Coverage Report

Created: 2026-09-03 06:43

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/xpath.c
Line
Count
Source
1
/*
2
 * xpath.c: XML Path Language implementation
3
 *          XPath is a language for addressing parts of an XML document,
4
 *          designed to be used by both XSLT and XPointer
5
 *
6
 * Reference: W3C Recommendation 16 November 1999
7
 *     http://www.w3.org/TR/1999/REC-xpath-19991116
8
 * Public reference:
9
 *     http://www.w3.org/TR/xpath
10
 *
11
 * See Copyright for the status of this software
12
 *
13
 * Author: daniel@veillard.com
14
 *
15
 */
16
17
/* To avoid EBCDIC trouble when parsing on zOS */
18
#if defined(__MVS__)
19
#pragma convert("ISO8859-1")
20
#endif
21
22
#define IN_LIBXML
23
#include "libxml.h"
24
25
#include <limits.h>
26
#include <string.h>
27
#include <stddef.h>
28
#include <math.h>
29
#include <float.h>
30
#include <ctype.h>
31
32
#include <libxml/xmlmemory.h>
33
#include <libxml/tree.h>
34
#include <libxml/xpath.h>
35
#include <libxml/xpathInternals.h>
36
#include <libxml/parserInternals.h>
37
#include <libxml/hash.h>
38
#ifdef LIBXML_DEBUG_ENABLED
39
#include <libxml/debugXML.h>
40
#endif
41
#include <libxml/xmlerror.h>
42
#include <libxml/threads.h>
43
#ifdef LIBXML_PATTERN_ENABLED
44
#include <libxml/pattern.h>
45
#endif
46
47
#include "private/buf.h"
48
#include "private/error.h"
49
#include "private/memory.h"
50
#include "private/xpath.h"
51
52
/* Disabled for now */
53
#if 0
54
#ifdef LIBXML_PATTERN_ENABLED
55
#define XPATH_STREAMING
56
#endif
57
#endif
58
59
/**
60
 * WITH_TIM_SORT:
61
 *
62
 * Use the Timsort algorithm provided in timsort.h to sort
63
 * nodeset as this is a great improvement over the old Shell sort
64
 * used in xmlXPathNodeSetSort()
65
 */
66
#define WITH_TIM_SORT
67
68
/*
69
* XP_OPTIMIZED_NON_ELEM_COMPARISON:
70
* If defined, this will use xmlXPathCmpNodesExt() instead of
71
* xmlXPathCmpNodes(). The new function is optimized comparison of
72
* non-element nodes; actually it will speed up comparison only if
73
* xmlXPathOrderDocElems() was called in order to index the elements of
74
* a tree in document order; Libxslt does such an indexing, thus it will
75
* benefit from this optimization.
76
*/
77
#define XP_OPTIMIZED_NON_ELEM_COMPARISON
78
79
/*
80
* XP_OPTIMIZED_FILTER_FIRST:
81
* If defined, this will optimize expressions like "key('foo', 'val')[b][1]"
82
* in a way, that it stop evaluation at the first node.
83
*/
84
#define XP_OPTIMIZED_FILTER_FIRST
85
86
/*
87
 * XPATH_MAX_STEPS:
88
 * when compiling an XPath expression we arbitrary limit the maximum
89
 * number of step operation in the compiled expression. 1000000 is
90
 * an insanely large value which should never be reached under normal
91
 * circumstances
92
 */
93
2.13M
#define XPATH_MAX_STEPS 1000000
94
95
/*
96
 * XPATH_MAX_STACK_DEPTH:
97
 * when evaluating an XPath expression we arbitrary limit the maximum
98
 * number of object allowed to be pushed on the stack. 1000000 is
99
 * an insanely large value which should never be reached under normal
100
 * circumstances
101
 */
102
1.71M
#define XPATH_MAX_STACK_DEPTH 1000000
103
104
/*
105
 * XPATH_MAX_NODESET_LENGTH:
106
 * when evaluating an XPath expression nodesets are created and we
107
 * arbitrary limit the maximum length of those node set. 10000000 is
108
 * an insanely large value which should never be reached under normal
109
 * circumstances, one would first need to construct an in memory tree
110
 * with more than 10 millions nodes.
111
 */
112
10.6M
#define XPATH_MAX_NODESET_LENGTH 10000000
113
114
/*
115
 * XPATH_MAX_RECRUSION_DEPTH:
116
 * Maximum amount of nested functions calls when parsing or evaluating
117
 * expressions
118
 */
119
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
120
31.1M
#define XPATH_MAX_RECURSION_DEPTH 500
121
#elif defined(_WIN32)
122
/* Windows typically limits stack size to 1MB. */
123
#define XPATH_MAX_RECURSION_DEPTH 1000
124
#else
125
#define XPATH_MAX_RECURSION_DEPTH 5000
126
#endif
127
128
/*
129
 * TODO:
130
 * There are a few spots where some tests are done which depend upon ascii
131
 * data.  These should be enhanced for full UTF8 support (see particularly
132
 * any use of the macros IS_ASCII_CHARACTER and IS_ASCII_DIGIT)
133
 */
134
135
#if defined(LIBXML_XPATH_ENABLED)
136
137
static void
138
xmlXPathNameFunction(xmlXPathParserContextPtr ctxt, int nargs);
139
140
static const struct {
141
    const char *name;
142
    xmlXPathFunction func;
143
} xmlXPathStandardFunctions[] = {
144
    { "boolean", xmlXPathBooleanFunction },
145
    { "ceiling", xmlXPathCeilingFunction },
146
    { "count", xmlXPathCountFunction },
147
    { "concat", xmlXPathConcatFunction },
148
    { "contains", xmlXPathContainsFunction },
149
    { "id", xmlXPathIdFunction },
150
    { "false", xmlXPathFalseFunction },
151
    { "floor", xmlXPathFloorFunction },
152
    { "last", xmlXPathLastFunction },
153
    { "lang", xmlXPathLangFunction },
154
    { "local-name", xmlXPathLocalNameFunction },
155
    { "not", xmlXPathNotFunction },
156
    { "name", xmlXPathNameFunction },
157
    { "namespace-uri", xmlXPathNamespaceURIFunction },
158
    { "normalize-space", xmlXPathNormalizeFunction },
159
    { "number", xmlXPathNumberFunction },
160
    { "position", xmlXPathPositionFunction },
161
    { "round", xmlXPathRoundFunction },
162
    { "string", xmlXPathStringFunction },
163
    { "string-length", xmlXPathStringLengthFunction },
164
    { "starts-with", xmlXPathStartsWithFunction },
165
    { "substring", xmlXPathSubstringFunction },
166
    { "substring-before", xmlXPathSubstringBeforeFunction },
167
    { "substring-after", xmlXPathSubstringAfterFunction },
168
    { "sum", xmlXPathSumFunction },
169
    { "true", xmlXPathTrueFunction },
170
    { "translate", xmlXPathTranslateFunction }
171
};
172
173
#define NUM_STANDARD_FUNCTIONS \
174
56
    (sizeof(xmlXPathStandardFunctions) / sizeof(xmlXPathStandardFunctions[0]))
175
176
253k
#define SF_HASH_SIZE 64
177
178
static unsigned char xmlXPathSFHash[SF_HASH_SIZE];
179
180
double xmlXPathNAN = 0.0;
181
double xmlXPathPINF = 0.0;
182
double xmlXPathNINF = 0.0;
183
184
/**
185
 * xmlXPathInit:
186
 *
187
 * DEPRECATED: Alias for xmlInitParser.
188
 */
189
void
190
0
xmlXPathInit(void) {
191
0
    xmlInitParser();
192
0
}
193
194
ATTRIBUTE_NO_SANITIZE_INTEGER
195
static unsigned
196
159k
xmlXPathSFComputeHash(const xmlChar *name) {
197
159k
    unsigned hashValue = 5381;
198
159k
    const xmlChar *ptr;
199
200
1.05M
    for (ptr = name; *ptr; ptr++)
201
897k
        hashValue = hashValue * 33 + *ptr;
202
203
159k
    return(hashValue);
204
159k
}
205
206
/**
207
 * xmlInitXPathInternal:
208
 *
209
 * Initialize the XPath environment
210
 */
211
ATTRIBUTE_NO_SANITIZE("float-divide-by-zero")
212
void
213
2
xmlInitXPathInternal(void) {
214
2
    size_t i;
215
216
2
#if defined(NAN) && defined(INFINITY)
217
2
    xmlXPathNAN = NAN;
218
2
    xmlXPathPINF = INFINITY;
219
2
    xmlXPathNINF = -INFINITY;
220
#else
221
    /* MSVC doesn't allow division by zero in constant expressions. */
222
    double zero = 0.0;
223
    xmlXPathNAN = 0.0 / zero;
224
    xmlXPathPINF = 1.0 / zero;
225
    xmlXPathNINF = -xmlXPathPINF;
226
#endif
227
228
    /*
229
     * Initialize hash table for standard functions
230
     */
231
232
130
    for (i = 0; i < SF_HASH_SIZE; i++)
233
128
        xmlXPathSFHash[i] = UCHAR_MAX;
234
235
56
    for (i = 0; i < NUM_STANDARD_FUNCTIONS; i++) {
236
54
        const char *name = xmlXPathStandardFunctions[i].name;
237
54
        int bucketIndex = xmlXPathSFComputeHash(BAD_CAST name) % SF_HASH_SIZE;
238
239
68
        while (xmlXPathSFHash[bucketIndex] != UCHAR_MAX) {
240
14
            bucketIndex += 1;
241
14
            if (bucketIndex >= SF_HASH_SIZE)
242
0
                bucketIndex = 0;
243
14
        }
244
245
54
        xmlXPathSFHash[bucketIndex] = i;
246
54
    }
247
2
}
248
249
/************************************************************************
250
 *                  *
251
 *      Floating point stuff        *
252
 *                  *
253
 ************************************************************************/
254
255
/**
256
 * xmlXPathIsNaN:
257
 * @val:  a double value
258
 *
259
 * Checks whether a double is a NaN.
260
 *
261
 * Returns 1 if the value is a NaN, 0 otherwise
262
 */
263
int
264
1.15M
xmlXPathIsNaN(double val) {
265
1.15M
#ifdef isnan
266
1.15M
    return isnan(val);
267
#else
268
    return !(val == val);
269
#endif
270
1.15M
}
271
272
/**
273
 * xmlXPathIsInf:
274
 * @val:  a double value
275
 *
276
 * Checks whether a double is an infinity.
277
 *
278
 * Returns 1 if the value is +Infinite, -1 if -Infinite, 0 otherwise
279
 */
280
int
281
727k
xmlXPathIsInf(double val) {
282
727k
#ifdef isinf
283
727k
    return isinf(val) ? (val > 0 ? 1 : -1) : 0;
284
#else
285
    if (val >= xmlXPathPINF)
286
        return 1;
287
    if (val <= -xmlXPathPINF)
288
        return -1;
289
    return 0;
290
#endif
291
727k
}
292
293
/*
294
 * TODO: when compatibility allows remove all "fake node libxslt" strings
295
 *       the test should just be name[0] = ' '
296
 */
297
298
static const xmlNs xmlXPathXMLNamespaceStruct = {
299
    NULL,
300
    XML_NAMESPACE_DECL,
301
    XML_XML_NAMESPACE,
302
    BAD_CAST "xml",
303
    NULL,
304
    NULL
305
};
306
static const xmlNs *const xmlXPathXMLNamespace = &xmlXPathXMLNamespaceStruct;
307
308
static void
309
xmlXPathNodeSetClear(xmlNodeSetPtr set, int hasNsNodes);
310
311
101M
#define XML_NODE_SORT_VALUE(n) XML_PTR_TO_INT((n)->content)
312
313
#ifdef XP_OPTIMIZED_NON_ELEM_COMPARISON
314
315
/**
316
 * xmlXPathCmpNodesExt:
317
 * @node1:  the first node
318
 * @node2:  the second node
319
 *
320
 * Compare two nodes w.r.t document order.
321
 * This one is optimized for handling of non-element nodes.
322
 *
323
 * Returns -2 in case of error 1 if first point < second point, 0 if
324
 *         it's the same node, -1 otherwise
325
 */
326
static int
327
38.6M
xmlXPathCmpNodesExt(xmlNodePtr node1, xmlNodePtr node2) {
328
38.6M
    int depth1, depth2;
329
38.6M
    int misc = 0, precedence1 = 0, precedence2 = 0;
330
38.6M
    xmlNodePtr miscNode1 = NULL, miscNode2 = NULL;
331
38.6M
    xmlNodePtr cur, root;
332
38.6M
    XML_INTPTR_T l1, l2;
333
334
38.6M
    if ((node1 == NULL) || (node2 == NULL))
335
0
  return(-2);
336
337
38.6M
    if (node1 == node2)
338
0
  return(0);
339
340
    /*
341
     * a couple of optimizations which will avoid computations in most cases
342
     */
343
38.6M
    switch (node1->type) {
344
26.7M
  case XML_ELEMENT_NODE:
345
26.7M
      if (node2->type == XML_ELEMENT_NODE) {
346
20.2M
    if ((0 > XML_NODE_SORT_VALUE(node1)) &&
347
6.60M
        (0 > XML_NODE_SORT_VALUE(node2)) &&
348
6.59M
        (node1->doc == node2->doc))
349
6.59M
    {
350
6.59M
        l1 = -XML_NODE_SORT_VALUE(node1);
351
6.59M
        l2 = -XML_NODE_SORT_VALUE(node2);
352
6.59M
        if (l1 < l2)
353
4.37M
      return(1);
354
2.22M
        if (l1 > l2)
355
2.22M
      return(-1);
356
2.22M
    } else
357
13.6M
        goto turtle_comparison;
358
20.2M
      }
359
6.51M
      break;
360
6.51M
  case XML_ATTRIBUTE_NODE:
361
91.3k
      precedence1 = 1; /* element is owner */
362
91.3k
      miscNode1 = node1;
363
91.3k
      node1 = node1->parent;
364
91.3k
      misc = 1;
365
91.3k
      break;
366
9.72M
  case XML_TEXT_NODE:
367
9.72M
  case XML_CDATA_SECTION_NODE:
368
10.2M
  case XML_COMMENT_NODE:
369
10.7M
  case XML_PI_NODE: {
370
10.7M
      miscNode1 = node1;
371
      /*
372
      * Find nearest element node.
373
      */
374
10.7M
      if (node1->prev != NULL) {
375
6.46M
    do {
376
6.46M
        node1 = node1->prev;
377
6.46M
        if (node1->type == XML_ELEMENT_NODE) {
378
4.69M
      precedence1 = 3; /* element in prev-sibl axis */
379
4.69M
      break;
380
4.69M
        }
381
1.76M
        if (node1->prev == NULL) {
382
904k
      precedence1 = 2; /* element is parent */
383
      /*
384
      * URGENT TODO: Are there any cases, where the
385
      * parent of such a node is not an element node?
386
      */
387
904k
      node1 = node1->parent;
388
904k
      break;
389
904k
        }
390
1.76M
    } while (1);
391
5.60M
      } else {
392
5.17M
    precedence1 = 2; /* element is parent */
393
5.17M
    node1 = node1->parent;
394
5.17M
      }
395
10.7M
      if ((node1 == NULL) || (node1->type != XML_ELEMENT_NODE) ||
396
10.6M
    (0 <= XML_NODE_SORT_VALUE(node1))) {
397
    /*
398
    * Fallback for whatever case.
399
    */
400
178k
    node1 = miscNode1;
401
178k
    precedence1 = 0;
402
178k
      } else
403
10.6M
    misc = 1;
404
10.7M
  }
405
10.7M
      break;
406
656k
  case XML_NAMESPACE_DECL:
407
      /*
408
      * TODO: why do we return 1 for namespace nodes?
409
      */
410
656k
      return(1);
411
333k
  default:
412
333k
      break;
413
38.6M
    }
414
17.7M
    switch (node2->type) {
415
6.54M
  case XML_ELEMENT_NODE:
416
6.54M
      break;
417
88.1k
  case XML_ATTRIBUTE_NODE:
418
88.1k
      precedence2 = 1; /* element is owner */
419
88.1k
      miscNode2 = node2;
420
88.1k
      node2 = node2->parent;
421
88.1k
      misc = 1;
422
88.1k
      break;
423
9.78M
  case XML_TEXT_NODE:
424
9.78M
  case XML_CDATA_SECTION_NODE:
425
10.4M
  case XML_COMMENT_NODE:
426
10.9M
  case XML_PI_NODE: {
427
10.9M
      miscNode2 = node2;
428
10.9M
      if (node2->prev != NULL) {
429
6.31M
    do {
430
6.31M
        node2 = node2->prev;
431
6.31M
        if (node2->type == XML_ELEMENT_NODE) {
432
4.54M
      precedence2 = 3; /* element in prev-sibl axis */
433
4.54M
      break;
434
4.54M
        }
435
1.76M
        if (node2->prev == NULL) {
436
901k
      precedence2 = 2; /* element is parent */
437
901k
      node2 = node2->parent;
438
901k
      break;
439
901k
        }
440
1.76M
    } while (1);
441
5.46M
      } else {
442
5.46M
    precedence2 = 2; /* element is parent */
443
5.46M
    node2 = node2->parent;
444
5.46M
      }
445
10.9M
      if ((node2 == NULL) || (node2->type != XML_ELEMENT_NODE) ||
446
10.6M
    (0 <= XML_NODE_SORT_VALUE(node2)))
447
307k
      {
448
307k
    node2 = miscNode2;
449
307k
    precedence2 = 0;
450
307k
      } else
451
10.6M
    misc = 1;
452
10.9M
  }
453
10.9M
      break;
454
21.0k
  case XML_NAMESPACE_DECL:
455
21.0k
      return(1);
456
152k
  default:
457
152k
      break;
458
17.7M
    }
459
17.7M
    if (misc) {
460
16.9M
  if (node1 == node2) {
461
6.13M
      if (precedence1 == precedence2) {
462
    /*
463
    * The ugly case; but normally there aren't many
464
    * adjacent non-element nodes around.
465
    */
466
954k
    cur = miscNode2->prev;
467
984k
    while (cur != NULL) {
468
932k
        if (cur == miscNode1)
469
871k
      return(1);
470
61.4k
        if (cur->type == XML_ELEMENT_NODE)
471
31.3k
      return(-1);
472
30.0k
        cur = cur->prev;
473
30.0k
    }
474
51.4k
    return (-1);
475
5.18M
      } else {
476
    /*
477
    * Evaluate based on higher precedence wrt to the element.
478
    * TODO: This assumes attributes are sorted before content.
479
    *   Is this 100% correct?
480
    */
481
5.18M
    if (precedence1 < precedence2)
482
4.14M
        return(1);
483
1.03M
    else
484
1.03M
        return(-1);
485
5.18M
      }
486
6.13M
  }
487
  /*
488
  * Special case: One of the helper-elements is contained by the other.
489
  * <foo>
490
  *   <node2>
491
  *     <node1>Text-1(precedence1 == 2)</node1>
492
  *   </node2>
493
  *   Text-6(precedence2 == 3)
494
  * </foo>
495
  */
496
10.8M
  if ((precedence2 == 3) && (precedence1 > 1)) {
497
1.39M
      cur = node1->parent;
498
6.30M
      while (cur) {
499
5.49M
    if (cur == node2)
500
580k
        return(1);
501
4.91M
    cur = cur->parent;
502
4.91M
      }
503
1.39M
  }
504
10.2M
  if ((precedence1 == 3) && (precedence2 > 1)) {
505
1.01M
      cur = node2->parent;
506
5.18M
      while (cur) {
507
4.23M
    if (cur == node1)
508
71.4k
        return(-1);
509
4.16M
    cur = cur->parent;
510
4.16M
      }
511
1.01M
  }
512
10.2M
    }
513
514
    /*
515
     * Speedup using document order if available.
516
     */
517
10.9M
    if ((node1->type == XML_ELEMENT_NODE) &&
518
10.4M
  (node2->type == XML_ELEMENT_NODE) &&
519
10.0M
  (0 > XML_NODE_SORT_VALUE(node1)) &&
520
9.99M
  (0 > XML_NODE_SORT_VALUE(node2)) &&
521
9.98M
  (node1->doc == node2->doc)) {
522
523
9.98M
  l1 = -XML_NODE_SORT_VALUE(node1);
524
9.98M
  l2 = -XML_NODE_SORT_VALUE(node2);
525
9.98M
  if (l1 < l2)
526
5.43M
      return(1);
527
4.55M
  if (l1 > l2)
528
4.55M
      return(-1);
529
4.55M
    }
530
531
14.6M
turtle_comparison:
532
533
14.6M
    if (node1 == node2->prev)
534
12.9M
  return(1);
535
1.70M
    if (node1 == node2->next)
536
59.7k
  return(-1);
537
    /*
538
     * compute depth to root
539
     */
540
3.14M
    for (depth2 = 0, cur = node2; cur->parent != NULL; cur = cur->parent) {
541
1.80M
  if (cur->parent == node1)
542
305k
      return(1);
543
1.49M
  depth2++;
544
1.49M
    }
545
1.34M
    root = cur;
546
3.31M
    for (depth1 = 0, cur = node1; cur->parent != NULL; cur = cur->parent) {
547
2.07M
  if (cur->parent == node2)
548
95.9k
      return(-1);
549
1.97M
  depth1++;
550
1.97M
    }
551
    /*
552
     * Distinct document (or distinct entities :-( ) case.
553
     */
554
1.24M
    if (root != cur) {
555
865k
  return(-2);
556
865k
    }
557
    /*
558
     * get the nearest common ancestor.
559
     */
560
815k
    while (depth1 > depth2) {
561
434k
  depth1--;
562
434k
  node1 = node1->parent;
563
434k
    }
564
482k
    while (depth2 > depth1) {
565
100k
  depth2--;
566
100k
  node2 = node2->parent;
567
100k
    }
568
442k
    while (node1->parent != node2->parent) {
569
61.2k
  node1 = node1->parent;
570
61.2k
  node2 = node2->parent;
571
  /* should not happen but just in case ... */
572
61.2k
  if ((node1 == NULL) || (node2 == NULL))
573
0
      return(-2);
574
61.2k
    }
575
    /*
576
     * Find who's first.
577
     */
578
381k
    if (node1 == node2->prev)
579
47.1k
  return(1);
580
334k
    if (node1 == node2->next)
581
178k
  return(-1);
582
    /*
583
     * Speedup using document order if available.
584
     */
585
155k
    if ((node1->type == XML_ELEMENT_NODE) &&
586
139k
  (node2->type == XML_ELEMENT_NODE) &&
587
130k
  (0 > XML_NODE_SORT_VALUE(node1)) &&
588
0
  (0 > XML_NODE_SORT_VALUE(node2)) &&
589
0
  (node1->doc == node2->doc)) {
590
591
0
  l1 = -XML_NODE_SORT_VALUE(node1);
592
0
  l2 = -XML_NODE_SORT_VALUE(node2);
593
0
  if (l1 < l2)
594
0
      return(1);
595
0
  if (l1 > l2)
596
0
      return(-1);
597
0
    }
598
599
2.85M
    for (cur = node1->next;cur != NULL;cur = cur->next)
600
2.79M
  if (cur == node2)
601
97.6k
      return(1);
602
58.0k
    return(-1); /* assume there is no sibling list corruption */
603
155k
}
604
#endif /* XP_OPTIMIZED_NON_ELEM_COMPARISON */
605
606
/*
607
 * Wrapper for the Timsort algorithm from timsort.h
608
 */
609
#ifdef WITH_TIM_SORT
610
#define SORT_NAME libxml_domnode
611
15.7M
#define SORT_TYPE xmlNodePtr
612
/**
613
 * wrap_cmp:
614
 * @x: a node
615
 * @y: another node
616
 *
617
 * Comparison function for the Timsort implementation
618
 *
619
 * Returns -2 in case of error -1 if first point < second point, 0 if
620
 *         it's the same node, +1 otherwise
621
 */
622
static
623
int wrap_cmp( xmlNodePtr x, xmlNodePtr y );
624
#ifdef XP_OPTIMIZED_NON_ELEM_COMPARISON
625
    static int wrap_cmp( xmlNodePtr x, xmlNodePtr y )
626
38.6M
    {
627
38.6M
        int res = xmlXPathCmpNodesExt(x, y);
628
38.6M
        return res == -2 ? res : -res;
629
38.6M
    }
630
#else
631
    static int wrap_cmp( xmlNodePtr x, xmlNodePtr y )
632
    {
633
        int res = xmlXPathCmpNodes(x, y);
634
        return res == -2 ? res : -res;
635
    }
636
#endif
637
38.6M
#define SORT_CMP(x, y)  (wrap_cmp(x, y))
638
#include "timsort.h"
639
#endif /* WITH_TIM_SORT */
640
641
/************************************************************************
642
 *                  *
643
 *      Error handling routines       *
644
 *                  *
645
 ************************************************************************/
646
647
/**
648
 * XP_ERRORNULL:
649
 * @X:  the error code
650
 *
651
 * Macro to raise an XPath error and return NULL.
652
 */
653
#define XP_ERRORNULL(X)             \
654
53.5k
    { xmlXPathErr(ctxt, X); return(NULL); }
655
656
/*
657
 * The array xmlXPathErrorMessages corresponds to the enum xmlXPathError
658
 */
659
static const char* const xmlXPathErrorMessages[] = {
660
    "Ok\n",
661
    "Number encoding\n",
662
    "Unfinished literal\n",
663
    "Start of literal\n",
664
    "Expected $ for variable reference\n",
665
    "Undefined variable\n",
666
    "Invalid predicate\n",
667
    "Invalid expression\n",
668
    "Missing closing curly brace\n",
669
    "Unregistered function\n",
670
    "Invalid operand\n",
671
    "Invalid type\n",
672
    "Invalid number of arguments\n",
673
    "Invalid context size\n",
674
    "Invalid context position\n",
675
    "Memory allocation error\n",
676
    "Syntax error\n",
677
    "Resource error\n",
678
    "Sub resource error\n",
679
    "Undefined namespace prefix\n",
680
    "Encoding error\n",
681
    "Char out of XML range\n",
682
    "Invalid or incomplete context\n",
683
    "Stack usage error\n",
684
    "Forbidden variable\n",
685
    "Operation limit exceeded\n",
686
    "Recursion limit exceeded\n",
687
    "?? Unknown error ??\n" /* Must be last in the list! */
688
};
689
1.32M
#define MAXERRNO ((int)(sizeof(xmlXPathErrorMessages) /  \
690
1.32M
       sizeof(xmlXPathErrorMessages[0])) - 1)
691
/**
692
 * xmlXPathErrMemory:
693
 * @ctxt:  an XPath context
694
 *
695
 * Handle a memory allocation failure.
696
 */
697
void
698
xmlXPathErrMemory(xmlXPathContextPtr ctxt)
699
166k
{
700
166k
    if (ctxt == NULL)
701
0
        return;
702
166k
    xmlRaiseMemoryError(ctxt->error, NULL, ctxt->userData, XML_FROM_XPATH,
703
166k
                        &ctxt->lastError);
704
166k
}
705
706
/**
707
 * xmlXPathPErrMemory:
708
 * @ctxt:  an XPath parser context
709
 *
710
 * Handle a memory allocation failure.
711
 */
712
void
713
xmlXPathPErrMemory(xmlXPathParserContextPtr ctxt)
714
66.2k
{
715
66.2k
    if (ctxt == NULL)
716
17
        return;
717
66.1k
    ctxt->error = XPATH_MEMORY_ERROR;
718
66.1k
    xmlXPathErrMemory(ctxt->context);
719
66.1k
}
720
721
/**
722
 * xmlXPathErr:
723
 * @ctxt:  a XPath parser context
724
 * @code:  the error code
725
 *
726
 * Handle an XPath error
727
 */
728
void
729
xmlXPathErr(xmlXPathParserContextPtr ctxt, int code)
730
1.32M
{
731
1.32M
    xmlStructuredErrorFunc schannel = NULL;
732
1.32M
    xmlGenericErrorFunc channel = NULL;
733
1.32M
    void *data = NULL;
734
1.32M
    xmlNodePtr node = NULL;
735
1.32M
    int res;
736
737
1.32M
    if (ctxt == NULL)
738
0
        return;
739
1.32M
    if ((code < 0) || (code > MAXERRNO))
740
0
  code = MAXERRNO;
741
    /* Only report the first error */
742
1.32M
    if (ctxt->error != 0)
743
37.4k
        return;
744
745
1.29M
    ctxt->error = code;
746
747
1.29M
    if (ctxt->context != NULL) {
748
1.29M
        xmlErrorPtr err = &ctxt->context->lastError;
749
750
        /* Don't overwrite memory error. */
751
1.29M
        if (err->code == XML_ERR_NO_MEMORY)
752
3.64k
            return;
753
754
        /* cleanup current last error */
755
1.28M
        xmlResetError(err);
756
757
1.28M
        err->domain = XML_FROM_XPATH;
758
1.28M
        err->code = code + XML_XPATH_EXPRESSION_OK - XPATH_EXPRESSION_OK;
759
1.28M
        err->level = XML_ERR_ERROR;
760
1.28M
        if (ctxt->base != NULL) {
761
344k
            err->str1 = (char *) xmlStrdup(ctxt->base);
762
344k
            if (err->str1 == NULL) {
763
21
                xmlXPathPErrMemory(ctxt);
764
21
                return;
765
21
            }
766
344k
        }
767
1.28M
        err->int1 = ctxt->cur - ctxt->base;
768
1.28M
        err->node = ctxt->context->debugNode;
769
770
1.28M
        schannel = ctxt->context->error;
771
1.28M
        data = ctxt->context->userData;
772
1.28M
        node = ctxt->context->debugNode;
773
1.28M
    }
774
775
1.28M
    if (schannel == NULL) {
776
1.28M
        channel = xmlGenericError;
777
1.28M
        data = xmlGenericErrorContext;
778
1.28M
    }
779
780
1.28M
    res = xmlRaiseError(schannel, channel, data, NULL, node, XML_FROM_XPATH,
781
1.28M
                        code + XML_XPATH_EXPRESSION_OK - XPATH_EXPRESSION_OK,
782
1.28M
                        XML_ERR_ERROR, NULL, 0,
783
1.28M
                        (const char *) ctxt->base, NULL, NULL,
784
1.28M
                        ctxt->cur - ctxt->base, 0,
785
1.28M
                        "%s", xmlXPathErrorMessages[code]);
786
1.28M
    if (res < 0)
787
321
        xmlXPathPErrMemory(ctxt);
788
1.28M
}
789
790
/**
791
 * xmlXPatherror:
792
 * @ctxt:  the XPath Parser context
793
 * @file:  the file name
794
 * @line:  the line number
795
 * @no:  the error number
796
 *
797
 * Formats an error message.
798
 */
799
void
800
xmlXPatherror(xmlXPathParserContextPtr ctxt, const char *file ATTRIBUTE_UNUSED,
801
97.8k
              int line ATTRIBUTE_UNUSED, int no) {
802
97.8k
    xmlXPathErr(ctxt, no);
803
97.8k
}
804
805
/**
806
 * xmlXPathCheckOpLimit:
807
 * @ctxt:  the XPath Parser context
808
 * @opCount:  the number of operations to be added
809
 *
810
 * Adds opCount to the running total of operations and returns -1 if the
811
 * operation limit is exceeded. Returns 0 otherwise.
812
 */
813
static int
814
56.4M
xmlXPathCheckOpLimit(xmlXPathParserContextPtr ctxt, unsigned long opCount) {
815
56.4M
    xmlXPathContextPtr xpctxt = ctxt->context;
816
817
56.4M
    if ((opCount > xpctxt->opLimit) ||
818
56.4M
        (xpctxt->opCount > xpctxt->opLimit - opCount)) {
819
599k
        xpctxt->opCount = xpctxt->opLimit;
820
599k
        xmlXPathErr(ctxt, XPATH_OP_LIMIT_EXCEEDED);
821
599k
        return(-1);
822
599k
    }
823
824
55.8M
    xpctxt->opCount += opCount;
825
55.8M
    return(0);
826
56.4M
}
827
828
#define OP_LIMIT_EXCEEDED(ctxt, n) \
829
53.4M
    ((ctxt->context->opLimit != 0) && (xmlXPathCheckOpLimit(ctxt, n) < 0))
830
831
/************************************************************************
832
 *                  *
833
 *      Parser Types          *
834
 *                  *
835
 ************************************************************************/
836
837
/*
838
 * Types are private:
839
 */
840
841
typedef enum {
842
    XPATH_OP_END=0,
843
    XPATH_OP_AND,
844
    XPATH_OP_OR,
845
    XPATH_OP_EQUAL,
846
    XPATH_OP_CMP,
847
    XPATH_OP_PLUS,
848
    XPATH_OP_MULT,
849
    XPATH_OP_UNION,
850
    XPATH_OP_ROOT,
851
    XPATH_OP_NODE,
852
    XPATH_OP_COLLECT,
853
    XPATH_OP_VALUE, /* 11 */
854
    XPATH_OP_VARIABLE,
855
    XPATH_OP_FUNCTION,
856
    XPATH_OP_ARG,
857
    XPATH_OP_PREDICATE,
858
    XPATH_OP_FILTER, /* 16 */
859
    XPATH_OP_SORT /* 17 */
860
} xmlXPathOp;
861
862
typedef enum {
863
    AXIS_ANCESTOR = 1,
864
    AXIS_ANCESTOR_OR_SELF,
865
    AXIS_ATTRIBUTE,
866
    AXIS_CHILD,
867
    AXIS_DESCENDANT,
868
    AXIS_DESCENDANT_OR_SELF,
869
    AXIS_FOLLOWING,
870
    AXIS_FOLLOWING_SIBLING,
871
    AXIS_NAMESPACE,
872
    AXIS_PARENT,
873
    AXIS_PRECEDING,
874
    AXIS_PRECEDING_SIBLING,
875
    AXIS_SELF
876
} xmlXPathAxisVal;
877
878
typedef enum {
879
    NODE_TEST_NONE = 0,
880
    NODE_TEST_TYPE = 1,
881
    NODE_TEST_PI = 2,
882
    NODE_TEST_ALL = 3,
883
    NODE_TEST_NS = 4,
884
    NODE_TEST_NAME = 5
885
} xmlXPathTestVal;
886
887
typedef enum {
888
    NODE_TYPE_NODE = 0,
889
    NODE_TYPE_COMMENT = XML_COMMENT_NODE,
890
    NODE_TYPE_TEXT = XML_TEXT_NODE,
891
    NODE_TYPE_PI = XML_PI_NODE
892
} xmlXPathTypeVal;
893
894
typedef struct _xmlXPathStepOp xmlXPathStepOp;
895
typedef xmlXPathStepOp *xmlXPathStepOpPtr;
896
struct _xmlXPathStepOp {
897
    xmlXPathOp op;    /* The identifier of the operation */
898
    int ch1;      /* First child */
899
    int ch2;      /* Second child */
900
    int value;
901
    int value2;
902
    int value3;
903
    void *value4;
904
    void *value5;
905
    xmlXPathFunction cache;
906
    void *cacheURI;
907
};
908
909
struct _xmlXPathCompExpr {
910
    int nbStep;     /* Number of steps in this expression */
911
    int maxStep;    /* Maximum number of steps allocated */
912
    xmlXPathStepOp *steps;  /* ops for computation of this expression */
913
    int last;     /* index of last step in expression */
914
    xmlChar *expr;    /* the expression being computed */
915
    xmlDictPtr dict;    /* the dictionary to use if any */
916
#ifdef XPATH_STREAMING
917
    xmlPatternPtr stream;
918
#endif
919
};
920
921
/************************************************************************
922
 *                  *
923
 *      Forward declarations        *
924
 *                  *
925
 ************************************************************************/
926
927
static void
928
xmlXPathReleaseObject(xmlXPathContextPtr ctxt, xmlXPathObjectPtr obj);
929
static int
930
xmlXPathCompOpEvalFirst(xmlXPathParserContextPtr ctxt,
931
                        xmlXPathStepOpPtr op, xmlNodePtr *first);
932
static int
933
xmlXPathCompOpEvalToBoolean(xmlXPathParserContextPtr ctxt,
934
          xmlXPathStepOpPtr op,
935
          int isPredicate);
936
static void
937
xmlXPathFreeObjectEntry(void *obj, const xmlChar *name);
938
939
/************************************************************************
940
 *                  *
941
 *      Parser Type functions       *
942
 *                  *
943
 ************************************************************************/
944
945
/**
946
 * xmlXPathNewCompExpr:
947
 *
948
 * Create a new Xpath component
949
 *
950
 * Returns the newly allocated xmlXPathCompExprPtr or NULL in case of error
951
 */
952
static xmlXPathCompExprPtr
953
663k
xmlXPathNewCompExpr(void) {
954
663k
    xmlXPathCompExprPtr cur;
955
956
663k
    cur = (xmlXPathCompExprPtr) xmlMalloc(sizeof(xmlXPathCompExpr));
957
663k
    if (cur == NULL)
958
50
  return(NULL);
959
663k
    memset(cur, 0, sizeof(xmlXPathCompExpr));
960
663k
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
961
663k
    cur->maxStep = 1;
962
#else
963
    cur->maxStep = 10;
964
#endif
965
663k
    cur->nbStep = 0;
966
663k
    cur->steps = (xmlXPathStepOp *) xmlMalloc(cur->maxStep *
967
663k
                                     sizeof(xmlXPathStepOp));
968
663k
    if (cur->steps == NULL) {
969
44
  xmlFree(cur);
970
44
  return(NULL);
971
44
    }
972
663k
    memset(cur->steps, 0, cur->maxStep * sizeof(xmlXPathStepOp));
973
663k
    cur->last = -1;
974
663k
    return(cur);
975
663k
}
976
977
/**
978
 * xmlXPathFreeCompExpr:
979
 * @comp:  an XPATH comp
980
 *
981
 * Free up the memory allocated by @comp
982
 */
983
void
984
xmlXPathFreeCompExpr(xmlXPathCompExprPtr comp)
985
663k
{
986
663k
    xmlXPathStepOpPtr op;
987
663k
    int i;
988
989
663k
    if (comp == NULL)
990
390
        return;
991
663k
    if (comp->dict == NULL) {
992
8.95M
  for (i = 0; i < comp->nbStep; i++) {
993
8.38M
      op = &comp->steps[i];
994
8.38M
      if (op->value4 != NULL) {
995
628k
    if (op->op == XPATH_OP_VALUE)
996
253k
        xmlXPathFreeObject(op->value4);
997
375k
    else
998
375k
        xmlFree(op->value4);
999
628k
      }
1000
8.38M
      if (op->value5 != NULL)
1001
1.10M
    xmlFree(op->value5);
1002
8.38M
  }
1003
566k
    } else {
1004
1.18M
  for (i = 0; i < comp->nbStep; i++) {
1005
1.08M
      op = &comp->steps[i];
1006
1.08M
      if (op->value4 != NULL) {
1007
89.2k
    if (op->op == XPATH_OP_VALUE)
1008
30.1k
        xmlXPathFreeObject(op->value4);
1009
89.2k
      }
1010
1.08M
  }
1011
96.8k
        xmlDictFree(comp->dict);
1012
96.8k
    }
1013
663k
    if (comp->steps != NULL) {
1014
663k
        xmlFree(comp->steps);
1015
663k
    }
1016
#ifdef XPATH_STREAMING
1017
    if (comp->stream != NULL) {
1018
        xmlFreePatternList(comp->stream);
1019
    }
1020
#endif
1021
663k
    if (comp->expr != NULL) {
1022
298k
        xmlFree(comp->expr);
1023
298k
    }
1024
1025
663k
    xmlFree(comp);
1026
663k
}
1027
1028
/**
1029
 * xmlXPathCompExprAdd:
1030
 * @comp:  the compiled expression
1031
 * @ch1: first child index
1032
 * @ch2: second child index
1033
 * @op:  an op
1034
 * @value:  the first int value
1035
 * @value2:  the second int value
1036
 * @value3:  the third int value
1037
 * @value4:  the first string value
1038
 * @value5:  the second string value
1039
 *
1040
 * Add a step to an XPath Compiled Expression
1041
 *
1042
 * Returns -1 in case of failure, the index otherwise
1043
 */
1044
static int
1045
xmlXPathCompExprAdd(xmlXPathParserContextPtr ctxt, int ch1, int ch2,
1046
   xmlXPathOp op, int value,
1047
9.47M
   int value2, int value3, void *value4, void *value5) {
1048
9.47M
    xmlXPathCompExprPtr comp = ctxt->comp;
1049
9.47M
    if (comp->nbStep >= comp->maxStep) {
1050
2.13M
  xmlXPathStepOp *real;
1051
2.13M
        int newSize;
1052
1053
2.13M
        newSize = xmlGrowCapacity(comp->maxStep, sizeof(real[0]),
1054
2.13M
                                  10, XPATH_MAX_STEPS);
1055
2.13M
        if (newSize < 0) {
1056
0
      xmlXPathPErrMemory(ctxt);
1057
0
      return(-1);
1058
0
        }
1059
2.13M
  real = xmlRealloc(comp->steps, newSize * sizeof(real[0]));
1060
2.13M
  if (real == NULL) {
1061
692
      xmlXPathPErrMemory(ctxt);
1062
692
      return(-1);
1063
692
  }
1064
2.13M
  comp->steps = real;
1065
2.13M
  comp->maxStep = newSize;
1066
2.13M
    }
1067
9.46M
    comp->last = comp->nbStep;
1068
9.46M
    comp->steps[comp->nbStep].ch1 = ch1;
1069
9.46M
    comp->steps[comp->nbStep].ch2 = ch2;
1070
9.46M
    comp->steps[comp->nbStep].op = op;
1071
9.46M
    comp->steps[comp->nbStep].value = value;
1072
9.46M
    comp->steps[comp->nbStep].value2 = value2;
1073
9.46M
    comp->steps[comp->nbStep].value3 = value3;
1074
9.46M
    if ((comp->dict != NULL) &&
1075
1.08M
        ((op == XPATH_OP_FUNCTION) || (op == XPATH_OP_VARIABLE) ||
1076
1.03M
   (op == XPATH_OP_COLLECT))) {
1077
351k
        if (value4 != NULL) {
1078
59.1k
      comp->steps[comp->nbStep].value4 = (xmlChar *)
1079
59.1k
          (void *)xmlDictLookup(comp->dict, value4, -1);
1080
59.1k
      xmlFree(value4);
1081
59.1k
  } else
1082
292k
      comp->steps[comp->nbStep].value4 = NULL;
1083
351k
        if (value5 != NULL) {
1084
125k
      comp->steps[comp->nbStep].value5 = (xmlChar *)
1085
125k
          (void *)xmlDictLookup(comp->dict, value5, -1);
1086
125k
      xmlFree(value5);
1087
125k
  } else
1088
225k
      comp->steps[comp->nbStep].value5 = NULL;
1089
9.11M
    } else {
1090
9.11M
  comp->steps[comp->nbStep].value4 = value4;
1091
9.11M
  comp->steps[comp->nbStep].value5 = value5;
1092
9.11M
    }
1093
9.46M
    comp->steps[comp->nbStep].cache = NULL;
1094
9.46M
    return(comp->nbStep++);
1095
9.47M
}
1096
1097
#define PUSH_FULL_EXPR(op, op1, op2, val, val2, val3, val4, val5) \
1098
2.22M
    xmlXPathCompExprAdd(ctxt, (op1), (op2),     \
1099
2.22M
                  (op), (val), (val2), (val3), (val4), (val5))
1100
#define PUSH_LONG_EXPR(op, val, val2, val3, val4, val5)     \
1101
906k
    xmlXPathCompExprAdd(ctxt, ctxt->comp->last, -1,   \
1102
906k
                  (op), (val), (val2), (val3), (val4), (val5))
1103
1104
2.83M
#define PUSH_LEAVE_EXPR(op, val, val2)          \
1105
2.83M
xmlXPathCompExprAdd(ctxt, -1, -1, (op), (val), (val2), 0 ,NULL ,NULL)
1106
1107
1.00M
#define PUSH_UNARY_EXPR(op, ch, val, val2)        \
1108
1.00M
xmlXPathCompExprAdd(ctxt, (ch), -1, (op), (val), (val2), 0 ,NULL ,NULL)
1109
1110
2.50M
#define PUSH_BINARY_EXPR(op, ch1, ch2, val, val2)     \
1111
2.50M
xmlXPathCompExprAdd(ctxt, (ch1), (ch2), (op),     \
1112
2.50M
      (val), (val2), 0 ,NULL ,NULL)
1113
1114
/************************************************************************
1115
 *                  *
1116
 *    XPath object cache structures       *
1117
 *                  *
1118
 ************************************************************************/
1119
1120
/* #define XP_DEFAULT_CACHE_ON */
1121
1122
typedef struct _xmlXPathContextCache xmlXPathContextCache;
1123
typedef xmlXPathContextCache *xmlXPathContextCachePtr;
1124
struct _xmlXPathContextCache {
1125
    xmlXPathObjectPtr nodesetObjs;  /* stringval points to next */
1126
    xmlXPathObjectPtr miscObjs;     /* stringval points to next */
1127
    int numNodeset;
1128
    int maxNodeset;
1129
    int numMisc;
1130
    int maxMisc;
1131
};
1132
1133
/************************************************************************
1134
 *                  *
1135
 *    Debugging related functions       *
1136
 *                  *
1137
 ************************************************************************/
1138
1139
#ifdef LIBXML_DEBUG_ENABLED
1140
static void
1141
0
xmlXPathDebugDumpNode(FILE *output, xmlNodePtr cur, int depth) {
1142
0
    int i;
1143
0
    char shift[100];
1144
1145
0
    for (i = 0;((i < depth) && (i < 25));i++)
1146
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1147
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1148
0
    if (cur == NULL) {
1149
0
  fprintf(output, "%s", shift);
1150
0
  fprintf(output, "Node is NULL !\n");
1151
0
  return;
1152
1153
0
    }
1154
1155
0
    if ((cur->type == XML_DOCUMENT_NODE) ||
1156
0
       (cur->type == XML_HTML_DOCUMENT_NODE)) {
1157
0
  fprintf(output, "%s", shift);
1158
0
  fprintf(output, " /\n");
1159
0
    } else if (cur->type == XML_ATTRIBUTE_NODE)
1160
0
  xmlDebugDumpAttr(output, (xmlAttrPtr)cur, depth);
1161
0
    else
1162
0
  xmlDebugDumpOneNode(output, cur, depth);
1163
0
}
1164
static void
1165
0
xmlXPathDebugDumpNodeList(FILE *output, xmlNodePtr cur, int depth) {
1166
0
    xmlNodePtr tmp;
1167
0
    int i;
1168
0
    char shift[100];
1169
1170
0
    for (i = 0;((i < depth) && (i < 25));i++)
1171
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1172
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1173
0
    if (cur == NULL) {
1174
0
  fprintf(output, "%s", shift);
1175
0
  fprintf(output, "Node is NULL !\n");
1176
0
  return;
1177
1178
0
    }
1179
1180
0
    while (cur != NULL) {
1181
0
  tmp = cur;
1182
0
  cur = cur->next;
1183
0
  xmlDebugDumpOneNode(output, tmp, depth);
1184
0
    }
1185
0
}
1186
1187
static void
1188
0
xmlXPathDebugDumpNodeSet(FILE *output, xmlNodeSetPtr cur, int depth) {
1189
0
    int i;
1190
0
    char shift[100];
1191
1192
0
    for (i = 0;((i < depth) && (i < 25));i++)
1193
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1194
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1195
1196
0
    if (cur == NULL) {
1197
0
  fprintf(output, "%s", shift);
1198
0
  fprintf(output, "NodeSet is NULL !\n");
1199
0
  return;
1200
1201
0
    }
1202
1203
0
    if (cur != NULL) {
1204
0
  fprintf(output, "Set contains %d nodes:\n", cur->nodeNr);
1205
0
  for (i = 0;i < cur->nodeNr;i++) {
1206
0
      fprintf(output, "%s", shift);
1207
0
      fprintf(output, "%d", i + 1);
1208
0
      xmlXPathDebugDumpNode(output, cur->nodeTab[i], depth + 1);
1209
0
  }
1210
0
    }
1211
0
}
1212
1213
static void
1214
0
xmlXPathDebugDumpValueTree(FILE *output, xmlNodeSetPtr cur, int depth) {
1215
0
    int i;
1216
0
    char shift[100];
1217
1218
0
    for (i = 0;((i < depth) && (i < 25));i++)
1219
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1220
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1221
1222
0
    if ((cur == NULL) || (cur->nodeNr == 0) || (cur->nodeTab[0] == NULL)) {
1223
0
  fprintf(output, "%s", shift);
1224
0
  fprintf(output, "Value Tree is NULL !\n");
1225
0
  return;
1226
1227
0
    }
1228
1229
0
    fprintf(output, "%s", shift);
1230
0
    fprintf(output, "%d", i + 1);
1231
0
    xmlXPathDebugDumpNodeList(output, cur->nodeTab[0]->children, depth + 1);
1232
0
}
1233
1234
/**
1235
 * xmlXPathDebugDumpObject:
1236
 * @output:  the FILE * to dump the output
1237
 * @cur:  the object to inspect
1238
 * @depth:  indentation level
1239
 *
1240
 * Dump the content of the object for debugging purposes
1241
 */
1242
void
1243
0
xmlXPathDebugDumpObject(FILE *output, xmlXPathObjectPtr cur, int depth) {
1244
0
    int i;
1245
0
    char shift[100];
1246
1247
0
    if (output == NULL) return;
1248
1249
0
    for (i = 0;((i < depth) && (i < 25));i++)
1250
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1251
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1252
1253
1254
0
    fprintf(output, "%s", shift);
1255
1256
0
    if (cur == NULL) {
1257
0
        fprintf(output, "Object is empty (NULL)\n");
1258
0
  return;
1259
0
    }
1260
0
    switch(cur->type) {
1261
0
        case XPATH_UNDEFINED:
1262
0
      fprintf(output, "Object is uninitialized\n");
1263
0
      break;
1264
0
        case XPATH_NODESET:
1265
0
      fprintf(output, "Object is a Node Set :\n");
1266
0
      xmlXPathDebugDumpNodeSet(output, cur->nodesetval, depth);
1267
0
      break;
1268
0
  case XPATH_XSLT_TREE:
1269
0
      fprintf(output, "Object is an XSLT value tree :\n");
1270
0
      xmlXPathDebugDumpValueTree(output, cur->nodesetval, depth);
1271
0
      break;
1272
0
        case XPATH_BOOLEAN:
1273
0
      fprintf(output, "Object is a Boolean : ");
1274
0
      if (cur->boolval) fprintf(output, "true\n");
1275
0
      else fprintf(output, "false\n");
1276
0
      break;
1277
0
        case XPATH_NUMBER:
1278
0
      switch (xmlXPathIsInf(cur->floatval)) {
1279
0
      case 1:
1280
0
    fprintf(output, "Object is a number : Infinity\n");
1281
0
    break;
1282
0
      case -1:
1283
0
    fprintf(output, "Object is a number : -Infinity\n");
1284
0
    break;
1285
0
      default:
1286
0
    if (xmlXPathIsNaN(cur->floatval)) {
1287
0
        fprintf(output, "Object is a number : NaN\n");
1288
0
    } else if (cur->floatval == 0) {
1289
                    /* Omit sign for negative zero. */
1290
0
        fprintf(output, "Object is a number : 0\n");
1291
0
    } else {
1292
0
        fprintf(output, "Object is a number : %0g\n", cur->floatval);
1293
0
    }
1294
0
      }
1295
0
      break;
1296
0
        case XPATH_STRING:
1297
0
      fprintf(output, "Object is a string : ");
1298
0
      xmlDebugDumpString(output, cur->stringval);
1299
0
      fprintf(output, "\n");
1300
0
      break;
1301
0
  case XPATH_USERS:
1302
0
      fprintf(output, "Object is user defined\n");
1303
0
      break;
1304
0
    }
1305
0
}
1306
1307
static void
1308
xmlXPathDebugDumpStepOp(FILE *output, xmlXPathCompExprPtr comp,
1309
0
                       xmlXPathStepOpPtr op, int depth) {
1310
0
    int i;
1311
0
    char shift[100];
1312
1313
0
    for (i = 0;((i < depth) && (i < 25));i++)
1314
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1315
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1316
1317
0
    fprintf(output, "%s", shift);
1318
0
    if (op == NULL) {
1319
0
  fprintf(output, "Step is NULL\n");
1320
0
  return;
1321
0
    }
1322
0
    switch (op->op) {
1323
0
        case XPATH_OP_END:
1324
0
      fprintf(output, "END"); break;
1325
0
        case XPATH_OP_AND:
1326
0
      fprintf(output, "AND"); break;
1327
0
        case XPATH_OP_OR:
1328
0
      fprintf(output, "OR"); break;
1329
0
        case XPATH_OP_EQUAL:
1330
0
       if (op->value)
1331
0
     fprintf(output, "EQUAL =");
1332
0
       else
1333
0
     fprintf(output, "EQUAL !=");
1334
0
       break;
1335
0
        case XPATH_OP_CMP:
1336
0
       if (op->value)
1337
0
     fprintf(output, "CMP <");
1338
0
       else
1339
0
     fprintf(output, "CMP >");
1340
0
       if (!op->value2)
1341
0
     fprintf(output, "=");
1342
0
       break;
1343
0
        case XPATH_OP_PLUS:
1344
0
       if (op->value == 0)
1345
0
     fprintf(output, "PLUS -");
1346
0
       else if (op->value == 1)
1347
0
     fprintf(output, "PLUS +");
1348
0
       else if (op->value == 2)
1349
0
     fprintf(output, "PLUS unary -");
1350
0
       else if (op->value == 3)
1351
0
     fprintf(output, "PLUS unary - -");
1352
0
       break;
1353
0
        case XPATH_OP_MULT:
1354
0
       if (op->value == 0)
1355
0
     fprintf(output, "MULT *");
1356
0
       else if (op->value == 1)
1357
0
     fprintf(output, "MULT div");
1358
0
       else
1359
0
     fprintf(output, "MULT mod");
1360
0
       break;
1361
0
        case XPATH_OP_UNION:
1362
0
       fprintf(output, "UNION"); break;
1363
0
        case XPATH_OP_ROOT:
1364
0
       fprintf(output, "ROOT"); break;
1365
0
        case XPATH_OP_NODE:
1366
0
       fprintf(output, "NODE"); break;
1367
0
        case XPATH_OP_SORT:
1368
0
       fprintf(output, "SORT"); break;
1369
0
        case XPATH_OP_COLLECT: {
1370
0
      xmlXPathAxisVal axis = (xmlXPathAxisVal)op->value;
1371
0
      xmlXPathTestVal test = (xmlXPathTestVal)op->value2;
1372
0
      xmlXPathTypeVal type = (xmlXPathTypeVal)op->value3;
1373
0
      const xmlChar *prefix = op->value4;
1374
0
      const xmlChar *name = op->value5;
1375
1376
0
      fprintf(output, "COLLECT ");
1377
0
      switch (axis) {
1378
0
    case AXIS_ANCESTOR:
1379
0
        fprintf(output, " 'ancestors' "); break;
1380
0
    case AXIS_ANCESTOR_OR_SELF:
1381
0
        fprintf(output, " 'ancestors-or-self' "); break;
1382
0
    case AXIS_ATTRIBUTE:
1383
0
        fprintf(output, " 'attributes' "); break;
1384
0
    case AXIS_CHILD:
1385
0
        fprintf(output, " 'child' "); break;
1386
0
    case AXIS_DESCENDANT:
1387
0
        fprintf(output, " 'descendant' "); break;
1388
0
    case AXIS_DESCENDANT_OR_SELF:
1389
0
        fprintf(output, " 'descendant-or-self' "); break;
1390
0
    case AXIS_FOLLOWING:
1391
0
        fprintf(output, " 'following' "); break;
1392
0
    case AXIS_FOLLOWING_SIBLING:
1393
0
        fprintf(output, " 'following-siblings' "); break;
1394
0
    case AXIS_NAMESPACE:
1395
0
        fprintf(output, " 'namespace' "); break;
1396
0
    case AXIS_PARENT:
1397
0
        fprintf(output, " 'parent' "); break;
1398
0
    case AXIS_PRECEDING:
1399
0
        fprintf(output, " 'preceding' "); break;
1400
0
    case AXIS_PRECEDING_SIBLING:
1401
0
        fprintf(output, " 'preceding-sibling' "); break;
1402
0
    case AXIS_SELF:
1403
0
        fprintf(output, " 'self' "); break;
1404
0
      }
1405
0
      switch (test) {
1406
0
                case NODE_TEST_NONE:
1407
0
        fprintf(output, "'none' "); break;
1408
0
                case NODE_TEST_TYPE:
1409
0
        fprintf(output, "'type' "); break;
1410
0
                case NODE_TEST_PI:
1411
0
        fprintf(output, "'PI' "); break;
1412
0
                case NODE_TEST_ALL:
1413
0
        fprintf(output, "'all' "); break;
1414
0
                case NODE_TEST_NS:
1415
0
        fprintf(output, "'namespace' "); break;
1416
0
                case NODE_TEST_NAME:
1417
0
        fprintf(output, "'name' "); break;
1418
0
      }
1419
0
      switch (type) {
1420
0
                case NODE_TYPE_NODE:
1421
0
        fprintf(output, "'node' "); break;
1422
0
                case NODE_TYPE_COMMENT:
1423
0
        fprintf(output, "'comment' "); break;
1424
0
                case NODE_TYPE_TEXT:
1425
0
        fprintf(output, "'text' "); break;
1426
0
                case NODE_TYPE_PI:
1427
0
        fprintf(output, "'PI' "); break;
1428
0
      }
1429
0
      if (prefix != NULL)
1430
0
    fprintf(output, "%s:", prefix);
1431
0
      if (name != NULL)
1432
0
    fprintf(output, "%s", (const char *) name);
1433
0
      break;
1434
1435
0
        }
1436
0
  case XPATH_OP_VALUE: {
1437
0
      xmlXPathObjectPtr object = (xmlXPathObjectPtr) op->value4;
1438
1439
0
      fprintf(output, "ELEM ");
1440
0
      xmlXPathDebugDumpObject(output, object, 0);
1441
0
      goto finish;
1442
0
  }
1443
0
  case XPATH_OP_VARIABLE: {
1444
0
      const xmlChar *prefix = op->value5;
1445
0
      const xmlChar *name = op->value4;
1446
1447
0
      if (prefix != NULL)
1448
0
    fprintf(output, "VARIABLE %s:%s", prefix, name);
1449
0
      else
1450
0
    fprintf(output, "VARIABLE %s", name);
1451
0
      break;
1452
0
  }
1453
0
  case XPATH_OP_FUNCTION: {
1454
0
      int nbargs = op->value;
1455
0
      const xmlChar *prefix = op->value5;
1456
0
      const xmlChar *name = op->value4;
1457
1458
0
      if (prefix != NULL)
1459
0
    fprintf(output, "FUNCTION %s:%s(%d args)",
1460
0
      prefix, name, nbargs);
1461
0
      else
1462
0
    fprintf(output, "FUNCTION %s(%d args)", name, nbargs);
1463
0
      break;
1464
0
  }
1465
0
        case XPATH_OP_ARG: fprintf(output, "ARG"); break;
1466
0
        case XPATH_OP_PREDICATE: fprintf(output, "PREDICATE"); break;
1467
0
        case XPATH_OP_FILTER: fprintf(output, "FILTER"); break;
1468
0
  default:
1469
0
        fprintf(output, "UNKNOWN %d\n", op->op); return;
1470
0
    }
1471
0
    fprintf(output, "\n");
1472
0
finish:
1473
    /* OP_VALUE has invalid ch1. */
1474
0
    if (op->op == XPATH_OP_VALUE)
1475
0
        return;
1476
1477
0
    if (op->ch1 >= 0)
1478
0
  xmlXPathDebugDumpStepOp(output, comp, &comp->steps[op->ch1], depth + 1);
1479
0
    if (op->ch2 >= 0)
1480
0
  xmlXPathDebugDumpStepOp(output, comp, &comp->steps[op->ch2], depth + 1);
1481
0
}
1482
1483
/**
1484
 * xmlXPathDebugDumpCompExpr:
1485
 * @output:  the FILE * for the output
1486
 * @comp:  the precompiled XPath expression
1487
 * @depth:  the indentation level.
1488
 *
1489
 * Dumps the tree of the compiled XPath expression.
1490
 */
1491
void
1492
xmlXPathDebugDumpCompExpr(FILE *output, xmlXPathCompExprPtr comp,
1493
0
                    int depth) {
1494
0
    int i;
1495
0
    char shift[100];
1496
1497
0
    if ((output == NULL) || (comp == NULL)) return;
1498
1499
0
    for (i = 0;((i < depth) && (i < 25));i++)
1500
0
        shift[2 * i] = shift[2 * i + 1] = ' ';
1501
0
    shift[2 * i] = shift[2 * i + 1] = 0;
1502
1503
0
    fprintf(output, "%s", shift);
1504
1505
#ifdef XPATH_STREAMING
1506
    if (comp->stream) {
1507
        fprintf(output, "Streaming Expression\n");
1508
    } else
1509
#endif
1510
0
    {
1511
0
        fprintf(output, "Compiled Expression : %d elements\n",
1512
0
                comp->nbStep);
1513
0
        i = comp->last;
1514
0
        xmlXPathDebugDumpStepOp(output, comp, &comp->steps[i], depth + 1);
1515
0
    }
1516
0
}
1517
1518
#endif /* LIBXML_DEBUG_ENABLED */
1519
1520
/************************************************************************
1521
 *                  *
1522
 *      XPath object caching        *
1523
 *                  *
1524
 ************************************************************************/
1525
1526
/**
1527
 * xmlXPathNewCache:
1528
 *
1529
 * Create a new object cache
1530
 *
1531
 * Returns the xmlXPathCache just allocated.
1532
 */
1533
static xmlXPathContextCachePtr
1534
xmlXPathNewCache(void)
1535
39.7k
{
1536
39.7k
    xmlXPathContextCachePtr ret;
1537
1538
39.7k
    ret = (xmlXPathContextCachePtr) xmlMalloc(sizeof(xmlXPathContextCache));
1539
39.7k
    if (ret == NULL)
1540
2
  return(NULL);
1541
39.7k
    memset(ret, 0 , sizeof(xmlXPathContextCache));
1542
39.7k
    ret->maxNodeset = 100;
1543
39.7k
    ret->maxMisc = 100;
1544
39.7k
    return(ret);
1545
39.7k
}
1546
1547
static void
1548
xmlXPathCacheFreeObjectList(xmlXPathObjectPtr list)
1549
17.0k
{
1550
399k
    while (list != NULL) {
1551
382k
        xmlXPathObjectPtr next;
1552
1553
382k
        next = (void *) list->stringval;
1554
1555
382k
  if (list->nodesetval != NULL) {
1556
334k
      if (list->nodesetval->nodeTab != NULL)
1557
288k
    xmlFree(list->nodesetval->nodeTab);
1558
334k
      xmlFree(list->nodesetval);
1559
334k
  }
1560
382k
  xmlFree(list);
1561
1562
382k
        list = next;
1563
382k
    }
1564
17.0k
}
1565
1566
static void
1567
xmlXPathFreeCache(xmlXPathContextCachePtr cache)
1568
39.7k
{
1569
39.7k
    if (cache == NULL)
1570
0
  return;
1571
39.7k
    if (cache->nodesetObjs)
1572
11.4k
  xmlXPathCacheFreeObjectList(cache->nodesetObjs);
1573
39.7k
    if (cache->miscObjs)
1574
5.56k
  xmlXPathCacheFreeObjectList(cache->miscObjs);
1575
39.7k
    xmlFree(cache);
1576
39.7k
}
1577
1578
/**
1579
 * xmlXPathContextSetCache:
1580
 *
1581
 * @ctxt:  the XPath context
1582
 * @active: enables/disables (creates/frees) the cache
1583
 * @value: a value with semantics dependent on @options
1584
 * @options: options (currently only the value 0 is used)
1585
 *
1586
 * Creates/frees an object cache on the XPath context.
1587
 * If activates XPath objects (xmlXPathObject) will be cached internally
1588
 * to be reused.
1589
 * @options:
1590
 *   0: This will set the XPath object caching:
1591
 *      @value:
1592
 *        This will set the maximum number of XPath objects
1593
 *        to be cached per slot
1594
 *        There are two slots for node-set and misc objects.
1595
 *        Use <0 for the default number (100).
1596
 *   Other values for @options have currently no effect.
1597
 *
1598
 * Returns 0 if the setting succeeded, and -1 on API or internal errors.
1599
 */
1600
int
1601
xmlXPathContextSetCache(xmlXPathContextPtr ctxt,
1602
      int active,
1603
      int value,
1604
      int options)
1605
39.7k
{
1606
39.7k
    if (ctxt == NULL)
1607
0
  return(-1);
1608
39.7k
    if (active) {
1609
39.7k
  xmlXPathContextCachePtr cache;
1610
1611
39.7k
  if (ctxt->cache == NULL) {
1612
39.7k
      ctxt->cache = xmlXPathNewCache();
1613
39.7k
      if (ctxt->cache == NULL) {
1614
2
                xmlXPathErrMemory(ctxt);
1615
2
    return(-1);
1616
2
            }
1617
39.7k
  }
1618
39.7k
  cache = (xmlXPathContextCachePtr) ctxt->cache;
1619
39.7k
  if (options == 0) {
1620
39.7k
      if (value < 0)
1621
39.7k
    value = 100;
1622
39.7k
      cache->maxNodeset = value;
1623
39.7k
      cache->maxMisc = value;
1624
39.7k
  }
1625
39.7k
    } else if (ctxt->cache != NULL) {
1626
0
  xmlXPathFreeCache((xmlXPathContextCachePtr) ctxt->cache);
1627
0
  ctxt->cache = NULL;
1628
0
    }
1629
39.7k
    return(0);
1630
39.7k
}
1631
1632
/**
1633
 * xmlXPathCacheWrapNodeSet:
1634
 * @pctxt: the XPath context
1635
 * @val:  the NodePtr value
1636
 *
1637
 * This is the cached version of xmlXPathWrapNodeSet().
1638
 * Wrap the Nodeset @val in a new xmlXPathObjectPtr
1639
 *
1640
 * Returns the created or reused object.
1641
 *
1642
 * In case of error the node set is destroyed and NULL is returned.
1643
 */
1644
static xmlXPathObjectPtr
1645
xmlXPathCacheWrapNodeSet(xmlXPathParserContextPtr pctxt, xmlNodeSetPtr val)
1646
4.68M
{
1647
4.68M
    xmlXPathObjectPtr ret;
1648
4.68M
    xmlXPathContextPtr ctxt = pctxt->context;
1649
1650
4.68M
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1651
4.66M
  xmlXPathContextCachePtr cache =
1652
4.66M
      (xmlXPathContextCachePtr) ctxt->cache;
1653
1654
4.66M
  if (cache->miscObjs != NULL) {
1655
2.99M
      ret = cache->miscObjs;
1656
2.99M
            cache->miscObjs = (void *) ret->stringval;
1657
2.99M
            cache->numMisc -= 1;
1658
2.99M
            ret->stringval = NULL;
1659
2.99M
      ret->type = XPATH_NODESET;
1660
2.99M
      ret->nodesetval = val;
1661
2.99M
      return(ret);
1662
2.99M
  }
1663
4.66M
    }
1664
1665
1.69M
    ret = xmlXPathWrapNodeSet(val);
1666
1.69M
    if (ret == NULL)
1667
2.78k
        xmlXPathPErrMemory(pctxt);
1668
1.69M
    return(ret);
1669
4.68M
}
1670
1671
/**
1672
 * xmlXPathCacheWrapString:
1673
 * @pctxt the XPath context
1674
 * @val:  the xmlChar * value
1675
 *
1676
 * This is the cached version of xmlXPathWrapString().
1677
 * Wraps the @val string into an XPath object.
1678
 *
1679
 * Returns the created or reused object.
1680
 */
1681
static xmlXPathObjectPtr
1682
xmlXPathCacheWrapString(xmlXPathParserContextPtr pctxt, xmlChar *val)
1683
445k
{
1684
445k
    xmlXPathObjectPtr ret;
1685
445k
    xmlXPathContextPtr ctxt = pctxt->context;
1686
1687
445k
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1688
445k
  xmlXPathContextCachePtr cache = (xmlXPathContextCachePtr) ctxt->cache;
1689
1690
445k
  if (cache->miscObjs != NULL) {
1691
400k
      ret = cache->miscObjs;
1692
400k
            cache->miscObjs = (void *) ret->stringval;
1693
400k
            cache->numMisc -= 1;
1694
400k
      ret->type = XPATH_STRING;
1695
400k
      ret->stringval = val;
1696
400k
      return(ret);
1697
400k
  }
1698
445k
    }
1699
1700
45.2k
    ret = xmlXPathWrapString(val);
1701
45.2k
    if (ret == NULL)
1702
1.06k
        xmlXPathPErrMemory(pctxt);
1703
45.2k
    return(ret);
1704
445k
}
1705
1706
/**
1707
 * xmlXPathCacheNewNodeSet:
1708
 * @pctxt the XPath context
1709
 * @val:  the NodePtr value
1710
 *
1711
 * This is the cached version of xmlXPathNewNodeSet().
1712
 * Acquire an xmlXPathObjectPtr of type NodeSet and initialize
1713
 * it with the single Node @val
1714
 *
1715
 * Returns the created or reused object.
1716
 */
1717
static xmlXPathObjectPtr
1718
xmlXPathCacheNewNodeSet(xmlXPathParserContextPtr pctxt, xmlNodePtr val)
1719
6.24M
{
1720
6.24M
    xmlXPathObjectPtr ret;
1721
6.24M
    xmlXPathContextPtr ctxt = pctxt->context;
1722
1723
6.24M
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1724
6.23M
  xmlXPathContextCachePtr cache = (xmlXPathContextCachePtr) ctxt->cache;
1725
1726
6.23M
  if (cache->nodesetObjs != NULL) {
1727
      /*
1728
      * Use the nodeset-cache.
1729
      */
1730
6.03M
      ret = cache->nodesetObjs;
1731
6.03M
            cache->nodesetObjs = (void *) ret->stringval;
1732
6.03M
            cache->numNodeset -= 1;
1733
6.03M
            ret->stringval = NULL;
1734
6.03M
      ret->type = XPATH_NODESET;
1735
6.03M
      ret->boolval = 0;
1736
6.03M
      if (val) {
1737
6.03M
    if ((ret->nodesetval->nodeMax == 0) ||
1738
5.66M
        (val->type == XML_NAMESPACE_DECL))
1739
539k
    {
1740
539k
        if (xmlXPathNodeSetAddUnique(ret->nodesetval, val) < 0)
1741
1.15k
                        xmlXPathPErrMemory(pctxt);
1742
5.50M
    } else {
1743
5.50M
        ret->nodesetval->nodeTab[0] = val;
1744
5.50M
        ret->nodesetval->nodeNr = 1;
1745
5.50M
    }
1746
6.03M
      }
1747
6.03M
      return(ret);
1748
6.03M
  } else if (cache->miscObjs != NULL) {
1749
21.4k
            xmlNodeSetPtr set;
1750
      /*
1751
      * Fallback to misc-cache.
1752
      */
1753
1754
21.4k
      set = xmlXPathNodeSetCreate(val);
1755
21.4k
      if (set == NULL) {
1756
480
                xmlXPathPErrMemory(pctxt);
1757
480
    return(NULL);
1758
480
      }
1759
1760
20.9k
      ret = cache->miscObjs;
1761
20.9k
            cache->miscObjs = (void *) ret->stringval;
1762
20.9k
            cache->numMisc -= 1;
1763
20.9k
            ret->stringval = NULL;
1764
20.9k
      ret->type = XPATH_NODESET;
1765
20.9k
      ret->boolval = 0;
1766
20.9k
      ret->nodesetval = set;
1767
20.9k
      return(ret);
1768
21.4k
  }
1769
6.23M
    }
1770
180k
    ret = xmlXPathNewNodeSet(val);
1771
180k
    if (ret == NULL)
1772
341
        xmlXPathPErrMemory(pctxt);
1773
180k
    return(ret);
1774
6.24M
}
1775
1776
/**
1777
 * xmlXPathCacheNewString:
1778
 * @pctxt the XPath context
1779
 * @val:  the xmlChar * value
1780
 *
1781
 * This is the cached version of xmlXPathNewString().
1782
 * Acquire an xmlXPathObjectPtr of type string and of value @val
1783
 *
1784
 * Returns the created or reused object.
1785
 */
1786
static xmlXPathObjectPtr
1787
xmlXPathCacheNewString(xmlXPathParserContextPtr pctxt, const xmlChar *val)
1788
433k
{
1789
433k
    xmlXPathObjectPtr ret;
1790
433k
    xmlXPathContextPtr ctxt = pctxt->context;
1791
1792
433k
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1793
433k
  xmlXPathContextCachePtr cache = (xmlXPathContextCachePtr) ctxt->cache;
1794
1795
433k
  if (cache->miscObjs != NULL) {
1796
346k
            xmlChar *copy;
1797
1798
346k
            if (val == NULL)
1799
1.07k
                val = BAD_CAST "";
1800
346k
            copy = xmlStrdup(val);
1801
346k
            if (copy == NULL) {
1802
429
                xmlXPathPErrMemory(pctxt);
1803
429
                return(NULL);
1804
429
            }
1805
1806
346k
      ret = cache->miscObjs;
1807
346k
            cache->miscObjs = (void *) ret->stringval;
1808
346k
            cache->numMisc -= 1;
1809
346k
      ret->type = XPATH_STRING;
1810
346k
            ret->stringval = copy;
1811
346k
      return(ret);
1812
346k
  }
1813
433k
    }
1814
1815
86.9k
    ret = xmlXPathNewString(val);
1816
86.9k
    if (ret == NULL)
1817
216
        xmlXPathPErrMemory(pctxt);
1818
86.9k
    return(ret);
1819
433k
}
1820
1821
/**
1822
 * xmlXPathCacheNewCString:
1823
 * @pctxt the XPath context
1824
 * @val:  the char * value
1825
 *
1826
 * This is the cached version of xmlXPathNewCString().
1827
 * Acquire an xmlXPathObjectPtr of type string and of value @val
1828
 *
1829
 * Returns the created or reused object.
1830
 */
1831
static xmlXPathObjectPtr
1832
xmlXPathCacheNewCString(xmlXPathParserContextPtr pctxt, const char *val)
1833
36.6k
{
1834
36.6k
    return xmlXPathCacheNewString(pctxt, BAD_CAST val);
1835
36.6k
}
1836
1837
/**
1838
 * xmlXPathCacheNewBoolean:
1839
 * @pctxt the XPath context
1840
 * @val:  the boolean value
1841
 *
1842
 * This is the cached version of xmlXPathNewBoolean().
1843
 * Acquires an xmlXPathObjectPtr of type boolean and of value @val
1844
 *
1845
 * Returns the created or reused object.
1846
 */
1847
static xmlXPathObjectPtr
1848
xmlXPathCacheNewBoolean(xmlXPathParserContextPtr pctxt, int val)
1849
1.02M
{
1850
1.02M
    xmlXPathObjectPtr ret;
1851
1.02M
    xmlXPathContextPtr ctxt = pctxt->context;
1852
1853
1.02M
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1854
1.02M
  xmlXPathContextCachePtr cache = (xmlXPathContextCachePtr) ctxt->cache;
1855
1856
1.02M
  if (cache->miscObjs != NULL) {
1857
908k
      ret = cache->miscObjs;
1858
908k
            cache->miscObjs = (void *) ret->stringval;
1859
908k
            cache->numMisc -= 1;
1860
908k
            ret->stringval = NULL;
1861
908k
      ret->type = XPATH_BOOLEAN;
1862
908k
      ret->boolval = (val != 0);
1863
908k
      return(ret);
1864
908k
  }
1865
1.02M
    }
1866
1867
117k
    ret = xmlXPathNewBoolean(val);
1868
117k
    if (ret == NULL)
1869
1.13k
        xmlXPathPErrMemory(pctxt);
1870
117k
    return(ret);
1871
1.02M
}
1872
1873
/**
1874
 * xmlXPathCacheNewFloat:
1875
 * @pctxt the XPath context
1876
 * @val:  the double value
1877
 *
1878
 * This is the cached version of xmlXPathNewFloat().
1879
 * Acquires an xmlXPathObjectPtr of type double and of value @val
1880
 *
1881
 * Returns the created or reused object.
1882
 */
1883
static xmlXPathObjectPtr
1884
xmlXPathCacheNewFloat(xmlXPathParserContextPtr pctxt, double val)
1885
1.65M
{
1886
1.65M
    xmlXPathObjectPtr ret;
1887
1.65M
    xmlXPathContextPtr ctxt = pctxt->context;
1888
1889
1.65M
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1890
1.65M
  xmlXPathContextCachePtr cache = (xmlXPathContextCachePtr) ctxt->cache;
1891
1892
1.65M
  if (cache->miscObjs != NULL) {
1893
1.22M
      ret = cache->miscObjs;
1894
1.22M
            cache->miscObjs = (void *) ret->stringval;
1895
1.22M
            cache->numMisc -= 1;
1896
1.22M
            ret->stringval = NULL;
1897
1.22M
      ret->type = XPATH_NUMBER;
1898
1.22M
      ret->floatval = val;
1899
1.22M
      return(ret);
1900
1.22M
  }
1901
1.65M
    }
1902
1903
428k
    ret = xmlXPathNewFloat(val);
1904
428k
    if (ret == NULL)
1905
1.95k
        xmlXPathPErrMemory(pctxt);
1906
428k
    return(ret);
1907
1.65M
}
1908
1909
/**
1910
 * xmlXPathCacheObjectCopy:
1911
 * @pctxt the XPath context
1912
 * @val:  the original object
1913
 *
1914
 * This is the cached version of xmlXPathObjectCopy().
1915
 * Acquire a copy of a given object
1916
 *
1917
 * Returns a created or reused created object.
1918
 */
1919
static xmlXPathObjectPtr
1920
xmlXPathCacheObjectCopy(xmlXPathParserContextPtr pctxt, xmlXPathObjectPtr val)
1921
792k
{
1922
792k
    xmlXPathObjectPtr ret;
1923
792k
    xmlXPathContextPtr ctxt = pctxt->context;
1924
1925
792k
    if (val == NULL)
1926
0
  return(NULL);
1927
1928
792k
    if ((ctxt != NULL) && (ctxt->cache != NULL)) {
1929
791k
  switch (val->type) {
1930
0
            case XPATH_NODESET: {
1931
0
                xmlNodeSetPtr set;
1932
1933
0
                set = xmlXPathNodeSetMerge(NULL, val->nodesetval);
1934
0
                if (set == NULL) {
1935
0
                    xmlXPathPErrMemory(pctxt);
1936
0
                    return(NULL);
1937
0
                }
1938
0
                return(xmlXPathCacheWrapNodeSet(pctxt, set));
1939
0
            }
1940
169k
      case XPATH_STRING:
1941
169k
    return(xmlXPathCacheNewString(pctxt, val->stringval));
1942
0
      case XPATH_BOOLEAN:
1943
0
    return(xmlXPathCacheNewBoolean(pctxt, val->boolval));
1944
621k
      case XPATH_NUMBER:
1945
621k
    return(xmlXPathCacheNewFloat(pctxt, val->floatval));
1946
0
      default:
1947
0
    break;
1948
791k
  }
1949
791k
    }
1950
932
    ret = xmlXPathObjectCopy(val);
1951
932
    if (ret == NULL)
1952
1
        xmlXPathPErrMemory(pctxt);
1953
932
    return(ret);
1954
792k
}
1955
1956
/************************************************************************
1957
 *                  *
1958
 *    Parser stacks related functions and macros    *
1959
 *                  *
1960
 ************************************************************************/
1961
1962
/**
1963
 * xmlXPathCastToNumberInternal:
1964
 * @ctxt:  parser context
1965
 * @val:  an XPath object
1966
 *
1967
 * Converts an XPath object to its number value
1968
 *
1969
 * Returns the number value
1970
 */
1971
static double
1972
xmlXPathCastToNumberInternal(xmlXPathParserContextPtr ctxt,
1973
1.30M
                             xmlXPathObjectPtr val) {
1974
1.30M
    double ret = 0.0;
1975
1976
1.30M
    if (val == NULL)
1977
0
  return(xmlXPathNAN);
1978
1.30M
    switch (val->type) {
1979
0
    case XPATH_UNDEFINED:
1980
0
  ret = xmlXPathNAN;
1981
0
  break;
1982
811k
    case XPATH_NODESET:
1983
811k
    case XPATH_XSLT_TREE: {
1984
811k
        xmlChar *str;
1985
1986
811k
  str = xmlXPathCastNodeSetToString(val->nodesetval);
1987
811k
        if (str == NULL) {
1988
2.42k
            xmlXPathPErrMemory(ctxt);
1989
2.42k
            ret = xmlXPathNAN;
1990
808k
        } else {
1991
808k
      ret = xmlXPathCastStringToNumber(str);
1992
808k
            xmlFree(str);
1993
808k
        }
1994
811k
  break;
1995
811k
    }
1996
203k
    case XPATH_STRING:
1997
203k
  ret = xmlXPathCastStringToNumber(val->stringval);
1998
203k
  break;
1999
161k
    case XPATH_NUMBER:
2000
161k
  ret = val->floatval;
2001
161k
  break;
2002
127k
    case XPATH_BOOLEAN:
2003
127k
  ret = xmlXPathCastBooleanToNumber(val->boolval);
2004
127k
  break;
2005
141
    case XPATH_USERS:
2006
  /* TODO */
2007
141
  ret = xmlXPathNAN;
2008
141
  break;
2009
1.30M
    }
2010
1.30M
    return(ret);
2011
1.30M
}
2012
2013
/**
2014
 * xmlXPathValuePop:
2015
 * @ctxt: an XPath evaluation context
2016
 *
2017
 * Pops the top XPath object from the value stack
2018
 *
2019
 * Returns the XPath object just removed
2020
 */
2021
xmlXPathObjectPtr
2022
xmlXPathValuePop(xmlXPathParserContextPtr ctxt)
2023
18.4M
{
2024
18.4M
    xmlXPathObjectPtr ret;
2025
2026
18.4M
    if ((ctxt == NULL) || (ctxt->valueNr <= 0))
2027
28.2k
        return (NULL);
2028
2029
18.4M
    ctxt->valueNr--;
2030
18.4M
    if (ctxt->valueNr > 0)
2031
10.2M
        ctxt->value = ctxt->valueTab[ctxt->valueNr - 1];
2032
8.17M
    else
2033
8.17M
        ctxt->value = NULL;
2034
18.4M
    ret = ctxt->valueTab[ctxt->valueNr];
2035
18.4M
    ctxt->valueTab[ctxt->valueNr] = NULL;
2036
18.4M
    return (ret);
2037
18.4M
}
2038
2039
/**
2040
 * xmlXPathValuePush:
2041
 * @ctxt:  an XPath evaluation context
2042
 * @value:  the XPath object
2043
 *
2044
 * Pushes a new XPath object on top of the value stack. If value is NULL,
2045
 * a memory error is recorded in the parser context.
2046
 *
2047
 * Returns the number of items on the value stack, or -1 in case of error.
2048
 *
2049
 * The object is destroyed in case of error.
2050
 */
2051
int
2052
xmlXPathValuePush(xmlXPathParserContextPtr ctxt, xmlXPathObjectPtr value)
2053
18.9M
{
2054
18.9M
    if (ctxt == NULL) return(-1);
2055
18.9M
    if (value == NULL) {
2056
        /*
2057
         * A NULL value typically indicates that a memory allocation failed.
2058
         */
2059
38.3k
        xmlXPathPErrMemory(ctxt);
2060
38.3k
        return(-1);
2061
38.3k
    }
2062
18.9M
    if (ctxt->valueNr >= ctxt->valueMax) {
2063
1.71M
        xmlXPathObjectPtr *tmp;
2064
1.71M
        int newSize;
2065
2066
1.71M
        newSize = xmlGrowCapacity(ctxt->valueMax, sizeof(tmp[0]),
2067
1.71M
                                  10, XPATH_MAX_STACK_DEPTH);
2068
1.71M
        if (newSize < 0) {
2069
0
            xmlXPathPErrMemory(ctxt);
2070
0
            xmlXPathFreeObject(value);
2071
0
            return (-1);
2072
0
        }
2073
1.71M
        tmp = xmlRealloc(ctxt->valueTab, newSize * sizeof(tmp[0]));
2074
1.71M
        if (tmp == NULL) {
2075
600
            xmlXPathPErrMemory(ctxt);
2076
600
            xmlXPathFreeObject(value);
2077
600
            return (-1);
2078
600
        }
2079
1.71M
  ctxt->valueTab = tmp;
2080
1.71M
        ctxt->valueMax = newSize;
2081
1.71M
    }
2082
18.9M
    ctxt->valueTab[ctxt->valueNr] = value;
2083
18.9M
    ctxt->value = value;
2084
18.9M
    return (ctxt->valueNr++);
2085
18.9M
}
2086
2087
/**
2088
 * xmlXPathPopBoolean:
2089
 * @ctxt:  an XPath parser context
2090
 *
2091
 * Pops a boolean from the stack, handling conversion if needed.
2092
 * Check error with #xmlXPathCheckError.
2093
 *
2094
 * Returns the boolean
2095
 */
2096
int
2097
1.83k
xmlXPathPopBoolean (xmlXPathParserContextPtr ctxt) {
2098
1.83k
    xmlXPathObjectPtr obj;
2099
1.83k
    int ret;
2100
2101
1.83k
    obj = xmlXPathValuePop(ctxt);
2102
1.83k
    if (obj == NULL) {
2103
0
  xmlXPathSetError(ctxt, XPATH_INVALID_OPERAND);
2104
0
  return(0);
2105
0
    }
2106
1.83k
    if (obj->type != XPATH_BOOLEAN)
2107
1.56k
  ret = xmlXPathCastToBoolean(obj);
2108
264
    else
2109
264
        ret = obj->boolval;
2110
1.83k
    xmlXPathReleaseObject(ctxt->context, obj);
2111
1.83k
    return(ret);
2112
1.83k
}
2113
2114
/**
2115
 * xmlXPathPopNumber:
2116
 * @ctxt:  an XPath parser context
2117
 *
2118
 * Pops a number from the stack, handling conversion if needed.
2119
 * Check error with #xmlXPathCheckError.
2120
 *
2121
 * Returns the number
2122
 */
2123
double
2124
16.4k
xmlXPathPopNumber (xmlXPathParserContextPtr ctxt) {
2125
16.4k
    xmlXPathObjectPtr obj;
2126
16.4k
    double ret;
2127
2128
16.4k
    obj = xmlXPathValuePop(ctxt);
2129
16.4k
    if (obj == NULL) {
2130
0
  xmlXPathSetError(ctxt, XPATH_INVALID_OPERAND);
2131
0
  return(0);
2132
0
    }
2133
16.4k
    if (obj->type != XPATH_NUMBER)
2134
16.0k
  ret = xmlXPathCastToNumberInternal(ctxt, obj);
2135
396
    else
2136
396
        ret = obj->floatval;
2137
16.4k
    xmlXPathReleaseObject(ctxt->context, obj);
2138
16.4k
    return(ret);
2139
16.4k
}
2140
2141
/**
2142
 * xmlXPathPopString:
2143
 * @ctxt:  an XPath parser context
2144
 *
2145
 * Pops a string from the stack, handling conversion if needed.
2146
 * Check error with #xmlXPathCheckError.
2147
 *
2148
 * Returns the string
2149
 */
2150
xmlChar *
2151
776k
xmlXPathPopString (xmlXPathParserContextPtr ctxt) {
2152
776k
    xmlXPathObjectPtr obj;
2153
776k
    xmlChar * ret;
2154
2155
776k
    obj = xmlXPathValuePop(ctxt);
2156
776k
    if (obj == NULL) {
2157
0
  xmlXPathSetError(ctxt, XPATH_INVALID_OPERAND);
2158
0
  return(NULL);
2159
0
    }
2160
776k
    ret = xmlXPathCastToString(obj);
2161
776k
    if (ret == NULL)
2162
302
        xmlXPathPErrMemory(ctxt);
2163
776k
    xmlXPathReleaseObject(ctxt->context, obj);
2164
776k
    return(ret);
2165
776k
}
2166
2167
/**
2168
 * xmlXPathPopNodeSet:
2169
 * @ctxt:  an XPath parser context
2170
 *
2171
 * Pops a node-set from the stack, handling conversion if needed.
2172
 * Check error with #xmlXPathCheckError.
2173
 *
2174
 * Returns the node-set
2175
 */
2176
xmlNodeSetPtr
2177
664k
xmlXPathPopNodeSet (xmlXPathParserContextPtr ctxt) {
2178
664k
    xmlXPathObjectPtr obj;
2179
664k
    xmlNodeSetPtr ret;
2180
2181
664k
    if (ctxt == NULL) return(NULL);
2182
664k
    if (ctxt->value == NULL) {
2183
0
  xmlXPathSetError(ctxt, XPATH_INVALID_OPERAND);
2184
0
  return(NULL);
2185
0
    }
2186
664k
    if (!xmlXPathStackIsNodeSet(ctxt)) {
2187
4.17k
  xmlXPathSetTypeError(ctxt);
2188
4.17k
  return(NULL);
2189
4.17k
    }
2190
660k
    obj = xmlXPathValuePop(ctxt);
2191
660k
    ret = obj->nodesetval;
2192
660k
    obj->nodesetval = NULL;
2193
660k
    xmlXPathReleaseObject(ctxt->context, obj);
2194
660k
    return(ret);
2195
664k
}
2196
2197
/**
2198
 * xmlXPathPopExternal:
2199
 * @ctxt:  an XPath parser context
2200
 *
2201
 * Pops an external object from the stack, handling conversion if needed.
2202
 * Check error with #xmlXPathCheckError.
2203
 *
2204
 * Returns the object
2205
 */
2206
void *
2207
1.69k
xmlXPathPopExternal (xmlXPathParserContextPtr ctxt) {
2208
1.69k
    xmlXPathObjectPtr obj;
2209
1.69k
    void * ret;
2210
2211
1.69k
    if ((ctxt == NULL) || (ctxt->value == NULL)) {
2212
0
  xmlXPathSetError(ctxt, XPATH_INVALID_OPERAND);
2213
0
  return(NULL);
2214
0
    }
2215
1.69k
    if (ctxt->value->type != XPATH_USERS) {
2216
0
  xmlXPathSetTypeError(ctxt);
2217
0
  return(NULL);
2218
0
    }
2219
1.69k
    obj = xmlXPathValuePop(ctxt);
2220
1.69k
    ret = obj->user;
2221
1.69k
    obj->user = NULL;
2222
1.69k
    xmlXPathReleaseObject(ctxt->context, obj);
2223
1.69k
    return(ret);
2224
1.69k
}
2225
2226
/*
2227
 * Macros for accessing the content. Those should be used only by the parser,
2228
 * and not exported.
2229
 *
2230
 * Dirty macros, i.e. one need to make assumption on the context to use them
2231
 *
2232
 *   CUR_PTR return the current pointer to the xmlChar to be parsed.
2233
 *   CUR     returns the current xmlChar value, i.e. a 8 bit value
2234
 *           in ISO-Latin or UTF-8.
2235
 *           This should be used internally by the parser
2236
 *           only to compare to ASCII values otherwise it would break when
2237
 *           running with UTF-8 encoding.
2238
 *   NXT(n)  returns the n'th next xmlChar. Same as CUR is should be used only
2239
 *           to compare on ASCII based substring.
2240
 *   SKIP(n) Skip n xmlChar, and must also be used only to skip ASCII defined
2241
 *           strings within the parser.
2242
 *   CURRENT Returns the current char value, with the full decoding of
2243
 *           UTF-8 if we are using this mode. It returns an int.
2244
 *   NEXT    Skip to the next character, this does the proper decoding
2245
 *           in UTF-8 mode. It also pop-up unfinished entities on the fly.
2246
 *           It returns the pointer to the current xmlChar.
2247
 */
2248
2249
94.1M
#define CUR (*ctxt->cur)
2250
382k
#define SKIP(val) ctxt->cur += (val)
2251
8.32M
#define NXT(val) ctxt->cur[(val)]
2252
5.05M
#define CUR_PTR ctxt->cur
2253
41.7M
#define CUR_CHAR(l) xmlXPathCurrentChar(ctxt, &l)
2254
2255
#define COPY_BUF(b, i, v)           \
2256
26.4M
    if (v < 0x80) b[i++] = v;           \
2257
26.4M
    else i += xmlCopyCharMultiByte(&b[i],v)
2258
2259
39.3M
#define NEXTL(l)  ctxt->cur += l
2260
2261
#define SKIP_BLANKS             \
2262
46.6M
    while (IS_BLANK_CH(*(ctxt->cur))) NEXT
2263
2264
#define CURRENT (*ctxt->cur)
2265
38.9M
#define NEXT ((*ctxt->cur) ?  ctxt->cur++: ctxt->cur)
2266
2267
2268
#ifndef DBL_DIG
2269
#define DBL_DIG 16
2270
#endif
2271
#ifndef DBL_EPSILON
2272
#define DBL_EPSILON 1E-9
2273
#endif
2274
2275
25.1k
#define UPPER_DOUBLE 1E9
2276
9.24k
#define LOWER_DOUBLE 1E-5
2277
#define LOWER_DOUBLE_EXP 5
2278
2279
#define INTEGER_DIGITS DBL_DIG
2280
#define FRACTION_DIGITS (DBL_DIG + 1 + (LOWER_DOUBLE_EXP))
2281
17.1k
#define EXPONENT_DIGITS (3 + 2)
2282
2283
/**
2284
 * xmlXPathFormatNumber:
2285
 * @number:     number to format
2286
 * @buffer:     output buffer
2287
 * @buffersize: size of output buffer
2288
 *
2289
 * Convert the number into a string representation.
2290
 */
2291
static void
2292
xmlXPathFormatNumber(double number, char buffer[], int buffersize)
2293
148k
{
2294
148k
    switch (xmlXPathIsInf(number)) {
2295
0
    case 1:
2296
0
  if (buffersize > (int)sizeof("Infinity"))
2297
0
      snprintf(buffer, buffersize, "Infinity");
2298
0
  break;
2299
0
    case -1:
2300
0
  if (buffersize > (int)sizeof("-Infinity"))
2301
0
      snprintf(buffer, buffersize, "-Infinity");
2302
0
  break;
2303
148k
    default:
2304
148k
  if (xmlXPathIsNaN(number)) {
2305
0
      if (buffersize > (int)sizeof("NaN"))
2306
0
    snprintf(buffer, buffersize, "NaN");
2307
148k
  } else if (number == 0) {
2308
            /* Omit sign for negative zero. */
2309
0
      snprintf(buffer, buffersize, "0");
2310
148k
  } else if ((number > INT_MIN) && (number < INT_MAX) &&
2311
132k
                   (number == (int) number)) {
2312
122k
      char work[30];
2313
122k
      char *ptr, *cur;
2314
122k
      int value = (int) number;
2315
2316
122k
            ptr = &buffer[0];
2317
122k
      if (value == 0) {
2318
0
    *ptr++ = '0';
2319
122k
      } else {
2320
122k
    snprintf(work, 29, "%d", value);
2321
122k
    cur = &work[0];
2322
360k
    while ((*cur) && (ptr - buffer < buffersize)) {
2323
237k
        *ptr++ = *cur++;
2324
237k
    }
2325
122k
      }
2326
122k
      if (ptr - buffer < buffersize) {
2327
122k
    *ptr = 0;
2328
122k
      } else if (buffersize > 0) {
2329
0
    ptr--;
2330
0
    *ptr = 0;
2331
0
      }
2332
122k
  } else {
2333
      /*
2334
        For the dimension of work,
2335
            DBL_DIG is number of significant digits
2336
      EXPONENT is only needed for "scientific notation"
2337
            3 is sign, decimal point, and terminating zero
2338
      LOWER_DOUBLE_EXP is max number of leading zeroes in fraction
2339
        Note that this dimension is slightly (a few characters)
2340
        larger than actually necessary.
2341
      */
2342
25.1k
      char work[DBL_DIG + EXPONENT_DIGITS + 3 + LOWER_DOUBLE_EXP];
2343
25.1k
      int integer_place, fraction_place;
2344
25.1k
      char *ptr;
2345
25.1k
      char *after_fraction;
2346
25.1k
      double absolute_value;
2347
25.1k
      int size;
2348
2349
25.1k
      absolute_value = fabs(number);
2350
2351
      /*
2352
       * First choose format - scientific or regular floating point.
2353
       * In either case, result is in work, and after_fraction points
2354
       * just past the fractional part.
2355
      */
2356
25.1k
      if ( ((absolute_value > UPPER_DOUBLE) ||
2357
9.24k
      (absolute_value < LOWER_DOUBLE)) &&
2358
17.1k
     (absolute_value != 0.0) ) {
2359
    /* Use scientific notation */
2360
17.1k
    integer_place = DBL_DIG + EXPONENT_DIGITS + 1;
2361
17.1k
    fraction_place = DBL_DIG - 1;
2362
17.1k
    size = snprintf(work, sizeof(work),"%*.*e",
2363
17.1k
       integer_place, fraction_place, number);
2364
85.8k
    while ((size > 0) && (work[size] != 'e')) size--;
2365
2366
17.1k
      }
2367
8.01k
      else {
2368
    /* Use regular notation */
2369
8.01k
    if (absolute_value > 0.0) {
2370
8.01k
        integer_place = (int)log10(absolute_value);
2371
8.01k
        if (integer_place > 0)
2372
1.60k
            fraction_place = DBL_DIG - integer_place - 1;
2373
6.41k
        else
2374
6.41k
            fraction_place = DBL_DIG - integer_place;
2375
8.01k
    } else {
2376
0
        fraction_place = 1;
2377
0
    }
2378
8.01k
    size = snprintf(work, sizeof(work), "%0.*f",
2379
8.01k
        fraction_place, number);
2380
8.01k
      }
2381
2382
      /* Remove leading spaces sometimes inserted by snprintf */
2383
39.7k
      while (work[0] == ' ') {
2384
305k
          for (ptr = &work[0];(ptr[0] = ptr[1]);ptr++);
2385
14.5k
    size--;
2386
14.5k
      }
2387
2388
      /* Remove fractional trailing zeroes */
2389
25.1k
      after_fraction = work + size;
2390
25.1k
      ptr = after_fraction;
2391
222k
      while (*(--ptr) == '0')
2392
197k
    ;
2393
25.1k
      if (*ptr != '.')
2394
19.5k
          ptr++;
2395
93.8k
      while ((*ptr++ = *after_fraction++) != 0);
2396
2397
      /* Finally copy result back to caller */
2398
25.1k
      size = strlen(work) + 1;
2399
25.1k
      if (size > buffersize) {
2400
0
    work[buffersize - 1] = 0;
2401
0
    size = buffersize;
2402
0
      }
2403
25.1k
      memmove(buffer, work, size);
2404
25.1k
  }
2405
148k
  break;
2406
148k
    }
2407
148k
}
2408
2409
2410
/************************************************************************
2411
 *                  *
2412
 *      Routines to handle NodeSets     *
2413
 *                  *
2414
 ************************************************************************/
2415
2416
/**
2417
 * xmlXPathOrderDocElems:
2418
 * @doc:  an input document
2419
 *
2420
 * Call this routine to speed up XPath computation on static documents.
2421
 * This stamps all the element nodes with the document order
2422
 * Like for line information, the order is kept in the element->content
2423
 * field, the value stored is actually - the node number (starting at -1)
2424
 * to be able to differentiate from line numbers.
2425
 *
2426
 * Returns the number of elements found in the document or -1 in case
2427
 *    of error.
2428
 */
2429
long
2430
15.4k
xmlXPathOrderDocElems(xmlDocPtr doc) {
2431
15.4k
    XML_INTPTR_T count = 0;
2432
15.4k
    xmlNodePtr cur;
2433
2434
15.4k
    if (doc == NULL)
2435
0
  return(-1);
2436
15.4k
    cur = doc->children;
2437
333k
    while (cur != NULL) {
2438
318k
  if (cur->type == XML_ELEMENT_NODE) {
2439
184k
            count += 1;
2440
184k
            cur->content = XML_INT_TO_PTR(-count);
2441
184k
      if (cur->children != NULL) {
2442
90.2k
    cur = cur->children;
2443
90.2k
    continue;
2444
90.2k
      }
2445
184k
  }
2446
227k
  if (cur->next != NULL) {
2447
166k
      cur = cur->next;
2448
166k
      continue;
2449
166k
  }
2450
105k
  do {
2451
105k
      cur = cur->parent;
2452
105k
      if (cur == NULL)
2453
0
    break;
2454
105k
      if (cur == (xmlNodePtr) doc) {
2455
15.4k
    cur = NULL;
2456
15.4k
    break;
2457
15.4k
      }
2458
90.2k
      if (cur->next != NULL) {
2459
45.5k
    cur = cur->next;
2460
45.5k
    break;
2461
45.5k
      }
2462
90.2k
  } while (cur != NULL);
2463
60.9k
    }
2464
15.4k
    return(count);
2465
15.4k
}
2466
2467
/**
2468
 * xmlXPathCmpNodes:
2469
 * @node1:  the first node
2470
 * @node2:  the second node
2471
 *
2472
 * Compare two nodes w.r.t document order
2473
 *
2474
 * Returns -2 in case of error 1 if first point < second point, 0 if
2475
 *         it's the same node, -1 otherwise
2476
 */
2477
int
2478
39.7k
xmlXPathCmpNodes(xmlNodePtr node1, xmlNodePtr node2) {
2479
39.7k
    int depth1, depth2;
2480
39.7k
    int attr1 = 0, attr2 = 0;
2481
39.7k
    xmlNodePtr attrNode1 = NULL, attrNode2 = NULL;
2482
39.7k
    xmlNodePtr cur, root;
2483
2484
39.7k
    if ((node1 == NULL) || (node2 == NULL))
2485
0
  return(-2);
2486
    /*
2487
     * a couple of optimizations which will avoid computations in most cases
2488
     */
2489
39.7k
    if (node1 == node2)    /* trivial case */
2490
0
  return(0);
2491
39.7k
    if (node1->type == XML_ATTRIBUTE_NODE) {
2492
1.19k
  attr1 = 1;
2493
1.19k
  attrNode1 = node1;
2494
1.19k
  node1 = node1->parent;
2495
1.19k
    }
2496
39.7k
    if (node2->type == XML_ATTRIBUTE_NODE) {
2497
2.88k
  attr2 = 1;
2498
2.88k
  attrNode2 = node2;
2499
2.88k
  node2 = node2->parent;
2500
2.88k
    }
2501
39.7k
    if (node1 == node2) {
2502
473
  if (attr1 == attr2) {
2503
      /* not required, but we keep attributes in order */
2504
244
      if (attr1 != 0) {
2505
244
          cur = attrNode2->prev;
2506
365
    while (cur != NULL) {
2507
365
        if (cur == attrNode1)
2508
244
            return (1);
2509
121
        cur = cur->prev;
2510
121
    }
2511
0
    return (-1);
2512
244
      }
2513
0
      return(0);
2514
244
  }
2515
229
  if (attr2 == 1)
2516
229
      return(1);
2517
0
  return(-1);
2518
229
    }
2519
39.3k
    if ((node1->type == XML_NAMESPACE_DECL) ||
2520
38.3k
        (node2->type == XML_NAMESPACE_DECL))
2521
1.82k
  return(1);
2522
37.4k
    if (node1 == node2->prev)
2523
624
  return(1);
2524
36.8k
    if (node1 == node2->next)
2525
83
  return(-1);
2526
2527
    /*
2528
     * Speedup using document order if available.
2529
     */
2530
36.7k
    if ((node1->type == XML_ELEMENT_NODE) &&
2531
4.72k
  (node2->type == XML_ELEMENT_NODE) &&
2532
2.08k
  (0 > XML_NODE_SORT_VALUE(node1)) &&
2533
2.08k
  (0 > XML_NODE_SORT_VALUE(node2)) &&
2534
2.08k
  (node1->doc == node2->doc)) {
2535
2.08k
  XML_INTPTR_T l1, l2;
2536
2537
2.08k
  l1 = -XML_NODE_SORT_VALUE(node1);
2538
2.08k
  l2 = -XML_NODE_SORT_VALUE(node2);
2539
2.08k
  if (l1 < l2)
2540
2.00k
      return(1);
2541
81
  if (l1 > l2)
2542
81
      return(-1);
2543
81
    }
2544
2545
    /*
2546
     * compute depth to root
2547
     */
2548
225k
    for (depth2 = 0, cur = node2;cur->parent != NULL;cur = cur->parent) {
2549
194k
  if (cur->parent == node1)
2550
3.25k
      return(1);
2551
191k
  depth2++;
2552
191k
    }
2553
31.4k
    root = cur;
2554
124k
    for (depth1 = 0, cur = node1;cur->parent != NULL;cur = cur->parent) {
2555
93.1k
  if (cur->parent == node2)
2556
335
      return(-1);
2557
92.8k
  depth1++;
2558
92.8k
    }
2559
    /*
2560
     * Distinct document (or distinct entities :-( ) case.
2561
     */
2562
31.1k
    if (root != cur) {
2563
4.70k
  return(-2);
2564
4.70k
    }
2565
    /*
2566
     * get the nearest common ancestor.
2567
     */
2568
43.0k
    while (depth1 > depth2) {
2569
16.6k
  depth1--;
2570
16.6k
  node1 = node1->parent;
2571
16.6k
    }
2572
135k
    while (depth2 > depth1) {
2573
108k
  depth2--;
2574
108k
  node2 = node2->parent;
2575
108k
    }
2576
37.1k
    while (node1->parent != node2->parent) {
2577
10.7k
  node1 = node1->parent;
2578
10.7k
  node2 = node2->parent;
2579
  /* should not happen but just in case ... */
2580
10.7k
  if ((node1 == NULL) || (node2 == NULL))
2581
0
      return(-2);
2582
10.7k
    }
2583
    /*
2584
     * Find who's first.
2585
     */
2586
26.4k
    if (node1 == node2->prev)
2587
9.80k
  return(1);
2588
16.6k
    if (node1 == node2->next)
2589
297
  return(-1);
2590
    /*
2591
     * Speedup using document order if available.
2592
     */
2593
16.3k
    if ((node1->type == XML_ELEMENT_NODE) &&
2594
12.7k
  (node2->type == XML_ELEMENT_NODE) &&
2595
10.7k
  (0 > XML_NODE_SORT_VALUE(node1)) &&
2596
10.7k
  (0 > XML_NODE_SORT_VALUE(node2)) &&
2597
10.7k
  (node1->doc == node2->doc)) {
2598
10.7k
  XML_INTPTR_T l1, l2;
2599
2600
10.7k
  l1 = -XML_NODE_SORT_VALUE(node1);
2601
10.7k
  l2 = -XML_NODE_SORT_VALUE(node2);
2602
10.7k
  if (l1 < l2)
2603
10.7k
      return(1);
2604
79
  if (l1 > l2)
2605
79
      return(-1);
2606
79
    }
2607
2608
21.8k
    for (cur = node1->next;cur != NULL;cur = cur->next)
2609
21.6k
  if (cur == node2)
2610
5.28k
      return(1);
2611
234
    return(-1); /* assume there is no sibling list corruption */
2612
5.51k
}
2613
2614
/**
2615
 * xmlXPathNodeSetSort:
2616
 * @set:  the node set
2617
 *
2618
 * Sort the node set in document order
2619
 */
2620
void
2621
970k
xmlXPathNodeSetSort(xmlNodeSetPtr set) {
2622
#ifndef WITH_TIM_SORT
2623
    int i, j, incr, len;
2624
    xmlNodePtr tmp;
2625
#endif
2626
2627
970k
    if (set == NULL)
2628
0
  return;
2629
2630
#ifndef WITH_TIM_SORT
2631
    /*
2632
     * Use the old Shell's sort implementation to sort the node-set
2633
     * Timsort ought to be quite faster
2634
     */
2635
    len = set->nodeNr;
2636
    for (incr = len / 2; incr > 0; incr /= 2) {
2637
  for (i = incr; i < len; i++) {
2638
      j = i - incr;
2639
      while (j >= 0) {
2640
#ifdef XP_OPTIMIZED_NON_ELEM_COMPARISON
2641
    if (xmlXPathCmpNodesExt(set->nodeTab[j],
2642
      set->nodeTab[j + incr]) == -1)
2643
#else
2644
    if (xmlXPathCmpNodes(set->nodeTab[j],
2645
      set->nodeTab[j + incr]) == -1)
2646
#endif
2647
    {
2648
        tmp = set->nodeTab[j];
2649
        set->nodeTab[j] = set->nodeTab[j + incr];
2650
        set->nodeTab[j + incr] = tmp;
2651
        j -= incr;
2652
    } else
2653
        break;
2654
      }
2655
  }
2656
    }
2657
#else /* WITH_TIM_SORT */
2658
970k
    libxml_domnode_tim_sort(set->nodeTab, set->nodeNr);
2659
970k
#endif /* WITH_TIM_SORT */
2660
970k
}
2661
2662
12.8M
#define XML_NODESET_DEFAULT 10
2663
/**
2664
 * xmlXPathNodeSetDupNs:
2665
 * @node:  the parent node of the namespace XPath node
2666
 * @ns:  the libxml namespace declaration node.
2667
 *
2668
 * Namespace node in libxml don't match the XPath semantic. In a node set
2669
 * the namespace nodes are duplicated and the next pointer is set to the
2670
 * parent node in the XPath semantic.
2671
 *
2672
 * Returns the newly created object.
2673
 */
2674
static xmlNodePtr
2675
1.90M
xmlXPathNodeSetDupNs(xmlNodePtr node, xmlNsPtr ns) {
2676
1.90M
    xmlNsPtr cur;
2677
2678
1.90M
    if ((ns == NULL) || (ns->type != XML_NAMESPACE_DECL))
2679
0
  return(NULL);
2680
1.90M
    if ((node == NULL) || (node->type == XML_NAMESPACE_DECL))
2681
0
  return((xmlNodePtr) ns);
2682
2683
    /*
2684
     * Allocate a new Namespace and fill the fields.
2685
     */
2686
1.90M
    cur = (xmlNsPtr) xmlMalloc(sizeof(xmlNs));
2687
1.90M
    if (cur == NULL)
2688
922
  return(NULL);
2689
1.90M
    memset(cur, 0, sizeof(xmlNs));
2690
1.90M
    cur->type = XML_NAMESPACE_DECL;
2691
1.90M
    if (ns->href != NULL) {
2692
1.90M
  cur->href = xmlStrdup(ns->href);
2693
1.90M
        if (cur->href == NULL) {
2694
76
            xmlFree(cur);
2695
76
            return(NULL);
2696
76
        }
2697
1.90M
    }
2698
1.90M
    if (ns->prefix != NULL) {
2699
1.75M
  cur->prefix = xmlStrdup(ns->prefix);
2700
1.75M
        if (cur->prefix == NULL) {
2701
90
            xmlFree((xmlChar *) cur->href);
2702
90
            xmlFree(cur);
2703
90
            return(NULL);
2704
90
        }
2705
1.75M
    }
2706
1.90M
    cur->next = (xmlNsPtr) node;
2707
1.90M
    return((xmlNodePtr) cur);
2708
1.90M
}
2709
2710
/**
2711
 * xmlXPathNodeSetFreeNs:
2712
 * @ns:  the XPath namespace node found in a nodeset.
2713
 *
2714
 * Namespace nodes in libxml don't match the XPath semantic. In a node set
2715
 * the namespace nodes are duplicated and the next pointer is set to the
2716
 * parent node in the XPath semantic. Check if such a node needs to be freed
2717
 */
2718
void
2719
1.90M
xmlXPathNodeSetFreeNs(xmlNsPtr ns) {
2720
1.90M
    if ((ns == NULL) || (ns->type != XML_NAMESPACE_DECL))
2721
0
  return;
2722
2723
1.90M
    if ((ns->next != NULL) && (ns->next->type != XML_NAMESPACE_DECL)) {
2724
1.90M
  if (ns->href != NULL)
2725
1.90M
      xmlFree((xmlChar *)ns->href);
2726
1.90M
  if (ns->prefix != NULL)
2727
1.75M
      xmlFree((xmlChar *)ns->prefix);
2728
1.90M
  xmlFree(ns);
2729
1.90M
    }
2730
1.90M
}
2731
2732
/**
2733
 * xmlXPathNodeSetCreate:
2734
 * @val:  an initial xmlNodePtr, or NULL
2735
 *
2736
 * Create a new xmlNodeSetPtr of type double and of value @val
2737
 *
2738
 * Returns the newly created object.
2739
 */
2740
xmlNodeSetPtr
2741
7.37M
xmlXPathNodeSetCreate(xmlNodePtr val) {
2742
7.37M
    xmlNodeSetPtr ret;
2743
2744
7.37M
    ret = (xmlNodeSetPtr) xmlMalloc(sizeof(xmlNodeSet));
2745
7.37M
    if (ret == NULL)
2746
5.46k
  return(NULL);
2747
7.37M
    memset(ret, 0 , sizeof(xmlNodeSet));
2748
7.37M
    if (val != NULL) {
2749
659k
        ret->nodeTab = (xmlNodePtr *) xmlMalloc(XML_NODESET_DEFAULT *
2750
659k
               sizeof(xmlNodePtr));
2751
659k
  if (ret->nodeTab == NULL) {
2752
150
      xmlFree(ret);
2753
150
      return(NULL);
2754
150
  }
2755
659k
  memset(ret->nodeTab, 0 ,
2756
659k
         XML_NODESET_DEFAULT * sizeof(xmlNodePtr));
2757
659k
        ret->nodeMax = XML_NODESET_DEFAULT;
2758
659k
  if (val->type == XML_NAMESPACE_DECL) {
2759
81.3k
      xmlNsPtr ns = (xmlNsPtr) val;
2760
81.3k
            xmlNodePtr nsNode = xmlXPathNodeSetDupNs((xmlNodePtr) ns->next, ns);
2761
2762
81.3k
            if (nsNode == NULL) {
2763
9
                xmlXPathFreeNodeSet(ret);
2764
9
                return(NULL);
2765
9
            }
2766
81.3k
      ret->nodeTab[ret->nodeNr++] = nsNode;
2767
81.3k
  } else
2768
578k
      ret->nodeTab[ret->nodeNr++] = val;
2769
659k
    }
2770
7.37M
    return(ret);
2771
7.37M
}
2772
2773
/**
2774
 * xmlXPathNodeSetContains:
2775
 * @cur:  the node-set
2776
 * @val:  the node
2777
 *
2778
 * checks whether @cur contains @val
2779
 *
2780
 * Returns true (1) if @cur contains @val, false (0) otherwise
2781
 */
2782
int
2783
10.4k
xmlXPathNodeSetContains (xmlNodeSetPtr cur, xmlNodePtr val) {
2784
10.4k
    int i;
2785
2786
10.4k
    if ((cur == NULL) || (val == NULL)) return(0);
2787
10.4k
    if (val->type == XML_NAMESPACE_DECL) {
2788
39.6k
  for (i = 0; i < cur->nodeNr; i++) {
2789
36.0k
      if (cur->nodeTab[i]->type == XML_NAMESPACE_DECL) {
2790
22.7k
    xmlNsPtr ns1, ns2;
2791
2792
22.7k
    ns1 = (xmlNsPtr) val;
2793
22.7k
    ns2 = (xmlNsPtr) cur->nodeTab[i];
2794
22.7k
    if (ns1 == ns2)
2795
0
        return(1);
2796
22.7k
    if ((ns1->next != NULL) && (ns2->next == ns1->next) &&
2797
5.35k
              (xmlStrEqual(ns1->prefix, ns2->prefix)))
2798
2.22k
        return(1);
2799
22.7k
      }
2800
36.0k
  }
2801
5.74k
    } else {
2802
44.3k
  for (i = 0; i < cur->nodeNr; i++) {
2803
41.4k
      if (cur->nodeTab[i] == val)
2804
1.80k
    return(1);
2805
41.4k
  }
2806
4.66k
    }
2807
6.37k
    return(0);
2808
10.4k
}
2809
2810
static int
2811
10.6M
xmlXPathNodeSetGrow(xmlNodeSetPtr cur) {
2812
10.6M
    xmlNodePtr *temp;
2813
10.6M
    int newSize;
2814
2815
10.6M
    newSize = xmlGrowCapacity(cur->nodeMax, sizeof(temp[0]),
2816
10.6M
                              XML_NODESET_DEFAULT, XPATH_MAX_NODESET_LENGTH);
2817
10.6M
    if (newSize < 0)
2818
0
        return(-1);
2819
10.6M
    temp = xmlRealloc(cur->nodeTab, newSize * sizeof(temp[0]));
2820
10.6M
    if (temp == NULL)
2821
3.63k
        return(-1);
2822
10.6M
    cur->nodeMax = newSize;
2823
10.6M
    cur->nodeTab = temp;
2824
2825
10.6M
    return(0);
2826
10.6M
}
2827
2828
/**
2829
 * xmlXPathNodeSetAddNs:
2830
 * @cur:  the initial node set
2831
 * @node:  the hosting node
2832
 * @ns:  a the namespace node
2833
 *
2834
 * add a new namespace node to an existing NodeSet
2835
 *
2836
 * Returns 0 in case of success and -1 in case of error
2837
 */
2838
int
2839
999k
xmlXPathNodeSetAddNs(xmlNodeSetPtr cur, xmlNodePtr node, xmlNsPtr ns) {
2840
999k
    int i;
2841
999k
    xmlNodePtr nsNode;
2842
2843
999k
    if ((cur == NULL) || (ns == NULL) || (node == NULL) ||
2844
999k
        (ns->type != XML_NAMESPACE_DECL) ||
2845
999k
  (node->type != XML_ELEMENT_NODE))
2846
0
  return(-1);
2847
2848
    /* @@ with_ns to check whether namespace nodes should be looked at @@ */
2849
    /*
2850
     * prevent duplicates
2851
     */
2852
3.76M
    for (i = 0;i < cur->nodeNr;i++) {
2853
2.76M
        if ((cur->nodeTab[i] != NULL) &&
2854
2.76M
      (cur->nodeTab[i]->type == XML_NAMESPACE_DECL) &&
2855
2.76M
      (((xmlNsPtr)cur->nodeTab[i])->next == (xmlNsPtr) node) &&
2856
2.76M
      (xmlStrEqual(ns->prefix, ((xmlNsPtr)cur->nodeTab[i])->prefix)))
2857
0
      return(0);
2858
2.76M
    }
2859
2860
    /*
2861
     * grow the nodeTab if needed
2862
     */
2863
999k
    if (cur->nodeNr >= cur->nodeMax) {
2864
208k
        if (xmlXPathNodeSetGrow(cur) < 0)
2865
19
            return(-1);
2866
208k
    }
2867
999k
    nsNode = xmlXPathNodeSetDupNs(node, ns);
2868
999k
    if(nsNode == NULL)
2869
130
        return(-1);
2870
999k
    cur->nodeTab[cur->nodeNr++] = nsNode;
2871
999k
    return(0);
2872
999k
}
2873
2874
/**
2875
 * xmlXPathNodeSetAdd:
2876
 * @cur:  the initial node set
2877
 * @val:  a new xmlNodePtr
2878
 *
2879
 * add a new xmlNodePtr to an existing NodeSet
2880
 *
2881
 * Returns 0 in case of success, and -1 in case of error
2882
 */
2883
int
2884
14.0M
xmlXPathNodeSetAdd(xmlNodeSetPtr cur, xmlNodePtr val) {
2885
14.0M
    int i;
2886
2887
14.0M
    if ((cur == NULL) || (val == NULL)) return(-1);
2888
2889
    /* @@ with_ns to check whether namespace nodes should be looked at @@ */
2890
    /*
2891
     * prevent duplicates
2892
     */
2893
15.4G
    for (i = 0;i < cur->nodeNr;i++)
2894
15.4G
        if (cur->nodeTab[i] == val) return(0);
2895
2896
    /*
2897
     * grow the nodeTab if needed
2898
     */
2899
13.6M
    if (cur->nodeNr >= cur->nodeMax) {
2900
313k
        if (xmlXPathNodeSetGrow(cur) < 0)
2901
1.00k
            return(-1);
2902
313k
    }
2903
2904
13.6M
    if (val->type == XML_NAMESPACE_DECL) {
2905
138k
  xmlNsPtr ns = (xmlNsPtr) val;
2906
138k
        xmlNodePtr nsNode = xmlXPathNodeSetDupNs((xmlNodePtr) ns->next, ns);
2907
2908
138k
        if (nsNode == NULL)
2909
542
            return(-1);
2910
138k
  cur->nodeTab[cur->nodeNr++] = nsNode;
2911
138k
    } else
2912
13.5M
  cur->nodeTab[cur->nodeNr++] = val;
2913
13.6M
    return(0);
2914
13.6M
}
2915
2916
/**
2917
 * xmlXPathNodeSetAddUnique:
2918
 * @cur:  the initial node set
2919
 * @val:  a new xmlNodePtr
2920
 *
2921
 * add a new xmlNodePtr to an existing NodeSet, optimized version
2922
 * when we are sure the node is not already in the set.
2923
 *
2924
 * Returns 0 in case of success and -1 in case of failure
2925
 */
2926
int
2927
17.6M
xmlXPathNodeSetAddUnique(xmlNodeSetPtr cur, xmlNodePtr val) {
2928
17.6M
    if ((cur == NULL) || (val == NULL)) return(-1);
2929
2930
    /* @@ with_ns to check whether namespace nodes should be looked at @@ */
2931
    /*
2932
     * grow the nodeTab if needed
2933
     */
2934
17.6M
    if (cur->nodeNr >= cur->nodeMax) {
2935
7.60M
        if (xmlXPathNodeSetGrow(cur) < 0)
2936
1.83k
            return(-1);
2937
7.60M
    }
2938
2939
17.6M
    if (val->type == XML_NAMESPACE_DECL) {
2940
378k
  xmlNsPtr ns = (xmlNsPtr) val;
2941
378k
        xmlNodePtr nsNode = xmlXPathNodeSetDupNs((xmlNodePtr) ns->next, ns);
2942
2943
378k
        if (nsNode == NULL)
2944
135
            return(-1);
2945
378k
  cur->nodeTab[cur->nodeNr++] = nsNode;
2946
378k
    } else
2947
17.3M
  cur->nodeTab[cur->nodeNr++] = val;
2948
17.6M
    return(0);
2949
17.6M
}
2950
2951
/**
2952
 * xmlXPathNodeSetMerge:
2953
 * @val1:  the first NodeSet or NULL
2954
 * @val2:  the second NodeSet
2955
 *
2956
 * Merges two nodesets, all nodes from @val2 are added to @val1
2957
 * if @val1 is NULL, a new set is created and copied from @val2
2958
 *
2959
 * Returns @val1 once extended or NULL in case of error.
2960
 *
2961
 * Frees @val1 in case of error.
2962
 */
2963
xmlNodeSetPtr
2964
1.36M
xmlXPathNodeSetMerge(xmlNodeSetPtr val1, xmlNodeSetPtr val2) {
2965
1.36M
    int i, j, initNr, skip;
2966
1.36M
    xmlNodePtr n1, n2;
2967
2968
1.36M
    if (val1 == NULL) {
2969
306k
  val1 = xmlXPathNodeSetCreate(NULL);
2970
306k
        if (val1 == NULL)
2971
520
            return (NULL);
2972
306k
    }
2973
1.36M
    if (val2 == NULL)
2974
8.08k
        return(val1);
2975
2976
    /* @@ with_ns to check whether namespace nodes should be looked at @@ */
2977
1.35M
    initNr = val1->nodeNr;
2978
2979
11.1M
    for (i = 0;i < val2->nodeNr;i++) {
2980
9.81M
  n2 = val2->nodeTab[i];
2981
  /*
2982
   * check against duplicates
2983
   */
2984
9.81M
  skip = 0;
2985
121M
  for (j = 0; j < initNr; j++) {
2986
111M
      n1 = val1->nodeTab[j];
2987
111M
      if (n1 == n2) {
2988
416k
    skip = 1;
2989
416k
    break;
2990
111M
      } else if ((n1->type == XML_NAMESPACE_DECL) &&
2991
101M
           (n2->type == XML_NAMESPACE_DECL)) {
2992
42.4k
    if ((((xmlNsPtr) n1)->next == ((xmlNsPtr) n2)->next) &&
2993
9.29k
        (xmlStrEqual(((xmlNsPtr) n1)->prefix,
2994
9.29k
      ((xmlNsPtr) n2)->prefix)))
2995
2.37k
    {
2996
2.37k
        skip = 1;
2997
2.37k
        break;
2998
2.37k
    }
2999
42.4k
      }
3000
111M
  }
3001
9.81M
  if (skip)
3002
418k
      continue;
3003
3004
  /*
3005
   * grow the nodeTab if needed
3006
   */
3007
9.39M
        if (val1->nodeNr >= val1->nodeMax) {
3008
2.31M
            if (xmlXPathNodeSetGrow(val1) < 0)
3009
661
                goto error;
3010
2.31M
        }
3011
9.39M
  if (n2->type == XML_NAMESPACE_DECL) {
3012
306k
      xmlNsPtr ns = (xmlNsPtr) n2;
3013
306k
            xmlNodePtr nsNode = xmlXPathNodeSetDupNs((xmlNodePtr) ns->next, ns);
3014
3015
306k
            if (nsNode == NULL)
3016
272
                goto error;
3017
306k
      val1->nodeTab[val1->nodeNr++] = nsNode;
3018
306k
  } else
3019
9.09M
      val1->nodeTab[val1->nodeNr++] = n2;
3020
9.39M
    }
3021
3022
1.35M
    return(val1);
3023
3024
933
error:
3025
933
    xmlXPathFreeNodeSet(val1);
3026
933
    return(NULL);
3027
1.35M
}
3028
3029
3030
/**
3031
 * xmlXPathNodeSetMergeAndClear:
3032
 * @set1:  the first NodeSet or NULL
3033
 * @set2:  the second NodeSet
3034
 *
3035
 * Merges two nodesets, all nodes from @set2 are added to @set1.
3036
 * Checks for duplicate nodes. Clears set2.
3037
 *
3038
 * Returns @set1 once extended or NULL in case of error.
3039
 *
3040
 * Frees @set1 in case of error.
3041
 */
3042
static xmlNodeSetPtr
3043
xmlXPathNodeSetMergeAndClear(xmlNodeSetPtr set1, xmlNodeSetPtr set2)
3044
240k
{
3045
240k
    {
3046
240k
  int i, j, initNbSet1;
3047
240k
  xmlNodePtr n1, n2;
3048
3049
240k
  initNbSet1 = set1->nodeNr;
3050
535k
  for (i = 0;i < set2->nodeNr;i++) {
3051
295k
      n2 = set2->nodeTab[i];
3052
      /*
3053
      * Skip duplicates.
3054
      */
3055
247M
      for (j = 0; j < initNbSet1; j++) {
3056
247M
    n1 = set1->nodeTab[j];
3057
247M
    if (n1 == n2) {
3058
57.4k
        goto skip_node;
3059
247M
    } else if ((n1->type == XML_NAMESPACE_DECL) &&
3060
244M
        (n2->type == XML_NAMESPACE_DECL))
3061
244M
    {
3062
244M
        if ((((xmlNsPtr) n1)->next == ((xmlNsPtr) n2)->next) &&
3063
786k
      (xmlStrEqual(((xmlNsPtr) n1)->prefix,
3064
786k
      ((xmlNsPtr) n2)->prefix)))
3065
348
        {
3066
      /*
3067
      * Free the namespace node.
3068
      */
3069
348
      xmlXPathNodeSetFreeNs((xmlNsPtr) n2);
3070
348
      goto skip_node;
3071
348
        }
3072
244M
    }
3073
247M
      }
3074
      /*
3075
      * grow the nodeTab if needed
3076
      */
3077
237k
            if (set1->nodeNr >= set1->nodeMax) {
3078
24.9k
                if (xmlXPathNodeSetGrow(set1) < 0)
3079
44
                    goto error;
3080
24.9k
            }
3081
237k
      set1->nodeTab[set1->nodeNr++] = n2;
3082
295k
skip_node:
3083
295k
            set2->nodeTab[i] = NULL;
3084
295k
  }
3085
240k
    }
3086
240k
    set2->nodeNr = 0;
3087
240k
    return(set1);
3088
3089
44
error:
3090
44
    xmlXPathFreeNodeSet(set1);
3091
44
    xmlXPathNodeSetClear(set2, 1);
3092
44
    return(NULL);
3093
240k
}
3094
3095
/**
3096
 * xmlXPathNodeSetMergeAndClearNoDupls:
3097
 * @set1:  the first NodeSet or NULL
3098
 * @set2:  the second NodeSet
3099
 *
3100
 * Merges two nodesets, all nodes from @set2 are added to @set1.
3101
 * Doesn't check for duplicate nodes. Clears set2.
3102
 *
3103
 * Returns @set1 once extended or NULL in case of error.
3104
 *
3105
 * Frees @set1 in case of error.
3106
 */
3107
static xmlNodeSetPtr
3108
xmlXPathNodeSetMergeAndClearNoDupls(xmlNodeSetPtr set1, xmlNodeSetPtr set2)
3109
468k
{
3110
468k
    {
3111
468k
  int i;
3112
468k
  xmlNodePtr n2;
3113
3114
1.80M
  for (i = 0;i < set2->nodeNr;i++) {
3115
1.33M
      n2 = set2->nodeTab[i];
3116
1.33M
            if (set1->nodeNr >= set1->nodeMax) {
3117
155k
                if (xmlXPathNodeSetGrow(set1) < 0)
3118
61
                    goto error;
3119
155k
            }
3120
1.33M
      set1->nodeTab[set1->nodeNr++] = n2;
3121
1.33M
            set2->nodeTab[i] = NULL;
3122
1.33M
  }
3123
468k
    }
3124
468k
    set2->nodeNr = 0;
3125
468k
    return(set1);
3126
3127
61
error:
3128
61
    xmlXPathFreeNodeSet(set1);
3129
61
    xmlXPathNodeSetClear(set2, 1);
3130
61
    return(NULL);
3131
468k
}
3132
3133
/**
3134
 * xmlXPathNodeSetDel:
3135
 * @cur:  the initial node set
3136
 * @val:  an xmlNodePtr
3137
 *
3138
 * Removes an xmlNodePtr from an existing NodeSet
3139
 */
3140
void
3141
0
xmlXPathNodeSetDel(xmlNodeSetPtr cur, xmlNodePtr val) {
3142
0
    int i;
3143
3144
0
    if (cur == NULL) return;
3145
0
    if (val == NULL) return;
3146
3147
    /*
3148
     * find node in nodeTab
3149
     */
3150
0
    for (i = 0;i < cur->nodeNr;i++)
3151
0
        if (cur->nodeTab[i] == val) break;
3152
3153
0
    if (i >= cur->nodeNr) { /* not found */
3154
0
        return;
3155
0
    }
3156
0
    if ((cur->nodeTab[i] != NULL) &&
3157
0
  (cur->nodeTab[i]->type == XML_NAMESPACE_DECL))
3158
0
  xmlXPathNodeSetFreeNs((xmlNsPtr) cur->nodeTab[i]);
3159
0
    cur->nodeNr--;
3160
0
    for (;i < cur->nodeNr;i++)
3161
0
        cur->nodeTab[i] = cur->nodeTab[i + 1];
3162
0
    cur->nodeTab[cur->nodeNr] = NULL;
3163
0
}
3164
3165
/**
3166
 * xmlXPathNodeSetRemove:
3167
 * @cur:  the initial node set
3168
 * @val:  the index to remove
3169
 *
3170
 * Removes an entry from an existing NodeSet list.
3171
 */
3172
void
3173
0
xmlXPathNodeSetRemove(xmlNodeSetPtr cur, int val) {
3174
0
    if (cur == NULL) return;
3175
0
    if (val >= cur->nodeNr) return;
3176
0
    if ((cur->nodeTab[val] != NULL) &&
3177
0
  (cur->nodeTab[val]->type == XML_NAMESPACE_DECL))
3178
0
  xmlXPathNodeSetFreeNs((xmlNsPtr) cur->nodeTab[val]);
3179
0
    cur->nodeNr--;
3180
0
    for (;val < cur->nodeNr;val++)
3181
0
        cur->nodeTab[val] = cur->nodeTab[val + 1];
3182
0
    cur->nodeTab[cur->nodeNr] = NULL;
3183
0
}
3184
3185
/**
3186
 * xmlXPathFreeNodeSet:
3187
 * @obj:  the xmlNodeSetPtr to free
3188
 *
3189
 * Free the NodeSet compound (not the actual nodes !).
3190
 */
3191
void
3192
7.05M
xmlXPathFreeNodeSet(xmlNodeSetPtr obj) {
3193
7.05M
    if (obj == NULL) return;
3194
7.03M
    if (obj->nodeTab != NULL) {
3195
3.45M
  int i;
3196
3197
  /* @@ with_ns to check whether namespace nodes should be looked at @@ */
3198
41.9M
  for (i = 0;i < obj->nodeNr;i++)
3199
38.4M
      if ((obj->nodeTab[i] != NULL) &&
3200
38.4M
    (obj->nodeTab[i]->type == XML_NAMESPACE_DECL))
3201
1.50M
    xmlXPathNodeSetFreeNs((xmlNsPtr) obj->nodeTab[i]);
3202
3.45M
  xmlFree(obj->nodeTab);
3203
3.45M
    }
3204
7.03M
    xmlFree(obj);
3205
7.03M
}
3206
3207
/**
3208
 * xmlXPathNodeSetClearFromPos:
3209
 * @set: the node set to be cleared
3210
 * @pos: the start position to clear from
3211
 *
3212
 * Clears the list from temporary XPath objects (e.g. namespace nodes
3213
 * are feed) starting with the entry at @pos, but does *not* free the list
3214
 * itself. Sets the length of the list to @pos.
3215
 */
3216
static void
3217
xmlXPathNodeSetClearFromPos(xmlNodeSetPtr set, int pos, int hasNsNodes)
3218
8.28k
{
3219
8.28k
    if ((set == NULL) || (pos >= set->nodeNr))
3220
0
  return;
3221
8.28k
    else if ((hasNsNodes)) {
3222
7.64k
  int i;
3223
7.64k
  xmlNodePtr node;
3224
3225
33.4k
  for (i = pos; i < set->nodeNr; i++) {
3226
25.8k
      node = set->nodeTab[i];
3227
25.8k
      if ((node != NULL) &&
3228
25.2k
    (node->type == XML_NAMESPACE_DECL))
3229
18.4k
    xmlXPathNodeSetFreeNs((xmlNsPtr) node);
3230
25.8k
  }
3231
7.64k
    }
3232
8.28k
    set->nodeNr = pos;
3233
8.28k
}
3234
3235
/**
3236
 * xmlXPathNodeSetClear:
3237
 * @set:  the node set to clear
3238
 *
3239
 * Clears the list from all temporary XPath objects (e.g. namespace nodes
3240
 * are feed), but does *not* free the list itself. Sets the length of the
3241
 * list to 0.
3242
 */
3243
static void
3244
xmlXPathNodeSetClear(xmlNodeSetPtr set, int hasNsNodes)
3245
3.28k
{
3246
3.28k
    xmlXPathNodeSetClearFromPos(set, 0, hasNsNodes);
3247
3.28k
}
3248
3249
/**
3250
 * xmlXPathNodeSetKeepLast:
3251
 * @set: the node set to be cleared
3252
 *
3253
 * Move the last node to the first position and clear temporary XPath objects
3254
 * (e.g. namespace nodes) from all other nodes. Sets the length of the list
3255
 * to 1.
3256
 */
3257
static void
3258
xmlXPathNodeSetKeepLast(xmlNodeSetPtr set)
3259
5.84k
{
3260
5.84k
    int i;
3261
5.84k
    xmlNodePtr node;
3262
3263
5.84k
    if ((set == NULL) || (set->nodeNr <= 1))
3264
0
  return;
3265
32.7k
    for (i = 0; i < set->nodeNr - 1; i++) {
3266
26.8k
        node = set->nodeTab[i];
3267
26.8k
        if ((node != NULL) &&
3268
26.8k
            (node->type == XML_NAMESPACE_DECL))
3269
2.67k
            xmlXPathNodeSetFreeNs((xmlNsPtr) node);
3270
26.8k
    }
3271
5.84k
    set->nodeTab[0] = set->nodeTab[set->nodeNr-1];
3272
5.84k
    set->nodeNr = 1;
3273
5.84k
}
3274
3275
/**
3276
 * xmlXPathNewNodeSet:
3277
 * @val:  the NodePtr value
3278
 *
3279
 * Create a new xmlXPathObjectPtr of type NodeSet and initialize
3280
 * it with the single Node @val
3281
 *
3282
 * Returns the newly created object.
3283
 */
3284
xmlXPathObjectPtr
3285
1.54M
xmlXPathNewNodeSet(xmlNodePtr val) {
3286
1.54M
    xmlXPathObjectPtr ret;
3287
3288
1.54M
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
3289
1.54M
    if (ret == NULL)
3290
15.2k
  return(NULL);
3291
1.52M
    memset(ret, 0 , sizeof(xmlXPathObject));
3292
1.52M
    ret->type = XPATH_NODESET;
3293
1.52M
    ret->boolval = 0;
3294
1.52M
    ret->nodesetval = xmlXPathNodeSetCreate(val);
3295
1.52M
    if (ret->nodesetval == NULL) {
3296
321
        xmlFree(ret);
3297
321
        return(NULL);
3298
321
    }
3299
    /* @@ with_ns to check whether namespace nodes should be looked at @@ */
3300
1.52M
    return(ret);
3301
1.52M
}
3302
3303
/**
3304
 * xmlXPathNewValueTree:
3305
 * @val:  the NodePtr value
3306
 *
3307
 * Create a new xmlXPathObjectPtr of type Value Tree (XSLT) and initialize
3308
 * it with the tree root @val
3309
 *
3310
 * Returns the newly created object.
3311
 */
3312
xmlXPathObjectPtr
3313
21.8k
xmlXPathNewValueTree(xmlNodePtr val) {
3314
21.8k
    xmlXPathObjectPtr ret;
3315
3316
21.8k
    ret = xmlXPathNewNodeSet(val);
3317
21.8k
    if (ret == NULL)
3318
1.76k
  return(NULL);
3319
20.1k
    ret->type = XPATH_XSLT_TREE;
3320
3321
20.1k
    return(ret);
3322
21.8k
}
3323
3324
/**
3325
 * xmlXPathNewNodeSetList:
3326
 * @val:  an existing NodeSet
3327
 *
3328
 * Create a new xmlXPathObjectPtr of type NodeSet and initialize
3329
 * it with the Nodeset @val
3330
 *
3331
 * Returns the newly created object.
3332
 */
3333
xmlXPathObjectPtr
3334
xmlXPathNewNodeSetList(xmlNodeSetPtr val)
3335
0
{
3336
0
    xmlXPathObjectPtr ret;
3337
3338
0
    if (val == NULL)
3339
0
        ret = NULL;
3340
0
    else if (val->nodeTab == NULL)
3341
0
        ret = xmlXPathNewNodeSet(NULL);
3342
0
    else {
3343
0
        ret = xmlXPathNewNodeSet(val->nodeTab[0]);
3344
0
        if (ret) {
3345
0
            ret->nodesetval = xmlXPathNodeSetMerge(NULL, val);
3346
0
            if (ret->nodesetval == NULL) {
3347
0
                xmlFree(ret);
3348
0
                return(NULL);
3349
0
            }
3350
0
        }
3351
0
    }
3352
3353
0
    return (ret);
3354
0
}
3355
3356
/**
3357
 * xmlXPathWrapNodeSet:
3358
 * @val:  the NodePtr value
3359
 *
3360
 * Wrap the Nodeset @val in a new xmlXPathObjectPtr
3361
 *
3362
 * Returns the newly created object.
3363
 *
3364
 * In case of error the node set is destroyed and NULL is returned.
3365
 */
3366
xmlXPathObjectPtr
3367
1.71M
xmlXPathWrapNodeSet(xmlNodeSetPtr val) {
3368
1.71M
    xmlXPathObjectPtr ret;
3369
3370
1.71M
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
3371
1.71M
    if (ret == NULL) {
3372
3.00k
        xmlXPathFreeNodeSet(val);
3373
3.00k
  return(NULL);
3374
3.00k
    }
3375
1.70M
    memset(ret, 0 , sizeof(xmlXPathObject));
3376
1.70M
    ret->type = XPATH_NODESET;
3377
1.70M
    ret->nodesetval = val;
3378
1.70M
    return(ret);
3379
1.71M
}
3380
3381
/**
3382
 * xmlXPathFreeNodeSetList:
3383
 * @obj:  an existing NodeSetList object
3384
 *
3385
 * Free up the xmlXPathObjectPtr @obj but don't deallocate the objects in
3386
 * the list contrary to xmlXPathFreeObject().
3387
 */
3388
void
3389
0
xmlXPathFreeNodeSetList(xmlXPathObjectPtr obj) {
3390
0
    if (obj == NULL) return;
3391
0
    xmlFree(obj);
3392
0
}
3393
3394
/**
3395
 * xmlXPathDifference:
3396
 * @nodes1:  a node-set
3397
 * @nodes2:  a node-set
3398
 *
3399
 * Implements the EXSLT - Sets difference() function:
3400
 *    node-set set:difference (node-set, node-set)
3401
 *
3402
 * Returns the difference between the two node sets, or nodes1 if
3403
 *         nodes2 is empty
3404
 */
3405
xmlNodeSetPtr
3406
1.07k
xmlXPathDifference (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3407
1.07k
    xmlNodeSetPtr ret;
3408
1.07k
    int i, l1;
3409
1.07k
    xmlNodePtr cur;
3410
3411
1.07k
    if (xmlXPathNodeSetIsEmpty(nodes2))
3412
217
  return(nodes1);
3413
3414
855
    ret = xmlXPathNodeSetCreate(NULL);
3415
855
    if (ret == NULL)
3416
2
        return(NULL);
3417
853
    if (xmlXPathNodeSetIsEmpty(nodes1))
3418
80
  return(ret);
3419
3420
773
    l1 = xmlXPathNodeSetGetLength(nodes1);
3421
3422
2.94k
    for (i = 0; i < l1; i++) {
3423
2.17k
  cur = xmlXPathNodeSetItem(nodes1, i);
3424
2.17k
  if (!xmlXPathNodeSetContains(nodes2, cur)) {
3425
1.58k
      if (xmlXPathNodeSetAddUnique(ret, cur) < 0) {
3426
8
                xmlXPathFreeNodeSet(ret);
3427
8
          return(NULL);
3428
8
            }
3429
1.58k
  }
3430
2.17k
    }
3431
765
    return(ret);
3432
773
}
3433
3434
/**
3435
 * xmlXPathIntersection:
3436
 * @nodes1:  a node-set
3437
 * @nodes2:  a node-set
3438
 *
3439
 * Implements the EXSLT - Sets intersection() function:
3440
 *    node-set set:intersection (node-set, node-set)
3441
 *
3442
 * Returns a node set comprising the nodes that are within both the
3443
 *         node sets passed as arguments
3444
 */
3445
xmlNodeSetPtr
3446
539
xmlXPathIntersection (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3447
539
    xmlNodeSetPtr ret = xmlXPathNodeSetCreate(NULL);
3448
539
    int i, l1;
3449
539
    xmlNodePtr cur;
3450
3451
539
    if (ret == NULL)
3452
1
        return(ret);
3453
538
    if (xmlXPathNodeSetIsEmpty(nodes1))
3454
232
  return(ret);
3455
306
    if (xmlXPathNodeSetIsEmpty(nodes2))
3456
35
  return(ret);
3457
3458
271
    l1 = xmlXPathNodeSetGetLength(nodes1);
3459
3460
2.77k
    for (i = 0; i < l1; i++) {
3461
2.50k
  cur = xmlXPathNodeSetItem(nodes1, i);
3462
2.50k
  if (xmlXPathNodeSetContains(nodes2, cur)) {
3463
1.48k
      if (xmlXPathNodeSetAddUnique(ret, cur) < 0) {
3464
4
                xmlXPathFreeNodeSet(ret);
3465
4
          return(NULL);
3466
4
            }
3467
1.48k
  }
3468
2.50k
    }
3469
267
    return(ret);
3470
271
}
3471
3472
/**
3473
 * xmlXPathDistinctSorted:
3474
 * @nodes:  a node-set, sorted by document order
3475
 *
3476
 * Implements the EXSLT - Sets distinct() function:
3477
 *    node-set set:distinct (node-set)
3478
 *
3479
 * Returns a subset of the nodes contained in @nodes, or @nodes if
3480
 *         it is empty
3481
 */
3482
xmlNodeSetPtr
3483
232
xmlXPathDistinctSorted (xmlNodeSetPtr nodes) {
3484
232
    xmlNodeSetPtr ret;
3485
232
    xmlHashTablePtr hash;
3486
232
    int i, l;
3487
232
    xmlChar * strval;
3488
232
    xmlNodePtr cur;
3489
3490
232
    if (xmlXPathNodeSetIsEmpty(nodes))
3491
87
  return(nodes);
3492
3493
145
    ret = xmlXPathNodeSetCreate(NULL);
3494
145
    if (ret == NULL)
3495
1
        return(ret);
3496
144
    l = xmlXPathNodeSetGetLength(nodes);
3497
144
    hash = xmlHashCreate (l);
3498
3.32k
    for (i = 0; i < l; i++) {
3499
3.18k
  cur = xmlXPathNodeSetItem(nodes, i);
3500
3.18k
  strval = xmlXPathCastNodeToString(cur);
3501
3.18k
  if (xmlHashLookup(hash, strval) == NULL) {
3502
971
      if (xmlHashAddEntry(hash, strval, strval) < 0) {
3503
7
                xmlFree(strval);
3504
7
                goto error;
3505
7
            }
3506
964
      if (xmlXPathNodeSetAddUnique(ret, cur) < 0)
3507
3
          goto error;
3508
2.21k
  } else {
3509
2.21k
      xmlFree(strval);
3510
2.21k
  }
3511
3.18k
    }
3512
134
    xmlHashFree(hash, xmlHashDefaultDeallocator);
3513
134
    return(ret);
3514
3515
10
error:
3516
10
    xmlHashFree(hash, xmlHashDefaultDeallocator);
3517
10
    xmlXPathFreeNodeSet(ret);
3518
10
    return(NULL);
3519
144
}
3520
3521
/**
3522
 * xmlXPathDistinct:
3523
 * @nodes:  a node-set
3524
 *
3525
 * Implements the EXSLT - Sets distinct() function:
3526
 *    node-set set:distinct (node-set)
3527
 * @nodes is sorted by document order, then #exslSetsDistinctSorted
3528
 * is called with the sorted node-set
3529
 *
3530
 * Returns a subset of the nodes contained in @nodes, or @nodes if
3531
 *         it is empty
3532
 */
3533
xmlNodeSetPtr
3534
0
xmlXPathDistinct (xmlNodeSetPtr nodes) {
3535
0
    if (xmlXPathNodeSetIsEmpty(nodes))
3536
0
  return(nodes);
3537
3538
0
    xmlXPathNodeSetSort(nodes);
3539
0
    return(xmlXPathDistinctSorted(nodes));
3540
0
}
3541
3542
/**
3543
 * xmlXPathHasSameNodes:
3544
 * @nodes1:  a node-set
3545
 * @nodes2:  a node-set
3546
 *
3547
 * Implements the EXSLT - Sets has-same-nodes function:
3548
 *    boolean set:has-same-node(node-set, node-set)
3549
 *
3550
 * Returns true (1) if @nodes1 shares any node with @nodes2, false (0)
3551
 *         otherwise
3552
 */
3553
int
3554
614
xmlXPathHasSameNodes (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3555
614
    int i, l;
3556
614
    xmlNodePtr cur;
3557
3558
614
    if (xmlXPathNodeSetIsEmpty(nodes1) ||
3559
514
  xmlXPathNodeSetIsEmpty(nodes2))
3560
191
  return(0);
3561
3562
423
    l = xmlXPathNodeSetGetLength(nodes1);
3563
1.01k
    for (i = 0; i < l; i++) {
3564
835
  cur = xmlXPathNodeSetItem(nodes1, i);
3565
835
  if (xmlXPathNodeSetContains(nodes2, cur))
3566
242
      return(1);
3567
835
    }
3568
181
    return(0);
3569
423
}
3570
3571
/**
3572
 * xmlXPathNodeLeadingSorted:
3573
 * @nodes: a node-set, sorted by document order
3574
 * @node: a node
3575
 *
3576
 * Implements the EXSLT - Sets leading() function:
3577
 *    node-set set:leading (node-set, node-set)
3578
 *
3579
 * Returns the nodes in @nodes that precede @node in document order,
3580
 *         @nodes if @node is NULL or an empty node-set if @nodes
3581
 *         doesn't contain @node
3582
 */
3583
xmlNodeSetPtr
3584
963
xmlXPathNodeLeadingSorted (xmlNodeSetPtr nodes, xmlNodePtr node) {
3585
963
    int i, l;
3586
963
    xmlNodePtr cur;
3587
963
    xmlNodeSetPtr ret;
3588
3589
963
    if (node == NULL)
3590
0
  return(nodes);
3591
3592
963
    ret = xmlXPathNodeSetCreate(NULL);
3593
963
    if (ret == NULL)
3594
2
        return(ret);
3595
961
    if (xmlXPathNodeSetIsEmpty(nodes) ||
3596
824
  (!xmlXPathNodeSetContains(nodes, node)))
3597
652
  return(ret);
3598
3599
309
    l = xmlXPathNodeSetGetLength(nodes);
3600
823
    for (i = 0; i < l; i++) {
3601
664
  cur = xmlXPathNodeSetItem(nodes, i);
3602
664
  if (cur == node)
3603
148
      break;
3604
516
  if (xmlXPathNodeSetAddUnique(ret, cur) < 0) {
3605
2
            xmlXPathFreeNodeSet(ret);
3606
2
      return(NULL);
3607
2
        }
3608
516
    }
3609
307
    return(ret);
3610
309
}
3611
3612
/**
3613
 * xmlXPathNodeLeading:
3614
 * @nodes:  a node-set
3615
 * @node:  a node
3616
 *
3617
 * Implements the EXSLT - Sets leading() function:
3618
 *    node-set set:leading (node-set, node-set)
3619
 * @nodes is sorted by document order, then #exslSetsNodeLeadingSorted
3620
 * is called.
3621
 *
3622
 * Returns the nodes in @nodes that precede @node in document order,
3623
 *         @nodes if @node is NULL or an empty node-set if @nodes
3624
 *         doesn't contain @node
3625
 */
3626
xmlNodeSetPtr
3627
0
xmlXPathNodeLeading (xmlNodeSetPtr nodes, xmlNodePtr node) {
3628
0
    xmlXPathNodeSetSort(nodes);
3629
0
    return(xmlXPathNodeLeadingSorted(nodes, node));
3630
0
}
3631
3632
/**
3633
 * xmlXPathLeadingSorted:
3634
 * @nodes1:  a node-set, sorted by document order
3635
 * @nodes2:  a node-set, sorted by document order
3636
 *
3637
 * Implements the EXSLT - Sets leading() function:
3638
 *    node-set set:leading (node-set, node-set)
3639
 *
3640
 * Returns the nodes in @nodes1 that precede the first node in @nodes2
3641
 *         in document order, @nodes1 if @nodes2 is NULL or empty or
3642
 *         an empty node-set if @nodes1 doesn't contain @nodes2
3643
 */
3644
xmlNodeSetPtr
3645
0
xmlXPathLeadingSorted (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3646
0
    if (xmlXPathNodeSetIsEmpty(nodes2))
3647
0
  return(nodes1);
3648
0
    return(xmlXPathNodeLeadingSorted(nodes1,
3649
0
             xmlXPathNodeSetItem(nodes2, 1)));
3650
0
}
3651
3652
/**
3653
 * xmlXPathLeading:
3654
 * @nodes1:  a node-set
3655
 * @nodes2:  a node-set
3656
 *
3657
 * Implements the EXSLT - Sets leading() function:
3658
 *    node-set set:leading (node-set, node-set)
3659
 * @nodes1 and @nodes2 are sorted by document order, then
3660
 * #exslSetsLeadingSorted is called.
3661
 *
3662
 * Returns the nodes in @nodes1 that precede the first node in @nodes2
3663
 *         in document order, @nodes1 if @nodes2 is NULL or empty or
3664
 *         an empty node-set if @nodes1 doesn't contain @nodes2
3665
 */
3666
xmlNodeSetPtr
3667
0
xmlXPathLeading (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3668
0
    if (xmlXPathNodeSetIsEmpty(nodes2))
3669
0
  return(nodes1);
3670
0
    if (xmlXPathNodeSetIsEmpty(nodes1))
3671
0
  return(xmlXPathNodeSetCreate(NULL));
3672
0
    xmlXPathNodeSetSort(nodes1);
3673
0
    xmlXPathNodeSetSort(nodes2);
3674
0
    return(xmlXPathNodeLeadingSorted(nodes1,
3675
0
             xmlXPathNodeSetItem(nodes2, 1)));
3676
0
}
3677
3678
/**
3679
 * xmlXPathNodeTrailingSorted:
3680
 * @nodes: a node-set, sorted by document order
3681
 * @node: a node
3682
 *
3683
 * Implements the EXSLT - Sets trailing() function:
3684
 *    node-set set:trailing (node-set, node-set)
3685
 *
3686
 * Returns the nodes in @nodes that follow @node in document order,
3687
 *         @nodes if @node is NULL or an empty node-set if @nodes
3688
 *         doesn't contain @node
3689
 */
3690
xmlNodeSetPtr
3691
5.15k
xmlXPathNodeTrailingSorted (xmlNodeSetPtr nodes, xmlNodePtr node) {
3692
5.15k
    int i, l;
3693
5.15k
    xmlNodePtr cur;
3694
5.15k
    xmlNodeSetPtr ret;
3695
3696
5.15k
    if (node == NULL)
3697
0
  return(nodes);
3698
3699
5.15k
    ret = xmlXPathNodeSetCreate(NULL);
3700
5.15k
    if (ret == NULL)
3701
1
        return(ret);
3702
5.15k
    if (xmlXPathNodeSetIsEmpty(nodes) ||
3703
4.06k
  (!xmlXPathNodeSetContains(nodes, node)))
3704
3.75k
  return(ret);
3705
3706
1.40k
    l = xmlXPathNodeSetGetLength(nodes);
3707
34.6k
    for (i = l - 1; i >= 0; i--) {
3708
33.8k
  cur = xmlXPathNodeSetItem(nodes, i);
3709
33.8k
  if (cur == node)
3710
604
      break;
3711
33.2k
  if (xmlXPathNodeSetAddUnique(ret, cur) < 0) {
3712
3
            xmlXPathFreeNodeSet(ret);
3713
3
      return(NULL);
3714
3
        }
3715
33.2k
    }
3716
1.40k
    xmlXPathNodeSetSort(ret); /* bug 413451 */
3717
1.40k
    return(ret);
3718
1.40k
}
3719
3720
/**
3721
 * xmlXPathNodeTrailing:
3722
 * @nodes:  a node-set
3723
 * @node:  a node
3724
 *
3725
 * Implements the EXSLT - Sets trailing() function:
3726
 *    node-set set:trailing (node-set, node-set)
3727
 * @nodes is sorted by document order, then #xmlXPathNodeTrailingSorted
3728
 * is called.
3729
 *
3730
 * Returns the nodes in @nodes that follow @node in document order,
3731
 *         @nodes if @node is NULL or an empty node-set if @nodes
3732
 *         doesn't contain @node
3733
 */
3734
xmlNodeSetPtr
3735
0
xmlXPathNodeTrailing (xmlNodeSetPtr nodes, xmlNodePtr node) {
3736
0
    xmlXPathNodeSetSort(nodes);
3737
0
    return(xmlXPathNodeTrailingSorted(nodes, node));
3738
0
}
3739
3740
/**
3741
 * xmlXPathTrailingSorted:
3742
 * @nodes1:  a node-set, sorted by document order
3743
 * @nodes2:  a node-set, sorted by document order
3744
 *
3745
 * Implements the EXSLT - Sets trailing() function:
3746
 *    node-set set:trailing (node-set, node-set)
3747
 *
3748
 * Returns the nodes in @nodes1 that follow the first node in @nodes2
3749
 *         in document order, @nodes1 if @nodes2 is NULL or empty or
3750
 *         an empty node-set if @nodes1 doesn't contain @nodes2
3751
 */
3752
xmlNodeSetPtr
3753
0
xmlXPathTrailingSorted (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3754
0
    if (xmlXPathNodeSetIsEmpty(nodes2))
3755
0
  return(nodes1);
3756
0
    return(xmlXPathNodeTrailingSorted(nodes1,
3757
0
              xmlXPathNodeSetItem(nodes2, 0)));
3758
0
}
3759
3760
/**
3761
 * xmlXPathTrailing:
3762
 * @nodes1:  a node-set
3763
 * @nodes2:  a node-set
3764
 *
3765
 * Implements the EXSLT - Sets trailing() function:
3766
 *    node-set set:trailing (node-set, node-set)
3767
 * @nodes1 and @nodes2 are sorted by document order, then
3768
 * #xmlXPathTrailingSorted is called.
3769
 *
3770
 * Returns the nodes in @nodes1 that follow the first node in @nodes2
3771
 *         in document order, @nodes1 if @nodes2 is NULL or empty or
3772
 *         an empty node-set if @nodes1 doesn't contain @nodes2
3773
 */
3774
xmlNodeSetPtr
3775
0
xmlXPathTrailing (xmlNodeSetPtr nodes1, xmlNodeSetPtr nodes2) {
3776
0
    if (xmlXPathNodeSetIsEmpty(nodes2))
3777
0
  return(nodes1);
3778
0
    if (xmlXPathNodeSetIsEmpty(nodes1))
3779
0
  return(xmlXPathNodeSetCreate(NULL));
3780
0
    xmlXPathNodeSetSort(nodes1);
3781
0
    xmlXPathNodeSetSort(nodes2);
3782
0
    return(xmlXPathNodeTrailingSorted(nodes1,
3783
0
              xmlXPathNodeSetItem(nodes2, 0)));
3784
0
}
3785
3786
/************************************************************************
3787
 *                  *
3788
 *    Routines to handle extra functions      *
3789
 *                  *
3790
 ************************************************************************/
3791
3792
/**
3793
 * xmlXPathRegisterFunc:
3794
 * @ctxt:  the XPath context
3795
 * @name:  the function name
3796
 * @f:  the function implementation or NULL
3797
 *
3798
 * Register a new function. If @f is NULL it unregisters the function
3799
 *
3800
 * Returns 0 in case of success, -1 in case of error
3801
 */
3802
int
3803
xmlXPathRegisterFunc(xmlXPathContextPtr ctxt, const xmlChar *name,
3804
139k
         xmlXPathFunction f) {
3805
139k
    return(xmlXPathRegisterFuncNS(ctxt, name, NULL, f));
3806
139k
}
3807
3808
/**
3809
 * xmlXPathRegisterFuncNS:
3810
 * @ctxt:  the XPath context
3811
 * @name:  the function name
3812
 * @ns_uri:  the function namespace URI
3813
 * @f:  the function implementation or NULL
3814
 *
3815
 * Register a new function. If @f is NULL it unregisters the function
3816
 *
3817
 * Returns 0 in case of success, -1 in case of error
3818
 */
3819
int
3820
xmlXPathRegisterFuncNS(xmlXPathContextPtr ctxt, const xmlChar *name,
3821
139k
           const xmlChar *ns_uri, xmlXPathFunction f) {
3822
139k
    int ret;
3823
139k
    void *payload;
3824
3825
139k
    if (ctxt == NULL)
3826
0
  return(-1);
3827
139k
    if (name == NULL)
3828
0
  return(-1);
3829
3830
139k
    if (ctxt->funcHash == NULL)
3831
15.4k
  ctxt->funcHash = xmlHashCreate(0);
3832
139k
    if (ctxt->funcHash == NULL) {
3833
18
        xmlXPathErrMemory(ctxt);
3834
18
  return(-1);
3835
18
    }
3836
139k
    if (f == NULL)
3837
0
        return(xmlHashRemoveEntry2(ctxt->funcHash, name, ns_uri, NULL));
3838
139k
    memcpy(&payload, &f, sizeof(f));
3839
139k
    ret = xmlHashAddEntry2(ctxt->funcHash, name, ns_uri, payload);
3840
139k
    if (ret < 0) {
3841
66
        xmlXPathErrMemory(ctxt);
3842
66
        return(-1);
3843
66
    }
3844
3845
139k
    return(0);
3846
139k
}
3847
3848
/**
3849
 * xmlXPathRegisterFuncLookup:
3850
 * @ctxt:  the XPath context
3851
 * @f:  the lookup function
3852
 * @funcCtxt:  the lookup data
3853
 *
3854
 * Registers an external mechanism to do function lookup.
3855
 */
3856
void
3857
xmlXPathRegisterFuncLookup (xmlXPathContextPtr ctxt,
3858
          xmlXPathFuncLookupFunc f,
3859
15.4k
          void *funcCtxt) {
3860
15.4k
    if (ctxt == NULL)
3861
0
  return;
3862
15.4k
    ctxt->funcLookupFunc = f;
3863
15.4k
    ctxt->funcLookupData = funcCtxt;
3864
15.4k
}
3865
3866
/**
3867
 * xmlXPathFunctionLookup:
3868
 * @ctxt:  the XPath context
3869
 * @name:  the function name
3870
 *
3871
 * Search in the Function array of the context for the given
3872
 * function.
3873
 *
3874
 * Returns the xmlXPathFunction or NULL if not found
3875
 */
3876
xmlXPathFunction
3877
158k
xmlXPathFunctionLookup(xmlXPathContextPtr ctxt, const xmlChar *name) {
3878
158k
    return(xmlXPathFunctionLookupNS(ctxt, name, NULL));
3879
158k
}
3880
3881
/**
3882
 * xmlXPathFunctionLookupNS:
3883
 * @ctxt:  the XPath context
3884
 * @name:  the function name
3885
 * @ns_uri:  the function namespace URI
3886
 *
3887
 * Search in the Function array of the context for the given
3888
 * function.
3889
 *
3890
 * Returns the xmlXPathFunction or NULL if not found
3891
 */
3892
xmlXPathFunction
3893
xmlXPathFunctionLookupNS(xmlXPathContextPtr ctxt, const xmlChar *name,
3894
291k
       const xmlChar *ns_uri) {
3895
291k
    xmlXPathFunction ret;
3896
291k
    void *payload;
3897
3898
291k
    if (ctxt == NULL)
3899
0
  return(NULL);
3900
291k
    if (name == NULL)
3901
4
  return(NULL);
3902
3903
291k
    if (ns_uri == NULL) {
3904
159k
        int bucketIndex = xmlXPathSFComputeHash(name) % SF_HASH_SIZE;
3905
3906
253k
        while (xmlXPathSFHash[bucketIndex] != UCHAR_MAX) {
3907
136k
            int funcIndex = xmlXPathSFHash[bucketIndex];
3908
3909
136k
            if (strcmp(xmlXPathStandardFunctions[funcIndex].name,
3910
136k
                       (char *) name) == 0)
3911
42.6k
                return(xmlXPathStandardFunctions[funcIndex].func);
3912
3913
93.7k
            bucketIndex += 1;
3914
93.7k
            if (bucketIndex >= SF_HASH_SIZE)
3915
0
                bucketIndex = 0;
3916
93.7k
        }
3917
159k
    }
3918
3919
248k
    if (ctxt->funcLookupFunc != NULL) {
3920
248k
  xmlXPathFuncLookupFunc f;
3921
3922
248k
  f = ctxt->funcLookupFunc;
3923
248k
  ret = f(ctxt->funcLookupData, name, ns_uri);
3924
248k
  if (ret != NULL)
3925
130k
      return(ret);
3926
248k
    }
3927
3928
118k
    if (ctxt->funcHash == NULL)
3929
352
  return(NULL);
3930
3931
118k
    payload = xmlHashLookup2(ctxt->funcHash, name, ns_uri);
3932
118k
    memcpy(&ret, &payload, sizeof(payload));
3933
3934
118k
    return(ret);
3935
118k
}
3936
3937
/**
3938
 * xmlXPathRegisteredFuncsCleanup:
3939
 * @ctxt:  the XPath context
3940
 *
3941
 * Cleanup the XPath context data associated to registered functions
3942
 */
3943
void
3944
59.1k
xmlXPathRegisteredFuncsCleanup(xmlXPathContextPtr ctxt) {
3945
59.1k
    if (ctxt == NULL)
3946
0
  return;
3947
3948
59.1k
    xmlHashFree(ctxt->funcHash, NULL);
3949
59.1k
    ctxt->funcHash = NULL;
3950
59.1k
}
3951
3952
/************************************************************************
3953
 *                  *
3954
 *      Routines to handle Variables      *
3955
 *                  *
3956
 ************************************************************************/
3957
3958
/**
3959
 * xmlXPathRegisterVariable:
3960
 * @ctxt:  the XPath context
3961
 * @name:  the variable name
3962
 * @value:  the variable value or NULL
3963
 *
3964
 * Register a new variable value. If @value is NULL it unregisters
3965
 * the variable
3966
 *
3967
 * Returns 0 in case of success, -1 in case of error
3968
 */
3969
int
3970
xmlXPathRegisterVariable(xmlXPathContextPtr ctxt, const xmlChar *name,
3971
0
       xmlXPathObjectPtr value) {
3972
0
    return(xmlXPathRegisterVariableNS(ctxt, name, NULL, value));
3973
0
}
3974
3975
/**
3976
 * xmlXPathRegisterVariableNS:
3977
 * @ctxt:  the XPath context
3978
 * @name:  the variable name
3979
 * @ns_uri:  the variable namespace URI
3980
 * @value:  the variable value or NULL
3981
 *
3982
 * Register a new variable value. If @value is NULL it unregisters
3983
 * the variable
3984
 *
3985
 * Returns 0 in case of success, -1 in case of error
3986
 */
3987
int
3988
xmlXPathRegisterVariableNS(xmlXPathContextPtr ctxt, const xmlChar *name,
3989
         const xmlChar *ns_uri,
3990
0
         xmlXPathObjectPtr value) {
3991
0
    if (ctxt == NULL)
3992
0
  return(-1);
3993
0
    if (name == NULL)
3994
0
  return(-1);
3995
3996
0
    if (ctxt->varHash == NULL)
3997
0
  ctxt->varHash = xmlHashCreate(0);
3998
0
    if (ctxt->varHash == NULL)
3999
0
  return(-1);
4000
0
    if (value == NULL)
4001
0
        return(xmlHashRemoveEntry2(ctxt->varHash, name, ns_uri,
4002
0
                             xmlXPathFreeObjectEntry));
4003
0
    return(xmlHashUpdateEntry2(ctxt->varHash, name, ns_uri,
4004
0
             (void *) value, xmlXPathFreeObjectEntry));
4005
0
}
4006
4007
/**
4008
 * xmlXPathRegisterVariableLookup:
4009
 * @ctxt:  the XPath context
4010
 * @f:  the lookup function
4011
 * @data:  the lookup data
4012
 *
4013
 * register an external mechanism to do variable lookup
4014
 */
4015
void
4016
xmlXPathRegisterVariableLookup(xmlXPathContextPtr ctxt,
4017
15.4k
   xmlXPathVariableLookupFunc f, void *data) {
4018
15.4k
    if (ctxt == NULL)
4019
0
  return;
4020
15.4k
    ctxt->varLookupFunc = f;
4021
15.4k
    ctxt->varLookupData = data;
4022
15.4k
}
4023
4024
/**
4025
 * xmlXPathVariableLookup:
4026
 * @ctxt:  the XPath context
4027
 * @name:  the variable name
4028
 *
4029
 * Search in the Variable array of the context for the given
4030
 * variable value.
4031
 *
4032
 * Returns a copy of the value or NULL if not found
4033
 */
4034
xmlXPathObjectPtr
4035
65.7k
xmlXPathVariableLookup(xmlXPathContextPtr ctxt, const xmlChar *name) {
4036
65.7k
    if (ctxt == NULL)
4037
0
  return(NULL);
4038
4039
65.7k
    if (ctxt->varLookupFunc != NULL) {
4040
65.5k
  xmlXPathObjectPtr ret;
4041
4042
65.5k
  ret = ((xmlXPathVariableLookupFunc)ctxt->varLookupFunc)
4043
65.5k
          (ctxt->varLookupData, name, NULL);
4044
65.5k
  return(ret);
4045
65.5k
    }
4046
250
    return(xmlXPathVariableLookupNS(ctxt, name, NULL));
4047
65.7k
}
4048
4049
/**
4050
 * xmlXPathVariableLookupNS:
4051
 * @ctxt:  the XPath context
4052
 * @name:  the variable name
4053
 * @ns_uri:  the variable namespace URI
4054
 *
4055
 * Search in the Variable array of the context for the given
4056
 * variable value.
4057
 *
4058
 * Returns the a copy of the value or NULL if not found
4059
 */
4060
xmlXPathObjectPtr
4061
xmlXPathVariableLookupNS(xmlXPathContextPtr ctxt, const xmlChar *name,
4062
988
       const xmlChar *ns_uri) {
4063
988
    if (ctxt == NULL)
4064
0
  return(NULL);
4065
4066
988
    if (ctxt->varLookupFunc != NULL) {
4067
528
  xmlXPathObjectPtr ret;
4068
4069
528
  ret = ((xmlXPathVariableLookupFunc)ctxt->varLookupFunc)
4070
528
          (ctxt->varLookupData, name, ns_uri);
4071
528
  if (ret != NULL) return(ret);
4072
528
    }
4073
4074
988
    if (ctxt->varHash == NULL)
4075
988
  return(NULL);
4076
0
    if (name == NULL)
4077
0
  return(NULL);
4078
4079
0
    return(xmlXPathObjectCopy(xmlHashLookup2(ctxt->varHash, name, ns_uri)));
4080
0
}
4081
4082
/**
4083
 * xmlXPathRegisteredVariablesCleanup:
4084
 * @ctxt:  the XPath context
4085
 *
4086
 * Cleanup the XPath context data associated to registered variables
4087
 */
4088
void
4089
59.1k
xmlXPathRegisteredVariablesCleanup(xmlXPathContextPtr ctxt) {
4090
59.1k
    if (ctxt == NULL)
4091
0
  return;
4092
4093
59.1k
    xmlHashFree(ctxt->varHash, xmlXPathFreeObjectEntry);
4094
59.1k
    ctxt->varHash = NULL;
4095
59.1k
}
4096
4097
/**
4098
 * xmlXPathRegisterNs:
4099
 * @ctxt:  the XPath context
4100
 * @prefix:  the namespace prefix cannot be NULL or empty string
4101
 * @ns_uri:  the namespace name
4102
 *
4103
 * Register a new namespace. If @ns_uri is NULL it unregisters
4104
 * the namespace
4105
 *
4106
 * Returns 0 in case of success, -1 in case of error
4107
 */
4108
int
4109
xmlXPathRegisterNs(xmlXPathContextPtr ctxt, const xmlChar *prefix,
4110
2.32k
         const xmlChar *ns_uri) {
4111
2.32k
    xmlChar *copy;
4112
4113
2.32k
    if (ctxt == NULL)
4114
0
  return(-1);
4115
2.32k
    if (prefix == NULL)
4116
0
  return(-1);
4117
2.32k
    if (prefix[0] == 0)
4118
0
  return(-1);
4119
4120
2.32k
    if (ctxt->nsHash == NULL)
4121
1.63k
  ctxt->nsHash = xmlHashCreate(10);
4122
2.32k
    if (ctxt->nsHash == NULL) {
4123
1
        xmlXPathErrMemory(ctxt);
4124
1
  return(-1);
4125
1
    }
4126
2.32k
    if (ns_uri == NULL)
4127
0
        return(xmlHashRemoveEntry(ctxt->nsHash, prefix,
4128
0
                            xmlHashDefaultDeallocator));
4129
4130
2.32k
    copy = xmlStrdup(ns_uri);
4131
2.32k
    if (copy == NULL) {
4132
2
        xmlXPathErrMemory(ctxt);
4133
2
        return(-1);
4134
2
    }
4135
2.32k
    if (xmlHashUpdateEntry(ctxt->nsHash, prefix, copy,
4136
2.32k
                           xmlHashDefaultDeallocator) < 0) {
4137
1
        xmlXPathErrMemory(ctxt);
4138
1
        xmlFree(copy);
4139
1
        return(-1);
4140
1
    }
4141
4142
2.32k
    return(0);
4143
2.32k
}
4144
4145
/**
4146
 * xmlXPathNsLookup:
4147
 * @ctxt:  the XPath context
4148
 * @prefix:  the namespace prefix value
4149
 *
4150
 * Search in the namespace declaration array of the context for the given
4151
 * namespace name associated to the given prefix
4152
 *
4153
 * Returns the value or NULL if not found
4154
 */
4155
const xmlChar *
4156
517k
xmlXPathNsLookup(xmlXPathContextPtr ctxt, const xmlChar *prefix) {
4157
517k
    if (ctxt == NULL)
4158
0
  return(NULL);
4159
517k
    if (prefix == NULL)
4160
0
  return(NULL);
4161
4162
517k
    if (xmlStrEqual(prefix, (const xmlChar *) "xml"))
4163
3.81k
  return(XML_XML_NAMESPACE);
4164
4165
513k
    if (ctxt->namespaces != NULL) {
4166
512k
  int i;
4167
4168
3.79M
  for (i = 0;i < ctxt->nsNr;i++) {
4169
3.68M
      if ((ctxt->namespaces[i] != NULL) &&
4170
3.68M
    (xmlStrEqual(ctxt->namespaces[i]->prefix, prefix)))
4171
397k
    return(ctxt->namespaces[i]->href);
4172
3.68M
  }
4173
512k
    }
4174
4175
116k
    return((const xmlChar *) xmlHashLookup(ctxt->nsHash, prefix));
4176
513k
}
4177
4178
/**
4179
 * xmlXPathRegisteredNsCleanup:
4180
 * @ctxt:  the XPath context
4181
 *
4182
 * Cleanup the XPath context data associated to registered variables
4183
 */
4184
void
4185
59.1k
xmlXPathRegisteredNsCleanup(xmlXPathContextPtr ctxt) {
4186
59.1k
    if (ctxt == NULL)
4187
0
  return;
4188
4189
59.1k
    xmlHashFree(ctxt->nsHash, xmlHashDefaultDeallocator);
4190
59.1k
    ctxt->nsHash = NULL;
4191
59.1k
}
4192
4193
/************************************************************************
4194
 *                  *
4195
 *      Routines to handle Values     *
4196
 *                  *
4197
 ************************************************************************/
4198
4199
/* Allocations are terrible, one needs to optimize all this !!! */
4200
4201
/**
4202
 * xmlXPathNewFloat:
4203
 * @val:  the double value
4204
 *
4205
 * Create a new xmlXPathObjectPtr of type double and of value @val
4206
 *
4207
 * Returns the newly created object.
4208
 */
4209
xmlXPathObjectPtr
4210
489k
xmlXPathNewFloat(double val) {
4211
489k
    xmlXPathObjectPtr ret;
4212
4213
489k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4214
489k
    if (ret == NULL)
4215
2.07k
  return(NULL);
4216
487k
    memset(ret, 0 , sizeof(xmlXPathObject));
4217
487k
    ret->type = XPATH_NUMBER;
4218
487k
    ret->floatval = val;
4219
487k
    return(ret);
4220
489k
}
4221
4222
/**
4223
 * xmlXPathNewBoolean:
4224
 * @val:  the boolean value
4225
 *
4226
 * Create a new xmlXPathObjectPtr of type boolean and of value @val
4227
 *
4228
 * Returns the newly created object.
4229
 */
4230
xmlXPathObjectPtr
4231
122k
xmlXPathNewBoolean(int val) {
4232
122k
    xmlXPathObjectPtr ret;
4233
4234
122k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4235
122k
    if (ret == NULL)
4236
1.14k
  return(NULL);
4237
121k
    memset(ret, 0 , sizeof(xmlXPathObject));
4238
121k
    ret->type = XPATH_BOOLEAN;
4239
121k
    ret->boolval = (val != 0);
4240
121k
    return(ret);
4241
122k
}
4242
4243
/**
4244
 * xmlXPathNewString:
4245
 * @val:  the xmlChar * value
4246
 *
4247
 * Create a new xmlXPathObjectPtr of type string and of value @val
4248
 *
4249
 * Returns the newly created object.
4250
 */
4251
xmlXPathObjectPtr
4252
150k
xmlXPathNewString(const xmlChar *val) {
4253
150k
    xmlXPathObjectPtr ret;
4254
4255
150k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4256
150k
    if (ret == NULL)
4257
9.21k
  return(NULL);
4258
141k
    memset(ret, 0 , sizeof(xmlXPathObject));
4259
141k
    ret->type = XPATH_STRING;
4260
141k
    if (val == NULL)
4261
47
        val = BAD_CAST "";
4262
141k
    ret->stringval = xmlStrdup(val);
4263
141k
    if (ret->stringval == NULL) {
4264
90
        xmlFree(ret);
4265
90
        return(NULL);
4266
90
    }
4267
141k
    return(ret);
4268
141k
}
4269
4270
/**
4271
 * xmlXPathWrapString:
4272
 * @val:  the xmlChar * value
4273
 *
4274
 * Wraps the @val string into an XPath object.
4275
 *
4276
 * Returns the newly created object.
4277
 *
4278
 * Frees @val in case of error.
4279
 */
4280
xmlXPathObjectPtr
4281
177k
xmlXPathWrapString (xmlChar *val) {
4282
177k
    xmlXPathObjectPtr ret;
4283
4284
177k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4285
177k
    if (ret == NULL) {
4286
1.18k
        xmlFree(val);
4287
1.18k
  return(NULL);
4288
1.18k
    }
4289
176k
    memset(ret, 0 , sizeof(xmlXPathObject));
4290
176k
    ret->type = XPATH_STRING;
4291
176k
    ret->stringval = val;
4292
176k
    return(ret);
4293
177k
}
4294
4295
/**
4296
 * xmlXPathNewCString:
4297
 * @val:  the char * value
4298
 *
4299
 * Create a new xmlXPathObjectPtr of type string and of value @val
4300
 *
4301
 * Returns the newly created object.
4302
 */
4303
xmlXPathObjectPtr
4304
55.9k
xmlXPathNewCString(const char *val) {
4305
55.9k
    return(xmlXPathNewString(BAD_CAST val));
4306
55.9k
}
4307
4308
/**
4309
 * xmlXPathWrapCString:
4310
 * @val:  the char * value
4311
 *
4312
 * Wraps a string into an XPath object.
4313
 *
4314
 * Returns the newly created object.
4315
 */
4316
xmlXPathObjectPtr
4317
0
xmlXPathWrapCString (char * val) {
4318
0
    return(xmlXPathWrapString((xmlChar *)(val)));
4319
0
}
4320
4321
/**
4322
 * xmlXPathWrapExternal:
4323
 * @val:  the user data
4324
 *
4325
 * Wraps the @val data into an XPath object.
4326
 *
4327
 * Returns the newly created object.
4328
 */
4329
xmlXPathObjectPtr
4330
6.86k
xmlXPathWrapExternal (void *val) {
4331
6.86k
    xmlXPathObjectPtr ret;
4332
4333
6.86k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4334
6.86k
    if (ret == NULL)
4335
4
  return(NULL);
4336
6.85k
    memset(ret, 0 , sizeof(xmlXPathObject));
4337
6.85k
    ret->type = XPATH_USERS;
4338
6.85k
    ret->user = val;
4339
6.85k
    return(ret);
4340
6.86k
}
4341
4342
/**
4343
 * xmlXPathObjectCopy:
4344
 * @val:  the original object
4345
 *
4346
 * allocate a new copy of a given object
4347
 *
4348
 * Returns the newly created object.
4349
 */
4350
xmlXPathObjectPtr
4351
324k
xmlXPathObjectCopy(xmlXPathObjectPtr val) {
4352
324k
    xmlXPathObjectPtr ret;
4353
4354
324k
    if (val == NULL)
4355
92
  return(NULL);
4356
4357
324k
    ret = (xmlXPathObjectPtr) xmlMalloc(sizeof(xmlXPathObject));
4358
324k
    if (ret == NULL)
4359
12.5k
  return(NULL);
4360
312k
    memcpy(ret, val , sizeof(xmlXPathObject));
4361
312k
    switch (val->type) {
4362
780
  case XPATH_BOOLEAN:
4363
4.70k
  case XPATH_NUMBER:
4364
4.70k
      break;
4365
9.72k
  case XPATH_STRING:
4366
9.72k
      ret->stringval = xmlStrdup(val->stringval);
4367
9.72k
            if (ret->stringval == NULL) {
4368
4
                xmlFree(ret);
4369
4
                return(NULL);
4370
4
            }
4371
9.72k
      break;
4372
24.2k
  case XPATH_XSLT_TREE:
4373
297k
  case XPATH_NODESET:
4374
297k
      ret->nodesetval = xmlXPathNodeSetMerge(NULL, val->nodesetval);
4375
297k
            if (ret->nodesetval == NULL) {
4376
73
                xmlFree(ret);
4377
73
                return(NULL);
4378
73
            }
4379
      /* Do not deallocate the copied tree value */
4380
297k
      ret->boolval = 0;
4381
297k
      break;
4382
0
        case XPATH_USERS:
4383
0
      ret->user = val->user;
4384
0
      break;
4385
0
        default:
4386
0
            xmlFree(ret);
4387
0
            ret = NULL;
4388
0
      break;
4389
312k
    }
4390
312k
    return(ret);
4391
312k
}
4392
4393
/**
4394
 * xmlXPathFreeObject:
4395
 * @obj:  the object to free
4396
 *
4397
 * Free up an xmlXPathObjectPtr object.
4398
 */
4399
void
4400
4.06M
xmlXPathFreeObject(xmlXPathObjectPtr obj) {
4401
4.06M
    if (obj == NULL) return;
4402
4.03M
    if ((obj->type == XPATH_NODESET) || (obj->type == XPATH_XSLT_TREE)) {
4403
2.55M
        if (obj->nodesetval != NULL)
4404
2.47M
            xmlXPathFreeNodeSet(obj->nodesetval);
4405
2.55M
    } else if (obj->type == XPATH_STRING) {
4406
572k
  if (obj->stringval != NULL)
4407
542k
      xmlFree(obj->stringval);
4408
572k
    }
4409
4.03M
    xmlFree(obj);
4410
4.03M
}
4411
4412
static void
4413
0
xmlXPathFreeObjectEntry(void *obj, const xmlChar *name ATTRIBUTE_UNUSED) {
4414
0
    xmlXPathFreeObject((xmlXPathObjectPtr) obj);
4415
0
}
4416
4417
/**
4418
 * xmlXPathReleaseObject:
4419
 * @obj:  the xmlXPathObjectPtr to free or to cache
4420
 *
4421
 * Depending on the state of the cache this frees the given
4422
 * XPath object or stores it in the cache.
4423
 */
4424
static void
4425
xmlXPathReleaseObject(xmlXPathContextPtr ctxt, xmlXPathObjectPtr obj)
4426
12.4M
{
4427
12.4M
    if (obj == NULL)
4428
10.3k
  return;
4429
12.4M
    if ((ctxt == NULL) || (ctxt->cache == NULL)) {
4430
33.8k
   xmlXPathFreeObject(obj);
4431
12.3M
    } else {
4432
12.3M
  xmlXPathContextCachePtr cache =
4433
12.3M
      (xmlXPathContextCachePtr) ctxt->cache;
4434
4435
12.3M
  switch (obj->type) {
4436
10.0M
      case XPATH_NODESET:
4437
10.0M
      case XPATH_XSLT_TREE:
4438
10.0M
    if (obj->nodesetval != NULL) {
4439
9.36M
        if ((obj->nodesetval->nodeMax <= 40) &&
4440
9.28M
      (cache->numNodeset < cache->maxNodeset)) {
4441
6.37M
                        obj->stringval = (void *) cache->nodesetObjs;
4442
6.37M
                        cache->nodesetObjs = obj;
4443
6.37M
                        cache->numNodeset += 1;
4444
6.37M
      goto obj_cached;
4445
6.37M
        } else {
4446
2.99M
      xmlXPathFreeNodeSet(obj->nodesetval);
4447
2.99M
      obj->nodesetval = NULL;
4448
2.99M
        }
4449
9.36M
    }
4450
3.65M
    break;
4451
3.65M
      case XPATH_STRING:
4452
500k
    if (obj->stringval != NULL)
4453
499k
        xmlFree(obj->stringval);
4454
500k
                obj->stringval = NULL;
4455
500k
    break;
4456
699k
      case XPATH_BOOLEAN:
4457
1.84M
      case XPATH_NUMBER:
4458
1.84M
    break;
4459
3.57k
      default:
4460
3.57k
    goto free_obj;
4461
12.3M
  }
4462
4463
  /*
4464
  * Fallback to adding to the misc-objects slot.
4465
  */
4466
6.00M
        if (cache->numMisc >= cache->maxMisc)
4467
58.0k
      goto free_obj;
4468
5.94M
        obj->stringval = (void *) cache->miscObjs;
4469
5.94M
        cache->miscObjs = obj;
4470
5.94M
        cache->numMisc += 1;
4471
4472
12.3M
obj_cached:
4473
12.3M
        obj->boolval = 0;
4474
12.3M
  if (obj->nodesetval != NULL) {
4475
6.37M
      xmlNodeSetPtr tmpset = obj->nodesetval;
4476
4477
      /*
4478
      * Due to those nasty ns-nodes, we need to traverse
4479
      * the list and free the ns-nodes.
4480
      */
4481
6.37M
      if (tmpset->nodeNr > 0) {
4482
5.94M
    int i;
4483
5.94M
    xmlNodePtr node;
4484
4485
14.7M
    for (i = 0; i < tmpset->nodeNr; i++) {
4486
8.81M
        node = tmpset->nodeTab[i];
4487
8.81M
        if ((node != NULL) &&
4488
8.81M
      (node->type == XML_NAMESPACE_DECL))
4489
211k
        {
4490
211k
      xmlXPathNodeSetFreeNs((xmlNsPtr) node);
4491
211k
        }
4492
8.81M
    }
4493
5.94M
      }
4494
6.37M
      tmpset->nodeNr = 0;
4495
6.37M
        }
4496
4497
12.3M
  return;
4498
4499
61.6k
free_obj:
4500
  /*
4501
  * Cache is full; free the object.
4502
  */
4503
61.6k
  if (obj->nodesetval != NULL)
4504
0
      xmlXPathFreeNodeSet(obj->nodesetval);
4505
61.6k
  xmlFree(obj);
4506
61.6k
    }
4507
12.4M
}
4508
4509
4510
/************************************************************************
4511
 *                  *
4512
 *      Type Casting Routines       *
4513
 *                  *
4514
 ************************************************************************/
4515
4516
/**
4517
 * xmlXPathCastBooleanToString:
4518
 * @val:  a boolean
4519
 *
4520
 * Converts a boolean to its string value.
4521
 *
4522
 * Returns a newly allocated string.
4523
 */
4524
xmlChar *
4525
49.8k
xmlXPathCastBooleanToString (int val) {
4526
49.8k
    xmlChar *ret;
4527
49.8k
    if (val)
4528
8.46k
  ret = xmlStrdup((const xmlChar *) "true");
4529
41.3k
    else
4530
41.3k
  ret = xmlStrdup((const xmlChar *) "false");
4531
49.8k
    return(ret);
4532
49.8k
}
4533
4534
/**
4535
 * xmlXPathCastNumberToString:
4536
 * @val:  a number
4537
 *
4538
 * Converts a number to its string value.
4539
 *
4540
 * Returns a newly allocated string.
4541
 */
4542
xmlChar *
4543
338k
xmlXPathCastNumberToString (double val) {
4544
338k
    xmlChar *ret;
4545
338k
    switch (xmlXPathIsInf(val)) {
4546
269
    case 1:
4547
269
  ret = xmlStrdup((const xmlChar *) "Infinity");
4548
269
  break;
4549
3.39k
    case -1:
4550
3.39k
  ret = xmlStrdup((const xmlChar *) "-Infinity");
4551
3.39k
  break;
4552
334k
    default:
4553
334k
  if (xmlXPathIsNaN(val)) {
4554
139k
      ret = xmlStrdup((const xmlChar *) "NaN");
4555
195k
  } else if (val == 0) {
4556
            /* Omit sign for negative zero. */
4557
47.1k
      ret = xmlStrdup((const xmlChar *) "0");
4558
148k
  } else {
4559
      /* could be improved */
4560
148k
      char buf[100];
4561
148k
      xmlXPathFormatNumber(val, buf, 99);
4562
148k
      buf[99] = 0;
4563
148k
      ret = xmlStrdup((const xmlChar *) buf);
4564
148k
  }
4565
338k
    }
4566
338k
    return(ret);
4567
338k
}
4568
4569
/**
4570
 * xmlXPathCastNodeToString:
4571
 * @node:  a node
4572
 *
4573
 * Converts a node to its string value.
4574
 *
4575
 * Returns a newly allocated string.
4576
 */
4577
xmlChar *
4578
1.62M
xmlXPathCastNodeToString (xmlNodePtr node) {
4579
1.62M
    return(xmlNodeGetContent(node));
4580
1.62M
}
4581
4582
/**
4583
 * xmlXPathCastNodeSetToString:
4584
 * @ns:  a node-set
4585
 *
4586
 * Converts a node-set to its string value.
4587
 *
4588
 * Returns a newly allocated string.
4589
 */
4590
xmlChar *
4591
2.03M
xmlXPathCastNodeSetToString (xmlNodeSetPtr ns) {
4592
2.03M
    if ((ns == NULL) || (ns->nodeNr == 0) || (ns->nodeTab == NULL))
4593
727k
  return(xmlStrdup((const xmlChar *) ""));
4594
4595
1.30M
    if (ns->nodeNr > 1)
4596
45.4k
  xmlXPathNodeSetSort(ns);
4597
1.30M
    return(xmlXPathCastNodeToString(ns->nodeTab[0]));
4598
2.03M
}
4599
4600
/**
4601
 * xmlXPathCastToString:
4602
 * @val:  an XPath object
4603
 *
4604
 * Converts an existing object to its string() equivalent
4605
 *
4606
 * Returns the allocated string value of the object, NULL in case of error.
4607
 *         It's up to the caller to free the string memory with xmlFree().
4608
 */
4609
xmlChar *
4610
1.36M
xmlXPathCastToString(xmlXPathObjectPtr val) {
4611
1.36M
    xmlChar *ret = NULL;
4612
4613
1.36M
    if (val == NULL)
4614
0
  return(xmlStrdup((const xmlChar *) ""));
4615
1.36M
    switch (val->type) {
4616
0
  case XPATH_UNDEFINED:
4617
0
      ret = xmlStrdup((const xmlChar *) "");
4618
0
      break;
4619
1.12M
        case XPATH_NODESET:
4620
1.12M
        case XPATH_XSLT_TREE:
4621
1.12M
      ret = xmlXPathCastNodeSetToString(val->nodesetval);
4622
1.12M
      break;
4623
97.4k
  case XPATH_STRING:
4624
97.4k
      return(xmlStrdup(val->stringval));
4625
49.2k
        case XPATH_BOOLEAN:
4626
49.2k
      ret = xmlXPathCastBooleanToString(val->boolval);
4627
49.2k
      break;
4628
86.1k
  case XPATH_NUMBER: {
4629
86.1k
      ret = xmlXPathCastNumberToString(val->floatval);
4630
86.1k
      break;
4631
1.12M
  }
4632
3.27k
  case XPATH_USERS:
4633
      /* TODO */
4634
3.27k
      ret = xmlStrdup((const xmlChar *) "");
4635
3.27k
      break;
4636
1.36M
    }
4637
1.26M
    return(ret);
4638
1.36M
}
4639
4640
/**
4641
 * xmlXPathConvertString:
4642
 * @val:  an XPath object
4643
 *
4644
 * Converts an existing object to its string() equivalent
4645
 *
4646
 * Returns the new object, the old one is freed (or the operation
4647
 *         is done directly on @val)
4648
 */
4649
xmlXPathObjectPtr
4650
96.6k
xmlXPathConvertString(xmlXPathObjectPtr val) {
4651
96.6k
    xmlChar *res = NULL;
4652
4653
96.6k
    if (val == NULL)
4654
0
  return(xmlXPathNewCString(""));
4655
4656
96.6k
    switch (val->type) {
4657
0
    case XPATH_UNDEFINED:
4658
0
  break;
4659
95.4k
    case XPATH_NODESET:
4660
95.5k
    case XPATH_XSLT_TREE:
4661
95.5k
  res = xmlXPathCastNodeSetToString(val->nodesetval);
4662
95.5k
  break;
4663
0
    case XPATH_STRING:
4664
0
  return(val);
4665
635
    case XPATH_BOOLEAN:
4666
635
  res = xmlXPathCastBooleanToString(val->boolval);
4667
635
  break;
4668
517
    case XPATH_NUMBER:
4669
517
  res = xmlXPathCastNumberToString(val->floatval);
4670
517
  break;
4671
0
    case XPATH_USERS:
4672
  /* TODO */
4673
0
  break;
4674
96.6k
    }
4675
96.6k
    xmlXPathFreeObject(val);
4676
96.6k
    if (res == NULL)
4677
119
  return(xmlXPathNewCString(""));
4678
96.5k
    return(xmlXPathWrapString(res));
4679
96.6k
}
4680
4681
/**
4682
 * xmlXPathCastBooleanToNumber:
4683
 * @val:  a boolean
4684
 *
4685
 * Converts a boolean to its number value
4686
 *
4687
 * Returns the number value
4688
 */
4689
double
4690
127k
xmlXPathCastBooleanToNumber(int val) {
4691
127k
    if (val)
4692
22.0k
  return(1.0);
4693
105k
    return(0.0);
4694
127k
}
4695
4696
/**
4697
 * xmlXPathCastStringToNumber:
4698
 * @val:  a string
4699
 *
4700
 * Converts a string to its number value
4701
 *
4702
 * Returns the number value
4703
 */
4704
double
4705
1.06M
xmlXPathCastStringToNumber(const xmlChar * val) {
4706
1.06M
    return(xmlXPathStringEvalNumber(val));
4707
1.06M
}
4708
4709
/**
4710
 * xmlXPathNodeToNumberInternal:
4711
 * @node:  a node
4712
 *
4713
 * Converts a node to its number value
4714
 *
4715
 * Returns the number value
4716
 */
4717
static double
4718
53.5k
xmlXPathNodeToNumberInternal(xmlXPathParserContextPtr ctxt, xmlNodePtr node) {
4719
53.5k
    xmlChar *strval;
4720
53.5k
    double ret;
4721
4722
53.5k
    if (node == NULL)
4723
0
  return(xmlXPathNAN);
4724
53.5k
    strval = xmlXPathCastNodeToString(node);
4725
53.5k
    if (strval == NULL) {
4726
935
        xmlXPathPErrMemory(ctxt);
4727
935
  return(xmlXPathNAN);
4728
935
    }
4729
52.6k
    ret = xmlXPathCastStringToNumber(strval);
4730
52.6k
    xmlFree(strval);
4731
4732
52.6k
    return(ret);
4733
53.5k
}
4734
4735
/**
4736
 * xmlXPathCastNodeToNumber:
4737
 * @node:  a node
4738
 *
4739
 * Converts a node to its number value
4740
 *
4741
 * Returns the number value
4742
 */
4743
double
4744
10.4k
xmlXPathCastNodeToNumber (xmlNodePtr node) {
4745
10.4k
    return(xmlXPathNodeToNumberInternal(NULL, node));
4746
10.4k
}
4747
4748
/**
4749
 * xmlXPathCastNodeSetToNumber:
4750
 * @ns:  a node-set
4751
 *
4752
 * Converts a node-set to its number value
4753
 *
4754
 * Returns the number value
4755
 */
4756
double
4757
0
xmlXPathCastNodeSetToNumber (xmlNodeSetPtr ns) {
4758
0
    xmlChar *str;
4759
0
    double ret;
4760
4761
0
    if (ns == NULL)
4762
0
  return(xmlXPathNAN);
4763
0
    str = xmlXPathCastNodeSetToString(ns);
4764
0
    ret = xmlXPathCastStringToNumber(str);
4765
0
    xmlFree(str);
4766
0
    return(ret);
4767
0
}
4768
4769
/**
4770
 * xmlXPathCastToNumber:
4771
 * @val:  an XPath object
4772
 *
4773
 * Converts an XPath object to its number value
4774
 *
4775
 * Returns the number value
4776
 */
4777
double
4778
0
xmlXPathCastToNumber(xmlXPathObjectPtr val) {
4779
0
    return(xmlXPathCastToNumberInternal(NULL, val));
4780
0
}
4781
4782
/**
4783
 * xmlXPathConvertNumber:
4784
 * @val:  an XPath object
4785
 *
4786
 * Converts an existing object to its number() equivalent
4787
 *
4788
 * Returns the new object, the old one is freed (or the operation
4789
 *         is done directly on @val)
4790
 */
4791
xmlXPathObjectPtr
4792
0
xmlXPathConvertNumber(xmlXPathObjectPtr val) {
4793
0
    xmlXPathObjectPtr ret;
4794
4795
0
    if (val == NULL)
4796
0
  return(xmlXPathNewFloat(0.0));
4797
0
    if (val->type == XPATH_NUMBER)
4798
0
  return(val);
4799
0
    ret = xmlXPathNewFloat(xmlXPathCastToNumber(val));
4800
0
    xmlXPathFreeObject(val);
4801
0
    return(ret);
4802
0
}
4803
4804
/**
4805
 * xmlXPathCastNumberToBoolean:
4806
 * @val:  a number
4807
 *
4808
 * Converts a number to its boolean value
4809
 *
4810
 * Returns the boolean value
4811
 */
4812
int
4813
120k
xmlXPathCastNumberToBoolean (double val) {
4814
120k
     if (xmlXPathIsNaN(val) || (val == 0.0))
4815
63.9k
   return(0);
4816
57.0k
     return(1);
4817
120k
}
4818
4819
/**
4820
 * xmlXPathCastStringToBoolean:
4821
 * @val:  a string
4822
 *
4823
 * Converts a string to its boolean value
4824
 *
4825
 * Returns the boolean value
4826
 */
4827
int
4828
46.9k
xmlXPathCastStringToBoolean (const xmlChar *val) {
4829
46.9k
    if ((val == NULL) || (xmlStrlen(val) == 0))
4830
13.3k
  return(0);
4831
33.6k
    return(1);
4832
46.9k
}
4833
4834
/**
4835
 * xmlXPathCastNodeSetToBoolean:
4836
 * @ns:  a node-set
4837
 *
4838
 * Converts a node-set to its boolean value
4839
 *
4840
 * Returns the boolean value
4841
 */
4842
int
4843
123k
xmlXPathCastNodeSetToBoolean (xmlNodeSetPtr ns) {
4844
123k
    if ((ns == NULL) || (ns->nodeNr == 0))
4845
101k
  return(0);
4846
21.2k
    return(1);
4847
123k
}
4848
4849
/**
4850
 * xmlXPathCastToBoolean:
4851
 * @val:  an XPath object
4852
 *
4853
 * Converts an XPath object to its boolean value
4854
 *
4855
 * Returns the boolean value
4856
 */
4857
int
4858
229k
xmlXPathCastToBoolean (xmlXPathObjectPtr val) {
4859
229k
    int ret = 0;
4860
4861
229k
    if (val == NULL)
4862
0
  return(0);
4863
229k
    switch (val->type) {
4864
0
    case XPATH_UNDEFINED:
4865
0
  ret = 0;
4866
0
  break;
4867
122k
    case XPATH_NODESET:
4868
123k
    case XPATH_XSLT_TREE:
4869
123k
  ret = xmlXPathCastNodeSetToBoolean(val->nodesetval);
4870
123k
  break;
4871
46.9k
    case XPATH_STRING:
4872
46.9k
  ret = xmlXPathCastStringToBoolean(val->stringval);
4873
46.9k
  break;
4874
59.5k
    case XPATH_NUMBER:
4875
59.5k
  ret = xmlXPathCastNumberToBoolean(val->floatval);
4876
59.5k
  break;
4877
0
    case XPATH_BOOLEAN:
4878
0
  ret = val->boolval;
4879
0
  break;
4880
142
    case XPATH_USERS:
4881
  /* TODO */
4882
142
  ret = 0;
4883
142
  break;
4884
229k
    }
4885
229k
    return(ret);
4886
229k
}
4887
4888
4889
/**
4890
 * xmlXPathConvertBoolean:
4891
 * @val:  an XPath object
4892
 *
4893
 * Converts an existing object to its boolean() equivalent
4894
 *
4895
 * Returns the new object, the old one is freed (or the operation
4896
 *         is done directly on @val)
4897
 */
4898
xmlXPathObjectPtr
4899
0
xmlXPathConvertBoolean(xmlXPathObjectPtr val) {
4900
0
    xmlXPathObjectPtr ret;
4901
4902
0
    if (val == NULL)
4903
0
  return(xmlXPathNewBoolean(0));
4904
0
    if (val->type == XPATH_BOOLEAN)
4905
0
  return(val);
4906
0
    ret = xmlXPathNewBoolean(xmlXPathCastToBoolean(val));
4907
0
    xmlXPathFreeObject(val);
4908
0
    return(ret);
4909
0
}
4910
4911
/************************************************************************
4912
 *                  *
4913
 *    Routines to handle XPath contexts     *
4914
 *                  *
4915
 ************************************************************************/
4916
4917
/**
4918
 * xmlXPathNewContext:
4919
 * @doc:  the XML document
4920
 *
4921
 * Create a new xmlXPathContext
4922
 *
4923
 * Returns the xmlXPathContext just allocated. The caller will need to free it.
4924
 */
4925
xmlXPathContextPtr
4926
59.1k
xmlXPathNewContext(xmlDocPtr doc) {
4927
59.1k
    xmlXPathContextPtr ret;
4928
4929
59.1k
    ret = (xmlXPathContextPtr) xmlMalloc(sizeof(xmlXPathContext));
4930
59.1k
    if (ret == NULL)
4931
10
  return(NULL);
4932
59.1k
    memset(ret, 0 , sizeof(xmlXPathContext));
4933
59.1k
    ret->doc = doc;
4934
59.1k
    ret->node = NULL;
4935
4936
59.1k
    ret->varHash = NULL;
4937
4938
59.1k
    ret->nb_types = 0;
4939
59.1k
    ret->max_types = 0;
4940
59.1k
    ret->types = NULL;
4941
4942
59.1k
    ret->nb_axis = 0;
4943
59.1k
    ret->max_axis = 0;
4944
59.1k
    ret->axis = NULL;
4945
4946
59.1k
    ret->nsHash = NULL;
4947
59.1k
    ret->user = NULL;
4948
4949
59.1k
    ret->contextSize = -1;
4950
59.1k
    ret->proximityPosition = -1;
4951
4952
#ifdef XP_DEFAULT_CACHE_ON
4953
    if (xmlXPathContextSetCache(ret, 1, -1, 0) == -1) {
4954
  xmlXPathFreeContext(ret);
4955
  return(NULL);
4956
    }
4957
#endif
4958
4959
59.1k
    return(ret);
4960
59.1k
}
4961
4962
/**
4963
 * xmlXPathFreeContext:
4964
 * @ctxt:  the context to free
4965
 *
4966
 * Free up an xmlXPathContext
4967
 */
4968
void
4969
59.1k
xmlXPathFreeContext(xmlXPathContextPtr ctxt) {
4970
59.1k
    if (ctxt == NULL) return;
4971
4972
59.1k
    if (ctxt->cache != NULL)
4973
39.7k
  xmlXPathFreeCache((xmlXPathContextCachePtr) ctxt->cache);
4974
59.1k
    xmlXPathRegisteredNsCleanup(ctxt);
4975
59.1k
    xmlXPathRegisteredFuncsCleanup(ctxt);
4976
59.1k
    xmlXPathRegisteredVariablesCleanup(ctxt);
4977
59.1k
    xmlResetError(&ctxt->lastError);
4978
59.1k
    xmlFree(ctxt);
4979
59.1k
}
4980
4981
/**
4982
 * xmlXPathSetErrorHandler:
4983
 * @ctxt:  the XPath context
4984
 * @handler:  error handler
4985
 * @data:  user data which will be passed to the handler
4986
 *
4987
 * Register a callback function that will be called on errors and
4988
 * warnings. If handler is NULL, the error handler will be deactivated.
4989
 *
4990
 * Available since 2.13.0.
4991
 */
4992
void
4993
xmlXPathSetErrorHandler(xmlXPathContextPtr ctxt,
4994
0
                        xmlStructuredErrorFunc handler, void *data) {
4995
0
    if (ctxt == NULL)
4996
0
        return;
4997
4998
0
    ctxt->error = handler;
4999
0
    ctxt->userData = data;
5000
0
}
5001
5002
/************************************************************************
5003
 *                  *
5004
 *    Routines to handle XPath parser contexts    *
5005
 *                  *
5006
 ************************************************************************/
5007
5008
/**
5009
 * xmlXPathNewParserContext:
5010
 * @str:  the XPath expression
5011
 * @ctxt:  the XPath context
5012
 *
5013
 * Create a new xmlXPathParserContext
5014
 *
5015
 * Returns the xmlXPathParserContext just allocated.
5016
 */
5017
xmlXPathParserContextPtr
5018
664k
xmlXPathNewParserContext(const xmlChar *str, xmlXPathContextPtr ctxt) {
5019
664k
    xmlXPathParserContextPtr ret;
5020
5021
664k
    ret = (xmlXPathParserContextPtr) xmlMalloc(sizeof(xmlXPathParserContext));
5022
664k
    if (ret == NULL) {
5023
1.31k
        xmlXPathErrMemory(ctxt);
5024
1.31k
  return(NULL);
5025
1.31k
    }
5026
663k
    memset(ret, 0 , sizeof(xmlXPathParserContext));
5027
663k
    ret->cur = ret->base = str;
5028
663k
    ret->context = ctxt;
5029
5030
663k
    ret->comp = xmlXPathNewCompExpr();
5031
663k
    if (ret->comp == NULL) {
5032
94
        xmlXPathErrMemory(ctxt);
5033
94
  xmlFree(ret->valueTab);
5034
94
  xmlFree(ret);
5035
94
  return(NULL);
5036
94
    }
5037
663k
    if ((ctxt != NULL) && (ctxt->dict != NULL)) {
5038
96.8k
        ret->comp->dict = ctxt->dict;
5039
96.8k
  xmlDictReference(ret->comp->dict);
5040
96.8k
    }
5041
5042
663k
    return(ret);
5043
663k
}
5044
5045
/**
5046
 * xmlXPathCompParserContext:
5047
 * @comp:  the XPath compiled expression
5048
 * @ctxt:  the XPath context
5049
 *
5050
 * Create a new xmlXPathParserContext when processing a compiled expression
5051
 *
5052
 * Returns the xmlXPathParserContext just allocated.
5053
 */
5054
static xmlXPathParserContextPtr
5055
3.33M
xmlXPathCompParserContext(xmlXPathCompExprPtr comp, xmlXPathContextPtr ctxt) {
5056
3.33M
    xmlXPathParserContextPtr ret;
5057
5058
3.33M
    ret = (xmlXPathParserContextPtr) xmlMalloc(sizeof(xmlXPathParserContext));
5059
3.33M
    if (ret == NULL) {
5060
98.1k
        xmlXPathErrMemory(ctxt);
5061
98.1k
  return(NULL);
5062
98.1k
    }
5063
3.23M
    memset(ret, 0 , sizeof(xmlXPathParserContext));
5064
5065
    /* Allocate the value stack */
5066
3.23M
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
5067
3.23M
    ret->valueMax = 1;
5068
#else
5069
    ret->valueMax = 10;
5070
#endif
5071
3.23M
    ret->valueTab = xmlMalloc(ret->valueMax * sizeof(xmlXPathObjectPtr));
5072
3.23M
    if (ret->valueTab == NULL) {
5073
418
  xmlFree(ret);
5074
418
  xmlXPathErrMemory(ctxt);
5075
418
  return(NULL);
5076
418
    }
5077
3.23M
    ret->valueNr = 0;
5078
3.23M
    ret->value = NULL;
5079
5080
3.23M
    ret->context = ctxt;
5081
3.23M
    ret->comp = comp;
5082
5083
3.23M
    return(ret);
5084
3.23M
}
5085
5086
/**
5087
 * xmlXPathFreeParserContext:
5088
 * @ctxt:  the context to free
5089
 *
5090
 * Free up an xmlXPathParserContext
5091
 */
5092
void
5093
3.89M
xmlXPathFreeParserContext(xmlXPathParserContextPtr ctxt) {
5094
3.89M
    int i;
5095
5096
3.89M
    if (ctxt->valueTab != NULL) {
5097
3.79M
        for (i = 0; i < ctxt->valueNr; i++) {
5098
509k
            if (ctxt->context)
5099
509k
                xmlXPathReleaseObject(ctxt->context, ctxt->valueTab[i]);
5100
0
            else
5101
0
                xmlXPathFreeObject(ctxt->valueTab[i]);
5102
509k
        }
5103
3.28M
        xmlFree(ctxt->valueTab);
5104
3.28M
    }
5105
3.89M
    if (ctxt->comp != NULL) {
5106
#ifdef XPATH_STREAMING
5107
  if (ctxt->comp->stream != NULL) {
5108
      xmlFreePatternList(ctxt->comp->stream);
5109
      ctxt->comp->stream = NULL;
5110
  }
5111
#endif
5112
364k
  xmlXPathFreeCompExpr(ctxt->comp);
5113
364k
    }
5114
3.89M
    xmlFree(ctxt);
5115
3.89M
}
5116
5117
/************************************************************************
5118
 *                  *
5119
 *    The implicit core function library      *
5120
 *                  *
5121
 ************************************************************************/
5122
5123
/**
5124
 * xmlXPathNodeValHash:
5125
 * @node:  a node pointer
5126
 *
5127
 * Function computing the beginning of the string value of the node,
5128
 * used to speed up comparisons
5129
 *
5130
 * Returns an int usable as a hash
5131
 */
5132
static unsigned int
5133
311k
xmlXPathNodeValHash(xmlNodePtr node) {
5134
311k
    int len = 2;
5135
311k
    const xmlChar * string = NULL;
5136
311k
    xmlNodePtr tmp = NULL;
5137
311k
    unsigned int ret = 0;
5138
5139
311k
    if (node == NULL)
5140
0
  return(0);
5141
5142
311k
    if (node->type == XML_DOCUMENT_NODE) {
5143
27.2k
  tmp = xmlDocGetRootElement((xmlDocPtr) node);
5144
27.2k
  if (tmp == NULL)
5145
10.2k
      node = node->children;
5146
17.0k
  else
5147
17.0k
      node = tmp;
5148
5149
27.2k
  if (node == NULL)
5150
1.42k
      return(0);
5151
27.2k
    }
5152
5153
310k
    switch (node->type) {
5154
1.48k
  case XML_COMMENT_NODE:
5155
2.88k
  case XML_PI_NODE:
5156
2.88k
  case XML_CDATA_SECTION_NODE:
5157
51.1k
  case XML_TEXT_NODE:
5158
51.1k
      string = node->content;
5159
51.1k
      if (string == NULL)
5160
1.39k
    return(0);
5161
49.7k
      if (string[0] == 0)
5162
32.9k
    return(0);
5163
16.8k
      return(string[0] + (string[1] << 8));
5164
165k
  case XML_NAMESPACE_DECL:
5165
165k
      string = ((xmlNsPtr)node)->href;
5166
165k
      if (string == NULL)
5167
0
    return(0);
5168
165k
      if (string[0] == 0)
5169
14.5k
    return(0);
5170
150k
      return(string[0] + (string[1] << 8));
5171
13.6k
  case XML_ATTRIBUTE_NODE:
5172
13.6k
      tmp = ((xmlAttrPtr) node)->children;
5173
13.6k
      break;
5174
80.0k
  case XML_ELEMENT_NODE:
5175
80.0k
      tmp = node->children;
5176
80.0k
      break;
5177
0
  default:
5178
0
      return(0);
5179
310k
    }
5180
196k
    while (tmp != NULL) {
5181
140k
  switch (tmp->type) {
5182
0
      case XML_CDATA_SECTION_NODE:
5183
89.1k
      case XML_TEXT_NODE:
5184
89.1k
    string = tmp->content;
5185
89.1k
    break;
5186
51.4k
      default:
5187
51.4k
                string = NULL;
5188
51.4k
    break;
5189
140k
  }
5190
140k
  if ((string != NULL) && (string[0] != 0)) {
5191
49.2k
      if (len == 1) {
5192
6.03k
    return(ret + (string[0] << 8));
5193
6.03k
      }
5194
43.2k
      if (string[1] == 0) {
5195
11.1k
    len = 1;
5196
11.1k
    ret = string[0];
5197
32.0k
      } else {
5198
32.0k
    return(string[0] + (string[1] << 8));
5199
32.0k
      }
5200
43.2k
  }
5201
  /*
5202
   * Skip to next node
5203
   */
5204
102k
        if ((tmp->children != NULL) &&
5205
41.6k
            (tmp->type != XML_DTD_NODE) &&
5206
41.6k
            (tmp->type != XML_ENTITY_REF_NODE) &&
5207
41.6k
            (tmp->children->type != XML_ENTITY_DECL)) {
5208
41.6k
            tmp = tmp->children;
5209
41.6k
            continue;
5210
41.6k
  }
5211
60.8k
  if (tmp == node)
5212
0
      break;
5213
5214
60.8k
  if (tmp->next != NULL) {
5215
13.7k
      tmp = tmp->next;
5216
13.7k
      continue;
5217
13.7k
  }
5218
5219
47.5k
  do {
5220
47.5k
      tmp = tmp->parent;
5221
47.5k
      if (tmp == NULL)
5222
0
    break;
5223
47.5k
      if (tmp == node) {
5224
45.1k
    tmp = NULL;
5225
45.1k
    break;
5226
45.1k
      }
5227
2.42k
      if (tmp->next != NULL) {
5228
1.94k
    tmp = tmp->next;
5229
1.94k
    break;
5230
1.94k
      }
5231
2.42k
  } while (tmp != NULL);
5232
47.0k
    }
5233
55.6k
    return(ret);
5234
93.7k
}
5235
5236
/**
5237
 * xmlXPathStringHash:
5238
 * @string:  a string
5239
 *
5240
 * Function computing the beginning of the string value of the node,
5241
 * used to speed up comparisons
5242
 *
5243
 * Returns an int usable as a hash
5244
 */
5245
static unsigned int
5246
27.7k
xmlXPathStringHash(const xmlChar * string) {
5247
27.7k
    if (string == NULL)
5248
0
  return(0);
5249
27.7k
    if (string[0] == 0)
5250
7.62k
  return(0);
5251
20.1k
    return(string[0] + (string[1] << 8));
5252
27.7k
}
5253
5254
/**
5255
 * xmlXPathCompareNodeSetFloat:
5256
 * @ctxt:  the XPath Parser context
5257
 * @inf:  less than (1) or greater than (0)
5258
 * @strict:  is the comparison strict
5259
 * @arg:  the node set
5260
 * @f:  the value
5261
 *
5262
 * Implement the compare operation between a nodeset and a number
5263
 *     @ns < @val    (1, 1, ...
5264
 *     @ns <= @val   (1, 0, ...
5265
 *     @ns > @val    (0, 1, ...
5266
 *     @ns >= @val   (0, 0, ...
5267
 *
5268
 * If one object to be compared is a node-set and the other is a number,
5269
 * then the comparison will be true if and only if there is a node in the
5270
 * node-set such that the result of performing the comparison on the number
5271
 * to be compared and on the result of converting the string-value of that
5272
 * node to a number using the number function is true.
5273
 *
5274
 * Returns 0 or 1 depending on the results of the test.
5275
 */
5276
static int
5277
xmlXPathCompareNodeSetFloat(xmlXPathParserContextPtr ctxt, int inf, int strict,
5278
87.3k
                      xmlXPathObjectPtr arg, xmlXPathObjectPtr f) {
5279
87.3k
    int i, ret = 0;
5280
87.3k
    xmlNodeSetPtr ns;
5281
87.3k
    xmlChar *str2;
5282
5283
87.3k
    if ((f == NULL) || (arg == NULL) ||
5284
87.3k
  ((arg->type != XPATH_NODESET) && (arg->type != XPATH_XSLT_TREE))) {
5285
0
  xmlXPathReleaseObject(ctxt->context, arg);
5286
0
  xmlXPathReleaseObject(ctxt->context, f);
5287
0
        return(0);
5288
0
    }
5289
87.3k
    ns = arg->nodesetval;
5290
87.3k
    if (ns != NULL) {
5291
133k
  for (i = 0;i < ns->nodeNr;i++) {
5292
46.6k
       str2 = xmlXPathCastNodeToString(ns->nodeTab[i]);
5293
46.6k
       if (str2 != NULL) {
5294
46.1k
     xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt, str2));
5295
46.1k
     xmlFree(str2);
5296
46.1k
     xmlXPathNumberFunction(ctxt, 1);
5297
46.1k
     xmlXPathValuePush(ctxt, xmlXPathCacheObjectCopy(ctxt, f));
5298
46.1k
     ret = xmlXPathCompareValues(ctxt, inf, strict);
5299
46.1k
     if (ret)
5300
997
         break;
5301
46.1k
       } else {
5302
492
                 xmlXPathPErrMemory(ctxt);
5303
492
             }
5304
46.6k
  }
5305
87.3k
    }
5306
87.3k
    xmlXPathReleaseObject(ctxt->context, arg);
5307
87.3k
    xmlXPathReleaseObject(ctxt->context, f);
5308
87.3k
    return(ret);
5309
87.3k
}
5310
5311
/**
5312
 * xmlXPathCompareNodeSetString:
5313
 * @ctxt:  the XPath Parser context
5314
 * @inf:  less than (1) or greater than (0)
5315
 * @strict:  is the comparison strict
5316
 * @arg:  the node set
5317
 * @s:  the value
5318
 *
5319
 * Implement the compare operation between a nodeset and a string
5320
 *     @ns < @val    (1, 1, ...
5321
 *     @ns <= @val   (1, 0, ...
5322
 *     @ns > @val    (0, 1, ...
5323
 *     @ns >= @val   (0, 0, ...
5324
 *
5325
 * If one object to be compared is a node-set and the other is a string,
5326
 * then the comparison will be true if and only if there is a node in
5327
 * the node-set such that the result of performing the comparison on the
5328
 * string-value of the node and the other string is true.
5329
 *
5330
 * Returns 0 or 1 depending on the results of the test.
5331
 */
5332
static int
5333
xmlXPathCompareNodeSetString(xmlXPathParserContextPtr ctxt, int inf, int strict,
5334
5.83k
                      xmlXPathObjectPtr arg, xmlXPathObjectPtr s) {
5335
5.83k
    int i, ret = 0;
5336
5.83k
    xmlNodeSetPtr ns;
5337
5.83k
    xmlChar *str2;
5338
5339
5.83k
    if ((s == NULL) || (arg == NULL) ||
5340
5.83k
  ((arg->type != XPATH_NODESET) && (arg->type != XPATH_XSLT_TREE))) {
5341
0
  xmlXPathReleaseObject(ctxt->context, arg);
5342
0
  xmlXPathReleaseObject(ctxt->context, s);
5343
0
        return(0);
5344
0
    }
5345
5.83k
    ns = arg->nodesetval;
5346
5.83k
    if (ns != NULL) {
5347
12.3k
  for (i = 0;i < ns->nodeNr;i++) {
5348
6.55k
       str2 = xmlXPathCastNodeToString(ns->nodeTab[i]);
5349
6.55k
       if (str2 != NULL) {
5350
6.27k
     xmlXPathValuePush(ctxt,
5351
6.27k
         xmlXPathCacheNewString(ctxt, str2));
5352
6.27k
     xmlFree(str2);
5353
6.27k
     xmlXPathValuePush(ctxt, xmlXPathCacheObjectCopy(ctxt, s));
5354
6.27k
     ret = xmlXPathCompareValues(ctxt, inf, strict);
5355
6.27k
     if (ret)
5356
90
         break;
5357
6.27k
       } else {
5358
282
                 xmlXPathPErrMemory(ctxt);
5359
282
             }
5360
6.55k
  }
5361
5.83k
    }
5362
5.83k
    xmlXPathReleaseObject(ctxt->context, arg);
5363
5.83k
    xmlXPathReleaseObject(ctxt->context, s);
5364
5.83k
    return(ret);
5365
5.83k
}
5366
5367
/**
5368
 * xmlXPathCompareNodeSets:
5369
 * @inf:  less than (1) or greater than (0)
5370
 * @strict:  is the comparison strict
5371
 * @arg1:  the first node set object
5372
 * @arg2:  the second node set object
5373
 *
5374
 * Implement the compare operation on nodesets:
5375
 *
5376
 * If both objects to be compared are node-sets, then the comparison
5377
 * will be true if and only if there is a node in the first node-set
5378
 * and a node in the second node-set such that the result of performing
5379
 * the comparison on the string-values of the two nodes is true.
5380
 * ....
5381
 * When neither object to be compared is a node-set and the operator
5382
 * is <=, <, >= or >, then the objects are compared by converting both
5383
 * objects to numbers and comparing the numbers according to IEEE 754.
5384
 * ....
5385
 * The number function converts its argument to a number as follows:
5386
 *  - a string that consists of optional whitespace followed by an
5387
 *    optional minus sign followed by a Number followed by whitespace
5388
 *    is converted to the IEEE 754 number that is nearest (according
5389
 *    to the IEEE 754 round-to-nearest rule) to the mathematical value
5390
 *    represented by the string; any other string is converted to NaN
5391
 *
5392
 * Conclusion all nodes need to be converted first to their string value
5393
 * and then the comparison must be done when possible
5394
 */
5395
static int
5396
xmlXPathCompareNodeSets(xmlXPathParserContextPtr ctxt, int inf, int strict,
5397
142k
                  xmlXPathObjectPtr arg1, xmlXPathObjectPtr arg2) {
5398
142k
    int i, j, init = 0;
5399
142k
    double val1;
5400
142k
    double *values2;
5401
142k
    int ret = 0;
5402
142k
    xmlNodeSetPtr ns1;
5403
142k
    xmlNodeSetPtr ns2;
5404
5405
142k
    if ((arg1 == NULL) ||
5406
142k
  ((arg1->type != XPATH_NODESET) && (arg1->type != XPATH_XSLT_TREE))) {
5407
0
  xmlXPathFreeObject(arg2);
5408
0
        return(0);
5409
0
    }
5410
142k
    if ((arg2 == NULL) ||
5411
142k
  ((arg2->type != XPATH_NODESET) && (arg2->type != XPATH_XSLT_TREE))) {
5412
0
  xmlXPathFreeObject(arg1);
5413
0
  xmlXPathFreeObject(arg2);
5414
0
        return(0);
5415
0
    }
5416
5417
142k
    ns1 = arg1->nodesetval;
5418
142k
    ns2 = arg2->nodesetval;
5419
5420
142k
    if ((ns1 == NULL) || (ns1->nodeNr <= 0)) {
5421
126k
  xmlXPathFreeObject(arg1);
5422
126k
  xmlXPathFreeObject(arg2);
5423
126k
  return(0);
5424
126k
    }
5425
15.9k
    if ((ns2 == NULL) || (ns2->nodeNr <= 0)) {
5426
10.6k
  xmlXPathFreeObject(arg1);
5427
10.6k
  xmlXPathFreeObject(arg2);
5428
10.6k
  return(0);
5429
10.6k
    }
5430
5431
5.33k
    values2 = (double *) xmlMalloc(ns2->nodeNr * sizeof(double));
5432
5.33k
    if (values2 == NULL) {
5433
192
        xmlXPathPErrMemory(ctxt);
5434
192
  xmlXPathFreeObject(arg1);
5435
192
  xmlXPathFreeObject(arg2);
5436
192
  return(0);
5437
192
    }
5438
20.6k
    for (i = 0;i < ns1->nodeNr;i++) {
5439
16.0k
  val1 = xmlXPathNodeToNumberInternal(ctxt, ns1->nodeTab[i]);
5440
16.0k
  if (xmlXPathIsNaN(val1))
5441
13.3k
      continue;
5442
74.2k
  for (j = 0;j < ns2->nodeNr;j++) {
5443
72.0k
      if (init == 0) {
5444
23.2k
    values2[j] = xmlXPathNodeToNumberInternal(ctxt,
5445
23.2k
                                                          ns2->nodeTab[j]);
5446
23.2k
      }
5447
72.0k
      if (xmlXPathIsNaN(values2[j]))
5448
20.8k
    continue;
5449
51.1k
      if (inf && strict)
5450
0
    ret = (val1 < values2[j]);
5451
51.1k
      else if (inf && !strict)
5452
0
    ret = (val1 <= values2[j]);
5453
51.1k
      else if (!inf && strict)
5454
50.5k
    ret = (val1 > values2[j]);
5455
608
      else if (!inf && !strict)
5456
608
    ret = (val1 >= values2[j]);
5457
51.1k
      if (ret)
5458
533
    break;
5459
51.1k
  }
5460
2.74k
  if (ret)
5461
533
      break;
5462
2.21k
  init = 1;
5463
2.21k
    }
5464
5.14k
    xmlFree(values2);
5465
5.14k
    xmlXPathFreeObject(arg1);
5466
5.14k
    xmlXPathFreeObject(arg2);
5467
5.14k
    return(ret);
5468
5.33k
}
5469
5470
/**
5471
 * xmlXPathCompareNodeSetValue:
5472
 * @ctxt:  the XPath Parser context
5473
 * @inf:  less than (1) or greater than (0)
5474
 * @strict:  is the comparison strict
5475
 * @arg:  the node set
5476
 * @val:  the value
5477
 *
5478
 * Implement the compare operation between a nodeset and a value
5479
 *     @ns < @val    (1, 1, ...
5480
 *     @ns <= @val   (1, 0, ...
5481
 *     @ns > @val    (0, 1, ...
5482
 *     @ns >= @val   (0, 0, ...
5483
 *
5484
 * If one object to be compared is a node-set and the other is a boolean,
5485
 * then the comparison will be true if and only if the result of performing
5486
 * the comparison on the boolean and on the result of converting
5487
 * the node-set to a boolean using the boolean function is true.
5488
 *
5489
 * Returns 0 or 1 depending on the results of the test.
5490
 */
5491
static int
5492
xmlXPathCompareNodeSetValue(xmlXPathParserContextPtr ctxt, int inf, int strict,
5493
141k
                      xmlXPathObjectPtr arg, xmlXPathObjectPtr val) {
5494
141k
    if ((val == NULL) || (arg == NULL) ||
5495
141k
  ((arg->type != XPATH_NODESET) && (arg->type != XPATH_XSLT_TREE)))
5496
0
        return(0);
5497
5498
141k
    switch(val->type) {
5499
87.3k
        case XPATH_NUMBER:
5500
87.3k
      return(xmlXPathCompareNodeSetFloat(ctxt, inf, strict, arg, val));
5501
0
        case XPATH_NODESET:
5502
0
        case XPATH_XSLT_TREE:
5503
0
      return(xmlXPathCompareNodeSets(ctxt, inf, strict, arg, val));
5504
5.83k
        case XPATH_STRING:
5505
5.83k
      return(xmlXPathCompareNodeSetString(ctxt, inf, strict, arg, val));
5506
48.4k
        case XPATH_BOOLEAN:
5507
48.4k
      xmlXPathValuePush(ctxt, arg);
5508
48.4k
      xmlXPathBooleanFunction(ctxt, 1);
5509
48.4k
      xmlXPathValuePush(ctxt, val);
5510
48.4k
      return(xmlXPathCompareValues(ctxt, inf, strict));
5511
299
  default:
5512
299
            xmlXPathReleaseObject(ctxt->context, arg);
5513
299
            xmlXPathReleaseObject(ctxt->context, val);
5514
299
            XP_ERROR0(XPATH_INVALID_TYPE);
5515
141k
    }
5516
0
    return(0);
5517
141k
}
5518
5519
/**
5520
 * xmlXPathEqualNodeSetString:
5521
 * @arg:  the nodeset object argument
5522
 * @str:  the string to compare to.
5523
 * @neq:  flag to show whether for '=' (0) or '!=' (1)
5524
 *
5525
 * Implement the equal operation on XPath objects content: @arg1 == @arg2
5526
 * If one object to be compared is a node-set and the other is a string,
5527
 * then the comparison will be true if and only if there is a node in
5528
 * the node-set such that the result of performing the comparison on the
5529
 * string-value of the node and the other string is true.
5530
 *
5531
 * Returns 0 or 1 depending on the results of the test.
5532
 */
5533
static int
5534
xmlXPathEqualNodeSetString(xmlXPathParserContextPtr ctxt,
5535
                           xmlXPathObjectPtr arg, const xmlChar * str, int neq)
5536
63.3k
{
5537
63.3k
    int i;
5538
63.3k
    xmlNodeSetPtr ns;
5539
63.3k
    xmlChar *str2;
5540
63.3k
    unsigned int hash;
5541
5542
63.3k
    if ((str == NULL) || (arg == NULL) ||
5543
63.3k
        ((arg->type != XPATH_NODESET) && (arg->type != XPATH_XSLT_TREE)))
5544
0
        return (0);
5545
63.3k
    ns = arg->nodesetval;
5546
    /*
5547
     * A NULL nodeset compared with a string is always false
5548
     * (since there is no node equal, and no node not equal)
5549
     */
5550
63.3k
    if ((ns == NULL) || (ns->nodeNr <= 0) )
5551
35.5k
        return (0);
5552
27.7k
    hash = xmlXPathStringHash(str);
5553
46.3k
    for (i = 0; i < ns->nodeNr; i++) {
5554
35.2k
        if (xmlXPathNodeValHash(ns->nodeTab[i]) == hash) {
5555
10.0k
            str2 = xmlNodeGetContent(ns->nodeTab[i]);
5556
10.0k
            if (str2 == NULL) {
5557
2
                xmlXPathPErrMemory(ctxt);
5558
2
                return(0);
5559
2
            }
5560
10.0k
            if (xmlStrEqual(str, str2)) {
5561
6.32k
                xmlFree(str2);
5562
6.32k
    if (neq)
5563
3.28k
        continue;
5564
3.03k
                return (1);
5565
6.32k
            } else if (neq) {
5566
3.08k
    xmlFree(str2);
5567
3.08k
    return (1);
5568
3.08k
      }
5569
608
            xmlFree(str2);
5570
25.2k
        } else if (neq)
5571
10.5k
      return (1);
5572
35.2k
    }
5573
11.0k
    return (0);
5574
27.7k
}
5575
5576
/**
5577
 * xmlXPathEqualNodeSetFloat:
5578
 * @arg:  the nodeset object argument
5579
 * @f:  the float to compare to
5580
 * @neq:  flag to show whether to compare '=' (0) or '!=' (1)
5581
 *
5582
 * Implement the equal operation on XPath objects content: @arg1 == @arg2
5583
 * If one object to be compared is a node-set and the other is a number,
5584
 * then the comparison will be true if and only if there is a node in
5585
 * the node-set such that the result of performing the comparison on the
5586
 * number to be compared and on the result of converting the string-value
5587
 * of that node to a number using the number function is true.
5588
 *
5589
 * Returns 0 or 1 depending on the results of the test.
5590
 */
5591
static int
5592
xmlXPathEqualNodeSetFloat(xmlXPathParserContextPtr ctxt,
5593
50.6k
    xmlXPathObjectPtr arg, double f, int neq) {
5594
50.6k
  int i, ret=0;
5595
50.6k
  xmlNodeSetPtr ns;
5596
50.6k
  xmlChar *str2;
5597
50.6k
  xmlXPathObjectPtr val;
5598
50.6k
  double v;
5599
5600
50.6k
    if ((arg == NULL) ||
5601
50.6k
  ((arg->type != XPATH_NODESET) && (arg->type != XPATH_XSLT_TREE)))
5602
0
        return(0);
5603
5604
50.6k
    ns = arg->nodesetval;
5605
50.6k
    if (ns != NULL) {
5606
101k
  for (i=0;i<ns->nodeNr;i++) {
5607
53.6k
      str2 = xmlXPathCastNodeToString(ns->nodeTab[i]);
5608
53.6k
      if (str2 != NULL) {
5609
53.3k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt, str2));
5610
53.3k
    xmlFree(str2);
5611
53.3k
    xmlXPathNumberFunction(ctxt, 1);
5612
53.3k
                CHECK_ERROR0;
5613
53.2k
    val = xmlXPathValuePop(ctxt);
5614
53.2k
    v = val->floatval;
5615
53.2k
    xmlXPathReleaseObject(ctxt->context, val);
5616
53.2k
    if (!xmlXPathIsNaN(v)) {
5617
3.90k
        if ((!neq) && (v==f)) {
5618
114
      ret = 1;
5619
114
      break;
5620
3.79k
        } else if ((neq) && (v!=f)) {
5621
2.91k
      ret = 1;
5622
2.91k
      break;
5623
2.91k
        }
5624
49.3k
    } else { /* NaN is unequal to any value */
5625
49.3k
        if (neq)
5626
35.6k
      ret = 1;
5627
49.3k
    }
5628
53.2k
      } else {
5629
297
                xmlXPathPErrMemory(ctxt);
5630
297
            }
5631
53.6k
  }
5632
50.6k
    }
5633
5634
50.6k
    return(ret);
5635
50.6k
}
5636
5637
5638
/**
5639
 * xmlXPathEqualNodeSets:
5640
 * @arg1:  first nodeset object argument
5641
 * @arg2:  second nodeset object argument
5642
 * @neq:   flag to show whether to test '=' (0) or '!=' (1)
5643
 *
5644
 * Implement the equal / not equal operation on XPath nodesets:
5645
 * @arg1 == @arg2  or  @arg1 != @arg2
5646
 * If both objects to be compared are node-sets, then the comparison
5647
 * will be true if and only if there is a node in the first node-set and
5648
 * a node in the second node-set such that the result of performing the
5649
 * comparison on the string-values of the two nodes is true.
5650
 *
5651
 * (needless to say, this is a costly operation)
5652
 *
5653
 * Returns 0 or 1 depending on the results of the test.
5654
 */
5655
static int
5656
xmlXPathEqualNodeSets(xmlXPathParserContextPtr ctxt, xmlXPathObjectPtr arg1,
5657
151k
                      xmlXPathObjectPtr arg2, int neq) {
5658
151k
    int i, j;
5659
151k
    unsigned int *hashs1;
5660
151k
    unsigned int *hashs2;
5661
151k
    xmlChar **values1;
5662
151k
    xmlChar **values2;
5663
151k
    int ret = 0;
5664
151k
    xmlNodeSetPtr ns1;
5665
151k
    xmlNodeSetPtr ns2;
5666
5667
151k
    if ((arg1 == NULL) ||
5668
151k
  ((arg1->type != XPATH_NODESET) && (arg1->type != XPATH_XSLT_TREE)))
5669
0
        return(0);
5670
151k
    if ((arg2 == NULL) ||
5671
151k
  ((arg2->type != XPATH_NODESET) && (arg2->type != XPATH_XSLT_TREE)))
5672
0
        return(0);
5673
5674
151k
    ns1 = arg1->nodesetval;
5675
151k
    ns2 = arg2->nodesetval;
5676
5677
151k
    if ((ns1 == NULL) || (ns1->nodeNr <= 0))
5678
93.9k
  return(0);
5679
57.1k
    if ((ns2 == NULL) || (ns2->nodeNr <= 0))
5680
39.0k
  return(0);
5681
5682
    /*
5683
     * for equal, check if there is a node pertaining to both sets
5684
     */
5685
18.1k
    if (neq == 0)
5686
187k
  for (i = 0;i < ns1->nodeNr;i++)
5687
544k
      for (j = 0;j < ns2->nodeNr;j++)
5688
369k
    if (ns1->nodeTab[i] == ns2->nodeTab[j])
5689
705
        return(1);
5690
5691
17.4k
    values1 = (xmlChar **) xmlMalloc(ns1->nodeNr * sizeof(xmlChar *));
5692
17.4k
    if (values1 == NULL) {
5693
223
        xmlXPathPErrMemory(ctxt);
5694
223
  return(0);
5695
223
    }
5696
17.1k
    hashs1 = (unsigned int *) xmlMalloc(ns1->nodeNr * sizeof(unsigned int));
5697
17.1k
    if (hashs1 == NULL) {
5698
3
        xmlXPathPErrMemory(ctxt);
5699
3
  xmlFree(values1);
5700
3
  return(0);
5701
3
    }
5702
17.1k
    memset(values1, 0, ns1->nodeNr * sizeof(xmlChar *));
5703
17.1k
    values2 = (xmlChar **) xmlMalloc(ns2->nodeNr * sizeof(xmlChar *));
5704
17.1k
    if (values2 == NULL) {
5705
6
        xmlXPathPErrMemory(ctxt);
5706
6
  xmlFree(hashs1);
5707
6
  xmlFree(values1);
5708
6
  return(0);
5709
6
    }
5710
17.1k
    hashs2 = (unsigned int *) xmlMalloc(ns2->nodeNr * sizeof(unsigned int));
5711
17.1k
    if (hashs2 == NULL) {
5712
2
        xmlXPathPErrMemory(ctxt);
5713
2
  xmlFree(hashs1);
5714
2
  xmlFree(values1);
5715
2
  xmlFree(values2);
5716
2
  return(0);
5717
2
    }
5718
17.1k
    memset(values2, 0, ns2->nodeNr * sizeof(xmlChar *));
5719
255k
    for (i = 0;i < ns1->nodeNr;i++) {
5720
244k
  hashs1[i] = xmlXPathNodeValHash(ns1->nodeTab[i]);
5721
585k
  for (j = 0;j < ns2->nodeNr;j++) {
5722
347k
      if (i == 0)
5723
31.6k
    hashs2[j] = xmlXPathNodeValHash(ns2->nodeTab[j]);
5724
347k
      if (hashs1[i] != hashs2[j]) {
5725
255k
    if (neq) {
5726
2.93k
        ret = 1;
5727
2.93k
        break;
5728
2.93k
    }
5729
255k
      }
5730
92.0k
      else {
5731
92.0k
    if (values1[i] == NULL) {
5732
74.0k
        values1[i] = xmlNodeGetContent(ns1->nodeTab[i]);
5733
74.0k
                    if (values1[i] == NULL)
5734
391
                        xmlXPathPErrMemory(ctxt);
5735
74.0k
                }
5736
92.0k
    if (values2[j] == NULL) {
5737
10.3k
        values2[j] = xmlNodeGetContent(ns2->nodeTab[j]);
5738
10.3k
                    if (values2[j] == NULL)
5739
242
                        xmlXPathPErrMemory(ctxt);
5740
10.3k
                }
5741
92.0k
    ret = xmlStrEqual(values1[i], values2[j]) ^ neq;
5742
92.0k
    if (ret)
5743
3.77k
        break;
5744
92.0k
      }
5745
347k
  }
5746
244k
  if (ret)
5747
6.70k
      break;
5748
244k
    }
5749
267k
    for (i = 0;i < ns1->nodeNr;i++)
5750
250k
  if (values1[i] != NULL)
5751
73.7k
      xmlFree(values1[i]);
5752
52.9k
    for (j = 0;j < ns2->nodeNr;j++)
5753
35.8k
  if (values2[j] != NULL)
5754
10.0k
      xmlFree(values2[j]);
5755
17.1k
    xmlFree(values1);
5756
17.1k
    xmlFree(values2);
5757
17.1k
    xmlFree(hashs1);
5758
17.1k
    xmlFree(hashs2);
5759
17.1k
    return(ret);
5760
17.1k
}
5761
5762
static int
5763
xmlXPathEqualValuesCommon(xmlXPathParserContextPtr ctxt,
5764
133k
  xmlXPathObjectPtr arg1, xmlXPathObjectPtr arg2) {
5765
133k
    int ret = 0;
5766
    /*
5767
     *At this point we are assured neither arg1 nor arg2
5768
     *is a nodeset, so we can just pick the appropriate routine.
5769
     */
5770
133k
    switch (arg1->type) {
5771
0
        case XPATH_UNDEFINED:
5772
0
      break;
5773
64.9k
        case XPATH_BOOLEAN:
5774
64.9k
      switch (arg2->type) {
5775
0
          case XPATH_UNDEFINED:
5776
0
        break;
5777
8.81k
    case XPATH_BOOLEAN:
5778
8.81k
        ret = (arg1->boolval == arg2->boolval);
5779
8.81k
        break;
5780
51.0k
    case XPATH_NUMBER:
5781
51.0k
        ret = (arg1->boolval ==
5782
51.0k
         xmlXPathCastNumberToBoolean(arg2->floatval));
5783
51.0k
        break;
5784
4.98k
    case XPATH_STRING:
5785
4.98k
        if ((arg2->stringval == NULL) ||
5786
4.98k
      (arg2->stringval[0] == 0)) ret = 0;
5787
3.17k
        else
5788
3.17k
      ret = 1;
5789
4.98k
        ret = (arg1->boolval == ret);
5790
4.98k
        break;
5791
151
    case XPATH_USERS:
5792
        /* TODO */
5793
151
        break;
5794
0
    case XPATH_NODESET:
5795
0
    case XPATH_XSLT_TREE:
5796
0
        break;
5797
64.9k
      }
5798
64.9k
      break;
5799
64.9k
        case XPATH_NUMBER:
5800
46.0k
      switch (arg2->type) {
5801
0
          case XPATH_UNDEFINED:
5802
0
        break;
5803
10.3k
    case XPATH_BOOLEAN:
5804
10.3k
        ret = (arg2->boolval==
5805
10.3k
         xmlXPathCastNumberToBoolean(arg1->floatval));
5806
10.3k
        break;
5807
6.50k
    case XPATH_STRING:
5808
6.50k
        xmlXPathValuePush(ctxt, arg2);
5809
6.50k
        xmlXPathNumberFunction(ctxt, 1);
5810
6.50k
        arg2 = xmlXPathValuePop(ctxt);
5811
6.50k
                    if (ctxt->error)
5812
0
                        break;
5813
                    /* Falls through. */
5814
35.5k
    case XPATH_NUMBER:
5815
        /* Hand check NaN and Infinity equalities */
5816
35.5k
        if (xmlXPathIsNaN(arg1->floatval) ||
5817
28.8k
          xmlXPathIsNaN(arg2->floatval)) {
5818
28.8k
            ret = 0;
5819
28.8k
        } else if (xmlXPathIsInf(arg1->floatval) == 1) {
5820
970
            if (xmlXPathIsInf(arg2->floatval) == 1)
5821
82
          ret = 1;
5822
888
      else
5823
888
          ret = 0;
5824
5.71k
        } else if (xmlXPathIsInf(arg1->floatval) == -1) {
5825
623
      if (xmlXPathIsInf(arg2->floatval) == -1)
5826
228
          ret = 1;
5827
395
      else
5828
395
          ret = 0;
5829
5.08k
        } else if (xmlXPathIsInf(arg2->floatval) == 1) {
5830
232
      if (xmlXPathIsInf(arg1->floatval) == 1)
5831
0
          ret = 1;
5832
232
      else
5833
232
          ret = 0;
5834
4.85k
        } else if (xmlXPathIsInf(arg2->floatval) == -1) {
5835
296
      if (xmlXPathIsInf(arg1->floatval) == -1)
5836
0
          ret = 1;
5837
296
      else
5838
296
          ret = 0;
5839
4.55k
        } else {
5840
4.55k
            ret = (arg1->floatval == arg2->floatval);
5841
4.55k
        }
5842
35.5k
        break;
5843
85
    case XPATH_USERS:
5844
        /* TODO */
5845
85
        break;
5846
0
    case XPATH_NODESET:
5847
0
    case XPATH_XSLT_TREE:
5848
0
        break;
5849
46.0k
      }
5850
46.0k
      break;
5851
46.0k
        case XPATH_STRING:
5852
22.2k
      switch (arg2->type) {
5853
0
          case XPATH_UNDEFINED:
5854
0
        break;
5855
1.05k
    case XPATH_BOOLEAN:
5856
1.05k
        if ((arg1->stringval == NULL) ||
5857
1.05k
      (arg1->stringval[0] == 0)) ret = 0;
5858
942
        else
5859
942
      ret = 1;
5860
1.05k
        ret = (arg2->boolval == ret);
5861
1.05k
        break;
5862
1.49k
    case XPATH_STRING:
5863
1.49k
        ret = xmlStrEqual(arg1->stringval, arg2->stringval);
5864
1.49k
        break;
5865
19.6k
    case XPATH_NUMBER:
5866
19.6k
        xmlXPathValuePush(ctxt, arg1);
5867
19.6k
        xmlXPathNumberFunction(ctxt, 1);
5868
19.6k
        arg1 = xmlXPathValuePop(ctxt);
5869
19.6k
                    if (ctxt->error)
5870
0
                        break;
5871
        /* Hand check NaN and Infinity equalities */
5872
19.6k
        if (xmlXPathIsNaN(arg1->floatval) ||
5873
17.6k
          xmlXPathIsNaN(arg2->floatval)) {
5874
17.6k
            ret = 0;
5875
17.6k
        } else if (xmlXPathIsInf(arg1->floatval) == 1) {
5876
418
      if (xmlXPathIsInf(arg2->floatval) == 1)
5877
210
          ret = 1;
5878
208
      else
5879
208
          ret = 0;
5880
1.67k
        } else if (xmlXPathIsInf(arg1->floatval) == -1) {
5881
508
      if (xmlXPathIsInf(arg2->floatval) == -1)
5882
209
          ret = 1;
5883
299
      else
5884
299
          ret = 0;
5885
1.16k
        } else if (xmlXPathIsInf(arg2->floatval) == 1) {
5886
234
      if (xmlXPathIsInf(arg1->floatval) == 1)
5887
0
          ret = 1;
5888
234
      else
5889
234
          ret = 0;
5890
932
        } else if (xmlXPathIsInf(arg2->floatval) == -1) {
5891
321
      if (xmlXPathIsInf(arg1->floatval) == -1)
5892
0
          ret = 1;
5893
321
      else
5894
321
          ret = 0;
5895
611
        } else {
5896
611
            ret = (arg1->floatval == arg2->floatval);
5897
611
        }
5898
19.6k
        break;
5899
0
    case XPATH_USERS:
5900
        /* TODO */
5901
0
        break;
5902
0
    case XPATH_NODESET:
5903
0
    case XPATH_XSLT_TREE:
5904
0
        break;
5905
22.2k
      }
5906
22.2k
      break;
5907
22.2k
        case XPATH_USERS:
5908
      /* TODO */
5909
276
      break;
5910
0
  case XPATH_NODESET:
5911
0
  case XPATH_XSLT_TREE:
5912
0
      break;
5913
133k
    }
5914
133k
    xmlXPathReleaseObject(ctxt->context, arg1);
5915
133k
    xmlXPathReleaseObject(ctxt->context, arg2);
5916
133k
    return(ret);
5917
133k
}
5918
5919
/**
5920
 * xmlXPathEqualValues:
5921
 * @ctxt:  the XPath Parser context
5922
 *
5923
 * Implement the equal operation on XPath objects content: @arg1 == @arg2
5924
 *
5925
 * Returns 0 or 1 depending on the results of the test.
5926
 */
5927
int
5928
322k
xmlXPathEqualValues(xmlXPathParserContextPtr ctxt) {
5929
322k
    xmlXPathObjectPtr arg1, arg2, argtmp;
5930
322k
    int ret = 0;
5931
5932
322k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(0);
5933
322k
    arg2 = xmlXPathValuePop(ctxt);
5934
322k
    arg1 = xmlXPathValuePop(ctxt);
5935
322k
    if ((arg1 == NULL) || (arg2 == NULL)) {
5936
0
  if (arg1 != NULL)
5937
0
      xmlXPathReleaseObject(ctxt->context, arg1);
5938
0
  else
5939
0
      xmlXPathReleaseObject(ctxt->context, arg2);
5940
0
  XP_ERROR0(XPATH_INVALID_OPERAND);
5941
0
    }
5942
5943
322k
    if (arg1 == arg2) {
5944
0
  xmlXPathFreeObject(arg1);
5945
0
        return(1);
5946
0
    }
5947
5948
    /*
5949
     *If either argument is a nodeset, it's a 'special case'
5950
     */
5951
322k
    if ((arg2->type == XPATH_NODESET) || (arg2->type == XPATH_XSLT_TREE) ||
5952
219k
      (arg1->type == XPATH_NODESET) || (arg1->type == XPATH_XSLT_TREE)) {
5953
  /*
5954
   *Hack it to assure arg1 is the nodeset
5955
   */
5956
219k
  if ((arg1->type != XPATH_NODESET) && (arg1->type != XPATH_XSLT_TREE)) {
5957
33.5k
    argtmp = arg2;
5958
33.5k
    arg2 = arg1;
5959
33.5k
    arg1 = argtmp;
5960
33.5k
  }
5961
219k
  switch (arg2->type) {
5962
0
      case XPATH_UNDEFINED:
5963
0
    break;
5964
113k
      case XPATH_NODESET:
5965
123k
      case XPATH_XSLT_TREE:
5966
123k
    ret = xmlXPathEqualNodeSets(ctxt, arg1, arg2, 0);
5967
123k
    break;
5968
42.5k
      case XPATH_BOOLEAN:
5969
42.5k
    if ((arg1->nodesetval == NULL) ||
5970
42.5k
      (arg1->nodesetval->nodeNr == 0)) ret = 0;
5971
2.68k
    else
5972
2.68k
        ret = 1;
5973
42.5k
    ret = (ret == arg2->boolval);
5974
42.5k
    break;
5975
13.3k
      case XPATH_NUMBER:
5976
13.3k
    ret = xmlXPathEqualNodeSetFloat(ctxt, arg1, arg2->floatval, 0);
5977
13.3k
    break;
5978
40.0k
      case XPATH_STRING:
5979
40.0k
    ret = xmlXPathEqualNodeSetString(ctxt, arg1,
5980
40.0k
                                                 arg2->stringval, 0);
5981
40.0k
    break;
5982
137
      case XPATH_USERS:
5983
    /* TODO */
5984
137
    break;
5985
219k
  }
5986
219k
  xmlXPathReleaseObject(ctxt->context, arg1);
5987
219k
  xmlXPathReleaseObject(ctxt->context, arg2);
5988
219k
  return(ret);
5989
219k
    }
5990
5991
102k
    return (xmlXPathEqualValuesCommon(ctxt, arg1, arg2));
5992
322k
}
5993
5994
/**
5995
 * xmlXPathNotEqualValues:
5996
 * @ctxt:  the XPath Parser context
5997
 *
5998
 * Implement the equal operation on XPath objects content: @arg1 == @arg2
5999
 *
6000
 * Returns 0 or 1 depending on the results of the test.
6001
 */
6002
int
6003
122k
xmlXPathNotEqualValues(xmlXPathParserContextPtr ctxt) {
6004
122k
    xmlXPathObjectPtr arg1, arg2, argtmp;
6005
122k
    int ret = 0;
6006
6007
122k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(0);
6008
122k
    arg2 = xmlXPathValuePop(ctxt);
6009
122k
    arg1 = xmlXPathValuePop(ctxt);
6010
122k
    if ((arg1 == NULL) || (arg2 == NULL)) {
6011
0
  if (arg1 != NULL)
6012
0
      xmlXPathReleaseObject(ctxt->context, arg1);
6013
0
  else
6014
0
      xmlXPathReleaseObject(ctxt->context, arg2);
6015
0
  XP_ERROR0(XPATH_INVALID_OPERAND);
6016
0
    }
6017
6018
122k
    if (arg1 == arg2) {
6019
0
  xmlXPathReleaseObject(ctxt->context, arg1);
6020
0
        return(0);
6021
0
    }
6022
6023
    /*
6024
     *If either argument is a nodeset, it's a 'special case'
6025
     */
6026
122k
    if ((arg2->type == XPATH_NODESET) || (arg2->type == XPATH_XSLT_TREE) ||
6027
91.9k
      (arg1->type == XPATH_NODESET) || (arg1->type == XPATH_XSLT_TREE)) {
6028
  /*
6029
   *Hack it to assure arg1 is the nodeset
6030
   */
6031
91.9k
  if ((arg1->type != XPATH_NODESET) && (arg1->type != XPATH_XSLT_TREE)) {
6032
62.7k
    argtmp = arg2;
6033
62.7k
    arg2 = arg1;
6034
62.7k
    arg1 = argtmp;
6035
62.7k
  }
6036
91.9k
  switch (arg2->type) {
6037
0
      case XPATH_UNDEFINED:
6038
0
    break;
6039
27.5k
      case XPATH_NODESET:
6040
27.7k
      case XPATH_XSLT_TREE:
6041
27.7k
    ret = xmlXPathEqualNodeSets(ctxt, arg1, arg2, 1);
6042
27.7k
    break;
6043
3.01k
      case XPATH_BOOLEAN:
6044
3.01k
    if ((arg1->nodesetval == NULL) ||
6045
3.01k
      (arg1->nodesetval->nodeNr == 0)) ret = 0;
6046
678
    else
6047
678
        ret = 1;
6048
3.01k
    ret = (ret != arg2->boolval);
6049
3.01k
    break;
6050
37.2k
      case XPATH_NUMBER:
6051
37.2k
    ret = xmlXPathEqualNodeSetFloat(ctxt, arg1, arg2->floatval, 1);
6052
37.2k
    break;
6053
23.2k
      case XPATH_STRING:
6054
23.2k
    ret = xmlXPathEqualNodeSetString(ctxt, arg1,
6055
23.2k
                                                 arg2->stringval, 1);
6056
23.2k
    break;
6057
651
      case XPATH_USERS:
6058
    /* TODO */
6059
651
    break;
6060
91.9k
  }
6061
91.9k
  xmlXPathReleaseObject(ctxt->context, arg1);
6062
91.9k
  xmlXPathReleaseObject(ctxt->context, arg2);
6063
91.9k
  return(ret);
6064
91.9k
    }
6065
6066
30.7k
    return (!xmlXPathEqualValuesCommon(ctxt, arg1, arg2));
6067
122k
}
6068
6069
/**
6070
 * xmlXPathCompareValues:
6071
 * @ctxt:  the XPath Parser context
6072
 * @inf:  less than (1) or greater than (0)
6073
 * @strict:  is the comparison strict
6074
 *
6075
 * Implement the compare operation on XPath objects:
6076
 *     @arg1 < @arg2    (1, 1, ...
6077
 *     @arg1 <= @arg2   (1, 0, ...
6078
 *     @arg1 > @arg2    (0, 1, ...
6079
 *     @arg1 >= @arg2   (0, 0, ...
6080
 *
6081
 * When neither object to be compared is a node-set and the operator is
6082
 * <=, <, >=, >, then the objects are compared by converted both objects
6083
 * to numbers and comparing the numbers according to IEEE 754. The <
6084
 * comparison will be true if and only if the first number is less than the
6085
 * second number. The <= comparison will be true if and only if the first
6086
 * number is less than or equal to the second number. The > comparison
6087
 * will be true if and only if the first number is greater than the second
6088
 * number. The >= comparison will be true if and only if the first number
6089
 * is greater than or equal to the second number.
6090
 *
6091
 * Returns 1 if the comparison succeeded, 0 if it failed
6092
 */
6093
int
6094
441k
xmlXPathCompareValues(xmlXPathParserContextPtr ctxt, int inf, int strict) {
6095
441k
    int ret = 0, arg1i = 0, arg2i = 0;
6096
441k
    xmlXPathObjectPtr arg1, arg2;
6097
6098
441k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(0);
6099
441k
    arg2 = xmlXPathValuePop(ctxt);
6100
441k
    arg1 = xmlXPathValuePop(ctxt);
6101
441k
    if ((arg1 == NULL) || (arg2 == NULL)) {
6102
104
  if (arg1 != NULL)
6103
0
      xmlXPathReleaseObject(ctxt->context, arg1);
6104
104
  else
6105
104
      xmlXPathReleaseObject(ctxt->context, arg2);
6106
104
  XP_ERROR0(XPATH_INVALID_OPERAND);
6107
0
    }
6108
6109
441k
    if ((arg2->type == XPATH_NODESET) || (arg2->type == XPATH_XSLT_TREE) ||
6110
283k
      (arg1->type == XPATH_NODESET) || (arg1->type == XPATH_XSLT_TREE)) {
6111
  /*
6112
   * If either argument is a XPATH_NODESET or XPATH_XSLT_TREE the two arguments
6113
   * are not freed from within this routine; they will be freed from the
6114
   * called routine, e.g. xmlXPathCompareNodeSets or xmlXPathCompareNodeSetValue
6115
   */
6116
283k
  if (((arg2->type == XPATH_NODESET) || (arg2->type == XPATH_XSLT_TREE)) &&
6117
261k
    ((arg1->type == XPATH_NODESET) || (arg1->type == XPATH_XSLT_TREE))){
6118
142k
      ret = xmlXPathCompareNodeSets(ctxt, inf, strict, arg1, arg2);
6119
142k
  } else {
6120
141k
      if ((arg1->type == XPATH_NODESET) || (arg1->type == XPATH_XSLT_TREE)) {
6121
22.7k
    ret = xmlXPathCompareNodeSetValue(ctxt, inf, strict,
6122
22.7k
                                arg1, arg2);
6123
119k
      } else {
6124
119k
    ret = xmlXPathCompareNodeSetValue(ctxt, !inf, strict,
6125
119k
                                arg2, arg1);
6126
119k
      }
6127
141k
  }
6128
283k
  return(ret);
6129
283k
    }
6130
6131
157k
    if (arg1->type != XPATH_NUMBER) {
6132
83.3k
  xmlXPathValuePush(ctxt, arg1);
6133
83.3k
  xmlXPathNumberFunction(ctxt, 1);
6134
83.3k
  arg1 = xmlXPathValuePop(ctxt);
6135
83.3k
    }
6136
157k
    if (arg2->type != XPATH_NUMBER) {
6137
54.5k
  xmlXPathValuePush(ctxt, arg2);
6138
54.5k
  xmlXPathNumberFunction(ctxt, 1);
6139
54.5k
  arg2 = xmlXPathValuePop(ctxt);
6140
54.5k
    }
6141
157k
    if (ctxt->error)
6142
2
        goto error;
6143
    /*
6144
     * Add tests for infinity and nan
6145
     * => feedback on 3.4 for Inf and NaN
6146
     */
6147
    /* Hand check NaN and Infinity comparisons */
6148
157k
    if (xmlXPathIsNaN(arg1->floatval) || xmlXPathIsNaN(arg2->floatval)) {
6149
77.2k
  ret=0;
6150
80.2k
    } else {
6151
80.2k
  arg1i=xmlXPathIsInf(arg1->floatval);
6152
80.2k
  arg2i=xmlXPathIsInf(arg2->floatval);
6153
80.2k
  if (inf && strict) {
6154
52.3k
      if ((arg1i == -1 && arg2i != -1) ||
6155
48.1k
    (arg2i == 1 && arg1i != 1)) {
6156
6.48k
    ret = 1;
6157
45.8k
      } else if (arg1i == 0 && arg2i == 0) {
6158
44.4k
    ret = (arg1->floatval < arg2->floatval);
6159
44.4k
      } else {
6160
1.44k
    ret = 0;
6161
1.44k
      }
6162
52.3k
  }
6163
27.8k
  else if (inf && !strict) {
6164
7.34k
      if (arg1i == -1 || arg2i == 1) {
6165
5.05k
    ret = 1;
6166
5.05k
      } else if (arg1i == 0 && arg2i == 0) {
6167
1.88k
    ret = (arg1->floatval <= arg2->floatval);
6168
1.88k
      } else {
6169
412
    ret = 0;
6170
412
      }
6171
7.34k
  }
6172
20.5k
  else if (!inf && strict) {
6173
16.7k
      if ((arg1i == 1 && arg2i != 1) ||
6174
16.5k
    (arg2i == -1 && arg1i != -1)) {
6175
562
    ret = 1;
6176
16.2k
      } else if (arg1i == 0 && arg2i == 0) {
6177
9.31k
    ret = (arg1->floatval > arg2->floatval);
6178
9.31k
      } else {
6179
6.89k
    ret = 0;
6180
6.89k
      }
6181
16.7k
  }
6182
3.76k
  else if (!inf && !strict) {
6183
3.76k
      if (arg1i == 1 || arg2i == -1) {
6184
806
    ret = 1;
6185
2.95k
      } else if (arg1i == 0 && arg2i == 0) {
6186
2.44k
    ret = (arg1->floatval >= arg2->floatval);
6187
2.44k
      } else {
6188
516
    ret = 0;
6189
516
      }
6190
3.76k
  }
6191
80.2k
    }
6192
157k
error:
6193
157k
    xmlXPathReleaseObject(ctxt->context, arg1);
6194
157k
    xmlXPathReleaseObject(ctxt->context, arg2);
6195
157k
    return(ret);
6196
157k
}
6197
6198
/**
6199
 * xmlXPathValueFlipSign:
6200
 * @ctxt:  the XPath Parser context
6201
 *
6202
 * Implement the unary - operation on an XPath object
6203
 * The numeric operators convert their operands to numbers as if
6204
 * by calling the number function.
6205
 */
6206
void
6207
196k
xmlXPathValueFlipSign(xmlXPathParserContextPtr ctxt) {
6208
196k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return;
6209
196k
    CAST_TO_NUMBER;
6210
196k
    CHECK_TYPE(XPATH_NUMBER);
6211
196k
    ctxt->value->floatval = -ctxt->value->floatval;
6212
196k
}
6213
6214
/**
6215
 * xmlXPathAddValues:
6216
 * @ctxt:  the XPath Parser context
6217
 *
6218
 * Implement the add operation on XPath objects:
6219
 * The numeric operators convert their operands to numbers as if
6220
 * by calling the number function.
6221
 */
6222
void
6223
147k
xmlXPathAddValues(xmlXPathParserContextPtr ctxt) {
6224
147k
    xmlXPathObjectPtr arg;
6225
147k
    double val;
6226
6227
147k
    arg = xmlXPathValuePop(ctxt);
6228
147k
    if (arg == NULL)
6229
147k
  XP_ERROR(XPATH_INVALID_OPERAND);
6230
147k
    val = xmlXPathCastToNumberInternal(ctxt, arg);
6231
147k
    xmlXPathReleaseObject(ctxt->context, arg);
6232
147k
    CAST_TO_NUMBER;
6233
147k
    CHECK_TYPE(XPATH_NUMBER);
6234
147k
    ctxt->value->floatval += val;
6235
147k
}
6236
6237
/**
6238
 * xmlXPathSubValues:
6239
 * @ctxt:  the XPath Parser context
6240
 *
6241
 * Implement the subtraction operation on XPath objects:
6242
 * The numeric operators convert their operands to numbers as if
6243
 * by calling the number function.
6244
 */
6245
void
6246
154k
xmlXPathSubValues(xmlXPathParserContextPtr ctxt) {
6247
154k
    xmlXPathObjectPtr arg;
6248
154k
    double val;
6249
6250
154k
    arg = xmlXPathValuePop(ctxt);
6251
154k
    if (arg == NULL)
6252
154k
  XP_ERROR(XPATH_INVALID_OPERAND);
6253
154k
    val = xmlXPathCastToNumberInternal(ctxt, arg);
6254
154k
    xmlXPathReleaseObject(ctxt->context, arg);
6255
154k
    CAST_TO_NUMBER;
6256
154k
    CHECK_TYPE(XPATH_NUMBER);
6257
154k
    ctxt->value->floatval -= val;
6258
154k
}
6259
6260
/**
6261
 * xmlXPathMultValues:
6262
 * @ctxt:  the XPath Parser context
6263
 *
6264
 * Implement the multiply operation on XPath objects:
6265
 * The numeric operators convert their operands to numbers as if
6266
 * by calling the number function.
6267
 */
6268
void
6269
242k
xmlXPathMultValues(xmlXPathParserContextPtr ctxt) {
6270
242k
    xmlXPathObjectPtr arg;
6271
242k
    double val;
6272
6273
242k
    arg = xmlXPathValuePop(ctxt);
6274
242k
    if (arg == NULL)
6275
242k
  XP_ERROR(XPATH_INVALID_OPERAND);
6276
242k
    val = xmlXPathCastToNumberInternal(ctxt, arg);
6277
242k
    xmlXPathReleaseObject(ctxt->context, arg);
6278
242k
    CAST_TO_NUMBER;
6279
242k
    CHECK_TYPE(XPATH_NUMBER);
6280
242k
    ctxt->value->floatval *= val;
6281
242k
}
6282
6283
/**
6284
 * xmlXPathDivValues:
6285
 * @ctxt:  the XPath Parser context
6286
 *
6287
 * Implement the div operation on XPath objects @arg1 / @arg2:
6288
 * The numeric operators convert their operands to numbers as if
6289
 * by calling the number function.
6290
 */
6291
ATTRIBUTE_NO_SANITIZE("float-divide-by-zero")
6292
void
6293
5.45k
xmlXPathDivValues(xmlXPathParserContextPtr ctxt) {
6294
5.45k
    xmlXPathObjectPtr arg;
6295
5.45k
    double val;
6296
6297
5.45k
    arg = xmlXPathValuePop(ctxt);
6298
5.45k
    if (arg == NULL)
6299
5.45k
  XP_ERROR(XPATH_INVALID_OPERAND);
6300
5.45k
    val = xmlXPathCastToNumberInternal(ctxt, arg);
6301
5.45k
    xmlXPathReleaseObject(ctxt->context, arg);
6302
5.45k
    CAST_TO_NUMBER;
6303
5.45k
    CHECK_TYPE(XPATH_NUMBER);
6304
5.45k
    ctxt->value->floatval /= val;
6305
5.45k
}
6306
6307
/**
6308
 * xmlXPathModValues:
6309
 * @ctxt:  the XPath Parser context
6310
 *
6311
 * Implement the mod operation on XPath objects: @arg1 / @arg2
6312
 * The numeric operators convert their operands to numbers as if
6313
 * by calling the number function.
6314
 */
6315
void
6316
41.2k
xmlXPathModValues(xmlXPathParserContextPtr ctxt) {
6317
41.2k
    xmlXPathObjectPtr arg;
6318
41.2k
    double arg1, arg2;
6319
6320
41.2k
    arg = xmlXPathValuePop(ctxt);
6321
41.2k
    if (arg == NULL)
6322
41.2k
  XP_ERROR(XPATH_INVALID_OPERAND);
6323
41.2k
    arg2 = xmlXPathCastToNumberInternal(ctxt, arg);
6324
41.2k
    xmlXPathReleaseObject(ctxt->context, arg);
6325
41.2k
    CAST_TO_NUMBER;
6326
41.2k
    CHECK_TYPE(XPATH_NUMBER);
6327
41.0k
    arg1 = ctxt->value->floatval;
6328
41.0k
    if (arg2 == 0)
6329
969
  ctxt->value->floatval = xmlXPathNAN;
6330
40.0k
    else {
6331
40.0k
  ctxt->value->floatval = fmod(arg1, arg2);
6332
40.0k
    }
6333
41.0k
}
6334
6335
/************************************************************************
6336
 *                  *
6337
 *    The traversal functions         *
6338
 *                  *
6339
 ************************************************************************/
6340
6341
/*
6342
 * A traversal function enumerates nodes along an axis.
6343
 * Initially it must be called with NULL, and it indicates
6344
 * termination on the axis by returning NULL.
6345
 */
6346
typedef xmlNodePtr (*xmlXPathTraversalFunction)
6347
                    (xmlXPathParserContextPtr ctxt, xmlNodePtr cur);
6348
6349
/*
6350
 * xmlXPathTraversalFunctionExt:
6351
 * A traversal function enumerates nodes along an axis.
6352
 * Initially it must be called with NULL, and it indicates
6353
 * termination on the axis by returning NULL.
6354
 * The context node of the traversal is specified via @contextNode.
6355
 */
6356
typedef xmlNodePtr (*xmlXPathTraversalFunctionExt)
6357
                    (xmlNodePtr cur, xmlNodePtr contextNode);
6358
6359
/*
6360
 * xmlXPathNodeSetMergeFunction:
6361
 * Used for merging node sets in xmlXPathCollectAndTest().
6362
 */
6363
typedef xmlNodeSetPtr (*xmlXPathNodeSetMergeFunction)
6364
        (xmlNodeSetPtr, xmlNodeSetPtr);
6365
6366
6367
/**
6368
 * xmlXPathNextSelf:
6369
 * @ctxt:  the XPath Parser context
6370
 * @cur:  the current node in the traversal
6371
 *
6372
 * Traversal function for the "self" direction
6373
 * The self axis contains just the context node itself
6374
 *
6375
 * Returns the next element following that axis
6376
 */
6377
xmlNodePtr
6378
873
xmlXPathNextSelf(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6379
873
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6380
873
    if (cur == NULL)
6381
442
        return(ctxt->context->node);
6382
431
    return(NULL);
6383
873
}
6384
6385
/**
6386
 * xmlXPathNextChild:
6387
 * @ctxt:  the XPath Parser context
6388
 * @cur:  the current node in the traversal
6389
 *
6390
 * Traversal function for the "child" direction
6391
 * The child axis contains the children of the context node in document order.
6392
 *
6393
 * Returns the next element following that axis
6394
 */
6395
xmlNodePtr
6396
1.91M
xmlXPathNextChild(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6397
1.91M
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6398
1.91M
    if (cur == NULL) {
6399
821k
  if (ctxt->context->node == NULL) return(NULL);
6400
821k
  switch (ctxt->context->node->type) {
6401
519k
            case XML_ELEMENT_NODE:
6402
705k
            case XML_TEXT_NODE:
6403
705k
            case XML_CDATA_SECTION_NODE:
6404
705k
            case XML_ENTITY_REF_NODE:
6405
705k
            case XML_ENTITY_NODE:
6406
713k
            case XML_PI_NODE:
6407
730k
            case XML_COMMENT_NODE:
6408
730k
            case XML_NOTATION_NODE:
6409
730k
            case XML_DTD_NODE:
6410
730k
    return(ctxt->context->node->children);
6411
88.3k
            case XML_DOCUMENT_NODE:
6412
88.3k
            case XML_DOCUMENT_TYPE_NODE:
6413
88.3k
            case XML_DOCUMENT_FRAG_NODE:
6414
88.3k
            case XML_HTML_DOCUMENT_NODE:
6415
88.3k
    return(((xmlDocPtr) ctxt->context->node)->children);
6416
0
      case XML_ELEMENT_DECL:
6417
0
      case XML_ATTRIBUTE_DECL:
6418
0
      case XML_ENTITY_DECL:
6419
0
            case XML_ATTRIBUTE_NODE:
6420
2.63k
      case XML_NAMESPACE_DECL:
6421
2.63k
      case XML_XINCLUDE_START:
6422
2.63k
      case XML_XINCLUDE_END:
6423
2.63k
    return(NULL);
6424
821k
  }
6425
0
  return(NULL);
6426
821k
    }
6427
1.09M
    if ((cur->type == XML_DOCUMENT_NODE) ||
6428
1.09M
        (cur->type == XML_HTML_DOCUMENT_NODE))
6429
0
  return(NULL);
6430
1.09M
    return(cur->next);
6431
1.09M
}
6432
6433
/**
6434
 * xmlXPathNextChildElement:
6435
 * @ctxt:  the XPath Parser context
6436
 * @cur:  the current node in the traversal
6437
 *
6438
 * Traversal function for the "child" direction and nodes of type element.
6439
 * The child axis contains the children of the context node in document order.
6440
 *
6441
 * Returns the next element following that axis
6442
 */
6443
static xmlNodePtr
6444
5.76M
xmlXPathNextChildElement(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6445
5.76M
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6446
5.76M
    if (cur == NULL) {
6447
3.35M
  cur = ctxt->context->node;
6448
3.35M
  if (cur == NULL) return(NULL);
6449
  /*
6450
  * Get the first element child.
6451
  */
6452
3.35M
  switch (cur->type) {
6453
1.70M
            case XML_ELEMENT_NODE:
6454
1.70M
      case XML_DOCUMENT_FRAG_NODE:
6455
1.70M
      case XML_ENTITY_REF_NODE: /* URGENT TODO: entify-refs as well? */
6456
1.70M
            case XML_ENTITY_NODE:
6457
1.70M
    cur = cur->children;
6458
1.70M
    if (cur != NULL) {
6459
946k
        if (cur->type == XML_ELEMENT_NODE)
6460
359k
      return(cur);
6461
652k
        do {
6462
652k
      cur = cur->next;
6463
652k
        } while ((cur != NULL) &&
6464
367k
      (cur->type != XML_ELEMENT_NODE));
6465
586k
        return(cur);
6466
946k
    }
6467
759k
    return(NULL);
6468
479k
            case XML_DOCUMENT_NODE:
6469
479k
            case XML_HTML_DOCUMENT_NODE:
6470
479k
    return(xmlDocGetRootElement((xmlDocPtr) cur));
6471
1.16M
      default:
6472
1.16M
    return(NULL);
6473
3.35M
  }
6474
0
  return(NULL);
6475
3.35M
    }
6476
    /*
6477
    * Get the next sibling element node.
6478
    */
6479
2.41M
    switch (cur->type) {
6480
2.41M
  case XML_ELEMENT_NODE:
6481
2.41M
  case XML_TEXT_NODE:
6482
2.41M
  case XML_ENTITY_REF_NODE:
6483
2.41M
  case XML_ENTITY_NODE:
6484
2.41M
  case XML_CDATA_SECTION_NODE:
6485
2.41M
  case XML_PI_NODE:
6486
2.41M
  case XML_COMMENT_NODE:
6487
2.41M
  case XML_XINCLUDE_END:
6488
2.41M
      break;
6489
  /* case XML_DTD_NODE: */ /* URGENT TODO: DTD-node as well? */
6490
0
  default:
6491
0
      return(NULL);
6492
2.41M
    }
6493
2.41M
    if (cur->next != NULL) {
6494
1.60M
  if (cur->next->type == XML_ELEMENT_NODE)
6495
857k
      return(cur->next);
6496
748k
  cur = cur->next;
6497
837k
  do {
6498
837k
      cur = cur->next;
6499
837k
  } while ((cur != NULL) && (cur->type != XML_ELEMENT_NODE));
6500
748k
  return(cur);
6501
1.60M
    }
6502
808k
    return(NULL);
6503
2.41M
}
6504
6505
/**
6506
 * xmlXPathNextDescendant:
6507
 * @ctxt:  the XPath Parser context
6508
 * @cur:  the current node in the traversal
6509
 *
6510
 * Traversal function for the "descendant" direction
6511
 * the descendant axis contains the descendants of the context node in document
6512
 * order; a descendant is a child or a child of a child and so on.
6513
 *
6514
 * Returns the next element following that axis
6515
 */
6516
xmlNodePtr
6517
16.0M
xmlXPathNextDescendant(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6518
16.0M
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6519
16.0M
    if (cur == NULL) {
6520
562k
  if (ctxt->context->node == NULL)
6521
0
      return(NULL);
6522
562k
  if ((ctxt->context->node->type == XML_ATTRIBUTE_NODE) ||
6523
562k
      (ctxt->context->node->type == XML_NAMESPACE_DECL))
6524
32.0k
      return(NULL);
6525
6526
530k
        if (ctxt->context->node == (xmlNodePtr) ctxt->context->doc)
6527
448k
      return(ctxt->context->doc->children);
6528
82.1k
        return(ctxt->context->node->children);
6529
530k
    }
6530
6531
15.4M
    if (cur->type == XML_NAMESPACE_DECL)
6532
0
        return(NULL);
6533
15.4M
    if (cur->children != NULL) {
6534
  /*
6535
   * Do not descend on entities declarations
6536
   */
6537
4.70M
  if (cur->children->type != XML_ENTITY_DECL) {
6538
4.70M
      cur = cur->children;
6539
      /*
6540
       * Skip DTDs
6541
       */
6542
4.70M
      if (cur->type != XML_DTD_NODE)
6543
4.70M
    return(cur);
6544
4.70M
  }
6545
4.70M
    }
6546
6547
10.7M
    if (cur == ctxt->context->node) return(NULL);
6548
6549
10.7M
    while (cur->next != NULL) {
6550
7.61M
  cur = cur->next;
6551
7.61M
  if ((cur->type != XML_ENTITY_DECL) &&
6552
7.61M
      (cur->type != XML_DTD_NODE))
6553
7.61M
      return(cur);
6554
7.61M
    }
6555
6556
5.21M
    do {
6557
5.21M
        cur = cur->parent;
6558
5.21M
  if (cur == NULL) break;
6559
5.21M
  if (cur == ctxt->context->node) return(NULL);
6560
4.46M
  if (cur->next != NULL) {
6561
2.39M
      cur = cur->next;
6562
2.39M
      return(cur);
6563
2.39M
  }
6564
4.46M
    } while (cur != NULL);
6565
0
    return(cur);
6566
3.14M
}
6567
6568
/**
6569
 * xmlXPathNextDescendantOrSelf:
6570
 * @ctxt:  the XPath Parser context
6571
 * @cur:  the current node in the traversal
6572
 *
6573
 * Traversal function for the "descendant-or-self" direction
6574
 * the descendant-or-self axis contains the context node and the descendants
6575
 * of the context node in document order; thus the context node is the first
6576
 * node on the axis, and the first child of the context node is the second node
6577
 * on the axis
6578
 *
6579
 * Returns the next element following that axis
6580
 */
6581
xmlNodePtr
6582
5.00M
xmlXPathNextDescendantOrSelf(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6583
5.00M
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6584
5.00M
    if (cur == NULL)
6585
426k
        return(ctxt->context->node);
6586
6587
4.58M
    if (ctxt->context->node == NULL)
6588
0
        return(NULL);
6589
4.58M
    if ((ctxt->context->node->type == XML_ATTRIBUTE_NODE) ||
6590
4.58M
        (ctxt->context->node->type == XML_NAMESPACE_DECL))
6591
182k
        return(NULL);
6592
6593
4.39M
    return(xmlXPathNextDescendant(ctxt, cur));
6594
4.58M
}
6595
6596
/**
6597
 * xmlXPathNextParent:
6598
 * @ctxt:  the XPath Parser context
6599
 * @cur:  the current node in the traversal
6600
 *
6601
 * Traversal function for the "parent" direction
6602
 * The parent axis contains the parent of the context node, if there is one.
6603
 *
6604
 * Returns the next element following that axis
6605
 */
6606
xmlNodePtr
6607
317k
xmlXPathNextParent(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6608
317k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6609
    /*
6610
     * the parent of an attribute or namespace node is the element
6611
     * to which the attribute or namespace node is attached
6612
     * Namespace handling !!!
6613
     */
6614
317k
    if (cur == NULL) {
6615
165k
  if (ctxt->context->node == NULL) return(NULL);
6616
165k
  switch (ctxt->context->node->type) {
6617
95.4k
            case XML_ELEMENT_NODE:
6618
144k
            case XML_TEXT_NODE:
6619
144k
            case XML_CDATA_SECTION_NODE:
6620
144k
            case XML_ENTITY_REF_NODE:
6621
144k
            case XML_ENTITY_NODE:
6622
145k
            case XML_PI_NODE:
6623
146k
            case XML_COMMENT_NODE:
6624
146k
            case XML_NOTATION_NODE:
6625
146k
            case XML_DTD_NODE:
6626
146k
      case XML_ELEMENT_DECL:
6627
146k
      case XML_ATTRIBUTE_DECL:
6628
146k
      case XML_XINCLUDE_START:
6629
146k
      case XML_XINCLUDE_END:
6630
146k
      case XML_ENTITY_DECL:
6631
146k
    if (ctxt->context->node->parent == NULL)
6632
0
        return((xmlNodePtr) ctxt->context->doc);
6633
146k
    if ((ctxt->context->node->parent->type == XML_ELEMENT_NODE) &&
6634
121k
        ((ctxt->context->node->parent->name[0] == ' ') ||
6635
121k
         (xmlStrEqual(ctxt->context->node->parent->name,
6636
121k
         BAD_CAST "fake node libxslt"))))
6637
216
        return(NULL);
6638
146k
    return(ctxt->context->node->parent);
6639
202
            case XML_ATTRIBUTE_NODE: {
6640
202
    xmlAttrPtr att = (xmlAttrPtr) ctxt->context->node;
6641
6642
202
    return(att->parent);
6643
146k
      }
6644
11.3k
            case XML_DOCUMENT_NODE:
6645
11.3k
            case XML_DOCUMENT_TYPE_NODE:
6646
11.3k
            case XML_DOCUMENT_FRAG_NODE:
6647
11.3k
            case XML_HTML_DOCUMENT_NODE:
6648
11.3k
                return(NULL);
6649
7.20k
      case XML_NAMESPACE_DECL: {
6650
7.20k
    xmlNsPtr ns = (xmlNsPtr) ctxt->context->node;
6651
6652
7.20k
    if ((ns->next != NULL) &&
6653
7.20k
        (ns->next->type != XML_NAMESPACE_DECL))
6654
7.20k
        return((xmlNodePtr) ns->next);
6655
0
                return(NULL);
6656
7.20k
      }
6657
165k
  }
6658
165k
    }
6659
152k
    return(NULL);
6660
317k
}
6661
6662
/**
6663
 * xmlXPathNextAncestor:
6664
 * @ctxt:  the XPath Parser context
6665
 * @cur:  the current node in the traversal
6666
 *
6667
 * Traversal function for the "ancestor" direction
6668
 * the ancestor axis contains the ancestors of the context node; the ancestors
6669
 * of the context node consist of the parent of context node and the parent's
6670
 * parent and so on; the nodes are ordered in reverse document order; thus the
6671
 * parent is the first node on the axis, and the parent's parent is the second
6672
 * node on the axis
6673
 *
6674
 * Returns the next element following that axis
6675
 */
6676
xmlNodePtr
6677
265k
xmlXPathNextAncestor(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6678
265k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6679
    /*
6680
     * the parent of an attribute or namespace node is the element
6681
     * to which the attribute or namespace node is attached
6682
     * !!!!!!!!!!!!!
6683
     */
6684
265k
    if (cur == NULL) {
6685
72.9k
  if (ctxt->context->node == NULL) return(NULL);
6686
72.9k
  switch (ctxt->context->node->type) {
6687
16.8k
            case XML_ELEMENT_NODE:
6688
36.1k
            case XML_TEXT_NODE:
6689
36.1k
            case XML_CDATA_SECTION_NODE:
6690
36.1k
            case XML_ENTITY_REF_NODE:
6691
36.1k
            case XML_ENTITY_NODE:
6692
38.3k
            case XML_PI_NODE:
6693
39.6k
            case XML_COMMENT_NODE:
6694
39.6k
      case XML_DTD_NODE:
6695
39.6k
      case XML_ELEMENT_DECL:
6696
39.6k
      case XML_ATTRIBUTE_DECL:
6697
39.6k
      case XML_ENTITY_DECL:
6698
39.6k
            case XML_NOTATION_NODE:
6699
39.6k
      case XML_XINCLUDE_START:
6700
39.6k
      case XML_XINCLUDE_END:
6701
39.6k
    if (ctxt->context->node->parent == NULL)
6702
0
        return((xmlNodePtr) ctxt->context->doc);
6703
39.6k
    if ((ctxt->context->node->parent->type == XML_ELEMENT_NODE) &&
6704
36.7k
        ((ctxt->context->node->parent->name[0] == ' ') ||
6705
36.7k
         (xmlStrEqual(ctxt->context->node->parent->name,
6706
36.7k
         BAD_CAST "fake node libxslt"))))
6707
0
        return(NULL);
6708
39.6k
    return(ctxt->context->node->parent);
6709
0
            case XML_ATTRIBUTE_NODE: {
6710
0
    xmlAttrPtr tmp = (xmlAttrPtr) ctxt->context->node;
6711
6712
0
    return(tmp->parent);
6713
39.6k
      }
6714
6.36k
            case XML_DOCUMENT_NODE:
6715
6.36k
            case XML_DOCUMENT_TYPE_NODE:
6716
6.36k
            case XML_DOCUMENT_FRAG_NODE:
6717
6.36k
            case XML_HTML_DOCUMENT_NODE:
6718
6.36k
                return(NULL);
6719
26.9k
      case XML_NAMESPACE_DECL: {
6720
26.9k
    xmlNsPtr ns = (xmlNsPtr) ctxt->context->node;
6721
6722
26.9k
    if ((ns->next != NULL) &&
6723
26.9k
        (ns->next->type != XML_NAMESPACE_DECL))
6724
26.9k
        return((xmlNodePtr) ns->next);
6725
    /* Bad, how did that namespace end up here ? */
6726
0
                return(NULL);
6727
26.9k
      }
6728
72.9k
  }
6729
0
  return(NULL);
6730
72.9k
    }
6731
192k
    if (cur == ctxt->context->doc->children)
6732
42.2k
  return((xmlNodePtr) ctxt->context->doc);
6733
150k
    if (cur == (xmlNodePtr) ctxt->context->doc)
6734
51.3k
  return(NULL);
6735
98.7k
    switch (cur->type) {
6736
65.1k
  case XML_ELEMENT_NODE:
6737
70.3k
  case XML_TEXT_NODE:
6738
70.3k
  case XML_CDATA_SECTION_NODE:
6739
70.3k
  case XML_ENTITY_REF_NODE:
6740
70.3k
  case XML_ENTITY_NODE:
6741
71.1k
  case XML_PI_NODE:
6742
71.6k
  case XML_COMMENT_NODE:
6743
71.6k
  case XML_NOTATION_NODE:
6744
71.6k
  case XML_DTD_NODE:
6745
71.6k
        case XML_ELEMENT_DECL:
6746
71.6k
        case XML_ATTRIBUTE_DECL:
6747
71.6k
        case XML_ENTITY_DECL:
6748
71.6k
  case XML_XINCLUDE_START:
6749
71.6k
  case XML_XINCLUDE_END:
6750
71.6k
      if (cur->parent == NULL)
6751
0
    return(NULL);
6752
71.6k
      if ((cur->parent->type == XML_ELEMENT_NODE) &&
6753
38.5k
    ((cur->parent->name[0] == ' ') ||
6754
38.5k
     (xmlStrEqual(cur->parent->name,
6755
38.5k
            BAD_CAST "fake node libxslt"))))
6756
0
    return(NULL);
6757
71.6k
      return(cur->parent);
6758
0
  case XML_ATTRIBUTE_NODE: {
6759
0
      xmlAttrPtr att = (xmlAttrPtr) cur;
6760
6761
0
      return(att->parent);
6762
71.6k
  }
6763
149
  case XML_NAMESPACE_DECL: {
6764
149
      xmlNsPtr ns = (xmlNsPtr) cur;
6765
6766
149
      if ((ns->next != NULL) &&
6767
149
          (ns->next->type != XML_NAMESPACE_DECL))
6768
149
          return((xmlNodePtr) ns->next);
6769
      /* Bad, how did that namespace end up here ? */
6770
0
            return(NULL);
6771
149
  }
6772
26.9k
  case XML_DOCUMENT_NODE:
6773
26.9k
  case XML_DOCUMENT_TYPE_NODE:
6774
26.9k
  case XML_DOCUMENT_FRAG_NODE:
6775
26.9k
  case XML_HTML_DOCUMENT_NODE:
6776
26.9k
      return(NULL);
6777
98.7k
    }
6778
0
    return(NULL);
6779
98.7k
}
6780
6781
/**
6782
 * xmlXPathNextAncestorOrSelf:
6783
 * @ctxt:  the XPath Parser context
6784
 * @cur:  the current node in the traversal
6785
 *
6786
 * Traversal function for the "ancestor-or-self" direction
6787
 * he ancestor-or-self axis contains the context node and ancestors of
6788
 * the context node in reverse document order; thus the context node is
6789
 * the first node on the axis, and the context node's parent the second;
6790
 * parent here is defined the same as with the parent axis.
6791
 *
6792
 * Returns the next element following that axis
6793
 */
6794
xmlNodePtr
6795
56.1k
xmlXPathNextAncestorOrSelf(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6796
56.1k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6797
56.1k
    if (cur == NULL)
6798
11.7k
        return(ctxt->context->node);
6799
44.4k
    return(xmlXPathNextAncestor(ctxt, cur));
6800
56.1k
}
6801
6802
/**
6803
 * xmlXPathNextFollowingSibling:
6804
 * @ctxt:  the XPath Parser context
6805
 * @cur:  the current node in the traversal
6806
 *
6807
 * Traversal function for the "following-sibling" direction
6808
 * The following-sibling axis contains the following siblings of the context
6809
 * node in document order.
6810
 *
6811
 * Returns the next element following that axis
6812
 */
6813
xmlNodePtr
6814
1.41k
xmlXPathNextFollowingSibling(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6815
1.41k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6816
1.41k
    if ((ctxt->context->node->type == XML_ATTRIBUTE_NODE) ||
6817
1.38k
  (ctxt->context->node->type == XML_NAMESPACE_DECL))
6818
255
  return(NULL);
6819
1.15k
    if (cur == (xmlNodePtr) ctxt->context->doc)
6820
0
        return(NULL);
6821
1.15k
    if (cur == NULL)
6822
459
        return(ctxt->context->node->next);
6823
699
    return(cur->next);
6824
1.15k
}
6825
6826
/**
6827
 * xmlXPathNextPrecedingSibling:
6828
 * @ctxt:  the XPath Parser context
6829
 * @cur:  the current node in the traversal
6830
 *
6831
 * Traversal function for the "preceding-sibling" direction
6832
 * The preceding-sibling axis contains the preceding siblings of the context
6833
 * node in reverse document order; the first preceding sibling is first on the
6834
 * axis; the sibling preceding that node is the second on the axis and so on.
6835
 *
6836
 * Returns the next element following that axis
6837
 */
6838
xmlNodePtr
6839
49.2k
xmlXPathNextPrecedingSibling(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6840
49.2k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6841
49.2k
    if ((ctxt->context->node->type == XML_ATTRIBUTE_NODE) ||
6842
49.2k
  (ctxt->context->node->type == XML_NAMESPACE_DECL))
6843
906
  return(NULL);
6844
48.3k
    if (cur == (xmlNodePtr) ctxt->context->doc)
6845
0
        return(NULL);
6846
48.3k
    if (cur == NULL)
6847
9.67k
        return(ctxt->context->node->prev);
6848
38.7k
    if ((cur->prev != NULL) && (cur->prev->type == XML_DTD_NODE)) {
6849
0
  cur = cur->prev;
6850
0
  if (cur == NULL)
6851
0
      return(ctxt->context->node->prev);
6852
0
    }
6853
38.7k
    return(cur->prev);
6854
38.7k
}
6855
6856
/**
6857
 * xmlXPathNextFollowing:
6858
 * @ctxt:  the XPath Parser context
6859
 * @cur:  the current node in the traversal
6860
 *
6861
 * Traversal function for the "following" direction
6862
 * The following axis contains all nodes in the same document as the context
6863
 * node that are after the context node in document order, excluding any
6864
 * descendants and excluding attribute nodes and namespace nodes; the nodes
6865
 * are ordered in document order
6866
 *
6867
 * Returns the next element following that axis
6868
 */
6869
xmlNodePtr
6870
14.1k
xmlXPathNextFollowing(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
6871
14.1k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6872
14.1k
    if ((cur != NULL) && (cur->type  != XML_ATTRIBUTE_NODE) &&
6873
11.1k
        (cur->type != XML_NAMESPACE_DECL) && (cur->children != NULL))
6874
1.38k
        return(cur->children);
6875
6876
12.7k
    if (cur == NULL) {
6877
3.03k
        cur = ctxt->context->node;
6878
3.03k
        if (cur->type == XML_ATTRIBUTE_NODE) {
6879
268
            cur = cur->parent;
6880
2.76k
        } else if (cur->type == XML_NAMESPACE_DECL) {
6881
97
            xmlNsPtr ns = (xmlNsPtr) cur;
6882
6883
97
            if ((ns->next == NULL) ||
6884
97
                (ns->next->type == XML_NAMESPACE_DECL))
6885
0
                return (NULL);
6886
97
            cur = (xmlNodePtr) ns->next;
6887
97
        }
6888
3.03k
    }
6889
12.7k
    if (cur == NULL) return(NULL) ; /* ERROR */
6890
12.7k
    if (cur->next != NULL) return(cur->next) ;
6891
7.46k
    do {
6892
7.46k
        cur = cur->parent;
6893
7.46k
        if (cur == NULL) break;
6894
7.37k
        if (cur == (xmlNodePtr) ctxt->context->doc) return(NULL);
6895
4.43k
        if (cur->next != NULL) return(cur->next);
6896
4.43k
    } while (cur != NULL);
6897
93
    return(cur);
6898
4.81k
}
6899
6900
/*
6901
 * xmlXPathIsAncestor:
6902
 * @ancestor:  the ancestor node
6903
 * @node:  the current node
6904
 *
6905
 * Check that @ancestor is a @node's ancestor
6906
 *
6907
 * returns 1 if @ancestor is a @node's ancestor, 0 otherwise.
6908
 */
6909
static int
6910
0
xmlXPathIsAncestor(xmlNodePtr ancestor, xmlNodePtr node) {
6911
0
    if ((ancestor == NULL) || (node == NULL)) return(0);
6912
0
    if (node->type == XML_NAMESPACE_DECL)
6913
0
        return(0);
6914
0
    if (ancestor->type == XML_NAMESPACE_DECL)
6915
0
        return(0);
6916
    /* nodes need to be in the same document */
6917
0
    if (ancestor->doc != node->doc) return(0);
6918
    /* avoid searching if ancestor or node is the root node */
6919
0
    if (ancestor == (xmlNodePtr) node->doc) return(1);
6920
0
    if (node == (xmlNodePtr) ancestor->doc) return(0);
6921
0
    while (node->parent != NULL) {
6922
0
        if (node->parent == ancestor)
6923
0
            return(1);
6924
0
  node = node->parent;
6925
0
    }
6926
0
    return(0);
6927
0
}
6928
6929
/**
6930
 * xmlXPathNextPreceding:
6931
 * @ctxt:  the XPath Parser context
6932
 * @cur:  the current node in the traversal
6933
 *
6934
 * Traversal function for the "preceding" direction
6935
 * the preceding axis contains all nodes in the same document as the context
6936
 * node that are before the context node in document order, excluding any
6937
 * ancestors and excluding attribute nodes and namespace nodes; the nodes are
6938
 * ordered in reverse document order
6939
 *
6940
 * Returns the next element following that axis
6941
 */
6942
xmlNodePtr
6943
xmlXPathNextPreceding(xmlXPathParserContextPtr ctxt, xmlNodePtr cur)
6944
0
{
6945
0
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6946
0
    if (cur == NULL) {
6947
0
        cur = ctxt->context->node;
6948
0
        if (cur->type == XML_ATTRIBUTE_NODE) {
6949
0
            cur = cur->parent;
6950
0
        } else if (cur->type == XML_NAMESPACE_DECL) {
6951
0
            xmlNsPtr ns = (xmlNsPtr) cur;
6952
6953
0
            if ((ns->next == NULL) ||
6954
0
                (ns->next->type == XML_NAMESPACE_DECL))
6955
0
                return (NULL);
6956
0
            cur = (xmlNodePtr) ns->next;
6957
0
        }
6958
0
    }
6959
0
    if ((cur == NULL) || (cur->type == XML_NAMESPACE_DECL))
6960
0
  return (NULL);
6961
0
    if ((cur->prev != NULL) && (cur->prev->type == XML_DTD_NODE))
6962
0
  cur = cur->prev;
6963
0
    do {
6964
0
        if (cur->prev != NULL) {
6965
0
            for (cur = cur->prev; cur->last != NULL; cur = cur->last) ;
6966
0
            return (cur);
6967
0
        }
6968
6969
0
        cur = cur->parent;
6970
0
        if (cur == NULL)
6971
0
            return (NULL);
6972
0
        if (cur == ctxt->context->doc->children)
6973
0
            return (NULL);
6974
0
    } while (xmlXPathIsAncestor(cur, ctxt->context->node));
6975
0
    return (cur);
6976
0
}
6977
6978
/**
6979
 * xmlXPathNextPrecedingInternal:
6980
 * @ctxt:  the XPath Parser context
6981
 * @cur:  the current node in the traversal
6982
 *
6983
 * Traversal function for the "preceding" direction
6984
 * the preceding axis contains all nodes in the same document as the context
6985
 * node that are before the context node in document order, excluding any
6986
 * ancestors and excluding attribute nodes and namespace nodes; the nodes are
6987
 * ordered in reverse document order
6988
 * This is a faster implementation but internal only since it requires a
6989
 * state kept in the parser context: ctxt->ancestor.
6990
 *
6991
 * Returns the next element following that axis
6992
 */
6993
static xmlNodePtr
6994
xmlXPathNextPrecedingInternal(xmlXPathParserContextPtr ctxt,
6995
                              xmlNodePtr cur)
6996
32.3k
{
6997
32.3k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
6998
32.3k
    if (cur == NULL) {
6999
5.72k
        cur = ctxt->context->node;
7000
5.72k
        if (cur == NULL)
7001
0
            return (NULL);
7002
5.72k
        if (cur->type == XML_ATTRIBUTE_NODE) {
7003
217
            cur = cur->parent;
7004
5.50k
        } else if (cur->type == XML_NAMESPACE_DECL) {
7005
284
            xmlNsPtr ns = (xmlNsPtr) cur;
7006
7007
284
            if ((ns->next == NULL) ||
7008
284
                (ns->next->type == XML_NAMESPACE_DECL))
7009
0
                return (NULL);
7010
284
            cur = (xmlNodePtr) ns->next;
7011
284
        }
7012
5.72k
        ctxt->ancestor = cur->parent;
7013
5.72k
    }
7014
32.3k
    if (cur->type == XML_NAMESPACE_DECL)
7015
0
        return(NULL);
7016
32.3k
    if ((cur->prev != NULL) && (cur->prev->type == XML_DTD_NODE))
7017
0
  cur = cur->prev;
7018
44.4k
    while (cur->prev == NULL) {
7019
20.1k
        cur = cur->parent;
7020
20.1k
        if (cur == NULL)
7021
5.34k
            return (NULL);
7022
14.8k
        if (cur == ctxt->context->doc->children)
7023
370
            return (NULL);
7024
14.4k
        if (cur != ctxt->ancestor)
7025
2.38k
            return (cur);
7026
12.0k
        ctxt->ancestor = cur->parent;
7027
12.0k
    }
7028
24.2k
    cur = cur->prev;
7029
26.6k
    while (cur->last != NULL)
7030
2.38k
        cur = cur->last;
7031
24.2k
    return (cur);
7032
32.3k
}
7033
7034
/**
7035
 * xmlXPathNextNamespace:
7036
 * @ctxt:  the XPath Parser context
7037
 * @cur:  the current attribute in the traversal
7038
 *
7039
 * Traversal function for the "namespace" direction
7040
 * the namespace axis contains the namespace nodes of the context node;
7041
 * the order of nodes on this axis is implementation-defined; the axis will
7042
 * be empty unless the context node is an element
7043
 *
7044
 * We keep the XML namespace node at the end of the list.
7045
 *
7046
 * Returns the next element following that axis
7047
 */
7048
xmlNodePtr
7049
1.42M
xmlXPathNextNamespace(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
7050
1.42M
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
7051
1.42M
    if (ctxt->context->node->type != XML_ELEMENT_NODE) return(NULL);
7052
1.32M
    if (cur == NULL) {
7053
252k
        if (ctxt->context->tmpNsList != NULL)
7054
5.54k
      xmlFree(ctxt->context->tmpNsList);
7055
252k
  ctxt->context->tmpNsNr = 0;
7056
252k
        if (xmlGetNsListSafe(ctxt->context->doc, ctxt->context->node,
7057
252k
                             &ctxt->context->tmpNsList) < 0) {
7058
38
            xmlXPathPErrMemory(ctxt);
7059
38
            return(NULL);
7060
38
        }
7061
252k
        if (ctxt->context->tmpNsList != NULL) {
7062
1.12M
            while (ctxt->context->tmpNsList[ctxt->context->tmpNsNr] != NULL) {
7063
876k
                ctxt->context->tmpNsNr++;
7064
876k
            }
7065
249k
        }
7066
252k
  return((xmlNodePtr) xmlXPathXMLNamespace);
7067
252k
    }
7068
1.07M
    if (ctxt->context->tmpNsNr > 0) {
7069
845k
  return (xmlNodePtr)ctxt->context->tmpNsList[--ctxt->context->tmpNsNr];
7070
845k
    } else {
7071
228k
  if (ctxt->context->tmpNsList != NULL)
7072
226k
      xmlFree(ctxt->context->tmpNsList);
7073
228k
  ctxt->context->tmpNsList = NULL;
7074
228k
  return(NULL);
7075
228k
    }
7076
1.07M
}
7077
7078
/**
7079
 * xmlXPathNextAttribute:
7080
 * @ctxt:  the XPath Parser context
7081
 * @cur:  the current attribute in the traversal
7082
 *
7083
 * Traversal function for the "attribute" direction
7084
 * TODO: support DTD inherited default attributes
7085
 *
7086
 * Returns the next element following that axis
7087
 */
7088
xmlNodePtr
7089
995k
xmlXPathNextAttribute(xmlXPathParserContextPtr ctxt, xmlNodePtr cur) {
7090
995k
    if ((ctxt == NULL) || (ctxt->context == NULL)) return(NULL);
7091
995k
    if (ctxt->context->node == NULL)
7092
0
  return(NULL);
7093
995k
    if (ctxt->context->node->type != XML_ELEMENT_NODE)
7094
245k
  return(NULL);
7095
749k
    if (cur == NULL) {
7096
426k
        if (ctxt->context->node == (xmlNodePtr) ctxt->context->doc)
7097
0
      return(NULL);
7098
426k
        return((xmlNodePtr)ctxt->context->node->properties);
7099
426k
    }
7100
323k
    return((xmlNodePtr)cur->next);
7101
749k
}
7102
7103
/************************************************************************
7104
 *                  *
7105
 *    NodeTest Functions          *
7106
 *                  *
7107
 ************************************************************************/
7108
7109
#define IS_FUNCTION     200
7110
7111
7112
/************************************************************************
7113
 *                  *
7114
 *    Implicit tree core function library     *
7115
 *                  *
7116
 ************************************************************************/
7117
7118
/**
7119
 * xmlXPathRoot:
7120
 * @ctxt:  the XPath Parser context
7121
 *
7122
 * Initialize the context to the root of the document
7123
 */
7124
void
7125
1.40M
xmlXPathRoot(xmlXPathParserContextPtr ctxt) {
7126
1.40M
    if ((ctxt == NULL) || (ctxt->context == NULL))
7127
0
  return;
7128
1.40M
    xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt,
7129
1.40M
                                            (xmlNodePtr) ctxt->context->doc));
7130
1.40M
}
7131
7132
/************************************************************************
7133
 *                  *
7134
 *    The explicit core function library      *
7135
 *http://www.w3.org/Style/XSL/Group/1999/07/xpath-19990705.html#corelib *
7136
 *                  *
7137
 ************************************************************************/
7138
7139
7140
/**
7141
 * xmlXPathLastFunction:
7142
 * @ctxt:  the XPath Parser context
7143
 * @nargs:  the number of arguments
7144
 *
7145
 * Implement the last() XPath function
7146
 *    number last()
7147
 * The last function returns the number of nodes in the context node list.
7148
 */
7149
void
7150
53.7k
xmlXPathLastFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7151
158k
    CHECK_ARITY(0);
7152
158k
    if (ctxt->context->contextSize >= 0) {
7153
52.4k
  xmlXPathValuePush(ctxt,
7154
52.4k
      xmlXPathCacheNewFloat(ctxt, (double) ctxt->context->contextSize));
7155
52.4k
    } else {
7156
0
  XP_ERROR(XPATH_INVALID_CTXT_SIZE);
7157
0
    }
7158
158k
}
7159
7160
/**
7161
 * xmlXPathPositionFunction:
7162
 * @ctxt:  the XPath Parser context
7163
 * @nargs:  the number of arguments
7164
 *
7165
 * Implement the position() XPath function
7166
 *    number position()
7167
 * The position function returns the position of the context node in the
7168
 * context node list. The first position is 1, and so the last position
7169
 * will be equal to last().
7170
 */
7171
void
7172
33.5k
xmlXPathPositionFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7173
98.7k
    CHECK_ARITY(0);
7174
98.7k
    if (ctxt->context->proximityPosition >= 0) {
7175
32.5k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt,
7176
32.5k
            (double) ctxt->context->proximityPosition));
7177
32.5k
    } else {
7178
0
  XP_ERROR(XPATH_INVALID_CTXT_POSITION);
7179
0
    }
7180
98.7k
}
7181
7182
/**
7183
 * xmlXPathCountFunction:
7184
 * @ctxt:  the XPath Parser context
7185
 * @nargs:  the number of arguments
7186
 *
7187
 * Implement the count() XPath function
7188
 *    number count(node-set)
7189
 */
7190
void
7191
5.47k
xmlXPathCountFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7192
5.47k
    xmlXPathObjectPtr cur;
7193
7194
16.2k
    CHECK_ARITY(1);
7195
16.2k
    if ((ctxt->value == NULL) ||
7196
5.38k
  ((ctxt->value->type != XPATH_NODESET) &&
7197
82
   (ctxt->value->type != XPATH_XSLT_TREE)))
7198
5.30k
  XP_ERROR(XPATH_INVALID_TYPE);
7199
5.30k
    cur = xmlXPathValuePop(ctxt);
7200
7201
5.30k
    if ((cur == NULL) || (cur->nodesetval == NULL))
7202
0
  xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt, 0.0));
7203
5.30k
    else
7204
5.30k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt,
7205
5.30k
      (double) cur->nodesetval->nodeNr));
7206
5.30k
    xmlXPathReleaseObject(ctxt->context, cur);
7207
5.30k
}
7208
7209
/**
7210
 * xmlXPathGetElementsByIds:
7211
 * @doc:  the document
7212
 * @ids:  a whitespace separated list of IDs
7213
 *
7214
 * Selects elements by their unique ID.
7215
 *
7216
 * Returns a node-set of selected elements.
7217
 */
7218
static xmlNodeSetPtr
7219
46.4k
xmlXPathGetElementsByIds (xmlDocPtr doc, const xmlChar *ids) {
7220
46.4k
    xmlNodeSetPtr ret;
7221
46.4k
    const xmlChar *cur = ids;
7222
46.4k
    xmlChar *ID;
7223
46.4k
    xmlAttrPtr attr;
7224
46.4k
    xmlNodePtr elem = NULL;
7225
7226
46.4k
    if (ids == NULL) return(NULL);
7227
7228
45.9k
    ret = xmlXPathNodeSetCreate(NULL);
7229
45.9k
    if (ret == NULL)
7230
6
        return(ret);
7231
7232
45.9k
    while (IS_BLANK_CH(*cur)) cur++;
7233
218k
    while (*cur != 0) {
7234
14.0M
  while ((!IS_BLANK_CH(*cur)) && (*cur != 0))
7235
13.8M
      cur++;
7236
7237
172k
        ID = xmlStrndup(ids, cur - ids);
7238
172k
  if (ID == NULL) {
7239
16
            xmlXPathFreeNodeSet(ret);
7240
16
            return(NULL);
7241
16
        }
7242
        /*
7243
         * We used to check the fact that the value passed
7244
         * was an NCName, but this generated much troubles for
7245
         * me and Aleksey Sanin, people blatantly violated that
7246
         * constraint, like Visa3D spec.
7247
         * if (xmlValidateNCName(ID, 1) == 0)
7248
         */
7249
172k
        attr = xmlGetID(doc, ID);
7250
172k
        xmlFree(ID);
7251
172k
        if (attr != NULL) {
7252
43
            if (attr->type == XML_ATTRIBUTE_NODE)
7253
43
                elem = attr->parent;
7254
0
            else if (attr->type == XML_ELEMENT_NODE)
7255
0
                elem = (xmlNodePtr) attr;
7256
0
            else
7257
0
                elem = NULL;
7258
43
            if (elem != NULL) {
7259
43
                if (xmlXPathNodeSetAdd(ret, elem) < 0) {
7260
1
                    xmlXPathFreeNodeSet(ret);
7261
1
                    return(NULL);
7262
1
                }
7263
43
            }
7264
43
        }
7265
7266
383k
  while (IS_BLANK_CH(*cur)) cur++;
7267
172k
  ids = cur;
7268
172k
    }
7269
45.9k
    return(ret);
7270
45.9k
}
7271
7272
/**
7273
 * xmlXPathIdFunction:
7274
 * @ctxt:  the XPath Parser context
7275
 * @nargs:  the number of arguments
7276
 *
7277
 * Implement the id() XPath function
7278
 *    node-set id(object)
7279
 * The id function selects elements by their unique ID
7280
 * (see [5.2.1 Unique IDs]). When the argument to id is of type node-set,
7281
 * then the result is the union of the result of applying id to the
7282
 * string value of each of the nodes in the argument node-set. When the
7283
 * argument to id is of any other type, the argument is converted to a
7284
 * string as if by a call to the string function; the string is split
7285
 * into a whitespace-separated list of tokens (whitespace is any sequence
7286
 * of characters matching the production S); the result is a node-set
7287
 * containing the elements in the same document as the context node that
7288
 * have a unique ID equal to any of the tokens in the list.
7289
 */
7290
void
7291
44.8k
xmlXPathIdFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7292
44.8k
    xmlChar *tokens;
7293
44.8k
    xmlNodeSetPtr ret;
7294
44.8k
    xmlXPathObjectPtr obj;
7295
7296
134k
    CHECK_ARITY(1);
7297
134k
    obj = xmlXPathValuePop(ctxt);
7298
134k
    if (obj == NULL) XP_ERROR(XPATH_INVALID_OPERAND);
7299
44.6k
    if ((obj->type == XPATH_NODESET) || (obj->type == XPATH_XSLT_TREE)) {
7300
12.8k
  xmlNodeSetPtr ns;
7301
12.8k
  int i;
7302
7303
12.8k
  ret = xmlXPathNodeSetCreate(NULL);
7304
12.8k
        if (ret == NULL)
7305
85
            xmlXPathPErrMemory(ctxt);
7306
7307
12.8k
  if (obj->nodesetval != NULL) {
7308
27.4k
      for (i = 0; i < obj->nodesetval->nodeNr; i++) {
7309
14.6k
    tokens =
7310
14.6k
        xmlXPathCastNodeToString(obj->nodesetval->nodeTab[i]);
7311
14.6k
                if (tokens == NULL)
7312
353
                    xmlXPathPErrMemory(ctxt);
7313
14.6k
    ns = xmlXPathGetElementsByIds(ctxt->context->doc, tokens);
7314
14.6k
                if (ns == NULL)
7315
370
                    xmlXPathPErrMemory(ctxt);
7316
14.6k
    ret = xmlXPathNodeSetMerge(ret, ns);
7317
14.6k
                if (ret == NULL)
7318
316
                    xmlXPathPErrMemory(ctxt);
7319
14.6k
    xmlXPathFreeNodeSet(ns);
7320
14.6k
    if (tokens != NULL)
7321
14.3k
        xmlFree(tokens);
7322
14.6k
      }
7323
12.8k
  }
7324
12.8k
  xmlXPathReleaseObject(ctxt->context, obj);
7325
12.8k
  xmlXPathValuePush(ctxt, xmlXPathCacheWrapNodeSet(ctxt, ret));
7326
12.8k
  return;
7327
12.8k
    }
7328
31.8k
    tokens = xmlXPathCastToString(obj);
7329
31.8k
    if (tokens == NULL)
7330
138
        xmlXPathPErrMemory(ctxt);
7331
31.8k
    xmlXPathReleaseObject(ctxt->context, obj);
7332
31.8k
    ret = xmlXPathGetElementsByIds(ctxt->context->doc, tokens);
7333
31.8k
    if (ret == NULL)
7334
144
        xmlXPathPErrMemory(ctxt);
7335
31.8k
    xmlFree(tokens);
7336
31.8k
    xmlXPathValuePush(ctxt, xmlXPathCacheWrapNodeSet(ctxt, ret));
7337
31.8k
}
7338
7339
/**
7340
 * xmlXPathLocalNameFunction:
7341
 * @ctxt:  the XPath Parser context
7342
 * @nargs:  the number of arguments
7343
 *
7344
 * Implement the local-name() XPath function
7345
 *    string local-name(node-set?)
7346
 * The local-name function returns a string containing the local part
7347
 * of the name of the node in the argument node-set that is first in
7348
 * document order. If the node-set is empty or the first node has no
7349
 * name, an empty string is returned. If the argument is omitted it
7350
 * defaults to the context node.
7351
 */
7352
void
7353
73.8k
xmlXPathLocalNameFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7354
73.8k
    xmlXPathObjectPtr cur;
7355
7356
73.8k
    if (ctxt == NULL) return;
7357
7358
73.8k
    if (nargs == 0) {
7359
9.78k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt, ctxt->context->node));
7360
9.78k
  nargs = 1;
7361
9.78k
    }
7362
7363
220k
    CHECK_ARITY(1);
7364
220k
    if ((ctxt->value == NULL) ||
7365
73.0k
  ((ctxt->value->type != XPATH_NODESET) &&
7366
8.41k
   (ctxt->value->type != XPATH_XSLT_TREE)))
7367
64.6k
  XP_ERROR(XPATH_INVALID_TYPE);
7368
64.6k
    cur = xmlXPathValuePop(ctxt);
7369
7370
64.6k
    if ((cur->nodesetval == NULL) || (cur->nodesetval->nodeNr == 0)) {
7371
89
  xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7372
64.5k
    } else {
7373
64.5k
  int i = 0; /* Should be first in document order !!!!! */
7374
64.5k
  switch (cur->nodesetval->nodeTab[i]->type) {
7375
4.60k
  case XML_ELEMENT_NODE:
7376
4.60k
  case XML_ATTRIBUTE_NODE:
7377
9.39k
  case XML_PI_NODE:
7378
9.39k
      if (cur->nodesetval->nodeTab[i]->name[0] == ' ')
7379
0
    xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7380
9.39k
      else
7381
9.39k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt,
7382
9.39k
      cur->nodesetval->nodeTab[i]->name));
7383
9.39k
      break;
7384
34.6k
  case XML_NAMESPACE_DECL:
7385
34.6k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt,
7386
34.6k
      ((xmlNsPtr)cur->nodesetval->nodeTab[i])->prefix));
7387
34.6k
      break;
7388
20.4k
  default:
7389
20.4k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7390
64.5k
  }
7391
64.5k
    }
7392
64.6k
    xmlXPathReleaseObject(ctxt->context, cur);
7393
64.6k
}
7394
7395
/**
7396
 * xmlXPathNamespaceURIFunction:
7397
 * @ctxt:  the XPath Parser context
7398
 * @nargs:  the number of arguments
7399
 *
7400
 * Implement the namespace-uri() XPath function
7401
 *    string namespace-uri(node-set?)
7402
 * The namespace-uri function returns a string containing the
7403
 * namespace URI of the expanded name of the node in the argument
7404
 * node-set that is first in document order. If the node-set is empty,
7405
 * the first node has no name, or the expanded name has no namespace
7406
 * URI, an empty string is returned. If the argument is omitted it
7407
 * defaults to the context node.
7408
 */
7409
void
7410
1.76k
xmlXPathNamespaceURIFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7411
1.76k
    xmlXPathObjectPtr cur;
7412
7413
1.76k
    if (ctxt == NULL) return;
7414
7415
1.76k
    if (nargs == 0) {
7416
1.01k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt, ctxt->context->node));
7417
1.01k
  nargs = 1;
7418
1.01k
    }
7419
5.13k
    CHECK_ARITY(1);
7420
5.13k
    if ((ctxt->value == NULL) ||
7421
1.68k
  ((ctxt->value->type != XPATH_NODESET) &&
7422
208
   (ctxt->value->type != XPATH_XSLT_TREE)))
7423
1.47k
  XP_ERROR(XPATH_INVALID_TYPE);
7424
1.47k
    cur = xmlXPathValuePop(ctxt);
7425
7426
1.47k
    if ((cur->nodesetval == NULL) || (cur->nodesetval->nodeNr == 0)) {
7427
236
  xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7428
1.24k
    } else {
7429
1.24k
  int i = 0; /* Should be first in document order !!!!! */
7430
1.24k
  switch (cur->nodesetval->nodeTab[i]->type) {
7431
686
  case XML_ELEMENT_NODE:
7432
686
  case XML_ATTRIBUTE_NODE:
7433
686
      if (cur->nodesetval->nodeTab[i]->ns == NULL)
7434
543
    xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7435
143
      else
7436
143
    xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt,
7437
143
        cur->nodesetval->nodeTab[i]->ns->href));
7438
686
      break;
7439
554
  default:
7440
554
      xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7441
1.24k
  }
7442
1.24k
    }
7443
1.47k
    xmlXPathReleaseObject(ctxt->context, cur);
7444
1.47k
}
7445
7446
/**
7447
 * xmlXPathNameFunction:
7448
 * @ctxt:  the XPath Parser context
7449
 * @nargs:  the number of arguments
7450
 *
7451
 * Implement the name() XPath function
7452
 *    string name(node-set?)
7453
 * The name function returns a string containing a QName representing
7454
 * the name of the node in the argument node-set that is first in document
7455
 * order. The QName must represent the name with respect to the namespace
7456
 * declarations in effect on the node whose name is being represented.
7457
 * Typically, this will be the form in which the name occurred in the XML
7458
 * source. This need not be the case if there are namespace declarations
7459
 * in effect on the node that associate multiple prefixes with the same
7460
 * namespace. However, an implementation may include information about
7461
 * the original prefix in its representation of nodes; in this case, an
7462
 * implementation can ensure that the returned string is always the same
7463
 * as the QName used in the XML source. If the argument it omitted it
7464
 * defaults to the context node.
7465
 * Libxml keep the original prefix so the "real qualified name" used is
7466
 * returned.
7467
 */
7468
static void
7469
xmlXPathNameFunction(xmlXPathParserContextPtr ctxt, int nargs)
7470
90.4k
{
7471
90.4k
    xmlXPathObjectPtr cur;
7472
7473
90.4k
    if (nargs == 0) {
7474
87.2k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt, ctxt->context->node));
7475
87.2k
        nargs = 1;
7476
87.2k
    }
7477
7478
270k
    CHECK_ARITY(1);
7479
270k
    if ((ctxt->value == NULL) ||
7480
90.1k
        ((ctxt->value->type != XPATH_NODESET) &&
7481
244
         (ctxt->value->type != XPATH_XSLT_TREE)))
7482
89.9k
        XP_ERROR(XPATH_INVALID_TYPE);
7483
89.9k
    cur = xmlXPathValuePop(ctxt);
7484
7485
89.9k
    if ((cur->nodesetval == NULL) || (cur->nodesetval->nodeNr == 0)) {
7486
2.70k
        xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7487
87.2k
    } else {
7488
87.2k
        int i = 0;              /* Should be first in document order !!!!! */
7489
7490
87.2k
        switch (cur->nodesetval->nodeTab[i]->type) {
7491
32.1k
            case XML_ELEMENT_NODE:
7492
32.1k
            case XML_ATTRIBUTE_NODE:
7493
32.1k
    if (cur->nodesetval->nodeTab[i]->name[0] == ' ')
7494
0
        xmlXPathValuePush(ctxt,
7495
0
      xmlXPathCacheNewCString(ctxt, ""));
7496
32.1k
    else if ((cur->nodesetval->nodeTab[i]->ns == NULL) ||
7497
19.4k
                         (cur->nodesetval->nodeTab[i]->ns->prefix == NULL)) {
7498
19.4k
        xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt,
7499
19.4k
          cur->nodesetval->nodeTab[i]->name));
7500
19.4k
    } else {
7501
12.7k
        xmlChar *fullname;
7502
7503
12.7k
        fullname = xmlBuildQName(cur->nodesetval->nodeTab[i]->name,
7504
12.7k
             cur->nodesetval->nodeTab[i]->ns->prefix,
7505
12.7k
             NULL, 0);
7506
12.7k
        if (fullname == cur->nodesetval->nodeTab[i]->name)
7507
0
      fullname = xmlStrdup(cur->nodesetval->nodeTab[i]->name);
7508
12.7k
        if (fullname == NULL)
7509
120
                        xmlXPathPErrMemory(ctxt);
7510
12.7k
        xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, fullname));
7511
12.7k
                }
7512
32.1k
                break;
7513
55.0k
            default:
7514
55.0k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt,
7515
55.0k
        cur->nodesetval->nodeTab[i]));
7516
55.0k
                xmlXPathLocalNameFunction(ctxt, 1);
7517
87.2k
        }
7518
87.2k
    }
7519
89.9k
    xmlXPathReleaseObject(ctxt->context, cur);
7520
89.9k
}
7521
7522
7523
/**
7524
 * xmlXPathStringFunction:
7525
 * @ctxt:  the XPath Parser context
7526
 * @nargs:  the number of arguments
7527
 *
7528
 * Implement the string() XPath function
7529
 *    string string(object?)
7530
 * The string function converts an object to a string as follows:
7531
 *    - A node-set is converted to a string by returning the value of
7532
 *      the node in the node-set that is first in document order.
7533
 *      If the node-set is empty, an empty string is returned.
7534
 *    - A number is converted to a string as follows
7535
 *      + NaN is converted to the string NaN
7536
 *      + positive zero is converted to the string 0
7537
 *      + negative zero is converted to the string 0
7538
 *      + positive infinity is converted to the string Infinity
7539
 *      + negative infinity is converted to the string -Infinity
7540
 *      + if the number is an integer, the number is represented in
7541
 *        decimal form as a Number with no decimal point and no leading
7542
 *        zeros, preceded by a minus sign (-) if the number is negative
7543
 *      + otherwise, the number is represented in decimal form as a
7544
 *        Number including a decimal point with at least one digit
7545
 *        before the decimal point and at least one digit after the
7546
 *        decimal point, preceded by a minus sign (-) if the number
7547
 *        is negative; there must be no leading zeros before the decimal
7548
 *        point apart possibly from the one required digit immediately
7549
 *        before the decimal point; beyond the one required digit
7550
 *        after the decimal point there must be as many, but only as
7551
 *        many, more digits as are needed to uniquely distinguish the
7552
 *        number from all other IEEE 754 numeric values.
7553
 *    - The boolean false value is converted to the string false.
7554
 *      The boolean true value is converted to the string true.
7555
 *
7556
 * If the argument is omitted, it defaults to a node-set with the
7557
 * context node as its only member.
7558
 */
7559
void
7560
734k
xmlXPathStringFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7561
734k
    xmlXPathObjectPtr cur;
7562
734k
    xmlChar *stringval;
7563
7564
734k
    if (ctxt == NULL) return;
7565
734k
    if (nargs == 0) {
7566
1.00k
        stringval = xmlXPathCastNodeToString(ctxt->context->node);
7567
1.00k
        if (stringval == NULL)
7568
181
            xmlXPathPErrMemory(ctxt);
7569
1.00k
        xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, stringval));
7570
1.00k
  return;
7571
1.00k
    }
7572
7573
2.90M
    CHECK_ARITY(1);
7574
2.90M
    cur = xmlXPathValuePop(ctxt);
7575
2.90M
    if (cur == NULL) XP_ERROR(XPATH_INVALID_OPERAND);
7576
709k
    if (cur->type != XPATH_STRING) {
7577
385k
        stringval = xmlXPathCastToString(cur);
7578
385k
        if (stringval == NULL)
7579
1.72k
            xmlXPathPErrMemory(ctxt);
7580
385k
        xmlXPathReleaseObject(ctxt->context, cur);
7581
385k
        cur = xmlXPathCacheWrapString(ctxt, stringval);
7582
385k
    }
7583
709k
    xmlXPathValuePush(ctxt, cur);
7584
709k
}
7585
7586
/**
7587
 * xmlXPathStringLengthFunction:
7588
 * @ctxt:  the XPath Parser context
7589
 * @nargs:  the number of arguments
7590
 *
7591
 * Implement the string-length() XPath function
7592
 *    number string-length(string?)
7593
 * The string-length returns the number of characters in the string
7594
 * (see [3.6 Strings]). If the argument is omitted, it defaults to
7595
 * the context node converted to a string, in other words the value
7596
 * of the context node.
7597
 */
7598
void
7599
3.79k
xmlXPathStringLengthFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7600
3.79k
    xmlXPathObjectPtr cur;
7601
7602
3.79k
    if (nargs == 0) {
7603
197
        if ((ctxt == NULL) || (ctxt->context == NULL))
7604
0
      return;
7605
197
  if (ctxt->context->node == NULL) {
7606
0
      xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt, 0));
7607
197
  } else {
7608
197
      xmlChar *content;
7609
7610
197
      content = xmlXPathCastNodeToString(ctxt->context->node);
7611
197
            if (content == NULL)
7612
4
                xmlXPathPErrMemory(ctxt);
7613
197
      xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt,
7614
197
    xmlUTF8Strlen(content)));
7615
197
      xmlFree(content);
7616
197
  }
7617
197
  return;
7618
197
    }
7619
14.3k
    CHECK_ARITY(1);
7620
14.3k
    CAST_TO_STRING;
7621
14.3k
    CHECK_TYPE(XPATH_STRING);
7622
3.57k
    cur = xmlXPathValuePop(ctxt);
7623
3.57k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt,
7624
3.57k
  xmlUTF8Strlen(cur->stringval)));
7625
3.57k
    xmlXPathReleaseObject(ctxt->context, cur);
7626
3.57k
}
7627
7628
/**
7629
 * xmlXPathConcatFunction:
7630
 * @ctxt:  the XPath Parser context
7631
 * @nargs:  the number of arguments
7632
 *
7633
 * Implement the concat() XPath function
7634
 *    string concat(string, string, string*)
7635
 * The concat function returns the concatenation of its arguments.
7636
 */
7637
void
7638
399
xmlXPathConcatFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7639
399
    xmlXPathObjectPtr cur, newobj;
7640
399
    xmlChar *tmp;
7641
7642
399
    if (ctxt == NULL) return;
7643
399
    if (nargs < 2) {
7644
80
  CHECK_ARITY(2);
7645
80
    }
7646
7647
319
    CAST_TO_STRING;
7648
319
    cur = xmlXPathValuePop(ctxt);
7649
319
    if ((cur == NULL) || (cur->type != XPATH_STRING)) {
7650
1
  xmlXPathReleaseObject(ctxt->context, cur);
7651
1
  return;
7652
1
    }
7653
318
    nargs--;
7654
7655
770
    while (nargs > 0) {
7656
454
  CAST_TO_STRING;
7657
454
  newobj = xmlXPathValuePop(ctxt);
7658
454
  if ((newobj == NULL) || (newobj->type != XPATH_STRING)) {
7659
2
      xmlXPathReleaseObject(ctxt->context, newobj);
7660
2
      xmlXPathReleaseObject(ctxt->context, cur);
7661
2
      XP_ERROR(XPATH_INVALID_TYPE);
7662
0
  }
7663
452
  tmp = xmlStrcat(newobj->stringval, cur->stringval);
7664
452
        if (tmp == NULL)
7665
29
            xmlXPathPErrMemory(ctxt);
7666
452
  newobj->stringval = cur->stringval;
7667
452
  cur->stringval = tmp;
7668
452
  xmlXPathReleaseObject(ctxt->context, newobj);
7669
452
  nargs--;
7670
452
    }
7671
316
    xmlXPathValuePush(ctxt, cur);
7672
316
}
7673
7674
/**
7675
 * xmlXPathContainsFunction:
7676
 * @ctxt:  the XPath Parser context
7677
 * @nargs:  the number of arguments
7678
 *
7679
 * Implement the contains() XPath function
7680
 *    boolean contains(string, string)
7681
 * The contains function returns true if the first argument string
7682
 * contains the second argument string, and otherwise returns false.
7683
 */
7684
void
7685
6.78k
xmlXPathContainsFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7686
6.78k
    xmlXPathObjectPtr hay, needle;
7687
7688
13.4k
    CHECK_ARITY(2);
7689
13.4k
    CAST_TO_STRING;
7690
13.4k
    CHECK_TYPE(XPATH_STRING);
7691
3.31k
    needle = xmlXPathValuePop(ctxt);
7692
3.31k
    CAST_TO_STRING;
7693
3.31k
    hay = xmlXPathValuePop(ctxt);
7694
7695
3.31k
    if ((hay == NULL) || (hay->type != XPATH_STRING)) {
7696
4
  xmlXPathReleaseObject(ctxt->context, hay);
7697
4
  xmlXPathReleaseObject(ctxt->context, needle);
7698
4
  XP_ERROR(XPATH_INVALID_TYPE);
7699
0
    }
7700
3.30k
    if (xmlStrstr(hay->stringval, needle->stringval))
7701
2.08k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 1));
7702
1.22k
    else
7703
1.22k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 0));
7704
3.30k
    xmlXPathReleaseObject(ctxt->context, hay);
7705
3.30k
    xmlXPathReleaseObject(ctxt->context, needle);
7706
3.30k
}
7707
7708
/**
7709
 * xmlXPathStartsWithFunction:
7710
 * @ctxt:  the XPath Parser context
7711
 * @nargs:  the number of arguments
7712
 *
7713
 * Implement the starts-with() XPath function
7714
 *    boolean starts-with(string, string)
7715
 * The starts-with function returns true if the first argument string
7716
 * starts with the second argument string, and otherwise returns false.
7717
 */
7718
void
7719
8.98k
xmlXPathStartsWithFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7720
8.98k
    xmlXPathObjectPtr hay, needle;
7721
8.98k
    int n;
7722
7723
19.0k
    CHECK_ARITY(2);
7724
19.0k
    CAST_TO_STRING;
7725
19.0k
    CHECK_TYPE(XPATH_STRING);
7726
5.03k
    needle = xmlXPathValuePop(ctxt);
7727
5.03k
    CAST_TO_STRING;
7728
5.03k
    hay = xmlXPathValuePop(ctxt);
7729
7730
5.03k
    if ((hay == NULL) || (hay->type != XPATH_STRING)) {
7731
3
  xmlXPathReleaseObject(ctxt->context, hay);
7732
3
  xmlXPathReleaseObject(ctxt->context, needle);
7733
3
  XP_ERROR(XPATH_INVALID_TYPE);
7734
0
    }
7735
5.03k
    n = xmlStrlen(needle->stringval);
7736
5.03k
    if (xmlStrncmp(hay->stringval, needle->stringval, n))
7737
347
        xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 0));
7738
4.68k
    else
7739
4.68k
        xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 1));
7740
5.03k
    xmlXPathReleaseObject(ctxt->context, hay);
7741
5.03k
    xmlXPathReleaseObject(ctxt->context, needle);
7742
5.03k
}
7743
7744
/**
7745
 * xmlXPathSubstringFunction:
7746
 * @ctxt:  the XPath Parser context
7747
 * @nargs:  the number of arguments
7748
 *
7749
 * Implement the substring() XPath function
7750
 *    string substring(string, number, number?)
7751
 * The substring function returns the substring of the first argument
7752
 * starting at the position specified in the second argument with
7753
 * length specified in the third argument. For example,
7754
 * substring("12345",2,3) returns "234". If the third argument is not
7755
 * specified, it returns the substring starting at the position specified
7756
 * in the second argument and continuing to the end of the string. For
7757
 * example, substring("12345",2) returns "2345".  More precisely, each
7758
 * character in the string (see [3.6 Strings]) is considered to have a
7759
 * numeric position: the position of the first character is 1, the position
7760
 * of the second character is 2 and so on. The returned substring contains
7761
 * those characters for which the position of the character is greater than
7762
 * or equal to the second argument and, if the third argument is specified,
7763
 * less than the sum of the second and third arguments; the comparisons
7764
 * and addition used for the above follow the standard IEEE 754 rules. Thus:
7765
 *  - substring("12345", 1.5, 2.6) returns "234"
7766
 *  - substring("12345", 0, 3) returns "12"
7767
 *  - substring("12345", 0 div 0, 3) returns ""
7768
 *  - substring("12345", 1, 0 div 0) returns ""
7769
 *  - substring("12345", -42, 1 div 0) returns "12345"
7770
 *  - substring("12345", -1 div 0, 1 div 0) returns ""
7771
 */
7772
void
7773
21.6k
xmlXPathSubstringFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7774
21.6k
    xmlXPathObjectPtr str, start, len;
7775
21.6k
    double le=0, in;
7776
21.6k
    int i = 1, j = INT_MAX;
7777
7778
21.6k
    if (nargs < 2) {
7779
76
  CHECK_ARITY(2);
7780
76
    }
7781
21.5k
    if (nargs > 3) {
7782
37
  CHECK_ARITY(3);
7783
37
    }
7784
    /*
7785
     * take care of possible last (position) argument
7786
    */
7787
21.5k
    if (nargs == 3) {
7788
1.28k
  CAST_TO_NUMBER;
7789
1.28k
  CHECK_TYPE(XPATH_NUMBER);
7790
1.27k
  len = xmlXPathValuePop(ctxt);
7791
1.27k
  le = len->floatval;
7792
1.27k
  xmlXPathReleaseObject(ctxt->context, len);
7793
1.27k
    }
7794
7795
21.5k
    CAST_TO_NUMBER;
7796
21.5k
    CHECK_TYPE(XPATH_NUMBER);
7797
21.5k
    start = xmlXPathValuePop(ctxt);
7798
21.5k
    in = start->floatval;
7799
21.5k
    xmlXPathReleaseObject(ctxt->context, start);
7800
21.5k
    CAST_TO_STRING;
7801
21.5k
    CHECK_TYPE(XPATH_STRING);
7802
21.5k
    str = xmlXPathValuePop(ctxt);
7803
7804
21.5k
    if (!(in < INT_MAX)) { /* Logical NOT to handle NaNs */
7805
2.30k
        i = INT_MAX;
7806
19.2k
    } else if (in >= 1.0) {
7807
9.77k
        i = (int)in;
7808
9.77k
        if (in - floor(in) >= 0.5)
7809
344
            i += 1;
7810
9.77k
    }
7811
7812
21.5k
    if (nargs == 3) {
7813
1.27k
        double rin, rle, end;
7814
7815
1.27k
        rin = floor(in);
7816
1.27k
        if (in - rin >= 0.5)
7817
231
            rin += 1.0;
7818
7819
1.27k
        rle = floor(le);
7820
1.27k
        if (le - rle >= 0.5)
7821
458
            rle += 1.0;
7822
7823
1.27k
        end = rin + rle;
7824
1.27k
        if (!(end >= 1.0)) { /* Logical NOT to handle NaNs */
7825
269
            j = 1;
7826
1.00k
        } else if (end < INT_MAX) {
7827
637
            j = (int)end;
7828
637
        }
7829
1.27k
    }
7830
7831
21.5k
    i -= 1;
7832
21.5k
    j -= 1;
7833
7834
21.5k
    if ((i < j) && (i < xmlUTF8Strlen(str->stringval))) {
7835
9.37k
        xmlChar *ret = xmlUTF8Strsub(str->stringval, i, j - i);
7836
9.37k
        if (ret == NULL)
7837
2
            xmlXPathPErrMemory(ctxt);
7838
9.37k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewString(ctxt, ret));
7839
9.37k
  xmlFree(ret);
7840
12.1k
    } else {
7841
12.1k
  xmlXPathValuePush(ctxt, xmlXPathCacheNewCString(ctxt, ""));
7842
12.1k
    }
7843
7844
21.5k
    xmlXPathReleaseObject(ctxt->context, str);
7845
21.5k
}
7846
7847
/**
7848
 * xmlXPathSubstringBeforeFunction:
7849
 * @ctxt:  the XPath Parser context
7850
 * @nargs:  the number of arguments
7851
 *
7852
 * Implement the substring-before() XPath function
7853
 *    string substring-before(string, string)
7854
 * The substring-before function returns the substring of the first
7855
 * argument string that precedes the first occurrence of the second
7856
 * argument string in the first argument string, or the empty string
7857
 * if the first argument string does not contain the second argument
7858
 * string. For example, substring-before("1999/04/01","/") returns 1999.
7859
 */
7860
void
7861
5.62k
xmlXPathSubstringBeforeFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7862
5.62k
    xmlXPathObjectPtr str = NULL;
7863
5.62k
    xmlXPathObjectPtr find = NULL;
7864
5.62k
    const xmlChar *point;
7865
5.62k
    xmlChar *result;
7866
7867
7.15k
    CHECK_ARITY(2);
7868
7.15k
    CAST_TO_STRING;
7869
7.15k
    find = xmlXPathValuePop(ctxt);
7870
7.15k
    CAST_TO_STRING;
7871
7.15k
    str = xmlXPathValuePop(ctxt);
7872
7.15k
    if (ctxt->error != 0)
7873
3
        goto error;
7874
7875
762
    point = xmlStrstr(str->stringval, find->stringval);
7876
762
    if (point == NULL) {
7877
405
        result = xmlStrdup(BAD_CAST "");
7878
405
    } else {
7879
357
        result = xmlStrndup(str->stringval, point - str->stringval);
7880
357
    }
7881
762
    if (result == NULL) {
7882
1
        xmlXPathPErrMemory(ctxt);
7883
1
        goto error;
7884
1
    }
7885
761
    xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, result));
7886
7887
765
error:
7888
765
    xmlXPathReleaseObject(ctxt->context, str);
7889
765
    xmlXPathReleaseObject(ctxt->context, find);
7890
765
}
7891
7892
/**
7893
 * xmlXPathSubstringAfterFunction:
7894
 * @ctxt:  the XPath Parser context
7895
 * @nargs:  the number of arguments
7896
 *
7897
 * Implement the substring-after() XPath function
7898
 *    string substring-after(string, string)
7899
 * The substring-after function returns the substring of the first
7900
 * argument string that follows the first occurrence of the second
7901
 * argument string in the first argument string, or the empty string
7902
 * if the first argument string does not contain the second argument
7903
 * string. For example, substring-after("1999/04/01","/") returns 04/01,
7904
 * and substring-after("1999/04/01","19") returns 99/04/01.
7905
 */
7906
void
7907
11.6k
xmlXPathSubstringAfterFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7908
11.6k
    xmlXPathObjectPtr str = NULL;
7909
11.6k
    xmlXPathObjectPtr find = NULL;
7910
11.6k
    const xmlChar *point;
7911
11.6k
    xmlChar *result;
7912
7913
33.0k
    CHECK_ARITY(2);
7914
33.0k
    CAST_TO_STRING;
7915
33.0k
    find = xmlXPathValuePop(ctxt);
7916
33.0k
    CAST_TO_STRING;
7917
33.0k
    str = xmlXPathValuePop(ctxt);
7918
33.0k
    if (ctxt->error != 0)
7919
172
        goto error;
7920
7921
10.5k
    point = xmlStrstr(str->stringval, find->stringval);
7922
10.5k
    if (point == NULL) {
7923
2.90k
        result = xmlStrdup(BAD_CAST "");
7924
7.63k
    } else {
7925
7.63k
        result = xmlStrdup(point + xmlStrlen(find->stringval));
7926
7.63k
    }
7927
10.5k
    if (result == NULL) {
7928
1
        xmlXPathPErrMemory(ctxt);
7929
1
        goto error;
7930
1
    }
7931
10.5k
    xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, result));
7932
7933
10.7k
error:
7934
10.7k
    xmlXPathReleaseObject(ctxt->context, str);
7935
10.7k
    xmlXPathReleaseObject(ctxt->context, find);
7936
10.7k
}
7937
7938
/**
7939
 * xmlXPathNormalizeFunction:
7940
 * @ctxt:  the XPath Parser context
7941
 * @nargs:  the number of arguments
7942
 *
7943
 * Implement the normalize-space() XPath function
7944
 *    string normalize-space(string?)
7945
 * The normalize-space function returns the argument string with white
7946
 * space normalized by stripping leading and trailing whitespace
7947
 * and replacing sequences of whitespace characters by a single
7948
 * space. Whitespace characters are the same allowed by the S production
7949
 * in XML. If the argument is omitted, it defaults to the context
7950
 * node converted to a string, in other words the value of the context node.
7951
 */
7952
void
7953
40.9k
xmlXPathNormalizeFunction(xmlXPathParserContextPtr ctxt, int nargs) {
7954
40.9k
    xmlChar *source, *target;
7955
40.9k
    int blank;
7956
7957
40.9k
    if (ctxt == NULL) return;
7958
40.9k
    if (nargs == 0) {
7959
        /* Use current context node */
7960
32.6k
        source = xmlXPathCastNodeToString(ctxt->context->node);
7961
32.6k
        if (source == NULL)
7962
307
            xmlXPathPErrMemory(ctxt);
7963
32.6k
        xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, source));
7964
32.6k
        nargs = 1;
7965
32.6k
    }
7966
7967
122k
    CHECK_ARITY(1);
7968
122k
    CAST_TO_STRING;
7969
122k
    CHECK_TYPE(XPATH_STRING);
7970
40.3k
    source = ctxt->value->stringval;
7971
40.3k
    if (source == NULL)
7972
258
        return;
7973
40.1k
    target = source;
7974
7975
    /* Skip leading whitespaces */
7976
40.1k
    while (IS_BLANK_CH(*source))
7977
46.5k
        source++;
7978
7979
    /* Collapse intermediate whitespaces, and skip trailing whitespaces */
7980
40.1k
    blank = 0;
7981
964k
    while (*source) {
7982
924k
        if (IS_BLANK_CH(*source)) {
7983
97.5k
      blank = 1;
7984
826k
        } else {
7985
826k
            if (blank) {
7986
54.5k
                *target++ = 0x20;
7987
54.5k
                blank = 0;
7988
54.5k
            }
7989
826k
            *target++ = *source;
7990
826k
        }
7991
924k
        source++;
7992
924k
    }
7993
40.1k
    *target = 0;
7994
40.1k
}
7995
7996
/**
7997
 * xmlXPathTranslateFunction:
7998
 * @ctxt:  the XPath Parser context
7999
 * @nargs:  the number of arguments
8000
 *
8001
 * Implement the translate() XPath function
8002
 *    string translate(string, string, string)
8003
 * The translate function returns the first argument string with
8004
 * occurrences of characters in the second argument string replaced
8005
 * by the character at the corresponding position in the third argument
8006
 * string. For example, translate("bar","abc","ABC") returns the string
8007
 * BAr. If there is a character in the second argument string with no
8008
 * character at a corresponding position in the third argument string
8009
 * (because the second argument string is longer than the third argument
8010
 * string), then occurrences of that character in the first argument
8011
 * string are removed. For example, translate("--aaa--","abc-","ABC")
8012
 * returns "AAA". If a character occurs more than once in second
8013
 * argument string, then the first occurrence determines the replacement
8014
 * character. If the third argument string is longer than the second
8015
 * argument string, then excess characters are ignored.
8016
 */
8017
void
8018
2.52k
xmlXPathTranslateFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8019
2.52k
    xmlXPathObjectPtr str = NULL;
8020
2.52k
    xmlXPathObjectPtr from = NULL;
8021
2.52k
    xmlXPathObjectPtr to = NULL;
8022
2.52k
    xmlBufPtr target;
8023
2.52k
    int offset, max;
8024
2.52k
    int ch;
8025
2.52k
    const xmlChar *point;
8026
2.52k
    xmlChar *cptr, *content;
8027
8028
7.21k
    CHECK_ARITY(3);
8029
8030
7.21k
    CAST_TO_STRING;
8031
7.21k
    to = xmlXPathValuePop(ctxt);
8032
7.21k
    CAST_TO_STRING;
8033
7.21k
    from = xmlXPathValuePop(ctxt);
8034
7.21k
    CAST_TO_STRING;
8035
7.21k
    str = xmlXPathValuePop(ctxt);
8036
7.21k
    if (ctxt->error != 0)
8037
17
        goto error;
8038
8039
    /*
8040
     * Account for quadratic runtime
8041
     */
8042
2.32k
    if (ctxt->context->opLimit != 0) {
8043
2.32k
        unsigned long f1 = xmlStrlen(from->stringval);
8044
2.32k
        unsigned long f2 = xmlStrlen(str->stringval);
8045
8046
2.32k
        if ((f1 > 0) && (f2 > 0)) {
8047
1.28k
            unsigned long p;
8048
8049
1.28k
            f1 = f1 / 10 + 1;
8050
1.28k
            f2 = f2 / 10 + 1;
8051
1.28k
            p = f1 > ULONG_MAX / f2 ? ULONG_MAX : f1 * f2;
8052
1.28k
            if (xmlXPathCheckOpLimit(ctxt, p) < 0)
8053
12
                goto error;
8054
1.28k
        }
8055
2.32k
    }
8056
8057
2.31k
    target = xmlBufCreate(50);
8058
2.31k
    if (target == NULL) {
8059
4
        xmlXPathPErrMemory(ctxt);
8060
4
        goto error;
8061
4
    }
8062
8063
2.31k
    max = xmlUTF8Strlen(to->stringval);
8064
942k
    for (cptr = str->stringval; (ch=*cptr); ) {
8065
940k
        offset = xmlUTF8Strloc(from->stringval, cptr);
8066
940k
        if (offset >= 0) {
8067
175k
            if (offset < max) {
8068
27.6k
                point = xmlUTF8Strpos(to->stringval, offset);
8069
27.6k
                if (point)
8070
27.6k
                    xmlBufAdd(target, point, xmlUTF8Strsize(point, 1));
8071
27.6k
            }
8072
175k
        } else
8073
764k
            xmlBufAdd(target, cptr, xmlUTF8Strsize(cptr, 1));
8074
8075
        /* Step to next character in input */
8076
940k
        cptr++;
8077
940k
        if ( ch & 0x80 ) {
8078
            /* if not simple ascii, verify proper format */
8079
3.96k
            if ( (ch & 0xc0) != 0xc0 ) {
8080
0
                xmlXPathErr(ctxt, XPATH_INVALID_CHAR_ERROR);
8081
0
                break;
8082
0
            }
8083
            /* then skip over remaining bytes for this char */
8084
11.5k
            while ( (ch <<= 1) & 0x80 )
8085
7.56k
                if ( (*cptr++ & 0xc0) != 0x80 ) {
8086
0
                    xmlXPathErr(ctxt, XPATH_INVALID_CHAR_ERROR);
8087
0
                    break;
8088
0
                }
8089
3.96k
            if (ch & 0x80) /* must have had error encountered */
8090
0
                break;
8091
3.96k
        }
8092
940k
    }
8093
8094
2.31k
    content = xmlBufDetach(target);
8095
2.31k
    if (content == NULL)
8096
6
        xmlXPathPErrMemory(ctxt);
8097
2.30k
    else
8098
2.30k
        xmlXPathValuePush(ctxt, xmlXPathCacheWrapString(ctxt, content));
8099
2.31k
    xmlBufFree(target);
8100
2.34k
error:
8101
2.34k
    xmlXPathReleaseObject(ctxt->context, str);
8102
2.34k
    xmlXPathReleaseObject(ctxt->context, from);
8103
2.34k
    xmlXPathReleaseObject(ctxt->context, to);
8104
2.34k
}
8105
8106
/**
8107
 * xmlXPathBooleanFunction:
8108
 * @ctxt:  the XPath Parser context
8109
 * @nargs:  the number of arguments
8110
 *
8111
 * Implement the boolean() XPath function
8112
 *    boolean boolean(object)
8113
 * The boolean function converts its argument to a boolean as follows:
8114
 *    - a number is true if and only if it is neither positive or
8115
 *      negative zero nor NaN
8116
 *    - a node-set is true if and only if it is non-empty
8117
 *    - a string is true if and only if its length is non-zero
8118
 */
8119
void
8120
290k
xmlXPathBooleanFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8121
290k
    xmlXPathObjectPtr cur;
8122
8123
871k
    CHECK_ARITY(1);
8124
871k
    cur = xmlXPathValuePop(ctxt);
8125
871k
    if (cur == NULL) XP_ERROR(XPATH_INVALID_OPERAND);
8126
290k
    if (cur->type != XPATH_BOOLEAN) {
8127
221k
        int boolval = xmlXPathCastToBoolean(cur);
8128
8129
221k
        xmlXPathReleaseObject(ctxt->context, cur);
8130
221k
        cur = xmlXPathCacheNewBoolean(ctxt, boolval);
8131
221k
    }
8132
290k
    xmlXPathValuePush(ctxt, cur);
8133
290k
}
8134
8135
/**
8136
 * xmlXPathNotFunction:
8137
 * @ctxt:  the XPath Parser context
8138
 * @nargs:  the number of arguments
8139
 *
8140
 * Implement the not() XPath function
8141
 *    boolean not(boolean)
8142
 * The not function returns true if its argument is false,
8143
 * and false otherwise.
8144
 */
8145
void
8146
2.54k
xmlXPathNotFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8147
3.97k
    CHECK_ARITY(1);
8148
3.97k
    CAST_TO_BOOLEAN;
8149
3.97k
    CHECK_TYPE(XPATH_BOOLEAN);
8150
642
    ctxt->value->boolval = ! ctxt->value->boolval;
8151
642
}
8152
8153
/**
8154
 * xmlXPathTrueFunction:
8155
 * @ctxt:  the XPath Parser context
8156
 * @nargs:  the number of arguments
8157
 *
8158
 * Implement the true() XPath function
8159
 *    boolean true()
8160
 */
8161
void
8162
1.07k
xmlXPathTrueFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8163
2.70k
    CHECK_ARITY(0);
8164
2.70k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 1));
8165
2.70k
}
8166
8167
/**
8168
 * xmlXPathFalseFunction:
8169
 * @ctxt:  the XPath Parser context
8170
 * @nargs:  the number of arguments
8171
 *
8172
 * Implement the false() XPath function
8173
 *    boolean false()
8174
 */
8175
void
8176
5.39k
xmlXPathFalseFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8177
14.2k
    CHECK_ARITY(0);
8178
14.2k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, 0));
8179
14.2k
}
8180
8181
/**
8182
 * xmlXPathLangFunction:
8183
 * @ctxt:  the XPath Parser context
8184
 * @nargs:  the number of arguments
8185
 *
8186
 * Implement the lang() XPath function
8187
 *    boolean lang(string)
8188
 * The lang function returns true or false depending on whether the
8189
 * language of the context node as specified by xml:lang attributes
8190
 * is the same as or is a sublanguage of the language specified by
8191
 * the argument string. The language of the context node is determined
8192
 * by the value of the xml:lang attribute on the context node, or, if
8193
 * the context node has no xml:lang attribute, by the value of the
8194
 * xml:lang attribute on the nearest ancestor of the context node that
8195
 * has an xml:lang attribute. If there is no such attribute, then lang
8196
 * returns false. If there is such an attribute, then lang returns
8197
 * true if the attribute value is equal to the argument ignoring case,
8198
 * or if there is some suffix starting with - such that the attribute
8199
 * value is equal to the argument ignoring that suffix of the attribute
8200
 * value and ignoring case.
8201
 */
8202
void
8203
6.70k
xmlXPathLangFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8204
6.70k
    xmlXPathObjectPtr val;
8205
6.70k
    xmlNodePtr cur;
8206
6.70k
    xmlChar *theLang;
8207
6.70k
    const xmlChar *lang;
8208
6.70k
    int ret = 0;
8209
6.70k
    int i;
8210
8211
18.0k
    CHECK_ARITY(1);
8212
18.0k
    CAST_TO_STRING;
8213
18.0k
    CHECK_TYPE(XPATH_STRING);
8214
5.53k
    val = xmlXPathValuePop(ctxt);
8215
5.53k
    lang = val->stringval;
8216
5.53k
    cur = ctxt->context->node;
8217
27.8k
    while (cur != NULL) {
8218
22.2k
        if (xmlNodeGetAttrValue(cur, BAD_CAST "lang", XML_XML_NAMESPACE,
8219
22.2k
                                &theLang) < 0)
8220
0
            xmlXPathPErrMemory(ctxt);
8221
22.2k
        if (theLang != NULL)
8222
0
            break;
8223
22.2k
        cur = cur->parent;
8224
22.2k
    }
8225
5.53k
    if ((theLang != NULL) && (lang != NULL)) {
8226
0
        for (i = 0;lang[i] != 0;i++)
8227
0
            if (toupper(lang[i]) != toupper(theLang[i]))
8228
0
                goto not_equal;
8229
0
        if ((theLang[i] == 0) || (theLang[i] == '-'))
8230
0
            ret = 1;
8231
0
    }
8232
5.53k
not_equal:
8233
5.53k
    if (theLang != NULL)
8234
0
  xmlFree((void *)theLang);
8235
8236
5.53k
    xmlXPathReleaseObject(ctxt->context, val);
8237
5.53k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, ret));
8238
5.53k
}
8239
8240
/**
8241
 * xmlXPathNumberFunction:
8242
 * @ctxt:  the XPath Parser context
8243
 * @nargs:  the number of arguments
8244
 *
8245
 * Implement the number() XPath function
8246
 *    number number(object?)
8247
 */
8248
void
8249
702k
xmlXPathNumberFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8250
702k
    xmlXPathObjectPtr cur;
8251
702k
    double res;
8252
8253
702k
    if (ctxt == NULL) return;
8254
702k
    if (nargs == 0) {
8255
900
  if (ctxt->context->node == NULL) {
8256
0
      xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt, 0.0));
8257
900
  } else {
8258
900
      xmlChar* content = xmlNodeGetContent(ctxt->context->node);
8259
900
            if (content == NULL)
8260
376
                xmlXPathPErrMemory(ctxt);
8261
8262
900
      res = xmlXPathStringEvalNumber(content);
8263
900
      xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt, res));
8264
900
      xmlFree(content);
8265
900
  }
8266
900
  return;
8267
900
    }
8268
8269
2.80M
    CHECK_ARITY(1);
8270
2.80M
    cur = xmlXPathValuePop(ctxt);
8271
2.80M
    if (cur->type != XPATH_NUMBER) {
8272
695k
        double floatval;
8273
8274
695k
        floatval = xmlXPathCastToNumberInternal(ctxt, cur);
8275
695k
        xmlXPathReleaseObject(ctxt->context, cur);
8276
695k
        cur = xmlXPathCacheNewFloat(ctxt, floatval);
8277
695k
    }
8278
2.80M
    xmlXPathValuePush(ctxt, cur);
8279
2.80M
}
8280
8281
/**
8282
 * xmlXPathSumFunction:
8283
 * @ctxt:  the XPath Parser context
8284
 * @nargs:  the number of arguments
8285
 *
8286
 * Implement the sum() XPath function
8287
 *    number sum(node-set)
8288
 * The sum function returns the sum of the values of the nodes in
8289
 * the argument node-set.
8290
 */
8291
void
8292
9.04k
xmlXPathSumFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8293
9.04k
    xmlXPathObjectPtr cur;
8294
9.04k
    int i;
8295
9.04k
    double res = 0.0;
8296
8297
25.5k
    CHECK_ARITY(1);
8298
25.5k
    if ((ctxt->value == NULL) ||
8299
8.25k
  ((ctxt->value->type != XPATH_NODESET) &&
8300
2.24k
   (ctxt->value->type != XPATH_XSLT_TREE)))
8301
6.01k
  XP_ERROR(XPATH_INVALID_TYPE);
8302
6.01k
    cur = xmlXPathValuePop(ctxt);
8303
8304
6.01k
    if ((cur->nodesetval != NULL) && (cur->nodesetval->nodeNr != 0)) {
8305
4.76k
  for (i = 0; i < cur->nodesetval->nodeNr; i++) {
8306
3.77k
      res += xmlXPathNodeToNumberInternal(ctxt,
8307
3.77k
                                                cur->nodesetval->nodeTab[i]);
8308
3.77k
  }
8309
989
    }
8310
6.01k
    xmlXPathValuePush(ctxt, xmlXPathCacheNewFloat(ctxt, res));
8311
6.01k
    xmlXPathReleaseObject(ctxt->context, cur);
8312
6.01k
}
8313
8314
/**
8315
 * xmlXPathFloorFunction:
8316
 * @ctxt:  the XPath Parser context
8317
 * @nargs:  the number of arguments
8318
 *
8319
 * Implement the floor() XPath function
8320
 *    number floor(number)
8321
 * The floor function returns the largest (closest to positive infinity)
8322
 * number that is not greater than the argument and that is an integer.
8323
 */
8324
void
8325
6.90k
xmlXPathFloorFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8326
20.1k
    CHECK_ARITY(1);
8327
20.1k
    CAST_TO_NUMBER;
8328
20.1k
    CHECK_TYPE(XPATH_NUMBER);
8329
8330
6.63k
    ctxt->value->floatval = floor(ctxt->value->floatval);
8331
6.63k
}
8332
8333
/**
8334
 * xmlXPathCeilingFunction:
8335
 * @ctxt:  the XPath Parser context
8336
 * @nargs:  the number of arguments
8337
 *
8338
 * Implement the ceiling() XPath function
8339
 *    number ceiling(number)
8340
 * The ceiling function returns the smallest (closest to negative infinity)
8341
 * number that is not less than the argument and that is an integer.
8342
 */
8343
void
8344
3.62k
xmlXPathCeilingFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8345
10.8k
    CHECK_ARITY(1);
8346
10.8k
    CAST_TO_NUMBER;
8347
10.8k
    CHECK_TYPE(XPATH_NUMBER);
8348
8349
#ifdef _AIX
8350
    /* Work around buggy ceil() function on AIX */
8351
    ctxt->value->floatval = copysign(ceil(ctxt->value->floatval), ctxt->value->floatval);
8352
#else
8353
3.61k
    ctxt->value->floatval = ceil(ctxt->value->floatval);
8354
3.61k
#endif
8355
3.61k
}
8356
8357
/**
8358
 * xmlXPathRoundFunction:
8359
 * @ctxt:  the XPath Parser context
8360
 * @nargs:  the number of arguments
8361
 *
8362
 * Implement the round() XPath function
8363
 *    number round(number)
8364
 * The round function returns the number that is closest to the
8365
 * argument and that is an integer. If there are two such numbers,
8366
 * then the one that is closest to positive infinity is returned.
8367
 */
8368
void
8369
0
xmlXPathRoundFunction(xmlXPathParserContextPtr ctxt, int nargs) {
8370
0
    double f;
8371
8372
0
    CHECK_ARITY(1);
8373
0
    CAST_TO_NUMBER;
8374
0
    CHECK_TYPE(XPATH_NUMBER);
8375
8376
0
    f = ctxt->value->floatval;
8377
8378
0
    if ((f >= -0.5) && (f < 0.5)) {
8379
        /* Handles negative zero. */
8380
0
        ctxt->value->floatval *= 0.0;
8381
0
    }
8382
0
    else {
8383
0
        double rounded = floor(f);
8384
0
        if (f - rounded >= 0.5)
8385
0
            rounded += 1.0;
8386
0
        ctxt->value->floatval = rounded;
8387
0
    }
8388
0
}
8389
8390
/************************************************************************
8391
 *                  *
8392
 *      The Parser          *
8393
 *                  *
8394
 ************************************************************************/
8395
8396
/*
8397
 * a few forward declarations since we use a recursive call based
8398
 * implementation.
8399
 */
8400
static void xmlXPathCompileExpr(xmlXPathParserContextPtr ctxt, int sort);
8401
static void xmlXPathCompPredicate(xmlXPathParserContextPtr ctxt, int filter);
8402
static void xmlXPathCompLocationPath(xmlXPathParserContextPtr ctxt);
8403
static void xmlXPathCompRelativeLocationPath(xmlXPathParserContextPtr ctxt);
8404
static xmlChar * xmlXPathParseNameComplex(xmlXPathParserContextPtr ctxt,
8405
                                    int qualified);
8406
8407
/**
8408
 * xmlXPathCurrentChar:
8409
 * @ctxt:  the XPath parser context
8410
 * @cur:  pointer to the beginning of the char
8411
 * @len:  pointer to the length of the char read
8412
 *
8413
 * The current char value, if using UTF-8 this may actually span multiple
8414
 * bytes in the input buffer.
8415
 *
8416
 * Returns the current char value and its length
8417
 */
8418
8419
static int
8420
41.7M
xmlXPathCurrentChar(xmlXPathParserContextPtr ctxt, int *len) {
8421
41.7M
    unsigned char c;
8422
41.7M
    unsigned int val;
8423
41.7M
    const xmlChar *cur;
8424
8425
41.7M
    if (ctxt == NULL)
8426
0
  return(0);
8427
41.7M
    cur = ctxt->cur;
8428
8429
    /*
8430
     * We are supposed to handle UTF8, check it's valid
8431
     * From rfc2044: encoding of the Unicode values on UTF-8:
8432
     *
8433
     * UCS-4 range (hex.)           UTF-8 octet sequence (binary)
8434
     * 0000 0000-0000 007F   0xxxxxxx
8435
     * 0000 0080-0000 07FF   110xxxxx 10xxxxxx
8436
     * 0000 0800-0000 FFFF   1110xxxx 10xxxxxx 10xxxxxx
8437
     *
8438
     * Check for the 0x110000 limit too
8439
     */
8440
41.7M
    c = *cur;
8441
41.7M
    if (c & 0x80) {
8442
10.8M
  if ((cur[1] & 0xc0) != 0x80)
8443
430
      goto encoding_error;
8444
10.8M
  if ((c & 0xe0) == 0xe0) {
8445
8446
10.6M
      if ((cur[2] & 0xc0) != 0x80)
8447
83
    goto encoding_error;
8448
10.6M
      if ((c & 0xf0) == 0xf0) {
8449
16.5k
    if (((c & 0xf8) != 0xf0) ||
8450
16.3k
        ((cur[3] & 0xc0) != 0x80))
8451
3.08k
        goto encoding_error;
8452
    /* 4-byte code */
8453
13.5k
    *len = 4;
8454
13.5k
    val = (cur[0] & 0x7) << 18;
8455
13.5k
    val |= (cur[1] & 0x3f) << 12;
8456
13.5k
    val |= (cur[2] & 0x3f) << 6;
8457
13.5k
    val |= cur[3] & 0x3f;
8458
10.6M
      } else {
8459
        /* 3-byte code */
8460
10.6M
    *len = 3;
8461
10.6M
    val = (cur[0] & 0xf) << 12;
8462
10.6M
    val |= (cur[1] & 0x3f) << 6;
8463
10.6M
    val |= cur[2] & 0x3f;
8464
10.6M
      }
8465
10.6M
  } else {
8466
    /* 2-byte code */
8467
172k
      *len = 2;
8468
172k
      val = (cur[0] & 0x1f) << 6;
8469
172k
      val |= cur[1] & 0x3f;
8470
172k
  }
8471
10.8M
  if (!IS_CHAR(val)) {
8472
236
      XP_ERROR0(XPATH_INVALID_CHAR_ERROR);
8473
0
  }
8474
10.8M
  return(val);
8475
30.8M
    } else {
8476
  /* 1-byte code */
8477
30.8M
  *len = 1;
8478
30.8M
  return(*cur);
8479
30.8M
    }
8480
3.59k
encoding_error:
8481
    /*
8482
     * If we detect an UTF8 error that probably means that the
8483
     * input encoding didn't get properly advertised in the
8484
     * declaration header. Report the error and switch the encoding
8485
     * to ISO-Latin-1 (if you don't like this policy, just declare the
8486
     * encoding !)
8487
     */
8488
3.59k
    *len = 0;
8489
3.59k
    XP_ERROR0(XPATH_ENCODING_ERROR);
8490
0
}
8491
8492
/**
8493
 * xmlXPathParseNCName:
8494
 * @ctxt:  the XPath Parser context
8495
 *
8496
 * parse an XML namespace non qualified name.
8497
 *
8498
 * [NS 3] NCName ::= (Letter | '_') (NCNameChar)*
8499
 *
8500
 * [NS 4] NCNameChar ::= Letter | Digit | '.' | '-' | '_' |
8501
 *                       CombiningChar | Extender
8502
 *
8503
 * Returns the namespace name or NULL
8504
 */
8505
8506
xmlChar *
8507
1.99M
xmlXPathParseNCName(xmlXPathParserContextPtr ctxt) {
8508
1.99M
    const xmlChar *in;
8509
1.99M
    xmlChar *ret;
8510
1.99M
    int count = 0;
8511
8512
1.99M
    if ((ctxt == NULL) || (ctxt->cur == NULL)) return(NULL);
8513
    /*
8514
     * Accelerator for simple ASCII names
8515
     */
8516
1.99M
    in = ctxt->cur;
8517
1.99M
    if (((*in >= 0x61) && (*in <= 0x7A)) ||
8518
332k
  ((*in >= 0x41) && (*in <= 0x5A)) ||
8519
1.82M
  (*in == '_')) {
8520
1.82M
  in++;
8521
8.76M
  while (((*in >= 0x61) && (*in <= 0x7A)) ||
8522
3.30M
         ((*in >= 0x41) && (*in <= 0x5A)) ||
8523
2.67M
         ((*in >= 0x30) && (*in <= 0x39)) ||
8524
2.18M
         (*in == '_') || (*in == '.') ||
8525
1.96M
         (*in == '-'))
8526
6.93M
      in++;
8527
1.82M
  if ((*in == ' ') || (*in == '>') || (*in == '/') ||
8528
1.53M
            (*in == '[') || (*in == ']') || (*in == ':') ||
8529
1.12M
            (*in == '@') || (*in == '*')) {
8530
740k
      count = in - ctxt->cur;
8531
740k
      if (count == 0)
8532
0
    return(NULL);
8533
740k
      ret = xmlStrndup(ctxt->cur, count);
8534
740k
            if (ret == NULL)
8535
84
                xmlXPathPErrMemory(ctxt);
8536
740k
      ctxt->cur = in;
8537
740k
      return(ret);
8538
740k
  }
8539
1.82M
    }
8540
1.25M
    return(xmlXPathParseNameComplex(ctxt, 0));
8541
1.99M
}
8542
8543
8544
/**
8545
 * xmlXPathParseQName:
8546
 * @ctxt:  the XPath Parser context
8547
 * @prefix:  a xmlChar **
8548
 *
8549
 * parse an XML qualified name
8550
 *
8551
 * [NS 5] QName ::= (Prefix ':')? LocalPart
8552
 *
8553
 * [NS 6] Prefix ::= NCName
8554
 *
8555
 * [NS 7] LocalPart ::= NCName
8556
 *
8557
 * Returns the function returns the local part, and prefix is updated
8558
 *   to get the Prefix if any.
8559
 */
8560
8561
static xmlChar *
8562
470k
xmlXPathParseQName(xmlXPathParserContextPtr ctxt, xmlChar **prefix) {
8563
470k
    xmlChar *ret = NULL;
8564
8565
470k
    *prefix = NULL;
8566
470k
    ret = xmlXPathParseNCName(ctxt);
8567
470k
    if (ret && CUR == ':') {
8568
222k
        *prefix = ret;
8569
222k
  NEXT;
8570
222k
  ret = xmlXPathParseNCName(ctxt);
8571
222k
    }
8572
470k
    return(ret);
8573
470k
}
8574
8575
/**
8576
 * xmlXPathParseName:
8577
 * @ctxt:  the XPath Parser context
8578
 *
8579
 * parse an XML name
8580
 *
8581
 * [4] NameChar ::= Letter | Digit | '.' | '-' | '_' | ':' |
8582
 *                  CombiningChar | Extender
8583
 *
8584
 * [5] Name ::= (Letter | '_' | ':') (NameChar)*
8585
 *
8586
 * Returns the namespace name or NULL
8587
 */
8588
8589
xmlChar *
8590
28.3k
xmlXPathParseName(xmlXPathParserContextPtr ctxt) {
8591
28.3k
    const xmlChar *in;
8592
28.3k
    xmlChar *ret;
8593
28.3k
    size_t count = 0;
8594
8595
28.3k
    if ((ctxt == NULL) || (ctxt->cur == NULL)) return(NULL);
8596
    /*
8597
     * Accelerator for simple ASCII names
8598
     */
8599
28.3k
    in = ctxt->cur;
8600
28.3k
    if (((*in >= 0x61) && (*in <= 0x7A)) ||
8601
11.6k
  ((*in >= 0x41) && (*in <= 0x5A)) ||
8602
24.9k
  (*in == '_') || (*in == ':')) {
8603
24.9k
  in++;
8604
92.4M
  while (((*in >= 0x61) && (*in <= 0x7A)) ||
8605
92.2M
         ((*in >= 0x41) && (*in <= 0x5A)) ||
8606
92.2M
         ((*in >= 0x30) && (*in <= 0x39)) ||
8607
50.8k
         (*in == '_') || (*in == '-') ||
8608
37.6k
         (*in == ':') || (*in == '.'))
8609
92.4M
      in++;
8610
24.9k
  if ((*in > 0) && (*in < 0x80)) {
8611
19.5k
      count = in - ctxt->cur;
8612
19.5k
            if (count > XML_MAX_NAME_LENGTH) {
8613
1.31k
                ctxt->cur = in;
8614
1.31k
                XP_ERRORNULL(XPATH_EXPR_ERROR);
8615
0
            }
8616
18.2k
      ret = xmlStrndup(ctxt->cur, count);
8617
18.2k
            if (ret == NULL)
8618
5
                xmlXPathPErrMemory(ctxt);
8619
18.2k
      ctxt->cur = in;
8620
18.2k
      return(ret);
8621
19.5k
  }
8622
24.9k
    }
8623
8.84k
    return(xmlXPathParseNameComplex(ctxt, 1));
8624
28.3k
}
8625
8626
static xmlChar *
8627
1.26M
xmlXPathParseNameComplex(xmlXPathParserContextPtr ctxt, int qualified) {
8628
1.26M
    xmlChar *ret;
8629
1.26M
    xmlChar buf[XML_MAX_NAMELEN + 5];
8630
1.26M
    int len = 0, l;
8631
1.26M
    int c;
8632
8633
    /*
8634
     * Handler for more complex cases
8635
     */
8636
1.26M
    c = CUR_CHAR(l);
8637
1.26M
    if ((c == ' ') || (c == '>') || (c == '/') || /* accelerators */
8638
1.24M
        (c == '[') || (c == ']') || (c == '@') || /* accelerators */
8639
1.16M
        (c == '*') || /* accelerators */
8640
1.16M
  (!IS_LETTER(c) && (c != '_') &&
8641
137k
         ((!qualified) || (c != ':')))) {
8642
137k
  return(NULL);
8643
137k
    }
8644
8645
6.66M
    while ((c != ' ') && (c != '>') && (c != '/') && /* test bigname.xml */
8646
6.65M
     ((IS_LETTER(c)) || (IS_DIGIT(c)) ||
8647
1.36M
            (c == '.') || (c == '-') ||
8648
1.14M
      (c == '_') || ((qualified) && (c == ':')) ||
8649
1.10M
      (IS_COMBINING(c)) ||
8650
5.54M
      (IS_EXTENDER(c)))) {
8651
5.54M
  COPY_BUF(buf,len,c);
8652
5.54M
  NEXTL(l);
8653
5.54M
  c = CUR_CHAR(l);
8654
5.54M
  if (len >= XML_MAX_NAMELEN) {
8655
      /*
8656
       * Okay someone managed to make a huge name, so he's ready to pay
8657
       * for the processing speed.
8658
       */
8659
5.28k
      xmlChar *buffer;
8660
5.28k
      int max = len * 2;
8661
8662
5.28k
            if (len > XML_MAX_NAME_LENGTH) {
8663
0
                XP_ERRORNULL(XPATH_EXPR_ERROR);
8664
0
            }
8665
5.28k
      buffer = xmlMalloc(max);
8666
5.28k
      if (buffer == NULL) {
8667
2
                xmlXPathPErrMemory(ctxt);
8668
2
                return(NULL);
8669
2
      }
8670
5.28k
      memcpy(buffer, buf, len);
8671
20.9M
      while ((IS_LETTER(c)) || (IS_DIGIT(c)) || /* test bigname.xml */
8672
32.8k
       (c == '.') || (c == '-') ||
8673
24.7k
       (c == '_') || ((qualified) && (c == ':')) ||
8674
20.6k
       (IS_COMBINING(c)) ||
8675
20.9M
       (IS_EXTENDER(c))) {
8676
20.9M
    if (len + 10 > max) {
8677
12.5k
                    xmlChar *tmp;
8678
12.5k
                    int newSize;
8679
8680
12.5k
                    newSize = xmlGrowCapacity(max, 1, 1, XML_MAX_NAME_LENGTH);
8681
12.5k
                    if (newSize < 0) {
8682
416
                        xmlFree(buffer);
8683
416
                        xmlXPathErr(ctxt, XPATH_EXPR_ERROR);
8684
416
                        return(NULL);
8685
416
                    }
8686
12.1k
        tmp = xmlRealloc(buffer, newSize);
8687
12.1k
        if (tmp == NULL) {
8688
2
                        xmlFree(buffer);
8689
2
                        xmlXPathPErrMemory(ctxt);
8690
2
                        return(NULL);
8691
2
        }
8692
12.1k
                    buffer = tmp;
8693
12.1k
        max = newSize;
8694
12.1k
    }
8695
20.9M
    COPY_BUF(buffer,len,c);
8696
20.9M
    NEXTL(l);
8697
20.9M
    c = CUR_CHAR(l);
8698
20.9M
      }
8699
4.86k
      buffer[len] = 0;
8700
4.86k
      return(buffer);
8701
5.28k
  }
8702
5.54M
    }
8703
1.11M
    if (len == 0)
8704
0
  return(NULL);
8705
1.11M
    ret = xmlStrndup(buf, len);
8706
1.11M
    if (ret == NULL)
8707
126
        xmlXPathPErrMemory(ctxt);
8708
1.11M
    return(ret);
8709
1.11M
}
8710
8711
70.4k
#define MAX_FRAC 20
8712
8713
/**
8714
 * xmlXPathStringEvalNumber:
8715
 * @str:  A string to scan
8716
 *
8717
 *  [30a]  Float  ::= Number ('e' Digits?)?
8718
 *
8719
 *  [30]   Number ::=   Digits ('.' Digits?)?
8720
 *                    | '.' Digits
8721
 *  [31]   Digits ::=   [0-9]+
8722
 *
8723
 * Compile a Number in the string
8724
 * In complement of the Number expression, this function also handles
8725
 * negative values : '-' Number.
8726
 *
8727
 * Returns the double value.
8728
 */
8729
double
8730
1.07M
xmlXPathStringEvalNumber(const xmlChar *str) {
8731
1.07M
    const xmlChar *cur = str;
8732
1.07M
    double ret;
8733
1.07M
    int ok = 0;
8734
1.07M
    int isneg = 0;
8735
1.07M
    int exponent = 0;
8736
1.07M
    int is_exponent_negative = 0;
8737
1.07M
#ifdef __GNUC__
8738
1.07M
    unsigned long tmp = 0;
8739
1.07M
    double temp;
8740
1.07M
#endif
8741
1.07M
    if (cur == NULL) return(0);
8742
1.07M
    while (IS_BLANK_CH(*cur)) cur++;
8743
1.07M
    if (*cur == '-') {
8744
12.4k
  isneg = 1;
8745
12.4k
  cur++;
8746
12.4k
    }
8747
1.07M
    if ((*cur != '.') && ((*cur < '0') || (*cur > '9'))) {
8748
956k
        return(xmlXPathNAN);
8749
956k
    }
8750
8751
113k
#ifdef __GNUC__
8752
    /*
8753
     * tmp/temp is a workaround against a gcc compiler bug
8754
     * http://veillard.com/gcc.bug
8755
     */
8756
113k
    ret = 0;
8757
614k
    while ((*cur >= '0') && (*cur <= '9')) {
8758
501k
  ret = ret * 10;
8759
501k
  tmp = (*cur - '0');
8760
501k
  ok = 1;
8761
501k
  cur++;
8762
501k
  temp = (double) tmp;
8763
501k
  ret = ret + temp;
8764
501k
    }
8765
#else
8766
    ret = 0;
8767
    while ((*cur >= '0') && (*cur <= '9')) {
8768
  ret = ret * 10 + (*cur - '0');
8769
  ok = 1;
8770
  cur++;
8771
    }
8772
#endif
8773
8774
113k
    if (*cur == '.') {
8775
51.0k
  int v, frac = 0, max;
8776
51.0k
  double fraction = 0;
8777
8778
51.0k
        cur++;
8779
51.0k
  if (((*cur < '0') || (*cur > '9')) && (!ok)) {
8780
9.25k
      return(xmlXPathNAN);
8781
9.25k
  }
8782
71.9k
        while (*cur == '0') {
8783
30.2k
      frac = frac + 1;
8784
30.2k
      cur++;
8785
30.2k
        }
8786
41.7k
        max = frac + MAX_FRAC;
8787
88.1k
  while (((*cur >= '0') && (*cur <= '9')) && (frac < max)) {
8788
46.3k
      v = (*cur - '0');
8789
46.3k
      fraction = fraction * 10 + v;
8790
46.3k
      frac = frac + 1;
8791
46.3k
      cur++;
8792
46.3k
  }
8793
41.7k
  fraction /= pow(10.0, frac);
8794
41.7k
  ret = ret + fraction;
8795
43.8k
  while ((*cur >= '0') && (*cur <= '9'))
8796
2.12k
      cur++;
8797
41.7k
    }
8798
104k
    if ((*cur == 'e') || (*cur == 'E')) {
8799
5.97k
      cur++;
8800
5.97k
      if (*cur == '-') {
8801
813
  is_exponent_negative = 1;
8802
813
  cur++;
8803
5.16k
      } else if (*cur == '+') {
8804
2.60k
        cur++;
8805
2.60k
      }
8806
43.0k
      while ((*cur >= '0') && (*cur <= '9')) {
8807
37.0k
        if (exponent < 1000000)
8808
29.6k
    exponent = exponent * 10 + (*cur - '0');
8809
37.0k
  cur++;
8810
37.0k
      }
8811
5.97k
    }
8812
104k
    while (IS_BLANK_CH(*cur)) cur++;
8813
104k
    if (*cur != 0) return(xmlXPathNAN);
8814
66.8k
    if (isneg) ret = -ret;
8815
66.8k
    if (is_exponent_negative) exponent = -exponent;
8816
66.8k
    ret *= pow(10.0, (double)exponent);
8817
66.8k
    return(ret);
8818
104k
}
8819
8820
/**
8821
 * xmlXPathCompNumber:
8822
 * @ctxt:  the XPath Parser context
8823
 *
8824
 *  [30]   Number ::=   Digits ('.' Digits?)?
8825
 *                    | '.' Digits
8826
 *  [31]   Digits ::=   [0-9]+
8827
 *
8828
 * Compile a Number, then push it on the stack
8829
 *
8830
 */
8831
static void
8832
xmlXPathCompNumber(xmlXPathParserContextPtr ctxt)
8833
236k
{
8834
236k
    double ret = 0.0;
8835
236k
    int ok = 0;
8836
236k
    int exponent = 0;
8837
236k
    int is_exponent_negative = 0;
8838
236k
    xmlXPathObjectPtr num;
8839
236k
#ifdef __GNUC__
8840
236k
    unsigned long tmp = 0;
8841
236k
    double temp;
8842
236k
#endif
8843
8844
236k
    CHECK_ERROR;
8845
235k
    if ((CUR != '.') && ((CUR < '0') || (CUR > '9'))) {
8846
0
        XP_ERROR(XPATH_NUMBER_ERROR);
8847
0
    }
8848
235k
#ifdef __GNUC__
8849
    /*
8850
     * tmp/temp is a workaround against a gcc compiler bug
8851
     * http://veillard.com/gcc.bug
8852
     */
8853
235k
    ret = 0;
8854
863k
    while ((CUR >= '0') && (CUR <= '9')) {
8855
628k
  ret = ret * 10;
8856
628k
  tmp = (CUR - '0');
8857
628k
        ok = 1;
8858
628k
        NEXT;
8859
628k
  temp = (double) tmp;
8860
628k
  ret = ret + temp;
8861
628k
    }
8862
#else
8863
    ret = 0;
8864
    while ((CUR >= '0') && (CUR <= '9')) {
8865
  ret = ret * 10 + (CUR - '0');
8866
  ok = 1;
8867
  NEXT;
8868
    }
8869
#endif
8870
235k
    if (CUR == '.') {
8871
28.7k
  int v, frac = 0, max;
8872
28.7k
  double fraction = 0;
8873
8874
28.7k
        NEXT;
8875
28.7k
        if (((CUR < '0') || (CUR > '9')) && (!ok)) {
8876
0
            XP_ERROR(XPATH_NUMBER_ERROR);
8877
0
        }
8878
44.3k
        while (CUR == '0') {
8879
15.6k
            frac = frac + 1;
8880
15.6k
            NEXT;
8881
15.6k
        }
8882
28.7k
        max = frac + MAX_FRAC;
8883
117k
        while ((CUR >= '0') && (CUR <= '9') && (frac < max)) {
8884
88.5k
      v = (CUR - '0');
8885
88.5k
      fraction = fraction * 10 + v;
8886
88.5k
      frac = frac + 1;
8887
88.5k
            NEXT;
8888
88.5k
        }
8889
28.7k
        fraction /= pow(10.0, frac);
8890
28.7k
        ret = ret + fraction;
8891
62.6k
        while ((CUR >= '0') && (CUR <= '9'))
8892
33.9k
            NEXT;
8893
28.7k
    }
8894
235k
    if ((CUR == 'e') || (CUR == 'E')) {
8895
20.2k
        NEXT;
8896
20.2k
        if (CUR == '-') {
8897
425
            is_exponent_negative = 1;
8898
425
            NEXT;
8899
19.8k
        } else if (CUR == '+') {
8900
12.5k
      NEXT;
8901
12.5k
  }
8902
116k
        while ((CUR >= '0') && (CUR <= '9')) {
8903
96.2k
            if (exponent < 1000000)
8904
69.8k
                exponent = exponent * 10 + (CUR - '0');
8905
96.2k
            NEXT;
8906
96.2k
        }
8907
20.2k
        if (is_exponent_negative)
8908
425
            exponent = -exponent;
8909
20.2k
        ret *= pow(10.0, (double) exponent);
8910
20.2k
    }
8911
235k
    num = xmlXPathCacheNewFloat(ctxt, ret);
8912
235k
    if (num == NULL) {
8913
15
  ctxt->error = XPATH_MEMORY_ERROR;
8914
235k
    } else if (PUSH_LONG_EXPR(XPATH_OP_VALUE, XPATH_NUMBER, 0, 0, num,
8915
235k
                              NULL) == -1) {
8916
11
        xmlXPathReleaseObject(ctxt->context, num);
8917
11
    }
8918
235k
}
8919
8920
/**
8921
 * xmlXPathParseLiteral:
8922
 * @ctxt:  the XPath Parser context
8923
 *
8924
 * Parse a Literal
8925
 *
8926
 *  [29]   Literal ::=   '"' [^"]* '"'
8927
 *                    | "'" [^']* "'"
8928
 *
8929
 * Returns the value found or NULL in case of error
8930
 */
8931
static xmlChar *
8932
58.5k
xmlXPathParseLiteral(xmlXPathParserContextPtr ctxt) {
8933
58.5k
    const xmlChar *q;
8934
58.5k
    xmlChar *ret = NULL;
8935
58.5k
    int quote;
8936
8937
58.5k
    if (CUR == '"') {
8938
20.5k
        quote = '"';
8939
38.0k
    } else if (CUR == '\'') {
8940
37.6k
        quote = '\'';
8941
37.6k
    } else {
8942
350
  XP_ERRORNULL(XPATH_START_LITERAL_ERROR);
8943
0
    }
8944
8945
58.1k
    NEXT;
8946
58.1k
    q = CUR_PTR;
8947
2.53M
    while (CUR != quote) {
8948
2.48M
        int ch;
8949
2.48M
        int len = 4;
8950
8951
2.48M
        if (CUR == 0)
8952
2.47M
            XP_ERRORNULL(XPATH_UNFINISHED_LITERAL_ERROR);
8953
2.47M
        ch = xmlGetUTF8Char(CUR_PTR, &len);
8954
2.47M
        if ((ch < 0) || (IS_CHAR(ch) == 0))
8955
2.47M
            XP_ERRORNULL(XPATH_INVALID_CHAR_ERROR);
8956
2.47M
        CUR_PTR += len;
8957
2.47M
    }
8958
48.7k
    ret = xmlStrndup(q, CUR_PTR - q);
8959
48.7k
    if (ret == NULL)
8960
8
        xmlXPathPErrMemory(ctxt);
8961
48.7k
    NEXT;
8962
48.7k
    return(ret);
8963
58.1k
}
8964
8965
/**
8966
 * xmlXPathCompLiteral:
8967
 * @ctxt:  the XPath Parser context
8968
 *
8969
 * Parse a Literal and push it on the stack.
8970
 *
8971
 *  [29]   Literal ::=   '"' [^"]* '"'
8972
 *                    | "'" [^']* "'"
8973
 *
8974
 * TODO: xmlXPathCompLiteral memory allocation could be improved.
8975
 */
8976
static void
8977
57.2k
xmlXPathCompLiteral(xmlXPathParserContextPtr ctxt) {
8978
57.2k
    xmlChar *ret = NULL;
8979
57.2k
    xmlXPathObjectPtr lit;
8980
8981
57.2k
    ret = xmlXPathParseLiteral(ctxt);
8982
57.2k
    if (ret == NULL)
8983
9.08k
        return;
8984
48.1k
    lit = xmlXPathCacheNewString(ctxt, ret);
8985
48.1k
    if (lit == NULL) {
8986
4
        ctxt->error = XPATH_MEMORY_ERROR;
8987
48.1k
    } else if (PUSH_LONG_EXPR(XPATH_OP_VALUE, XPATH_STRING, 0, 0, lit,
8988
48.1k
                              NULL) == -1) {
8989
4
        xmlXPathReleaseObject(ctxt->context, lit);
8990
4
    }
8991
48.1k
    xmlFree(ret);
8992
48.1k
}
8993
8994
/**
8995
 * xmlXPathCompVariableReference:
8996
 * @ctxt:  the XPath Parser context
8997
 *
8998
 * Parse a VariableReference, evaluate it and push it on the stack.
8999
 *
9000
 * The variable bindings consist of a mapping from variable names
9001
 * to variable values. The value of a variable is an object, which can be
9002
 * of any of the types that are possible for the value of an expression,
9003
 * and may also be of additional types not specified here.
9004
 *
9005
 * Early evaluation is possible since:
9006
 * The variable bindings [...] used to evaluate a subexpression are
9007
 * always the same as those used to evaluate the containing expression.
9008
 *
9009
 *  [36]   VariableReference ::=   '$' QName
9010
 */
9011
static void
9012
34.2k
xmlXPathCompVariableReference(xmlXPathParserContextPtr ctxt) {
9013
34.2k
    xmlChar *name;
9014
34.2k
    xmlChar *prefix;
9015
9016
34.2k
    SKIP_BLANKS;
9017
34.2k
    if (CUR != '$') {
9018
0
  XP_ERROR(XPATH_VARIABLE_REF_ERROR);
9019
0
    }
9020
34.2k
    NEXT;
9021
34.2k
    name = xmlXPathParseQName(ctxt, &prefix);
9022
34.2k
    if (name == NULL) {
9023
2.06k
        xmlFree(prefix);
9024
2.06k
  XP_ERROR(XPATH_VARIABLE_REF_ERROR);
9025
0
    }
9026
32.1k
    ctxt->comp->last = -1;
9027
32.1k
    if (PUSH_LONG_EXPR(XPATH_OP_VARIABLE, 0, 0, 0, name, prefix) == -1) {
9028
1
        xmlFree(prefix);
9029
1
        xmlFree(name);
9030
1
    }
9031
32.1k
    SKIP_BLANKS;
9032
32.1k
    if ((ctxt->context != NULL) && (ctxt->context->flags & XML_XPATH_NOVAR)) {
9033
220
  XP_ERROR(XPATH_FORBID_VARIABLE_ERROR);
9034
0
    }
9035
32.1k
}
9036
9037
/**
9038
 * xmlXPathIsNodeType:
9039
 * @name:  a name string
9040
 *
9041
 * Is the name given a NodeType one.
9042
 *
9043
 *  [38]   NodeType ::=   'comment'
9044
 *                    | 'text'
9045
 *                    | 'processing-instruction'
9046
 *                    | 'node'
9047
 *
9048
 * Returns 1 if true 0 otherwise
9049
 */
9050
int
9051
487k
xmlXPathIsNodeType(const xmlChar *name) {
9052
487k
    if (name == NULL)
9053
0
  return(0);
9054
9055
487k
    if (xmlStrEqual(name, BAD_CAST "node"))
9056
27.0k
  return(1);
9057
460k
    if (xmlStrEqual(name, BAD_CAST "text"))
9058
12.1k
  return(1);
9059
448k
    if (xmlStrEqual(name, BAD_CAST "comment"))
9060
1.00k
  return(1);
9061
447k
    if (xmlStrEqual(name, BAD_CAST "processing-instruction"))
9062
1.78k
  return(1);
9063
445k
    return(0);
9064
447k
}
9065
9066
/**
9067
 * xmlXPathCompFunctionCall:
9068
 * @ctxt:  the XPath Parser context
9069
 *
9070
 *  [16]   FunctionCall ::=   FunctionName '(' ( Argument ( ',' Argument)*)? ')'
9071
 *  [17]   Argument ::=   Expr
9072
 *
9073
 * Compile a function call, the evaluation of all arguments are
9074
 * pushed on the stack
9075
 */
9076
static void
9077
435k
xmlXPathCompFunctionCall(xmlXPathParserContextPtr ctxt) {
9078
435k
    xmlChar *name;
9079
435k
    xmlChar *prefix;
9080
435k
    int nbargs = 0;
9081
435k
    int sort = 1;
9082
9083
435k
    name = xmlXPathParseQName(ctxt, &prefix);
9084
435k
    if (name == NULL) {
9085
1.00k
  xmlFree(prefix);
9086
1.00k
  XP_ERROR(XPATH_EXPR_ERROR);
9087
0
    }
9088
434k
    SKIP_BLANKS;
9089
9090
434k
    if (CUR != '(') {
9091
1.50k
  xmlFree(name);
9092
1.50k
  xmlFree(prefix);
9093
1.50k
  XP_ERROR(XPATH_EXPR_ERROR);
9094
0
    }
9095
433k
    NEXT;
9096
433k
    SKIP_BLANKS;
9097
9098
    /*
9099
    * Optimization for count(): we don't need the node-set to be sorted.
9100
    */
9101
433k
    if ((prefix == NULL) && (name[0] == 'c') &&
9102
25.0k
  xmlStrEqual(name, BAD_CAST "count"))
9103
1.00k
    {
9104
1.00k
  sort = 0;
9105
1.00k
    }
9106
433k
    ctxt->comp->last = -1;
9107
433k
    if (CUR != ')') {
9108
558k
  while (CUR != 0) {
9109
540k
      int op1 = ctxt->comp->last;
9110
540k
      ctxt->comp->last = -1;
9111
540k
      xmlXPathCompileExpr(ctxt, sort);
9112
540k
      if (ctxt->error != XPATH_EXPRESSION_OK) {
9113
87.3k
    xmlFree(name);
9114
87.3k
    xmlFree(prefix);
9115
87.3k
    return;
9116
87.3k
      }
9117
452k
      PUSH_BINARY_EXPR(XPATH_OP_ARG, op1, ctxt->comp->last, 0, 0);
9118
452k
      nbargs++;
9119
452k
      if (CUR == ')') break;
9120
217k
      if (CUR != ',') {
9121
13.6k
    xmlFree(name);
9122
13.6k
    xmlFree(prefix);
9123
13.6k
    XP_ERROR(XPATH_EXPR_ERROR);
9124
0
      }
9125
203k
      NEXT;
9126
203k
      SKIP_BLANKS;
9127
203k
  }
9128
355k
    }
9129
332k
    if (PUSH_LONG_EXPR(XPATH_OP_FUNCTION, nbargs, 0, 0, name, prefix) == -1) {
9130
13
        xmlFree(prefix);
9131
13
        xmlFree(name);
9132
13
    }
9133
332k
    NEXT;
9134
332k
    SKIP_BLANKS;
9135
332k
}
9136
9137
/**
9138
 * xmlXPathCompPrimaryExpr:
9139
 * @ctxt:  the XPath Parser context
9140
 *
9141
 *  [15]   PrimaryExpr ::=   VariableReference
9142
 *                | '(' Expr ')'
9143
 *                | Literal
9144
 *                | Number
9145
 *                | FunctionCall
9146
 *
9147
 * Compile a primary expression.
9148
 */
9149
static void
9150
862k
xmlXPathCompPrimaryExpr(xmlXPathParserContextPtr ctxt) {
9151
862k
    SKIP_BLANKS;
9152
862k
    if (CUR == '$') xmlXPathCompVariableReference(ctxt);
9153
828k
    else if (CUR == '(') {
9154
99.5k
  NEXT;
9155
99.5k
  SKIP_BLANKS;
9156
99.5k
  xmlXPathCompileExpr(ctxt, 1);
9157
99.5k
  CHECK_ERROR;
9158
48.8k
  if (CUR != ')') {
9159
14.6k
      XP_ERROR(XPATH_EXPR_ERROR);
9160
0
  }
9161
34.1k
  NEXT;
9162
34.1k
  SKIP_BLANKS;
9163
729k
    } else if (IS_ASCII_DIGIT(CUR) || (CUR == '.' && IS_ASCII_DIGIT(NXT(1)))) {
9164
236k
  xmlXPathCompNumber(ctxt);
9165
493k
    } else if ((CUR == '\'') || (CUR == '"')) {
9166
57.2k
  xmlXPathCompLiteral(ctxt);
9167
435k
    } else {
9168
435k
  xmlXPathCompFunctionCall(ctxt);
9169
435k
    }
9170
797k
    SKIP_BLANKS;
9171
797k
}
9172
9173
/**
9174
 * xmlXPathCompFilterExpr:
9175
 * @ctxt:  the XPath Parser context
9176
 *
9177
 *  [20]   FilterExpr ::=   PrimaryExpr
9178
 *               | FilterExpr Predicate
9179
 *
9180
 * Compile a filter expression.
9181
 * Square brackets are used to filter expressions in the same way that
9182
 * they are used in location paths. It is an error if the expression to
9183
 * be filtered does not evaluate to a node-set. The context node list
9184
 * used for evaluating the expression in square brackets is the node-set
9185
 * to be filtered listed in document order.
9186
 */
9187
9188
static void
9189
862k
xmlXPathCompFilterExpr(xmlXPathParserContextPtr ctxt) {
9190
862k
    xmlXPathCompPrimaryExpr(ctxt);
9191
862k
    CHECK_ERROR;
9192
682k
    SKIP_BLANKS;
9193
9194
780k
    while (CUR == '[') {
9195
98.3k
  xmlXPathCompPredicate(ctxt, 1);
9196
98.3k
  SKIP_BLANKS;
9197
98.3k
    }
9198
9199
9200
682k
}
9201
9202
/**
9203
 * xmlXPathScanName:
9204
 * @ctxt:  the XPath Parser context
9205
 *
9206
 * Trickery: parse an XML name but without consuming the input flow
9207
 * Needed to avoid insanity in the parser state.
9208
 *
9209
 * [4] NameChar ::= Letter | Digit | '.' | '-' | '_' | ':' |
9210
 *                  CombiningChar | Extender
9211
 *
9212
 * [5] Name ::= (Letter | '_' | ':') (NameChar)*
9213
 *
9214
 * [6] Names ::= Name (S Name)*
9215
 *
9216
 * Returns the Name parsed or NULL
9217
 */
9218
9219
static xmlChar *
9220
1.15M
xmlXPathScanName(xmlXPathParserContextPtr ctxt) {
9221
1.15M
    int l;
9222
1.15M
    int c;
9223
1.15M
    const xmlChar *cur;
9224
1.15M
    xmlChar *ret;
9225
9226
1.15M
    cur = ctxt->cur;
9227
9228
1.15M
    c = CUR_CHAR(l);
9229
1.15M
    if ((c == ' ') || (c == '>') || (c == '/') || /* accelerators */
9230
1.14M
  (!IS_LETTER(c) && (c != '_') &&
9231
98.1k
         (c != ':'))) {
9232
98.1k
  return(NULL);
9233
98.1k
    }
9234
9235
13.9M
    while ((c != ' ') && (c != '>') && (c != '/') && /* test bigname.xml */
9236
13.7M
     ((IS_LETTER(c)) || (IS_DIGIT(c)) ||
9237
1.45M
            (c == '.') || (c == '-') ||
9238
1.23M
      (c == '_') || (c == ':') ||
9239
873k
      (IS_COMBINING(c)) ||
9240
12.8M
      (IS_EXTENDER(c)))) {
9241
12.8M
  NEXTL(l);
9242
12.8M
  c = CUR_CHAR(l);
9243
12.8M
    }
9244
1.05M
    ret = xmlStrndup(cur, ctxt->cur - cur);
9245
1.05M
    if (ret == NULL)
9246
82
        xmlXPathPErrMemory(ctxt);
9247
1.05M
    ctxt->cur = cur;
9248
1.05M
    return(ret);
9249
1.15M
}
9250
9251
/**
9252
 * xmlXPathCompPathExpr:
9253
 * @ctxt:  the XPath Parser context
9254
 *
9255
 *  [19]   PathExpr ::=   LocationPath
9256
 *               | FilterExpr
9257
 *               | FilterExpr '/' RelativeLocationPath
9258
 *               | FilterExpr '//' RelativeLocationPath
9259
 *
9260
 * Compile a path expression.
9261
 * The / operator and // operators combine an arbitrary expression
9262
 * and a relative location path. It is an error if the expression
9263
 * does not evaluate to a node-set.
9264
 * The / operator does composition in the same way as when / is
9265
 * used in a location path. As in location paths, // is short for
9266
 * /descendant-or-self::node()/.
9267
 */
9268
9269
static void
9270
3.40M
xmlXPathCompPathExpr(xmlXPathParserContextPtr ctxt) {
9271
3.40M
    int lc = 1;           /* Should we branch to LocationPath ?         */
9272
3.40M
    xmlChar *name = NULL; /* we may have to preparse a name to find out */
9273
9274
3.40M
    SKIP_BLANKS;
9275
3.40M
    if ((CUR == '$') || (CUR == '(') ||
9276
3.26M
  (IS_ASCII_DIGIT(CUR)) ||
9277
3.04M
        (CUR == '\'') || (CUR == '"') ||
9278
2.98M
  (CUR == '.' && IS_ASCII_DIGIT(NXT(1)))) {
9279
427k
  lc = 0;
9280
2.97M
    } else if (CUR == '*') {
9281
  /* relative or absolute location path */
9282
1.06M
  lc = 1;
9283
1.91M
    } else if (CUR == '/') {
9284
  /* relative or absolute location path */
9285
389k
  lc = 1;
9286
1.52M
    } else if (CUR == '@') {
9287
  /* relative abbreviated attribute location path */
9288
65.4k
  lc = 1;
9289
1.45M
    } else if (CUR == '.') {
9290
  /* relative abbreviated attribute location path */
9291
303k
  lc = 1;
9292
1.15M
    } else {
9293
  /*
9294
   * Problem is finding if we have a name here whether it's:
9295
   *   - a nodetype
9296
   *   - a function call in which case it's followed by '('
9297
   *   - an axis in which case it's followed by ':'
9298
   *   - a element name
9299
   * We do an a priori analysis here rather than having to
9300
   * maintain parsed token content through the recursive function
9301
   * calls. This looks uglier but makes the code easier to
9302
   * read/write/debug.
9303
   */
9304
1.15M
  SKIP_BLANKS;
9305
1.15M
  name = xmlXPathScanName(ctxt);
9306
1.15M
  if ((name != NULL) && (xmlStrstr(name, (xmlChar *) "::") != NULL)) {
9307
15.0k
      lc = 1;
9308
15.0k
      xmlFree(name);
9309
1.14M
  } else if (name != NULL) {
9310
1.04M
      int len =xmlStrlen(name);
9311
9312
9313
1.27M
      while (NXT(len) != 0) {
9314
1.21M
    if (NXT(len) == '/') {
9315
        /* element name */
9316
82.3k
        lc = 1;
9317
82.3k
        break;
9318
1.12M
    } else if (IS_BLANK_CH(NXT(len))) {
9319
        /* ignore blanks */
9320
235k
        ;
9321
892k
    } else if (NXT(len) == ':') {
9322
1.52k
        lc = 1;
9323
1.52k
        break;
9324
891k
    } else if ((NXT(len) == '(')) {
9325
        /* Node Type or Function */
9326
475k
        if (xmlXPathIsNodeType(name)) {
9327
39.4k
      lc = 1;
9328
435k
        } else {
9329
435k
      lc = 0;
9330
435k
        }
9331
475k
                    break;
9332
475k
    } else if ((NXT(len) == '[')) {
9333
        /* element name */
9334
30.5k
        lc = 1;
9335
30.5k
        break;
9336
385k
    } else if ((NXT(len) == '<') || (NXT(len) == '>') ||
9337
330k
         (NXT(len) == '=')) {
9338
110k
        lc = 1;
9339
110k
        break;
9340
274k
    } else {
9341
274k
        lc = 1;
9342
274k
        break;
9343
274k
    }
9344
235k
    len++;
9345
235k
      }
9346
1.04M
      if (NXT(len) == 0) {
9347
    /* element name */
9348
66.6k
    lc = 1;
9349
66.6k
      }
9350
1.04M
      xmlFree(name);
9351
1.04M
  } else {
9352
      /* make sure all cases are covered explicitly */
9353
98.2k
      XP_ERROR(XPATH_EXPR_ERROR);
9354
0
  }
9355
1.15M
    }
9356
9357
3.30M
    if (lc) {
9358
2.44M
  if (CUR == '/') {
9359
389k
      PUSH_LEAVE_EXPR(XPATH_OP_ROOT, 0, 0);
9360
2.05M
  } else {
9361
2.05M
      PUSH_LEAVE_EXPR(XPATH_OP_NODE, 0, 0);
9362
2.05M
  }
9363
2.44M
  xmlXPathCompLocationPath(ctxt);
9364
2.44M
    } else {
9365
862k
  xmlXPathCompFilterExpr(ctxt);
9366
862k
  CHECK_ERROR;
9367
677k
  if ((CUR == '/') && (NXT(1) == '/')) {
9368
6.93k
      SKIP(2);
9369
6.93k
      SKIP_BLANKS;
9370
9371
6.93k
      PUSH_LONG_EXPR(XPATH_OP_COLLECT, AXIS_DESCENDANT_OR_SELF,
9372
6.93k
        NODE_TEST_TYPE, NODE_TYPE_NODE, NULL, NULL);
9373
9374
6.93k
      xmlXPathCompRelativeLocationPath(ctxt);
9375
670k
  } else if (CUR == '/') {
9376
55.5k
      xmlXPathCompRelativeLocationPath(ctxt);
9377
55.5k
  }
9378
677k
    }
9379
3.11M
    SKIP_BLANKS;
9380
3.11M
}
9381
9382
/**
9383
 * xmlXPathCompUnionExpr:
9384
 * @ctxt:  the XPath Parser context
9385
 *
9386
 *  [18]   UnionExpr ::=   PathExpr
9387
 *               | UnionExpr '|' PathExpr
9388
 *
9389
 * Compile an union expression.
9390
 */
9391
9392
static void
9393
3.01M
xmlXPathCompUnionExpr(xmlXPathParserContextPtr ctxt) {
9394
3.01M
    xmlXPathCompPathExpr(ctxt);
9395
3.01M
    CHECK_ERROR;
9396
2.68M
    SKIP_BLANKS;
9397
3.07M
    while (CUR == '|') {
9398
388k
  int op1 = ctxt->comp->last;
9399
388k
  PUSH_LEAVE_EXPR(XPATH_OP_NODE, 0, 0);
9400
9401
388k
  NEXT;
9402
388k
  SKIP_BLANKS;
9403
388k
  xmlXPathCompPathExpr(ctxt);
9404
9405
388k
  PUSH_BINARY_EXPR(XPATH_OP_UNION, op1, ctxt->comp->last, 0, 0);
9406
9407
388k
  SKIP_BLANKS;
9408
388k
    }
9409
2.68M
}
9410
9411
/**
9412
 * xmlXPathCompUnaryExpr:
9413
 * @ctxt:  the XPath Parser context
9414
 *
9415
 *  [27]   UnaryExpr ::=   UnionExpr
9416
 *                   | '-' UnaryExpr
9417
 *
9418
 * Compile an unary expression.
9419
 */
9420
9421
static void
9422
3.01M
xmlXPathCompUnaryExpr(xmlXPathParserContextPtr ctxt) {
9423
3.01M
    int minus = 0;
9424
3.01M
    int found = 0;
9425
9426
3.01M
    SKIP_BLANKS;
9427
3.19M
    while (CUR == '-') {
9428
177k
        minus = 1 - minus;
9429
177k
  found = 1;
9430
177k
  NEXT;
9431
177k
  SKIP_BLANKS;
9432
177k
    }
9433
9434
3.01M
    xmlXPathCompUnionExpr(ctxt);
9435
3.01M
    CHECK_ERROR;
9436
2.66M
    if (found) {
9437
66.8k
  if (minus)
9438
55.9k
      PUSH_UNARY_EXPR(XPATH_OP_PLUS, ctxt->comp->last, 2, 0);
9439
10.8k
  else
9440
10.8k
      PUSH_UNARY_EXPR(XPATH_OP_PLUS, ctxt->comp->last, 3, 0);
9441
66.8k
    }
9442
2.66M
}
9443
9444
/**
9445
 * xmlXPathCompMultiplicativeExpr:
9446
 * @ctxt:  the XPath Parser context
9447
 *
9448
 *  [26]   MultiplicativeExpr ::=   UnaryExpr
9449
 *                   | MultiplicativeExpr MultiplyOperator UnaryExpr
9450
 *                   | MultiplicativeExpr 'div' UnaryExpr
9451
 *                   | MultiplicativeExpr 'mod' UnaryExpr
9452
 *  [34]   MultiplyOperator ::=   '*'
9453
 *
9454
 * Compile an Additive expression.
9455
 */
9456
9457
static void
9458
1.93M
xmlXPathCompMultiplicativeExpr(xmlXPathParserContextPtr ctxt) {
9459
1.93M
    xmlXPathCompUnaryExpr(ctxt);
9460
1.93M
    CHECK_ERROR;
9461
1.59M
    SKIP_BLANKS;
9462
2.66M
    while ((CUR == '*') ||
9463
1.61M
           ((CUR == 'd') && (NXT(1) == 'i') && (NXT(2) == 'v')) ||
9464
1.61M
           ((CUR == 'm') && (NXT(1) == 'o') && (NXT(2) == 'd'))) {
9465
1.08M
  int op = -1;
9466
1.08M
  int op1 = ctxt->comp->last;
9467
9468
1.08M
        if (CUR == '*') {
9469
1.05M
      op = 0;
9470
1.05M
      NEXT;
9471
1.05M
  } else if (CUR == 'd') {
9472
817
      op = 1;
9473
817
      SKIP(3);
9474
27.0k
  } else if (CUR == 'm') {
9475
27.0k
      op = 2;
9476
27.0k
      SKIP(3);
9477
27.0k
  }
9478
1.08M
  SKIP_BLANKS;
9479
1.08M
        xmlXPathCompUnaryExpr(ctxt);
9480
1.08M
  CHECK_ERROR;
9481
1.07M
  PUSH_BINARY_EXPR(XPATH_OP_MULT, op1, ctxt->comp->last, op, 0);
9482
1.07M
  SKIP_BLANKS;
9483
1.07M
    }
9484
1.59M
}
9485
9486
/**
9487
 * xmlXPathCompAdditiveExpr:
9488
 * @ctxt:  the XPath Parser context
9489
 *
9490
 *  [25]   AdditiveExpr ::=   MultiplicativeExpr
9491
 *                   | AdditiveExpr '+' MultiplicativeExpr
9492
 *                   | AdditiveExpr '-' MultiplicativeExpr
9493
 *
9494
 * Compile an Additive expression.
9495
 */
9496
9497
static void
9498
1.73M
xmlXPathCompAdditiveExpr(xmlXPathParserContextPtr ctxt) {
9499
9500
1.73M
    xmlXPathCompMultiplicativeExpr(ctxt);
9501
1.73M
    CHECK_ERROR;
9502
1.41M
    SKIP_BLANKS;
9503
1.58M
    while ((CUR == '+') || (CUR == '-')) {
9504
194k
  int plus;
9505
194k
  int op1 = ctxt->comp->last;
9506
9507
194k
        if (CUR == '+') plus = 1;
9508
124k
  else plus = 0;
9509
194k
  NEXT;
9510
194k
  SKIP_BLANKS;
9511
194k
        xmlXPathCompMultiplicativeExpr(ctxt);
9512
194k
  CHECK_ERROR;
9513
169k
  PUSH_BINARY_EXPR(XPATH_OP_PLUS, op1, ctxt->comp->last, plus, 0);
9514
169k
  SKIP_BLANKS;
9515
169k
    }
9516
1.41M
}
9517
9518
/**
9519
 * xmlXPathCompRelationalExpr:
9520
 * @ctxt:  the XPath Parser context
9521
 *
9522
 *  [24]   RelationalExpr ::=   AdditiveExpr
9523
 *                 | RelationalExpr '<' AdditiveExpr
9524
 *                 | RelationalExpr '>' AdditiveExpr
9525
 *                 | RelationalExpr '<=' AdditiveExpr
9526
 *                 | RelationalExpr '>=' AdditiveExpr
9527
 *
9528
 *  A <= B > C is allowed ? Answer from James, yes with
9529
 *  (AdditiveExpr <= AdditiveExpr) > AdditiveExpr
9530
 *  which is basically what got implemented.
9531
 *
9532
 * Compile a Relational expression, then push the result
9533
 * on the stack
9534
 */
9535
9536
static void
9537
1.60M
xmlXPathCompRelationalExpr(xmlXPathParserContextPtr ctxt) {
9538
1.60M
    xmlXPathCompAdditiveExpr(ctxt);
9539
1.60M
    CHECK_ERROR;
9540
1.28M
    SKIP_BLANKS;
9541
1.39M
    while ((CUR == '<') || (CUR == '>')) {
9542
133k
  int inf, strict;
9543
133k
  int op1 = ctxt->comp->last;
9544
9545
133k
        if (CUR == '<') inf = 1;
9546
129k
  else inf = 0;
9547
133k
  if (NXT(1) == '=') strict = 0;
9548
126k
  else strict = 1;
9549
133k
  NEXT;
9550
133k
  if (!strict) NEXT;
9551
133k
  SKIP_BLANKS;
9552
133k
        xmlXPathCompAdditiveExpr(ctxt);
9553
133k
  CHECK_ERROR;
9554
108k
  PUSH_BINARY_EXPR(XPATH_OP_CMP, op1, ctxt->comp->last, inf, strict);
9555
108k
  SKIP_BLANKS;
9556
108k
    }
9557
1.28M
}
9558
9559
/**
9560
 * xmlXPathCompEqualityExpr:
9561
 * @ctxt:  the XPath Parser context
9562
 *
9563
 *  [23]   EqualityExpr ::=   RelationalExpr
9564
 *                 | EqualityExpr '=' RelationalExpr
9565
 *                 | EqualityExpr '!=' RelationalExpr
9566
 *
9567
 *  A != B != C is allowed ? Answer from James, yes with
9568
 *  (RelationalExpr = RelationalExpr) = RelationalExpr
9569
 *  (RelationalExpr != RelationalExpr) != RelationalExpr
9570
 *  which is basically what got implemented.
9571
 *
9572
 * Compile an Equality expression.
9573
 *
9574
 */
9575
static void
9576
1.48M
xmlXPathCompEqualityExpr(xmlXPathParserContextPtr ctxt) {
9577
1.48M
    xmlXPathCompRelationalExpr(ctxt);
9578
1.48M
    CHECK_ERROR;
9579
1.15M
    SKIP_BLANKS;
9580
1.25M
    while ((CUR == '=') || ((CUR == '!') && (NXT(1) == '='))) {
9581
120k
  int eq;
9582
120k
  int op1 = ctxt->comp->last;
9583
9584
120k
        if (CUR == '=') eq = 1;
9585
19.6k
  else eq = 0;
9586
120k
  NEXT;
9587
120k
  if (!eq) NEXT;
9588
120k
  SKIP_BLANKS;
9589
120k
        xmlXPathCompRelationalExpr(ctxt);
9590
120k
  CHECK_ERROR;
9591
98.3k
  PUSH_BINARY_EXPR(XPATH_OP_EQUAL, op1, ctxt->comp->last, eq, 0);
9592
98.3k
  SKIP_BLANKS;
9593
98.3k
    }
9594
1.15M
}
9595
9596
/**
9597
 * xmlXPathCompAndExpr:
9598
 * @ctxt:  the XPath Parser context
9599
 *
9600
 *  [22]   AndExpr ::=   EqualityExpr
9601
 *                 | AndExpr 'and' EqualityExpr
9602
 *
9603
 * Compile an AND expression.
9604
 *
9605
 */
9606
static void
9607
1.46M
xmlXPathCompAndExpr(xmlXPathParserContextPtr ctxt) {
9608
1.46M
    xmlXPathCompEqualityExpr(ctxt);
9609
1.46M
    CHECK_ERROR;
9610
1.11M
    SKIP_BLANKS;
9611
1.13M
    while ((CUR == 'a') && (NXT(1) == 'n') && (NXT(2) == 'd')) {
9612
18.3k
  int op1 = ctxt->comp->last;
9613
18.3k
        SKIP(3);
9614
18.3k
  SKIP_BLANKS;
9615
18.3k
        xmlXPathCompEqualityExpr(ctxt);
9616
18.3k
  CHECK_ERROR;
9617
17.2k
  PUSH_BINARY_EXPR(XPATH_OP_AND, op1, ctxt->comp->last, 0, 0);
9618
17.2k
  SKIP_BLANKS;
9619
17.2k
    }
9620
1.11M
}
9621
9622
/**
9623
 * xmlXPathCompileExpr:
9624
 * @ctxt:  the XPath Parser context
9625
 *
9626
 *  [14]   Expr ::=   OrExpr
9627
 *  [21]   OrExpr ::=   AndExpr
9628
 *                 | OrExpr 'or' AndExpr
9629
 *
9630
 * Parse and compile an expression
9631
 */
9632
static void
9633
1.48M
xmlXPathCompileExpr(xmlXPathParserContextPtr ctxt, int sort) {
9634
1.48M
    xmlXPathContextPtr xpctxt = ctxt->context;
9635
9636
1.48M
    if (xpctxt != NULL) {
9637
1.48M
        if (xpctxt->depth >= XPATH_MAX_RECURSION_DEPTH)
9638
1.43M
            XP_ERROR(XPATH_RECURSION_LIMIT_EXCEEDED);
9639
        /*
9640
         * Parsing a single '(' pushes about 10 functions on the call stack
9641
         * before recursing!
9642
         */
9643
1.43M
        xpctxt->depth += 10;
9644
1.43M
    }
9645
9646
1.43M
    xmlXPathCompAndExpr(ctxt);
9647
1.43M
    CHECK_ERROR;
9648
1.09M
    SKIP_BLANKS;
9649
1.11M
    while ((CUR == 'o') && (NXT(1) == 'r')) {
9650
27.1k
  int op1 = ctxt->comp->last;
9651
27.1k
        SKIP(2);
9652
27.1k
  SKIP_BLANKS;
9653
27.1k
        xmlXPathCompAndExpr(ctxt);
9654
27.1k
  CHECK_ERROR;
9655
21.4k
  PUSH_BINARY_EXPR(XPATH_OP_OR, op1, ctxt->comp->last, 0, 0);
9656
21.4k
  SKIP_BLANKS;
9657
21.4k
    }
9658
1.09M
    if ((sort) && (ctxt->comp->steps[ctxt->comp->last].op != XPATH_OP_VALUE)) {
9659
  /* more ops could be optimized too */
9660
  /*
9661
  * This is the main place to eliminate sorting for
9662
  * operations which don't require a sorted node-set.
9663
  * E.g. count().
9664
  */
9665
937k
  PUSH_UNARY_EXPR(XPATH_OP_SORT, ctxt->comp->last , 0, 0);
9666
937k
    }
9667
9668
1.09M
    if (xpctxt != NULL)
9669
1.09M
        xpctxt->depth -= 10;
9670
1.09M
}
9671
9672
/**
9673
 * xmlXPathCompPredicate:
9674
 * @ctxt:  the XPath Parser context
9675
 * @filter:  act as a filter
9676
 *
9677
 *  [8]   Predicate ::=   '[' PredicateExpr ']'
9678
 *  [9]   PredicateExpr ::=   Expr
9679
 *
9680
 * Compile a predicate expression
9681
 */
9682
static void
9683
199k
xmlXPathCompPredicate(xmlXPathParserContextPtr ctxt, int filter) {
9684
199k
    int op1 = ctxt->comp->last;
9685
9686
199k
    SKIP_BLANKS;
9687
199k
    if (CUR != '[') {
9688
0
  XP_ERROR(XPATH_INVALID_PREDICATE_ERROR);
9689
0
    }
9690
199k
    NEXT;
9691
199k
    SKIP_BLANKS;
9692
9693
199k
    ctxt->comp->last = -1;
9694
    /*
9695
    * This call to xmlXPathCompileExpr() will deactivate sorting
9696
    * of the predicate result.
9697
    * TODO: Sorting is still activated for filters, since I'm not
9698
    *  sure if needed. Normally sorting should not be needed, since
9699
    *  a filter can only diminish the number of items in a sequence,
9700
    *  but won't change its order; so if the initial sequence is sorted,
9701
    *  subsequent sorting is not needed.
9702
    */
9703
199k
    if (! filter)
9704
101k
  xmlXPathCompileExpr(ctxt, 0);
9705
98.3k
    else
9706
98.3k
  xmlXPathCompileExpr(ctxt, 1);
9707
199k
    CHECK_ERROR;
9708
9709
179k
    if (CUR != ']') {
9710
6.78k
  XP_ERROR(XPATH_INVALID_PREDICATE_ERROR);
9711
0
    }
9712
9713
172k
    if (filter)
9714
92.2k
  PUSH_BINARY_EXPR(XPATH_OP_FILTER, op1, ctxt->comp->last, 0, 0);
9715
80.1k
    else
9716
80.1k
  PUSH_BINARY_EXPR(XPATH_OP_PREDICATE, op1, ctxt->comp->last, 0, 0);
9717
9718
172k
    NEXT;
9719
172k
    SKIP_BLANKS;
9720
172k
}
9721
9722
/**
9723
 * xmlXPathCompNodeTest:
9724
 * @ctxt:  the XPath Parser context
9725
 * @test:  pointer to a xmlXPathTestVal
9726
 * @type:  pointer to a xmlXPathTypeVal
9727
 * @prefix:  placeholder for a possible name prefix
9728
 *
9729
 * [7] NodeTest ::=   NameTest
9730
 *        | NodeType '(' ')'
9731
 *        | 'processing-instruction' '(' Literal ')'
9732
 *
9733
 * [37] NameTest ::=  '*'
9734
 *        | NCName ':' '*'
9735
 *        | QName
9736
 * [38] NodeType ::= 'comment'
9737
 *       | 'text'
9738
 *       | 'processing-instruction'
9739
 *       | 'node'
9740
 *
9741
 * Returns the name found and updates @test, @type and @prefix appropriately
9742
 */
9743
static xmlChar *
9744
xmlXPathCompNodeTest(xmlXPathParserContextPtr ctxt, xmlXPathTestVal *test,
9745
               xmlXPathTypeVal *type, xmlChar **prefix,
9746
2.24M
         xmlChar *name) {
9747
2.24M
    int blanks;
9748
9749
2.24M
    if ((test == NULL) || (type == NULL) || (prefix == NULL)) {
9750
0
  return(NULL);
9751
0
    }
9752
2.24M
    *type = (xmlXPathTypeVal) 0;
9753
2.24M
    *test = (xmlXPathTestVal) 0;
9754
2.24M
    *prefix = NULL;
9755
2.24M
    SKIP_BLANKS;
9756
9757
2.24M
    if ((name == NULL) && (CUR == '*')) {
9758
  /*
9759
   * All elements
9760
   */
9761
1.15M
  NEXT;
9762
1.15M
  *test = NODE_TEST_ALL;
9763
1.15M
  return(NULL);
9764
1.15M
    }
9765
9766
1.08M
    if (name == NULL)
9767
108k
  name = xmlXPathParseNCName(ctxt);
9768
1.08M
    if (name == NULL) {
9769
22.1k
  XP_ERRORNULL(XPATH_EXPR_ERROR);
9770
0
    }
9771
9772
1.06M
    blanks = IS_BLANK_CH(CUR);
9773
1.06M
    SKIP_BLANKS;
9774
1.06M
    if (CUR == '(') {
9775
196k
  NEXT;
9776
  /*
9777
   * NodeType or PI search
9778
   */
9779
196k
  if (xmlStrEqual(name, BAD_CAST "comment"))
9780
21.4k
      *type = NODE_TYPE_COMMENT;
9781
174k
  else if (xmlStrEqual(name, BAD_CAST "node"))
9782
130k
      *type = NODE_TYPE_NODE;
9783
44.2k
  else if (xmlStrEqual(name, BAD_CAST "processing-instruction"))
9784
8.53k
      *type = NODE_TYPE_PI;
9785
35.7k
  else if (xmlStrEqual(name, BAD_CAST "text"))
9786
32.7k
      *type = NODE_TYPE_TEXT;
9787
3.03k
  else {
9788
3.03k
      if (name != NULL)
9789
3.03k
    xmlFree(name);
9790
3.03k
      XP_ERRORNULL(XPATH_EXPR_ERROR);
9791
0
  }
9792
9793
193k
  *test = NODE_TEST_TYPE;
9794
9795
193k
  SKIP_BLANKS;
9796
193k
  if (*type == NODE_TYPE_PI) {
9797
      /*
9798
       * Specific case: search a PI by name.
9799
       */
9800
8.53k
      if (name != NULL)
9801
8.53k
    xmlFree(name);
9802
8.53k
      name = NULL;
9803
8.53k
      if (CUR != ')') {
9804
1.27k
    name = xmlXPathParseLiteral(ctxt);
9805
1.27k
    *test = NODE_TEST_PI;
9806
1.27k
    SKIP_BLANKS;
9807
1.27k
      }
9808
8.53k
  }
9809
193k
  if (CUR != ')') {
9810
1.70k
      if (name != NULL)
9811
1.03k
    xmlFree(name);
9812
1.70k
      XP_ERRORNULL(XPATH_UNCLOSED_ERROR);
9813
0
  }
9814
191k
  NEXT;
9815
191k
  return(name);
9816
193k
    }
9817
869k
    *test = NODE_TEST_NAME;
9818
869k
    if ((!blanks) && (CUR == ':')) {
9819
69.8k
  NEXT;
9820
9821
  /*
9822
   * Since currently the parser context don't have a
9823
   * namespace list associated:
9824
   * The namespace name for this prefix can be computed
9825
   * only at evaluation time. The compilation is done
9826
   * outside of any context.
9827
   */
9828
69.8k
  *prefix = name;
9829
9830
69.8k
  if (CUR == '*') {
9831
      /*
9832
       * All elements
9833
       */
9834
6.39k
      NEXT;
9835
6.39k
      *test = NODE_TEST_ALL;
9836
6.39k
      return(NULL);
9837
6.39k
  }
9838
9839
63.4k
  name = xmlXPathParseNCName(ctxt);
9840
63.4k
  if (name == NULL) {
9841
15.6k
      XP_ERRORNULL(XPATH_EXPR_ERROR);
9842
0
  }
9843
63.4k
    }
9844
847k
    return(name);
9845
869k
}
9846
9847
/**
9848
 * xmlXPathIsAxisName:
9849
 * @name:  a preparsed name token
9850
 *
9851
 * [6] AxisName ::=   'ancestor'
9852
 *                  | 'ancestor-or-self'
9853
 *                  | 'attribute'
9854
 *                  | 'child'
9855
 *                  | 'descendant'
9856
 *                  | 'descendant-or-self'
9857
 *                  | 'following'
9858
 *                  | 'following-sibling'
9859
 *                  | 'namespace'
9860
 *                  | 'parent'
9861
 *                  | 'preceding'
9862
 *                  | 'preceding-sibling'
9863
 *                  | 'self'
9864
 *
9865
 * Returns the axis or 0
9866
 */
9867
static xmlXPathAxisVal
9868
1.03M
xmlXPathIsAxisName(const xmlChar *name) {
9869
1.03M
    xmlXPathAxisVal ret = (xmlXPathAxisVal) 0;
9870
1.03M
    switch (name[0]) {
9871
64.5k
  case 'a':
9872
64.5k
      if (xmlStrEqual(name, BAD_CAST "ancestor"))
9873
1.87k
    ret = AXIS_ANCESTOR;
9874
64.5k
      if (xmlStrEqual(name, BAD_CAST "ancestor-or-self"))
9875
1.52k
    ret = AXIS_ANCESTOR_OR_SELF;
9876
64.5k
      if (xmlStrEqual(name, BAD_CAST "attribute"))
9877
1.56k
    ret = AXIS_ATTRIBUTE;
9878
64.5k
      break;
9879
101k
  case 'c':
9880
101k
      if (xmlStrEqual(name, BAD_CAST "child"))
9881
304
    ret = AXIS_CHILD;
9882
101k
      break;
9883
52.7k
  case 'd':
9884
52.7k
      if (xmlStrEqual(name, BAD_CAST "descendant"))
9885
1.02k
    ret = AXIS_DESCENDANT;
9886
52.7k
      if (xmlStrEqual(name, BAD_CAST "descendant-or-self"))
9887
854
    ret = AXIS_DESCENDANT_OR_SELF;
9888
52.7k
      break;
9889
8.97k
  case 'f':
9890
8.97k
      if (xmlStrEqual(name, BAD_CAST "following"))
9891
685
    ret = AXIS_FOLLOWING;
9892
8.97k
      if (xmlStrEqual(name, BAD_CAST "following-sibling"))
9893
92
    ret = AXIS_FOLLOWING_SIBLING;
9894
8.97k
      break;
9895
239k
  case 'n':
9896
239k
      if (xmlStrEqual(name, BAD_CAST "namespace"))
9897
48.7k
    ret = AXIS_NAMESPACE;
9898
239k
      break;
9899
44.4k
  case 'p':
9900
44.4k
      if (xmlStrEqual(name, BAD_CAST "parent"))
9901
388
    ret = AXIS_PARENT;
9902
44.4k
      if (xmlStrEqual(name, BAD_CAST "preceding"))
9903
973
    ret = AXIS_PRECEDING;
9904
44.4k
      if (xmlStrEqual(name, BAD_CAST "preceding-sibling"))
9905
921
    ret = AXIS_PRECEDING_SIBLING;
9906
44.4k
      break;
9907
26.4k
  case 's':
9908
26.4k
      if (xmlStrEqual(name, BAD_CAST "self"))
9909
902
    ret = AXIS_SELF;
9910
26.4k
      break;
9911
1.03M
    }
9912
1.03M
    return(ret);
9913
1.03M
}
9914
9915
/**
9916
 * xmlXPathCompStep:
9917
 * @ctxt:  the XPath Parser context
9918
 *
9919
 * [4] Step ::=   AxisSpecifier NodeTest Predicate*
9920
 *                  | AbbreviatedStep
9921
 *
9922
 * [12] AbbreviatedStep ::=   '.' | '..'
9923
 *
9924
 * [5] AxisSpecifier ::= AxisName '::'
9925
 *                  | AbbreviatedAxisSpecifier
9926
 *
9927
 * [13] AbbreviatedAxisSpecifier ::= '@'?
9928
 *
9929
 * Modified for XPtr range support as:
9930
 *
9931
 *  [4xptr] Step ::= AxisSpecifier NodeTest Predicate*
9932
 *                     | AbbreviatedStep
9933
 *                     | 'range-to' '(' Expr ')' Predicate*
9934
 *
9935
 * Compile one step in a Location Path
9936
 * A location step of . is short for self::node(). This is
9937
 * particularly useful in conjunction with //. For example, the
9938
 * location path .//para is short for
9939
 * self::node()/descendant-or-self::node()/child::para
9940
 * and so will select all para descendant elements of the context
9941
 * node.
9942
 * Similarly, a location step of .. is short for parent::node().
9943
 * For example, ../title is short for parent::node()/child::title
9944
 * and so will select the title children of the parent of the context
9945
 * node.
9946
 */
9947
static void
9948
2.65M
xmlXPathCompStep(xmlXPathParserContextPtr ctxt) {
9949
2.65M
    SKIP_BLANKS;
9950
2.65M
    if ((CUR == '.') && (NXT(1) == '.')) {
9951
47.4k
  SKIP(2);
9952
47.4k
  SKIP_BLANKS;
9953
47.4k
  PUSH_LONG_EXPR(XPATH_OP_COLLECT, AXIS_PARENT,
9954
47.4k
        NODE_TEST_TYPE, NODE_TYPE_NODE, NULL, NULL);
9955
2.60M
    } else if (CUR == '.') {
9956
356k
  NEXT;
9957
356k
  SKIP_BLANKS;
9958
2.25M
    } else {
9959
2.25M
  xmlChar *name = NULL;
9960
2.25M
  xmlChar *prefix = NULL;
9961
2.25M
  xmlXPathTestVal test = (xmlXPathTestVal) 0;
9962
2.25M
  xmlXPathAxisVal axis = (xmlXPathAxisVal) 0;
9963
2.25M
  xmlXPathTypeVal type = (xmlXPathTypeVal) 0;
9964
2.25M
  int op1;
9965
9966
2.25M
  if (CUR == '*') {
9967
1.12M
      axis = AXIS_CHILD;
9968
1.12M
  } else {
9969
1.12M
      if (name == NULL)
9970
1.12M
    name = xmlXPathParseNCName(ctxt);
9971
1.12M
      if (name != NULL) {
9972
1.03M
    axis = xmlXPathIsAxisName(name);
9973
1.03M
    if (axis != 0) {
9974
59.8k
        SKIP_BLANKS;
9975
59.8k
        if ((CUR == ':') && (NXT(1) == ':')) {
9976
51.0k
      SKIP(2);
9977
51.0k
      xmlFree(name);
9978
51.0k
      name = NULL;
9979
51.0k
        } else {
9980
      /* an element name can conflict with an axis one :-\ */
9981
8.84k
      axis = AXIS_CHILD;
9982
8.84k
        }
9983
973k
    } else {
9984
973k
        axis = AXIS_CHILD;
9985
973k
    }
9986
1.03M
      } else if (CUR == '@') {
9987
73.8k
    NEXT;
9988
73.8k
    axis = AXIS_ATTRIBUTE;
9989
73.8k
      } else {
9990
19.5k
    axis = AXIS_CHILD;
9991
19.5k
      }
9992
1.12M
  }
9993
9994
2.25M
        if (ctxt->error != XPATH_EXPRESSION_OK) {
9995
3.23k
            xmlFree(name);
9996
3.23k
            return;
9997
3.23k
        }
9998
9999
2.24M
  name = xmlXPathCompNodeTest(ctxt, &test, &type, &prefix, name);
10000
2.24M
  if (test == 0)
10001
25.1k
      return;
10002
10003
2.22M
        if ((prefix != NULL) && (ctxt->context != NULL) &&
10004
69.8k
      (ctxt->context->flags & XML_XPATH_CHECKNS)) {
10005
0
      if (xmlXPathNsLookup(ctxt->context, prefix) == NULL) {
10006
0
    xmlXPathErr(ctxt, XPATH_UNDEF_PREFIX_ERROR);
10007
0
      }
10008
0
  }
10009
10010
2.22M
  op1 = ctxt->comp->last;
10011
2.22M
  ctxt->comp->last = -1;
10012
10013
2.22M
  SKIP_BLANKS;
10014
2.32M
  while (CUR == '[') {
10015
101k
      xmlXPathCompPredicate(ctxt, 0);
10016
101k
  }
10017
10018
2.22M
        if (PUSH_FULL_EXPR(XPATH_OP_COLLECT, op1, ctxt->comp->last, axis,
10019
2.22M
                           test, type, (void *)prefix, (void *)name) == -1) {
10020
107
            xmlFree(prefix);
10021
107
            xmlFree(name);
10022
107
        }
10023
2.22M
    }
10024
2.65M
}
10025
10026
/**
10027
 * xmlXPathCompRelativeLocationPath:
10028
 * @ctxt:  the XPath Parser context
10029
 *
10030
 *  [3]   RelativeLocationPath ::=   Step
10031
 *                     | RelativeLocationPath '/' Step
10032
 *                     | AbbreviatedRelativeLocationPath
10033
 *  [11]  AbbreviatedRelativeLocationPath ::=   RelativeLocationPath '//' Step
10034
 *
10035
 * Compile a relative location path.
10036
 */
10037
static void
10038
xmlXPathCompRelativeLocationPath
10039
2.43M
(xmlXPathParserContextPtr ctxt) {
10040
2.43M
    SKIP_BLANKS;
10041
2.43M
    if ((CUR == '/') && (NXT(1) == '/')) {
10042
3.27k
  SKIP(2);
10043
3.27k
  SKIP_BLANKS;
10044
3.27k
  PUSH_LONG_EXPR(XPATH_OP_COLLECT, AXIS_DESCENDANT_OR_SELF,
10045
3.27k
             NODE_TEST_TYPE, NODE_TYPE_NODE, NULL, NULL);
10046
2.42M
    } else if (CUR == '/') {
10047
57.9k
      NEXT;
10048
57.9k
  SKIP_BLANKS;
10049
57.9k
    }
10050
2.43M
    xmlXPathCompStep(ctxt);
10051
2.43M
    CHECK_ERROR;
10052
2.38M
    SKIP_BLANKS;
10053
2.60M
    while (CUR == '/') {
10054
223k
  if ((CUR == '/') && (NXT(1) == '/')) {
10055
17.6k
      SKIP(2);
10056
17.6k
      SKIP_BLANKS;
10057
17.6k
      PUSH_LONG_EXPR(XPATH_OP_COLLECT, AXIS_DESCENDANT_OR_SELF,
10058
17.6k
           NODE_TEST_TYPE, NODE_TYPE_NODE, NULL, NULL);
10059
17.6k
      xmlXPathCompStep(ctxt);
10060
206k
  } else if (CUR == '/') {
10061
206k
      NEXT;
10062
206k
      SKIP_BLANKS;
10063
206k
      xmlXPathCompStep(ctxt);
10064
206k
  }
10065
223k
  SKIP_BLANKS;
10066
223k
    }
10067
2.38M
}
10068
10069
/**
10070
 * xmlXPathCompLocationPath:
10071
 * @ctxt:  the XPath Parser context
10072
 *
10073
 *  [1]   LocationPath ::=   RelativeLocationPath
10074
 *                     | AbsoluteLocationPath
10075
 *  [2]   AbsoluteLocationPath ::=   '/' RelativeLocationPath?
10076
 *                     | AbbreviatedAbsoluteLocationPath
10077
 *  [10]   AbbreviatedAbsoluteLocationPath ::=
10078
 *                           '//' RelativeLocationPath
10079
 *
10080
 * Compile a location path
10081
 *
10082
 * // is short for /descendant-or-self::node()/. For example,
10083
 * //para is short for /descendant-or-self::node()/child::para and
10084
 * so will select any para element in the document (even a para element
10085
 * that is a document element will be selected by //para since the
10086
 * document element node is a child of the root node); div//para is
10087
 * short for div/descendant-or-self::node()/child::para and so will
10088
 * select all para descendants of div children.
10089
 */
10090
static void
10091
2.44M
xmlXPathCompLocationPath(xmlXPathParserContextPtr ctxt) {
10092
2.44M
    SKIP_BLANKS;
10093
2.44M
    if (CUR != '/') {
10094
2.05M
        xmlXPathCompRelativeLocationPath(ctxt);
10095
2.05M
    } else {
10096
770k
  while (CUR == '/') {
10097
391k
      if ((CUR == '/') && (NXT(1) == '/')) {
10098
182k
    SKIP(2);
10099
182k
    SKIP_BLANKS;
10100
182k
    PUSH_LONG_EXPR(XPATH_OP_COLLECT, AXIS_DESCENDANT_OR_SELF,
10101
182k
           NODE_TEST_TYPE, NODE_TYPE_NODE, NULL, NULL);
10102
182k
    xmlXPathCompRelativeLocationPath(ctxt);
10103
208k
      } else if (CUR == '/') {
10104
208k
    NEXT;
10105
208k
    SKIP_BLANKS;
10106
208k
    if ((CUR != 0) &&
10107
205k
        ((IS_ASCII_LETTER(CUR)) || (CUR >= 0x80) ||
10108
123k
                     (CUR == '_') || (CUR == '.') ||
10109
89.0k
         (CUR == '@') || (CUR == '*')))
10110
133k
        xmlXPathCompRelativeLocationPath(ctxt);
10111
208k
      }
10112
391k
      CHECK_ERROR;
10113
391k
  }
10114
389k
    }
10115
2.44M
}
10116
10117
/************************************************************************
10118
 *                  *
10119
 *    XPath precompiled expression evaluation     *
10120
 *                  *
10121
 ************************************************************************/
10122
10123
static int
10124
xmlXPathCompOpEval(xmlXPathParserContextPtr ctxt, xmlXPathStepOpPtr op);
10125
10126
/**
10127
 * xmlXPathNodeSetFilter:
10128
 * @ctxt:  the XPath Parser context
10129
 * @set: the node set to filter
10130
 * @filterOpIndex: the index of the predicate/filter op
10131
 * @minPos: minimum position in the filtered set (1-based)
10132
 * @maxPos: maximum position in the filtered set (1-based)
10133
 * @hasNsNodes: true if the node set may contain namespace nodes
10134
 *
10135
 * Filter a node set, keeping only nodes for which the predicate expression
10136
 * matches. Afterwards, keep only nodes between minPos and maxPos in the
10137
 * filtered result.
10138
 */
10139
static void
10140
xmlXPathNodeSetFilter(xmlXPathParserContextPtr ctxt,
10141
          xmlNodeSetPtr set,
10142
          int filterOpIndex,
10143
                      int minPos, int maxPos,
10144
          int hasNsNodes)
10145
391k
{
10146
391k
    xmlXPathContextPtr xpctxt;
10147
391k
    xmlNodePtr oldnode;
10148
391k
    xmlDocPtr olddoc;
10149
391k
    xmlXPathStepOpPtr filterOp;
10150
391k
    int oldcs, oldpp;
10151
391k
    int i, j, pos;
10152
10153
391k
    if ((set == NULL) || (set->nodeNr == 0))
10154
166k
        return;
10155
10156
    /*
10157
    * Check if the node set contains a sufficient number of nodes for
10158
    * the requested range.
10159
    */
10160
224k
    if (set->nodeNr < minPos) {
10161
3.17k
        xmlXPathNodeSetClear(set, hasNsNodes);
10162
3.17k
        return;
10163
3.17k
    }
10164
10165
221k
    xpctxt = ctxt->context;
10166
221k
    oldnode = xpctxt->node;
10167
221k
    olddoc = xpctxt->doc;
10168
221k
    oldcs = xpctxt->contextSize;
10169
221k
    oldpp = xpctxt->proximityPosition;
10170
221k
    filterOp = &ctxt->comp->steps[filterOpIndex];
10171
10172
221k
    xpctxt->contextSize = set->nodeNr;
10173
10174
732k
    for (i = 0, j = 0, pos = 1; i < set->nodeNr; i++) {
10175
653k
        xmlNodePtr node = set->nodeTab[i];
10176
653k
        int res;
10177
10178
653k
        xpctxt->node = node;
10179
653k
        xpctxt->proximityPosition = i + 1;
10180
10181
        /*
10182
        * Also set the xpath document in case things like
10183
        * key() are evaluated in the predicate.
10184
        *
10185
        * TODO: Get real doc for namespace nodes.
10186
        */
10187
653k
        if ((node->type != XML_NAMESPACE_DECL) &&
10188
536k
            (node->doc != NULL))
10189
536k
            xpctxt->doc = node->doc;
10190
10191
653k
        res = xmlXPathCompOpEvalToBoolean(ctxt, filterOp, 1);
10192
10193
653k
        if (ctxt->error != XPATH_EXPRESSION_OK)
10194
33.0k
            break;
10195
620k
        if (res < 0) {
10196
            /* Shouldn't happen */
10197
0
            xmlXPathErr(ctxt, XPATH_EXPR_ERROR);
10198
0
            break;
10199
0
        }
10200
10201
620k
        if ((res != 0) && ((pos >= minPos) && (pos <= maxPos))) {
10202
392k
            if (i != j) {
10203
64.2k
                set->nodeTab[j] = node;
10204
64.2k
                set->nodeTab[i] = NULL;
10205
64.2k
            }
10206
10207
392k
            j += 1;
10208
392k
        } else {
10209
            /* Remove the entry from the initial node set. */
10210
228k
            set->nodeTab[i] = NULL;
10211
228k
            if (node->type == XML_NAMESPACE_DECL)
10212
69.8k
                xmlXPathNodeSetFreeNs((xmlNsPtr) node);
10213
228k
        }
10214
10215
620k
        if (res != 0) {
10216
397k
            if (pos == maxPos) {
10217
109k
                i += 1;
10218
109k
                break;
10219
109k
            }
10220
10221
287k
            pos += 1;
10222
287k
        }
10223
620k
    }
10224
10225
    /* Free remaining nodes. */
10226
221k
    if (hasNsNodes) {
10227
371k
        for (; i < set->nodeNr; i++) {
10228
283k
            xmlNodePtr node = set->nodeTab[i];
10229
283k
            if ((node != NULL) && (node->type == XML_NAMESPACE_DECL))
10230
99.8k
                xmlXPathNodeSetFreeNs((xmlNsPtr) node);
10231
283k
        }
10232
87.6k
    }
10233
10234
221k
    set->nodeNr = j;
10235
10236
    /* If too many elements were removed, shrink table to preserve memory. */
10237
221k
    if ((set->nodeMax > XML_NODESET_DEFAULT) &&
10238
24.7k
        (set->nodeNr < set->nodeMax / 2)) {
10239
17.5k
        xmlNodePtr *tmp;
10240
17.5k
        int nodeMax = set->nodeNr;
10241
10242
17.5k
        if (nodeMax < XML_NODESET_DEFAULT)
10243
16.9k
            nodeMax = XML_NODESET_DEFAULT;
10244
17.5k
        tmp = (xmlNodePtr *) xmlRealloc(set->nodeTab,
10245
17.5k
                nodeMax * sizeof(xmlNodePtr));
10246
17.5k
        if (tmp == NULL) {
10247
901
            xmlXPathPErrMemory(ctxt);
10248
16.6k
        } else {
10249
16.6k
            set->nodeTab = tmp;
10250
16.6k
            set->nodeMax = nodeMax;
10251
16.6k
        }
10252
17.5k
    }
10253
10254
221k
    xpctxt->node = oldnode;
10255
221k
    xpctxt->doc = olddoc;
10256
221k
    xpctxt->contextSize = oldcs;
10257
221k
    xpctxt->proximityPosition = oldpp;
10258
221k
}
10259
10260
/**
10261
 * xmlXPathCompOpEvalPredicate:
10262
 * @ctxt:  the XPath Parser context
10263
 * @op: the predicate op
10264
 * @set: the node set to filter
10265
 * @minPos: minimum position in the filtered set (1-based)
10266
 * @maxPos: maximum position in the filtered set (1-based)
10267
 * @hasNsNodes: true if the node set may contain namespace nodes
10268
 *
10269
 * Filter a node set, keeping only nodes for which the sequence of predicate
10270
 * expressions matches. Afterwards, keep only nodes between minPos and maxPos
10271
 * in the filtered result.
10272
 */
10273
static void
10274
xmlXPathCompOpEvalPredicate(xmlXPathParserContextPtr ctxt,
10275
          xmlXPathStepOpPtr op,
10276
          xmlNodeSetPtr set,
10277
                            int minPos, int maxPos,
10278
          int hasNsNodes)
10279
163k
{
10280
163k
    if (op->ch1 != -1) {
10281
11.6k
  xmlXPathCompExprPtr comp = ctxt->comp;
10282
  /*
10283
  * Process inner predicates first.
10284
  */
10285
11.6k
  if (comp->steps[op->ch1].op != XPATH_OP_PREDICATE) {
10286
0
            XP_ERROR(XPATH_INVALID_OPERAND);
10287
0
  }
10288
11.6k
        if (ctxt->context->depth >= XPATH_MAX_RECURSION_DEPTH)
10289
11.6k
            XP_ERROR(XPATH_RECURSION_LIMIT_EXCEEDED);
10290
11.6k
        ctxt->context->depth += 1;
10291
11.6k
  xmlXPathCompOpEvalPredicate(ctxt, &comp->steps[op->ch1], set,
10292
11.6k
                                    1, set->nodeNr, hasNsNodes);
10293
11.6k
        ctxt->context->depth -= 1;
10294
11.6k
  CHECK_ERROR;
10295
11.6k
    }
10296
10297
162k
    if (op->ch2 != -1)
10298
162k
        xmlXPathNodeSetFilter(ctxt, set, op->ch2, minPos, maxPos, hasNsNodes);
10299
162k
}
10300
10301
static int
10302
xmlXPathIsPositionalPredicate(xmlXPathParserContextPtr ctxt,
10303
          xmlXPathStepOpPtr op,
10304
          int *maxPos)
10305
129k
{
10306
10307
129k
    xmlXPathStepOpPtr exprOp;
10308
10309
    /*
10310
    * BIG NOTE: This is not intended for XPATH_OP_FILTER yet!
10311
    */
10312
10313
    /*
10314
    * If not -1, then ch1 will point to:
10315
    * 1) For predicates (XPATH_OP_PREDICATE):
10316
    *    - an inner predicate operator
10317
    * 2) For filters (XPATH_OP_FILTER):
10318
    *    - an inner filter operator OR
10319
    *    - an expression selecting the node set.
10320
    *      E.g. "key('a', 'b')" or "(//foo | //bar)".
10321
    */
10322
129k
    if ((op->op != XPATH_OP_PREDICATE) && (op->op != XPATH_OP_FILTER))
10323
0
  return(0);
10324
10325
129k
    if (op->ch2 != -1) {
10326
129k
  exprOp = &ctxt->comp->steps[op->ch2];
10327
129k
    } else
10328
0
  return(0);
10329
10330
129k
    if ((exprOp != NULL) &&
10331
129k
  (exprOp->op == XPATH_OP_VALUE) &&
10332
42.8k
  (exprOp->value4 != NULL) &&
10333
42.8k
  (((xmlXPathObjectPtr) exprOp->value4)->type == XPATH_NUMBER))
10334
29.7k
    {
10335
29.7k
        double floatval = ((xmlXPathObjectPtr) exprOp->value4)->floatval;
10336
10337
  /*
10338
  * We have a "[n]" predicate here.
10339
  * TODO: Unfortunately this simplistic test here is not
10340
  * able to detect a position() predicate in compound
10341
  * expressions like "[@attr = 'a" and position() = 1],
10342
  * and even not the usage of position() in
10343
  * "[position() = 1]"; thus - obviously - a position-range,
10344
  * like it "[position() < 5]", is also not detected.
10345
  * Maybe we could rewrite the AST to ease the optimization.
10346
  */
10347
10348
29.7k
        if ((floatval > INT_MIN) && (floatval < INT_MAX)) {
10349
26.6k
      *maxPos = (int) floatval;
10350
26.6k
            if (floatval == (double) *maxPos)
10351
26.1k
                return(1);
10352
26.6k
        }
10353
29.7k
    }
10354
103k
    return(0);
10355
129k
}
10356
10357
static int
10358
xmlXPathNodeCollectAndTest(xmlXPathParserContextPtr ctxt,
10359
                           xmlXPathStepOpPtr op,
10360
         xmlNodePtr * first, xmlNodePtr * last,
10361
         int toBool)
10362
5.25M
{
10363
10364
5.25M
#define XP_TEST_HIT \
10365
15.3M
    if (hasAxisRange != 0) { \
10366
54.9k
  if (++pos == maxPos) { \
10367
37.3k
      if (addNode(seq, cur) < 0) \
10368
37.3k
          xmlXPathPErrMemory(ctxt); \
10369
37.3k
      goto axis_range_end; } \
10370
15.3M
    } else { \
10371
15.3M
  if (addNode(seq, cur) < 0) \
10372
15.3M
      xmlXPathPErrMemory(ctxt); \
10373
15.3M
  if (breakOnFirstHit) goto first_hit; }
10374
10375
5.25M
#define XP_TEST_HIT_NS \
10376
5.25M
    if (hasAxisRange != 0) { \
10377
13.6k
  if (++pos == maxPos) { \
10378
6.57k
      hasNsNodes = 1; \
10379
6.57k
      if (xmlXPathNodeSetAddNs(seq, xpctxt->node, (xmlNsPtr) cur) < 0) \
10380
6.57k
          xmlXPathPErrMemory(ctxt); \
10381
6.57k
  goto axis_range_end; } \
10382
993k
    } else { \
10383
993k
  hasNsNodes = 1; \
10384
993k
  if (xmlXPathNodeSetAddNs(seq, xpctxt->node, (xmlNsPtr) cur) < 0) \
10385
993k
      xmlXPathPErrMemory(ctxt); \
10386
993k
  if (breakOnFirstHit) goto first_hit; }
10387
10388
5.25M
    xmlXPathAxisVal axis = (xmlXPathAxisVal) op->value;
10389
5.25M
    xmlXPathTestVal test = (xmlXPathTestVal) op->value2;
10390
5.25M
    xmlXPathTypeVal type = (xmlXPathTypeVal) op->value3;
10391
5.25M
    const xmlChar *prefix = op->value4;
10392
5.25M
    const xmlChar *name = op->value5;
10393
5.25M
    const xmlChar *URI = NULL;
10394
10395
5.25M
    int total = 0, hasNsNodes = 0;
10396
    /* The popped object holding the context nodes */
10397
5.25M
    xmlXPathObjectPtr obj;
10398
    /* The set of context nodes for the node tests */
10399
5.25M
    xmlNodeSetPtr contextSeq;
10400
5.25M
    int contextIdx;
10401
5.25M
    xmlNodePtr contextNode;
10402
    /* The final resulting node set wrt to all context nodes */
10403
5.25M
    xmlNodeSetPtr outSeq;
10404
    /*
10405
    * The temporary resulting node set wrt 1 context node.
10406
    * Used to feed predicate evaluation.
10407
    */
10408
5.25M
    xmlNodeSetPtr seq;
10409
5.25M
    xmlNodePtr cur;
10410
    /* First predicate operator */
10411
5.25M
    xmlXPathStepOpPtr predOp;
10412
5.25M
    int maxPos; /* The requested position() (when a "[n]" predicate) */
10413
5.25M
    int hasPredicateRange, hasAxisRange, pos;
10414
5.25M
    int breakOnFirstHit;
10415
10416
5.25M
    xmlXPathTraversalFunction next = NULL;
10417
5.25M
    int (*addNode) (xmlNodeSetPtr, xmlNodePtr);
10418
5.25M
    xmlXPathNodeSetMergeFunction mergeAndClear;
10419
5.25M
    xmlNodePtr oldContextNode;
10420
5.25M
    xmlXPathContextPtr xpctxt = ctxt->context;
10421
10422
10423
5.25M
    CHECK_TYPE0(XPATH_NODESET);
10424
5.24M
    obj = xmlXPathValuePop(ctxt);
10425
    /*
10426
    * Setup namespaces.
10427
    */
10428
5.24M
    if (prefix != NULL) {
10429
345k
        URI = xmlXPathNsLookup(xpctxt, prefix);
10430
345k
        if (URI == NULL) {
10431
78.9k
      xmlXPathReleaseObject(xpctxt, obj);
10432
78.9k
            XP_ERROR0(XPATH_UNDEF_PREFIX_ERROR);
10433
0
  }
10434
345k
    }
10435
    /*
10436
    * Setup axis.
10437
    *
10438
    * MAYBE FUTURE TODO: merging optimizations:
10439
    * - If the nodes to be traversed wrt to the initial nodes and
10440
    *   the current axis cannot overlap, then we could avoid searching
10441
    *   for duplicates during the merge.
10442
    *   But the question is how/when to evaluate if they cannot overlap.
10443
    *   Example: if we know that for two initial nodes, the one is
10444
    *   not in the ancestor-or-self axis of the other, then we could safely
10445
    *   avoid a duplicate-aware merge, if the axis to be traversed is e.g.
10446
    *   the descendant-or-self axis.
10447
    */
10448
5.16M
    mergeAndClear = xmlXPathNodeSetMergeAndClear;
10449
5.16M
    switch (axis) {
10450
40.2k
        case AXIS_ANCESTOR:
10451
40.2k
            first = NULL;
10452
40.2k
            next = xmlXPathNextAncestor;
10453
40.2k
            break;
10454
11.3k
        case AXIS_ANCESTOR_OR_SELF:
10455
11.3k
            first = NULL;
10456
11.3k
            next = xmlXPathNextAncestorOrSelf;
10457
11.3k
            break;
10458
299k
        case AXIS_ATTRIBUTE:
10459
299k
            first = NULL;
10460
299k
      last = NULL;
10461
299k
            next = xmlXPathNextAttribute;
10462
299k
      mergeAndClear = xmlXPathNodeSetMergeAndClearNoDupls;
10463
299k
            break;
10464
3.74M
        case AXIS_CHILD:
10465
3.74M
      last = NULL;
10466
3.74M
      if (((test == NODE_TEST_NAME) || (test == NODE_TEST_ALL)) &&
10467
3.31M
    (type == NODE_TYPE_NODE))
10468
3.31M
      {
10469
    /*
10470
    * Optimization if an element node type is 'element'.
10471
    */
10472
3.31M
    next = xmlXPathNextChildElement;
10473
3.31M
      } else
10474
436k
    next = xmlXPathNextChild;
10475
3.74M
      mergeAndClear = xmlXPathNodeSetMergeAndClearNoDupls;
10476
3.74M
            break;
10477
519k
        case AXIS_DESCENDANT:
10478
519k
      last = NULL;
10479
519k
            next = xmlXPathNextDescendant;
10480
519k
            break;
10481
244k
        case AXIS_DESCENDANT_OR_SELF:
10482
244k
      last = NULL;
10483
244k
            next = xmlXPathNextDescendantOrSelf;
10484
244k
            break;
10485
2.81k
        case AXIS_FOLLOWING:
10486
2.81k
      last = NULL;
10487
2.81k
            next = xmlXPathNextFollowing;
10488
2.81k
            break;
10489
598
        case AXIS_FOLLOWING_SIBLING:
10490
598
      last = NULL;
10491
598
            next = xmlXPathNextFollowingSibling;
10492
598
            break;
10493
154k
        case AXIS_NAMESPACE:
10494
154k
            first = NULL;
10495
154k
      last = NULL;
10496
154k
            next = (xmlXPathTraversalFunction) xmlXPathNextNamespace;
10497
154k
      mergeAndClear = xmlXPathNodeSetMergeAndClearNoDupls;
10498
154k
            break;
10499
130k
        case AXIS_PARENT:
10500
130k
            first = NULL;
10501
130k
            next = xmlXPathNextParent;
10502
130k
            break;
10503
5.57k
        case AXIS_PRECEDING:
10504
5.57k
            first = NULL;
10505
5.57k
            next = xmlXPathNextPrecedingInternal;
10506
5.57k
            break;
10507
10.5k
        case AXIS_PRECEDING_SIBLING:
10508
10.5k
            first = NULL;
10509
10.5k
            next = xmlXPathNextPrecedingSibling;
10510
10.5k
            break;
10511
442
        case AXIS_SELF:
10512
442
            first = NULL;
10513
442
      last = NULL;
10514
442
            next = xmlXPathNextSelf;
10515
442
      mergeAndClear = xmlXPathNodeSetMergeAndClearNoDupls;
10516
442
            break;
10517
5.16M
    }
10518
10519
5.16M
    if (next == NULL) {
10520
0
  xmlXPathReleaseObject(xpctxt, obj);
10521
0
        return(0);
10522
0
    }
10523
5.16M
    contextSeq = obj->nodesetval;
10524
5.16M
    if ((contextSeq == NULL) || (contextSeq->nodeNr <= 0)) {
10525
529k
        xmlXPathValuePush(ctxt, obj);
10526
529k
        return(0);
10527
529k
    }
10528
    /*
10529
    * Predicate optimization ---------------------------------------------
10530
    * If this step has a last predicate, which contains a position(),
10531
    * then we'll optimize (although not exactly "position()", but only
10532
    * the  short-hand form, i.e., "[n]".
10533
    *
10534
    * Example - expression "/foo[parent::bar][1]":
10535
    *
10536
    * COLLECT 'child' 'name' 'node' foo    -- op (we are here)
10537
    *   ROOT                               -- op->ch1
10538
    *   PREDICATE                          -- op->ch2 (predOp)
10539
    *     PREDICATE                          -- predOp->ch1 = [parent::bar]
10540
    *       SORT
10541
    *         COLLECT  'parent' 'name' 'node' bar
10542
    *           NODE
10543
    *     ELEM Object is a number : 1        -- predOp->ch2 = [1]
10544
    *
10545
    */
10546
4.63M
    maxPos = 0;
10547
4.63M
    predOp = NULL;
10548
4.63M
    hasPredicateRange = 0;
10549
4.63M
    hasAxisRange = 0;
10550
4.63M
    if (op->ch2 != -1) {
10551
  /*
10552
  * There's at least one predicate. 16 == XPATH_OP_PREDICATE
10553
  */
10554
129k
  predOp = &ctxt->comp->steps[op->ch2];
10555
129k
  if (xmlXPathIsPositionalPredicate(ctxt, predOp, &maxPos)) {
10556
26.1k
      if (predOp->ch1 != -1) {
10557
    /*
10558
    * Use the next inner predicate operator.
10559
    */
10560
6.93k
    predOp = &ctxt->comp->steps[predOp->ch1];
10561
6.93k
    hasPredicateRange = 1;
10562
19.1k
      } else {
10563
    /*
10564
    * There's no other predicate than the [n] predicate.
10565
    */
10566
19.1k
    predOp = NULL;
10567
19.1k
    hasAxisRange = 1;
10568
19.1k
      }
10569
26.1k
  }
10570
129k
    }
10571
4.63M
    breakOnFirstHit = ((toBool) && (predOp == NULL)) ? 1 : 0;
10572
    /*
10573
    * Axis traversal -----------------------------------------------------
10574
    */
10575
    /*
10576
     * 2.3 Node Tests
10577
     *  - For the attribute axis, the principal node type is attribute.
10578
     *  - For the namespace axis, the principal node type is namespace.
10579
     *  - For other axes, the principal node type is element.
10580
     *
10581
     * A node test * is true for any node of the
10582
     * principal node type. For example, child::* will
10583
     * select all element children of the context node
10584
     */
10585
4.63M
    oldContextNode = xpctxt->node;
10586
4.63M
    addNode = xmlXPathNodeSetAddUnique;
10587
4.63M
    outSeq = NULL;
10588
4.63M
    seq = NULL;
10589
4.63M
    contextNode = NULL;
10590
4.63M
    contextIdx = 0;
10591
10592
10593
11.0M
    while (((contextIdx < contextSeq->nodeNr) || (contextNode != NULL)) &&
10594
6.46M
           (ctxt->error == XPATH_EXPRESSION_OK)) {
10595
6.46M
  xpctxt->node = contextSeq->nodeTab[contextIdx++];
10596
10597
6.46M
  if (seq == NULL) {
10598
4.69M
      seq = xmlXPathNodeSetCreate(NULL);
10599
4.69M
      if (seq == NULL) {
10600
1.64k
                xmlXPathPErrMemory(ctxt);
10601
1.64k
    total = 0;
10602
1.64k
    goto error;
10603
1.64k
      }
10604
4.69M
  }
10605
  /*
10606
  * Traverse the axis and test the nodes.
10607
  */
10608
6.46M
  pos = 0;
10609
6.46M
  cur = NULL;
10610
6.46M
  hasNsNodes = 0;
10611
27.4M
        do {
10612
27.4M
            if (OP_LIMIT_EXCEEDED(ctxt, 1))
10613
1.90k
                goto error;
10614
10615
27.4M
            cur = next(ctxt, cur);
10616
27.4M
            if (cur == NULL)
10617
6.38M
                break;
10618
10619
      /*
10620
      * QUESTION TODO: What does the "first" and "last" stuff do?
10621
      */
10622
21.0M
            if ((first != NULL) && (*first != NULL)) {
10623
3.77k
    if (*first == cur)
10624
767
        break;
10625
3.00k
    if (((total % 256) == 0) &&
10626
2.42k
#ifdef XP_OPTIMIZED_NON_ELEM_COMPARISON
10627
2.42k
        (xmlXPathCmpNodesExt(*first, cur) >= 0))
10628
#else
10629
        (xmlXPathCmpNodes(*first, cur) >= 0))
10630
#endif
10631
1.88k
    {
10632
1.88k
        break;
10633
1.88k
    }
10634
3.00k
      }
10635
21.0M
      if ((last != NULL) && (*last != NULL)) {
10636
15.9k
    if (*last == cur)
10637
710
        break;
10638
15.2k
    if (((total % 256) == 0) &&
10639
2.19k
#ifdef XP_OPTIMIZED_NON_ELEM_COMPARISON
10640
2.19k
        (xmlXPathCmpNodesExt(cur, *last) >= 0))
10641
#else
10642
        (xmlXPathCmpNodes(cur, *last) >= 0))
10643
#endif
10644
950
    {
10645
950
        break;
10646
950
    }
10647
15.2k
      }
10648
10649
21.0M
            total++;
10650
10651
21.0M
      switch (test) {
10652
0
                case NODE_TEST_NONE:
10653
0
        total = 0;
10654
0
        goto error;
10655
14.7M
                case NODE_TEST_TYPE:
10656
14.7M
        if (type == NODE_TYPE_NODE) {
10657
13.5M
      switch (cur->type) {
10658
261k
          case XML_DOCUMENT_NODE:
10659
261k
          case XML_HTML_DOCUMENT_NODE:
10660
7.49M
          case XML_ELEMENT_NODE:
10661
7.51M
          case XML_ATTRIBUTE_NODE:
10662
7.75M
          case XML_PI_NODE:
10663
8.15M
          case XML_COMMENT_NODE:
10664
8.15M
          case XML_CDATA_SECTION_NODE:
10665
13.3M
          case XML_TEXT_NODE:
10666
13.3M
        XP_TEST_HIT
10667
13.3M
        break;
10668
13.3M
          case XML_NAMESPACE_DECL: {
10669
205k
        if (axis == AXIS_NAMESPACE) {
10670
22.6k
            XP_TEST_HIT_NS
10671
182k
        } else {
10672
182k
                              hasNsNodes = 1;
10673
182k
            XP_TEST_HIT
10674
182k
        }
10675
204k
        break;
10676
205k
                            }
10677
204k
          default:
10678
2.29k
        break;
10679
13.5M
      }
10680
13.5M
        } else if (cur->type == (xmlElementType) type) {
10681
225k
      if (cur->type == XML_NAMESPACE_DECL)
10682
0
          XP_TEST_HIT_NS
10683
225k
      else
10684
225k
          XP_TEST_HIT
10685
893k
        } else if ((type == NODE_TYPE_TEXT) &&
10686
373k
       (cur->type == XML_CDATA_SECTION_NODE))
10687
0
        {
10688
0
      XP_TEST_HIT
10689
0
        }
10690
14.6M
        break;
10691
14.6M
                case NODE_TEST_PI:
10692
2.30k
                    if ((cur->type == XML_PI_NODE) &&
10693
1.04k
                        ((name == NULL) || xmlStrEqual(name, cur->name)))
10694
686
        {
10695
686
      XP_TEST_HIT
10696
686
                    }
10697
2.30k
                    break;
10698
2.72M
                case NODE_TEST_ALL:
10699
2.72M
                    if (axis == AXIS_ATTRIBUTE) {
10700
59.2k
                        if (cur->type == XML_ATTRIBUTE_NODE)
10701
59.2k
      {
10702
59.2k
                            if (prefix == NULL)
10703
55.7k
          {
10704
55.7k
        XP_TEST_HIT
10705
55.7k
                            } else if ((cur->ns != NULL) &&
10706
1.11k
        (xmlStrEqual(URI, cur->ns->href)))
10707
715
          {
10708
715
        XP_TEST_HIT
10709
715
                            }
10710
59.2k
                        }
10711
2.66M
                    } else if (axis == AXIS_NAMESPACE) {
10712
961k
                        if (cur->type == XML_NAMESPACE_DECL)
10713
961k
      {
10714
961k
          XP_TEST_HIT_NS
10715
961k
                        }
10716
1.70M
                    } else {
10717
1.70M
                        if (cur->type == XML_ELEMENT_NODE) {
10718
1.20M
                            if (prefix == NULL)
10719
1.18M
          {
10720
1.18M
        XP_TEST_HIT
10721
10722
1.18M
                            } else if ((cur->ns != NULL) &&
10723
10.8k
        (xmlStrEqual(URI, cur->ns->href)))
10724
5.28k
          {
10725
5.28k
        XP_TEST_HIT
10726
5.28k
                            }
10727
1.20M
                        }
10728
1.70M
                    }
10729
2.71M
                    break;
10730
2.71M
                case NODE_TEST_NS:{
10731
                        /* TODO */
10732
0
                        break;
10733
2.72M
                    }
10734
3.60M
                case NODE_TEST_NAME:
10735
3.60M
                    if (axis == AXIS_ATTRIBUTE) {
10736
252k
                        if (cur->type != XML_ATTRIBUTE_NODE)
10737
0
          break;
10738
3.34M
        } else if (axis == AXIS_NAMESPACE) {
10739
112k
                        if (cur->type != XML_NAMESPACE_DECL)
10740
0
          break;
10741
3.23M
        } else {
10742
3.23M
            if (cur->type != XML_ELEMENT_NODE)
10743
615k
          break;
10744
3.23M
        }
10745
2.98M
                    switch (cur->type) {
10746
2.62M
                        case XML_ELEMENT_NODE:
10747
2.62M
                            if (xmlStrEqual(name, cur->name)) {
10748
236k
                                if (prefix == NULL) {
10749
211k
                                    if (cur->ns == NULL)
10750
197k
            {
10751
197k
          XP_TEST_HIT
10752
197k
                                    }
10753
211k
                                } else {
10754
25.5k
                                    if ((cur->ns != NULL) &&
10755
3.08k
                                        (xmlStrEqual(URI, cur->ns->href)))
10756
2.53k
            {
10757
2.53k
          XP_TEST_HIT
10758
2.53k
                                    }
10759
25.5k
                                }
10760
236k
                            }
10761
2.61M
                            break;
10762
2.61M
                        case XML_ATTRIBUTE_NODE:{
10763
252k
                                xmlAttrPtr attr = (xmlAttrPtr) cur;
10764
10765
252k
                                if (xmlStrEqual(name, attr->name)) {
10766
144k
                                    if (prefix == NULL) {
10767
143k
                                        if ((attr->ns == NULL) ||
10768
45
                                            (attr->ns->prefix == NULL))
10769
143k
          {
10770
143k
              XP_TEST_HIT
10771
143k
                                        }
10772
143k
                                    } else {
10773
468
                                        if ((attr->ns != NULL) &&
10774
391
                                            (xmlStrEqual(URI,
10775
391
                attr->ns->href)))
10776
309
          {
10777
309
              XP_TEST_HIT
10778
309
                                        }
10779
468
                                    }
10780
144k
                                }
10781
250k
                                break;
10782
252k
                            }
10783
250k
                        case XML_NAMESPACE_DECL:
10784
112k
                            if (cur->type == XML_NAMESPACE_DECL) {
10785
112k
                                xmlNsPtr ns = (xmlNsPtr) cur;
10786
10787
112k
                                if ((ns->prefix != NULL) && (name != NULL)
10788
112k
                                    && (xmlStrEqual(ns->prefix, name)))
10789
22.1k
        {
10790
22.1k
            XP_TEST_HIT_NS
10791
22.1k
                                }
10792
112k
                            }
10793
92.8k
                            break;
10794
92.8k
                        default:
10795
0
                            break;
10796
2.98M
                    }
10797
2.95M
                    break;
10798
21.0M
      } /* switch(test) */
10799
21.0M
        } while ((cur != NULL) && (ctxt->error == XPATH_EXPRESSION_OK));
10800
10801
6.39M
  goto apply_predicates;
10802
10803
6.39M
axis_range_end: /* ----------------------------------------------------- */
10804
  /*
10805
  * We have a "/foo[n]", and position() = n was reached.
10806
  * Note that we can have as well "/foo/::parent::foo[1]", so
10807
  * a duplicate-aware merge is still needed.
10808
  * Merge with the result.
10809
  */
10810
43.9k
  if (outSeq == NULL) {
10811
9.74k
      outSeq = seq;
10812
9.74k
      seq = NULL;
10813
34.1k
  } else {
10814
34.1k
      outSeq = mergeAndClear(outSeq, seq);
10815
34.1k
            if (outSeq == NULL)
10816
4
                xmlXPathPErrMemory(ctxt);
10817
34.1k
        }
10818
  /*
10819
  * Break if only a true/false result was requested.
10820
  */
10821
43.9k
  if (toBool)
10822
240
      break;
10823
43.6k
  continue;
10824
10825
43.6k
first_hit: /* ---------------------------------------------------------- */
10826
  /*
10827
  * Break if only a true/false result was requested and
10828
  * no predicates existed and a node test succeeded.
10829
  */
10830
20.7k
  if (outSeq == NULL) {
10831
20.7k
      outSeq = seq;
10832
20.7k
      seq = NULL;
10833
20.7k
  } else {
10834
0
      outSeq = mergeAndClear(outSeq, seq);
10835
0
            if (outSeq == NULL)
10836
0
                xmlXPathPErrMemory(ctxt);
10837
0
        }
10838
20.7k
  break;
10839
10840
6.39M
apply_predicates: /* --------------------------------------------------- */
10841
6.39M
        if (ctxt->error != XPATH_EXPRESSION_OK)
10842
734
      goto error;
10843
10844
        /*
10845
  * Apply predicates.
10846
  */
10847
6.39M
        if ((predOp != NULL) && (seq->nodeNr > 0)) {
10848
      /*
10849
      * E.g. when we have a "/foo[some expression][n]".
10850
      */
10851
      /*
10852
      * QUESTION TODO: The old predicate evaluation took into
10853
      *  account location-sets.
10854
      *  (E.g. ctxt->value->type == XPATH_LOCATIONSET)
10855
      *  Do we expect such a set here?
10856
      *  All what I learned now from the evaluation semantics
10857
      *  does not indicate that a location-set will be processed
10858
      *  here, so this looks OK.
10859
      */
10860
      /*
10861
      * Iterate over all predicates, starting with the outermost
10862
      * predicate.
10863
      * TODO: Problem: we cannot execute the inner predicates first
10864
      *  since we cannot go back *up* the operator tree!
10865
      *  Options we have:
10866
      *  1) Use of recursive functions (like is it currently done
10867
      *     via xmlXPathCompOpEval())
10868
      *  2) Add a predicate evaluation information stack to the
10869
      *     context struct
10870
      *  3) Change the way the operators are linked; we need a
10871
      *     "parent" field on xmlXPathStepOp
10872
      *
10873
      * For the moment, I'll try to solve this with a recursive
10874
      * function: xmlXPathCompOpEvalPredicate().
10875
      */
10876
152k
      if (hasPredicateRange != 0)
10877
14.3k
    xmlXPathCompOpEvalPredicate(ctxt, predOp, seq, maxPos, maxPos,
10878
14.3k
              hasNsNodes);
10879
137k
      else
10880
137k
    xmlXPathCompOpEvalPredicate(ctxt, predOp, seq, 1, seq->nodeNr,
10881
137k
              hasNsNodes);
10882
10883
152k
      if (ctxt->error != XPATH_EXPRESSION_OK) {
10884
18.2k
    total = 0;
10885
18.2k
    goto error;
10886
18.2k
      }
10887
152k
        }
10888
10889
6.37M
        if (seq->nodeNr > 0) {
10890
      /*
10891
      * Add to result set.
10892
      */
10893
2.06M
      if (outSeq == NULL) {
10894
1.38M
    outSeq = seq;
10895
1.38M
    seq = NULL;
10896
1.38M
      } else {
10897
674k
    outSeq = mergeAndClear(outSeq, seq);
10898
674k
                if (outSeq == NULL)
10899
101
                    xmlXPathPErrMemory(ctxt);
10900
674k
      }
10901
10902
2.06M
            if (toBool)
10903
228
                break;
10904
2.06M
  }
10905
6.37M
    }
10906
10907
4.63M
error:
10908
4.63M
    if ((obj->boolval) && (obj->user != NULL)) {
10909
  /*
10910
  * QUESTION TODO: What does this do and why?
10911
  * TODO: Do we have to do this also for the "error"
10912
  * cleanup further down?
10913
  */
10914
0
  ctxt->value->boolval = 1;
10915
0
  ctxt->value->user = obj->user;
10916
0
  obj->user = NULL;
10917
0
  obj->boolval = 0;
10918
0
    }
10919
4.63M
    xmlXPathReleaseObject(xpctxt, obj);
10920
10921
    /*
10922
    * Ensure we return at least an empty set.
10923
    */
10924
4.63M
    if (outSeq == NULL) {
10925
3.22M
  if ((seq != NULL) && (seq->nodeNr == 0)) {
10926
3.21M
      outSeq = seq;
10927
3.21M
        } else {
10928
2.98k
      outSeq = xmlXPathNodeSetCreate(NULL);
10929
2.98k
            if (outSeq == NULL)
10930
2.10k
                xmlXPathPErrMemory(ctxt);
10931
2.98k
        }
10932
3.22M
    }
10933
4.63M
    if ((seq != NULL) && (seq != outSeq)) {
10934
60.8k
   xmlXPathFreeNodeSet(seq);
10935
60.8k
    }
10936
    /*
10937
    * Hand over the result. Better to push the set also in
10938
    * case of errors.
10939
    */
10940
4.63M
    xmlXPathValuePush(ctxt, xmlXPathCacheWrapNodeSet(ctxt, outSeq));
10941
    /*
10942
    * Reset the context node.
10943
    */
10944
4.63M
    xpctxt->node = oldContextNode;
10945
    /*
10946
    * When traversing the namespace axis in "toBool" mode, it's
10947
    * possible that tmpNsList wasn't freed.
10948
    */
10949
4.63M
    if (xpctxt->tmpNsList != NULL) {
10950
18.0k
        xmlFree(xpctxt->tmpNsList);
10951
18.0k
        xpctxt->tmpNsList = NULL;
10952
18.0k
    }
10953
10954
4.63M
    return(total);
10955
4.63M
}
10956
10957
static int
10958
xmlXPathCompOpEvalFilterFirst(xmlXPathParserContextPtr ctxt,
10959
            xmlXPathStepOpPtr op, xmlNodePtr * first);
10960
10961
/**
10962
 * xmlXPathCompOpEvalFirst:
10963
 * @ctxt:  the XPath parser context with the compiled expression
10964
 * @op:  an XPath compiled operation
10965
 * @first:  the first elem found so far
10966
 *
10967
 * Evaluate the Precompiled XPath operation searching only the first
10968
 * element in document order
10969
 *
10970
 * Returns the number of examined objects.
10971
 */
10972
static int
10973
xmlXPathCompOpEvalFirst(xmlXPathParserContextPtr ctxt,
10974
                        xmlXPathStepOpPtr op, xmlNodePtr * first)
10975
104k
{
10976
104k
    int total = 0, cur;
10977
104k
    xmlXPathCompExprPtr comp;
10978
104k
    xmlXPathObjectPtr arg1, arg2;
10979
10980
104k
    CHECK_ERROR0;
10981
104k
    if (OP_LIMIT_EXCEEDED(ctxt, 1))
10982
1
        return(0);
10983
104k
    if (ctxt->context->depth >= XPATH_MAX_RECURSION_DEPTH)
10984
103k
        XP_ERROR0(XPATH_RECURSION_LIMIT_EXCEEDED);
10985
103k
    ctxt->context->depth += 1;
10986
103k
    comp = ctxt->comp;
10987
103k
    switch (op->op) {
10988
0
        case XPATH_OP_END:
10989
0
            break;
10990
22.2k
        case XPATH_OP_UNION:
10991
22.2k
            total =
10992
22.2k
                xmlXPathCompOpEvalFirst(ctxt, &comp->steps[op->ch1],
10993
22.2k
                                        first);
10994
22.2k
      CHECK_ERROR0;
10995
21.9k
            if ((ctxt->value != NULL)
10996
21.9k
                && (ctxt->value->type == XPATH_NODESET)
10997
21.8k
                && (ctxt->value->nodesetval != NULL)
10998
21.8k
                && (ctxt->value->nodesetval->nodeNr >= 1)) {
10999
                /*
11000
                 * limit tree traversing to first node in the result
11001
                 */
11002
    /*
11003
    * OPTIMIZE TODO: This implicitly sorts
11004
    *  the result, even if not needed. E.g. if the argument
11005
    *  of the count() function, no sorting is needed.
11006
    * OPTIMIZE TODO: How do we know if the node-list wasn't
11007
    *  already sorted?
11008
    */
11009
11.8k
    if (ctxt->value->nodesetval->nodeNr > 1)
11010
348
        xmlXPathNodeSetSort(ctxt->value->nodesetval);
11011
11.8k
                *first = ctxt->value->nodesetval->nodeTab[0];
11012
11.8k
            }
11013
21.9k
            cur =
11014
21.9k
                xmlXPathCompOpEvalFirst(ctxt, &comp->steps[op->ch2],
11015
21.9k
                                        first);
11016
21.9k
      CHECK_ERROR0;
11017
11018
21.7k
            arg2 = xmlXPathValuePop(ctxt);
11019
21.7k
            arg1 = xmlXPathValuePop(ctxt);
11020
21.7k
            if ((arg1 == NULL) || (arg1->type != XPATH_NODESET) ||
11021
21.7k
                (arg2 == NULL) || (arg2->type != XPATH_NODESET)) {
11022
302
          xmlXPathReleaseObject(ctxt->context, arg1);
11023
302
          xmlXPathReleaseObject(ctxt->context, arg2);
11024
302
                XP_ERROR0(XPATH_INVALID_TYPE);
11025
0
            }
11026
21.4k
            if ((ctxt->context->opLimit != 0) &&
11027
21.4k
                (((arg1->nodesetval != NULL) &&
11028
21.4k
                  (xmlXPathCheckOpLimit(ctxt,
11029
21.4k
                                        arg1->nodesetval->nodeNr) < 0)) ||
11030
21.4k
                 ((arg2->nodesetval != NULL) &&
11031
21.4k
                  (xmlXPathCheckOpLimit(ctxt,
11032
21.4k
                                        arg2->nodesetval->nodeNr) < 0)))) {
11033
2
          xmlXPathReleaseObject(ctxt->context, arg1);
11034
2
          xmlXPathReleaseObject(ctxt->context, arg2);
11035
2
                break;
11036
2
            }
11037
11038
21.4k
            if ((arg2->nodesetval != NULL) &&
11039
21.4k
                (arg2->nodesetval->nodeNr != 0)) {
11040
12.3k
                arg1->nodesetval = xmlXPathNodeSetMerge(arg1->nodesetval,
11041
12.3k
                                                        arg2->nodesetval);
11042
12.3k
                if (arg1->nodesetval == NULL)
11043
8
                    xmlXPathPErrMemory(ctxt);
11044
12.3k
            }
11045
21.4k
            xmlXPathValuePush(ctxt, arg1);
11046
21.4k
      xmlXPathReleaseObject(ctxt->context, arg2);
11047
21.4k
            total += cur;
11048
21.4k
            break;
11049
4.84k
        case XPATH_OP_ROOT:
11050
4.84k
            xmlXPathRoot(ctxt);
11051
4.84k
            break;
11052
6.76k
        case XPATH_OP_NODE:
11053
6.76k
            if (op->ch1 != -1)
11054
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11055
6.76k
      CHECK_ERROR0;
11056
6.76k
            if (op->ch2 != -1)
11057
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11058
6.76k
      CHECK_ERROR0;
11059
6.76k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt,
11060
6.76k
    ctxt->context->node));
11061
6.76k
            break;
11062
18.3k
        case XPATH_OP_COLLECT:{
11063
18.3k
                if (op->ch1 == -1)
11064
0
                    break;
11065
11066
18.3k
                total = xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11067
18.3k
    CHECK_ERROR0;
11068
11069
18.1k
                total += xmlXPathNodeCollectAndTest(ctxt, op, first, NULL, 0);
11070
18.1k
                break;
11071
18.3k
            }
11072
309
        case XPATH_OP_VALUE:
11073
309
            xmlXPathValuePush(ctxt, xmlXPathCacheObjectCopy(ctxt, op->value4));
11074
309
            break;
11075
11.6k
        case XPATH_OP_SORT:
11076
11.6k
            if (op->ch1 != -1)
11077
11.6k
                total +=
11078
11.6k
                    xmlXPathCompOpEvalFirst(ctxt, &comp->steps[op->ch1],
11079
11.6k
                                            first);
11080
11.6k
      CHECK_ERROR0;
11081
9.15k
            if ((ctxt->value != NULL)
11082
9.15k
                && (ctxt->value->type == XPATH_NODESET)
11083
7.74k
                && (ctxt->value->nodesetval != NULL)
11084
7.74k
    && (ctxt->value->nodesetval->nodeNr > 1))
11085
5.00k
                xmlXPathNodeSetSort(ctxt->value->nodesetval);
11086
9.15k
            break;
11087
0
#ifdef XP_OPTIMIZED_FILTER_FIRST
11088
36.5k
  case XPATH_OP_FILTER:
11089
36.5k
                total += xmlXPathCompOpEvalFilterFirst(ctxt, op, first);
11090
36.5k
            break;
11091
0
#endif
11092
3.20k
        default:
11093
3.20k
            total += xmlXPathCompOpEval(ctxt, op);
11094
3.20k
            break;
11095
103k
    }
11096
11097
100k
    ctxt->context->depth -= 1;
11098
100k
    return(total);
11099
103k
}
11100
11101
/**
11102
 * xmlXPathCompOpEvalLast:
11103
 * @ctxt:  the XPath parser context with the compiled expression
11104
 * @op:  an XPath compiled operation
11105
 * @last:  the last elem found so far
11106
 *
11107
 * Evaluate the Precompiled XPath operation searching only the last
11108
 * element in document order
11109
 *
11110
 * Returns the number of nodes traversed
11111
 */
11112
static int
11113
xmlXPathCompOpEvalLast(xmlXPathParserContextPtr ctxt, xmlXPathStepOpPtr op,
11114
                       xmlNodePtr * last)
11115
180k
{
11116
180k
    int total = 0, cur;
11117
180k
    xmlXPathCompExprPtr comp;
11118
180k
    xmlXPathObjectPtr arg1, arg2;
11119
11120
180k
    CHECK_ERROR0;
11121
180k
    if (OP_LIMIT_EXCEEDED(ctxt, 1))
11122
3
        return(0);
11123
180k
    if (ctxt->context->depth >= XPATH_MAX_RECURSION_DEPTH)
11124
180k
        XP_ERROR0(XPATH_RECURSION_LIMIT_EXCEEDED);
11125
180k
    ctxt->context->depth += 1;
11126
180k
    comp = ctxt->comp;
11127
180k
    switch (op->op) {
11128
0
        case XPATH_OP_END:
11129
0
            break;
11130
60.2k
        case XPATH_OP_UNION:
11131
60.2k
            total =
11132
60.2k
                xmlXPathCompOpEvalLast(ctxt, &comp->steps[op->ch1], last);
11133
60.2k
      CHECK_ERROR0;
11134
58.4k
            if ((ctxt->value != NULL)
11135
58.4k
                && (ctxt->value->type == XPATH_NODESET)
11136
58.2k
                && (ctxt->value->nodesetval != NULL)
11137
58.2k
                && (ctxt->value->nodesetval->nodeNr >= 1)) {
11138
                /*
11139
                 * limit tree traversing to first node in the result
11140
                 */
11141
12.3k
    if (ctxt->value->nodesetval->nodeNr > 1)
11142
3.04k
        xmlXPathNodeSetSort(ctxt->value->nodesetval);
11143
12.3k
                *last =
11144
12.3k
                    ctxt->value->nodesetval->nodeTab[ctxt->value->
11145
12.3k
                                                     nodesetval->nodeNr -
11146
12.3k
                                                     1];
11147
12.3k
            }
11148
58.4k
            cur =
11149
58.4k
                xmlXPathCompOpEvalLast(ctxt, &comp->steps[op->ch2], last);
11150
58.4k
      CHECK_ERROR0;
11151
58.0k
            if ((ctxt->value != NULL)
11152
58.0k
                && (ctxt->value->type == XPATH_NODESET)
11153
57.9k
                && (ctxt->value->nodesetval != NULL)
11154
57.9k
                && (ctxt->value->nodesetval->nodeNr >= 1)) { /* TODO: NOP ? */
11155
25.7k
            }
11156
11157
58.0k
            arg2 = xmlXPathValuePop(ctxt);
11158
58.0k
            arg1 = xmlXPathValuePop(ctxt);
11159
58.0k
            if ((arg1 == NULL) || (arg1->type != XPATH_NODESET) ||
11160
58.0k
                (arg2 == NULL) || (arg2->type != XPATH_NODESET)) {
11161
203
          xmlXPathReleaseObject(ctxt->context, arg1);
11162
203
          xmlXPathReleaseObject(ctxt->context, arg2);
11163
203
                XP_ERROR0(XPATH_INVALID_TYPE);
11164
0
            }
11165
57.8k
            if ((ctxt->context->opLimit != 0) &&
11166
57.8k
                (((arg1->nodesetval != NULL) &&
11167
57.8k
                  (xmlXPathCheckOpLimit(ctxt,
11168
57.8k
                                        arg1->nodesetval->nodeNr) < 0)) ||
11169
57.8k
                 ((arg2->nodesetval != NULL) &&
11170
57.8k
                  (xmlXPathCheckOpLimit(ctxt,
11171
57.8k
                                        arg2->nodesetval->nodeNr) < 0)))) {
11172
2
          xmlXPathReleaseObject(ctxt->context, arg1);
11173
2
          xmlXPathReleaseObject(ctxt->context, arg2);
11174
2
                break;
11175
2
            }
11176
11177
57.8k
            if ((arg2->nodesetval != NULL) &&
11178
57.8k
                (arg2->nodesetval->nodeNr != 0)) {
11179
25.7k
                arg1->nodesetval = xmlXPathNodeSetMerge(arg1->nodesetval,
11180
25.7k
                                                        arg2->nodesetval);
11181
25.7k
                if (arg1->nodesetval == NULL)
11182
3
                    xmlXPathPErrMemory(ctxt);
11183
25.7k
            }
11184
57.8k
            xmlXPathValuePush(ctxt, arg1);
11185
57.8k
      xmlXPathReleaseObject(ctxt->context, arg2);
11186
57.8k
            total += cur;
11187
57.8k
            break;
11188
1.28k
        case XPATH_OP_ROOT:
11189
1.28k
            xmlXPathRoot(ctxt);
11190
1.28k
            break;
11191
14.2k
        case XPATH_OP_NODE:
11192
14.2k
            if (op->ch1 != -1)
11193
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11194
14.2k
      CHECK_ERROR0;
11195
14.2k
            if (op->ch2 != -1)
11196
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11197
14.2k
      CHECK_ERROR0;
11198
14.2k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt,
11199
14.2k
    ctxt->context->node));
11200
14.2k
            break;
11201
70.2k
        case XPATH_OP_COLLECT:{
11202
70.2k
                if (op->ch1 == -1)
11203
0
                    break;
11204
11205
70.2k
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11206
70.2k
    CHECK_ERROR0;
11207
11208
68.3k
                total += xmlXPathNodeCollectAndTest(ctxt, op, NULL, last, 0);
11209
68.3k
                break;
11210
70.2k
            }
11211
231
        case XPATH_OP_VALUE:
11212
231
            xmlXPathValuePush(ctxt, xmlXPathCacheObjectCopy(ctxt, op->value4));
11213
231
            break;
11214
30.7k
        case XPATH_OP_SORT:
11215
30.7k
            if (op->ch1 != -1)
11216
30.7k
                total +=
11217
30.7k
                    xmlXPathCompOpEvalLast(ctxt, &comp->steps[op->ch1],
11218
30.7k
                                           last);
11219
30.7k
      CHECK_ERROR0;
11220
28.3k
            if ((ctxt->value != NULL)
11221
28.3k
                && (ctxt->value->type == XPATH_NODESET)
11222
25.3k
                && (ctxt->value->nodesetval != NULL)
11223
25.3k
    && (ctxt->value->nodesetval->nodeNr > 1))
11224
5.84k
                xmlXPathNodeSetSort(ctxt->value->nodesetval);
11225
28.3k
            break;
11226
3.09k
        default:
11227
3.09k
            total += xmlXPathCompOpEval(ctxt, op);
11228
3.09k
            break;
11229
180k
    }
11230
11231
173k
    ctxt->context->depth -= 1;
11232
173k
    return (total);
11233
180k
}
11234
11235
#ifdef XP_OPTIMIZED_FILTER_FIRST
11236
static int
11237
xmlXPathCompOpEvalFilterFirst(xmlXPathParserContextPtr ctxt,
11238
            xmlXPathStepOpPtr op, xmlNodePtr * first)
11239
36.5k
{
11240
36.5k
    int total = 0;
11241
36.5k
    xmlXPathCompExprPtr comp;
11242
36.5k
    xmlXPathObjectPtr obj;
11243
36.5k
    xmlNodeSetPtr set;
11244
11245
36.5k
    CHECK_ERROR0;
11246
36.5k
    comp = ctxt->comp;
11247
    /*
11248
    * Optimization for ()[last()] selection i.e. the last elem
11249
    */
11250
36.5k
    if ((op->ch1 != -1) && (op->ch2 != -1) &&
11251
36.5k
  (comp->steps[op->ch1].op == XPATH_OP_SORT) &&
11252
18.3k
  (comp->steps[op->ch2].op == XPATH_OP_SORT)) {
11253
16.7k
  int f = comp->steps[op->ch2].ch1;
11254
11255
16.7k
  if ((f != -1) &&
11256
16.7k
      (comp->steps[f].op == XPATH_OP_FUNCTION) &&
11257
15.9k
      (comp->steps[f].value5 == NULL) &&
11258
15.1k
      (comp->steps[f].value == 0) &&
11259
14.8k
      (comp->steps[f].value4 != NULL) &&
11260
14.8k
      (xmlStrEqual
11261
14.8k
      (comp->steps[f].value4, BAD_CAST "last"))) {
11262
14.2k
      xmlNodePtr last = NULL;
11263
11264
14.2k
      total +=
11265
14.2k
    xmlXPathCompOpEvalLast(ctxt,
11266
14.2k
        &comp->steps[op->ch1],
11267
14.2k
        &last);
11268
14.2k
      CHECK_ERROR0;
11269
      /*
11270
      * The nodeset should be in document order,
11271
      * Keep only the last value
11272
      */
11273
11.9k
      if ((ctxt->value != NULL) &&
11274
11.9k
    (ctxt->value->type == XPATH_NODESET) &&
11275
8.97k
    (ctxt->value->nodesetval != NULL) &&
11276
8.97k
    (ctxt->value->nodesetval->nodeTab != NULL) &&
11277
6.89k
    (ctxt->value->nodesetval->nodeNr > 1)) {
11278
2.57k
                xmlXPathNodeSetKeepLast(ctxt->value->nodesetval);
11279
2.57k
    *first = *(ctxt->value->nodesetval->nodeTab);
11280
2.57k
      }
11281
11.9k
      return (total);
11282
14.2k
  }
11283
16.7k
    }
11284
11285
22.3k
    if (op->ch1 != -1)
11286
22.3k
  total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11287
22.3k
    CHECK_ERROR0;
11288
21.3k
    if (op->ch2 == -1)
11289
0
  return (total);
11290
21.3k
    if (ctxt->value == NULL)
11291
0
  return (total);
11292
11293
    /*
11294
     * In case of errors, xmlXPathNodeSetFilter can pop additional nodes from
11295
     * the stack. We have to temporarily remove the nodeset object from the
11296
     * stack to avoid freeing it prematurely.
11297
     */
11298
21.3k
    CHECK_TYPE0(XPATH_NODESET);
11299
20.5k
    obj = xmlXPathValuePop(ctxt);
11300
20.5k
    set = obj->nodesetval;
11301
20.5k
    if (set != NULL) {
11302
20.5k
        xmlXPathNodeSetFilter(ctxt, set, op->ch2, 1, 1, 1);
11303
20.5k
        if (set->nodeNr > 0)
11304
7.14k
            *first = set->nodeTab[0];
11305
20.5k
    }
11306
20.5k
    xmlXPathValuePush(ctxt, obj);
11307
11308
20.5k
    return (total);
11309
21.3k
}
11310
#endif /* XP_OPTIMIZED_FILTER_FIRST */
11311
11312
/**
11313
 * xmlXPathCompOpEval:
11314
 * @ctxt:  the XPath parser context with the compiled expression
11315
 * @op:  an XPath compiled operation
11316
 *
11317
 * Evaluate the Precompiled XPath operation
11318
 * Returns the number of nodes traversed
11319
 */
11320
static int
11321
xmlXPathCompOpEval(xmlXPathParserContextPtr ctxt, xmlXPathStepOpPtr op)
11322
24.8M
{
11323
24.8M
    int total = 0;
11324
24.8M
    int equal, ret;
11325
24.8M
    xmlXPathCompExprPtr comp;
11326
24.8M
    xmlXPathObjectPtr arg1, arg2;
11327
11328
24.8M
    CHECK_ERROR0;
11329
24.8M
    if (OP_LIMIT_EXCEEDED(ctxt, 1))
11330
591k
        return(0);
11331
24.2M
    if (ctxt->context->depth >= XPATH_MAX_RECURSION_DEPTH)
11332
24.2M
        XP_ERROR0(XPATH_RECURSION_LIMIT_EXCEEDED);
11333
24.2M
    ctxt->context->depth += 1;
11334
24.2M
    comp = ctxt->comp;
11335
24.2M
    switch (op->op) {
11336
0
        case XPATH_OP_END:
11337
0
            break;
11338
81.1k
        case XPATH_OP_AND:
11339
81.1k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11340
81.1k
      CHECK_ERROR0;
11341
69.3k
            xmlXPathBooleanFunction(ctxt, 1);
11342
69.3k
            if ((ctxt->value == NULL) || (ctxt->value->boolval == 0))
11343
46.3k
                break;
11344
23.0k
            arg2 = xmlXPathValuePop(ctxt);
11345
23.0k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11346
23.0k
      if (ctxt->error) {
11347
1.43k
    xmlXPathFreeObject(arg2);
11348
1.43k
    break;
11349
1.43k
      }
11350
21.5k
            xmlXPathBooleanFunction(ctxt, 1);
11351
21.5k
            if (ctxt->value != NULL)
11352
21.5k
                ctxt->value->boolval &= arg2->boolval;
11353
21.5k
      xmlXPathReleaseObject(ctxt->context, arg2);
11354
21.5k
            break;
11355
106k
        case XPATH_OP_OR:
11356
106k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11357
106k
      CHECK_ERROR0;
11358
95.1k
            xmlXPathBooleanFunction(ctxt, 1);
11359
95.1k
            if ((ctxt->value == NULL) || (ctxt->value->boolval == 1))
11360
35.6k
                break;
11361
59.5k
            arg2 = xmlXPathValuePop(ctxt);
11362
59.5k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11363
59.5k
      if (ctxt->error) {
11364
4.02k
    xmlXPathFreeObject(arg2);
11365
4.02k
    break;
11366
4.02k
      }
11367
55.4k
            xmlXPathBooleanFunction(ctxt, 1);
11368
55.4k
            if (ctxt->value != NULL)
11369
55.3k
                ctxt->value->boolval |= arg2->boolval;
11370
55.4k
      xmlXPathReleaseObject(ctxt->context, arg2);
11371
55.4k
            break;
11372
570k
        case XPATH_OP_EQUAL:
11373
570k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11374
570k
      CHECK_ERROR0;
11375
539k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11376
539k
      CHECK_ERROR0;
11377
444k
      if (op->value)
11378
322k
    equal = xmlXPathEqualValues(ctxt);
11379
122k
      else
11380
122k
    equal = xmlXPathNotEqualValues(ctxt);
11381
444k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, equal));
11382
444k
            break;
11383
436k
        case XPATH_OP_CMP:
11384
436k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11385
436k
      CHECK_ERROR0;
11386
393k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11387
393k
      CHECK_ERROR0;
11388
340k
            ret = xmlXPathCompareValues(ctxt, op->value, op->value2);
11389
340k
      xmlXPathValuePush(ctxt, xmlXPathCacheNewBoolean(ctxt, ret));
11390
340k
            break;
11391
681k
        case XPATH_OP_PLUS:
11392
681k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11393
681k
      CHECK_ERROR0;
11394
598k
            if (op->ch2 != -1) {
11395
388k
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11396
388k
      }
11397
598k
      CHECK_ERROR0;
11398
512k
            if (op->value == 0)
11399
154k
                xmlXPathSubValues(ctxt);
11400
357k
            else if (op->value == 1)
11401
147k
                xmlXPathAddValues(ctxt);
11402
209k
            else if (op->value == 2)
11403
196k
                xmlXPathValueFlipSign(ctxt);
11404
13.4k
            else if (op->value == 3) {
11405
13.4k
                CAST_TO_NUMBER;
11406
13.4k
                CHECK_TYPE0(XPATH_NUMBER);
11407
13.3k
            }
11408
512k
            break;
11409
533k
        case XPATH_OP_MULT:
11410
533k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11411
533k
      CHECK_ERROR0;
11412
323k
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11413
323k
      CHECK_ERROR0;
11414
289k
            if (op->value == 0)
11415
242k
                xmlXPathMultValues(ctxt);
11416
46.6k
            else if (op->value == 1)
11417
5.45k
                xmlXPathDivValues(ctxt);
11418
41.2k
            else if (op->value == 2)
11419
41.2k
                xmlXPathModValues(ctxt);
11420
289k
            break;
11421
1.51M
        case XPATH_OP_UNION:
11422
1.51M
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11423
1.51M
      CHECK_ERROR0;
11424
1.46M
            total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11425
1.46M
      CHECK_ERROR0;
11426
11427
1.43M
            arg2 = xmlXPathValuePop(ctxt);
11428
1.43M
            arg1 = xmlXPathValuePop(ctxt);
11429
1.43M
            if ((arg1 == NULL) || (arg1->type != XPATH_NODESET) ||
11430
1.43M
                (arg2 == NULL) || (arg2->type != XPATH_NODESET)) {
11431
19.1k
          xmlXPathReleaseObject(ctxt->context, arg1);
11432
19.1k
          xmlXPathReleaseObject(ctxt->context, arg2);
11433
19.1k
                XP_ERROR0(XPATH_INVALID_TYPE);
11434
0
            }
11435
1.42M
            if ((ctxt->context->opLimit != 0) &&
11436
1.42M
                (((arg1->nodesetval != NULL) &&
11437
1.42M
                  (xmlXPathCheckOpLimit(ctxt,
11438
1.42M
                                        arg1->nodesetval->nodeNr) < 0)) ||
11439
1.41M
                 ((arg2->nodesetval != NULL) &&
11440
1.41M
                  (xmlXPathCheckOpLimit(ctxt,
11441
1.41M
                                        arg2->nodesetval->nodeNr) < 0)))) {
11442
2.47k
          xmlXPathReleaseObject(ctxt->context, arg1);
11443
2.47k
          xmlXPathReleaseObject(ctxt->context, arg2);
11444
2.47k
                break;
11445
2.47k
            }
11446
11447
1.41M
      if (((arg2->nodesetval != NULL) &&
11448
1.41M
     (arg2->nodesetval->nodeNr != 0)))
11449
697k
      {
11450
697k
    arg1->nodesetval = xmlXPathNodeSetMerge(arg1->nodesetval,
11451
697k
              arg2->nodesetval);
11452
697k
                if (arg1->nodesetval == NULL)
11453
873
                    xmlXPathPErrMemory(ctxt);
11454
697k
      }
11455
11456
1.41M
            xmlXPathValuePush(ctxt, arg1);
11457
1.41M
      xmlXPathReleaseObject(ctxt->context, arg2);
11458
1.41M
            break;
11459
1.39M
        case XPATH_OP_ROOT:
11460
1.39M
            xmlXPathRoot(ctxt);
11461
1.39M
            break;
11462
4.66M
        case XPATH_OP_NODE:
11463
4.66M
            if (op->ch1 != -1)
11464
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11465
4.66M
      CHECK_ERROR0;
11466
4.66M
            if (op->ch2 != -1)
11467
0
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11468
4.66M
      CHECK_ERROR0;
11469
4.66M
      xmlXPathValuePush(ctxt, xmlXPathCacheNewNodeSet(ctxt,
11470
4.66M
                                                    ctxt->context->node));
11471
4.66M
            break;
11472
5.23M
        case XPATH_OP_COLLECT:{
11473
5.23M
                if (op->ch1 == -1)
11474
0
                    break;
11475
11476
5.23M
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11477
5.23M
    CHECK_ERROR0;
11478
11479
5.10M
                total += xmlXPathNodeCollectAndTest(ctxt, op, NULL, NULL, 0);
11480
5.10M
                break;
11481
5.23M
            }
11482
739k
        case XPATH_OP_VALUE:
11483
739k
            xmlXPathValuePush(ctxt, xmlXPathCacheObjectCopy(ctxt, op->value4));
11484
739k
            break;
11485
82.7k
        case XPATH_OP_VARIABLE:{
11486
82.7k
    xmlXPathObjectPtr val;
11487
11488
82.7k
                if (op->ch1 != -1)
11489
0
                    total +=
11490
0
                        xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11491
82.7k
                if (op->value5 == NULL) {
11492
65.7k
        val = xmlXPathVariableLookup(ctxt->context, op->value4);
11493
65.7k
        if (val == NULL)
11494
45.3k
      XP_ERROR0(XPATH_UNDEF_VARIABLE_ERROR);
11495
45.3k
                    xmlXPathValuePush(ctxt, val);
11496
45.3k
    } else {
11497
16.9k
                    const xmlChar *URI;
11498
11499
16.9k
                    URI = xmlXPathNsLookup(ctxt->context, op->value5);
11500
16.9k
                    if (URI == NULL) {
11501
16.2k
                        XP_ERROR0(XPATH_UNDEF_PREFIX_ERROR);
11502
0
                        break;
11503
16.2k
                    }
11504
738
        val = xmlXPathVariableLookupNS(ctxt->context,
11505
738
                                                       op->value4, URI);
11506
738
        if (val == NULL)
11507
738
      XP_ERROR0(XPATH_UNDEF_VARIABLE_ERROR);
11508
0
                    xmlXPathValuePush(ctxt, val);
11509
0
                }
11510
45.3k
                break;
11511
82.7k
            }
11512
1.46M
        case XPATH_OP_FUNCTION:{
11513
1.46M
                xmlXPathFunction func;
11514
1.46M
                const xmlChar *oldFunc, *oldFuncURI;
11515
1.46M
    int i;
11516
1.46M
                int frame;
11517
11518
1.46M
                frame = ctxt->valueNr;
11519
1.46M
                if (op->ch1 != -1) {
11520
1.14M
                    total +=
11521
1.14M
                        xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11522
1.14M
                    if (ctxt->error != XPATH_EXPRESSION_OK)
11523
65.8k
                        break;
11524
1.14M
                }
11525
1.40M
    if (ctxt->valueNr < frame + op->value)
11526
1.40M
        XP_ERROR0(XPATH_INVALID_OPERAND);
11527
3.29M
    for (i = 0; i < op->value; i++) {
11528
1.88M
        if (ctxt->valueTab[(ctxt->valueNr - 1) - i] == NULL)
11529
1.88M
      XP_ERROR0(XPATH_INVALID_OPERAND);
11530
1.88M
                }
11531
1.40M
                if (op->cache != NULL)
11532
1.09M
                    func = op->cache;
11533
309k
                else {
11534
309k
                    const xmlChar *URI = NULL;
11535
11536
309k
                    if (op->value5 == NULL)
11537
158k
                        func =
11538
158k
                            xmlXPathFunctionLookup(ctxt->context,
11539
158k
                                                   op->value4);
11540
150k
                    else {
11541
150k
                        URI = xmlXPathNsLookup(ctxt->context, op->value5);
11542
150k
                        if (URI == NULL)
11543
132k
                            XP_ERROR0(XPATH_UNDEF_PREFIX_ERROR);
11544
132k
                        func = xmlXPathFunctionLookupNS(ctxt->context,
11545
132k
                                                        op->value4, URI);
11546
132k
                    }
11547
290k
                    if (func == NULL)
11548
176k
                        XP_ERROR0(XPATH_UNKNOWN_FUNC_ERROR);
11549
176k
                    op->cache = func;
11550
176k
                    op->cacheURI = (void *) URI;
11551
176k
                }
11552
1.27M
                oldFunc = ctxt->context->function;
11553
1.27M
                oldFuncURI = ctxt->context->functionURI;
11554
1.27M
                ctxt->context->function = op->value4;
11555
1.27M
                ctxt->context->functionURI = op->cacheURI;
11556
1.27M
                func(ctxt, op->value);
11557
1.27M
                ctxt->context->function = oldFunc;
11558
1.27M
                ctxt->context->functionURI = oldFuncURI;
11559
1.27M
                if ((ctxt->error == XPATH_EXPRESSION_OK) &&
11560
1.20M
                    (ctxt->valueNr != frame + 1))
11561
1.25M
                    XP_ERROR0(XPATH_STACK_ERROR);
11562
1.25M
                break;
11563
1.27M
            }
11564
1.97M
        case XPATH_OP_ARG:
11565
1.97M
            if (op->ch1 != -1) {
11566
834k
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11567
834k
          CHECK_ERROR0;
11568
834k
            }
11569
1.96M
            if (op->ch2 != -1) {
11570
1.96M
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch2]);
11571
1.96M
          CHECK_ERROR0;
11572
1.96M
      }
11573
1.89M
            break;
11574
1.89M
        case XPATH_OP_PREDICATE:
11575
305k
        case XPATH_OP_FILTER:{
11576
305k
                xmlXPathObjectPtr obj;
11577
305k
                xmlNodeSetPtr set;
11578
11579
                /*
11580
                 * Optimization for ()[1] selection i.e. the first elem
11581
                 */
11582
305k
                if ((op->ch1 != -1) && (op->ch2 != -1) &&
11583
305k
#ifdef XP_OPTIMIZED_FILTER_FIRST
11584
        /*
11585
        * FILTER TODO: Can we assume that the inner processing
11586
        *  will result in an ordered list if we have an
11587
        *  XPATH_OP_FILTER?
11588
        *  What about an additional field or flag on
11589
        *  xmlXPathObject like @sorted ? This way we wouldn't need
11590
        *  to assume anything, so it would be more robust and
11591
        *  easier to optimize.
11592
        */
11593
305k
                    ((comp->steps[op->ch1].op == XPATH_OP_SORT) || /* 18 */
11594
265k
         (comp->steps[op->ch1].op == XPATH_OP_FILTER)) && /* 17 */
11595
#else
11596
        (comp->steps[op->ch1].op == XPATH_OP_SORT) &&
11597
#endif
11598
144k
                    (comp->steps[op->ch2].op == XPATH_OP_VALUE)) { /* 12 */
11599
83.6k
                    xmlXPathObjectPtr val;
11600
11601
83.6k
                    val = comp->steps[op->ch2].value4;
11602
83.6k
                    if ((val != NULL) && (val->type == XPATH_NUMBER) &&
11603
82.4k
                        (val->floatval == 1.0)) {
11604
48.2k
                        xmlNodePtr first = NULL;
11605
11606
48.2k
                        total +=
11607
48.2k
                            xmlXPathCompOpEvalFirst(ctxt,
11608
48.2k
                                                    &comp->steps[op->ch1],
11609
48.2k
                                                    &first);
11610
48.2k
      CHECK_ERROR0;
11611
                        /*
11612
                         * The nodeset should be in document order,
11613
                         * Keep only the first value
11614
                         */
11615
41.2k
                        if ((ctxt->value != NULL) &&
11616
41.2k
                            (ctxt->value->type == XPATH_NODESET) &&
11617
36.8k
                            (ctxt->value->nodesetval != NULL) &&
11618
36.8k
                            (ctxt->value->nodesetval->nodeNr > 1))
11619
5.00k
                            xmlXPathNodeSetClearFromPos(ctxt->value->nodesetval,
11620
5.00k
                                                        1, 1);
11621
41.2k
                        break;
11622
48.2k
                    }
11623
83.6k
                }
11624
                /*
11625
                 * Optimization for ()[last()] selection i.e. the last elem
11626
                 */
11627
257k
                if ((op->ch1 != -1) && (op->ch2 != -1) &&
11628
257k
                    (comp->steps[op->ch1].op == XPATH_OP_SORT) &&
11629
28.5k
                    (comp->steps[op->ch2].op == XPATH_OP_SORT)) {
11630
24.1k
                    int f = comp->steps[op->ch2].ch1;
11631
11632
24.1k
                    if ((f != -1) &&
11633
24.1k
                        (comp->steps[f].op == XPATH_OP_FUNCTION) &&
11634
18.7k
                        (comp->steps[f].value5 == NULL) &&
11635
18.5k
                        (comp->steps[f].value == 0) &&
11636
18.0k
                        (comp->steps[f].value4 != NULL) &&
11637
18.0k
                        (xmlStrEqual
11638
18.0k
                         (comp->steps[f].value4, BAD_CAST "last"))) {
11639
17.0k
                        xmlNodePtr last = NULL;
11640
11641
17.0k
                        total +=
11642
17.0k
                            xmlXPathCompOpEvalLast(ctxt,
11643
17.0k
                                                   &comp->steps[op->ch1],
11644
17.0k
                                                   &last);
11645
17.0k
      CHECK_ERROR0;
11646
                        /*
11647
                         * The nodeset should be in document order,
11648
                         * Keep only the last value
11649
                         */
11650
16.4k
                        if ((ctxt->value != NULL) &&
11651
16.4k
                            (ctxt->value->type == XPATH_NODESET) &&
11652
16.3k
                            (ctxt->value->nodesetval != NULL) &&
11653
16.3k
                            (ctxt->value->nodesetval->nodeTab != NULL) &&
11654
13.3k
                            (ctxt->value->nodesetval->nodeNr > 1))
11655
3.27k
                            xmlXPathNodeSetKeepLast(ctxt->value->nodesetval);
11656
16.4k
                        break;
11657
17.0k
                    }
11658
24.1k
                }
11659
    /*
11660
    * Process inner predicates first.
11661
    * Example "index[parent::book][1]":
11662
    * ...
11663
    *   PREDICATE   <-- we are here "[1]"
11664
    *     PREDICATE <-- process "[parent::book]" first
11665
    *       SORT
11666
    *         COLLECT  'parent' 'name' 'node' book
11667
    *           NODE
11668
    *     ELEM Object is a number : 1
11669
    */
11670
240k
                if (op->ch1 != -1)
11671
240k
                    total +=
11672
240k
                        xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11673
240k
    CHECK_ERROR0;
11674
216k
                if (op->ch2 == -1)
11675
0
                    break;
11676
216k
                if (ctxt->value == NULL)
11677
0
                    break;
11678
11679
                /*
11680
                 * In case of errors, xmlXPathNodeSetFilter can pop additional
11681
                 * nodes from the stack. We have to temporarily remove the
11682
                 * nodeset object from the stack to avoid freeing it
11683
                 * prematurely.
11684
                 */
11685
216k
                CHECK_TYPE0(XPATH_NODESET);
11686
208k
                obj = xmlXPathValuePop(ctxt);
11687
208k
                set = obj->nodesetval;
11688
208k
                if (set != NULL)
11689
208k
                    xmlXPathNodeSetFilter(ctxt, set, op->ch2,
11690
208k
                                          1, set->nodeNr, 1);
11691
208k
                xmlXPathValuePush(ctxt, obj);
11692
208k
                break;
11693
216k
            }
11694
4.45M
        case XPATH_OP_SORT:
11695
4.45M
            if (op->ch1 != -1)
11696
4.45M
                total += xmlXPathCompOpEval(ctxt, &comp->steps[op->ch1]);
11697
4.45M
      CHECK_ERROR0;
11698
3.97M
            if ((ctxt->value != NULL) &&
11699
3.97M
                (ctxt->value->type == XPATH_NODESET) &&
11700
3.23M
                (ctxt->value->nodesetval != NULL) &&
11701
3.23M
    (ctxt->value->nodesetval->nodeNr > 1))
11702
711k
      {
11703
711k
                xmlXPathNodeSetSort(ctxt->value->nodesetval);
11704
711k
      }
11705
3.97M
            break;
11706
0
        default:
11707
0
            XP_ERROR0(XPATH_INVALID_OPERAND);
11708
0
            break;
11709
24.2M
    }
11710
11711
22.5M
    ctxt->context->depth -= 1;
11712
22.5M
    return (total);
11713
24.2M
}
11714
11715
/**
11716
 * xmlXPathCompOpEvalToBoolean:
11717
 * @ctxt:  the XPath parser context
11718
 *
11719
 * Evaluates if the expression evaluates to true.
11720
 *
11721
 * Returns 1 if true, 0 if false and -1 on API or internal errors.
11722
 */
11723
static int
11724
xmlXPathCompOpEvalToBoolean(xmlXPathParserContextPtr ctxt,
11725
          xmlXPathStepOpPtr op,
11726
          int isPredicate)
11727
664k
{
11728
664k
    xmlXPathObjectPtr resObj = NULL;
11729
11730
908k
start:
11731
908k
    if (OP_LIMIT_EXCEEDED(ctxt, 1))
11732
3.70k
        return(0);
11733
    /* comp = ctxt->comp; */
11734
904k
    switch (op->op) {
11735
0
        case XPATH_OP_END:
11736
0
            return (0);
11737
175k
  case XPATH_OP_VALUE:
11738
175k
      resObj = (xmlXPathObjectPtr) op->value4;
11739
175k
      if (isPredicate)
11740
174k
    return(xmlXPathEvaluatePredicateResult(ctxt, resObj));
11741
1.34k
      return(xmlXPathCastToBoolean(resObj));
11742
244k
  case XPATH_OP_SORT:
11743
      /*
11744
      * We don't need sorting for boolean results. Skip this one.
11745
      */
11746
244k
            if (op->ch1 != -1) {
11747
244k
    op = &ctxt->comp->steps[op->ch1];
11748
244k
    goto start;
11749
244k
      }
11750
0
      return(0);
11751
65.9k
  case XPATH_OP_COLLECT:
11752
65.9k
      if (op->ch1 == -1)
11753
0
    return(0);
11754
11755
65.9k
            xmlXPathCompOpEval(ctxt, &ctxt->comp->steps[op->ch1]);
11756
65.9k
      if (ctxt->error != XPATH_EXPRESSION_OK)
11757
354
    return(-1);
11758
11759
65.6k
            xmlXPathNodeCollectAndTest(ctxt, op, NULL, NULL, 1);
11760
65.6k
      if (ctxt->error != XPATH_EXPRESSION_OK)
11761
709
    return(-1);
11762
11763
64.8k
      resObj = xmlXPathValuePop(ctxt);
11764
64.8k
      if (resObj == NULL)
11765
0
    return(-1);
11766
64.8k
      break;
11767
419k
  default:
11768
      /*
11769
      * Fallback to call xmlXPathCompOpEval().
11770
      */
11771
419k
      xmlXPathCompOpEval(ctxt, op);
11772
419k
      if (ctxt->error != XPATH_EXPRESSION_OK)
11773
28.4k
    return(-1);
11774
11775
390k
      resObj = xmlXPathValuePop(ctxt);
11776
390k
      if (resObj == NULL)
11777
0
    return(-1);
11778
390k
      break;
11779
904k
    }
11780
11781
455k
    if (resObj) {
11782
455k
  int res;
11783
11784
455k
  if (resObj->type == XPATH_BOOLEAN) {
11785
232k
      res = resObj->boolval;
11786
232k
  } else if (isPredicate) {
11787
      /*
11788
      * For predicates a result of type "number" is handled
11789
      * differently:
11790
      * SPEC XPath 1.0:
11791
      * "If the result is a number, the result will be converted
11792
      *  to true if the number is equal to the context position
11793
      *  and will be converted to false otherwise;"
11794
      */
11795
218k
      res = xmlXPathEvaluatePredicateResult(ctxt, resObj);
11796
218k
  } else {
11797
5.28k
      res = xmlXPathCastToBoolean(resObj);
11798
5.28k
  }
11799
455k
  xmlXPathReleaseObject(ctxt->context, resObj);
11800
455k
  return(res);
11801
455k
    }
11802
11803
0
    return(0);
11804
455k
}
11805
11806
#ifdef XPATH_STREAMING
11807
/**
11808
 * xmlXPathRunStreamEval:
11809
 * @pctxt:  the XPath parser context with the compiled expression
11810
 *
11811
 * Evaluate the Precompiled Streamable XPath expression in the given context.
11812
 */
11813
static int
11814
xmlXPathRunStreamEval(xmlXPathParserContextPtr pctxt, xmlPatternPtr comp,
11815
          xmlXPathObjectPtr *resultSeq, int toBool)
11816
{
11817
    int max_depth, min_depth;
11818
    int from_root;
11819
    int ret, depth;
11820
    int eval_all_nodes;
11821
    xmlNodePtr cur = NULL, limit = NULL;
11822
    xmlStreamCtxtPtr patstream = NULL;
11823
    xmlXPathContextPtr ctxt = pctxt->context;
11824
11825
    if ((ctxt == NULL) || (comp == NULL))
11826
        return(-1);
11827
    max_depth = xmlPatternMaxDepth(comp);
11828
    if (max_depth == -1)
11829
        return(-1);
11830
    if (max_depth == -2)
11831
        max_depth = 10000;
11832
    min_depth = xmlPatternMinDepth(comp);
11833
    if (min_depth == -1)
11834
        return(-1);
11835
    from_root = xmlPatternFromRoot(comp);
11836
    if (from_root < 0)
11837
        return(-1);
11838
11839
    if (! toBool) {
11840
  if (resultSeq == NULL)
11841
      return(-1);
11842
  *resultSeq = xmlXPathCacheNewNodeSet(pctxt, NULL);
11843
  if (*resultSeq == NULL)
11844
      return(-1);
11845
    }
11846
11847
    /*
11848
     * handle the special cases of "/" amd "." being matched
11849
     */
11850
    if (min_depth == 0) {
11851
        int res;
11852
11853
  if (from_root) {
11854
      /* Select "/" */
11855
      if (toBool)
11856
    return(1);
11857
            res = xmlXPathNodeSetAddUnique((*resultSeq)->nodesetval,
11858
                                           (xmlNodePtr) ctxt->doc);
11859
  } else {
11860
      /* Select "self::node()" */
11861
      if (toBool)
11862
    return(1);
11863
            res = xmlXPathNodeSetAddUnique((*resultSeq)->nodesetval,
11864
                                           ctxt->node);
11865
  }
11866
11867
        if (res < 0)
11868
            xmlXPathPErrMemory(pctxt);
11869
    }
11870
    if (max_depth == 0) {
11871
  return(0);
11872
    }
11873
11874
    if (from_root) {
11875
        cur = (xmlNodePtr)ctxt->doc;
11876
    } else if (ctxt->node != NULL) {
11877
        switch (ctxt->node->type) {
11878
            case XML_ELEMENT_NODE:
11879
            case XML_DOCUMENT_NODE:
11880
            case XML_DOCUMENT_FRAG_NODE:
11881
            case XML_HTML_DOCUMENT_NODE:
11882
          cur = ctxt->node;
11883
    break;
11884
            case XML_ATTRIBUTE_NODE:
11885
            case XML_TEXT_NODE:
11886
            case XML_CDATA_SECTION_NODE:
11887
            case XML_ENTITY_REF_NODE:
11888
            case XML_ENTITY_NODE:
11889
            case XML_PI_NODE:
11890
            case XML_COMMENT_NODE:
11891
            case XML_NOTATION_NODE:
11892
            case XML_DTD_NODE:
11893
            case XML_DOCUMENT_TYPE_NODE:
11894
            case XML_ELEMENT_DECL:
11895
            case XML_ATTRIBUTE_DECL:
11896
            case XML_ENTITY_DECL:
11897
            case XML_NAMESPACE_DECL:
11898
            case XML_XINCLUDE_START:
11899
            case XML_XINCLUDE_END:
11900
    break;
11901
  }
11902
  limit = cur;
11903
    }
11904
    if (cur == NULL) {
11905
        return(0);
11906
    }
11907
11908
    patstream = xmlPatternGetStreamCtxt(comp);
11909
    if (patstream == NULL) {
11910
        xmlXPathPErrMemory(pctxt);
11911
  return(-1);
11912
    }
11913
11914
    eval_all_nodes = xmlStreamWantsAnyNode(patstream);
11915
11916
    if (from_root) {
11917
  ret = xmlStreamPush(patstream, NULL, NULL);
11918
  if (ret < 0) {
11919
  } else if (ret == 1) {
11920
      if (toBool)
11921
    goto return_1;
11922
      if (xmlXPathNodeSetAddUnique((*resultSeq)->nodesetval, cur) < 0)
11923
                xmlXPathPErrMemory(pctxt);
11924
  }
11925
    }
11926
    depth = 0;
11927
    goto scan_children;
11928
next_node:
11929
    do {
11930
        if (ctxt->opLimit != 0) {
11931
            if (ctxt->opCount >= ctxt->opLimit) {
11932
                xmlXPathErr(ctxt, XPATH_RECURSION_LIMIT_EXCEEDED);
11933
                xmlFreeStreamCtxt(patstream);
11934
                return(-1);
11935
            }
11936
            ctxt->opCount++;
11937
        }
11938
11939
  switch (cur->type) {
11940
      case XML_ELEMENT_NODE:
11941
      case XML_TEXT_NODE:
11942
      case XML_CDATA_SECTION_NODE:
11943
      case XML_COMMENT_NODE:
11944
      case XML_PI_NODE:
11945
    if (cur->type == XML_ELEMENT_NODE) {
11946
        ret = xmlStreamPush(patstream, cur->name,
11947
        (cur->ns ? cur->ns->href : NULL));
11948
    } else if (eval_all_nodes)
11949
        ret = xmlStreamPushNode(patstream, NULL, NULL, cur->type);
11950
    else
11951
        break;
11952
11953
    if (ret < 0) {
11954
        xmlXPathPErrMemory(pctxt);
11955
    } else if (ret == 1) {
11956
        if (toBool)
11957
      goto return_1;
11958
        if (xmlXPathNodeSetAddUnique((*resultSeq)->nodesetval,
11959
                                                 cur) < 0)
11960
                        xmlXPathPErrMemory(pctxt);
11961
    }
11962
    if ((cur->children == NULL) || (depth >= max_depth)) {
11963
        ret = xmlStreamPop(patstream);
11964
        while (cur->next != NULL) {
11965
      cur = cur->next;
11966
      if ((cur->type != XML_ENTITY_DECL) &&
11967
          (cur->type != XML_DTD_NODE))
11968
          goto next_node;
11969
        }
11970
    }
11971
      default:
11972
    break;
11973
  }
11974
11975
scan_children:
11976
  if (cur->type == XML_NAMESPACE_DECL) break;
11977
  if ((cur->children != NULL) && (depth < max_depth)) {
11978
      /*
11979
       * Do not descend on entities declarations
11980
       */
11981
      if (cur->children->type != XML_ENTITY_DECL) {
11982
    cur = cur->children;
11983
    depth++;
11984
    /*
11985
     * Skip DTDs
11986
     */
11987
    if (cur->type != XML_DTD_NODE)
11988
        continue;
11989
      }
11990
  }
11991
11992
  if (cur == limit)
11993
      break;
11994
11995
  while (cur->next != NULL) {
11996
      cur = cur->next;
11997
      if ((cur->type != XML_ENTITY_DECL) &&
11998
    (cur->type != XML_DTD_NODE))
11999
    goto next_node;
12000
  }
12001
12002
  do {
12003
      cur = cur->parent;
12004
      depth--;
12005
      if ((cur == NULL) || (cur == limit) ||
12006
                (cur->type == XML_DOCUMENT_NODE))
12007
          goto done;
12008
      if (cur->type == XML_ELEMENT_NODE) {
12009
    ret = xmlStreamPop(patstream);
12010
      } else if ((eval_all_nodes) &&
12011
    ((cur->type == XML_TEXT_NODE) ||
12012
     (cur->type == XML_CDATA_SECTION_NODE) ||
12013
     (cur->type == XML_COMMENT_NODE) ||
12014
     (cur->type == XML_PI_NODE)))
12015
      {
12016
    ret = xmlStreamPop(patstream);
12017
      }
12018
      if (cur->next != NULL) {
12019
    cur = cur->next;
12020
    break;
12021
      }
12022
  } while (cur != NULL);
12023
12024
    } while ((cur != NULL) && (depth >= 0));
12025
12026
done:
12027
12028
    if (patstream)
12029
  xmlFreeStreamCtxt(patstream);
12030
    return(0);
12031
12032
return_1:
12033
    if (patstream)
12034
  xmlFreeStreamCtxt(patstream);
12035
    return(1);
12036
}
12037
#endif /* XPATH_STREAMING */
12038
12039
/**
12040
 * xmlXPathRunEval:
12041
 * @ctxt:  the XPath parser context with the compiled expression
12042
 * @toBool:  evaluate to a boolean result
12043
 *
12044
 * Evaluate the Precompiled XPath expression in the given context.
12045
 */
12046
static int
12047
xmlXPathRunEval(xmlXPathParserContextPtr ctxt, int toBool)
12048
3.26M
{
12049
3.26M
    xmlXPathCompExprPtr comp;
12050
3.26M
    int oldDepth;
12051
12052
3.26M
    if ((ctxt == NULL) || (ctxt->comp == NULL))
12053
0
  return(-1);
12054
12055
3.26M
    if (ctxt->valueTab == NULL) {
12056
25.9k
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
12057
25.9k
        int valueMax = 1;
12058
#else
12059
        int valueMax = 10;
12060
#endif
12061
12062
  /* Allocate the value stack */
12063
25.9k
  ctxt->valueTab = xmlMalloc(valueMax * sizeof(xmlXPathObjectPtr));
12064
25.9k
  if (ctxt->valueTab == NULL) {
12065
6
      xmlXPathPErrMemory(ctxt);
12066
6
      return(-1);
12067
6
  }
12068
25.9k
  ctxt->valueNr = 0;
12069
25.9k
  ctxt->valueMax = valueMax;
12070
25.9k
  ctxt->value = NULL;
12071
25.9k
    }
12072
#ifdef XPATH_STREAMING
12073
    if (ctxt->comp->stream) {
12074
  int res;
12075
12076
  if (toBool) {
12077
      /*
12078
      * Evaluation to boolean result.
12079
      */
12080
      res = xmlXPathRunStreamEval(ctxt, ctxt->comp->stream, NULL, 1);
12081
      if (res != -1)
12082
    return(res);
12083
  } else {
12084
      xmlXPathObjectPtr resObj = NULL;
12085
12086
      /*
12087
      * Evaluation to a sequence.
12088
      */
12089
      res = xmlXPathRunStreamEval(ctxt, ctxt->comp->stream, &resObj, 0);
12090
12091
      if ((res != -1) && (resObj != NULL)) {
12092
    xmlXPathValuePush(ctxt, resObj);
12093
    return(0);
12094
      }
12095
      if (resObj != NULL)
12096
    xmlXPathReleaseObject(ctxt->context, resObj);
12097
  }
12098
  /*
12099
  * QUESTION TODO: This falls back to normal XPath evaluation
12100
  * if res == -1. Is this intended?
12101
  */
12102
    }
12103
#endif
12104
3.26M
    comp = ctxt->comp;
12105
3.26M
    if (comp->last < 0) {
12106
0
        xmlXPathErr(ctxt, XPATH_STACK_ERROR);
12107
0
  return(-1);
12108
0
    }
12109
3.26M
    oldDepth = ctxt->context->depth;
12110
3.26M
    if (toBool)
12111
10.2k
  return(xmlXPathCompOpEvalToBoolean(ctxt,
12112
10.2k
      &comp->steps[comp->last], 0));
12113
3.25M
    else
12114
3.25M
  xmlXPathCompOpEval(ctxt, &comp->steps[comp->last]);
12115
3.25M
    ctxt->context->depth = oldDepth;
12116
12117
3.25M
    return(0);
12118
3.26M
}
12119
12120
/************************************************************************
12121
 *                  *
12122
 *      Public interfaces       *
12123
 *                  *
12124
 ************************************************************************/
12125
12126
/**
12127
 * xmlXPathEvalPredicate:
12128
 * @ctxt:  the XPath context
12129
 * @res:  the Predicate Expression evaluation result
12130
 *
12131
 * Evaluate a predicate result for the current node.
12132
 * A PredicateExpr is evaluated by evaluating the Expr and converting
12133
 * the result to a boolean. If the result is a number, the result will
12134
 * be converted to true if the number is equal to the position of the
12135
 * context node in the context node list (as returned by the position
12136
 * function) and will be converted to false otherwise; if the result
12137
 * is not a number, then the result will be converted as if by a call
12138
 * to the boolean function.
12139
 *
12140
 * Returns 1 if predicate is true, 0 otherwise
12141
 */
12142
int
12143
17.1k
xmlXPathEvalPredicate(xmlXPathContextPtr ctxt, xmlXPathObjectPtr res) {
12144
17.1k
    if ((ctxt == NULL) || (res == NULL)) return(0);
12145
17.1k
    switch (res->type) {
12146
7.28k
        case XPATH_BOOLEAN:
12147
7.28k
      return(res->boolval);
12148
5.92k
        case XPATH_NUMBER:
12149
5.92k
      return(res->floatval == ctxt->proximityPosition);
12150
3.01k
        case XPATH_NODESET:
12151
3.01k
        case XPATH_XSLT_TREE:
12152
3.01k
      if (res->nodesetval == NULL)
12153
1
    return(0);
12154
3.01k
      return(res->nodesetval->nodeNr != 0);
12155
930
        case XPATH_STRING:
12156
930
      return((res->stringval != NULL) &&
12157
930
             (xmlStrlen(res->stringval) != 0));
12158
0
        default:
12159
0
      break;
12160
17.1k
    }
12161
0
    return(0);
12162
17.1k
}
12163
12164
/**
12165
 * xmlXPathEvaluatePredicateResult:
12166
 * @ctxt:  the XPath Parser context
12167
 * @res:  the Predicate Expression evaluation result
12168
 *
12169
 * Evaluate a predicate result for the current node.
12170
 * A PredicateExpr is evaluated by evaluating the Expr and converting
12171
 * the result to a boolean. If the result is a number, the result will
12172
 * be converted to true if the number is equal to the position of the
12173
 * context node in the context node list (as returned by the position
12174
 * function) and will be converted to false otherwise; if the result
12175
 * is not a number, then the result will be converted as if by a call
12176
 * to the boolean function.
12177
 *
12178
 * Returns 1 if predicate is true, 0 otherwise
12179
 */
12180
int
12181
xmlXPathEvaluatePredicateResult(xmlXPathParserContextPtr ctxt,
12182
392k
                                xmlXPathObjectPtr res) {
12183
392k
    if ((ctxt == NULL) || (res == NULL)) return(0);
12184
392k
    switch (res->type) {
12185
0
        case XPATH_BOOLEAN:
12186
0
      return(res->boolval);
12187
137k
        case XPATH_NUMBER:
12188
#if defined(__BORLANDC__) || (defined(_MSC_VER) && (_MSC_VER == 1200))
12189
      return((res->floatval == ctxt->context->proximityPosition) &&
12190
             (!xmlXPathIsNaN(res->floatval))); /* MSC pbm Mark Vakoc !*/
12191
#else
12192
137k
      return(res->floatval == ctxt->context->proximityPosition);
12193
0
#endif
12194
78.1k
        case XPATH_NODESET:
12195
78.9k
        case XPATH_XSLT_TREE:
12196
78.9k
      if (res->nodesetval == NULL)
12197
0
    return(0);
12198
78.9k
      return(res->nodesetval->nodeNr != 0);
12199
176k
        case XPATH_STRING:
12200
176k
      return((res->stringval != NULL) && (res->stringval[0] != 0));
12201
0
        default:
12202
0
      break;
12203
392k
    }
12204
0
    return(0);
12205
392k
}
12206
12207
#ifdef XPATH_STREAMING
12208
/**
12209
 * xmlXPathTryStreamCompile:
12210
 * @ctxt: an XPath context
12211
 * @str:  the XPath expression
12212
 *
12213
 * Try to compile the XPath expression as a streamable subset.
12214
 *
12215
 * Returns the compiled expression or NULL if failed to compile.
12216
 */
12217
static xmlXPathCompExprPtr
12218
xmlXPathTryStreamCompile(xmlXPathContextPtr ctxt, const xmlChar *str) {
12219
    /*
12220
     * Optimization: use streaming patterns when the XPath expression can
12221
     * be compiled to a stream lookup
12222
     */
12223
    xmlPatternPtr stream;
12224
    xmlXPathCompExprPtr comp;
12225
    xmlDictPtr dict = NULL;
12226
    const xmlChar **namespaces = NULL;
12227
    xmlNsPtr ns;
12228
    int i, j;
12229
12230
    if ((!xmlStrchr(str, '[')) && (!xmlStrchr(str, '(')) &&
12231
        (!xmlStrchr(str, '@'))) {
12232
  const xmlChar *tmp;
12233
        int res;
12234
12235
  /*
12236
   * We don't try to handle expressions using the verbose axis
12237
   * specifiers ("::"), just the simplified form at this point.
12238
   * Additionally, if there is no list of namespaces available and
12239
   *  there's a ":" in the expression, indicating a prefixed QName,
12240
   *  then we won't try to compile either. xmlPatterncompile() needs
12241
   *  to have a list of namespaces at compilation time in order to
12242
   *  compile prefixed name tests.
12243
   */
12244
  tmp = xmlStrchr(str, ':');
12245
  if ((tmp != NULL) &&
12246
      ((ctxt == NULL) || (ctxt->nsNr == 0) || (tmp[1] == ':')))
12247
      return(NULL);
12248
12249
  if (ctxt != NULL) {
12250
      dict = ctxt->dict;
12251
      if (ctxt->nsNr > 0) {
12252
    namespaces = xmlMalloc(2 * (ctxt->nsNr + 1) * sizeof(xmlChar*));
12253
    if (namespaces == NULL) {
12254
        xmlXPathErrMemory(ctxt);
12255
        return(NULL);
12256
    }
12257
    for (i = 0, j = 0; (j < ctxt->nsNr); j++) {
12258
        ns = ctxt->namespaces[j];
12259
        namespaces[i++] = ns->href;
12260
        namespaces[i++] = ns->prefix;
12261
    }
12262
    namespaces[i++] = NULL;
12263
    namespaces[i] = NULL;
12264
      }
12265
  }
12266
12267
  res = xmlPatternCompileSafe(str, dict, XML_PATTERN_XPATH, namespaces,
12268
                                    &stream);
12269
  if (namespaces != NULL) {
12270
      xmlFree((xmlChar **)namespaces);
12271
  }
12272
        if (res < 0) {
12273
            xmlXPathErrMemory(ctxt);
12274
            return(NULL);
12275
        }
12276
  if ((stream != NULL) && (xmlPatternStreamable(stream) == 1)) {
12277
      comp = xmlXPathNewCompExpr();
12278
      if (comp == NULL) {
12279
    xmlXPathErrMemory(ctxt);
12280
          xmlFreePattern(stream);
12281
    return(NULL);
12282
      }
12283
      comp->stream = stream;
12284
      comp->dict = dict;
12285
      if (comp->dict)
12286
    xmlDictReference(comp->dict);
12287
      return(comp);
12288
  }
12289
  xmlFreePattern(stream);
12290
    }
12291
    return(NULL);
12292
}
12293
#endif /* XPATH_STREAMING */
12294
12295
static void
12296
xmlXPathOptimizeExpression(xmlXPathParserContextPtr pctxt,
12297
                           xmlXPathStepOpPtr op)
12298
5.35M
{
12299
5.35M
    xmlXPathCompExprPtr comp = pctxt->comp;
12300
5.35M
    xmlXPathContextPtr ctxt;
12301
12302
    /*
12303
    * Try to rewrite "descendant-or-self::node()/foo" to an optimized
12304
    * internal representation.
12305
    */
12306
12307
5.35M
    if ((op->op == XPATH_OP_COLLECT /* 11 */) &&
12308
1.20M
        (op->ch1 != -1) &&
12309
1.20M
        (op->ch2 == -1 /* no predicate */))
12310
1.14M
    {
12311
1.14M
        xmlXPathStepOpPtr prevop = &comp->steps[op->ch1];
12312
12313
1.14M
        if ((prevop->op == XPATH_OP_COLLECT /* 11 */) &&
12314
225k
            ((xmlXPathAxisVal) prevop->value ==
12315
225k
                AXIS_DESCENDANT_OR_SELF) &&
12316
106k
            (prevop->ch2 == -1) &&
12317
106k
            ((xmlXPathTestVal) prevop->value2 == NODE_TEST_TYPE) &&
12318
106k
            ((xmlXPathTypeVal) prevop->value3 == NODE_TYPE_NODE))
12319
106k
        {
12320
            /*
12321
            * This is a "descendant-or-self::node()" without predicates.
12322
            * Try to eliminate it.
12323
            */
12324
12325
106k
            switch ((xmlXPathAxisVal) op->value) {
12326
96.5k
                case AXIS_CHILD:
12327
96.5k
                case AXIS_DESCENDANT:
12328
                    /*
12329
                    * Convert "descendant-or-self::node()/child::" or
12330
                    * "descendant-or-self::node()/descendant::" to
12331
                    * "descendant::"
12332
                    */
12333
96.5k
                    op->ch1   = prevop->ch1;
12334
96.5k
                    op->value = AXIS_DESCENDANT;
12335
96.5k
                    break;
12336
50
                case AXIS_SELF:
12337
2.48k
                case AXIS_DESCENDANT_OR_SELF:
12338
                    /*
12339
                    * Convert "descendant-or-self::node()/self::" or
12340
                    * "descendant-or-self::node()/descendant-or-self::" to
12341
                    * to "descendant-or-self::"
12342
                    */
12343
2.48k
                    op->ch1   = prevop->ch1;
12344
2.48k
                    op->value = AXIS_DESCENDANT_OR_SELF;
12345
2.48k
                    break;
12346
7.22k
                default:
12347
7.22k
                    break;
12348
106k
            }
12349
106k
  }
12350
1.14M
    }
12351
12352
    /* OP_VALUE has invalid ch1. */
12353
5.35M
    if (op->op == XPATH_OP_VALUE)
12354
201k
        return;
12355
12356
    /* Recurse */
12357
5.15M
    ctxt = pctxt->context;
12358
5.15M
    if (ctxt != NULL) {
12359
5.15M
        if (ctxt->depth >= XPATH_MAX_RECURSION_DEPTH)
12360
2.40k
            return;
12361
5.15M
        ctxt->depth += 1;
12362
5.15M
    }
12363
5.15M
    if (op->ch1 != -1)
12364
3.47M
        xmlXPathOptimizeExpression(pctxt, &comp->steps[op->ch1]);
12365
5.15M
    if (op->ch2 != -1)
12366
1.55M
  xmlXPathOptimizeExpression(pctxt, &comp->steps[op->ch2]);
12367
5.15M
    if (ctxt != NULL)
12368
5.15M
        ctxt->depth -= 1;
12369
5.15M
}
12370
12371
/**
12372
 * xmlXPathCtxtCompile:
12373
 * @ctxt: an XPath context
12374
 * @str:  the XPath expression
12375
 *
12376
 * Compile an XPath expression
12377
 *
12378
 * Returns the xmlXPathCompExprPtr resulting from the compilation or NULL.
12379
 *         the caller has to free the object.
12380
 */
12381
xmlXPathCompExprPtr
12382
610k
xmlXPathCtxtCompile(xmlXPathContextPtr ctxt, const xmlChar *str) {
12383
610k
    xmlXPathParserContextPtr pctxt;
12384
610k
    xmlXPathContextPtr tmpctxt = NULL;
12385
610k
    xmlXPathCompExprPtr comp;
12386
610k
    int oldDepth = 0;
12387
12388
#ifdef XPATH_STREAMING
12389
    comp = xmlXPathTryStreamCompile(ctxt, str);
12390
    if (comp != NULL)
12391
        return(comp);
12392
#endif
12393
12394
610k
    xmlInitParser();
12395
12396
    /*
12397
     * We need an xmlXPathContext for the depth check.
12398
     */
12399
610k
    if (ctxt == NULL) {
12400
0
        tmpctxt = xmlXPathNewContext(NULL);
12401
0
        if (tmpctxt == NULL)
12402
0
            return(NULL);
12403
0
        ctxt = tmpctxt;
12404
0
    }
12405
12406
610k
    pctxt = xmlXPathNewParserContext(str, ctxt);
12407
610k
    if (pctxt == NULL) {
12408
173
        if (tmpctxt != NULL)
12409
0
            xmlXPathFreeContext(tmpctxt);
12410
173
        return NULL;
12411
173
    }
12412
12413
610k
    oldDepth = ctxt->depth;
12414
610k
    xmlXPathCompileExpr(pctxt, 1);
12415
610k
    ctxt->depth = oldDepth;
12416
12417
610k
    if( pctxt->error != XPATH_EXPRESSION_OK )
12418
232k
    {
12419
232k
        xmlXPathFreeParserContext(pctxt);
12420
232k
        if (tmpctxt != NULL)
12421
0
            xmlXPathFreeContext(tmpctxt);
12422
232k
        return(NULL);
12423
232k
    }
12424
12425
377k
    if (*pctxt->cur != 0) {
12426
  /*
12427
   * aleksey: in some cases this line prints *second* error message
12428
   * (see bug #78858) and probably this should be fixed.
12429
   * However, we are not sure that all error messages are printed
12430
   * out in other places. It's not critical so we leave it as-is for now
12431
   */
12432
78.9k
  xmlXPatherror(pctxt, __FILE__, __LINE__, XPATH_EXPR_ERROR);
12433
78.9k
  comp = NULL;
12434
298k
    } else {
12435
298k
  comp = pctxt->comp;
12436
298k
  if ((comp->nbStep > 1) && (comp->last >= 0)) {
12437
288k
            if (ctxt != NULL)
12438
288k
                oldDepth = ctxt->depth;
12439
288k
      xmlXPathOptimizeExpression(pctxt, &comp->steps[comp->last]);
12440
288k
            if (ctxt != NULL)
12441
288k
                ctxt->depth = oldDepth;
12442
288k
  }
12443
298k
  pctxt->comp = NULL;
12444
298k
    }
12445
377k
    xmlXPathFreeParserContext(pctxt);
12446
377k
    if (tmpctxt != NULL)
12447
0
        xmlXPathFreeContext(tmpctxt);
12448
12449
377k
    if (comp != NULL) {
12450
298k
  comp->expr = xmlStrdup(str);
12451
298k
    }
12452
377k
    return(comp);
12453
610k
}
12454
12455
/**
12456
 * xmlXPathCompile:
12457
 * @str:  the XPath expression
12458
 *
12459
 * Compile an XPath expression
12460
 *
12461
 * Returns the xmlXPathCompExprPtr resulting from the compilation or NULL.
12462
 *         the caller has to free the object.
12463
 */
12464
xmlXPathCompExprPtr
12465
0
xmlXPathCompile(const xmlChar *str) {
12466
0
    return(xmlXPathCtxtCompile(NULL, str));
12467
0
}
12468
12469
/**
12470
 * xmlXPathCompiledEvalInternal:
12471
 * @comp:  the compiled XPath expression
12472
 * @ctxt:  the XPath context
12473
 * @resObj: the resulting XPath object or NULL
12474
 * @toBool: 1 if only a boolean result is requested
12475
 *
12476
 * Evaluate the Precompiled XPath expression in the given context.
12477
 * The caller has to free @resObj.
12478
 *
12479
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
12480
 *         the caller has to free the object.
12481
 */
12482
static int
12483
xmlXPathCompiledEvalInternal(xmlXPathCompExprPtr comp,
12484
           xmlXPathContextPtr ctxt,
12485
           xmlXPathObjectPtr *resObjPtr,
12486
           int toBool)
12487
3.33M
{
12488
3.33M
    xmlXPathParserContextPtr pctxt;
12489
3.33M
    xmlXPathObjectPtr resObj = NULL;
12490
3.33M
    int res;
12491
12492
3.33M
    if (comp == NULL)
12493
390
  return(-1);
12494
3.33M
    xmlInitParser();
12495
12496
3.33M
    xmlResetError(&ctxt->lastError);
12497
12498
3.33M
    pctxt = xmlXPathCompParserContext(comp, ctxt);
12499
3.33M
    if (pctxt == NULL)
12500
98.5k
        return(-1);
12501
3.23M
    res = xmlXPathRunEval(pctxt, toBool);
12502
12503
3.23M
    if (pctxt->error == XPATH_EXPRESSION_OK) {
12504
2.27M
        if (pctxt->valueNr != ((toBool) ? 0 : 1))
12505
0
            xmlXPathErr(pctxt, XPATH_STACK_ERROR);
12506
2.27M
        else if (!toBool)
12507
2.26M
            resObj = xmlXPathValuePop(pctxt);
12508
2.27M
    }
12509
12510
3.23M
    if (resObjPtr)
12511
3.22M
        *resObjPtr = resObj;
12512
10.2k
    else
12513
10.2k
        xmlXPathReleaseObject(ctxt, resObj);
12514
12515
3.23M
    pctxt->comp = NULL;
12516
3.23M
    xmlXPathFreeParserContext(pctxt);
12517
12518
3.23M
    return(res);
12519
3.33M
}
12520
12521
/**
12522
 * xmlXPathCompiledEval:
12523
 * @comp:  the compiled XPath expression
12524
 * @ctx:  the XPath context
12525
 *
12526
 * Evaluate the Precompiled XPath expression in the given context.
12527
 *
12528
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
12529
 *         the caller has to free the object.
12530
 */
12531
xmlXPathObjectPtr
12532
xmlXPathCompiledEval(xmlXPathCompExprPtr comp, xmlXPathContextPtr ctx)
12533
3.32M
{
12534
3.32M
    xmlXPathObjectPtr res = NULL;
12535
12536
3.32M
    xmlXPathCompiledEvalInternal(comp, ctx, &res, 0);
12537
3.32M
    return(res);
12538
3.32M
}
12539
12540
/**
12541
 * xmlXPathCompiledEvalToBoolean:
12542
 * @comp:  the compiled XPath expression
12543
 * @ctxt:  the XPath context
12544
 *
12545
 * Applies the XPath boolean() function on the result of the given
12546
 * compiled expression.
12547
 *
12548
 * Returns 1 if the expression evaluated to true, 0 if to false and
12549
 *         -1 in API and internal errors.
12550
 */
12551
int
12552
xmlXPathCompiledEvalToBoolean(xmlXPathCompExprPtr comp,
12553
            xmlXPathContextPtr ctxt)
12554
10.2k
{
12555
10.2k
    return(xmlXPathCompiledEvalInternal(comp, ctxt, NULL, 1));
12556
10.2k
}
12557
12558
/**
12559
 * xmlXPathEvalExpr:
12560
 * @ctxt:  the XPath Parser context
12561
 *
12562
 * DEPRECATED: Internal function, don't use.
12563
 *
12564
 * Parse and evaluate an XPath expression in the given context,
12565
 * then push the result on the context stack
12566
 */
12567
void
12568
38.1k
xmlXPathEvalExpr(xmlXPathParserContextPtr ctxt) {
12569
#ifdef XPATH_STREAMING
12570
    xmlXPathCompExprPtr comp;
12571
#endif
12572
38.1k
    int oldDepth = 0;
12573
12574
38.1k
    if ((ctxt == NULL) || (ctxt->context == NULL))
12575
0
        return;
12576
38.1k
    if (ctxt->context->lastError.code != 0)
12577
77
        return;
12578
12579
#ifdef XPATH_STREAMING
12580
    comp = xmlXPathTryStreamCompile(ctxt->context, ctxt->base);
12581
    if ((comp == NULL) &&
12582
        (ctxt->context->lastError.code == XML_ERR_NO_MEMORY)) {
12583
        xmlXPathPErrMemory(ctxt);
12584
        return;
12585
    }
12586
    if (comp != NULL) {
12587
        if (ctxt->comp != NULL)
12588
      xmlXPathFreeCompExpr(ctxt->comp);
12589
        ctxt->comp = comp;
12590
    } else
12591
#endif
12592
38.0k
    {
12593
38.0k
        if (ctxt->context != NULL)
12594
38.0k
            oldDepth = ctxt->context->depth;
12595
38.0k
  xmlXPathCompileExpr(ctxt, 1);
12596
38.0k
        if (ctxt->context != NULL)
12597
38.0k
            ctxt->context->depth = oldDepth;
12598
38.0k
        CHECK_ERROR;
12599
12600
        /* Check for trailing characters. */
12601
32.9k
        if (*ctxt->cur != 0)
12602
29.5k
            XP_ERROR(XPATH_EXPR_ERROR);
12603
12604
29.5k
  if ((ctxt->comp->nbStep > 1) && (ctxt->comp->last >= 0)) {
12605
29.2k
            if (ctxt->context != NULL)
12606
29.2k
                oldDepth = ctxt->context->depth;
12607
29.2k
      xmlXPathOptimizeExpression(ctxt,
12608
29.2k
    &ctxt->comp->steps[ctxt->comp->last]);
12609
29.2k
            if (ctxt->context != NULL)
12610
29.2k
                ctxt->context->depth = oldDepth;
12611
29.2k
        }
12612
29.5k
    }
12613
12614
0
    xmlXPathRunEval(ctxt, 0);
12615
29.5k
}
12616
12617
/**
12618
 * xmlXPathEval:
12619
 * @str:  the XPath expression
12620
 * @ctx:  the XPath context
12621
 *
12622
 * Evaluate the XPath Location Path in the given context.
12623
 *
12624
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
12625
 *         the caller has to free the object.
12626
 */
12627
xmlXPathObjectPtr
12628
34.9k
xmlXPathEval(const xmlChar *str, xmlXPathContextPtr ctx) {
12629
34.9k
    xmlXPathParserContextPtr ctxt;
12630
34.9k
    xmlXPathObjectPtr res;
12631
12632
34.9k
    if (ctx == NULL)
12633
0
        return(NULL);
12634
12635
34.9k
    xmlInitParser();
12636
12637
34.9k
    xmlResetError(&ctx->lastError);
12638
12639
34.9k
    ctxt = xmlXPathNewParserContext(str, ctx);
12640
34.9k
    if (ctxt == NULL)
12641
1.22k
        return NULL;
12642
33.6k
    xmlXPathEvalExpr(ctxt);
12643
12644
33.6k
    if (ctxt->error != XPATH_EXPRESSION_OK) {
12645
18.8k
  res = NULL;
12646
18.8k
    } else if (ctxt->valueNr != 1) {
12647
0
        xmlXPathErr(ctxt, XPATH_STACK_ERROR);
12648
0
  res = NULL;
12649
14.8k
    } else {
12650
14.8k
  res = xmlXPathValuePop(ctxt);
12651
14.8k
    }
12652
12653
33.6k
    xmlXPathFreeParserContext(ctxt);
12654
33.6k
    return(res);
12655
34.9k
}
12656
12657
/**
12658
 * xmlXPathSetContextNode:
12659
 * @node: the node to to use as the context node
12660
 * @ctx:  the XPath context
12661
 *
12662
 * Sets 'node' as the context node. The node must be in the same
12663
 * document as that associated with the context.
12664
 *
12665
 * Returns -1 in case of error or 0 if successful
12666
 */
12667
int
12668
0
xmlXPathSetContextNode(xmlNodePtr node, xmlXPathContextPtr ctx) {
12669
0
    if ((node == NULL) || (ctx == NULL))
12670
0
        return(-1);
12671
12672
0
    if (node->doc == ctx->doc) {
12673
0
        ctx->node = node;
12674
0
  return(0);
12675
0
    }
12676
0
    return(-1);
12677
0
}
12678
12679
/**
12680
 * xmlXPathNodeEval:
12681
 * @node: the node to to use as the context node
12682
 * @str:  the XPath expression
12683
 * @ctx:  the XPath context
12684
 *
12685
 * Evaluate the XPath Location Path in the given context. The node 'node'
12686
 * is set as the context node. The context node is not restored.
12687
 *
12688
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
12689
 *         the caller has to free the object.
12690
 */
12691
xmlXPathObjectPtr
12692
0
xmlXPathNodeEval(xmlNodePtr node, const xmlChar *str, xmlXPathContextPtr ctx) {
12693
0
    if (str == NULL)
12694
0
        return(NULL);
12695
0
    if (xmlXPathSetContextNode(node, ctx) < 0)
12696
0
        return(NULL);
12697
0
    return(xmlXPathEval(str, ctx));
12698
0
}
12699
12700
/**
12701
 * xmlXPathEvalExpression:
12702
 * @str:  the XPath expression
12703
 * @ctxt:  the XPath context
12704
 *
12705
 * Alias for xmlXPathEval().
12706
 *
12707
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
12708
 *         the caller has to free the object.
12709
 */
12710
xmlXPathObjectPtr
12711
10.1k
xmlXPathEvalExpression(const xmlChar *str, xmlXPathContextPtr ctxt) {
12712
10.1k
    return(xmlXPathEval(str, ctxt));
12713
10.1k
}
12714
12715
/**
12716
 * xmlXPathRegisterAllFunctions:
12717
 * @ctxt:  the XPath context
12718
 *
12719
 * DEPRECATED: No-op since 2.14.0.
12720
 *
12721
 * Registers all default XPath functions in this context
12722
 */
12723
void
12724
xmlXPathRegisterAllFunctions(xmlXPathContextPtr ctxt ATTRIBUTE_UNUSED)
12725
0
{
12726
0
}
12727
12728
#endif /* LIBXML_XPATH_ENABLED */