Coverage Report

Created: 2026-10-03 06:05

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/uri.c
Line
Count
Source
1
/**
2
 * uri.c: set of generic URI related routines
3
 *
4
 * Reference: RFCs 3986, 2732 and 2373
5
 *
6
 * See Copyright for the status of this software.
7
 *
8
 * Author: Daniel Veillard
9
 */
10
11
#define IN_LIBXML
12
#include "libxml.h"
13
14
#include <limits.h>
15
#include <string.h>
16
17
#include <libxml/xmlmemory.h>
18
#include <libxml/uri.h>
19
#include <libxml/xmlerror.h>
20
21
#include "private/error.h"
22
#include "private/memory.h"
23
24
/**
25
 * The definition of the URI regexp in the above RFC has no size limit
26
 * In practice they are usually relatively short except for the
27
 * data URI scheme as defined in RFC 2397. Even for data URI the usual
28
 * maximum size before hitting random practical limits is around 64 KB
29
 * and 4KB is usually a maximum admitted limit for proper operations.
30
 * The value below is more a security limit than anything else and
31
 * really should never be hit by 'normal' operations
32
 * Set to 1 MByte in 2012, this is only enforced on output
33
 */
34
161k
#define MAX_URI_LENGTH 1024 * 1024
35
36
2.65M
#define PORT_EMPTY           0
37
21.6k
#define PORT_EMPTY_SERVER   -1
38
39
static void xmlCleanURI(xmlURIPtr uri);
40
41
/*
42
 * Old rule from 2396 used in legacy handling code
43
 * alpha    = lowalpha | upalpha
44
 */
45
343M
#define IS_ALPHA(x) (IS_LOWALPHA(x) || IS_UPALPHA(x))
46
47
48
/*
49
 * lowalpha = "a" | "b" | "c" | "d" | "e" | "f" | "g" | "h" | "i" | "j" |
50
 *            "k" | "l" | "m" | "n" | "o" | "p" | "q" | "r" | "s" | "t" |
51
 *            "u" | "v" | "w" | "x" | "y" | "z"
52
 */
53
343M
#define IS_LOWALPHA(x) (((x) >= 'a') && ((x) <= 'z'))
54
55
/*
56
 * upalpha = "A" | "B" | "C" | "D" | "E" | "F" | "G" | "H" | "I" | "J" |
57
 *           "K" | "L" | "M" | "N" | "O" | "P" | "Q" | "R" | "S" | "T" |
58
 *           "U" | "V" | "W" | "X" | "Y" | "Z"
59
 */
60
146M
#define IS_UPALPHA(x) (((x) >= 'A') && ((x) <= 'Z'))
61
62
#ifdef IS_DIGIT
63
#undef IS_DIGIT
64
#endif
65
/*
66
 * digit = "0" | "1" | "2" | "3" | "4" | "5" | "6" | "7" | "8" | "9"
67
 */
68
75.6M
#define IS_DIGIT(x) (((x) >= '0') && ((x) <= '9'))
69
70
/*
71
 * alphanum = alpha | digit
72
 */
73
343M
#define IS_ALPHANUM(x) (IS_ALPHA(x) || IS_DIGIT(x))
74
75
/*
76
 * mark = "-" | "_" | "." | "!" | "~" | "*" | "'" | "(" | ")"
77
 */
78
79
68.8M
#define IS_MARK(x) (((x) == '-') || ((x) == '_') || ((x) == '.') ||     \
80
68.8M
    ((x) == '!') || ((x) == '~') || ((x) == '*') || ((x) == '\'') ||    \
81
68.8M
    ((x) == '(') || ((x) == ')'))
82
83
/*
84
 * unwise = "{" | "}" | "|" | "\" | "^" | "`"
85
 */
86
#define IS_UNWISE(p)                                                    \
87
108k
      (((*(p) == '{')) || ((*(p) == '}')) || ((*(p) == '|')) ||         \
88
108k
       ((*(p) == '\\')) || ((*(p) == '^')) || ((*(p) == '[')) ||        \
89
108k
       ((*(p) == ']')) || ((*(p) == '`')))
90
91
/*
92
 * reserved = ";" | "/" | "?" | ":" | "@" | "&" | "=" | "+" | "$" | "," |
93
 *            "[" | "]"
94
 */
95
3.41M
#define IS_RESERVED(x) (((x) == ';') || ((x) == '/') || ((x) == '?') || \
96
3.41M
        ((x) == ':') || ((x) == '@') || ((x) == '&') || ((x) == '=') || \
97
3.41M
        ((x) == '+') || ((x) == '$') || ((x) == ',') || ((x) == '[') || \
98
3.41M
        ((x) == ']'))
99
100
/*
101
 * unreserved = alphanum | mark
102
 */
103
171M
#define IS_UNRESERVED(x) (IS_ALPHANUM(x) || IS_MARK(x))
104
105
/*
106
 * Skip to next pointer char, handle escaped sequences
107
 */
108
329M
#define NEXT(p) ((*p == '%')? p += 3 : p++)
109
110
/*
111
 * Productions from the spec.
112
 *
113
 *    authority     = server | reg_name
114
 *    reg_name      = 1*( unreserved | escaped | "$" | "," |
115
 *                        ";" | ":" | "@" | "&" | "=" | "+" )
116
 *
117
 * path          = [ abs_path | opaque_part ]
118
 */
119
856k
#define STRNDUP(s, n) (char *) xmlStrndup((const xmlChar *)(s), (n))
120
121
/************************************************************************
122
 *                  *
123
 *                         RFC 3986 parser        *
124
 *                  *
125
 ************************************************************************/
126
127
111M
#define ISA_DIGIT(p) ((*(p) >= '0') && (*(p) <= '9'))
128
343M
#define ISA_ALPHA(p) (((*(p) >= 'a') && (*(p) <= 'z')) ||   \
129
343M
                      ((*(p) >= 'A') && (*(p) <= 'Z')))
130
#define ISA_HEXDIG(p)             \
131
23.3M
       (ISA_DIGIT(p) || ((*(p) >= 'a') && (*(p) <= 'f')) ||   \
132
23.3M
        ((*(p) >= 'A') && (*(p) <= 'F')))
133
134
/*
135
 *    sub-delims    = "!" / "$" / "&" / "'" / "(" / ")"
136
 *                     / "*" / "+" / "," / ";" / "="
137
 */
138
#define ISA_SUB_DELIM(p)            \
139
363M
      (((*(p) == '!')) || ((*(p) == '$')) || ((*(p) == '&')) ||   \
140
36.5M
       ((*(p) == '(')) || ((*(p) == ')')) || ((*(p) == '*')) ||   \
141
36.5M
       ((*(p) == '+')) || ((*(p) == ',')) || ((*(p) == ';')) ||   \
142
36.5M
       ((*(p) == '=')) || ((*(p) == '\'')))
143
144
/*
145
 *    gen-delims    = ":" / "/" / "?" / "\#" / "[" / "]" / "@"
146
 */
147
#define ISA_GEN_DELIM(p)            \
148
      (((*(p) == ':')) || ((*(p) == '/')) || ((*(p) == '?')) ||         \
149
       ((*(p) == '#')) || ((*(p) == '[')) || ((*(p) == ']')) ||         \
150
       ((*(p) == '@')))
151
152
/*
153
 *    reserved      = gen-delims / sub-delims
154
 */
155
#define ISA_RESERVED(p) (ISA_GEN_DELIM(p) || (ISA_SUB_DELIM(p)))
156
157
/*
158
 *    unreserved    = ALPHA / DIGIT / "-" / "." / "_" / "~"
159
 */
160
#define ISA_STRICTLY_UNRESERVED(p)          \
161
332M
      ((ISA_ALPHA(p)) || (ISA_DIGIT(p)) || ((*(p) == '-')) ||   \
162
332M
       ((*(p) == '.')) || ((*(p) == '_')) || ((*(p) == '~')))
163
164
/*
165
 *    pct-encoded   = "%" HEXDIG HEXDIG
166
 */
167
#define ISA_PCT_ENCODED(p)            \
168
381M
     ((*(p) == '%') && (ISA_HEXDIG(p + 1)) && (ISA_HEXDIG(p + 2)))
169
170
/*
171
 *    pchar         = unreserved / pct-encoded / sub-delims / ":" / "@"
172
 */
173
#define ISA_PCHAR(u, p)             \
174
576M
     (ISA_UNRESERVED(u, p) || ISA_PCT_ENCODED(p) || ISA_SUB_DELIM(p) ||  \
175
322M
      ((*(p) == ':')) || ((*(p) == '@')))
176
177
/*
178
 * From https://www.w3.org/TR/leiri/
179
 *
180
 * " " / "<" / ">" / '"' / "{" / "}" / "|"
181
 * / "\" / "^" / "`" / %x0-1F / %x7F-D7FF
182
 * / %xE000-FFFD / %x10000-10FFFF
183
 */
184
#define ISA_UCSCHAR(p) \
185
0
    ((*(p) <= 0x20) || (*(p) >= 0x7F) || (*(p) == '<') || (*(p) == '>') || \
186
0
     (*(p) == '"')  || (*(p) == '{')  || (*(p) == '}') || (*(p) == '|') || \
187
0
     (*(p) == '\\') || (*(p) == '^')  || (*(p) == '`'))
188
189
665M
#define ISA_UNRESERVED(u, p) (xmlIsUnreserved(u, p))
190
191
48.0M
#define XML_URI_ALLOW_UNWISE    1
192
2.36M
#define XML_URI_NO_UNESCAPE     2
193
47.9M
#define XML_URI_ALLOW_UCSCHAR   4
194
195
static int
196
332M
xmlIsUnreserved(xmlURIPtr uri, const char *cur) {
197
332M
    if (uri == NULL)
198
0
        return(0);
199
200
332M
    if (ISA_STRICTLY_UNRESERVED(cur))
201
284M
        return(1);
202
203
48.0M
    if (uri->cleanup & XML_URI_ALLOW_UNWISE) {
204
108k
        if (IS_UNWISE(cur))
205
3.76k
            return(1);
206
47.9M
    } else if (uri->cleanup & XML_URI_ALLOW_UCSCHAR) {
207
0
        if (ISA_UCSCHAR(cur))
208
0
            return(1);
209
0
    }
210
211
48.0M
    return(0);
212
48.0M
}
213
214
/**
215
 * Parse an URI scheme
216
 *
217
 * ALPHA *( ALPHA / DIGIT / "+" / "-" / "." )
218
 *
219
 * @param uri  pointer to an URI structure
220
 * @param str  pointer to the string to analyze
221
 * @returns 0 or the error code
222
 */
223
static int
224
2.19M
xmlParse3986Scheme(xmlURIPtr uri, const char **str) {
225
2.19M
    const char *cur;
226
227
2.19M
    cur = *str;
228
2.19M
    if (!ISA_ALPHA(cur))
229
1.42M
  return(1);
230
769k
    cur++;
231
232
#if defined(LIBXML_WINPATH_ENABLED)
233
    /*
234
     * Don't treat Windows drive letters as scheme.
235
     */
236
    if (*cur == ':')
237
        return(1);
238
#endif
239
240
3.98M
    while (ISA_ALPHA(cur) || ISA_DIGIT(cur) ||
241
3.21M
           (*cur == '+') || (*cur == '-') || (*cur == '.')) cur++;
242
769k
    if (uri != NULL) {
243
769k
  if (uri->scheme != NULL) xmlFree(uri->scheme);
244
769k
  uri->scheme = STRNDUP(*str, cur - *str);
245
769k
        if (uri->scheme == NULL)
246
201
            return(-1);
247
769k
    }
248
769k
    *str = cur;
249
769k
    return(0);
250
769k
}
251
252
/**
253
 * Parse the query part of an URI
254
 *
255
 * fragment      = *( pchar / "/" / "?" )
256
 * NOTE: the strict syntax as defined by 3986 does not allow '[' and ']'
257
 *       in the fragment identifier but this is used very broadly for
258
 *       xpointer scheme selection, so we are allowing it here to not break
259
 *       for example all the DocBook processing chains.
260
 *
261
 * @param uri  pointer to an URI structure
262
 * @param str  pointer to the string to analyze
263
 * @returns 0 or the error code
264
 */
265
static int
266
xmlParse3986Fragment(xmlURIPtr uri, const char **str)
267
1.08M
{
268
1.08M
    const char *cur;
269
270
1.08M
    cur = *str;
271
272
17.5M
    while ((ISA_PCHAR(uri, cur)) || (*cur == '/') || (*cur == '?') ||
273
1.31M
           (*cur == '[') || (*cur == ']'))
274
16.4M
        NEXT(cur);
275
1.08M
    if (uri != NULL) {
276
1.08M
        if (uri->fragment != NULL)
277
0
            xmlFree(uri->fragment);
278
1.08M
  if (uri->cleanup & XML_URI_NO_UNESCAPE)
279
623
      uri->fragment = STRNDUP(*str, cur - *str);
280
1.08M
  else
281
1.08M
      uri->fragment = xmlURIUnescapeString(*str, cur - *str, NULL);
282
1.08M
        if (uri->fragment == NULL)
283
133
            return (-1);
284
1.08M
    }
285
1.08M
    *str = cur;
286
1.08M
    return (0);
287
1.08M
}
288
289
/**
290
 * Parse the query part of an URI
291
 *
292
 * query = *uric
293
 *
294
 * @param uri  pointer to an URI structure
295
 * @param str  pointer to the string to analyze
296
 * @returns 0 or the error code
297
 */
298
static int
299
xmlParse3986Query(xmlURIPtr uri, const char **str)
300
82.9k
{
301
82.9k
    const char *cur;
302
303
82.9k
    cur = *str;
304
305
47.7M
    while ((ISA_PCHAR(uri, cur)) || (*cur == '/') || (*cur == '?'))
306
47.6M
        NEXT(cur);
307
82.9k
    if (uri != NULL) {
308
82.9k
        if (uri->query != NULL)
309
0
            xmlFree(uri->query);
310
82.9k
  if (uri->cleanup & XML_URI_NO_UNESCAPE)
311
488
      uri->query = STRNDUP(*str, cur - *str);
312
82.4k
  else
313
82.4k
      uri->query = xmlURIUnescapeString(*str, cur - *str, NULL);
314
82.9k
        if (uri->query == NULL)
315
80
            return (-1);
316
317
  /* Save the raw bytes of the query as well.
318
   * See: http://mail.gnome.org/archives/xml/2007-April/thread.html#00114
319
   */
320
82.8k
  if (uri->query_raw != NULL)
321
0
      xmlFree (uri->query_raw);
322
82.8k
  uri->query_raw = STRNDUP (*str, cur - *str);
323
82.8k
        if (uri->query_raw == NULL)
324
118
            return (-1);
325
82.8k
    }
326
82.7k
    *str = cur;
327
82.7k
    return (0);
328
82.9k
}
329
330
/**
331
 * Parse a port part and fills in the appropriate fields
332
 * of the `uri` structure
333
 *
334
 * port          = *DIGIT
335
 *
336
 * @param uri  pointer to an URI structure
337
 * @param str  the string to analyze
338
 * @returns 0 or the error code
339
 */
340
static int
341
xmlParse3986Port(xmlURIPtr uri, const char **str)
342
19.0k
{
343
19.0k
    const char *cur = *str;
344
19.0k
    int port = 0;
345
346
19.0k
    if (ISA_DIGIT(cur)) {
347
74.2k
  while (ISA_DIGIT(cur)) {
348
64.4k
            int digit = *cur - '0';
349
350
64.4k
            if (port > INT_MAX / 10)
351
1.58k
                return(1);
352
62.8k
            port *= 10;
353
62.8k
            if (port > INT_MAX - digit)
354
1.60k
                return(1);
355
61.2k
      port += digit;
356
357
61.2k
      cur++;
358
61.2k
  }
359
9.81k
  if (uri != NULL)
360
9.81k
      uri->port = port;
361
9.81k
  *str = cur;
362
9.81k
  return(0);
363
13.0k
    }
364
6.08k
    return(1);
365
19.0k
}
366
367
/**
368
 * Parse an user information part and fills in the appropriate fields
369
 * of the `uri` structure
370
 *
371
 * userinfo      = *( unreserved / pct-encoded / sub-delims / ":" )
372
 *
373
 * @param uri  pointer to an URI structure
374
 * @param str  the string to analyze
375
 * @returns 0 or the error code
376
 */
377
static int
378
xmlParse3986Userinfo(xmlURIPtr uri, const char **str)
379
231k
{
380
231k
    const char *cur;
381
382
231k
    cur = *str;
383
4.55M
    while (ISA_UNRESERVED(uri, cur) || ISA_PCT_ENCODED(cur) ||
384
621k
           ISA_SUB_DELIM(cur) || (*cur == ':'))
385
4.32M
  NEXT(cur);
386
231k
    if (*cur == '@') {
387
46.0k
  if (uri != NULL) {
388
46.0k
      if (uri->user != NULL) xmlFree(uri->user);
389
46.0k
      if (uri->cleanup & XML_URI_NO_UNESCAPE)
390
517
    uri->user = STRNDUP(*str, cur - *str);
391
45.5k
      else
392
45.5k
    uri->user = xmlURIUnescapeString(*str, cur - *str, NULL);
393
46.0k
            if (uri->user == NULL)
394
45
                return(-1);
395
46.0k
  }
396
45.9k
  *str = cur;
397
45.9k
  return(0);
398
46.0k
    }
399
185k
    return(1);
400
231k
}
401
402
/**
403
 *    dec-octet     = DIGIT                 ; 0-9
404
 *                  / %x31-39 DIGIT         ; 10-99
405
 *                  / "1" 2DIGIT            ; 100-199
406
 *                  / "2" %x30-34 DIGIT     ; 200-249
407
 *                  / "25" %x30-35          ; 250-255
408
 *
409
 * Skip a dec-octet.
410
 *
411
 * @param str  the string to analyze
412
 * @returns 0 if found and skipped, 1 otherwise
413
 */
414
static int
415
84.7k
xmlParse3986DecOctet(const char **str) {
416
84.7k
    const char *cur = *str;
417
418
84.7k
    if (!(ISA_DIGIT(cur)))
419
11.6k
        return(1);
420
73.1k
    if (!ISA_DIGIT(cur+1))
421
42.1k
  cur++;
422
30.9k
    else if ((*cur != '0') && (ISA_DIGIT(cur + 1)) && (!ISA_DIGIT(cur+2)))
423
8.60k
  cur += 2;
424
22.3k
    else if ((*cur == '1') && (ISA_DIGIT(cur + 1)) && (ISA_DIGIT(cur + 2)))
425
4.85k
  cur += 3;
426
17.4k
    else if ((*cur == '2') && (*(cur + 1) >= '0') &&
427
10.3k
       (*(cur + 1) <= '4') && (ISA_DIGIT(cur + 2)))
428
4.17k
  cur += 3;
429
13.2k
    else if ((*cur == '2') && (*(cur + 1) == '5') &&
430
3.35k
       (*(cur + 2) >= '0') && (*(cur + 1) <= '5'))
431
3.35k
  cur += 3;
432
9.91k
    else
433
9.91k
        return(1);
434
63.1k
    *str = cur;
435
63.1k
    return(0);
436
73.1k
}
437
/**
438
 * Parse an host part and fills in the appropriate fields
439
 * of the `uri` structure
440
 *
441
 * host          = IP-literal / IPv4address / reg-name
442
 * IP-literal    = "[" ( IPv6address / IPvFuture  ) "]"
443
 * IPv4address   = dec-octet "." dec-octet "." dec-octet "." dec-octet
444
 * reg-name      = *( unreserved / pct-encoded / sub-delims )
445
 *
446
 * @param uri  pointer to an URI structure
447
 * @param str  the string to analyze
448
 * @returns 0 or the error code
449
 */
450
static int
451
xmlParse3986Host(xmlURIPtr uri, const char **str)
452
231k
{
453
231k
    const char *cur = *str;
454
231k
    const char *host;
455
456
231k
    host = cur;
457
    /*
458
     * IPv6 and future addressing scheme are enclosed between brackets
459
     */
460
231k
    if (*cur == '[') {
461
13.0k
        cur++;
462
256M
  while ((*cur != ']') && (*cur != 0))
463
256M
      cur++;
464
13.0k
  if (*cur != ']')
465
5.95k
      return(1);
466
7.09k
  cur++;
467
7.09k
  goto found;
468
13.0k
    }
469
    /*
470
     * try to parse an IPv4
471
     */
472
218k
    if (ISA_DIGIT(cur)) {
473
52.0k
        if (xmlParse3986DecOctet(&cur) != 0)
474
5.31k
      goto not_ipv4;
475
46.7k
  if (*cur != '.')
476
19.4k
      goto not_ipv4;
477
27.3k
  cur++;
478
27.3k
        if (xmlParse3986DecOctet(&cur) != 0)
479
10.8k
      goto not_ipv4;
480
16.4k
  if (*cur != '.')
481
11.1k
      goto not_ipv4;
482
5.31k
        if (xmlParse3986DecOctet(&cur) != 0)
483
5.31k
      goto not_ipv4;
484
0
  if (*cur != '.')
485
0
      goto not_ipv4;
486
0
        if (xmlParse3986DecOctet(&cur) != 0)
487
0
      goto not_ipv4;
488
0
  goto found;
489
52.0k
not_ipv4:
490
52.0k
        cur = *str;
491
52.0k
    }
492
    /*
493
     * then this should be a hostname which can be empty
494
     */
495
6.24M
    while (ISA_UNRESERVED(uri, cur) ||
496
384k
           ISA_PCT_ENCODED(cur) || ISA_SUB_DELIM(cur))
497
6.02M
        NEXT(cur);
498
225k
found:
499
225k
    if (uri != NULL) {
500
225k
  if (uri->authority != NULL) xmlFree(uri->authority);
501
225k
  uri->authority = NULL;
502
225k
  if (uri->server != NULL) xmlFree(uri->server);
503
225k
  if (cur != host) {
504
184k
      if (uri->cleanup & XML_URI_NO_UNESCAPE)
505
782
    uri->server = STRNDUP(host, cur - host);
506
184k
      else
507
184k
    uri->server = xmlURIUnescapeString(host, cur - host, NULL);
508
184k
            if (uri->server == NULL)
509
114
                return(-1);
510
184k
  } else
511
40.5k
      uri->server = NULL;
512
225k
    }
513
225k
    *str = cur;
514
225k
    return(0);
515
225k
}
516
517
/**
518
 * Parse an authority part and fills in the appropriate fields
519
 * of the `uri` structure
520
 *
521
 * authority     = [ userinfo "@" ] host [ ":" port ]
522
 *
523
 * @param uri  pointer to an URI structure
524
 * @param str  the string to analyze
525
 * @returns 0 or the error code
526
 */
527
static int
528
xmlParse3986Authority(xmlURIPtr uri, const char **str)
529
231k
{
530
231k
    const char *cur;
531
231k
    int ret;
532
533
231k
    cur = *str;
534
    /*
535
     * try to parse an userinfo and check for the trailing @
536
     */
537
231k
    ret = xmlParse3986Userinfo(uri, &cur);
538
231k
    if (ret < 0)
539
45
        return(ret);
540
231k
    if ((ret != 0) || (*cur != '@'))
541
185k
        cur = *str;
542
45.9k
    else
543
45.9k
        cur++;
544
231k
    ret = xmlParse3986Host(uri, &cur);
545
231k
    if (ret != 0) return(ret);
546
225k
    if (*cur == ':') {
547
19.0k
        cur++;
548
19.0k
        ret = xmlParse3986Port(uri, &cur);
549
19.0k
  if (ret != 0) return(ret);
550
19.0k
    }
551
215k
    *str = cur;
552
215k
    return(0);
553
225k
}
554
555
/**
556
 * Parse a segment and fills in the appropriate fields
557
 * of the `uri` structure
558
 *
559
 * segment       = *pchar
560
 * segment-nz    = 1*pchar
561
 * segment-nz-nc = 1*( unreserved / pct-encoded / sub-delims / "@" )
562
 *               ; non-zero-length segment without any colon ":"
563
 *
564
 * @param uri  the URI
565
 * @param str  the string to analyze
566
 * @param forbid  an optional forbidden character
567
 * @param empty  allow an empty segment
568
 * @returns 0 or the error code
569
 */
570
static int
571
xmlParse3986Segment(xmlURIPtr uri, const char **str, char forbid, int empty)
572
5.17M
{
573
5.17M
    const char *cur;
574
575
5.17M
    cur = *str;
576
5.17M
    if (!ISA_PCHAR(uri, cur) || (*cur == forbid)) {
577
326k
        if (empty)
578
283k
      return(0);
579
43.1k
  return(1);
580
326k
    }
581
4.84M
    NEXT(cur);
582
583
#if defined(LIBXML_WINPATH_ENABLED)
584
    /*
585
     * Allow Windows drive letters.
586
     */
587
    if ((forbid == ':') && (*cur == forbid))
588
        NEXT(cur);
589
#endif
590
591
249M
    while (ISA_PCHAR(uri, cur) && (*cur != forbid))
592
244M
        NEXT(cur);
593
4.84M
    *str = cur;
594
4.84M
    return (0);
595
5.17M
}
596
597
/**
598
 * Parse an path absolute or empty and fills in the appropriate fields
599
 * of the `uri` structure
600
 *
601
 * path-abempty  = *( "/" segment )
602
 *
603
 * @param uri  pointer to an URI structure
604
 * @param str  the string to analyze
605
 * @returns 0 or the error code
606
 */
607
static int
608
xmlParse3986PathAbEmpty(xmlURIPtr uri, const char **str)
609
215k
{
610
215k
    const char *cur;
611
215k
    int ret;
612
613
215k
    cur = *str;
614
615
505k
    while (*cur == '/') {
616
289k
        cur++;
617
289k
  ret = xmlParse3986Segment(uri, &cur, 0, 1);
618
289k
  if (ret != 0) return(ret);
619
289k
    }
620
215k
    if (uri != NULL) {
621
215k
  if (uri->path != NULL) xmlFree(uri->path);
622
215k
        if (*str != cur) {
623
88.2k
            if (uri->cleanup & XML_URI_NO_UNESCAPE)
624
142
                uri->path = STRNDUP(*str, cur - *str);
625
88.0k
            else
626
88.0k
                uri->path = xmlURIUnescapeString(*str, cur - *str, NULL);
627
88.2k
            if (uri->path == NULL)
628
62
                return (-1);
629
127k
        } else {
630
127k
            uri->path = NULL;
631
127k
        }
632
215k
    }
633
215k
    *str = cur;
634
215k
    return (0);
635
215k
}
636
637
/**
638
 * Parse an path absolute and fills in the appropriate fields
639
 * of the `uri` structure
640
 *
641
 * path-absolute = "/" [ segment-nz *( "/" segment ) ]
642
 *
643
 * @param uri  pointer to an URI structure
644
 * @param str  the string to analyze
645
 * @returns 0 or the error code
646
 */
647
static int
648
xmlParse3986PathAbsolute(xmlURIPtr uri, const char **str)
649
34.6k
{
650
34.6k
    const char *cur;
651
34.6k
    int ret;
652
653
34.6k
    cur = *str;
654
655
34.6k
    if (*cur != '/')
656
0
        return(1);
657
34.6k
    cur++;
658
34.6k
    ret = xmlParse3986Segment(uri, &cur, 0, 0);
659
34.6k
    if (ret == 0) {
660
52.4k
  while (*cur == '/') {
661
35.6k
      cur++;
662
35.6k
      ret = xmlParse3986Segment(uri, &cur, 0, 1);
663
35.6k
      if (ret != 0) return(ret);
664
35.6k
  }
665
16.8k
    }
666
34.6k
    if (uri != NULL) {
667
34.6k
  if (uri->path != NULL) xmlFree(uri->path);
668
34.6k
        if (cur != *str) {
669
34.6k
            if (uri->cleanup & XML_URI_NO_UNESCAPE)
670
259
                uri->path = STRNDUP(*str, cur - *str);
671
34.4k
            else
672
34.4k
                uri->path = xmlURIUnescapeString(*str, cur - *str, NULL);
673
34.6k
            if (uri->path == NULL)
674
69
                return (-1);
675
34.6k
        } else {
676
0
            uri->path = NULL;
677
0
        }
678
34.6k
    }
679
34.6k
    *str = cur;
680
34.6k
    return (0);
681
34.6k
}
682
683
/**
684
 * Parse an path without root and fills in the appropriate fields
685
 * of the `uri` structure
686
 *
687
 * path-rootless = segment-nz *( "/" segment )
688
 *
689
 * @param uri  pointer to an URI structure
690
 * @param str  the string to analyze
691
 * @returns 0 or the error code
692
 */
693
static int
694
xmlParse3986PathRootless(xmlURIPtr uri, const char **str)
695
108k
{
696
108k
    const char *cur;
697
108k
    int ret;
698
699
108k
    cur = *str;
700
701
108k
    ret = xmlParse3986Segment(uri, &cur, 0, 0);
702
108k
    if (ret != 0) return(ret);
703
155k
    while (*cur == '/') {
704
47.1k
        cur++;
705
47.1k
  ret = xmlParse3986Segment(uri, &cur, 0, 1);
706
47.1k
  if (ret != 0) return(ret);
707
47.1k
    }
708
108k
    if (uri != NULL) {
709
108k
  if (uri->path != NULL) xmlFree(uri->path);
710
108k
        if (cur != *str) {
711
108k
            if (uri->cleanup & XML_URI_NO_UNESCAPE)
712
78
                uri->path = STRNDUP(*str, cur - *str);
713
108k
            else
714
108k
                uri->path = xmlURIUnescapeString(*str, cur - *str, NULL);
715
108k
            if (uri->path == NULL)
716
47
                return (-1);
717
108k
        } else {
718
0
            uri->path = NULL;
719
0
        }
720
108k
    }
721
108k
    *str = cur;
722
108k
    return (0);
723
108k
}
724
725
/**
726
 * Parse an path which is not a scheme and fills in the appropriate fields
727
 * of the `uri` structure
728
 *
729
 * path-noscheme = segment-nz-nc *( "/" segment )
730
 *
731
 * @param uri  pointer to an URI structure
732
 * @param str  the string to analyze
733
 * @returns 0 or the error code
734
 */
735
static int
736
xmlParse3986PathNoScheme(xmlURIPtr uri, const char **str)
737
762k
{
738
762k
    const char *cur;
739
762k
    int ret;
740
741
762k
    cur = *str;
742
743
762k
    ret = xmlParse3986Segment(uri, &cur, ':', 0);
744
762k
    if (ret != 0) return(ret);
745
4.63M
    while (*cur == '/') {
746
3.89M
        cur++;
747
3.89M
  ret = xmlParse3986Segment(uri, &cur, 0, 1);
748
3.89M
  if (ret != 0) return(ret);
749
3.89M
    }
750
736k
    if (uri != NULL) {
751
736k
  if (uri->path != NULL) xmlFree(uri->path);
752
736k
        if (cur != *str) {
753
736k
            if (uri->cleanup & XML_URI_NO_UNESCAPE)
754
990
                uri->path = STRNDUP(*str, cur - *str);
755
735k
            else
756
735k
                uri->path = xmlURIUnescapeString(*str, cur - *str, NULL);
757
736k
            if (uri->path == NULL)
758
294
                return (-1);
759
736k
        } else {
760
0
            uri->path = NULL;
761
0
        }
762
736k
    }
763
736k
    *str = cur;
764
736k
    return (0);
765
736k
}
766
767
/**
768
 * Parse an hierarchical part and fills in the appropriate fields
769
 * of the `uri` structure
770
 *
771
 * hier-part     = "//" authority path-abempty
772
 *                / path-absolute
773
 *                / path-rootless
774
 *                / path-empty
775
 *
776
 * @param uri  pointer to an URI structure
777
 * @param str  the string to analyze
778
 * @returns 0 or the error code
779
 */
780
static int
781
xmlParse3986HierPart(xmlURIPtr uri, const char **str)
782
380k
{
783
380k
    const char *cur;
784
380k
    int ret;
785
786
380k
    cur = *str;
787
788
380k
    if ((*cur == '/') && (*(cur + 1) == '/')) {
789
163k
        cur += 2;
790
163k
  ret = xmlParse3986Authority(uri, &cur);
791
163k
  if (ret != 0) return(ret);
792
        /*
793
         * An empty server is marked with a special URI value.
794
         */
795
158k
  if ((uri->server == NULL) && (uri->port == PORT_EMPTY))
796
21.6k
      uri->port = PORT_EMPTY_SERVER;
797
158k
  ret = xmlParse3986PathAbEmpty(uri, &cur);
798
158k
  if (ret != 0) return(ret);
799
158k
  *str = cur;
800
158k
  return(0);
801
217k
    } else if (*cur == '/') {
802
8.46k
        ret = xmlParse3986PathAbsolute(uri, &cur);
803
8.46k
  if (ret != 0) return(ret);
804
208k
    } else if (ISA_PCHAR(uri, cur)) {
805
108k
        ret = xmlParse3986PathRootless(uri, &cur);
806
108k
  if (ret != 0) return(ret);
807
108k
    } else {
808
  /* path-empty is effectively empty */
809
100k
  if (uri != NULL) {
810
100k
      if (uri->path != NULL) xmlFree(uri->path);
811
100k
      uri->path = NULL;
812
100k
  }
813
100k
    }
814
217k
    *str = cur;
815
217k
    return (0);
816
380k
}
817
818
/**
819
 * Parse an URI string and fills in the appropriate fields
820
 * of the `uri` structure
821
 *
822
 * relative-ref  = relative-part [ "?" query ] [ "\#" fragment ]
823
 * relative-part = "//" authority path-abempty
824
 *               / path-absolute
825
 *               / path-noscheme
826
 *               / path-empty
827
 *
828
 * @param uri  pointer to an URI structure
829
 * @param str  the string to analyze
830
 * @returns 0 or the error code
831
 */
832
static int
833
1.97M
xmlParse3986RelativeRef(xmlURIPtr uri, const char *str) {
834
1.97M
    int ret;
835
836
1.97M
    if ((*str == '/') && (*(str + 1) == '/')) {
837
68.2k
        str += 2;
838
68.2k
  ret = xmlParse3986Authority(uri, &str);
839
68.2k
  if (ret != 0) return(ret);
840
57.3k
  ret = xmlParse3986PathAbEmpty(uri, &str);
841
57.3k
  if (ret != 0) return(ret);
842
1.90M
    } else if (*str == '/') {
843
26.2k
  ret = xmlParse3986PathAbsolute(uri, &str);
844
26.2k
  if (ret != 0) return(ret);
845
1.88M
    } else if (ISA_PCHAR(uri, str)) {
846
762k
        ret = xmlParse3986PathNoScheme(uri, &str);
847
762k
  if (ret != 0) return(ret);
848
1.11M
    } else {
849
  /* path-empty is effectively empty */
850
1.11M
  if (uri != NULL) {
851
1.11M
      if (uri->path != NULL) xmlFree(uri->path);
852
1.11M
      uri->path = NULL;
853
1.11M
  }
854
1.11M
    }
855
856
1.93M
    if (*str == '?') {
857
63.2k
  str++;
858
63.2k
  ret = xmlParse3986Query(uri, &str);
859
63.2k
  if (ret != 0) return(ret);
860
63.2k
    }
861
1.93M
    if (*str == '#') {
862
1.06M
  str++;
863
1.06M
  ret = xmlParse3986Fragment(uri, &str);
864
1.06M
  if (ret != 0) return(ret);
865
1.06M
    }
866
1.93M
    if (*str != 0) {
867
353k
  xmlCleanURI(uri);
868
353k
  return(1);
869
353k
    }
870
1.58M
    return(0);
871
1.93M
}
872
873
874
/**
875
 * Parse an URI string and fills in the appropriate fields
876
 * of the `uri` structure
877
 *
878
 * scheme ":" hier-part [ "?" query ] [ "\#" fragment ]
879
 *
880
 * @param uri  pointer to an URI structure
881
 * @param str  the string to analyze
882
 * @returns 0 or the error code
883
 */
884
static int
885
2.19M
xmlParse3986URI(xmlURIPtr uri, const char *str) {
886
2.19M
    int ret;
887
888
2.19M
    ret = xmlParse3986Scheme(uri, &str);
889
2.19M
    if (ret != 0) return(ret);
890
769k
    if (*str != ':') {
891
389k
  return(1);
892
389k
    }
893
380k
    str++;
894
380k
    ret = xmlParse3986HierPart(uri, &str);
895
380k
    if (ret != 0) return(ret);
896
375k
    if (*str == '?') {
897
19.7k
  str++;
898
19.7k
  ret = xmlParse3986Query(uri, &str);
899
19.7k
  if (ret != 0) return(ret);
900
19.7k
    }
901
375k
    if (*str == '#') {
902
20.5k
  str++;
903
20.5k
  ret = xmlParse3986Fragment(uri, &str);
904
20.5k
  if (ret != 0) return(ret);
905
20.5k
    }
906
375k
    if (*str != 0) {
907
159k
  xmlCleanURI(uri);
908
159k
  return(1);
909
159k
    }
910
215k
    return(0);
911
375k
}
912
913
/**
914
 * Parse an URI reference string and fills in the appropriate fields
915
 * of the `uri` structure
916
 *
917
 * URI-reference = URI / relative-ref
918
 *
919
 * @param uri  pointer to an URI structure
920
 * @param str  the string to analyze
921
 * @returns 0 or the error code
922
 */
923
static int
924
2.19M
xmlParse3986URIReference(xmlURIPtr uri, const char *str) {
925
2.19M
    int ret;
926
927
2.19M
    if (str == NULL)
928
0
  return(-1);
929
2.19M
    xmlCleanURI(uri);
930
931
    /*
932
     * Try first to parse absolute refs, then fallback to relative if
933
     * it fails.
934
     */
935
2.19M
    ret = xmlParse3986URI(uri, str);
936
2.19M
    if (ret < 0)
937
443
        return(ret);
938
2.19M
    if (ret != 0) {
939
1.97M
  xmlCleanURI(uri);
940
1.97M
        ret = xmlParse3986RelativeRef(uri, str);
941
1.97M
  if (ret != 0) {
942
389k
      xmlCleanURI(uri);
943
389k
      return(ret);
944
389k
  }
945
1.97M
    }
946
1.80M
    return(0);
947
2.19M
}
948
949
/**
950
 * Parse an URI based on RFC 3986
951
 *
952
 * URI-reference = [ absoluteURI | relativeURI ] [ "\#" fragment ]
953
 *
954
 * @since 2.13.0
955
 *
956
 * @param str  the URI string to analyze
957
 * @param uriOut  optional pointer to parsed URI
958
 * @returns 0 on success, an error code (typically 1) if the URI is invalid
959
 * or -1 if a memory allocation failed.
960
 */
961
int
962
2.16M
xmlParseURISafe(const char *str, xmlURI **uriOut) {
963
2.16M
    xmlURIPtr uri;
964
2.16M
    int ret;
965
966
2.16M
    if (uriOut == NULL)
967
0
        return(1);
968
2.16M
    *uriOut = NULL;
969
2.16M
    if (str == NULL)
970
10
  return(1);
971
972
2.16M
    uri = xmlCreateURI();
973
2.16M
    if (uri == NULL)
974
873
        return(-1);
975
976
2.16M
    ret = xmlParse3986URIReference(uri, str);
977
2.16M
    if (ret) {
978
381k
        xmlFreeURI(uri);
979
381k
        return(ret);
980
381k
    }
981
982
1.77M
    *uriOut = uri;
983
1.77M
    return(0);
984
2.16M
}
985
986
/**
987
 * Parse an URI based on RFC 3986
988
 *
989
 * URI-reference = [ absoluteURI | relativeURI ] [ "\#" fragment ]
990
 *
991
 * @param str  the URI string to analyze
992
 * @returns a newly built xmlURI or NULL in case of error
993
 */
994
xmlURI *
995
121k
xmlParseURI(const char *str) {
996
121k
    xmlURIPtr uri;
997
121k
    xmlParseURISafe(str, &uri);
998
121k
    return(uri);
999
121k
}
1000
1001
/**
1002
 * Parse an URI reference string based on RFC 3986 and fills in the
1003
 * appropriate fields of the `uri` structure
1004
 *
1005
 * URI-reference = URI / relative-ref
1006
 *
1007
 * @param uri  pointer to an URI structure
1008
 * @param str  the string to analyze
1009
 * @returns 0 or the error code
1010
 */
1011
int
1012
31.0k
xmlParseURIReference(xmlURI *uri, const char *str) {
1013
31.0k
    return(xmlParse3986URIReference(uri, str));
1014
31.0k
}
1015
1016
/**
1017
 * Parse an URI but allows to keep intact the original fragments.
1018
 *
1019
 * URI-reference = URI / relative-ref
1020
 *
1021
 * @param str  the URI string to analyze
1022
 * @param raw  if 1 unescaping of URI pieces are disabled
1023
 * @returns a newly built xmlURI or NULL in case of error
1024
 */
1025
xmlURI *
1026
4.48k
xmlParseURIRaw(const char *str, int raw) {
1027
4.48k
    xmlURIPtr uri;
1028
4.48k
    int ret;
1029
1030
4.48k
    if (str == NULL)
1031
5
  return(NULL);
1032
4.47k
    uri = xmlCreateURI();
1033
4.47k
    if (uri != NULL) {
1034
4.39k
        if (raw) {
1035
4.39k
      uri->cleanup |= XML_URI_NO_UNESCAPE;
1036
4.39k
  }
1037
4.39k
  ret = xmlParseURIReference(uri, str);
1038
4.39k
        if (ret) {
1039
1.57k
      xmlFreeURI(uri);
1040
1.57k
      return(NULL);
1041
1.57k
  }
1042
4.39k
    }
1043
2.90k
    return(uri);
1044
4.47k
}
1045
1046
/************************************************************************
1047
 *                  *
1048
 *      Generic URI structure functions     *
1049
 *                  *
1050
 ************************************************************************/
1051
1052
/**
1053
 * Simply creates an empty xmlURI
1054
 *
1055
 * @returns the new structure or NULL in case of error
1056
 */
1057
xmlURI *
1058
2.35M
xmlCreateURI(void) {
1059
2.35M
    xmlURIPtr ret;
1060
1061
2.35M
    ret = (xmlURIPtr) xmlMalloc(sizeof(xmlURI));
1062
2.35M
    if (ret == NULL)
1063
1.12k
  return(NULL);
1064
2.35M
    memset(ret, 0, sizeof(xmlURI));
1065
2.35M
    ret->port = PORT_EMPTY;
1066
2.35M
    return(ret);
1067
2.35M
}
1068
1069
/**
1070
 * Function to handle properly a reallocation when saving an URI
1071
 * Also imposes some limit on the length of an URI string output
1072
 */
1073
static xmlChar *
1074
161k
xmlSaveUriRealloc(xmlChar *ret, int *max) {
1075
161k
    xmlChar *temp;
1076
161k
    int newSize;
1077
1078
161k
    newSize = xmlGrowCapacity(*max, 1, 80, MAX_URI_LENGTH);
1079
161k
    if (newSize < 0)
1080
28
        return(NULL);
1081
161k
    temp = xmlRealloc(ret, newSize + 1);
1082
161k
    if (temp == NULL)
1083
250
        return(NULL);
1084
161k
    *max = newSize;
1085
161k
    return(temp);
1086
161k
}
1087
1088
/**
1089
 * Save the URI as an escaped string
1090
 *
1091
 * @param uri  pointer to an xmlURI
1092
 * @returns a new string (to be deallocated by caller)
1093
 */
1094
xmlChar *
1095
230k
xmlSaveUri(xmlURI *uri) {
1096
230k
    xmlChar *ret = NULL;
1097
230k
    xmlChar *temp;
1098
230k
    const char *p;
1099
230k
    int len;
1100
230k
    int max;
1101
1102
230k
    if (uri == NULL) return(NULL);
1103
1104
1105
228k
    max = 80;
1106
228k
    ret = xmlMalloc(max + 1);
1107
228k
    if (ret == NULL)
1108
490
  return(NULL);
1109
227k
    len = 0;
1110
1111
227k
    if (uri->scheme != NULL) {
1112
50.1k
  p = uri->scheme;
1113
957k
  while (*p != 0) {
1114
907k
      if (len >= max) {
1115
2.26k
                temp = xmlSaveUriRealloc(ret, &max);
1116
2.26k
                if (temp == NULL) goto mem_error;
1117
2.25k
    ret = temp;
1118
2.25k
      }
1119
907k
      ret[len++] = *p++;
1120
907k
  }
1121
50.1k
  if (len >= max) {
1122
920
            temp = xmlSaveUriRealloc(ret, &max);
1123
920
            if (temp == NULL) goto mem_error;
1124
911
            ret = temp;
1125
911
  }
1126
50.1k
  ret[len++] = ':';
1127
50.1k
    }
1128
227k
    if (uri->opaque != NULL) {
1129
0
  p = uri->opaque;
1130
0
  while (*p != 0) {
1131
0
      if (len + 3 >= max) {
1132
0
                temp = xmlSaveUriRealloc(ret, &max);
1133
0
                if (temp == NULL) goto mem_error;
1134
0
                ret = temp;
1135
0
      }
1136
0
      if (IS_RESERVED(*(p)) || IS_UNRESERVED(*(p)))
1137
0
    ret[len++] = *p++;
1138
0
      else {
1139
0
    int val = *(unsigned char *)p++;
1140
0
    int hi = val / 0x10, lo = val % 0x10;
1141
0
    ret[len++] = '%';
1142
0
    ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1143
0
    ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1144
0
      }
1145
0
  }
1146
227k
    } else {
1147
227k
  if ((uri->server != NULL) || (uri->port != PORT_EMPTY)) {
1148
49.3k
      if (len + 3 >= max) {
1149
962
                temp = xmlSaveUriRealloc(ret, &max);
1150
962
                if (temp == NULL) goto mem_error;
1151
954
                ret = temp;
1152
954
      }
1153
49.3k
      ret[len++] = '/';
1154
49.3k
      ret[len++] = '/';
1155
49.3k
      if (uri->user != NULL) {
1156
19.7k
    p = uri->user;
1157
58.4M
    while (*p != 0) {
1158
58.4M
        if (len + 3 >= max) {
1159
25.9k
                        temp = xmlSaveUriRealloc(ret, &max);
1160
25.9k
                        if (temp == NULL) goto mem_error;
1161
25.9k
                        ret = temp;
1162
25.9k
        }
1163
58.4M
        if ((IS_UNRESERVED(*(p))) ||
1164
20.4M
      ((*(p) == ';')) || ((*(p) == ':')) ||
1165
20.2M
      ((*(p) == '&')) || ((*(p) == '=')) ||
1166
20.0M
      ((*(p) == '+')) || ((*(p) == '$')) ||
1167
19.9M
      ((*(p) == ',')))
1168
38.5M
      ret[len++] = *p++;
1169
19.8M
        else {
1170
19.8M
      int val = *(unsigned char *)p++;
1171
19.8M
      int hi = val / 0x10, lo = val % 0x10;
1172
19.8M
      ret[len++] = '%';
1173
19.8M
      ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1174
19.8M
      ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1175
19.8M
        }
1176
58.4M
    }
1177
19.7k
    if (len + 3 >= max) {
1178
1.53k
                    temp = xmlSaveUriRealloc(ret, &max);
1179
1.53k
                    if (temp == NULL) goto mem_error;
1180
1.51k
                    ret = temp;
1181
1.51k
    }
1182
19.6k
    ret[len++] = '@';
1183
19.6k
      }
1184
49.2k
      if (uri->server != NULL) {
1185
35.3k
    p = uri->server;
1186
138M
    while (*p != 0) {
1187
138M
        if (len >= max) {
1188
9.40k
      temp = xmlSaveUriRealloc(ret, &max);
1189
9.40k
      if (temp == NULL) goto mem_error;
1190
9.37k
      ret = temp;
1191
9.37k
        }
1192
                    /* TODO: escaping? */
1193
138M
        ret[len++] = (xmlChar) *p++;
1194
138M
    }
1195
35.3k
      }
1196
49.2k
            if (uri->port > 0) {
1197
4.32k
                if (len + 10 >= max) {
1198
602
                    temp = xmlSaveUriRealloc(ret, &max);
1199
602
                    if (temp == NULL) goto mem_error;
1200
588
                    ret = temp;
1201
588
                }
1202
4.31k
                len += snprintf((char *) &ret[len], max - len, ":%d", uri->port);
1203
4.31k
            }
1204
178k
  } else if (uri->authority != NULL) {
1205
0
      if (len + 3 >= max) {
1206
0
                temp = xmlSaveUriRealloc(ret, &max);
1207
0
                if (temp == NULL) goto mem_error;
1208
0
                ret = temp;
1209
0
      }
1210
0
      ret[len++] = '/';
1211
0
      ret[len++] = '/';
1212
0
      p = uri->authority;
1213
0
      while (*p != 0) {
1214
0
    if (len + 3 >= max) {
1215
0
                    temp = xmlSaveUriRealloc(ret, &max);
1216
0
                    if (temp == NULL) goto mem_error;
1217
0
                    ret = temp;
1218
0
    }
1219
0
    if ((IS_UNRESERVED(*(p))) ||
1220
0
                    ((*(p) == '$')) || ((*(p) == ',')) || ((*(p) == ';')) ||
1221
0
                    ((*(p) == ':')) || ((*(p) == '@')) || ((*(p) == '&')) ||
1222
0
                    ((*(p) == '=')) || ((*(p) == '+')))
1223
0
        ret[len++] = *p++;
1224
0
    else {
1225
0
        int val = *(unsigned char *)p++;
1226
0
        int hi = val / 0x10, lo = val % 0x10;
1227
0
        ret[len++] = '%';
1228
0
        ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1229
0
        ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1230
0
    }
1231
0
      }
1232
178k
  } else if (uri->scheme != NULL) {
1233
8.48k
      if (len + 3 >= max) {
1234
831
                temp = xmlSaveUriRealloc(ret, &max);
1235
831
                if (temp == NULL) goto mem_error;
1236
826
                ret = temp;
1237
826
      }
1238
8.48k
  }
1239
227k
  if (uri->path != NULL) {
1240
182k
      p = uri->path;
1241
      /*
1242
       * the colon in file:///d: should not be escaped or
1243
       * Windows accesses fail later.
1244
       */
1245
182k
      if ((uri->scheme != NULL) &&
1246
32.3k
    (p[0] == '/') &&
1247
25.0k
    (((p[1] >= 'a') && (p[1] <= 'z')) ||
1248
18.4k
     ((p[1] >= 'A') && (p[1] <= 'Z'))) &&
1249
9.71k
    (p[2] == ':') &&
1250
2.59k
          (xmlStrEqual(BAD_CAST uri->scheme, BAD_CAST "file"))) {
1251
1.54k
    if (len + 3 >= max) {
1252
746
                    temp = xmlSaveUriRealloc(ret, &max);
1253
746
                    if (temp == NULL) goto mem_error;
1254
741
                    ret = temp;
1255
741
    }
1256
1.54k
    ret[len++] = *p++;
1257
1.54k
    ret[len++] = *p++;
1258
1.54k
    ret[len++] = *p++;
1259
1.54k
      }
1260
65.0M
      while (*p != 0) {
1261
64.8M
    if (len + 3 >= max) {
1262
87.8k
                    temp = xmlSaveUriRealloc(ret, &max);
1263
87.8k
                    if (temp == NULL) goto mem_error;
1264
87.8k
                    ret = temp;
1265
87.8k
    }
1266
64.8M
    if ((IS_UNRESERVED(*(p))) || ((*(p) == '/')) ||
1267
10.1M
                    ((*(p) == ';')) || ((*(p) == '@')) || ((*(p) == '&')) ||
1268
9.68M
              ((*(p) == '=')) || ((*(p) == '+')) || ((*(p) == '$')) ||
1269
9.33M
              ((*(p) == ',')))
1270
55.6M
        ret[len++] = *p++;
1271
9.21M
    else {
1272
9.21M
        int val = *(unsigned char *)p++;
1273
9.21M
        int hi = val / 0x10, lo = val % 0x10;
1274
9.21M
        ret[len++] = '%';
1275
9.21M
        ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1276
9.21M
        ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1277
9.21M
    }
1278
64.8M
      }
1279
182k
  }
1280
227k
  if (uri->query_raw != NULL) {
1281
24.6k
      if (len + 1 >= max) {
1282
925
                temp = xmlSaveUriRealloc(ret, &max);
1283
925
                if (temp == NULL) goto mem_error;
1284
911
                ret = temp;
1285
911
      }
1286
24.6k
      ret[len++] = '?';
1287
24.6k
      p = uri->query_raw;
1288
22.9M
      while (*p != 0) {
1289
22.9M
    if (len + 1 >= max) {
1290
20.6k
                    temp = xmlSaveUriRealloc(ret, &max);
1291
20.6k
                    if (temp == NULL) goto mem_error;
1292
20.6k
                    ret = temp;
1293
20.6k
    }
1294
22.9M
    ret[len++] = *p++;
1295
22.9M
      }
1296
203k
  } else if (uri->query != NULL) {
1297
0
      if (len + 3 >= max) {
1298
0
                temp = xmlSaveUriRealloc(ret, &max);
1299
0
                if (temp == NULL) goto mem_error;
1300
0
                ret = temp;
1301
0
      }
1302
0
      ret[len++] = '?';
1303
0
      p = uri->query;
1304
0
      while (*p != 0) {
1305
0
    if (len + 3 >= max) {
1306
0
                    temp = xmlSaveUriRealloc(ret, &max);
1307
0
                    if (temp == NULL) goto mem_error;
1308
0
                    ret = temp;
1309
0
    }
1310
0
    if ((IS_UNRESERVED(*(p))) || (IS_RESERVED(*(p))))
1311
0
        ret[len++] = *p++;
1312
0
    else {
1313
0
        int val = *(unsigned char *)p++;
1314
0
        int hi = val / 0x10, lo = val % 0x10;
1315
0
        ret[len++] = '%';
1316
0
        ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1317
0
        ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1318
0
    }
1319
0
      }
1320
0
  }
1321
227k
    }
1322
227k
    if (uri->fragment != NULL) {
1323
26.4k
  if (len + 3 >= max) {
1324
1.43k
            temp = xmlSaveUriRealloc(ret, &max);
1325
1.43k
            if (temp == NULL) goto mem_error;
1326
1.41k
            ret = temp;
1327
1.41k
  }
1328
26.4k
  ret[len++] = '#';
1329
26.4k
  p = uri->fragment;
1330
3.76M
  while (*p != 0) {
1331
3.74M
      if (len + 3 >= max) {
1332
6.09k
                temp = xmlSaveUriRealloc(ret, &max);
1333
6.09k
                if (temp == NULL) goto mem_error;
1334
6.07k
                ret = temp;
1335
6.07k
      }
1336
3.74M
      if ((IS_UNRESERVED(*(p))) || (IS_RESERVED(*(p))))
1337
3.68M
    ret[len++] = *p++;
1338
53.4k
      else {
1339
53.4k
    int val = *(unsigned char *)p++;
1340
53.4k
    int hi = val / 0x10, lo = val % 0x10;
1341
53.4k
    ret[len++] = '%';
1342
53.4k
    ret[len++] = hi + (hi > 9? 'A'-10 : '0');
1343
53.4k
    ret[len++] = lo + (lo > 9? 'A'-10 : '0');
1344
53.4k
      }
1345
3.74M
  }
1346
26.4k
    }
1347
227k
    if (len >= max) {
1348
1.71k
        temp = xmlSaveUriRealloc(ret, &max);
1349
1.71k
        if (temp == NULL) goto mem_error;
1350
1.69k
        ret = temp;
1351
1.69k
    }
1352
227k
    ret[len] = 0;
1353
227k
    return(ret);
1354
1355
278
mem_error:
1356
278
    xmlFree(ret);
1357
278
    return(NULL);
1358
227k
}
1359
1360
/**
1361
 * Prints the URI in the stream `stream`.
1362
 *
1363
 * @param stream  a FILE* for the output
1364
 * @param uri  pointer to an xmlURI
1365
 */
1366
void
1367
0
xmlPrintURI(FILE *stream, xmlURI *uri) {
1368
0
    xmlChar *out;
1369
1370
0
    out = xmlSaveUri(uri);
1371
0
    if (out != NULL) {
1372
0
  fprintf(stream, "%s", (char *) out);
1373
0
  xmlFree(out);
1374
0
    }
1375
0
}
1376
1377
/**
1378
 * Make sure the xmlURI struct is free of content
1379
 *
1380
 * @param uri  pointer to an xmlURI
1381
 */
1382
static void
1383
5.06M
xmlCleanURI(xmlURIPtr uri) {
1384
5.06M
    if (uri == NULL) return;
1385
1386
5.06M
    if (uri->scheme != NULL) xmlFree(uri->scheme);
1387
5.06M
    uri->scheme = NULL;
1388
5.06M
    if (uri->server != NULL) xmlFree(uri->server);
1389
5.06M
    uri->server = NULL;
1390
5.06M
    if (uri->user != NULL) xmlFree(uri->user);
1391
5.06M
    uri->user = NULL;
1392
5.06M
    if (uri->path != NULL) xmlFree(uri->path);
1393
5.06M
    uri->path = NULL;
1394
5.06M
    if (uri->fragment != NULL) xmlFree(uri->fragment);
1395
5.06M
    uri->fragment = NULL;
1396
5.06M
    if (uri->opaque != NULL) xmlFree(uri->opaque);
1397
5.06M
    uri->opaque = NULL;
1398
5.06M
    if (uri->authority != NULL) xmlFree(uri->authority);
1399
5.06M
    uri->authority = NULL;
1400
5.06M
    if (uri->query != NULL) xmlFree(uri->query);
1401
5.06M
    uri->query = NULL;
1402
5.06M
    if (uri->query_raw != NULL) xmlFree(uri->query_raw);
1403
5.06M
    uri->query_raw = NULL;
1404
5.06M
}
1405
1406
/**
1407
 * Free up the xmlURI struct
1408
 *
1409
 * @param uri  pointer to an xmlURI
1410
 */
1411
void
1412
2.48M
xmlFreeURI(xmlURI *uri) {
1413
2.48M
    if (uri == NULL) return;
1414
1415
2.35M
    if (uri->scheme != NULL) xmlFree(uri->scheme);
1416
2.35M
    if (uri->server != NULL) xmlFree(uri->server);
1417
2.35M
    if (uri->user != NULL) xmlFree(uri->user);
1418
2.35M
    if (uri->path != NULL) xmlFree(uri->path);
1419
2.35M
    if (uri->fragment != NULL) xmlFree(uri->fragment);
1420
2.35M
    if (uri->opaque != NULL) xmlFree(uri->opaque);
1421
2.35M
    if (uri->authority != NULL) xmlFree(uri->authority);
1422
2.35M
    if (uri->query != NULL) xmlFree(uri->query);
1423
2.35M
    if (uri->query_raw != NULL) xmlFree(uri->query_raw);
1424
2.35M
    xmlFree(uri);
1425
2.35M
}
1426
1427
/************************************************************************
1428
 *                  *
1429
 *      Helper functions        *
1430
 *                  *
1431
 ************************************************************************/
1432
1433
static int
1434
265M
xmlIsPathSeparator(int c, int isFile) {
1435
265M
    (void) isFile;
1436
1437
265M
    if (c == '/')
1438
4.35M
        return(1);
1439
1440
#if defined(LIBXML_WINPATH_ENABLED)
1441
    if (isFile && (c == '\\'))
1442
        return(1);
1443
#endif
1444
1445
260M
    return(0);
1446
265M
}
1447
1448
/**
1449
 * Normalize a filesystem path or URI.
1450
 *
1451
 * @param path  pointer to the path string
1452
 * @param isFile  true for filesystem paths, false for URIs
1453
 * @returns 0 or an error code
1454
 */
1455
static int
1456
225k
xmlNormalizePath(char *path, int isFile) {
1457
225k
    char *cur, *out;
1458
225k
    int numSeg = 0;
1459
1460
225k
    if (path == NULL)
1461
49.4k
  return(-1);
1462
1463
175k
    cur = path;
1464
175k
    out = path;
1465
1466
175k
    if (*cur == 0)
1467
846
        return(0);
1468
1469
174k
    if (xmlIsPathSeparator(*cur, isFile)) {
1470
28.2k
        cur++;
1471
28.2k
        *out++ = '/';
1472
28.2k
    }
1473
1474
4.37M
    while (*cur != 0) {
1475
        /*
1476
         * At this point, out is either empty or ends with a separator.
1477
         * Collapse multiple separators first.
1478
         */
1479
4.38M
        while (xmlIsPathSeparator(*cur, isFile)) {
1480
#if defined(LIBXML_WINPATH_ENABLED)
1481
            /* Allow two separators at start of path */
1482
            if ((isFile) && (out == path + 1))
1483
                *out++ = '/';
1484
#endif
1485
181k
            cur++;
1486
181k
        }
1487
1488
4.20M
        if (*cur == '.') {
1489
173k
            if (cur[1] == 0) {
1490
                /* Ignore "." at end of path */
1491
6.36k
                break;
1492
167k
            } else if (xmlIsPathSeparator(cur[1], isFile)) {
1493
                /* Skip "./" */
1494
87.7k
                cur += 2;
1495
87.7k
                continue;
1496
87.7k
            } else if ((cur[1] == '.') &&
1497
73.7k
                       ((cur[2] == 0) || xmlIsPathSeparator(cur[2], isFile))) {
1498
71.2k
                if (numSeg > 0) {
1499
                    /* Handle ".." by removing last segment */
1500
56.1k
                    do {
1501
56.1k
                        out--;
1502
56.1k
                    } while ((out > path) &&
1503
53.1k
                             !xmlIsPathSeparator(out[-1], isFile));
1504
9.93k
                    numSeg--;
1505
1506
9.93k
                    if (cur[2] == 0)
1507
1.11k
                        break;
1508
8.81k
                    cur += 3;
1509
8.81k
                    continue;
1510
61.3k
                } else if (out[0] == '/') {
1511
                    /* Ignore extraneous ".." in absolute paths */
1512
2.48k
                    if (cur[2] == 0)
1513
464
                        break;
1514
2.02k
                    cur += 3;
1515
2.02k
                    continue;
1516
58.8k
                } else {
1517
                    /* Keep "../" at start of relative path */
1518
58.8k
                    numSeg--;
1519
58.8k
                }
1520
71.2k
            }
1521
173k
        }
1522
1523
        /* Copy segment */
1524
257M
        while ((*cur != 0) && !xmlIsPathSeparator(*cur, isFile)) {
1525
253M
            *out++ = *cur++;
1526
253M
        }
1527
1528
        /* Copy separator */
1529
4.10M
        if (*cur != 0) {
1530
3.94M
            cur++;
1531
3.94M
            *out++ = '/';
1532
3.94M
        }
1533
1534
4.10M
        numSeg++;
1535
4.10M
    }
1536
1537
    /* Keep "." if output is empty and it's a file */
1538
174k
    if ((isFile) && (out <= path))
1539
2.94k
        *out++ = '.';
1540
174k
    *out = 0;
1541
1542
174k
    return(0);
1543
175k
}
1544
1545
/**
1546
 * Applies the 5 normalization steps to a path string--that is, RFC 2396
1547
 * Section 5.2, steps 6.c through 6.g.
1548
 *
1549
 * Normalization occurs directly on the string, no new allocation is done
1550
 *
1551
 * @param path  pointer to the path string
1552
 * @returns 0 or an error code
1553
 */
1554
int
1555
40.1k
xmlNormalizeURIPath(char *path) {
1556
40.1k
    return(xmlNormalizePath(path, 0));
1557
40.1k
}
1558
1559
37.0M
static int is_hex(char c) {
1560
37.0M
    if (((c >= '0') && (c <= '9')) ||
1561
17.7M
        ((c >= 'a') && (c <= 'f')) ||
1562
17.6M
        ((c >= 'A') && (c <= 'F')))
1563
37.0M
  return(1);
1564
31.7k
    return(0);
1565
37.0M
}
1566
1567
/**
1568
 * Unescaping routine, but does not check that the string is an URI. The
1569
 * output is a direct unsigned char translation of %XX values (no encoding)
1570
 * Note that the length of the result can only be smaller or same size as
1571
 * the input string.
1572
 *
1573
 * @param str  the string to unescape
1574
 * @param len  the length in bytes to unescape (or <= 0 to indicate full string)
1575
 * @param target  optional destination buffer
1576
 * @returns a copy of the string, but unescaped, will return NULL only in case
1577
 * of error
1578
 */
1579
char *
1580
3.44M
xmlURIUnescapeString(const char *str, int len, char *target) {
1581
3.44M
    char *ret, *out;
1582
3.44M
    const char *in;
1583
1584
3.44M
    if (str == NULL)
1585
5
  return(NULL);
1586
3.44M
    if (len <= 0) len = strlen(str);
1587
3.44M
    if (len < 0) return(NULL);
1588
1589
3.44M
    if (target == NULL) {
1590
3.44M
  ret = xmlMalloc(len + 1);
1591
3.44M
  if (ret == NULL)
1592
939
      return(NULL);
1593
3.44M
    } else
1594
0
  ret = target;
1595
3.44M
    in = str;
1596
3.44M
    out = ret;
1597
765M
    while(len > 0) {
1598
761M
  if ((len > 2) && (*in == '%') && (is_hex(in[1])) && (is_hex(in[2]))) {
1599
18.4M
            int c = 0;
1600
18.4M
      in++;
1601
18.4M
      if ((*in >= '0') && (*in <= '9'))
1602
11.1M
          c = (*in - '0');
1603
7.36M
      else if ((*in >= 'a') && (*in <= 'f'))
1604
40.6k
          c = (*in - 'a') + 10;
1605
7.32M
      else if ((*in >= 'A') && (*in <= 'F'))
1606
7.32M
          c = (*in - 'A') + 10;
1607
18.4M
      in++;
1608
18.4M
      if ((*in >= '0') && (*in <= '9'))
1609
8.15M
          c = c * 16 + (*in - '0');
1610
10.3M
      else if ((*in >= 'a') && (*in <= 'f'))
1611
44.0k
          c = c * 16 + (*in - 'a') + 10;
1612
10.3M
      else if ((*in >= 'A') && (*in <= 'F'))
1613
10.3M
          c = c * 16 + (*in - 'A') + 10;
1614
18.4M
      in++;
1615
18.4M
      len -= 3;
1616
            /* Explicit sign change */
1617
18.4M
      *out++ = (char) c;
1618
743M
  } else {
1619
743M
      *out++ = *in++;
1620
743M
      len--;
1621
743M
  }
1622
761M
    }
1623
3.44M
    *out = 0;
1624
3.44M
    return(ret);
1625
3.44M
}
1626
1627
/**
1628
 * This routine escapes a string to hex, ignoring unreserved characters
1629
 * a-z, A-Z, 0-9, "-._~", a few sub-delims "!*'()", the gen-delim "@"
1630
 * (why?) and the characters in the exception list.
1631
 *
1632
 * @param str  string to escape
1633
 * @param list  exception list string of chars not to escape
1634
 * @returns a new escaped string or NULL in case of error.
1635
 */
1636
xmlChar *
1637
55.7k
xmlURIEscapeStr(const xmlChar *str, const xmlChar *list) {
1638
55.7k
    xmlChar *ret, ch;
1639
55.7k
    const xmlChar *in;
1640
55.7k
    int len, out;
1641
1642
55.7k
    if (str == NULL)
1643
5
  return(NULL);
1644
55.7k
    if (str[0] == 0)
1645
586
  return(xmlStrdup(str));
1646
55.1k
    len = xmlStrlen(str);
1647
55.1k
    if (len == 0)
1648
0
        return(NULL);
1649
1650
55.1k
    len += 20;
1651
55.1k
    ret = xmlMalloc(len);
1652
55.1k
    if (ret == NULL)
1653
123
  return(NULL);
1654
55.0k
    in = (const xmlChar *) str;
1655
55.0k
    out = 0;
1656
44.8M
    while(*in != 0) {
1657
44.7M
  if (len - out <= 3) {
1658
10.7k
            xmlChar *temp;
1659
10.7k
            int newSize;
1660
1661
10.7k
            newSize = xmlGrowCapacity(len, 1, 1, XML_MAX_ITEMS);
1662
10.7k
            if (newSize < 0) {
1663
0
    xmlFree(ret);
1664
0
                return(NULL);
1665
0
            }
1666
10.7k
            temp = xmlRealloc(ret, newSize);
1667
10.7k
      if (temp == NULL) {
1668
28
    xmlFree(ret);
1669
28
    return(NULL);
1670
28
      }
1671
10.7k
      ret = temp;
1672
10.7k
            len = newSize;
1673
10.7k
  }
1674
1675
44.7M
  ch = *in;
1676
1677
44.7M
  if ((ch != '@') && (!IS_UNRESERVED(ch)) && (!xmlStrchr(list, ch))) {
1678
12.7M
      unsigned char val;
1679
12.7M
      ret[out++] = '%';
1680
12.7M
      val = ch >> 4;
1681
12.7M
      if (val <= 9)
1682
2.32M
    ret[out++] = '0' + val;
1683
10.4M
      else
1684
10.4M
    ret[out++] = 'A' + val - 0xA;
1685
12.7M
      val = ch & 0xF;
1686
12.7M
      if (val <= 9)
1687
2.25M
    ret[out++] = '0' + val;
1688
10.4M
      else
1689
10.4M
    ret[out++] = 'A' + val - 0xA;
1690
12.7M
      in++;
1691
32.0M
  } else {
1692
32.0M
      ret[out++] = *in++;
1693
32.0M
  }
1694
1695
44.7M
    }
1696
55.0k
    ret[out] = 0;
1697
55.0k
    return(ret);
1698
55.0k
}
1699
1700
/**
1701
 * Escaping routine, does not do validity checks !
1702
 * It will try to escape the chars needing this, but this is heuristic
1703
 * based it's impossible to be sure.
1704
 *
1705
 * 25 May 2001
1706
 * Uses #xmlParseURI and #xmlURIEscapeStr to try to escape correctly
1707
 * according to RFC2396.
1708
 *   - Carl Douglas
1709
 * @param str  the string of the URI to escape
1710
 * @returns an copy of the string, but escaped
1711
 */
1712
xmlChar *
1713
xmlURIEscape(const xmlChar * str)
1714
4.48k
{
1715
4.48k
    xmlChar *ret, *segment = NULL;
1716
4.48k
    xmlURIPtr uri;
1717
4.48k
    int ret2;
1718
1719
4.48k
    if (str == NULL)
1720
5
        return (NULL);
1721
1722
4.47k
    uri = xmlCreateURI();
1723
4.47k
    if (uri != NULL) {
1724
  /*
1725
   * Allow escaping errors in the unescaped form
1726
   */
1727
4.42k
        uri->cleanup = XML_URI_ALLOW_UNWISE;
1728
4.42k
        ret2 = xmlParseURIReference(uri, (const char *)str);
1729
4.42k
        if (ret2) {
1730
1.28k
            xmlFreeURI(uri);
1731
1.28k
            return (NULL);
1732
1.28k
        }
1733
4.42k
    }
1734
1735
3.19k
    if (!uri)
1736
58
        return NULL;
1737
1738
3.13k
    ret = NULL;
1739
1740
3.65k
#define NULLCHK(p) if(!p) { \
1741
39
         xmlFreeURI(uri); \
1742
39
         xmlFree(ret); \
1743
39
         return NULL; } \
1744
3.13k
1745
3.13k
    if (uri->scheme) {
1746
712
        segment = xmlURIEscapeStr(BAD_CAST uri->scheme, BAD_CAST "+-.");
1747
712
        NULLCHK(segment)
1748
707
        ret = xmlStrcat(ret, segment);
1749
707
        ret = xmlStrcat(ret, BAD_CAST ":");
1750
707
        xmlFree(segment);
1751
707
    }
1752
1753
3.13k
    if (uri->authority) {
1754
0
        segment =
1755
0
            xmlURIEscapeStr(BAD_CAST uri->authority, BAD_CAST "/?;:@");
1756
0
        NULLCHK(segment)
1757
0
        ret = xmlStrcat(ret, BAD_CAST "//");
1758
0
        ret = xmlStrcat(ret, segment);
1759
0
        xmlFree(segment);
1760
0
    }
1761
1762
3.13k
    if (uri->user) {
1763
527
        segment = xmlURIEscapeStr(BAD_CAST uri->user, BAD_CAST ";:&=+$,");
1764
527
        NULLCHK(segment)
1765
519
        ret = xmlStrcat(ret,BAD_CAST "//");
1766
519
        ret = xmlStrcat(ret, segment);
1767
519
        ret = xmlStrcat(ret, BAD_CAST "@");
1768
519
        xmlFree(segment);
1769
519
    }
1770
1771
3.12k
    if (uri->server) {
1772
803
        segment = xmlURIEscapeStr(BAD_CAST uri->server, BAD_CAST "/?;:@");
1773
803
        NULLCHK(segment)
1774
797
        if (uri->user == NULL)
1775
367
            ret = xmlStrcat(ret, BAD_CAST "//");
1776
797
        ret = xmlStrcat(ret, segment);
1777
797
        xmlFree(segment);
1778
797
    }
1779
1780
3.11k
    if (uri->port > 0) {
1781
223
        xmlChar port[11];
1782
1783
223
        snprintf((char *) port, 11, "%d", uri->port);
1784
223
        ret = xmlStrcat(ret, BAD_CAST ":");
1785
223
        ret = xmlStrcat(ret, port);
1786
223
    }
1787
1788
3.11k
    if (uri->path) {
1789
1.09k
        segment =
1790
1.09k
            xmlURIEscapeStr(BAD_CAST uri->path, BAD_CAST ":@&=+$,/?;");
1791
1.09k
        NULLCHK(segment)
1792
1.07k
        ret = xmlStrcat(ret, segment);
1793
1.07k
        xmlFree(segment);
1794
1.07k
    }
1795
1796
3.09k
    if (uri->query_raw) {
1797
385
        ret = xmlStrcat(ret, BAD_CAST "?");
1798
385
        ret = xmlStrcat(ret, BAD_CAST uri->query_raw);
1799
385
    }
1800
2.71k
    else if (uri->query) {
1801
0
        segment =
1802
0
            xmlURIEscapeStr(BAD_CAST uri->query, BAD_CAST ";/?:@&=+,$");
1803
0
        NULLCHK(segment)
1804
0
        ret = xmlStrcat(ret, BAD_CAST "?");
1805
0
        ret = xmlStrcat(ret, segment);
1806
0
        xmlFree(segment);
1807
0
    }
1808
1809
3.09k
    if (uri->opaque) {
1810
0
        segment = xmlURIEscapeStr(BAD_CAST uri->opaque, BAD_CAST "");
1811
0
        NULLCHK(segment)
1812
0
        ret = xmlStrcat(ret, segment);
1813
0
        xmlFree(segment);
1814
0
    }
1815
1816
3.09k
    if (uri->fragment) {
1817
514
        segment = xmlURIEscapeStr(BAD_CAST uri->fragment, BAD_CAST "#");
1818
514
        NULLCHK(segment)
1819
512
        ret = xmlStrcat(ret, BAD_CAST "#");
1820
512
        ret = xmlStrcat(ret, segment);
1821
512
        xmlFree(segment);
1822
512
    }
1823
1824
3.09k
    xmlFreeURI(uri);
1825
3.09k
#undef NULLCHK
1826
1827
3.09k
    return (ret);
1828
3.09k
}
1829
1830
/************************************************************************
1831
 *                  *
1832
 *      Public functions        *
1833
 *                  *
1834
 ************************************************************************/
1835
1836
static int
1837
177k
xmlIsAbsolutePath(const xmlChar *path) {
1838
177k
    int c = path[0];
1839
1840
177k
    if (xmlIsPathSeparator(c, 1))
1841
11.2k
        return(1);
1842
1843
#if defined(LIBXML_WINPATH_ENABLED)
1844
    if ((((c >= 'A') && (c <= 'Z')) ||
1845
         ((c >= 'a') && (c <= 'z'))) &&
1846
        (path[1] == ':'))
1847
        return(1);
1848
#endif
1849
1850
166k
    return(0);
1851
177k
}
1852
1853
/**
1854
 * Resolves a filesystem path from a base path.
1855
 *
1856
 * @param escRef  the filesystem path
1857
 * @param base  the base value
1858
 * @param out  pointer to result URI
1859
 * @returns 0 on success, -1 if a memory allocation failed or an error
1860
 * code if URI or base are invalid.
1861
 */
1862
static int
1863
1.09M
xmlResolvePath(const xmlChar *escRef, const xmlChar *base, xmlChar **out) {
1864
1.09M
    const xmlChar *fragment;
1865
1.09M
    xmlChar *tmp = NULL;
1866
1.09M
    xmlChar *ref = NULL;
1867
1.09M
    xmlChar *result = NULL;
1868
1.09M
    int ret = -1;
1869
1.09M
    int i;
1870
1871
1.09M
    if (out == NULL)
1872
0
        return(1);
1873
1.09M
    *out = NULL;
1874
1875
1.09M
    if ((escRef == NULL) || (escRef[0] == 0)) {
1876
16.3k
        if ((base == NULL) || (base[0] == 0))
1877
3.46k
            return(1);
1878
12.9k
        ref = xmlStrdup(base);
1879
12.9k
        if (ref == NULL)
1880
21
            goto err_memory;
1881
12.8k
        *out = ref;
1882
12.8k
        return(0);
1883
12.9k
    }
1884
1885
    /*
1886
     * If a URI is resolved, we can assume it is a valid URI and not
1887
     * a filesystem path. This means we have to unescape the part
1888
     * before the fragment.
1889
     */
1890
1.07M
    fragment = xmlStrchr(escRef, '#');
1891
1.07M
    if (fragment != NULL) {
1892
989k
        tmp = xmlStrndup(escRef, fragment - escRef);
1893
989k
        if (tmp == NULL)
1894
25
            goto err_memory;
1895
989k
        escRef = tmp;
1896
989k
    }
1897
1898
1.07M
    ref = (xmlChar *) xmlURIUnescapeString((char *) escRef, -1, NULL);
1899
1.07M
    if (ref == NULL)
1900
86
        goto err_memory;
1901
1902
1.07M
    if ((base == NULL) || (base[0] == 0))
1903
999k
        goto done;
1904
1905
78.1k
    if (xmlIsAbsolutePath(ref))
1906
8.40k
        goto done;
1907
1908
    /*
1909
     * Remove last segment from base
1910
     */
1911
69.7k
    i = xmlStrlen(base);
1912
3.08M
    while ((i > 0) && !xmlIsPathSeparator(base[i-1], 1))
1913
3.01M
        i--;
1914
1915
    /*
1916
     * Concatenate base and ref
1917
     */
1918
69.7k
    if (i > 0) {
1919
27.0k
        int refLen = xmlStrlen(ref);
1920
1921
27.0k
        result = xmlMalloc(i + refLen + 1);
1922
27.0k
        if (result == NULL)
1923
73
            goto err_memory;
1924
1925
26.9k
        memcpy(result, base, i);
1926
26.9k
        memcpy(result + i, ref, refLen + 1);
1927
26.9k
    }
1928
1929
    /*
1930
     * Normalize
1931
     */
1932
69.6k
    xmlNormalizePath((char *) result, 1);
1933
1934
1.07M
done:
1935
1.07M
    if (result == NULL) {
1936
1.05M
        result = ref;
1937
1.05M
        ref = NULL;
1938
1.05M
    }
1939
1940
1.07M
    if (fragment != NULL) {
1941
989k
        result = xmlStrcat(result, fragment);
1942
989k
        if (result == NULL)
1943
40
            goto err_memory;
1944
989k
    }
1945
1946
1.07M
    *out = result;
1947
1.07M
    ret = 0;
1948
1949
1.07M
err_memory:
1950
1.07M
    xmlFree(tmp);
1951
1.07M
    xmlFree(ref);
1952
1.07M
    return(ret);
1953
1.07M
}
1954
1955
/**
1956
 * Computes he final URI of the reference done by checking that
1957
 * the given URI is valid, and building the final URI using the
1958
 * base URI. This is processed according to section 5.2 of the
1959
 * RFC 2396
1960
 *
1961
 * 5.2. Resolving Relative References to Absolute Form
1962
 *
1963
 * @since 2.13.0
1964
 *
1965
 * @param URI  the URI instance found in the document
1966
 * @param base  the base value
1967
 * @param valPtr  pointer to result URI
1968
 * @returns 0 on success, -1 if a memory allocation failed or an error
1969
 * code if URI or base are invalid.
1970
 */
1971
int
1972
1.27M
xmlBuildURISafe(const xmlChar *URI, const xmlChar *base, xmlChar **valPtr) {
1973
1.27M
    xmlChar *val = NULL;
1974
1.27M
    int ret, len, indx, cur, out;
1975
1.27M
    xmlURIPtr ref = NULL;
1976
1.27M
    xmlURIPtr bas = NULL;
1977
1.27M
    xmlURIPtr res = NULL;
1978
1979
1.27M
    if (valPtr == NULL)
1980
0
        return(1);
1981
1.27M
    *valPtr = NULL;
1982
1983
1.27M
    if (URI == NULL)
1984
5.49k
        return(1);
1985
1986
1.27M
    if (base == NULL) {
1987
37.9k
        val = xmlStrdup(URI);
1988
37.9k
        if (val == NULL)
1989
14
            return(-1);
1990
37.9k
        *valPtr = val;
1991
37.9k
        return(0);
1992
37.9k
    }
1993
1994
    /*
1995
     * 1) The URI reference is parsed into the potential four components and
1996
     *    fragment identifier, as described in Section 4.3.
1997
     *
1998
     *    NOTE that a completely empty URI is treated by modern browsers
1999
     *    as a reference to "." rather than as a synonym for the current
2000
     *    URI.  Should we do that here?
2001
     */
2002
1.23M
    if (URI[0] != 0)
2003
1.20M
        ret = xmlParseURISafe((const char *) URI, &ref);
2004
29.2k
    else
2005
29.2k
        ret = 0;
2006
1.23M
    if (ret != 0)
2007
29.8k
  goto done;
2008
1.20M
    if ((ref != NULL) && (ref->scheme != NULL)) {
2009
  /*
2010
   * The URI is absolute don't modify.
2011
   */
2012
18.3k
  val = xmlStrdup(URI);
2013
18.3k
        if (val == NULL)
2014
45
            ret = -1;
2015
18.3k
  goto done;
2016
18.3k
    }
2017
2018
    /*
2019
     * If base has no scheme or authority, it is assumed to be a
2020
     * filesystem path.
2021
     */
2022
1.18M
    if (xmlStrstr(base, BAD_CAST "://") == NULL) {
2023
1.09M
        xmlFreeURI(ref);
2024
1.09M
        return(xmlResolvePath(URI, base, valPtr));
2025
1.09M
    }
2026
2027
#if defined(LIBXML_WINPATH_ENABLED)
2028
    /*
2029
     * Resolve paths with a Windows drive letter as filesystem path
2030
     * even if base has a scheme.
2031
     */
2032
    if ((ref != NULL) && (ref->path != NULL)) {
2033
        int c = ref->path[0];
2034
2035
        if ((((c >= 'A') && (c <= 'Z')) ||
2036
             ((c >= 'a') && (c <= 'z'))) &&
2037
            (ref->path[1] == ':')) {
2038
            xmlFreeURI(ref);
2039
            return(xmlResolvePath(URI, base, valPtr));
2040
        }
2041
    }
2042
#endif
2043
2044
92.4k
    ret = xmlParseURISafe((const char *) base, &bas);
2045
92.4k
    if (ret < 0)
2046
263
        goto done;
2047
92.1k
    if (ret != 0) {
2048
22.2k
  if (ref) {
2049
19.9k
            ret = 0;
2050
19.9k
      val = xmlSaveUri(ref);
2051
19.9k
            if (val == NULL)
2052
207
                ret = -1;
2053
19.9k
        }
2054
22.2k
  goto done;
2055
22.2k
    }
2056
69.9k
    if (ref == NULL) {
2057
  /*
2058
   * the base fragment must be ignored
2059
   */
2060
10.5k
  if (bas->fragment != NULL) {
2061
2.36k
      xmlFree(bas->fragment);
2062
2.36k
      bas->fragment = NULL;
2063
2.36k
  }
2064
10.5k
  val = xmlSaveUri(bas);
2065
10.5k
        if (val == NULL)
2066
124
            ret = -1;
2067
10.5k
  goto done;
2068
10.5k
    }
2069
2070
    /*
2071
     * 2) If the path component is empty and the scheme, authority, and
2072
     *    query components are undefined, then it is a reference to the
2073
     *    current document and we are done.  Otherwise, the reference URI's
2074
     *    query and fragment components are defined as found (or not found)
2075
     *    within the URI reference and not inherited from the base URI.
2076
     *
2077
     *    NOTE that in modern browsers, the parsing differs from the above
2078
     *    in the following aspect:  the query component is allowed to be
2079
     *    defined while still treating this as a reference to the current
2080
     *    document.
2081
     */
2082
59.4k
    ret = -1;
2083
59.4k
    res = xmlCreateURI();
2084
59.4k
    if (res == NULL)
2085
64
  goto done;
2086
59.3k
    if ((ref->scheme == NULL) && (ref->path == NULL) &&
2087
19.0k
  ((ref->authority == NULL) && (ref->server == NULL) &&
2088
14.1k
         (ref->port == PORT_EMPTY))) {
2089
13.3k
  if (bas->scheme != NULL) {
2090
10.5k
      res->scheme = xmlMemStrdup(bas->scheme);
2091
10.5k
            if (res->scheme == NULL)
2092
25
                goto done;
2093
10.5k
        }
2094
13.2k
  if (bas->authority != NULL) {
2095
0
      res->authority = xmlMemStrdup(bas->authority);
2096
0
            if (res->authority == NULL)
2097
0
                goto done;
2098
13.2k
        } else {
2099
13.2k
      if (bas->server != NULL) {
2100
6.06k
    res->server = xmlMemStrdup(bas->server);
2101
6.06k
                if (res->server == NULL)
2102
19
                    goto done;
2103
6.06k
            }
2104
13.2k
      if (bas->user != NULL) {
2105
4.33k
    res->user = xmlMemStrdup(bas->user);
2106
4.33k
                if (res->user == NULL)
2107
16
                    goto done;
2108
4.33k
            }
2109
13.2k
      res->port = bas->port;
2110
13.2k
  }
2111
13.2k
  if (bas->path != NULL) {
2112
6.27k
      res->path = xmlMemStrdup(bas->path);
2113
6.27k
            if (res->path == NULL)
2114
22
                goto done;
2115
6.27k
        }
2116
13.2k
  if (ref->query_raw != NULL) {
2117
4.59k
      res->query_raw = xmlMemStrdup (ref->query_raw);
2118
4.59k
            if (res->query_raw == NULL)
2119
21
                goto done;
2120
8.62k
        } else if (ref->query != NULL) {
2121
0
      res->query = xmlMemStrdup(ref->query);
2122
0
            if (res->query == NULL)
2123
0
                goto done;
2124
8.62k
        } else if (bas->query_raw != NULL) {
2125
3.39k
      res->query_raw = xmlMemStrdup(bas->query_raw);
2126
3.39k
            if (res->query_raw == NULL)
2127
19
                goto done;
2128
5.23k
        } else if (bas->query != NULL) {
2129
0
      res->query = xmlMemStrdup(bas->query);
2130
0
            if (res->query == NULL)
2131
0
                goto done;
2132
0
        }
2133
13.1k
  if (ref->fragment != NULL) {
2134
8.75k
      res->fragment = xmlMemStrdup(ref->fragment);
2135
8.75k
            if (res->fragment == NULL)
2136
30
                goto done;
2137
8.75k
        }
2138
13.1k
  goto step_7;
2139
13.1k
    }
2140
2141
    /*
2142
     * 3) If the scheme component is defined, indicating that the reference
2143
     *    starts with a scheme name, then the reference is interpreted as an
2144
     *    absolute URI and we are done.  Otherwise, the reference URI's
2145
     *    scheme is inherited from the base URI's scheme component.
2146
     */
2147
46.0k
    if (ref->scheme != NULL) {
2148
0
  val = xmlSaveUri(ref);
2149
0
        if (val != NULL)
2150
0
            ret = 0;
2151
0
  goto done;
2152
0
    }
2153
46.0k
    if (bas->scheme != NULL) {
2154
24.5k
  res->scheme = xmlMemStrdup(bas->scheme);
2155
24.5k
        if (res->scheme == NULL)
2156
48
            goto done;
2157
24.5k
    }
2158
2159
45.9k
    if (ref->query_raw != NULL) {
2160
8.77k
  res->query_raw = xmlMemStrdup(ref->query_raw);
2161
8.77k
        if (res->query_raw == NULL)
2162
15
            goto done;
2163
37.2k
    } else if (ref->query != NULL) {
2164
0
  res->query = xmlMemStrdup(ref->query);
2165
0
        if (res->query == NULL)
2166
0
            goto done;
2167
0
    }
2168
45.9k
    if (ref->fragment != NULL) {
2169
8.25k
  res->fragment = xmlMemStrdup(ref->fragment);
2170
8.25k
        if (res->fragment == NULL)
2171
14
            goto done;
2172
8.25k
    }
2173
2174
    /*
2175
     * 4) If the authority component is defined, then the reference is a
2176
     *    network-path and we skip to step 7.  Otherwise, the reference
2177
     *    URI's authority is inherited from the base URI's authority
2178
     *    component, which will also be undefined if the URI scheme does not
2179
     *    use an authority component.
2180
     */
2181
45.9k
    if ((ref->authority != NULL) || (ref->server != NULL) ||
2182
39.8k
         (ref->port != PORT_EMPTY)) {
2183
7.01k
  if (ref->authority != NULL) {
2184
0
      res->authority = xmlMemStrdup(ref->authority);
2185
0
            if (res->authority == NULL)
2186
0
                goto done;
2187
7.01k
        } else {
2188
7.01k
            if (ref->server != NULL) {
2189
6.13k
                res->server = xmlMemStrdup(ref->server);
2190
6.13k
                if (res->server == NULL)
2191
21
                    goto done;
2192
6.13k
            }
2193
6.99k
      if (ref->user != NULL) {
2194
3.70k
    res->user = xmlMemStrdup(ref->user);
2195
3.70k
                if (res->user == NULL)
2196
17
                    goto done;
2197
3.70k
            }
2198
6.98k
            res->port = ref->port;
2199
6.98k
  }
2200
6.98k
  if (ref->path != NULL) {
2201
1.30k
      res->path = xmlMemStrdup(ref->path);
2202
1.30k
            if (res->path == NULL)
2203
15
                goto done;
2204
1.30k
        }
2205
6.96k
  goto step_7;
2206
6.98k
    }
2207
38.9k
    if (bas->authority != NULL) {
2208
0
  res->authority = xmlMemStrdup(bas->authority);
2209
0
        if (res->authority == NULL)
2210
0
            goto done;
2211
38.9k
    } else if ((bas->server != NULL) || (bas->port != PORT_EMPTY)) {
2212
17.7k
  if (bas->server != NULL) {
2213
12.0k
      res->server = xmlMemStrdup(bas->server);
2214
12.0k
            if (res->server == NULL)
2215
27
                goto done;
2216
12.0k
        }
2217
17.7k
  if (bas->user != NULL) {
2218
5.33k
      res->user = xmlMemStrdup(bas->user);
2219
5.33k
            if (res->user == NULL)
2220
20
                goto done;
2221
5.33k
        }
2222
17.7k
  res->port = bas->port;
2223
17.7k
    }
2224
2225
    /*
2226
     * 5) If the path component begins with a slash character ("/"), then
2227
     *    the reference is an absolute-path and we skip to step 7.
2228
     */
2229
38.8k
    if ((ref->path != NULL) && (ref->path[0] == '/')) {
2230
3.16k
  res->path = xmlMemStrdup(ref->path);
2231
3.16k
        if (res->path == NULL)
2232
22
            goto done;
2233
3.13k
  goto step_7;
2234
3.16k
    }
2235
2236
2237
    /*
2238
     * 6) If this step is reached, then we are resolving a relative-path
2239
     *    reference.  The relative path needs to be merged with the base
2240
     *    URI's path.  Although there are many ways to do this, we will
2241
     *    describe a simple method using a separate string buffer.
2242
     *
2243
     * Allocate a buffer large enough for the result string.
2244
     */
2245
35.7k
    len = 2; /* extra / and 0 */
2246
35.7k
    if (ref->path != NULL)
2247
35.7k
  len += strlen(ref->path);
2248
35.7k
    if (bas->path != NULL)
2249
21.9k
  len += strlen(bas->path);
2250
35.7k
    res->path = xmlMalloc(len);
2251
35.7k
    if (res->path == NULL)
2252
76
  goto done;
2253
35.6k
    res->path[0] = 0;
2254
2255
    /*
2256
     * a) All but the last segment of the base URI's path component is
2257
     *    copied to the buffer.  In other words, any characters after the
2258
     *    last (right-most) slash character, if any, are excluded.
2259
     */
2260
35.6k
    cur = 0;
2261
35.6k
    out = 0;
2262
35.6k
    if (bas->path != NULL) {
2263
266k
  while (bas->path[cur] != 0) {
2264
4.62M
      while ((bas->path[cur] != 0) && (bas->path[cur] != '/'))
2265
4.36M
    cur++;
2266
261k
      if (bas->path[cur] == 0)
2267
17.4k
    break;
2268
2269
244k
      cur++;
2270
4.69M
      while (out < cur) {
2271
4.44M
    res->path[out] = bas->path[out];
2272
4.44M
    out++;
2273
4.44M
      }
2274
244k
  }
2275
21.9k
    }
2276
35.6k
    res->path[out] = 0;
2277
2278
    /*
2279
     * b) The reference's path component is appended to the buffer
2280
     *    string.
2281
     */
2282
35.6k
    if (ref->path != NULL && ref->path[0] != 0) {
2283
35.1k
  indx = 0;
2284
  /*
2285
   * Ensure the path includes a '/'
2286
   */
2287
35.1k
  if ((out == 0) && ((bas->server != NULL) || bas->port != PORT_EMPTY))
2288
12.0k
      res->path[out++] = '/';
2289
52.6M
  while (ref->path[indx] != 0) {
2290
52.5M
      res->path[out++] = ref->path[indx++];
2291
52.5M
  }
2292
35.1k
    }
2293
35.6k
    res->path[out] = 0;
2294
2295
    /*
2296
     * Steps c) to h) are really path normalization steps
2297
     */
2298
35.6k
    xmlNormalizeURIPath(res->path);
2299
2300
58.9k
step_7:
2301
2302
    /*
2303
     * 7) The resulting URI components, including any inherited from the
2304
     *    base URI, are recombined to give the absolute form of the URI
2305
     *    reference.
2306
     */
2307
58.9k
    val = xmlSaveUri(res);
2308
58.9k
    if (val != NULL)
2309
58.6k
        ret = 0;
2310
2311
140k
done:
2312
140k
    if (ref != NULL)
2313
97.9k
  xmlFreeURI(ref);
2314
140k
    if (bas != NULL)
2315
69.9k
  xmlFreeURI(bas);
2316
140k
    if (res != NULL)
2317
59.3k
  xmlFreeURI(res);
2318
140k
    *valPtr = val;
2319
140k
    return(ret);
2320
58.9k
}
2321
2322
/**
2323
 * Computes he final URI of the reference done by checking that
2324
 * the given URI is valid, and building the final URI using the
2325
 * base URI. This is processed according to section 5.2 of the
2326
 * RFC 2396
2327
 *
2328
 * 5.2. Resolving Relative References to Absolute Form
2329
 *
2330
 * @param URI  the URI instance found in the document
2331
 * @param base  the base value
2332
 * @returns a new URI string (to be freed by the caller) or NULL in case
2333
 *         of error.
2334
 */
2335
xmlChar *
2336
28.0k
xmlBuildURI(const xmlChar *URI, const xmlChar *base) {
2337
28.0k
    xmlChar *out;
2338
2339
28.0k
    xmlBuildURISafe(URI, base, &out);
2340
28.0k
    return(out);
2341
28.0k
}
2342
2343
static int
2344
121k
xmlParseUriOrPath(const char *str, xmlURIPtr *out, int *drive) {
2345
121k
    xmlURIPtr uri;
2346
121k
    char *buf = NULL;
2347
121k
    int ret;
2348
2349
121k
    *out = NULL;
2350
121k
    *drive = 0;
2351
2352
121k
    uri = xmlCreateURI();
2353
121k
    if (uri == NULL) {
2354
44
        ret = -1;
2355
44
  goto done;
2356
44
    }
2357
2358
121k
    if (xmlStrstr(BAD_CAST str, BAD_CAST "://") == NULL) {
2359
99.5k
        const char *path;
2360
99.5k
        size_t pathSize;
2361
99.5k
        int prependSlash = 0;
2362
2363
99.5k
        buf = xmlMemStrdup(str);
2364
99.5k
        if (buf == NULL) {
2365
36
            ret = -1;
2366
36
            goto done;
2367
36
        }
2368
99.4k
        xmlNormalizePath(buf, /* isFile */ 1);
2369
2370
99.4k
        path = buf;
2371
2372
99.4k
        if (xmlIsAbsolutePath(BAD_CAST buf)) {
2373
#if defined(LIBXML_WINPATH_ENABLED)
2374
            const char *server = NULL;
2375
            int isFileScheme = 0;
2376
#endif
2377
2378
#if defined(LIBXML_WINPATH_ENABLED)
2379
            if (strncmp(buf, "//?/UNC/", 8) == 0) {
2380
                server = buf + 8;
2381
                isFileScheme = 1;
2382
            } else if (strncmp(buf, "//?/", 4) == 0) {
2383
                path = buf + 3;
2384
                isFileScheme = 1;
2385
            } else if (strncmp(buf, "//", 2) == 0) {
2386
                server = buf + 2;
2387
                isFileScheme = 1;
2388
            }
2389
2390
            if (server != NULL) {
2391
                const char *end = strchr(server, '/');
2392
2393
                if (end == NULL) {
2394
                    uri->server = xmlMemStrdup(server);
2395
                    path = "/";
2396
                } else {
2397
                    uri->server = (char *) xmlStrndup(BAD_CAST server,
2398
                                                      end - server);
2399
                    path = end;
2400
                }
2401
                if (uri->server == NULL) {
2402
                    ret = -1;
2403
                    goto done;
2404
                }
2405
            }
2406
2407
            if ((((path[0] >= 'A') && (path[0] <= 'Z')) ||
2408
                 ((path[0] >= 'a') && (path[0] <= 'z'))) &&
2409
                (path[1] == ':')) {
2410
                prependSlash = 1;
2411
                isFileScheme = 1;
2412
            }
2413
2414
            if (isFileScheme) {
2415
                uri->scheme = xmlMemStrdup("file");
2416
                if (uri->scheme == NULL) {
2417
                    ret = -1;
2418
                    goto done;
2419
                }
2420
2421
                if (uri->server == NULL)
2422
                    uri->port = PORT_EMPTY_SERVER;
2423
            }
2424
#endif
2425
2.89k
        }
2426
2427
99.4k
        pathSize = strlen(path);
2428
99.4k
        uri->path = xmlMalloc(pathSize + prependSlash + 1);
2429
99.4k
        if (uri->path == NULL) {
2430
35
            ret = -1;
2431
35
            goto done;
2432
35
        }
2433
99.4k
        if (prependSlash) {
2434
0
            uri->path[0] = '/';
2435
0
            memcpy(uri->path + 1, path, pathSize + 1);
2436
99.4k
        } else {
2437
99.4k
            memcpy(uri->path, path, pathSize + 1);
2438
99.4k
        }
2439
99.4k
    } else {
2440
22.2k
  ret = xmlParseURIReference(uri, str);
2441
22.2k
  if (ret != 0)
2442
6.44k
      goto done;
2443
2444
15.7k
        xmlNormalizePath(uri->path, /* isFile */ 0);
2445
15.7k
    }
2446
2447
#if defined(LIBXML_WINPATH_ENABLED)
2448
    if ((uri->path[0] == '/') &&
2449
        (((uri->path[1] >= 'A') && (uri->path[1] <= 'Z')) ||
2450
         ((uri->path[1] >= 'a') && (uri->path[1] <= 'z'))) &&
2451
        (uri->path[2] == ':'))
2452
        *drive = uri->path[1];
2453
#endif
2454
2455
115k
    *out = uri;
2456
115k
    uri = NULL;
2457
115k
    ret = 0;
2458
2459
121k
done:
2460
121k
    xmlFreeURI(uri);
2461
121k
    xmlFree(buf);
2462
2463
121k
    return(ret);
2464
115k
}
2465
2466
/**
2467
 * Expresses the URI of the reference in terms relative to the
2468
 * base. Some examples of this operation include:
2469
 *
2470
 *     base = "http://site1.com/docs/book1.html"
2471
 *        URI input                        URI returned
2472
 *     http://site1.com/docs/pic1.gif   pic1.gif
2473
 *     http://site2.com/docs/pic1.gif   http://site2.com/docs/pic1.gif
2474
 *
2475
 *     base = "docs/book1.html"
2476
 *        URI input                        URI returned
2477
 *     docs/pic1.gif                    pic1.gif
2478
 *     docs/img/pic1.gif                img/pic1.gif
2479
 *     img/pic1.gif                     ../img/pic1.gif
2480
 *     http://site1.com/docs/pic1.gif   http://site1.com/docs/pic1.gif
2481
 *
2482
 * @since 2.13.0
2483
 *
2484
 * @param URI  the URI reference under consideration
2485
 * @param base  the base value
2486
 * @param valPtr  pointer to result URI
2487
 * @returns 0 on success, -1 if a memory allocation failed or an error
2488
 * code if URI or base are invalid.
2489
 */
2490
int
2491
xmlBuildRelativeURISafe(const xmlChar * URI, const xmlChar * base,
2492
                        xmlChar **valPtr)
2493
111k
{
2494
111k
    xmlChar *val = NULL;
2495
111k
    int ret = 0;
2496
111k
    size_t ix = 0;
2497
111k
    size_t nbslash = 0;
2498
111k
    size_t len = 0;
2499
111k
    xmlURIPtr ref = NULL;
2500
111k
    xmlURIPtr bas = NULL;
2501
111k
    const xmlChar *bptr, *uptr, *rptr;
2502
111k
    xmlChar *vptr;
2503
111k
    int remove_path = 0;
2504
111k
    int refDrive, baseDrive;
2505
2506
111k
    if (valPtr == NULL)
2507
0
        return(1);
2508
111k
    *valPtr = NULL;
2509
111k
    if ((URI == NULL) || (*URI == 0))
2510
7.18k
  return(1);
2511
2512
104k
    ret = xmlParseUriOrPath((char *) URI, &ref, &refDrive);
2513
104k
    if (ret < 0)
2514
91
        goto done;
2515
104k
    if (ret != 0) {
2516
        /* Return URI if URI is invalid */
2517
4.14k
        ret = 0;
2518
4.14k
        val = xmlStrdup(URI);
2519
4.14k
        if (val == NULL)
2520
4
            ret = -1;
2521
4.14k
        goto done;
2522
4.14k
    }
2523
2524
    /* Return URI if base is empty */
2525
99.9k
    if ((base == NULL) || (*base == 0))
2526
82.2k
        goto done;
2527
2528
17.6k
    ret = xmlParseUriOrPath((char *) base, &bas, &baseDrive);
2529
17.6k
    if (ret < 0)
2530
51
        goto done;
2531
17.5k
    if (ret != 0) {
2532
        /* Return URI if base is invalid */
2533
2.27k
        ret = 0;
2534
2.27k
        goto done;
2535
2.27k
    }
2536
2537
    /*
2538
     * If the scheme / server on the URI differs from the base,
2539
     * just return the URI
2540
     */
2541
15.2k
    if ((xmlStrcmp ((xmlChar *)bas->scheme, (xmlChar *)ref->scheme)) ||
2542
12.2k
  (xmlStrcmp ((xmlChar *)bas->server, (xmlChar *)ref->server)) ||
2543
11.4k
        (bas->port != ref->port) ||
2544
11.1k
        (baseDrive != refDrive)) {
2545
4.12k
  goto done;
2546
4.12k
    }
2547
11.1k
    if (xmlStrEqual((xmlChar *)bas->path, (xmlChar *)ref->path)) {
2548
572
  val = xmlStrdup(BAD_CAST "");
2549
572
        if (val == NULL)
2550
4
            ret = -1;
2551
572
  goto done;
2552
572
    }
2553
10.5k
    if (bas->path == NULL) {
2554
614
  val = xmlStrdup((xmlChar *)ref->path);
2555
614
        if (val == NULL) {
2556
3
            ret = -1;
2557
3
            goto done;
2558
3
        }
2559
611
  goto escape;
2560
614
    }
2561
9.98k
    if (ref->path == NULL) {
2562
1.57k
        ref->path = (char *) "/";
2563
1.57k
  remove_path = 1;
2564
1.57k
    }
2565
2566
9.98k
    bptr = (xmlChar *) bas->path;
2567
9.98k
    rptr = (xmlChar *) ref->path;
2568
2569
    /*
2570
     * Return URI if URI and base aren't both absolute or relative.
2571
     */
2572
9.98k
    if ((bptr[0] == '/') != (rptr[0] == '/'))
2573
2.31k
        goto done;
2574
2575
    /*
2576
     * At this point we can compare the two paths
2577
     */
2578
7.66k
    {
2579
7.66k
        size_t pos = 0;
2580
2581
        /*
2582
         * Next we compare the two strings and find where they first differ
2583
         */
2584
46.6k
  while ((bptr[pos] == rptr[pos]) && (bptr[pos] != 0))
2585
39.0k
      pos++;
2586
2587
7.66k
  if (bptr[pos] == rptr[pos]) {
2588
215
      val = xmlStrdup(BAD_CAST "");
2589
215
            if (val == NULL)
2590
2
                ret = -1;
2591
215
      goto done;    /* (I can't imagine why anyone would do this) */
2592
215
  }
2593
2594
  /*
2595
   * In URI, "back up" to the last '/' encountered.  This will be the
2596
   * beginning of the "unique" suffix of URI
2597
   */
2598
7.45k
  ix = pos;
2599
32.8k
  for (; ix > 0; ix--) {
2600
28.4k
      if (rptr[ix - 1] == '/')
2601
2.99k
    break;
2602
28.4k
  }
2603
7.45k
  uptr = (xmlChar *)&rptr[ix];
2604
2605
  /*
2606
   * In base, count the number of '/' from the differing point
2607
   */
2608
461k
  for (; bptr[ix] != 0; ix++) {
2609
454k
      if (bptr[ix] == '/')
2610
128k
    nbslash++;
2611
454k
  }
2612
2613
  /*
2614
   * e.g: URI="foo/" base="foo/bar" -> "./"
2615
   */
2616
7.45k
  if (nbslash == 0 && !uptr[0]) {
2617
1.30k
      val = xmlStrdup(BAD_CAST "./");
2618
1.30k
            if (val == NULL)
2619
3
                ret = -1;
2620
1.30k
      goto done;
2621
1.30k
  }
2622
2623
6.14k
  len = (size_t) xmlStrlen (uptr) + 1;
2624
6.14k
    }
2625
2626
6.14k
    if (nbslash == 0) {
2627
2.21k
  if (uptr != NULL) {
2628
      /* exception characters from xmlSaveUri */
2629
2.21k
      val = xmlURIEscapeStr(uptr, BAD_CAST "/;&=+$,");
2630
2.21k
            if (val == NULL)
2631
7
                ret = -1;
2632
2.21k
        }
2633
2.21k
  goto done;
2634
2.21k
    }
2635
2636
    /*
2637
     * Allocate just enough space for the returned string -
2638
     * length of the remainder of the URI, plus enough space
2639
     * for the "../" groups, plus one for the terminator
2640
     */
2641
3.93k
    if (len + 3 * nbslash > SIZE_MAX) {
2642
0
        ret = -1;
2643
0
        goto done;
2644
0
    }
2645
3.93k
    val = (xmlChar *) xmlMalloc (len + 3 * nbslash);
2646
3.93k
    if (val == NULL) {
2647
6
        ret = -1;
2648
6
  goto done;
2649
6
    }
2650
3.92k
    vptr = val;
2651
    /*
2652
     * Put in as many "../" as needed
2653
     */
2654
132k
    for (; nbslash>0; nbslash--) {
2655
128k
  *vptr++ = '.';
2656
128k
  *vptr++ = '.';
2657
128k
  *vptr++ = '/';
2658
128k
    }
2659
    /*
2660
     * Finish up with the end of the URI
2661
     */
2662
3.92k
    if (uptr != NULL) {
2663
3.92k
        if ((vptr > val) && (len > 0) &&
2664
3.92k
      (uptr[0] == '/') && (vptr[-1] == '/')) {
2665
0
      memcpy (vptr, uptr + 1, len - 1);
2666
0
      vptr[len - 2] = 0;
2667
3.92k
  } else {
2668
3.92k
      memcpy (vptr, uptr, len);
2669
3.92k
      vptr[len - 1] = 0;
2670
3.92k
  }
2671
3.92k
    } else {
2672
0
  vptr[len - 1] = 0;
2673
0
    }
2674
2675
4.53k
escape:
2676
    /* escape the freshly-built path */
2677
4.53k
    vptr = val;
2678
    /* exception characters from xmlSaveUri */
2679
4.53k
    val = xmlURIEscapeStr(vptr, BAD_CAST "/;&=+$,");
2680
4.53k
    if (val == NULL)
2681
8
        ret = -1;
2682
4.53k
    else
2683
4.53k
        ret = 0;
2684
4.53k
    xmlFree(vptr);
2685
2686
104k
done:
2687
104k
    if ((ret == 0) && (val == NULL)) {
2688
91.0k
        val = xmlSaveUri(ref);
2689
91.0k
        if (val == NULL)
2690
33
            ret = -1;
2691
91.0k
    }
2692
2693
    /*
2694
     * Free the working variables
2695
     */
2696
104k
    if (remove_path != 0)
2697
1.57k
        ref->path = NULL;
2698
104k
    if (ref != NULL)
2699
99.9k
  xmlFreeURI (ref);
2700
104k
    if (bas != NULL)
2701
15.2k
  xmlFreeURI (bas);
2702
104k
    if (ret != 0) {
2703
212
        xmlFree(val);
2704
212
        val = NULL;
2705
212
    }
2706
2707
104k
    *valPtr = val;
2708
104k
    return(ret);
2709
4.53k
}
2710
2711
/**
2712
 * See #xmlBuildRelativeURISafe.
2713
 *
2714
 * @param URI  the URI reference under consideration
2715
 * @param base  the base value
2716
 * @returns a new URI string (to be freed by the caller) or NULL in case
2717
 * error.
2718
 */
2719
xmlChar *
2720
xmlBuildRelativeURI(const xmlChar * URI, const xmlChar * base)
2721
4.48k
{
2722
4.48k
    xmlChar *val;
2723
2724
4.48k
    xmlBuildRelativeURISafe(URI, base, &val);
2725
4.48k
    return(val);
2726
4.48k
}
2727
2728
/**
2729
 * Prepares a path.
2730
 *
2731
 * If the path contains the substring "://", it is considered a
2732
 * Legacy Extended IRI. Characters which aren't allowed in URIs are
2733
 * escaped.
2734
 *
2735
 * Otherwise, the path is considered a filesystem path which is
2736
 * copied without modification.
2737
 *
2738
 * The caller is responsible for freeing the memory occupied
2739
 * by the returned string. If there is insufficient memory available, or the
2740
 * argument is NULL, the function returns NULL.
2741
 *
2742
 * @param path  the resource locator in a filesystem notation
2743
 * @returns the escaped path.
2744
 */
2745
xmlChar *
2746
xmlCanonicPath(const xmlChar *path)
2747
424k
{
2748
424k
    xmlChar *ret;
2749
2750
424k
    if (path == NULL)
2751
1.19k
  return(NULL);
2752
2753
    /* Check if this is an "absolute uri" */
2754
423k
    if (xmlStrstr(path, BAD_CAST "://") != NULL) {
2755
  /*
2756
         * Escape all characters except reserved, unreserved and the
2757
         * percent sign.
2758
         *
2759
         * xmlURIEscapeStr already keeps unreserved characters, so we
2760
         * pass gen-delims, sub-delims and "%" to ignore.
2761
         */
2762
40.8k
        ret = xmlURIEscapeStr(path, BAD_CAST ":/?#[]@!$&()*+,;='%");
2763
382k
    } else {
2764
382k
        ret = xmlStrdup((const xmlChar *) path);
2765
382k
    }
2766
2767
423k
    return(ret);
2768
424k
}
2769
2770
/**
2771
 * Constructs an URI expressing the existing path
2772
 *
2773
 * @param path  the resource locator in a filesystem notation
2774
 * @returns a new URI, or a duplicate of the path parameter if the
2775
 * construction fails. The caller is responsible for freeing the memory
2776
 * occupied by the returned string. If there is insufficient memory available,
2777
 * or the argument is NULL, the function returns NULL.
2778
 */
2779
xmlChar *
2780
xmlPathToURI(const xmlChar *path)
2781
381k
{
2782
381k
    return(xmlCanonicPath(path));
2783
381k
}