Home | History | Annotate | Line # | Download | only in lib
xmlparse.c revision 1.9
      1  1.9  christos /* a30d2613dcfdef81475a9d1a349134d2d42722172fdaa7d5bb12ed2aa74b9596 (2.4.6+)
      2  1.8      maya                             __  __            _
      3  1.8      maya                          ___\ \/ /_ __   __ _| |_
      4  1.8      maya                         / _ \\  /| '_ \ / _` | __|
      5  1.8      maya                        |  __//  \| |_) | (_| | |_
      6  1.8      maya                         \___/_/\_\ .__/ \__,_|\__|
      7  1.8      maya                                  |_| XML parser
      8  1.8      maya 
      9  1.8      maya    Copyright (c) 1997-2000 Thai Open Source Software Center Ltd
     10  1.9  christos    Copyright (c) 2000      Clark Cooper <coopercc (at) users.sourceforge.net>
     11  1.9  christos    Copyright (c) 2000-2006 Fred L. Drake, Jr. <fdrake (at) users.sourceforge.net>
     12  1.9  christos    Copyright (c) 2001-2002 Greg Stein <gstein (at) users.sourceforge.net>
     13  1.9  christos    Copyright (c) 2002-2016 Karl Waclawek <karl (at) waclawek.net>
     14  1.9  christos    Copyright (c) 2005-2009 Steven Solie <steven (at) solie.ca>
     15  1.9  christos    Copyright (c) 2016      Eric Rahm <erahm (at) mozilla.com>
     16  1.9  christos    Copyright (c) 2016-2022 Sebastian Pipping <sebastian (at) pipping.org>
     17  1.9  christos    Copyright (c) 2016      Gaurav <g.gupta (at) samsung.com>
     18  1.9  christos    Copyright (c) 2016      Thomas Beutlich <tc (at) tbeu.de>
     19  1.9  christos    Copyright (c) 2016      Gustavo Grieco <gustavo.grieco (at) imag.fr>
     20  1.9  christos    Copyright (c) 2016      Pascal Cuoq <cuoq (at) trust-in-soft.com>
     21  1.9  christos    Copyright (c) 2016      Ed Schouten <ed (at) nuxi.nl>
     22  1.9  christos    Copyright (c) 2017-2018 Rhodri James <rhodri (at) wildebeest.org.uk>
     23  1.9  christos    Copyright (c) 2017      Vclav Slavk <vaclav (at) slavik.io>
     24  1.9  christos    Copyright (c) 2017      Viktor Szakats <commit (at) vsz.me>
     25  1.9  christos    Copyright (c) 2017      Chanho Park <chanho61.park (at) samsung.com>
     26  1.9  christos    Copyright (c) 2017      Rolf Eike Beer <eike (at) sf-mail.de>
     27  1.9  christos    Copyright (c) 2017      Hans Wennborg <hans (at) chromium.org>
     28  1.9  christos    Copyright (c) 2018      Anton Maklakov <antmak.pub (at) gmail.com>
     29  1.9  christos    Copyright (c) 2018      Benjamin Peterson <benjamin (at) python.org>
     30  1.9  christos    Copyright (c) 2018      Marco Maggi <marco.maggi-ipsu (at) poste.it>
     31  1.9  christos    Copyright (c) 2018      Mariusz Zaborski <oshogbo (at) vexillium.org>
     32  1.9  christos    Copyright (c) 2019      David Loffredo <loffredo (at) steptools.com>
     33  1.9  christos    Copyright (c) 2019-2020 Ben Wagner <bungeman (at) chromium.org>
     34  1.9  christos    Copyright (c) 2019      Vadim Zeitlin <vadim (at) zeitlins.org>
     35  1.9  christos    Copyright (c) 2021      Dong-hee Na <donghee.na (at) python.org>
     36  1.9  christos    Copyright (c) 2022      Samanta Navarro <ferivoz (at) riseup.net>
     37  1.8      maya    Licensed under the MIT license:
     38  1.8      maya 
     39  1.8      maya    Permission is  hereby granted,  free of charge,  to any  person obtaining
     40  1.8      maya    a  copy  of  this  software   and  associated  documentation  files  (the
     41  1.8      maya    "Software"),  to  deal in  the  Software  without restriction,  including
     42  1.8      maya    without  limitation the  rights  to use,  copy,  modify, merge,  publish,
     43  1.8      maya    distribute, sublicense, and/or sell copies of the Software, and to permit
     44  1.8      maya    persons  to whom  the Software  is  furnished to  do so,  subject to  the
     45  1.8      maya    following conditions:
     46  1.8      maya 
     47  1.8      maya    The above copyright  notice and this permission notice  shall be included
     48  1.8      maya    in all copies or substantial portions of the Software.
     49  1.8      maya 
     50  1.8      maya    THE  SOFTWARE  IS  PROVIDED  "AS  IS",  WITHOUT  WARRANTY  OF  ANY  KIND,
     51  1.8      maya    EXPRESS  OR IMPLIED,  INCLUDING  BUT  NOT LIMITED  TO  THE WARRANTIES  OF
     52  1.8      maya    MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
     53  1.8      maya    NO EVENT SHALL THE AUTHORS OR  COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
     54  1.8      maya    DAMAGES OR  OTHER LIABILITY, WHETHER  IN AN  ACTION OF CONTRACT,  TORT OR
     55  1.8      maya    OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
     56  1.8      maya    USE OR OTHER DEALINGS IN THE SOFTWARE.
     57  1.8      maya */
     58  1.7  christos 
     59  1.9  christos #define XML_BUILDING_EXPAT 1
     60  1.9  christos 
     61  1.9  christos #include <expat_config.h>
     62  1.9  christos 
     63  1.8      maya #if ! defined(_GNU_SOURCE)
     64  1.8      maya #  define _GNU_SOURCE 1 /* syscall prototype */
     65  1.8      maya #endif
     66  1.1      tron 
     67  1.8      maya #ifdef _WIN32
     68  1.8      maya /* force stdlib to define rand_s() */
     69  1.9  christos #  if ! defined(_CRT_RAND_S)
     70  1.9  christos #    define _CRT_RAND_S
     71  1.9  christos #  endif
     72  1.8      maya #endif
     73  1.7  christos 
     74  1.1      tron #include <stddef.h>
     75  1.8      maya #include <string.h> /* memset(), memcpy() */
     76  1.1      tron #include <assert.h>
     77  1.8      maya #include <limits.h> /* UINT_MAX */
     78  1.8      maya #include <stdio.h>  /* fprintf */
     79  1.8      maya #include <stdlib.h> /* getenv, rand_s */
     80  1.9  christos #include <stdint.h> /* uintptr_t */
     81  1.9  christos #include <math.h>   /* isnan */
     82  1.6       spz 
     83  1.7  christos #ifdef _WIN32
     84  1.8      maya #  define getpid GetCurrentProcessId
     85  1.6       spz #else
     86  1.8      maya #  include <sys/time.h>  /* gettimeofday() */
     87  1.8      maya #  include <sys/types.h> /* getpid() */
     88  1.8      maya #  include <unistd.h>    /* getpid() */
     89  1.8      maya #  include <fcntl.h>     /* O_RDONLY */
     90  1.8      maya #  include <errno.h>
     91  1.6       spz #endif
     92  1.1      tron 
     93  1.7  christos #ifdef _WIN32
     94  1.8      maya #  include "winconfig.h"
     95  1.9  christos #endif
     96  1.1      tron 
     97  1.1      tron #include "ascii.h"
     98  1.1      tron #include "expat.h"
     99  1.7  christos #include "siphash.h"
    100  1.1      tron 
    101  1.8      maya #if defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
    102  1.8      maya #  if defined(HAVE_GETRANDOM)
    103  1.8      maya #    include <sys/random.h> /* getrandom */
    104  1.8      maya #  else
    105  1.8      maya #    include <unistd.h>      /* syscall */
    106  1.8      maya #    include <sys/syscall.h> /* SYS_getrandom */
    107  1.8      maya #  endif
    108  1.8      maya #  if ! defined(GRND_NONBLOCK)
    109  1.8      maya #    define GRND_NONBLOCK 0x0001
    110  1.8      maya #  endif /* defined(GRND_NONBLOCK) */
    111  1.8      maya #endif   /* defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM) */
    112  1.8      maya 
    113  1.8      maya #if defined(HAVE_LIBBSD)                                                       \
    114  1.8      maya     && (defined(HAVE_ARC4RANDOM_BUF) || defined(HAVE_ARC4RANDOM))
    115  1.8      maya #  include <bsd/stdlib.h>
    116  1.8      maya #endif
    117  1.8      maya 
    118  1.8      maya #if defined(_WIN32) && ! defined(LOAD_LIBRARY_SEARCH_SYSTEM32)
    119  1.8      maya #  define LOAD_LIBRARY_SEARCH_SYSTEM32 0x00000800
    120  1.8      maya #endif
    121  1.8      maya 
    122  1.8      maya #if ! defined(HAVE_GETRANDOM) && ! defined(HAVE_SYSCALL_GETRANDOM)             \
    123  1.8      maya     && ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM)            \
    124  1.8      maya     && ! defined(XML_DEV_URANDOM) && ! defined(_WIN32)                         \
    125  1.8      maya     && ! defined(XML_POOR_ENTROPY)
    126  1.8      maya #  error You do not have support for any sources of high quality entropy \
    127  1.8      maya     enabled.  For end user security, that is probably not what you want. \
    128  1.8      maya     \
    129  1.8      maya     Your options include: \
    130  1.9  christos       * Linux >=3.17 + glibc >=2.25 (getrandom): HAVE_GETRANDOM, \
    131  1.9  christos       * Linux >=3.17 + glibc (including <2.25) (syscall SYS_getrandom): HAVE_SYSCALL_GETRANDOM, \
    132  1.8      maya       * BSD / macOS >=10.7 (arc4random_buf): HAVE_ARC4RANDOM_BUF, \
    133  1.9  christos       * BSD / macOS (including <10.7) (arc4random): HAVE_ARC4RANDOM, \
    134  1.8      maya       * libbsd (arc4random_buf): HAVE_ARC4RANDOM_BUF + HAVE_LIBBSD, \
    135  1.8      maya       * libbsd (arc4random): HAVE_ARC4RANDOM + HAVE_LIBBSD, \
    136  1.9  christos       * Linux (including <3.17) / BSD / macOS (including <10.7) (/dev/urandom): XML_DEV_URANDOM, \
    137  1.9  christos       * Windows >=Vista (rand_s): _WIN32. \
    138  1.8      maya     \
    139  1.8      maya     If insist on not using any of these, bypass this error by defining \
    140  1.8      maya     XML_POOR_ENTROPY; you have been warned. \
    141  1.8      maya     \
    142  1.8      maya     If you have reasons to patch this detection code away or need changes \
    143  1.8      maya     to the build system, please open a bug.  Thank you!
    144  1.8      maya #endif
    145  1.8      maya 
    146  1.1      tron #ifdef XML_UNICODE
    147  1.8      maya #  define XML_ENCODE_MAX XML_UTF16_ENCODE_MAX
    148  1.8      maya #  define XmlConvert XmlUtf16Convert
    149  1.8      maya #  define XmlGetInternalEncoding XmlGetUtf16InternalEncoding
    150  1.8      maya #  define XmlGetInternalEncodingNS XmlGetUtf16InternalEncodingNS
    151  1.8      maya #  define XmlEncode XmlUtf16Encode
    152  1.9  christos #  define MUST_CONVERT(enc, s) (! (enc)->isUtf16 || (((uintptr_t)(s)) & 1))
    153  1.1      tron typedef unsigned short ICHAR;
    154  1.1      tron #else
    155  1.8      maya #  define XML_ENCODE_MAX XML_UTF8_ENCODE_MAX
    156  1.8      maya #  define XmlConvert XmlUtf8Convert
    157  1.8      maya #  define XmlGetInternalEncoding XmlGetUtf8InternalEncoding
    158  1.8      maya #  define XmlGetInternalEncodingNS XmlGetUtf8InternalEncodingNS
    159  1.8      maya #  define XmlEncode XmlUtf8Encode
    160  1.8      maya #  define MUST_CONVERT(enc, s) (! (enc)->isUtf8)
    161  1.1      tron typedef char ICHAR;
    162  1.1      tron #endif
    163  1.1      tron 
    164  1.1      tron #ifndef XML_NS
    165  1.1      tron 
    166  1.8      maya #  define XmlInitEncodingNS XmlInitEncoding
    167  1.8      maya #  define XmlInitUnknownEncodingNS XmlInitUnknownEncoding
    168  1.8      maya #  undef XmlGetInternalEncodingNS
    169  1.8      maya #  define XmlGetInternalEncodingNS XmlGetInternalEncoding
    170  1.8      maya #  define XmlParseXmlDeclNS XmlParseXmlDecl
    171  1.1      tron 
    172  1.1      tron #endif
    173  1.1      tron 
    174  1.1      tron #ifdef XML_UNICODE
    175  1.1      tron 
    176  1.8      maya #  ifdef XML_UNICODE_WCHAR_T
    177  1.8      maya #    define XML_T(x) (const wchar_t) x
    178  1.8      maya #    define XML_L(x) L##x
    179  1.8      maya #  else
    180  1.8      maya #    define XML_T(x) (const unsigned short)x
    181  1.8      maya #    define XML_L(x) x
    182  1.8      maya #  endif
    183  1.1      tron 
    184  1.1      tron #else
    185  1.1      tron 
    186  1.8      maya #  define XML_T(x) x
    187  1.8      maya #  define XML_L(x) x
    188  1.1      tron 
    189  1.1      tron #endif
    190  1.1      tron 
    191  1.1      tron /* Round up n to be a multiple of sz, where sz is a power of 2. */
    192  1.8      maya #define ROUND_UP(n, sz) (((n) + ((sz)-1)) & ~((sz)-1))
    193  1.1      tron 
    194  1.8      maya /* Do safe (NULL-aware) pointer arithmetic */
    195  1.8      maya #define EXPAT_SAFE_PTR_DIFF(p, q) (((p) && (q)) ? ((p) - (q)) : 0)
    196  1.1      tron 
    197  1.1      tron #include "internal.h"
    198  1.1      tron #include "xmltok.h"
    199  1.1      tron #include "xmlrole.h"
    200  1.1      tron 
    201  1.1      tron typedef const XML_Char *KEY;
    202  1.1      tron 
    203  1.1      tron typedef struct {
    204  1.1      tron   KEY name;
    205  1.1      tron } NAMED;
    206  1.1      tron 
    207  1.1      tron typedef struct {
    208  1.1      tron   NAMED **v;
    209  1.1      tron   unsigned char power;
    210  1.1      tron   size_t size;
    211  1.1      tron   size_t used;
    212  1.1      tron   const XML_Memory_Handling_Suite *mem;
    213  1.1      tron } HASH_TABLE;
    214  1.1      tron 
    215  1.8      maya static size_t keylen(KEY s);
    216  1.1      tron 
    217  1.8      maya static void copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key);
    218  1.1      tron 
    219  1.1      tron /* For probing (after a collision) we need a step size relative prime
    220  1.1      tron    to the hash table size, which is a power of 2. We use double-hashing,
    221  1.1      tron    since we can calculate a second hash value cheaply by taking those bits
    222  1.1      tron    of the first hash value that were discarded (masked out) when the table
    223  1.1      tron    index was calculated: index = hash & mask, where mask = table->size - 1.
    224  1.1      tron    We limit the maximum step size to table->size / 4 (mask >> 2) and make
    225  1.1      tron    it odd, since odd numbers are always relative prime to a power of 2.
    226  1.1      tron */
    227  1.8      maya #define SECOND_HASH(hash, mask, power)                                         \
    228  1.8      maya   ((((hash) & ~(mask)) >> ((power)-1)) & ((mask) >> 2))
    229  1.8      maya #define PROBE_STEP(hash, mask, power)                                          \
    230  1.1      tron   ((unsigned char)((SECOND_HASH(hash, mask, power)) | 1))
    231  1.1      tron 
    232  1.1      tron typedef struct {
    233  1.1      tron   NAMED **p;
    234  1.1      tron   NAMED **end;
    235  1.1      tron } HASH_TABLE_ITER;
    236  1.1      tron 
    237  1.8      maya #define INIT_TAG_BUF_SIZE 32 /* must be a multiple of sizeof(XML_Char) */
    238  1.1      tron #define INIT_DATA_BUF_SIZE 1024
    239  1.1      tron #define INIT_ATTS_SIZE 16
    240  1.1      tron #define INIT_ATTS_VERSION 0xFFFFFFFF
    241  1.1      tron #define INIT_BLOCK_SIZE 1024
    242  1.1      tron #define INIT_BUFFER_SIZE 1024
    243  1.1      tron 
    244  1.1      tron #define EXPAND_SPARE 24
    245  1.1      tron 
    246  1.1      tron typedef struct binding {
    247  1.1      tron   struct prefix *prefix;
    248  1.1      tron   struct binding *nextTagBinding;
    249  1.1      tron   struct binding *prevPrefixBinding;
    250  1.1      tron   const struct attribute_id *attId;
    251  1.1      tron   XML_Char *uri;
    252  1.1      tron   int uriLen;
    253  1.1      tron   int uriAlloc;
    254  1.1      tron } BINDING;
    255  1.1      tron 
    256  1.1      tron typedef struct prefix {
    257  1.1      tron   const XML_Char *name;
    258  1.1      tron   BINDING *binding;
    259  1.1      tron } PREFIX;
    260  1.1      tron 
    261  1.1      tron typedef struct {
    262  1.1      tron   const XML_Char *str;
    263  1.1      tron   const XML_Char *localPart;
    264  1.1      tron   const XML_Char *prefix;
    265  1.1      tron   int strLen;
    266  1.1      tron   int uriLen;
    267  1.1      tron   int prefixLen;
    268  1.1      tron } TAG_NAME;
    269  1.1      tron 
    270  1.1      tron /* TAG represents an open element.
    271  1.1      tron    The name of the element is stored in both the document and API
    272  1.1      tron    encodings.  The memory buffer 'buf' is a separately-allocated
    273  1.1      tron    memory area which stores the name.  During the XML_Parse()/
    274  1.1      tron    XMLParseBuffer() when the element is open, the memory for the 'raw'
    275  1.1      tron    version of the name (in the document encoding) is shared with the
    276  1.1      tron    document buffer.  If the element is open across calls to
    277  1.1      tron    XML_Parse()/XML_ParseBuffer(), the buffer is re-allocated to
    278  1.1      tron    contain the 'raw' name as well.
    279  1.1      tron 
    280  1.1      tron    A parser re-uses these structures, maintaining a list of allocated
    281  1.1      tron    TAG objects in a free list.
    282  1.1      tron */
    283  1.1      tron typedef struct tag {
    284  1.8      maya   struct tag *parent;  /* parent of this element */
    285  1.8      maya   const char *rawName; /* tagName in the original encoding */
    286  1.1      tron   int rawNameLength;
    287  1.8      maya   TAG_NAME name; /* tagName in the API encoding */
    288  1.8      maya   char *buf;     /* buffer for name components */
    289  1.8      maya   char *bufEnd;  /* end of the buffer */
    290  1.1      tron   BINDING *bindings;
    291  1.1      tron } TAG;
    292  1.1      tron 
    293  1.1      tron typedef struct {
    294  1.1      tron   const XML_Char *name;
    295  1.1      tron   const XML_Char *textPtr;
    296  1.8      maya   int textLen;   /* length in XML_Chars */
    297  1.8      maya   int processed; /* # of processed bytes - when suspended */
    298  1.1      tron   const XML_Char *systemId;
    299  1.1      tron   const XML_Char *base;
    300  1.1      tron   const XML_Char *publicId;
    301  1.1      tron   const XML_Char *notation;
    302  1.1      tron   XML_Bool open;
    303  1.1      tron   XML_Bool is_param;
    304  1.1      tron   XML_Bool is_internal; /* true if declared in internal subset outside PE */
    305  1.1      tron } ENTITY;
    306  1.1      tron 
    307  1.1      tron typedef struct {
    308  1.8      maya   enum XML_Content_Type type;
    309  1.8      maya   enum XML_Content_Quant quant;
    310  1.8      maya   const XML_Char *name;
    311  1.8      maya   int firstchild;
    312  1.8      maya   int lastchild;
    313  1.8      maya   int childcnt;
    314  1.8      maya   int nextsib;
    315  1.1      tron } CONTENT_SCAFFOLD;
    316  1.1      tron 
    317  1.1      tron #define INIT_SCAFFOLD_ELEMENTS 32
    318  1.1      tron 
    319  1.1      tron typedef struct block {
    320  1.1      tron   struct block *next;
    321  1.1      tron   int size;
    322  1.1      tron   XML_Char s[1];
    323  1.1      tron } BLOCK;
    324  1.1      tron 
    325  1.1      tron typedef struct {
    326  1.1      tron   BLOCK *blocks;
    327  1.1      tron   BLOCK *freeBlocks;
    328  1.1      tron   const XML_Char *end;
    329  1.1      tron   XML_Char *ptr;
    330  1.1      tron   XML_Char *start;
    331  1.1      tron   const XML_Memory_Handling_Suite *mem;
    332  1.1      tron } STRING_POOL;
    333  1.1      tron 
    334  1.1      tron /* The XML_Char before the name is used to determine whether
    335  1.1      tron    an attribute has been specified. */
    336  1.1      tron typedef struct attribute_id {
    337  1.1      tron   XML_Char *name;
    338  1.1      tron   PREFIX *prefix;
    339  1.1      tron   XML_Bool maybeTokenized;
    340  1.1      tron   XML_Bool xmlns;
    341  1.1      tron } ATTRIBUTE_ID;
    342  1.1      tron 
    343  1.1      tron typedef struct {
    344  1.1      tron   const ATTRIBUTE_ID *id;
    345  1.1      tron   XML_Bool isCdata;
    346  1.1      tron   const XML_Char *value;
    347  1.1      tron } DEFAULT_ATTRIBUTE;
    348  1.1      tron 
    349  1.1      tron typedef struct {
    350  1.1      tron   unsigned long version;
    351  1.1      tron   unsigned long hash;
    352  1.1      tron   const XML_Char *uriName;
    353  1.1      tron } NS_ATT;
    354  1.1      tron 
    355  1.1      tron typedef struct {
    356  1.1      tron   const XML_Char *name;
    357  1.1      tron   PREFIX *prefix;
    358  1.1      tron   const ATTRIBUTE_ID *idAtt;
    359  1.1      tron   int nDefaultAtts;
    360  1.1      tron   int allocDefaultAtts;
    361  1.1      tron   DEFAULT_ATTRIBUTE *defaultAtts;
    362  1.1      tron } ELEMENT_TYPE;
    363  1.1      tron 
    364  1.1      tron typedef struct {
    365  1.1      tron   HASH_TABLE generalEntities;
    366  1.1      tron   HASH_TABLE elementTypes;
    367  1.1      tron   HASH_TABLE attributeIds;
    368  1.1      tron   HASH_TABLE prefixes;
    369  1.1      tron   STRING_POOL pool;
    370  1.1      tron   STRING_POOL entityValuePool;
    371  1.1      tron   /* false once a parameter entity reference has been skipped */
    372  1.1      tron   XML_Bool keepProcessing;
    373  1.1      tron   /* true once an internal or external PE reference has been encountered;
    374  1.1      tron      this includes the reference to an external subset */
    375  1.1      tron   XML_Bool hasParamEntityRefs;
    376  1.1      tron   XML_Bool standalone;
    377  1.1      tron #ifdef XML_DTD
    378  1.1      tron   /* indicates if external PE has been read */
    379  1.1      tron   XML_Bool paramEntityRead;
    380  1.1      tron   HASH_TABLE paramEntities;
    381  1.1      tron #endif /* XML_DTD */
    382  1.1      tron   PREFIX defaultPrefix;
    383  1.1      tron   /* === scaffolding for building content model === */
    384  1.1      tron   XML_Bool in_eldecl;
    385  1.1      tron   CONTENT_SCAFFOLD *scaffold;
    386  1.1      tron   unsigned contentStringLen;
    387  1.1      tron   unsigned scaffSize;
    388  1.1      tron   unsigned scaffCount;
    389  1.1      tron   int scaffLevel;
    390  1.1      tron   int *scaffIndex;
    391  1.1      tron } DTD;
    392  1.1      tron 
    393  1.1      tron typedef struct open_internal_entity {
    394  1.1      tron   const char *internalEventPtr;
    395  1.1      tron   const char *internalEventEndPtr;
    396  1.1      tron   struct open_internal_entity *next;
    397  1.1      tron   ENTITY *entity;
    398  1.1      tron   int startTagLevel;
    399  1.1      tron   XML_Bool betweenDecl; /* WFC: PE Between Declarations */
    400  1.1      tron } OPEN_INTERNAL_ENTITY;
    401  1.1      tron 
    402  1.9  christos enum XML_Account {
    403  1.9  christos   XML_ACCOUNT_DIRECT,           /* bytes directly passed to the Expat parser */
    404  1.9  christos   XML_ACCOUNT_ENTITY_EXPANSION, /* intermediate bytes produced during entity
    405  1.9  christos                                    expansion */
    406  1.9  christos   XML_ACCOUNT_NONE              /* i.e. do not account, was accounted already */
    407  1.9  christos };
    408  1.9  christos 
    409  1.9  christos #ifdef XML_DTD
    410  1.9  christos typedef unsigned long long XmlBigCount;
    411  1.9  christos typedef struct accounting {
    412  1.9  christos   XmlBigCount countBytesDirect;
    413  1.9  christos   XmlBigCount countBytesIndirect;
    414  1.9  christos   int debugLevel;
    415  1.9  christos   float maximumAmplificationFactor; // >=1.0
    416  1.9  christos   unsigned long long activationThresholdBytes;
    417  1.9  christos } ACCOUNTING;
    418  1.9  christos 
    419  1.9  christos typedef struct entity_stats {
    420  1.9  christos   unsigned int countEverOpened;
    421  1.9  christos   unsigned int currentDepth;
    422  1.9  christos   unsigned int maximumDepthSeen;
    423  1.9  christos   int debugLevel;
    424  1.9  christos } ENTITY_STATS;
    425  1.9  christos #endif /* XML_DTD */
    426  1.9  christos 
    427  1.8      maya typedef enum XML_Error PTRCALL Processor(XML_Parser parser, const char *start,
    428  1.8      maya                                          const char *end, const char **endPtr);
    429  1.1      tron 
    430  1.1      tron static Processor prologProcessor;
    431  1.1      tron static Processor prologInitProcessor;
    432  1.1      tron static Processor contentProcessor;
    433  1.1      tron static Processor cdataSectionProcessor;
    434  1.1      tron #ifdef XML_DTD
    435  1.1      tron static Processor ignoreSectionProcessor;
    436  1.1      tron static Processor externalParEntProcessor;
    437  1.1      tron static Processor externalParEntInitProcessor;
    438  1.1      tron static Processor entityValueProcessor;
    439  1.1      tron static Processor entityValueInitProcessor;
    440  1.1      tron #endif /* XML_DTD */
    441  1.1      tron static Processor epilogProcessor;
    442  1.1      tron static Processor errorProcessor;
    443  1.1      tron static Processor externalEntityInitProcessor;
    444  1.1      tron static Processor externalEntityInitProcessor2;
    445  1.1      tron static Processor externalEntityInitProcessor3;
    446  1.1      tron static Processor externalEntityContentProcessor;
    447  1.1      tron static Processor internalEntityProcessor;
    448  1.1      tron 
    449  1.8      maya static enum XML_Error handleUnknownEncoding(XML_Parser parser,
    450  1.8      maya                                             const XML_Char *encodingName);
    451  1.8      maya static enum XML_Error processXmlDecl(XML_Parser parser, int isGeneralTextEntity,
    452  1.8      maya                                      const char *s, const char *next);
    453  1.8      maya static enum XML_Error initializeEncoding(XML_Parser parser);
    454  1.8      maya static enum XML_Error doProlog(XML_Parser parser, const ENCODING *enc,
    455  1.8      maya                                const char *s, const char *end, int tok,
    456  1.8      maya                                const char *next, const char **nextPtr,
    457  1.9  christos                                XML_Bool haveMore, XML_Bool allowClosingDoctype,
    458  1.9  christos                                enum XML_Account account);
    459  1.8      maya static enum XML_Error processInternalEntity(XML_Parser parser, ENTITY *entity,
    460  1.8      maya                                             XML_Bool betweenDecl);
    461  1.8      maya static enum XML_Error doContent(XML_Parser parser, int startTagLevel,
    462  1.8      maya                                 const ENCODING *enc, const char *start,
    463  1.8      maya                                 const char *end, const char **endPtr,
    464  1.9  christos                                 XML_Bool haveMore, enum XML_Account account);
    465  1.8      maya static enum XML_Error doCdataSection(XML_Parser parser, const ENCODING *,
    466  1.8      maya                                      const char **startPtr, const char *end,
    467  1.9  christos                                      const char **nextPtr, XML_Bool haveMore,
    468  1.9  christos                                      enum XML_Account account);
    469  1.8      maya #ifdef XML_DTD
    470  1.8      maya static enum XML_Error doIgnoreSection(XML_Parser parser, const ENCODING *,
    471  1.8      maya                                       const char **startPtr, const char *end,
    472  1.8      maya                                       const char **nextPtr, XML_Bool haveMore);
    473  1.1      tron #endif /* XML_DTD */
    474  1.1      tron 
    475  1.8      maya static void freeBindings(XML_Parser parser, BINDING *bindings);
    476  1.8      maya static enum XML_Error storeAtts(XML_Parser parser, const ENCODING *,
    477  1.8      maya                                 const char *s, TAG_NAME *tagNamePtr,
    478  1.9  christos                                 BINDING **bindingsPtr,
    479  1.9  christos                                 enum XML_Account account);
    480  1.8      maya static enum XML_Error addBinding(XML_Parser parser, PREFIX *prefix,
    481  1.8      maya                                  const ATTRIBUTE_ID *attId, const XML_Char *uri,
    482  1.8      maya                                  BINDING **bindingsPtr);
    483  1.8      maya static int defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *, XML_Bool isCdata,
    484  1.8      maya                            XML_Bool isId, const XML_Char *dfltValue,
    485  1.8      maya                            XML_Parser parser);
    486  1.8      maya static enum XML_Error storeAttributeValue(XML_Parser parser, const ENCODING *,
    487  1.8      maya                                           XML_Bool isCdata, const char *,
    488  1.9  christos                                           const char *, STRING_POOL *,
    489  1.9  christos                                           enum XML_Account account);
    490  1.8      maya static enum XML_Error appendAttributeValue(XML_Parser parser, const ENCODING *,
    491  1.8      maya                                            XML_Bool isCdata, const char *,
    492  1.9  christos                                            const char *, STRING_POOL *,
    493  1.9  christos                                            enum XML_Account account);
    494  1.8      maya static ATTRIBUTE_ID *getAttributeId(XML_Parser parser, const ENCODING *enc,
    495  1.8      maya                                     const char *start, const char *end);
    496  1.8      maya static int setElementTypePrefix(XML_Parser parser, ELEMENT_TYPE *);
    497  1.8      maya static enum XML_Error storeEntityValue(XML_Parser parser, const ENCODING *enc,
    498  1.9  christos                                        const char *start, const char *end,
    499  1.9  christos                                        enum XML_Account account);
    500  1.8      maya static int reportProcessingInstruction(XML_Parser parser, const ENCODING *enc,
    501  1.8      maya                                        const char *start, const char *end);
    502  1.8      maya static int reportComment(XML_Parser parser, const ENCODING *enc,
    503  1.8      maya                          const char *start, const char *end);
    504  1.8      maya static void reportDefault(XML_Parser parser, const ENCODING *enc,
    505  1.8      maya                           const char *start, const char *end);
    506  1.1      tron 
    507  1.8      maya static const XML_Char *getContext(XML_Parser parser);
    508  1.8      maya static XML_Bool setContext(XML_Parser parser, const XML_Char *context);
    509  1.1      tron 
    510  1.1      tron static void FASTCALL normalizePublicId(XML_Char *s);
    511  1.1      tron 
    512  1.8      maya static DTD *dtdCreate(const XML_Memory_Handling_Suite *ms);
    513  1.8      maya /* do not call if m_parentParser != NULL */
    514  1.1      tron static void dtdReset(DTD *p, const XML_Memory_Handling_Suite *ms);
    515  1.8      maya static void dtdDestroy(DTD *p, XML_Bool isDocEntity,
    516  1.8      maya                        const XML_Memory_Handling_Suite *ms);
    517  1.8      maya static int dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
    518  1.8      maya                    const XML_Memory_Handling_Suite *ms);
    519  1.8      maya static int copyEntityTable(XML_Parser oldParser, HASH_TABLE *, STRING_POOL *,
    520  1.8      maya                            const HASH_TABLE *);
    521  1.8      maya static NAMED *lookup(XML_Parser parser, HASH_TABLE *table, KEY name,
    522  1.8      maya                      size_t createSize);
    523  1.8      maya static void FASTCALL hashTableInit(HASH_TABLE *,
    524  1.8      maya                                    const XML_Memory_Handling_Suite *ms);
    525  1.1      tron static void FASTCALL hashTableClear(HASH_TABLE *);
    526  1.1      tron static void FASTCALL hashTableDestroy(HASH_TABLE *);
    527  1.8      maya static void FASTCALL hashTableIterInit(HASH_TABLE_ITER *, const HASH_TABLE *);
    528  1.8      maya static NAMED *FASTCALL hashTableIterNext(HASH_TABLE_ITER *);
    529  1.1      tron 
    530  1.8      maya static void FASTCALL poolInit(STRING_POOL *,
    531  1.8      maya                               const XML_Memory_Handling_Suite *ms);
    532  1.1      tron static void FASTCALL poolClear(STRING_POOL *);
    533  1.1      tron static void FASTCALL poolDestroy(STRING_POOL *);
    534  1.8      maya static XML_Char *poolAppend(STRING_POOL *pool, const ENCODING *enc,
    535  1.8      maya                             const char *ptr, const char *end);
    536  1.8      maya static XML_Char *poolStoreString(STRING_POOL *pool, const ENCODING *enc,
    537  1.8      maya                                  const char *ptr, const char *end);
    538  1.1      tron static XML_Bool FASTCALL poolGrow(STRING_POOL *pool);
    539  1.8      maya static const XML_Char *FASTCALL poolCopyString(STRING_POOL *pool,
    540  1.8      maya                                                const XML_Char *s);
    541  1.8      maya static const XML_Char *poolCopyStringN(STRING_POOL *pool, const XML_Char *s,
    542  1.8      maya                                        int n);
    543  1.8      maya static const XML_Char *FASTCALL poolAppendString(STRING_POOL *pool,
    544  1.8      maya                                                  const XML_Char *s);
    545  1.1      tron 
    546  1.1      tron static int FASTCALL nextScaffoldPart(XML_Parser parser);
    547  1.8      maya static XML_Content *build_model(XML_Parser parser);
    548  1.8      maya static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc,
    549  1.8      maya                                     const char *ptr, const char *end);
    550  1.8      maya 
    551  1.8      maya static XML_Char *copyString(const XML_Char *s,
    552  1.8      maya                             const XML_Memory_Handling_Suite *memsuite);
    553  1.1      tron 
    554  1.6       spz static unsigned long generate_hash_secret_salt(XML_Parser parser);
    555  1.3       spz static XML_Bool startParsing(XML_Parser parser);
    556  1.3       spz 
    557  1.8      maya static XML_Parser parserCreate(const XML_Char *encodingName,
    558  1.8      maya                                const XML_Memory_Handling_Suite *memsuite,
    559  1.8      maya                                const XML_Char *nameSep, DTD *dtd);
    560  1.3       spz 
    561  1.8      maya static void parserInit(XML_Parser parser, const XML_Char *encodingName);
    562  1.1      tron 
    563  1.9  christos #ifdef XML_DTD
    564  1.9  christos static float accountingGetCurrentAmplification(XML_Parser rootParser);
    565  1.9  christos static void accountingReportStats(XML_Parser originParser, const char *epilog);
    566  1.9  christos static void accountingOnAbort(XML_Parser originParser);
    567  1.9  christos static void accountingReportDiff(XML_Parser rootParser,
    568  1.9  christos                                  unsigned int levelsAwayFromRootParser,
    569  1.9  christos                                  const char *before, const char *after,
    570  1.9  christos                                  ptrdiff_t bytesMore, int source_line,
    571  1.9  christos                                  enum XML_Account account);
    572  1.9  christos static XML_Bool accountingDiffTolerated(XML_Parser originParser, int tok,
    573  1.9  christos                                         const char *before, const char *after,
    574  1.9  christos                                         int source_line,
    575  1.9  christos                                         enum XML_Account account);
    576  1.9  christos 
    577  1.9  christos static void entityTrackingReportStats(XML_Parser parser, ENTITY *entity,
    578  1.9  christos                                       const char *action, int sourceLine);
    579  1.9  christos static void entityTrackingOnOpen(XML_Parser parser, ENTITY *entity,
    580  1.9  christos                                  int sourceLine);
    581  1.9  christos static void entityTrackingOnClose(XML_Parser parser, ENTITY *entity,
    582  1.9  christos                                   int sourceLine);
    583  1.9  christos 
    584  1.9  christos static XML_Parser getRootParserOf(XML_Parser parser,
    585  1.9  christos                                   unsigned int *outLevelDiff);
    586  1.9  christos #endif /* XML_DTD */
    587  1.9  christos 
    588  1.9  christos static unsigned long getDebugLevel(const char *variableName,
    589  1.9  christos                                    unsigned long defaultDebugLevel);
    590  1.9  christos 
    591  1.1      tron #define poolStart(pool) ((pool)->start)
    592  1.1      tron #define poolEnd(pool) ((pool)->ptr)
    593  1.1      tron #define poolLength(pool) ((pool)->ptr - (pool)->start)
    594  1.1      tron #define poolChop(pool) ((void)--(pool->ptr))
    595  1.1      tron #define poolLastChar(pool) (((pool)->ptr)[-1])
    596  1.1      tron #define poolDiscard(pool) ((pool)->ptr = (pool)->start)
    597  1.1      tron #define poolFinish(pool) ((pool)->start = (pool)->ptr)
    598  1.8      maya #define poolAppendChar(pool, c)                                                \
    599  1.8      maya   (((pool)->ptr == (pool)->end && ! poolGrow(pool))                            \
    600  1.8      maya        ? 0                                                                     \
    601  1.8      maya        : ((*((pool)->ptr)++ = c), 1))
    602  1.1      tron 
    603  1.1      tron struct XML_ParserStruct {
    604  1.8      maya   /* The first member must be m_userData so that the XML_GetUserData
    605  1.1      tron      macro works. */
    606  1.1      tron   void *m_userData;
    607  1.1      tron   void *m_handlerArg;
    608  1.1      tron   char *m_buffer;
    609  1.1      tron   const XML_Memory_Handling_Suite m_mem;
    610  1.1      tron   /* first character to be parsed */
    611  1.1      tron   const char *m_bufferPtr;
    612  1.1      tron   /* past last character to be parsed */
    613  1.1      tron   char *m_bufferEnd;
    614  1.8      maya   /* allocated end of m_buffer */
    615  1.1      tron   const char *m_bufferLim;
    616  1.1      tron   XML_Index m_parseEndByteIndex;
    617  1.1      tron   const char *m_parseEndPtr;
    618  1.1      tron   XML_Char *m_dataBuf;
    619  1.1      tron   XML_Char *m_dataBufEnd;
    620  1.1      tron   XML_StartElementHandler m_startElementHandler;
    621  1.1      tron   XML_EndElementHandler m_endElementHandler;
    622  1.1      tron   XML_CharacterDataHandler m_characterDataHandler;
    623  1.1      tron   XML_ProcessingInstructionHandler m_processingInstructionHandler;
    624  1.1      tron   XML_CommentHandler m_commentHandler;
    625  1.1      tron   XML_StartCdataSectionHandler m_startCdataSectionHandler;
    626  1.1      tron   XML_EndCdataSectionHandler m_endCdataSectionHandler;
    627  1.1      tron   XML_DefaultHandler m_defaultHandler;
    628  1.1      tron   XML_StartDoctypeDeclHandler m_startDoctypeDeclHandler;
    629  1.1      tron   XML_EndDoctypeDeclHandler m_endDoctypeDeclHandler;
    630  1.1      tron   XML_UnparsedEntityDeclHandler m_unparsedEntityDeclHandler;
    631  1.1      tron   XML_NotationDeclHandler m_notationDeclHandler;
    632  1.1      tron   XML_StartNamespaceDeclHandler m_startNamespaceDeclHandler;
    633  1.1      tron   XML_EndNamespaceDeclHandler m_endNamespaceDeclHandler;
    634  1.1      tron   XML_NotStandaloneHandler m_notStandaloneHandler;
    635  1.1      tron   XML_ExternalEntityRefHandler m_externalEntityRefHandler;
    636  1.1      tron   XML_Parser m_externalEntityRefHandlerArg;
    637  1.1      tron   XML_SkippedEntityHandler m_skippedEntityHandler;
    638  1.1      tron   XML_UnknownEncodingHandler m_unknownEncodingHandler;
    639  1.1      tron   XML_ElementDeclHandler m_elementDeclHandler;
    640  1.1      tron   XML_AttlistDeclHandler m_attlistDeclHandler;
    641  1.1      tron   XML_EntityDeclHandler m_entityDeclHandler;
    642  1.1      tron   XML_XmlDeclHandler m_xmlDeclHandler;
    643  1.1      tron   const ENCODING *m_encoding;
    644  1.1      tron   INIT_ENCODING m_initEncoding;
    645  1.1      tron   const ENCODING *m_internalEncoding;
    646  1.1      tron   const XML_Char *m_protocolEncodingName;
    647  1.1      tron   XML_Bool m_ns;
    648  1.1      tron   XML_Bool m_ns_triplets;
    649  1.1      tron   void *m_unknownEncodingMem;
    650  1.1      tron   void *m_unknownEncodingData;
    651  1.1      tron   void *m_unknownEncodingHandlerData;
    652  1.8      maya   void(XMLCALL *m_unknownEncodingRelease)(void *);
    653  1.1      tron   PROLOG_STATE m_prologState;
    654  1.1      tron   Processor *m_processor;
    655  1.1      tron   enum XML_Error m_errorCode;
    656  1.1      tron   const char *m_eventPtr;
    657  1.1      tron   const char *m_eventEndPtr;
    658  1.1      tron   const char *m_positionPtr;
    659  1.1      tron   OPEN_INTERNAL_ENTITY *m_openInternalEntities;
    660  1.1      tron   OPEN_INTERNAL_ENTITY *m_freeInternalEntities;
    661  1.1      tron   XML_Bool m_defaultExpandInternalEntities;
    662  1.1      tron   int m_tagLevel;
    663  1.1      tron   ENTITY *m_declEntity;
    664  1.1      tron   const XML_Char *m_doctypeName;
    665  1.1      tron   const XML_Char *m_doctypeSysid;
    666  1.1      tron   const XML_Char *m_doctypePubid;
    667  1.1      tron   const XML_Char *m_declAttributeType;
    668  1.1      tron   const XML_Char *m_declNotationName;
    669  1.1      tron   const XML_Char *m_declNotationPublicId;
    670  1.1      tron   ELEMENT_TYPE *m_declElementType;
    671  1.1      tron   ATTRIBUTE_ID *m_declAttributeId;
    672  1.1      tron   XML_Bool m_declAttributeIsCdata;
    673  1.1      tron   XML_Bool m_declAttributeIsId;
    674  1.1      tron   DTD *m_dtd;
    675  1.1      tron   const XML_Char *m_curBase;
    676  1.1      tron   TAG *m_tagStack;
    677  1.1      tron   TAG *m_freeTagList;
    678  1.1      tron   BINDING *m_inheritedBindings;
    679  1.1      tron   BINDING *m_freeBindingList;
    680  1.1      tron   int m_attsSize;
    681  1.1      tron   int m_nSpecifiedAtts;
    682  1.1      tron   int m_idAttIndex;
    683  1.1      tron   ATTRIBUTE *m_atts;
    684  1.1      tron   NS_ATT *m_nsAtts;
    685  1.1      tron   unsigned long m_nsAttsVersion;
    686  1.1      tron   unsigned char m_nsAttsPower;
    687  1.3       spz #ifdef XML_ATTR_INFO
    688  1.3       spz   XML_AttrInfo *m_attInfo;
    689  1.3       spz #endif
    690  1.1      tron   POSITION m_position;
    691  1.1      tron   STRING_POOL m_tempPool;
    692  1.1      tron   STRING_POOL m_temp2Pool;
    693  1.1      tron   char *m_groupConnector;
    694  1.1      tron   unsigned int m_groupSize;
    695  1.1      tron   XML_Char m_namespaceSeparator;
    696  1.1      tron   XML_Parser m_parentParser;
    697  1.1      tron   XML_ParsingStatus m_parsingStatus;
    698  1.1      tron #ifdef XML_DTD
    699  1.1      tron   XML_Bool m_isParamEntity;
    700  1.1      tron   XML_Bool m_useForeignDTD;
    701  1.1      tron   enum XML_ParamEntityParsing m_paramEntityParsing;
    702  1.1      tron #endif
    703  1.3       spz   unsigned long m_hash_secret_salt;
    704  1.9  christos #ifdef XML_DTD
    705  1.9  christos   ACCOUNTING m_accounting;
    706  1.9  christos   ENTITY_STATS m_entity_stats;
    707  1.9  christos #endif
    708  1.1      tron };
    709  1.1      tron 
    710  1.8      maya #define MALLOC(parser, s) (parser->m_mem.malloc_fcn((s)))
    711  1.8      maya #define REALLOC(parser, p, s) (parser->m_mem.realloc_fcn((p), (s)))
    712  1.8      maya #define FREE(parser, p) (parser->m_mem.free_fcn((p)))
    713  1.1      tron 
    714  1.1      tron XML_Parser XMLCALL
    715  1.8      maya XML_ParserCreate(const XML_Char *encodingName) {
    716  1.1      tron   return XML_ParserCreate_MM(encodingName, NULL, NULL);
    717  1.1      tron }
    718  1.1      tron 
    719  1.1      tron XML_Parser XMLCALL
    720  1.8      maya XML_ParserCreateNS(const XML_Char *encodingName, XML_Char nsSep) {
    721  1.9  christos   XML_Char tmp[2] = {nsSep, 0};
    722  1.1      tron   return XML_ParserCreate_MM(encodingName, NULL, tmp);
    723  1.1      tron }
    724  1.1      tron 
    725  1.8      maya static const XML_Char implicitContext[]
    726  1.8      maya     = {ASCII_x,     ASCII_m,     ASCII_l,      ASCII_EQUALS, ASCII_h,
    727  1.8      maya        ASCII_t,     ASCII_t,     ASCII_p,      ASCII_COLON,  ASCII_SLASH,
    728  1.8      maya        ASCII_SLASH, ASCII_w,     ASCII_w,      ASCII_w,      ASCII_PERIOD,
    729  1.8      maya        ASCII_w,     ASCII_3,     ASCII_PERIOD, ASCII_o,      ASCII_r,
    730  1.8      maya        ASCII_g,     ASCII_SLASH, ASCII_X,      ASCII_M,      ASCII_L,
    731  1.8      maya        ASCII_SLASH, ASCII_1,     ASCII_9,      ASCII_9,      ASCII_8,
    732  1.8      maya        ASCII_SLASH, ASCII_n,     ASCII_a,      ASCII_m,      ASCII_e,
    733  1.8      maya        ASCII_s,     ASCII_p,     ASCII_a,      ASCII_c,      ASCII_e,
    734  1.8      maya        '\0'};
    735  1.7  christos 
    736  1.8      maya /* To avoid warnings about unused functions: */
    737  1.8      maya #if ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM)
    738  1.7  christos 
    739  1.8      maya #  if defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
    740  1.7  christos 
    741  1.7  christos /* Obtain entropy on Linux 3.17+ */
    742  1.7  christos static int
    743  1.8      maya writeRandomBytes_getrandom_nonblock(void *target, size_t count) {
    744  1.8      maya   int success = 0; /* full count bytes written? */
    745  1.7  christos   size_t bytesWrittenTotal = 0;
    746  1.8      maya   const unsigned int getrandomFlags = GRND_NONBLOCK;
    747  1.7  christos 
    748  1.7  christos   do {
    749  1.8      maya     void *const currentTarget = (void *)((char *)target + bytesWrittenTotal);
    750  1.7  christos     const size_t bytesToWrite = count - bytesWrittenTotal;
    751  1.7  christos 
    752  1.7  christos     const int bytesWrittenMore =
    753  1.8      maya #    if defined(HAVE_GETRANDOM)
    754  1.7  christos         getrandom(currentTarget, bytesToWrite, getrandomFlags);
    755  1.8      maya #    else
    756  1.7  christos         syscall(SYS_getrandom, currentTarget, bytesToWrite, getrandomFlags);
    757  1.8      maya #    endif
    758  1.8      maya 
    759  1.8      maya     if (bytesWrittenMore > 0) {
    760  1.8      maya       bytesWrittenTotal += bytesWrittenMore;
    761  1.8      maya       if (bytesWrittenTotal >= count)
    762  1.8      maya         success = 1;
    763  1.8      maya     }
    764  1.8      maya   } while (! success && (errno == EINTR));
    765  1.8      maya 
    766  1.8      maya   return success;
    767  1.8      maya }
    768  1.8      maya 
    769  1.8      maya #  endif /* defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM) */
    770  1.8      maya 
    771  1.8      maya #  if ! defined(_WIN32) && defined(XML_DEV_URANDOM)
    772  1.8      maya 
    773  1.8      maya /* Extract entropy from /dev/urandom */
    774  1.8      maya static int
    775  1.8      maya writeRandomBytes_dev_urandom(void *target, size_t count) {
    776  1.8      maya   int success = 0; /* full count bytes written? */
    777  1.8      maya   size_t bytesWrittenTotal = 0;
    778  1.8      maya 
    779  1.8      maya   const int fd = open("/dev/urandom", O_RDONLY);
    780  1.8      maya   if (fd < 0) {
    781  1.8      maya     return 0;
    782  1.8      maya   }
    783  1.8      maya 
    784  1.8      maya   do {
    785  1.8      maya     void *const currentTarget = (void *)((char *)target + bytesWrittenTotal);
    786  1.8      maya     const size_t bytesToWrite = count - bytesWrittenTotal;
    787  1.8      maya 
    788  1.8      maya     const ssize_t bytesWrittenMore = read(fd, currentTarget, bytesToWrite);
    789  1.7  christos 
    790  1.7  christos     if (bytesWrittenMore > 0) {
    791  1.7  christos       bytesWrittenTotal += bytesWrittenMore;
    792  1.7  christos       if (bytesWrittenTotal >= count)
    793  1.7  christos         success = 1;
    794  1.7  christos     }
    795  1.8      maya   } while (! success && (errno == EINTR));
    796  1.7  christos 
    797  1.8      maya   close(fd);
    798  1.7  christos   return success;
    799  1.7  christos }
    800  1.7  christos 
    801  1.8      maya #  endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
    802  1.7  christos 
    803  1.8      maya #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */
    804  1.8      maya 
    805  1.8      maya #if defined(HAVE_ARC4RANDOM) && ! defined(HAVE_ARC4RANDOM_BUF)
    806  1.8      maya 
    807  1.8      maya static void
    808  1.8      maya writeRandomBytes_arc4random(void *target, size_t count) {
    809  1.8      maya   size_t bytesWrittenTotal = 0;
    810  1.8      maya 
    811  1.8      maya   while (bytesWrittenTotal < count) {
    812  1.8      maya     const uint32_t random32 = arc4random();
    813  1.8      maya     size_t i = 0;
    814  1.8      maya 
    815  1.8      maya     for (; (i < sizeof(random32)) && (bytesWrittenTotal < count);
    816  1.8      maya          i++, bytesWrittenTotal++) {
    817  1.8      maya       const uint8_t random8 = (uint8_t)(random32 >> (i * 8));
    818  1.8      maya       ((uint8_t *)target)[bytesWrittenTotal] = random8;
    819  1.8      maya     }
    820  1.8      maya   }
    821  1.8      maya }
    822  1.8      maya 
    823  1.8      maya #endif /* defined(HAVE_ARC4RANDOM) && ! defined(HAVE_ARC4RANDOM_BUF) */
    824  1.7  christos 
    825  1.7  christos #ifdef _WIN32
    826  1.7  christos 
    827  1.9  christos /* Provide declaration of rand_s() for MinGW-32 (not 64, which has it),
    828  1.9  christos    as it didn't declare it in its header prior to version 5.3.0 of its
    829  1.9  christos    runtime package (mingwrt, containing stdlib.h).  The upstream fix
    830  1.9  christos    was introduced at https://osdn.net/projects/mingw/ticket/39658 . */
    831  1.9  christos #  if defined(__MINGW32__) && defined(__MINGW32_VERSION)                       \
    832  1.9  christos       && __MINGW32_VERSION < 5003000L && ! defined(__MINGW64_VERSION_MAJOR)
    833  1.9  christos __declspec(dllimport) int rand_s(unsigned int *);
    834  1.9  christos #  endif
    835  1.9  christos 
    836  1.8      maya /* Obtain entropy on Windows using the rand_s() function which
    837  1.8      maya  * generates cryptographically secure random numbers.  Internally it
    838  1.8      maya  * uses RtlGenRandom API which is present in Windows XP and later.
    839  1.7  christos  */
    840  1.7  christos static int
    841  1.8      maya writeRandomBytes_rand_s(void *target, size_t count) {
    842  1.8      maya   size_t bytesWrittenTotal = 0;
    843  1.8      maya 
    844  1.8      maya   while (bytesWrittenTotal < count) {
    845  1.8      maya     unsigned int random32 = 0;
    846  1.8      maya     size_t i = 0;
    847  1.8      maya 
    848  1.8      maya     if (rand_s(&random32))
    849  1.8      maya       return 0; /* failure */
    850  1.8      maya 
    851  1.8      maya     for (; (i < sizeof(random32)) && (bytesWrittenTotal < count);
    852  1.8      maya          i++, bytesWrittenTotal++) {
    853  1.8      maya       const uint8_t random8 = (uint8_t)(random32 >> (i * 8));
    854  1.8      maya       ((uint8_t *)target)[bytesWrittenTotal] = random8;
    855  1.7  christos     }
    856  1.7  christos   }
    857  1.8      maya   return 1; /* success */
    858  1.7  christos }
    859  1.7  christos 
    860  1.7  christos #endif /* _WIN32 */
    861  1.7  christos 
    862  1.8      maya #if ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM)
    863  1.7  christos 
    864  1.3       spz static unsigned long
    865  1.8      maya gather_time_entropy(void) {
    866  1.8      maya #  ifdef _WIN32
    867  1.6       spz   FILETIME ft;
    868  1.6       spz   GetSystemTimeAsFileTime(&ft); /* never fails */
    869  1.6       spz   return ft.dwHighDateTime ^ ft.dwLowDateTime;
    870  1.8      maya #  else
    871  1.6       spz   struct timeval tv;
    872  1.6       spz   int gettimeofday_res;
    873  1.6       spz 
    874  1.6       spz   gettimeofday_res = gettimeofday(&tv, NULL);
    875  1.8      maya 
    876  1.8      maya #    if defined(NDEBUG)
    877  1.8      maya   (void)gettimeofday_res;
    878  1.8      maya #    else
    879  1.8      maya   assert(gettimeofday_res == 0);
    880  1.8      maya #    endif /* defined(NDEBUG) */
    881  1.6       spz 
    882  1.6       spz   /* Microseconds time is <20 bits entropy */
    883  1.6       spz   return tv.tv_usec;
    884  1.8      maya #  endif
    885  1.6       spz }
    886  1.6       spz 
    887  1.8      maya #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */
    888  1.7  christos 
    889  1.7  christos static unsigned long
    890  1.8      maya ENTROPY_DEBUG(const char *label, unsigned long entropy) {
    891  1.9  christos   if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) {
    892  1.9  christos     fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label,
    893  1.8      maya             (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy));
    894  1.7  christos   }
    895  1.7  christos   return entropy;
    896  1.7  christos }
    897  1.7  christos 
    898  1.6       spz static unsigned long
    899  1.8      maya generate_hash_secret_salt(XML_Parser parser) {
    900  1.7  christos   unsigned long entropy;
    901  1.7  christos   (void)parser;
    902  1.8      maya 
    903  1.8      maya   /* "Failproof" high quality providers: */
    904  1.8      maya #if defined(HAVE_ARC4RANDOM_BUF)
    905  1.7  christos   arc4random_buf(&entropy, sizeof(entropy));
    906  1.7  christos   return ENTROPY_DEBUG("arc4random_buf", entropy);
    907  1.8      maya #elif defined(HAVE_ARC4RANDOM)
    908  1.8      maya   writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy));
    909  1.8      maya   return ENTROPY_DEBUG("arc4random", entropy);
    910  1.7  christos #else
    911  1.7  christos   /* Try high quality providers first .. */
    912  1.8      maya #  ifdef _WIN32
    913  1.8      maya   if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) {
    914  1.8      maya     return ENTROPY_DEBUG("rand_s", entropy);
    915  1.7  christos   }
    916  1.8      maya #  elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
    917  1.8      maya   if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) {
    918  1.7  christos     return ENTROPY_DEBUG("getrandom", entropy);
    919  1.7  christos   }
    920  1.8      maya #  endif
    921  1.8      maya #  if ! defined(_WIN32) && defined(XML_DEV_URANDOM)
    922  1.8      maya   if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) {
    923  1.8      maya     return ENTROPY_DEBUG("/dev/urandom", entropy);
    924  1.8      maya   }
    925  1.8      maya #  endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
    926  1.7  christos   /* .. and self-made low quality for backup: */
    927  1.7  christos 
    928  1.7  christos   /* Process ID is 0 bits entropy if attacker has local access */
    929  1.7  christos   entropy = gather_time_entropy() ^ getpid();
    930  1.6       spz 
    931  1.6       spz   /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */
    932  1.6       spz   if (sizeof(unsigned long) == 4) {
    933  1.7  christos     return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647);
    934  1.6       spz   } else {
    935  1.7  christos     return ENTROPY_DEBUG("fallback(8)",
    936  1.8      maya                          entropy * (unsigned long)2305843009213693951ULL);
    937  1.6       spz   }
    938  1.7  christos #endif
    939  1.7  christos }
    940  1.7  christos 
    941  1.7  christos static unsigned long
    942  1.7  christos get_hash_secret_salt(XML_Parser parser) {
    943  1.7  christos   if (parser->m_parentParser != NULL)
    944  1.7  christos     return get_hash_secret_salt(parser->m_parentParser);
    945  1.7  christos   return parser->m_hash_secret_salt;
    946  1.3       spz }
    947  1.3       spz 
    948  1.8      maya static XML_Bool /* only valid for root parser */
    949  1.8      maya startParsing(XML_Parser parser) {
    950  1.8      maya   /* hash functions must be initialized before setContext() is called */
    951  1.8      maya   if (parser->m_hash_secret_salt == 0)
    952  1.8      maya     parser->m_hash_secret_salt = generate_hash_secret_salt(parser);
    953  1.8      maya   if (parser->m_ns) {
    954  1.8      maya     /* implicit context only set for root parser, since child
    955  1.8      maya        parsers (i.e. external entity parsers) will inherit it
    956  1.8      maya     */
    957  1.8      maya     return setContext(parser, implicitContext);
    958  1.8      maya   }
    959  1.8      maya   return XML_TRUE;
    960  1.3       spz }
    961  1.3       spz 
    962  1.1      tron XML_Parser XMLCALL
    963  1.1      tron XML_ParserCreate_MM(const XML_Char *encodingName,
    964  1.1      tron                     const XML_Memory_Handling_Suite *memsuite,
    965  1.8      maya                     const XML_Char *nameSep) {
    966  1.3       spz   return parserCreate(encodingName, memsuite, nameSep, NULL);
    967  1.1      tron }
    968  1.1      tron 
    969  1.1      tron static XML_Parser
    970  1.1      tron parserCreate(const XML_Char *encodingName,
    971  1.8      maya              const XML_Memory_Handling_Suite *memsuite, const XML_Char *nameSep,
    972  1.8      maya              DTD *dtd) {
    973  1.1      tron   XML_Parser parser;
    974  1.1      tron 
    975  1.1      tron   if (memsuite) {
    976  1.1      tron     XML_Memory_Handling_Suite *mtemp;
    977  1.9  christos     parser = memsuite->malloc_fcn(sizeof(struct XML_ParserStruct));
    978  1.1      tron     if (parser != NULL) {
    979  1.1      tron       mtemp = (XML_Memory_Handling_Suite *)&(parser->m_mem);
    980  1.1      tron       mtemp->malloc_fcn = memsuite->malloc_fcn;
    981  1.1      tron       mtemp->realloc_fcn = memsuite->realloc_fcn;
    982  1.1      tron       mtemp->free_fcn = memsuite->free_fcn;
    983  1.1      tron     }
    984  1.8      maya   } else {
    985  1.1      tron     XML_Memory_Handling_Suite *mtemp;
    986  1.1      tron     parser = (XML_Parser)malloc(sizeof(struct XML_ParserStruct));
    987  1.1      tron     if (parser != NULL) {
    988  1.1      tron       mtemp = (XML_Memory_Handling_Suite *)&(parser->m_mem);
    989  1.1      tron       mtemp->malloc_fcn = malloc;
    990  1.1      tron       mtemp->realloc_fcn = realloc;
    991  1.1      tron       mtemp->free_fcn = free;
    992  1.1      tron     }
    993  1.1      tron   }
    994  1.1      tron 
    995  1.8      maya   if (! parser)
    996  1.1      tron     return parser;
    997  1.1      tron 
    998  1.8      maya   parser->m_buffer = NULL;
    999  1.8      maya   parser->m_bufferLim = NULL;
   1000  1.1      tron 
   1001  1.8      maya   parser->m_attsSize = INIT_ATTS_SIZE;
   1002  1.8      maya   parser->m_atts
   1003  1.8      maya       = (ATTRIBUTE *)MALLOC(parser, parser->m_attsSize * sizeof(ATTRIBUTE));
   1004  1.8      maya   if (parser->m_atts == NULL) {
   1005  1.8      maya     FREE(parser, parser);
   1006  1.1      tron     return NULL;
   1007  1.1      tron   }
   1008  1.3       spz #ifdef XML_ATTR_INFO
   1009  1.8      maya   parser->m_attInfo = (XML_AttrInfo *)MALLOC(
   1010  1.8      maya       parser, parser->m_attsSize * sizeof(XML_AttrInfo));
   1011  1.8      maya   if (parser->m_attInfo == NULL) {
   1012  1.8      maya     FREE(parser, parser->m_atts);
   1013  1.8      maya     FREE(parser, parser);
   1014  1.3       spz     return NULL;
   1015  1.3       spz   }
   1016  1.3       spz #endif
   1017  1.8      maya   parser->m_dataBuf
   1018  1.8      maya       = (XML_Char *)MALLOC(parser, INIT_DATA_BUF_SIZE * sizeof(XML_Char));
   1019  1.8      maya   if (parser->m_dataBuf == NULL) {
   1020  1.8      maya     FREE(parser, parser->m_atts);
   1021  1.3       spz #ifdef XML_ATTR_INFO
   1022  1.8      maya     FREE(parser, parser->m_attInfo);
   1023  1.3       spz #endif
   1024  1.8      maya     FREE(parser, parser);
   1025  1.1      tron     return NULL;
   1026  1.1      tron   }
   1027  1.8      maya   parser->m_dataBufEnd = parser->m_dataBuf + INIT_DATA_BUF_SIZE;
   1028  1.1      tron 
   1029  1.1      tron   if (dtd)
   1030  1.8      maya     parser->m_dtd = dtd;
   1031  1.1      tron   else {
   1032  1.8      maya     parser->m_dtd = dtdCreate(&parser->m_mem);
   1033  1.8      maya     if (parser->m_dtd == NULL) {
   1034  1.8      maya       FREE(parser, parser->m_dataBuf);
   1035  1.8      maya       FREE(parser, parser->m_atts);
   1036  1.3       spz #ifdef XML_ATTR_INFO
   1037  1.8      maya       FREE(parser, parser->m_attInfo);
   1038  1.3       spz #endif
   1039  1.8      maya       FREE(parser, parser);
   1040  1.1      tron       return NULL;
   1041  1.1      tron     }
   1042  1.1      tron   }
   1043  1.1      tron 
   1044  1.8      maya   parser->m_freeBindingList = NULL;
   1045  1.8      maya   parser->m_freeTagList = NULL;
   1046  1.8      maya   parser->m_freeInternalEntities = NULL;
   1047  1.8      maya 
   1048  1.8      maya   parser->m_groupSize = 0;
   1049  1.8      maya   parser->m_groupConnector = NULL;
   1050  1.1      tron 
   1051  1.8      maya   parser->m_unknownEncodingHandler = NULL;
   1052  1.8      maya   parser->m_unknownEncodingHandlerData = NULL;
   1053  1.8      maya 
   1054  1.8      maya   parser->m_namespaceSeparator = ASCII_EXCL;
   1055  1.8      maya   parser->m_ns = XML_FALSE;
   1056  1.8      maya   parser->m_ns_triplets = XML_FALSE;
   1057  1.8      maya 
   1058  1.8      maya   parser->m_nsAtts = NULL;
   1059  1.8      maya   parser->m_nsAttsVersion = 0;
   1060  1.8      maya   parser->m_nsAttsPower = 0;
   1061  1.8      maya 
   1062  1.8      maya   parser->m_protocolEncodingName = NULL;
   1063  1.8      maya 
   1064  1.8      maya   poolInit(&parser->m_tempPool, &(parser->m_mem));
   1065  1.8      maya   poolInit(&parser->m_temp2Pool, &(parser->m_mem));
   1066  1.1      tron   parserInit(parser, encodingName);
   1067  1.1      tron 
   1068  1.8      maya   if (encodingName && ! parser->m_protocolEncodingName) {
   1069  1.1      tron     XML_ParserFree(parser);
   1070  1.1      tron     return NULL;
   1071  1.1      tron   }
   1072  1.1      tron 
   1073  1.1      tron   if (nameSep) {
   1074  1.8      maya     parser->m_ns = XML_TRUE;
   1075  1.8      maya     parser->m_internalEncoding = XmlGetInternalEncodingNS();
   1076  1.8      maya     parser->m_namespaceSeparator = *nameSep;
   1077  1.8      maya   } else {
   1078  1.8      maya     parser->m_internalEncoding = XmlGetInternalEncoding();
   1079  1.1      tron   }
   1080  1.1      tron 
   1081  1.1      tron   return parser;
   1082  1.1      tron }
   1083  1.1      tron 
   1084  1.1      tron static void
   1085  1.8      maya parserInit(XML_Parser parser, const XML_Char *encodingName) {
   1086  1.8      maya   parser->m_processor = prologInitProcessor;
   1087  1.8      maya   XmlPrologStateInit(&parser->m_prologState);
   1088  1.8      maya   if (encodingName != NULL) {
   1089  1.8      maya     parser->m_protocolEncodingName = copyString(encodingName, &(parser->m_mem));
   1090  1.8      maya   }
   1091  1.8      maya   parser->m_curBase = NULL;
   1092  1.8      maya   XmlInitEncoding(&parser->m_initEncoding, &parser->m_encoding, 0);
   1093  1.8      maya   parser->m_userData = NULL;
   1094  1.8      maya   parser->m_handlerArg = NULL;
   1095  1.8      maya   parser->m_startElementHandler = NULL;
   1096  1.8      maya   parser->m_endElementHandler = NULL;
   1097  1.8      maya   parser->m_characterDataHandler = NULL;
   1098  1.8      maya   parser->m_processingInstructionHandler = NULL;
   1099  1.8      maya   parser->m_commentHandler = NULL;
   1100  1.8      maya   parser->m_startCdataSectionHandler = NULL;
   1101  1.8      maya   parser->m_endCdataSectionHandler = NULL;
   1102  1.8      maya   parser->m_defaultHandler = NULL;
   1103  1.8      maya   parser->m_startDoctypeDeclHandler = NULL;
   1104  1.8      maya   parser->m_endDoctypeDeclHandler = NULL;
   1105  1.8      maya   parser->m_unparsedEntityDeclHandler = NULL;
   1106  1.8      maya   parser->m_notationDeclHandler = NULL;
   1107  1.8      maya   parser->m_startNamespaceDeclHandler = NULL;
   1108  1.8      maya   parser->m_endNamespaceDeclHandler = NULL;
   1109  1.8      maya   parser->m_notStandaloneHandler = NULL;
   1110  1.8      maya   parser->m_externalEntityRefHandler = NULL;
   1111  1.8      maya   parser->m_externalEntityRefHandlerArg = parser;
   1112  1.8      maya   parser->m_skippedEntityHandler = NULL;
   1113  1.8      maya   parser->m_elementDeclHandler = NULL;
   1114  1.8      maya   parser->m_attlistDeclHandler = NULL;
   1115  1.8      maya   parser->m_entityDeclHandler = NULL;
   1116  1.8      maya   parser->m_xmlDeclHandler = NULL;
   1117  1.8      maya   parser->m_bufferPtr = parser->m_buffer;
   1118  1.8      maya   parser->m_bufferEnd = parser->m_buffer;
   1119  1.8      maya   parser->m_parseEndByteIndex = 0;
   1120  1.8      maya   parser->m_parseEndPtr = NULL;
   1121  1.8      maya   parser->m_declElementType = NULL;
   1122  1.8      maya   parser->m_declAttributeId = NULL;
   1123  1.8      maya   parser->m_declEntity = NULL;
   1124  1.8      maya   parser->m_doctypeName = NULL;
   1125  1.8      maya   parser->m_doctypeSysid = NULL;
   1126  1.8      maya   parser->m_doctypePubid = NULL;
   1127  1.8      maya   parser->m_declAttributeType = NULL;
   1128  1.8      maya   parser->m_declNotationName = NULL;
   1129  1.8      maya   parser->m_declNotationPublicId = NULL;
   1130  1.8      maya   parser->m_declAttributeIsCdata = XML_FALSE;
   1131  1.8      maya   parser->m_declAttributeIsId = XML_FALSE;
   1132  1.8      maya   memset(&parser->m_position, 0, sizeof(POSITION));
   1133  1.8      maya   parser->m_errorCode = XML_ERROR_NONE;
   1134  1.8      maya   parser->m_eventPtr = NULL;
   1135  1.8      maya   parser->m_eventEndPtr = NULL;
   1136  1.8      maya   parser->m_positionPtr = NULL;
   1137  1.8      maya   parser->m_openInternalEntities = NULL;
   1138  1.8      maya   parser->m_defaultExpandInternalEntities = XML_TRUE;
   1139  1.8      maya   parser->m_tagLevel = 0;
   1140  1.8      maya   parser->m_tagStack = NULL;
   1141  1.8      maya   parser->m_inheritedBindings = NULL;
   1142  1.8      maya   parser->m_nSpecifiedAtts = 0;
   1143  1.8      maya   parser->m_unknownEncodingMem = NULL;
   1144  1.8      maya   parser->m_unknownEncodingRelease = NULL;
   1145  1.8      maya   parser->m_unknownEncodingData = NULL;
   1146  1.8      maya   parser->m_parentParser = NULL;
   1147  1.8      maya   parser->m_parsingStatus.parsing = XML_INITIALIZED;
   1148  1.8      maya #ifdef XML_DTD
   1149  1.8      maya   parser->m_isParamEntity = XML_FALSE;
   1150  1.8      maya   parser->m_useForeignDTD = XML_FALSE;
   1151  1.8      maya   parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER;
   1152  1.1      tron #endif
   1153  1.8      maya   parser->m_hash_secret_salt = 0;
   1154  1.9  christos 
   1155  1.9  christos #ifdef XML_DTD
   1156  1.9  christos   memset(&parser->m_accounting, 0, sizeof(ACCOUNTING));
   1157  1.9  christos   parser->m_accounting.debugLevel = getDebugLevel("EXPAT_ACCOUNTING_DEBUG", 0u);
   1158  1.9  christos   parser->m_accounting.maximumAmplificationFactor
   1159  1.9  christos       = EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT;
   1160  1.9  christos   parser->m_accounting.activationThresholdBytes
   1161  1.9  christos       = EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT;
   1162  1.9  christos 
   1163  1.9  christos   memset(&parser->m_entity_stats, 0, sizeof(ENTITY_STATS));
   1164  1.9  christos   parser->m_entity_stats.debugLevel = getDebugLevel("EXPAT_ENTITY_DEBUG", 0u);
   1165  1.9  christos #endif
   1166  1.1      tron }
   1167  1.1      tron 
   1168  1.8      maya /* moves list of bindings to m_freeBindingList */
   1169  1.1      tron static void FASTCALL
   1170  1.8      maya moveToFreeBindingList(XML_Parser parser, BINDING *bindings) {
   1171  1.1      tron   while (bindings) {
   1172  1.1      tron     BINDING *b = bindings;
   1173  1.1      tron     bindings = bindings->nextTagBinding;
   1174  1.8      maya     b->nextTagBinding = parser->m_freeBindingList;
   1175  1.8      maya     parser->m_freeBindingList = b;
   1176  1.1      tron   }
   1177  1.1      tron }
   1178  1.1      tron 
   1179  1.1      tron XML_Bool XMLCALL
   1180  1.8      maya XML_ParserReset(XML_Parser parser, const XML_Char *encodingName) {
   1181  1.1      tron   TAG *tStk;
   1182  1.1      tron   OPEN_INTERNAL_ENTITY *openEntityList;
   1183  1.7  christos 
   1184  1.7  christos   if (parser == NULL)
   1185  1.8      maya     return XML_FALSE;
   1186  1.7  christos 
   1187  1.8      maya   if (parser->m_parentParser)
   1188  1.1      tron     return XML_FALSE;
   1189  1.8      maya   /* move m_tagStack to m_freeTagList */
   1190  1.8      maya   tStk = parser->m_tagStack;
   1191  1.1      tron   while (tStk) {
   1192  1.1      tron     TAG *tag = tStk;
   1193  1.1      tron     tStk = tStk->parent;
   1194  1.8      maya     tag->parent = parser->m_freeTagList;
   1195  1.1      tron     moveToFreeBindingList(parser, tag->bindings);
   1196  1.1      tron     tag->bindings = NULL;
   1197  1.8      maya     parser->m_freeTagList = tag;
   1198  1.1      tron   }
   1199  1.8      maya   /* move m_openInternalEntities to m_freeInternalEntities */
   1200  1.8      maya   openEntityList = parser->m_openInternalEntities;
   1201  1.1      tron   while (openEntityList) {
   1202  1.1      tron     OPEN_INTERNAL_ENTITY *openEntity = openEntityList;
   1203  1.1      tron     openEntityList = openEntity->next;
   1204  1.8      maya     openEntity->next = parser->m_freeInternalEntities;
   1205  1.8      maya     parser->m_freeInternalEntities = openEntity;
   1206  1.1      tron   }
   1207  1.8      maya   moveToFreeBindingList(parser, parser->m_inheritedBindings);
   1208  1.8      maya   FREE(parser, parser->m_unknownEncodingMem);
   1209  1.8      maya   if (parser->m_unknownEncodingRelease)
   1210  1.8      maya     parser->m_unknownEncodingRelease(parser->m_unknownEncodingData);
   1211  1.8      maya   poolClear(&parser->m_tempPool);
   1212  1.8      maya   poolClear(&parser->m_temp2Pool);
   1213  1.8      maya   FREE(parser, (void *)parser->m_protocolEncodingName);
   1214  1.8      maya   parser->m_protocolEncodingName = NULL;
   1215  1.1      tron   parserInit(parser, encodingName);
   1216  1.8      maya   dtdReset(parser->m_dtd, &parser->m_mem);
   1217  1.3       spz   return XML_TRUE;
   1218  1.1      tron }
   1219  1.1      tron 
   1220  1.1      tron enum XML_Status XMLCALL
   1221  1.8      maya XML_SetEncoding(XML_Parser parser, const XML_Char *encodingName) {
   1222  1.7  christos   if (parser == NULL)
   1223  1.8      maya     return XML_STATUS_ERROR;
   1224  1.1      tron   /* Block after XML_Parse()/XML_ParseBuffer() has been called.
   1225  1.1      tron      XXX There's no way for the caller to determine which of the
   1226  1.1      tron      XXX possible error cases caused the XML_STATUS_ERROR return.
   1227  1.1      tron   */
   1228  1.8      maya   if (parser->m_parsingStatus.parsing == XML_PARSING
   1229  1.8      maya       || parser->m_parsingStatus.parsing == XML_SUSPENDED)
   1230  1.1      tron     return XML_STATUS_ERROR;
   1231  1.8      maya 
   1232  1.8      maya   /* Get rid of any previous encoding name */
   1233  1.8      maya   FREE(parser, (void *)parser->m_protocolEncodingName);
   1234  1.8      maya 
   1235  1.1      tron   if (encodingName == NULL)
   1236  1.8      maya     /* No new encoding name */
   1237  1.8      maya     parser->m_protocolEncodingName = NULL;
   1238  1.1      tron   else {
   1239  1.8      maya     /* Copy the new encoding name into allocated memory */
   1240  1.8      maya     parser->m_protocolEncodingName = copyString(encodingName, &(parser->m_mem));
   1241  1.8      maya     if (! parser->m_protocolEncodingName)
   1242  1.1      tron       return XML_STATUS_ERROR;
   1243  1.1      tron   }
   1244  1.1      tron   return XML_STATUS_OK;
   1245  1.1      tron }
   1246  1.1      tron 
   1247  1.1      tron XML_Parser XMLCALL
   1248  1.8      maya XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
   1249  1.8      maya                                const XML_Char *encodingName) {
   1250  1.1      tron   XML_Parser parser = oldParser;
   1251  1.1      tron   DTD *newDtd = NULL;
   1252  1.7  christos   DTD *oldDtd;
   1253  1.7  christos   XML_StartElementHandler oldStartElementHandler;
   1254  1.7  christos   XML_EndElementHandler oldEndElementHandler;
   1255  1.7  christos   XML_CharacterDataHandler oldCharacterDataHandler;
   1256  1.7  christos   XML_ProcessingInstructionHandler oldProcessingInstructionHandler;
   1257  1.7  christos   XML_CommentHandler oldCommentHandler;
   1258  1.7  christos   XML_StartCdataSectionHandler oldStartCdataSectionHandler;
   1259  1.7  christos   XML_EndCdataSectionHandler oldEndCdataSectionHandler;
   1260  1.7  christos   XML_DefaultHandler oldDefaultHandler;
   1261  1.7  christos   XML_UnparsedEntityDeclHandler oldUnparsedEntityDeclHandler;
   1262  1.7  christos   XML_NotationDeclHandler oldNotationDeclHandler;
   1263  1.7  christos   XML_StartNamespaceDeclHandler oldStartNamespaceDeclHandler;
   1264  1.7  christos   XML_EndNamespaceDeclHandler oldEndNamespaceDeclHandler;
   1265  1.7  christos   XML_NotStandaloneHandler oldNotStandaloneHandler;
   1266  1.7  christos   XML_ExternalEntityRefHandler oldExternalEntityRefHandler;
   1267  1.7  christos   XML_SkippedEntityHandler oldSkippedEntityHandler;
   1268  1.7  christos   XML_UnknownEncodingHandler oldUnknownEncodingHandler;
   1269  1.7  christos   XML_ElementDeclHandler oldElementDeclHandler;
   1270  1.7  christos   XML_AttlistDeclHandler oldAttlistDeclHandler;
   1271  1.7  christos   XML_EntityDeclHandler oldEntityDeclHandler;
   1272  1.7  christos   XML_XmlDeclHandler oldXmlDeclHandler;
   1273  1.8      maya   ELEMENT_TYPE *oldDeclElementType;
   1274  1.7  christos 
   1275  1.7  christos   void *oldUserData;
   1276  1.7  christos   void *oldHandlerArg;
   1277  1.7  christos   XML_Bool oldDefaultExpandInternalEntities;
   1278  1.7  christos   XML_Parser oldExternalEntityRefHandlerArg;
   1279  1.1      tron #ifdef XML_DTD
   1280  1.7  christos   enum XML_ParamEntityParsing oldParamEntityParsing;
   1281  1.7  christos   int oldInEntityValue;
   1282  1.7  christos #endif
   1283  1.7  christos   XML_Bool oldns_triplets;
   1284  1.7  christos   /* Note that the new parser shares the same hash secret as the old
   1285  1.7  christos      parser, so that dtdCopy and copyEntityTable can lookup values
   1286  1.7  christos      from hash tables associated with either parser without us having
   1287  1.7  christos      to worry which hash secrets each table has.
   1288  1.7  christos   */
   1289  1.7  christos   unsigned long oldhash_secret_salt;
   1290  1.7  christos 
   1291  1.7  christos   /* Validate the oldParser parameter before we pull everything out of it */
   1292  1.7  christos   if (oldParser == NULL)
   1293  1.7  christos     return NULL;
   1294  1.7  christos 
   1295  1.7  christos   /* Stash the original parser contents on the stack */
   1296  1.8      maya   oldDtd = parser->m_dtd;
   1297  1.8      maya   oldStartElementHandler = parser->m_startElementHandler;
   1298  1.8      maya   oldEndElementHandler = parser->m_endElementHandler;
   1299  1.8      maya   oldCharacterDataHandler = parser->m_characterDataHandler;
   1300  1.8      maya   oldProcessingInstructionHandler = parser->m_processingInstructionHandler;
   1301  1.8      maya   oldCommentHandler = parser->m_commentHandler;
   1302  1.8      maya   oldStartCdataSectionHandler = parser->m_startCdataSectionHandler;
   1303  1.8      maya   oldEndCdataSectionHandler = parser->m_endCdataSectionHandler;
   1304  1.8      maya   oldDefaultHandler = parser->m_defaultHandler;
   1305  1.8      maya   oldUnparsedEntityDeclHandler = parser->m_unparsedEntityDeclHandler;
   1306  1.8      maya   oldNotationDeclHandler = parser->m_notationDeclHandler;
   1307  1.8      maya   oldStartNamespaceDeclHandler = parser->m_startNamespaceDeclHandler;
   1308  1.8      maya   oldEndNamespaceDeclHandler = parser->m_endNamespaceDeclHandler;
   1309  1.8      maya   oldNotStandaloneHandler = parser->m_notStandaloneHandler;
   1310  1.8      maya   oldExternalEntityRefHandler = parser->m_externalEntityRefHandler;
   1311  1.8      maya   oldSkippedEntityHandler = parser->m_skippedEntityHandler;
   1312  1.8      maya   oldUnknownEncodingHandler = parser->m_unknownEncodingHandler;
   1313  1.8      maya   oldElementDeclHandler = parser->m_elementDeclHandler;
   1314  1.8      maya   oldAttlistDeclHandler = parser->m_attlistDeclHandler;
   1315  1.8      maya   oldEntityDeclHandler = parser->m_entityDeclHandler;
   1316  1.8      maya   oldXmlDeclHandler = parser->m_xmlDeclHandler;
   1317  1.8      maya   oldDeclElementType = parser->m_declElementType;
   1318  1.8      maya 
   1319  1.8      maya   oldUserData = parser->m_userData;
   1320  1.8      maya   oldHandlerArg = parser->m_handlerArg;
   1321  1.8      maya   oldDefaultExpandInternalEntities = parser->m_defaultExpandInternalEntities;
   1322  1.8      maya   oldExternalEntityRefHandlerArg = parser->m_externalEntityRefHandlerArg;
   1323  1.7  christos #ifdef XML_DTD
   1324  1.8      maya   oldParamEntityParsing = parser->m_paramEntityParsing;
   1325  1.8      maya   oldInEntityValue = parser->m_prologState.inEntityValue;
   1326  1.1      tron #endif
   1327  1.8      maya   oldns_triplets = parser->m_ns_triplets;
   1328  1.3       spz   /* Note that the new parser shares the same hash secret as the old
   1329  1.3       spz      parser, so that dtdCopy and copyEntityTable can lookup values
   1330  1.3       spz      from hash tables associated with either parser without us having
   1331  1.3       spz      to worry which hash secrets each table has.
   1332  1.3       spz   */
   1333  1.8      maya   oldhash_secret_salt = parser->m_hash_secret_salt;
   1334  1.1      tron 
   1335  1.1      tron #ifdef XML_DTD
   1336  1.8      maya   if (! context)
   1337  1.1      tron     newDtd = oldDtd;
   1338  1.1      tron #endif /* XML_DTD */
   1339  1.1      tron 
   1340  1.1      tron   /* Note that the magical uses of the pre-processor to make field
   1341  1.1      tron      access look more like C++ require that `parser' be overwritten
   1342  1.1      tron      here.  This makes this function more painful to follow than it
   1343  1.1      tron      would be otherwise.
   1344  1.1      tron   */
   1345  1.8      maya   if (parser->m_ns) {
   1346  1.9  christos     XML_Char tmp[2] = {parser->m_namespaceSeparator, 0};
   1347  1.1      tron     parser = parserCreate(encodingName, &parser->m_mem, tmp, newDtd);
   1348  1.8      maya   } else {
   1349  1.1      tron     parser = parserCreate(encodingName, &parser->m_mem, NULL, newDtd);
   1350  1.1      tron   }
   1351  1.1      tron 
   1352  1.8      maya   if (! parser)
   1353  1.1      tron     return NULL;
   1354  1.1      tron 
   1355  1.8      maya   parser->m_startElementHandler = oldStartElementHandler;
   1356  1.8      maya   parser->m_endElementHandler = oldEndElementHandler;
   1357  1.8      maya   parser->m_characterDataHandler = oldCharacterDataHandler;
   1358  1.8      maya   parser->m_processingInstructionHandler = oldProcessingInstructionHandler;
   1359  1.8      maya   parser->m_commentHandler = oldCommentHandler;
   1360  1.8      maya   parser->m_startCdataSectionHandler = oldStartCdataSectionHandler;
   1361  1.8      maya   parser->m_endCdataSectionHandler = oldEndCdataSectionHandler;
   1362  1.8      maya   parser->m_defaultHandler = oldDefaultHandler;
   1363  1.8      maya   parser->m_unparsedEntityDeclHandler = oldUnparsedEntityDeclHandler;
   1364  1.8      maya   parser->m_notationDeclHandler = oldNotationDeclHandler;
   1365  1.8      maya   parser->m_startNamespaceDeclHandler = oldStartNamespaceDeclHandler;
   1366  1.8      maya   parser->m_endNamespaceDeclHandler = oldEndNamespaceDeclHandler;
   1367  1.8      maya   parser->m_notStandaloneHandler = oldNotStandaloneHandler;
   1368  1.8      maya   parser->m_externalEntityRefHandler = oldExternalEntityRefHandler;
   1369  1.8      maya   parser->m_skippedEntityHandler = oldSkippedEntityHandler;
   1370  1.8      maya   parser->m_unknownEncodingHandler = oldUnknownEncodingHandler;
   1371  1.8      maya   parser->m_elementDeclHandler = oldElementDeclHandler;
   1372  1.8      maya   parser->m_attlistDeclHandler = oldAttlistDeclHandler;
   1373  1.8      maya   parser->m_entityDeclHandler = oldEntityDeclHandler;
   1374  1.8      maya   parser->m_xmlDeclHandler = oldXmlDeclHandler;
   1375  1.8      maya   parser->m_declElementType = oldDeclElementType;
   1376  1.8      maya   parser->m_userData = oldUserData;
   1377  1.1      tron   if (oldUserData == oldHandlerArg)
   1378  1.8      maya     parser->m_handlerArg = parser->m_userData;
   1379  1.1      tron   else
   1380  1.8      maya     parser->m_handlerArg = parser;
   1381  1.1      tron   if (oldExternalEntityRefHandlerArg != oldParser)
   1382  1.8      maya     parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg;
   1383  1.8      maya   parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities;
   1384  1.8      maya   parser->m_ns_triplets = oldns_triplets;
   1385  1.8      maya   parser->m_hash_secret_salt = oldhash_secret_salt;
   1386  1.8      maya   parser->m_parentParser = oldParser;
   1387  1.1      tron #ifdef XML_DTD
   1388  1.8      maya   parser->m_paramEntityParsing = oldParamEntityParsing;
   1389  1.8      maya   parser->m_prologState.inEntityValue = oldInEntityValue;
   1390  1.1      tron   if (context) {
   1391  1.1      tron #endif /* XML_DTD */
   1392  1.8      maya     if (! dtdCopy(oldParser, parser->m_dtd, oldDtd, &parser->m_mem)
   1393  1.8      maya         || ! setContext(parser, context)) {
   1394  1.1      tron       XML_ParserFree(parser);
   1395  1.1      tron       return NULL;
   1396  1.1      tron     }
   1397  1.8      maya     parser->m_processor = externalEntityInitProcessor;
   1398  1.1      tron #ifdef XML_DTD
   1399  1.8      maya   } else {
   1400  1.8      maya     /* The DTD instance referenced by parser->m_dtd is shared between the
   1401  1.8      maya        document's root parser and external PE parsers, therefore one does not
   1402  1.8      maya        need to call setContext. In addition, one also *must* not call
   1403  1.8      maya        setContext, because this would overwrite existing prefix->binding
   1404  1.8      maya        pointers in parser->m_dtd with ones that get destroyed with the external
   1405  1.8      maya        PE parser. This would leave those prefixes with dangling pointers.
   1406  1.1      tron     */
   1407  1.8      maya     parser->m_isParamEntity = XML_TRUE;
   1408  1.8      maya     XmlPrologStateInitExternalEntity(&parser->m_prologState);
   1409  1.8      maya     parser->m_processor = externalParEntInitProcessor;
   1410  1.1      tron   }
   1411  1.1      tron #endif /* XML_DTD */
   1412  1.1      tron   return parser;
   1413  1.1      tron }
   1414  1.1      tron 
   1415  1.1      tron static void FASTCALL
   1416  1.8      maya destroyBindings(BINDING *bindings, XML_Parser parser) {
   1417  1.1      tron   for (;;) {
   1418  1.1      tron     BINDING *b = bindings;
   1419  1.8      maya     if (! b)
   1420  1.1      tron       break;
   1421  1.1      tron     bindings = b->nextTagBinding;
   1422  1.8      maya     FREE(parser, b->uri);
   1423  1.8      maya     FREE(parser, b);
   1424  1.1      tron   }
   1425  1.1      tron }
   1426  1.1      tron 
   1427  1.1      tron void XMLCALL
   1428  1.8      maya XML_ParserFree(XML_Parser parser) {
   1429  1.1      tron   TAG *tagList;
   1430  1.1      tron   OPEN_INTERNAL_ENTITY *entityList;
   1431  1.1      tron   if (parser == NULL)
   1432  1.1      tron     return;
   1433  1.8      maya   /* free m_tagStack and m_freeTagList */
   1434  1.8      maya   tagList = parser->m_tagStack;
   1435  1.1      tron   for (;;) {
   1436  1.1      tron     TAG *p;
   1437  1.1      tron     if (tagList == NULL) {
   1438  1.8      maya       if (parser->m_freeTagList == NULL)
   1439  1.1      tron         break;
   1440  1.8      maya       tagList = parser->m_freeTagList;
   1441  1.8      maya       parser->m_freeTagList = NULL;
   1442  1.1      tron     }
   1443  1.1      tron     p = tagList;
   1444  1.1      tron     tagList = tagList->parent;
   1445  1.8      maya     FREE(parser, p->buf);
   1446  1.1      tron     destroyBindings(p->bindings, parser);
   1447  1.8      maya     FREE(parser, p);
   1448  1.1      tron   }
   1449  1.8      maya   /* free m_openInternalEntities and m_freeInternalEntities */
   1450  1.8      maya   entityList = parser->m_openInternalEntities;
   1451  1.1      tron   for (;;) {
   1452  1.1      tron     OPEN_INTERNAL_ENTITY *openEntity;
   1453  1.1      tron     if (entityList == NULL) {
   1454  1.8      maya       if (parser->m_freeInternalEntities == NULL)
   1455  1.1      tron         break;
   1456  1.8      maya       entityList = parser->m_freeInternalEntities;
   1457  1.8      maya       parser->m_freeInternalEntities = NULL;
   1458  1.1      tron     }
   1459  1.1      tron     openEntity = entityList;
   1460  1.1      tron     entityList = entityList->next;
   1461  1.8      maya     FREE(parser, openEntity);
   1462  1.1      tron   }
   1463  1.1      tron 
   1464  1.8      maya   destroyBindings(parser->m_freeBindingList, parser);
   1465  1.8      maya   destroyBindings(parser->m_inheritedBindings, parser);
   1466  1.8      maya   poolDestroy(&parser->m_tempPool);
   1467  1.8      maya   poolDestroy(&parser->m_temp2Pool);
   1468  1.8      maya   FREE(parser, (void *)parser->m_protocolEncodingName);
   1469  1.1      tron #ifdef XML_DTD
   1470  1.1      tron   /* external parameter entity parsers share the DTD structure
   1471  1.1      tron      parser->m_dtd with the root parser, so we must not destroy it
   1472  1.1      tron   */
   1473  1.8      maya   if (! parser->m_isParamEntity && parser->m_dtd)
   1474  1.1      tron #else
   1475  1.8      maya   if (parser->m_dtd)
   1476  1.1      tron #endif /* XML_DTD */
   1477  1.8      maya     dtdDestroy(parser->m_dtd, (XML_Bool)! parser->m_parentParser,
   1478  1.8      maya                &parser->m_mem);
   1479  1.8      maya   FREE(parser, (void *)parser->m_atts);
   1480  1.3       spz #ifdef XML_ATTR_INFO
   1481  1.8      maya   FREE(parser, (void *)parser->m_attInfo);
   1482  1.3       spz #endif
   1483  1.8      maya   FREE(parser, parser->m_groupConnector);
   1484  1.8      maya   FREE(parser, parser->m_buffer);
   1485  1.8      maya   FREE(parser, parser->m_dataBuf);
   1486  1.8      maya   FREE(parser, parser->m_nsAtts);
   1487  1.8      maya   FREE(parser, parser->m_unknownEncodingMem);
   1488  1.8      maya   if (parser->m_unknownEncodingRelease)
   1489  1.8      maya     parser->m_unknownEncodingRelease(parser->m_unknownEncodingData);
   1490  1.8      maya   FREE(parser, parser);
   1491  1.1      tron }
   1492  1.1      tron 
   1493  1.1      tron void XMLCALL
   1494  1.8      maya XML_UseParserAsHandlerArg(XML_Parser parser) {
   1495  1.7  christos   if (parser != NULL)
   1496  1.8      maya     parser->m_handlerArg = parser;
   1497  1.1      tron }
   1498  1.1      tron 
   1499  1.1      tron enum XML_Error XMLCALL
   1500  1.8      maya XML_UseForeignDTD(XML_Parser parser, XML_Bool useDTD) {
   1501  1.7  christos   if (parser == NULL)
   1502  1.7  christos     return XML_ERROR_INVALID_ARGUMENT;
   1503  1.1      tron #ifdef XML_DTD
   1504  1.1      tron   /* block after XML_Parse()/XML_ParseBuffer() has been called */
   1505  1.8      maya   if (parser->m_parsingStatus.parsing == XML_PARSING
   1506  1.8      maya       || parser->m_parsingStatus.parsing == XML_SUSPENDED)
   1507  1.1      tron     return XML_ERROR_CANT_CHANGE_FEATURE_ONCE_PARSING;
   1508  1.8      maya   parser->m_useForeignDTD = useDTD;
   1509  1.1      tron   return XML_ERROR_NONE;
   1510  1.1      tron #else
   1511  1.9  christos   UNUSED_P(useDTD);
   1512  1.1      tron   return XML_ERROR_FEATURE_REQUIRES_XML_DTD;
   1513  1.1      tron #endif
   1514  1.1      tron }
   1515  1.1      tron 
   1516  1.1      tron void XMLCALL
   1517  1.8      maya XML_SetReturnNSTriplet(XML_Parser parser, int do_nst) {
   1518  1.7  christos   if (parser == NULL)
   1519  1.7  christos     return;
   1520  1.1      tron   /* block after XML_Parse()/XML_ParseBuffer() has been called */
   1521  1.8      maya   if (parser->m_parsingStatus.parsing == XML_PARSING
   1522  1.8      maya       || parser->m_parsingStatus.parsing == XML_SUSPENDED)
   1523  1.1      tron     return;
   1524  1.8      maya   parser->m_ns_triplets = do_nst ? XML_TRUE : XML_FALSE;
   1525  1.1      tron }
   1526  1.1      tron 
   1527  1.1      tron void XMLCALL
   1528  1.8      maya XML_SetUserData(XML_Parser parser, void *p) {
   1529  1.7  christos   if (parser == NULL)
   1530  1.7  christos     return;
   1531  1.8      maya   if (parser->m_handlerArg == parser->m_userData)
   1532  1.8      maya     parser->m_handlerArg = parser->m_userData = p;
   1533  1.1      tron   else
   1534  1.8      maya     parser->m_userData = p;
   1535  1.1      tron }
   1536  1.1      tron 
   1537  1.1      tron enum XML_Status XMLCALL
   1538  1.8      maya XML_SetBase(XML_Parser parser, const XML_Char *p) {
   1539  1.7  christos   if (parser == NULL)
   1540  1.7  christos     return XML_STATUS_ERROR;
   1541  1.1      tron   if (p) {
   1542  1.8      maya     p = poolCopyString(&parser->m_dtd->pool, p);
   1543  1.8      maya     if (! p)
   1544  1.1      tron       return XML_STATUS_ERROR;
   1545  1.8      maya     parser->m_curBase = p;
   1546  1.8      maya   } else
   1547  1.8      maya     parser->m_curBase = NULL;
   1548  1.1      tron   return XML_STATUS_OK;
   1549  1.1      tron }
   1550  1.1      tron 
   1551  1.8      maya const XML_Char *XMLCALL
   1552  1.8      maya XML_GetBase(XML_Parser parser) {
   1553  1.7  christos   if (parser == NULL)
   1554  1.7  christos     return NULL;
   1555  1.8      maya   return parser->m_curBase;
   1556  1.1      tron }
   1557  1.1      tron 
   1558  1.1      tron int XMLCALL
   1559  1.8      maya XML_GetSpecifiedAttributeCount(XML_Parser parser) {
   1560  1.7  christos   if (parser == NULL)
   1561  1.7  christos     return -1;
   1562  1.8      maya   return parser->m_nSpecifiedAtts;
   1563  1.1      tron }
   1564  1.1      tron 
   1565  1.1      tron int XMLCALL
   1566  1.8      maya XML_GetIdAttributeIndex(XML_Parser parser) {
   1567  1.7  christos   if (parser == NULL)
   1568  1.7  christos     return -1;
   1569  1.8      maya   return parser->m_idAttIndex;
   1570  1.1      tron }
   1571  1.1      tron 
   1572  1.3       spz #ifdef XML_ATTR_INFO
   1573  1.8      maya const XML_AttrInfo *XMLCALL
   1574  1.8      maya XML_GetAttributeInfo(XML_Parser parser) {
   1575  1.7  christos   if (parser == NULL)
   1576  1.7  christos     return NULL;
   1577  1.8      maya   return parser->m_attInfo;
   1578  1.3       spz }
   1579  1.3       spz #endif
   1580  1.3       spz 
   1581  1.1      tron void XMLCALL
   1582  1.8      maya XML_SetElementHandler(XML_Parser parser, XML_StartElementHandler start,
   1583  1.8      maya                       XML_EndElementHandler end) {
   1584  1.7  christos   if (parser == NULL)
   1585  1.7  christos     return;
   1586  1.8      maya   parser->m_startElementHandler = start;
   1587  1.8      maya   parser->m_endElementHandler = end;
   1588  1.1      tron }
   1589  1.1      tron 
   1590  1.1      tron void XMLCALL
   1591  1.8      maya XML_SetStartElementHandler(XML_Parser parser, XML_StartElementHandler start) {
   1592  1.7  christos   if (parser != NULL)
   1593  1.8      maya     parser->m_startElementHandler = start;
   1594  1.1      tron }
   1595  1.1      tron 
   1596  1.1      tron void XMLCALL
   1597  1.8      maya XML_SetEndElementHandler(XML_Parser parser, XML_EndElementHandler end) {
   1598  1.7  christos   if (parser != NULL)
   1599  1.8      maya     parser->m_endElementHandler = end;
   1600  1.1      tron }
   1601  1.1      tron 
   1602  1.1      tron void XMLCALL
   1603  1.1      tron XML_SetCharacterDataHandler(XML_Parser parser,
   1604  1.8      maya                             XML_CharacterDataHandler handler) {
   1605  1.7  christos   if (parser != NULL)
   1606  1.8      maya     parser->m_characterDataHandler = handler;
   1607  1.1      tron }
   1608  1.1      tron 
   1609  1.1      tron void XMLCALL
   1610  1.1      tron XML_SetProcessingInstructionHandler(XML_Parser parser,
   1611  1.8      maya                                     XML_ProcessingInstructionHandler handler) {
   1612  1.7  christos   if (parser != NULL)
   1613  1.8      maya     parser->m_processingInstructionHandler = handler;
   1614  1.1      tron }
   1615  1.1      tron 
   1616  1.1      tron void XMLCALL
   1617  1.8      maya XML_SetCommentHandler(XML_Parser parser, XML_CommentHandler handler) {
   1618  1.7  christos   if (parser != NULL)
   1619  1.8      maya     parser->m_commentHandler = handler;
   1620  1.1      tron }
   1621  1.1      tron 
   1622  1.1      tron void XMLCALL
   1623  1.1      tron XML_SetCdataSectionHandler(XML_Parser parser,
   1624  1.1      tron                            XML_StartCdataSectionHandler start,
   1625  1.8      maya                            XML_EndCdataSectionHandler end) {
   1626  1.7  christos   if (parser == NULL)
   1627  1.7  christos     return;
   1628  1.8      maya   parser->m_startCdataSectionHandler = start;
   1629  1.8      maya   parser->m_endCdataSectionHandler = end;
   1630  1.1      tron }
   1631  1.1      tron 
   1632  1.1      tron void XMLCALL
   1633  1.1      tron XML_SetStartCdataSectionHandler(XML_Parser parser,
   1634  1.1      tron                                 XML_StartCdataSectionHandler start) {
   1635  1.7  christos   if (parser != NULL)
   1636  1.8      maya     parser->m_startCdataSectionHandler = start;
   1637  1.1      tron }
   1638  1.1      tron 
   1639  1.1      tron void XMLCALL
   1640  1.1      tron XML_SetEndCdataSectionHandler(XML_Parser parser,
   1641  1.1      tron                               XML_EndCdataSectionHandler end) {
   1642  1.7  christos   if (parser != NULL)
   1643  1.8      maya     parser->m_endCdataSectionHandler = end;
   1644  1.1      tron }
   1645  1.1      tron 
   1646  1.1      tron void XMLCALL
   1647  1.8      maya XML_SetDefaultHandler(XML_Parser parser, XML_DefaultHandler handler) {
   1648  1.7  christos   if (parser == NULL)
   1649  1.7  christos     return;
   1650  1.8      maya   parser->m_defaultHandler = handler;
   1651  1.8      maya   parser->m_defaultExpandInternalEntities = XML_FALSE;
   1652  1.1      tron }
   1653  1.1      tron 
   1654  1.1      tron void XMLCALL
   1655  1.8      maya XML_SetDefaultHandlerExpand(XML_Parser parser, XML_DefaultHandler handler) {
   1656  1.7  christos   if (parser == NULL)
   1657  1.7  christos     return;
   1658  1.8      maya   parser->m_defaultHandler = handler;
   1659  1.8      maya   parser->m_defaultExpandInternalEntities = XML_TRUE;
   1660  1.1      tron }
   1661  1.1      tron 
   1662  1.1      tron void XMLCALL
   1663  1.8      maya XML_SetDoctypeDeclHandler(XML_Parser parser, XML_StartDoctypeDeclHandler start,
   1664  1.8      maya                           XML_EndDoctypeDeclHandler end) {
   1665  1.7  christos   if (parser == NULL)
   1666  1.7  christos     return;
   1667  1.8      maya   parser->m_startDoctypeDeclHandler = start;
   1668  1.8      maya   parser->m_endDoctypeDeclHandler = end;
   1669  1.1      tron }
   1670  1.1      tron 
   1671  1.1      tron void XMLCALL
   1672  1.1      tron XML_SetStartDoctypeDeclHandler(XML_Parser parser,
   1673  1.1      tron                                XML_StartDoctypeDeclHandler start) {
   1674  1.7  christos   if (parser != NULL)
   1675  1.8      maya     parser->m_startDoctypeDeclHandler = start;
   1676  1.1      tron }
   1677  1.1      tron 
   1678  1.1      tron void XMLCALL
   1679  1.8      maya XML_SetEndDoctypeDeclHandler(XML_Parser parser, XML_EndDoctypeDeclHandler end) {
   1680  1.7  christos   if (parser != NULL)
   1681  1.8      maya     parser->m_endDoctypeDeclHandler = end;
   1682  1.1      tron }
   1683  1.1      tron 
   1684  1.1      tron void XMLCALL
   1685  1.1      tron XML_SetUnparsedEntityDeclHandler(XML_Parser parser,
   1686  1.8      maya                                  XML_UnparsedEntityDeclHandler handler) {
   1687  1.7  christos   if (parser != NULL)
   1688  1.8      maya     parser->m_unparsedEntityDeclHandler = handler;
   1689  1.1      tron }
   1690  1.1      tron 
   1691  1.1      tron void XMLCALL
   1692  1.8      maya XML_SetNotationDeclHandler(XML_Parser parser, XML_NotationDeclHandler handler) {
   1693  1.7  christos   if (parser != NULL)
   1694  1.8      maya     parser->m_notationDeclHandler = handler;
   1695  1.1      tron }
   1696  1.1      tron 
   1697  1.1      tron void XMLCALL
   1698  1.1      tron XML_SetNamespaceDeclHandler(XML_Parser parser,
   1699  1.1      tron                             XML_StartNamespaceDeclHandler start,
   1700  1.8      maya                             XML_EndNamespaceDeclHandler end) {
   1701  1.7  christos   if (parser == NULL)
   1702  1.7  christos     return;
   1703  1.8      maya   parser->m_startNamespaceDeclHandler = start;
   1704  1.8      maya   parser->m_endNamespaceDeclHandler = end;
   1705  1.1      tron }
   1706  1.1      tron 
   1707  1.1      tron void XMLCALL
   1708  1.1      tron XML_SetStartNamespaceDeclHandler(XML_Parser parser,
   1709  1.1      tron                                  XML_StartNamespaceDeclHandler start) {
   1710  1.7  christos   if (parser != NULL)
   1711  1.8      maya     parser->m_startNamespaceDeclHandler = start;
   1712  1.1      tron }
   1713  1.1      tron 
   1714  1.1      tron void XMLCALL
   1715  1.1      tron XML_SetEndNamespaceDeclHandler(XML_Parser parser,
   1716  1.1      tron                                XML_EndNamespaceDeclHandler end) {
   1717  1.7  christos   if (parser != NULL)
   1718  1.8      maya     parser->m_endNamespaceDeclHandler = end;
   1719  1.1      tron }
   1720  1.1      tron 
   1721  1.1      tron void XMLCALL
   1722  1.1      tron XML_SetNotStandaloneHandler(XML_Parser parser,
   1723  1.8      maya                             XML_NotStandaloneHandler handler) {
   1724  1.7  christos   if (parser != NULL)
   1725  1.8      maya     parser->m_notStandaloneHandler = handler;
   1726  1.1      tron }
   1727  1.1      tron 
   1728  1.1      tron void XMLCALL
   1729  1.1      tron XML_SetExternalEntityRefHandler(XML_Parser parser,
   1730  1.8      maya                                 XML_ExternalEntityRefHandler handler) {
   1731  1.7  christos   if (parser != NULL)
   1732  1.8      maya     parser->m_externalEntityRefHandler = handler;
   1733  1.1      tron }
   1734  1.1      tron 
   1735  1.1      tron void XMLCALL
   1736  1.8      maya XML_SetExternalEntityRefHandlerArg(XML_Parser parser, void *arg) {
   1737  1.7  christos   if (parser == NULL)
   1738  1.7  christos     return;
   1739  1.1      tron   if (arg)
   1740  1.8      maya     parser->m_externalEntityRefHandlerArg = (XML_Parser)arg;
   1741  1.1      tron   else
   1742  1.8      maya     parser->m_externalEntityRefHandlerArg = parser;
   1743  1.1      tron }
   1744  1.1      tron 
   1745  1.1      tron void XMLCALL
   1746  1.1      tron XML_SetSkippedEntityHandler(XML_Parser parser,
   1747  1.8      maya                             XML_SkippedEntityHandler handler) {
   1748  1.7  christos   if (parser != NULL)
   1749  1.8      maya     parser->m_skippedEntityHandler = handler;
   1750  1.1      tron }
   1751  1.1      tron 
   1752  1.1      tron void XMLCALL
   1753  1.1      tron XML_SetUnknownEncodingHandler(XML_Parser parser,
   1754  1.8      maya                               XML_UnknownEncodingHandler handler, void *data) {
   1755  1.7  christos   if (parser == NULL)
   1756  1.7  christos     return;
   1757  1.8      maya   parser->m_unknownEncodingHandler = handler;
   1758  1.8      maya   parser->m_unknownEncodingHandlerData = data;
   1759  1.1      tron }
   1760  1.1      tron 
   1761  1.1      tron void XMLCALL
   1762  1.8      maya XML_SetElementDeclHandler(XML_Parser parser, XML_ElementDeclHandler eldecl) {
   1763  1.7  christos   if (parser != NULL)
   1764  1.8      maya     parser->m_elementDeclHandler = eldecl;
   1765  1.1      tron }
   1766  1.1      tron 
   1767  1.1      tron void XMLCALL
   1768  1.8      maya XML_SetAttlistDeclHandler(XML_Parser parser, XML_AttlistDeclHandler attdecl) {
   1769  1.7  christos   if (parser != NULL)
   1770  1.8      maya     parser->m_attlistDeclHandler = attdecl;
   1771  1.1      tron }
   1772  1.1      tron 
   1773  1.1      tron void XMLCALL
   1774  1.8      maya XML_SetEntityDeclHandler(XML_Parser parser, XML_EntityDeclHandler handler) {
   1775  1.7  christos   if (parser != NULL)
   1776  1.8      maya     parser->m_entityDeclHandler = handler;
   1777  1.1      tron }
   1778  1.1      tron 
   1779  1.1      tron void XMLCALL
   1780  1.8      maya XML_SetXmlDeclHandler(XML_Parser parser, XML_XmlDeclHandler handler) {
   1781  1.7  christos   if (parser != NULL)
   1782  1.8      maya     parser->m_xmlDeclHandler = handler;
   1783  1.1      tron }
   1784  1.1      tron 
   1785  1.1      tron int XMLCALL
   1786  1.1      tron XML_SetParamEntityParsing(XML_Parser parser,
   1787  1.8      maya                           enum XML_ParamEntityParsing peParsing) {
   1788  1.7  christos   if (parser == NULL)
   1789  1.7  christos     return 0;
   1790  1.1      tron   /* block after XML_Parse()/XML_ParseBuffer() has been called */
   1791  1.8      maya   if (parser->m_parsingStatus.parsing == XML_PARSING
   1792  1.8      maya       || parser->m_parsingStatus.parsing == XML_SUSPENDED)
   1793  1.1      tron     return 0;
   1794  1.1      tron #ifdef XML_DTD
   1795  1.8      maya   parser->m_paramEntityParsing = peParsing;
   1796  1.1      tron   return 1;
   1797  1.1      tron #else
   1798  1.1      tron   return peParsing == XML_PARAM_ENTITY_PARSING_NEVER;
   1799  1.1      tron #endif
   1800  1.1      tron }
   1801  1.1      tron 
   1802  1.3       spz int XMLCALL
   1803  1.8      maya XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
   1804  1.7  christos   if (parser == NULL)
   1805  1.7  christos     return 0;
   1806  1.7  christos   if (parser->m_parentParser)
   1807  1.7  christos     return XML_SetHashSalt(parser->m_parentParser, hash_salt);
   1808  1.3       spz   /* block after XML_Parse()/XML_ParseBuffer() has been called */
   1809  1.8      maya   if (parser->m_parsingStatus.parsing == XML_PARSING
   1810  1.8      maya       || parser->m_parsingStatus.parsing == XML_SUSPENDED)
   1811  1.3       spz     return 0;
   1812  1.8      maya   parser->m_hash_secret_salt = hash_salt;
   1813  1.3       spz   return 1;
   1814  1.3       spz }
   1815  1.3       spz 
   1816  1.1      tron enum XML_Status XMLCALL
   1817  1.8      maya XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
   1818  1.7  christos   if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) {
   1819  1.8      maya     if (parser != NULL)
   1820  1.8      maya       parser->m_errorCode = XML_ERROR_INVALID_ARGUMENT;
   1821  1.7  christos     return XML_STATUS_ERROR;
   1822  1.7  christos   }
   1823  1.8      maya   switch (parser->m_parsingStatus.parsing) {
   1824  1.1      tron   case XML_SUSPENDED:
   1825  1.8      maya     parser->m_errorCode = XML_ERROR_SUSPENDED;
   1826  1.1      tron     return XML_STATUS_ERROR;
   1827  1.1      tron   case XML_FINISHED:
   1828  1.8      maya     parser->m_errorCode = XML_ERROR_FINISHED;
   1829  1.1      tron     return XML_STATUS_ERROR;
   1830  1.3       spz   case XML_INITIALIZED:
   1831  1.8      maya     if (parser->m_parentParser == NULL && ! startParsing(parser)) {
   1832  1.8      maya       parser->m_errorCode = XML_ERROR_NO_MEMORY;
   1833  1.3       spz       return XML_STATUS_ERROR;
   1834  1.3       spz     }
   1835  1.8      maya     /* fall through */
   1836  1.1      tron   default:
   1837  1.8      maya     parser->m_parsingStatus.parsing = XML_PARSING;
   1838  1.1      tron   }
   1839  1.1      tron 
   1840  1.1      tron   if (len == 0) {
   1841  1.8      maya     parser->m_parsingStatus.finalBuffer = (XML_Bool)isFinal;
   1842  1.8      maya     if (! isFinal)
   1843  1.1      tron       return XML_STATUS_OK;
   1844  1.8      maya     parser->m_positionPtr = parser->m_bufferPtr;
   1845  1.8      maya     parser->m_parseEndPtr = parser->m_bufferEnd;
   1846  1.1      tron 
   1847  1.1      tron     /* If data are left over from last buffer, and we now know that these
   1848  1.1      tron        data are the final chunk of input, then we have to check them again
   1849  1.1      tron        to detect errors based on that fact.
   1850  1.1      tron     */
   1851  1.8      maya     parser->m_errorCode
   1852  1.8      maya         = parser->m_processor(parser, parser->m_bufferPtr,
   1853  1.8      maya                               parser->m_parseEndPtr, &parser->m_bufferPtr);
   1854  1.1      tron 
   1855  1.8      maya     if (parser->m_errorCode == XML_ERROR_NONE) {
   1856  1.8      maya       switch (parser->m_parsingStatus.parsing) {
   1857  1.1      tron       case XML_SUSPENDED:
   1858  1.8      maya         /* It is hard to be certain, but it seems that this case
   1859  1.8      maya          * cannot occur.  This code is cleaning up a previous parse
   1860  1.8      maya          * with no new data (since len == 0).  Changing the parsing
   1861  1.8      maya          * state requires getting to execute a handler function, and
   1862  1.8      maya          * there doesn't seem to be an opportunity for that while in
   1863  1.8      maya          * this circumstance.
   1864  1.8      maya          *
   1865  1.8      maya          * Given the uncertainty, we retain the code but exclude it
   1866  1.8      maya          * from coverage tests.
   1867  1.8      maya          *
   1868  1.8      maya          * LCOV_EXCL_START
   1869  1.8      maya          */
   1870  1.8      maya         XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr,
   1871  1.8      maya                           parser->m_bufferPtr, &parser->m_position);
   1872  1.8      maya         parser->m_positionPtr = parser->m_bufferPtr;
   1873  1.1      tron         return XML_STATUS_SUSPENDED;
   1874  1.8      maya         /* LCOV_EXCL_STOP */
   1875  1.3       spz       case XML_INITIALIZED:
   1876  1.1      tron       case XML_PARSING:
   1877  1.8      maya         parser->m_parsingStatus.parsing = XML_FINISHED;
   1878  1.1      tron         /* fall through */
   1879  1.1      tron       default:
   1880  1.1      tron         return XML_STATUS_OK;
   1881  1.1      tron       }
   1882  1.1      tron     }
   1883  1.8      maya     parser->m_eventEndPtr = parser->m_eventPtr;
   1884  1.8      maya     parser->m_processor = errorProcessor;
   1885  1.1      tron     return XML_STATUS_ERROR;
   1886  1.1      tron   }
   1887  1.1      tron #ifndef XML_CONTEXT_BYTES
   1888  1.8      maya   else if (parser->m_bufferPtr == parser->m_bufferEnd) {
   1889  1.1      tron     const char *end;
   1890  1.1      tron     int nLeftOver;
   1891  1.4       spz     enum XML_Status result;
   1892  1.7  christos     /* Detect overflow (a+b > MAX <==> b > MAX-a) */
   1893  1.9  christos     if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) {
   1894  1.8      maya       parser->m_errorCode = XML_ERROR_NO_MEMORY;
   1895  1.8      maya       parser->m_eventPtr = parser->m_eventEndPtr = NULL;
   1896  1.8      maya       parser->m_processor = errorProcessor;
   1897  1.1      tron       return XML_STATUS_ERROR;
   1898  1.1      tron     }
   1899  1.8      maya     parser->m_parseEndByteIndex += len;
   1900  1.8      maya     parser->m_positionPtr = s;
   1901  1.8      maya     parser->m_parsingStatus.finalBuffer = (XML_Bool)isFinal;
   1902  1.8      maya 
   1903  1.8      maya     parser->m_errorCode
   1904  1.8      maya         = parser->m_processor(parser, s, parser->m_parseEndPtr = s + len, &end);
   1905  1.8      maya 
   1906  1.8      maya     if (parser->m_errorCode != XML_ERROR_NONE) {
   1907  1.8      maya       parser->m_eventEndPtr = parser->m_eventPtr;
   1908  1.8      maya       parser->m_processor = errorProcessor;
   1909  1.8      maya       return XML_STATUS_ERROR;
   1910  1.8      maya     } else {
   1911  1.8      maya       switch (parser->m_parsingStatus.parsing) {
   1912  1.1      tron       case XML_SUSPENDED:
   1913  1.1      tron         result = XML_STATUS_SUSPENDED;
   1914  1.1      tron         break;
   1915  1.1      tron       case XML_INITIALIZED:
   1916  1.1      tron       case XML_PARSING:
   1917  1.1      tron         if (isFinal) {
   1918  1.8      maya           parser->m_parsingStatus.parsing = XML_FINISHED;
   1919  1.3       spz           return XML_STATUS_OK;
   1920  1.1      tron         }
   1921  1.3       spz       /* fall through */
   1922  1.3       spz       default:
   1923  1.3       spz         result = XML_STATUS_OK;
   1924  1.1      tron       }
   1925  1.1      tron     }
   1926  1.1      tron 
   1927  1.8      maya     XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr, end,
   1928  1.8      maya                       &parser->m_position);
   1929  1.1      tron     nLeftOver = s + len - end;
   1930  1.1      tron     if (nLeftOver) {
   1931  1.8      maya       if (parser->m_buffer == NULL
   1932  1.8      maya           || nLeftOver > parser->m_bufferLim - parser->m_buffer) {
   1933  1.7  christos         /* avoid _signed_ integer overflow */
   1934  1.7  christos         char *temp = NULL;
   1935  1.7  christos         const int bytesToAllocate = (int)((unsigned)len * 2U);
   1936  1.7  christos         if (bytesToAllocate > 0) {
   1937  1.8      maya           temp = (char *)REALLOC(parser, parser->m_buffer, bytesToAllocate);
   1938  1.7  christos         }
   1939  1.1      tron         if (temp == NULL) {
   1940  1.8      maya           parser->m_errorCode = XML_ERROR_NO_MEMORY;
   1941  1.8      maya           parser->m_eventPtr = parser->m_eventEndPtr = NULL;
   1942  1.8      maya           parser->m_processor = errorProcessor;
   1943  1.1      tron           return XML_STATUS_ERROR;
   1944  1.1      tron         }
   1945  1.8      maya         parser->m_buffer = temp;
   1946  1.8      maya         parser->m_bufferLim = parser->m_buffer + bytesToAllocate;
   1947  1.1      tron       }
   1948  1.8      maya       memcpy(parser->m_buffer, end, nLeftOver);
   1949  1.1      tron     }
   1950  1.8      maya     parser->m_bufferPtr = parser->m_buffer;
   1951  1.8      maya     parser->m_bufferEnd = parser->m_buffer + nLeftOver;
   1952  1.8      maya     parser->m_positionPtr = parser->m_bufferPtr;
   1953  1.8      maya     parser->m_parseEndPtr = parser->m_bufferEnd;
   1954  1.8      maya     parser->m_eventPtr = parser->m_bufferPtr;
   1955  1.8      maya     parser->m_eventEndPtr = parser->m_bufferPtr;
   1956  1.1      tron     return result;
   1957  1.1      tron   }
   1958  1.8      maya #endif /* not defined XML_CONTEXT_BYTES */
   1959  1.1      tron   else {
   1960  1.1      tron     void *buff = XML_GetBuffer(parser, len);
   1961  1.1      tron     if (buff == NULL)
   1962  1.1      tron       return XML_STATUS_ERROR;
   1963  1.1      tron     else {
   1964  1.1      tron       memcpy(buff, s, len);
   1965  1.1      tron       return XML_ParseBuffer(parser, len, isFinal);
   1966  1.1      tron     }
   1967  1.1      tron   }
   1968  1.1      tron }
   1969  1.1      tron 
   1970  1.1      tron enum XML_Status XMLCALL
   1971  1.8      maya XML_ParseBuffer(XML_Parser parser, int len, int isFinal) {
   1972  1.1      tron   const char *start;
   1973  1.1      tron   enum XML_Status result = XML_STATUS_OK;
   1974  1.1      tron 
   1975  1.7  christos   if (parser == NULL)
   1976  1.7  christos     return XML_STATUS_ERROR;
   1977  1.8      maya   switch (parser->m_parsingStatus.parsing) {
   1978  1.1      tron   case XML_SUSPENDED:
   1979  1.8      maya     parser->m_errorCode = XML_ERROR_SUSPENDED;
   1980  1.1      tron     return XML_STATUS_ERROR;
   1981  1.1      tron   case XML_FINISHED:
   1982  1.8      maya     parser->m_errorCode = XML_ERROR_FINISHED;
   1983  1.1      tron     return XML_STATUS_ERROR;
   1984  1.3       spz   case XML_INITIALIZED:
   1985  1.9  christos     /* Has someone called XML_GetBuffer successfully before? */
   1986  1.9  christos     if (! parser->m_bufferPtr) {
   1987  1.9  christos       parser->m_errorCode = XML_ERROR_NO_BUFFER;
   1988  1.9  christos       return XML_STATUS_ERROR;
   1989  1.9  christos     }
   1990  1.9  christos 
   1991  1.8      maya     if (parser->m_parentParser == NULL && ! startParsing(parser)) {
   1992  1.8      maya       parser->m_errorCode = XML_ERROR_NO_MEMORY;
   1993  1.3       spz       return XML_STATUS_ERROR;
   1994  1.3       spz     }
   1995  1.8      maya     /* fall through */
   1996  1.1      tron   default:
   1997  1.8      maya     parser->m_parsingStatus.parsing = XML_PARSING;
   1998  1.1      tron   }
   1999  1.1      tron 
   2000  1.8      maya   start = parser->m_bufferPtr;
   2001  1.8      maya   parser->m_positionPtr = start;
   2002  1.8      maya   parser->m_bufferEnd += len;
   2003  1.8      maya   parser->m_parseEndPtr = parser->m_bufferEnd;
   2004  1.8      maya   parser->m_parseEndByteIndex += len;
   2005  1.8      maya   parser->m_parsingStatus.finalBuffer = (XML_Bool)isFinal;
   2006  1.8      maya 
   2007  1.8      maya   parser->m_errorCode = parser->m_processor(
   2008  1.8      maya       parser, start, parser->m_parseEndPtr, &parser->m_bufferPtr);
   2009  1.8      maya 
   2010  1.8      maya   if (parser->m_errorCode != XML_ERROR_NONE) {
   2011  1.8      maya     parser->m_eventEndPtr = parser->m_eventPtr;
   2012  1.8      maya     parser->m_processor = errorProcessor;
   2013  1.1      tron     return XML_STATUS_ERROR;
   2014  1.8      maya   } else {
   2015  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   2016  1.1      tron     case XML_SUSPENDED:
   2017  1.1      tron       result = XML_STATUS_SUSPENDED;
   2018  1.1      tron       break;
   2019  1.3       spz     case XML_INITIALIZED:
   2020  1.1      tron     case XML_PARSING:
   2021  1.1      tron       if (isFinal) {
   2022  1.8      maya         parser->m_parsingStatus.parsing = XML_FINISHED;
   2023  1.1      tron         return result;
   2024  1.1      tron       }
   2025  1.8      maya     default:; /* should not happen */
   2026  1.1      tron     }
   2027  1.1      tron   }
   2028  1.1      tron 
   2029  1.8      maya   XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr,
   2030  1.8      maya                     parser->m_bufferPtr, &parser->m_position);
   2031  1.8      maya   parser->m_positionPtr = parser->m_bufferPtr;
   2032  1.1      tron   return result;
   2033  1.1      tron }
   2034  1.1      tron 
   2035  1.8      maya void *XMLCALL
   2036  1.8      maya XML_GetBuffer(XML_Parser parser, int len) {
   2037  1.7  christos   if (parser == NULL)
   2038  1.7  christos     return NULL;
   2039  1.4       spz   if (len < 0) {
   2040  1.8      maya     parser->m_errorCode = XML_ERROR_NO_MEMORY;
   2041  1.4       spz     return NULL;
   2042  1.4       spz   }
   2043  1.8      maya   switch (parser->m_parsingStatus.parsing) {
   2044  1.1      tron   case XML_SUSPENDED:
   2045  1.8      maya     parser->m_errorCode = XML_ERROR_SUSPENDED;
   2046  1.1      tron     return NULL;
   2047  1.1      tron   case XML_FINISHED:
   2048  1.8      maya     parser->m_errorCode = XML_ERROR_FINISHED;
   2049  1.1      tron     return NULL;
   2050  1.8      maya   default:;
   2051  1.1      tron   }
   2052  1.1      tron 
   2053  1.8      maya   if (len > EXPAT_SAFE_PTR_DIFF(parser->m_bufferLim, parser->m_bufferEnd)) {
   2054  1.6       spz #ifdef XML_CONTEXT_BYTES
   2055  1.6       spz     int keep;
   2056  1.8      maya #endif /* defined XML_CONTEXT_BYTES */
   2057  1.5       spz     /* Do not invoke signed arithmetic overflow: */
   2058  1.8      maya     int neededSize = (int)((unsigned)len
   2059  1.8      maya                            + (unsigned)EXPAT_SAFE_PTR_DIFF(
   2060  1.8      maya                                parser->m_bufferEnd, parser->m_bufferPtr));
   2061  1.4       spz     if (neededSize < 0) {
   2062  1.8      maya       parser->m_errorCode = XML_ERROR_NO_MEMORY;
   2063  1.4       spz       return NULL;
   2064  1.4       spz     }
   2065  1.1      tron #ifdef XML_CONTEXT_BYTES
   2066  1.8      maya     keep = (int)EXPAT_SAFE_PTR_DIFF(parser->m_bufferPtr, parser->m_buffer);
   2067  1.1      tron     if (keep > XML_CONTEXT_BYTES)
   2068  1.1      tron       keep = XML_CONTEXT_BYTES;
   2069  1.9  christos     /* Detect and prevent integer overflow */
   2070  1.9  christos     if (keep > INT_MAX - neededSize) {
   2071  1.9  christos       parser->m_errorCode = XML_ERROR_NO_MEMORY;
   2072  1.9  christos       return NULL;
   2073  1.9  christos     }
   2074  1.1      tron     neededSize += keep;
   2075  1.8      maya #endif /* defined XML_CONTEXT_BYTES */
   2076  1.8      maya     if (neededSize
   2077  1.8      maya         <= EXPAT_SAFE_PTR_DIFF(parser->m_bufferLim, parser->m_buffer)) {
   2078  1.1      tron #ifdef XML_CONTEXT_BYTES
   2079  1.8      maya       if (keep < EXPAT_SAFE_PTR_DIFF(parser->m_bufferPtr, parser->m_buffer)) {
   2080  1.8      maya         int offset
   2081  1.8      maya             = (int)EXPAT_SAFE_PTR_DIFF(parser->m_bufferPtr, parser->m_buffer)
   2082  1.8      maya               - keep;
   2083  1.8      maya         /* The buffer pointers cannot be NULL here; we have at least some bytes
   2084  1.8      maya          * in the buffer */
   2085  1.8      maya         memmove(parser->m_buffer, &parser->m_buffer[offset],
   2086  1.8      maya                 parser->m_bufferEnd - parser->m_bufferPtr + keep);
   2087  1.8      maya         parser->m_bufferEnd -= offset;
   2088  1.8      maya         parser->m_bufferPtr -= offset;
   2089  1.1      tron       }
   2090  1.1      tron #else
   2091  1.8      maya       if (parser->m_buffer && parser->m_bufferPtr) {
   2092  1.8      maya         memmove(parser->m_buffer, parser->m_bufferPtr,
   2093  1.8      maya                 EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr));
   2094  1.8      maya         parser->m_bufferEnd
   2095  1.8      maya             = parser->m_buffer
   2096  1.8      maya               + EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr);
   2097  1.8      maya         parser->m_bufferPtr = parser->m_buffer;
   2098  1.8      maya       }
   2099  1.8      maya #endif /* not defined XML_CONTEXT_BYTES */
   2100  1.8      maya     } else {
   2101  1.1      tron       char *newBuf;
   2102  1.8      maya       int bufferSize
   2103  1.8      maya           = (int)EXPAT_SAFE_PTR_DIFF(parser->m_bufferLim, parser->m_bufferPtr);
   2104  1.1      tron       if (bufferSize == 0)
   2105  1.1      tron         bufferSize = INIT_BUFFER_SIZE;
   2106  1.1      tron       do {
   2107  1.5       spz         /* Do not invoke signed arithmetic overflow: */
   2108  1.8      maya         bufferSize = (int)(2U * (unsigned)bufferSize);
   2109  1.4       spz       } while (bufferSize < neededSize && bufferSize > 0);
   2110  1.4       spz       if (bufferSize <= 0) {
   2111  1.8      maya         parser->m_errorCode = XML_ERROR_NO_MEMORY;
   2112  1.4       spz         return NULL;
   2113  1.4       spz       }
   2114  1.8      maya       newBuf = (char *)MALLOC(parser, bufferSize);
   2115  1.1      tron       if (newBuf == 0) {
   2116  1.8      maya         parser->m_errorCode = XML_ERROR_NO_MEMORY;
   2117  1.1      tron         return NULL;
   2118  1.1      tron       }
   2119  1.8      maya       parser->m_bufferLim = newBuf + bufferSize;
   2120  1.1      tron #ifdef XML_CONTEXT_BYTES
   2121  1.8      maya       if (parser->m_bufferPtr) {
   2122  1.8      maya         memcpy(newBuf, &parser->m_bufferPtr[-keep],
   2123  1.8      maya                EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr)
   2124  1.8      maya                    + keep);
   2125  1.8      maya         FREE(parser, parser->m_buffer);
   2126  1.8      maya         parser->m_buffer = newBuf;
   2127  1.8      maya         parser->m_bufferEnd
   2128  1.8      maya             = parser->m_buffer
   2129  1.8      maya               + EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr)
   2130  1.8      maya               + keep;
   2131  1.8      maya         parser->m_bufferPtr = parser->m_buffer + keep;
   2132  1.8      maya       } else {
   2133  1.8      maya         /* This must be a brand new buffer with no data in it yet */
   2134  1.8      maya         parser->m_bufferEnd = newBuf;
   2135  1.8      maya         parser->m_bufferPtr = parser->m_buffer = newBuf;
   2136  1.1      tron       }
   2137  1.8      maya #else
   2138  1.8      maya       if (parser->m_bufferPtr) {
   2139  1.8      maya         memcpy(newBuf, parser->m_bufferPtr,
   2140  1.8      maya                EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr));
   2141  1.8      maya         FREE(parser, parser->m_buffer);
   2142  1.8      maya         parser->m_bufferEnd
   2143  1.8      maya             = newBuf
   2144  1.8      maya               + EXPAT_SAFE_PTR_DIFF(parser->m_bufferEnd, parser->m_bufferPtr);
   2145  1.8      maya       } else {
   2146  1.8      maya         /* This must be a brand new buffer with no data in it yet */
   2147  1.8      maya         parser->m_bufferEnd = newBuf;
   2148  1.1      tron       }
   2149  1.8      maya       parser->m_bufferPtr = parser->m_buffer = newBuf;
   2150  1.8      maya #endif /* not defined XML_CONTEXT_BYTES */
   2151  1.1      tron     }
   2152  1.8      maya     parser->m_eventPtr = parser->m_eventEndPtr = NULL;
   2153  1.8      maya     parser->m_positionPtr = NULL;
   2154  1.1      tron   }
   2155  1.8      maya   return parser->m_bufferEnd;
   2156  1.1      tron }
   2157  1.1      tron 
   2158  1.1      tron enum XML_Status XMLCALL
   2159  1.8      maya XML_StopParser(XML_Parser parser, XML_Bool resumable) {
   2160  1.7  christos   if (parser == NULL)
   2161  1.7  christos     return XML_STATUS_ERROR;
   2162  1.8      maya   switch (parser->m_parsingStatus.parsing) {
   2163  1.1      tron   case XML_SUSPENDED:
   2164  1.1      tron     if (resumable) {
   2165  1.8      maya       parser->m_errorCode = XML_ERROR_SUSPENDED;
   2166  1.1      tron       return XML_STATUS_ERROR;
   2167  1.1      tron     }
   2168  1.8      maya     parser->m_parsingStatus.parsing = XML_FINISHED;
   2169  1.1      tron     break;
   2170  1.1      tron   case XML_FINISHED:
   2171  1.8      maya     parser->m_errorCode = XML_ERROR_FINISHED;
   2172  1.1      tron     return XML_STATUS_ERROR;
   2173  1.1      tron   default:
   2174  1.1      tron     if (resumable) {
   2175  1.1      tron #ifdef XML_DTD
   2176  1.8      maya       if (parser->m_isParamEntity) {
   2177  1.8      maya         parser->m_errorCode = XML_ERROR_SUSPEND_PE;
   2178  1.1      tron         return XML_STATUS_ERROR;
   2179  1.1      tron       }
   2180  1.1      tron #endif
   2181  1.8      maya       parser->m_parsingStatus.parsing = XML_SUSPENDED;
   2182  1.8      maya     } else
   2183  1.8      maya       parser->m_parsingStatus.parsing = XML_FINISHED;
   2184  1.1      tron   }
   2185  1.1      tron   return XML_STATUS_OK;
   2186  1.1      tron }
   2187  1.1      tron 
   2188  1.1      tron enum XML_Status XMLCALL
   2189  1.8      maya XML_ResumeParser(XML_Parser parser) {
   2190  1.1      tron   enum XML_Status result = XML_STATUS_OK;
   2191  1.1      tron 
   2192  1.7  christos   if (parser == NULL)
   2193  1.7  christos     return XML_STATUS_ERROR;
   2194  1.8      maya   if (parser->m_parsingStatus.parsing != XML_SUSPENDED) {
   2195  1.8      maya     parser->m_errorCode = XML_ERROR_NOT_SUSPENDED;
   2196  1.1      tron     return XML_STATUS_ERROR;
   2197  1.1      tron   }
   2198  1.8      maya   parser->m_parsingStatus.parsing = XML_PARSING;
   2199  1.1      tron 
   2200  1.8      maya   parser->m_errorCode = parser->m_processor(
   2201  1.8      maya       parser, parser->m_bufferPtr, parser->m_parseEndPtr, &parser->m_bufferPtr);
   2202  1.1      tron 
   2203  1.8      maya   if (parser->m_errorCode != XML_ERROR_NONE) {
   2204  1.8      maya     parser->m_eventEndPtr = parser->m_eventPtr;
   2205  1.8      maya     parser->m_processor = errorProcessor;
   2206  1.1      tron     return XML_STATUS_ERROR;
   2207  1.8      maya   } else {
   2208  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   2209  1.1      tron     case XML_SUSPENDED:
   2210  1.1      tron       result = XML_STATUS_SUSPENDED;
   2211  1.1      tron       break;
   2212  1.3       spz     case XML_INITIALIZED:
   2213  1.1      tron     case XML_PARSING:
   2214  1.8      maya       if (parser->m_parsingStatus.finalBuffer) {
   2215  1.8      maya         parser->m_parsingStatus.parsing = XML_FINISHED;
   2216  1.1      tron         return result;
   2217  1.1      tron       }
   2218  1.8      maya     default:;
   2219  1.1      tron     }
   2220  1.1      tron   }
   2221  1.1      tron 
   2222  1.8      maya   XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr,
   2223  1.8      maya                     parser->m_bufferPtr, &parser->m_position);
   2224  1.8      maya   parser->m_positionPtr = parser->m_bufferPtr;
   2225  1.1      tron   return result;
   2226  1.1      tron }
   2227  1.1      tron 
   2228  1.1      tron void XMLCALL
   2229  1.8      maya XML_GetParsingStatus(XML_Parser parser, XML_ParsingStatus *status) {
   2230  1.7  christos   if (parser == NULL)
   2231  1.7  christos     return;
   2232  1.1      tron   assert(status != NULL);
   2233  1.1      tron   *status = parser->m_parsingStatus;
   2234  1.1      tron }
   2235  1.1      tron 
   2236  1.1      tron enum XML_Error XMLCALL
   2237  1.8      maya XML_GetErrorCode(XML_Parser parser) {
   2238  1.7  christos   if (parser == NULL)
   2239  1.7  christos     return XML_ERROR_INVALID_ARGUMENT;
   2240  1.8      maya   return parser->m_errorCode;
   2241  1.1      tron }
   2242  1.1      tron 
   2243  1.1      tron XML_Index XMLCALL
   2244  1.8      maya XML_GetCurrentByteIndex(XML_Parser parser) {
   2245  1.7  christos   if (parser == NULL)
   2246  1.7  christos     return -1;
   2247  1.8      maya   if (parser->m_eventPtr)
   2248  1.8      maya     return (XML_Index)(parser->m_parseEndByteIndex
   2249  1.8      maya                        - (parser->m_parseEndPtr - parser->m_eventPtr));
   2250  1.1      tron   return -1;
   2251  1.1      tron }
   2252  1.1      tron 
   2253  1.1      tron int XMLCALL
   2254  1.8      maya XML_GetCurrentByteCount(XML_Parser parser) {
   2255  1.7  christos   if (parser == NULL)
   2256  1.7  christos     return 0;
   2257  1.8      maya   if (parser->m_eventEndPtr && parser->m_eventPtr)
   2258  1.8      maya     return (int)(parser->m_eventEndPtr - parser->m_eventPtr);
   2259  1.1      tron   return 0;
   2260  1.1      tron }
   2261  1.1      tron 
   2262  1.8      maya const char *XMLCALL
   2263  1.8      maya XML_GetInputContext(XML_Parser parser, int *offset, int *size) {
   2264  1.1      tron #ifdef XML_CONTEXT_BYTES
   2265  1.7  christos   if (parser == NULL)
   2266  1.7  christos     return NULL;
   2267  1.8      maya   if (parser->m_eventPtr && parser->m_buffer) {
   2268  1.7  christos     if (offset != NULL)
   2269  1.8      maya       *offset = (int)(parser->m_eventPtr - parser->m_buffer);
   2270  1.7  christos     if (size != NULL)
   2271  1.8      maya       *size = (int)(parser->m_bufferEnd - parser->m_buffer);
   2272  1.8      maya     return parser->m_buffer;
   2273  1.1      tron   }
   2274  1.7  christos #else
   2275  1.7  christos   (void)parser;
   2276  1.7  christos   (void)offset;
   2277  1.7  christos   (void)size;
   2278  1.1      tron #endif /* defined XML_CONTEXT_BYTES */
   2279  1.9  christos   return (const char *)0;
   2280  1.1      tron }
   2281  1.1      tron 
   2282  1.1      tron XML_Size XMLCALL
   2283  1.8      maya XML_GetCurrentLineNumber(XML_Parser parser) {
   2284  1.7  christos   if (parser == NULL)
   2285  1.7  christos     return 0;
   2286  1.8      maya   if (parser->m_eventPtr && parser->m_eventPtr >= parser->m_positionPtr) {
   2287  1.8      maya     XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr,
   2288  1.8      maya                       parser->m_eventPtr, &parser->m_position);
   2289  1.8      maya     parser->m_positionPtr = parser->m_eventPtr;
   2290  1.1      tron   }
   2291  1.8      maya   return parser->m_position.lineNumber + 1;
   2292  1.1      tron }
   2293  1.1      tron 
   2294  1.1      tron XML_Size XMLCALL
   2295  1.8      maya XML_GetCurrentColumnNumber(XML_Parser parser) {
   2296  1.7  christos   if (parser == NULL)
   2297  1.7  christos     return 0;
   2298  1.8      maya   if (parser->m_eventPtr && parser->m_eventPtr >= parser->m_positionPtr) {
   2299  1.8      maya     XmlUpdatePosition(parser->m_encoding, parser->m_positionPtr,
   2300  1.8      maya                       parser->m_eventPtr, &parser->m_position);
   2301  1.8      maya     parser->m_positionPtr = parser->m_eventPtr;
   2302  1.1      tron   }
   2303  1.8      maya   return parser->m_position.columnNumber;
   2304  1.1      tron }
   2305  1.1      tron 
   2306  1.1      tron void XMLCALL
   2307  1.8      maya XML_FreeContentModel(XML_Parser parser, XML_Content *model) {
   2308  1.7  christos   if (parser != NULL)
   2309  1.8      maya     FREE(parser, model);
   2310  1.1      tron }
   2311  1.1      tron 
   2312  1.8      maya void *XMLCALL
   2313  1.8      maya XML_MemMalloc(XML_Parser parser, size_t size) {
   2314  1.7  christos   if (parser == NULL)
   2315  1.7  christos     return NULL;
   2316  1.8      maya   return MALLOC(parser, size);
   2317  1.1      tron }
   2318  1.1      tron 
   2319  1.8      maya void *XMLCALL
   2320  1.8      maya XML_MemRealloc(XML_Parser parser, void *ptr, size_t size) {
   2321  1.7  christos   if (parser == NULL)
   2322  1.7  christos     return NULL;
   2323  1.8      maya   return REALLOC(parser, ptr, size);
   2324  1.1      tron }
   2325  1.1      tron 
   2326  1.1      tron void XMLCALL
   2327  1.8      maya XML_MemFree(XML_Parser parser, void *ptr) {
   2328  1.7  christos   if (parser != NULL)
   2329  1.8      maya     FREE(parser, ptr);
   2330  1.1      tron }
   2331  1.1      tron 
   2332  1.1      tron void XMLCALL
   2333  1.8      maya XML_DefaultCurrent(XML_Parser parser) {
   2334  1.7  christos   if (parser == NULL)
   2335  1.7  christos     return;
   2336  1.8      maya   if (parser->m_defaultHandler) {
   2337  1.8      maya     if (parser->m_openInternalEntities)
   2338  1.8      maya       reportDefault(parser, parser->m_internalEncoding,
   2339  1.8      maya                     parser->m_openInternalEntities->internalEventPtr,
   2340  1.8      maya                     parser->m_openInternalEntities->internalEventEndPtr);
   2341  1.1      tron     else
   2342  1.8      maya       reportDefault(parser, parser->m_encoding, parser->m_eventPtr,
   2343  1.8      maya                     parser->m_eventEndPtr);
   2344  1.1      tron   }
   2345  1.1      tron }
   2346  1.1      tron 
   2347  1.8      maya const XML_LChar *XMLCALL
   2348  1.8      maya XML_ErrorString(enum XML_Error code) {
   2349  1.8      maya   switch (code) {
   2350  1.8      maya   case XML_ERROR_NONE:
   2351  1.8      maya     return NULL;
   2352  1.8      maya   case XML_ERROR_NO_MEMORY:
   2353  1.8      maya     return XML_L("out of memory");
   2354  1.8      maya   case XML_ERROR_SYNTAX:
   2355  1.8      maya     return XML_L("syntax error");
   2356  1.8      maya   case XML_ERROR_NO_ELEMENTS:
   2357  1.8      maya     return XML_L("no element found");
   2358  1.8      maya   case XML_ERROR_INVALID_TOKEN:
   2359  1.8      maya     return XML_L("not well-formed (invalid token)");
   2360  1.8      maya   case XML_ERROR_UNCLOSED_TOKEN:
   2361  1.8      maya     return XML_L("unclosed token");
   2362  1.8      maya   case XML_ERROR_PARTIAL_CHAR:
   2363  1.8      maya     return XML_L("partial character");
   2364  1.8      maya   case XML_ERROR_TAG_MISMATCH:
   2365  1.8      maya     return XML_L("mismatched tag");
   2366  1.8      maya   case XML_ERROR_DUPLICATE_ATTRIBUTE:
   2367  1.8      maya     return XML_L("duplicate attribute");
   2368  1.8      maya   case XML_ERROR_JUNK_AFTER_DOC_ELEMENT:
   2369  1.8      maya     return XML_L("junk after document element");
   2370  1.8      maya   case XML_ERROR_PARAM_ENTITY_REF:
   2371  1.8      maya     return XML_L("illegal parameter entity reference");
   2372  1.8      maya   case XML_ERROR_UNDEFINED_ENTITY:
   2373  1.8      maya     return XML_L("undefined entity");
   2374  1.8      maya   case XML_ERROR_RECURSIVE_ENTITY_REF:
   2375  1.8      maya     return XML_L("recursive entity reference");
   2376  1.8      maya   case XML_ERROR_ASYNC_ENTITY:
   2377  1.8      maya     return XML_L("asynchronous entity");
   2378  1.8      maya   case XML_ERROR_BAD_CHAR_REF:
   2379  1.8      maya     return XML_L("reference to invalid character number");
   2380  1.8      maya   case XML_ERROR_BINARY_ENTITY_REF:
   2381  1.8      maya     return XML_L("reference to binary entity");
   2382  1.8      maya   case XML_ERROR_ATTRIBUTE_EXTERNAL_ENTITY_REF:
   2383  1.8      maya     return XML_L("reference to external entity in attribute");
   2384  1.8      maya   case XML_ERROR_MISPLACED_XML_PI:
   2385  1.8      maya     return XML_L("XML or text declaration not at start of entity");
   2386  1.8      maya   case XML_ERROR_UNKNOWN_ENCODING:
   2387  1.8      maya     return XML_L("unknown encoding");
   2388  1.8      maya   case XML_ERROR_INCORRECT_ENCODING:
   2389  1.8      maya     return XML_L("encoding specified in XML declaration is incorrect");
   2390  1.8      maya   case XML_ERROR_UNCLOSED_CDATA_SECTION:
   2391  1.8      maya     return XML_L("unclosed CDATA section");
   2392  1.8      maya   case XML_ERROR_EXTERNAL_ENTITY_HANDLING:
   2393  1.8      maya     return XML_L("error in processing external entity reference");
   2394  1.8      maya   case XML_ERROR_NOT_STANDALONE:
   2395  1.8      maya     return XML_L("document is not standalone");
   2396  1.8      maya   case XML_ERROR_UNEXPECTED_STATE:
   2397  1.8      maya     return XML_L("unexpected parser state - please send a bug report");
   2398  1.8      maya   case XML_ERROR_ENTITY_DECLARED_IN_PE:
   2399  1.8      maya     return XML_L("entity declared in parameter entity");
   2400  1.8      maya   case XML_ERROR_FEATURE_REQUIRES_XML_DTD:
   2401  1.8      maya     return XML_L("requested feature requires XML_DTD support in Expat");
   2402  1.8      maya   case XML_ERROR_CANT_CHANGE_FEATURE_ONCE_PARSING:
   2403  1.8      maya     return XML_L("cannot change setting once parsing has begun");
   2404  1.8      maya   /* Added in 1.95.7. */
   2405  1.8      maya   case XML_ERROR_UNBOUND_PREFIX:
   2406  1.8      maya     return XML_L("unbound prefix");
   2407  1.8      maya   /* Added in 1.95.8. */
   2408  1.8      maya   case XML_ERROR_UNDECLARING_PREFIX:
   2409  1.8      maya     return XML_L("must not undeclare prefix");
   2410  1.8      maya   case XML_ERROR_INCOMPLETE_PE:
   2411  1.8      maya     return XML_L("incomplete markup in parameter entity");
   2412  1.8      maya   case XML_ERROR_XML_DECL:
   2413  1.8      maya     return XML_L("XML declaration not well-formed");
   2414  1.8      maya   case XML_ERROR_TEXT_DECL:
   2415  1.8      maya     return XML_L("text declaration not well-formed");
   2416  1.8      maya   case XML_ERROR_PUBLICID:
   2417  1.8      maya     return XML_L("illegal character(s) in public id");
   2418  1.8      maya   case XML_ERROR_SUSPENDED:
   2419  1.8      maya     return XML_L("parser suspended");
   2420  1.8      maya   case XML_ERROR_NOT_SUSPENDED:
   2421  1.8      maya     return XML_L("parser not suspended");
   2422  1.8      maya   case XML_ERROR_ABORTED:
   2423  1.8      maya     return XML_L("parsing aborted");
   2424  1.8      maya   case XML_ERROR_FINISHED:
   2425  1.8      maya     return XML_L("parsing finished");
   2426  1.8      maya   case XML_ERROR_SUSPEND_PE:
   2427  1.8      maya     return XML_L("cannot suspend in external parameter entity");
   2428  1.8      maya   /* Added in 2.0.0. */
   2429  1.8      maya   case XML_ERROR_RESERVED_PREFIX_XML:
   2430  1.8      maya     return XML_L(
   2431  1.8      maya         "reserved prefix (xml) must not be undeclared or bound to another namespace name");
   2432  1.8      maya   case XML_ERROR_RESERVED_PREFIX_XMLNS:
   2433  1.8      maya     return XML_L("reserved prefix (xmlns) must not be declared or undeclared");
   2434  1.8      maya   case XML_ERROR_RESERVED_NAMESPACE_URI:
   2435  1.8      maya     return XML_L(
   2436  1.8      maya         "prefix must not be bound to one of the reserved namespace names");
   2437  1.8      maya   /* Added in 2.2.5. */
   2438  1.8      maya   case XML_ERROR_INVALID_ARGUMENT: /* Constant added in 2.2.1, already */
   2439  1.8      maya     return XML_L("invalid argument");
   2440  1.9  christos     /* Added in 2.3.0. */
   2441  1.9  christos   case XML_ERROR_NO_BUFFER:
   2442  1.9  christos     return XML_L(
   2443  1.9  christos         "a successful prior call to function XML_GetBuffer is required");
   2444  1.9  christos   /* Added in 2.4.0. */
   2445  1.9  christos   case XML_ERROR_AMPLIFICATION_LIMIT_BREACH:
   2446  1.9  christos     return XML_L(
   2447  1.9  christos         "limit on input amplification factor (from DTD and entities) breached");
   2448  1.8      maya   }
   2449  1.1      tron   return NULL;
   2450  1.1      tron }
   2451  1.1      tron 
   2452  1.8      maya const XML_LChar *XMLCALL
   2453  1.1      tron XML_ExpatVersion(void) {
   2454  1.1      tron   /* V1 is used to string-ize the version number. However, it would
   2455  1.1      tron      string-ize the actual version macro *names* unless we get them
   2456  1.1      tron      substituted before being passed to V1. CPP is defined to expand
   2457  1.1      tron      a macro, then rescan for more expansions. Thus, we use V2 to expand
   2458  1.1      tron      the version macros, then CPP will expand the resulting V1() macro
   2459  1.1      tron      with the correct numerals. */
   2460  1.1      tron   /* ### I'm assuming cpp is portable in this respect... */
   2461  1.1      tron 
   2462  1.8      maya #define V1(a, b, c) XML_L(#a) XML_L(".") XML_L(#b) XML_L(".") XML_L(#c)
   2463  1.8      maya #define V2(a, b, c) XML_L("expat_") V1(a, b, c)
   2464  1.1      tron 
   2465  1.1      tron   return V2(XML_MAJOR_VERSION, XML_MINOR_VERSION, XML_MICRO_VERSION);
   2466  1.1      tron 
   2467  1.1      tron #undef V1
   2468  1.1      tron #undef V2
   2469  1.1      tron }
   2470  1.1      tron 
   2471  1.1      tron XML_Expat_Version XMLCALL
   2472  1.8      maya XML_ExpatVersionInfo(void) {
   2473  1.1      tron   XML_Expat_Version version;
   2474  1.1      tron 
   2475  1.1      tron   version.major = XML_MAJOR_VERSION;
   2476  1.1      tron   version.minor = XML_MINOR_VERSION;
   2477  1.1      tron   version.micro = XML_MICRO_VERSION;
   2478  1.1      tron 
   2479  1.1      tron   return version;
   2480  1.1      tron }
   2481  1.1      tron 
   2482  1.8      maya const XML_Feature *XMLCALL
   2483  1.8      maya XML_GetFeatureList(void) {
   2484  1.9  christos   static const XML_Feature features[] = {
   2485  1.9  christos       {XML_FEATURE_SIZEOF_XML_CHAR, XML_L("sizeof(XML_Char)"),
   2486  1.9  christos        sizeof(XML_Char)},
   2487  1.9  christos       {XML_FEATURE_SIZEOF_XML_LCHAR, XML_L("sizeof(XML_LChar)"),
   2488  1.9  christos        sizeof(XML_LChar)},
   2489  1.1      tron #ifdef XML_UNICODE
   2490  1.9  christos       {XML_FEATURE_UNICODE, XML_L("XML_UNICODE"), 0},
   2491  1.1      tron #endif
   2492  1.1      tron #ifdef XML_UNICODE_WCHAR_T
   2493  1.9  christos       {XML_FEATURE_UNICODE_WCHAR_T, XML_L("XML_UNICODE_WCHAR_T"), 0},
   2494  1.1      tron #endif
   2495  1.1      tron #ifdef XML_DTD
   2496  1.9  christos       {XML_FEATURE_DTD, XML_L("XML_DTD"), 0},
   2497  1.1      tron #endif
   2498  1.1      tron #ifdef XML_CONTEXT_BYTES
   2499  1.9  christos       {XML_FEATURE_CONTEXT_BYTES, XML_L("XML_CONTEXT_BYTES"),
   2500  1.9  christos        XML_CONTEXT_BYTES},
   2501  1.1      tron #endif
   2502  1.1      tron #ifdef XML_MIN_SIZE
   2503  1.9  christos       {XML_FEATURE_MIN_SIZE, XML_L("XML_MIN_SIZE"), 0},
   2504  1.1      tron #endif
   2505  1.1      tron #ifdef XML_NS
   2506  1.9  christos       {XML_FEATURE_NS, XML_L("XML_NS"), 0},
   2507  1.1      tron #endif
   2508  1.1      tron #ifdef XML_LARGE_SIZE
   2509  1.9  christos       {XML_FEATURE_LARGE_SIZE, XML_L("XML_LARGE_SIZE"), 0},
   2510  1.3       spz #endif
   2511  1.3       spz #ifdef XML_ATTR_INFO
   2512  1.9  christos       {XML_FEATURE_ATTR_INFO, XML_L("XML_ATTR_INFO"), 0},
   2513  1.9  christos #endif
   2514  1.9  christos #ifdef XML_DTD
   2515  1.9  christos       /* Added in Expat 2.4.0. */
   2516  1.9  christos       {XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT,
   2517  1.9  christos        XML_L("XML_BLAP_MAX_AMP"),
   2518  1.9  christos        (long int)
   2519  1.9  christos            EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT},
   2520  1.9  christos       {XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT,
   2521  1.9  christos        XML_L("XML_BLAP_ACT_THRES"),
   2522  1.9  christos        EXPAT_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT},
   2523  1.3       spz #endif
   2524  1.9  christos       {XML_FEATURE_END, NULL, 0}};
   2525  1.1      tron 
   2526  1.1      tron   return features;
   2527  1.1      tron }
   2528  1.1      tron 
   2529  1.9  christos #ifdef XML_DTD
   2530  1.9  christos XML_Bool XMLCALL
   2531  1.9  christos XML_SetBillionLaughsAttackProtectionMaximumAmplification(
   2532  1.9  christos     XML_Parser parser, float maximumAmplificationFactor) {
   2533  1.9  christos   if ((parser == NULL) || (parser->m_parentParser != NULL)
   2534  1.9  christos       || isnan(maximumAmplificationFactor)
   2535  1.9  christos       || (maximumAmplificationFactor < 1.0f)) {
   2536  1.9  christos     return XML_FALSE;
   2537  1.9  christos   }
   2538  1.9  christos   parser->m_accounting.maximumAmplificationFactor = maximumAmplificationFactor;
   2539  1.9  christos   return XML_TRUE;
   2540  1.9  christos }
   2541  1.9  christos 
   2542  1.9  christos XML_Bool XMLCALL
   2543  1.9  christos XML_SetBillionLaughsAttackProtectionActivationThreshold(
   2544  1.9  christos     XML_Parser parser, unsigned long long activationThresholdBytes) {
   2545  1.9  christos   if ((parser == NULL) || (parser->m_parentParser != NULL)) {
   2546  1.9  christos     return XML_FALSE;
   2547  1.9  christos   }
   2548  1.9  christos   parser->m_accounting.activationThresholdBytes = activationThresholdBytes;
   2549  1.9  christos   return XML_TRUE;
   2550  1.9  christos }
   2551  1.9  christos #endif /* XML_DTD */
   2552  1.9  christos 
   2553  1.1      tron /* Initially tag->rawName always points into the parse buffer;
   2554  1.1      tron    for those TAG instances opened while the current parse buffer was
   2555  1.1      tron    processed, and not yet closed, we need to store tag->rawName in a more
   2556  1.1      tron    permanent location, since the parse buffer is about to be discarded.
   2557  1.1      tron */
   2558  1.1      tron static XML_Bool
   2559  1.8      maya storeRawNames(XML_Parser parser) {
   2560  1.8      maya   TAG *tag = parser->m_tagStack;
   2561  1.1      tron   while (tag) {
   2562  1.1      tron     int bufSize;
   2563  1.1      tron     int nameLen = sizeof(XML_Char) * (tag->name.strLen + 1);
   2564  1.9  christos     size_t rawNameLen;
   2565  1.1      tron     char *rawNameBuf = tag->buf + nameLen;
   2566  1.8      maya     /* Stop if already stored.  Since m_tagStack is a stack, we can stop
   2567  1.1      tron        at the first entry that has already been copied; everything
   2568  1.1      tron        below it in the stack is already been accounted for in a
   2569  1.1      tron        previous call to this function.
   2570  1.1      tron     */
   2571  1.1      tron     if (tag->rawName == rawNameBuf)
   2572  1.1      tron       break;
   2573  1.1      tron     /* For re-use purposes we need to ensure that the
   2574  1.1      tron        size of tag->buf is a multiple of sizeof(XML_Char).
   2575  1.1      tron     */
   2576  1.9  christos     rawNameLen = ROUND_UP(tag->rawNameLength, sizeof(XML_Char));
   2577  1.9  christos     /* Detect and prevent integer overflow. */
   2578  1.9  christos     if (rawNameLen > (size_t)INT_MAX - nameLen)
   2579  1.9  christos       return XML_FALSE;
   2580  1.9  christos     bufSize = nameLen + (int)rawNameLen;
   2581  1.1      tron     if (bufSize > tag->bufEnd - tag->buf) {
   2582  1.8      maya       char *temp = (char *)REALLOC(parser, tag->buf, bufSize);
   2583  1.1      tron       if (temp == NULL)
   2584  1.1      tron         return XML_FALSE;
   2585  1.1      tron       /* if tag->name.str points to tag->buf (only when namespace
   2586  1.1      tron          processing is off) then we have to update it
   2587  1.1      tron       */
   2588  1.1      tron       if (tag->name.str == (XML_Char *)tag->buf)
   2589  1.1      tron         tag->name.str = (XML_Char *)temp;
   2590  1.1      tron       /* if tag->name.localPart is set (when namespace processing is on)
   2591  1.1      tron          then update it as well, since it will always point into tag->buf
   2592  1.1      tron       */
   2593  1.1      tron       if (tag->name.localPart)
   2594  1.8      maya         tag->name.localPart
   2595  1.8      maya             = (XML_Char *)temp + (tag->name.localPart - (XML_Char *)tag->buf);
   2596  1.1      tron       tag->buf = temp;
   2597  1.1      tron       tag->bufEnd = temp + bufSize;
   2598  1.1      tron       rawNameBuf = temp + nameLen;
   2599  1.1      tron     }
   2600  1.1      tron     memcpy(rawNameBuf, tag->rawName, tag->rawNameLength);
   2601  1.1      tron     tag->rawName = rawNameBuf;
   2602  1.1      tron     tag = tag->parent;
   2603  1.1      tron   }
   2604  1.1      tron   return XML_TRUE;
   2605  1.1      tron }
   2606  1.1      tron 
   2607  1.1      tron static enum XML_Error PTRCALL
   2608  1.8      maya contentProcessor(XML_Parser parser, const char *start, const char *end,
   2609  1.8      maya                  const char **endPtr) {
   2610  1.9  christos   enum XML_Error result = doContent(
   2611  1.9  christos       parser, 0, parser->m_encoding, start, end, endPtr,
   2612  1.9  christos       (XML_Bool)! parser->m_parsingStatus.finalBuffer, XML_ACCOUNT_DIRECT);
   2613  1.1      tron   if (result == XML_ERROR_NONE) {
   2614  1.8      maya     if (! storeRawNames(parser))
   2615  1.1      tron       return XML_ERROR_NO_MEMORY;
   2616  1.1      tron   }
   2617  1.1      tron   return result;
   2618  1.1      tron }
   2619  1.1      tron 
   2620  1.1      tron static enum XML_Error PTRCALL
   2621  1.8      maya externalEntityInitProcessor(XML_Parser parser, const char *start,
   2622  1.8      maya                             const char *end, const char **endPtr) {
   2623  1.1      tron   enum XML_Error result = initializeEncoding(parser);
   2624  1.1      tron   if (result != XML_ERROR_NONE)
   2625  1.1      tron     return result;
   2626  1.8      maya   parser->m_processor = externalEntityInitProcessor2;
   2627  1.1      tron   return externalEntityInitProcessor2(parser, start, end, endPtr);
   2628  1.1      tron }
   2629  1.1      tron 
   2630  1.1      tron static enum XML_Error PTRCALL
   2631  1.8      maya externalEntityInitProcessor2(XML_Parser parser, const char *start,
   2632  1.8      maya                              const char *end, const char **endPtr) {
   2633  1.1      tron   const char *next = start; /* XmlContentTok doesn't always set the last arg */
   2634  1.8      maya   int tok = XmlContentTok(parser->m_encoding, start, end, &next);
   2635  1.1      tron   switch (tok) {
   2636  1.1      tron   case XML_TOK_BOM:
   2637  1.9  christos #ifdef XML_DTD
   2638  1.9  christos     if (! accountingDiffTolerated(parser, tok, start, next, __LINE__,
   2639  1.9  christos                                   XML_ACCOUNT_DIRECT)) {
   2640  1.9  christos       accountingOnAbort(parser);
   2641  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   2642  1.9  christos     }
   2643  1.9  christos #endif /* XML_DTD */
   2644  1.9  christos 
   2645  1.1      tron     /* If we are at the end of the buffer, this would cause the next stage,
   2646  1.1      tron        i.e. externalEntityInitProcessor3, to pass control directly to
   2647  1.1      tron        doContent (by detecting XML_TOK_NONE) without processing any xml text
   2648  1.1      tron        declaration - causing the error XML_ERROR_MISPLACED_XML_PI in doContent.
   2649  1.1      tron     */
   2650  1.8      maya     if (next == end && ! parser->m_parsingStatus.finalBuffer) {
   2651  1.1      tron       *endPtr = next;
   2652  1.1      tron       return XML_ERROR_NONE;
   2653  1.1      tron     }
   2654  1.1      tron     start = next;
   2655  1.1      tron     break;
   2656  1.1      tron   case XML_TOK_PARTIAL:
   2657  1.8      maya     if (! parser->m_parsingStatus.finalBuffer) {
   2658  1.1      tron       *endPtr = start;
   2659  1.1      tron       return XML_ERROR_NONE;
   2660  1.1      tron     }
   2661  1.8      maya     parser->m_eventPtr = start;
   2662  1.1      tron     return XML_ERROR_UNCLOSED_TOKEN;
   2663  1.1      tron   case XML_TOK_PARTIAL_CHAR:
   2664  1.8      maya     if (! parser->m_parsingStatus.finalBuffer) {
   2665  1.1      tron       *endPtr = start;
   2666  1.1      tron       return XML_ERROR_NONE;
   2667  1.1      tron     }
   2668  1.8      maya     parser->m_eventPtr = start;
   2669  1.1      tron     return XML_ERROR_PARTIAL_CHAR;
   2670  1.1      tron   }
   2671  1.8      maya   parser->m_processor = externalEntityInitProcessor3;
   2672  1.1      tron   return externalEntityInitProcessor3(parser, start, end, endPtr);
   2673  1.1      tron }
   2674  1.1      tron 
   2675  1.1      tron static enum XML_Error PTRCALL
   2676  1.8      maya externalEntityInitProcessor3(XML_Parser parser, const char *start,
   2677  1.8      maya                              const char *end, const char **endPtr) {
   2678  1.1      tron   int tok;
   2679  1.1      tron   const char *next = start; /* XmlContentTok doesn't always set the last arg */
   2680  1.8      maya   parser->m_eventPtr = start;
   2681  1.8      maya   tok = XmlContentTok(parser->m_encoding, start, end, &next);
   2682  1.9  christos   /* Note: These bytes are accounted later in:
   2683  1.9  christos            - processXmlDecl
   2684  1.9  christos            - externalEntityContentProcessor
   2685  1.9  christos   */
   2686  1.8      maya   parser->m_eventEndPtr = next;
   2687  1.1      tron 
   2688  1.1      tron   switch (tok) {
   2689  1.8      maya   case XML_TOK_XML_DECL: {
   2690  1.8      maya     enum XML_Error result;
   2691  1.8      maya     result = processXmlDecl(parser, 1, start, next);
   2692  1.8      maya     if (result != XML_ERROR_NONE)
   2693  1.8      maya       return result;
   2694  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   2695  1.8      maya     case XML_SUSPENDED:
   2696  1.8      maya       *endPtr = next;
   2697  1.8      maya       return XML_ERROR_NONE;
   2698  1.8      maya     case XML_FINISHED:
   2699  1.8      maya       return XML_ERROR_ABORTED;
   2700  1.8      maya     default:
   2701  1.8      maya       start = next;
   2702  1.1      tron     }
   2703  1.8      maya   } break;
   2704  1.1      tron   case XML_TOK_PARTIAL:
   2705  1.8      maya     if (! parser->m_parsingStatus.finalBuffer) {
   2706  1.1      tron       *endPtr = start;
   2707  1.1      tron       return XML_ERROR_NONE;
   2708  1.1      tron     }
   2709  1.1      tron     return XML_ERROR_UNCLOSED_TOKEN;
   2710  1.1      tron   case XML_TOK_PARTIAL_CHAR:
   2711  1.8      maya     if (! parser->m_parsingStatus.finalBuffer) {
   2712  1.1      tron       *endPtr = start;
   2713  1.1      tron       return XML_ERROR_NONE;
   2714  1.1      tron     }
   2715  1.1      tron     return XML_ERROR_PARTIAL_CHAR;
   2716  1.1      tron   }
   2717  1.8      maya   parser->m_processor = externalEntityContentProcessor;
   2718  1.8      maya   parser->m_tagLevel = 1;
   2719  1.1      tron   return externalEntityContentProcessor(parser, start, end, endPtr);
   2720  1.1      tron }
   2721  1.1      tron 
   2722  1.1      tron static enum XML_Error PTRCALL
   2723  1.8      maya externalEntityContentProcessor(XML_Parser parser, const char *start,
   2724  1.8      maya                                const char *end, const char **endPtr) {
   2725  1.8      maya   enum XML_Error result
   2726  1.8      maya       = doContent(parser, 1, parser->m_encoding, start, end, endPtr,
   2727  1.9  christos                   (XML_Bool)! parser->m_parsingStatus.finalBuffer,
   2728  1.9  christos                   XML_ACCOUNT_ENTITY_EXPANSION);
   2729  1.1      tron   if (result == XML_ERROR_NONE) {
   2730  1.8      maya     if (! storeRawNames(parser))
   2731  1.1      tron       return XML_ERROR_NO_MEMORY;
   2732  1.1      tron   }
   2733  1.1      tron   return result;
   2734  1.1      tron }
   2735  1.1      tron 
   2736  1.1      tron static enum XML_Error
   2737  1.8      maya doContent(XML_Parser parser, int startTagLevel, const ENCODING *enc,
   2738  1.8      maya           const char *s, const char *end, const char **nextPtr,
   2739  1.9  christos           XML_Bool haveMore, enum XML_Account account) {
   2740  1.1      tron   /* save one level of indirection */
   2741  1.8      maya   DTD *const dtd = parser->m_dtd;
   2742  1.1      tron 
   2743  1.1      tron   const char **eventPP;
   2744  1.1      tron   const char **eventEndPP;
   2745  1.8      maya   if (enc == parser->m_encoding) {
   2746  1.8      maya     eventPP = &parser->m_eventPtr;
   2747  1.8      maya     eventEndPP = &parser->m_eventEndPtr;
   2748  1.8      maya   } else {
   2749  1.8      maya     eventPP = &(parser->m_openInternalEntities->internalEventPtr);
   2750  1.8      maya     eventEndPP = &(parser->m_openInternalEntities->internalEventEndPtr);
   2751  1.1      tron   }
   2752  1.1      tron   *eventPP = s;
   2753  1.1      tron 
   2754  1.1      tron   for (;;) {
   2755  1.1      tron     const char *next = s; /* XmlContentTok doesn't always set the last arg */
   2756  1.1      tron     int tok = XmlContentTok(enc, s, end, &next);
   2757  1.9  christos #ifdef XML_DTD
   2758  1.9  christos     const char *accountAfter
   2759  1.9  christos         = ((tok == XML_TOK_TRAILING_RSQB) || (tok == XML_TOK_TRAILING_CR))
   2760  1.9  christos               ? (haveMore ? s /* i.e. 0 bytes */ : end)
   2761  1.9  christos               : next;
   2762  1.9  christos     if (! accountingDiffTolerated(parser, tok, s, accountAfter, __LINE__,
   2763  1.9  christos                                   account)) {
   2764  1.9  christos       accountingOnAbort(parser);
   2765  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   2766  1.9  christos     }
   2767  1.9  christos #endif
   2768  1.1      tron     *eventEndPP = next;
   2769  1.1      tron     switch (tok) {
   2770  1.1      tron     case XML_TOK_TRAILING_CR:
   2771  1.1      tron       if (haveMore) {
   2772  1.1      tron         *nextPtr = s;
   2773  1.1      tron         return XML_ERROR_NONE;
   2774  1.1      tron       }
   2775  1.1      tron       *eventEndPP = end;
   2776  1.8      maya       if (parser->m_characterDataHandler) {
   2777  1.1      tron         XML_Char c = 0xA;
   2778  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, &c, 1);
   2779  1.8      maya       } else if (parser->m_defaultHandler)
   2780  1.1      tron         reportDefault(parser, enc, s, end);
   2781  1.3       spz       /* We are at the end of the final buffer, should we check for
   2782  1.3       spz          XML_SUSPENDED, XML_FINISHED?
   2783  1.1      tron       */
   2784  1.1      tron       if (startTagLevel == 0)
   2785  1.1      tron         return XML_ERROR_NO_ELEMENTS;
   2786  1.8      maya       if (parser->m_tagLevel != startTagLevel)
   2787  1.1      tron         return XML_ERROR_ASYNC_ENTITY;
   2788  1.1      tron       *nextPtr = end;
   2789  1.1      tron       return XML_ERROR_NONE;
   2790  1.1      tron     case XML_TOK_NONE:
   2791  1.1      tron       if (haveMore) {
   2792  1.1      tron         *nextPtr = s;
   2793  1.1      tron         return XML_ERROR_NONE;
   2794  1.1      tron       }
   2795  1.1      tron       if (startTagLevel > 0) {
   2796  1.8      maya         if (parser->m_tagLevel != startTagLevel)
   2797  1.1      tron           return XML_ERROR_ASYNC_ENTITY;
   2798  1.1      tron         *nextPtr = s;
   2799  1.1      tron         return XML_ERROR_NONE;
   2800  1.1      tron       }
   2801  1.1      tron       return XML_ERROR_NO_ELEMENTS;
   2802  1.1      tron     case XML_TOK_INVALID:
   2803  1.1      tron       *eventPP = next;
   2804  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   2805  1.1      tron     case XML_TOK_PARTIAL:
   2806  1.1      tron       if (haveMore) {
   2807  1.1      tron         *nextPtr = s;
   2808  1.1      tron         return XML_ERROR_NONE;
   2809  1.1      tron       }
   2810  1.1      tron       return XML_ERROR_UNCLOSED_TOKEN;
   2811  1.1      tron     case XML_TOK_PARTIAL_CHAR:
   2812  1.1      tron       if (haveMore) {
   2813  1.1      tron         *nextPtr = s;
   2814  1.1      tron         return XML_ERROR_NONE;
   2815  1.1      tron       }
   2816  1.1      tron       return XML_ERROR_PARTIAL_CHAR;
   2817  1.8      maya     case XML_TOK_ENTITY_REF: {
   2818  1.8      maya       const XML_Char *name;
   2819  1.8      maya       ENTITY *entity;
   2820  1.8      maya       XML_Char ch = (XML_Char)XmlPredefinedEntityName(
   2821  1.8      maya           enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar);
   2822  1.8      maya       if (ch) {
   2823  1.9  christos #ifdef XML_DTD
   2824  1.9  christos         /* NOTE: We are replacing 4-6 characters original input for 1 character
   2825  1.9  christos          *       so there is no amplification and hence recording without
   2826  1.9  christos          *       protection. */
   2827  1.9  christos         accountingDiffTolerated(parser, tok, (char *)&ch,
   2828  1.9  christos                                 ((char *)&ch) + sizeof(XML_Char), __LINE__,
   2829  1.9  christos                                 XML_ACCOUNT_ENTITY_EXPANSION);
   2830  1.9  christos #endif /* XML_DTD */
   2831  1.8      maya         if (parser->m_characterDataHandler)
   2832  1.8      maya           parser->m_characterDataHandler(parser->m_handlerArg, &ch, 1);
   2833  1.8      maya         else if (parser->m_defaultHandler)
   2834  1.8      maya           reportDefault(parser, enc, s, next);
   2835  1.8      maya         break;
   2836  1.8      maya       }
   2837  1.8      maya       name = poolStoreString(&dtd->pool, enc, s + enc->minBytesPerChar,
   2838  1.8      maya                              next - enc->minBytesPerChar);
   2839  1.8      maya       if (! name)
   2840  1.8      maya         return XML_ERROR_NO_MEMORY;
   2841  1.8      maya       entity = (ENTITY *)lookup(parser, &dtd->generalEntities, name, 0);
   2842  1.8      maya       poolDiscard(&dtd->pool);
   2843  1.8      maya       /* First, determine if a check for an existing declaration is needed;
   2844  1.8      maya          if yes, check that the entity exists, and that it is internal,
   2845  1.8      maya          otherwise call the skipped entity or default handler.
   2846  1.8      maya       */
   2847  1.8      maya       if (! dtd->hasParamEntityRefs || dtd->standalone) {
   2848  1.8      maya         if (! entity)
   2849  1.8      maya           return XML_ERROR_UNDEFINED_ENTITY;
   2850  1.8      maya         else if (! entity->is_internal)
   2851  1.8      maya           return XML_ERROR_ENTITY_DECLARED_IN_PE;
   2852  1.8      maya       } else if (! entity) {
   2853  1.8      maya         if (parser->m_skippedEntityHandler)
   2854  1.8      maya           parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0);
   2855  1.8      maya         else if (parser->m_defaultHandler)
   2856  1.8      maya           reportDefault(parser, enc, s, next);
   2857  1.8      maya         break;
   2858  1.8      maya       }
   2859  1.8      maya       if (entity->open)
   2860  1.8      maya         return XML_ERROR_RECURSIVE_ENTITY_REF;
   2861  1.8      maya       if (entity->notation)
   2862  1.8      maya         return XML_ERROR_BINARY_ENTITY_REF;
   2863  1.8      maya       if (entity->textPtr) {
   2864  1.8      maya         enum XML_Error result;
   2865  1.8      maya         if (! parser->m_defaultExpandInternalEntities) {
   2866  1.8      maya           if (parser->m_skippedEntityHandler)
   2867  1.8      maya             parser->m_skippedEntityHandler(parser->m_handlerArg, entity->name,
   2868  1.8      maya                                            0);
   2869  1.8      maya           else if (parser->m_defaultHandler)
   2870  1.1      tron             reportDefault(parser, enc, s, next);
   2871  1.1      tron           break;
   2872  1.1      tron         }
   2873  1.8      maya         result = processInternalEntity(parser, entity, XML_FALSE);
   2874  1.8      maya         if (result != XML_ERROR_NONE)
   2875  1.8      maya           return result;
   2876  1.8      maya       } else if (parser->m_externalEntityRefHandler) {
   2877  1.8      maya         const XML_Char *context;
   2878  1.8      maya         entity->open = XML_TRUE;
   2879  1.8      maya         context = getContext(parser);
   2880  1.8      maya         entity->open = XML_FALSE;
   2881  1.8      maya         if (! context)
   2882  1.8      maya           return XML_ERROR_NO_MEMORY;
   2883  1.8      maya         if (! parser->m_externalEntityRefHandler(
   2884  1.8      maya                 parser->m_externalEntityRefHandlerArg, context, entity->base,
   2885  1.8      maya                 entity->systemId, entity->publicId))
   2886  1.8      maya           return XML_ERROR_EXTERNAL_ENTITY_HANDLING;
   2887  1.8      maya         poolDiscard(&parser->m_tempPool);
   2888  1.8      maya       } else if (parser->m_defaultHandler)
   2889  1.8      maya         reportDefault(parser, enc, s, next);
   2890  1.8      maya       break;
   2891  1.8      maya     }
   2892  1.8      maya     case XML_TOK_START_TAG_NO_ATTS:
   2893  1.8      maya       /* fall through */
   2894  1.8      maya     case XML_TOK_START_TAG_WITH_ATTS: {
   2895  1.8      maya       TAG *tag;
   2896  1.8      maya       enum XML_Error result;
   2897  1.8      maya       XML_Char *toPtr;
   2898  1.8      maya       if (parser->m_freeTagList) {
   2899  1.8      maya         tag = parser->m_freeTagList;
   2900  1.8      maya         parser->m_freeTagList = parser->m_freeTagList->parent;
   2901  1.8      maya       } else {
   2902  1.8      maya         tag = (TAG *)MALLOC(parser, sizeof(TAG));
   2903  1.8      maya         if (! tag)
   2904  1.8      maya           return XML_ERROR_NO_MEMORY;
   2905  1.8      maya         tag->buf = (char *)MALLOC(parser, INIT_TAG_BUF_SIZE);
   2906  1.8      maya         if (! tag->buf) {
   2907  1.8      maya           FREE(parser, tag);
   2908  1.1      tron           return XML_ERROR_NO_MEMORY;
   2909  1.1      tron         }
   2910  1.8      maya         tag->bufEnd = tag->buf + INIT_TAG_BUF_SIZE;
   2911  1.1      tron       }
   2912  1.8      maya       tag->bindings = NULL;
   2913  1.8      maya       tag->parent = parser->m_tagStack;
   2914  1.8      maya       parser->m_tagStack = tag;
   2915  1.8      maya       tag->name.localPart = NULL;
   2916  1.8      maya       tag->name.prefix = NULL;
   2917  1.8      maya       tag->rawName = s + enc->minBytesPerChar;
   2918  1.8      maya       tag->rawNameLength = XmlNameLength(enc, tag->rawName);
   2919  1.8      maya       ++parser->m_tagLevel;
   2920  1.1      tron       {
   2921  1.8      maya         const char *rawNameEnd = tag->rawName + tag->rawNameLength;
   2922  1.8      maya         const char *fromPtr = tag->rawName;
   2923  1.8      maya         toPtr = (XML_Char *)tag->buf;
   2924  1.8      maya         for (;;) {
   2925  1.8      maya           int bufSize;
   2926  1.8      maya           int convLen;
   2927  1.8      maya           const enum XML_Convert_Result convert_res
   2928  1.8      maya               = XmlConvert(enc, &fromPtr, rawNameEnd, (ICHAR **)&toPtr,
   2929  1.8      maya                            (ICHAR *)tag->bufEnd - 1);
   2930  1.8      maya           convLen = (int)(toPtr - (XML_Char *)tag->buf);
   2931  1.8      maya           if ((fromPtr >= rawNameEnd)
   2932  1.8      maya               || (convert_res == XML_CONVERT_INPUT_INCOMPLETE)) {
   2933  1.8      maya             tag->name.strLen = convLen;
   2934  1.8      maya             break;
   2935  1.1      tron           }
   2936  1.8      maya           bufSize = (int)(tag->bufEnd - tag->buf) << 1;
   2937  1.8      maya           {
   2938  1.8      maya             char *temp = (char *)REALLOC(parser, tag->buf, bufSize);
   2939  1.8      maya             if (temp == NULL)
   2940  1.8      maya               return XML_ERROR_NO_MEMORY;
   2941  1.8      maya             tag->buf = temp;
   2942  1.8      maya             tag->bufEnd = temp + bufSize;
   2943  1.8      maya             toPtr = (XML_Char *)temp + convLen;
   2944  1.1      tron           }
   2945  1.1      tron         }
   2946  1.1      tron       }
   2947  1.8      maya       tag->name.str = (XML_Char *)tag->buf;
   2948  1.8      maya       *toPtr = XML_T('\0');
   2949  1.9  christos       result
   2950  1.9  christos           = storeAtts(parser, enc, s, &(tag->name), &(tag->bindings), account);
   2951  1.8      maya       if (result)
   2952  1.8      maya         return result;
   2953  1.8      maya       if (parser->m_startElementHandler)
   2954  1.8      maya         parser->m_startElementHandler(parser->m_handlerArg, tag->name.str,
   2955  1.8      maya                                       (const XML_Char **)parser->m_atts);
   2956  1.8      maya       else if (parser->m_defaultHandler)
   2957  1.8      maya         reportDefault(parser, enc, s, next);
   2958  1.8      maya       poolClear(&parser->m_tempPool);
   2959  1.8      maya       break;
   2960  1.8      maya     }
   2961  1.1      tron     case XML_TOK_EMPTY_ELEMENT_NO_ATTS:
   2962  1.1      tron       /* fall through */
   2963  1.8      maya     case XML_TOK_EMPTY_ELEMENT_WITH_ATTS: {
   2964  1.8      maya       const char *rawName = s + enc->minBytesPerChar;
   2965  1.8      maya       enum XML_Error result;
   2966  1.8      maya       BINDING *bindings = NULL;
   2967  1.8      maya       XML_Bool noElmHandlers = XML_TRUE;
   2968  1.8      maya       TAG_NAME name;
   2969  1.8      maya       name.str = poolStoreString(&parser->m_tempPool, enc, rawName,
   2970  1.8      maya                                  rawName + XmlNameLength(enc, rawName));
   2971  1.8      maya       if (! name.str)
   2972  1.8      maya         return XML_ERROR_NO_MEMORY;
   2973  1.8      maya       poolFinish(&parser->m_tempPool);
   2974  1.9  christos       result = storeAtts(parser, enc, s, &name, &bindings,
   2975  1.9  christos                          XML_ACCOUNT_NONE /* token spans whole start tag */);
   2976  1.8      maya       if (result != XML_ERROR_NONE) {
   2977  1.7  christos         freeBindings(parser, bindings);
   2978  1.8      maya         return result;
   2979  1.8      maya       }
   2980  1.8      maya       poolFinish(&parser->m_tempPool);
   2981  1.8      maya       if (parser->m_startElementHandler) {
   2982  1.8      maya         parser->m_startElementHandler(parser->m_handlerArg, name.str,
   2983  1.8      maya                                       (const XML_Char **)parser->m_atts);
   2984  1.8      maya         noElmHandlers = XML_FALSE;
   2985  1.8      maya       }
   2986  1.8      maya       if (parser->m_endElementHandler) {
   2987  1.8      maya         if (parser->m_startElementHandler)
   2988  1.8      maya           *eventPP = *eventEndPP;
   2989  1.8      maya         parser->m_endElementHandler(parser->m_handlerArg, name.str);
   2990  1.8      maya         noElmHandlers = XML_FALSE;
   2991  1.8      maya       }
   2992  1.8      maya       if (noElmHandlers && parser->m_defaultHandler)
   2993  1.8      maya         reportDefault(parser, enc, s, next);
   2994  1.8      maya       poolClear(&parser->m_tempPool);
   2995  1.8      maya       freeBindings(parser, bindings);
   2996  1.8      maya     }
   2997  1.8      maya       if ((parser->m_tagLevel == 0)
   2998  1.8      maya           && (parser->m_parsingStatus.parsing != XML_FINISHED)) {
   2999  1.8      maya         if (parser->m_parsingStatus.parsing == XML_SUSPENDED)
   3000  1.8      maya           parser->m_processor = epilogProcessor;
   3001  1.8      maya         else
   3002  1.8      maya           return epilogProcessor(parser, next, end, nextPtr);
   3003  1.1      tron       }
   3004  1.1      tron       break;
   3005  1.1      tron     case XML_TOK_END_TAG:
   3006  1.8      maya       if (parser->m_tagLevel == startTagLevel)
   3007  1.1      tron         return XML_ERROR_ASYNC_ENTITY;
   3008  1.1      tron       else {
   3009  1.1      tron         int len;
   3010  1.1      tron         const char *rawName;
   3011  1.8      maya         TAG *tag = parser->m_tagStack;
   3012  1.8      maya         parser->m_tagStack = tag->parent;
   3013  1.8      maya         tag->parent = parser->m_freeTagList;
   3014  1.8      maya         parser->m_freeTagList = tag;
   3015  1.8      maya         rawName = s + enc->minBytesPerChar * 2;
   3016  1.1      tron         len = XmlNameLength(enc, rawName);
   3017  1.1      tron         if (len != tag->rawNameLength
   3018  1.1      tron             || memcmp(tag->rawName, rawName, len) != 0) {
   3019  1.1      tron           *eventPP = rawName;
   3020  1.1      tron           return XML_ERROR_TAG_MISMATCH;
   3021  1.1      tron         }
   3022  1.8      maya         --parser->m_tagLevel;
   3023  1.8      maya         if (parser->m_endElementHandler) {
   3024  1.1      tron           const XML_Char *localPart;
   3025  1.1      tron           const XML_Char *prefix;
   3026  1.1      tron           XML_Char *uri;
   3027  1.1      tron           localPart = tag->name.localPart;
   3028  1.8      maya           if (parser->m_ns && localPart) {
   3029  1.1      tron             /* localPart and prefix may have been overwritten in
   3030  1.1      tron                tag->name.str, since this points to the binding->uri
   3031  1.1      tron                buffer which gets re-used; so we have to add them again
   3032  1.1      tron             */
   3033  1.1      tron             uri = (XML_Char *)tag->name.str + tag->name.uriLen;
   3034  1.1      tron             /* don't need to check for space - already done in storeAtts() */
   3035  1.8      maya             while (*localPart)
   3036  1.8      maya               *uri++ = *localPart++;
   3037  1.1      tron             prefix = (XML_Char *)tag->name.prefix;
   3038  1.8      maya             if (parser->m_ns_triplets && prefix) {
   3039  1.8      maya               *uri++ = parser->m_namespaceSeparator;
   3040  1.8      maya               while (*prefix)
   3041  1.8      maya                 *uri++ = *prefix++;
   3042  1.8      maya             }
   3043  1.1      tron             *uri = XML_T('\0');
   3044  1.1      tron           }
   3045  1.8      maya           parser->m_endElementHandler(parser->m_handlerArg, tag->name.str);
   3046  1.8      maya         } else if (parser->m_defaultHandler)
   3047  1.1      tron           reportDefault(parser, enc, s, next);
   3048  1.1      tron         while (tag->bindings) {
   3049  1.1      tron           BINDING *b = tag->bindings;
   3050  1.8      maya           if (parser->m_endNamespaceDeclHandler)
   3051  1.8      maya             parser->m_endNamespaceDeclHandler(parser->m_handlerArg,
   3052  1.8      maya                                               b->prefix->name);
   3053  1.1      tron           tag->bindings = tag->bindings->nextTagBinding;
   3054  1.8      maya           b->nextTagBinding = parser->m_freeBindingList;
   3055  1.8      maya           parser->m_freeBindingList = b;
   3056  1.1      tron           b->prefix->binding = b->prevPrefixBinding;
   3057  1.1      tron         }
   3058  1.8      maya         if ((parser->m_tagLevel == 0)
   3059  1.8      maya             && (parser->m_parsingStatus.parsing != XML_FINISHED)) {
   3060  1.8      maya           if (parser->m_parsingStatus.parsing == XML_SUSPENDED)
   3061  1.8      maya             parser->m_processor = epilogProcessor;
   3062  1.8      maya           else
   3063  1.8      maya             return epilogProcessor(parser, next, end, nextPtr);
   3064  1.1      tron         }
   3065  1.1      tron       }
   3066  1.1      tron       break;
   3067  1.8      maya     case XML_TOK_CHAR_REF: {
   3068  1.8      maya       int n = XmlCharRefNumber(enc, s);
   3069  1.8      maya       if (n < 0)
   3070  1.8      maya         return XML_ERROR_BAD_CHAR_REF;
   3071  1.8      maya       if (parser->m_characterDataHandler) {
   3072  1.8      maya         XML_Char buf[XML_ENCODE_MAX];
   3073  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, buf,
   3074  1.8      maya                                        XmlEncode(n, (ICHAR *)buf));
   3075  1.8      maya       } else if (parser->m_defaultHandler)
   3076  1.8      maya         reportDefault(parser, enc, s, next);
   3077  1.8      maya     } break;
   3078  1.1      tron     case XML_TOK_XML_DECL:
   3079  1.1      tron       return XML_ERROR_MISPLACED_XML_PI;
   3080  1.1      tron     case XML_TOK_DATA_NEWLINE:
   3081  1.8      maya       if (parser->m_characterDataHandler) {
   3082  1.1      tron         XML_Char c = 0xA;
   3083  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, &c, 1);
   3084  1.8      maya       } else if (parser->m_defaultHandler)
   3085  1.1      tron         reportDefault(parser, enc, s, next);
   3086  1.1      tron       break;
   3087  1.8      maya     case XML_TOK_CDATA_SECT_OPEN: {
   3088  1.8      maya       enum XML_Error result;
   3089  1.8      maya       if (parser->m_startCdataSectionHandler)
   3090  1.8      maya         parser->m_startCdataSectionHandler(parser->m_handlerArg);
   3091  1.8      maya       /* BEGIN disabled code */
   3092  1.8      maya       /* Suppose you doing a transformation on a document that involves
   3093  1.8      maya          changing only the character data.  You set up a defaultHandler
   3094  1.8      maya          and a characterDataHandler.  The defaultHandler simply copies
   3095  1.8      maya          characters through.  The characterDataHandler does the
   3096  1.8      maya          transformation and writes the characters out escaping them as
   3097  1.8      maya          necessary.  This case will fail to work if we leave out the
   3098  1.8      maya          following two lines (because & and < inside CDATA sections will
   3099  1.8      maya          be incorrectly escaped).
   3100  1.1      tron 
   3101  1.8      maya          However, now we have a start/endCdataSectionHandler, so it seems
   3102  1.8      maya          easier to let the user deal with this.
   3103  1.8      maya       */
   3104  1.8      maya       else if (0 && parser->m_characterDataHandler)
   3105  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, parser->m_dataBuf,
   3106  1.8      maya                                        0);
   3107  1.8      maya       /* END disabled code */
   3108  1.8      maya       else if (parser->m_defaultHandler)
   3109  1.8      maya         reportDefault(parser, enc, s, next);
   3110  1.9  christos       result
   3111  1.9  christos           = doCdataSection(parser, enc, &next, end, nextPtr, haveMore, account);
   3112  1.8      maya       if (result != XML_ERROR_NONE)
   3113  1.8      maya         return result;
   3114  1.8      maya       else if (! next) {
   3115  1.8      maya         parser->m_processor = cdataSectionProcessor;
   3116  1.8      maya         return result;
   3117  1.1      tron       }
   3118  1.8      maya     } break;
   3119  1.1      tron     case XML_TOK_TRAILING_RSQB:
   3120  1.1      tron       if (haveMore) {
   3121  1.1      tron         *nextPtr = s;
   3122  1.1      tron         return XML_ERROR_NONE;
   3123  1.1      tron       }
   3124  1.8      maya       if (parser->m_characterDataHandler) {
   3125  1.1      tron         if (MUST_CONVERT(enc, s)) {
   3126  1.8      maya           ICHAR *dataPtr = (ICHAR *)parser->m_dataBuf;
   3127  1.8      maya           XmlConvert(enc, &s, end, &dataPtr, (ICHAR *)parser->m_dataBufEnd);
   3128  1.8      maya           parser->m_characterDataHandler(
   3129  1.8      maya               parser->m_handlerArg, parser->m_dataBuf,
   3130  1.8      maya               (int)(dataPtr - (ICHAR *)parser->m_dataBuf));
   3131  1.8      maya         } else
   3132  1.8      maya           parser->m_characterDataHandler(
   3133  1.8      maya               parser->m_handlerArg, (XML_Char *)s,
   3134  1.8      maya               (int)((XML_Char *)end - (XML_Char *)s));
   3135  1.8      maya       } else if (parser->m_defaultHandler)
   3136  1.1      tron         reportDefault(parser, enc, s, end);
   3137  1.3       spz       /* We are at the end of the final buffer, should we check for
   3138  1.3       spz          XML_SUSPENDED, XML_FINISHED?
   3139  1.1      tron       */
   3140  1.1      tron       if (startTagLevel == 0) {
   3141  1.1      tron         *eventPP = end;
   3142  1.1      tron         return XML_ERROR_NO_ELEMENTS;
   3143  1.1      tron       }
   3144  1.8      maya       if (parser->m_tagLevel != startTagLevel) {
   3145  1.1      tron         *eventPP = end;
   3146  1.1      tron         return XML_ERROR_ASYNC_ENTITY;
   3147  1.1      tron       }
   3148  1.1      tron       *nextPtr = end;
   3149  1.1      tron       return XML_ERROR_NONE;
   3150  1.8      maya     case XML_TOK_DATA_CHARS: {
   3151  1.8      maya       XML_CharacterDataHandler charDataHandler = parser->m_characterDataHandler;
   3152  1.8      maya       if (charDataHandler) {
   3153  1.8      maya         if (MUST_CONVERT(enc, s)) {
   3154  1.8      maya           for (;;) {
   3155  1.8      maya             ICHAR *dataPtr = (ICHAR *)parser->m_dataBuf;
   3156  1.8      maya             const enum XML_Convert_Result convert_res = XmlConvert(
   3157  1.8      maya                 enc, &s, next, &dataPtr, (ICHAR *)parser->m_dataBufEnd);
   3158  1.8      maya             *eventEndPP = s;
   3159  1.8      maya             charDataHandler(parser->m_handlerArg, parser->m_dataBuf,
   3160  1.8      maya                             (int)(dataPtr - (ICHAR *)parser->m_dataBuf));
   3161  1.8      maya             if ((convert_res == XML_CONVERT_COMPLETED)
   3162  1.8      maya                 || (convert_res == XML_CONVERT_INPUT_INCOMPLETE))
   3163  1.8      maya               break;
   3164  1.8      maya             *eventPP = s;
   3165  1.1      tron           }
   3166  1.8      maya         } else
   3167  1.8      maya           charDataHandler(parser->m_handlerArg, (XML_Char *)s,
   3168  1.8      maya                           (int)((XML_Char *)next - (XML_Char *)s));
   3169  1.8      maya       } else if (parser->m_defaultHandler)
   3170  1.8      maya         reportDefault(parser, enc, s, next);
   3171  1.8      maya     } break;
   3172  1.1      tron     case XML_TOK_PI:
   3173  1.8      maya       if (! reportProcessingInstruction(parser, enc, s, next))
   3174  1.1      tron         return XML_ERROR_NO_MEMORY;
   3175  1.1      tron       break;
   3176  1.1      tron     case XML_TOK_COMMENT:
   3177  1.8      maya       if (! reportComment(parser, enc, s, next))
   3178  1.1      tron         return XML_ERROR_NO_MEMORY;
   3179  1.1      tron       break;
   3180  1.1      tron     default:
   3181  1.8      maya       /* All of the tokens produced by XmlContentTok() have their own
   3182  1.8      maya        * explicit cases, so this default is not strictly necessary.
   3183  1.8      maya        * However it is a useful safety net, so we retain the code and
   3184  1.8      maya        * simply exclude it from the coverage tests.
   3185  1.8      maya        *
   3186  1.8      maya        * LCOV_EXCL_START
   3187  1.8      maya        */
   3188  1.8      maya       if (parser->m_defaultHandler)
   3189  1.1      tron         reportDefault(parser, enc, s, next);
   3190  1.1      tron       break;
   3191  1.8      maya       /* LCOV_EXCL_STOP */
   3192  1.1      tron     }
   3193  1.1      tron     *eventPP = s = next;
   3194  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   3195  1.3       spz     case XML_SUSPENDED:
   3196  1.1      tron       *nextPtr = next;
   3197  1.1      tron       return XML_ERROR_NONE;
   3198  1.1      tron     case XML_FINISHED:
   3199  1.1      tron       return XML_ERROR_ABORTED;
   3200  1.8      maya     default:;
   3201  1.1      tron     }
   3202  1.1      tron   }
   3203  1.1      tron   /* not reached */
   3204  1.1      tron }
   3205  1.1      tron 
   3206  1.7  christos /* This function does not call free() on the allocated memory, merely
   3207  1.8      maya  * moving it to the parser's m_freeBindingList where it can be freed or
   3208  1.7  christos  * reused as appropriate.
   3209  1.7  christos  */
   3210  1.7  christos static void
   3211  1.8      maya freeBindings(XML_Parser parser, BINDING *bindings) {
   3212  1.7  christos   while (bindings) {
   3213  1.7  christos     BINDING *b = bindings;
   3214  1.7  christos 
   3215  1.8      maya     /* m_startNamespaceDeclHandler will have been called for this
   3216  1.7  christos      * binding in addBindings(), so call the end handler now.
   3217  1.7  christos      */
   3218  1.8      maya     if (parser->m_endNamespaceDeclHandler)
   3219  1.8      maya       parser->m_endNamespaceDeclHandler(parser->m_handlerArg, b->prefix->name);
   3220  1.7  christos 
   3221  1.7  christos     bindings = bindings->nextTagBinding;
   3222  1.8      maya     b->nextTagBinding = parser->m_freeBindingList;
   3223  1.8      maya     parser->m_freeBindingList = b;
   3224  1.7  christos     b->prefix->binding = b->prevPrefixBinding;
   3225  1.7  christos   }
   3226  1.7  christos }
   3227  1.7  christos 
   3228  1.1      tron /* Precondition: all arguments must be non-NULL;
   3229  1.1      tron    Purpose:
   3230  1.1      tron    - normalize attributes
   3231  1.1      tron    - check attributes for well-formedness
   3232  1.1      tron    - generate namespace aware attribute names (URI, prefix)
   3233  1.1      tron    - build list of attributes for startElementHandler
   3234  1.1      tron    - default attributes
   3235  1.1      tron    - process namespace declarations (check and report them)
   3236  1.1      tron    - generate namespace aware element name (URI, prefix)
   3237  1.1      tron */
   3238  1.1      tron static enum XML_Error
   3239  1.8      maya storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
   3240  1.9  christos           TAG_NAME *tagNamePtr, BINDING **bindingsPtr,
   3241  1.9  christos           enum XML_Account account) {
   3242  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   3243  1.1      tron   ELEMENT_TYPE *elementType;
   3244  1.1      tron   int nDefaultAtts;
   3245  1.8      maya   const XML_Char **appAtts; /* the attribute list for the application */
   3246  1.1      tron   int attIndex = 0;
   3247  1.1      tron   int prefixLen;
   3248  1.1      tron   int i;
   3249  1.1      tron   int n;
   3250  1.1      tron   XML_Char *uri;
   3251  1.1      tron   int nPrefixes = 0;
   3252  1.1      tron   BINDING *binding;
   3253  1.1      tron   const XML_Char *localPart;
   3254  1.1      tron 
   3255  1.1      tron   /* lookup the element type name */
   3256  1.8      maya   elementType
   3257  1.8      maya       = (ELEMENT_TYPE *)lookup(parser, &dtd->elementTypes, tagNamePtr->str, 0);
   3258  1.8      maya   if (! elementType) {
   3259  1.1      tron     const XML_Char *name = poolCopyString(&dtd->pool, tagNamePtr->str);
   3260  1.8      maya     if (! name)
   3261  1.1      tron       return XML_ERROR_NO_MEMORY;
   3262  1.3       spz     elementType = (ELEMENT_TYPE *)lookup(parser, &dtd->elementTypes, name,
   3263  1.1      tron                                          sizeof(ELEMENT_TYPE));
   3264  1.8      maya     if (! elementType)
   3265  1.1      tron       return XML_ERROR_NO_MEMORY;
   3266  1.8      maya     if (parser->m_ns && ! setElementTypePrefix(parser, elementType))
   3267  1.1      tron       return XML_ERROR_NO_MEMORY;
   3268  1.1      tron   }
   3269  1.1      tron   nDefaultAtts = elementType->nDefaultAtts;
   3270  1.1      tron 
   3271  1.1      tron   /* get the attributes from the tokenizer */
   3272  1.8      maya   n = XmlGetAttributes(enc, attStr, parser->m_attsSize, parser->m_atts);
   3273  1.9  christos 
   3274  1.9  christos   /* Detect and prevent integer overflow */
   3275  1.9  christos   if (n > INT_MAX - nDefaultAtts) {
   3276  1.9  christos     return XML_ERROR_NO_MEMORY;
   3277  1.9  christos   }
   3278  1.9  christos 
   3279  1.8      maya   if (n + nDefaultAtts > parser->m_attsSize) {
   3280  1.8      maya     int oldAttsSize = parser->m_attsSize;
   3281  1.1      tron     ATTRIBUTE *temp;
   3282  1.3       spz #ifdef XML_ATTR_INFO
   3283  1.3       spz     XML_AttrInfo *temp2;
   3284  1.3       spz #endif
   3285  1.9  christos 
   3286  1.9  christos     /* Detect and prevent integer overflow */
   3287  1.9  christos     if ((nDefaultAtts > INT_MAX - INIT_ATTS_SIZE)
   3288  1.9  christos         || (n > INT_MAX - (nDefaultAtts + INIT_ATTS_SIZE))) {
   3289  1.9  christos       return XML_ERROR_NO_MEMORY;
   3290  1.9  christos     }
   3291  1.9  christos 
   3292  1.8      maya     parser->m_attsSize = n + nDefaultAtts + INIT_ATTS_SIZE;
   3293  1.9  christos 
   3294  1.9  christos     /* Detect and prevent integer overflow.
   3295  1.9  christos      * The preprocessor guard addresses the "always false" warning
   3296  1.9  christos      * from -Wtype-limits on platforms where
   3297  1.9  christos      * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3298  1.9  christos #if UINT_MAX >= SIZE_MAX
   3299  1.9  christos     if ((unsigned)parser->m_attsSize > (size_t)(-1) / sizeof(ATTRIBUTE)) {
   3300  1.9  christos       parser->m_attsSize = oldAttsSize;
   3301  1.9  christos       return XML_ERROR_NO_MEMORY;
   3302  1.9  christos     }
   3303  1.9  christos #endif
   3304  1.9  christos 
   3305  1.8      maya     temp = (ATTRIBUTE *)REALLOC(parser, (void *)parser->m_atts,
   3306  1.8      maya                                 parser->m_attsSize * sizeof(ATTRIBUTE));
   3307  1.8      maya     if (temp == NULL) {
   3308  1.8      maya       parser->m_attsSize = oldAttsSize;
   3309  1.1      tron       return XML_ERROR_NO_MEMORY;
   3310  1.8      maya     }
   3311  1.8      maya     parser->m_atts = temp;
   3312  1.3       spz #ifdef XML_ATTR_INFO
   3313  1.9  christos     /* Detect and prevent integer overflow.
   3314  1.9  christos      * The preprocessor guard addresses the "always false" warning
   3315  1.9  christos      * from -Wtype-limits on platforms where
   3316  1.9  christos      * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3317  1.9  christos #  if UINT_MAX >= SIZE_MAX
   3318  1.9  christos     if ((unsigned)parser->m_attsSize > (size_t)(-1) / sizeof(XML_AttrInfo)) {
   3319  1.9  christos       parser->m_attsSize = oldAttsSize;
   3320  1.9  christos       return XML_ERROR_NO_MEMORY;
   3321  1.9  christos     }
   3322  1.9  christos #  endif
   3323  1.9  christos 
   3324  1.8      maya     temp2 = (XML_AttrInfo *)REALLOC(parser, (void *)parser->m_attInfo,
   3325  1.8      maya                                     parser->m_attsSize * sizeof(XML_AttrInfo));
   3326  1.8      maya     if (temp2 == NULL) {
   3327  1.8      maya       parser->m_attsSize = oldAttsSize;
   3328  1.3       spz       return XML_ERROR_NO_MEMORY;
   3329  1.8      maya     }
   3330  1.8      maya     parser->m_attInfo = temp2;
   3331  1.3       spz #endif
   3332  1.1      tron     if (n > oldAttsSize)
   3333  1.8      maya       XmlGetAttributes(enc, attStr, n, parser->m_atts);
   3334  1.1      tron   }
   3335  1.1      tron 
   3336  1.8      maya   appAtts = (const XML_Char **)parser->m_atts;
   3337  1.1      tron   for (i = 0; i < n; i++) {
   3338  1.8      maya     ATTRIBUTE *currAtt = &parser->m_atts[i];
   3339  1.3       spz #ifdef XML_ATTR_INFO
   3340  1.8      maya     XML_AttrInfo *currAttInfo = &parser->m_attInfo[i];
   3341  1.3       spz #endif
   3342  1.1      tron     /* add the name and value to the attribute list */
   3343  1.8      maya     ATTRIBUTE_ID *attId
   3344  1.8      maya         = getAttributeId(parser, enc, currAtt->name,
   3345  1.8      maya                          currAtt->name + XmlNameLength(enc, currAtt->name));
   3346  1.8      maya     if (! attId)
   3347  1.1      tron       return XML_ERROR_NO_MEMORY;
   3348  1.3       spz #ifdef XML_ATTR_INFO
   3349  1.8      maya     currAttInfo->nameStart
   3350  1.8      maya         = parser->m_parseEndByteIndex - (parser->m_parseEndPtr - currAtt->name);
   3351  1.8      maya     currAttInfo->nameEnd
   3352  1.8      maya         = currAttInfo->nameStart + XmlNameLength(enc, currAtt->name);
   3353  1.8      maya     currAttInfo->valueStart = parser->m_parseEndByteIndex
   3354  1.8      maya                               - (parser->m_parseEndPtr - currAtt->valuePtr);
   3355  1.8      maya     currAttInfo->valueEnd = parser->m_parseEndByteIndex
   3356  1.8      maya                             - (parser->m_parseEndPtr - currAtt->valueEnd);
   3357  1.3       spz #endif
   3358  1.1      tron     /* Detect duplicate attributes by their QNames. This does not work when
   3359  1.1      tron        namespace processing is turned on and different prefixes for the same
   3360  1.1      tron        namespace are used. For this case we have a check further down.
   3361  1.1      tron     */
   3362  1.1      tron     if ((attId->name)[-1]) {
   3363  1.8      maya       if (enc == parser->m_encoding)
   3364  1.8      maya         parser->m_eventPtr = parser->m_atts[i].name;
   3365  1.1      tron       return XML_ERROR_DUPLICATE_ATTRIBUTE;
   3366  1.1      tron     }
   3367  1.1      tron     (attId->name)[-1] = 1;
   3368  1.1      tron     appAtts[attIndex++] = attId->name;
   3369  1.8      maya     if (! parser->m_atts[i].normalized) {
   3370  1.1      tron       enum XML_Error result;
   3371  1.1      tron       XML_Bool isCdata = XML_TRUE;
   3372  1.1      tron 
   3373  1.1      tron       /* figure out whether declared as other than CDATA */
   3374  1.1      tron       if (attId->maybeTokenized) {
   3375  1.1      tron         int j;
   3376  1.1      tron         for (j = 0; j < nDefaultAtts; j++) {
   3377  1.1      tron           if (attId == elementType->defaultAtts[j].id) {
   3378  1.1      tron             isCdata = elementType->defaultAtts[j].isCdata;
   3379  1.1      tron             break;
   3380  1.1      tron           }
   3381  1.1      tron         }
   3382  1.1      tron       }
   3383  1.1      tron 
   3384  1.1      tron       /* normalize the attribute value */
   3385  1.8      maya       result = storeAttributeValue(
   3386  1.8      maya           parser, enc, isCdata, parser->m_atts[i].valuePtr,
   3387  1.9  christos           parser->m_atts[i].valueEnd, &parser->m_tempPool, account);
   3388  1.1      tron       if (result)
   3389  1.1      tron         return result;
   3390  1.8      maya       appAtts[attIndex] = poolStart(&parser->m_tempPool);
   3391  1.8      maya       poolFinish(&parser->m_tempPool);
   3392  1.8      maya     } else {
   3393  1.1      tron       /* the value did not need normalizing */
   3394  1.8      maya       appAtts[attIndex] = poolStoreString(&parser->m_tempPool, enc,
   3395  1.8      maya                                           parser->m_atts[i].valuePtr,
   3396  1.8      maya                                           parser->m_atts[i].valueEnd);
   3397  1.1      tron       if (appAtts[attIndex] == 0)
   3398  1.1      tron         return XML_ERROR_NO_MEMORY;
   3399  1.8      maya       poolFinish(&parser->m_tempPool);
   3400  1.1      tron     }
   3401  1.1      tron     /* handle prefixed attribute names */
   3402  1.1      tron     if (attId->prefix) {
   3403  1.1      tron       if (attId->xmlns) {
   3404  1.1      tron         /* deal with namespace declarations here */
   3405  1.1      tron         enum XML_Error result = addBinding(parser, attId->prefix, attId,
   3406  1.1      tron                                            appAtts[attIndex], bindingsPtr);
   3407  1.1      tron         if (result)
   3408  1.1      tron           return result;
   3409  1.1      tron         --attIndex;
   3410  1.8      maya       } else {
   3411  1.1      tron         /* deal with other prefixed names later */
   3412  1.1      tron         attIndex++;
   3413  1.1      tron         nPrefixes++;
   3414  1.1      tron         (attId->name)[-1] = 2;
   3415  1.1      tron       }
   3416  1.8      maya     } else
   3417  1.1      tron       attIndex++;
   3418  1.1      tron   }
   3419  1.1      tron 
   3420  1.1      tron   /* set-up for XML_GetSpecifiedAttributeCount and XML_GetIdAttributeIndex */
   3421  1.8      maya   parser->m_nSpecifiedAtts = attIndex;
   3422  1.1      tron   if (elementType->idAtt && (elementType->idAtt->name)[-1]) {
   3423  1.1      tron     for (i = 0; i < attIndex; i += 2)
   3424  1.1      tron       if (appAtts[i] == elementType->idAtt->name) {
   3425  1.8      maya         parser->m_idAttIndex = i;
   3426  1.1      tron         break;
   3427  1.1      tron       }
   3428  1.8      maya   } else
   3429  1.8      maya     parser->m_idAttIndex = -1;
   3430  1.1      tron 
   3431  1.1      tron   /* do attribute defaulting */
   3432  1.1      tron   for (i = 0; i < nDefaultAtts; i++) {
   3433  1.1      tron     const DEFAULT_ATTRIBUTE *da = elementType->defaultAtts + i;
   3434  1.8      maya     if (! (da->id->name)[-1] && da->value) {
   3435  1.1      tron       if (da->id->prefix) {
   3436  1.1      tron         if (da->id->xmlns) {
   3437  1.1      tron           enum XML_Error result = addBinding(parser, da->id->prefix, da->id,
   3438  1.1      tron                                              da->value, bindingsPtr);
   3439  1.1      tron           if (result)
   3440  1.1      tron             return result;
   3441  1.8      maya         } else {
   3442  1.1      tron           (da->id->name)[-1] = 2;
   3443  1.1      tron           nPrefixes++;
   3444  1.1      tron           appAtts[attIndex++] = da->id->name;
   3445  1.1      tron           appAtts[attIndex++] = da->value;
   3446  1.1      tron         }
   3447  1.8      maya       } else {
   3448  1.1      tron         (da->id->name)[-1] = 1;
   3449  1.1      tron         appAtts[attIndex++] = da->id->name;
   3450  1.1      tron         appAtts[attIndex++] = da->value;
   3451  1.1      tron       }
   3452  1.1      tron     }
   3453  1.1      tron   }
   3454  1.1      tron   appAtts[attIndex] = 0;
   3455  1.1      tron 
   3456  1.1      tron   /* expand prefixed attribute names, check for duplicates,
   3457  1.1      tron      and clear flags that say whether attributes were specified */
   3458  1.1      tron   i = 0;
   3459  1.1      tron   if (nPrefixes) {
   3460  1.8      maya     int j; /* hash table index */
   3461  1.8      maya     unsigned long version = parser->m_nsAttsVersion;
   3462  1.9  christos 
   3463  1.9  christos     /* Detect and prevent invalid shift */
   3464  1.9  christos     if (parser->m_nsAttsPower >= sizeof(unsigned int) * 8 /* bits per byte */) {
   3465  1.9  christos       return XML_ERROR_NO_MEMORY;
   3466  1.9  christos     }
   3467  1.9  christos 
   3468  1.9  christos     unsigned int nsAttsSize = 1u << parser->m_nsAttsPower;
   3469  1.8      maya     unsigned char oldNsAttsPower = parser->m_nsAttsPower;
   3470  1.1      tron     /* size of hash table must be at least 2 * (# of prefixed attributes) */
   3471  1.8      maya     if ((nPrefixes << 1)
   3472  1.8      maya         >> parser->m_nsAttsPower) { /* true for m_nsAttsPower = 0 */
   3473  1.1      tron       NS_ATT *temp;
   3474  1.1      tron       /* hash table size must also be a power of 2 and >= 8 */
   3475  1.8      maya       while (nPrefixes >> parser->m_nsAttsPower++)
   3476  1.8      maya         ;
   3477  1.8      maya       if (parser->m_nsAttsPower < 3)
   3478  1.8      maya         parser->m_nsAttsPower = 3;
   3479  1.9  christos 
   3480  1.9  christos       /* Detect and prevent invalid shift */
   3481  1.9  christos       if (parser->m_nsAttsPower >= sizeof(nsAttsSize) * 8 /* bits per byte */) {
   3482  1.9  christos         /* Restore actual size of memory in m_nsAtts */
   3483  1.9  christos         parser->m_nsAttsPower = oldNsAttsPower;
   3484  1.9  christos         return XML_ERROR_NO_MEMORY;
   3485  1.9  christos       }
   3486  1.9  christos 
   3487  1.9  christos       nsAttsSize = 1u << parser->m_nsAttsPower;
   3488  1.9  christos 
   3489  1.9  christos       /* Detect and prevent integer overflow.
   3490  1.9  christos        * The preprocessor guard addresses the "always false" warning
   3491  1.9  christos        * from -Wtype-limits on platforms where
   3492  1.9  christos        * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3493  1.9  christos #if UINT_MAX >= SIZE_MAX
   3494  1.9  christos       if (nsAttsSize > (size_t)(-1) / sizeof(NS_ATT)) {
   3495  1.9  christos         /* Restore actual size of memory in m_nsAtts */
   3496  1.9  christos         parser->m_nsAttsPower = oldNsAttsPower;
   3497  1.9  christos         return XML_ERROR_NO_MEMORY;
   3498  1.9  christos       }
   3499  1.9  christos #endif
   3500  1.9  christos 
   3501  1.8      maya       temp = (NS_ATT *)REALLOC(parser, parser->m_nsAtts,
   3502  1.8      maya                                nsAttsSize * sizeof(NS_ATT));
   3503  1.8      maya       if (! temp) {
   3504  1.8      maya         /* Restore actual size of memory in m_nsAtts */
   3505  1.8      maya         parser->m_nsAttsPower = oldNsAttsPower;
   3506  1.1      tron         return XML_ERROR_NO_MEMORY;
   3507  1.8      maya       }
   3508  1.8      maya       parser->m_nsAtts = temp;
   3509  1.8      maya       version = 0; /* force re-initialization of m_nsAtts hash table */
   3510  1.1      tron     }
   3511  1.8      maya     /* using a version flag saves us from initializing m_nsAtts every time */
   3512  1.8      maya     if (! version) { /* initialize version flags when version wraps around */
   3513  1.1      tron       version = INIT_ATTS_VERSION;
   3514  1.8      maya       for (j = nsAttsSize; j != 0;)
   3515  1.8      maya         parser->m_nsAtts[--j].version = version;
   3516  1.1      tron     }
   3517  1.8      maya     parser->m_nsAttsVersion = --version;
   3518  1.1      tron 
   3519  1.1      tron     /* expand prefixed names and check for duplicates */
   3520  1.1      tron     for (; i < attIndex; i += 2) {
   3521  1.1      tron       const XML_Char *s = appAtts[i];
   3522  1.8      maya       if (s[-1] == 2) { /* prefixed */
   3523  1.1      tron         ATTRIBUTE_ID *id;
   3524  1.1      tron         const BINDING *b;
   3525  1.7  christos         unsigned long uriHash;
   3526  1.7  christos         struct siphash sip_state;
   3527  1.7  christos         struct sipkey sip_key;
   3528  1.7  christos 
   3529  1.7  christos         copy_salt_to_sipkey(parser, &sip_key);
   3530  1.7  christos         sip24_init(&sip_state, &sip_key);
   3531  1.7  christos 
   3532  1.8      maya         ((XML_Char *)s)[-1] = 0; /* clear flag */
   3533  1.3       spz         id = (ATTRIBUTE_ID *)lookup(parser, &dtd->attributeIds, s, 0);
   3534  1.8      maya         if (! id || ! id->prefix) {
   3535  1.8      maya           /* This code is walking through the appAtts array, dealing
   3536  1.8      maya            * with (in this case) a prefixed attribute name.  To be in
   3537  1.8      maya            * the array, the attribute must have already been bound, so
   3538  1.8      maya            * has to have passed through the hash table lookup once
   3539  1.8      maya            * already.  That implies that an entry for it already
   3540  1.8      maya            * exists, so the lookup above will return a pointer to
   3541  1.8      maya            * already allocated memory.  There is no opportunaity for
   3542  1.8      maya            * the allocator to fail, so the condition above cannot be
   3543  1.8      maya            * fulfilled.
   3544  1.8      maya            *
   3545  1.8      maya            * Since it is difficult to be certain that the above
   3546  1.8      maya            * analysis is complete, we retain the test and merely
   3547  1.8      maya            * remove the code from coverage tests.
   3548  1.8      maya            */
   3549  1.8      maya           return XML_ERROR_NO_MEMORY; /* LCOV_EXCL_LINE */
   3550  1.8      maya         }
   3551  1.1      tron         b = id->prefix->binding;
   3552  1.8      maya         if (! b)
   3553  1.1      tron           return XML_ERROR_UNBOUND_PREFIX;
   3554  1.1      tron 
   3555  1.1      tron         for (j = 0; j < b->uriLen; j++) {
   3556  1.1      tron           const XML_Char c = b->uri[j];
   3557  1.8      maya           if (! poolAppendChar(&parser->m_tempPool, c))
   3558  1.1      tron             return XML_ERROR_NO_MEMORY;
   3559  1.1      tron         }
   3560  1.7  christos 
   3561  1.7  christos         sip24_update(&sip_state, b->uri, b->uriLen * sizeof(XML_Char));
   3562  1.7  christos 
   3563  1.1      tron         while (*s++ != XML_T(ASCII_COLON))
   3564  1.1      tron           ;
   3565  1.7  christos 
   3566  1.7  christos         sip24_update(&sip_state, s, keylen(s) * sizeof(XML_Char));
   3567  1.7  christos 
   3568  1.8      maya         do { /* copies null terminator */
   3569  1.8      maya           if (! poolAppendChar(&parser->m_tempPool, *s))
   3570  1.1      tron             return XML_ERROR_NO_MEMORY;
   3571  1.1      tron         } while (*s++);
   3572  1.1      tron 
   3573  1.7  christos         uriHash = (unsigned long)sip24_final(&sip_state);
   3574  1.7  christos 
   3575  1.1      tron         { /* Check hash table for duplicate of expanded name (uriName).
   3576  1.3       spz              Derived from code in lookup(parser, HASH_TABLE *table, ...).
   3577  1.1      tron           */
   3578  1.1      tron           unsigned char step = 0;
   3579  1.1      tron           unsigned long mask = nsAttsSize - 1;
   3580  1.8      maya           j = uriHash & mask; /* index into hash table */
   3581  1.8      maya           while (parser->m_nsAtts[j].version == version) {
   3582  1.1      tron             /* for speed we compare stored hash values first */
   3583  1.8      maya             if (uriHash == parser->m_nsAtts[j].hash) {
   3584  1.8      maya               const XML_Char *s1 = poolStart(&parser->m_tempPool);
   3585  1.8      maya               const XML_Char *s2 = parser->m_nsAtts[j].uriName;
   3586  1.1      tron               /* s1 is null terminated, but not s2 */
   3587  1.8      maya               for (; *s1 == *s2 && *s1 != 0; s1++, s2++)
   3588  1.8      maya                 ;
   3589  1.1      tron               if (*s1 == 0)
   3590  1.1      tron                 return XML_ERROR_DUPLICATE_ATTRIBUTE;
   3591  1.1      tron             }
   3592  1.8      maya             if (! step)
   3593  1.8      maya               step = PROBE_STEP(uriHash, mask, parser->m_nsAttsPower);
   3594  1.1      tron             j < step ? (j += nsAttsSize - step) : (j -= step);
   3595  1.1      tron           }
   3596  1.1      tron         }
   3597  1.1      tron 
   3598  1.8      maya         if (parser->m_ns_triplets) { /* append namespace separator and prefix */
   3599  1.8      maya           parser->m_tempPool.ptr[-1] = parser->m_namespaceSeparator;
   3600  1.1      tron           s = b->prefix->name;
   3601  1.1      tron           do {
   3602  1.8      maya             if (! poolAppendChar(&parser->m_tempPool, *s))
   3603  1.1      tron               return XML_ERROR_NO_MEMORY;
   3604  1.1      tron           } while (*s++);
   3605  1.1      tron         }
   3606  1.1      tron 
   3607  1.1      tron         /* store expanded name in attribute list */
   3608  1.8      maya         s = poolStart(&parser->m_tempPool);
   3609  1.8      maya         poolFinish(&parser->m_tempPool);
   3610  1.1      tron         appAtts[i] = s;
   3611  1.1      tron 
   3612  1.1      tron         /* fill empty slot with new version, uriName and hash value */
   3613  1.8      maya         parser->m_nsAtts[j].version = version;
   3614  1.8      maya         parser->m_nsAtts[j].hash = uriHash;
   3615  1.8      maya         parser->m_nsAtts[j].uriName = s;
   3616  1.1      tron 
   3617  1.8      maya         if (! --nPrefixes) {
   3618  1.1      tron           i += 2;
   3619  1.1      tron           break;
   3620  1.1      tron         }
   3621  1.8      maya       } else                     /* not prefixed */
   3622  1.8      maya         ((XML_Char *)s)[-1] = 0; /* clear flag */
   3623  1.1      tron     }
   3624  1.1      tron   }
   3625  1.1      tron   /* clear flags for the remaining attributes */
   3626  1.1      tron   for (; i < attIndex; i += 2)
   3627  1.1      tron     ((XML_Char *)(appAtts[i]))[-1] = 0;
   3628  1.1      tron   for (binding = *bindingsPtr; binding; binding = binding->nextTagBinding)
   3629  1.1      tron     binding->attId->name[-1] = 0;
   3630  1.1      tron 
   3631  1.8      maya   if (! parser->m_ns)
   3632  1.1      tron     return XML_ERROR_NONE;
   3633  1.1      tron 
   3634  1.1      tron   /* expand the element type name */
   3635  1.1      tron   if (elementType->prefix) {
   3636  1.1      tron     binding = elementType->prefix->binding;
   3637  1.8      maya     if (! binding)
   3638  1.1      tron       return XML_ERROR_UNBOUND_PREFIX;
   3639  1.1      tron     localPart = tagNamePtr->str;
   3640  1.1      tron     while (*localPart++ != XML_T(ASCII_COLON))
   3641  1.1      tron       ;
   3642  1.8      maya   } else if (dtd->defaultPrefix.binding) {
   3643  1.1      tron     binding = dtd->defaultPrefix.binding;
   3644  1.1      tron     localPart = tagNamePtr->str;
   3645  1.8      maya   } else
   3646  1.1      tron     return XML_ERROR_NONE;
   3647  1.1      tron   prefixLen = 0;
   3648  1.8      maya   if (parser->m_ns_triplets && binding->prefix->name) {
   3649  1.1      tron     for (; binding->prefix->name[prefixLen++];)
   3650  1.8      maya       ; /* prefixLen includes null terminator */
   3651  1.1      tron   }
   3652  1.1      tron   tagNamePtr->localPart = localPart;
   3653  1.1      tron   tagNamePtr->uriLen = binding->uriLen;
   3654  1.1      tron   tagNamePtr->prefix = binding->prefix->name;
   3655  1.1      tron   tagNamePtr->prefixLen = prefixLen;
   3656  1.1      tron   for (i = 0; localPart[i++];)
   3657  1.8      maya     ; /* i includes null terminator */
   3658  1.9  christos 
   3659  1.9  christos   /* Detect and prevent integer overflow */
   3660  1.9  christos   if (binding->uriLen > INT_MAX - prefixLen
   3661  1.9  christos       || i > INT_MAX - (binding->uriLen + prefixLen)) {
   3662  1.9  christos     return XML_ERROR_NO_MEMORY;
   3663  1.9  christos   }
   3664  1.9  christos 
   3665  1.1      tron   n = i + binding->uriLen + prefixLen;
   3666  1.1      tron   if (n > binding->uriAlloc) {
   3667  1.1      tron     TAG *p;
   3668  1.9  christos 
   3669  1.9  christos     /* Detect and prevent integer overflow */
   3670  1.9  christos     if (n > INT_MAX - EXPAND_SPARE) {
   3671  1.9  christos       return XML_ERROR_NO_MEMORY;
   3672  1.9  christos     }
   3673  1.9  christos     /* Detect and prevent integer overflow.
   3674  1.9  christos      * The preprocessor guard addresses the "always false" warning
   3675  1.9  christos      * from -Wtype-limits on platforms where
   3676  1.9  christos      * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3677  1.9  christos #if UINT_MAX >= SIZE_MAX
   3678  1.9  christos     if ((unsigned)(n + EXPAND_SPARE) > (size_t)(-1) / sizeof(XML_Char)) {
   3679  1.9  christos       return XML_ERROR_NO_MEMORY;
   3680  1.9  christos     }
   3681  1.9  christos #endif
   3682  1.9  christos 
   3683  1.8      maya     uri = (XML_Char *)MALLOC(parser, (n + EXPAND_SPARE) * sizeof(XML_Char));
   3684  1.8      maya     if (! uri)
   3685  1.1      tron       return XML_ERROR_NO_MEMORY;
   3686  1.1      tron     binding->uriAlloc = n + EXPAND_SPARE;
   3687  1.1      tron     memcpy(uri, binding->uri, binding->uriLen * sizeof(XML_Char));
   3688  1.8      maya     for (p = parser->m_tagStack; p; p = p->parent)
   3689  1.1      tron       if (p->name.str == binding->uri)
   3690  1.1      tron         p->name.str = uri;
   3691  1.8      maya     FREE(parser, binding->uri);
   3692  1.1      tron     binding->uri = uri;
   3693  1.1      tron   }
   3694  1.8      maya   /* if m_namespaceSeparator != '\0' then uri includes it already */
   3695  1.1      tron   uri = binding->uri + binding->uriLen;
   3696  1.1      tron   memcpy(uri, localPart, i * sizeof(XML_Char));
   3697  1.1      tron   /* we always have a namespace separator between localPart and prefix */
   3698  1.1      tron   if (prefixLen) {
   3699  1.1      tron     uri += i - 1;
   3700  1.8      maya     *uri = parser->m_namespaceSeparator; /* replace null terminator */
   3701  1.1      tron     memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char));
   3702  1.1      tron   }
   3703  1.1      tron   tagNamePtr->str = binding->uri;
   3704  1.1      tron   return XML_ERROR_NONE;
   3705  1.1      tron }
   3706  1.1      tron 
   3707  1.1      tron /* addBinding() overwrites the value of prefix->binding without checking.
   3708  1.1      tron    Therefore one must keep track of the old value outside of addBinding().
   3709  1.1      tron */
   3710  1.1      tron static enum XML_Error
   3711  1.1      tron addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId,
   3712  1.8      maya            const XML_Char *uri, BINDING **bindingsPtr) {
   3713  1.8      maya   static const XML_Char xmlNamespace[]
   3714  1.8      maya       = {ASCII_h,      ASCII_t,     ASCII_t,     ASCII_p,      ASCII_COLON,
   3715  1.8      maya          ASCII_SLASH,  ASCII_SLASH, ASCII_w,     ASCII_w,      ASCII_w,
   3716  1.8      maya          ASCII_PERIOD, ASCII_w,     ASCII_3,     ASCII_PERIOD, ASCII_o,
   3717  1.8      maya          ASCII_r,      ASCII_g,     ASCII_SLASH, ASCII_X,      ASCII_M,
   3718  1.8      maya          ASCII_L,      ASCII_SLASH, ASCII_1,     ASCII_9,      ASCII_9,
   3719  1.8      maya          ASCII_8,      ASCII_SLASH, ASCII_n,     ASCII_a,      ASCII_m,
   3720  1.8      maya          ASCII_e,      ASCII_s,     ASCII_p,     ASCII_a,      ASCII_c,
   3721  1.8      maya          ASCII_e,      '\0'};
   3722  1.8      maya   static const int xmlLen = (int)sizeof(xmlNamespace) / sizeof(XML_Char) - 1;
   3723  1.8      maya   static const XML_Char xmlnsNamespace[]
   3724  1.8      maya       = {ASCII_h,     ASCII_t,      ASCII_t, ASCII_p, ASCII_COLON,  ASCII_SLASH,
   3725  1.8      maya          ASCII_SLASH, ASCII_w,      ASCII_w, ASCII_w, ASCII_PERIOD, ASCII_w,
   3726  1.8      maya          ASCII_3,     ASCII_PERIOD, ASCII_o, ASCII_r, ASCII_g,      ASCII_SLASH,
   3727  1.8      maya          ASCII_2,     ASCII_0,      ASCII_0, ASCII_0, ASCII_SLASH,  ASCII_x,
   3728  1.8      maya          ASCII_m,     ASCII_l,      ASCII_n, ASCII_s, ASCII_SLASH,  '\0'};
   3729  1.8      maya   static const int xmlnsLen
   3730  1.8      maya       = (int)sizeof(xmlnsNamespace) / sizeof(XML_Char) - 1;
   3731  1.1      tron 
   3732  1.1      tron   XML_Bool mustBeXML = XML_FALSE;
   3733  1.1      tron   XML_Bool isXML = XML_TRUE;
   3734  1.1      tron   XML_Bool isXMLNS = XML_TRUE;
   3735  1.3       spz 
   3736  1.1      tron   BINDING *b;
   3737  1.1      tron   int len;
   3738  1.1      tron 
   3739  1.1      tron   /* empty URI is only valid for default namespace per XML NS 1.0 (not 1.1) */
   3740  1.1      tron   if (*uri == XML_T('\0') && prefix->name)
   3741  1.1      tron     return XML_ERROR_UNDECLARING_PREFIX;
   3742  1.1      tron 
   3743  1.8      maya   if (prefix->name && prefix->name[0] == XML_T(ASCII_x)
   3744  1.1      tron       && prefix->name[1] == XML_T(ASCII_m)
   3745  1.1      tron       && prefix->name[2] == XML_T(ASCII_l)) {
   3746  1.1      tron     /* Not allowed to bind xmlns */
   3747  1.8      maya     if (prefix->name[3] == XML_T(ASCII_n) && prefix->name[4] == XML_T(ASCII_s)
   3748  1.1      tron         && prefix->name[5] == XML_T('\0'))
   3749  1.1      tron       return XML_ERROR_RESERVED_PREFIX_XMLNS;
   3750  1.1      tron 
   3751  1.1      tron     if (prefix->name[3] == XML_T('\0'))
   3752  1.1      tron       mustBeXML = XML_TRUE;
   3753  1.1      tron   }
   3754  1.1      tron 
   3755  1.1      tron   for (len = 0; uri[len]; len++) {
   3756  1.1      tron     if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len]))
   3757  1.1      tron       isXML = XML_FALSE;
   3758  1.1      tron 
   3759  1.8      maya     if (! mustBeXML && isXMLNS
   3760  1.1      tron         && (len > xmlnsLen || uri[len] != xmlnsNamespace[len]))
   3761  1.1      tron       isXMLNS = XML_FALSE;
   3762  1.9  christos 
   3763  1.9  christos     // NOTE: While Expat does not validate namespace URIs against RFC 3986,
   3764  1.9  christos     //       we have to at least make sure that the XML processor on top of
   3765  1.9  christos     //       Expat (that is splitting tag names by namespace separator into
   3766  1.9  christos     //       2- or 3-tuples (uri-local or uri-local-prefix)) cannot be confused
   3767  1.9  christos     //       by an attacker putting additional namespace separator characters
   3768  1.9  christos     //       into namespace declarations.  That would be ambiguous and not to
   3769  1.9  christos     //       be expected.
   3770  1.9  christos     if (parser->m_ns && (uri[len] == parser->m_namespaceSeparator)) {
   3771  1.9  christos       return XML_ERROR_SYNTAX;
   3772  1.9  christos     }
   3773  1.1      tron   }
   3774  1.1      tron   isXML = isXML && len == xmlLen;
   3775  1.1      tron   isXMLNS = isXMLNS && len == xmlnsLen;
   3776  1.1      tron 
   3777  1.1      tron   if (mustBeXML != isXML)
   3778  1.1      tron     return mustBeXML ? XML_ERROR_RESERVED_PREFIX_XML
   3779  1.1      tron                      : XML_ERROR_RESERVED_NAMESPACE_URI;
   3780  1.1      tron 
   3781  1.1      tron   if (isXMLNS)
   3782  1.1      tron     return XML_ERROR_RESERVED_NAMESPACE_URI;
   3783  1.1      tron 
   3784  1.8      maya   if (parser->m_namespaceSeparator)
   3785  1.1      tron     len++;
   3786  1.8      maya   if (parser->m_freeBindingList) {
   3787  1.8      maya     b = parser->m_freeBindingList;
   3788  1.1      tron     if (len > b->uriAlloc) {
   3789  1.9  christos       /* Detect and prevent integer overflow */
   3790  1.9  christos       if (len > INT_MAX - EXPAND_SPARE) {
   3791  1.9  christos         return XML_ERROR_NO_MEMORY;
   3792  1.9  christos       }
   3793  1.9  christos 
   3794  1.9  christos       /* Detect and prevent integer overflow.
   3795  1.9  christos        * The preprocessor guard addresses the "always false" warning
   3796  1.9  christos        * from -Wtype-limits on platforms where
   3797  1.9  christos        * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3798  1.9  christos #if UINT_MAX >= SIZE_MAX
   3799  1.9  christos       if ((unsigned)(len + EXPAND_SPARE) > (size_t)(-1) / sizeof(XML_Char)) {
   3800  1.9  christos         return XML_ERROR_NO_MEMORY;
   3801  1.9  christos       }
   3802  1.9  christos #endif
   3803  1.9  christos 
   3804  1.8      maya       XML_Char *temp = (XML_Char *)REALLOC(
   3805  1.8      maya           parser, b->uri, sizeof(XML_Char) * (len + EXPAND_SPARE));
   3806  1.1      tron       if (temp == NULL)
   3807  1.1      tron         return XML_ERROR_NO_MEMORY;
   3808  1.1      tron       b->uri = temp;
   3809  1.1      tron       b->uriAlloc = len + EXPAND_SPARE;
   3810  1.1      tron     }
   3811  1.8      maya     parser->m_freeBindingList = b->nextTagBinding;
   3812  1.8      maya   } else {
   3813  1.8      maya     b = (BINDING *)MALLOC(parser, sizeof(BINDING));
   3814  1.8      maya     if (! b)
   3815  1.1      tron       return XML_ERROR_NO_MEMORY;
   3816  1.9  christos 
   3817  1.9  christos     /* Detect and prevent integer overflow */
   3818  1.9  christos     if (len > INT_MAX - EXPAND_SPARE) {
   3819  1.9  christos       return XML_ERROR_NO_MEMORY;
   3820  1.9  christos     }
   3821  1.9  christos     /* Detect and prevent integer overflow.
   3822  1.9  christos      * The preprocessor guard addresses the "always false" warning
   3823  1.9  christos      * from -Wtype-limits on platforms where
   3824  1.9  christos      * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   3825  1.9  christos #if UINT_MAX >= SIZE_MAX
   3826  1.9  christos     if ((unsigned)(len + EXPAND_SPARE) > (size_t)(-1) / sizeof(XML_Char)) {
   3827  1.9  christos       return XML_ERROR_NO_MEMORY;
   3828  1.9  christos     }
   3829  1.9  christos #endif
   3830  1.9  christos 
   3831  1.8      maya     b->uri
   3832  1.8      maya         = (XML_Char *)MALLOC(parser, sizeof(XML_Char) * (len + EXPAND_SPARE));
   3833  1.8      maya     if (! b->uri) {
   3834  1.8      maya       FREE(parser, b);
   3835  1.1      tron       return XML_ERROR_NO_MEMORY;
   3836  1.1      tron     }
   3837  1.1      tron     b->uriAlloc = len + EXPAND_SPARE;
   3838  1.1      tron   }
   3839  1.1      tron   b->uriLen = len;
   3840  1.1      tron   memcpy(b->uri, uri, len * sizeof(XML_Char));
   3841  1.8      maya   if (parser->m_namespaceSeparator)
   3842  1.8      maya     b->uri[len - 1] = parser->m_namespaceSeparator;
   3843  1.1      tron   b->prefix = prefix;
   3844  1.1      tron   b->attId = attId;
   3845  1.1      tron   b->prevPrefixBinding = prefix->binding;
   3846  1.1      tron   /* NULL binding when default namespace undeclared */
   3847  1.8      maya   if (*uri == XML_T('\0') && prefix == &parser->m_dtd->defaultPrefix)
   3848  1.1      tron     prefix->binding = NULL;
   3849  1.1      tron   else
   3850  1.1      tron     prefix->binding = b;
   3851  1.1      tron   b->nextTagBinding = *bindingsPtr;
   3852  1.1      tron   *bindingsPtr = b;
   3853  1.1      tron   /* if attId == NULL then we are not starting a namespace scope */
   3854  1.8      maya   if (attId && parser->m_startNamespaceDeclHandler)
   3855  1.8      maya     parser->m_startNamespaceDeclHandler(parser->m_handlerArg, prefix->name,
   3856  1.8      maya                                         prefix->binding ? uri : 0);
   3857  1.1      tron   return XML_ERROR_NONE;
   3858  1.1      tron }
   3859  1.1      tron 
   3860  1.1      tron /* The idea here is to avoid using stack for each CDATA section when
   3861  1.1      tron    the whole file is parsed with one call.
   3862  1.1      tron */
   3863  1.1      tron static enum XML_Error PTRCALL
   3864  1.8      maya cdataSectionProcessor(XML_Parser parser, const char *start, const char *end,
   3865  1.8      maya                       const char **endPtr) {
   3866  1.9  christos   enum XML_Error result = doCdataSection(
   3867  1.9  christos       parser, parser->m_encoding, &start, end, endPtr,
   3868  1.9  christos       (XML_Bool)! parser->m_parsingStatus.finalBuffer, XML_ACCOUNT_DIRECT);
   3869  1.1      tron   if (result != XML_ERROR_NONE)
   3870  1.1      tron     return result;
   3871  1.1      tron   if (start) {
   3872  1.8      maya     if (parser->m_parentParser) { /* we are parsing an external entity */
   3873  1.8      maya       parser->m_processor = externalEntityContentProcessor;
   3874  1.1      tron       return externalEntityContentProcessor(parser, start, end, endPtr);
   3875  1.8      maya     } else {
   3876  1.8      maya       parser->m_processor = contentProcessor;
   3877  1.1      tron       return contentProcessor(parser, start, end, endPtr);
   3878  1.1      tron     }
   3879  1.1      tron   }
   3880  1.1      tron   return result;
   3881  1.1      tron }
   3882  1.1      tron 
   3883  1.1      tron /* startPtr gets set to non-null if the section is closed, and to null if
   3884  1.1      tron    the section is not yet closed.
   3885  1.1      tron */
   3886  1.1      tron static enum XML_Error
   3887  1.8      maya doCdataSection(XML_Parser parser, const ENCODING *enc, const char **startPtr,
   3888  1.9  christos                const char *end, const char **nextPtr, XML_Bool haveMore,
   3889  1.9  christos                enum XML_Account account) {
   3890  1.1      tron   const char *s = *startPtr;
   3891  1.1      tron   const char **eventPP;
   3892  1.1      tron   const char **eventEndPP;
   3893  1.8      maya   if (enc == parser->m_encoding) {
   3894  1.8      maya     eventPP = &parser->m_eventPtr;
   3895  1.1      tron     *eventPP = s;
   3896  1.8      maya     eventEndPP = &parser->m_eventEndPtr;
   3897  1.8      maya   } else {
   3898  1.8      maya     eventPP = &(parser->m_openInternalEntities->internalEventPtr);
   3899  1.8      maya     eventEndPP = &(parser->m_openInternalEntities->internalEventEndPtr);
   3900  1.1      tron   }
   3901  1.1      tron   *eventPP = s;
   3902  1.1      tron   *startPtr = NULL;
   3903  1.1      tron 
   3904  1.1      tron   for (;;) {
   3905  1.9  christos     const char *next = s; /* in case of XML_TOK_NONE or XML_TOK_PARTIAL */
   3906  1.1      tron     int tok = XmlCdataSectionTok(enc, s, end, &next);
   3907  1.9  christos #ifdef XML_DTD
   3908  1.9  christos     if (! accountingDiffTolerated(parser, tok, s, next, __LINE__, account)) {
   3909  1.9  christos       accountingOnAbort(parser);
   3910  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   3911  1.9  christos     }
   3912  1.9  christos #else
   3913  1.9  christos     UNUSED_P(account);
   3914  1.9  christos #endif
   3915  1.1      tron     *eventEndPP = next;
   3916  1.1      tron     switch (tok) {
   3917  1.1      tron     case XML_TOK_CDATA_SECT_CLOSE:
   3918  1.8      maya       if (parser->m_endCdataSectionHandler)
   3919  1.8      maya         parser->m_endCdataSectionHandler(parser->m_handlerArg);
   3920  1.8      maya       /* BEGIN disabled code */
   3921  1.1      tron       /* see comment under XML_TOK_CDATA_SECT_OPEN */
   3922  1.8      maya       else if (0 && parser->m_characterDataHandler)
   3923  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, parser->m_dataBuf,
   3924  1.8      maya                                        0);
   3925  1.8      maya       /* END disabled code */
   3926  1.8      maya       else if (parser->m_defaultHandler)
   3927  1.1      tron         reportDefault(parser, enc, s, next);
   3928  1.1      tron       *startPtr = next;
   3929  1.1      tron       *nextPtr = next;
   3930  1.8      maya       if (parser->m_parsingStatus.parsing == XML_FINISHED)
   3931  1.1      tron         return XML_ERROR_ABORTED;
   3932  1.1      tron       else
   3933  1.1      tron         return XML_ERROR_NONE;
   3934  1.1      tron     case XML_TOK_DATA_NEWLINE:
   3935  1.8      maya       if (parser->m_characterDataHandler) {
   3936  1.1      tron         XML_Char c = 0xA;
   3937  1.8      maya         parser->m_characterDataHandler(parser->m_handlerArg, &c, 1);
   3938  1.8      maya       } else if (parser->m_defaultHandler)
   3939  1.1      tron         reportDefault(parser, enc, s, next);
   3940  1.1      tron       break;
   3941  1.8      maya     case XML_TOK_DATA_CHARS: {
   3942  1.8      maya       XML_CharacterDataHandler charDataHandler = parser->m_characterDataHandler;
   3943  1.8      maya       if (charDataHandler) {
   3944  1.8      maya         if (MUST_CONVERT(enc, s)) {
   3945  1.8      maya           for (;;) {
   3946  1.8      maya             ICHAR *dataPtr = (ICHAR *)parser->m_dataBuf;
   3947  1.8      maya             const enum XML_Convert_Result convert_res = XmlConvert(
   3948  1.8      maya                 enc, &s, next, &dataPtr, (ICHAR *)parser->m_dataBufEnd);
   3949  1.8      maya             *eventEndPP = next;
   3950  1.8      maya             charDataHandler(parser->m_handlerArg, parser->m_dataBuf,
   3951  1.8      maya                             (int)(dataPtr - (ICHAR *)parser->m_dataBuf));
   3952  1.8      maya             if ((convert_res == XML_CONVERT_COMPLETED)
   3953  1.8      maya                 || (convert_res == XML_CONVERT_INPUT_INCOMPLETE))
   3954  1.8      maya               break;
   3955  1.8      maya             *eventPP = s;
   3956  1.1      tron           }
   3957  1.8      maya         } else
   3958  1.8      maya           charDataHandler(parser->m_handlerArg, (XML_Char *)s,
   3959  1.8      maya                           (int)((XML_Char *)next - (XML_Char *)s));
   3960  1.8      maya       } else if (parser->m_defaultHandler)
   3961  1.8      maya         reportDefault(parser, enc, s, next);
   3962  1.8      maya     } break;
   3963  1.1      tron     case XML_TOK_INVALID:
   3964  1.1      tron       *eventPP = next;
   3965  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   3966  1.1      tron     case XML_TOK_PARTIAL_CHAR:
   3967  1.1      tron       if (haveMore) {
   3968  1.1      tron         *nextPtr = s;
   3969  1.1      tron         return XML_ERROR_NONE;
   3970  1.1      tron       }
   3971  1.1      tron       return XML_ERROR_PARTIAL_CHAR;
   3972  1.1      tron     case XML_TOK_PARTIAL:
   3973  1.1      tron     case XML_TOK_NONE:
   3974  1.1      tron       if (haveMore) {
   3975  1.1      tron         *nextPtr = s;
   3976  1.1      tron         return XML_ERROR_NONE;
   3977  1.1      tron       }
   3978  1.1      tron       return XML_ERROR_UNCLOSED_CDATA_SECTION;
   3979  1.1      tron     default:
   3980  1.8      maya       /* Every token returned by XmlCdataSectionTok() has its own
   3981  1.8      maya        * explicit case, so this default case will never be executed.
   3982  1.8      maya        * We retain it as a safety net and exclude it from the coverage
   3983  1.8      maya        * statistics.
   3984  1.8      maya        *
   3985  1.8      maya        * LCOV_EXCL_START
   3986  1.8      maya        */
   3987  1.1      tron       *eventPP = next;
   3988  1.1      tron       return XML_ERROR_UNEXPECTED_STATE;
   3989  1.8      maya       /* LCOV_EXCL_STOP */
   3990  1.1      tron     }
   3991  1.1      tron 
   3992  1.1      tron     *eventPP = s = next;
   3993  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   3994  1.1      tron     case XML_SUSPENDED:
   3995  1.1      tron       *nextPtr = next;
   3996  1.1      tron       return XML_ERROR_NONE;
   3997  1.1      tron     case XML_FINISHED:
   3998  1.1      tron       return XML_ERROR_ABORTED;
   3999  1.8      maya     default:;
   4000  1.1      tron     }
   4001  1.1      tron   }
   4002  1.1      tron   /* not reached */
   4003  1.1      tron }
   4004  1.1      tron 
   4005  1.1      tron #ifdef XML_DTD
   4006  1.1      tron 
   4007  1.1      tron /* The idea here is to avoid using stack for each IGNORE section when
   4008  1.1      tron    the whole file is parsed with one call.
   4009  1.1      tron */
   4010  1.1      tron static enum XML_Error PTRCALL
   4011  1.8      maya ignoreSectionProcessor(XML_Parser parser, const char *start, const char *end,
   4012  1.8      maya                        const char **endPtr) {
   4013  1.8      maya   enum XML_Error result
   4014  1.8      maya       = doIgnoreSection(parser, parser->m_encoding, &start, end, endPtr,
   4015  1.8      maya                         (XML_Bool)! parser->m_parsingStatus.finalBuffer);
   4016  1.1      tron   if (result != XML_ERROR_NONE)
   4017  1.1      tron     return result;
   4018  1.1      tron   if (start) {
   4019  1.8      maya     parser->m_processor = prologProcessor;
   4020  1.1      tron     return prologProcessor(parser, start, end, endPtr);
   4021  1.1      tron   }
   4022  1.1      tron   return result;
   4023  1.1      tron }
   4024  1.1      tron 
   4025  1.1      tron /* startPtr gets set to non-null is the section is closed, and to null
   4026  1.1      tron    if the section is not yet closed.
   4027  1.1      tron */
   4028  1.1      tron static enum XML_Error
   4029  1.8      maya doIgnoreSection(XML_Parser parser, const ENCODING *enc, const char **startPtr,
   4030  1.8      maya                 const char *end, const char **nextPtr, XML_Bool haveMore) {
   4031  1.9  christos   const char *next = *startPtr; /* in case of XML_TOK_NONE or XML_TOK_PARTIAL */
   4032  1.1      tron   int tok;
   4033  1.1      tron   const char *s = *startPtr;
   4034  1.1      tron   const char **eventPP;
   4035  1.1      tron   const char **eventEndPP;
   4036  1.8      maya   if (enc == parser->m_encoding) {
   4037  1.8      maya     eventPP = &parser->m_eventPtr;
   4038  1.1      tron     *eventPP = s;
   4039  1.8      maya     eventEndPP = &parser->m_eventEndPtr;
   4040  1.8      maya   } else {
   4041  1.8      maya     /* It's not entirely clear, but it seems the following two lines
   4042  1.8      maya      * of code cannot be executed.  The only occasions on which 'enc'
   4043  1.8      maya      * is not 'encoding' are when this function is called
   4044  1.8      maya      * from the internal entity processing, and IGNORE sections are an
   4045  1.8      maya      * error in internal entities.
   4046  1.8      maya      *
   4047  1.8      maya      * Since it really isn't clear that this is true, we keep the code
   4048  1.8      maya      * and just remove it from our coverage tests.
   4049  1.8      maya      *
   4050  1.8      maya      * LCOV_EXCL_START
   4051  1.8      maya      */
   4052  1.8      maya     eventPP = &(parser->m_openInternalEntities->internalEventPtr);
   4053  1.8      maya     eventEndPP = &(parser->m_openInternalEntities->internalEventEndPtr);
   4054  1.8      maya     /* LCOV_EXCL_STOP */
   4055  1.1      tron   }
   4056  1.1      tron   *eventPP = s;
   4057  1.1      tron   *startPtr = NULL;
   4058  1.1      tron   tok = XmlIgnoreSectionTok(enc, s, end, &next);
   4059  1.9  christos #  ifdef XML_DTD
   4060  1.9  christos   if (! accountingDiffTolerated(parser, tok, s, next, __LINE__,
   4061  1.9  christos                                 XML_ACCOUNT_DIRECT)) {
   4062  1.9  christos     accountingOnAbort(parser);
   4063  1.9  christos     return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   4064  1.9  christos   }
   4065  1.9  christos #  endif
   4066  1.1      tron   *eventEndPP = next;
   4067  1.1      tron   switch (tok) {
   4068  1.1      tron   case XML_TOK_IGNORE_SECT:
   4069  1.8      maya     if (parser->m_defaultHandler)
   4070  1.1      tron       reportDefault(parser, enc, s, next);
   4071  1.1      tron     *startPtr = next;
   4072  1.1      tron     *nextPtr = next;
   4073  1.8      maya     if (parser->m_parsingStatus.parsing == XML_FINISHED)
   4074  1.1      tron       return XML_ERROR_ABORTED;
   4075  1.1      tron     else
   4076  1.1      tron       return XML_ERROR_NONE;
   4077  1.1      tron   case XML_TOK_INVALID:
   4078  1.1      tron     *eventPP = next;
   4079  1.1      tron     return XML_ERROR_INVALID_TOKEN;
   4080  1.1      tron   case XML_TOK_PARTIAL_CHAR:
   4081  1.1      tron     if (haveMore) {
   4082  1.1      tron       *nextPtr = s;
   4083  1.1      tron       return XML_ERROR_NONE;
   4084  1.1      tron     }
   4085  1.1      tron     return XML_ERROR_PARTIAL_CHAR;
   4086  1.1      tron   case XML_TOK_PARTIAL:
   4087  1.1      tron   case XML_TOK_NONE:
   4088  1.1      tron     if (haveMore) {
   4089  1.1      tron       *nextPtr = s;
   4090  1.1      tron       return XML_ERROR_NONE;
   4091  1.1      tron     }
   4092  1.1      tron     return XML_ERROR_SYNTAX; /* XML_ERROR_UNCLOSED_IGNORE_SECTION */
   4093  1.1      tron   default:
   4094  1.8      maya     /* All of the tokens that XmlIgnoreSectionTok() returns have
   4095  1.8      maya      * explicit cases to handle them, so this default case is never
   4096  1.8      maya      * executed.  We keep it as a safety net anyway, and remove it
   4097  1.8      maya      * from our test coverage statistics.
   4098  1.8      maya      *
   4099  1.8      maya      * LCOV_EXCL_START
   4100  1.8      maya      */
   4101  1.1      tron     *eventPP = next;
   4102  1.1      tron     return XML_ERROR_UNEXPECTED_STATE;
   4103  1.8      maya     /* LCOV_EXCL_STOP */
   4104  1.1      tron   }
   4105  1.1      tron   /* not reached */
   4106  1.1      tron }
   4107  1.1      tron 
   4108  1.1      tron #endif /* XML_DTD */
   4109  1.1      tron 
   4110  1.1      tron static enum XML_Error
   4111  1.8      maya initializeEncoding(XML_Parser parser) {
   4112  1.1      tron   const char *s;
   4113  1.1      tron #ifdef XML_UNICODE
   4114  1.1      tron   char encodingBuf[128];
   4115  1.9  christos   /* See comments about `protocolEncodingName` in parserInit() */
   4116  1.8      maya   if (! parser->m_protocolEncodingName)
   4117  1.1      tron     s = NULL;
   4118  1.1      tron   else {
   4119  1.1      tron     int i;
   4120  1.8      maya     for (i = 0; parser->m_protocolEncodingName[i]; i++) {
   4121  1.1      tron       if (i == sizeof(encodingBuf) - 1
   4122  1.8      maya           || (parser->m_protocolEncodingName[i] & ~0x7f) != 0) {
   4123  1.1      tron         encodingBuf[0] = '\0';
   4124  1.1      tron         break;
   4125  1.1      tron       }
   4126  1.8      maya       encodingBuf[i] = (char)parser->m_protocolEncodingName[i];
   4127  1.1      tron     }
   4128  1.1      tron     encodingBuf[i] = '\0';
   4129  1.1      tron     s = encodingBuf;
   4130  1.1      tron   }
   4131  1.1      tron #else
   4132  1.8      maya   s = parser->m_protocolEncodingName;
   4133  1.1      tron #endif
   4134  1.8      maya   if ((parser->m_ns ? XmlInitEncodingNS : XmlInitEncoding)(
   4135  1.8      maya           &parser->m_initEncoding, &parser->m_encoding, s))
   4136  1.1      tron     return XML_ERROR_NONE;
   4137  1.8      maya   return handleUnknownEncoding(parser, parser->m_protocolEncodingName);
   4138  1.1      tron }
   4139  1.1      tron 
   4140  1.1      tron static enum XML_Error
   4141  1.8      maya processXmlDecl(XML_Parser parser, int isGeneralTextEntity, const char *s,
   4142  1.8      maya                const char *next) {
   4143  1.1      tron   const char *encodingName = NULL;
   4144  1.1      tron   const XML_Char *storedEncName = NULL;
   4145  1.1      tron   const ENCODING *newEncoding = NULL;
   4146  1.1      tron   const char *version = NULL;
   4147  1.1      tron   const char *versionend;
   4148  1.1      tron   const XML_Char *storedversion = NULL;
   4149  1.1      tron   int standalone = -1;
   4150  1.9  christos 
   4151  1.9  christos #ifdef XML_DTD
   4152  1.9  christos   if (! accountingDiffTolerated(parser, XML_TOK_XML_DECL, s, next, __LINE__,
   4153  1.9  christos                                 XML_ACCOUNT_DIRECT)) {
   4154  1.9  christos     accountingOnAbort(parser);
   4155  1.9  christos     return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   4156  1.9  christos   }
   4157  1.9  christos #endif
   4158  1.9  christos 
   4159  1.8      maya   if (! (parser->m_ns ? XmlParseXmlDeclNS : XmlParseXmlDecl)(
   4160  1.8      maya           isGeneralTextEntity, parser->m_encoding, s, next, &parser->m_eventPtr,
   4161  1.8      maya           &version, &versionend, &encodingName, &newEncoding, &standalone)) {
   4162  1.1      tron     if (isGeneralTextEntity)
   4163  1.1      tron       return XML_ERROR_TEXT_DECL;
   4164  1.1      tron     else
   4165  1.1      tron       return XML_ERROR_XML_DECL;
   4166  1.1      tron   }
   4167  1.8      maya   if (! isGeneralTextEntity && standalone == 1) {
   4168  1.8      maya     parser->m_dtd->standalone = XML_TRUE;
   4169  1.1      tron #ifdef XML_DTD
   4170  1.8      maya     if (parser->m_paramEntityParsing
   4171  1.8      maya         == XML_PARAM_ENTITY_PARSING_UNLESS_STANDALONE)
   4172  1.8      maya       parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER;
   4173  1.1      tron #endif /* XML_DTD */
   4174  1.1      tron   }
   4175  1.8      maya   if (parser->m_xmlDeclHandler) {
   4176  1.1      tron     if (encodingName != NULL) {
   4177  1.8      maya       storedEncName = poolStoreString(
   4178  1.8      maya           &parser->m_temp2Pool, parser->m_encoding, encodingName,
   4179  1.8      maya           encodingName + XmlNameLength(parser->m_encoding, encodingName));
   4180  1.8      maya       if (! storedEncName)
   4181  1.8      maya         return XML_ERROR_NO_MEMORY;
   4182  1.8      maya       poolFinish(&parser->m_temp2Pool);
   4183  1.1      tron     }
   4184  1.1      tron     if (version) {
   4185  1.8      maya       storedversion
   4186  1.8      maya           = poolStoreString(&parser->m_temp2Pool, parser->m_encoding, version,
   4187  1.8      maya                             versionend - parser->m_encoding->minBytesPerChar);
   4188  1.8      maya       if (! storedversion)
   4189  1.1      tron         return XML_ERROR_NO_MEMORY;
   4190  1.1      tron     }
   4191  1.8      maya     parser->m_xmlDeclHandler(parser->m_handlerArg, storedversion, storedEncName,
   4192  1.8      maya                              standalone);
   4193  1.8      maya   } else if (parser->m_defaultHandler)
   4194  1.8      maya     reportDefault(parser, parser->m_encoding, s, next);
   4195  1.8      maya   if (parser->m_protocolEncodingName == NULL) {
   4196  1.1      tron     if (newEncoding) {
   4197  1.8      maya       /* Check that the specified encoding does not conflict with what
   4198  1.8      maya        * the parser has already deduced.  Do we have the same number
   4199  1.8      maya        * of bytes in the smallest representation of a character?  If
   4200  1.8      maya        * this is UTF-16, is it the same endianness?
   4201  1.8      maya        */
   4202  1.8      maya       if (newEncoding->minBytesPerChar != parser->m_encoding->minBytesPerChar
   4203  1.8      maya           || (newEncoding->minBytesPerChar == 2
   4204  1.8      maya               && newEncoding != parser->m_encoding)) {
   4205  1.8      maya         parser->m_eventPtr = encodingName;
   4206  1.1      tron         return XML_ERROR_INCORRECT_ENCODING;
   4207  1.1      tron       }
   4208  1.8      maya       parser->m_encoding = newEncoding;
   4209  1.8      maya     } else if (encodingName) {
   4210  1.1      tron       enum XML_Error result;
   4211  1.8      maya       if (! storedEncName) {
   4212  1.1      tron         storedEncName = poolStoreString(
   4213  1.8      maya             &parser->m_temp2Pool, parser->m_encoding, encodingName,
   4214  1.8      maya             encodingName + XmlNameLength(parser->m_encoding, encodingName));
   4215  1.8      maya         if (! storedEncName)
   4216  1.1      tron           return XML_ERROR_NO_MEMORY;
   4217  1.1      tron       }
   4218  1.1      tron       result = handleUnknownEncoding(parser, storedEncName);
   4219  1.8      maya       poolClear(&parser->m_temp2Pool);
   4220  1.1      tron       if (result == XML_ERROR_UNKNOWN_ENCODING)
   4221  1.8      maya         parser->m_eventPtr = encodingName;
   4222  1.1      tron       return result;
   4223  1.1      tron     }
   4224  1.1      tron   }
   4225  1.1      tron 
   4226  1.1      tron   if (storedEncName || storedversion)
   4227  1.8      maya     poolClear(&parser->m_temp2Pool);
   4228  1.1      tron 
   4229  1.1      tron   return XML_ERROR_NONE;
   4230  1.1      tron }
   4231  1.1      tron 
   4232  1.1      tron static enum XML_Error
   4233  1.8      maya handleUnknownEncoding(XML_Parser parser, const XML_Char *encodingName) {
   4234  1.8      maya   if (parser->m_unknownEncodingHandler) {
   4235  1.1      tron     XML_Encoding info;
   4236  1.1      tron     int i;
   4237  1.1      tron     for (i = 0; i < 256; i++)
   4238  1.1      tron       info.map[i] = -1;
   4239  1.1      tron     info.convert = NULL;
   4240  1.1      tron     info.data = NULL;
   4241  1.1      tron     info.release = NULL;
   4242  1.8      maya     if (parser->m_unknownEncodingHandler(parser->m_unknownEncodingHandlerData,
   4243  1.8      maya                                          encodingName, &info)) {
   4244  1.1      tron       ENCODING *enc;
   4245  1.8      maya       parser->m_unknownEncodingMem = MALLOC(parser, XmlSizeOfUnknownEncoding());
   4246  1.8      maya       if (! parser->m_unknownEncodingMem) {
   4247  1.1      tron         if (info.release)
   4248  1.1      tron           info.release(info.data);
   4249  1.1      tron         return XML_ERROR_NO_MEMORY;
   4250  1.1      tron       }
   4251  1.8      maya       enc = (parser->m_ns ? XmlInitUnknownEncodingNS : XmlInitUnknownEncoding)(
   4252  1.8      maya           parser->m_unknownEncodingMem, info.map, info.convert, info.data);
   4253  1.1      tron       if (enc) {
   4254  1.8      maya         parser->m_unknownEncodingData = info.data;
   4255  1.8      maya         parser->m_unknownEncodingRelease = info.release;
   4256  1.8      maya         parser->m_encoding = enc;
   4257  1.1      tron         return XML_ERROR_NONE;
   4258  1.1      tron       }
   4259  1.1      tron     }
   4260  1.1      tron     if (info.release != NULL)
   4261  1.1      tron       info.release(info.data);
   4262  1.1      tron   }
   4263  1.1      tron   return XML_ERROR_UNKNOWN_ENCODING;
   4264  1.1      tron }
   4265  1.1      tron 
   4266  1.1      tron static enum XML_Error PTRCALL
   4267  1.8      maya prologInitProcessor(XML_Parser parser, const char *s, const char *end,
   4268  1.8      maya                     const char **nextPtr) {
   4269  1.1      tron   enum XML_Error result = initializeEncoding(parser);
   4270  1.1      tron   if (result != XML_ERROR_NONE)
   4271  1.1      tron     return result;
   4272  1.8      maya   parser->m_processor = prologProcessor;
   4273  1.1      tron   return prologProcessor(parser, s, end, nextPtr);
   4274  1.1      tron }
   4275  1.1      tron 
   4276  1.1      tron #ifdef XML_DTD
   4277  1.1      tron 
   4278  1.1      tron static enum XML_Error PTRCALL
   4279  1.8      maya externalParEntInitProcessor(XML_Parser parser, const char *s, const char *end,
   4280  1.8      maya                             const char **nextPtr) {
   4281  1.1      tron   enum XML_Error result = initializeEncoding(parser);
   4282  1.1      tron   if (result != XML_ERROR_NONE)
   4283  1.1      tron     return result;
   4284  1.1      tron 
   4285  1.1      tron   /* we know now that XML_Parse(Buffer) has been called,
   4286  1.1      tron      so we consider the external parameter entity read */
   4287  1.8      maya   parser->m_dtd->paramEntityRead = XML_TRUE;
   4288  1.1      tron 
   4289  1.8      maya   if (parser->m_prologState.inEntityValue) {
   4290  1.8      maya     parser->m_processor = entityValueInitProcessor;
   4291  1.1      tron     return entityValueInitProcessor(parser, s, end, nextPtr);
   4292  1.8      maya   } else {
   4293  1.8      maya     parser->m_processor = externalParEntProcessor;
   4294  1.1      tron     return externalParEntProcessor(parser, s, end, nextPtr);
   4295  1.1      tron   }
   4296  1.1      tron }
   4297  1.1      tron 
   4298  1.1      tron static enum XML_Error PTRCALL
   4299  1.8      maya entityValueInitProcessor(XML_Parser parser, const char *s, const char *end,
   4300  1.8      maya                          const char **nextPtr) {
   4301  1.1      tron   int tok;
   4302  1.1      tron   const char *start = s;
   4303  1.1      tron   const char *next = start;
   4304  1.8      maya   parser->m_eventPtr = start;
   4305  1.1      tron 
   4306  1.3       spz   for (;;) {
   4307  1.8      maya     tok = XmlPrologTok(parser->m_encoding, start, end, &next);
   4308  1.9  christos     /* Note: Except for XML_TOK_BOM below, these bytes are accounted later in:
   4309  1.9  christos              - storeEntityValue
   4310  1.9  christos              - processXmlDecl
   4311  1.9  christos     */
   4312  1.8      maya     parser->m_eventEndPtr = next;
   4313  1.1      tron     if (tok <= 0) {
   4314  1.8      maya       if (! parser->m_parsingStatus.finalBuffer && tok != XML_TOK_INVALID) {
   4315  1.1      tron         *nextPtr = s;
   4316  1.1      tron         return XML_ERROR_NONE;
   4317  1.1      tron       }
   4318  1.1      tron       switch (tok) {
   4319  1.1      tron       case XML_TOK_INVALID:
   4320  1.1      tron         return XML_ERROR_INVALID_TOKEN;
   4321  1.1      tron       case XML_TOK_PARTIAL:
   4322  1.1      tron         return XML_ERROR_UNCLOSED_TOKEN;
   4323  1.1      tron       case XML_TOK_PARTIAL_CHAR:
   4324  1.1      tron         return XML_ERROR_PARTIAL_CHAR;
   4325  1.8      maya       case XML_TOK_NONE: /* start == end */
   4326  1.1      tron       default:
   4327  1.1      tron         break;
   4328  1.1      tron       }
   4329  1.1      tron       /* found end of entity value - can store it now */
   4330  1.9  christos       return storeEntityValue(parser, parser->m_encoding, s, end,
   4331  1.9  christos                               XML_ACCOUNT_DIRECT);
   4332  1.8      maya     } else if (tok == XML_TOK_XML_DECL) {
   4333  1.1      tron       enum XML_Error result;
   4334  1.1      tron       result = processXmlDecl(parser, 0, start, next);
   4335  1.1      tron       if (result != XML_ERROR_NONE)
   4336  1.1      tron         return result;
   4337  1.8      maya       /* At this point, m_parsingStatus.parsing cannot be XML_SUSPENDED.  For
   4338  1.8      maya        * that to happen, a parameter entity parsing handler must have attempted
   4339  1.8      maya        * to suspend the parser, which fails and raises an error.  The parser can
   4340  1.8      maya        * be aborted, but can't be suspended.
   4341  1.8      maya        */
   4342  1.8      maya       if (parser->m_parsingStatus.parsing == XML_FINISHED)
   4343  1.1      tron         return XML_ERROR_ABORTED;
   4344  1.8      maya       *nextPtr = next;
   4345  1.1      tron       /* stop scanning for text declaration - we found one */
   4346  1.8      maya       parser->m_processor = entityValueProcessor;
   4347  1.1      tron       return entityValueProcessor(parser, next, end, nextPtr);
   4348  1.1      tron     }
   4349  1.1      tron     /* If we are at the end of the buffer, this would cause XmlPrologTok to
   4350  1.1      tron        return XML_TOK_NONE on the next call, which would then cause the
   4351  1.1      tron        function to exit with *nextPtr set to s - that is what we want for other
   4352  1.1      tron        tokens, but not for the BOM - we would rather like to skip it;
   4353  1.1      tron        then, when this routine is entered the next time, XmlPrologTok will
   4354  1.1      tron        return XML_TOK_INVALID, since the BOM is still in the buffer
   4355  1.1      tron     */
   4356  1.8      maya     else if (tok == XML_TOK_BOM && next == end
   4357  1.8      maya              && ! parser->m_parsingStatus.finalBuffer) {
   4358  1.9  christos #  ifdef XML_DTD
   4359  1.9  christos       if (! accountingDiffTolerated(parser, tok, s, next, __LINE__,
   4360  1.9  christos                                     XML_ACCOUNT_DIRECT)) {
   4361  1.9  christos         accountingOnAbort(parser);
   4362  1.9  christos         return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   4363  1.9  christos       }
   4364  1.9  christos #  endif
   4365  1.9  christos 
   4366  1.1      tron       *nextPtr = next;
   4367  1.1      tron       return XML_ERROR_NONE;
   4368  1.1      tron     }
   4369  1.7  christos     /* If we get this token, we have the start of what might be a
   4370  1.7  christos        normal tag, but not a declaration (i.e. it doesn't begin with
   4371  1.7  christos        "<!").  In a DTD context, that isn't legal.
   4372  1.7  christos     */
   4373  1.7  christos     else if (tok == XML_TOK_INSTANCE_START) {
   4374  1.7  christos       *nextPtr = next;
   4375  1.7  christos       return XML_ERROR_SYNTAX;
   4376  1.7  christos     }
   4377  1.1      tron     start = next;
   4378  1.8      maya     parser->m_eventPtr = start;
   4379  1.1      tron   }
   4380  1.1      tron }
   4381  1.1      tron 
   4382  1.1      tron static enum XML_Error PTRCALL
   4383  1.8      maya externalParEntProcessor(XML_Parser parser, const char *s, const char *end,
   4384  1.8      maya                         const char **nextPtr) {
   4385  1.1      tron   const char *next = s;
   4386  1.1      tron   int tok;
   4387  1.1      tron 
   4388  1.8      maya   tok = XmlPrologTok(parser->m_encoding, s, end, &next);
   4389  1.1      tron   if (tok <= 0) {
   4390  1.8      maya     if (! parser->m_parsingStatus.finalBuffer && tok != XML_TOK_INVALID) {
   4391  1.1      tron       *nextPtr = s;
   4392  1.1      tron       return XML_ERROR_NONE;
   4393  1.1      tron     }
   4394  1.1      tron     switch (tok) {
   4395  1.1      tron     case XML_TOK_INVALID:
   4396  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   4397  1.1      tron     case XML_TOK_PARTIAL:
   4398  1.1      tron       return XML_ERROR_UNCLOSED_TOKEN;
   4399  1.1      tron     case XML_TOK_PARTIAL_CHAR:
   4400  1.1      tron       return XML_ERROR_PARTIAL_CHAR;
   4401  1.8      maya     case XML_TOK_NONE: /* start == end */
   4402  1.1      tron     default:
   4403  1.1      tron       break;
   4404  1.1      tron     }
   4405  1.1      tron   }
   4406  1.1      tron   /* This would cause the next stage, i.e. doProlog to be passed XML_TOK_BOM.
   4407  1.1      tron      However, when parsing an external subset, doProlog will not accept a BOM
   4408  1.9  christos      as valid, and report a syntax error, so we have to skip the BOM, and
   4409  1.9  christos      account for the BOM bytes.
   4410  1.1      tron   */
   4411  1.1      tron   else if (tok == XML_TOK_BOM) {
   4412  1.9  christos     if (! accountingDiffTolerated(parser, tok, s, next, __LINE__,
   4413  1.9  christos                                   XML_ACCOUNT_DIRECT)) {
   4414  1.9  christos       accountingOnAbort(parser);
   4415  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   4416  1.9  christos     }
   4417  1.9  christos 
   4418  1.1      tron     s = next;
   4419  1.8      maya     tok = XmlPrologTok(parser->m_encoding, s, end, &next);
   4420  1.1      tron   }
   4421  1.1      tron 
   4422  1.8      maya   parser->m_processor = prologProcessor;
   4423  1.8      maya   return doProlog(parser, parser->m_encoding, s, end, tok, next, nextPtr,
   4424  1.9  christos                   (XML_Bool)! parser->m_parsingStatus.finalBuffer, XML_TRUE,
   4425  1.9  christos                   XML_ACCOUNT_DIRECT);
   4426  1.1      tron }
   4427  1.1      tron 
   4428  1.1      tron static enum XML_Error PTRCALL
   4429  1.8      maya entityValueProcessor(XML_Parser parser, const char *s, const char *end,
   4430  1.8      maya                      const char **nextPtr) {
   4431  1.1      tron   const char *start = s;
   4432  1.1      tron   const char *next = s;
   4433  1.8      maya   const ENCODING *enc = parser->m_encoding;
   4434  1.1      tron   int tok;
   4435  1.1      tron 
   4436  1.1      tron   for (;;) {
   4437  1.1      tron     tok = XmlPrologTok(enc, start, end, &next);
   4438  1.9  christos     /* Note: These bytes are accounted later in:
   4439  1.9  christos              - storeEntityValue
   4440  1.9  christos     */
   4441  1.1      tron     if (tok <= 0) {
   4442  1.8      maya       if (! parser->m_parsingStatus.finalBuffer && tok != XML_TOK_INVALID) {
   4443  1.1      tron         *nextPtr = s;
   4444  1.1      tron         return XML_ERROR_NONE;
   4445  1.1      tron       }
   4446  1.1      tron       switch (tok) {
   4447  1.1      tron       case XML_TOK_INVALID:
   4448  1.1      tron         return XML_ERROR_INVALID_TOKEN;
   4449  1.1      tron       case XML_TOK_PARTIAL:
   4450  1.1      tron         return XML_ERROR_UNCLOSED_TOKEN;
   4451  1.1      tron       case XML_TOK_PARTIAL_CHAR:
   4452  1.1      tron         return XML_ERROR_PARTIAL_CHAR;
   4453  1.8      maya       case XML_TOK_NONE: /* start == end */
   4454  1.1      tron       default:
   4455  1.1      tron         break;
   4456  1.1      tron       }
   4457  1.1      tron       /* found end of entity value - can store it now */
   4458  1.9  christos       return storeEntityValue(parser, enc, s, end, XML_ACCOUNT_DIRECT);
   4459  1.1      tron     }
   4460  1.1      tron     start = next;
   4461  1.1      tron   }
   4462  1.1      tron }
   4463  1.1      tron 
   4464  1.1      tron #endif /* XML_DTD */
   4465  1.1      tron 
   4466  1.1      tron static enum XML_Error PTRCALL
   4467  1.8      maya prologProcessor(XML_Parser parser, const char *s, const char *end,
   4468  1.8      maya                 const char **nextPtr) {
   4469  1.1      tron   const char *next = s;
   4470  1.8      maya   int tok = XmlPrologTok(parser->m_encoding, s, end, &next);
   4471  1.8      maya   return doProlog(parser, parser->m_encoding, s, end, tok, next, nextPtr,
   4472  1.9  christos                   (XML_Bool)! parser->m_parsingStatus.finalBuffer, XML_TRUE,
   4473  1.9  christos                   XML_ACCOUNT_DIRECT);
   4474  1.1      tron }
   4475  1.1      tron 
   4476  1.1      tron static enum XML_Error
   4477  1.8      maya doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end,
   4478  1.8      maya          int tok, const char *next, const char **nextPtr, XML_Bool haveMore,
   4479  1.9  christos          XML_Bool allowClosingDoctype, enum XML_Account account) {
   4480  1.1      tron #ifdef XML_DTD
   4481  1.8      maya   static const XML_Char externalSubsetName[] = {ASCII_HASH, '\0'};
   4482  1.1      tron #endif /* XML_DTD */
   4483  1.8      maya   static const XML_Char atypeCDATA[]
   4484  1.8      maya       = {ASCII_C, ASCII_D, ASCII_A, ASCII_T, ASCII_A, '\0'};
   4485  1.8      maya   static const XML_Char atypeID[] = {ASCII_I, ASCII_D, '\0'};
   4486  1.8      maya   static const XML_Char atypeIDREF[]
   4487  1.8      maya       = {ASCII_I, ASCII_D, ASCII_R, ASCII_E, ASCII_F, '\0'};
   4488  1.8      maya   static const XML_Char atypeIDREFS[]
   4489  1.8      maya       = {ASCII_I, ASCII_D, ASCII_R, ASCII_E, ASCII_F, ASCII_S, '\0'};
   4490  1.8      maya   static const XML_Char atypeENTITY[]
   4491  1.8      maya       = {ASCII_E, ASCII_N, ASCII_T, ASCII_I, ASCII_T, ASCII_Y, '\0'};
   4492  1.8      maya   static const XML_Char atypeENTITIES[]
   4493  1.8      maya       = {ASCII_E, ASCII_N, ASCII_T, ASCII_I, ASCII_T,
   4494  1.8      maya          ASCII_I, ASCII_E, ASCII_S, '\0'};
   4495  1.8      maya   static const XML_Char atypeNMTOKEN[]
   4496  1.8      maya       = {ASCII_N, ASCII_M, ASCII_T, ASCII_O, ASCII_K, ASCII_E, ASCII_N, '\0'};
   4497  1.8      maya   static const XML_Char atypeNMTOKENS[]
   4498  1.8      maya       = {ASCII_N, ASCII_M, ASCII_T, ASCII_O, ASCII_K,
   4499  1.8      maya          ASCII_E, ASCII_N, ASCII_S, '\0'};
   4500  1.8      maya   static const XML_Char notationPrefix[]
   4501  1.8      maya       = {ASCII_N, ASCII_O, ASCII_T, ASCII_A,      ASCII_T,
   4502  1.8      maya          ASCII_I, ASCII_O, ASCII_N, ASCII_LPAREN, '\0'};
   4503  1.8      maya   static const XML_Char enumValueSep[] = {ASCII_PIPE, '\0'};
   4504  1.8      maya   static const XML_Char enumValueStart[] = {ASCII_LPAREN, '\0'};
   4505  1.1      tron 
   4506  1.9  christos #ifndef XML_DTD
   4507  1.9  christos   UNUSED_P(account);
   4508  1.9  christos #endif
   4509  1.9  christos 
   4510  1.1      tron   /* save one level of indirection */
   4511  1.8      maya   DTD *const dtd = parser->m_dtd;
   4512  1.1      tron 
   4513  1.1      tron   const char **eventPP;
   4514  1.1      tron   const char **eventEndPP;
   4515  1.1      tron   enum XML_Content_Quant quant;
   4516  1.1      tron 
   4517  1.8      maya   if (enc == parser->m_encoding) {
   4518  1.8      maya     eventPP = &parser->m_eventPtr;
   4519  1.8      maya     eventEndPP = &parser->m_eventEndPtr;
   4520  1.8      maya   } else {
   4521  1.8      maya     eventPP = &(parser->m_openInternalEntities->internalEventPtr);
   4522  1.8      maya     eventEndPP = &(parser->m_openInternalEntities->internalEventEndPtr);
   4523  1.1      tron   }
   4524  1.1      tron 
   4525  1.1      tron   for (;;) {
   4526  1.1      tron     int role;
   4527  1.1      tron     XML_Bool handleDefault = XML_TRUE;
   4528  1.1      tron     *eventPP = s;
   4529  1.1      tron     *eventEndPP = next;
   4530  1.1      tron     if (tok <= 0) {
   4531  1.1      tron       if (haveMore && tok != XML_TOK_INVALID) {
   4532  1.1      tron         *nextPtr = s;
   4533  1.1      tron         return XML_ERROR_NONE;
   4534  1.1      tron       }
   4535  1.1      tron       switch (tok) {
   4536  1.1      tron       case XML_TOK_INVALID:
   4537  1.1      tron         *eventPP = next;
   4538  1.1      tron         return XML_ERROR_INVALID_TOKEN;
   4539  1.1      tron       case XML_TOK_PARTIAL:
   4540  1.1      tron         return XML_ERROR_UNCLOSED_TOKEN;
   4541  1.1      tron       case XML_TOK_PARTIAL_CHAR:
   4542  1.1      tron         return XML_ERROR_PARTIAL_CHAR;
   4543  1.2      tron       case -XML_TOK_PROLOG_S:
   4544  1.3       spz         tok = -tok;
   4545  1.3       spz         break;
   4546  1.1      tron       case XML_TOK_NONE:
   4547  1.1      tron #ifdef XML_DTD
   4548  1.1      tron         /* for internal PE NOT referenced between declarations */
   4549  1.8      maya         if (enc != parser->m_encoding
   4550  1.8      maya             && ! parser->m_openInternalEntities->betweenDecl) {
   4551  1.1      tron           *nextPtr = s;
   4552  1.1      tron           return XML_ERROR_NONE;
   4553  1.1      tron         }
   4554  1.1      tron         /* WFC: PE Between Declarations - must check that PE contains
   4555  1.1      tron            complete markup, not only for external PEs, but also for
   4556  1.1      tron            internal PEs if the reference occurs between declarations.
   4557  1.1      tron         */
   4558  1.8      maya         if (parser->m_isParamEntity || enc != parser->m_encoding) {
   4559  1.8      maya           if (XmlTokenRole(&parser->m_prologState, XML_TOK_NONE, end, end, enc)
   4560  1.1      tron               == XML_ROLE_ERROR)
   4561  1.1      tron             return XML_ERROR_INCOMPLETE_PE;
   4562  1.1      tron           *nextPtr = s;
   4563  1.1      tron           return XML_ERROR_NONE;
   4564  1.1      tron         }
   4565  1.1      tron #endif /* XML_DTD */
   4566  1.1      tron         return XML_ERROR_NO_ELEMENTS;
   4567  1.1      tron       default:
   4568  1.1      tron         tok = -tok;
   4569  1.1      tron         next = end;
   4570  1.1      tron         break;
   4571  1.1      tron       }
   4572  1.1      tron     }
   4573  1.8      maya     role = XmlTokenRole(&parser->m_prologState, tok, s, next, enc);
   4574  1.9  christos #ifdef XML_DTD
   4575  1.9  christos     switch (role) {
   4576  1.9  christos     case XML_ROLE_INSTANCE_START: // bytes accounted in contentProcessor
   4577  1.9  christos     case XML_ROLE_XML_DECL:       // bytes accounted in processXmlDecl
   4578  1.9  christos     case XML_ROLE_TEXT_DECL:      // bytes accounted in processXmlDecl
   4579  1.9  christos       break;
   4580  1.9  christos     default:
   4581  1.9  christos       if (! accountingDiffTolerated(parser, tok, s, next, __LINE__, account)) {
   4582  1.9  christos         accountingOnAbort(parser);
   4583  1.9  christos         return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   4584  1.9  christos       }
   4585  1.9  christos     }
   4586  1.9  christos #endif
   4587  1.1      tron     switch (role) {
   4588  1.8      maya     case XML_ROLE_XML_DECL: {
   4589  1.8      maya       enum XML_Error result = processXmlDecl(parser, 0, s, next);
   4590  1.8      maya       if (result != XML_ERROR_NONE)
   4591  1.8      maya         return result;
   4592  1.8      maya       enc = parser->m_encoding;
   4593  1.8      maya       handleDefault = XML_FALSE;
   4594  1.8      maya     } break;
   4595  1.1      tron     case XML_ROLE_DOCTYPE_NAME:
   4596  1.8      maya       if (parser->m_startDoctypeDeclHandler) {
   4597  1.8      maya         parser->m_doctypeName
   4598  1.8      maya             = poolStoreString(&parser->m_tempPool, enc, s, next);
   4599  1.8      maya         if (! parser->m_doctypeName)
   4600  1.1      tron           return XML_ERROR_NO_MEMORY;
   4601  1.8      maya         poolFinish(&parser->m_tempPool);
   4602  1.8      maya         parser->m_doctypePubid = NULL;
   4603  1.1      tron         handleDefault = XML_FALSE;
   4604  1.1      tron       }
   4605  1.8      maya       parser->m_doctypeSysid = NULL; /* always initialize to NULL */
   4606  1.1      tron       break;
   4607  1.1      tron     case XML_ROLE_DOCTYPE_INTERNAL_SUBSET:
   4608  1.8      maya       if (parser->m_startDoctypeDeclHandler) {
   4609  1.8      maya         parser->m_startDoctypeDeclHandler(
   4610  1.8      maya             parser->m_handlerArg, parser->m_doctypeName, parser->m_doctypeSysid,
   4611  1.8      maya             parser->m_doctypePubid, 1);
   4612  1.8      maya         parser->m_doctypeName = NULL;
   4613  1.8      maya         poolClear(&parser->m_tempPool);
   4614  1.1      tron         handleDefault = XML_FALSE;
   4615  1.1      tron       }
   4616  1.1      tron       break;
   4617  1.1      tron #ifdef XML_DTD
   4618  1.8      maya     case XML_ROLE_TEXT_DECL: {
   4619  1.8      maya       enum XML_Error result = processXmlDecl(parser, 1, s, next);
   4620  1.8      maya       if (result != XML_ERROR_NONE)
   4621  1.8      maya         return result;
   4622  1.8      maya       enc = parser->m_encoding;
   4623  1.8      maya       handleDefault = XML_FALSE;
   4624  1.8      maya     } break;
   4625  1.1      tron #endif /* XML_DTD */
   4626  1.1      tron     case XML_ROLE_DOCTYPE_PUBLIC_ID:
   4627  1.1      tron #ifdef XML_DTD
   4628  1.8      maya       parser->m_useForeignDTD = XML_FALSE;
   4629  1.8      maya       parser->m_declEntity = (ENTITY *)lookup(
   4630  1.8      maya           parser, &dtd->paramEntities, externalSubsetName, sizeof(ENTITY));
   4631  1.8      maya       if (! parser->m_declEntity)
   4632  1.1      tron         return XML_ERROR_NO_MEMORY;
   4633  1.1      tron #endif /* XML_DTD */
   4634  1.1      tron       dtd->hasParamEntityRefs = XML_TRUE;
   4635  1.8      maya       if (parser->m_startDoctypeDeclHandler) {
   4636  1.3       spz         XML_Char *pubId;
   4637  1.8      maya         if (! XmlIsPublicId(enc, s, next, eventPP))
   4638  1.1      tron           return XML_ERROR_PUBLICID;
   4639  1.8      maya         pubId = poolStoreString(&parser->m_tempPool, enc,
   4640  1.3       spz                                 s + enc->minBytesPerChar,
   4641  1.3       spz                                 next - enc->minBytesPerChar);
   4642  1.8      maya         if (! pubId)
   4643  1.1      tron           return XML_ERROR_NO_MEMORY;
   4644  1.3       spz         normalizePublicId(pubId);
   4645  1.8      maya         poolFinish(&parser->m_tempPool);
   4646  1.8      maya         parser->m_doctypePubid = pubId;
   4647  1.1      tron         handleDefault = XML_FALSE;
   4648  1.1      tron         goto alreadyChecked;
   4649  1.1      tron       }
   4650  1.1      tron       /* fall through */
   4651  1.1      tron     case XML_ROLE_ENTITY_PUBLIC_ID:
   4652  1.8      maya       if (! XmlIsPublicId(enc, s, next, eventPP))
   4653  1.1      tron         return XML_ERROR_PUBLICID;
   4654  1.1      tron     alreadyChecked:
   4655  1.8      maya       if (dtd->keepProcessing && parser->m_declEntity) {
   4656  1.8      maya         XML_Char *tem
   4657  1.8      maya             = poolStoreString(&dtd->pool, enc, s + enc->minBytesPerChar,
   4658  1.8      maya                               next - enc->minBytesPerChar);
   4659  1.8      maya         if (! tem)
   4660  1.1      tron           return XML_ERROR_NO_MEMORY;
   4661  1.1      tron         normalizePublicId(tem);
   4662  1.8      maya         parser->m_declEntity->publicId = tem;
   4663  1.1      tron         poolFinish(&dtd->pool);
   4664  1.8      maya         /* Don't suppress the default handler if we fell through from
   4665  1.8      maya          * the XML_ROLE_DOCTYPE_PUBLIC_ID case.
   4666  1.8      maya          */
   4667  1.8      maya         if (parser->m_entityDeclHandler && role == XML_ROLE_ENTITY_PUBLIC_ID)
   4668  1.1      tron           handleDefault = XML_FALSE;
   4669  1.1      tron       }
   4670  1.1      tron       break;
   4671  1.1      tron     case XML_ROLE_DOCTYPE_CLOSE:
   4672  1.8      maya       if (allowClosingDoctype != XML_TRUE) {
   4673  1.8      maya         /* Must not close doctype from within expanded parameter entities */
   4674  1.8      maya         return XML_ERROR_INVALID_TOKEN;
   4675  1.8      maya       }
   4676  1.8      maya 
   4677  1.8      maya       if (parser->m_doctypeName) {
   4678  1.8      maya         parser->m_startDoctypeDeclHandler(
   4679  1.8      maya             parser->m_handlerArg, parser->m_doctypeName, parser->m_doctypeSysid,
   4680  1.8      maya             parser->m_doctypePubid, 0);
   4681  1.8      maya         poolClear(&parser->m_tempPool);
   4682  1.1      tron         handleDefault = XML_FALSE;
   4683  1.1      tron       }
   4684  1.8      maya       /* parser->m_doctypeSysid will be non-NULL in the case of a previous
   4685  1.8      maya          XML_ROLE_DOCTYPE_SYSTEM_ID, even if parser->m_startDoctypeDeclHandler
   4686  1.1      tron          was not set, indicating an external subset
   4687  1.1      tron       */
   4688  1.1      tron #ifdef XML_DTD
   4689  1.8      maya       if (parser->m_doctypeSysid || parser->m_useForeignDTD) {
   4690  1.1      tron         XML_Bool hadParamEntityRefs = dtd->hasParamEntityRefs;
   4691  1.1      tron         dtd->hasParamEntityRefs = XML_TRUE;
   4692  1.8      maya         if (parser->m_paramEntityParsing
   4693  1.8      maya             && parser->m_externalEntityRefHandler) {
   4694  1.8      maya           ENTITY *entity = (ENTITY *)lookup(parser, &dtd->paramEntities,
   4695  1.8      maya                                             externalSubsetName, sizeof(ENTITY));
   4696  1.8      maya           if (! entity) {
   4697  1.8      maya             /* The external subset name "#" will have already been
   4698  1.8      maya              * inserted into the hash table at the start of the
   4699  1.8      maya              * external entity parsing, so no allocation will happen
   4700  1.8      maya              * and lookup() cannot fail.
   4701  1.8      maya              */
   4702  1.8      maya             return XML_ERROR_NO_MEMORY; /* LCOV_EXCL_LINE */
   4703  1.8      maya           }
   4704  1.8      maya           if (parser->m_useForeignDTD)
   4705  1.8      maya             entity->base = parser->m_curBase;
   4706  1.1      tron           dtd->paramEntityRead = XML_FALSE;
   4707  1.8      maya           if (! parser->m_externalEntityRefHandler(
   4708  1.8      maya                   parser->m_externalEntityRefHandlerArg, 0, entity->base,
   4709  1.8      maya                   entity->systemId, entity->publicId))
   4710  1.1      tron             return XML_ERROR_EXTERNAL_ENTITY_HANDLING;
   4711  1.1      tron           if (dtd->paramEntityRead) {
   4712  1.8      maya             if (! dtd->standalone && parser->m_notStandaloneHandler
   4713  1.8      maya                 && ! parser->m_notStandaloneHandler(parser->m_handlerArg))
   4714  1.1      tron               return XML_ERROR_NOT_STANDALONE;
   4715  1.1      tron           }
   4716  1.1      tron           /* if we didn't read the foreign DTD then this means that there
   4717  1.1      tron              is no external subset and we must reset dtd->hasParamEntityRefs
   4718  1.1      tron           */
   4719  1.8      maya           else if (! parser->m_doctypeSysid)
   4720  1.1      tron             dtd->hasParamEntityRefs = hadParamEntityRefs;
   4721  1.1      tron           /* end of DTD - no need to update dtd->keepProcessing */
   4722  1.1      tron         }
   4723  1.8      maya         parser->m_useForeignDTD = XML_FALSE;
   4724  1.1      tron       }
   4725  1.1      tron #endif /* XML_DTD */
   4726  1.8      maya       if (parser->m_endDoctypeDeclHandler) {
   4727  1.8      maya         parser->m_endDoctypeDeclHandler(parser->m_handlerArg);
   4728  1.1      tron         handleDefault = XML_FALSE;
   4729  1.1      tron       }
   4730  1.1      tron       break;
   4731  1.1      tron     case XML_ROLE_INSTANCE_START:
   4732  1.1      tron #ifdef XML_DTD
   4733  1.1      tron       /* if there is no DOCTYPE declaration then now is the
   4734  1.1      tron          last chance to read the foreign DTD
   4735  1.1      tron       */
   4736  1.8      maya       if (parser->m_useForeignDTD) {
   4737  1.1      tron         XML_Bool hadParamEntityRefs = dtd->hasParamEntityRefs;
   4738  1.1      tron         dtd->hasParamEntityRefs = XML_TRUE;
   4739  1.8      maya         if (parser->m_paramEntityParsing
   4740  1.8      maya             && parser->m_externalEntityRefHandler) {
   4741  1.3       spz           ENTITY *entity = (ENTITY *)lookup(parser, &dtd->paramEntities,
   4742  1.8      maya                                             externalSubsetName, sizeof(ENTITY));
   4743  1.8      maya           if (! entity)
   4744  1.1      tron             return XML_ERROR_NO_MEMORY;
   4745  1.8      maya           entity->base = parser->m_curBase;
   4746  1.1      tron           dtd->paramEntityRead = XML_FALSE;
   4747  1.8      maya           if (! parser->m_externalEntityRefHandler(
   4748  1.8      maya                   parser->m_externalEntityRefHandlerArg, 0, entity->base,
   4749  1.8      maya                   entity->systemId, entity->publicId))
   4750  1.1      tron             return XML_ERROR_EXTERNAL_ENTITY_HANDLING;
   4751  1.1      tron           if (dtd->paramEntityRead) {
   4752  1.8      maya             if (! dtd->standalone && parser->m_notStandaloneHandler
   4753  1.8      maya                 && ! parser->m_notStandaloneHandler(parser->m_handlerArg))
   4754  1.1      tron               return XML_ERROR_NOT_STANDALONE;
   4755  1.1      tron           }
   4756  1.1      tron           /* if we didn't read the foreign DTD then this means that there
   4757  1.1      tron              is no external subset and we must reset dtd->hasParamEntityRefs
   4758  1.1      tron           */
   4759  1.1      tron           else
   4760  1.1      tron             dtd->hasParamEntityRefs = hadParamEntityRefs;
   4761  1.1      tron           /* end of DTD - no need to update dtd->keepProcessing */
   4762  1.1      tron         }
   4763  1.1      tron       }
   4764  1.1      tron #endif /* XML_DTD */
   4765  1.8      maya       parser->m_processor = contentProcessor;
   4766  1.1      tron       return contentProcessor(parser, s, end, nextPtr);
   4767  1.1      tron     case XML_ROLE_ATTLIST_ELEMENT_NAME:
   4768  1.8      maya       parser->m_declElementType = getElementType(parser, enc, s, next);
   4769  1.8      maya       if (! parser->m_declElementType)
   4770  1.1      tron         return XML_ERROR_NO_MEMORY;
   4771  1.1      tron       goto checkAttListDeclHandler;
   4772  1.1      tron     case XML_ROLE_ATTRIBUTE_NAME:
   4773  1.8      maya       parser->m_declAttributeId = getAttributeId(parser, enc, s, next);
   4774  1.8      maya       if (! parser->m_declAttributeId)
   4775  1.1      tron         return XML_ERROR_NO_MEMORY;
   4776  1.8      maya       parser->m_declAttributeIsCdata = XML_FALSE;
   4777  1.8      maya       parser->m_declAttributeType = NULL;
   4778  1.8      maya       parser->m_declAttributeIsId = XML_FALSE;
   4779  1.1      tron       goto checkAttListDeclHandler;
   4780  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_CDATA:
   4781  1.8      maya       parser->m_declAttributeIsCdata = XML_TRUE;
   4782  1.8      maya       parser->m_declAttributeType = atypeCDATA;
   4783  1.1      tron       goto checkAttListDeclHandler;
   4784  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_ID:
   4785  1.8      maya       parser->m_declAttributeIsId = XML_TRUE;
   4786  1.8      maya       parser->m_declAttributeType = atypeID;
   4787  1.1      tron       goto checkAttListDeclHandler;
   4788  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_IDREF:
   4789  1.8      maya       parser->m_declAttributeType = atypeIDREF;
   4790  1.1      tron       goto checkAttListDeclHandler;
   4791  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_IDREFS:
   4792  1.8      maya       parser->m_declAttributeType = atypeIDREFS;
   4793  1.1      tron       goto checkAttListDeclHandler;
   4794  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_ENTITY:
   4795  1.8      maya       parser->m_declAttributeType = atypeENTITY;
   4796  1.1      tron       goto checkAttListDeclHandler;
   4797  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_ENTITIES:
   4798  1.8      maya       parser->m_declAttributeType = atypeENTITIES;
   4799  1.1      tron       goto checkAttListDeclHandler;
   4800  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_NMTOKEN:
   4801  1.8      maya       parser->m_declAttributeType = atypeNMTOKEN;
   4802  1.1      tron       goto checkAttListDeclHandler;
   4803  1.1      tron     case XML_ROLE_ATTRIBUTE_TYPE_NMTOKENS:
   4804  1.8      maya       parser->m_declAttributeType = atypeNMTOKENS;
   4805  1.1      tron     checkAttListDeclHandler:
   4806  1.8      maya       if (dtd->keepProcessing && parser->m_attlistDeclHandler)
   4807  1.1      tron         handleDefault = XML_FALSE;
   4808  1.1      tron       break;
   4809  1.1      tron     case XML_ROLE_ATTRIBUTE_ENUM_VALUE:
   4810  1.1      tron     case XML_ROLE_ATTRIBUTE_NOTATION_VALUE:
   4811  1.8      maya       if (dtd->keepProcessing && parser->m_attlistDeclHandler) {
   4812  1.1      tron         const XML_Char *prefix;
   4813  1.8      maya         if (parser->m_declAttributeType) {
   4814  1.1      tron           prefix = enumValueSep;
   4815  1.8      maya         } else {
   4816  1.8      maya           prefix = (role == XML_ROLE_ATTRIBUTE_NOTATION_VALUE ? notationPrefix
   4817  1.8      maya                                                               : enumValueStart);
   4818  1.1      tron         }
   4819  1.8      maya         if (! poolAppendString(&parser->m_tempPool, prefix))
   4820  1.1      tron           return XML_ERROR_NO_MEMORY;
   4821  1.8      maya         if (! poolAppend(&parser->m_tempPool, enc, s, next))
   4822  1.1      tron           return XML_ERROR_NO_MEMORY;
   4823  1.8      maya         parser->m_declAttributeType = parser->m_tempPool.start;
   4824  1.1      tron         handleDefault = XML_FALSE;
   4825  1.1      tron       }
   4826  1.1      tron       break;
   4827  1.1      tron     case XML_ROLE_IMPLIED_ATTRIBUTE_VALUE:
   4828  1.1      tron     case XML_ROLE_REQUIRED_ATTRIBUTE_VALUE:
   4829  1.1      tron       if (dtd->keepProcessing) {
   4830  1.8      maya         if (! defineAttribute(parser->m_declElementType,
   4831  1.8      maya                               parser->m_declAttributeId,
   4832  1.8      maya                               parser->m_declAttributeIsCdata,
   4833  1.8      maya                               parser->m_declAttributeIsId, 0, parser))
   4834  1.1      tron           return XML_ERROR_NO_MEMORY;
   4835  1.8      maya         if (parser->m_attlistDeclHandler && parser->m_declAttributeType) {
   4836  1.8      maya           if (*parser->m_declAttributeType == XML_T(ASCII_LPAREN)
   4837  1.8      maya               || (*parser->m_declAttributeType == XML_T(ASCII_N)
   4838  1.8      maya                   && parser->m_declAttributeType[1] == XML_T(ASCII_O))) {
   4839  1.1      tron             /* Enumerated or Notation type */
   4840  1.8      maya             if (! poolAppendChar(&parser->m_tempPool, XML_T(ASCII_RPAREN))
   4841  1.8      maya                 || ! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   4842  1.1      tron               return XML_ERROR_NO_MEMORY;
   4843  1.8      maya             parser->m_declAttributeType = parser->m_tempPool.start;
   4844  1.8      maya             poolFinish(&parser->m_tempPool);
   4845  1.1      tron           }
   4846  1.1      tron           *eventEndPP = s;
   4847  1.8      maya           parser->m_attlistDeclHandler(
   4848  1.8      maya               parser->m_handlerArg, parser->m_declElementType->name,
   4849  1.8      maya               parser->m_declAttributeId->name, parser->m_declAttributeType, 0,
   4850  1.8      maya               role == XML_ROLE_REQUIRED_ATTRIBUTE_VALUE);
   4851  1.8      maya           poolClear(&parser->m_tempPool);
   4852  1.1      tron           handleDefault = XML_FALSE;
   4853  1.1      tron         }
   4854  1.1      tron       }
   4855  1.1      tron       break;
   4856  1.1      tron     case XML_ROLE_DEFAULT_ATTRIBUTE_VALUE:
   4857  1.1      tron     case XML_ROLE_FIXED_ATTRIBUTE_VALUE:
   4858  1.1      tron       if (dtd->keepProcessing) {
   4859  1.1      tron         const XML_Char *attVal;
   4860  1.8      maya         enum XML_Error result = storeAttributeValue(
   4861  1.8      maya             parser, enc, parser->m_declAttributeIsCdata,
   4862  1.9  christos             s + enc->minBytesPerChar, next - enc->minBytesPerChar, &dtd->pool,
   4863  1.9  christos             XML_ACCOUNT_NONE);
   4864  1.1      tron         if (result)
   4865  1.1      tron           return result;
   4866  1.1      tron         attVal = poolStart(&dtd->pool);
   4867  1.1      tron         poolFinish(&dtd->pool);
   4868  1.1      tron         /* ID attributes aren't allowed to have a default */
   4869  1.8      maya         if (! defineAttribute(
   4870  1.8      maya                 parser->m_declElementType, parser->m_declAttributeId,
   4871  1.8      maya                 parser->m_declAttributeIsCdata, XML_FALSE, attVal, parser))
   4872  1.1      tron           return XML_ERROR_NO_MEMORY;
   4873  1.8      maya         if (parser->m_attlistDeclHandler && parser->m_declAttributeType) {
   4874  1.8      maya           if (*parser->m_declAttributeType == XML_T(ASCII_LPAREN)
   4875  1.8      maya               || (*parser->m_declAttributeType == XML_T(ASCII_N)
   4876  1.8      maya                   && parser->m_declAttributeType[1] == XML_T(ASCII_O))) {
   4877  1.1      tron             /* Enumerated or Notation type */
   4878  1.8      maya             if (! poolAppendChar(&parser->m_tempPool, XML_T(ASCII_RPAREN))
   4879  1.8      maya                 || ! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   4880  1.1      tron               return XML_ERROR_NO_MEMORY;
   4881  1.8      maya             parser->m_declAttributeType = parser->m_tempPool.start;
   4882  1.8      maya             poolFinish(&parser->m_tempPool);
   4883  1.1      tron           }
   4884  1.1      tron           *eventEndPP = s;
   4885  1.8      maya           parser->m_attlistDeclHandler(
   4886  1.8      maya               parser->m_handlerArg, parser->m_declElementType->name,
   4887  1.8      maya               parser->m_declAttributeId->name, parser->m_declAttributeType,
   4888  1.8      maya               attVal, role == XML_ROLE_FIXED_ATTRIBUTE_VALUE);
   4889  1.8      maya           poolClear(&parser->m_tempPool);
   4890  1.1      tron           handleDefault = XML_FALSE;
   4891  1.1      tron         }
   4892  1.1      tron       }
   4893  1.1      tron       break;
   4894  1.1      tron     case XML_ROLE_ENTITY_VALUE:
   4895  1.1      tron       if (dtd->keepProcessing) {
   4896  1.9  christos         enum XML_Error result
   4897  1.9  christos             = storeEntityValue(parser, enc, s + enc->minBytesPerChar,
   4898  1.9  christos                                next - enc->minBytesPerChar, XML_ACCOUNT_NONE);
   4899  1.8      maya         if (parser->m_declEntity) {
   4900  1.8      maya           parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool);
   4901  1.8      maya           parser->m_declEntity->textLen
   4902  1.8      maya               = (int)(poolLength(&dtd->entityValuePool));
   4903  1.1      tron           poolFinish(&dtd->entityValuePool);
   4904  1.8      maya           if (parser->m_entityDeclHandler) {
   4905  1.1      tron             *eventEndPP = s;
   4906  1.8      maya             parser->m_entityDeclHandler(
   4907  1.8      maya                 parser->m_handlerArg, parser->m_declEntity->name,
   4908  1.8      maya                 parser->m_declEntity->is_param, parser->m_declEntity->textPtr,
   4909  1.8      maya                 parser->m_declEntity->textLen, parser->m_curBase, 0, 0, 0);
   4910  1.1      tron             handleDefault = XML_FALSE;
   4911  1.1      tron           }
   4912  1.8      maya         } else
   4913  1.1      tron           poolDiscard(&dtd->entityValuePool);
   4914  1.1      tron         if (result != XML_ERROR_NONE)
   4915  1.1      tron           return result;
   4916  1.1      tron       }
   4917  1.1      tron       break;
   4918  1.1      tron     case XML_ROLE_DOCTYPE_SYSTEM_ID:
   4919  1.1      tron #ifdef XML_DTD
   4920  1.8      maya       parser->m_useForeignDTD = XML_FALSE;
   4921  1.1      tron #endif /* XML_DTD */
   4922  1.1      tron       dtd->hasParamEntityRefs = XML_TRUE;
   4923  1.8      maya       if (parser->m_startDoctypeDeclHandler) {
   4924  1.8      maya         parser->m_doctypeSysid = poolStoreString(&parser->m_tempPool, enc,
   4925  1.8      maya                                                  s + enc->minBytesPerChar,
   4926  1.8      maya                                                  next - enc->minBytesPerChar);
   4927  1.8      maya         if (parser->m_doctypeSysid == NULL)
   4928  1.1      tron           return XML_ERROR_NO_MEMORY;
   4929  1.8      maya         poolFinish(&parser->m_tempPool);
   4930  1.1      tron         handleDefault = XML_FALSE;
   4931  1.1      tron       }
   4932  1.1      tron #ifdef XML_DTD
   4933  1.1      tron       else
   4934  1.8      maya         /* use externalSubsetName to make parser->m_doctypeSysid non-NULL
   4935  1.8      maya            for the case where no parser->m_startDoctypeDeclHandler is set */
   4936  1.8      maya         parser->m_doctypeSysid = externalSubsetName;
   4937  1.1      tron #endif /* XML_DTD */
   4938  1.8      maya       if (! dtd->standalone
   4939  1.1      tron #ifdef XML_DTD
   4940  1.8      maya           && ! parser->m_paramEntityParsing
   4941  1.1      tron #endif /* XML_DTD */
   4942  1.8      maya           && parser->m_notStandaloneHandler
   4943  1.8      maya           && ! parser->m_notStandaloneHandler(parser->m_handlerArg))
   4944  1.1      tron         return XML_ERROR_NOT_STANDALONE;
   4945  1.1      tron #ifndef XML_DTD
   4946  1.1      tron       break;
   4947  1.8      maya #else  /* XML_DTD */
   4948  1.8      maya       if (! parser->m_declEntity) {
   4949  1.8      maya         parser->m_declEntity = (ENTITY *)lookup(
   4950  1.8      maya             parser, &dtd->paramEntities, externalSubsetName, sizeof(ENTITY));
   4951  1.8      maya         if (! parser->m_declEntity)
   4952  1.1      tron           return XML_ERROR_NO_MEMORY;
   4953  1.8      maya         parser->m_declEntity->publicId = NULL;
   4954  1.1      tron       }
   4955  1.8      maya #endif /* XML_DTD */
   4956  1.1      tron       /* fall through */
   4957  1.1      tron     case XML_ROLE_ENTITY_SYSTEM_ID:
   4958  1.8      maya       if (dtd->keepProcessing && parser->m_declEntity) {
   4959  1.8      maya         parser->m_declEntity->systemId
   4960  1.8      maya             = poolStoreString(&dtd->pool, enc, s + enc->minBytesPerChar,
   4961  1.8      maya                               next - enc->minBytesPerChar);
   4962  1.8      maya         if (! parser->m_declEntity->systemId)
   4963  1.1      tron           return XML_ERROR_NO_MEMORY;
   4964  1.8      maya         parser->m_declEntity->base = parser->m_curBase;
   4965  1.1      tron         poolFinish(&dtd->pool);
   4966  1.8      maya         /* Don't suppress the default handler if we fell through from
   4967  1.8      maya          * the XML_ROLE_DOCTYPE_SYSTEM_ID case.
   4968  1.8      maya          */
   4969  1.8      maya         if (parser->m_entityDeclHandler && role == XML_ROLE_ENTITY_SYSTEM_ID)
   4970  1.1      tron           handleDefault = XML_FALSE;
   4971  1.1      tron       }
   4972  1.1      tron       break;
   4973  1.1      tron     case XML_ROLE_ENTITY_COMPLETE:
   4974  1.8      maya       if (dtd->keepProcessing && parser->m_declEntity
   4975  1.8      maya           && parser->m_entityDeclHandler) {
   4976  1.1      tron         *eventEndPP = s;
   4977  1.8      maya         parser->m_entityDeclHandler(
   4978  1.8      maya             parser->m_handlerArg, parser->m_declEntity->name,
   4979  1.8      maya             parser->m_declEntity->is_param, 0, 0, parser->m_declEntity->base,
   4980  1.8      maya             parser->m_declEntity->systemId, parser->m_declEntity->publicId, 0);
   4981  1.1      tron         handleDefault = XML_FALSE;
   4982  1.1      tron       }
   4983  1.1      tron       break;
   4984  1.1      tron     case XML_ROLE_ENTITY_NOTATION_NAME:
   4985  1.8      maya       if (dtd->keepProcessing && parser->m_declEntity) {
   4986  1.8      maya         parser->m_declEntity->notation
   4987  1.8      maya             = poolStoreString(&dtd->pool, enc, s, next);
   4988  1.8      maya         if (! parser->m_declEntity->notation)
   4989  1.1      tron           return XML_ERROR_NO_MEMORY;
   4990  1.1      tron         poolFinish(&dtd->pool);
   4991  1.8      maya         if (parser->m_unparsedEntityDeclHandler) {
   4992  1.1      tron           *eventEndPP = s;
   4993  1.8      maya           parser->m_unparsedEntityDeclHandler(
   4994  1.8      maya               parser->m_handlerArg, parser->m_declEntity->name,
   4995  1.8      maya               parser->m_declEntity->base, parser->m_declEntity->systemId,
   4996  1.8      maya               parser->m_declEntity->publicId, parser->m_declEntity->notation);
   4997  1.1      tron           handleDefault = XML_FALSE;
   4998  1.8      maya         } else if (parser->m_entityDeclHandler) {
   4999  1.1      tron           *eventEndPP = s;
   5000  1.8      maya           parser->m_entityDeclHandler(
   5001  1.8      maya               parser->m_handlerArg, parser->m_declEntity->name, 0, 0, 0,
   5002  1.8      maya               parser->m_declEntity->base, parser->m_declEntity->systemId,
   5003  1.8      maya               parser->m_declEntity->publicId, parser->m_declEntity->notation);
   5004  1.1      tron           handleDefault = XML_FALSE;
   5005  1.1      tron         }
   5006  1.1      tron       }
   5007  1.1      tron       break;
   5008  1.8      maya     case XML_ROLE_GENERAL_ENTITY_NAME: {
   5009  1.8      maya       if (XmlPredefinedEntityName(enc, s, next)) {
   5010  1.8      maya         parser->m_declEntity = NULL;
   5011  1.8      maya         break;
   5012  1.8      maya       }
   5013  1.8      maya       if (dtd->keepProcessing) {
   5014  1.8      maya         const XML_Char *name = poolStoreString(&dtd->pool, enc, s, next);
   5015  1.8      maya         if (! name)
   5016  1.8      maya           return XML_ERROR_NO_MEMORY;
   5017  1.8      maya         parser->m_declEntity = (ENTITY *)lookup(parser, &dtd->generalEntities,
   5018  1.8      maya                                                 name, sizeof(ENTITY));
   5019  1.8      maya         if (! parser->m_declEntity)
   5020  1.8      maya           return XML_ERROR_NO_MEMORY;
   5021  1.8      maya         if (parser->m_declEntity->name != name) {
   5022  1.1      tron           poolDiscard(&dtd->pool);
   5023  1.8      maya           parser->m_declEntity = NULL;
   5024  1.8      maya         } else {
   5025  1.8      maya           poolFinish(&dtd->pool);
   5026  1.8      maya           parser->m_declEntity->publicId = NULL;
   5027  1.8      maya           parser->m_declEntity->is_param = XML_FALSE;
   5028  1.8      maya           /* if we have a parent parser or are reading an internal parameter
   5029  1.8      maya              entity, then the entity declaration is not considered "internal"
   5030  1.8      maya           */
   5031  1.8      maya           parser->m_declEntity->is_internal
   5032  1.8      maya               = ! (parser->m_parentParser || parser->m_openInternalEntities);
   5033  1.8      maya           if (parser->m_entityDeclHandler)
   5034  1.8      maya             handleDefault = XML_FALSE;
   5035  1.1      tron         }
   5036  1.8      maya       } else {
   5037  1.8      maya         poolDiscard(&dtd->pool);
   5038  1.8      maya         parser->m_declEntity = NULL;
   5039  1.1      tron       }
   5040  1.8      maya     } break;
   5041  1.1      tron     case XML_ROLE_PARAM_ENTITY_NAME:
   5042  1.1      tron #ifdef XML_DTD
   5043  1.1      tron       if (dtd->keepProcessing) {
   5044  1.1      tron         const XML_Char *name = poolStoreString(&dtd->pool, enc, s, next);
   5045  1.8      maya         if (! name)
   5046  1.1      tron           return XML_ERROR_NO_MEMORY;
   5047  1.8      maya         parser->m_declEntity = (ENTITY *)lookup(parser, &dtd->paramEntities,
   5048  1.8      maya                                                 name, sizeof(ENTITY));
   5049  1.8      maya         if (! parser->m_declEntity)
   5050  1.1      tron           return XML_ERROR_NO_MEMORY;
   5051  1.8      maya         if (parser->m_declEntity->name != name) {
   5052  1.1      tron           poolDiscard(&dtd->pool);
   5053  1.8      maya           parser->m_declEntity = NULL;
   5054  1.8      maya         } else {
   5055  1.1      tron           poolFinish(&dtd->pool);
   5056  1.8      maya           parser->m_declEntity->publicId = NULL;
   5057  1.8      maya           parser->m_declEntity->is_param = XML_TRUE;
   5058  1.1      tron           /* if we have a parent parser or are reading an internal parameter
   5059  1.1      tron              entity, then the entity declaration is not considered "internal"
   5060  1.1      tron           */
   5061  1.8      maya           parser->m_declEntity->is_internal
   5062  1.8      maya               = ! (parser->m_parentParser || parser->m_openInternalEntities);
   5063  1.8      maya           if (parser->m_entityDeclHandler)
   5064  1.1      tron             handleDefault = XML_FALSE;
   5065  1.1      tron         }
   5066  1.8      maya       } else {
   5067  1.1      tron         poolDiscard(&dtd->pool);
   5068  1.8      maya         parser->m_declEntity = NULL;
   5069  1.1      tron       }
   5070  1.8      maya #else  /* not XML_DTD */
   5071  1.8      maya       parser->m_declEntity = NULL;
   5072  1.1      tron #endif /* XML_DTD */
   5073  1.1      tron       break;
   5074  1.1      tron     case XML_ROLE_NOTATION_NAME:
   5075  1.8      maya       parser->m_declNotationPublicId = NULL;
   5076  1.8      maya       parser->m_declNotationName = NULL;
   5077  1.8      maya       if (parser->m_notationDeclHandler) {
   5078  1.8      maya         parser->m_declNotationName
   5079  1.8      maya             = poolStoreString(&parser->m_tempPool, enc, s, next);
   5080  1.8      maya         if (! parser->m_declNotationName)
   5081  1.1      tron           return XML_ERROR_NO_MEMORY;
   5082  1.8      maya         poolFinish(&parser->m_tempPool);
   5083  1.1      tron         handleDefault = XML_FALSE;
   5084  1.1      tron       }
   5085  1.1      tron       break;
   5086  1.1      tron     case XML_ROLE_NOTATION_PUBLIC_ID:
   5087  1.8      maya       if (! XmlIsPublicId(enc, s, next, eventPP))
   5088  1.1      tron         return XML_ERROR_PUBLICID;
   5089  1.8      maya       if (parser
   5090  1.8      maya               ->m_declNotationName) { /* means m_notationDeclHandler != NULL */
   5091  1.8      maya         XML_Char *tem = poolStoreString(&parser->m_tempPool, enc,
   5092  1.1      tron                                         s + enc->minBytesPerChar,
   5093  1.1      tron                                         next - enc->minBytesPerChar);
   5094  1.8      maya         if (! tem)
   5095  1.1      tron           return XML_ERROR_NO_MEMORY;
   5096  1.1      tron         normalizePublicId(tem);
   5097  1.8      maya         parser->m_declNotationPublicId = tem;
   5098  1.8      maya         poolFinish(&parser->m_tempPool);
   5099  1.1      tron         handleDefault = XML_FALSE;
   5100  1.1      tron       }
   5101  1.1      tron       break;
   5102  1.1      tron     case XML_ROLE_NOTATION_SYSTEM_ID:
   5103  1.8      maya       if (parser->m_declNotationName && parser->m_notationDeclHandler) {
   5104  1.8      maya         const XML_Char *systemId = poolStoreString(&parser->m_tempPool, enc,
   5105  1.8      maya                                                    s + enc->minBytesPerChar,
   5106  1.8      maya                                                    next - enc->minBytesPerChar);
   5107  1.8      maya         if (! systemId)
   5108  1.1      tron           return XML_ERROR_NO_MEMORY;
   5109  1.1      tron         *eventEndPP = s;
   5110  1.8      maya         parser->m_notationDeclHandler(
   5111  1.8      maya             parser->m_handlerArg, parser->m_declNotationName, parser->m_curBase,
   5112  1.8      maya             systemId, parser->m_declNotationPublicId);
   5113  1.1      tron         handleDefault = XML_FALSE;
   5114  1.1      tron       }
   5115  1.8      maya       poolClear(&parser->m_tempPool);
   5116  1.1      tron       break;
   5117  1.1      tron     case XML_ROLE_NOTATION_NO_SYSTEM_ID:
   5118  1.8      maya       if (parser->m_declNotationPublicId && parser->m_notationDeclHandler) {
   5119  1.1      tron         *eventEndPP = s;
   5120  1.8      maya         parser->m_notationDeclHandler(
   5121  1.8      maya             parser->m_handlerArg, parser->m_declNotationName, parser->m_curBase,
   5122  1.8      maya             0, parser->m_declNotationPublicId);
   5123  1.1      tron         handleDefault = XML_FALSE;
   5124  1.1      tron       }
   5125  1.8      maya       poolClear(&parser->m_tempPool);
   5126  1.1      tron       break;
   5127  1.1      tron     case XML_ROLE_ERROR:
   5128  1.1      tron       switch (tok) {
   5129  1.1      tron       case XML_TOK_PARAM_ENTITY_REF:
   5130  1.1      tron         /* PE references in internal subset are
   5131  1.3       spz            not allowed within declarations. */
   5132  1.1      tron         return XML_ERROR_PARAM_ENTITY_REF;
   5133  1.1      tron       case XML_TOK_XML_DECL:
   5134  1.1      tron         return XML_ERROR_MISPLACED_XML_PI;
   5135  1.1      tron       default:
   5136  1.1      tron         return XML_ERROR_SYNTAX;
   5137  1.1      tron       }
   5138  1.1      tron #ifdef XML_DTD
   5139  1.8      maya     case XML_ROLE_IGNORE_SECT: {
   5140  1.8      maya       enum XML_Error result;
   5141  1.8      maya       if (parser->m_defaultHandler)
   5142  1.8      maya         reportDefault(parser, enc, s, next);
   5143  1.8      maya       handleDefault = XML_FALSE;
   5144  1.8      maya       result = doIgnoreSection(parser, enc, &next, end, nextPtr, haveMore);
   5145  1.8      maya       if (result != XML_ERROR_NONE)
   5146  1.8      maya         return result;
   5147  1.8      maya       else if (! next) {
   5148  1.8      maya         parser->m_processor = ignoreSectionProcessor;
   5149  1.8      maya         return result;
   5150  1.1      tron       }
   5151  1.8      maya     } break;
   5152  1.1      tron #endif /* XML_DTD */
   5153  1.1      tron     case XML_ROLE_GROUP_OPEN:
   5154  1.8      maya       if (parser->m_prologState.level >= parser->m_groupSize) {
   5155  1.8      maya         if (parser->m_groupSize) {
   5156  1.8      maya           {
   5157  1.9  christos             /* Detect and prevent integer overflow */
   5158  1.9  christos             if (parser->m_groupSize > (unsigned int)(-1) / 2u) {
   5159  1.9  christos               return XML_ERROR_NO_MEMORY;
   5160  1.9  christos             }
   5161  1.9  christos 
   5162  1.8      maya             char *const new_connector = (char *)REALLOC(
   5163  1.8      maya                 parser, parser->m_groupConnector, parser->m_groupSize *= 2);
   5164  1.8      maya             if (new_connector == NULL) {
   5165  1.8      maya               parser->m_groupSize /= 2;
   5166  1.8      maya               return XML_ERROR_NO_MEMORY;
   5167  1.8      maya             }
   5168  1.8      maya             parser->m_groupConnector = new_connector;
   5169  1.8      maya           }
   5170  1.8      maya 
   5171  1.1      tron           if (dtd->scaffIndex) {
   5172  1.9  christos             /* Detect and prevent integer overflow.
   5173  1.9  christos              * The preprocessor guard addresses the "always false" warning
   5174  1.9  christos              * from -Wtype-limits on platforms where
   5175  1.9  christos              * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   5176  1.9  christos #if UINT_MAX >= SIZE_MAX
   5177  1.9  christos             if (parser->m_groupSize > (size_t)(-1) / sizeof(int)) {
   5178  1.9  christos               return XML_ERROR_NO_MEMORY;
   5179  1.9  christos             }
   5180  1.9  christos #endif
   5181  1.9  christos 
   5182  1.8      maya             int *const new_scaff_index = (int *)REALLOC(
   5183  1.8      maya                 parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int));
   5184  1.8      maya             if (new_scaff_index == NULL)
   5185  1.1      tron               return XML_ERROR_NO_MEMORY;
   5186  1.8      maya             dtd->scaffIndex = new_scaff_index;
   5187  1.1      tron           }
   5188  1.8      maya         } else {
   5189  1.8      maya           parser->m_groupConnector
   5190  1.8      maya               = (char *)MALLOC(parser, parser->m_groupSize = 32);
   5191  1.8      maya           if (! parser->m_groupConnector) {
   5192  1.8      maya             parser->m_groupSize = 0;
   5193  1.1      tron             return XML_ERROR_NO_MEMORY;
   5194  1.8      maya           }
   5195  1.1      tron         }
   5196  1.1      tron       }
   5197  1.8      maya       parser->m_groupConnector[parser->m_prologState.level] = 0;
   5198  1.1      tron       if (dtd->in_eldecl) {
   5199  1.1      tron         int myindex = nextScaffoldPart(parser);
   5200  1.1      tron         if (myindex < 0)
   5201  1.1      tron           return XML_ERROR_NO_MEMORY;
   5202  1.8      maya         assert(dtd->scaffIndex != NULL);
   5203  1.1      tron         dtd->scaffIndex[dtd->scaffLevel] = myindex;
   5204  1.1      tron         dtd->scaffLevel++;
   5205  1.1      tron         dtd->scaffold[myindex].type = XML_CTYPE_SEQ;
   5206  1.8      maya         if (parser->m_elementDeclHandler)
   5207  1.1      tron           handleDefault = XML_FALSE;
   5208  1.1      tron       }
   5209  1.1      tron       break;
   5210  1.1      tron     case XML_ROLE_GROUP_SEQUENCE:
   5211  1.8      maya       if (parser->m_groupConnector[parser->m_prologState.level] == ASCII_PIPE)
   5212  1.1      tron         return XML_ERROR_SYNTAX;
   5213  1.8      maya       parser->m_groupConnector[parser->m_prologState.level] = ASCII_COMMA;
   5214  1.8      maya       if (dtd->in_eldecl && parser->m_elementDeclHandler)
   5215  1.1      tron         handleDefault = XML_FALSE;
   5216  1.1      tron       break;
   5217  1.1      tron     case XML_ROLE_GROUP_CHOICE:
   5218  1.8      maya       if (parser->m_groupConnector[parser->m_prologState.level] == ASCII_COMMA)
   5219  1.1      tron         return XML_ERROR_SYNTAX;
   5220  1.1      tron       if (dtd->in_eldecl
   5221  1.8      maya           && ! parser->m_groupConnector[parser->m_prologState.level]
   5222  1.1      tron           && (dtd->scaffold[dtd->scaffIndex[dtd->scaffLevel - 1]].type
   5223  1.8      maya               != XML_CTYPE_MIXED)) {
   5224  1.1      tron         dtd->scaffold[dtd->scaffIndex[dtd->scaffLevel - 1]].type
   5225  1.1      tron             = XML_CTYPE_CHOICE;
   5226  1.8      maya         if (parser->m_elementDeclHandler)
   5227  1.1      tron           handleDefault = XML_FALSE;
   5228  1.1      tron       }
   5229  1.8      maya       parser->m_groupConnector[parser->m_prologState.level] = ASCII_PIPE;
   5230  1.1      tron       break;
   5231  1.1      tron     case XML_ROLE_PARAM_ENTITY_REF:
   5232  1.1      tron #ifdef XML_DTD
   5233  1.1      tron     case XML_ROLE_INNER_PARAM_ENTITY_REF:
   5234  1.1      tron       dtd->hasParamEntityRefs = XML_TRUE;
   5235  1.8      maya       if (! parser->m_paramEntityParsing)
   5236  1.1      tron         dtd->keepProcessing = dtd->standalone;
   5237  1.1      tron       else {
   5238  1.1      tron         const XML_Char *name;
   5239  1.1      tron         ENTITY *entity;
   5240  1.8      maya         name = poolStoreString(&dtd->pool, enc, s + enc->minBytesPerChar,
   5241  1.8      maya                                next - enc->minBytesPerChar);
   5242  1.8      maya         if (! name)
   5243  1.1      tron           return XML_ERROR_NO_MEMORY;
   5244  1.3       spz         entity = (ENTITY *)lookup(parser, &dtd->paramEntities, name, 0);
   5245  1.1      tron         poolDiscard(&dtd->pool);
   5246  1.1      tron         /* first, determine if a check for an existing declaration is needed;
   5247  1.1      tron            if yes, check that the entity exists, and that it is internal,
   5248  1.1      tron            otherwise call the skipped entity handler
   5249  1.1      tron         */
   5250  1.8      maya         if (parser->m_prologState.documentEntity
   5251  1.8      maya             && (dtd->standalone ? ! parser->m_openInternalEntities
   5252  1.8      maya                                 : ! dtd->hasParamEntityRefs)) {
   5253  1.8      maya           if (! entity)
   5254  1.1      tron             return XML_ERROR_UNDEFINED_ENTITY;
   5255  1.8      maya           else if (! entity->is_internal) {
   5256  1.8      maya             /* It's hard to exhaustively search the code to be sure,
   5257  1.8      maya              * but there doesn't seem to be a way of executing the
   5258  1.8      maya              * following line.  There are two cases:
   5259  1.8      maya              *
   5260  1.8      maya              * If 'standalone' is false, the DTD must have no
   5261  1.8      maya              * parameter entities or we wouldn't have passed the outer
   5262  1.8      maya              * 'if' statement.  That measn the only entity in the hash
   5263  1.8      maya              * table is the external subset name "#" which cannot be
   5264  1.8      maya              * given as a parameter entity name in XML syntax, so the
   5265  1.8      maya              * lookup must have returned NULL and we don't even reach
   5266  1.8      maya              * the test for an internal entity.
   5267  1.8      maya              *
   5268  1.8      maya              * If 'standalone' is true, it does not seem to be
   5269  1.8      maya              * possible to create entities taking this code path that
   5270  1.8      maya              * are not internal entities, so fail the test above.
   5271  1.8      maya              *
   5272  1.8      maya              * Because this analysis is very uncertain, the code is
   5273  1.8      maya              * being left in place and merely removed from the
   5274  1.8      maya              * coverage test statistics.
   5275  1.8      maya              */
   5276  1.8      maya             return XML_ERROR_ENTITY_DECLARED_IN_PE; /* LCOV_EXCL_LINE */
   5277  1.8      maya           }
   5278  1.8      maya         } else if (! entity) {
   5279  1.1      tron           dtd->keepProcessing = dtd->standalone;
   5280  1.1      tron           /* cannot report skipped entities in declarations */
   5281  1.8      maya           if ((role == XML_ROLE_PARAM_ENTITY_REF)
   5282  1.8      maya               && parser->m_skippedEntityHandler) {
   5283  1.8      maya             parser->m_skippedEntityHandler(parser->m_handlerArg, name, 1);
   5284  1.1      tron             handleDefault = XML_FALSE;
   5285  1.1      tron           }
   5286  1.1      tron           break;
   5287  1.1      tron         }
   5288  1.1      tron         if (entity->open)
   5289  1.1      tron           return XML_ERROR_RECURSIVE_ENTITY_REF;
   5290  1.1      tron         if (entity->textPtr) {
   5291  1.1      tron           enum XML_Error result;
   5292  1.8      maya           XML_Bool betweenDecl
   5293  1.8      maya               = (role == XML_ROLE_PARAM_ENTITY_REF ? XML_TRUE : XML_FALSE);
   5294  1.1      tron           result = processInternalEntity(parser, entity, betweenDecl);
   5295  1.1      tron           if (result != XML_ERROR_NONE)
   5296  1.1      tron             return result;
   5297  1.1      tron           handleDefault = XML_FALSE;
   5298  1.1      tron           break;
   5299  1.1      tron         }
   5300  1.8      maya         if (parser->m_externalEntityRefHandler) {
   5301  1.1      tron           dtd->paramEntityRead = XML_FALSE;
   5302  1.1      tron           entity->open = XML_TRUE;
   5303  1.9  christos           entityTrackingOnOpen(parser, entity, __LINE__);
   5304  1.8      maya           if (! parser->m_externalEntityRefHandler(
   5305  1.8      maya                   parser->m_externalEntityRefHandlerArg, 0, entity->base,
   5306  1.8      maya                   entity->systemId, entity->publicId)) {
   5307  1.9  christos             entityTrackingOnClose(parser, entity, __LINE__);
   5308  1.1      tron             entity->open = XML_FALSE;
   5309  1.1      tron             return XML_ERROR_EXTERNAL_ENTITY_HANDLING;
   5310  1.1      tron           }
   5311  1.9  christos           entityTrackingOnClose(parser, entity, __LINE__);
   5312  1.1      tron           entity->open = XML_FALSE;
   5313  1.1      tron           handleDefault = XML_FALSE;
   5314  1.8      maya           if (! dtd->paramEntityRead) {
   5315  1.1      tron             dtd->keepProcessing = dtd->standalone;
   5316  1.1      tron             break;
   5317  1.1      tron           }
   5318  1.8      maya         } else {
   5319  1.1      tron           dtd->keepProcessing = dtd->standalone;
   5320  1.1      tron           break;
   5321  1.1      tron         }
   5322  1.1      tron       }
   5323  1.1      tron #endif /* XML_DTD */
   5324  1.8      maya       if (! dtd->standalone && parser->m_notStandaloneHandler
   5325  1.8      maya           && ! parser->m_notStandaloneHandler(parser->m_handlerArg))
   5326  1.1      tron         return XML_ERROR_NOT_STANDALONE;
   5327  1.1      tron       break;
   5328  1.1      tron 
   5329  1.8      maya       /* Element declaration stuff */
   5330  1.1      tron 
   5331  1.1      tron     case XML_ROLE_ELEMENT_NAME:
   5332  1.8      maya       if (parser->m_elementDeclHandler) {
   5333  1.8      maya         parser->m_declElementType = getElementType(parser, enc, s, next);
   5334  1.8      maya         if (! parser->m_declElementType)
   5335  1.1      tron           return XML_ERROR_NO_MEMORY;
   5336  1.1      tron         dtd->scaffLevel = 0;
   5337  1.1      tron         dtd->scaffCount = 0;
   5338  1.1      tron         dtd->in_eldecl = XML_TRUE;
   5339  1.1      tron         handleDefault = XML_FALSE;
   5340  1.1      tron       }
   5341  1.1      tron       break;
   5342  1.1      tron 
   5343  1.1      tron     case XML_ROLE_CONTENT_ANY:
   5344  1.1      tron     case XML_ROLE_CONTENT_EMPTY:
   5345  1.1      tron       if (dtd->in_eldecl) {
   5346  1.8      maya         if (parser->m_elementDeclHandler) {
   5347  1.8      maya           XML_Content *content
   5348  1.8      maya               = (XML_Content *)MALLOC(parser, sizeof(XML_Content));
   5349  1.8      maya           if (! content)
   5350  1.1      tron             return XML_ERROR_NO_MEMORY;
   5351  1.1      tron           content->quant = XML_CQUANT_NONE;
   5352  1.1      tron           content->name = NULL;
   5353  1.1      tron           content->numchildren = 0;
   5354  1.1      tron           content->children = NULL;
   5355  1.8      maya           content->type = ((role == XML_ROLE_CONTENT_ANY) ? XML_CTYPE_ANY
   5356  1.8      maya                                                           : XML_CTYPE_EMPTY);
   5357  1.1      tron           *eventEndPP = s;
   5358  1.8      maya           parser->m_elementDeclHandler(
   5359  1.8      maya               parser->m_handlerArg, parser->m_declElementType->name, content);
   5360  1.1      tron           handleDefault = XML_FALSE;
   5361  1.1      tron         }
   5362  1.1      tron         dtd->in_eldecl = XML_FALSE;
   5363  1.1      tron       }
   5364  1.1      tron       break;
   5365  1.1      tron 
   5366  1.1      tron     case XML_ROLE_CONTENT_PCDATA:
   5367  1.1      tron       if (dtd->in_eldecl) {
   5368  1.1      tron         dtd->scaffold[dtd->scaffIndex[dtd->scaffLevel - 1]].type
   5369  1.1      tron             = XML_CTYPE_MIXED;
   5370  1.8      maya         if (parser->m_elementDeclHandler)
   5371  1.1      tron           handleDefault = XML_FALSE;
   5372  1.1      tron       }
   5373  1.1      tron       break;
   5374  1.1      tron 
   5375  1.1      tron     case XML_ROLE_CONTENT_ELEMENT:
   5376  1.1      tron       quant = XML_CQUANT_NONE;
   5377  1.1      tron       goto elementContent;
   5378  1.1      tron     case XML_ROLE_CONTENT_ELEMENT_OPT:
   5379  1.1      tron       quant = XML_CQUANT_OPT;
   5380  1.1      tron       goto elementContent;
   5381  1.1      tron     case XML_ROLE_CONTENT_ELEMENT_REP:
   5382  1.1      tron       quant = XML_CQUANT_REP;
   5383  1.1      tron       goto elementContent;
   5384  1.1      tron     case XML_ROLE_CONTENT_ELEMENT_PLUS:
   5385  1.1      tron       quant = XML_CQUANT_PLUS;
   5386  1.1      tron     elementContent:
   5387  1.1      tron       if (dtd->in_eldecl) {
   5388  1.1      tron         ELEMENT_TYPE *el;
   5389  1.1      tron         const XML_Char *name;
   5390  1.9  christos         size_t nameLen;
   5391  1.8      maya         const char *nxt
   5392  1.8      maya             = (quant == XML_CQUANT_NONE ? next : next - enc->minBytesPerChar);
   5393  1.1      tron         int myindex = nextScaffoldPart(parser);
   5394  1.1      tron         if (myindex < 0)
   5395  1.1      tron           return XML_ERROR_NO_MEMORY;
   5396  1.1      tron         dtd->scaffold[myindex].type = XML_CTYPE_NAME;
   5397  1.1      tron         dtd->scaffold[myindex].quant = quant;
   5398  1.1      tron         el = getElementType(parser, enc, s, nxt);
   5399  1.8      maya         if (! el)
   5400  1.1      tron           return XML_ERROR_NO_MEMORY;
   5401  1.1      tron         name = el->name;
   5402  1.1      tron         dtd->scaffold[myindex].name = name;
   5403  1.1      tron         nameLen = 0;
   5404  1.8      maya         for (; name[nameLen++];)
   5405  1.8      maya           ;
   5406  1.9  christos 
   5407  1.9  christos         /* Detect and prevent integer overflow */
   5408  1.9  christos         if (nameLen > UINT_MAX - dtd->contentStringLen) {
   5409  1.9  christos           return XML_ERROR_NO_MEMORY;
   5410  1.9  christos         }
   5411  1.9  christos 
   5412  1.9  christos         dtd->contentStringLen += (unsigned)nameLen;
   5413  1.8      maya         if (parser->m_elementDeclHandler)
   5414  1.1      tron           handleDefault = XML_FALSE;
   5415  1.1      tron       }
   5416  1.1      tron       break;
   5417  1.1      tron 
   5418  1.1      tron     case XML_ROLE_GROUP_CLOSE:
   5419  1.1      tron       quant = XML_CQUANT_NONE;
   5420  1.1      tron       goto closeGroup;
   5421  1.1      tron     case XML_ROLE_GROUP_CLOSE_OPT:
   5422  1.1      tron       quant = XML_CQUANT_OPT;
   5423  1.1      tron       goto closeGroup;
   5424  1.1      tron     case XML_ROLE_GROUP_CLOSE_REP:
   5425  1.1      tron       quant = XML_CQUANT_REP;
   5426  1.1      tron       goto closeGroup;
   5427  1.1      tron     case XML_ROLE_GROUP_CLOSE_PLUS:
   5428  1.1      tron       quant = XML_CQUANT_PLUS;
   5429  1.1      tron     closeGroup:
   5430  1.1      tron       if (dtd->in_eldecl) {
   5431  1.8      maya         if (parser->m_elementDeclHandler)
   5432  1.1      tron           handleDefault = XML_FALSE;
   5433  1.1      tron         dtd->scaffLevel--;
   5434  1.1      tron         dtd->scaffold[dtd->scaffIndex[dtd->scaffLevel]].quant = quant;
   5435  1.1      tron         if (dtd->scaffLevel == 0) {
   5436  1.8      maya           if (! handleDefault) {
   5437  1.1      tron             XML_Content *model = build_model(parser);
   5438  1.8      maya             if (! model)
   5439  1.1      tron               return XML_ERROR_NO_MEMORY;
   5440  1.1      tron             *eventEndPP = s;
   5441  1.8      maya             parser->m_elementDeclHandler(
   5442  1.8      maya                 parser->m_handlerArg, parser->m_declElementType->name, model);
   5443  1.1      tron           }
   5444  1.1      tron           dtd->in_eldecl = XML_FALSE;
   5445  1.1      tron           dtd->contentStringLen = 0;
   5446  1.1      tron         }
   5447  1.1      tron       }
   5448  1.1      tron       break;
   5449  1.1      tron       /* End element declaration stuff */
   5450  1.1      tron 
   5451  1.1      tron     case XML_ROLE_PI:
   5452  1.8      maya       if (! reportProcessingInstruction(parser, enc, s, next))
   5453  1.1      tron         return XML_ERROR_NO_MEMORY;
   5454  1.1      tron       handleDefault = XML_FALSE;
   5455  1.1      tron       break;
   5456  1.1      tron     case XML_ROLE_COMMENT:
   5457  1.8      maya       if (! reportComment(parser, enc, s, next))
   5458  1.1      tron         return XML_ERROR_NO_MEMORY;
   5459  1.1      tron       handleDefault = XML_FALSE;
   5460  1.1      tron       break;
   5461  1.1      tron     case XML_ROLE_NONE:
   5462  1.1      tron       switch (tok) {
   5463  1.1      tron       case XML_TOK_BOM:
   5464  1.1      tron         handleDefault = XML_FALSE;
   5465  1.1      tron         break;
   5466  1.1      tron       }
   5467  1.1      tron       break;
   5468  1.1      tron     case XML_ROLE_DOCTYPE_NONE:
   5469  1.8      maya       if (parser->m_startDoctypeDeclHandler)
   5470  1.1      tron         handleDefault = XML_FALSE;
   5471  1.1      tron       break;
   5472  1.1      tron     case XML_ROLE_ENTITY_NONE:
   5473  1.8      maya       if (dtd->keepProcessing && parser->m_entityDeclHandler)
   5474  1.1      tron         handleDefault = XML_FALSE;
   5475  1.1      tron       break;
   5476  1.1      tron     case XML_ROLE_NOTATION_NONE:
   5477  1.8      maya       if (parser->m_notationDeclHandler)
   5478  1.1      tron         handleDefault = XML_FALSE;
   5479  1.1      tron       break;
   5480  1.1      tron     case XML_ROLE_ATTLIST_NONE:
   5481  1.8      maya       if (dtd->keepProcessing && parser->m_attlistDeclHandler)
   5482  1.1      tron         handleDefault = XML_FALSE;
   5483  1.1      tron       break;
   5484  1.1      tron     case XML_ROLE_ELEMENT_NONE:
   5485  1.8      maya       if (parser->m_elementDeclHandler)
   5486  1.1      tron         handleDefault = XML_FALSE;
   5487  1.1      tron       break;
   5488  1.1      tron     } /* end of big switch */
   5489  1.1      tron 
   5490  1.8      maya     if (handleDefault && parser->m_defaultHandler)
   5491  1.1      tron       reportDefault(parser, enc, s, next);
   5492  1.1      tron 
   5493  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   5494  1.3       spz     case XML_SUSPENDED:
   5495  1.1      tron       *nextPtr = next;
   5496  1.1      tron       return XML_ERROR_NONE;
   5497  1.1      tron     case XML_FINISHED:
   5498  1.1      tron       return XML_ERROR_ABORTED;
   5499  1.1      tron     default:
   5500  1.1      tron       s = next;
   5501  1.1      tron       tok = XmlPrologTok(enc, s, end, &next);
   5502  1.1      tron     }
   5503  1.1      tron   }
   5504  1.1      tron   /* not reached */
   5505  1.1      tron }
   5506  1.1      tron 
   5507  1.1      tron static enum XML_Error PTRCALL
   5508  1.8      maya epilogProcessor(XML_Parser parser, const char *s, const char *end,
   5509  1.8      maya                 const char **nextPtr) {
   5510  1.8      maya   parser->m_processor = epilogProcessor;
   5511  1.8      maya   parser->m_eventPtr = s;
   5512  1.1      tron   for (;;) {
   5513  1.1      tron     const char *next = NULL;
   5514  1.8      maya     int tok = XmlPrologTok(parser->m_encoding, s, end, &next);
   5515  1.9  christos #ifdef XML_DTD
   5516  1.9  christos     if (! accountingDiffTolerated(parser, tok, s, next, __LINE__,
   5517  1.9  christos                                   XML_ACCOUNT_DIRECT)) {
   5518  1.9  christos       accountingOnAbort(parser);
   5519  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   5520  1.9  christos     }
   5521  1.9  christos #endif
   5522  1.8      maya     parser->m_eventEndPtr = next;
   5523  1.1      tron     switch (tok) {
   5524  1.1      tron     /* report partial linebreak - it might be the last token */
   5525  1.1      tron     case -XML_TOK_PROLOG_S:
   5526  1.8      maya       if (parser->m_defaultHandler) {
   5527  1.8      maya         reportDefault(parser, parser->m_encoding, s, next);
   5528  1.8      maya         if (parser->m_parsingStatus.parsing == XML_FINISHED)
   5529  1.1      tron           return XML_ERROR_ABORTED;
   5530  1.1      tron       }
   5531  1.1      tron       *nextPtr = next;
   5532  1.1      tron       return XML_ERROR_NONE;
   5533  1.1      tron     case XML_TOK_NONE:
   5534  1.1      tron       *nextPtr = s;
   5535  1.1      tron       return XML_ERROR_NONE;
   5536  1.1      tron     case XML_TOK_PROLOG_S:
   5537  1.8      maya       if (parser->m_defaultHandler)
   5538  1.8      maya         reportDefault(parser, parser->m_encoding, s, next);
   5539  1.1      tron       break;
   5540  1.1      tron     case XML_TOK_PI:
   5541  1.8      maya       if (! reportProcessingInstruction(parser, parser->m_encoding, s, next))
   5542  1.1      tron         return XML_ERROR_NO_MEMORY;
   5543  1.1      tron       break;
   5544  1.1      tron     case XML_TOK_COMMENT:
   5545  1.8      maya       if (! reportComment(parser, parser->m_encoding, s, next))
   5546  1.1      tron         return XML_ERROR_NO_MEMORY;
   5547  1.1      tron       break;
   5548  1.1      tron     case XML_TOK_INVALID:
   5549  1.8      maya       parser->m_eventPtr = next;
   5550  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   5551  1.1      tron     case XML_TOK_PARTIAL:
   5552  1.8      maya       if (! parser->m_parsingStatus.finalBuffer) {
   5553  1.1      tron         *nextPtr = s;
   5554  1.1      tron         return XML_ERROR_NONE;
   5555  1.1      tron       }
   5556  1.1      tron       return XML_ERROR_UNCLOSED_TOKEN;
   5557  1.1      tron     case XML_TOK_PARTIAL_CHAR:
   5558  1.8      maya       if (! parser->m_parsingStatus.finalBuffer) {
   5559  1.1      tron         *nextPtr = s;
   5560  1.1      tron         return XML_ERROR_NONE;
   5561  1.1      tron       }
   5562  1.1      tron       return XML_ERROR_PARTIAL_CHAR;
   5563  1.1      tron     default:
   5564  1.1      tron       return XML_ERROR_JUNK_AFTER_DOC_ELEMENT;
   5565  1.1      tron     }
   5566  1.8      maya     parser->m_eventPtr = s = next;
   5567  1.8      maya     switch (parser->m_parsingStatus.parsing) {
   5568  1.3       spz     case XML_SUSPENDED:
   5569  1.1      tron       *nextPtr = next;
   5570  1.1      tron       return XML_ERROR_NONE;
   5571  1.1      tron     case XML_FINISHED:
   5572  1.1      tron       return XML_ERROR_ABORTED;
   5573  1.8      maya     default:;
   5574  1.1      tron     }
   5575  1.1      tron   }
   5576  1.1      tron }
   5577  1.1      tron 
   5578  1.1      tron static enum XML_Error
   5579  1.8      maya processInternalEntity(XML_Parser parser, ENTITY *entity, XML_Bool betweenDecl) {
   5580  1.1      tron   const char *textStart, *textEnd;
   5581  1.1      tron   const char *next;
   5582  1.1      tron   enum XML_Error result;
   5583  1.1      tron   OPEN_INTERNAL_ENTITY *openEntity;
   5584  1.1      tron 
   5585  1.8      maya   if (parser->m_freeInternalEntities) {
   5586  1.8      maya     openEntity = parser->m_freeInternalEntities;
   5587  1.8      maya     parser->m_freeInternalEntities = openEntity->next;
   5588  1.8      maya   } else {
   5589  1.8      maya     openEntity
   5590  1.8      maya         = (OPEN_INTERNAL_ENTITY *)MALLOC(parser, sizeof(OPEN_INTERNAL_ENTITY));
   5591  1.8      maya     if (! openEntity)
   5592  1.1      tron       return XML_ERROR_NO_MEMORY;
   5593  1.1      tron   }
   5594  1.1      tron   entity->open = XML_TRUE;
   5595  1.9  christos #ifdef XML_DTD
   5596  1.9  christos   entityTrackingOnOpen(parser, entity, __LINE__);
   5597  1.9  christos #endif
   5598  1.1      tron   entity->processed = 0;
   5599  1.8      maya   openEntity->next = parser->m_openInternalEntities;
   5600  1.8      maya   parser->m_openInternalEntities = openEntity;
   5601  1.1      tron   openEntity->entity = entity;
   5602  1.8      maya   openEntity->startTagLevel = parser->m_tagLevel;
   5603  1.1      tron   openEntity->betweenDecl = betweenDecl;
   5604  1.1      tron   openEntity->internalEventPtr = NULL;
   5605  1.1      tron   openEntity->internalEventEndPtr = NULL;
   5606  1.9  christos   textStart = (const char *)entity->textPtr;
   5607  1.9  christos   textEnd = (const char *)(entity->textPtr + entity->textLen);
   5608  1.7  christos   /* Set a safe default value in case 'next' does not get set */
   5609  1.7  christos   next = textStart;
   5610  1.1      tron 
   5611  1.1      tron #ifdef XML_DTD
   5612  1.1      tron   if (entity->is_param) {
   5613  1.8      maya     int tok
   5614  1.8      maya         = XmlPrologTok(parser->m_internalEncoding, textStart, textEnd, &next);
   5615  1.8      maya     result = doProlog(parser, parser->m_internalEncoding, textStart, textEnd,
   5616  1.9  christos                       tok, next, &next, XML_FALSE, XML_FALSE,
   5617  1.9  christos                       XML_ACCOUNT_ENTITY_EXPANSION);
   5618  1.8      maya   } else
   5619  1.1      tron #endif /* XML_DTD */
   5620  1.8      maya     result = doContent(parser, parser->m_tagLevel, parser->m_internalEncoding,
   5621  1.9  christos                        textStart, textEnd, &next, XML_FALSE,
   5622  1.9  christos                        XML_ACCOUNT_ENTITY_EXPANSION);
   5623  1.1      tron 
   5624  1.1      tron   if (result == XML_ERROR_NONE) {
   5625  1.8      maya     if (textEnd != next && parser->m_parsingStatus.parsing == XML_SUSPENDED) {
   5626  1.1      tron       entity->processed = (int)(next - textStart);
   5627  1.8      maya       parser->m_processor = internalEntityProcessor;
   5628  1.8      maya     } else {
   5629  1.9  christos #ifdef XML_DTD
   5630  1.9  christos       entityTrackingOnClose(parser, entity, __LINE__);
   5631  1.9  christos #endif /* XML_DTD */
   5632  1.1      tron       entity->open = XML_FALSE;
   5633  1.8      maya       parser->m_openInternalEntities = openEntity->next;
   5634  1.1      tron       /* put openEntity back in list of free instances */
   5635  1.8      maya       openEntity->next = parser->m_freeInternalEntities;
   5636  1.8      maya       parser->m_freeInternalEntities = openEntity;
   5637  1.1      tron     }
   5638  1.1      tron   }
   5639  1.1      tron   return result;
   5640  1.1      tron }
   5641  1.1      tron 
   5642  1.1      tron static enum XML_Error PTRCALL
   5643  1.8      maya internalEntityProcessor(XML_Parser parser, const char *s, const char *end,
   5644  1.8      maya                         const char **nextPtr) {
   5645  1.1      tron   ENTITY *entity;
   5646  1.1      tron   const char *textStart, *textEnd;
   5647  1.1      tron   const char *next;
   5648  1.1      tron   enum XML_Error result;
   5649  1.8      maya   OPEN_INTERNAL_ENTITY *openEntity = parser->m_openInternalEntities;
   5650  1.8      maya   if (! openEntity)
   5651  1.1      tron     return XML_ERROR_UNEXPECTED_STATE;
   5652  1.1      tron 
   5653  1.1      tron   entity = openEntity->entity;
   5654  1.9  christos   textStart = ((const char *)entity->textPtr) + entity->processed;
   5655  1.9  christos   textEnd = (const char *)(entity->textPtr + entity->textLen);
   5656  1.7  christos   /* Set a safe default value in case 'next' does not get set */
   5657  1.7  christos   next = textStart;
   5658  1.1      tron 
   5659  1.1      tron #ifdef XML_DTD
   5660  1.1      tron   if (entity->is_param) {
   5661  1.8      maya     int tok
   5662  1.8      maya         = XmlPrologTok(parser->m_internalEncoding, textStart, textEnd, &next);
   5663  1.8      maya     result = doProlog(parser, parser->m_internalEncoding, textStart, textEnd,
   5664  1.9  christos                       tok, next, &next, XML_FALSE, XML_TRUE,
   5665  1.9  christos                       XML_ACCOUNT_ENTITY_EXPANSION);
   5666  1.8      maya   } else
   5667  1.1      tron #endif /* XML_DTD */
   5668  1.8      maya     result = doContent(parser, openEntity->startTagLevel,
   5669  1.8      maya                        parser->m_internalEncoding, textStart, textEnd, &next,
   5670  1.9  christos                        XML_FALSE, XML_ACCOUNT_ENTITY_EXPANSION);
   5671  1.1      tron 
   5672  1.1      tron   if (result != XML_ERROR_NONE)
   5673  1.1      tron     return result;
   5674  1.8      maya   else if (textEnd != next
   5675  1.8      maya            && parser->m_parsingStatus.parsing == XML_SUSPENDED) {
   5676  1.9  christos     entity->processed = (int)(next - (const char *)entity->textPtr);
   5677  1.1      tron     return result;
   5678  1.8      maya   } else {
   5679  1.9  christos #ifdef XML_DTD
   5680  1.9  christos     entityTrackingOnClose(parser, entity, __LINE__);
   5681  1.9  christos #endif
   5682  1.1      tron     entity->open = XML_FALSE;
   5683  1.8      maya     parser->m_openInternalEntities = openEntity->next;
   5684  1.1      tron     /* put openEntity back in list of free instances */
   5685  1.8      maya     openEntity->next = parser->m_freeInternalEntities;
   5686  1.8      maya     parser->m_freeInternalEntities = openEntity;
   5687  1.1      tron   }
   5688  1.1      tron 
   5689  1.1      tron #ifdef XML_DTD
   5690  1.1      tron   if (entity->is_param) {
   5691  1.1      tron     int tok;
   5692  1.8      maya     parser->m_processor = prologProcessor;
   5693  1.8      maya     tok = XmlPrologTok(parser->m_encoding, s, end, &next);
   5694  1.8      maya     return doProlog(parser, parser->m_encoding, s, end, tok, next, nextPtr,
   5695  1.9  christos                     (XML_Bool)! parser->m_parsingStatus.finalBuffer, XML_TRUE,
   5696  1.9  christos                     XML_ACCOUNT_DIRECT);
   5697  1.8      maya   } else
   5698  1.1      tron #endif /* XML_DTD */
   5699  1.1      tron   {
   5700  1.8      maya     parser->m_processor = contentProcessor;
   5701  1.1      tron     /* see externalEntityContentProcessor vs contentProcessor */
   5702  1.8      maya     return doContent(parser, parser->m_parentParser ? 1 : 0, parser->m_encoding,
   5703  1.8      maya                      s, end, nextPtr,
   5704  1.9  christos                      (XML_Bool)! parser->m_parsingStatus.finalBuffer,
   5705  1.9  christos                      XML_ACCOUNT_DIRECT);
   5706  1.3       spz   }
   5707  1.1      tron }
   5708  1.1      tron 
   5709  1.1      tron static enum XML_Error PTRCALL
   5710  1.8      maya errorProcessor(XML_Parser parser, const char *s, const char *end,
   5711  1.8      maya                const char **nextPtr) {
   5712  1.8      maya   UNUSED_P(s);
   5713  1.8      maya   UNUSED_P(end);
   5714  1.8      maya   UNUSED_P(nextPtr);
   5715  1.8      maya   return parser->m_errorCode;
   5716  1.1      tron }
   5717  1.1      tron 
   5718  1.1      tron static enum XML_Error
   5719  1.1      tron storeAttributeValue(XML_Parser parser, const ENCODING *enc, XML_Bool isCdata,
   5720  1.9  christos                     const char *ptr, const char *end, STRING_POOL *pool,
   5721  1.9  christos                     enum XML_Account account) {
   5722  1.8      maya   enum XML_Error result
   5723  1.9  christos       = appendAttributeValue(parser, enc, isCdata, ptr, end, pool, account);
   5724  1.1      tron   if (result)
   5725  1.1      tron     return result;
   5726  1.8      maya   if (! isCdata && poolLength(pool) && poolLastChar(pool) == 0x20)
   5727  1.1      tron     poolChop(pool);
   5728  1.8      maya   if (! poolAppendChar(pool, XML_T('\0')))
   5729  1.1      tron     return XML_ERROR_NO_MEMORY;
   5730  1.1      tron   return XML_ERROR_NONE;
   5731  1.1      tron }
   5732  1.1      tron 
   5733  1.1      tron static enum XML_Error
   5734  1.1      tron appendAttributeValue(XML_Parser parser, const ENCODING *enc, XML_Bool isCdata,
   5735  1.9  christos                      const char *ptr, const char *end, STRING_POOL *pool,
   5736  1.9  christos                      enum XML_Account account) {
   5737  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   5738  1.9  christos #ifndef XML_DTD
   5739  1.9  christos   UNUSED_P(account);
   5740  1.9  christos #endif
   5741  1.9  christos 
   5742  1.1      tron   for (;;) {
   5743  1.9  christos     const char *next
   5744  1.9  christos         = ptr; /* XmlAttributeValueTok doesn't always set the last arg */
   5745  1.1      tron     int tok = XmlAttributeValueTok(enc, ptr, end, &next);
   5746  1.9  christos #ifdef XML_DTD
   5747  1.9  christos     if (! accountingDiffTolerated(parser, tok, ptr, next, __LINE__, account)) {
   5748  1.9  christos       accountingOnAbort(parser);
   5749  1.9  christos       return XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   5750  1.9  christos     }
   5751  1.9  christos #endif
   5752  1.1      tron     switch (tok) {
   5753  1.1      tron     case XML_TOK_NONE:
   5754  1.1      tron       return XML_ERROR_NONE;
   5755  1.1      tron     case XML_TOK_INVALID:
   5756  1.8      maya       if (enc == parser->m_encoding)
   5757  1.8      maya         parser->m_eventPtr = next;
   5758  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   5759  1.1      tron     case XML_TOK_PARTIAL:
   5760  1.8      maya       if (enc == parser->m_encoding)
   5761  1.8      maya         parser->m_eventPtr = ptr;
   5762  1.1      tron       return XML_ERROR_INVALID_TOKEN;
   5763  1.8      maya     case XML_TOK_CHAR_REF: {
   5764  1.8      maya       XML_Char buf[XML_ENCODE_MAX];
   5765  1.8      maya       int i;
   5766  1.8      maya       int n = XmlCharRefNumber(enc, ptr);
   5767  1.8      maya       if (n < 0) {
   5768  1.8      maya         if (enc == parser->m_encoding)
   5769  1.8      maya           parser->m_eventPtr = ptr;
   5770  1.8      maya         return XML_ERROR_BAD_CHAR_REF;
   5771  1.8      maya       }
   5772  1.8      maya       if (! isCdata && n == 0x20 /* space */
   5773  1.8      maya           && (poolLength(pool) == 0 || poolLastChar(pool) == 0x20))
   5774  1.8      maya         break;
   5775  1.8      maya       n = XmlEncode(n, (ICHAR *)buf);
   5776  1.8      maya       /* The XmlEncode() functions can never return 0 here.  That
   5777  1.8      maya        * error return happens if the code point passed in is either
   5778  1.8      maya        * negative or greater than or equal to 0x110000.  The
   5779  1.8      maya        * XmlCharRefNumber() functions will all return a number
   5780  1.8      maya        * strictly less than 0x110000 or a negative value if an error
   5781  1.8      maya        * occurred.  The negative value is intercepted above, so
   5782  1.8      maya        * XmlEncode() is never passed a value it might return an
   5783  1.8      maya        * error for.
   5784  1.8      maya        */
   5785  1.8      maya       for (i = 0; i < n; i++) {
   5786  1.8      maya         if (! poolAppendChar(pool, buf[i]))
   5787  1.8      maya           return XML_ERROR_NO_MEMORY;
   5788  1.1      tron       }
   5789  1.8      maya     } break;
   5790  1.1      tron     case XML_TOK_DATA_CHARS:
   5791  1.8      maya       if (! poolAppend(pool, enc, ptr, next))
   5792  1.1      tron         return XML_ERROR_NO_MEMORY;
   5793  1.1      tron       break;
   5794  1.1      tron     case XML_TOK_TRAILING_CR:
   5795  1.1      tron       next = ptr + enc->minBytesPerChar;
   5796  1.1      tron       /* fall through */
   5797  1.1      tron     case XML_TOK_ATTRIBUTE_VALUE_S:
   5798  1.1      tron     case XML_TOK_DATA_NEWLINE:
   5799  1.8      maya       if (! isCdata && (poolLength(pool) == 0 || poolLastChar(pool) == 0x20))
   5800  1.1      tron         break;
   5801  1.8      maya       if (! poolAppendChar(pool, 0x20))
   5802  1.1      tron         return XML_ERROR_NO_MEMORY;
   5803  1.1      tron       break;
   5804  1.8      maya     case XML_TOK_ENTITY_REF: {
   5805  1.8      maya       const XML_Char *name;
   5806  1.8      maya       ENTITY *entity;
   5807  1.8      maya       char checkEntityDecl;
   5808  1.8      maya       XML_Char ch = (XML_Char)XmlPredefinedEntityName(
   5809  1.8      maya           enc, ptr + enc->minBytesPerChar, next - enc->minBytesPerChar);
   5810  1.8      maya       if (ch) {
   5811  1.9  christos #ifdef XML_DTD
   5812  1.9  christos         /* NOTE: We are replacing 4-6 characters original input for 1 character
   5813  1.9  christos          *       so there is no amplification and hence recording without
   5814  1.9  christos          *       protection. */
   5815  1.9  christos         accountingDiffTolerated(parser, tok, (char *)&ch,
   5816  1.9  christos                                 ((char *)&ch) + sizeof(XML_Char), __LINE__,
   5817  1.9  christos                                 XML_ACCOUNT_ENTITY_EXPANSION);
   5818  1.9  christos #endif /* XML_DTD */
   5819  1.8      maya         if (! poolAppendChar(pool, ch))
   5820  1.1      tron           return XML_ERROR_NO_MEMORY;
   5821  1.8      maya         break;
   5822  1.8      maya       }
   5823  1.8      maya       name = poolStoreString(&parser->m_temp2Pool, enc,
   5824  1.8      maya                              ptr + enc->minBytesPerChar,
   5825  1.8      maya                              next - enc->minBytesPerChar);
   5826  1.8      maya       if (! name)
   5827  1.8      maya         return XML_ERROR_NO_MEMORY;
   5828  1.8      maya       entity = (ENTITY *)lookup(parser, &dtd->generalEntities, name, 0);
   5829  1.8      maya       poolDiscard(&parser->m_temp2Pool);
   5830  1.8      maya       /* First, determine if a check for an existing declaration is needed;
   5831  1.8      maya          if yes, check that the entity exists, and that it is internal.
   5832  1.8      maya       */
   5833  1.8      maya       if (pool == &dtd->pool) /* are we called from prolog? */
   5834  1.8      maya         checkEntityDecl =
   5835  1.1      tron #ifdef XML_DTD
   5836  1.8      maya             parser->m_prologState.documentEntity &&
   5837  1.1      tron #endif /* XML_DTD */
   5838  1.8      maya             (dtd->standalone ? ! parser->m_openInternalEntities
   5839  1.8      maya                              : ! dtd->hasParamEntityRefs);
   5840  1.8      maya       else /* if (pool == &parser->m_tempPool): we are called from content */
   5841  1.8      maya         checkEntityDecl = ! dtd->hasParamEntityRefs || dtd->standalone;
   5842  1.8      maya       if (checkEntityDecl) {
   5843  1.8      maya         if (! entity)
   5844  1.8      maya           return XML_ERROR_UNDEFINED_ENTITY;
   5845  1.8      maya         else if (! entity->is_internal)
   5846  1.8      maya           return XML_ERROR_ENTITY_DECLARED_IN_PE;
   5847  1.8      maya       } else if (! entity) {
   5848  1.8      maya         /* Cannot report skipped entity here - see comments on
   5849  1.8      maya            parser->m_skippedEntityHandler.
   5850  1.8      maya         if (parser->m_skippedEntityHandler)
   5851  1.8      maya           parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0);
   5852  1.8      maya         */
   5853  1.8      maya         /* Cannot call the default handler because this would be
   5854  1.8      maya            out of sync with the call to the startElementHandler.
   5855  1.8      maya         if ((pool == &parser->m_tempPool) && parser->m_defaultHandler)
   5856  1.8      maya           reportDefault(parser, enc, ptr, next);
   5857  1.8      maya         */
   5858  1.8      maya         break;
   5859  1.8      maya       }
   5860  1.8      maya       if (entity->open) {
   5861  1.8      maya         if (enc == parser->m_encoding) {
   5862  1.8      maya           /* It does not appear that this line can be executed.
   5863  1.8      maya            *
   5864  1.8      maya            * The "if (entity->open)" check catches recursive entity
   5865  1.8      maya            * definitions.  In order to be called with an open
   5866  1.8      maya            * entity, it must have gone through this code before and
   5867  1.8      maya            * been through the recursive call to
   5868  1.8      maya            * appendAttributeValue() some lines below.  That call
   5869  1.8      maya            * sets the local encoding ("enc") to the parser's
   5870  1.8      maya            * internal encoding (internal_utf8 or internal_utf16),
   5871  1.8      maya            * which can never be the same as the principle encoding.
   5872  1.8      maya            * It doesn't appear there is another code path that gets
   5873  1.8      maya            * here with entity->open being TRUE.
   5874  1.8      maya            *
   5875  1.8      maya            * Since it is not certain that this logic is watertight,
   5876  1.8      maya            * we keep the line and merely exclude it from coverage
   5877  1.8      maya            * tests.
   5878  1.8      maya            */
   5879  1.8      maya           parser->m_eventPtr = ptr; /* LCOV_EXCL_LINE */
   5880  1.8      maya         }
   5881  1.8      maya         return XML_ERROR_RECURSIVE_ENTITY_REF;
   5882  1.8      maya       }
   5883  1.8      maya       if (entity->notation) {
   5884  1.8      maya         if (enc == parser->m_encoding)
   5885  1.8      maya           parser->m_eventPtr = ptr;
   5886  1.8      maya         return XML_ERROR_BINARY_ENTITY_REF;
   5887  1.8      maya       }
   5888  1.8      maya       if (! entity->textPtr) {
   5889  1.8      maya         if (enc == parser->m_encoding)
   5890  1.8      maya           parser->m_eventPtr = ptr;
   5891  1.8      maya         return XML_ERROR_ATTRIBUTE_EXTERNAL_ENTITY_REF;
   5892  1.8      maya       } else {
   5893  1.8      maya         enum XML_Error result;
   5894  1.8      maya         const XML_Char *textEnd = entity->textPtr + entity->textLen;
   5895  1.8      maya         entity->open = XML_TRUE;
   5896  1.9  christos #ifdef XML_DTD
   5897  1.9  christos         entityTrackingOnOpen(parser, entity, __LINE__);
   5898  1.9  christos #endif
   5899  1.8      maya         result = appendAttributeValue(parser, parser->m_internalEncoding,
   5900  1.9  christos                                       isCdata, (const char *)entity->textPtr,
   5901  1.9  christos                                       (const char *)textEnd, pool,
   5902  1.9  christos                                       XML_ACCOUNT_ENTITY_EXPANSION);
   5903  1.9  christos #ifdef XML_DTD
   5904  1.9  christos         entityTrackingOnClose(parser, entity, __LINE__);
   5905  1.9  christos #endif
   5906  1.8      maya         entity->open = XML_FALSE;
   5907  1.8      maya         if (result)
   5908  1.8      maya           return result;
   5909  1.1      tron       }
   5910  1.8      maya     } break;
   5911  1.1      tron     default:
   5912  1.8      maya       /* The only token returned by XmlAttributeValueTok() that does
   5913  1.8      maya        * not have an explicit case here is XML_TOK_PARTIAL_CHAR.
   5914  1.8      maya        * Getting that would require an entity name to contain an
   5915  1.8      maya        * incomplete XML character (e.g. \xE2\x82); however previous
   5916  1.8      maya        * tokenisers will have already recognised and rejected such
   5917  1.8      maya        * names before XmlAttributeValueTok() gets a look-in.  This
   5918  1.8      maya        * default case should be retained as a safety net, but the code
   5919  1.8      maya        * excluded from coverage tests.
   5920  1.8      maya        *
   5921  1.8      maya        * LCOV_EXCL_START
   5922  1.8      maya        */
   5923  1.8      maya       if (enc == parser->m_encoding)
   5924  1.8      maya         parser->m_eventPtr = ptr;
   5925  1.1      tron       return XML_ERROR_UNEXPECTED_STATE;
   5926  1.8      maya       /* LCOV_EXCL_STOP */
   5927  1.1      tron     }
   5928  1.1      tron     ptr = next;
   5929  1.1      tron   }
   5930  1.1      tron   /* not reached */
   5931  1.1      tron }
   5932  1.1      tron 
   5933  1.1      tron static enum XML_Error
   5934  1.8      maya storeEntityValue(XML_Parser parser, const ENCODING *enc,
   5935  1.9  christos                  const char *entityTextPtr, const char *entityTextEnd,
   5936  1.9  christos                  enum XML_Account account) {
   5937  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   5938  1.1      tron   STRING_POOL *pool = &(dtd->entityValuePool);
   5939  1.1      tron   enum XML_Error result = XML_ERROR_NONE;
   5940  1.1      tron #ifdef XML_DTD
   5941  1.8      maya   int oldInEntityValue = parser->m_prologState.inEntityValue;
   5942  1.8      maya   parser->m_prologState.inEntityValue = 1;
   5943  1.9  christos #else
   5944  1.9  christos   UNUSED_P(account);
   5945  1.1      tron #endif /* XML_DTD */
   5946  1.1      tron   /* never return Null for the value argument in EntityDeclHandler,
   5947  1.1      tron      since this would indicate an external entity; therefore we
   5948  1.1      tron      have to make sure that entityValuePool.start is not null */
   5949  1.8      maya   if (! pool->blocks) {
   5950  1.8      maya     if (! poolGrow(pool))
   5951  1.1      tron       return XML_ERROR_NO_MEMORY;
   5952  1.1      tron   }
   5953  1.1      tron 
   5954  1.1      tron   for (;;) {
   5955  1.9  christos     const char *next
   5956  1.9  christos         = entityTextPtr; /* XmlEntityValueTok doesn't always set the last arg */
   5957  1.1      tron     int tok = XmlEntityValueTok(enc, entityTextPtr, entityTextEnd, &next);
   5958  1.9  christos 
   5959  1.9  christos #ifdef XML_DTD
   5960  1.9  christos     if (! accountingDiffTolerated(parser, tok, entityTextPtr, next, __LINE__,
   5961  1.9  christos                                   account)) {
   5962  1.9  christos       accountingOnAbort(parser);
   5963  1.9  christos       result = XML_ERROR_AMPLIFICATION_LIMIT_BREACH;
   5964  1.9  christos       goto endEntityValue;
   5965  1.9  christos     }
   5966  1.9  christos #endif
   5967  1.9  christos 
   5968  1.1      tron     switch (tok) {
   5969  1.1      tron     case XML_TOK_PARAM_ENTITY_REF:
   5970  1.1      tron #ifdef XML_DTD
   5971  1.8      maya       if (parser->m_isParamEntity || enc != parser->m_encoding) {
   5972  1.1      tron         const XML_Char *name;
   5973  1.1      tron         ENTITY *entity;
   5974  1.8      maya         name = poolStoreString(&parser->m_tempPool, enc,
   5975  1.1      tron                                entityTextPtr + enc->minBytesPerChar,
   5976  1.1      tron                                next - enc->minBytesPerChar);
   5977  1.8      maya         if (! name) {
   5978  1.1      tron           result = XML_ERROR_NO_MEMORY;
   5979  1.1      tron           goto endEntityValue;
   5980  1.1      tron         }
   5981  1.3       spz         entity = (ENTITY *)lookup(parser, &dtd->paramEntities, name, 0);
   5982  1.8      maya         poolDiscard(&parser->m_tempPool);
   5983  1.8      maya         if (! entity) {
   5984  1.1      tron           /* not a well-formedness error - see XML 1.0: WFC Entity Declared */
   5985  1.1      tron           /* cannot report skipped entity here - see comments on
   5986  1.8      maya              parser->m_skippedEntityHandler
   5987  1.8      maya           if (parser->m_skippedEntityHandler)
   5988  1.8      maya             parser->m_skippedEntityHandler(parser->m_handlerArg, name, 0);
   5989  1.1      tron           */
   5990  1.1      tron           dtd->keepProcessing = dtd->standalone;
   5991  1.1      tron           goto endEntityValue;
   5992  1.1      tron         }
   5993  1.1      tron         if (entity->open) {
   5994  1.8      maya           if (enc == parser->m_encoding)
   5995  1.8      maya             parser->m_eventPtr = entityTextPtr;
   5996  1.1      tron           result = XML_ERROR_RECURSIVE_ENTITY_REF;
   5997  1.1      tron           goto endEntityValue;
   5998  1.1      tron         }
   5999  1.1      tron         if (entity->systemId) {
   6000  1.8      maya           if (parser->m_externalEntityRefHandler) {
   6001  1.1      tron             dtd->paramEntityRead = XML_FALSE;
   6002  1.1      tron             entity->open = XML_TRUE;
   6003  1.9  christos             entityTrackingOnOpen(parser, entity, __LINE__);
   6004  1.8      maya             if (! parser->m_externalEntityRefHandler(
   6005  1.8      maya                     parser->m_externalEntityRefHandlerArg, 0, entity->base,
   6006  1.8      maya                     entity->systemId, entity->publicId)) {
   6007  1.9  christos               entityTrackingOnClose(parser, entity, __LINE__);
   6008  1.1      tron               entity->open = XML_FALSE;
   6009  1.1      tron               result = XML_ERROR_EXTERNAL_ENTITY_HANDLING;
   6010  1.1      tron               goto endEntityValue;
   6011  1.1      tron             }
   6012  1.9  christos             entityTrackingOnClose(parser, entity, __LINE__);
   6013  1.1      tron             entity->open = XML_FALSE;
   6014  1.8      maya             if (! dtd->paramEntityRead)
   6015  1.1      tron               dtd->keepProcessing = dtd->standalone;
   6016  1.8      maya           } else
   6017  1.1      tron             dtd->keepProcessing = dtd->standalone;
   6018  1.8      maya         } else {
   6019  1.1      tron           entity->open = XML_TRUE;
   6020  1.9  christos           entityTrackingOnOpen(parser, entity, __LINE__);
   6021  1.8      maya           result = storeEntityValue(
   6022  1.9  christos               parser, parser->m_internalEncoding, (const char *)entity->textPtr,
   6023  1.9  christos               (const char *)(entity->textPtr + entity->textLen),
   6024  1.9  christos               XML_ACCOUNT_ENTITY_EXPANSION);
   6025  1.9  christos           entityTrackingOnClose(parser, entity, __LINE__);
   6026  1.1      tron           entity->open = XML_FALSE;
   6027  1.1      tron           if (result)
   6028  1.1      tron             goto endEntityValue;
   6029  1.1      tron         }
   6030  1.1      tron         break;
   6031  1.1      tron       }
   6032  1.1      tron #endif /* XML_DTD */
   6033  1.1      tron       /* In the internal subset, PE references are not legal
   6034  1.1      tron          within markup declarations, e.g entity values in this case. */
   6035  1.8      maya       parser->m_eventPtr = entityTextPtr;
   6036  1.1      tron       result = XML_ERROR_PARAM_ENTITY_REF;
   6037  1.1      tron       goto endEntityValue;
   6038  1.1      tron     case XML_TOK_NONE:
   6039  1.1      tron       result = XML_ERROR_NONE;
   6040  1.1      tron       goto endEntityValue;
   6041  1.1      tron     case XML_TOK_ENTITY_REF:
   6042  1.1      tron     case XML_TOK_DATA_CHARS:
   6043  1.8      maya       if (! poolAppend(pool, enc, entityTextPtr, next)) {
   6044  1.1      tron         result = XML_ERROR_NO_MEMORY;
   6045  1.1      tron         goto endEntityValue;
   6046  1.1      tron       }
   6047  1.1      tron       break;
   6048  1.1      tron     case XML_TOK_TRAILING_CR:
   6049  1.1      tron       next = entityTextPtr + enc->minBytesPerChar;
   6050  1.1      tron       /* fall through */
   6051  1.1      tron     case XML_TOK_DATA_NEWLINE:
   6052  1.8      maya       if (pool->end == pool->ptr && ! poolGrow(pool)) {
   6053  1.8      maya         result = XML_ERROR_NO_MEMORY;
   6054  1.1      tron         goto endEntityValue;
   6055  1.1      tron       }
   6056  1.1      tron       *(pool->ptr)++ = 0xA;
   6057  1.1      tron       break;
   6058  1.8      maya     case XML_TOK_CHAR_REF: {
   6059  1.8      maya       XML_Char buf[XML_ENCODE_MAX];
   6060  1.8      maya       int i;
   6061  1.8      maya       int n = XmlCharRefNumber(enc, entityTextPtr);
   6062  1.8      maya       if (n < 0) {
   6063  1.8      maya         if (enc == parser->m_encoding)
   6064  1.8      maya           parser->m_eventPtr = entityTextPtr;
   6065  1.8      maya         result = XML_ERROR_BAD_CHAR_REF;
   6066  1.8      maya         goto endEntityValue;
   6067  1.8      maya       }
   6068  1.8      maya       n = XmlEncode(n, (ICHAR *)buf);
   6069  1.8      maya       /* The XmlEncode() functions can never return 0 here.  That
   6070  1.8      maya        * error return happens if the code point passed in is either
   6071  1.8      maya        * negative or greater than or equal to 0x110000.  The
   6072  1.8      maya        * XmlCharRefNumber() functions will all return a number
   6073  1.8      maya        * strictly less than 0x110000 or a negative value if an error
   6074  1.8      maya        * occurred.  The negative value is intercepted above, so
   6075  1.8      maya        * XmlEncode() is never passed a value it might return an
   6076  1.8      maya        * error for.
   6077  1.8      maya        */
   6078  1.8      maya       for (i = 0; i < n; i++) {
   6079  1.8      maya         if (pool->end == pool->ptr && ! poolGrow(pool)) {
   6080  1.8      maya           result = XML_ERROR_NO_MEMORY;
   6081  1.1      tron           goto endEntityValue;
   6082  1.1      tron         }
   6083  1.8      maya         *(pool->ptr)++ = buf[i];
   6084  1.1      tron       }
   6085  1.8      maya     } break;
   6086  1.1      tron     case XML_TOK_PARTIAL:
   6087  1.8      maya       if (enc == parser->m_encoding)
   6088  1.8      maya         parser->m_eventPtr = entityTextPtr;
   6089  1.1      tron       result = XML_ERROR_INVALID_TOKEN;
   6090  1.1      tron       goto endEntityValue;
   6091  1.1      tron     case XML_TOK_INVALID:
   6092  1.8      maya       if (enc == parser->m_encoding)
   6093  1.8      maya         parser->m_eventPtr = next;
   6094  1.1      tron       result = XML_ERROR_INVALID_TOKEN;
   6095  1.1      tron       goto endEntityValue;
   6096  1.1      tron     default:
   6097  1.8      maya       /* This default case should be unnecessary -- all the tokens
   6098  1.8      maya        * that XmlEntityValueTok() can return have their own explicit
   6099  1.8      maya        * cases -- but should be retained for safety.  We do however
   6100  1.8      maya        * exclude it from the coverage statistics.
   6101  1.8      maya        *
   6102  1.8      maya        * LCOV_EXCL_START
   6103  1.8      maya        */
   6104  1.8      maya       if (enc == parser->m_encoding)
   6105  1.8      maya         parser->m_eventPtr = entityTextPtr;
   6106  1.1      tron       result = XML_ERROR_UNEXPECTED_STATE;
   6107  1.1      tron       goto endEntityValue;
   6108  1.8      maya       /* LCOV_EXCL_STOP */
   6109  1.1      tron     }
   6110  1.1      tron     entityTextPtr = next;
   6111  1.1      tron   }
   6112  1.1      tron endEntityValue:
   6113  1.1      tron #ifdef XML_DTD
   6114  1.8      maya   parser->m_prologState.inEntityValue = oldInEntityValue;
   6115  1.1      tron #endif /* XML_DTD */
   6116  1.1      tron   return result;
   6117  1.1      tron }
   6118  1.1      tron 
   6119  1.1      tron static void FASTCALL
   6120  1.8      maya normalizeLines(XML_Char *s) {
   6121  1.1      tron   XML_Char *p;
   6122  1.1      tron   for (;; s++) {
   6123  1.1      tron     if (*s == XML_T('\0'))
   6124  1.1      tron       return;
   6125  1.1      tron     if (*s == 0xD)
   6126  1.1      tron       break;
   6127  1.1      tron   }
   6128  1.1      tron   p = s;
   6129  1.1      tron   do {
   6130  1.1      tron     if (*s == 0xD) {
   6131  1.1      tron       *p++ = 0xA;
   6132  1.1      tron       if (*++s == 0xA)
   6133  1.1      tron         s++;
   6134  1.8      maya     } else
   6135  1.1      tron       *p++ = *s++;
   6136  1.1      tron   } while (*s);
   6137  1.1      tron   *p = XML_T('\0');
   6138  1.1      tron }
   6139  1.1      tron 
   6140  1.1      tron static int
   6141  1.1      tron reportProcessingInstruction(XML_Parser parser, const ENCODING *enc,
   6142  1.8      maya                             const char *start, const char *end) {
   6143  1.1      tron   const XML_Char *target;
   6144  1.1      tron   XML_Char *data;
   6145  1.1      tron   const char *tem;
   6146  1.8      maya   if (! parser->m_processingInstructionHandler) {
   6147  1.8      maya     if (parser->m_defaultHandler)
   6148  1.1      tron       reportDefault(parser, enc, start, end);
   6149  1.1      tron     return 1;
   6150  1.1      tron   }
   6151  1.1      tron   start += enc->minBytesPerChar * 2;
   6152  1.1      tron   tem = start + XmlNameLength(enc, start);
   6153  1.8      maya   target = poolStoreString(&parser->m_tempPool, enc, start, tem);
   6154  1.8      maya   if (! target)
   6155  1.1      tron     return 0;
   6156  1.8      maya   poolFinish(&parser->m_tempPool);
   6157  1.8      maya   data = poolStoreString(&parser->m_tempPool, enc, XmlSkipS(enc, tem),
   6158  1.8      maya                          end - enc->minBytesPerChar * 2);
   6159  1.8      maya   if (! data)
   6160  1.1      tron     return 0;
   6161  1.1      tron   normalizeLines(data);
   6162  1.8      maya   parser->m_processingInstructionHandler(parser->m_handlerArg, target, data);
   6163  1.8      maya   poolClear(&parser->m_tempPool);
   6164  1.1      tron   return 1;
   6165  1.1      tron }
   6166  1.1      tron 
   6167  1.1      tron static int
   6168  1.8      maya reportComment(XML_Parser parser, const ENCODING *enc, const char *start,
   6169  1.8      maya               const char *end) {
   6170  1.1      tron   XML_Char *data;
   6171  1.8      maya   if (! parser->m_commentHandler) {
   6172  1.8      maya     if (parser->m_defaultHandler)
   6173  1.1      tron       reportDefault(parser, enc, start, end);
   6174  1.1      tron     return 1;
   6175  1.1      tron   }
   6176  1.8      maya   data = poolStoreString(&parser->m_tempPool, enc,
   6177  1.1      tron                          start + enc->minBytesPerChar * 4,
   6178  1.1      tron                          end - enc->minBytesPerChar * 3);
   6179  1.8      maya   if (! data)
   6180  1.1      tron     return 0;
   6181  1.1      tron   normalizeLines(data);
   6182  1.8      maya   parser->m_commentHandler(parser->m_handlerArg, data);
   6183  1.8      maya   poolClear(&parser->m_tempPool);
   6184  1.1      tron   return 1;
   6185  1.1      tron }
   6186  1.1      tron 
   6187  1.1      tron static void
   6188  1.8      maya reportDefault(XML_Parser parser, const ENCODING *enc, const char *s,
   6189  1.8      maya               const char *end) {
   6190  1.1      tron   if (MUST_CONVERT(enc, s)) {
   6191  1.5       spz     enum XML_Convert_Result convert_res;
   6192  1.1      tron     const char **eventPP;
   6193  1.1      tron     const char **eventEndPP;
   6194  1.8      maya     if (enc == parser->m_encoding) {
   6195  1.8      maya       eventPP = &parser->m_eventPtr;
   6196  1.8      maya       eventEndPP = &parser->m_eventEndPtr;
   6197  1.8      maya     } else {
   6198  1.8      maya       /* To get here, two things must be true; the parser must be
   6199  1.8      maya        * using a character encoding that is not the same as the
   6200  1.8      maya        * encoding passed in, and the encoding passed in must need
   6201  1.8      maya        * conversion to the internal format (UTF-8 unless XML_UNICODE
   6202  1.8      maya        * is defined).  The only occasions on which the encoding passed
   6203  1.8      maya        * in is not the same as the parser's encoding are when it is
   6204  1.8      maya        * the internal encoding (e.g. a previously defined parameter
   6205  1.8      maya        * entity, already converted to internal format).  This by
   6206  1.8      maya        * definition doesn't need conversion, so the whole branch never
   6207  1.8      maya        * gets executed.
   6208  1.8      maya        *
   6209  1.8      maya        * For safety's sake we don't delete these lines and merely
   6210  1.8      maya        * exclude them from coverage statistics.
   6211  1.8      maya        *
   6212  1.8      maya        * LCOV_EXCL_START
   6213  1.8      maya        */
   6214  1.8      maya       eventPP = &(parser->m_openInternalEntities->internalEventPtr);
   6215  1.8      maya       eventEndPP = &(parser->m_openInternalEntities->internalEventEndPtr);
   6216  1.8      maya       /* LCOV_EXCL_STOP */
   6217  1.1      tron     }
   6218  1.1      tron     do {
   6219  1.8      maya       ICHAR *dataPtr = (ICHAR *)parser->m_dataBuf;
   6220  1.8      maya       convert_res
   6221  1.8      maya           = XmlConvert(enc, &s, end, &dataPtr, (ICHAR *)parser->m_dataBufEnd);
   6222  1.1      tron       *eventEndPP = s;
   6223  1.8      maya       parser->m_defaultHandler(parser->m_handlerArg, parser->m_dataBuf,
   6224  1.8      maya                                (int)(dataPtr - (ICHAR *)parser->m_dataBuf));
   6225  1.1      tron       *eventPP = s;
   6226  1.8      maya     } while ((convert_res != XML_CONVERT_COMPLETED)
   6227  1.8      maya              && (convert_res != XML_CONVERT_INPUT_INCOMPLETE));
   6228  1.8      maya   } else
   6229  1.8      maya     parser->m_defaultHandler(parser->m_handlerArg, (XML_Char *)s,
   6230  1.8      maya                              (int)((XML_Char *)end - (XML_Char *)s));
   6231  1.1      tron }
   6232  1.1      tron 
   6233  1.1      tron static int
   6234  1.1      tron defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
   6235  1.8      maya                 XML_Bool isId, const XML_Char *value, XML_Parser parser) {
   6236  1.1      tron   DEFAULT_ATTRIBUTE *att;
   6237  1.1      tron   if (value || isId) {
   6238  1.1      tron     /* The handling of default attributes gets messed up if we have
   6239  1.1      tron        a default which duplicates a non-default. */
   6240  1.1      tron     int i;
   6241  1.1      tron     for (i = 0; i < type->nDefaultAtts; i++)
   6242  1.1      tron       if (attId == type->defaultAtts[i].id)
   6243  1.1      tron         return 1;
   6244  1.8      maya     if (isId && ! type->idAtt && ! attId->xmlns)
   6245  1.1      tron       type->idAtt = attId;
   6246  1.1      tron   }
   6247  1.1      tron   if (type->nDefaultAtts == type->allocDefaultAtts) {
   6248  1.1      tron     if (type->allocDefaultAtts == 0) {
   6249  1.1      tron       type->allocDefaultAtts = 8;
   6250  1.8      maya       type->defaultAtts = (DEFAULT_ATTRIBUTE *)MALLOC(
   6251  1.8      maya           parser, type->allocDefaultAtts * sizeof(DEFAULT_ATTRIBUTE));
   6252  1.8      maya       if (! type->defaultAtts) {
   6253  1.8      maya         type->allocDefaultAtts = 0;
   6254  1.1      tron         return 0;
   6255  1.8      maya       }
   6256  1.8      maya     } else {
   6257  1.1      tron       DEFAULT_ATTRIBUTE *temp;
   6258  1.9  christos 
   6259  1.9  christos       /* Detect and prevent integer overflow */
   6260  1.9  christos       if (type->allocDefaultAtts > INT_MAX / 2) {
   6261  1.9  christos         return 0;
   6262  1.9  christos       }
   6263  1.9  christos 
   6264  1.1      tron       int count = type->allocDefaultAtts * 2;
   6265  1.9  christos 
   6266  1.9  christos       /* Detect and prevent integer overflow.
   6267  1.9  christos        * The preprocessor guard addresses the "always false" warning
   6268  1.9  christos        * from -Wtype-limits on platforms where
   6269  1.9  christos        * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   6270  1.9  christos #if UINT_MAX >= SIZE_MAX
   6271  1.9  christos       if ((unsigned)count > (size_t)(-1) / sizeof(DEFAULT_ATTRIBUTE)) {
   6272  1.9  christos         return 0;
   6273  1.9  christos       }
   6274  1.9  christos #endif
   6275  1.9  christos 
   6276  1.8      maya       temp = (DEFAULT_ATTRIBUTE *)REALLOC(parser, type->defaultAtts,
   6277  1.8      maya                                           (count * sizeof(DEFAULT_ATTRIBUTE)));
   6278  1.1      tron       if (temp == NULL)
   6279  1.1      tron         return 0;
   6280  1.1      tron       type->allocDefaultAtts = count;
   6281  1.1      tron       type->defaultAtts = temp;
   6282  1.1      tron     }
   6283  1.1      tron   }
   6284  1.1      tron   att = type->defaultAtts + type->nDefaultAtts;
   6285  1.1      tron   att->id = attId;
   6286  1.1      tron   att->value = value;
   6287  1.1      tron   att->isCdata = isCdata;
   6288  1.8      maya   if (! isCdata)
   6289  1.1      tron     attId->maybeTokenized = XML_TRUE;
   6290  1.1      tron   type->nDefaultAtts += 1;
   6291  1.1      tron   return 1;
   6292  1.1      tron }
   6293  1.1      tron 
   6294  1.1      tron static int
   6295  1.8      maya setElementTypePrefix(XML_Parser parser, ELEMENT_TYPE *elementType) {
   6296  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   6297  1.1      tron   const XML_Char *name;
   6298  1.1      tron   for (name = elementType->name; *name; name++) {
   6299  1.1      tron     if (*name == XML_T(ASCII_COLON)) {
   6300  1.1      tron       PREFIX *prefix;
   6301  1.1      tron       const XML_Char *s;
   6302  1.1      tron       for (s = elementType->name; s != name; s++) {
   6303  1.8      maya         if (! poolAppendChar(&dtd->pool, *s))
   6304  1.1      tron           return 0;
   6305  1.1      tron       }
   6306  1.8      maya       if (! poolAppendChar(&dtd->pool, XML_T('\0')))
   6307  1.1      tron         return 0;
   6308  1.3       spz       prefix = (PREFIX *)lookup(parser, &dtd->prefixes, poolStart(&dtd->pool),
   6309  1.1      tron                                 sizeof(PREFIX));
   6310  1.8      maya       if (! prefix)
   6311  1.1      tron         return 0;
   6312  1.1      tron       if (prefix->name == poolStart(&dtd->pool))
   6313  1.1      tron         poolFinish(&dtd->pool);
   6314  1.1      tron       else
   6315  1.1      tron         poolDiscard(&dtd->pool);
   6316  1.1      tron       elementType->prefix = prefix;
   6317  1.8      maya       break;
   6318  1.1      tron     }
   6319  1.1      tron   }
   6320  1.1      tron   return 1;
   6321  1.1      tron }
   6322  1.1      tron 
   6323  1.1      tron static ATTRIBUTE_ID *
   6324  1.8      maya getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start,
   6325  1.8      maya                const char *end) {
   6326  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   6327  1.1      tron   ATTRIBUTE_ID *id;
   6328  1.1      tron   const XML_Char *name;
   6329  1.8      maya   if (! poolAppendChar(&dtd->pool, XML_T('\0')))
   6330  1.1      tron     return NULL;
   6331  1.1      tron   name = poolStoreString(&dtd->pool, enc, start, end);
   6332  1.8      maya   if (! name)
   6333  1.1      tron     return NULL;
   6334  1.1      tron   /* skip quotation mark - its storage will be re-used (like in name[-1]) */
   6335  1.1      tron   ++name;
   6336  1.8      maya   id = (ATTRIBUTE_ID *)lookup(parser, &dtd->attributeIds, name,
   6337  1.8      maya                               sizeof(ATTRIBUTE_ID));
   6338  1.8      maya   if (! id)
   6339  1.1      tron     return NULL;
   6340  1.1      tron   if (id->name != name)
   6341  1.1      tron     poolDiscard(&dtd->pool);
   6342  1.1      tron   else {
   6343  1.1      tron     poolFinish(&dtd->pool);
   6344  1.8      maya     if (! parser->m_ns)
   6345  1.1      tron       ;
   6346  1.8      maya     else if (name[0] == XML_T(ASCII_x) && name[1] == XML_T(ASCII_m)
   6347  1.8      maya              && name[2] == XML_T(ASCII_l) && name[3] == XML_T(ASCII_n)
   6348  1.8      maya              && name[4] == XML_T(ASCII_s)
   6349  1.8      maya              && (name[5] == XML_T('\0') || name[5] == XML_T(ASCII_COLON))) {
   6350  1.1      tron       if (name[5] == XML_T('\0'))
   6351  1.1      tron         id->prefix = &dtd->defaultPrefix;
   6352  1.1      tron       else
   6353  1.8      maya         id->prefix = (PREFIX *)lookup(parser, &dtd->prefixes, name + 6,
   6354  1.8      maya                                       sizeof(PREFIX));
   6355  1.1      tron       id->xmlns = XML_TRUE;
   6356  1.8      maya     } else {
   6357  1.1      tron       int i;
   6358  1.1      tron       for (i = 0; name[i]; i++) {
   6359  1.1      tron         /* attributes without prefix are *not* in the default namespace */
   6360  1.1      tron         if (name[i] == XML_T(ASCII_COLON)) {
   6361  1.1      tron           int j;
   6362  1.1      tron           for (j = 0; j < i; j++) {
   6363  1.8      maya             if (! poolAppendChar(&dtd->pool, name[j]))
   6364  1.1      tron               return NULL;
   6365  1.1      tron           }
   6366  1.8      maya           if (! poolAppendChar(&dtd->pool, XML_T('\0')))
   6367  1.1      tron             return NULL;
   6368  1.8      maya           id->prefix = (PREFIX *)lookup(parser, &dtd->prefixes,
   6369  1.8      maya                                         poolStart(&dtd->pool), sizeof(PREFIX));
   6370  1.8      maya           if (! id->prefix)
   6371  1.4       spz             return NULL;
   6372  1.1      tron           if (id->prefix->name == poolStart(&dtd->pool))
   6373  1.1      tron             poolFinish(&dtd->pool);
   6374  1.1      tron           else
   6375  1.1      tron             poolDiscard(&dtd->pool);
   6376  1.1      tron           break;
   6377  1.1      tron         }
   6378  1.1      tron       }
   6379  1.1      tron     }
   6380  1.1      tron   }
   6381  1.1      tron   return id;
   6382  1.1      tron }
   6383  1.1      tron 
   6384  1.1      tron #define CONTEXT_SEP XML_T(ASCII_FF)
   6385  1.1      tron 
   6386  1.1      tron static const XML_Char *
   6387  1.8      maya getContext(XML_Parser parser) {
   6388  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   6389  1.1      tron   HASH_TABLE_ITER iter;
   6390  1.1      tron   XML_Bool needSep = XML_FALSE;
   6391  1.1      tron 
   6392  1.1      tron   if (dtd->defaultPrefix.binding) {
   6393  1.1      tron     int i;
   6394  1.1      tron     int len;
   6395  1.8      maya     if (! poolAppendChar(&parser->m_tempPool, XML_T(ASCII_EQUALS)))
   6396  1.1      tron       return NULL;
   6397  1.1      tron     len = dtd->defaultPrefix.binding->uriLen;
   6398  1.8      maya     if (parser->m_namespaceSeparator)
   6399  1.1      tron       len--;
   6400  1.8      maya     for (i = 0; i < len; i++) {
   6401  1.8      maya       if (! poolAppendChar(&parser->m_tempPool,
   6402  1.8      maya                            dtd->defaultPrefix.binding->uri[i])) {
   6403  1.8      maya         /* Because of memory caching, I don't believe this line can be
   6404  1.8      maya          * executed.
   6405  1.8      maya          *
   6406  1.8      maya          * This is part of a loop copying the default prefix binding
   6407  1.8      maya          * URI into the parser's temporary string pool.  Previously,
   6408  1.8      maya          * that URI was copied into the same string pool, with a
   6409  1.8      maya          * terminating NUL character, as part of setContext().  When
   6410  1.8      maya          * the pool was cleared, that leaves a block definitely big
   6411  1.8      maya          * enough to hold the URI on the free block list of the pool.
   6412  1.8      maya          * The URI copy in getContext() therefore cannot run out of
   6413  1.8      maya          * memory.
   6414  1.8      maya          *
   6415  1.8      maya          * If the pool is used between the setContext() and
   6416  1.8      maya          * getContext() calls, the worst it can do is leave a bigger
   6417  1.8      maya          * block on the front of the free list.  Given that this is
   6418  1.8      maya          * all somewhat inobvious and program logic can be changed, we
   6419  1.8      maya          * don't delete the line but we do exclude it from the test
   6420  1.8      maya          * coverage statistics.
   6421  1.8      maya          */
   6422  1.8      maya         return NULL; /* LCOV_EXCL_LINE */
   6423  1.8      maya       }
   6424  1.8      maya     }
   6425  1.1      tron     needSep = XML_TRUE;
   6426  1.1      tron   }
   6427  1.1      tron 
   6428  1.1      tron   hashTableIterInit(&iter, &(dtd->prefixes));
   6429  1.1      tron   for (;;) {
   6430  1.1      tron     int i;
   6431  1.1      tron     int len;
   6432  1.1      tron     const XML_Char *s;
   6433  1.1      tron     PREFIX *prefix = (PREFIX *)hashTableIterNext(&iter);
   6434  1.8      maya     if (! prefix)
   6435  1.1      tron       break;
   6436  1.8      maya     if (! prefix->binding) {
   6437  1.8      maya       /* This test appears to be (justifiable) paranoia.  There does
   6438  1.8      maya        * not seem to be a way of injecting a prefix without a binding
   6439  1.8      maya        * that doesn't get errored long before this function is called.
   6440  1.8      maya        * The test should remain for safety's sake, so we instead
   6441  1.8      maya        * exclude the following line from the coverage statistics.
   6442  1.8      maya        */
   6443  1.8      maya       continue; /* LCOV_EXCL_LINE */
   6444  1.8      maya     }
   6445  1.8      maya     if (needSep && ! poolAppendChar(&parser->m_tempPool, CONTEXT_SEP))
   6446  1.1      tron       return NULL;
   6447  1.1      tron     for (s = prefix->name; *s; s++)
   6448  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, *s))
   6449  1.1      tron         return NULL;
   6450  1.8      maya     if (! poolAppendChar(&parser->m_tempPool, XML_T(ASCII_EQUALS)))
   6451  1.1      tron       return NULL;
   6452  1.1      tron     len = prefix->binding->uriLen;
   6453  1.8      maya     if (parser->m_namespaceSeparator)
   6454  1.1      tron       len--;
   6455  1.1      tron     for (i = 0; i < len; i++)
   6456  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, prefix->binding->uri[i]))
   6457  1.1      tron         return NULL;
   6458  1.1      tron     needSep = XML_TRUE;
   6459  1.1      tron   }
   6460  1.1      tron 
   6461  1.1      tron   hashTableIterInit(&iter, &(dtd->generalEntities));
   6462  1.1      tron   for (;;) {
   6463  1.1      tron     const XML_Char *s;
   6464  1.1      tron     ENTITY *e = (ENTITY *)hashTableIterNext(&iter);
   6465  1.8      maya     if (! e)
   6466  1.1      tron       break;
   6467  1.8      maya     if (! e->open)
   6468  1.1      tron       continue;
   6469  1.8      maya     if (needSep && ! poolAppendChar(&parser->m_tempPool, CONTEXT_SEP))
   6470  1.1      tron       return NULL;
   6471  1.1      tron     for (s = e->name; *s; s++)
   6472  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, *s))
   6473  1.1      tron         return 0;
   6474  1.1      tron     needSep = XML_TRUE;
   6475  1.1      tron   }
   6476  1.1      tron 
   6477  1.8      maya   if (! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   6478  1.1      tron     return NULL;
   6479  1.8      maya   return parser->m_tempPool.start;
   6480  1.1      tron }
   6481  1.1      tron 
   6482  1.1      tron static XML_Bool
   6483  1.8      maya setContext(XML_Parser parser, const XML_Char *context) {
   6484  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   6485  1.1      tron   const XML_Char *s = context;
   6486  1.1      tron 
   6487  1.1      tron   while (*context != XML_T('\0')) {
   6488  1.1      tron     if (*s == CONTEXT_SEP || *s == XML_T('\0')) {
   6489  1.1      tron       ENTITY *e;
   6490  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   6491  1.1      tron         return XML_FALSE;
   6492  1.8      maya       e = (ENTITY *)lookup(parser, &dtd->generalEntities,
   6493  1.8      maya                            poolStart(&parser->m_tempPool), 0);
   6494  1.1      tron       if (e)
   6495  1.1      tron         e->open = XML_TRUE;
   6496  1.1      tron       if (*s != XML_T('\0'))
   6497  1.1      tron         s++;
   6498  1.1      tron       context = s;
   6499  1.8      maya       poolDiscard(&parser->m_tempPool);
   6500  1.8      maya     } else if (*s == XML_T(ASCII_EQUALS)) {
   6501  1.1      tron       PREFIX *prefix;
   6502  1.8      maya       if (poolLength(&parser->m_tempPool) == 0)
   6503  1.1      tron         prefix = &dtd->defaultPrefix;
   6504  1.1      tron       else {
   6505  1.8      maya         if (! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   6506  1.1      tron           return XML_FALSE;
   6507  1.8      maya         prefix
   6508  1.8      maya             = (PREFIX *)lookup(parser, &dtd->prefixes,
   6509  1.8      maya                                poolStart(&parser->m_tempPool), sizeof(PREFIX));
   6510  1.8      maya         if (! prefix)
   6511  1.1      tron           return XML_FALSE;
   6512  1.8      maya         if (prefix->name == poolStart(&parser->m_tempPool)) {
   6513  1.1      tron           prefix->name = poolCopyString(&dtd->pool, prefix->name);
   6514  1.8      maya           if (! prefix->name)
   6515  1.1      tron             return XML_FALSE;
   6516  1.1      tron         }
   6517  1.8      maya         poolDiscard(&parser->m_tempPool);
   6518  1.1      tron       }
   6519  1.8      maya       for (context = s + 1; *context != CONTEXT_SEP && *context != XML_T('\0');
   6520  1.1      tron            context++)
   6521  1.8      maya         if (! poolAppendChar(&parser->m_tempPool, *context))
   6522  1.1      tron           return XML_FALSE;
   6523  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, XML_T('\0')))
   6524  1.1      tron         return XML_FALSE;
   6525  1.8      maya       if (addBinding(parser, prefix, NULL, poolStart(&parser->m_tempPool),
   6526  1.8      maya                      &parser->m_inheritedBindings)
   6527  1.8      maya           != XML_ERROR_NONE)
   6528  1.1      tron         return XML_FALSE;
   6529  1.8      maya       poolDiscard(&parser->m_tempPool);
   6530  1.1      tron       if (*context != XML_T('\0'))
   6531  1.1      tron         ++context;
   6532  1.1      tron       s = context;
   6533  1.8      maya     } else {
   6534  1.8      maya       if (! poolAppendChar(&parser->m_tempPool, *s))
   6535  1.1      tron         return XML_FALSE;
   6536  1.1      tron       s++;
   6537  1.1      tron     }
   6538  1.1      tron   }
   6539  1.1      tron   return XML_TRUE;
   6540  1.1      tron }
   6541  1.1      tron 
   6542  1.1      tron static void FASTCALL
   6543  1.8      maya normalizePublicId(XML_Char *publicId) {
   6544  1.1      tron   XML_Char *p = publicId;
   6545  1.1      tron   XML_Char *s;
   6546  1.1      tron   for (s = publicId; *s; s++) {
   6547  1.1      tron     switch (*s) {
   6548  1.1      tron     case 0x20:
   6549  1.1      tron     case 0xD:
   6550  1.1      tron     case 0xA:
   6551  1.1      tron       if (p != publicId && p[-1] != 0x20)
   6552  1.1      tron         *p++ = 0x20;
   6553  1.1      tron       break;
   6554  1.1      tron     default:
   6555  1.1      tron       *p++ = *s;
   6556  1.1      tron     }
   6557  1.1      tron   }
   6558  1.1      tron   if (p != publicId && p[-1] == 0x20)
   6559  1.1      tron     --p;
   6560  1.1      tron   *p = XML_T('\0');
   6561  1.1      tron }
   6562  1.1      tron 
   6563  1.1      tron static DTD *
   6564  1.8      maya dtdCreate(const XML_Memory_Handling_Suite *ms) {
   6565  1.9  christos   DTD *p = ms->malloc_fcn(sizeof(DTD));
   6566  1.1      tron   if (p == NULL)
   6567  1.1      tron     return p;
   6568  1.1      tron   poolInit(&(p->pool), ms);
   6569  1.1      tron   poolInit(&(p->entityValuePool), ms);
   6570  1.1      tron   hashTableInit(&(p->generalEntities), ms);
   6571  1.1      tron   hashTableInit(&(p->elementTypes), ms);
   6572  1.1      tron   hashTableInit(&(p->attributeIds), ms);
   6573  1.1      tron   hashTableInit(&(p->prefixes), ms);
   6574  1.1      tron #ifdef XML_DTD
   6575  1.1      tron   p->paramEntityRead = XML_FALSE;
   6576  1.1      tron   hashTableInit(&(p->paramEntities), ms);
   6577  1.1      tron #endif /* XML_DTD */
   6578  1.1      tron   p->defaultPrefix.name = NULL;
   6579  1.1      tron   p->defaultPrefix.binding = NULL;
   6580  1.1      tron 
   6581  1.1      tron   p->in_eldecl = XML_FALSE;
   6582  1.1      tron   p->scaffIndex = NULL;
   6583  1.1      tron   p->scaffold = NULL;
   6584  1.1      tron   p->scaffLevel = 0;
   6585  1.1      tron   p->scaffSize = 0;
   6586  1.1      tron   p->scaffCount = 0;
   6587  1.1      tron   p->contentStringLen = 0;
   6588  1.1      tron 
   6589  1.1      tron   p->keepProcessing = XML_TRUE;
   6590  1.1      tron   p->hasParamEntityRefs = XML_FALSE;
   6591  1.1      tron   p->standalone = XML_FALSE;
   6592  1.1      tron   return p;
   6593  1.1      tron }
   6594  1.1      tron 
   6595  1.1      tron static void
   6596  1.8      maya dtdReset(DTD *p, const XML_Memory_Handling_Suite *ms) {
   6597  1.1      tron   HASH_TABLE_ITER iter;
   6598  1.1      tron   hashTableIterInit(&iter, &(p->elementTypes));
   6599  1.1      tron   for (;;) {
   6600  1.1      tron     ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
   6601  1.8      maya     if (! e)
   6602  1.1      tron       break;
   6603  1.1      tron     if (e->allocDefaultAtts != 0)
   6604  1.1      tron       ms->free_fcn(e->defaultAtts);
   6605  1.1      tron   }
   6606  1.1      tron   hashTableClear(&(p->generalEntities));
   6607  1.1      tron #ifdef XML_DTD
   6608  1.1      tron   p->paramEntityRead = XML_FALSE;
   6609  1.1      tron   hashTableClear(&(p->paramEntities));
   6610  1.1      tron #endif /* XML_DTD */
   6611  1.1      tron   hashTableClear(&(p->elementTypes));
   6612  1.1      tron   hashTableClear(&(p->attributeIds));
   6613  1.1      tron   hashTableClear(&(p->prefixes));
   6614  1.1      tron   poolClear(&(p->pool));
   6615  1.1      tron   poolClear(&(p->entityValuePool));
   6616  1.1      tron   p->defaultPrefix.name = NULL;
   6617  1.1      tron   p->defaultPrefix.binding = NULL;
   6618  1.1      tron 
   6619  1.1      tron   p->in_eldecl = XML_FALSE;
   6620  1.1      tron 
   6621  1.1      tron   ms->free_fcn(p->scaffIndex);
   6622  1.1      tron   p->scaffIndex = NULL;
   6623  1.1      tron   ms->free_fcn(p->scaffold);
   6624  1.1      tron   p->scaffold = NULL;
   6625  1.1      tron 
   6626  1.1      tron   p->scaffLevel = 0;
   6627  1.1      tron   p->scaffSize = 0;
   6628  1.1      tron   p->scaffCount = 0;
   6629  1.1      tron   p->contentStringLen = 0;
   6630  1.1      tron 
   6631  1.1      tron   p->keepProcessing = XML_TRUE;
   6632  1.1      tron   p->hasParamEntityRefs = XML_FALSE;
   6633  1.1      tron   p->standalone = XML_FALSE;
   6634  1.1      tron }
   6635  1.1      tron 
   6636  1.1      tron static void
   6637  1.8      maya dtdDestroy(DTD *p, XML_Bool isDocEntity, const XML_Memory_Handling_Suite *ms) {
   6638  1.1      tron   HASH_TABLE_ITER iter;
   6639  1.1      tron   hashTableIterInit(&iter, &(p->elementTypes));
   6640  1.1      tron   for (;;) {
   6641  1.1      tron     ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
   6642  1.8      maya     if (! e)
   6643  1.1      tron       break;
   6644  1.1      tron     if (e->allocDefaultAtts != 0)
   6645  1.1      tron       ms->free_fcn(e->defaultAtts);
   6646  1.1      tron   }
   6647  1.1      tron   hashTableDestroy(&(p->generalEntities));
   6648  1.1      tron #ifdef XML_DTD
   6649  1.1      tron   hashTableDestroy(&(p->paramEntities));
   6650  1.1      tron #endif /* XML_DTD */
   6651  1.1      tron   hashTableDestroy(&(p->elementTypes));
   6652  1.1      tron   hashTableDestroy(&(p->attributeIds));
   6653  1.1      tron   hashTableDestroy(&(p->prefixes));
   6654  1.1      tron   poolDestroy(&(p->pool));
   6655  1.1      tron   poolDestroy(&(p->entityValuePool));
   6656  1.1      tron   if (isDocEntity) {
   6657  1.1      tron     ms->free_fcn(p->scaffIndex);
   6658  1.1      tron     ms->free_fcn(p->scaffold);
   6659  1.1      tron   }
   6660  1.1      tron   ms->free_fcn(p);
   6661  1.1      tron }
   6662  1.1      tron 
   6663  1.1      tron /* Do a deep copy of the DTD. Return 0 for out of memory, non-zero otherwise.
   6664  1.1      tron    The new DTD has already been initialized.
   6665  1.1      tron */
   6666  1.1      tron static int
   6667  1.8      maya dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
   6668  1.8      maya         const XML_Memory_Handling_Suite *ms) {
   6669  1.1      tron   HASH_TABLE_ITER iter;
   6670  1.1      tron 
   6671  1.1      tron   /* Copy the prefix table. */
   6672  1.1      tron 
   6673  1.1      tron   hashTableIterInit(&iter, &(oldDtd->prefixes));
   6674  1.1      tron   for (;;) {
   6675  1.1      tron     const XML_Char *name;
   6676  1.1      tron     const PREFIX *oldP = (PREFIX *)hashTableIterNext(&iter);
   6677  1.8      maya     if (! oldP)
   6678  1.1      tron       break;
   6679  1.1      tron     name = poolCopyString(&(newDtd->pool), oldP->name);
   6680  1.8      maya     if (! name)
   6681  1.1      tron       return 0;
   6682  1.8      maya     if (! lookup(oldParser, &(newDtd->prefixes), name, sizeof(PREFIX)))
   6683  1.1      tron       return 0;
   6684  1.1      tron   }
   6685  1.1      tron 
   6686  1.1      tron   hashTableIterInit(&iter, &(oldDtd->attributeIds));
   6687  1.1      tron 
   6688  1.1      tron   /* Copy the attribute id table. */
   6689  1.1      tron 
   6690  1.1      tron   for (;;) {
   6691  1.1      tron     ATTRIBUTE_ID *newA;
   6692  1.1      tron     const XML_Char *name;
   6693  1.1      tron     const ATTRIBUTE_ID *oldA = (ATTRIBUTE_ID *)hashTableIterNext(&iter);
   6694  1.1      tron 
   6695  1.8      maya     if (! oldA)
   6696  1.1      tron       break;
   6697  1.1      tron     /* Remember to allocate the scratch byte before the name. */
   6698  1.8      maya     if (! poolAppendChar(&(newDtd->pool), XML_T('\0')))
   6699  1.1      tron       return 0;
   6700  1.1      tron     name = poolCopyString(&(newDtd->pool), oldA->name);
   6701  1.8      maya     if (! name)
   6702  1.1      tron       return 0;
   6703  1.1      tron     ++name;
   6704  1.3       spz     newA = (ATTRIBUTE_ID *)lookup(oldParser, &(newDtd->attributeIds), name,
   6705  1.1      tron                                   sizeof(ATTRIBUTE_ID));
   6706  1.8      maya     if (! newA)
   6707  1.1      tron       return 0;
   6708  1.1      tron     newA->maybeTokenized = oldA->maybeTokenized;
   6709  1.1      tron     if (oldA->prefix) {
   6710  1.1      tron       newA->xmlns = oldA->xmlns;
   6711  1.1      tron       if (oldA->prefix == &oldDtd->defaultPrefix)
   6712  1.1      tron         newA->prefix = &newDtd->defaultPrefix;
   6713  1.1      tron       else
   6714  1.3       spz         newA->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes),
   6715  1.1      tron                                         oldA->prefix->name, 0);
   6716  1.1      tron     }
   6717  1.1      tron   }
   6718  1.1      tron 
   6719  1.1      tron   /* Copy the element type table. */
   6720  1.1      tron 
   6721  1.1      tron   hashTableIterInit(&iter, &(oldDtd->elementTypes));
   6722  1.1      tron 
   6723  1.1      tron   for (;;) {
   6724  1.1      tron     int i;
   6725  1.1      tron     ELEMENT_TYPE *newE;
   6726  1.1      tron     const XML_Char *name;
   6727  1.1      tron     const ELEMENT_TYPE *oldE = (ELEMENT_TYPE *)hashTableIterNext(&iter);
   6728  1.8      maya     if (! oldE)
   6729  1.1      tron       break;
   6730  1.1      tron     name = poolCopyString(&(newDtd->pool), oldE->name);
   6731  1.8      maya     if (! name)
   6732  1.1      tron       return 0;
   6733  1.3       spz     newE = (ELEMENT_TYPE *)lookup(oldParser, &(newDtd->elementTypes), name,
   6734  1.1      tron                                   sizeof(ELEMENT_TYPE));
   6735  1.8      maya     if (! newE)
   6736  1.1      tron       return 0;
   6737  1.1      tron     if (oldE->nDefaultAtts) {
   6738  1.9  christos       newE->defaultAtts
   6739  1.9  christos           = ms->malloc_fcn(oldE->nDefaultAtts * sizeof(DEFAULT_ATTRIBUTE));
   6740  1.8      maya       if (! newE->defaultAtts) {
   6741  1.1      tron         return 0;
   6742  1.1      tron       }
   6743  1.1      tron     }
   6744  1.1      tron     if (oldE->idAtt)
   6745  1.8      maya       newE->idAtt = (ATTRIBUTE_ID *)lookup(oldParser, &(newDtd->attributeIds),
   6746  1.8      maya                                            oldE->idAtt->name, 0);
   6747  1.1      tron     newE->allocDefaultAtts = newE->nDefaultAtts = oldE->nDefaultAtts;
   6748  1.1      tron     if (oldE->prefix)
   6749  1.3       spz       newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes),
   6750  1.1      tron                                       oldE->prefix->name, 0);
   6751  1.1      tron     for (i = 0; i < newE->nDefaultAtts; i++) {
   6752  1.8      maya       newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup(
   6753  1.8      maya           oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0);
   6754  1.1      tron       newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata;
   6755  1.1      tron       if (oldE->defaultAtts[i].value) {
   6756  1.1      tron         newE->defaultAtts[i].value
   6757  1.1      tron             = poolCopyString(&(newDtd->pool), oldE->defaultAtts[i].value);
   6758  1.8      maya         if (! newE->defaultAtts[i].value)
   6759  1.1      tron           return 0;
   6760  1.8      maya       } else
   6761  1.1      tron         newE->defaultAtts[i].value = NULL;
   6762  1.1      tron     }
   6763  1.1      tron   }
   6764  1.1      tron 
   6765  1.1      tron   /* Copy the entity tables. */
   6766  1.8      maya   if (! copyEntityTable(oldParser, &(newDtd->generalEntities), &(newDtd->pool),
   6767  1.8      maya                         &(oldDtd->generalEntities)))
   6768  1.8      maya     return 0;
   6769  1.1      tron 
   6770  1.1      tron #ifdef XML_DTD
   6771  1.8      maya   if (! copyEntityTable(oldParser, &(newDtd->paramEntities), &(newDtd->pool),
   6772  1.8      maya                         &(oldDtd->paramEntities)))
   6773  1.8      maya     return 0;
   6774  1.1      tron   newDtd->paramEntityRead = oldDtd->paramEntityRead;
   6775  1.1      tron #endif /* XML_DTD */
   6776  1.1      tron 
   6777  1.1      tron   newDtd->keepProcessing = oldDtd->keepProcessing;
   6778  1.1      tron   newDtd->hasParamEntityRefs = oldDtd->hasParamEntityRefs;
   6779  1.1      tron   newDtd->standalone = oldDtd->standalone;
   6780  1.1      tron 
   6781  1.1      tron   /* Don't want deep copying for scaffolding */
   6782  1.1      tron   newDtd->in_eldecl = oldDtd->in_eldecl;
   6783  1.1      tron   newDtd->scaffold = oldDtd->scaffold;
   6784  1.1      tron   newDtd->contentStringLen = oldDtd->contentStringLen;
   6785  1.1      tron   newDtd->scaffSize = oldDtd->scaffSize;
   6786  1.1      tron   newDtd->scaffLevel = oldDtd->scaffLevel;
   6787  1.1      tron   newDtd->scaffIndex = oldDtd->scaffIndex;
   6788  1.1      tron 
   6789  1.1      tron   return 1;
   6790  1.8      maya } /* End dtdCopy */
   6791  1.1      tron 
   6792  1.1      tron static int
   6793  1.8      maya copyEntityTable(XML_Parser oldParser, HASH_TABLE *newTable,
   6794  1.8      maya                 STRING_POOL *newPool, const HASH_TABLE *oldTable) {
   6795  1.1      tron   HASH_TABLE_ITER iter;
   6796  1.1      tron   const XML_Char *cachedOldBase = NULL;
   6797  1.1      tron   const XML_Char *cachedNewBase = NULL;
   6798  1.1      tron 
   6799  1.1      tron   hashTableIterInit(&iter, oldTable);
   6800  1.1      tron 
   6801  1.1      tron   for (;;) {
   6802  1.1      tron     ENTITY *newE;
   6803  1.1      tron     const XML_Char *name;
   6804  1.1      tron     const ENTITY *oldE = (ENTITY *)hashTableIterNext(&iter);
   6805  1.8      maya     if (! oldE)
   6806  1.1      tron       break;
   6807  1.1      tron     name = poolCopyString(newPool, oldE->name);
   6808  1.8      maya     if (! name)
   6809  1.1      tron       return 0;
   6810  1.3       spz     newE = (ENTITY *)lookup(oldParser, newTable, name, sizeof(ENTITY));
   6811  1.8      maya     if (! newE)
   6812  1.1      tron       return 0;
   6813  1.1      tron     if (oldE->systemId) {
   6814  1.1      tron       const XML_Char *tem = poolCopyString(newPool, oldE->systemId);
   6815  1.8      maya       if (! tem)
   6816  1.1      tron         return 0;
   6817  1.1      tron       newE->systemId = tem;
   6818  1.1      tron       if (oldE->base) {
   6819  1.1      tron         if (oldE->base == cachedOldBase)
   6820  1.1      tron           newE->base = cachedNewBase;
   6821  1.1      tron         else {
   6822  1.1      tron           cachedOldBase = oldE->base;
   6823  1.1      tron           tem = poolCopyString(newPool, cachedOldBase);
   6824  1.8      maya           if (! tem)
   6825  1.1      tron             return 0;
   6826  1.1      tron           cachedNewBase = newE->base = tem;
   6827  1.1      tron         }
   6828  1.1      tron       }
   6829  1.1      tron       if (oldE->publicId) {
   6830  1.1      tron         tem = poolCopyString(newPool, oldE->publicId);
   6831  1.8      maya         if (! tem)
   6832  1.1      tron           return 0;
   6833  1.1      tron         newE->publicId = tem;
   6834  1.1      tron       }
   6835  1.8      maya     } else {
   6836  1.8      maya       const XML_Char *tem
   6837  1.8      maya           = poolCopyStringN(newPool, oldE->textPtr, oldE->textLen);
   6838  1.8      maya       if (! tem)
   6839  1.1      tron         return 0;
   6840  1.1      tron       newE->textPtr = tem;
   6841  1.1      tron       newE->textLen = oldE->textLen;
   6842  1.1      tron     }
   6843  1.1      tron     if (oldE->notation) {
   6844  1.1      tron       const XML_Char *tem = poolCopyString(newPool, oldE->notation);
   6845  1.8      maya       if (! tem)
   6846  1.1      tron         return 0;
   6847  1.1      tron       newE->notation = tem;
   6848  1.1      tron     }
   6849  1.1      tron     newE->is_param = oldE->is_param;
   6850  1.1      tron     newE->is_internal = oldE->is_internal;
   6851  1.1      tron   }
   6852  1.1      tron   return 1;
   6853  1.1      tron }
   6854  1.1      tron 
   6855  1.1      tron #define INIT_POWER 6
   6856  1.1      tron 
   6857  1.1      tron static XML_Bool FASTCALL
   6858  1.8      maya keyeq(KEY s1, KEY s2) {
   6859  1.1      tron   for (; *s1 == *s2; s1++, s2++)
   6860  1.1      tron     if (*s1 == 0)
   6861  1.1      tron       return XML_TRUE;
   6862  1.1      tron   return XML_FALSE;
   6863  1.1      tron }
   6864  1.1      tron 
   6865  1.7  christos static size_t
   6866  1.8      maya keylen(KEY s) {
   6867  1.7  christos   size_t len = 0;
   6868  1.8      maya   for (; *s; s++, len++)
   6869  1.8      maya     ;
   6870  1.7  christos   return len;
   6871  1.7  christos }
   6872  1.7  christos 
   6873  1.7  christos static void
   6874  1.8      maya copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) {
   6875  1.7  christos   key->k[0] = 0;
   6876  1.7  christos   key->k[1] = get_hash_secret_salt(parser);
   6877  1.7  christos }
   6878  1.7  christos 
   6879  1.1      tron static unsigned long FASTCALL
   6880  1.8      maya hash(XML_Parser parser, KEY s) {
   6881  1.7  christos   struct siphash state;
   6882  1.7  christos   struct sipkey key;
   6883  1.7  christos   (void)sip24_valid;
   6884  1.7  christos   copy_salt_to_sipkey(parser, &key);
   6885  1.7  christos   sip24_init(&state, &key);
   6886  1.7  christos   sip24_update(&state, s, keylen(s) * sizeof(XML_Char));
   6887  1.7  christos   return (unsigned long)sip24_final(&state);
   6888  1.1      tron }
   6889  1.1      tron 
   6890  1.1      tron static NAMED *
   6891  1.8      maya lookup(XML_Parser parser, HASH_TABLE *table, KEY name, size_t createSize) {
   6892  1.1      tron   size_t i;
   6893  1.1      tron   if (table->size == 0) {
   6894  1.1      tron     size_t tsize;
   6895  1.8      maya     if (! createSize)
   6896  1.1      tron       return NULL;
   6897  1.1      tron     table->power = INIT_POWER;
   6898  1.1      tron     /* table->size is a power of 2 */
   6899  1.1      tron     table->size = (size_t)1 << INIT_POWER;
   6900  1.1      tron     tsize = table->size * sizeof(NAMED *);
   6901  1.9  christos     table->v = table->mem->malloc_fcn(tsize);
   6902  1.8      maya     if (! table->v) {
   6903  1.1      tron       table->size = 0;
   6904  1.1      tron       return NULL;
   6905  1.1      tron     }
   6906  1.1      tron     memset(table->v, 0, tsize);
   6907  1.3       spz     i = hash(parser, name) & ((unsigned long)table->size - 1);
   6908  1.8      maya   } else {
   6909  1.3       spz     unsigned long h = hash(parser, name);
   6910  1.1      tron     unsigned long mask = (unsigned long)table->size - 1;
   6911  1.1      tron     unsigned char step = 0;
   6912  1.1      tron     i = h & mask;
   6913  1.1      tron     while (table->v[i]) {
   6914  1.1      tron       if (keyeq(name, table->v[i]->name))
   6915  1.1      tron         return table->v[i];
   6916  1.8      maya       if (! step)
   6917  1.1      tron         step = PROBE_STEP(h, mask, table->power);
   6918  1.1      tron       i < step ? (i += table->size - step) : (i -= step);
   6919  1.1      tron     }
   6920  1.8      maya     if (! createSize)
   6921  1.1      tron       return NULL;
   6922  1.1      tron 
   6923  1.1      tron     /* check for overflow (table is half full) */
   6924  1.1      tron     if (table->used >> (table->power - 1)) {
   6925  1.1      tron       unsigned char newPower = table->power + 1;
   6926  1.9  christos 
   6927  1.9  christos       /* Detect and prevent invalid shift */
   6928  1.9  christos       if (newPower >= sizeof(unsigned long) * 8 /* bits per byte */) {
   6929  1.9  christos         return NULL;
   6930  1.9  christos       }
   6931  1.9  christos 
   6932  1.1      tron       size_t newSize = (size_t)1 << newPower;
   6933  1.1      tron       unsigned long newMask = (unsigned long)newSize - 1;
   6934  1.9  christos 
   6935  1.9  christos       /* Detect and prevent integer overflow */
   6936  1.9  christos       if (newSize > (size_t)(-1) / sizeof(NAMED *)) {
   6937  1.9  christos         return NULL;
   6938  1.9  christos       }
   6939  1.9  christos 
   6940  1.1      tron       size_t tsize = newSize * sizeof(NAMED *);
   6941  1.9  christos       NAMED **newV = table->mem->malloc_fcn(tsize);
   6942  1.8      maya       if (! newV)
   6943  1.1      tron         return NULL;
   6944  1.1      tron       memset(newV, 0, tsize);
   6945  1.1      tron       for (i = 0; i < table->size; i++)
   6946  1.1      tron         if (table->v[i]) {
   6947  1.3       spz           unsigned long newHash = hash(parser, table->v[i]->name);
   6948  1.1      tron           size_t j = newHash & newMask;
   6949  1.1      tron           step = 0;
   6950  1.1      tron           while (newV[j]) {
   6951  1.8      maya             if (! step)
   6952  1.1      tron               step = PROBE_STEP(newHash, newMask, newPower);
   6953  1.1      tron             j < step ? (j += newSize - step) : (j -= step);
   6954  1.1      tron           }
   6955  1.1      tron           newV[j] = table->v[i];
   6956  1.1      tron         }
   6957  1.1      tron       table->mem->free_fcn(table->v);
   6958  1.1      tron       table->v = newV;
   6959  1.1      tron       table->power = newPower;
   6960  1.1      tron       table->size = newSize;
   6961  1.1      tron       i = h & newMask;
   6962  1.1      tron       step = 0;
   6963  1.1      tron       while (table->v[i]) {
   6964  1.8      maya         if (! step)
   6965  1.1      tron           step = PROBE_STEP(h, newMask, newPower);
   6966  1.1      tron         i < step ? (i += newSize - step) : (i -= step);
   6967  1.1      tron       }
   6968  1.1      tron     }
   6969  1.1      tron   }
   6970  1.9  christos   table->v[i] = table->mem->malloc_fcn(createSize);
   6971  1.8      maya   if (! table->v[i])
   6972  1.1      tron     return NULL;
   6973  1.1      tron   memset(table->v[i], 0, createSize);
   6974  1.1      tron   table->v[i]->name = name;
   6975  1.1      tron   (table->used)++;
   6976  1.1      tron   return table->v[i];
   6977  1.1      tron }
   6978  1.1      tron 
   6979  1.1      tron static void FASTCALL
   6980  1.8      maya hashTableClear(HASH_TABLE *table) {
   6981  1.1      tron   size_t i;
   6982  1.1      tron   for (i = 0; i < table->size; i++) {
   6983  1.1      tron     table->mem->free_fcn(table->v[i]);
   6984  1.1      tron     table->v[i] = NULL;
   6985  1.1      tron   }
   6986  1.1      tron   table->used = 0;
   6987  1.1      tron }
   6988  1.1      tron 
   6989  1.1      tron static void FASTCALL
   6990  1.8      maya hashTableDestroy(HASH_TABLE *table) {
   6991  1.1      tron   size_t i;
   6992  1.1      tron   for (i = 0; i < table->size; i++)
   6993  1.1      tron     table->mem->free_fcn(table->v[i]);
   6994  1.1      tron   table->mem->free_fcn(table->v);
   6995  1.1      tron }
   6996  1.1      tron 
   6997  1.1      tron static void FASTCALL
   6998  1.8      maya hashTableInit(HASH_TABLE *p, const XML_Memory_Handling_Suite *ms) {
   6999  1.1      tron   p->power = 0;
   7000  1.1      tron   p->size = 0;
   7001  1.1      tron   p->used = 0;
   7002  1.1      tron   p->v = NULL;
   7003  1.1      tron   p->mem = ms;
   7004  1.1      tron }
   7005  1.1      tron 
   7006  1.1      tron static void FASTCALL
   7007  1.8      maya hashTableIterInit(HASH_TABLE_ITER *iter, const HASH_TABLE *table) {
   7008  1.1      tron   iter->p = table->v;
   7009  1.9  christos   iter->end = iter->p ? iter->p + table->size : NULL;
   7010  1.1      tron }
   7011  1.1      tron 
   7012  1.8      maya static NAMED *FASTCALL
   7013  1.8      maya hashTableIterNext(HASH_TABLE_ITER *iter) {
   7014  1.1      tron   while (iter->p != iter->end) {
   7015  1.1      tron     NAMED *tem = *(iter->p)++;
   7016  1.1      tron     if (tem)
   7017  1.1      tron       return tem;
   7018  1.1      tron   }
   7019  1.1      tron   return NULL;
   7020  1.1      tron }
   7021  1.1      tron 
   7022  1.1      tron static void FASTCALL
   7023  1.8      maya poolInit(STRING_POOL *pool, const XML_Memory_Handling_Suite *ms) {
   7024  1.1      tron   pool->blocks = NULL;
   7025  1.1      tron   pool->freeBlocks = NULL;
   7026  1.1      tron   pool->start = NULL;
   7027  1.1      tron   pool->ptr = NULL;
   7028  1.1      tron   pool->end = NULL;
   7029  1.1      tron   pool->mem = ms;
   7030  1.1      tron }
   7031  1.1      tron 
   7032  1.1      tron static void FASTCALL
   7033  1.8      maya poolClear(STRING_POOL *pool) {
   7034  1.8      maya   if (! pool->freeBlocks)
   7035  1.1      tron     pool->freeBlocks = pool->blocks;
   7036  1.1      tron   else {
   7037  1.1      tron     BLOCK *p = pool->blocks;
   7038  1.1      tron     while (p) {
   7039  1.1      tron       BLOCK *tem = p->next;
   7040  1.1      tron       p->next = pool->freeBlocks;
   7041  1.1      tron       pool->freeBlocks = p;
   7042  1.1      tron       p = tem;
   7043  1.1      tron     }
   7044  1.1      tron   }
   7045  1.1      tron   pool->blocks = NULL;
   7046  1.1      tron   pool->start = NULL;
   7047  1.1      tron   pool->ptr = NULL;
   7048  1.1      tron   pool->end = NULL;
   7049  1.1      tron }
   7050  1.1      tron 
   7051  1.1      tron static void FASTCALL
   7052  1.8      maya poolDestroy(STRING_POOL *pool) {
   7053  1.1      tron   BLOCK *p = pool->blocks;
   7054  1.1      tron   while (p) {
   7055  1.1      tron     BLOCK *tem = p->next;
   7056  1.1      tron     pool->mem->free_fcn(p);
   7057  1.1      tron     p = tem;
   7058  1.1      tron   }
   7059  1.1      tron   p = pool->freeBlocks;
   7060  1.1      tron   while (p) {
   7061  1.1      tron     BLOCK *tem = p->next;
   7062  1.1      tron     pool->mem->free_fcn(p);
   7063  1.1      tron     p = tem;
   7064  1.1      tron   }
   7065  1.1      tron }
   7066  1.1      tron 
   7067  1.1      tron static XML_Char *
   7068  1.8      maya poolAppend(STRING_POOL *pool, const ENCODING *enc, const char *ptr,
   7069  1.8      maya            const char *end) {
   7070  1.8      maya   if (! pool->ptr && ! poolGrow(pool))
   7071  1.1      tron     return NULL;
   7072  1.1      tron   for (;;) {
   7073  1.8      maya     const enum XML_Convert_Result convert_res = XmlConvert(
   7074  1.8      maya         enc, &ptr, end, (ICHAR **)&(pool->ptr), (ICHAR *)pool->end);
   7075  1.8      maya     if ((convert_res == XML_CONVERT_COMPLETED)
   7076  1.8      maya         || (convert_res == XML_CONVERT_INPUT_INCOMPLETE))
   7077  1.1      tron       break;
   7078  1.8      maya     if (! poolGrow(pool))
   7079  1.1      tron       return NULL;
   7080  1.1      tron   }
   7081  1.1      tron   return pool->start;
   7082  1.1      tron }
   7083  1.1      tron 
   7084  1.8      maya static const XML_Char *FASTCALL
   7085  1.8      maya poolCopyString(STRING_POOL *pool, const XML_Char *s) {
   7086  1.1      tron   do {
   7087  1.8      maya     if (! poolAppendChar(pool, *s))
   7088  1.1      tron       return NULL;
   7089  1.1      tron   } while (*s++);
   7090  1.1      tron   s = pool->start;
   7091  1.1      tron   poolFinish(pool);
   7092  1.1      tron   return s;
   7093  1.1      tron }
   7094  1.1      tron 
   7095  1.1      tron static const XML_Char *
   7096  1.8      maya poolCopyStringN(STRING_POOL *pool, const XML_Char *s, int n) {
   7097  1.8      maya   if (! pool->ptr && ! poolGrow(pool)) {
   7098  1.8      maya     /* The following line is unreachable given the current usage of
   7099  1.8      maya      * poolCopyStringN().  Currently it is called from exactly one
   7100  1.8      maya      * place to copy the text of a simple general entity.  By that
   7101  1.8      maya      * point, the name of the entity is already stored in the pool, so
   7102  1.8      maya      * pool->ptr cannot be NULL.
   7103  1.8      maya      *
   7104  1.8      maya      * If poolCopyStringN() is used elsewhere as it well might be,
   7105  1.8      maya      * this line may well become executable again.  Regardless, this
   7106  1.8      maya      * sort of check shouldn't be removed lightly, so we just exclude
   7107  1.8      maya      * it from the coverage statistics.
   7108  1.8      maya      */
   7109  1.8      maya     return NULL; /* LCOV_EXCL_LINE */
   7110  1.8      maya   }
   7111  1.1      tron   for (; n > 0; --n, s++) {
   7112  1.8      maya     if (! poolAppendChar(pool, *s))
   7113  1.1      tron       return NULL;
   7114  1.1      tron   }
   7115  1.1      tron   s = pool->start;
   7116  1.1      tron   poolFinish(pool);
   7117  1.1      tron   return s;
   7118  1.1      tron }
   7119  1.1      tron 
   7120  1.8      maya static const XML_Char *FASTCALL
   7121  1.8      maya poolAppendString(STRING_POOL *pool, const XML_Char *s) {
   7122  1.1      tron   while (*s) {
   7123  1.8      maya     if (! poolAppendChar(pool, *s))
   7124  1.1      tron       return NULL;
   7125  1.1      tron     s++;
   7126  1.1      tron   }
   7127  1.1      tron   return pool->start;
   7128  1.1      tron }
   7129  1.1      tron 
   7130  1.1      tron static XML_Char *
   7131  1.8      maya poolStoreString(STRING_POOL *pool, const ENCODING *enc, const char *ptr,
   7132  1.8      maya                 const char *end) {
   7133  1.8      maya   if (! poolAppend(pool, enc, ptr, end))
   7134  1.1      tron     return NULL;
   7135  1.8      maya   if (pool->ptr == pool->end && ! poolGrow(pool))
   7136  1.1      tron     return NULL;
   7137  1.1      tron   *(pool->ptr)++ = 0;
   7138  1.1      tron   return pool->start;
   7139  1.1      tron }
   7140  1.1      tron 
   7141  1.7  christos static size_t
   7142  1.8      maya poolBytesToAllocateFor(int blockSize) {
   7143  1.7  christos   /* Unprotected math would be:
   7144  1.7  christos   ** return offsetof(BLOCK, s) + blockSize * sizeof(XML_Char);
   7145  1.7  christos   **
   7146  1.7  christos   ** Detect overflow, avoiding _signed_ overflow undefined behavior
   7147  1.7  christos   ** For a + b * c we check b * c in isolation first, so that addition of a
   7148  1.7  christos   ** on top has no chance of making us accept a small non-negative number
   7149  1.7  christos   */
   7150  1.8      maya   const size_t stretch = sizeof(XML_Char); /* can be 4 bytes */
   7151  1.7  christos 
   7152  1.7  christos   if (blockSize <= 0)
   7153  1.7  christos     return 0;
   7154  1.7  christos 
   7155  1.7  christos   if (blockSize > (int)(INT_MAX / stretch))
   7156  1.7  christos     return 0;
   7157  1.7  christos 
   7158  1.7  christos   {
   7159  1.7  christos     const int stretchedBlockSize = blockSize * (int)stretch;
   7160  1.8      maya     const int bytesToAllocate
   7161  1.8      maya         = (int)(offsetof(BLOCK, s) + (unsigned)stretchedBlockSize);
   7162  1.7  christos     if (bytesToAllocate < 0)
   7163  1.7  christos       return 0;
   7164  1.7  christos 
   7165  1.7  christos     return (size_t)bytesToAllocate;
   7166  1.7  christos   }
   7167  1.7  christos }
   7168  1.7  christos 
   7169  1.1      tron static XML_Bool FASTCALL
   7170  1.8      maya poolGrow(STRING_POOL *pool) {
   7171  1.1      tron   if (pool->freeBlocks) {
   7172  1.1      tron     if (pool->start == 0) {
   7173  1.1      tron       pool->blocks = pool->freeBlocks;
   7174  1.1      tron       pool->freeBlocks = pool->freeBlocks->next;
   7175  1.1      tron       pool->blocks->next = NULL;
   7176  1.1      tron       pool->start = pool->blocks->s;
   7177  1.1      tron       pool->end = pool->start + pool->blocks->size;
   7178  1.1      tron       pool->ptr = pool->start;
   7179  1.1      tron       return XML_TRUE;
   7180  1.1      tron     }
   7181  1.1      tron     if (pool->end - pool->start < pool->freeBlocks->size) {
   7182  1.1      tron       BLOCK *tem = pool->freeBlocks->next;
   7183  1.1      tron       pool->freeBlocks->next = pool->blocks;
   7184  1.1      tron       pool->blocks = pool->freeBlocks;
   7185  1.1      tron       pool->freeBlocks = tem;
   7186  1.1      tron       memcpy(pool->blocks->s, pool->start,
   7187  1.1      tron              (pool->end - pool->start) * sizeof(XML_Char));
   7188  1.1      tron       pool->ptr = pool->blocks->s + (pool->ptr - pool->start);
   7189  1.1      tron       pool->start = pool->blocks->s;
   7190  1.1      tron       pool->end = pool->start + pool->blocks->size;
   7191  1.1      tron       return XML_TRUE;
   7192  1.1      tron     }
   7193  1.1      tron   }
   7194  1.1      tron   if (pool->blocks && pool->start == pool->blocks->s) {
   7195  1.5       spz     BLOCK *temp;
   7196  1.8      maya     int blockSize = (int)((unsigned)(pool->end - pool->start) * 2U);
   7197  1.7  christos     size_t bytesToAllocate;
   7198  1.5       spz 
   7199  1.8      maya     /* NOTE: Needs to be calculated prior to calling `realloc`
   7200  1.8      maya              to avoid dangling pointers: */
   7201  1.8      maya     const ptrdiff_t offsetInsideBlock = pool->ptr - pool->start;
   7202  1.8      maya 
   7203  1.8      maya     if (blockSize < 0) {
   7204  1.8      maya       /* This condition traps a situation where either more than
   7205  1.8      maya        * INT_MAX/2 bytes have already been allocated.  This isn't
   7206  1.8      maya        * readily testable, since it is unlikely that an average
   7207  1.8      maya        * machine will have that much memory, so we exclude it from the
   7208  1.8      maya        * coverage statistics.
   7209  1.8      maya        */
   7210  1.8      maya       return XML_FALSE; /* LCOV_EXCL_LINE */
   7211  1.8      maya     }
   7212  1.5       spz 
   7213  1.7  christos     bytesToAllocate = poolBytesToAllocateFor(blockSize);
   7214  1.7  christos     if (bytesToAllocate == 0)
   7215  1.7  christos       return XML_FALSE;
   7216  1.7  christos 
   7217  1.8      maya     temp = (BLOCK *)pool->mem->realloc_fcn(pool->blocks,
   7218  1.8      maya                                            (unsigned)bytesToAllocate);
   7219  1.3       spz     if (temp == NULL)
   7220  1.1      tron       return XML_FALSE;
   7221  1.3       spz     pool->blocks = temp;
   7222  1.1      tron     pool->blocks->size = blockSize;
   7223  1.8      maya     pool->ptr = pool->blocks->s + offsetInsideBlock;
   7224  1.1      tron     pool->start = pool->blocks->s;
   7225  1.1      tron     pool->end = pool->start + blockSize;
   7226  1.8      maya   } else {
   7227  1.1      tron     BLOCK *tem;
   7228  1.1      tron     int blockSize = (int)(pool->end - pool->start);
   7229  1.7  christos     size_t bytesToAllocate;
   7230  1.5       spz 
   7231  1.8      maya     if (blockSize < 0) {
   7232  1.8      maya       /* This condition traps a situation where either more than
   7233  1.8      maya        * INT_MAX bytes have already been allocated (which is prevented
   7234  1.8      maya        * by various pieces of program logic, not least this one, never
   7235  1.8      maya        * mind the unlikelihood of actually having that much memory) or
   7236  1.8      maya        * the pool control fields have been corrupted (which could
   7237  1.8      maya        * conceivably happen in an extremely buggy user handler
   7238  1.8      maya        * function).  Either way it isn't readily testable, so we
   7239  1.8      maya        * exclude it from the coverage statistics.
   7240  1.8      maya        */
   7241  1.8      maya       return XML_FALSE; /* LCOV_EXCL_LINE */
   7242  1.8      maya     }
   7243  1.5       spz 
   7244  1.1      tron     if (blockSize < INIT_BLOCK_SIZE)
   7245  1.1      tron       blockSize = INIT_BLOCK_SIZE;
   7246  1.7  christos     else {
   7247  1.7  christos       /* Detect overflow, avoiding _signed_ overflow undefined behavior */
   7248  1.7  christos       if ((int)((unsigned)blockSize * 2U) < 0) {
   7249  1.7  christos         return XML_FALSE;
   7250  1.7  christos       }
   7251  1.1      tron       blockSize *= 2;
   7252  1.7  christos     }
   7253  1.7  christos 
   7254  1.7  christos     bytesToAllocate = poolBytesToAllocateFor(blockSize);
   7255  1.7  christos     if (bytesToAllocate == 0)
   7256  1.7  christos       return XML_FALSE;
   7257  1.7  christos 
   7258  1.9  christos     tem = pool->mem->malloc_fcn(bytesToAllocate);
   7259  1.8      maya     if (! tem)
   7260  1.1      tron       return XML_FALSE;
   7261  1.1      tron     tem->size = blockSize;
   7262  1.1      tron     tem->next = pool->blocks;
   7263  1.1      tron     pool->blocks = tem;
   7264  1.1      tron     if (pool->ptr != pool->start)
   7265  1.8      maya       memcpy(tem->s, pool->start, (pool->ptr - pool->start) * sizeof(XML_Char));
   7266  1.1      tron     pool->ptr = tem->s + (pool->ptr - pool->start);
   7267  1.1      tron     pool->start = tem->s;
   7268  1.1      tron     pool->end = tem->s + blockSize;
   7269  1.1      tron   }
   7270  1.1      tron   return XML_TRUE;
   7271  1.1      tron }
   7272  1.1      tron 
   7273  1.1      tron static int FASTCALL
   7274  1.8      maya nextScaffoldPart(XML_Parser parser) {
   7275  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   7276  1.8      maya   CONTENT_SCAFFOLD *me;
   7277  1.1      tron   int next;
   7278  1.1      tron 
   7279  1.8      maya   if (! dtd->scaffIndex) {
   7280  1.8      maya     dtd->scaffIndex = (int *)MALLOC(parser, parser->m_groupSize * sizeof(int));
   7281  1.8      maya     if (! dtd->scaffIndex)
   7282  1.1      tron       return -1;
   7283  1.1      tron     dtd->scaffIndex[0] = 0;
   7284  1.1      tron   }
   7285  1.1      tron 
   7286  1.1      tron   if (dtd->scaffCount >= dtd->scaffSize) {
   7287  1.1      tron     CONTENT_SCAFFOLD *temp;
   7288  1.1      tron     if (dtd->scaffold) {
   7289  1.9  christos       /* Detect and prevent integer overflow */
   7290  1.9  christos       if (dtd->scaffSize > UINT_MAX / 2u) {
   7291  1.9  christos         return -1;
   7292  1.9  christos       }
   7293  1.9  christos       /* Detect and prevent integer overflow.
   7294  1.9  christos        * The preprocessor guard addresses the "always false" warning
   7295  1.9  christos        * from -Wtype-limits on platforms where
   7296  1.9  christos        * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   7297  1.9  christos #if UINT_MAX >= SIZE_MAX
   7298  1.9  christos       if (dtd->scaffSize > (size_t)(-1) / 2u / sizeof(CONTENT_SCAFFOLD)) {
   7299  1.9  christos         return -1;
   7300  1.9  christos       }
   7301  1.9  christos #endif
   7302  1.9  christos 
   7303  1.8      maya       temp = (CONTENT_SCAFFOLD *)REALLOC(
   7304  1.8      maya           parser, dtd->scaffold, dtd->scaffSize * 2 * sizeof(CONTENT_SCAFFOLD));
   7305  1.1      tron       if (temp == NULL)
   7306  1.1      tron         return -1;
   7307  1.1      tron       dtd->scaffSize *= 2;
   7308  1.8      maya     } else {
   7309  1.8      maya       temp = (CONTENT_SCAFFOLD *)MALLOC(parser, INIT_SCAFFOLD_ELEMENTS
   7310  1.8      maya                                                     * sizeof(CONTENT_SCAFFOLD));
   7311  1.1      tron       if (temp == NULL)
   7312  1.1      tron         return -1;
   7313  1.1      tron       dtd->scaffSize = INIT_SCAFFOLD_ELEMENTS;
   7314  1.1      tron     }
   7315  1.1      tron     dtd->scaffold = temp;
   7316  1.1      tron   }
   7317  1.1      tron   next = dtd->scaffCount++;
   7318  1.1      tron   me = &dtd->scaffold[next];
   7319  1.1      tron   if (dtd->scaffLevel) {
   7320  1.8      maya     CONTENT_SCAFFOLD *parent
   7321  1.8      maya         = &dtd->scaffold[dtd->scaffIndex[dtd->scaffLevel - 1]];
   7322  1.1      tron     if (parent->lastchild) {
   7323  1.1      tron       dtd->scaffold[parent->lastchild].nextsib = next;
   7324  1.1      tron     }
   7325  1.8      maya     if (! parent->childcnt)
   7326  1.1      tron       parent->firstchild = next;
   7327  1.1      tron     parent->lastchild = next;
   7328  1.1      tron     parent->childcnt++;
   7329  1.1      tron   }
   7330  1.1      tron   me->firstchild = me->lastchild = me->childcnt = me->nextsib = 0;
   7331  1.1      tron   return next;
   7332  1.1      tron }
   7333  1.1      tron 
   7334  1.1      tron static XML_Content *
   7335  1.8      maya build_model(XML_Parser parser) {
   7336  1.9  christos   /* Function build_model transforms the existing parser->m_dtd->scaffold
   7337  1.9  christos    * array of CONTENT_SCAFFOLD tree nodes into a new array of
   7338  1.9  christos    * XML_Content tree nodes followed by a gapless list of zero-terminated
   7339  1.9  christos    * strings. */
   7340  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   7341  1.1      tron   XML_Content *ret;
   7342  1.9  christos   XML_Char *str; /* the current string writing location */
   7343  1.9  christos 
   7344  1.9  christos   /* Detect and prevent integer overflow.
   7345  1.9  christos    * The preprocessor guard addresses the "always false" warning
   7346  1.9  christos    * from -Wtype-limits on platforms where
   7347  1.9  christos    * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */
   7348  1.9  christos #if UINT_MAX >= SIZE_MAX
   7349  1.9  christos   if (dtd->scaffCount > (size_t)(-1) / sizeof(XML_Content)) {
   7350  1.9  christos     return NULL;
   7351  1.9  christos   }
   7352  1.9  christos   if (dtd->contentStringLen > (size_t)(-1) / sizeof(XML_Char)) {
   7353  1.9  christos     return NULL;
   7354  1.9  christos   }
   7355  1.9  christos #endif
   7356  1.9  christos   if (dtd->scaffCount * sizeof(XML_Content)
   7357  1.9  christos       > (size_t)(-1) - dtd->contentStringLen * sizeof(XML_Char)) {
   7358  1.9  christos     return NULL;
   7359  1.9  christos   }
   7360  1.9  christos 
   7361  1.9  christos   const size_t allocsize = (dtd->scaffCount * sizeof(XML_Content)
   7362  1.9  christos                             + (dtd->contentStringLen * sizeof(XML_Char)));
   7363  1.1      tron 
   7364  1.8      maya   ret = (XML_Content *)MALLOC(parser, allocsize);
   7365  1.8      maya   if (! ret)
   7366  1.1      tron     return NULL;
   7367  1.1      tron 
   7368  1.9  christos   /* What follows is an iterative implementation (of what was previously done
   7369  1.9  christos    * recursively in a dedicated function called "build_node".  The old recursive
   7370  1.9  christos    * build_node could be forced into stack exhaustion from input as small as a
   7371  1.9  christos    * few megabyte, and so that was a security issue.  Hence, a function call
   7372  1.9  christos    * stack is avoided now by resolving recursion.)
   7373  1.9  christos    *
   7374  1.9  christos    * The iterative approach works as follows:
   7375  1.9  christos    *
   7376  1.9  christos    * - We have two writing pointers, both walking up the result array; one does
   7377  1.9  christos    *   the work, the other creates "jobs" for its colleague to do, and leads
   7378  1.9  christos    *   the way:
   7379  1.9  christos    *
   7380  1.9  christos    *   - The faster one, pointer jobDest, always leads and writes "what job
   7381  1.9  christos    *     to do" by the other, once they reach that place in the
   7382  1.9  christos    *     array: leader "jobDest" stores the source node array index (relative
   7383  1.9  christos    *     to array dtd->scaffold) in field "numchildren".
   7384  1.9  christos    *
   7385  1.9  christos    *   - The slower one, pointer dest, looks at the value stored in the
   7386  1.9  christos    *     "numchildren" field (which actually holds a source node array index
   7387  1.9  christos    *     at that time) and puts the real data from dtd->scaffold in.
   7388  1.9  christos    *
   7389  1.9  christos    * - Before the loop starts, jobDest writes source array index 0
   7390  1.9  christos    *   (where the root node is located) so that dest will have something to do
   7391  1.9  christos    *   when it starts operation.
   7392  1.9  christos    *
   7393  1.9  christos    * - Whenever nodes with children are encountered, jobDest appends
   7394  1.9  christos    *   them as new jobs, in order.  As a result, tree node siblings are
   7395  1.9  christos    *   adjacent in the resulting array, for example:
   7396  1.9  christos    *
   7397  1.9  christos    *     [0] root, has two children
   7398  1.9  christos    *       [1] first child of 0, has three children
   7399  1.9  christos    *         [3] first child of 1, does not have children
   7400  1.9  christos    *         [4] second child of 1, does not have children
   7401  1.9  christos    *         [5] third child of 1, does not have children
   7402  1.9  christos    *       [2] second child of 0, does not have children
   7403  1.9  christos    *
   7404  1.9  christos    *   Or (the same data) presented in flat array view:
   7405  1.9  christos    *
   7406  1.9  christos    *     [0] root, has two children
   7407  1.9  christos    *
   7408  1.9  christos    *     [1] first child of 0, has three children
   7409  1.9  christos    *     [2] second child of 0, does not have children
   7410  1.9  christos    *
   7411  1.9  christos    *     [3] first child of 1, does not have children
   7412  1.9  christos    *     [4] second child of 1, does not have children
   7413  1.9  christos    *     [5] third child of 1, does not have children
   7414  1.9  christos    *
   7415  1.9  christos    * - The algorithm repeats until all target array indices have been processed.
   7416  1.9  christos    */
   7417  1.9  christos   XML_Content *dest = ret; /* tree node writing location, moves upwards */
   7418  1.9  christos   XML_Content *const destLimit = &ret[dtd->scaffCount];
   7419  1.9  christos   XML_Content *jobDest = ret; /* next free writing location in target array */
   7420  1.9  christos   str = (XML_Char *)&ret[dtd->scaffCount];
   7421  1.9  christos 
   7422  1.9  christos   /* Add the starting job, the root node (index 0) of the source tree  */
   7423  1.9  christos   (jobDest++)->numchildren = 0;
   7424  1.9  christos 
   7425  1.9  christos   for (; dest < destLimit; dest++) {
   7426  1.9  christos     /* Retrieve source tree array index from job storage */
   7427  1.9  christos     const int src_node = (int)dest->numchildren;
   7428  1.9  christos 
   7429  1.9  christos     /* Convert item */
   7430  1.9  christos     dest->type = dtd->scaffold[src_node].type;
   7431  1.9  christos     dest->quant = dtd->scaffold[src_node].quant;
   7432  1.9  christos     if (dest->type == XML_CTYPE_NAME) {
   7433  1.9  christos       const XML_Char *src;
   7434  1.9  christos       dest->name = str;
   7435  1.9  christos       src = dtd->scaffold[src_node].name;
   7436  1.9  christos       for (;;) {
   7437  1.9  christos         *str++ = *src;
   7438  1.9  christos         if (! *src)
   7439  1.9  christos           break;
   7440  1.9  christos         src++;
   7441  1.9  christos       }
   7442  1.9  christos       dest->numchildren = 0;
   7443  1.9  christos       dest->children = NULL;
   7444  1.9  christos     } else {
   7445  1.9  christos       unsigned int i;
   7446  1.9  christos       int cn;
   7447  1.9  christos       dest->name = NULL;
   7448  1.9  christos       dest->numchildren = dtd->scaffold[src_node].childcnt;
   7449  1.9  christos       dest->children = jobDest;
   7450  1.9  christos 
   7451  1.9  christos       /* Append scaffold indices of children to array */
   7452  1.9  christos       for (i = 0, cn = dtd->scaffold[src_node].firstchild;
   7453  1.9  christos            i < dest->numchildren; i++, cn = dtd->scaffold[cn].nextsib)
   7454  1.9  christos         (jobDest++)->numchildren = (unsigned int)cn;
   7455  1.9  christos     }
   7456  1.9  christos   }
   7457  1.1      tron 
   7458  1.1      tron   return ret;
   7459  1.1      tron }
   7460  1.1      tron 
   7461  1.1      tron static ELEMENT_TYPE *
   7462  1.8      maya getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr,
   7463  1.8      maya                const char *end) {
   7464  1.8      maya   DTD *const dtd = parser->m_dtd; /* save one level of indirection */
   7465  1.1      tron   const XML_Char *name = poolStoreString(&dtd->pool, enc, ptr, end);
   7466  1.1      tron   ELEMENT_TYPE *ret;
   7467  1.1      tron 
   7468  1.8      maya   if (! name)
   7469  1.1      tron     return NULL;
   7470  1.8      maya   ret = (ELEMENT_TYPE *)lookup(parser, &dtd->elementTypes, name,
   7471  1.8      maya                                sizeof(ELEMENT_TYPE));
   7472  1.8      maya   if (! ret)
   7473  1.1      tron     return NULL;
   7474  1.1      tron   if (ret->name != name)
   7475  1.1      tron     poolDiscard(&dtd->pool);
   7476  1.1      tron   else {
   7477  1.1      tron     poolFinish(&dtd->pool);
   7478  1.8      maya     if (! setElementTypePrefix(parser, ret))
   7479  1.1      tron       return NULL;
   7480  1.1      tron   }
   7481  1.1      tron   return ret;
   7482  1.1      tron }
   7483  1.8      maya 
   7484  1.8      maya static XML_Char *
   7485  1.8      maya copyString(const XML_Char *s, const XML_Memory_Handling_Suite *memsuite) {
   7486  1.9  christos   size_t charsRequired = 0;
   7487  1.8      maya   XML_Char *result;
   7488  1.8      maya 
   7489  1.8      maya   /* First determine how long the string is */
   7490  1.8      maya   while (s[charsRequired] != 0) {
   7491  1.8      maya     charsRequired++;
   7492  1.8      maya   }
   7493  1.8      maya   /* Include the terminator */
   7494  1.8      maya   charsRequired++;
   7495  1.8      maya 
   7496  1.8      maya   /* Now allocate space for the copy */
   7497  1.8      maya   result = memsuite->malloc_fcn(charsRequired * sizeof(XML_Char));
   7498  1.8      maya   if (result == NULL)
   7499  1.8      maya     return NULL;
   7500  1.8      maya   /* Copy the original into place */
   7501  1.8      maya   memcpy(result, s, charsRequired * sizeof(XML_Char));
   7502  1.8      maya   return result;
   7503  1.8      maya }
   7504  1.9  christos 
   7505  1.9  christos #ifdef XML_DTD
   7506  1.9  christos 
   7507  1.9  christos static float
   7508  1.9  christos accountingGetCurrentAmplification(XML_Parser rootParser) {
   7509  1.9  christos   const XmlBigCount countBytesOutput
   7510  1.9  christos       = rootParser->m_accounting.countBytesDirect
   7511  1.9  christos         + rootParser->m_accounting.countBytesIndirect;
   7512  1.9  christos   const float amplificationFactor
   7513  1.9  christos       = rootParser->m_accounting.countBytesDirect
   7514  1.9  christos             ? (countBytesOutput
   7515  1.9  christos                / (float)(rootParser->m_accounting.countBytesDirect))
   7516  1.9  christos             : 1.0f;
   7517  1.9  christos   assert(! rootParser->m_parentParser);
   7518  1.9  christos   return amplificationFactor;
   7519  1.9  christos }
   7520  1.9  christos 
   7521  1.9  christos static void
   7522  1.9  christos accountingReportStats(XML_Parser originParser, const char *epilog) {
   7523  1.9  christos   const XML_Parser rootParser = getRootParserOf(originParser, NULL);
   7524  1.9  christos   assert(! rootParser->m_parentParser);
   7525  1.9  christos 
   7526  1.9  christos   if (rootParser->m_accounting.debugLevel < 1) {
   7527  1.9  christos     return;
   7528  1.9  christos   }
   7529  1.9  christos 
   7530  1.9  christos   const float amplificationFactor
   7531  1.9  christos       = accountingGetCurrentAmplification(rootParser);
   7532  1.9  christos   fprintf(stderr,
   7533  1.9  christos           "expat: Accounting(%p): Direct " EXPAT_FMT_ULL(
   7534  1.9  christos               "10") ", indirect " EXPAT_FMT_ULL("10") ", amplification %8.2f%s",
   7535  1.9  christos           (void *)rootParser, rootParser->m_accounting.countBytesDirect,
   7536  1.9  christos           rootParser->m_accounting.countBytesIndirect,
   7537  1.9  christos           (double)amplificationFactor, epilog);
   7538  1.9  christos }
   7539  1.9  christos 
   7540  1.9  christos static void
   7541  1.9  christos accountingOnAbort(XML_Parser originParser) {
   7542  1.9  christos   accountingReportStats(originParser, " ABORTING\n");
   7543  1.9  christos }
   7544  1.9  christos 
   7545  1.9  christos static void
   7546  1.9  christos accountingReportDiff(XML_Parser rootParser,
   7547  1.9  christos                      unsigned int levelsAwayFromRootParser, const char *before,
   7548  1.9  christos                      const char *after, ptrdiff_t bytesMore, int source_line,
   7549  1.9  christos                      enum XML_Account account) {
   7550  1.9  christos   assert(! rootParser->m_parentParser);
   7551  1.9  christos 
   7552  1.9  christos   fprintf(stderr,
   7553  1.9  christos           " (+" EXPAT_FMT_PTRDIFF_T("6") " bytes %s|%d, xmlparse.c:%d) %*s\"",
   7554  1.9  christos           bytesMore, (account == XML_ACCOUNT_DIRECT) ? "DIR" : "EXP",
   7555  1.9  christos           levelsAwayFromRootParser, source_line, 10, "");
   7556  1.9  christos 
   7557  1.9  christos   const char ellipis[] = "[..]";
   7558  1.9  christos   const size_t ellipsisLength = sizeof(ellipis) /* because compile-time */ - 1;
   7559  1.9  christos   const unsigned int contextLength = 10;
   7560  1.9  christos 
   7561  1.9  christos   /* Note: Performance is of no concern here */
   7562  1.9  christos   const char *walker = before;
   7563  1.9  christos   if ((rootParser->m_accounting.debugLevel >= 3)
   7564  1.9  christos       || (after - before)
   7565  1.9  christos              <= (ptrdiff_t)(contextLength + ellipsisLength + contextLength)) {
   7566  1.9  christos     for (; walker < after; walker++) {
   7567  1.9  christos       fprintf(stderr, "%s", unsignedCharToPrintable(walker[0]));
   7568  1.9  christos     }
   7569  1.9  christos   } else {
   7570  1.9  christos     for (; walker < before + contextLength; walker++) {
   7571  1.9  christos       fprintf(stderr, "%s", unsignedCharToPrintable(walker[0]));
   7572  1.9  christos     }
   7573  1.9  christos     fprintf(stderr, ellipis);
   7574  1.9  christos     walker = after - contextLength;
   7575  1.9  christos     for (; walker < after; walker++) {
   7576  1.9  christos       fprintf(stderr, "%s", unsignedCharToPrintable(walker[0]));
   7577  1.9  christos     }
   7578  1.9  christos   }
   7579  1.9  christos   fprintf(stderr, "\"\n");
   7580  1.9  christos }
   7581  1.9  christos 
   7582  1.9  christos static XML_Bool
   7583  1.9  christos accountingDiffTolerated(XML_Parser originParser, int tok, const char *before,
   7584  1.9  christos                         const char *after, int source_line,
   7585  1.9  christos                         enum XML_Account account) {
   7586  1.9  christos   /* Note: We need to check the token type *first* to be sure that
   7587  1.9  christos    *       we can even access variable <after>, safely.
   7588  1.9  christos    *       E.g. for XML_TOK_NONE <after> may hold an invalid pointer. */
   7589  1.9  christos   switch (tok) {
   7590  1.9  christos   case XML_TOK_INVALID:
   7591  1.9  christos   case XML_TOK_PARTIAL:
   7592  1.9  christos   case XML_TOK_PARTIAL_CHAR:
   7593  1.9  christos   case XML_TOK_NONE:
   7594  1.9  christos     return XML_TRUE;
   7595  1.9  christos   }
   7596  1.9  christos 
   7597  1.9  christos   if (account == XML_ACCOUNT_NONE)
   7598  1.9  christos     return XML_TRUE; /* because these bytes have been accounted for, already */
   7599  1.9  christos 
   7600  1.9  christos   unsigned int levelsAwayFromRootParser;
   7601  1.9  christos   const XML_Parser rootParser
   7602  1.9  christos       = getRootParserOf(originParser, &levelsAwayFromRootParser);
   7603  1.9  christos   assert(! rootParser->m_parentParser);
   7604  1.9  christos 
   7605  1.9  christos   const int isDirect
   7606  1.9  christos       = (account == XML_ACCOUNT_DIRECT) && (originParser == rootParser);
   7607  1.9  christos   const ptrdiff_t bytesMore = after - before;
   7608  1.9  christos 
   7609  1.9  christos   XmlBigCount *const additionTarget
   7610  1.9  christos       = isDirect ? &rootParser->m_accounting.countBytesDirect
   7611  1.9  christos                  : &rootParser->m_accounting.countBytesIndirect;
   7612  1.9  christos 
   7613  1.9  christos   /* Detect and avoid integer overflow */
   7614  1.9  christos   if (*additionTarget > (XmlBigCount)(-1) - (XmlBigCount)bytesMore)
   7615  1.9  christos     return XML_FALSE;
   7616  1.9  christos   *additionTarget += bytesMore;
   7617  1.9  christos 
   7618  1.9  christos   const XmlBigCount countBytesOutput
   7619  1.9  christos       = rootParser->m_accounting.countBytesDirect
   7620  1.9  christos         + rootParser->m_accounting.countBytesIndirect;
   7621  1.9  christos   const float amplificationFactor
   7622  1.9  christos       = accountingGetCurrentAmplification(rootParser);
   7623  1.9  christos   const XML_Bool tolerated
   7624  1.9  christos       = (countBytesOutput < rootParser->m_accounting.activationThresholdBytes)
   7625  1.9  christos         || (amplificationFactor
   7626  1.9  christos             <= rootParser->m_accounting.maximumAmplificationFactor);
   7627  1.9  christos 
   7628  1.9  christos   if (rootParser->m_accounting.debugLevel >= 2) {
   7629  1.9  christos     accountingReportStats(rootParser, "");
   7630  1.9  christos     accountingReportDiff(rootParser, levelsAwayFromRootParser, before, after,
   7631  1.9  christos                          bytesMore, source_line, account);
   7632  1.9  christos   }
   7633  1.9  christos 
   7634  1.9  christos   return tolerated;
   7635  1.9  christos }
   7636  1.9  christos 
   7637  1.9  christos unsigned long long
   7638  1.9  christos testingAccountingGetCountBytesDirect(XML_Parser parser) {
   7639  1.9  christos   if (! parser)
   7640  1.9  christos     return 0;
   7641  1.9  christos   return parser->m_accounting.countBytesDirect;
   7642  1.9  christos }
   7643  1.9  christos 
   7644  1.9  christos unsigned long long
   7645  1.9  christos testingAccountingGetCountBytesIndirect(XML_Parser parser) {
   7646  1.9  christos   if (! parser)
   7647  1.9  christos     return 0;
   7648  1.9  christos   return parser->m_accounting.countBytesIndirect;
   7649  1.9  christos }
   7650  1.9  christos 
   7651  1.9  christos static void
   7652  1.9  christos entityTrackingReportStats(XML_Parser rootParser, ENTITY *entity,
   7653  1.9  christos                           const char *action, int sourceLine) {
   7654  1.9  christos   assert(! rootParser->m_parentParser);
   7655  1.9  christos   if (rootParser->m_entity_stats.debugLevel < 1)
   7656  1.9  christos     return;
   7657  1.9  christos 
   7658  1.9  christos #  if defined(XML_UNICODE)
   7659  1.9  christos   const char *const entityName = "[..]";
   7660  1.9  christos #  else
   7661  1.9  christos   const char *const entityName = entity->name;
   7662  1.9  christos #  endif
   7663  1.9  christos 
   7664  1.9  christos   fprintf(
   7665  1.9  christos       stderr,
   7666  1.9  christos       "expat: Entities(%p): Count %9d, depth %2d/%2d %*s%s%s; %s length %d (xmlparse.c:%d)\n",
   7667  1.9  christos       (void *)rootParser, rootParser->m_entity_stats.countEverOpened,
   7668  1.9  christos       rootParser->m_entity_stats.currentDepth,
   7669  1.9  christos       rootParser->m_entity_stats.maximumDepthSeen,
   7670  1.9  christos       (rootParser->m_entity_stats.currentDepth - 1) * 2, "",
   7671  1.9  christos       entity->is_param ? "%" : "&", entityName, action, entity->textLen,
   7672  1.9  christos       sourceLine);
   7673  1.9  christos }
   7674  1.9  christos 
   7675  1.9  christos static void
   7676  1.9  christos entityTrackingOnOpen(XML_Parser originParser, ENTITY *entity, int sourceLine) {
   7677  1.9  christos   const XML_Parser rootParser = getRootParserOf(originParser, NULL);
   7678  1.9  christos   assert(! rootParser->m_parentParser);
   7679  1.9  christos 
   7680  1.9  christos   rootParser->m_entity_stats.countEverOpened++;
   7681  1.9  christos   rootParser->m_entity_stats.currentDepth++;
   7682  1.9  christos   if (rootParser->m_entity_stats.currentDepth
   7683  1.9  christos       > rootParser->m_entity_stats.maximumDepthSeen) {
   7684  1.9  christos     rootParser->m_entity_stats.maximumDepthSeen++;
   7685  1.9  christos   }
   7686  1.9  christos 
   7687  1.9  christos   entityTrackingReportStats(rootParser, entity, "OPEN ", sourceLine);
   7688  1.9  christos }
   7689  1.9  christos 
   7690  1.9  christos static void
   7691  1.9  christos entityTrackingOnClose(XML_Parser originParser, ENTITY *entity, int sourceLine) {
   7692  1.9  christos   const XML_Parser rootParser = getRootParserOf(originParser, NULL);
   7693  1.9  christos   assert(! rootParser->m_parentParser);
   7694  1.9  christos 
   7695  1.9  christos   entityTrackingReportStats(rootParser, entity, "CLOSE", sourceLine);
   7696  1.9  christos   rootParser->m_entity_stats.currentDepth--;
   7697  1.9  christos }
   7698  1.9  christos 
   7699  1.9  christos static XML_Parser
   7700  1.9  christos getRootParserOf(XML_Parser parser, unsigned int *outLevelDiff) {
   7701  1.9  christos   XML_Parser rootParser = parser;
   7702  1.9  christos   unsigned int stepsTakenUpwards = 0;
   7703  1.9  christos   while (rootParser->m_parentParser) {
   7704  1.9  christos     rootParser = rootParser->m_parentParser;
   7705  1.9  christos     stepsTakenUpwards++;
   7706  1.9  christos   }
   7707  1.9  christos   assert(! rootParser->m_parentParser);
   7708  1.9  christos   if (outLevelDiff != NULL) {
   7709  1.9  christos     *outLevelDiff = stepsTakenUpwards;
   7710  1.9  christos   }
   7711  1.9  christos   return rootParser;
   7712  1.9  christos }
   7713  1.9  christos 
   7714  1.9  christos const char *
   7715  1.9  christos unsignedCharToPrintable(unsigned char c) {
   7716  1.9  christos   switch (c) {
   7717  1.9  christos   case 0:
   7718  1.9  christos     return "\\0";
   7719  1.9  christos   case 1:
   7720  1.9  christos     return "\\x1";
   7721  1.9  christos   case 2:
   7722  1.9  christos     return "\\x2";
   7723  1.9  christos   case 3:
   7724  1.9  christos     return "\\x3";
   7725  1.9  christos   case 4:
   7726  1.9  christos     return "\\x4";
   7727  1.9  christos   case 5:
   7728  1.9  christos     return "\\x5";
   7729  1.9  christos   case 6:
   7730  1.9  christos     return "\\x6";
   7731  1.9  christos   case 7:
   7732  1.9  christos     return "\\x7";
   7733  1.9  christos   case 8:
   7734  1.9  christos     return "\\x8";
   7735  1.9  christos   case 9:
   7736  1.9  christos     return "\\t";
   7737  1.9  christos   case 10:
   7738  1.9  christos     return "\\n";
   7739  1.9  christos   case 11:
   7740  1.9  christos     return "\\xB";
   7741  1.9  christos   case 12:
   7742  1.9  christos     return "\\xC";
   7743  1.9  christos   case 13:
   7744  1.9  christos     return "\\r";
   7745  1.9  christos   case 14:
   7746  1.9  christos     return "\\xE";
   7747  1.9  christos   case 15:
   7748  1.9  christos     return "\\xF";
   7749  1.9  christos   case 16:
   7750  1.9  christos     return "\\x10";
   7751  1.9  christos   case 17:
   7752  1.9  christos     return "\\x11";
   7753  1.9  christos   case 18:
   7754  1.9  christos     return "\\x12";
   7755  1.9  christos   case 19:
   7756  1.9  christos     return "\\x13";
   7757  1.9  christos   case 20:
   7758  1.9  christos     return "\\x14";
   7759  1.9  christos   case 21:
   7760  1.9  christos     return "\\x15";
   7761  1.9  christos   case 22:
   7762  1.9  christos     return "\\x16";
   7763  1.9  christos   case 23:
   7764  1.9  christos     return "\\x17";
   7765  1.9  christos   case 24:
   7766  1.9  christos     return "\\x18";
   7767  1.9  christos   case 25:
   7768  1.9  christos     return "\\x19";
   7769  1.9  christos   case 26:
   7770  1.9  christos     return "\\x1A";
   7771  1.9  christos   case 27:
   7772  1.9  christos     return "\\x1B";
   7773  1.9  christos   case 28:
   7774  1.9  christos     return "\\x1C";
   7775  1.9  christos   case 29:
   7776  1.9  christos     return "\\x1D";
   7777  1.9  christos   case 30:
   7778  1.9  christos     return "\\x1E";
   7779  1.9  christos   case 31:
   7780  1.9  christos     return "\\x1F";
   7781  1.9  christos   case 32:
   7782  1.9  christos     return " ";
   7783  1.9  christos   case 33:
   7784  1.9  christos     return "!";
   7785  1.9  christos   case 34:
   7786  1.9  christos     return "\\\"";
   7787  1.9  christos   case 35:
   7788  1.9  christos     return "#";
   7789  1.9  christos   case 36:
   7790  1.9  christos     return "$";
   7791  1.9  christos   case 37:
   7792  1.9  christos     return "%";
   7793  1.9  christos   case 38:
   7794  1.9  christos     return "&";
   7795  1.9  christos   case 39:
   7796  1.9  christos     return "'";
   7797  1.9  christos   case 40:
   7798  1.9  christos     return "(";
   7799  1.9  christos   case 41:
   7800  1.9  christos     return ")";
   7801  1.9  christos   case 42:
   7802  1.9  christos     return "*";
   7803  1.9  christos   case 43:
   7804  1.9  christos     return "+";
   7805  1.9  christos   case 44:
   7806  1.9  christos     return ",";
   7807  1.9  christos   case 45:
   7808  1.9  christos     return "-";
   7809  1.9  christos   case 46:
   7810  1.9  christos     return ".";
   7811  1.9  christos   case 47:
   7812  1.9  christos     return "/";
   7813  1.9  christos   case 48:
   7814  1.9  christos     return "0";
   7815  1.9  christos   case 49:
   7816  1.9  christos     return "1";
   7817  1.9  christos   case 50:
   7818  1.9  christos     return "2";
   7819  1.9  christos   case 51:
   7820  1.9  christos     return "3";
   7821  1.9  christos   case 52:
   7822  1.9  christos     return "4";
   7823  1.9  christos   case 53:
   7824  1.9  christos     return "5";
   7825  1.9  christos   case 54:
   7826  1.9  christos     return "6";
   7827  1.9  christos   case 55:
   7828  1.9  christos     return "7";
   7829  1.9  christos   case 56:
   7830  1.9  christos     return "8";
   7831  1.9  christos   case 57:
   7832  1.9  christos     return "9";
   7833  1.9  christos   case 58:
   7834  1.9  christos     return ":";
   7835  1.9  christos   case 59:
   7836  1.9  christos     return ";";
   7837  1.9  christos   case 60:
   7838  1.9  christos     return "<";
   7839  1.9  christos   case 61:
   7840  1.9  christos     return "=";
   7841  1.9  christos   case 62:
   7842  1.9  christos     return ">";
   7843  1.9  christos   case 63:
   7844  1.9  christos     return "?";
   7845  1.9  christos   case 64:
   7846  1.9  christos     return "@";
   7847  1.9  christos   case 65:
   7848  1.9  christos     return "A";
   7849  1.9  christos   case 66:
   7850  1.9  christos     return "B";
   7851  1.9  christos   case 67:
   7852  1.9  christos     return "C";
   7853  1.9  christos   case 68:
   7854  1.9  christos     return "D";
   7855  1.9  christos   case 69:
   7856  1.9  christos     return "E";
   7857  1.9  christos   case 70:
   7858  1.9  christos     return "F";
   7859  1.9  christos   case 71:
   7860  1.9  christos     return "G";
   7861  1.9  christos   case 72:
   7862  1.9  christos     return "H";
   7863  1.9  christos   case 73:
   7864  1.9  christos     return "I";
   7865  1.9  christos   case 74:
   7866  1.9  christos     return "J";
   7867  1.9  christos   case 75:
   7868  1.9  christos     return "K";
   7869  1.9  christos   case 76:
   7870  1.9  christos     return "L";
   7871  1.9  christos   case 77:
   7872  1.9  christos     return "M";
   7873  1.9  christos   case 78:
   7874  1.9  christos     return "N";
   7875  1.9  christos   case 79:
   7876  1.9  christos     return "O";
   7877  1.9  christos   case 80:
   7878  1.9  christos     return "P";
   7879  1.9  christos   case 81:
   7880  1.9  christos     return "Q";
   7881  1.9  christos   case 82:
   7882  1.9  christos     return "R";
   7883  1.9  christos   case 83:
   7884  1.9  christos     return "S";
   7885  1.9  christos   case 84:
   7886  1.9  christos     return "T";
   7887  1.9  christos   case 85:
   7888  1.9  christos     return "U";
   7889  1.9  christos   case 86:
   7890  1.9  christos     return "V";
   7891  1.9  christos   case 87:
   7892  1.9  christos     return "W";
   7893  1.9  christos   case 88:
   7894  1.9  christos     return "X";
   7895  1.9  christos   case 89:
   7896  1.9  christos     return "Y";
   7897  1.9  christos   case 90:
   7898  1.9  christos     return "Z";
   7899  1.9  christos   case 91:
   7900  1.9  christos     return "[";
   7901  1.9  christos   case 92:
   7902  1.9  christos     return "\\\\";
   7903  1.9  christos   case 93:
   7904  1.9  christos     return "]";
   7905  1.9  christos   case 94:
   7906  1.9  christos     return "^";
   7907  1.9  christos   case 95:
   7908  1.9  christos     return "_";
   7909  1.9  christos   case 96:
   7910  1.9  christos     return "`";
   7911  1.9  christos   case 97:
   7912  1.9  christos     return "a";
   7913  1.9  christos   case 98:
   7914  1.9  christos     return "b";
   7915  1.9  christos   case 99:
   7916  1.9  christos     return "c";
   7917  1.9  christos   case 100:
   7918  1.9  christos     return "d";
   7919  1.9  christos   case 101:
   7920  1.9  christos     return "e";
   7921  1.9  christos   case 102:
   7922  1.9  christos     return "f";
   7923  1.9  christos   case 103:
   7924  1.9  christos     return "g";
   7925  1.9  christos   case 104:
   7926  1.9  christos     return "h";
   7927  1.9  christos   case 105:
   7928  1.9  christos     return "i";
   7929  1.9  christos   case 106:
   7930  1.9  christos     return "j";
   7931  1.9  christos   case 107:
   7932  1.9  christos     return "k";
   7933  1.9  christos   case 108:
   7934  1.9  christos     return "l";
   7935  1.9  christos   case 109:
   7936  1.9  christos     return "m";
   7937  1.9  christos   case 110:
   7938  1.9  christos     return "n";
   7939  1.9  christos   case 111:
   7940  1.9  christos     return "o";
   7941  1.9  christos   case 112:
   7942  1.9  christos     return "p";
   7943  1.9  christos   case 113:
   7944  1.9  christos     return "q";
   7945  1.9  christos   case 114:
   7946  1.9  christos     return "r";
   7947  1.9  christos   case 115:
   7948  1.9  christos     return "s";
   7949  1.9  christos   case 116:
   7950  1.9  christos     return "t";
   7951  1.9  christos   case 117:
   7952  1.9  christos     return "u";
   7953  1.9  christos   case 118:
   7954  1.9  christos     return "v";
   7955  1.9  christos   case 119:
   7956  1.9  christos     return "w";
   7957  1.9  christos   case 120:
   7958  1.9  christos     return "x";
   7959  1.9  christos   case 121:
   7960  1.9  christos     return "y";
   7961  1.9  christos   case 122:
   7962  1.9  christos     return "z";
   7963  1.9  christos   case 123:
   7964  1.9  christos     return "{";
   7965  1.9  christos   case 124:
   7966  1.9  christos     return "|";
   7967  1.9  christos   case 125:
   7968  1.9  christos     return "}";
   7969  1.9  christos   case 126:
   7970  1.9  christos     return "~";
   7971  1.9  christos   case 127:
   7972  1.9  christos     return "\\x7F";
   7973  1.9  christos   case 128:
   7974  1.9  christos     return "\\x80";
   7975  1.9  christos   case 129:
   7976  1.9  christos     return "\\x81";
   7977  1.9  christos   case 130:
   7978  1.9  christos     return "\\x82";
   7979  1.9  christos   case 131:
   7980  1.9  christos     return "\\x83";
   7981  1.9  christos   case 132:
   7982  1.9  christos     return "\\x84";
   7983  1.9  christos   case 133:
   7984  1.9  christos     return "\\x85";
   7985  1.9  christos   case 134:
   7986  1.9  christos     return "\\x86";
   7987  1.9  christos   case 135:
   7988  1.9  christos     return "\\x87";
   7989  1.9  christos   case 136:
   7990  1.9  christos     return "\\x88";
   7991  1.9  christos   case 137:
   7992  1.9  christos     return "\\x89";
   7993  1.9  christos   case 138:
   7994  1.9  christos     return "\\x8A";
   7995  1.9  christos   case 139:
   7996  1.9  christos     return "\\x8B";
   7997  1.9  christos   case 140:
   7998  1.9  christos     return "\\x8C";
   7999  1.9  christos   case 141:
   8000  1.9  christos     return "\\x8D";
   8001  1.9  christos   case 142:
   8002  1.9  christos     return "\\x8E";
   8003  1.9  christos   case 143:
   8004  1.9  christos     return "\\x8F";
   8005  1.9  christos   case 144:
   8006  1.9  christos     return "\\x90";
   8007  1.9  christos   case 145:
   8008  1.9  christos     return "\\x91";
   8009  1.9  christos   case 146:
   8010  1.9  christos     return "\\x92";
   8011  1.9  christos   case 147:
   8012  1.9  christos     return "\\x93";
   8013  1.9  christos   case 148:
   8014  1.9  christos     return "\\x94";
   8015  1.9  christos   case 149:
   8016  1.9  christos     return "\\x95";
   8017  1.9  christos   case 150:
   8018  1.9  christos     return "\\x96";
   8019  1.9  christos   case 151:
   8020  1.9  christos     return "\\x97";
   8021  1.9  christos   case 152:
   8022  1.9  christos     return "\\x98";
   8023  1.9  christos   case 153:
   8024  1.9  christos     return "\\x99";
   8025  1.9  christos   case 154:
   8026  1.9  christos     return "\\x9A";
   8027  1.9  christos   case 155:
   8028  1.9  christos     return "\\x9B";
   8029  1.9  christos   case 156:
   8030  1.9  christos     return "\\x9C";
   8031  1.9  christos   case 157:
   8032  1.9  christos     return "\\x9D";
   8033  1.9  christos   case 158:
   8034  1.9  christos     return "\\x9E";
   8035  1.9  christos   case 159:
   8036  1.9  christos     return "\\x9F";
   8037  1.9  christos   case 160:
   8038  1.9  christos     return "\\xA0";
   8039  1.9  christos   case 161:
   8040  1.9  christos     return "\\xA1";
   8041  1.9  christos   case 162:
   8042  1.9  christos     return "\\xA2";
   8043  1.9  christos   case 163:
   8044  1.9  christos     return "\\xA3";
   8045  1.9  christos   case 164:
   8046  1.9  christos     return "\\xA4";
   8047  1.9  christos   case 165:
   8048  1.9  christos     return "\\xA5";
   8049  1.9  christos   case 166:
   8050  1.9  christos     return "\\xA6";
   8051  1.9  christos   case 167:
   8052  1.9  christos     return "\\xA7";
   8053  1.9  christos   case 168:
   8054  1.9  christos     return "\\xA8";
   8055  1.9  christos   case 169:
   8056  1.9  christos     return "\\xA9";
   8057  1.9  christos   case 170:
   8058  1.9  christos     return "\\xAA";
   8059  1.9  christos   case 171:
   8060  1.9  christos     return "\\xAB";
   8061  1.9  christos   case 172:
   8062  1.9  christos     return "\\xAC";
   8063  1.9  christos   case 173:
   8064  1.9  christos     return "\\xAD";
   8065  1.9  christos   case 174:
   8066  1.9  christos     return "\\xAE";
   8067  1.9  christos   case 175:
   8068  1.9  christos     return "\\xAF";
   8069  1.9  christos   case 176:
   8070  1.9  christos     return "\\xB0";
   8071  1.9  christos   case 177:
   8072  1.9  christos     return "\\xB1";
   8073  1.9  christos   case 178:
   8074  1.9  christos     return "\\xB2";
   8075  1.9  christos   case 179:
   8076  1.9  christos     return "\\xB3";
   8077  1.9  christos   case 180:
   8078  1.9  christos     return "\\xB4";
   8079  1.9  christos   case 181:
   8080  1.9  christos     return "\\xB5";
   8081  1.9  christos   case 182:
   8082  1.9  christos     return "\\xB6";
   8083  1.9  christos   case 183:
   8084  1.9  christos     return "\\xB7";
   8085  1.9  christos   case 184:
   8086  1.9  christos     return "\\xB8";
   8087  1.9  christos   case 185:
   8088  1.9  christos     return "\\xB9";
   8089  1.9  christos   case 186:
   8090  1.9  christos     return "\\xBA";
   8091  1.9  christos   case 187:
   8092  1.9  christos     return "\\xBB";
   8093  1.9  christos   case 188:
   8094  1.9  christos     return "\\xBC";
   8095  1.9  christos   case 189:
   8096  1.9  christos     return "\\xBD";
   8097  1.9  christos   case 190:
   8098  1.9  christos     return "\\xBE";
   8099  1.9  christos   case 191:
   8100  1.9  christos     return "\\xBF";
   8101  1.9  christos   case 192:
   8102  1.9  christos     return "\\xC0";
   8103  1.9  christos   case 193:
   8104  1.9  christos     return "\\xC1";
   8105  1.9  christos   case 194:
   8106  1.9  christos     return "\\xC2";
   8107  1.9  christos   case 195:
   8108  1.9  christos     return "\\xC3";
   8109  1.9  christos   case 196:
   8110  1.9  christos     return "\\xC4";
   8111  1.9  christos   case 197:
   8112  1.9  christos     return "\\xC5";
   8113  1.9  christos   case 198:
   8114  1.9  christos     return "\\xC6";
   8115  1.9  christos   case 199:
   8116  1.9  christos     return "\\xC7";
   8117  1.9  christos   case 200:
   8118  1.9  christos     return "\\xC8";
   8119  1.9  christos   case 201:
   8120  1.9  christos     return "\\xC9";
   8121  1.9  christos   case 202:
   8122  1.9  christos     return "\\xCA";
   8123  1.9  christos   case 203:
   8124  1.9  christos     return "\\xCB";
   8125  1.9  christos   case 204:
   8126  1.9  christos     return "\\xCC";
   8127  1.9  christos   case 205:
   8128  1.9  christos     return "\\xCD";
   8129  1.9  christos   case 206:
   8130  1.9  christos     return "\\xCE";
   8131  1.9  christos   case 207:
   8132  1.9  christos     return "\\xCF";
   8133  1.9  christos   case 208:
   8134  1.9  christos     return "\\xD0";
   8135  1.9  christos   case 209:
   8136  1.9  christos     return "\\xD1";
   8137  1.9  christos   case 210:
   8138  1.9  christos     return "\\xD2";
   8139  1.9  christos   case 211:
   8140  1.9  christos     return "\\xD3";
   8141  1.9  christos   case 212:
   8142  1.9  christos     return "\\xD4";
   8143  1.9  christos   case 213:
   8144  1.9  christos     return "\\xD5";
   8145  1.9  christos   case 214:
   8146  1.9  christos     return "\\xD6";
   8147  1.9  christos   case 215:
   8148  1.9  christos     return "\\xD7";
   8149  1.9  christos   case 216:
   8150  1.9  christos     return "\\xD8";
   8151  1.9  christos   case 217:
   8152  1.9  christos     return "\\xD9";
   8153  1.9  christos   case 218:
   8154  1.9  christos     return "\\xDA";
   8155  1.9  christos   case 219:
   8156  1.9  christos     return "\\xDB";
   8157  1.9  christos   case 220:
   8158  1.9  christos     return "\\xDC";
   8159  1.9  christos   case 221:
   8160  1.9  christos     return "\\xDD";
   8161  1.9  christos   case 222:
   8162  1.9  christos     return "\\xDE";
   8163  1.9  christos   case 223:
   8164  1.9  christos     return "\\xDF";
   8165  1.9  christos   case 224:
   8166  1.9  christos     return "\\xE0";
   8167  1.9  christos   case 225:
   8168  1.9  christos     return "\\xE1";
   8169  1.9  christos   case 226:
   8170  1.9  christos     return "\\xE2";
   8171  1.9  christos   case 227:
   8172  1.9  christos     return "\\xE3";
   8173  1.9  christos   case 228:
   8174  1.9  christos     return "\\xE4";
   8175  1.9  christos   case 229:
   8176  1.9  christos     return "\\xE5";
   8177  1.9  christos   case 230:
   8178  1.9  christos     return "\\xE6";
   8179  1.9  christos   case 231:
   8180  1.9  christos     return "\\xE7";
   8181  1.9  christos   case 232:
   8182  1.9  christos     return "\\xE8";
   8183  1.9  christos   case 233:
   8184  1.9  christos     return "\\xE9";
   8185  1.9  christos   case 234:
   8186  1.9  christos     return "\\xEA";
   8187  1.9  christos   case 235:
   8188  1.9  christos     return "\\xEB";
   8189  1.9  christos   case 236:
   8190  1.9  christos     return "\\xEC";
   8191  1.9  christos   case 237:
   8192  1.9  christos     return "\\xED";
   8193  1.9  christos   case 238:
   8194  1.9  christos     return "\\xEE";
   8195  1.9  christos   case 239:
   8196  1.9  christos     return "\\xEF";
   8197  1.9  christos   case 240:
   8198  1.9  christos     return "\\xF0";
   8199  1.9  christos   case 241:
   8200  1.9  christos     return "\\xF1";
   8201  1.9  christos   case 242:
   8202  1.9  christos     return "\\xF2";
   8203  1.9  christos   case 243:
   8204  1.9  christos     return "\\xF3";
   8205  1.9  christos   case 244:
   8206  1.9  christos     return "\\xF4";
   8207  1.9  christos   case 245:
   8208  1.9  christos     return "\\xF5";
   8209  1.9  christos   case 246:
   8210  1.9  christos     return "\\xF6";
   8211  1.9  christos   case 247:
   8212  1.9  christos     return "\\xF7";
   8213  1.9  christos   case 248:
   8214  1.9  christos     return "\\xF8";
   8215  1.9  christos   case 249:
   8216  1.9  christos     return "\\xF9";
   8217  1.9  christos   case 250:
   8218  1.9  christos     return "\\xFA";
   8219  1.9  christos   case 251:
   8220  1.9  christos     return "\\xFB";
   8221  1.9  christos   case 252:
   8222  1.9  christos     return "\\xFC";
   8223  1.9  christos   case 253:
   8224  1.9  christos     return "\\xFD";
   8225  1.9  christos   case 254:
   8226  1.9  christos     return "\\xFE";
   8227  1.9  christos   case 255:
   8228  1.9  christos     return "\\xFF";
   8229  1.9  christos   default:
   8230  1.9  christos     assert(0); /* never gets here */
   8231  1.9  christos     return "dead code";
   8232  1.9  christos   }
   8233  1.9  christos   assert(0); /* never gets here */
   8234  1.9  christos }
   8235  1.9  christos 
   8236  1.9  christos #endif /* XML_DTD */
   8237  1.9  christos 
   8238  1.9  christos static unsigned long
   8239  1.9  christos getDebugLevel(const char *variableName, unsigned long defaultDebugLevel) {
   8240  1.9  christos   const char *const valueOrNull = getenv(variableName);
   8241  1.9  christos   if (valueOrNull == NULL) {
   8242  1.9  christos     return defaultDebugLevel;
   8243  1.9  christos   }
   8244  1.9  christos   const char *const value = valueOrNull;
   8245  1.9  christos 
   8246  1.9  christos   errno = 0;
   8247  1.9  christos   char *afterValue = (char *)value;
   8248  1.9  christos   unsigned long debugLevel = strtoul(value, &afterValue, 10);
   8249  1.9  christos   if ((errno != 0) || (afterValue[0] != '\0')) {
   8250  1.9  christos     errno = 0;
   8251  1.9  christos     return defaultDebugLevel;
   8252  1.9  christos   }
   8253  1.9  christos 
   8254  1.9  christos   return debugLevel;
   8255  1.9  christos }
   8256