT_CONTENT_OR) &&
5103
0
         (cont->c1 != NULL) &&
5104
0
         (cont->c1->type == XML_ELEMENT_CONTENT_ELEMENT)){
5105
0
    if ((cont->c1->prefix == NULL) &&
5106
0
        (xmlStrEqual(cont->c1->name, qname)))
5107
0
        return(1);
5108
0
      } else if ((cont->type != XML_ELEMENT_CONTENT_OR) ||
5109
0
    (cont->c1 == NULL) ||
5110
0
    (cont->c1->type != XML_ELEMENT_CONTENT_PCDATA)){
5111
0
    xmlErrValid(ctxt, XML_DTD_MIXED_CORRUPT,
5112
0
      "Internal: MIXED struct corrupted\n",
5113
0
      NULL);
5114
0
    break;
5115
0
      }
5116
0
      cont = cont->c2;
5117
0
  }
5118
0
    } else {
5119
0
  while (cont != NULL) {
5120
0
      if (cont->type == XML_ELEMENT_CONTENT_ELEMENT) {
5121
0
    if ((cont->prefix != NULL) &&
5122
0
        (xmlStrncmp(cont->prefix, qname, plen) == 0) &&
5123
0
        (xmlStrEqual(cont->name, name)))
5124
0
        return(1);
5125
0
      } else if ((cont->type == XML_ELEMENT_CONTENT_OR) &&
5126
0
         (cont->c1 != NULL) &&
5127
0
         (cont->c1->type == XML_ELEMENT_CONTENT_ELEMENT)){
5128
0
    if ((cont->c1->prefix != NULL) &&
5129
0
        (xmlStrncmp(cont->c1->prefix, qname, plen) == 0) &&
5130
0
        (xmlStrEqual(cont->c1->name, name)))
5131
0
        return(1);
5132
0
      } else if ((cont->type != XML_ELEMENT_CONTENT_OR) ||
5133
0
    (cont->c1 == NULL) ||
5134
0
    (cont->c1->type != XML_ELEMENT_CONTENT_PCDATA)){
5135
0
    xmlErrValid(ctxt, XML_DTD_MIXED_CORRUPT,
5136
0
      "Internal: MIXED struct corrupted\n",
5137
0
      NULL);
5138
0
    break;
5139
0
      }
5140
0
      cont = cont->c2;
5141
0
  }
5142
0
    }
5143
0
    return(0);
5144
0
}
5145
#endif /* LIBXML_REGEXP_ENABLED */
5146
5147
/**
5148
 * Finds a declaration associated to an element in the document.
5149
 *
5150
 * @param ctxt  the validation context
5151
 * @param doc  a document instance
5152
 * @param elem  an element instance
5153
 * @param extsubset  pointer, (out) indicate if the declaration was found
5154
 *              in the external subset.
5155
 * @returns the pointer to the declaration or NULL if not found.
5156
 */
5157
static xmlElementPtr
5158
xmlValidGetElemDecl(xmlValidCtxtPtr ctxt, xmlDocPtr doc,
5159
220k
              xmlNodePtr elem, int *extsubset) {
5160
220k
    xmlElementPtr elemDecl = NULL;
5161
220k
    const xmlChar *prefix = NULL;
5162
5163
220k
    if ((ctxt == NULL) || (doc == NULL) ||
5164
220k
        (elem == NULL) || (elem->name == NULL))
5165
0
        return(NULL);
5166
220k
    if (extsubset != NULL)
5167
220k
  *extsubset = 0;
5168
5169
    /*
5170
     * Fetch the declaration for the qualified name
5171
     */
5172
220k
    if ((elem->ns != NULL) && (elem->ns->prefix != NULL))
5173
7.08k
  prefix = elem->ns->prefix;
5174
5175
220k
    if (prefix != NULL) {
5176
7.08k
  elemDecl = xmlGetDtdQElementDesc(doc->intSubset,
5177
7.08k
                             elem->name, prefix);
5178
7.08k
  if ((elemDecl == NULL) && (doc->extSubset != NULL)) {
5179
1.83k
      elemDecl = xmlGetDtdQElementDesc(doc->extSubset,
5180
1.83k
                                 elem->name, prefix);
5181
1.83k
      if ((elemDecl != NULL) && (extsubset != NULL))
5182
194
    *extsubset = 1;
5183
1.83k
  }
5184
7.08k
    }
5185
5186
    /*
5187
     * Fetch the declaration for the non qualified name
5188
     * This is "non-strict" validation should be done on the
5189
     * full QName but in that case being flexible makes sense.
5190
     */
5191
220k
    if (elemDecl == NULL) {
5192
219k
  elemDecl = xmlGetDtdQElementDesc(doc->intSubset, elem->name, NULL);
5193
219k
  if ((elemDecl == NULL) && (doc->extSubset != NULL)) {
5194
13.3k
      elemDecl = xmlGetDtdQElementDesc(doc->extSubset, elem->name, NULL);
5195
13.3k
      if ((elemDecl != NULL) && (extsubset != NULL))
5196
8.61k
    *extsubset = 1;
5197
13.3k
  }
5198
219k
    }
5199
220k
    if (elemDecl == NULL) {
5200
124k
  xmlErrValidNode(ctxt, elem,
5201
124k
      XML_DTD_UNKNOWN_ELEM,
5202
124k
         "No declaration for element %s\n",
5203
124k
         elem->name, NULL, NULL);
5204
124k
    }
5205
220k
    return(elemDecl);
5206
220k
}
5207
5208
#ifdef LIBXML_REGEXP_ENABLED
5209
/**
5210
 * Push a new element start on the validation stack.
5211
 *
5212
 * @deprecated Internal function, don't use.
5213
 *
5214
 * @param ctxt  the validation context
5215
 * @param doc  a document instance
5216
 * @param elem  an element instance
5217
 * @param qname  the qualified name as appearing in the serialization
5218
 * @returns 1 if no validation problem was found or 0 otherwise.
5219
 */
5220
int
5221
xmlValidatePushElement(xmlValidCtxt *ctxt, xmlDoc *doc,
5222
0
                       xmlNode *elem, const xmlChar *qname) {
5223
0
    int ret = 1;
5224
0
    xmlElementPtr eDecl;
5225
0
    int extsubset = 0;
5226
5227
0
    if (ctxt == NULL)
5228
0
        return(0);
5229
5230
0
    if ((ctxt->vstateNr > 0) && (ctxt->vstate != NULL)) {
5231
0
  xmlValidStatePtr state = ctxt->vstate;
5232
0
  xmlElementPtr elemDecl;
5233
5234
  /*
5235
   * Check the new element against the content model of the new elem.
5236
   */
5237
0
  if (state->elemDecl != NULL) {
5238
0
      elemDecl = state->elemDecl;
5239
5240
0
      switch(elemDecl->etype) {
5241
0
    case XML_ELEMENT_TYPE_UNDEFINED:
5242
0
        ret = 0;
5243
0
        break;
5244
0
    case XML_ELEMENT_TYPE_EMPTY:
5245
0
        xmlErrValidNode(ctxt, state->node,
5246
0
            XML_DTD_NOT_EMPTY,
5247
0
         "Element %s was declared EMPTY this one has content\n",
5248
0
         state->node->name, NULL, NULL);
5249
0
        ret = 0;
5250
0
        break;
5251
0
    case XML_ELEMENT_TYPE_ANY:
5252
        /* I don't think anything is required then */
5253
0
        break;
5254
0
    case XML_ELEMENT_TYPE_MIXED:
5255
        /* simple case of declared as #PCDATA */
5256
0
        if ((elemDecl->content != NULL) &&
5257
0
      (elemDecl->content->type ==
5258
0
       XML_ELEMENT_CONTENT_PCDATA)) {
5259
0
      xmlErrValidNode(ctxt, state->node,
5260
0
          XML_DTD_NOT_PCDATA,
5261
0
         "Element %s was declared #PCDATA but contains non text nodes\n",
5262
0
        state->node->name, NULL, NULL);
5263
0
      ret = 0;
5264
0
        } else {
5265
0
      ret = xmlValidateCheckMixed(ctxt, elemDecl->content,
5266
0
                            qname);
5267
0
      if (ret != 1) {
5268
0
          xmlErrValidNode(ctxt, state->node,
5269
0
              XML_DTD_INVALID_CHILD,
5270
0
         "Element %s is not declared in %s list of possible children\n",
5271
0
            qname, state->node->name, NULL);
5272
0
      }
5273
0
        }
5274
0
        break;
5275
0
    case XML_ELEMENT_TYPE_ELEMENT:
5276
        /*
5277
         * TODO:
5278
         * VC: Standalone Document Declaration
5279
         *     - element types with element content, if white space
5280
         *       occurs directly within any instance of those types.
5281
         */
5282
0
        if (state->exec != NULL) {
5283
0
      ret = xmlRegExecPushString(state->exec, qname, NULL);
5284
0
                        if (ret == XML_REGEXP_OUT_OF_MEMORY) {
5285
0
                            xmlVErrMemory(ctxt);
5286
0
                            return(0);
5287
0
                        }
5288
0
      if (ret < 0) {
5289
0
          xmlErrValidNode(ctxt, state->node,
5290
0
              XML_DTD_CONTENT_MODEL,
5291
0
         "Element %s content does not follow the DTD, Misplaced %s\n",
5292
0
           state->node->name, qname, NULL);
5293
0
          ret = 0;
5294
0
      } else {
5295
0
          ret = 1;
5296
0
      }
5297
0
        }
5298
0
        break;
5299
0
      }
5300
0
  }
5301
0
    }
5302
0
    eDecl = xmlValidGetElemDecl(ctxt, doc, elem, &extsubset);
5303
0
    vstateVPush(ctxt, eDecl, elem);
5304
0
    return(ret);
5305
0
}
5306
5307
/**
5308
 * Check the CData parsed for validation in the current stack.
5309
 *
5310
 * @deprecated Internal function, don't use.
5311
 *
5312
 * @param ctxt  the validation context
5313
 * @param data  some character data read
5314
 * @param len  the length of the data
5315
 * @returns 1 if no validation problem was found or 0 otherwise.
5316
 */
5317
int
5318
0
xmlValidatePushCData(xmlValidCtxt *ctxt, const xmlChar *data, int len) {
5319
0
    int ret = 1;
5320
5321
0
    if (ctxt == NULL)
5322
0
        return(0);
5323
0
    if (len <= 0)
5324
0
  return(ret);
5325
0
    if ((ctxt->vstateNr > 0) && (ctxt->vstate != NULL)) {
5326
0
  xmlValidStatePtr state = ctxt->vstate;
5327
0
  xmlElementPtr elemDecl;
5328
5329
  /*
5330
   * Check the new element against the content model of the new elem.
5331
   */
5332
0
  if (state->elemDecl != NULL) {
5333
0
      elemDecl = state->elemDecl;
5334
5335
0
      switch(elemDecl->etype) {
5336
0
    case XML_ELEMENT_TYPE_UNDEFINED:
5337
0
        ret = 0;
5338
0
        break;
5339
0
    case XML_ELEMENT_TYPE_EMPTY:
5340
0
        xmlErrValidNode(ctxt, state->node,
5341
0
            XML_DTD_NOT_EMPTY,
5342
0
         "Element %s was declared EMPTY this one has content\n",
5343
0
         state->node->name, NULL, NULL);
5344
0
        ret = 0;
5345
0
        break;
5346
0
    case XML_ELEMENT_TYPE_ANY:
5347
0
        break;
5348
0
    case XML_ELEMENT_TYPE_MIXED:
5349
0
        break;
5350
0
    case XML_ELEMENT_TYPE_ELEMENT: {
5351
0
                    int i;
5352
5353
0
                    for (i = 0;i < len;i++) {
5354
0
                        if (!IS_BLANK_CH(data[i])) {
5355
0
                            xmlErrValidNode(ctxt, state->node,
5356
0
                                            XML_DTD_CONTENT_MODEL,
5357
0
       "Element %s content does not follow the DTD, Text not allowed\n",
5358
0
                                   state->node->name, NULL, NULL);
5359
0
                            ret = 0;
5360
0
                            goto done;
5361
0
                        }
5362
0
                    }
5363
                    /*
5364
                     * TODO:
5365
                     * VC: Standalone Document Declaration
5366
                     *  element types with element content, if white space
5367
                     *  occurs directly within any instance of those types.
5368
                     */
5369
0
                    break;
5370
0
                }
5371
0
      }
5372
0
  }
5373
0
    }
5374
0
done:
5375
0
    return(ret);
5376
0
}
5377
5378
/**
5379
 * Pop the element end from the validation stack.
5380
 *
5381
 * @deprecated Internal function, don't use.
5382
 *
5383
 * @param ctxt  the validation context
5384
 * @param doc  a document instance
5385
 * @param elem  an element instance
5386
 * @param qname  the qualified name as appearing in the serialization
5387
 * @returns 1 if no validation problem was found or 0 otherwise.
5388
 */
5389
int
5390
xmlValidatePopElement(xmlValidCtxt *ctxt, xmlDoc *doc ATTRIBUTE_UNUSED,
5391
                      xmlNode *elem ATTRIBUTE_UNUSED,
5392
0
          const xmlChar *qname ATTRIBUTE_UNUSED) {
5393
0
    int ret = 1;
5394
5395
0
    if (ctxt == NULL)
5396
0
        return(0);
5397
5398
0
    if ((ctxt->vstateNr > 0) && (ctxt->vstate != NULL)) {
5399
0
  xmlValidStatePtr state = ctxt->vstate;
5400
0
  xmlElementPtr elemDecl;
5401
5402
  /*
5403
   * Check the new element against the content model of the new elem.
5404
   */
5405
0
  if (state->elemDecl != NULL) {
5406
0
      elemDecl = state->elemDecl;
5407
5408
0
      if (elemDecl->etype == XML_ELEMENT_TYPE_ELEMENT) {
5409
0
    if (state->exec != NULL) {
5410
0
        ret = xmlRegExecPushString(state->exec, NULL, NULL);
5411
0
        if (ret <= 0) {
5412
0
                        if (ret == XML_REGEXP_OUT_OF_MEMORY)
5413
0
                            xmlVErrMemory(ctxt);
5414
0
                        else
5415
0
          xmlErrValidNode(ctxt, state->node,
5416
0
                          XML_DTD_CONTENT_MODEL,
5417
0
     "Element %s content does not follow the DTD, Expecting more children\n",
5418
0
             state->node->name, NULL,NULL);
5419
0
      ret = 0;
5420
0
        } else {
5421
      /*
5422
       * previous validation errors should not generate
5423
       * a new one here
5424
       */
5425
0
      ret = 1;
5426
0
        }
5427
0
    }
5428
0
      }
5429
0
  }
5430
0
  vstateVPop(ctxt);
5431
0
    }
5432
0
    return(ret);
5433
0
}
5434
#endif /* LIBXML_REGEXP_ENABLED */
5435
5436
/**
5437
 * Try to validate a single element and its attributes.
5438
 * Performs the following checks as described by the
5439
 * XML-1.0 recommendation:
5440
 *
5441
 * @deprecated Internal function, don't use.
5442
 *
5443
 * - [ VC: Element Valid ]
5444
 * - [ VC: Required Attribute ]
5445
 *
5446
 * Then calls #xmlValidateOneAttribute for each attribute present.
5447
 *
5448
 * ID/IDREF checks are handled separately.
5449
 *
5450
 * @param ctxt  the validation context
5451
 * @param doc  a document instance
5452
 * @param elem  an element instance
5453
 * @returns 1 if valid or 0 otherwise.
5454
 */
5455
5456
int
5457
xmlValidateOneElement(xmlValidCtxt *ctxt, xmlDoc *doc,
5458
326k
                      xmlNode *elem) {
5459
326k
    xmlElementPtr elemDecl = NULL;
5460
326k
    xmlElementContentPtr cont;
5461
326k
    xmlAttributePtr attr;
5462
326k
    xmlNodePtr child;
5463
326k
    int ret = 1, tmp;
5464
326k
    const xmlChar *name;
5465
326k
    int extsubset = 0;
5466
5467
326k
    CHECK_DTD;
5468
5469
326k
    if (elem == NULL) return(0);
5470
326k
    switch (elem->type) {
5471
68.4k
        case XML_TEXT_NODE:
5472
73.1k
        case XML_CDATA_SECTION_NODE:
5473
90.3k
        case XML_ENTITY_REF_NODE:
5474
97.5k
        case XML_PI_NODE:
5475
105k
        case XML_COMMENT_NODE:
5476
105k
        case XML_XINCLUDE_START:
5477
105k
        case XML_XINCLUDE_END:
5478
105k
      return(1);
5479
220k
        case XML_ELEMENT_NODE:
5480
220k
      break;
5481
0
  default:
5482
0
      xmlErrValidNode(ctxt, elem, XML_ERR_INTERNAL_ERROR,
5483
0
       "unexpected element type\n", NULL, NULL ,NULL);
5484
0
      return(0);
5485
326k
    }
5486
5487
    /*
5488
     * Fetch the declaration
5489
     */
5490
220k
    elemDecl = xmlValidGetElemDecl(ctxt, doc, elem, &extsubset);
5491
220k
    if (elemDecl == NULL)
5492
124k
  return(0);
5493
5494
    /*
5495
     * If vstateNr is not zero that means continuous validation is
5496
     * activated, do not try to check the content model at that level.
5497
     */
5498
96.4k
    if (ctxt->vstateNr == 0) {
5499
    /* Check that the element content matches the definition */
5500
96.4k
    switch (elemDecl->etype) {
5501
58.4k
        case XML_ELEMENT_TYPE_UNDEFINED:
5502
58.4k
      xmlErrValidNode(ctxt, elem, XML_DTD_UNKNOWN_ELEM,
5503
58.4k
                      "No declaration for element %s\n",
5504
58.4k
       elem->name, NULL, NULL);
5505
58.4k
      return(0);
5506
2.31k
        case XML_ELEMENT_TYPE_EMPTY:
5507
2.31k
      if (elem->children != NULL) {
5508
611
    xmlErrValidNode(ctxt, elem, XML_DTD_NOT_EMPTY,
5509
611
         "Element %s was declared EMPTY this one has content\n",
5510
611
                 elem->name, NULL, NULL);
5511
611
    ret = 0;
5512
611
      }
5513
2.31k
      break;
5514
523
        case XML_ELEMENT_TYPE_ANY:
5515
      /* I don't think anything is required then */
5516
523
      break;
5517
11.5k
        case XML_ELEMENT_TYPE_MIXED:
5518
5519
      /* simple case of declared as #PCDATA */
5520
11.5k
      if ((elemDecl->content != NULL) &&
5521
11.5k
    (elemDecl->content->type == XML_ELEMENT_CONTENT_PCDATA)) {
5522
3.35k
    ret = xmlValidateOneCdataElement(ctxt, doc, elem);
5523
3.35k
    if (!ret) {
5524
626
        xmlErrValidNode(ctxt, elem, XML_DTD_NOT_PCDATA,
5525
626
         "Element %s was declared #PCDATA but contains non text nodes\n",
5526
626
         elem->name, NULL, NULL);
5527
626
    }
5528
3.35k
    break;
5529
3.35k
      }
5530
8.23k
      child = elem->children;
5531
      /* Hum, this start to get messy */
5532
35.6k
      while (child != NULL) {
5533
27.4k
          if (child->type == XML_ELEMENT_NODE) {
5534
8.80k
        name = child->name;
5535
8.80k
        if ((child->ns != NULL) && (child->ns->prefix != NULL)) {
5536
1.53k
      xmlChar fn[50];
5537
1.53k
      xmlChar *fullname;
5538
5539
1.53k
      fullname = xmlBuildQName(child->name, child->ns->prefix,
5540
1.53k
                         fn, 50);
5541
1.53k
      if (fullname == NULL) {
5542
6
                            xmlVErrMemory(ctxt);
5543
6
          return(0);
5544
6
                        }
5545
1.52k
      cont = elemDecl->content;
5546
4.65k
      while (cont != NULL) {
5547
3.51k
          if (cont->type == XML_ELEMENT_CONTENT_ELEMENT) {
5548
1.33k
        if (xmlStrEqual(cont->name, fullname))
5549
194
            break;
5550
2.18k
          } else if ((cont->type == XML_ELEMENT_CONTENT_OR) &&
5551
2.18k
             (cont->c1 != NULL) &&
5552
2.18k
             (cont->c1->type == XML_ELEMENT_CONTENT_ELEMENT)){
5553
654
        if (xmlStrEqual(cont->c1->name, fullname))
5554
197
            break;
5555
1.52k
          } else if ((cont->type != XML_ELEMENT_CONTENT_OR) ||
5556
1.52k
        (cont->c1 == NULL) ||
5557
1.52k
        (cont->c1->type != XML_ELEMENT_CONTENT_PCDATA)){
5558
0
        xmlErrValid(ctxt, XML_DTD_MIXED_CORRUPT,
5559
0
          "Internal: MIXED struct corrupted\n",
5560
0
          NULL);
5561
0
        break;
5562
0
          }
5563
3.12k
          cont = cont->c2;
5564
3.12k
      }
5565
1.52k
      if ((fullname != fn) && (fullname != child->name))
5566
609
          xmlFree(fullname);
5567
1.52k
      if (cont != NULL)
5568
391
          goto child_ok;
5569
1.52k
        }
5570
8.40k
        cont = elemDecl->content;
5571
37.4k
        while (cont != NULL) {
5572
35.0k
            if (cont->type == XML_ELEMENT_CONTENT_ELEMENT) {
5573
6.01k
          if (xmlStrEqual(cont->name, name)) break;
5574
29.0k
      } else if ((cont->type == XML_ELEMENT_CONTENT_OR) &&
5575
29.0k
         (cont->c1 != NULL) &&
5576
29.0k
         (cont->c1->type == XML_ELEMENT_CONTENT_ELEMENT)) {
5577
20.6k
          if (xmlStrEqual(cont->c1->name, name)) break;
5578
20.6k
      } else if ((cont->type != XML_ELEMENT_CONTENT_OR) ||
5579
8.40k
          (cont->c1 == NULL) ||
5580
8.40k
          (cont->c1->type != XML_ELEMENT_CONTENT_PCDATA)) {
5581
0
          xmlErrValid(ctxt, XML_DTD_MIXED_CORRUPT,
5582
0
            "Internal: MIXED struct corrupted\n",
5583
0
            NULL);
5584
0
          break;
5585
0
      }
5586
29.0k
      cont = cont->c2;
5587
29.0k
        }
5588
8.40k
        if (cont == NULL) {
5589
2.39k
      xmlErrValidNode(ctxt, elem, XML_DTD_INVALID_CHILD,
5590
2.39k
         "Element %s is not declared in %s list of possible children\n",
5591
2.39k
             name, elem->name, NULL);
5592
2.39k
      ret = 0;
5593
2.39k
        }
5594
8.40k
    }
5595
27.4k
child_ok:
5596
27.4k
          child = child->next;
5597
27.4k
      }
5598
8.22k
      break;
5599
23.5k
        case XML_ELEMENT_TYPE_ELEMENT:
5600
23.5k
      if ((doc->standalone == 1) && (extsubset == 1)) {
5601
    /*
5602
     * VC: Standalone Document Declaration
5603
     *     - element types with element content, if white space
5604
     *       occurs directly within any instance of those types.
5605
     */
5606
884
    child = elem->children;
5607
1.78k
    while (child != NULL) {
5608
1.11k
        if ((child->type == XML_TEXT_NODE) &&
5609
516
                        (child->content != NULL)) {
5610
516
      const xmlChar *content = child->content;
5611
5612
516
      while (IS_BLANK_CH(*content))
5613
709
          content++;
5614
516
      if (*content == 0) {
5615
215
          xmlErrValidNode(ctxt, elem,
5616
215
                          XML_DTD_STANDALONE_WHITE_SPACE,
5617
215
"standalone: %s declared in the external subset contains white spaces nodes\n",
5618
215
           elem->name, NULL, NULL);
5619
215
          ret = 0;
5620
215
          break;
5621
215
      }
5622
516
        }
5623
902
        child =child->next;
5624
902
    }
5625
884
      }
5626
23.5k
      child = elem->children;
5627
23.5k
      cont = elemDecl->content;
5628
23.5k
      tmp = xmlValidateElementContent(ctxt, child, elemDecl, 1, elem);
5629
23.5k
      if (tmp <= 0)
5630
18.8k
    ret = 0;
5631
23.5k
      break;
5632
96.4k
    }
5633
96.4k
    } /* not continuous */
5634
5635
    /* [ VC: Required Attribute ] */
5636
37.9k
    attr = elemDecl->attributes;
5637
141k
    while (attr != NULL) {
5638
103k
  if (attr->def == XML_ATTRIBUTE_REQUIRED) {
5639
4.72k
      int qualified = -1;
5640
5641
4.72k
      if ((attr->prefix == NULL) &&
5642
2.40k
    (xmlStrEqual(attr->name, BAD_CAST "xmlns"))) {
5643
475
    xmlNsPtr ns;
5644
5645
475
    ns = elem->nsDef;
5646
812
    while (ns != NULL) {
5647
531
        if (ns->prefix == NULL)
5648
194
      goto found;
5649
337
        ns = ns->next;
5650
337
    }
5651
4.25k
      } else if (xmlStrEqual(attr->prefix, BAD_CAST "xmlns")) {
5652
490
    xmlNsPtr ns;
5653
5654
490
    ns = elem->nsDef;
5655
691
    while (ns != NULL) {
5656
398
        if (xmlStrEqual(attr->name, ns->prefix))
5657
197
      goto found;
5658
201
        ns = ns->next;
5659
201
    }
5660
3.76k
      } else {
5661
3.76k
    xmlAttrPtr attrib;
5662
5663
3.76k
    attrib = elem->properties;
5664
6.15k
    while (attrib != NULL) {
5665
4.24k
        if (xmlStrEqual(attrib->name, attr->name)) {
5666
3.09k
      if (attr->prefix != NULL) {
5667
1.70k
          xmlNsPtr nameSpace = attrib->ns;
5668
5669
          /*
5670
           * qualified names handling is problematic, having a
5671
           * different prefix should be possible but DTDs don't
5672
           * allow to define the URI instead of the prefix :-(
5673
           */
5674
1.70k
          if (nameSpace == NULL) {
5675
752
        if (qualified < 0)
5676
549
            qualified = 0;
5677
952
          } else if (!xmlStrEqual(nameSpace->prefix,
5678
952
                attr->prefix)) {
5679
492
        if (qualified < 1)
5680
490
            qualified = 1;
5681
492
          } else
5682
460
        goto found;
5683
1.70k
      } else {
5684
          /*
5685
           * We should allow applications to define namespaces
5686
           * for their application even if the DTD doesn't
5687
           * carry one, otherwise, basically we would always
5688
           * break.
5689
           */
5690
1.39k
          goto found;
5691
1.39k
      }
5692
3.09k
        }
5693
2.38k
        attrib = attrib->next;
5694
2.38k
    }
5695
3.76k
      }
5696
2.48k
      if (qualified == -1) {
5697
1.44k
    if (attr->prefix == NULL) {
5698
822
        xmlErrValidNode(ctxt, elem, XML_DTD_MISSING_ATTRIBUTE,
5699
822
           "Element %s does not carry attribute %s\n",
5700
822
         elem->name, attr->name, NULL);
5701
822
        ret = 0;
5702
822
          } else {
5703
624
        xmlErrValidNode(ctxt, elem, XML_DTD_MISSING_ATTRIBUTE,
5704
624
           "Element %s does not carry attribute %s:%s\n",
5705
624
         elem->name, attr->prefix,attr->name);
5706
624
        ret = 0;
5707
624
    }
5708
1.44k
      } else if (qualified == 0) {
5709
549
    if (xmlErrValidWarning(ctxt, elem, XML_DTD_NO_PREFIX,
5710
549
                           "Element %s required attribute %s:%s "
5711
549
                                       "has no prefix\n",
5712
549
                           elem->name, attr->prefix,
5713
549
                                       attr->name) < 0)
5714
293
                    ret = 0;
5715
549
      } else if (qualified == 1) {
5716
490
    if (xmlErrValidWarning(ctxt, elem, XML_DTD_DIFFERENT_PREFIX,
5717
490
                           "Element %s required attribute %s:%s "
5718
490
                                       "has different prefix\n",
5719
490
                           elem->name, attr->prefix,
5720
490
                                       attr->name) < 0)
5721
196
                    ret = 0;
5722
490
      }
5723
2.48k
  }
5724
103k
found:
5725
103k
        attr = attr->nexth;
5726
103k
    }
5727
37.9k
    return(ret);
5728
37.9k
}
5729
5730
/**
5731
 * Try to validate the root element.
5732
 * Performs the following check as described by the
5733
 * XML-1.0 recommendation:
5734
 *
5735
 * @deprecated Internal function, don't use.
5736
 *
5737
 * - [ VC: Root Element Type ]
5738
 *
5739
 * It doesn't try to recurse or apply other checks to the element.
5740
 *
5741
 * @param ctxt  the validation context
5742
 * @param doc  a document instance
5743
 * @returns 1 if valid or 0 otherwise.
5744
 */
5745
5746
int
5747
26.5k
xmlValidateRoot(xmlValidCtxt *ctxt, xmlDoc *doc) {
5748
26.5k
    xmlNodePtr root;
5749
26.5k
    int ret;
5750
5751
26.5k
    if (doc == NULL) return(0);
5752
5753
26.5k
    root = xmlDocGetRootElement(doc);
5754
26.5k
    if ((root == NULL) || (root->name == NULL)) {
5755
3.85k
  xmlErrValid(ctxt, XML_DTD_NO_ROOT,
5756
3.85k
              "no root element\n", NULL);
5757
3.85k
        return(0);
5758
3.85k
    }
5759
5760
    /*
5761
     * When doing post validation against a separate DTD, those may
5762
     * no internal subset has been generated
5763
     */
5764
22.6k
    if ((doc->intSubset != NULL) &&
5765
22.6k
  (doc->intSubset->name != NULL)) {
5766
  /*
5767
   * Check first the document root against the NQName
5768
   */
5769
16.4k
  if (!xmlStrEqual(doc->intSubset->name, root->name)) {
5770
8.44k
      if ((root->ns != NULL) && (root->ns->prefix != NULL)) {
5771
182
    xmlChar fn[50];
5772
182
    xmlChar *fullname;
5773
5774
182
    fullname = xmlBuildQName(root->name, root->ns->prefix, fn, 50);
5775
182
    if (fullname == NULL) {
5776
3
        xmlVErrMemory(ctxt);
5777
3
        return(0);
5778
3
    }
5779
179
    ret = xmlStrEqual(doc->intSubset->name, fullname);
5780
179
    if ((fullname != fn) && (fullname != root->name))
5781
64
        xmlFree(fullname);
5782
179
    if (ret == 1)
5783
92
        goto name_ok;
5784
179
      }
5785
8.35k
      if ((xmlStrEqual(doc->intSubset->name, BAD_CAST "HTML")) &&
5786
17
    (xmlStrEqual(root->name, BAD_CAST "html")))
5787
6
    goto name_ok;
5788
8.34k
      xmlErrValidNode(ctxt, root, XML_DTD_ROOT_NAME,
5789
8.34k
       "root and DTD name do not match '%s' and '%s'\n",
5790
8.34k
       root->name, doc->intSubset->name, NULL);
5791
8.34k
      return(0);
5792
8.35k
  }
5793
16.4k
    }
5794
14.3k
name_ok:
5795
14.3k
    return(1);
5796
22.6k
}
5797
5798
5799
/**
5800
 * Try to validate the subtree under an element.
5801
 *
5802
 * @param ctxt  the validation context
5803
 * @param doc  a document instance
5804
 * @param root  an element instance
5805
 * @returns 1 if valid or 0 otherwise.
5806
 */
5807
5808
int
5809
4.56k
xmlValidateElement(xmlValidCtxt *ctxt, xmlDoc *doc, xmlNode *root) {
5810
4.56k
    xmlNodePtr elem;
5811
4.56k
    xmlAttrPtr attr;
5812
4.56k
    xmlNsPtr ns;
5813
4.56k
    xmlChar *value;
5814
4.56k
    int ret = 1;
5815
5816
4.56k
    if (root == NULL) return(0);
5817
5818
4.56k
    CHECK_DTD;
5819
5820
4.56k
    elem = root;
5821
302k
    while (1) {
5822
302k
        ret &= xmlValidateOneElement(ctxt, doc, elem);
5823
5824
302k
        if (elem->type == XML_ELEMENT_NODE) {
5825
196k
            attr = elem->properties;
5826
305k
            while (attr != NULL) {
5827
108k
                if (attr->children == NULL)
5828
2.12k
                    value = xmlStrdup(BAD_CAST "");
5829
106k
                else
5830
106k
                    value = xmlNodeListGetString(doc, attr->children, 0);
5831
108k
                if (value == NULL) {
5832
56
                    xmlVErrMemory(ctxt);
5833
56
                    ret = 0;
5834
108k
                } else {
5835
108k
                    ret &= xmlValidateOneAttribute(ctxt, doc, elem, attr, value);
5836
108k
                    xmlFree(value);
5837
108k
                }
5838
108k
                attr= attr->next;
5839
108k
            }
5840
5841
196k
            ns = elem->nsDef;
5842
343k
            while (ns != NULL) {
5843
146k
                if (elem->ns == NULL)
5844
128k
                    ret &= xmlValidateOneNamespace(ctxt, doc, elem, NULL,
5845
128k
                                                   ns, ns->href);
5846
18.2k
                else
5847
18.2k
                    ret &= xmlValidateOneNamespace(ctxt, doc, elem,
5848
18.2k
                                                   elem->ns->prefix, ns,
5849
18.2k
                                                   ns->href);
5850
146k
                ns = ns->next;
5851
146k
            }
5852
5853
196k
            if (elem->children != NULL) {
5854
68.4k
                elem = elem->children;
5855
68.4k
                continue;
5856
68.4k
            }
5857
196k
        }
5858
5859
302k
        while (1) {
5860
302k
            if (elem == root)
5861
4.56k
                goto done;
5862
297k
            if (elem->next != NULL)
5863
228k
                break;
5864
68.4k
            elem = elem->parent;
5865
68.4k
        }
5866
228k
        elem = elem->next;
5867
228k
    }
5868
5869
4.56k
done:
5870
4.56k
    return(ret);
5871
4.56k
}
5872
5873
/**
5874
 * @param ref  A reference to be validated
5875
 * @param ctxt  Validation context
5876
 * @param name  Name of ID we are searching for
5877
 */
5878
static void
5879
xmlValidateRef(xmlRefPtr ref, xmlValidCtxtPtr ctxt,
5880
6.26k
                     const xmlChar *name) {
5881
6.26k
    xmlAttrPtr id;
5882
6.26k
    xmlAttrPtr attr;
5883
5884
6.26k
    if (ref == NULL)
5885
0
  return;
5886
6.26k
    if ((ref->attr == NULL) && (ref->name == NULL))
5887
0
  return;
5888
6.26k
    attr = ref->attr;
5889
6.26k
    if (attr == NULL) {
5890
0
  xmlChar *dup, *str = NULL, *cur, save;
5891
5892
0
  dup = xmlStrdup(name);
5893
0
  if (dup == NULL) {
5894
0
            xmlVErrMemory(ctxt);
5895
0
      return;
5896
0
  }
5897
0
  cur = dup;
5898
0
  while (*cur != 0) {
5899
0
      str = cur;
5900
0
      while ((*cur != 0) && (!IS_BLANK_CH(*cur))) cur++;
5901
0
      save = *cur;
5902
0
      *cur = 0;
5903
0
      id = xmlGetID(ctxt->doc, str);
5904
0
      if (id == NULL) {
5905
0
    xmlErrValidNodeNr(ctxt, NULL, XML_DTD_UNKNOWN_ID,
5906
0
     "attribute %s line %d references an unknown ID \"%s\"\n",
5907
0
           ref->name, ref->lineno, str);
5908
0
    ctxt->valid = 0;
5909
0
      }
5910
0
      if (save == 0)
5911
0
    break;
5912
0
      *cur = save;
5913
0
      while (IS_BLANK_CH(*cur)) cur++;
5914
0
  }
5915
0
  xmlFree(dup);
5916
6.26k
    } else if (attr->atype == XML_ATTRIBUTE_IDREF) {
5917
3.76k
  id = xmlGetID(ctxt->doc, name);
5918
3.76k
  if (id == NULL) {
5919
2.69k
      xmlErrValidNode(ctxt, attr->parent, XML_DTD_UNKNOWN_ID,
5920
2.69k
     "IDREF attribute %s references an unknown ID \"%s\"\n",
5921
2.69k
       attr->name, name, NULL);
5922
2.69k
      ctxt->valid = 0;
5923
2.69k
  }
5924
3.76k
    } else if (attr->atype == XML_ATTRIBUTE_IDREFS) {
5925
2.50k
  xmlChar *dup, *str = NULL, *cur, save;
5926
5927
2.50k
  dup = xmlStrdup(name);
5928
2.50k
  if (dup == NULL) {
5929
3
      xmlVErrMemory(ctxt);
5930
3
      ctxt->valid = 0;
5931
3
      return;
5932
3
  }
5933
2.49k
  cur = dup;
5934
24.0k
  while (*cur != 0) {
5935
23.5k
      str = cur;
5936
16.4M
      while ((*cur != 0) && (!IS_BLANK_CH(*cur))) cur++;
5937
23.5k
      save = *cur;
5938
23.5k
      *cur = 0;
5939
23.5k
      id = xmlGetID(ctxt->doc, str);
5940
23.5k
      if (id == NULL) {
5941
23.3k
    xmlErrValidNode(ctxt, attr->parent, XML_DTD_UNKNOWN_ID,
5942
23.3k
     "IDREFS attribute %s references an unknown ID \"%s\"\n",
5943
23.3k
           attr->name, str, NULL);
5944
23.3k
    ctxt->valid = 0;
5945
23.3k
      }
5946
23.5k
      if (save == 0)
5947
1.97k
    break;
5948
21.5k
      *cur = save;
5949
354k
      while (IS_BLANK_CH(*cur)) cur++;
5950
21.5k
  }
5951
2.49k
  xmlFree(dup);
5952
2.49k
    }
5953
6.26k
}
5954
5955
/**
5956
 * @param data  Contents of current link
5957
 * @param user  Value supplied by the user
5958
 * @returns 0 to abort the walk or 1 to continue.
5959
 */
5960
static int
5961
xmlWalkValidateList(const void *data, void *user)
5962
6.26k
{
5963
6.26k
  xmlValidateMemoPtr memo = (xmlValidateMemoPtr)user;
5964
6.26k
  xmlValidateRef((xmlRefPtr)data, memo->ctxt, memo->name);
5965
6.26k
  return 1;
5966
6.26k
}
5967
5968
/**
5969
 * @param payload  list of references
5970
 * @param data  validation context
5971
 * @param name  name of ID we are searching for
5972
 */
5973
static void
5974
812
xmlValidateCheckRefCallback(void *payload, void *data, const xmlChar *name) {
5975
812
    xmlListPtr ref_list = (xmlListPtr) payload;
5976
812
    xmlValidCtxtPtr ctxt = (xmlValidCtxtPtr) data;
5977
812
    xmlValidateMemo memo;
5978
5979
812
    if (ref_list == NULL)
5980
0
  return;
5981
812
    memo.ctxt = ctxt;
5982
812
    memo.name = name;
5983
5984
812
    xmlListWalk(ref_list, xmlWalkValidateList, &memo);
5985
5986
812
}
5987
5988
/**
5989
 * Performs the final step of document validation once all the
5990
 * incremental validation steps have been completed.
5991
 *
5992
 * @deprecated Internal function, don't use.
5993
 *
5994
 * Performs the following checks described by the XML Rec:
5995
 *
5996
 * - Check all the IDREF/IDREFS attributes definition for validity.
5997
 *
5998
 * @param ctxt  the validation context
5999
 * @param doc  a document instance
6000
 * @returns 1 if valid or 0 otherwise.
6001
 */
6002
6003
int
6004
5.13k
xmlValidateDocumentFinal(xmlValidCtxt *ctxt, xmlDoc *doc) {
6005
5.13k
    xmlRefTablePtr table;
6006
5.13k
    xmlParserCtxtPtr pctxt = NULL;
6007
5.13k
    xmlParserInputPtr oldInput = NULL;
6008
6009
5.13k
    if (ctxt == NULL)
6010
0
        return(0);
6011
5.13k
    if (doc == NULL) {
6012
0
        xmlErrValid(ctxt, XML_DTD_NO_DOC,
6013
0
    "xmlValidateDocumentFinal: doc == NULL\n", NULL);
6014
0
  return(0);
6015
0
    }
6016
6017
    /*
6018
     * Check all the NOTATION/NOTATIONS attributes
6019
     */
6020
    /*
6021
     * Check all the ENTITY/ENTITIES attributes definition for validity
6022
     */
6023
    /*
6024
     * Check all the IDREF/IDREFS attributes definition for validity
6025
     */
6026
6027
    /*
6028
     * Don't print line numbers.
6029
     */
6030
5.13k
    if (ctxt->flags & XML_VCTXT_USE_PCTXT) {
6031
5.13k
        pctxt = ctxt->userData;
6032
5.13k
        oldInput = pctxt->input;
6033
5.13k
        pctxt->input = NULL;
6034
5.13k
    }
6035
6036
5.13k
    table = (xmlRefTablePtr) doc->refs;
6037
5.13k
    ctxt->doc = doc;
6038
5.13k
    ctxt->valid = 1;
6039
5.13k
    xmlHashScan(table, xmlValidateCheckRefCallback, ctxt);
6040
6041
5.13k
    if (ctxt->flags & XML_VCTXT_USE_PCTXT)
6042
5.13k
        pctxt->input = oldInput;
6043
6044
5.13k
    return(ctxt->valid);
6045
5.13k
}
6046
6047
/**
6048
 * Try to validate the document against the DTD instance.
6049
 *
6050
 * Note that the internal subset (if present) is de-coupled
6051
 * (i.e. not used), which could cause problems if ID or IDREF
6052
 * attributes are present.
6053
 *
6054
 * @param ctxt  the validation context
6055
 * @param doc  a document instance
6056
 * @param dtd  a DTD instance
6057
 * @returns 1 if valid or 0 otherwise.
6058
 */
6059
6060
int
6061
0
xmlValidateDtd(xmlValidCtxt *ctxt, xmlDoc *doc, xmlDtd *dtd) {
6062
0
    int ret;
6063
0
    xmlDtdPtr oldExt, oldInt;
6064
0
    xmlNodePtr root;
6065
6066
0
    if (dtd == NULL)
6067
0
        return(0);
6068
0
    if (doc == NULL)
6069
0
        return(0);
6070
6071
0
    oldExt = doc->extSubset;
6072
0
    oldInt = doc->intSubset;
6073
0
    doc->extSubset = dtd;
6074
0
    doc->intSubset = NULL;
6075
0
    if (doc->ids != NULL) {
6076
0
        xmlFreeIDTable(doc->ids);
6077
0
        doc->ids = NULL;
6078
0
    }
6079
0
    if (doc->refs != NULL) {
6080
0
        xmlFreeRefTable(doc->refs);
6081
0
        doc->refs = NULL;
6082
0
    }
6083
6084
0
    ret = xmlValidateRoot(ctxt, doc);
6085
0
    if (ret != 0) {
6086
0
        root = xmlDocGetRootElement(doc);
6087
0
        ret = xmlValidateElement(ctxt, doc, root);
6088
0
        ret &= xmlValidateDocumentFinal(ctxt, doc);
6089
0
    }
6090
6091
0
    doc->extSubset = oldExt;
6092
0
    doc->intSubset = oldInt;
6093
0
    if (doc->ids != NULL) {
6094
0
        xmlFreeIDTable(doc->ids);
6095
0
        doc->ids = NULL;
6096
0
    }
6097
0
    if (doc->refs != NULL) {
6098
0
        xmlFreeRefTable(doc->refs);
6099
0
        doc->refs = NULL;
6100
0
    }
6101
6102
0
    return(ret);
6103
0
}
6104
6105
/**
6106
 * Validate a document against a DTD.
6107
 *
6108
 * Like #xmlValidateDtd but uses the parser context's error handler.
6109
 *
6110
 * @since 2.14.0
6111
 *
6112
 * @param ctxt  a parser context
6113
 * @param doc  a document instance
6114
 * @param dtd  a dtd instance
6115
 * @returns 1 if valid or 0 otherwise.
6116
 */
6117
int
6118
0
xmlCtxtValidateDtd(xmlParserCtxt *ctxt, xmlDoc *doc, xmlDtd *dtd) {
6119
0
    if ((ctxt == NULL) || (ctxt->html))
6120
0
        return(0);
6121
6122
0
    xmlCtxtReset(ctxt);
6123
6124
0
    return(xmlValidateDtd(&ctxt->vctxt, doc, dtd));
6125
0
}
6126
6127
static void
6128
xmlValidateNotationCallback(void *payload, void *data,
6129
20.0k
                      const xmlChar *name ATTRIBUTE_UNUSED) {
6130
20.0k
    xmlEntityPtr cur = (xmlEntityPtr) payload;
6131
20.0k
    xmlValidCtxtPtr ctxt = (xmlValidCtxtPtr) data;
6132
20.0k
    if (cur == NULL)
6133
0
  return;
6134
20.0k
    if (cur->etype == XML_EXTERNAL_GENERAL_UNPARSED_ENTITY) {
6135
218
  xmlChar *notation = cur->content;
6136
6137
218
  if (notation != NULL) {
6138
176
      int ret;
6139
6140
176
      ret = xmlValidateNotationUse(ctxt, cur->doc, notation);
6141
176
      if (ret != 1) {
6142
145
    ctxt->valid = 0;
6143
145
      }
6144
176
  }
6145
218
    }
6146
20.0k
}
6147
6148
static void
6149
xmlValidateAttributeCallback(void *payload, void *data,
6150
38.3k
                       const xmlChar *name ATTRIBUTE_UNUSED) {
6151
38.3k
    xmlAttributePtr cur = (xmlAttributePtr) payload;
6152
38.3k
    xmlValidCtxtPtr ctxt = (xmlValidCtxtPtr) data;
6153
38.3k
    xmlDocPtr doc;
6154
38.3k
    xmlElementPtr elem = NULL;
6155
6156
38.3k
    if (cur == NULL)
6157
0
  return;
6158
38.3k
    if (cur->atype == XML_ATTRIBUTE_NOTATION) {
6159
501
        const xmlChar *elemLocalName;
6160
501
        xmlChar *elemPrefix;
6161
6162
501
  doc = cur->doc;
6163
501
  if (cur->elem == NULL) {
6164
0
      xmlErrValid(ctxt, XML_ERR_INTERNAL_ERROR,
6165
0
       "xmlValidateAttributeCallback(%s): internal error\n",
6166
0
       (const char *) cur->name);
6167
0
      return;
6168
0
  }
6169
6170
501
        elemLocalName = xmlSplitQName4(cur->elem, &elemPrefix);
6171
501
        if (elemLocalName == NULL) {
6172
6
            xmlVErrMemory(ctxt);
6173
6
            return;
6174
6
        }
6175
6176
495
  if ((doc != NULL) && (doc->intSubset != NULL))
6177
490
      elem = xmlHashLookup2(doc->intSubset->elements,
6178
490
                                  elemLocalName, elemPrefix);
6179
495
  if ((elem == NULL) && (doc != NULL) && (doc->extSubset != NULL))
6180
143
      elem = xmlHashLookup2(doc->extSubset->elements,
6181
143
                                  elemLocalName, elemPrefix);
6182
495
  if ((elem == NULL) && (cur->parent != NULL) &&
6183
5
      (cur->parent->type == XML_DTD_NODE))
6184
5
      elem = xmlHashLookup2(((xmlDtdPtr) cur->parent)->elements,
6185
5
                                  elemLocalName, elemPrefix);
6186
6187
495
        xmlFree(elemPrefix);
6188
6189
495
  if (elem == NULL) {
6190
0
      xmlErrValidNode(ctxt, NULL, XML_DTD_UNKNOWN_ELEM,
6191
0
       "attribute %s: could not find decl for element %s\n",
6192
0
       cur->name, cur->elem, NULL);
6193
0
      return;
6194
0
  }
6195
495
  if (elem->etype == XML_ELEMENT_TYPE_EMPTY) {
6196
12
      xmlErrValidNode(ctxt, NULL, XML_DTD_EMPTY_NOTATION,
6197
12
       "NOTATION attribute %s declared for EMPTY element %s\n",
6198
12
       cur->name, cur->elem, NULL);
6199
12
      ctxt->valid = 0;
6200
12
  }
6201
495
    }
6202
38.3k
}
6203
6204
/**
6205
 * Performs the final validation steps of DTD content once all the
6206
 * subsets have been parsed.
6207
 *
6208
 * @deprecated Internal function, don't use.
6209
 *
6210
 * Performs the following checks described by the XML Rec:
6211
 *
6212
 * - check that ENTITY and ENTITIES type attributes default or
6213
 *   possible values matches one of the defined entities.
6214
 * - check that NOTATION type attributes default or
6215
 *   possible values matches one of the defined notations.
6216
 *
6217
 * @param ctxt  the validation context
6218
 * @param doc  a document instance
6219
 * @returns 1 if valid or 0 if invalid and -1 if not well-formed.
6220
 */
6221
6222
int
6223
26.5k
xmlValidateDtdFinal(xmlValidCtxt *ctxt, xmlDoc *doc) {
6224
26.5k
    xmlDtdPtr dtd;
6225
26.5k
    xmlAttributeTablePtr table;
6226
26.5k
    xmlEntitiesTablePtr entities;
6227
6228
26.5k
    if ((doc == NULL) || (ctxt == NULL)) return(0);
6229
26.5k
    if ((doc->intSubset == NULL) && (doc->extSubset == NULL))
6230
0
  return(0);
6231
26.5k
    ctxt->doc = doc;
6232
26.5k
    ctxt->valid = 1;
6233
26.5k
    dtd = doc->intSubset;
6234
26.5k
    if ((dtd != NULL) && (dtd->attributes != NULL)) {
6235
10.7k
  table = (xmlAttributeTablePtr) dtd->attributes;
6236
10.7k
  xmlHashScan(table, xmlValidateAttributeCallback, ctxt);
6237
10.7k
    }
6238
26.5k
    if ((dtd != NULL) && (dtd->entities != NULL)) {
6239
10.6k
  entities = (xmlEntitiesTablePtr) dtd->entities;
6240
10.6k
  xmlHashScan(entities, xmlValidateNotationCallback, ctxt);
6241
10.6k
    }
6242
26.5k
    dtd = doc->extSubset;
6243
26.5k
    if ((dtd != NULL) && (dtd->attributes != NULL)) {
6244
749
  table = (xmlAttributeTablePtr) dtd->attributes;
6245
749
  xmlHashScan(table, xmlValidateAttributeCallback, ctxt);
6246
749
    }
6247
26.5k
    if ((dtd != NULL) && (dtd->entities != NULL)) {
6248
317
  entities = (xmlEntitiesTablePtr) dtd->entities;
6249
317
  xmlHashScan(entities, xmlValidateNotationCallback, ctxt);
6250
317
    }
6251
26.5k
    return(ctxt->valid);
6252
26.5k
}
6253
6254
/**
6255
 * Validate a document.
6256
 *
6257
 * @param ctxt  parser context (optional)
6258
 * @param vctxt  validation context (optional)
6259
 * @param doc  document
6260
 * @returns 1 if valid or 0 otherwise.
6261
 */
6262
static int
6263
xmlValidateDocumentInternal(xmlParserCtxtPtr ctxt, xmlValidCtxtPtr vctxt,
6264
16.9k
                            xmlDocPtr doc) {
6265
16.9k
    int ret;
6266
16.9k
    xmlNodePtr root;
6267
6268
16.9k
    if (doc == NULL)
6269
0
        return(0);
6270
16.9k
    if ((doc->intSubset == NULL) && (doc->extSubset == NULL)) {
6271
4.54k
        xmlErrValid(vctxt, XML_DTD_NO_DTD,
6272
4.54k
              "no DTD found!\n", NULL);
6273
4.54k
  return(0);
6274
4.54k
    }
6275
6276
12.4k
    if ((doc->intSubset != NULL) && ((doc->intSubset->SystemID != NULL) ||
6277
9.96k
  (doc->intSubset->ExternalID != NULL)) && (doc->extSubset == NULL)) {
6278
1.91k
  xmlChar *sysID = NULL;
6279
6280
1.91k
  if (doc->intSubset->SystemID != NULL) {
6281
1.90k
            int res;
6282
6283
1.90k
            res = xmlBuildURISafe(doc->intSubset->SystemID, doc->URL, &sysID);
6284
1.90k
            if (res < 0) {
6285
53
                xmlVErrMemory(vctxt);
6286
53
                return 0;
6287
1.85k
            } else if (res != 0) {
6288
114
                xmlErrValid(vctxt, XML_DTD_LOAD_ERROR,
6289
114
      "Could not build URI for external subset \"%s\"\n",
6290
114
      (const char *) doc->intSubset->SystemID);
6291
114
    return 0;
6292
114
      }
6293
1.90k
  }
6294
6295
1.75k
        if (ctxt != NULL) {
6296
1.75k
            xmlParserInputPtr input;
6297
6298
1.75k
            input = xmlLoadResource(ctxt, (const char *) sysID,
6299
1.75k
                    (const char *) doc->intSubset->ExternalID,
6300
1.75k
                    XML_RESOURCE_DTD);
6301
1.75k
            if (input == NULL) {
6302
1.01k
                xmlFree(sysID);
6303
1.01k
                return 0;
6304
1.01k
            }
6305
6306
737
            doc->extSubset = xmlCtxtParseDtd(ctxt, input,
6307
737
                                             doc->intSubset->ExternalID,
6308
737
                                             sysID);
6309
737
        } else {
6310
0
            doc->extSubset = xmlParseDTD(doc->intSubset->ExternalID, sysID);
6311
0
        }
6312
6313
737
  if (sysID != NULL)
6314
737
      xmlFree(sysID);
6315
737
        if (doc->extSubset == NULL) {
6316
643
      if (doc->intSubset->SystemID != NULL) {
6317
643
    xmlErrValid(vctxt, XML_DTD_LOAD_ERROR,
6318
643
           "Could not load the external subset \"%s\"\n",
6319
643
           (const char *) doc->intSubset->SystemID);
6320
643
      } else {
6321
0
    xmlErrValid(vctxt, XML_DTD_LOAD_ERROR,
6322
0
           "Could not load the external subset \"%s\"\n",
6323
0
           (const char *) doc->intSubset->ExternalID);
6324
0
      }
6325
643
      return(0);
6326
643
  }
6327
737
    }
6328
6329
10.5k
    if (doc->ids != NULL) {
6330
288
          xmlFreeIDTable(doc->ids);
6331
288
          doc->ids = NULL;
6332
288
    }
6333
10.5k
    if (doc->refs != NULL) {
6334
175
          xmlFreeRefTable(doc->refs);
6335
175
          doc->refs = NULL;
6336
175
    }
6337
10.5k
    ret = xmlValidateDtdFinal(vctxt, doc);
6338
10.5k
    if (!xmlValidateRoot(vctxt, doc)) return(0);
6339
6340
4.56k
    root = xmlDocGetRootElement(doc);
6341
4.56k
    ret &= xmlValidateElement(vctxt, doc, root);
6342
4.56k
    ret &= xmlValidateDocumentFinal(vctxt, doc);
6343
4.56k
    return(ret);
6344
10.5k
}
6345
6346
/**
6347
 * Try to validate the document instance.
6348
 *
6349
 * @deprecated This function can't report malloc or other failures.
6350
 * Use #xmlCtxtValidateDocument.
6351
 *
6352
 * Performs the all the checks described by the XML Rec,
6353
 * i.e. validates the internal and external subset (if present)
6354
 * and validates the document tree.
6355
 *
6356
 * @param vctxt  the validation context
6357
 * @param doc  a document instance
6358
 * @returns 1 if valid or 0 otherwise.
6359
 */
6360
int
6361
0
xmlValidateDocument(xmlValidCtxt *vctxt, xmlDoc *doc) {
6362
0
    return(xmlValidateDocumentInternal(NULL, vctxt, doc));
6363
0
}
6364
6365
/**
6366
 * Validate a document.
6367
 *
6368
 * Like #xmlValidateDocument but uses the parser context's error handler.
6369
 *
6370
 * Option XML_PARSE_DTDLOAD should be enabled in the parser context
6371
 * to make external entities work.
6372
 *
6373
 * @since 2.14.0
6374
 *
6375
 * @param ctxt  a parser context
6376
 * @param doc  a document instance
6377
 * @returns 1 if valid or 0 otherwise.
6378
 */
6379
int
6380
16.9k
xmlCtxtValidateDocument(xmlParserCtxt *ctxt, xmlDoc *doc) {
6381
16.9k
    if ((ctxt == NULL) || (ctxt->html))
6382
0
        return(0);
6383
6384
16.9k
    xmlCtxtReset(ctxt);
6385
6386
16.9k
    return(xmlValidateDocumentInternal(ctxt, &ctxt->vctxt, doc));
6387
16.9k
}
6388
6389
/************************************************************************
6390
 *                  *
6391
 *    Routines for dynamic validation editing     *
6392
 *                  *
6393
 ************************************************************************/
6394
6395
/**
6396
 * Build/extend a list of  potential children allowed by the content tree
6397
 *
6398
 * @param ctree  an element content tree
6399
 * @param names  an array to store the list of child names
6400
 * @param len  a pointer to the number of element in the list
6401
 * @param max  the size of the array
6402
 * @returns the number of element in the list, or -1 in case of error.
6403
 */
6404
6405
int
6406
xmlValidGetPotentialChildren(xmlElementContent *ctree,
6407
                             const xmlChar **names,
6408
0
                             int *len, int max) {
6409
0
    int i;
6410
6411
0
    if ((ctree == NULL) || (names == NULL) || (len == NULL))
6412
0
        return(-1);
6413
0
    if (*len >= max) return(*len);
6414
6415
0
    switch (ctree->type) {
6416
0
  case XML_ELEMENT_CONTENT_PCDATA:
6417
0
      for (i = 0; i < *len;i++)
6418
0
    if (xmlStrEqual(BAD_CAST "#PCDATA", names[i])) return(*len);
6419
0
      names[(*len)++] = BAD_CAST "#PCDATA";
6420
0
      break;
6421
0
  case XML_ELEMENT_CONTENT_ELEMENT:
6422
0
      for (i = 0; i < *len;i++)
6423
0
    if (xmlStrEqual(ctree->name, names[i])) return(*len);
6424
0
      names[(*len)++] = ctree->name;
6425
0
      break;
6426
0
  case XML_ELEMENT_CONTENT_SEQ:
6427
0
      xmlValidGetPotentialChildren(ctree->c1, names, len, max);
6428
0
      xmlValidGetPotentialChildren(ctree->c2, names, len, max);
6429
0
      break;
6430
0
  case XML_ELEMENT_CONTENT_OR:
6431
0
      xmlValidGetPotentialChildren(ctree->c1, names, len, max);
6432
0
      xmlValidGetPotentialChildren(ctree->c2, names, len, max);
6433
0
      break;
6434
0
   }
6435
6436
0
   return(*len);
6437
0
}
6438
6439
/*
6440
 * Dummy function to suppress messages while we try out valid elements
6441
 */
6442
static void xmlNoValidityErr(void *ctx ATTRIBUTE_UNUSED,
6443
0
                                const char *msg ATTRIBUTE_UNUSED, ...) {
6444
0
}
6445
6446
/**
6447
 * This function returns the list of authorized children to insert
6448
 * within an existing tree while respecting the validity constraints
6449
 * forced by the Dtd. The insertion point is defined using `prev` and
6450
 * `next` in the following ways:
6451
 *  to insert before 'node': xmlValidGetValidElements(node->prev, node, ...
6452
 *  to insert next 'node': xmlValidGetValidElements(node, node->next, ...
6453
 *  to replace 'node': xmlValidGetValidElements(node->prev, node->next, ...
6454
 *  to prepend a child to 'node': xmlValidGetValidElements(NULL, node->childs,
6455
 *  to append a child to 'node': xmlValidGetValidElements(node->last, NULL, ...
6456
 *
6457
 * pointers to the element names are inserted at the beginning of the array
6458
 * and do not need to be freed.
6459
 *
6460
 * @deprecated This feature will be removed.
6461
 *
6462
 * @param prev  an element to insert after
6463
 * @param next  an element to insert next
6464
 * @param names  an array to store the list of child names
6465
 * @param max  the size of the array
6466
 * @returns the number of element in the list, or -1 in case of error. If
6467
 *    the function returns the value `max` the caller is invited to grow the
6468
 *    receiving array and retry.
6469
 */
6470
6471
int
6472
xmlValidGetValidElements(xmlNode *prev, xmlNode *next, const xmlChar **names,
6473
0
                         int max) {
6474
0
    xmlValidCtxt vctxt;
6475
0
    int nb_valid_elements = 0;
6476
0
    const xmlChar *elements[256]={0};
6477
0
    int nb_elements = 0, i;
6478
0
    const xmlChar *name;
6479
6480
0
    xmlNode *ref_node;
6481
0
    xmlNode *parent;
6482
0
    xmlNode *test_node;
6483
6484
0
    xmlNode *prev_next;
6485
0
    xmlNode *next_prev;
6486
0
    xmlNode *parent_childs;
6487
0
    xmlNode *parent_last;
6488
6489
0
    xmlElement *element_desc;
6490
6491
0
    if (prev == NULL && next == NULL)
6492
0
        return(-1);
6493
6494
0
    if (names == NULL) return(-1);
6495
0
    if (max <= 0) return(-1);
6496
6497
0
    memset(&vctxt, 0, sizeof (xmlValidCtxt));
6498
0
    vctxt.error = xmlNoValidityErr; /* this suppresses err/warn output */
6499
6500
0
    nb_valid_elements = 0;
6501
0
    ref_node = prev ? prev : next;
6502
0
    parent = ref_node->parent;
6503
6504
    /*
6505
     * Retrieves the parent element declaration
6506
     */
6507
0
    element_desc = xmlGetDtdElementDesc(parent->doc->intSubset,
6508
0
                                         parent->name);
6509
0
    if ((element_desc == NULL) && (parent->doc->extSubset != NULL))
6510
0
        element_desc = xmlGetDtdElementDesc(parent->doc->extSubset,
6511
0
                                             parent->name);
6512
0
    if (element_desc == NULL) return(-1);
6513
6514
    /*
6515
     * Do a backup of the current tree structure
6516
     */
6517
0
    prev_next = prev ? prev->next : NULL;
6518
0
    next_prev = next ? next->prev : NULL;
6519
0
    parent_childs = parent->children;
6520
0
    parent_last = parent->last;
6521
6522
    /*
6523
     * Creates a dummy node and insert it into the tree
6524
     */
6525
0
    test_node = xmlNewDocNode (ref_node->doc, NULL, BAD_CAST "<!dummy?>", NULL);
6526
0
    if (test_node == NULL)
6527
0
        return(-1);
6528
6529
0
    test_node->parent = parent;
6530
0
    test_node->prev = prev;
6531
0
    test_node->next = next;
6532
0
    name = test_node->name;
6533
6534
0
    if (prev) prev->next = test_node;
6535
0
    else parent->children = test_node;
6536
6537
0
    if (next) next->prev = test_node;
6538
0
    else parent->last = test_node;
6539
6540
    /*
6541
     * Insert each potential child node and check if the parent is
6542
     * still valid
6543
     */
6544
0
    nb_elements = xmlValidGetPotentialChildren(element_desc->content,
6545
0
           elements, &nb_elements, 256);
6546
6547
0
    for (i = 0;i < nb_elements;i++) {
6548
0
  test_node->name = elements[i];
6549
0
  if (xmlValidateOneElement(&vctxt, parent->doc, parent)) {
6550
0
      int j;
6551
6552
0
      for (j = 0; j < nb_valid_elements;j++)
6553
0
    if (xmlStrEqual(elements[i], names[j])) break;
6554
0
      names[nb_valid_elements++] = elements[i];
6555
0
      if (nb_valid_elements >= max) break;
6556
0
  }
6557
0
    }
6558
6559
    /*
6560
     * Restore the tree structure
6561
     */
6562
0
    if (prev) prev->next = prev_next;
6563
0
    if (next) next->prev = next_prev;
6564
0
    parent->children = parent_childs;
6565
0
    parent->last = parent_last;
6566
6567
    /*
6568
     * Free up the dummy node
6569
     */
6570
0
    test_node->name = name;
6571
0
    xmlFreeNode(test_node);
6572
6573
0
    return(nb_valid_elements);
6574
0
}
6575
#endif /* LIBXML_VALID_ENABLED */