Coverage Report

Created: 2026-08-15 06:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/xinclude.c
Line
Count
Source
1
/*
2
 * xinclude.c : Code to implement XInclude processing
3
 *
4
 * World Wide Web Consortium W3C Last Call Working Draft 10 November 2003
5
 * http://www.w3.org/TR/2003/WD-xinclude-20031110
6
 *
7
 * See Copyright for the status of this software.
8
 *
9
 * Author: Daniel Veillard
10
 */
11
12
#define IN_LIBXML
13
#include "libxml.h"
14
15
#include <string.h>
16
#include <libxml/xmlmemory.h>
17
#include <libxml/tree.h>
18
#include <libxml/parser.h>
19
#include <libxml/uri.h>
20
#include <libxml/xpath.h>
21
#include <libxml/xpointer.h>
22
#include <libxml/parserInternals.h>
23
#include <libxml/xmlerror.h>
24
#include <libxml/encoding.h>
25
26
#ifdef LIBXML_XINCLUDE_ENABLED
27
#include <libxml/xinclude.h>
28
29
#include "private/buf.h"
30
#include "private/error.h"
31
#include "private/memory.h"
32
#include "private/parser.h"
33
#include "private/tree.h"
34
#include "private/xinclude.h"
35
36
22.7k
#define XINCLUDE_MAX_DEPTH 40
37
38
/************************************************************************
39
 *                  *
40
 *      XInclude context handling     *
41
 *                  *
42
 ************************************************************************/
43
44
/*
45
 * An XInclude context
46
 */
47
typedef xmlChar *xmlURL;
48
49
typedef struct _xmlXIncludeRef xmlXIncludeRef;
50
typedef xmlXIncludeRef *xmlXIncludeRefPtr;
51
struct _xmlXIncludeRef {
52
    xmlChar              *URI; /* the fully resolved resource URL */
53
    xmlChar         *fragment; /* the fragment in the URI */
54
    xmlChar             *base; /* base URI of xi:include element */
55
    xmlNodePtr           elem; /* the xi:include element */
56
    xmlNodePtr            inc; /* the included copy */
57
    int                   xml; /* xml or txt */
58
    int              fallback; /* fallback was loaded */
59
    int       expanding; /* flag to detect inclusion loops */
60
    int         replace; /* should the node be replaced? */
61
};
62
63
typedef struct _xmlXIncludeDoc xmlXIncludeDoc;
64
typedef xmlXIncludeDoc *xmlXIncludeDocPtr;
65
struct _xmlXIncludeDoc {
66
    xmlDocPtr             doc; /* the parsed document */
67
    xmlChar              *url; /* the URL */
68
    int             expanding; /* flag to detect inclusion loops */
69
};
70
71
typedef struct _xmlXIncludeTxt xmlXIncludeTxt;
72
typedef xmlXIncludeTxt *xmlXIncludeTxtPtr;
73
struct _xmlXIncludeTxt {
74
    xmlChar   *text; /* text string */
75
    xmlChar              *url; /* the URL */
76
};
77
78
struct _xmlXIncludeCtxt {
79
    xmlDocPtr             doc; /* the source document */
80
    int                 incNr; /* number of includes */
81
    int                incMax; /* size of includes tab */
82
    xmlXIncludeRefPtr *incTab; /* array of included references */
83
84
    int                 txtNr; /* number of unparsed documents */
85
    int                txtMax; /* size of unparsed documents tab */
86
    xmlXIncludeTxt    *txtTab; /* array of unparsed documents */
87
88
    int                 urlNr; /* number of documents stacked */
89
    int                urlMax; /* size of document stack */
90
    xmlXIncludeDoc    *urlTab; /* document stack */
91
92
    int              nbErrors; /* the number of errors detected */
93
    int              fatalErr; /* abort processing */
94
    int                 errNo; /* error code */
95
    int                legacy; /* using XINCLUDE_OLD_NS */
96
    int            parseFlags; /* the flags used for parsing XML documents */
97
98
    void            *_private; /* application data */
99
100
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
101
    unsigned long    incTotal; /* total number of processed inclusions */
102
#endif
103
    int     depth; /* recursion depth */
104
    int        isStream; /* streaming mode */
105
106
#ifdef LIBXML_XPTR_ENABLED
107
    xmlXPathContextPtr xpctxt;
108
#endif
109
110
    xmlStructuredErrorFunc errorHandler;
111
    void *errorCtxt;
112
113
    xmlResourceLoader resourceLoader;
114
    void *resourceCtxt;
115
};
116
117
static xmlXIncludeRefPtr
118
xmlXIncludeExpandNode(xmlXIncludeCtxtPtr ctxt, xmlNodePtr node);
119
120
static int
121
xmlXIncludeLoadNode(xmlXIncludeCtxtPtr ctxt, xmlXIncludeRefPtr ref);
122
123
static int
124
xmlXIncludeDoProcess(xmlXIncludeCtxtPtr ctxt, xmlNodePtr tree);
125
126
127
/************************************************************************
128
 *                  *
129
 *      XInclude error handler        *
130
 *                  *
131
 ************************************************************************/
132
133
/**
134
 * Handle an out of memory condition
135
 *
136
 * @param ctxt  an XInclude context
137
 */
138
static void
139
xmlXIncludeErrMemory(xmlXIncludeCtxtPtr ctxt)
140
1.56k
{
141
1.56k
    ctxt->errNo = XML_ERR_NO_MEMORY;
142
1.56k
    ctxt->fatalErr = 1;
143
1.56k
    ctxt->nbErrors++;
144
145
1.56k
    xmlRaiseMemoryError(ctxt->errorHandler, NULL, ctxt->errorCtxt,
146
1.56k
                        XML_FROM_XINCLUDE, NULL);
147
1.56k
}
148
149
/**
150
 * Handle an XInclude error
151
 *
152
 * @param ctxt  the XInclude context
153
 * @param node  the context node
154
 * @param error  the error code
155
 * @param msg  the error message
156
 * @param extra  extra information
157
 */
158
static void LIBXML_ATTR_FORMAT(4,0)
159
xmlXIncludeErr(xmlXIncludeCtxtPtr ctxt, xmlNodePtr node, int error,
160
               const char *msg, const xmlChar *extra)
161
25.6k
{
162
25.6k
    xmlStructuredErrorFunc schannel = NULL;
163
25.6k
    xmlGenericErrorFunc channel = NULL;
164
25.6k
    void *data = NULL;
165
25.6k
    int res;
166
167
25.6k
    if (error == XML_ERR_NO_MEMORY) {
168
100
        xmlXIncludeErrMemory(ctxt);
169
100
        return;
170
100
    }
171
172
25.5k
    if (ctxt->fatalErr != 0)
173
1.97k
        return;
174
23.5k
    ctxt->nbErrors++;
175
176
23.5k
    schannel = ctxt->errorHandler;
177
23.5k
    data = ctxt->errorCtxt;
178
179
23.5k
    if (schannel == NULL) {
180
23.5k
        channel = xmlGenericError;
181
23.5k
        data = xmlGenericErrorContext;
182
23.5k
    }
183
184
23.5k
    res = xmlRaiseError(schannel, channel, data, ctxt, node,
185
23.5k
                        XML_FROM_XINCLUDE, error, XML_ERR_ERROR,
186
23.5k
                        NULL, 0, (const char *) extra, NULL, NULL, 0, 0,
187
23.5k
                        msg, (const char *) extra);
188
23.5k
    if (res < 0) {
189
71
        ctxt->errNo = XML_ERR_NO_MEMORY;
190
71
        ctxt->fatalErr = 1;
191
23.5k
    } else {
192
23.5k
        ctxt->errNo = error;
193
        /*
194
         * Note that we treat IO errors except ENOENT as fatal
195
         * although the XInclude spec could be interpreted in a
196
         * way that at least some IO errors should be handled
197
         * gracefully.
198
         */
199
23.5k
        if (xmlIsCatastrophicError(XML_ERR_FATAL, error))
200
2
            ctxt->fatalErr = 1;
201
23.5k
    }
202
23.5k
}
203
204
/**
205
 * Get an XInclude attribute
206
 *
207
 * @param ctxt  the XInclude context
208
 * @param cur  the node
209
 * @param name  the attribute name
210
 * @returns the value (to be freed) or NULL if not found
211
 */
212
static xmlChar *
213
xmlXIncludeGetProp(xmlXIncludeCtxtPtr ctxt, xmlNodePtr cur,
214
58.3k
                   const xmlChar *name) {
215
58.3k
    xmlChar *ret;
216
217
58.3k
    if (xmlNodeGetAttrValue(cur, name, XINCLUDE_NS, &ret) < 0)
218
1
        xmlXIncludeErrMemory(ctxt);
219
58.3k
    if (ret != NULL)
220
37
        return(ret);
221
222
58.2k
    if (ctxt->legacy != 0) {
223
49.1k
        if (xmlNodeGetAttrValue(cur, name, XINCLUDE_OLD_NS, &ret) < 0)
224
1
            xmlXIncludeErrMemory(ctxt);
225
49.1k
        if (ret != NULL)
226
90
            return(ret);
227
49.1k
    }
228
229
58.2k
    if (xmlNodeGetAttrValue(cur, name, NULL, &ret) < 0)
230
2
        xmlXIncludeErrMemory(ctxt);
231
58.2k
    return(ret);
232
58.2k
}
233
/**
234
 * Free an XInclude reference
235
 *
236
 * @param ref  the XInclude reference
237
 */
238
static void
239
37.8k
xmlXIncludeFreeRef(xmlXIncludeRefPtr ref) {
240
37.8k
    if (ref == NULL)
241
19.7k
  return;
242
18.0k
    if (ref->URI != NULL)
243
18.0k
  xmlFree(ref->URI);
244
18.0k
    if (ref->fragment != NULL)
245
13.4k
  xmlFree(ref->fragment);
246
18.0k
    if (ref->base != NULL)
247
10.9k
  xmlFree(ref->base);
248
18.0k
    xmlFree(ref);
249
18.0k
}
250
251
/**
252
 * Creates a new XInclude context
253
 *
254
 * @param doc  an XML Document
255
 * @returns the new set
256
 */
257
xmlXIncludeCtxt *
258
25.4k
xmlXIncludeNewContext(xmlDoc *doc) {
259
25.4k
    xmlXIncludeCtxtPtr ret;
260
261
25.4k
    if (doc == NULL)
262
8.00k
  return(NULL);
263
17.4k
    ret = (xmlXIncludeCtxtPtr) xmlMalloc(sizeof(xmlXIncludeCtxt));
264
17.4k
    if (ret == NULL)
265
40
  return(NULL);
266
17.3k
    memset(ret, 0, sizeof(xmlXIncludeCtxt));
267
17.3k
    ret->doc = doc;
268
17.3k
    ret->incNr = 0;
269
17.3k
    ret->incMax = 0;
270
17.3k
    ret->incTab = NULL;
271
17.3k
    ret->nbErrors = 0;
272
17.3k
    return(ret);
273
17.4k
}
274
275
/**
276
 * Free an XInclude context
277
 *
278
 * @param ctxt  the XInclude context
279
 */
280
void
281
25.4k
xmlXIncludeFreeContext(xmlXIncludeCtxt *ctxt) {
282
25.4k
    int i;
283
284
25.4k
    if (ctxt == NULL)
285
8.04k
  return;
286
17.3k
    if (ctxt->urlTab != NULL) {
287
5.38k
  for (i = 0; i < ctxt->urlNr; i++) {
288
3.46k
      xmlFreeDoc(ctxt->urlTab[i].doc);
289
3.46k
      xmlFree(ctxt->urlTab[i].url);
290
3.46k
  }
291
1.92k
  xmlFree(ctxt->urlTab);
292
1.92k
    }
293
35.2k
    for (i = 0;i < ctxt->incNr;i++) {
294
17.8k
  if (ctxt->incTab[i] != NULL)
295
17.8k
      xmlXIncludeFreeRef(ctxt->incTab[i]);
296
17.8k
    }
297
17.3k
    if (ctxt->incTab != NULL)
298
8.40k
  xmlFree(ctxt->incTab);
299
17.3k
    if (ctxt->txtTab != NULL) {
300
74
  for (i = 0;i < ctxt->txtNr;i++) {
301
40
      xmlFree(ctxt->txtTab[i].text);
302
40
      xmlFree(ctxt->txtTab[i].url);
303
40
  }
304
34
  xmlFree(ctxt->txtTab);
305
34
    }
306
17.3k
#ifdef LIBXML_XPTR_ENABLED
307
17.3k
    if (ctxt->xpctxt != NULL)
308
6.45k
  xmlXPathFreeContext(ctxt->xpctxt);
309
17.3k
#endif
310
17.3k
    xmlFree(ctxt);
311
17.3k
}
312
313
/**
314
 * parse a document for XInclude
315
 *
316
 * @param ctxt  the XInclude context
317
 * @param URL  the URL or file path
318
 */
319
static xmlDocPtr
320
3.47k
xmlXIncludeParseFile(xmlXIncludeCtxtPtr ctxt, const char *URL) {
321
3.47k
    xmlDocPtr ret = NULL;
322
3.47k
    xmlParserCtxtPtr pctxt;
323
3.47k
    xmlParserInputPtr inputStream;
324
325
3.47k
    xmlInitParser();
326
327
3.47k
    pctxt = xmlNewParserCtxt();
328
3.47k
    if (pctxt == NULL) {
329
15
  xmlXIncludeErrMemory(ctxt);
330
15
  return(NULL);
331
15
    }
332
3.45k
    if (ctxt->errorHandler != NULL)
333
0
        xmlCtxtSetErrorHandler(pctxt, ctxt->errorHandler, ctxt->errorCtxt);
334
3.45k
    if (ctxt->resourceLoader != NULL)
335
3.45k
        xmlCtxtSetResourceLoader(pctxt, ctxt->resourceLoader,
336
3.45k
                                 ctxt->resourceCtxt);
337
338
    /*
339
     * pass in the application data to the parser context.
340
     */
341
3.45k
    pctxt->_private = ctxt->_private;
342
343
    /*
344
     * try to ensure that new documents included are actually
345
     * built with the same dictionary as the including document.
346
     */
347
3.45k
    if ((ctxt->doc != NULL) && (ctxt->doc->dict != NULL)) {
348
2.29k
       if (pctxt->dict != NULL)
349
2.29k
            xmlDictFree(pctxt->dict);
350
2.29k
  pctxt->dict = ctxt->doc->dict;
351
2.29k
  xmlDictReference(pctxt->dict);
352
2.29k
    }
353
354
    /*
355
     * We set DTDLOAD to make sure that ID attributes declared in
356
     * external DTDs are detected.
357
     */
358
3.45k
    xmlCtxtUseOptions(pctxt, ctxt->parseFlags | XML_PARSE_DTDLOAD);
359
360
3.45k
    inputStream = xmlLoadResource(pctxt, URL, NULL, XML_RESOURCE_XINCLUDE);
361
3.45k
    if (inputStream == NULL)
362
2.11k
        goto error;
363
364
1.34k
    if (xmlCtxtPushInput(pctxt, inputStream) < 0) {
365
1
        xmlFreeInputStream(inputStream);
366
1
        goto error;
367
1
    }
368
369
1.33k
    xmlParseDocument(pctxt);
370
371
1.33k
    if (pctxt->wellFormed) {
372
137
        ret = pctxt->myDoc;
373
137
    }
374
1.20k
    else {
375
1.20k
        ret = NULL;
376
1.20k
  if (pctxt->myDoc != NULL)
377
1.19k
      xmlFreeDoc(pctxt->myDoc);
378
1.20k
        pctxt->myDoc = NULL;
379
1.20k
    }
380
381
3.45k
error:
382
3.45k
    if (xmlCtxtIsCatastrophicError(pctxt))
383
101
        xmlXIncludeErr(ctxt, NULL, pctxt->errNo, "parser error", NULL);
384
3.45k
    xmlFreeParserCtxt(pctxt);
385
386
3.45k
    return(ret);
387
1.33k
}
388
389
/**
390
 * Add a new node to process to an XInclude context
391
 *
392
 * @param ctxt  the XInclude context
393
 * @param cur  the new node
394
 */
395
static xmlXIncludeRefPtr
396
19.7k
xmlXIncludeAddNode(xmlXIncludeCtxtPtr ctxt, xmlNodePtr cur) {
397
19.7k
    xmlXIncludeRefPtr ref = NULL;
398
19.7k
    xmlXIncludeRefPtr ret = NULL;
399
19.7k
    xmlURIPtr uri = NULL;
400
19.7k
    xmlChar *href = NULL;
401
19.7k
    xmlChar *parse = NULL;
402
19.7k
    xmlChar *fragment = NULL;
403
19.7k
    xmlChar *base = NULL;
404
19.7k
    xmlChar *tmp;
405
19.7k
    int xml = 1;
406
19.7k
    int local = 0;
407
19.7k
    int res;
408
409
19.7k
    if (ctxt == NULL)
410
0
  return(NULL);
411
19.7k
    if (cur == NULL)
412
0
  return(NULL);
413
414
    /*
415
     * read the attributes
416
     */
417
418
19.7k
    fragment = xmlXIncludeGetProp(ctxt, cur, XINCLUDE_PARSE_XPOINTER);
419
420
19.7k
    href = xmlXIncludeGetProp(ctxt, cur, XINCLUDE_HREF);
421
19.7k
    if (href == NULL) {
422
14.2k
        if (fragment == NULL) {
423
1.34k
      xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_NO_HREF,
424
1.34k
                     "href or xpointer must be present\n", parse);
425
1.34k
      goto error;
426
1.34k
        }
427
428
12.9k
  href = xmlStrdup(BAD_CAST ""); /* @@@@ href is now optional */
429
12.9k
  if (href == NULL) {
430
5
            xmlXIncludeErrMemory(ctxt);
431
5
      goto error;
432
5
        }
433
12.9k
    } else if (xmlStrlen(href) > XML_MAX_URI_LENGTH) {
434
17
        xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_HREF_URI, "URI too long\n",
435
17
                       NULL);
436
17
        goto error;
437
17
    }
438
439
18.3k
    parse = xmlXIncludeGetProp(ctxt, cur, XINCLUDE_PARSE);
440
18.3k
    if (parse != NULL) {
441
704
  if (xmlStrEqual(parse, XINCLUDE_PARSE_XML))
442
150
      xml = 1;
443
554
  else if (xmlStrEqual(parse, XINCLUDE_PARSE_TEXT))
444
516
      xml = 0;
445
38
  else {
446
38
      xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_PARSE_VALUE,
447
38
                     "invalid value %s for 'parse'\n", parse);
448
38
      goto error;
449
38
  }
450
704
    }
451
452
    /*
453
     * Check the URL and remove any fragment identifier
454
     */
455
18.3k
    res = xmlParseURISafe((const char *)href, &uri);
456
18.3k
    if (uri == NULL) {
457
129
        if (res < 0)
458
2
            xmlXIncludeErrMemory(ctxt);
459
127
        else
460
127
            xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_HREF_URI,
461
127
                           "invalid value href %s\n", href);
462
129
        goto error;
463
129
    }
464
465
18.2k
    if (uri->fragment != NULL) {
466
240
        if (ctxt->legacy != 0) {
467
232
      if (fragment == NULL) {
468
201
    fragment = (xmlChar *) uri->fragment;
469
201
      } else {
470
31
    xmlFree(uri->fragment);
471
31
      }
472
232
  } else {
473
8
      xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_FRAGMENT_ID,
474
8
       "Invalid fragment identifier in URI %s use the xpointer attribute\n",
475
8
                           href);
476
8
      goto error;
477
8
  }
478
232
  uri->fragment = NULL;
479
232
    }
480
18.2k
    tmp = xmlSaveUri(uri);
481
18.2k
    if (tmp == NULL) {
482
2
  xmlXIncludeErrMemory(ctxt);
483
2
  goto error;
484
2
    }
485
18.2k
    xmlFree(href);
486
18.2k
    href = tmp;
487
488
    /*
489
     * Resolve URI
490
     */
491
492
18.2k
    if (xmlNodeGetBaseSafe(ctxt->doc, cur, &base) < 0) {
493
4
        xmlXIncludeErrMemory(ctxt);
494
4
        goto error;
495
4
    }
496
497
18.2k
    if (href[0] != 0) {
498
5.19k
        if (xmlBuildURISafe(href, base, &tmp) < 0) {
499
10
            xmlXIncludeErrMemory(ctxt);
500
10
            goto error;
501
10
        }
502
5.18k
        if (tmp == NULL) {
503
34
            xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_HREF_URI,
504
34
                           "failed build URL\n", NULL);
505
34
            goto error;
506
34
        }
507
5.14k
        xmlFree(href);
508
5.14k
        href = tmp;
509
510
5.14k
        if (xmlStrEqual(href, ctxt->doc->URL))
511
28
            local = 1;
512
13.0k
    } else {
513
13.0k
        local = 1;
514
13.0k
    }
515
516
    /*
517
     * If local and xml then we need a fragment
518
     */
519
18.1k
    if ((local == 1) && (xml == 1) &&
520
13.0k
        ((fragment == NULL) || (fragment[0] == 0))) {
521
70
  xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_RECURSION,
522
70
                 "detected a local recursion with no xpointer in %s\n",
523
70
           href);
524
70
  goto error;
525
70
    }
526
527
18.0k
    ref = (xmlXIncludeRefPtr) xmlMalloc(sizeof(xmlXIncludeRef));
528
18.0k
    if (ref == NULL) {
529
3
        xmlXIncludeErrMemory(ctxt);
530
3
        goto error;
531
3
    }
532
18.0k
    memset(ref, 0, sizeof(xmlXIncludeRef));
533
534
18.0k
    ref->elem = cur;
535
18.0k
    ref->xml = xml;
536
18.0k
    ref->URI = href;
537
18.0k
    href = NULL;
538
18.0k
    ref->fragment = fragment;
539
18.0k
    fragment = NULL;
540
541
    /*
542
     * xml:base fixup
543
     */
544
18.0k
    if (((ctxt->parseFlags & XML_PARSE_NOBASEFIX) == 0) &&
545
10.9k
        (cur->doc != NULL) &&
546
10.9k
        ((cur->doc->parseFlags & XML_PARSE_NOBASEFIX) == 0)) {
547
10.9k
        if (base != NULL) {
548
10.5k
            ref->base = base;
549
10.5k
            base = NULL;
550
10.5k
        } else {
551
408
            ref->base = xmlStrdup(BAD_CAST "");
552
408
            if (ref->base == NULL) {
553
1
          xmlXIncludeErrMemory(ctxt);
554
1
                goto error;
555
1
            }
556
408
        }
557
10.9k
    }
558
559
18.0k
    if (ctxt->incNr >= ctxt->incMax) {
560
15.0k
        xmlXIncludeRefPtr *table;
561
15.0k
        int newSize;
562
563
15.0k
        newSize = xmlGrowCapacity(ctxt->incMax, sizeof(table[0]),
564
15.0k
                                  4, XML_MAX_ITEMS);
565
15.0k
        if (newSize < 0) {
566
0
      xmlXIncludeErrMemory(ctxt);
567
0
      goto error;
568
0
  }
569
15.0k
        table = xmlRealloc(ctxt->incTab, newSize * sizeof(table[0]));
570
15.0k
        if (table == NULL) {
571
5
      xmlXIncludeErrMemory(ctxt);
572
5
      goto error;
573
5
  }
574
15.0k
        ctxt->incTab = table;
575
15.0k
        ctxt->incMax = newSize;
576
15.0k
    }
577
18.0k
    ctxt->incTab[ctxt->incNr++] = ref;
578
579
18.0k
    ret = ref;
580
18.0k
    ref = NULL;
581
582
19.7k
error:
583
19.7k
    xmlXIncludeFreeRef(ref);
584
19.7k
    xmlFreeURI(uri);
585
19.7k
    xmlFree(href);
586
19.7k
    xmlFree(parse);
587
19.7k
    xmlFree(fragment);
588
19.7k
    xmlFree(base);
589
19.7k
    return(ret);
590
18.0k
}
591
592
/**
593
 * The XInclude recursive nature is handled at this point.
594
 *
595
 * @param ctxt  the XInclude context
596
 * @param doc  the new document
597
 */
598
static void
599
137
xmlXIncludeRecurseDoc(xmlXIncludeCtxtPtr ctxt, xmlDocPtr doc) {
600
137
    xmlDocPtr oldDoc;
601
137
    xmlXIncludeRefPtr *oldIncTab;
602
137
    int oldIncMax, oldIncNr, oldIsStream;
603
137
    int i;
604
605
137
    oldDoc = ctxt->doc;
606
137
    oldIncMax = ctxt->incMax;
607
137
    oldIncNr = ctxt->incNr;
608
137
    oldIncTab = ctxt->incTab;
609
137
    oldIsStream = ctxt->isStream;
610
137
    ctxt->doc = doc;
611
137
    ctxt->incMax = 0;
612
137
    ctxt->incNr = 0;
613
137
    ctxt->incTab = NULL;
614
137
    ctxt->isStream = 0;
615
616
137
    xmlXIncludeDoProcess(ctxt, xmlDocGetRootElement(doc));
617
618
137
    if (ctxt->incTab != NULL) {
619
318
        for (i = 0; i < ctxt->incNr; i++)
620
237
            xmlXIncludeFreeRef(ctxt->incTab[i]);
621
81
        xmlFree(ctxt->incTab);
622
81
    }
623
624
137
    ctxt->doc = oldDoc;
625
137
    ctxt->incMax = oldIncMax;
626
137
    ctxt->incNr = oldIncNr;
627
137
    ctxt->incTab = oldIncTab;
628
137
    ctxt->isStream = oldIsStream;
629
137
}
630
631
/************************************************************************
632
 *                  *
633
 *      Node copy with specific semantic    *
634
 *                  *
635
 ************************************************************************/
636
637
static void
638
xmlXIncludeBaseFixup(xmlXIncludeCtxtPtr ctxt, xmlNodePtr cur, xmlNodePtr copy,
639
62.3k
                     const xmlChar *targetBase) {
640
62.3k
    xmlChar *base = NULL;
641
62.3k
    xmlChar *relBase = NULL;
642
62.3k
    xmlNs ns;
643
62.3k
    int res;
644
645
62.3k
    if (cur->type != XML_ELEMENT_NODE)
646
11.2k
        return;
647
648
51.1k
    if (xmlNodeGetBaseSafe(cur->doc, cur, &base) < 0)
649
89
        xmlXIncludeErrMemory(ctxt);
650
651
51.1k
    if ((base != NULL) && !xmlStrEqual(base, targetBase)) {
652
19.1k
        if ((xmlStrlen(base) > XML_MAX_URI_LENGTH) ||
653
18.5k
            (xmlStrlen(targetBase) > XML_MAX_URI_LENGTH)) {
654
700
            relBase = xmlStrdup(base);
655
700
            if (relBase == NULL) {
656
1
                xmlXIncludeErrMemory(ctxt);
657
1
                goto done;
658
1
            }
659
18.4k
        } else if (xmlBuildRelativeURISafe(base, targetBase, &relBase) < 0) {
660
30
            xmlXIncludeErrMemory(ctxt);
661
30
            goto done;
662
30
        }
663
19.1k
        if (relBase == NULL) {
664
611
            xmlXIncludeErr(ctxt, cur,
665
611
                    XML_XINCLUDE_HREF_URI,
666
611
                    "Building relative URI failed: %s\n",
667
611
                    base);
668
611
            goto done;
669
611
        }
670
671
        /*
672
         * If the new base doesn't contain a slash, it can be omitted.
673
         */
674
18.5k
        if (xmlStrchr(relBase, '/') != NULL) {
675
16.6k
            res = xmlNodeSetBase(copy, relBase);
676
16.6k
            if (res < 0)
677
19
                xmlXIncludeErrMemory(ctxt);
678
16.6k
            goto done;
679
16.6k
        }
680
18.5k
    }
681
682
    /*
683
     * Delete existing xml:base if bases are equal
684
     */
685
33.8k
    memset(&ns, 0, sizeof(ns));
686
33.8k
    ns.href = XML_XML_NAMESPACE;
687
33.8k
    xmlUnsetNsProp(copy, &ns, BAD_CAST "base");
688
689
51.1k
done:
690
51.1k
    xmlFree(base);
691
51.1k
    xmlFree(relBase);
692
51.1k
}
693
694
/**
695
 * Make a copy of the node while expanding nested XIncludes.
696
 *
697
 * @param ctxt  the XInclude context
698
 * @param elem  the element
699
 * @param copyChildren  copy children instead of node if true
700
 * @param targetBase  the xml:base of the target node
701
 * @returns a node list, not a single node.
702
 */
703
static xmlNodePtr
704
xmlXIncludeCopyNode(xmlXIncludeCtxtPtr ctxt, xmlNodePtr elem,
705
10.1k
                    int copyChildren, const xmlChar *targetBase) {
706
10.1k
    xmlNodePtr result = NULL;
707
10.1k
    xmlNodePtr insertParent = NULL;
708
10.1k
    xmlNodePtr insertLast = NULL;
709
10.1k
    xmlNodePtr cur;
710
10.1k
    xmlNodePtr item;
711
10.1k
    int depth = 0;
712
713
10.1k
    if (copyChildren) {
714
2.37k
        cur = elem->children;
715
2.37k
        if (cur == NULL)
716
0
            return(NULL);
717
7.72k
    } else {
718
7.72k
        cur = elem;
719
7.72k
    }
720
721
152k
    while (1) {
722
152k
        xmlNodePtr copy = NULL;
723
152k
        int recurse = 0;
724
725
152k
        if ((cur->type == XML_DOCUMENT_NODE) ||
726
152k
            (cur->type == XML_DTD_NODE)) {
727
0
            ;
728
152k
        } else if ((cur->type == XML_ELEMENT_NODE) &&
729
126k
                   (cur->ns != NULL) &&
730
47.3k
                   (xmlStrEqual(cur->name, XINCLUDE_NODE)) &&
731
3.21k
                   ((xmlStrEqual(cur->ns->href, XINCLUDE_NS)) ||
732
3.12k
                    (xmlStrEqual(cur->ns->href, XINCLUDE_OLD_NS)))) {
733
3.12k
            xmlXIncludeRefPtr ref = xmlXIncludeExpandNode(ctxt, cur);
734
735
3.12k
            if (ref == NULL)
736
795
                goto error;
737
            /*
738
             * TODO: Insert XML_XINCLUDE_START and XML_XINCLUDE_END nodes
739
             */
740
39.3k
            for (item = ref->inc; item != NULL; item = item->next) {
741
37.0k
                copy = xmlStaticCopyNode(item, ctxt->doc, insertParent, 1);
742
37.0k
                if (copy == NULL) {
743
7
                    xmlXIncludeErrMemory(ctxt);
744
7
                    goto error;
745
7
                }
746
747
37.0k
                if (result == NULL)
748
58
                    result = copy;
749
37.0k
                if (insertLast != NULL) {
750
36.9k
                    insertLast->next = copy;
751
36.9k
                    copy->prev = insertLast;
752
36.9k
                } else if (insertParent != NULL) {
753
55
                    insertParent->children = copy;
754
55
                }
755
37.0k
                insertLast = copy;
756
757
37.0k
                if ((depth == 0) && (targetBase != NULL))
758
23.9k
                    xmlXIncludeBaseFixup(ctxt, item, copy, targetBase);
759
37.0k
            }
760
149k
        } else {
761
149k
            copy = xmlStaticCopyNode(cur, ctxt->doc, insertParent, 2);
762
149k
            if (copy == NULL) {
763
25
                xmlXIncludeErrMemory(ctxt);
764
25
                goto error;
765
25
            }
766
767
149k
            if (result == NULL)
768
9.92k
                result = copy;
769
149k
            if (insertLast != NULL) {
770
97.0k
                insertLast->next = copy;
771
97.0k
                copy->prev = insertLast;
772
97.0k
            } else if (insertParent != NULL) {
773
42.4k
                insertParent->children = copy;
774
42.4k
            }
775
149k
            insertLast = copy;
776
777
149k
            if ((depth == 0) && (targetBase != NULL))
778
38.3k
                xmlXIncludeBaseFixup(ctxt, cur, copy, targetBase);
779
780
149k
            recurse = (cur->type != XML_ENTITY_REF_NODE) &&
781
149k
                      (cur->children != NULL);
782
149k
        }
783
784
151k
        if (recurse) {
785
42.6k
            cur = cur->children;
786
42.6k
            insertParent = insertLast;
787
42.6k
            insertLast = NULL;
788
42.6k
            depth += 1;
789
42.6k
            continue;
790
42.6k
        }
791
792
109k
        if (cur == elem)
793
4.33k
            return(result);
794
795
134k
        while (cur->next == NULL) {
796
34.9k
            if (insertParent != NULL)
797
32.6k
                insertParent->last = insertLast;
798
34.9k
            cur = cur->parent;
799
34.9k
            if (cur == elem)
800
4.94k
                return(result);
801
30.0k
            insertLast = insertParent;
802
30.0k
            insertParent = insertParent->parent;
803
30.0k
            depth -= 1;
804
30.0k
        }
805
806
99.9k
        cur = cur->next;
807
99.9k
    }
808
809
827
error:
810
827
    xmlFreeNodeList(result);
811
827
    return(NULL);
812
10.1k
}
813
814
#ifdef LIBXML_XPTR_ENABLED
815
/**
816
 * Build a node list tree copy of the XPointer result.
817
 * This will drop Attributes and Namespace declarations.
818
 *
819
 * @param ctxt  the XInclude context
820
 * @param obj  the XPointer result from the evaluation.
821
 * @param targetBase  the xml:base of the target node
822
 * @returns an xmlNode list or NULL.
823
 *         the caller has to free the node tree.
824
 */
825
static xmlNodePtr
826
xmlXIncludeCopyXPointer(xmlXIncludeCtxtPtr ctxt, xmlXPathObjectPtr obj,
827
1.40k
                        const xmlChar *targetBase) {
828
1.40k
    xmlNodePtr list = NULL, last = NULL, copy;
829
1.40k
    int i;
830
831
1.40k
    if ((ctxt == NULL) || (obj == NULL))
832
0
  return(NULL);
833
1.40k
    switch (obj->type) {
834
1.40k
        case XPATH_NODESET: {
835
1.40k
      xmlNodeSetPtr set = obj->nodesetval;
836
1.40k
      if (set == NULL)
837
0
    break;
838
8.32k
      for (i = 0;i < set->nodeNr;i++) {
839
7.72k
                xmlNodePtr node;
840
841
7.72k
    if (set->nodeTab[i] == NULL)
842
0
        continue;
843
7.72k
    switch (set->nodeTab[i]->type) {
844
65
        case XML_DOCUMENT_NODE:
845
65
        case XML_HTML_DOCUMENT_NODE:
846
65
                        node = xmlDocGetRootElement(
847
65
                                (xmlDocPtr) set->nodeTab[i]);
848
65
                        if (node == NULL) {
849
0
                            xmlXIncludeErr(ctxt, set->nodeTab[i],
850
0
                                           XML_ERR_INTERNAL_ERROR,
851
0
                                          "document without root\n", NULL);
852
0
                            continue;
853
0
                        }
854
65
                        break;
855
1.48k
                    case XML_TEXT_NODE:
856
1.67k
        case XML_CDATA_SECTION_NODE:
857
7.22k
        case XML_ELEMENT_NODE:
858
7.46k
        case XML_PI_NODE:
859
7.66k
        case XML_COMMENT_NODE:
860
7.66k
                        node = set->nodeTab[i];
861
7.66k
      break;
862
0
                    default:
863
0
                        xmlXIncludeErr(ctxt, set->nodeTab[i],
864
0
                                       XML_XINCLUDE_XPTR_RESULT,
865
0
                                       "invalid node type in XPtr result\n",
866
0
                                       NULL);
867
0
      continue; /* for */
868
7.72k
    }
869
                /*
870
                 * OPTIMIZE TODO: External documents should already be
871
                 * expanded, so xmlDocCopyNode should work as well.
872
                 * xmlXIncludeCopyNode is only required for the initial
873
                 * document.
874
                 */
875
7.72k
    copy = xmlXIncludeCopyNode(ctxt, node, 0, targetBase);
876
7.72k
                if (copy == NULL) {
877
803
                    xmlFreeNodeList(list);
878
803
                    return(NULL);
879
803
                }
880
6.92k
    if (last == NULL) {
881
526
                    list = copy;
882
6.39k
                } else {
883
6.87k
                    while (last->next != NULL)
884
476
                        last = last->next;
885
6.39k
                    copy->prev = last;
886
6.39k
                    last->next = copy;
887
6.39k
    }
888
6.92k
                last = copy;
889
6.92k
      }
890
597
      break;
891
1.40k
  }
892
597
  default:
893
0
      break;
894
1.40k
    }
895
597
    return(list);
896
1.40k
}
897
#endif
898
899
/************************************************************************
900
 *                  *
901
 *      XInclude I/O handling       *
902
 *                  *
903
 ************************************************************************/
904
905
typedef struct _xmlXIncludeMergeData xmlXIncludeMergeData;
906
typedef xmlXIncludeMergeData *xmlXIncludeMergeDataPtr;
907
struct _xmlXIncludeMergeData {
908
    xmlDocPtr doc;
909
    xmlXIncludeCtxtPtr ctxt;
910
};
911
912
/**
913
 * Implements the merge of one entity
914
 *
915
 * @param payload  the entity
916
 * @param vdata  the merge data
917
 * @param name  unused
918
 */
919
static void
920
xmlXIncludeMergeEntity(void *payload, void *vdata,
921
108
                 const xmlChar *name ATTRIBUTE_UNUSED) {
922
108
    xmlEntityPtr ent = (xmlEntityPtr) payload;
923
108
    xmlXIncludeMergeDataPtr data = (xmlXIncludeMergeDataPtr) vdata;
924
108
    xmlEntityPtr ret, prev;
925
108
    xmlDocPtr doc;
926
108
    xmlXIncludeCtxtPtr ctxt;
927
928
108
    if ((ent == NULL) || (data == NULL))
929
0
  return;
930
108
    ctxt = data->ctxt;
931
108
    doc = data->doc;
932
108
    if ((ctxt == NULL) || (doc == NULL))
933
0
  return;
934
108
    switch (ent->etype) {
935
0
        case XML_INTERNAL_PARAMETER_ENTITY:
936
0
        case XML_EXTERNAL_PARAMETER_ENTITY:
937
0
        case XML_INTERNAL_PREDEFINED_ENTITY:
938
0
      return;
939
64
        case XML_INTERNAL_GENERAL_ENTITY:
940
107
        case XML_EXTERNAL_GENERAL_PARSED_ENTITY:
941
108
        case XML_EXTERNAL_GENERAL_UNPARSED_ENTITY:
942
108
      break;
943
108
    }
944
108
    prev = xmlGetDocEntity(doc, ent->name);
945
108
    if (prev == NULL) {
946
96
        ret = xmlAddDocEntity(doc, ent->name, ent->etype, ent->ExternalID,
947
96
                              ent->SystemID, ent->content);
948
96
        if (ret == NULL) {
949
6
            xmlXIncludeErrMemory(ctxt);
950
6
            return;
951
6
        }
952
90
  if (ent->URI != NULL) {
953
35
      ret->URI = xmlStrdup(ent->URI);
954
35
            if (ret->URI == 0)
955
1
                xmlXIncludeErrMemory(ctxt);
956
35
        }
957
90
    } else {
958
12
        if (ent->etype != prev->etype)
959
2
            goto error;
960
961
10
        if ((ent->SystemID != NULL) && (prev->SystemID != NULL)) {
962
2
            if (!xmlStrEqual(ent->SystemID, prev->SystemID))
963
1
                goto error;
964
8
        } else if ((ent->ExternalID != NULL) &&
965
3
                   (prev->ExternalID != NULL)) {
966
3
            if (!xmlStrEqual(ent->ExternalID, prev->ExternalID))
967
2
                goto error;
968
5
        } else if ((ent->content != NULL) && (prev->content != NULL)) {
969
4
            if (!xmlStrEqual(ent->content, prev->content))
970
3
                goto error;
971
4
        } else {
972
1
            goto error;
973
1
        }
974
10
    }
975
93
    return;
976
93
error:
977
9
    switch (ent->etype) {
978
0
        case XML_INTERNAL_PARAMETER_ENTITY:
979
0
        case XML_EXTERNAL_PARAMETER_ENTITY:
980
0
        case XML_INTERNAL_PREDEFINED_ENTITY:
981
3
        case XML_INTERNAL_GENERAL_ENTITY:
982
8
        case XML_EXTERNAL_GENERAL_PARSED_ENTITY:
983
8
      return;
984
1
        case XML_EXTERNAL_GENERAL_UNPARSED_ENTITY:
985
1
      break;
986
9
    }
987
1
    xmlXIncludeErr(ctxt, (xmlNodePtr) ent, XML_XINCLUDE_ENTITY_DEF_MISMATCH,
988
1
                   "mismatch in redefinition of entity %s\n",
989
1
       ent->name);
990
1
}
991
992
/**
993
 * Implements the entity merge
994
 *
995
 * @param ctxt  an XInclude context
996
 * @param doc  the including doc
997
 * @param from  the included doc
998
 * @returns 0 if merge succeeded, -1 if some processing failed
999
 */
1000
static int
1001
xmlXIncludeMergeEntities(xmlXIncludeCtxtPtr ctxt, xmlDocPtr doc,
1002
137
                   xmlDocPtr from) {
1003
137
    xmlNodePtr cur;
1004
137
    xmlDtdPtr target, source;
1005
1006
137
    if (ctxt == NULL)
1007
0
  return(-1);
1008
1009
137
    if ((from == NULL) || (from->intSubset == NULL))
1010
64
  return(0);
1011
1012
73
    target = doc->intSubset;
1013
73
    if (target == NULL) {
1014
51
  cur = xmlDocGetRootElement(doc);
1015
51
  if (cur == NULL)
1016
0
      return(-1);
1017
51
        target = xmlCreateIntSubset(doc, cur->name, NULL, NULL);
1018
51
  if (target == NULL) {
1019
1
            xmlXIncludeErrMemory(ctxt);
1020
1
      return(-1);
1021
1
        }
1022
51
    }
1023
1024
72
    source = from->intSubset;
1025
72
    if ((source != NULL) && (source->entities != NULL)) {
1026
36
  xmlXIncludeMergeData data;
1027
1028
36
  data.ctxt = ctxt;
1029
36
  data.doc = doc;
1030
1031
36
  xmlHashScan((xmlHashTablePtr) source->entities,
1032
36
        xmlXIncludeMergeEntity, &data);
1033
36
    }
1034
72
    source = from->extSubset;
1035
72
    if ((source != NULL) && (source->entities != NULL)) {
1036
4
  xmlXIncludeMergeData data;
1037
1038
4
  data.ctxt = ctxt;
1039
4
  data.doc = doc;
1040
1041
  /*
1042
   * don't duplicate existing stuff when external subsets are the same
1043
   */
1044
4
  if ((!xmlStrEqual(target->ExternalID, source->ExternalID)) &&
1045
0
      (!xmlStrEqual(target->SystemID, source->SystemID))) {
1046
0
      xmlHashScan((xmlHashTablePtr) source->entities,
1047
0
      xmlXIncludeMergeEntity, &data);
1048
0
  }
1049
4
    }
1050
72
    return(0);
1051
73
}
1052
1053
/**
1054
 * Load the document, and store the result in the XInclude context
1055
 *
1056
 * @param ctxt  the XInclude context
1057
 * @param ref  an XMLXincludeRefPtr
1058
 * @returns 0 in case of success, -1 in case of failure
1059
 */
1060
static int
1061
17.5k
xmlXIncludeLoadDoc(xmlXIncludeCtxtPtr ctxt, xmlXIncludeRefPtr ref) {
1062
17.5k
    xmlXIncludeDocPtr cache;
1063
17.5k
    xmlDocPtr doc;
1064
17.5k
    const xmlChar *url = ref->URI;
1065
17.5k
    const xmlChar *fragment = ref->fragment;
1066
17.5k
    int i = 0;
1067
17.5k
    int ret = -1;
1068
17.5k
    int cacheNr;
1069
17.5k
#ifdef LIBXML_XPTR_ENABLED
1070
17.5k
    int saveFlags;
1071
17.5k
#endif
1072
1073
    /*
1074
     * Handling of references to the local document are done
1075
     * directly through ctxt->doc.
1076
     */
1077
17.5k
    if ((url[0] == 0) || (url[0] == '#') ||
1078
13.0k
  ((ctxt->doc != NULL) && (xmlStrEqual(url, ctxt->doc->URL)))) {
1079
13.0k
  doc = ctxt->doc;
1080
13.0k
        goto loaded;
1081
13.0k
    }
1082
1083
    /*
1084
     * Prevent reloading the document twice.
1085
     */
1086
8.56k
    for (i = 0; i < ctxt->urlNr; i++) {
1087
5.09k
  if (xmlStrEqual(url, ctxt->urlTab[i].url)) {
1088
1.04k
            if (ctxt->urlTab[i].expanding) {
1089
86
                xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_RECURSION,
1090
86
                               "inclusion loop detected\n", NULL);
1091
86
                goto error;
1092
86
            }
1093
962
      doc = ctxt->urlTab[i].doc;
1094
962
            if (doc == NULL)
1095
905
                goto error;
1096
57
      goto loaded;
1097
962
  }
1098
5.09k
    }
1099
1100
    /*
1101
     * Load it.
1102
     */
1103
3.47k
#ifdef LIBXML_XPTR_ENABLED
1104
    /*
1105
     * If this is an XPointer evaluation, we want to assure that
1106
     * all entities have been resolved prior to processing the
1107
     * referenced document
1108
     */
1109
3.47k
    saveFlags = ctxt->parseFlags;
1110
3.47k
    if (fragment != NULL) { /* if this is an XPointer eval */
1111
394
  ctxt->parseFlags |= XML_PARSE_NOENT;
1112
394
    }
1113
3.47k
#endif
1114
1115
3.47k
    doc = xmlXIncludeParseFile(ctxt, (const char *)url);
1116
3.47k
#ifdef LIBXML_XPTR_ENABLED
1117
3.47k
    ctxt->parseFlags = saveFlags;
1118
3.47k
#endif
1119
1120
    /* Also cache NULL docs */
1121
3.47k
    if (ctxt->urlNr >= ctxt->urlMax) {
1122
3.32k
        xmlXIncludeDoc *tmp;
1123
3.32k
        int newSize;
1124
1125
3.32k
        newSize = xmlGrowCapacity(ctxt->urlMax, sizeof(tmp[0]),
1126
3.32k
                                  8, XML_MAX_ITEMS);
1127
3.32k
        if (newSize < 0) {
1128
0
            xmlXIncludeErrMemory(ctxt);
1129
0
            xmlFreeDoc(doc);
1130
0
            goto error;
1131
0
        }
1132
3.32k
        tmp = xmlRealloc(ctxt->urlTab, newSize * sizeof(tmp[0]));
1133
3.32k
        if (tmp == NULL) {
1134
3
            xmlXIncludeErrMemory(ctxt);
1135
3
            xmlFreeDoc(doc);
1136
3
            goto error;
1137
3
        }
1138
3.32k
        ctxt->urlMax = newSize;
1139
3.32k
        ctxt->urlTab = tmp;
1140
3.32k
    }
1141
3.46k
    cache = &ctxt->urlTab[ctxt->urlNr];
1142
3.46k
    cache->doc = doc;
1143
3.46k
    cache->url = xmlStrdup(url);
1144
3.46k
    if (cache->url == NULL) {
1145
1
        xmlXIncludeErrMemory(ctxt);
1146
1
        xmlFreeDoc(doc);
1147
1
        goto error;
1148
1
    }
1149
3.46k
    cache->expanding = 0;
1150
3.46k
    cacheNr = ctxt->urlNr++;
1151
1152
3.46k
    if (doc == NULL)
1153
3.33k
        goto error;
1154
    /*
1155
     * It's possible that the requested URL has been mapped to a
1156
     * completely different location (e.g. through a catalog entry).
1157
     * To check for this, we compare the URL with that of the doc
1158
     * and change it if they disagree (bug 146988).
1159
     */
1160
137
    if ((doc->URL != NULL) && (!xmlStrEqual(url, doc->URL)))
1161
0
        url = doc->URL;
1162
1163
    /*
1164
     * Make sure we have all entities fixed up
1165
     */
1166
137
    xmlXIncludeMergeEntities(ctxt, ctxt->doc, doc);
1167
1168
    /*
1169
     * We don't need the DTD anymore, free up space
1170
    if (doc->intSubset != NULL) {
1171
  xmlUnlinkNode((xmlNodePtr) doc->intSubset);
1172
  xmlFreeNode((xmlNodePtr) doc->intSubset);
1173
  doc->intSubset = NULL;
1174
    }
1175
    if (doc->extSubset != NULL) {
1176
  xmlUnlinkNode((xmlNodePtr) doc->extSubset);
1177
  xmlFreeNode((xmlNodePtr) doc->extSubset);
1178
  doc->extSubset = NULL;
1179
    }
1180
     */
1181
137
    cache->expanding = 1;
1182
137
    xmlXIncludeRecurseDoc(ctxt, doc);
1183
    /* urlTab might be reallocated. */
1184
137
    cache = &ctxt->urlTab[cacheNr];
1185
137
    cache->expanding = 0;
1186
1187
13.2k
loaded:
1188
13.2k
    if (fragment == NULL) {
1189
251
        xmlNodePtr root;
1190
1191
251
        root = xmlDocGetRootElement(doc);
1192
251
        if (root == NULL) {
1193
0
            xmlXIncludeErr(ctxt, ref->elem, XML_ERR_INTERNAL_ERROR,
1194
0
                           "document without root\n", NULL);
1195
0
            goto error;
1196
0
        }
1197
1198
251
        ref->inc = xmlDocCopyNode(root, ctxt->doc, 1);
1199
251
        if (ref->inc == NULL) {
1200
5
            xmlXIncludeErrMemory(ctxt);
1201
5
            goto error;
1202
5
        }
1203
1204
246
        if (ref->base != NULL)
1205
143
            xmlXIncludeBaseFixup(ctxt, root, ref->inc, ref->base);
1206
246
    }
1207
12.9k
#ifdef LIBXML_XPTR_ENABLED
1208
12.9k
    else {
1209
  /*
1210
   * Computes the XPointer expression and make a copy used
1211
   * as the replacement copy.
1212
   */
1213
12.9k
  xmlXPathObjectPtr xptr;
1214
12.9k
  xmlNodeSetPtr set;
1215
1216
12.9k
        if (ctxt->isStream && doc == ctxt->doc) {
1217
0
      xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_XPTR_FAILED,
1218
0
         "XPointer expressions not allowed in streaming"
1219
0
                           " mode\n", NULL);
1220
0
            goto error;
1221
0
        }
1222
1223
12.9k
        if (ctxt->xpctxt == NULL) {
1224
6.45k
            ctxt->xpctxt = xmlXPathNewContext(doc);
1225
6.45k
            if (ctxt->xpctxt == NULL) {
1226
2
                xmlXIncludeErrMemory(ctxt);
1227
2
                goto error;
1228
2
            }
1229
6.45k
            if (ctxt->errorHandler != NULL)
1230
0
                xmlXPathSetErrorHandler(ctxt->xpctxt, ctxt->errorHandler,
1231
0
                                        ctxt->errorCtxt);
1232
6.45k
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
1233
6.45k
            ctxt->xpctxt->opLimit = 100000;
1234
6.45k
#endif
1235
6.53k
        } else {
1236
6.53k
            ctxt->xpctxt->doc = doc;
1237
6.53k
        }
1238
12.9k
  xptr = xmlXPtrEval(fragment, ctxt->xpctxt);
1239
12.9k
  if (ctxt->xpctxt->lastError.code != XML_ERR_OK) {
1240
9.30k
            if (ctxt->xpctxt->lastError.code == XML_ERR_NO_MEMORY)
1241
1.17k
                xmlXIncludeErrMemory(ctxt);
1242
8.12k
            else
1243
8.12k
                xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_XPTR_FAILED,
1244
8.12k
                               "XPointer evaluation failed: #%s\n",
1245
8.12k
                               fragment);
1246
9.30k
            goto error;
1247
9.30k
  }
1248
3.69k
        if (xptr == NULL)
1249
2.18k
            goto done;
1250
1.51k
  switch (xptr->type) {
1251
0
      case XPATH_UNDEFINED:
1252
0
      case XPATH_BOOLEAN:
1253
0
      case XPATH_NUMBER:
1254
0
      case XPATH_STRING:
1255
0
      case XPATH_USERS:
1256
0
      case XPATH_XSLT_TREE:
1257
0
    xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_XPTR_RESULT,
1258
0
             "XPointer is not a range: #%s\n",
1259
0
             fragment);
1260
0
                xmlXPathFreeObject(xptr);
1261
0
                goto error;
1262
1.51k
      case XPATH_NODESET:
1263
1.51k
                break;
1264
1265
1.51k
  }
1266
1.51k
  set = xptr->nodesetval;
1267
1.51k
  if (set != NULL) {
1268
259k
      for (i = 0;i < set->nodeNr;i++) {
1269
258k
    if (set->nodeTab[i] == NULL) /* shouldn't happen */
1270
0
        continue;
1271
258k
    switch (set->nodeTab[i]->type) {
1272
245k
        case XML_ELEMENT_NODE:
1273
257k
        case XML_TEXT_NODE:
1274
257k
        case XML_CDATA_SECTION_NODE:
1275
257k
        case XML_ENTITY_REF_NODE:
1276
257k
        case XML_ENTITY_NODE:
1277
257k
        case XML_PI_NODE:
1278
258k
        case XML_COMMENT_NODE:
1279
258k
        case XML_DOCUMENT_NODE:
1280
258k
        case XML_HTML_DOCUMENT_NODE:
1281
258k
      continue;
1282
1283
69
        case XML_ATTRIBUTE_NODE:
1284
69
      xmlXIncludeErr(ctxt, ref->elem,
1285
69
                     XML_XINCLUDE_XPTR_RESULT,
1286
69
               "XPointer selects an attribute: #%s\n",
1287
69
               fragment);
1288
69
      goto xptr_error;
1289
44
        case XML_NAMESPACE_DECL:
1290
44
      xmlXIncludeErr(ctxt, ref->elem,
1291
44
                     XML_XINCLUDE_XPTR_RESULT,
1292
44
               "XPointer selects a namespace: #%s\n",
1293
44
               fragment);
1294
44
      goto xptr_error;
1295
0
        case XML_DOCUMENT_TYPE_NODE:
1296
0
        case XML_DOCUMENT_FRAG_NODE:
1297
0
        case XML_NOTATION_NODE:
1298
0
        case XML_DTD_NODE:
1299
0
        case XML_ELEMENT_DECL:
1300
0
        case XML_ATTRIBUTE_DECL:
1301
0
        case XML_ENTITY_DECL:
1302
0
        case XML_XINCLUDE_START:
1303
0
        case XML_XINCLUDE_END:
1304
                        /* shouldn't happen */
1305
0
      xmlXIncludeErr(ctxt, ref->elem,
1306
0
                     XML_XINCLUDE_XPTR_RESULT,
1307
0
           "XPointer selects unexpected nodes: #%s\n",
1308
0
               fragment);
1309
0
      goto xptr_error;
1310
258k
    }
1311
258k
      }
1312
1.51k
  }
1313
1.40k
        ref->inc = xmlXIncludeCopyXPointer(ctxt, xptr, ref->base);
1314
1.51k
xptr_error:
1315
1.51k
        xmlXPathFreeObject(xptr);
1316
1.51k
    }
1317
1318
3.94k
done:
1319
3.94k
#endif
1320
1321
3.94k
    ret = 0;
1322
1323
17.5k
error:
1324
17.5k
    return(ret);
1325
3.94k
}
1326
1327
/**
1328
 * Load the content, and store the result in the XInclude context
1329
 *
1330
 * @param ctxt  the XInclude context
1331
 * @param ref  an XMLXincludeRefPtr
1332
 * @returns 0 in case of success, -1 in case of failure
1333
 */
1334
static int
1335
513
xmlXIncludeLoadTxt(xmlXIncludeCtxtPtr ctxt, xmlXIncludeRefPtr ref) {
1336
513
    xmlParserInputBufferPtr buf;
1337
513
    xmlNodePtr node = NULL;
1338
513
    const xmlChar *url = ref->URI;
1339
513
    int i;
1340
513
    int ret = -1;
1341
513
    xmlChar *encoding = NULL;
1342
513
    xmlCharEncodingHandlerPtr handler = NULL;
1343
513
    xmlParserCtxtPtr pctxt = NULL;
1344
513
    xmlParserInputPtr inputStream = NULL;
1345
513
    int len;
1346
513
    int res;
1347
513
    const xmlChar *content;
1348
1349
    /*
1350
     * Handling of references to the local document are done
1351
     * directly through ctxt->doc.
1352
     */
1353
513
    if (url[0] == 0) {
1354
46
  xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_TEXT_DOCUMENT,
1355
46
           "text serialization of document not available\n", NULL);
1356
46
  goto error;
1357
46
    }
1358
1359
    /*
1360
     * Prevent reloading the document twice.
1361
     */
1362
581
    for (i = 0; i < ctxt->txtNr; i++) {
1363
160
  if (xmlStrEqual(url, ctxt->txtTab[i].url)) {
1364
46
            node = xmlNewDocText(ctxt->doc, ctxt->txtTab[i].text);
1365
46
            if (node == NULL)
1366
2
                xmlXIncludeErrMemory(ctxt);
1367
46
      goto loaded;
1368
46
  }
1369
160
    }
1370
1371
    /*
1372
     * Try to get the encoding if available
1373
     */
1374
421
    if (ref->elem != NULL) {
1375
421
  encoding = xmlXIncludeGetProp(ctxt, ref->elem, XINCLUDE_PARSE_ENCODING);
1376
421
    }
1377
421
    if (encoding != NULL) {
1378
173
        xmlParserErrors code;
1379
1380
173
        code = xmlOpenCharEncodingHandler((const char *) encoding,
1381
173
                                          /* output */ 0, &handler);
1382
1383
173
        if (code != XML_ERR_OK) {
1384
30
            if (code == XML_ERR_NO_MEMORY) {
1385
3
                xmlXIncludeErrMemory(ctxt);
1386
27
            } else if (code == XML_ERR_UNSUPPORTED_ENCODING) {
1387
27
                xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_UNKNOWN_ENCODING,
1388
27
                               "encoding %s not supported\n", encoding);
1389
27
                goto error;
1390
27
            } else {
1391
0
                xmlXIncludeErr(ctxt, ref->elem, code,
1392
0
                               "unexpected error from iconv or ICU\n", NULL);
1393
0
                goto error;
1394
0
            }
1395
30
        }
1396
173
    }
1397
1398
    /*
1399
     * Load it.
1400
     */
1401
394
    pctxt = xmlNewParserCtxt();
1402
394
    if (pctxt == NULL) {
1403
2
        xmlXIncludeErrMemory(ctxt);
1404
2
        goto error;
1405
2
    }
1406
392
    if (ctxt->errorHandler != NULL)
1407
0
        xmlCtxtSetErrorHandler(pctxt, ctxt->errorHandler, ctxt->errorCtxt);
1408
392
    if (ctxt->resourceLoader != NULL)
1409
392
        xmlCtxtSetResourceLoader(pctxt, ctxt->resourceLoader,
1410
392
                                 ctxt->resourceCtxt);
1411
1412
392
    xmlCtxtUseOptions(pctxt, ctxt->parseFlags);
1413
1414
392
    inputStream = xmlLoadResource(pctxt, (const char*) url, NULL,
1415
392
                                  XML_RESOURCE_XINCLUDE_TEXT);
1416
392
    if (inputStream == NULL) {
1417
        /*
1418
         * ENOENT only produces a warning which isn't reflected in errNo.
1419
         */
1420
144
        if (pctxt->errNo == XML_ERR_NO_MEMORY)
1421
1
            xmlXIncludeErrMemory(ctxt);
1422
143
        else if ((pctxt->errNo != XML_ERR_OK) &&
1423
1
                 (pctxt->errNo != XML_IO_ENOENT) &&
1424
1
                 (pctxt->errNo != XML_IO_UNKNOWN) &&
1425
1
                 (pctxt->errNo != XML_IO_NETWORK_ATTEMPT))
1426
1
            xmlXIncludeErr(ctxt, NULL, pctxt->errNo, "load error", NULL);
1427
144
  goto error;
1428
144
    }
1429
248
    buf = inputStream->buf;
1430
248
    if (buf == NULL)
1431
0
  goto error;
1432
248
    if (buf->encoder)
1433
0
  xmlCharEncCloseFunc(buf->encoder);
1434
248
    buf->encoder = handler;
1435
248
    handler = NULL;
1436
1437
248
    node = xmlNewDocText(ctxt->doc, NULL);
1438
248
    if (node == NULL) {
1439
2
        xmlXIncludeErrMemory(ctxt);
1440
2
  goto error;
1441
2
    }
1442
1443
    /*
1444
     * Scan all chars from the resource and add the to the node
1445
     */
1446
246
    do {
1447
246
        res = xmlParserInputBufferRead(buf, 4096);
1448
246
    } while (res > 0);
1449
246
    if (res < 0) {
1450
0
        if (buf->error == XML_ERR_NO_MEMORY)
1451
0
            xmlXIncludeErrMemory(ctxt);
1452
0
        else
1453
0
            xmlXIncludeErr(ctxt, NULL, buf->error, "read error", NULL);
1454
0
        goto error;
1455
0
    }
1456
1457
246
    content = xmlBufContent(buf->buffer);
1458
246
    len = xmlBufUse(buf->buffer);
1459
7.09k
    for (i = 0; i < len;) {
1460
7.05k
        int cur;
1461
7.05k
        int l;
1462
1463
7.05k
        l = len - i;
1464
7.05k
        cur = xmlGetUTF8Char(&content[i], &l);
1465
7.05k
        if ((cur < 0) || (!IS_CHAR(cur))) {
1466
203
            xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_INVALID_CHAR,
1467
203
                           "%s contains invalid char\n", url);
1468
203
            goto error;
1469
203
        }
1470
1471
6.84k
        i += l;
1472
6.84k
    }
1473
1474
43
    if (xmlNodeAddContentLen(node, content, len) < 0)
1475
1
        xmlXIncludeErrMemory(ctxt);
1476
1477
43
    if (ctxt->txtNr >= ctxt->txtMax) {
1478
43
        xmlXIncludeTxt *tmp;
1479
43
        int newSize;
1480
1481
43
        newSize = xmlGrowCapacity(ctxt->txtMax, sizeof(tmp[0]),
1482
43
                                  8, XML_MAX_ITEMS);
1483
43
        if (newSize < 0) {
1484
0
            xmlXIncludeErrMemory(ctxt);
1485
0
      goto error;
1486
0
        }
1487
43
        tmp = xmlRealloc(ctxt->txtTab, newSize * sizeof(tmp[0]));
1488
43
        if (tmp == NULL) {
1489
1
            xmlXIncludeErrMemory(ctxt);
1490
1
      goto error;
1491
1
        }
1492
42
        ctxt->txtMax = newSize;
1493
42
        ctxt->txtTab = tmp;
1494
42
    }
1495
42
    ctxt->txtTab[ctxt->txtNr].text = xmlStrdup(node->content);
1496
42
    if ((node->content != NULL) &&
1497
40
        (ctxt->txtTab[ctxt->txtNr].text == NULL)) {
1498
1
        xmlXIncludeErrMemory(ctxt);
1499
1
        goto error;
1500
1
    }
1501
41
    ctxt->txtTab[ctxt->txtNr].url = xmlStrdup(url);
1502
41
    if (ctxt->txtTab[ctxt->txtNr].url == NULL) {
1503
1
        xmlXIncludeErrMemory(ctxt);
1504
1
        xmlFree(ctxt->txtTab[ctxt->txtNr].text);
1505
1
        goto error;
1506
1
    }
1507
40
    ctxt->txtNr++;
1508
1509
86
loaded:
1510
    /*
1511
     * Add the element as the replacement copy.
1512
     */
1513
86
    ref->inc = node;
1514
86
    node = NULL;
1515
86
    ret = 0;
1516
1517
513
error:
1518
513
    xmlFreeNode(node);
1519
513
    xmlFreeInputStream(inputStream);
1520
513
    xmlFreeParserCtxt(pctxt);
1521
513
    xmlCharEncCloseFunc(handler);
1522
513
    xmlFree(encoding);
1523
513
    return(ret);
1524
86
}
1525
1526
/**
1527
 * Load the content of the fallback node, and store the result
1528
 * in the XInclude context
1529
 *
1530
 * @param ctxt  the XInclude context
1531
 * @param fallback  the fallback node
1532
 * @param ref  an XMLXincludeRefPtr
1533
 * @returns 0 in case of success, -1 in case of failure
1534
 */
1535
static int
1536
xmlXIncludeLoadFallback(xmlXIncludeCtxtPtr ctxt, xmlNodePtr fallback,
1537
2.45k
                        xmlXIncludeRefPtr ref) {
1538
2.45k
    int ret = 0;
1539
2.45k
    int oldNbErrors;
1540
1541
2.45k
    if ((fallback == NULL) || (fallback->type == XML_NAMESPACE_DECL) ||
1542
2.45k
        (ctxt == NULL))
1543
0
  return(-1);
1544
2.45k
    if (fallback->children != NULL) {
1545
  /*
1546
   * It's possible that the fallback also has 'includes'
1547
   * (Bug 129969), so we re-process the fallback just in case
1548
   */
1549
2.37k
        oldNbErrors = ctxt->nbErrors;
1550
2.37k
  ref->inc = xmlXIncludeCopyNode(ctxt, fallback, 1, ref->base);
1551
2.37k
  if (ctxt->nbErrors > oldNbErrors)
1552
601
      ret = -1;
1553
2.37k
    } else {
1554
80
        ref->inc = NULL;
1555
80
    }
1556
2.45k
    ref->fallback = 1;
1557
2.45k
    return(ret);
1558
2.45k
}
1559
1560
/************************************************************************
1561
 *                  *
1562
 *      XInclude Processing       *
1563
 *                  *
1564
 ************************************************************************/
1565
1566
/**
1567
 * If the XInclude node wasn't processed yet, create a new RefPtr,
1568
 * add it to ctxt->incTab and load the included items.
1569
 *
1570
 * @param ctxt  an XInclude context
1571
 * @param node  an XInclude node
1572
 * @returns the new or existing xmlXIncludeRef, or NULL in case of error.
1573
 */
1574
static xmlXIncludeRefPtr
1575
23.1k
xmlXIncludeExpandNode(xmlXIncludeCtxtPtr ctxt, xmlNodePtr node) {
1576
23.1k
    xmlXIncludeRefPtr ref;
1577
23.1k
    int i;
1578
1579
23.1k
    if (ctxt->fatalErr)
1580
434
        return(NULL);
1581
22.7k
    if (ctxt->depth >= XINCLUDE_MAX_DEPTH) {
1582
0
        xmlXIncludeErr(ctxt, node, XML_XINCLUDE_RECURSION,
1583
0
                       "maximum recursion depth exceeded\n", NULL);
1584
0
        ctxt->fatalErr = 1;
1585
0
        return(NULL);
1586
0
    }
1587
1588
22.7k
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
1589
    /*
1590
     * The XInclude engine offers no protection against exponential
1591
     * expansion attacks similar to "billion laughs". Avoid timeouts by
1592
     * limiting the total number of replacements when fuzzing.
1593
     *
1594
     * Unfortuately, a single XInclude can already result in quadratic
1595
     * behavior:
1596
     *
1597
     *     <doc xmlns:xi="http://www.w3.org/2001/XInclude">
1598
     *       <xi:include xpointer="xpointer(//e)"/>
1599
     *       <e>
1600
     *         <e>
1601
     *           <e>
1602
     *             <!-- more nested elements -->
1603
     *           </e>
1604
     *         </e>
1605
     *       </e>
1606
     *     </doc>
1607
     */
1608
22.7k
    if (ctxt->incTotal >= 20)
1609
1.57k
        return(NULL);
1610
21.1k
    ctxt->incTotal++;
1611
21.1k
#endif
1612
1613
69.2k
    for (i = 0; i < ctxt->incNr; i++) {
1614
49.4k
        if (ctxt->incTab[i]->elem == node) {
1615
1.39k
            if (ctxt->incTab[i]->expanding) {
1616
683
                xmlXIncludeErr(ctxt, node, XML_XINCLUDE_RECURSION,
1617
683
                               "inclusion loop detected\n", NULL);
1618
683
                return(NULL);
1619
683
            }
1620
707
            return(ctxt->incTab[i]);
1621
1.39k
        }
1622
49.4k
    }
1623
1624
19.7k
    ref = xmlXIncludeAddNode(ctxt, node);
1625
19.7k
    if (ref == NULL)
1626
1.67k
        return(NULL);
1627
18.0k
    ref->expanding = 1;
1628
18.0k
    ctxt->depth++;
1629
18.0k
    xmlXIncludeLoadNode(ctxt, ref);
1630
18.0k
    ctxt->depth--;
1631
18.0k
    ref->expanding = 0;
1632
1633
18.0k
    return(ref);
1634
19.7k
}
1635
1636
/**
1637
 * Find and load the infoset replacement for the given node.
1638
 *
1639
 * @param ctxt  an XInclude context
1640
 * @param ref  an xmlXIncludeRef
1641
 * @returns 0 if substitution succeeded, -1 if some processing failed
1642
 */
1643
static int
1644
18.0k
xmlXIncludeLoadNode(xmlXIncludeCtxtPtr ctxt, xmlXIncludeRefPtr ref) {
1645
18.0k
    xmlNodePtr cur;
1646
18.0k
    int ret;
1647
1648
18.0k
    if ((ctxt == NULL) || (ref == NULL))
1649
0
  return(-1);
1650
18.0k
    cur = ref->elem;
1651
18.0k
    if (cur == NULL)
1652
0
  return(-1);
1653
1654
18.0k
    if (ref->xml) {
1655
17.5k
  ret = xmlXIncludeLoadDoc(ctxt, ref);
1656
  /* xmlXIncludeGetFragment(ctxt, cur, URI); */
1657
17.5k
    } else {
1658
513
  ret = xmlXIncludeLoadTxt(ctxt, ref);
1659
513
    }
1660
1661
18.0k
    if (ret < 0) {
1662
14.0k
  xmlNodePtr children;
1663
1664
  /*
1665
   * Time to try a fallback if available
1666
   */
1667
14.0k
  children = cur->children;
1668
25.7k
  while (children != NULL) {
1669
14.1k
      if ((children->type == XML_ELEMENT_NODE) &&
1670
8.40k
    (children->ns != NULL) &&
1671
4.63k
    (xmlStrEqual(children->name, XINCLUDE_FALLBACK)) &&
1672
2.53k
    ((xmlStrEqual(children->ns->href, XINCLUDE_NS)) ||
1673
2.45k
     (xmlStrEqual(children->ns->href, XINCLUDE_OLD_NS)))) {
1674
2.45k
    ret = xmlXIncludeLoadFallback(ctxt, children, ref);
1675
2.45k
    break;
1676
2.45k
      }
1677
11.6k
      children = children->next;
1678
11.6k
  }
1679
14.0k
    }
1680
18.0k
    if (ret < 0) {
1681
12.2k
  xmlXIncludeErr(ctxt, cur, XML_XINCLUDE_NO_FALLBACK,
1682
12.2k
           "could not load %s, and no fallback was found\n",
1683
12.2k
           ref->URI);
1684
12.2k
    }
1685
1686
18.0k
    return(0);
1687
18.0k
}
1688
1689
/**
1690
 * Implement the infoset replacement for the given node
1691
 *
1692
 * @param ctxt  an XInclude context
1693
 * @param ref  an xmlXIncludeRef
1694
 * @returns 0 if substitution succeeded, -1 if some processing failed
1695
 */
1696
static int
1697
16.4k
xmlXIncludeIncludeNode(xmlXIncludeCtxtPtr ctxt, xmlXIncludeRefPtr ref) {
1698
16.4k
    xmlNodePtr cur, end, list, tmp;
1699
1700
16.4k
    if ((ctxt == NULL) || (ref == NULL))
1701
0
  return(-1);
1702
16.4k
    cur = ref->elem;
1703
16.4k
    if ((cur == NULL) || (cur->type == XML_NAMESPACE_DECL))
1704
0
  return(-1);
1705
1706
16.4k
    list = ref->inc;
1707
16.4k
    ref->inc = NULL;
1708
1709
    /*
1710
     * Check against the risk of generating a multi-rooted document
1711
     */
1712
16.4k
    if ((cur->parent != NULL) &&
1713
16.4k
  (cur->parent->type != XML_ELEMENT_NODE)) {
1714
71
  int nb_elem = 0;
1715
1716
71
  tmp = list;
1717
196
  while (tmp != NULL) {
1718
125
      if (tmp->type == XML_ELEMENT_NODE)
1719
79
    nb_elem++;
1720
125
      tmp = tmp->next;
1721
125
  }
1722
71
        if (nb_elem != 1) {
1723
60
            if (nb_elem > 1)
1724
5
                xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_MULTIPLE_ROOT,
1725
5
                               "XInclude error: would result in multiple root "
1726
5
                               "nodes\n", NULL);
1727
55
            else
1728
55
                xmlXIncludeErr(ctxt, ref->elem, XML_XINCLUDE_MULTIPLE_ROOT,
1729
55
                               "XInclude error: would result in no root "
1730
55
                               "node\n", NULL);
1731
60
            xmlFreeNodeList(list);
1732
60
      return(-1);
1733
60
  }
1734
71
    }
1735
1736
16.4k
    if (ctxt->parseFlags & XML_PARSE_NOXINCNODE) {
1737
  /*
1738
   * Add the list of nodes
1739
         *
1740
         * TODO: Coalesce text nodes unless we are streaming mode.
1741
   */
1742
9.02k
  while (list != NULL) {
1743
5.29k
      end = list;
1744
5.29k
      list = list->next;
1745
1746
5.29k
      if (xmlAddPrevSibling(cur, end) == NULL) {
1747
0
                xmlUnlinkNode(end);
1748
0
                xmlFreeNode(end);
1749
0
                goto err_memory;
1750
0
            }
1751
5.29k
  }
1752
3.72k
  xmlUnlinkNode(cur);
1753
3.72k
  xmlFreeNode(cur);
1754
12.6k
    } else {
1755
12.6k
        xmlNodePtr child, next;
1756
1757
  /*
1758
   * Change the current node as an XInclude start one, and add an
1759
   * XInclude end one
1760
   */
1761
12.6k
        if (ref->fallback)
1762
1.09k
            xmlUnsetProp(cur, BAD_CAST "href");
1763
12.6k
  cur->type = XML_XINCLUDE_START;
1764
        /* Remove fallback children */
1765
25.3k
        for (child = cur->children; child != NULL; child = next) {
1766
12.7k
            next = child->next;
1767
12.7k
            xmlUnlinkNode(child);
1768
12.7k
            xmlFreeNode(child);
1769
12.7k
        }
1770
12.6k
  end = xmlNewDocNode(cur->doc, cur->ns, cur->name, NULL);
1771
12.6k
  if (end == NULL)
1772
29
            goto err_memory;
1773
12.6k
  end->type = XML_XINCLUDE_END;
1774
12.6k
  if (xmlAddNextSibling(cur, end) == NULL) {
1775
0
            xmlFreeNode(end);
1776
0
            goto err_memory;
1777
0
        }
1778
1779
  /*
1780
   * Add the list of nodes
1781
   */
1782
40.6k
  while (list != NULL) {
1783
28.0k
      cur = list;
1784
28.0k
      list = list->next;
1785
1786
28.0k
      if (xmlAddPrevSibling(end, cur) == NULL) {
1787
0
                xmlUnlinkNode(cur);
1788
0
                xmlFreeNode(cur);
1789
0
                goto err_memory;
1790
0
            }
1791
28.0k
  }
1792
12.6k
    }
1793
1794
1795
16.3k
    return(0);
1796
1797
29
err_memory:
1798
29
    xmlXIncludeErrMemory(ctxt);
1799
29
    xmlFreeNodeList(list);
1800
29
    return(-1);
1801
16.4k
}
1802
1803
/**
1804
 * test if the node is an XInclude node
1805
 *
1806
 * @param ctxt  the XInclude processing context
1807
 * @param node  an XInclude node
1808
 * @returns 1 true, 0 otherwise
1809
 */
1810
static int
1811
688k
xmlXIncludeTestNode(xmlXIncludeCtxtPtr ctxt, xmlNodePtr node) {
1812
688k
    if (node == NULL)
1813
0
  return(0);
1814
688k
    if (node->type != XML_ELEMENT_NODE)
1815
217k
  return(0);
1816
471k
    if (node->ns == NULL)
1817
224k
  return(0);
1818
246k
    if ((xmlStrEqual(node->ns->href, XINCLUDE_NS)) ||
1819
241k
        (xmlStrEqual(node->ns->href, XINCLUDE_OLD_NS))) {
1820
26.9k
  if (xmlStrEqual(node->ns->href, XINCLUDE_OLD_NS)) {
1821
22.4k
      if (ctxt->legacy == 0) {
1822
7.21k
          ctxt->legacy = 1;
1823
7.21k
      }
1824
22.4k
  }
1825
26.9k
  if (xmlStrEqual(node->name, XINCLUDE_NODE)) {
1826
20.7k
      xmlNodePtr child = node->children;
1827
20.7k
      int nb_fallback = 0;
1828
1829
40.3k
      while (child != NULL) {
1830
20.0k
    if ((child->type == XML_ELEMENT_NODE) &&
1831
12.0k
        (child->ns != NULL) &&
1832
6.33k
        ((xmlStrEqual(child->ns->href, XINCLUDE_NS)) ||
1833
5.49k
         (xmlStrEqual(child->ns->href, XINCLUDE_OLD_NS)))) {
1834
3.22k
        if (xmlStrEqual(child->name, XINCLUDE_NODE)) {
1835
535
      xmlXIncludeErr(ctxt, node,
1836
535
                     XML_XINCLUDE_INCLUDE_IN_INCLUDE,
1837
535
               "%s has an 'include' child\n",
1838
535
               XINCLUDE_NODE);
1839
535
      return(0);
1840
535
        }
1841
2.68k
        if (xmlStrEqual(child->name, XINCLUDE_FALLBACK)) {
1842
1.83k
      nb_fallback++;
1843
1.83k
        }
1844
2.68k
    }
1845
19.5k
    child = child->next;
1846
19.5k
      }
1847
20.2k
      if (nb_fallback > 1) {
1848
201
    xmlXIncludeErr(ctxt, node, XML_XINCLUDE_FALLBACKS_IN_INCLUDE,
1849
201
             "%s has multiple fallback children\n",
1850
201
                   XINCLUDE_NODE);
1851
201
    return(0);
1852
201
      }
1853
20.0k
      return(1);
1854
20.2k
  }
1855
6.16k
  if (xmlStrEqual(node->name, XINCLUDE_FALLBACK)) {
1856
1.54k
      if ((node->parent == NULL) ||
1857
1.54k
    (node->parent->type != XML_ELEMENT_NODE) ||
1858
1.54k
    (node->parent->ns == NULL) ||
1859
1.14k
    ((!xmlStrEqual(node->parent->ns->href, XINCLUDE_NS)) &&
1860
777
     (!xmlStrEqual(node->parent->ns->href, XINCLUDE_OLD_NS))) ||
1861
1.09k
    (!xmlStrEqual(node->parent->name, XINCLUDE_NODE))) {
1862
1.02k
    xmlXIncludeErr(ctxt, node,
1863
1.02k
                   XML_XINCLUDE_FALLBACK_NOT_IN_INCLUDE,
1864
1.02k
             "%s is not the child of an 'include'\n",
1865
1.02k
             XINCLUDE_FALLBACK);
1866
1.02k
      }
1867
1.54k
  }
1868
6.16k
    }
1869
225k
    return(0);
1870
246k
}
1871
1872
/**
1873
 * Implement the XInclude substitution on the XML document `doc`
1874
 *
1875
 * @param ctxt  the XInclude processing context
1876
 * @param tree  the top of the tree to process
1877
 * @returns 0 if no substitution were done, -1 if some processing failed
1878
 *    or the number of substitutions done.
1879
 */
1880
static int
1881
17.5k
xmlXIncludeDoProcess(xmlXIncludeCtxtPtr ctxt, xmlNodePtr tree) {
1882
17.5k
    xmlXIncludeRefPtr ref;
1883
17.5k
    xmlNodePtr cur;
1884
17.5k
    int ret = 0;
1885
17.5k
    int i, start;
1886
1887
    /*
1888
     * First phase: lookup the elements in the document
1889
     */
1890
17.5k
    start = ctxt->incNr;
1891
17.5k
    cur = tree;
1892
688k
    do {
1893
  /* TODO: need to work on entities -> stack */
1894
688k
        if (xmlXIncludeTestNode(ctxt, cur) == 1) {
1895
20.0k
            ref = xmlXIncludeExpandNode(ctxt, cur);
1896
            /*
1897
             * Mark direct includes.
1898
             */
1899
20.0k
            if (ref != NULL)
1900
16.4k
                ref->replace = 1;
1901
668k
        } else if ((cur->children != NULL) &&
1902
167k
                   ((cur->type == XML_DOCUMENT_NODE) ||
1903
160k
                    (cur->type == XML_ELEMENT_NODE))) {
1904
160k
            cur = cur->children;
1905
160k
            continue;
1906
160k
        }
1907
688k
        do {
1908
688k
            if (cur == tree)
1909
17.5k
                break;
1910
671k
            if (cur->next != NULL) {
1911
510k
                cur = cur->next;
1912
510k
                break;
1913
510k
            }
1914
160k
            cur = cur->parent;
1915
160k
        } while (cur != NULL);
1916
688k
    } while ((cur != NULL) && (cur != tree));
1917
1918
    /*
1919
     * Second phase: extend the original document infoset.
1920
     */
1921
35.5k
    for (i = start; i < ctxt->incNr; i++) {
1922
18.0k
  if (ctxt->incTab[i]->replace != 0) {
1923
16.4k
            xmlXIncludeIncludeNode(ctxt, ctxt->incTab[i]);
1924
16.4k
            ctxt->incTab[i]->replace = 0;
1925
16.4k
        } else {
1926
            /*
1927
             * Ignore includes which were added indirectly, for example
1928
             * inside xi:fallback elements.
1929
             */
1930
1.62k
            if (ctxt->incTab[i]->inc != NULL) {
1931
1.14k
                xmlFreeNodeList(ctxt->incTab[i]->inc);
1932
1.14k
                ctxt->incTab[i]->inc = NULL;
1933
1.14k
            }
1934
1.62k
        }
1935
18.0k
  ret++;
1936
18.0k
    }
1937
1938
17.5k
    if (ctxt->isStream) {
1939
        /*
1940
         * incTab references nodes which will eventually be deleted in
1941
         * streaming mode. The table is only required for XPointer
1942
         * expressions which aren't allowed in streaming mode.
1943
         */
1944
0
        for (i = 0;i < ctxt->incNr;i++) {
1945
0
            xmlXIncludeFreeRef(ctxt->incTab[i]);
1946
0
        }
1947
0
        ctxt->incNr = 0;
1948
0
    }
1949
1950
17.5k
    return(ret);
1951
17.5k
}
1952
1953
/**
1954
 * Implement the XInclude substitution on the XML document `doc`
1955
 *
1956
 * @param ctxt  the XInclude processing context
1957
 * @param tree  the top of the tree to process
1958
 * @returns 0 if no substitution were done, -1 if some processing failed
1959
 *    or the number of substitutions done.
1960
 */
1961
static int
1962
17.3k
xmlXIncludeDoProcessRoot(xmlXIncludeCtxtPtr ctxt, xmlNodePtr tree) {
1963
17.3k
    if ((tree == NULL) || (tree->type == XML_NAMESPACE_DECL))
1964
0
  return(-1);
1965
17.3k
    if (ctxt == NULL)
1966
0
  return(-1);
1967
1968
17.3k
    return(xmlXIncludeDoProcess(ctxt, tree));
1969
17.3k
}
1970
1971
/**
1972
 * @since 2.13.0
1973
 *
1974
 * @param ctxt  an XInclude processing context
1975
 * @returns the last error code.
1976
 */
1977
int
1978
34.7k
xmlXIncludeGetLastError(xmlXIncludeCtxt *ctxt) {
1979
34.7k
    if (ctxt == NULL)
1980
0
        return(XML_ERR_ARGUMENT);
1981
34.7k
    return(ctxt->errNo);
1982
34.7k
}
1983
1984
/**
1985
 * Register a callback function that will be called on errors and
1986
 * warnings. If handler is NULL, the error handler will be deactivated.
1987
 *
1988
 * @since 2.13.0
1989
 * @param ctxt  an XInclude processing context
1990
 * @param handler  error handler
1991
 * @param data  user data which will be passed to the handler
1992
 */
1993
void
1994
xmlXIncludeSetErrorHandler(xmlXIncludeCtxt *ctxt,
1995
0
                           xmlStructuredErrorFunc handler, void *data) {
1996
0
    if (ctxt == NULL)
1997
0
        return;
1998
0
    ctxt->errorHandler = handler;
1999
0
    ctxt->errorCtxt = data;
2000
0
}
2001
2002
/**
2003
 * Register a callback function that will be called to load included
2004
 * documents.
2005
 *
2006
 * @since 2.14.0
2007
 * @param ctxt  an XInclude processing context
2008
 * @param loader  resource loader
2009
 * @param data  user data which will be passed to the loader
2010
 */
2011
void
2012
xmlXIncludeSetResourceLoader(xmlXIncludeCtxt *ctxt,
2013
25.4k
                             xmlResourceLoader loader, void *data) {
2014
25.4k
    if (ctxt == NULL)
2015
8.04k
        return;
2016
17.3k
    ctxt->resourceLoader = loader;
2017
17.3k
    ctxt->resourceCtxt = data;
2018
17.3k
}
2019
2020
/**
2021
 * Set the flags used for further processing of XML resources.
2022
 *
2023
 * @param ctxt  an XInclude processing context
2024
 * @param flags  a set of xmlParserOption used for parsing XML includes
2025
 * @returns 0 in case of success and -1 in case of error.
2026
 */
2027
int
2028
25.4k
xmlXIncludeSetFlags(xmlXIncludeCtxt *ctxt, int flags) {
2029
25.4k
    if (ctxt == NULL)
2030
8.04k
        return(-1);
2031
17.3k
    ctxt->parseFlags = flags;
2032
17.3k
    return(0);
2033
25.4k
}
2034
2035
/**
2036
 * In streaming mode, XPointer expressions aren't allowed.
2037
 *
2038
 * @param ctxt  an XInclude processing context
2039
 * @param mode  whether streaming mode should be enabled
2040
 * @returns 0 in case of success and -1 in case of error.
2041
 */
2042
int
2043
0
xmlXIncludeSetStreamingMode(xmlXIncludeCtxt *ctxt, int mode) {
2044
0
    if (ctxt == NULL)
2045
0
        return(-1);
2046
0
    ctxt->isStream = !!mode;
2047
0
    return(0);
2048
0
}
2049
2050
/**
2051
 * Implement the XInclude substitution on the XML node `tree`
2052
 *
2053
 * @param tree  an XML node
2054
 * @param flags  a set of xmlParserOption used for parsing XML includes
2055
 * @param data  application data that will be passed to the parser context
2056
 *        in the _private field of the parser context(s)
2057
 * @returns 0 if no substitution were done, -1 if some processing failed
2058
 *    or the number of substitutions done.
2059
 */
2060
2061
int
2062
0
xmlXIncludeProcessTreeFlagsData(xmlNode *tree, int flags, void *data) {
2063
0
    xmlXIncludeCtxtPtr ctxt;
2064
0
    int ret = 0;
2065
2066
0
    if ((tree == NULL) || (tree->type == XML_NAMESPACE_DECL) ||
2067
0
        (tree->doc == NULL))
2068
0
        return(-1);
2069
2070
0
    ctxt = xmlXIncludeNewContext(tree->doc);
2071
0
    if (ctxt == NULL)
2072
0
        return(-1);
2073
0
    ctxt->_private = data;
2074
0
    xmlXIncludeSetFlags(ctxt, flags);
2075
0
    ret = xmlXIncludeDoProcessRoot(ctxt, tree);
2076
0
    if ((ret >= 0) && (ctxt->nbErrors > 0))
2077
0
        ret = -1;
2078
2079
0
    xmlXIncludeFreeContext(ctxt);
2080
0
    return(ret);
2081
0
}
2082
2083
/**
2084
 * Implement the XInclude substitution on the XML document `doc`
2085
 *
2086
 * @param doc  an XML document
2087
 * @param flags  a set of xmlParserOption used for parsing XML includes
2088
 * @param data  application data that will be passed to the parser context
2089
 *        in the _private field of the parser context(s)
2090
 * @returns 0 if no substitution were done, -1 if some processing failed
2091
 *    or the number of substitutions done.
2092
 */
2093
int
2094
0
xmlXIncludeProcessFlagsData(xmlDoc *doc, int flags, void *data) {
2095
0
    xmlNodePtr tree;
2096
2097
0
    if (doc == NULL)
2098
0
  return(-1);
2099
0
    tree = xmlDocGetRootElement(doc);
2100
0
    if (tree == NULL)
2101
0
  return(-1);
2102
0
    return(xmlXIncludeProcessTreeFlagsData(tree, flags, data));
2103
0
}
2104
2105
/**
2106
 * Implement the XInclude substitution on the XML document `doc`
2107
 *
2108
 * @param doc  an XML document
2109
 * @param flags  a set of xmlParserOption used for parsing XML includes
2110
 * @returns 0 if no substitution were done, -1 if some processing failed
2111
 *    or the number of substitutions done.
2112
 */
2113
int
2114
0
xmlXIncludeProcessFlags(xmlDoc *doc, int flags) {
2115
0
    return xmlXIncludeProcessFlagsData(doc, flags, NULL);
2116
0
}
2117
2118
/**
2119
 * Implement the XInclude substitution on the XML document `doc`
2120
 *
2121
 * @param doc  an XML document
2122
 * @returns 0 if no substitution were done, -1 if some processing failed
2123
 *    or the number of substitutions done.
2124
 */
2125
int
2126
0
xmlXIncludeProcess(xmlDoc *doc) {
2127
0
    return(xmlXIncludeProcessFlags(doc, doc ? doc->parseFlags : 0));
2128
0
}
2129
2130
/**
2131
 * Implement the XInclude substitution for the given subtree
2132
 *
2133
 * @param tree  a node in an XML document
2134
 * @param flags  a set of xmlParserOption used for parsing XML includes
2135
 * @returns 0 if no substitution were done, -1 if some processing failed
2136
 *    or the number of substitutions done.
2137
 */
2138
int
2139
0
xmlXIncludeProcessTreeFlags(xmlNode *tree, int flags) {
2140
0
    xmlXIncludeCtxtPtr ctxt;
2141
0
    int ret = 0;
2142
2143
0
    if ((tree == NULL) || (tree->type == XML_NAMESPACE_DECL) ||
2144
0
        (tree->doc == NULL))
2145
0
  return(-1);
2146
0
    ctxt = xmlXIncludeNewContext(tree->doc);
2147
0
    if (ctxt == NULL)
2148
0
  return(-1);
2149
0
    xmlXIncludeSetFlags(ctxt, flags);
2150
0
    ret = xmlXIncludeDoProcessRoot(ctxt, tree);
2151
0
    if ((ret >= 0) && (ctxt->nbErrors > 0))
2152
0
  ret = -1;
2153
2154
0
    xmlXIncludeFreeContext(ctxt);
2155
0
    return(ret);
2156
0
}
2157
2158
/**
2159
 * Implement the XInclude substitution for the given subtree
2160
 *
2161
 * @param tree  a node in an XML document
2162
 * @returns 0 if no substitution were done, -1 if some processing failed
2163
 *    or the number of substitutions done.
2164
 */
2165
int
2166
0
xmlXIncludeProcessTree(xmlNode *tree) {
2167
0
    return(xmlXIncludeProcessTreeFlags(tree, (tree && tree->doc) ? tree->doc->parseFlags : 0));
2168
0
}
2169
2170
/**
2171
 * Implement the XInclude substitution for the given subtree reusing
2172
 * the information and data coming from the given context.
2173
 *
2174
 * @param ctxt  an existing XInclude context
2175
 * @param node  a node in an XML document
2176
 * @returns 0 if no substitution were done, -1 if some processing failed
2177
 *    or the number of substitutions done.
2178
 */
2179
int
2180
25.4k
xmlXIncludeProcessNode(xmlXIncludeCtxt *ctxt, xmlNode *node) {
2181
25.4k
    int ret = 0;
2182
2183
25.4k
    if ((node == NULL) || (node->type == XML_NAMESPACE_DECL) ||
2184
17.4k
        (node->doc == NULL) || (ctxt == NULL))
2185
8.04k
  return(-1);
2186
17.3k
    ret = xmlXIncludeDoProcessRoot(ctxt, node);
2187
17.3k
    if ((ret >= 0) && (ctxt->nbErrors > 0))
2188
6.08k
  ret = -1;
2189
17.3k
    return(ret);
2190
25.4k
}
2191
2192
#else /* !LIBXML_XINCLUDE_ENABLED */
2193
#endif