Coverage Report

Created: 2026-09-18 06:12

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libxml2/xpointer.c
Line
Count
Source
1
/*
2
 * xpointer.c : Code to handle XML Pointer
3
 *
4
 * Base implementation was made accordingly to
5
 * W3C Candidate Recommendation 7 June 2000
6
 * http://www.w3.org/TR/2000/CR-xptr-20000607
7
 *
8
 * Added support for the element() scheme described in:
9
 * W3C Proposed Recommendation 13 November 2002
10
 * http://www.w3.org/TR/2002/PR-xptr-element-20021113/
11
 *
12
 * See Copyright for the status of this software.
13
 *
14
 * Author: Daniel Veillard
15
 */
16
17
/* To avoid EBCDIC trouble when parsing on zOS */
18
#if defined(__MVS__)
19
#pragma convert("ISO8859-1")
20
#endif
21
22
#define IN_LIBXML
23
#include "libxml.h"
24
25
/*
26
 * TODO: better handling of error cases, the full expression should
27
 *       be parsed beforehand instead of a progressive evaluation
28
 * TODO: Access into entities references are not supported now ...
29
 *       need a start to be able to pop out of entities refs since
30
 *       parent is the entity declaration, not the ref.
31
 */
32
33
#include <string.h>
34
#include <libxml/xpointer.h>
35
#include <libxml/xmlmemory.h>
36
#include <libxml/parserInternals.h>
37
#include <libxml/uri.h>
38
#include <libxml/xpath.h>
39
#include <libxml/xpathInternals.h>
40
#include <libxml/xmlerror.h>
41
42
#ifdef LIBXML_XPTR_ENABLED
43
44
/* Add support of the xmlns() xpointer scheme to initialize the namespaces */
45
#define XPTR_XMLNS_SCHEME
46
47
#include "private/error.h"
48
#include "private/xpath.h"
49
50
/************************************************************************
51
 *                  *
52
 *    Some factorized error routines        *
53
 *                  *
54
 ************************************************************************/
55
56
/**
57
 * Handle an XPointer error
58
 *
59
 * @param ctxt  an XPTR evaluation context
60
 * @param code  error code
61
 * @param msg  error message
62
 * @param extra  extra information
63
 */
64
static void LIBXML_ATTR_FORMAT(3,0)
65
xmlXPtrErr(xmlXPathParserContextPtr ctxt, int code,
66
           const char * msg, const xmlChar *extra)
67
1.69k
{
68
1.69k
    xmlStructuredErrorFunc serror = NULL;
69
1.69k
    void *data = NULL;
70
1.69k
    xmlNodePtr node = NULL;
71
1.69k
    int res;
72
73
1.69k
    if (ctxt == NULL)
74
0
        return;
75
    /* Only report the first error */
76
1.69k
    if (ctxt->error != 0)
77
0
        return;
78
79
1.69k
    ctxt->error = code;
80
81
1.69k
    if (ctxt->context != NULL) {
82
1.69k
        xmlErrorPtr err = &ctxt->context->lastError;
83
84
        /* cleanup current last error */
85
1.69k
        xmlResetError(err);
86
87
1.69k
        err->domain = XML_FROM_XPOINTER;
88
1.69k
        err->code = code;
89
1.69k
        err->level = XML_ERR_ERROR;
90
1.69k
        err->str1 = (char *) xmlStrdup(ctxt->base);
91
1.69k
        if (err->str1 == NULL) {
92
0
            xmlXPathPErrMemory(ctxt);
93
0
            return;
94
0
        }
95
1.69k
        err->int1 = ctxt->cur - ctxt->base;
96
1.69k
        err->node = ctxt->context->debugNode;
97
98
1.69k
        serror = ctxt->context->error;
99
1.69k
        data = ctxt->context->userData;
100
1.69k
        node = ctxt->context->debugNode;
101
1.69k
    }
102
103
1.69k
    res = xmlRaiseError(serror, NULL, data, NULL, node,
104
1.69k
                        XML_FROM_XPOINTER, code, XML_ERR_ERROR, NULL, 0,
105
1.69k
                        (const char *) extra, (const char *) ctxt->base,
106
1.69k
                        NULL, ctxt->cur - ctxt->base, 0,
107
1.69k
                        msg, extra);
108
1.69k
    if (res < 0)
109
0
        xmlXPathPErrMemory(ctxt);
110
1.69k
}
111
112
/************************************************************************
113
 *                  *
114
 *    A few helper functions for child sequences    *
115
 *                  *
116
 ************************************************************************/
117
118
/**
119
 * @param cur  the node
120
 * @param no  the child number
121
 * @returns the `no`'th element child of `cur` or NULL
122
 */
123
static xmlNodePtr
124
713
xmlXPtrGetNthChild(xmlNodePtr cur, int no) {
125
713
    int i;
126
713
    if ((cur == NULL) || (cur->type == XML_NAMESPACE_DECL))
127
0
  return(cur);
128
713
    cur = cur->children;
129
1.93k
    for (i = 0;i <= no;cur = cur->next) {
130
1.93k
  if (cur == NULL)
131
603
      return(cur);
132
1.32k
  if ((cur->type == XML_ELEMENT_NODE) ||
133
593
      (cur->type == XML_DOCUMENT_NODE) ||
134
735
      (cur->type == XML_HTML_DOCUMENT_NODE)) {
135
735
      i++;
136
735
      if (i == no)
137
110
    break;
138
735
  }
139
1.32k
    }
140
110
    return(cur);
141
713
}
142
143
/************************************************************************
144
 *                  *
145
 *      The parser          *
146
 *                  *
147
 ************************************************************************/
148
149
static void xmlXPtrEvalChildSeq(xmlXPathParserContextPtr ctxt, xmlChar *name);
150
151
/*
152
 * Macros for accessing the content. Those should be used only by the parser,
153
 * and not exported.
154
 *
155
 * Dirty macros, i.e. one need to make assumption on the context to use them
156
 *
157
 *   CUR     returns the current xmlChar value, i.e. a 8 bit value
158
 *           in ISO-Latin or UTF-8.
159
 *           This should be used internally by the parser
160
 *           only to compare to ASCII values otherwise it would break when
161
 *           running with UTF-8 encoding.
162
 *   NXT(n)  returns the n'th next xmlChar. Same as CUR is should be used only
163
 *           to compare on ASCII based substring.
164
 *   SKIP(n) Skip n xmlChar, and must also be used only to skip ASCII defined
165
 *           strings within the parser.
166
 *   CURRENT Returns the current char value, with the full decoding of
167
 *           UTF-8 if we are using this mode. It returns an int.
168
 *   NEXT    Skip to the next character, this does the proper decoding
169
 *           in UTF-8 mode. It also pop-up unfinished entities on the fly.
170
 *           It returns the pointer to the current xmlChar.
171
 */
172
173
147M
#define CUR (*ctxt->cur)
174
#define SKIP(val) ctxt->cur += (val)
175
89.2k
#define NXT(val) ctxt->cur[(val)]
176
177
#define SKIP_BLANKS             \
178
60.0k
    while (IS_BLANK_CH(*(ctxt->cur))) NEXT
179
180
#define CURRENT (*ctxt->cur)
181
29.6M
#define NEXT ((*ctxt->cur) ?  ctxt->cur++: ctxt->cur)
182
183
/*
184
 * @param ctxt  the XPointer Parser context
185
 * @param index  the child number
186
 *
187
 * Move the current node of the nodeset on the stack to the
188
 * given child if found
189
 */
190
static void
191
1.99k
xmlXPtrGetChildNo(xmlXPathParserContextPtr ctxt, int indx) {
192
1.99k
    xmlNodePtr cur = NULL;
193
1.99k
    xmlXPathObjectPtr obj;
194
1.99k
    xmlNodeSetPtr oldset;
195
196
1.99k
    CHECK_TYPE(XPATH_NODESET);
197
1.99k
    obj = xmlXPathValuePop(ctxt);
198
1.99k
    oldset = obj->nodesetval;
199
1.99k
    if ((indx <= 0) || (oldset == NULL) || (oldset->nodeNr != 1)) {
200
1.27k
  xmlXPathFreeObject(obj);
201
1.27k
  xmlXPathValuePush(ctxt, xmlXPathNewNodeSet(NULL));
202
1.27k
  return;
203
1.27k
    }
204
713
    cur = xmlXPtrGetNthChild(oldset->nodeTab[0], indx);
205
713
    if (cur == NULL) {
206
603
  xmlXPathFreeObject(obj);
207
603
  xmlXPathValuePush(ctxt, xmlXPathNewNodeSet(NULL));
208
603
  return;
209
603
    }
210
110
    oldset->nodeTab[0] = cur;
211
110
    xmlXPathValuePush(ctxt, obj);
212
110
}
213
214
/**
215
 * XPtrPart ::= 'xpointer' '(' XPtrExpr ')'
216
 *            | Scheme '(' SchemeSpecificExpr ')'
217
 *
218
 * Scheme   ::=  NCName - 'xpointer' [VC: Non-XPointer schemes]
219
 *
220
 * SchemeSpecificExpr ::= StringWithBalancedParens
221
 *
222
 * StringWithBalancedParens ::=
223
 *              [^()]* ('(' StringWithBalancedParens ')' [^()]*)*
224
 *              [VC: Parenthesis escaping]
225
 *
226
 * XPtrExpr ::= Expr [VC: Parenthesis escaping]
227
 *
228
 * VC: Parenthesis escaping:
229
 *   The end of an XPointer part is signaled by the right parenthesis ")"
230
 *   character that is balanced with the left parenthesis "(" character
231
 *   that began the part. Any unbalanced parenthesis character inside the
232
 *   expression, even within literals, must be escaped with a circumflex (^)
233
 *   character preceding it. If the expression contains any literal
234
 *   occurrences of the circumflex, each must be escaped with an additional
235
 *   circumflex (that is, ^^). If the unescaped parentheses in the expression
236
 *   are not balanced, a syntax error results.
237
 *
238
 * Parse and evaluate an XPtrPart. Basically it generates the unescaped
239
 * string and if the scheme is 'xpointer' it will call the XPath interpreter.
240
 *
241
 * TODO: there is no new scheme registration mechanism
242
 *
243
 * @param ctxt  the XPointer Parser context
244
 * @param name  the preparsed Scheme for the XPtrPart
245
 */
246
247
static void
248
11.9k
xmlXPtrEvalXPtrPart(xmlXPathParserContextPtr ctxt, xmlChar *name) {
249
11.9k
    xmlChar *buffer, *cur;
250
11.9k
    int len;
251
11.9k
    int level;
252
253
11.9k
    if (name == NULL)
254
0
    name = xmlXPathParseName(ctxt);
255
11.9k
    if (name == NULL)
256
11.9k
  XP_ERROR(XPATH_EXPR_ERROR);
257
258
11.9k
    if (CUR != '(') {
259
188
        xmlFree(name);
260
188
  XP_ERROR(XPATH_EXPR_ERROR);
261
0
    }
262
11.8k
    NEXT;
263
11.8k
    level = 1;
264
265
11.8k
    len = xmlStrlen(ctxt->cur);
266
    /* Overflow in xmlStrlen */
267
11.8k
    if (len == 0 && ctxt->cur != NULL && *ctxt->cur != 0) {
268
0
        xmlXPathPErrMemory(ctxt);
269
0
        xmlFree(name);
270
0
        return;
271
0
    }
272
273
11.8k
    len++;
274
11.8k
    buffer = xmlMalloc(len);
275
11.8k
    if (buffer == NULL) {
276
0
        xmlXPathPErrMemory(ctxt);
277
0
        xmlFree(name);
278
0
  return;
279
0
    }
280
281
11.8k
    cur = buffer;
282
29.4M
    while (CUR != 0) {
283
29.4M
  if (CUR == ')') {
284
27.0k
      level--;
285
27.0k
      if (level == 0) {
286
11.7k
    NEXT;
287
11.7k
    break;
288
11.7k
      }
289
29.4M
  } else if (CUR == '(') {
290
15.5k
      level++;
291
29.4M
  } else if (CUR == '^') {
292
29.7k
            if ((NXT(1) == ')') || (NXT(1) == '(') || (NXT(1) == '^')) {
293
28.0k
                NEXT;
294
28.0k
            }
295
29.7k
  }
296
29.4M
        *cur++ = CUR;
297
29.4M
  NEXT;
298
29.4M
    }
299
11.8k
    *cur = 0;
300
301
11.8k
    if ((level != 0) && (CUR == 0)) {
302
44
        xmlFree(name);
303
44
  xmlFree(buffer);
304
44
  XP_ERROR(XPTR_SYNTAX_ERROR);
305
0
    }
306
307
11.7k
    if (xmlStrEqual(name, (xmlChar *) "xpointer") ||
308
8.68k
        xmlStrEqual(name, (xmlChar *) "xpath1")) {
309
8.68k
  const xmlChar *oldBase = ctxt->base;
310
8.68k
  const xmlChar *oldCur = ctxt->cur;
311
312
8.68k
  ctxt->cur = ctxt->base = buffer;
313
  /*
314
   * To evaluate an xpointer scheme element (4.3) we need:
315
   *   context initialized to the root
316
   *   context position initialized to 1
317
   *   context size initialized to 1
318
   */
319
8.68k
  ctxt->context->node = (xmlNodePtr)ctxt->context->doc;
320
8.68k
  ctxt->context->proximityPosition = 1;
321
8.68k
  ctxt->context->contextSize = 1;
322
8.68k
  xmlXPathEvalExpr(ctxt);
323
8.68k
  ctxt->base = oldBase;
324
8.68k
        ctxt->cur = oldCur;
325
8.68k
    } else if (xmlStrEqual(name, (xmlChar *) "element")) {
326
836
  const xmlChar *oldBase = ctxt->base;
327
836
  const xmlChar *oldCur = ctxt->cur;
328
836
  xmlChar *name2;
329
330
836
  ctxt->cur = ctxt->base = buffer;
331
836
  if (buffer[0] == '/') {
332
796
      xmlXPathRoot(ctxt);
333
796
      xmlXPtrEvalChildSeq(ctxt, NULL);
334
796
  } else {
335
40
      name2 = xmlXPathParseName(ctxt);
336
40
      if (name2 == NULL) {
337
2
                ctxt->base = oldBase;
338
2
                ctxt->cur = oldCur;
339
2
    xmlFree(buffer);
340
2
                xmlFree(name);
341
2
    XP_ERROR(XPATH_EXPR_ERROR);
342
0
      }
343
38
      xmlXPtrEvalChildSeq(ctxt, name2);
344
38
  }
345
834
  ctxt->base = oldBase;
346
834
        ctxt->cur = oldCur;
347
834
#ifdef XPTR_XMLNS_SCHEME
348
2.23k
    } else if (xmlStrEqual(name, (xmlChar *) "xmlns")) {
349
605
  const xmlChar *oldBase = ctxt->base;
350
605
  const xmlChar *oldCur = ctxt->cur;
351
605
  xmlChar *prefix;
352
353
605
  ctxt->cur = ctxt->base = buffer;
354
605
        prefix = xmlXPathParseNCName(ctxt);
355
605
  if (prefix == NULL) {
356
1
            ctxt->base = oldBase;
357
1
            ctxt->cur = oldCur;
358
1
      xmlFree(buffer);
359
1
      xmlFree(name);
360
1
      XP_ERROR(XPTR_SYNTAX_ERROR);
361
0
  }
362
604
  SKIP_BLANKS;
363
604
  if (CUR != '=') {
364
24
            ctxt->base = oldBase;
365
24
            ctxt->cur = oldCur;
366
24
      xmlFree(prefix);
367
24
      xmlFree(buffer);
368
24
      xmlFree(name);
369
24
      XP_ERROR(XPTR_SYNTAX_ERROR);
370
0
  }
371
580
  NEXT;
372
580
  SKIP_BLANKS;
373
374
580
  if (xmlXPathRegisterNs(ctxt->context, prefix, ctxt->cur) < 0)
375
0
            xmlXPathPErrMemory(ctxt);
376
580
        ctxt->base = oldBase;
377
580
        ctxt->cur = oldCur;
378
580
  xmlFree(prefix);
379
580
#endif /* XPTR_XMLNS_SCHEME */
380
1.63k
    } else {
381
1.63k
        xmlXPtrErr(ctxt, XML_XPTR_UNKNOWN_SCHEME,
382
1.63k
       "unsupported scheme '%s'\n", name);
383
1.63k
    }
384
11.7k
    xmlFree(buffer);
385
11.7k
    xmlFree(name);
386
11.7k
}
387
388
/**
389
 * FullXPtr ::= XPtrPart (S? XPtrPart)*
390
 *
391
 * As the specs says:
392
 * -----------
393
 * When multiple XPtrParts are provided, they must be evaluated in
394
 * left-to-right order. If evaluation of one part fails, the nexti
395
 * is evaluated. The following conditions cause XPointer part failure:
396
 *
397
 * - An unknown scheme
398
 * - A scheme that does not locate any sub-resource present in the resource
399
 * - A scheme that is not applicable to the media type of the resource
400
 *
401
 * The XPointer application must consume a failed XPointer part and
402
 * attempt to evaluate the next one, if any. The result of the first
403
 * XPointer part whose evaluation succeeds is taken to be the fragment
404
 * located by the XPointer as a whole. If all the parts fail, the result
405
 * for the XPointer as a whole is a sub-resource error.
406
 * -----------
407
 *
408
 * Parse and evaluate a Full XPtr i.e. possibly a cascade of XPath based
409
 * expressions or other schemes.
410
 *
411
 * @param ctxt  the XPointer Parser context
412
 * @param name  the preparsed Scheme for the first XPtrPart
413
 */
414
static void
415
8.21k
xmlXPtrEvalFullXPtr(xmlXPathParserContextPtr ctxt, xmlChar *name) {
416
8.21k
    if (name == NULL)
417
0
    name = xmlXPathParseName(ctxt);
418
8.21k
    if (name == NULL)
419
8.21k
  XP_ERROR(XPATH_EXPR_ERROR);
420
13.8k
    while (name != NULL) {
421
11.9k
  ctxt->error = XPATH_EXPRESSION_OK;
422
11.9k
  xmlXPtrEvalXPtrPart(ctxt, name);
423
424
  /* in case of syntax error, break here */
425
11.9k
  if ((ctxt->error != XPATH_EXPRESSION_OK) &&
426
5.34k
            (ctxt->error != XML_XPTR_UNKNOWN_SCHEME))
427
3.71k
      return;
428
429
  /*
430
   * If the returned value is a non-empty nodeset
431
   * or location set, return here.
432
   */
433
8.28k
  if (ctxt->value != NULL) {
434
5.74k
      xmlXPathObjectPtr obj = ctxt->value;
435
436
5.74k
      switch (obj->type) {
437
5.19k
    case XPATH_NODESET: {
438
5.19k
        xmlNodeSetPtr loc = ctxt->value->nodesetval;
439
5.19k
        if ((loc != NULL) && (loc->nodeNr > 0))
440
2.59k
      return;
441
2.59k
        break;
442
5.19k
    }
443
2.59k
    default:
444
545
        break;
445
5.74k
      }
446
447
      /*
448
       * Evaluating to improper values is equivalent to
449
       * a sub-resource error, clean-up the stack
450
       */
451
6.28k
      do {
452
6.28k
    obj = xmlXPathValuePop(ctxt);
453
6.28k
    if (obj != NULL) {
454
3.14k
        xmlXPathFreeObject(obj);
455
3.14k
    }
456
6.28k
      } while (obj != NULL);
457
3.14k
  }
458
459
  /*
460
   * Is there another XPointer part.
461
   */
462
5.68k
  SKIP_BLANKS;
463
5.68k
  name = xmlXPathParseName(ctxt);
464
5.68k
    }
465
8.21k
}
466
467
/**
468
 *  ChildSeq ::= '/1' ('/' [0-9]*)*
469
 *             | Name ('/' [0-9]*)+
470
 *
471
 * Parse and evaluate a Child Sequence. This routine also handle the
472
 * case of a Bare Name used to get a document ID.
473
 *
474
 * @param ctxt  the XPointer Parser context
475
 * @param name  a possible ID name of the child sequence
476
 */
477
static void
478
834
xmlXPtrEvalChildSeq(xmlXPathParserContextPtr ctxt, xmlChar *name) {
479
    /*
480
     * XPointer don't allow by syntax to address in multirooted trees
481
     * this might prove useful in some cases, warn about it.
482
     */
483
834
    if ((name == NULL) && (CUR == '/') && (NXT(1) != '1')) {
484
64
        xmlXPtrErr(ctxt, XML_XPTR_CHILDSEQ_START,
485
64
       "warning: ChildSeq not starting by /1\n", NULL);
486
64
    }
487
488
834
    if (name != NULL) {
489
38
  xmlXPathValuePush(ctxt, xmlXPathNewString(name));
490
38
  xmlFree(name);
491
38
  xmlXPathIdFunction(ctxt, 1);
492
38
  CHECK_ERROR;
493
38
    }
494
495
2.82k
    while (CUR == '/') {
496
1.99k
  int child = 0, overflow = 0;
497
1.99k
  NEXT;
498
499
15.5k
  while ((CUR >= '0') && (CUR <= '9')) {
500
13.5k
            int d = CUR - '0';
501
13.5k
            if (child > INT_MAX / 10)
502
5.37k
                overflow = 1;
503
8.18k
            else
504
8.18k
                child *= 10;
505
13.5k
            if (child > INT_MAX - d)
506
224
                overflow = 1;
507
13.3k
            else
508
13.3k
                child += d;
509
13.5k
      NEXT;
510
13.5k
  }
511
1.99k
        if (overflow)
512
368
            child = 0;
513
1.99k
  xmlXPtrGetChildNo(ctxt, child);
514
1.99k
    }
515
834
}
516
517
518
/**
519
 *  XPointer ::= Name
520
 *             | ChildSeq
521
 *             | FullXPtr
522
 *
523
 * Parse and evaluate an XPointer
524
 *
525
 * @param ctxt  the XPointer Parser context
526
 */
527
static void
528
8.21k
xmlXPtrEvalXPointer(xmlXPathParserContextPtr ctxt) {
529
8.21k
    if (ctxt->valueTab == NULL) {
530
  /* Allocate the value stack */
531
8.21k
  ctxt->valueTab = (xmlXPathObjectPtr *)
532
8.21k
       xmlMalloc(10 * sizeof(xmlXPathObjectPtr));
533
8.21k
  if (ctxt->valueTab == NULL) {
534
0
      xmlXPathPErrMemory(ctxt);
535
0
      return;
536
0
  }
537
8.21k
  ctxt->valueNr = 0;
538
8.21k
  ctxt->valueMax = 10;
539
8.21k
  ctxt->value = NULL;
540
8.21k
    }
541
8.21k
    SKIP_BLANKS;
542
8.21k
    if (CUR == '/') {
543
0
  xmlXPathRoot(ctxt);
544
0
        xmlXPtrEvalChildSeq(ctxt, NULL);
545
8.21k
    } else {
546
8.21k
  xmlChar *name;
547
548
8.21k
  name = xmlXPathParseName(ctxt);
549
8.21k
  if (name == NULL)
550
8.21k
      XP_ERROR(XPATH_EXPR_ERROR);
551
8.21k
  if (CUR == '(') {
552
8.21k
      xmlXPtrEvalFullXPtr(ctxt, name);
553
      /* Short evaluation */
554
8.21k
      return;
555
8.21k
  } else {
556
      /* this handle both Bare Names and Child Sequences */
557
0
      xmlXPtrEvalChildSeq(ctxt, name);
558
0
  }
559
8.21k
    }
560
0
    SKIP_BLANKS;
561
0
    if (CUR != 0)
562
0
  XP_ERROR(XPATH_EXPR_ERROR);
563
0
}
564
565
566
/************************************************************************
567
 *                  *
568
 *      General routines        *
569
 *                  *
570
 ************************************************************************/
571
572
/**
573
 * Create a new XPointer context
574
 *
575
 * @deprecated Same as xmlXPathNewContext.
576
 *
577
 * @param doc  the XML document
578
 * @param here  unused
579
 * @param origin  unused
580
 * @returns the xmlXPathContext just allocated.
581
 */
582
xmlXPathContext *
583
0
xmlXPtrNewContext(xmlDoc *doc, xmlNode *here, xmlNode *origin) {
584
0
    xmlXPathContextPtr ret;
585
0
    (void) here;
586
0
    (void) origin;
587
588
0
    ret = xmlXPathNewContext(doc);
589
0
    if (ret == NULL)
590
0
  return(ret);
591
592
0
    return(ret);
593
0
}
594
595
/**
596
 * Evaluate an XPointer expression.
597
 *
598
 * This function can only return nodesets. The caller has to
599
 * free the object.
600
 *
601
 * @param str  an XPointer expression
602
 * @param ctx  an XPath context
603
 * @returns the xmlXPathObject resulting from the evaluation or NULL
604
 * in case of error.
605
 */
606
xmlXPathObject *
607
8.21k
xmlXPtrEval(const xmlChar *str, xmlXPathContext *ctx) {
608
8.21k
    xmlXPathParserContextPtr ctxt;
609
8.21k
    xmlXPathObjectPtr res = NULL, tmp;
610
8.21k
    xmlXPathObjectPtr init = NULL;
611
8.21k
    int stack = 0;
612
613
8.21k
    xmlInitParser();
614
615
8.21k
    if ((ctx == NULL) || (str == NULL))
616
0
  return(NULL);
617
618
8.21k
    xmlResetError(&ctx->lastError);
619
620
8.21k
    ctxt = xmlXPathNewParserContext(str, ctx);
621
8.21k
    if (ctxt == NULL) {
622
0
        xmlXPathErrMemory(ctx);
623
0
  return(NULL);
624
0
    }
625
8.21k
    xmlXPtrEvalXPointer(ctxt);
626
8.21k
    if (ctx->lastError.code != XML_ERR_OK)
627
3.72k
        goto error;
628
629
4.49k
    if ((ctxt->value != NULL) &&
630
2.59k
  (ctxt->value->type != XPATH_NODESET)) {
631
0
        xmlXPtrErr(ctxt, XML_XPTR_EVAL_FAILED,
632
0
    "xmlXPtrEval: evaluation failed to return a node set\n",
633
0
       NULL);
634
4.49k
    } else {
635
4.49k
  res = xmlXPathValuePop(ctxt);
636
4.49k
    }
637
638
4.49k
    do {
639
4.49k
        tmp = xmlXPathValuePop(ctxt);
640
4.49k
  if (tmp != NULL) {
641
0
      if (tmp != init) {
642
0
    if (tmp->type == XPATH_NODESET) {
643
        /*
644
         * Evaluation may push a root nodeset which is unused
645
         */
646
0
        xmlNodeSetPtr set;
647
0
        set = tmp->nodesetval;
648
0
        if ((set == NULL) || (set->nodeNr != 1) ||
649
0
      (set->nodeTab[0] != (xmlNodePtr) ctx->doc))
650
0
      stack++;
651
0
    } else
652
0
        stack++;
653
0
      }
654
0
      xmlXPathFreeObject(tmp);
655
0
        }
656
4.49k
    } while (tmp != NULL);
657
4.49k
    if (stack != 0) {
658
0
        xmlXPtrErr(ctxt, XML_XPTR_EXTRA_OBJECTS,
659
0
       "xmlXPtrEval: object(s) left on the eval stack\n",
660
0
       NULL);
661
0
    }
662
4.49k
    if (ctx->lastError.code != XML_ERR_OK) {
663
0
  xmlXPathFreeObject(res);
664
0
  res = NULL;
665
0
    }
666
667
8.21k
error:
668
8.21k
    xmlXPathFreeParserContext(ctxt);
669
8.21k
    return(res);
670
4.49k
}
671
672
#endif
673