Coverage Report

Created: 2026-09-01 06:53

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/xpointer.c
Line
Count
Source
1
/*
2
 * xpointer.c : Code to handle XML Pointer
3
 *
4
 * Base implementation was made accordingly to
5
 * W3C Candidate Recommendation 7 June 2000
6
 * http://www.w3.org/TR/2000/CR-xptr-20000607
7
 *
8
 * Added support for the element() scheme described in:
9
 * W3C Proposed Recommendation 13 November 2002
10
 * http://www.w3.org/TR/2002/PR-xptr-element-20021113/
11
 *
12
 * See Copyright for the status of this software.
13
 *
14
 * daniel@veillard.com
15
 */
16
17
/* To avoid EBCDIC trouble when parsing on zOS */
18
#if defined(__MVS__)
19
#pragma convert("ISO8859-1")
20
#endif
21
22
#define IN_LIBXML
23
#include "libxml.h"
24
25
/*
26
 * TODO: better handling of error cases, the full expression should
27
 *       be parsed beforehand instead of a progressive evaluation
28
 * TODO: Access into entities references are not supported now ...
29
 *       need a start to be able to pop out of entities refs since
30
 *       parent is the entity declaration, not the ref.
31
 */
32
33
#include <string.h>
34
#include <libxml/xpointer.h>
35
#include <libxml/xmlmemory.h>
36
#include <libxml/parserInternals.h>
37
#include <libxml/uri.h>
38
#include <libxml/xpath.h>
39
#include <libxml/xpathInternals.h>
40
#include <libxml/xmlerror.h>
41
42
#ifdef LIBXML_XPTR_ENABLED
43
44
/* Add support of the xmlns() xpointer scheme to initialize the namespaces */
45
#define XPTR_XMLNS_SCHEME
46
47
#include "private/error.h"
48
#include "private/xpath.h"
49
50
/************************************************************************
51
 *                  *
52
 *    Some factorized error routines        *
53
 *                  *
54
 ************************************************************************/
55
56
/**
57
 * xmlXPtrErr:
58
 * @ctxt:  an XPTR evaluation context
59
 * @extra:  extra information
60
 *
61
 * Handle an XPointer error
62
 */
63
static void LIBXML_ATTR_FORMAT(3,0)
64
xmlXPtrErr(xmlXPathParserContextPtr ctxt, int code,
65
           const char * msg, const xmlChar *extra)
66
4.94k
{
67
4.94k
    xmlStructuredErrorFunc serror = NULL;
68
4.94k
    void *data = NULL;
69
4.94k
    xmlNodePtr node = NULL;
70
4.94k
    int res;
71
72
4.94k
    if (ctxt == NULL)
73
0
        return;
74
    /* Only report the first error */
75
4.94k
    if (ctxt->error != 0)
76
4
        return;
77
78
4.94k
    ctxt->error = code;
79
80
4.94k
    if (ctxt->context != NULL) {
81
4.94k
        xmlErrorPtr err = &ctxt->context->lastError;
82
83
        /* cleanup current last error */
84
4.94k
        xmlResetError(err);
85
86
4.94k
        err->domain = XML_FROM_XPOINTER;
87
4.94k
        err->code = code;
88
4.94k
        err->level = XML_ERR_ERROR;
89
4.94k
        err->str1 = (char *) xmlStrdup(ctxt->base);
90
4.94k
        if (err->str1 == NULL) {
91
2
            xmlXPathPErrMemory(ctxt);
92
2
            return;
93
2
        }
94
4.94k
        err->int1 = ctxt->cur - ctxt->base;
95
4.94k
        err->node = ctxt->context->debugNode;
96
97
4.94k
        serror = ctxt->context->error;
98
4.94k
        data = ctxt->context->userData;
99
4.94k
        node = ctxt->context->debugNode;
100
4.94k
    }
101
102
4.94k
    res = xmlRaiseError(serror, NULL, data, NULL, node,
103
4.94k
                        XML_FROM_XPOINTER, code, XML_ERR_ERROR, NULL, 0,
104
4.94k
                        (const char *) extra, (const char *) ctxt->base,
105
4.94k
                        NULL, ctxt->cur - ctxt->base, 0,
106
4.94k
                        msg, extra);
107
4.94k
    if (res < 0)
108
5
        xmlXPathPErrMemory(ctxt);
109
4.94k
}
110
111
/************************************************************************
112
 *                  *
113
 *    A few helper functions for child sequences    *
114
 *                  *
115
 ************************************************************************/
116
117
/**
118
 * xmlXPtrGetNthChild:
119
 * @cur:  the node
120
 * @no:  the child number
121
 *
122
 * Returns the @no'th element child of @cur or NULL
123
 */
124
static xmlNodePtr
125
1.03k
xmlXPtrGetNthChild(xmlNodePtr cur, int no) {
126
1.03k
    int i;
127
1.03k
    if ((cur == NULL) || (cur->type == XML_NAMESPACE_DECL))
128
0
  return(cur);
129
1.03k
    cur = cur->children;
130
2.27k
    for (i = 0;i <= no;cur = cur->next) {
131
2.27k
  if (cur == NULL)
132
333
      return(cur);
133
1.93k
  if ((cur->type == XML_ELEMENT_NODE) ||
134
899
      (cur->type == XML_DOCUMENT_NODE) ||
135
1.03k
      (cur->type == XML_HTML_DOCUMENT_NODE)) {
136
1.03k
      i++;
137
1.03k
      if (i == no)
138
706
    break;
139
1.03k
  }
140
1.93k
    }
141
706
    return(cur);
142
1.03k
}
143
144
/************************************************************************
145
 *                  *
146
 *      The parser          *
147
 *                  *
148
 ************************************************************************/
149
150
static void xmlXPtrEvalChildSeq(xmlXPathParserContextPtr ctxt, xmlChar *name);
151
152
/*
153
 * Macros for accessing the content. Those should be used only by the parser,
154
 * and not exported.
155
 *
156
 * Dirty macros, i.e. one need to make assumption on the context to use them
157
 *
158
 *   CUR     returns the current xmlChar value, i.e. a 8 bit value
159
 *           in ISO-Latin or UTF-8.
160
 *           This should be used internally by the parser
161
 *           only to compare to ASCII values otherwise it would break when
162
 *           running with UTF-8 encoding.
163
 *   NXT(n)  returns the n'th next xmlChar. Same as CUR is should be used only
164
 *           to compare on ASCII based substring.
165
 *   SKIP(n) Skip n xmlChar, and must also be used only to skip ASCII defined
166
 *           strings within the parser.
167
 *   CURRENT Returns the current char value, with the full decoding of
168
 *           UTF-8 if we are using this mode. It returns an int.
169
 *   NEXT    Skip to the next character, this does the proper decoding
170
 *           in UTF-8 mode. It also pop-up unfinished entities on the fly.
171
 *           It returns the pointer to the current xmlChar.
172
 */
173
174
937k
#define CUR (*ctxt->cur)
175
#define SKIP(val) ctxt->cur += (val)
176
2.38k
#define NXT(val) ctxt->cur[(val)]
177
178
#define SKIP_BLANKS             \
179
29.9k
    while (IS_BLANK_CH(*(ctxt->cur))) NEXT
180
181
#define CURRENT (*ctxt->cur)
182
248k
#define NEXT ((*ctxt->cur) ?  ctxt->cur++: ctxt->cur)
183
184
/*
185
 * xmlXPtrGetChildNo:
186
 * @ctxt:  the XPointer Parser context
187
 * @index:  the child number
188
 *
189
 * Move the current node of the nodeset on the stack to the
190
 * given child if found
191
 */
192
static void
193
2.79k
xmlXPtrGetChildNo(xmlXPathParserContextPtr ctxt, int indx) {
194
2.79k
    xmlNodePtr cur = NULL;
195
2.79k
    xmlXPathObjectPtr obj;
196
2.79k
    xmlNodeSetPtr oldset;
197
198
2.79k
    CHECK_TYPE(XPATH_NODESET);
199
2.53k
    obj = xmlXPathValuePop(ctxt);
200
2.53k
    oldset = obj->nodesetval;
201
2.53k
    if ((indx <= 0) || (oldset == NULL) || (oldset->nodeNr != 1)) {
202
1.49k
  xmlXPathFreeObject(obj);
203
1.49k
  xmlXPathValuePush(ctxt, xmlXPathNewNodeSet(NULL));
204
1.49k
  return;
205
1.49k
    }
206
1.03k
    cur = xmlXPtrGetNthChild(oldset->nodeTab[0], indx);
207
1.03k
    if (cur == NULL) {
208
333
  xmlXPathFreeObject(obj);
209
333
  xmlXPathValuePush(ctxt, xmlXPathNewNodeSet(NULL));
210
333
  return;
211
333
    }
212
706
    oldset->nodeTab[0] = cur;
213
706
    xmlXPathValuePush(ctxt, obj);
214
706
}
215
216
/**
217
 * xmlXPtrEvalXPtrPart:
218
 * @ctxt:  the XPointer Parser context
219
 * @name:  the preparsed Scheme for the XPtrPart
220
 *
221
 * XPtrPart ::= 'xpointer' '(' XPtrExpr ')'
222
 *            | Scheme '(' SchemeSpecificExpr ')'
223
 *
224
 * Scheme   ::=  NCName - 'xpointer' [VC: Non-XPointer schemes]
225
 *
226
 * SchemeSpecificExpr ::= StringWithBalancedParens
227
 *
228
 * StringWithBalancedParens ::=
229
 *              [^()]* ('(' StringWithBalancedParens ')' [^()]*)*
230
 *              [VC: Parenthesis escaping]
231
 *
232
 * XPtrExpr ::= Expr [VC: Parenthesis escaping]
233
 *
234
 * VC: Parenthesis escaping:
235
 *   The end of an XPointer part is signaled by the right parenthesis ")"
236
 *   character that is balanced with the left parenthesis "(" character
237
 *   that began the part. Any unbalanced parenthesis character inside the
238
 *   expression, even within literals, must be escaped with a circumflex (^)
239
 *   character preceding it. If the expression contains any literal
240
 *   occurrences of the circumflex, each must be escaped with an additional
241
 *   circumflex (that is, ^^). If the unescaped parentheses in the expression
242
 *   are not balanced, a syntax error results.
243
 *
244
 * Parse and evaluate an XPtrPart. Basically it generates the unescaped
245
 * string and if the scheme is 'xpointer' it will call the XPath interpreter.
246
 *
247
 * TODO: there is no new scheme registration mechanism
248
 */
249
250
static void
251
12.1k
xmlXPtrEvalXPtrPart(xmlXPathParserContextPtr ctxt, xmlChar *name) {
252
12.1k
    xmlChar *buffer, *cur;
253
12.1k
    int len;
254
12.1k
    int level;
255
256
12.1k
    if (name == NULL)
257
0
    name = xmlXPathParseName(ctxt);
258
12.1k
    if (name == NULL)
259
12.1k
  XP_ERROR(XPATH_EXPR_ERROR);
260
261
12.1k
    if (CUR != '(') {
262
314
        xmlFree(name);
263
314
  XP_ERROR(XPATH_EXPR_ERROR);
264
0
    }
265
11.8k
    NEXT;
266
11.8k
    level = 1;
267
268
11.8k
    len = xmlStrlen(ctxt->cur);
269
11.8k
    len++;
270
11.8k
    buffer = xmlMalloc(len);
271
11.8k
    if (buffer == NULL) {
272
5
        xmlXPathPErrMemory(ctxt);
273
5
        xmlFree(name);
274
5
  return;
275
5
    }
276
277
11.8k
    cur = buffer;
278
178k
    while (CUR != 0) {
279
177k
  if (CUR == ')') {
280
13.8k
      level--;
281
13.8k
      if (level == 0) {
282
11.0k
    NEXT;
283
11.0k
    break;
284
11.0k
      }
285
163k
  } else if (CUR == '(') {
286
2.85k
      level++;
287
160k
  } else if (CUR == '^') {
288
540
            if ((NXT(1) == ')') || (NXT(1) == '(') || (NXT(1) == '^')) {
289
466
                NEXT;
290
466
            }
291
540
  }
292
166k
        *cur++ = CUR;
293
166k
  NEXT;
294
166k
    }
295
11.8k
    *cur = 0;
296
297
11.8k
    if ((level != 0) && (CUR == 0)) {
298
848
        xmlFree(name);
299
848
  xmlFree(buffer);
300
848
  XP_ERROR(XPTR_SYNTAX_ERROR);
301
0
    }
302
303
11.0k
    if (xmlStrEqual(name, (xmlChar *) "xpointer") ||
304
10.8k
        xmlStrEqual(name, (xmlChar *) "xpath1")) {
305
2.92k
  const xmlChar *oldBase = ctxt->base;
306
2.92k
  const xmlChar *oldCur = ctxt->cur;
307
308
2.92k
  ctxt->cur = ctxt->base = buffer;
309
  /*
310
   * To evaluate an xpointer scheme element (4.3) we need:
311
   *   context initialized to the root
312
   *   context position initialized to 1
313
   *   context size initialized to 1
314
   */
315
2.92k
  ctxt->context->node = (xmlNodePtr)ctxt->context->doc;
316
2.92k
  ctxt->context->proximityPosition = 1;
317
2.92k
  ctxt->context->contextSize = 1;
318
2.92k
  xmlXPathEvalExpr(ctxt);
319
2.92k
  ctxt->base = oldBase;
320
2.92k
        ctxt->cur = oldCur;
321
8.09k
    } else if (xmlStrEqual(name, (xmlChar *) "element")) {
322
767
  const xmlChar *oldBase = ctxt->base;
323
767
  const xmlChar *oldCur = ctxt->cur;
324
767
  xmlChar *name2;
325
326
767
  ctxt->cur = ctxt->base = buffer;
327
767
  if (buffer[0] == '/') {
328
293
      xmlXPathRoot(ctxt);
329
293
      xmlXPtrEvalChildSeq(ctxt, NULL);
330
474
  } else {
331
474
      name2 = xmlXPathParseName(ctxt);
332
474
      if (name2 == NULL) {
333
210
                ctxt->base = oldBase;
334
210
                ctxt->cur = oldCur;
335
210
    xmlFree(buffer);
336
210
                xmlFree(name);
337
210
    XP_ERROR(XPATH_EXPR_ERROR);
338
0
      }
339
264
      xmlXPtrEvalChildSeq(ctxt, name2);
340
264
  }
341
557
  ctxt->base = oldBase;
342
557
        ctxt->cur = oldCur;
343
557
#ifdef XPTR_XMLNS_SCHEME
344
7.33k
    } else if (xmlStrEqual(name, (xmlChar *) "xmlns")) {
345
2.75k
  const xmlChar *oldBase = ctxt->base;
346
2.75k
  const xmlChar *oldCur = ctxt->cur;
347
2.75k
  xmlChar *prefix;
348
349
2.75k
  ctxt->cur = ctxt->base = buffer;
350
2.75k
        prefix = xmlXPathParseNCName(ctxt);
351
2.75k
  if (prefix == NULL) {
352
54
            ctxt->base = oldBase;
353
54
            ctxt->cur = oldCur;
354
54
      xmlFree(buffer);
355
54
      xmlFree(name);
356
54
      XP_ERROR(XPTR_SYNTAX_ERROR);
357
0
  }
358
2.70k
  SKIP_BLANKS;
359
2.70k
  if (CUR != '=') {
360
640
            ctxt->base = oldBase;
361
640
            ctxt->cur = oldCur;
362
640
      xmlFree(prefix);
363
640
      xmlFree(buffer);
364
640
      xmlFree(name);
365
640
      XP_ERROR(XPTR_SYNTAX_ERROR);
366
0
  }
367
2.06k
  NEXT;
368
2.06k
  SKIP_BLANKS;
369
370
2.06k
  if (xmlXPathRegisterNs(ctxt->context, prefix, ctxt->cur) < 0)
371
4
            xmlXPathPErrMemory(ctxt);
372
2.06k
        ctxt->base = oldBase;
373
2.06k
        ctxt->cur = oldCur;
374
2.06k
  xmlFree(prefix);
375
2.06k
#endif /* XPTR_XMLNS_SCHEME */
376
4.57k
    } else {
377
4.57k
        xmlXPtrErr(ctxt, XML_XPTR_UNKNOWN_SCHEME,
378
4.57k
       "unsupported scheme '%s'\n", name);
379
4.57k
    }
380
10.1k
    xmlFree(buffer);
381
10.1k
    xmlFree(name);
382
10.1k
}
383
384
/**
385
 * xmlXPtrEvalFullXPtr:
386
 * @ctxt:  the XPointer Parser context
387
 * @name:  the preparsed Scheme for the first XPtrPart
388
 *
389
 * FullXPtr ::= XPtrPart (S? XPtrPart)*
390
 *
391
 * As the specs says:
392
 * -----------
393
 * When multiple XPtrParts are provided, they must be evaluated in
394
 * left-to-right order. If evaluation of one part fails, the nexti
395
 * is evaluated. The following conditions cause XPointer part failure:
396
 *
397
 * - An unknown scheme
398
 * - A scheme that does not locate any sub-resource present in the resource
399
 * - A scheme that is not applicable to the media type of the resource
400
 *
401
 * The XPointer application must consume a failed XPointer part and
402
 * attempt to evaluate the next one, if any. The result of the first
403
 * XPointer part whose evaluation succeeds is taken to be the fragment
404
 * located by the XPointer as a whole. If all the parts fail, the result
405
 * for the XPointer as a whole is a sub-resource error.
406
 * -----------
407
 *
408
 * Parse and evaluate a Full XPtr i.e. possibly a cascade of XPath based
409
 * expressions or other schemes.
410
 */
411
static void
412
6.59k
xmlXPtrEvalFullXPtr(xmlXPathParserContextPtr ctxt, xmlChar *name) {
413
6.59k
    if (name == NULL)
414
0
    name = xmlXPathParseName(ctxt);
415
6.59k
    if (name == NULL)
416
6.59k
  XP_ERROR(XPATH_EXPR_ERROR);
417
14.1k
    while (name != NULL) {
418
12.1k
  ctxt->error = XPATH_EXPRESSION_OK;
419
12.1k
  xmlXPtrEvalXPtrPart(ctxt, name);
420
421
  /* in case of syntax error, break here */
422
12.1k
  if ((ctxt->error != XPATH_EXPRESSION_OK) &&
423
8.96k
            (ctxt->error != XML_XPTR_UNKNOWN_SCHEME))
424
4.39k
      return;
425
426
  /*
427
   * If the returned value is a non-empty nodeset
428
   * or location set, return here.
429
   */
430
7.80k
  if (ctxt->value != NULL) {
431
1.09k
      xmlXPathObjectPtr obj = ctxt->value;
432
433
1.09k
      switch (obj->type) {
434
660
    case XPATH_NODESET: {
435
660
        xmlNodeSetPtr loc = ctxt->value->nodesetval;
436
660
        if ((loc != NULL) && (loc->nodeNr > 0))
437
286
      return;
438
374
        break;
439
660
    }
440
434
    default:
441
434
        break;
442
1.09k
      }
443
444
      /*
445
       * Evaluating to improper values is equivalent to
446
       * a sub-resource error, clean-up the stack
447
       */
448
1.61k
      do {
449
1.61k
    obj = xmlXPathValuePop(ctxt);
450
1.61k
    if (obj != NULL) {
451
808
        xmlXPathFreeObject(obj);
452
808
    }
453
1.61k
      } while (obj != NULL);
454
808
  }
455
456
  /*
457
   * Is there another XPointer part.
458
   */
459
7.51k
  SKIP_BLANKS;
460
7.51k
  name = xmlXPathParseName(ctxt);
461
7.51k
    }
462
6.59k
}
463
464
/**
465
 * xmlXPtrEvalChildSeq:
466
 * @ctxt:  the XPointer Parser context
467
 * @name:  a possible ID name of the child sequence
468
 *
469
 *  ChildSeq ::= '/1' ('/' [0-9]*)*
470
 *             | Name ('/' [0-9]*)+
471
 *
472
 * Parse and evaluate a Child Sequence. This routine also handle the
473
 * case of a Bare Name used to get a document ID.
474
 */
475
static void
476
5.16k
xmlXPtrEvalChildSeq(xmlXPathParserContextPtr ctxt, xmlChar *name) {
477
    /*
478
     * XPointer don't allow by syntax to address in multirooted trees
479
     * this might prove useful in some cases, warn about it.
480
     */
481
5.16k
    if ((name == NULL) && (CUR == '/') && (NXT(1) != '1')) {
482
370
        xmlXPtrErr(ctxt, XML_XPTR_CHILDSEQ_START,
483
370
       "warning: ChildSeq not starting by /1\n", NULL);
484
370
    }
485
486
5.16k
    if (name != NULL) {
487
4.08k
  xmlXPathValuePush(ctxt, xmlXPathNewString(name));
488
4.08k
  xmlFree(name);
489
4.08k
  xmlXPathIdFunction(ctxt, 1);
490
4.08k
  CHECK_ERROR;
491
4.08k
    }
492
493
6.87k
    while (CUR == '/') {
494
2.79k
  int child = 0, overflow = 0;
495
2.79k
  NEXT;
496
497
14.3k
  while ((CUR >= '0') && (CUR <= '9')) {
498
11.6k
            int d = CUR - '0';
499
11.6k
            if (child > INT_MAX / 10)
500
5.07k
                overflow = 1;
501
6.53k
            else
502
6.53k
                child *= 10;
503
11.6k
            if (child > INT_MAX - d)
504
120
                overflow = 1;
505
11.4k
            else
506
11.4k
                child += d;
507
11.6k
      NEXT;
508
11.6k
  }
509
2.79k
        if (overflow)
510
355
            child = 0;
511
2.79k
  xmlXPtrGetChildNo(ctxt, child);
512
2.79k
    }
513
4.08k
}
514
515
516
/**
517
 * xmlXPtrEvalXPointer:
518
 * @ctxt:  the XPointer Parser context
519
 *
520
 *  XPointer ::= Name
521
 *             | ChildSeq
522
 *             | FullXPtr
523
 *
524
 * Parse and evaluate an XPointer
525
 */
526
static void
527
13.1k
xmlXPtrEvalXPointer(xmlXPathParserContextPtr ctxt) {
528
13.1k
    if (ctxt->valueTab == NULL) {
529
  /* Allocate the value stack */
530
13.1k
  ctxt->valueTab = (xmlXPathObjectPtr *)
531
13.1k
       xmlMalloc(10 * sizeof(xmlXPathObjectPtr));
532
13.1k
  if (ctxt->valueTab == NULL) {
533
2
      xmlXPathPErrMemory(ctxt);
534
2
      return;
535
2
  }
536
13.1k
  ctxt->valueNr = 0;
537
13.1k
  ctxt->valueMax = 10;
538
13.1k
  ctxt->value = NULL;
539
13.1k
    }
540
13.1k
    SKIP_BLANKS;
541
13.1k
    if (CUR == '/') {
542
791
  xmlXPathRoot(ctxt);
543
791
        xmlXPtrEvalChildSeq(ctxt, NULL);
544
12.3k
    } else {
545
12.3k
  xmlChar *name;
546
547
12.3k
  name = xmlXPathParseName(ctxt);
548
12.3k
  if (name == NULL)
549
10.4k
      XP_ERROR(XPATH_EXPR_ERROR);
550
10.4k
  if (CUR == '(') {
551
6.59k
      xmlXPtrEvalFullXPtr(ctxt, name);
552
      /* Short evaluation */
553
6.59k
      return;
554
6.59k
  } else {
555
      /* this handle both Bare Names and Child Sequences */
556
3.81k
      xmlXPtrEvalChildSeq(ctxt, name);
557
3.81k
  }
558
10.4k
    }
559
4.60k
    SKIP_BLANKS;
560
4.60k
    if (CUR != 0)
561
4.10k
  XP_ERROR(XPATH_EXPR_ERROR);
562
505
}
563
564
565
/************************************************************************
566
 *                  *
567
 *      General routines        *
568
 *                  *
569
 ************************************************************************/
570
571
/**
572
 * xmlXPtrNewContext:
573
 * @doc:  the XML document
574
 * @here:  the node that directly contains the XPointer being evaluated or NULL
575
 * @origin:  the element from which a user or program initiated traversal of
576
 *           the link, or NULL.
577
 *
578
 * Create a new XPointer context
579
 *
580
 * Returns the xmlXPathContext just allocated.
581
 */
582
xmlXPathContextPtr
583
0
xmlXPtrNewContext(xmlDocPtr doc, xmlNodePtr here, xmlNodePtr origin) {
584
0
    xmlXPathContextPtr ret;
585
0
    (void) here;
586
0
    (void) origin;
587
588
0
    ret = xmlXPathNewContext(doc);
589
0
    if (ret == NULL)
590
0
  return(ret);
591
592
0
    return(ret);
593
0
}
594
595
/**
596
 * xmlXPtrEval:
597
 * @str:  the XPointer expression
598
 * @ctx:  the XPointer context
599
 *
600
 * Evaluate the XPath Location Path in the given context.
601
 *
602
 * Returns the xmlXPathObjectPtr resulting from the evaluation or NULL.
603
 *         the caller has to free the object.
604
 */
605
xmlXPathObjectPtr
606
13.1k
xmlXPtrEval(const xmlChar *str, xmlXPathContextPtr ctx) {
607
13.1k
    xmlXPathParserContextPtr ctxt;
608
13.1k
    xmlXPathObjectPtr res = NULL, tmp;
609
13.1k
    xmlXPathObjectPtr init = NULL;
610
13.1k
    int stack = 0;
611
612
13.1k
    xmlInitParser();
613
614
13.1k
    if ((ctx == NULL) || (str == NULL))
615
0
  return(NULL);
616
617
13.1k
    xmlResetError(&ctx->lastError);
618
619
13.1k
    ctxt = xmlXPathNewParserContext(str, ctx);
620
13.1k
    if (ctxt == NULL) {
621
7
        xmlXPathErrMemory(ctx);
622
7
  return(NULL);
623
7
    }
624
13.1k
    xmlXPtrEvalXPointer(ctxt);
625
13.1k
    if (ctx->lastError.code != XML_ERR_OK)
626
11.8k
        goto error;
627
628
1.28k
    if ((ctxt->value != NULL) &&
629
784
  (ctxt->value->type != XPATH_NODESET)) {
630
0
        xmlXPtrErr(ctxt, XML_XPTR_EVAL_FAILED,
631
0
    "xmlXPtrEval: evaluation failed to return a node set\n",
632
0
       NULL);
633
1.28k
    } else {
634
1.28k
  res = xmlXPathValuePop(ctxt);
635
1.28k
    }
636
637
1.28k
    do {
638
1.28k
        tmp = xmlXPathValuePop(ctxt);
639
1.28k
  if (tmp != NULL) {
640
0
      if (tmp != init) {
641
0
    if (tmp->type == XPATH_NODESET) {
642
        /*
643
         * Evaluation may push a root nodeset which is unused
644
         */
645
0
        xmlNodeSetPtr set;
646
0
        set = tmp->nodesetval;
647
0
        if ((set == NULL) || (set->nodeNr != 1) ||
648
0
      (set->nodeTab[0] != (xmlNodePtr) ctx->doc))
649
0
      stack++;
650
0
    } else
651
0
        stack++;
652
0
      }
653
0
      xmlXPathFreeObject(tmp);
654
0
        }
655
1.28k
    } while (tmp != NULL);
656
1.28k
    if (stack != 0) {
657
0
        xmlXPtrErr(ctxt, XML_XPTR_EXTRA_OBJECTS,
658
0
       "xmlXPtrEval: object(s) left on the eval stack\n",
659
0
       NULL);
660
0
    }
661
1.28k
    if (ctx->lastError.code != XML_ERR_OK) {
662
0
  xmlXPathFreeObject(res);
663
0
  res = NULL;
664
0
    }
665
666
13.1k
error:
667
13.1k
    xmlXPathFreeParserContext(ctxt);
668
13.1k
    return(res);
669
1.28k
}
670
671
#endif
672