xref: /openbsd-src/usr.bin/mandoc/roff.c (revision ae3cb403620ab940fbaabb3055fac045a63d56b7)
1 /*	$OpenBSD: roff.c,v 1.196 2017/07/14 17:16:13 schwarze Exp $ */
2 /*
3  * Copyright (c) 2008-2012, 2014 Kristaps Dzonsons <kristaps@bsd.lv>
4  * Copyright (c) 2010-2015, 2017 Ingo Schwarze <schwarze@openbsd.org>
5  *
6  * Permission to use, copy, modify, and distribute this software for any
7  * purpose with or without fee is hereby granted, provided that the above
8  * copyright notice and this permission notice appear in all copies.
9  *
10  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHORS DISCLAIM ALL WARRANTIES
11  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
12  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR
13  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
14  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17  */
18 #include <sys/types.h>
19 
20 #include <assert.h>
21 #include <ctype.h>
22 #include <limits.h>
23 #include <stddef.h>
24 #include <stdint.h>
25 #include <stdio.h>
26 #include <stdlib.h>
27 #include <string.h>
28 
29 #include "mandoc.h"
30 #include "mandoc_aux.h"
31 #include "mandoc_ohash.h"
32 #include "roff.h"
33 #include "libmandoc.h"
34 #include "roff_int.h"
35 #include "libroff.h"
36 
37 /* Maximum number of string expansions per line, to break infinite loops. */
38 #define	EXPAND_LIMIT	1000
39 
40 /* Types of definitions of macros and strings. */
41 #define	ROFFDEF_USER	(1 << 1)  /* User-defined. */
42 #define	ROFFDEF_PRE	(1 << 2)  /* Predefined. */
43 #define	ROFFDEF_REN	(1 << 3)  /* Renamed standard macro. */
44 #define	ROFFDEF_STD	(1 << 4)  /* mdoc(7) or man(7) macro. */
45 #define	ROFFDEF_ANY	(ROFFDEF_USER | ROFFDEF_PRE | \
46 			 ROFFDEF_REN | ROFFDEF_STD)
47 
48 /* --- data types --------------------------------------------------------- */
49 
50 /*
51  * An incredibly-simple string buffer.
52  */
53 struct	roffstr {
54 	char		*p; /* nil-terminated buffer */
55 	size_t		 sz; /* saved strlen(p) */
56 };
57 
58 /*
59  * A key-value roffstr pair as part of a singly-linked list.
60  */
61 struct	roffkv {
62 	struct roffstr	 key;
63 	struct roffstr	 val;
64 	struct roffkv	*next; /* next in list */
65 };
66 
67 /*
68  * A single number register as part of a singly-linked list.
69  */
70 struct	roffreg {
71 	struct roffstr	 key;
72 	int		 val;
73 	struct roffreg	*next;
74 };
75 
76 /*
77  * Association of request and macro names with token IDs.
78  */
79 struct	roffreq {
80 	enum roff_tok	 tok;
81 	char		 name[];
82 };
83 
84 struct	roff {
85 	struct mparse	*parse; /* parse point */
86 	struct roff_man	*man; /* mdoc or man parser */
87 	struct roffnode	*last; /* leaf of stack */
88 	int		*rstack; /* stack of inverted `ie' values */
89 	struct ohash	*reqtab; /* request lookup table */
90 	struct roffreg	*regtab; /* number registers */
91 	struct roffkv	*strtab; /* user-defined strings & macros */
92 	struct roffkv	*rentab; /* renamed strings & macros */
93 	struct roffkv	*xmbtab; /* multi-byte trans table (`tr') */
94 	struct roffstr	*xtab; /* single-byte trans table (`tr') */
95 	const char	*current_string; /* value of last called user macro */
96 	struct tbl_node	*first_tbl; /* first table parsed */
97 	struct tbl_node	*last_tbl; /* last table parsed */
98 	struct tbl_node	*tbl; /* current table being parsed */
99 	struct eqn_node	*last_eqn; /* equation parser */
100 	struct eqn_node	*eqn; /* active equation parser */
101 	int		 eqn_inline; /* current equation is inline */
102 	int		 options; /* parse options */
103 	int		 rstacksz; /* current size limit of rstack */
104 	int		 rstackpos; /* position in rstack */
105 	int		 format; /* current file in mdoc or man format */
106 	int		 argc; /* number of args of the last macro */
107 	char		 control; /* control character */
108 	char		 escape; /* escape character */
109 };
110 
111 struct	roffnode {
112 	enum roff_tok	 tok; /* type of node */
113 	struct roffnode	*parent; /* up one in stack */
114 	int		 line; /* parse line */
115 	int		 col; /* parse col */
116 	char		*name; /* node name, e.g. macro name */
117 	char		*end; /* end-rules: custom token */
118 	int		 endspan; /* end-rules: next-line or infty */
119 	int		 rule; /* current evaluation rule */
120 };
121 
122 #define	ROFF_ARGS	 struct roff *r, /* parse ctx */ \
123 			 enum roff_tok tok, /* tok of macro */ \
124 			 struct buf *buf, /* input buffer */ \
125 			 int ln, /* parse line */ \
126 			 int ppos, /* original pos in buffer */ \
127 			 int pos, /* current pos in buffer */ \
128 			 int *offs /* reset offset of buffer data */
129 
130 typedef	enum rofferr (*roffproc)(ROFF_ARGS);
131 
132 struct	roffmac {
133 	roffproc	 proc; /* process new macro */
134 	roffproc	 text; /* process as child text of macro */
135 	roffproc	 sub; /* process as child of macro */
136 	int		 flags;
137 #define	ROFFMAC_STRUCT	(1 << 0) /* always interpret */
138 };
139 
140 struct	predef {
141 	const char	*name; /* predefined input name */
142 	const char	*str; /* replacement symbol */
143 };
144 
145 #define	PREDEF(__name, __str) \
146 	{ (__name), (__str) },
147 
148 /* --- function prototypes ------------------------------------------------ */
149 
150 static	void		 roffnode_cleanscope(struct roff *);
151 static	void		 roffnode_pop(struct roff *);
152 static	void		 roffnode_push(struct roff *, enum roff_tok,
153 				const char *, int, int);
154 static	void		 roff_addtbl(struct roff_man *, struct tbl_node *);
155 static	enum rofferr	 roff_als(ROFF_ARGS);
156 static	enum rofferr	 roff_block(ROFF_ARGS);
157 static	enum rofferr	 roff_block_text(ROFF_ARGS);
158 static	enum rofferr	 roff_block_sub(ROFF_ARGS);
159 static	enum rofferr	 roff_br(ROFF_ARGS);
160 static	enum rofferr	 roff_cblock(ROFF_ARGS);
161 static	enum rofferr	 roff_cc(ROFF_ARGS);
162 static	void		 roff_ccond(struct roff *, int, int);
163 static	enum rofferr	 roff_cond(ROFF_ARGS);
164 static	enum rofferr	 roff_cond_text(ROFF_ARGS);
165 static	enum rofferr	 roff_cond_sub(ROFF_ARGS);
166 static	enum rofferr	 roff_ds(ROFF_ARGS);
167 static	enum rofferr	 roff_ec(ROFF_ARGS);
168 static	enum rofferr	 roff_eo(ROFF_ARGS);
169 static	enum rofferr	 roff_eqndelim(struct roff *, struct buf *, int);
170 static	int		 roff_evalcond(struct roff *r, int, char *, int *);
171 static	int		 roff_evalnum(struct roff *, int,
172 				const char *, int *, int *, int);
173 static	int		 roff_evalpar(struct roff *, int,
174 				const char *, int *, int *, int);
175 static	int		 roff_evalstrcond(const char *, int *);
176 static	void		 roff_free1(struct roff *);
177 static	void		 roff_freereg(struct roffreg *);
178 static	void		 roff_freestr(struct roffkv *);
179 static	size_t		 roff_getname(struct roff *, char **, int, int);
180 static	int		 roff_getnum(const char *, int *, int *, int);
181 static	int		 roff_getop(const char *, int *, char *);
182 static	int		 roff_getregn(const struct roff *,
183 				const char *, size_t);
184 static	int		 roff_getregro(const struct roff *,
185 				const char *name);
186 static	const char	*roff_getstrn(const struct roff *,
187 				const char *, size_t, int *);
188 static	int		 roff_hasregn(const struct roff *,
189 				const char *, size_t);
190 static	enum rofferr	 roff_insec(ROFF_ARGS);
191 static	enum rofferr	 roff_it(ROFF_ARGS);
192 static	enum rofferr	 roff_line_ignore(ROFF_ARGS);
193 static	void		 roff_man_alloc1(struct roff_man *);
194 static	void		 roff_man_free1(struct roff_man *);
195 static	enum rofferr	 roff_manyarg(ROFF_ARGS);
196 static	enum rofferr	 roff_nr(ROFF_ARGS);
197 static	enum rofferr	 roff_onearg(ROFF_ARGS);
198 static	enum roff_tok	 roff_parse(struct roff *, char *, int *,
199 				int, int);
200 static	enum rofferr	 roff_parsetext(struct roff *, struct buf *,
201 				int, int *);
202 static	enum rofferr	 roff_renamed(ROFF_ARGS);
203 static	enum rofferr	 roff_res(struct roff *, struct buf *, int, int);
204 static	enum rofferr	 roff_rm(ROFF_ARGS);
205 static	enum rofferr	 roff_rn(ROFF_ARGS);
206 static	enum rofferr	 roff_rr(ROFF_ARGS);
207 static	void		 roff_setstr(struct roff *,
208 				const char *, const char *, int);
209 static	void		 roff_setstrn(struct roffkv **, const char *,
210 				size_t, const char *, size_t, int);
211 static	enum rofferr	 roff_so(ROFF_ARGS);
212 static	enum rofferr	 roff_tr(ROFF_ARGS);
213 static	enum rofferr	 roff_Dd(ROFF_ARGS);
214 static	enum rofferr	 roff_TE(ROFF_ARGS);
215 static	enum rofferr	 roff_TS(ROFF_ARGS);
216 static	enum rofferr	 roff_EQ(ROFF_ARGS);
217 static	enum rofferr	 roff_EN(ROFF_ARGS);
218 static	enum rofferr	 roff_T_(ROFF_ARGS);
219 static	enum rofferr	 roff_unsupp(ROFF_ARGS);
220 static	enum rofferr	 roff_userdef(ROFF_ARGS);
221 
222 /* --- constant data ------------------------------------------------------ */
223 
224 #define	ROFFNUM_SCALE	(1 << 0)  /* Honour scaling in roff_getnum(). */
225 #define	ROFFNUM_WHITE	(1 << 1)  /* Skip whitespace in roff_evalnum(). */
226 
227 const char *__roff_name[MAN_MAX + 1] = {
228 	"br",		"ce",		"ft",		"ll",
229 	"mc",		"po",		"rj",		"sp",
230 	"ta",		"ti",		NULL,
231 	"ab",		"ad",		"af",		"aln",
232 	"als",		"am",		"am1",		"ami",
233 	"ami1",		"as",		"as1",		"asciify",
234 	"backtrace",	"bd",		"bleedat",	"blm",
235         "box",		"boxa",		"bp",		"BP",
236 	"break",	"breakchar",	"brnl",		"brp",
237 	"brpnl",	"c2",		"cc",
238 	"cf",		"cflags",	"ch",		"char",
239 	"chop",		"class",	"close",	"CL",
240 	"color",	"composite",	"continue",	"cp",
241 	"cropat",	"cs",		"cu",		"da",
242 	"dch",		"Dd",		"de",		"de1",
243 	"defcolor",	"dei",		"dei1",		"device",
244 	"devicem",	"di",		"do",		"ds",
245 	"ds1",		"dwh",		"dt",		"ec",
246 	"ecr",		"ecs",		"el",		"em",
247 	"EN",		"eo",		"EP",		"EQ",
248 	"errprint",	"ev",		"evc",		"ex",
249 	"fallback",	"fam",		"fc",		"fchar",
250 	"fcolor",	"fdeferlig",	"feature",	"fkern",
251 	"fl",		"flig",		"fp",		"fps",
252 	"fschar",	"fspacewidth",	"fspecial",	"ftr",
253 	"fzoom",	"gcolor",	"hc",		"hcode",
254 	"hidechar",	"hla",		"hlm",		"hpf",
255 	"hpfa",		"hpfcode",	"hw",		"hy",
256 	"hylang",	"hylen",	"hym",		"hypp",
257 	"hys",		"ie",		"if",		"ig",
258 	"index",	"it",		"itc",		"IX",
259 	"kern",		"kernafter",	"kernbefore",	"kernpair",
260 	"lc",		"lc_ctype",	"lds",		"length",
261 	"letadj",	"lf",		"lg",		"lhang",
262 	"linetabs",	"lnr",		"lnrf",		"lpfx",
263 	"ls",		"lsm",		"lt",
264 	"mediasize",	"minss",	"mk",		"mso",
265 	"na",		"ne",		"nh",		"nhychar",
266 	"nm",		"nn",		"nop",		"nr",
267 	"nrf",		"nroff",	"ns",		"nx",
268 	"open",		"opena",	"os",		"output",
269 	"padj",		"papersize",	"pc",		"pev",
270 	"pi",		"PI",		"pl",		"pm",
271 	"pn",		"pnr",		"ps",
272 	"psbb",		"pshape",	"pso",		"ptr",
273 	"pvs",		"rchar",	"rd",		"recursionlimit",
274 	"return",	"rfschar",	"rhang",
275 	"rm",		"rn",		"rnn",		"rr",
276 	"rs",		"rt",		"schar",	"sentchar",
277 	"shc",		"shift",	"sizes",	"so",
278 	"spacewidth",	"special",	"spreadwarn",	"ss",
279 	"sty",		"substring",	"sv",		"sy",
280 	"T&",		"tc",		"TE",
281 	"TH",		"tkf",		"tl",
282 	"tm",		"tm1",		"tmc",		"tr",
283 	"track",	"transchar",	"trf",		"trimat",
284 	"trin",		"trnt",		"troff",	"TS",
285 	"uf",		"ul",		"unformat",	"unwatch",
286 	"unwatchn",	"vpt",		"vs",		"warn",
287 	"warnscale",	"watch",	"watchlength",	"watchn",
288 	"wh",		"while",	"write",	"writec",
289 	"writem",	"xflag",	".",		NULL,
290 	NULL,		"text",
291 	"Dd",		"Dt",		"Os",		"Sh",
292 	"Ss",		"Pp",		"D1",		"Dl",
293 	"Bd",		"Ed",		"Bl",		"El",
294 	"It",		"Ad",		"An",		"Ap",
295 	"Ar",		"Cd",		"Cm",		"Dv",
296 	"Er",		"Ev",		"Ex",		"Fa",
297 	"Fd",		"Fl",		"Fn",		"Ft",
298 	"Ic",		"In",		"Li",		"Nd",
299 	"Nm",		"Op",		"Ot",		"Pa",
300 	"Rv",		"St",		"Va",		"Vt",
301 	"Xr",		"%A",		"%B",		"%D",
302 	"%I",		"%J",		"%N",		"%O",
303 	"%P",		"%R",		"%T",		"%V",
304 	"Ac",		"Ao",		"Aq",		"At",
305 	"Bc",		"Bf",		"Bo",		"Bq",
306 	"Bsx",		"Bx",		"Db",		"Dc",
307 	"Do",		"Dq",		"Ec",		"Ef",
308 	"Em",		"Eo",		"Fx",		"Ms",
309 	"No",		"Ns",		"Nx",		"Ox",
310 	"Pc",		"Pf",		"Po",		"Pq",
311 	"Qc",		"Ql",		"Qo",		"Qq",
312 	"Re",		"Rs",		"Sc",		"So",
313 	"Sq",		"Sm",		"Sx",		"Sy",
314 	"Tn",		"Ux",		"Xc",		"Xo",
315 	"Fo",		"Fc",		"Oo",		"Oc",
316 	"Bk",		"Ek",		"Bt",		"Hf",
317 	"Fr",		"Ud",		"Lb",		"Lp",
318 	"Lk",		"Mt",		"Brq",		"Bro",
319 	"Brc",		"%C",		"Es",		"En",
320 	"Dx",		"%Q",		"%U",		"Ta",
321 	NULL,
322 	"TH",		"SH",		"SS",		"TP",
323 	"LP",		"PP",		"P",		"IP",
324 	"HP",		"SM",		"SB",		"BI",
325 	"IB",		"BR",		"RB",		"R",
326 	"B",		"I",		"IR",		"RI",
327 	"nf",		"fi",
328 	"RE",		"RS",		"DT",		"UC",
329 	"PD",		"AT",		"in",
330 	"OP",		"EX",		"EE",		"UR",
331 	"UE",		"MT",		"ME",		NULL
332 };
333 const	char *const *roff_name = __roff_name;
334 
335 static	struct roffmac	 roffs[TOKEN_NONE] = {
336 	{ roff_br, NULL, NULL, 0 },  /* br */
337 	{ roff_onearg, NULL, NULL, 0 },  /* ce */
338 	{ roff_onearg, NULL, NULL, 0 },  /* ft */
339 	{ roff_onearg, NULL, NULL, 0 },  /* ll */
340 	{ roff_onearg, NULL, NULL, 0 },  /* mc */
341 	{ roff_onearg, NULL, NULL, 0 },  /* po */
342 	{ roff_onearg, NULL, NULL, 0 },  /* rj */
343 	{ roff_onearg, NULL, NULL, 0 },  /* sp */
344 	{ roff_manyarg, NULL, NULL, 0 },  /* ta */
345 	{ roff_onearg, NULL, NULL, 0 },  /* ti */
346 	{ NULL, NULL, NULL, 0 },  /* ROFF_MAX */
347 	{ roff_unsupp, NULL, NULL, 0 },  /* ab */
348 	{ roff_line_ignore, NULL, NULL, 0 },  /* ad */
349 	{ roff_line_ignore, NULL, NULL, 0 },  /* af */
350 	{ roff_unsupp, NULL, NULL, 0 },  /* aln */
351 	{ roff_als, NULL, NULL, 0 },  /* als */
352 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* am */
353 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* am1 */
354 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* ami */
355 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* ami1 */
356 	{ roff_ds, NULL, NULL, 0 },  /* as */
357 	{ roff_ds, NULL, NULL, 0 },  /* as1 */
358 	{ roff_unsupp, NULL, NULL, 0 },  /* asciify */
359 	{ roff_line_ignore, NULL, NULL, 0 },  /* backtrace */
360 	{ roff_line_ignore, NULL, NULL, 0 },  /* bd */
361 	{ roff_line_ignore, NULL, NULL, 0 },  /* bleedat */
362 	{ roff_unsupp, NULL, NULL, 0 },  /* blm */
363 	{ roff_unsupp, NULL, NULL, 0 },  /* box */
364 	{ roff_unsupp, NULL, NULL, 0 },  /* boxa */
365 	{ roff_line_ignore, NULL, NULL, 0 },  /* bp */
366 	{ roff_unsupp, NULL, NULL, 0 },  /* BP */
367 	{ roff_unsupp, NULL, NULL, 0 },  /* break */
368 	{ roff_line_ignore, NULL, NULL, 0 },  /* breakchar */
369 	{ roff_line_ignore, NULL, NULL, 0 },  /* brnl */
370 	{ roff_br, NULL, NULL, 0 },  /* brp */
371 	{ roff_line_ignore, NULL, NULL, 0 },  /* brpnl */
372 	{ roff_unsupp, NULL, NULL, 0 },  /* c2 */
373 	{ roff_cc, NULL, NULL, 0 },  /* cc */
374 	{ roff_insec, NULL, NULL, 0 },  /* cf */
375 	{ roff_line_ignore, NULL, NULL, 0 },  /* cflags */
376 	{ roff_line_ignore, NULL, NULL, 0 },  /* ch */
377 	{ roff_unsupp, NULL, NULL, 0 },  /* char */
378 	{ roff_unsupp, NULL, NULL, 0 },  /* chop */
379 	{ roff_line_ignore, NULL, NULL, 0 },  /* class */
380 	{ roff_insec, NULL, NULL, 0 },  /* close */
381 	{ roff_unsupp, NULL, NULL, 0 },  /* CL */
382 	{ roff_line_ignore, NULL, NULL, 0 },  /* color */
383 	{ roff_unsupp, NULL, NULL, 0 },  /* composite */
384 	{ roff_unsupp, NULL, NULL, 0 },  /* continue */
385 	{ roff_line_ignore, NULL, NULL, 0 },  /* cp */
386 	{ roff_line_ignore, NULL, NULL, 0 },  /* cropat */
387 	{ roff_line_ignore, NULL, NULL, 0 },  /* cs */
388 	{ roff_line_ignore, NULL, NULL, 0 },  /* cu */
389 	{ roff_unsupp, NULL, NULL, 0 },  /* da */
390 	{ roff_unsupp, NULL, NULL, 0 },  /* dch */
391 	{ roff_Dd, NULL, NULL, 0 },  /* Dd */
392 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* de */
393 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* de1 */
394 	{ roff_line_ignore, NULL, NULL, 0 },  /* defcolor */
395 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* dei */
396 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* dei1 */
397 	{ roff_unsupp, NULL, NULL, 0 },  /* device */
398 	{ roff_unsupp, NULL, NULL, 0 },  /* devicem */
399 	{ roff_unsupp, NULL, NULL, 0 },  /* di */
400 	{ roff_unsupp, NULL, NULL, 0 },  /* do */
401 	{ roff_ds, NULL, NULL, 0 },  /* ds */
402 	{ roff_ds, NULL, NULL, 0 },  /* ds1 */
403 	{ roff_unsupp, NULL, NULL, 0 },  /* dwh */
404 	{ roff_unsupp, NULL, NULL, 0 },  /* dt */
405 	{ roff_ec, NULL, NULL, 0 },  /* ec */
406 	{ roff_unsupp, NULL, NULL, 0 },  /* ecr */
407 	{ roff_unsupp, NULL, NULL, 0 },  /* ecs */
408 	{ roff_cond, roff_cond_text, roff_cond_sub, ROFFMAC_STRUCT },  /* el */
409 	{ roff_unsupp, NULL, NULL, 0 },  /* em */
410 	{ roff_EN, NULL, NULL, 0 },  /* EN */
411 	{ roff_eo, NULL, NULL, 0 },  /* eo */
412 	{ roff_unsupp, NULL, NULL, 0 },  /* EP */
413 	{ roff_EQ, NULL, NULL, 0 },  /* EQ */
414 	{ roff_line_ignore, NULL, NULL, 0 },  /* errprint */
415 	{ roff_unsupp, NULL, NULL, 0 },  /* ev */
416 	{ roff_unsupp, NULL, NULL, 0 },  /* evc */
417 	{ roff_unsupp, NULL, NULL, 0 },  /* ex */
418 	{ roff_line_ignore, NULL, NULL, 0 },  /* fallback */
419 	{ roff_line_ignore, NULL, NULL, 0 },  /* fam */
420 	{ roff_unsupp, NULL, NULL, 0 },  /* fc */
421 	{ roff_unsupp, NULL, NULL, 0 },  /* fchar */
422 	{ roff_line_ignore, NULL, NULL, 0 },  /* fcolor */
423 	{ roff_line_ignore, NULL, NULL, 0 },  /* fdeferlig */
424 	{ roff_line_ignore, NULL, NULL, 0 },  /* feature */
425 	{ roff_line_ignore, NULL, NULL, 0 },  /* fkern */
426 	{ roff_line_ignore, NULL, NULL, 0 },  /* fl */
427 	{ roff_line_ignore, NULL, NULL, 0 },  /* flig */
428 	{ roff_line_ignore, NULL, NULL, 0 },  /* fp */
429 	{ roff_line_ignore, NULL, NULL, 0 },  /* fps */
430 	{ roff_unsupp, NULL, NULL, 0 },  /* fschar */
431 	{ roff_line_ignore, NULL, NULL, 0 },  /* fspacewidth */
432 	{ roff_line_ignore, NULL, NULL, 0 },  /* fspecial */
433 	{ roff_line_ignore, NULL, NULL, 0 },  /* ftr */
434 	{ roff_line_ignore, NULL, NULL, 0 },  /* fzoom */
435 	{ roff_line_ignore, NULL, NULL, 0 },  /* gcolor */
436 	{ roff_line_ignore, NULL, NULL, 0 },  /* hc */
437 	{ roff_line_ignore, NULL, NULL, 0 },  /* hcode */
438 	{ roff_line_ignore, NULL, NULL, 0 },  /* hidechar */
439 	{ roff_line_ignore, NULL, NULL, 0 },  /* hla */
440 	{ roff_line_ignore, NULL, NULL, 0 },  /* hlm */
441 	{ roff_line_ignore, NULL, NULL, 0 },  /* hpf */
442 	{ roff_line_ignore, NULL, NULL, 0 },  /* hpfa */
443 	{ roff_line_ignore, NULL, NULL, 0 },  /* hpfcode */
444 	{ roff_line_ignore, NULL, NULL, 0 },  /* hw */
445 	{ roff_line_ignore, NULL, NULL, 0 },  /* hy */
446 	{ roff_line_ignore, NULL, NULL, 0 },  /* hylang */
447 	{ roff_line_ignore, NULL, NULL, 0 },  /* hylen */
448 	{ roff_line_ignore, NULL, NULL, 0 },  /* hym */
449 	{ roff_line_ignore, NULL, NULL, 0 },  /* hypp */
450 	{ roff_line_ignore, NULL, NULL, 0 },  /* hys */
451 	{ roff_cond, roff_cond_text, roff_cond_sub, ROFFMAC_STRUCT },  /* ie */
452 	{ roff_cond, roff_cond_text, roff_cond_sub, ROFFMAC_STRUCT },  /* if */
453 	{ roff_block, roff_block_text, roff_block_sub, 0 },  /* ig */
454 	{ roff_unsupp, NULL, NULL, 0 },  /* index */
455 	{ roff_it, NULL, NULL, 0 },  /* it */
456 	{ roff_unsupp, NULL, NULL, 0 },  /* itc */
457 	{ roff_line_ignore, NULL, NULL, 0 },  /* IX */
458 	{ roff_line_ignore, NULL, NULL, 0 },  /* kern */
459 	{ roff_line_ignore, NULL, NULL, 0 },  /* kernafter */
460 	{ roff_line_ignore, NULL, NULL, 0 },  /* kernbefore */
461 	{ roff_line_ignore, NULL, NULL, 0 },  /* kernpair */
462 	{ roff_unsupp, NULL, NULL, 0 },  /* lc */
463 	{ roff_unsupp, NULL, NULL, 0 },  /* lc_ctype */
464 	{ roff_unsupp, NULL, NULL, 0 },  /* lds */
465 	{ roff_unsupp, NULL, NULL, 0 },  /* length */
466 	{ roff_line_ignore, NULL, NULL, 0 },  /* letadj */
467 	{ roff_insec, NULL, NULL, 0 },  /* lf */
468 	{ roff_line_ignore, NULL, NULL, 0 },  /* lg */
469 	{ roff_line_ignore, NULL, NULL, 0 },  /* lhang */
470 	{ roff_unsupp, NULL, NULL, 0 },  /* linetabs */
471 	{ roff_unsupp, NULL, NULL, 0 },  /* lnr */
472 	{ roff_unsupp, NULL, NULL, 0 },  /* lnrf */
473 	{ roff_unsupp, NULL, NULL, 0 },  /* lpfx */
474 	{ roff_line_ignore, NULL, NULL, 0 },  /* ls */
475 	{ roff_unsupp, NULL, NULL, 0 },  /* lsm */
476 	{ roff_line_ignore, NULL, NULL, 0 },  /* lt */
477 	{ roff_line_ignore, NULL, NULL, 0 },  /* mediasize */
478 	{ roff_line_ignore, NULL, NULL, 0 },  /* minss */
479 	{ roff_line_ignore, NULL, NULL, 0 },  /* mk */
480 	{ roff_insec, NULL, NULL, 0 },  /* mso */
481 	{ roff_line_ignore, NULL, NULL, 0 },  /* na */
482 	{ roff_line_ignore, NULL, NULL, 0 },  /* ne */
483 	{ roff_line_ignore, NULL, NULL, 0 },  /* nh */
484 	{ roff_line_ignore, NULL, NULL, 0 },  /* nhychar */
485 	{ roff_unsupp, NULL, NULL, 0 },  /* nm */
486 	{ roff_unsupp, NULL, NULL, 0 },  /* nn */
487 	{ roff_unsupp, NULL, NULL, 0 },  /* nop */
488 	{ roff_nr, NULL, NULL, 0 },  /* nr */
489 	{ roff_unsupp, NULL, NULL, 0 },  /* nrf */
490 	{ roff_line_ignore, NULL, NULL, 0 },  /* nroff */
491 	{ roff_line_ignore, NULL, NULL, 0 },  /* ns */
492 	{ roff_insec, NULL, NULL, 0 },  /* nx */
493 	{ roff_insec, NULL, NULL, 0 },  /* open */
494 	{ roff_insec, NULL, NULL, 0 },  /* opena */
495 	{ roff_line_ignore, NULL, NULL, 0 },  /* os */
496 	{ roff_unsupp, NULL, NULL, 0 },  /* output */
497 	{ roff_line_ignore, NULL, NULL, 0 },  /* padj */
498 	{ roff_line_ignore, NULL, NULL, 0 },  /* papersize */
499 	{ roff_line_ignore, NULL, NULL, 0 },  /* pc */
500 	{ roff_line_ignore, NULL, NULL, 0 },  /* pev */
501 	{ roff_insec, NULL, NULL, 0 },  /* pi */
502 	{ roff_unsupp, NULL, NULL, 0 },  /* PI */
503 	{ roff_line_ignore, NULL, NULL, 0 },  /* pl */
504 	{ roff_line_ignore, NULL, NULL, 0 },  /* pm */
505 	{ roff_line_ignore, NULL, NULL, 0 },  /* pn */
506 	{ roff_line_ignore, NULL, NULL, 0 },  /* pnr */
507 	{ roff_line_ignore, NULL, NULL, 0 },  /* ps */
508 	{ roff_unsupp, NULL, NULL, 0 },  /* psbb */
509 	{ roff_unsupp, NULL, NULL, 0 },  /* pshape */
510 	{ roff_insec, NULL, NULL, 0 },  /* pso */
511 	{ roff_line_ignore, NULL, NULL, 0 },  /* ptr */
512 	{ roff_line_ignore, NULL, NULL, 0 },  /* pvs */
513 	{ roff_unsupp, NULL, NULL, 0 },  /* rchar */
514 	{ roff_line_ignore, NULL, NULL, 0 },  /* rd */
515 	{ roff_line_ignore, NULL, NULL, 0 },  /* recursionlimit */
516 	{ roff_unsupp, NULL, NULL, 0 },  /* return */
517 	{ roff_unsupp, NULL, NULL, 0 },  /* rfschar */
518 	{ roff_line_ignore, NULL, NULL, 0 },  /* rhang */
519 	{ roff_rm, NULL, NULL, 0 },  /* rm */
520 	{ roff_rn, NULL, NULL, 0 },  /* rn */
521 	{ roff_unsupp, NULL, NULL, 0 },  /* rnn */
522 	{ roff_rr, NULL, NULL, 0 },  /* rr */
523 	{ roff_line_ignore, NULL, NULL, 0 },  /* rs */
524 	{ roff_line_ignore, NULL, NULL, 0 },  /* rt */
525 	{ roff_unsupp, NULL, NULL, 0 },  /* schar */
526 	{ roff_line_ignore, NULL, NULL, 0 },  /* sentchar */
527 	{ roff_line_ignore, NULL, NULL, 0 },  /* shc */
528 	{ roff_unsupp, NULL, NULL, 0 },  /* shift */
529 	{ roff_line_ignore, NULL, NULL, 0 },  /* sizes */
530 	{ roff_so, NULL, NULL, 0 },  /* so */
531 	{ roff_line_ignore, NULL, NULL, 0 },  /* spacewidth */
532 	{ roff_line_ignore, NULL, NULL, 0 },  /* special */
533 	{ roff_line_ignore, NULL, NULL, 0 },  /* spreadwarn */
534 	{ roff_line_ignore, NULL, NULL, 0 },  /* ss */
535 	{ roff_line_ignore, NULL, NULL, 0 },  /* sty */
536 	{ roff_unsupp, NULL, NULL, 0 },  /* substring */
537 	{ roff_line_ignore, NULL, NULL, 0 },  /* sv */
538 	{ roff_insec, NULL, NULL, 0 },  /* sy */
539 	{ roff_T_, NULL, NULL, 0 },  /* T& */
540 	{ roff_unsupp, NULL, NULL, 0 },  /* tc */
541 	{ roff_TE, NULL, NULL, 0 },  /* TE */
542 	{ roff_Dd, NULL, NULL, 0 },  /* TH */
543 	{ roff_line_ignore, NULL, NULL, 0 },  /* tkf */
544 	{ roff_unsupp, NULL, NULL, 0 },  /* tl */
545 	{ roff_line_ignore, NULL, NULL, 0 },  /* tm */
546 	{ roff_line_ignore, NULL, NULL, 0 },  /* tm1 */
547 	{ roff_line_ignore, NULL, NULL, 0 },  /* tmc */
548 	{ roff_tr, NULL, NULL, 0 },  /* tr */
549 	{ roff_line_ignore, NULL, NULL, 0 },  /* track */
550 	{ roff_line_ignore, NULL, NULL, 0 },  /* transchar */
551 	{ roff_insec, NULL, NULL, 0 },  /* trf */
552 	{ roff_line_ignore, NULL, NULL, 0 },  /* trimat */
553 	{ roff_unsupp, NULL, NULL, 0 },  /* trin */
554 	{ roff_unsupp, NULL, NULL, 0 },  /* trnt */
555 	{ roff_line_ignore, NULL, NULL, 0 },  /* troff */
556 	{ roff_TS, NULL, NULL, 0 },  /* TS */
557 	{ roff_line_ignore, NULL, NULL, 0 },  /* uf */
558 	{ roff_line_ignore, NULL, NULL, 0 },  /* ul */
559 	{ roff_unsupp, NULL, NULL, 0 },  /* unformat */
560 	{ roff_line_ignore, NULL, NULL, 0 },  /* unwatch */
561 	{ roff_line_ignore, NULL, NULL, 0 },  /* unwatchn */
562 	{ roff_line_ignore, NULL, NULL, 0 },  /* vpt */
563 	{ roff_line_ignore, NULL, NULL, 0 },  /* vs */
564 	{ roff_line_ignore, NULL, NULL, 0 },  /* warn */
565 	{ roff_line_ignore, NULL, NULL, 0 },  /* warnscale */
566 	{ roff_line_ignore, NULL, NULL, 0 },  /* watch */
567 	{ roff_line_ignore, NULL, NULL, 0 },  /* watchlength */
568 	{ roff_line_ignore, NULL, NULL, 0 },  /* watchn */
569 	{ roff_unsupp, NULL, NULL, 0 },  /* wh */
570 	{ roff_unsupp, NULL, NULL, 0 },  /* while */
571 	{ roff_insec, NULL, NULL, 0 },  /* write */
572 	{ roff_insec, NULL, NULL, 0 },  /* writec */
573 	{ roff_insec, NULL, NULL, 0 },  /* writem */
574 	{ roff_line_ignore, NULL, NULL, 0 },  /* xflag */
575 	{ roff_cblock, NULL, NULL, 0 },  /* . */
576 	{ roff_renamed, NULL, NULL, 0 },
577 	{ roff_userdef, NULL, NULL, 0 }
578 };
579 
580 /* Array of injected predefined strings. */
581 #define	PREDEFS_MAX	 38
582 static	const struct predef predefs[PREDEFS_MAX] = {
583 #include "predefs.in"
584 };
585 
586 static	int	 roffce_lines;	/* number of input lines to center */
587 static	struct roff_node *roffce_node;  /* active request */
588 static	int	 roffit_lines;  /* number of lines to delay */
589 static	char	*roffit_macro;  /* nil-terminated macro line */
590 
591 
592 /* --- request table ------------------------------------------------------ */
593 
594 struct ohash *
595 roffhash_alloc(enum roff_tok mintok, enum roff_tok maxtok)
596 {
597 	struct ohash	*htab;
598 	struct roffreq	*req;
599 	enum roff_tok	 tok;
600 	size_t		 sz;
601 	unsigned int	 slot;
602 
603 	htab = mandoc_malloc(sizeof(*htab));
604 	mandoc_ohash_init(htab, 8, offsetof(struct roffreq, name));
605 
606 	for (tok = mintok; tok < maxtok; tok++) {
607 		if (roff_name[tok] == NULL)
608 			continue;
609 		sz = strlen(roff_name[tok]);
610 		req = mandoc_malloc(sizeof(*req) + sz + 1);
611 		req->tok = tok;
612 		memcpy(req->name, roff_name[tok], sz + 1);
613 		slot = ohash_qlookup(htab, req->name);
614 		ohash_insert(htab, slot, req);
615 	}
616 	return htab;
617 }
618 
619 void
620 roffhash_free(struct ohash *htab)
621 {
622 	struct roffreq	*req;
623 	unsigned int	 slot;
624 
625 	if (htab == NULL)
626 		return;
627 	for (req = ohash_first(htab, &slot); req != NULL;
628 	     req = ohash_next(htab, &slot))
629 		free(req);
630 	ohash_delete(htab);
631 	free(htab);
632 }
633 
634 enum roff_tok
635 roffhash_find(struct ohash *htab, const char *name, size_t sz)
636 {
637 	struct roffreq	*req;
638 	const char	*end;
639 
640 	if (sz) {
641 		end = name + sz;
642 		req = ohash_find(htab, ohash_qlookupi(htab, name, &end));
643 	} else
644 		req = ohash_find(htab, ohash_qlookup(htab, name));
645 	return req == NULL ? TOKEN_NONE : req->tok;
646 }
647 
648 /* --- stack of request blocks -------------------------------------------- */
649 
650 /*
651  * Pop the current node off of the stack of roff instructions currently
652  * pending.
653  */
654 static void
655 roffnode_pop(struct roff *r)
656 {
657 	struct roffnode	*p;
658 
659 	assert(r->last);
660 	p = r->last;
661 
662 	r->last = r->last->parent;
663 	free(p->name);
664 	free(p->end);
665 	free(p);
666 }
667 
668 /*
669  * Push a roff node onto the instruction stack.  This must later be
670  * removed with roffnode_pop().
671  */
672 static void
673 roffnode_push(struct roff *r, enum roff_tok tok, const char *name,
674 		int line, int col)
675 {
676 	struct roffnode	*p;
677 
678 	p = mandoc_calloc(1, sizeof(struct roffnode));
679 	p->tok = tok;
680 	if (name)
681 		p->name = mandoc_strdup(name);
682 	p->parent = r->last;
683 	p->line = line;
684 	p->col = col;
685 	p->rule = p->parent ? p->parent->rule : 0;
686 
687 	r->last = p;
688 }
689 
690 /* --- roff parser state data management ---------------------------------- */
691 
692 static void
693 roff_free1(struct roff *r)
694 {
695 	struct tbl_node	*tbl;
696 	int		 i;
697 
698 	while (NULL != (tbl = r->first_tbl)) {
699 		r->first_tbl = tbl->next;
700 		tbl_free(tbl);
701 	}
702 	r->first_tbl = r->last_tbl = r->tbl = NULL;
703 
704 	if (r->last_eqn != NULL)
705 		eqn_free(r->last_eqn);
706 	r->last_eqn = r->eqn = NULL;
707 
708 	while (r->last)
709 		roffnode_pop(r);
710 
711 	free (r->rstack);
712 	r->rstack = NULL;
713 	r->rstacksz = 0;
714 	r->rstackpos = -1;
715 
716 	roff_freereg(r->regtab);
717 	r->regtab = NULL;
718 
719 	roff_freestr(r->strtab);
720 	roff_freestr(r->rentab);
721 	roff_freestr(r->xmbtab);
722 	r->strtab = r->rentab = r->xmbtab = NULL;
723 
724 	if (r->xtab)
725 		for (i = 0; i < 128; i++)
726 			free(r->xtab[i].p);
727 	free(r->xtab);
728 	r->xtab = NULL;
729 }
730 
731 void
732 roff_reset(struct roff *r)
733 {
734 	roff_free1(r);
735 	r->format = r->options & (MPARSE_MDOC | MPARSE_MAN);
736 	r->control = '\0';
737 	r->escape = '\\';
738 	roffce_lines = 0;
739 	roffce_node = NULL;
740 	roffit_lines = 0;
741 	roffit_macro = NULL;
742 }
743 
744 void
745 roff_free(struct roff *r)
746 {
747 	roff_free1(r);
748 	roffhash_free(r->reqtab);
749 	free(r);
750 }
751 
752 struct roff *
753 roff_alloc(struct mparse *parse, int options)
754 {
755 	struct roff	*r;
756 
757 	r = mandoc_calloc(1, sizeof(struct roff));
758 	r->parse = parse;
759 	r->reqtab = roffhash_alloc(0, ROFF_USERDEF);
760 	r->options = options;
761 	r->format = options & (MPARSE_MDOC | MPARSE_MAN);
762 	r->rstackpos = -1;
763 	r->escape = '\\';
764 	return r;
765 }
766 
767 /* --- syntax tree state data management ---------------------------------- */
768 
769 static void
770 roff_man_free1(struct roff_man *man)
771 {
772 
773 	if (man->first != NULL)
774 		roff_node_delete(man, man->first);
775 	free(man->meta.msec);
776 	free(man->meta.vol);
777 	free(man->meta.os);
778 	free(man->meta.arch);
779 	free(man->meta.title);
780 	free(man->meta.name);
781 	free(man->meta.date);
782 }
783 
784 static void
785 roff_man_alloc1(struct roff_man *man)
786 {
787 
788 	memset(&man->meta, 0, sizeof(man->meta));
789 	man->first = mandoc_calloc(1, sizeof(*man->first));
790 	man->first->type = ROFFT_ROOT;
791 	man->last = man->first;
792 	man->last_es = NULL;
793 	man->flags = 0;
794 	man->macroset = MACROSET_NONE;
795 	man->lastsec = man->lastnamed = SEC_NONE;
796 	man->next = ROFF_NEXT_CHILD;
797 }
798 
799 void
800 roff_man_reset(struct roff_man *man)
801 {
802 
803 	roff_man_free1(man);
804 	roff_man_alloc1(man);
805 }
806 
807 void
808 roff_man_free(struct roff_man *man)
809 {
810 
811 	roff_man_free1(man);
812 	free(man);
813 }
814 
815 struct roff_man *
816 roff_man_alloc(struct roff *roff, struct mparse *parse,
817 	const char *os_s, int quick)
818 {
819 	struct roff_man *man;
820 
821 	man = mandoc_calloc(1, sizeof(*man));
822 	man->parse = parse;
823 	man->roff = roff;
824 	man->os_s = os_s;
825 	man->quick = quick;
826 	roff_man_alloc1(man);
827 	roff->man = man;
828 	return man;
829 }
830 
831 /* --- syntax tree handling ----------------------------------------------- */
832 
833 struct roff_node *
834 roff_node_alloc(struct roff_man *man, int line, int pos,
835 	enum roff_type type, int tok)
836 {
837 	struct roff_node	*n;
838 
839 	n = mandoc_calloc(1, sizeof(*n));
840 	n->line = line;
841 	n->pos = pos;
842 	n->tok = tok;
843 	n->type = type;
844 	n->sec = man->lastsec;
845 
846 	if (man->flags & MDOC_SYNOPSIS)
847 		n->flags |= NODE_SYNPRETTY;
848 	else
849 		n->flags &= ~NODE_SYNPRETTY;
850 	if (man->flags & MDOC_NEWLINE)
851 		n->flags |= NODE_LINE;
852 	man->flags &= ~MDOC_NEWLINE;
853 
854 	return n;
855 }
856 
857 void
858 roff_node_append(struct roff_man *man, struct roff_node *n)
859 {
860 
861 	switch (man->next) {
862 	case ROFF_NEXT_SIBLING:
863 		if (man->last->next != NULL) {
864 			n->next = man->last->next;
865 			man->last->next->prev = n;
866 		} else
867 			man->last->parent->last = n;
868 		man->last->next = n;
869 		n->prev = man->last;
870 		n->parent = man->last->parent;
871 		break;
872 	case ROFF_NEXT_CHILD:
873 		if (man->last->child != NULL) {
874 			n->next = man->last->child;
875 			man->last->child->prev = n;
876 		} else
877 			man->last->last = n;
878 		man->last->child = n;
879 		n->parent = man->last;
880 		break;
881 	default:
882 		abort();
883 	}
884 	man->last = n;
885 
886 	switch (n->type) {
887 	case ROFFT_HEAD:
888 		n->parent->head = n;
889 		break;
890 	case ROFFT_BODY:
891 		if (n->end != ENDBODY_NOT)
892 			return;
893 		n->parent->body = n;
894 		break;
895 	case ROFFT_TAIL:
896 		n->parent->tail = n;
897 		break;
898 	default:
899 		return;
900 	}
901 
902 	/*
903 	 * Copy over the normalised-data pointer of our parent.  Not
904 	 * everybody has one, but copying a null pointer is fine.
905 	 */
906 
907 	n->norm = n->parent->norm;
908 	assert(n->parent->type == ROFFT_BLOCK);
909 }
910 
911 void
912 roff_word_alloc(struct roff_man *man, int line, int pos, const char *word)
913 {
914 	struct roff_node	*n;
915 
916 	n = roff_node_alloc(man, line, pos, ROFFT_TEXT, TOKEN_NONE);
917 	n->string = roff_strdup(man->roff, word);
918 	roff_node_append(man, n);
919 	n->flags |= NODE_VALID | NODE_ENDED;
920 	man->next = ROFF_NEXT_SIBLING;
921 }
922 
923 void
924 roff_word_append(struct roff_man *man, const char *word)
925 {
926 	struct roff_node	*n;
927 	char			*addstr, *newstr;
928 
929 	n = man->last;
930 	addstr = roff_strdup(man->roff, word);
931 	mandoc_asprintf(&newstr, "%s %s", n->string, addstr);
932 	free(addstr);
933 	free(n->string);
934 	n->string = newstr;
935 	man->next = ROFF_NEXT_SIBLING;
936 }
937 
938 void
939 roff_elem_alloc(struct roff_man *man, int line, int pos, int tok)
940 {
941 	struct roff_node	*n;
942 
943 	n = roff_node_alloc(man, line, pos, ROFFT_ELEM, tok);
944 	roff_node_append(man, n);
945 	man->next = ROFF_NEXT_CHILD;
946 }
947 
948 struct roff_node *
949 roff_block_alloc(struct roff_man *man, int line, int pos, int tok)
950 {
951 	struct roff_node	*n;
952 
953 	n = roff_node_alloc(man, line, pos, ROFFT_BLOCK, tok);
954 	roff_node_append(man, n);
955 	man->next = ROFF_NEXT_CHILD;
956 	return n;
957 }
958 
959 struct roff_node *
960 roff_head_alloc(struct roff_man *man, int line, int pos, int tok)
961 {
962 	struct roff_node	*n;
963 
964 	n = roff_node_alloc(man, line, pos, ROFFT_HEAD, tok);
965 	roff_node_append(man, n);
966 	man->next = ROFF_NEXT_CHILD;
967 	return n;
968 }
969 
970 struct roff_node *
971 roff_body_alloc(struct roff_man *man, int line, int pos, int tok)
972 {
973 	struct roff_node	*n;
974 
975 	n = roff_node_alloc(man, line, pos, ROFFT_BODY, tok);
976 	roff_node_append(man, n);
977 	man->next = ROFF_NEXT_CHILD;
978 	return n;
979 }
980 
981 static void
982 roff_addtbl(struct roff_man *man, struct tbl_node *tbl)
983 {
984 	struct roff_node	*n;
985 	const struct tbl_span	*span;
986 
987 	if (man->macroset == MACROSET_MAN)
988 		man_breakscope(man, ROFF_TS);
989 	while ((span = tbl_span(tbl)) != NULL) {
990 		n = roff_node_alloc(man, tbl->line, 0, ROFFT_TBL, TOKEN_NONE);
991 		n->span = span;
992 		roff_node_append(man, n);
993 		n->flags |= NODE_VALID | NODE_ENDED;
994 		man->next = ROFF_NEXT_SIBLING;
995 	}
996 }
997 
998 void
999 roff_node_unlink(struct roff_man *man, struct roff_node *n)
1000 {
1001 
1002 	/* Adjust siblings. */
1003 
1004 	if (n->prev)
1005 		n->prev->next = n->next;
1006 	if (n->next)
1007 		n->next->prev = n->prev;
1008 
1009 	/* Adjust parent. */
1010 
1011 	if (n->parent != NULL) {
1012 		if (n->parent->child == n)
1013 			n->parent->child = n->next;
1014 		if (n->parent->last == n)
1015 			n->parent->last = n->prev;
1016 	}
1017 
1018 	/* Adjust parse point. */
1019 
1020 	if (man == NULL)
1021 		return;
1022 	if (man->last == n) {
1023 		if (n->prev == NULL) {
1024 			man->last = n->parent;
1025 			man->next = ROFF_NEXT_CHILD;
1026 		} else {
1027 			man->last = n->prev;
1028 			man->next = ROFF_NEXT_SIBLING;
1029 		}
1030 	}
1031 	if (man->first == n)
1032 		man->first = NULL;
1033 }
1034 
1035 void
1036 roff_node_free(struct roff_node *n)
1037 {
1038 
1039 	if (n->args != NULL)
1040 		mdoc_argv_free(n->args);
1041 	if (n->type == ROFFT_BLOCK || n->type == ROFFT_ELEM)
1042 		free(n->norm);
1043 	if (n->eqn != NULL)
1044 		eqn_box_free(n->eqn);
1045 	free(n->string);
1046 	free(n);
1047 }
1048 
1049 void
1050 roff_node_delete(struct roff_man *man, struct roff_node *n)
1051 {
1052 
1053 	while (n->child != NULL)
1054 		roff_node_delete(man, n->child);
1055 	roff_node_unlink(man, n);
1056 	roff_node_free(n);
1057 }
1058 
1059 void
1060 deroff(char **dest, const struct roff_node *n)
1061 {
1062 	char	*cp;
1063 	size_t	 sz;
1064 
1065 	if (n->type != ROFFT_TEXT) {
1066 		for (n = n->child; n != NULL; n = n->next)
1067 			deroff(dest, n);
1068 		return;
1069 	}
1070 
1071 	/* Skip leading whitespace. */
1072 
1073 	for (cp = n->string; *cp != '\0'; cp++) {
1074 		if (cp[0] == '\\' && cp[1] != '\0' &&
1075 		    strchr(" %&0^|~", cp[1]) != NULL)
1076 			cp++;
1077 		else if ( ! isspace((unsigned char)*cp))
1078 			break;
1079 	}
1080 
1081 	/* Skip trailing backslash. */
1082 
1083 	sz = strlen(cp);
1084 	if (sz > 0 && cp[sz - 1] == '\\')
1085 		sz--;
1086 
1087 	/* Skip trailing whitespace. */
1088 
1089 	for (; sz; sz--)
1090 		if ( ! isspace((unsigned char)cp[sz-1]))
1091 			break;
1092 
1093 	/* Skip empty strings. */
1094 
1095 	if (sz == 0)
1096 		return;
1097 
1098 	if (*dest == NULL) {
1099 		*dest = mandoc_strndup(cp, sz);
1100 		return;
1101 	}
1102 
1103 	mandoc_asprintf(&cp, "%s %*s", *dest, (int)sz, cp);
1104 	free(*dest);
1105 	*dest = cp;
1106 }
1107 
1108 /* --- main functions of the roff parser ---------------------------------- */
1109 
1110 /*
1111  * In the current line, expand escape sequences that tend to get
1112  * used in numerical expressions and conditional requests.
1113  * Also check the syntax of the remaining escape sequences.
1114  */
1115 static enum rofferr
1116 roff_res(struct roff *r, struct buf *buf, int ln, int pos)
1117 {
1118 	char		 ubuf[24]; /* buffer to print the number */
1119 	const char	*start;	/* start of the string to process */
1120 	char		*stesc;	/* start of an escape sequence ('\\') */
1121 	const char	*stnam;	/* start of the name, after "[(*" */
1122 	const char	*cp;	/* end of the name, e.g. before ']' */
1123 	const char	*res;	/* the string to be substituted */
1124 	char		*nbuf;	/* new buffer to copy buf->buf to */
1125 	size_t		 maxl;  /* expected length of the escape name */
1126 	size_t		 naml;	/* actual length of the escape name */
1127 	enum mandoc_esc	 esc;	/* type of the escape sequence */
1128 	int		 inaml;	/* length returned from mandoc_escape() */
1129 	int		 expand_count;	/* to avoid infinite loops */
1130 	int		 npos;	/* position in numeric expression */
1131 	int		 arg_complete; /* argument not interrupted by eol */
1132 	int		 done;	/* no more input available */
1133 	int		 deftype; /* type of definition to paste */
1134 	int		 rcsid;	/* kind of RCS id seen */
1135 	char		 term;	/* character terminating the escape */
1136 
1137 	/* Search forward for comments. */
1138 
1139 	done = 0;
1140 	start = buf->buf + pos;
1141 	for (stesc = buf->buf + pos; *stesc != '\0'; stesc++) {
1142 		if (stesc[0] != r->escape || stesc[1] == '\0')
1143 			continue;
1144 		stesc++;
1145 		if (*stesc != '"' && *stesc != '#')
1146 			continue;
1147 
1148 		/* Comment found, look for RCS id. */
1149 
1150 		rcsid = 0;
1151 		if ((cp = strstr(stesc, "$" "OpenBSD")) != NULL) {
1152 			rcsid = 1 << MANDOC_OS_OPENBSD;
1153 			cp += 8;
1154 		} else if ((cp = strstr(stesc, "$" "NetBSD")) != NULL) {
1155 			rcsid = 1 << MANDOC_OS_NETBSD;
1156 			cp += 7;
1157 		}
1158 		if (cp != NULL &&
1159 		    isalnum((unsigned char)*cp) == 0 &&
1160 		    strchr(cp, '$') != NULL) {
1161 			if (r->man->meta.rcsids & rcsid)
1162 				mandoc_msg(MANDOCERR_RCS_REP, r->parse,
1163 				    ln, stesc + 1 - buf->buf, stesc + 1);
1164 			r->man->meta.rcsids |= rcsid;
1165 		}
1166 
1167 		/* Handle trailing whitespace. */
1168 
1169 		cp = strchr(stesc--, '\0') - 1;
1170 		if (*cp == '\n') {
1171 			done = 1;
1172 			cp--;
1173 		}
1174 		if (*cp == ' ' || *cp == '\t')
1175 			mandoc_msg(MANDOCERR_SPACE_EOL, r->parse,
1176 			    ln, cp - buf->buf, NULL);
1177 		while (stesc > start && stesc[-1] == ' ')
1178 			stesc--;
1179 		*stesc = '\0';
1180 		break;
1181 	}
1182 	if (stesc == start)
1183 		return ROFF_CONT;
1184 	stesc--;
1185 
1186 	/* Notice the end of the input. */
1187 
1188 	if (*stesc == '\n') {
1189 		*stesc-- = '\0';
1190 		done = 1;
1191 	}
1192 
1193 	expand_count = 0;
1194 	while (stesc >= start) {
1195 
1196 		/* Search backwards for the next backslash. */
1197 
1198 		if (*stesc != r->escape) {
1199 			if (*stesc == '\\') {
1200 				*stesc = '\0';
1201 				buf->sz = mandoc_asprintf(&nbuf, "%s\\e%s",
1202 				    buf->buf, stesc + 1) + 1;
1203 				start = nbuf + pos;
1204 				stesc = nbuf + (stesc - buf->buf);
1205 				free(buf->buf);
1206 				buf->buf = nbuf;
1207 			}
1208 			stesc--;
1209 			continue;
1210 		}
1211 
1212 		/* If it is escaped, skip it. */
1213 
1214 		for (cp = stesc - 1; cp >= start; cp--)
1215 			if (*cp != r->escape)
1216 				break;
1217 
1218 		if ((stesc - cp) % 2 == 0) {
1219 			while (stesc > cp)
1220 				*stesc-- = '\\';
1221 			continue;
1222 		} else if (stesc[1] != '\0') {
1223 			*stesc = '\\';
1224 		} else {
1225 			*stesc-- = '\0';
1226 			if (done)
1227 				continue;
1228 			else
1229 				return ROFF_APPEND;
1230 		}
1231 
1232 		/* Decide whether to expand or to check only. */
1233 
1234 		term = '\0';
1235 		cp = stesc + 1;
1236 		switch (*cp) {
1237 		case '*':
1238 			res = NULL;
1239 			break;
1240 		case 'B':
1241 		case 'w':
1242 			term = cp[1];
1243 			/* FALLTHROUGH */
1244 		case 'n':
1245 			res = ubuf;
1246 			break;
1247 		default:
1248 			esc = mandoc_escape(&cp, &stnam, &inaml);
1249 			if (esc == ESCAPE_ERROR ||
1250 			    (esc == ESCAPE_SPECIAL &&
1251 			     mchars_spec2cp(stnam, inaml) < 0))
1252 				mandoc_vmsg(MANDOCERR_ESC_BAD,
1253 				    r->parse, ln, (int)(stesc - buf->buf),
1254 				    "%.*s", (int)(cp - stesc), stesc);
1255 			stesc--;
1256 			continue;
1257 		}
1258 
1259 		if (EXPAND_LIMIT < ++expand_count) {
1260 			mandoc_msg(MANDOCERR_ROFFLOOP, r->parse,
1261 			    ln, (int)(stesc - buf->buf), NULL);
1262 			return ROFF_IGN;
1263 		}
1264 
1265 		/*
1266 		 * The third character decides the length
1267 		 * of the name of the string or register.
1268 		 * Save a pointer to the name.
1269 		 */
1270 
1271 		if (term == '\0') {
1272 			switch (*++cp) {
1273 			case '\0':
1274 				maxl = 0;
1275 				break;
1276 			case '(':
1277 				cp++;
1278 				maxl = 2;
1279 				break;
1280 			case '[':
1281 				cp++;
1282 				term = ']';
1283 				maxl = 0;
1284 				break;
1285 			default:
1286 				maxl = 1;
1287 				break;
1288 			}
1289 		} else {
1290 			cp += 2;
1291 			maxl = 0;
1292 		}
1293 		stnam = cp;
1294 
1295 		/* Advance to the end of the name. */
1296 
1297 		naml = 0;
1298 		arg_complete = 1;
1299 		while (maxl == 0 || naml < maxl) {
1300 			if (*cp == '\0') {
1301 				mandoc_msg(MANDOCERR_ESC_BAD, r->parse,
1302 				    ln, (int)(stesc - buf->buf), stesc);
1303 				arg_complete = 0;
1304 				break;
1305 			}
1306 			if (maxl == 0 && *cp == term) {
1307 				cp++;
1308 				break;
1309 			}
1310 			if (*cp++ != '\\' || stesc[1] != 'w') {
1311 				naml++;
1312 				continue;
1313 			}
1314 			switch (mandoc_escape(&cp, NULL, NULL)) {
1315 			case ESCAPE_SPECIAL:
1316 			case ESCAPE_UNICODE:
1317 			case ESCAPE_NUMBERED:
1318 			case ESCAPE_OVERSTRIKE:
1319 				naml++;
1320 				break;
1321 			default:
1322 				break;
1323 			}
1324 		}
1325 
1326 		/*
1327 		 * Retrieve the replacement string; if it is
1328 		 * undefined, resume searching for escapes.
1329 		 */
1330 
1331 		switch (stesc[1]) {
1332 		case '*':
1333 			if (arg_complete) {
1334 				deftype = ROFFDEF_USER | ROFFDEF_PRE;
1335 				res = roff_getstrn(r, stnam, naml, &deftype);
1336 			}
1337 			break;
1338 		case 'B':
1339 			npos = 0;
1340 			ubuf[0] = arg_complete &&
1341 			    roff_evalnum(r, ln, stnam, &npos,
1342 			      NULL, ROFFNUM_SCALE) &&
1343 			    stnam + npos + 1 == cp ? '1' : '0';
1344 			ubuf[1] = '\0';
1345 			break;
1346 		case 'n':
1347 			if (arg_complete)
1348 				(void)snprintf(ubuf, sizeof(ubuf), "%d",
1349 				    roff_getregn(r, stnam, naml));
1350 			else
1351 				ubuf[0] = '\0';
1352 			break;
1353 		case 'w':
1354 			/* use even incomplete args */
1355 			(void)snprintf(ubuf, sizeof(ubuf), "%d",
1356 			    24 * (int)naml);
1357 			break;
1358 		}
1359 
1360 		if (res == NULL) {
1361 			mandoc_vmsg(MANDOCERR_STR_UNDEF,
1362 			    r->parse, ln, (int)(stesc - buf->buf),
1363 			    "%.*s", (int)naml, stnam);
1364 			res = "";
1365 		} else if (buf->sz + strlen(res) > SHRT_MAX) {
1366 			mandoc_msg(MANDOCERR_ROFFLOOP, r->parse,
1367 			    ln, (int)(stesc - buf->buf), NULL);
1368 			return ROFF_IGN;
1369 		}
1370 
1371 		/* Replace the escape sequence by the string. */
1372 
1373 		*stesc = '\0';
1374 		buf->sz = mandoc_asprintf(&nbuf, "%s%s%s",
1375 		    buf->buf, res, cp) + 1;
1376 
1377 		/* Prepare for the next replacement. */
1378 
1379 		start = nbuf + pos;
1380 		stesc = nbuf + (stesc - buf->buf) + strlen(res);
1381 		free(buf->buf);
1382 		buf->buf = nbuf;
1383 	}
1384 	return ROFF_CONT;
1385 }
1386 
1387 /*
1388  * Process text streams.
1389  */
1390 static enum rofferr
1391 roff_parsetext(struct roff *r, struct buf *buf, int pos, int *offs)
1392 {
1393 	size_t		 sz;
1394 	const char	*start;
1395 	char		*p;
1396 	int		 isz;
1397 	enum mandoc_esc	 esc;
1398 
1399 	/* Spring the input line trap. */
1400 
1401 	if (roffit_lines == 1) {
1402 		isz = mandoc_asprintf(&p, "%s\n.%s", buf->buf, roffit_macro);
1403 		free(buf->buf);
1404 		buf->buf = p;
1405 		buf->sz = isz + 1;
1406 		*offs = 0;
1407 		free(roffit_macro);
1408 		roffit_lines = 0;
1409 		return ROFF_REPARSE;
1410 	} else if (roffit_lines > 1)
1411 		--roffit_lines;
1412 
1413 	if (roffce_node != NULL && buf->buf[pos] != '\0') {
1414 		if (roffce_lines < 1) {
1415 			r->man->last = roffce_node;
1416 			r->man->next = ROFF_NEXT_SIBLING;
1417 			roffce_lines = 0;
1418 			roffce_node = NULL;
1419 		} else
1420 			roffce_lines--;
1421 	}
1422 
1423 	/* Convert all breakable hyphens into ASCII_HYPH. */
1424 
1425 	start = p = buf->buf + pos;
1426 
1427 	while (*p != '\0') {
1428 		sz = strcspn(p, "-\\");
1429 		p += sz;
1430 
1431 		if (*p == '\0')
1432 			break;
1433 
1434 		if (*p == '\\') {
1435 			/* Skip over escapes. */
1436 			p++;
1437 			esc = mandoc_escape((const char **)&p, NULL, NULL);
1438 			if (esc == ESCAPE_ERROR)
1439 				break;
1440 			while (*p == '-')
1441 				p++;
1442 			continue;
1443 		} else if (p == start) {
1444 			p++;
1445 			continue;
1446 		}
1447 
1448 		if (isalpha((unsigned char)p[-1]) &&
1449 		    isalpha((unsigned char)p[1]))
1450 			*p = ASCII_HYPH;
1451 		p++;
1452 	}
1453 	return ROFF_CONT;
1454 }
1455 
1456 enum rofferr
1457 roff_parseln(struct roff *r, int ln, struct buf *buf, int *offs)
1458 {
1459 	enum roff_tok	 t;
1460 	enum rofferr	 e;
1461 	int		 pos;	/* parse point */
1462 	int		 spos;	/* saved parse point for messages */
1463 	int		 ppos;	/* original offset in buf->buf */
1464 	int		 ctl;	/* macro line (boolean) */
1465 
1466 	ppos = pos = *offs;
1467 
1468 	/* Handle in-line equation delimiters. */
1469 
1470 	if (r->tbl == NULL &&
1471 	    r->last_eqn != NULL && r->last_eqn->delim &&
1472 	    (r->eqn == NULL || r->eqn_inline)) {
1473 		e = roff_eqndelim(r, buf, pos);
1474 		if (e == ROFF_REPARSE)
1475 			return e;
1476 		assert(e == ROFF_CONT);
1477 	}
1478 
1479 	/* Expand some escape sequences. */
1480 
1481 	e = roff_res(r, buf, ln, pos);
1482 	if (e == ROFF_IGN || e == ROFF_APPEND)
1483 		return e;
1484 	assert(e == ROFF_CONT);
1485 
1486 	ctl = roff_getcontrol(r, buf->buf, &pos);
1487 
1488 	/*
1489 	 * First, if a scope is open and we're not a macro, pass the
1490 	 * text through the macro's filter.
1491 	 * Equations process all content themselves.
1492 	 * Tables process almost all content themselves, but we want
1493 	 * to warn about macros before passing it there.
1494 	 */
1495 
1496 	if (r->last != NULL && ! ctl) {
1497 		t = r->last->tok;
1498 		e = (*roffs[t].text)(r, t, buf, ln, pos, pos, offs);
1499 		if (e == ROFF_IGN)
1500 			return e;
1501 		assert(e == ROFF_CONT);
1502 	}
1503 	if (r->eqn != NULL && strncmp(buf->buf + ppos, ".EN", 3)) {
1504 		eqn_read(r->eqn, buf->buf + ppos);
1505 		return ROFF_IGN;
1506 	}
1507 	if (r->tbl != NULL && (ctl == 0 || buf->buf[pos] == '\0')) {
1508 		tbl_read(r->tbl, ln, buf->buf, ppos);
1509 		roff_addtbl(r->man, r->tbl);
1510 		return ROFF_IGN;
1511 	}
1512 	if ( ! ctl)
1513 		return roff_parsetext(r, buf, pos, offs);
1514 
1515 	/* Skip empty request lines. */
1516 
1517 	if (buf->buf[pos] == '"') {
1518 		mandoc_msg(MANDOCERR_COMMENT_BAD, r->parse,
1519 		    ln, pos, NULL);
1520 		return ROFF_IGN;
1521 	} else if (buf->buf[pos] == '\0')
1522 		return ROFF_IGN;
1523 
1524 	/*
1525 	 * If a scope is open, go to the child handler for that macro,
1526 	 * as it may want to preprocess before doing anything with it.
1527 	 * Don't do so if an equation is open.
1528 	 */
1529 
1530 	if (r->last) {
1531 		t = r->last->tok;
1532 		return (*roffs[t].sub)(r, t, buf, ln, ppos, pos, offs);
1533 	}
1534 
1535 	/* No scope is open.  This is a new request or macro. */
1536 
1537 	spos = pos;
1538 	t = roff_parse(r, buf->buf, &pos, ln, ppos);
1539 
1540 	/* Tables ignore most macros. */
1541 
1542 	if (r->tbl != NULL && (t == TOKEN_NONE || t == ROFF_TS ||
1543 	    t == ROFF_br || t == ROFF_ce || t == ROFF_rj || t == ROFF_sp)) {
1544 		mandoc_msg(MANDOCERR_TBLMACRO, r->parse,
1545 		    ln, pos, buf->buf + spos);
1546 		if (t != TOKEN_NONE)
1547 			return ROFF_IGN;
1548 		while (buf->buf[pos] != '\0' && buf->buf[pos] != ' ')
1549 			pos++;
1550 		while (buf->buf[pos] == ' ')
1551 			pos++;
1552 		tbl_read(r->tbl, ln, buf->buf, pos);
1553 		roff_addtbl(r->man, r->tbl);
1554 		return ROFF_IGN;
1555 	}
1556 
1557 	/* For now, let high level macros abort .ce mode. */
1558 
1559 	if (ctl && roffce_node != NULL &&
1560 	    (t == TOKEN_NONE || t == ROFF_Dd || t == ROFF_EQ ||
1561 	     t == ROFF_TH || t == ROFF_TS)) {
1562 		r->man->last = roffce_node;
1563 		r->man->next = ROFF_NEXT_SIBLING;
1564 		roffce_lines = 0;
1565 		roffce_node = NULL;
1566 	}
1567 
1568 	/*
1569 	 * This is neither a roff request nor a user-defined macro.
1570 	 * Let the standard macro set parsers handle it.
1571 	 */
1572 
1573 	if (t == TOKEN_NONE)
1574 		return ROFF_CONT;
1575 
1576 	/* Execute a roff request or a user defined macro. */
1577 
1578 	return (*roffs[t].proc)(r, t, buf, ln, spos, pos, offs);
1579 }
1580 
1581 void
1582 roff_endparse(struct roff *r)
1583 {
1584 	if (r->last != NULL)
1585 		mandoc_msg(MANDOCERR_BLK_NOEND, r->parse,
1586 		    r->last->line, r->last->col,
1587 		    roff_name[r->last->tok]);
1588 
1589 	if (r->eqn != NULL) {
1590 		mandoc_msg(MANDOCERR_BLK_NOEND, r->parse,
1591 		    r->eqn->node->line, r->eqn->node->pos, "EQ");
1592 		eqn_parse(r->eqn);
1593 		r->eqn = NULL;
1594 	}
1595 
1596 	if (r->tbl != NULL) {
1597 		mandoc_msg(MANDOCERR_BLK_NOEND, r->parse,
1598 		    r->tbl->line, r->tbl->pos, "TS");
1599 		tbl_end(r->tbl);
1600 		r->tbl = NULL;
1601 	}
1602 }
1603 
1604 /*
1605  * Parse a roff node's type from the input buffer.  This must be in the
1606  * form of ".foo xxx" in the usual way.
1607  */
1608 static enum roff_tok
1609 roff_parse(struct roff *r, char *buf, int *pos, int ln, int ppos)
1610 {
1611 	char		*cp;
1612 	const char	*mac;
1613 	size_t		 maclen;
1614 	int		 deftype;
1615 	enum roff_tok	 t;
1616 
1617 	cp = buf + *pos;
1618 
1619 	if ('\0' == *cp || '"' == *cp || '\t' == *cp || ' ' == *cp)
1620 		return TOKEN_NONE;
1621 
1622 	mac = cp;
1623 	maclen = roff_getname(r, &cp, ln, ppos);
1624 
1625 	deftype = ROFFDEF_USER | ROFFDEF_REN;
1626 	r->current_string = roff_getstrn(r, mac, maclen, &deftype);
1627 	switch (deftype) {
1628 	case ROFFDEF_USER:
1629 		t = ROFF_USERDEF;
1630 		break;
1631 	case ROFFDEF_REN:
1632 		t = ROFF_RENAMED;
1633 		break;
1634 	default:
1635 		t = roffhash_find(r->reqtab, mac, maclen);
1636 		break;
1637 	}
1638 	if (t != TOKEN_NONE)
1639 		*pos = cp - buf;
1640 	return t;
1641 }
1642 
1643 /* --- handling of request blocks ----------------------------------------- */
1644 
1645 static enum rofferr
1646 roff_cblock(ROFF_ARGS)
1647 {
1648 
1649 	/*
1650 	 * A block-close `..' should only be invoked as a child of an
1651 	 * ignore macro, otherwise raise a warning and just ignore it.
1652 	 */
1653 
1654 	if (r->last == NULL) {
1655 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
1656 		    ln, ppos, "..");
1657 		return ROFF_IGN;
1658 	}
1659 
1660 	switch (r->last->tok) {
1661 	case ROFF_am:
1662 		/* ROFF_am1 is remapped to ROFF_am in roff_block(). */
1663 	case ROFF_ami:
1664 	case ROFF_de:
1665 		/* ROFF_de1 is remapped to ROFF_de in roff_block(). */
1666 	case ROFF_dei:
1667 	case ROFF_ig:
1668 		break;
1669 	default:
1670 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
1671 		    ln, ppos, "..");
1672 		return ROFF_IGN;
1673 	}
1674 
1675 	if (buf->buf[pos] != '\0')
1676 		mandoc_vmsg(MANDOCERR_ARG_SKIP, r->parse, ln, pos,
1677 		    ".. %s", buf->buf + pos);
1678 
1679 	roffnode_pop(r);
1680 	roffnode_cleanscope(r);
1681 	return ROFF_IGN;
1682 
1683 }
1684 
1685 static void
1686 roffnode_cleanscope(struct roff *r)
1687 {
1688 
1689 	while (r->last) {
1690 		if (--r->last->endspan != 0)
1691 			break;
1692 		roffnode_pop(r);
1693 	}
1694 }
1695 
1696 static void
1697 roff_ccond(struct roff *r, int ln, int ppos)
1698 {
1699 
1700 	if (NULL == r->last) {
1701 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
1702 		    ln, ppos, "\\}");
1703 		return;
1704 	}
1705 
1706 	switch (r->last->tok) {
1707 	case ROFF_el:
1708 	case ROFF_ie:
1709 	case ROFF_if:
1710 		break;
1711 	default:
1712 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
1713 		    ln, ppos, "\\}");
1714 		return;
1715 	}
1716 
1717 	if (r->last->endspan > -1) {
1718 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
1719 		    ln, ppos, "\\}");
1720 		return;
1721 	}
1722 
1723 	roffnode_pop(r);
1724 	roffnode_cleanscope(r);
1725 	return;
1726 }
1727 
1728 static enum rofferr
1729 roff_block(ROFF_ARGS)
1730 {
1731 	const char	*name, *value;
1732 	char		*call, *cp, *iname, *rname;
1733 	size_t		 csz, namesz, rsz;
1734 	int		 deftype;
1735 
1736 	/* Ignore groff compatibility mode for now. */
1737 
1738 	if (tok == ROFF_de1)
1739 		tok = ROFF_de;
1740 	else if (tok == ROFF_dei1)
1741 		tok = ROFF_dei;
1742 	else if (tok == ROFF_am1)
1743 		tok = ROFF_am;
1744 	else if (tok == ROFF_ami1)
1745 		tok = ROFF_ami;
1746 
1747 	/* Parse the macro name argument. */
1748 
1749 	cp = buf->buf + pos;
1750 	if (tok == ROFF_ig) {
1751 		iname = NULL;
1752 		namesz = 0;
1753 	} else {
1754 		iname = cp;
1755 		namesz = roff_getname(r, &cp, ln, ppos);
1756 		iname[namesz] = '\0';
1757 	}
1758 
1759 	/* Resolve the macro name argument if it is indirect. */
1760 
1761 	if (namesz && (tok == ROFF_dei || tok == ROFF_ami)) {
1762 		deftype = ROFFDEF_USER;
1763 		name = roff_getstrn(r, iname, namesz, &deftype);
1764 		if (name == NULL) {
1765 			mandoc_vmsg(MANDOCERR_STR_UNDEF,
1766 			    r->parse, ln, (int)(iname - buf->buf),
1767 			    "%.*s", (int)namesz, iname);
1768 			namesz = 0;
1769 		} else
1770 			namesz = strlen(name);
1771 	} else
1772 		name = iname;
1773 
1774 	if (namesz == 0 && tok != ROFF_ig) {
1775 		mandoc_msg(MANDOCERR_REQ_EMPTY, r->parse,
1776 		    ln, ppos, roff_name[tok]);
1777 		return ROFF_IGN;
1778 	}
1779 
1780 	roffnode_push(r, tok, name, ln, ppos);
1781 
1782 	/*
1783 	 * At the beginning of a `de' macro, clear the existing string
1784 	 * with the same name, if there is one.  New content will be
1785 	 * appended from roff_block_text() in multiline mode.
1786 	 */
1787 
1788 	if (tok == ROFF_de || tok == ROFF_dei) {
1789 		roff_setstrn(&r->strtab, name, namesz, "", 0, 0);
1790 		roff_setstrn(&r->rentab, name, namesz, NULL, 0, 0);
1791 	} else if (tok == ROFF_am || tok == ROFF_ami) {
1792 		deftype = ROFFDEF_ANY;
1793 		value = roff_getstrn(r, iname, namesz, &deftype);
1794 		switch (deftype) {  /* Before appending, ... */
1795 		case ROFFDEF_PRE: /* copy predefined to user-defined. */
1796 			roff_setstrn(&r->strtab, name, namesz,
1797 			    value, strlen(value), 0);
1798 			break;
1799 		case ROFFDEF_REN: /* call original standard macro. */
1800 			csz = mandoc_asprintf(&call, ".%.*s \\$* \\\"\n",
1801 			    (int)strlen(value), value);
1802 			roff_setstrn(&r->strtab, name, namesz, call, csz, 0);
1803 			roff_setstrn(&r->rentab, name, namesz, NULL, 0, 0);
1804 			free(call);
1805 			break;
1806 		case ROFFDEF_STD:  /* rename and call standard macro. */
1807 			rsz = mandoc_asprintf(&rname, "__%s_renamed", name);
1808 			roff_setstrn(&r->rentab, rname, rsz, name, namesz, 0);
1809 			csz = mandoc_asprintf(&call, ".%.*s \\$* \\\"\n",
1810 			    (int)rsz, rname);
1811 			roff_setstrn(&r->strtab, name, namesz, call, csz, 0);
1812 			free(call);
1813 			free(rname);
1814 			break;
1815 		default:
1816 			break;
1817 		}
1818 	}
1819 
1820 	if (*cp == '\0')
1821 		return ROFF_IGN;
1822 
1823 	/* Get the custom end marker. */
1824 
1825 	iname = cp;
1826 	namesz = roff_getname(r, &cp, ln, ppos);
1827 
1828 	/* Resolve the end marker if it is indirect. */
1829 
1830 	if (namesz && (tok == ROFF_dei || tok == ROFF_ami)) {
1831 		deftype = ROFFDEF_USER;
1832 		name = roff_getstrn(r, iname, namesz, &deftype);
1833 		if (name == NULL) {
1834 			mandoc_vmsg(MANDOCERR_STR_UNDEF,
1835 			    r->parse, ln, (int)(iname - buf->buf),
1836 			    "%.*s", (int)namesz, iname);
1837 			namesz = 0;
1838 		} else
1839 			namesz = strlen(name);
1840 	} else
1841 		name = iname;
1842 
1843 	if (namesz)
1844 		r->last->end = mandoc_strndup(name, namesz);
1845 
1846 	if (*cp != '\0')
1847 		mandoc_vmsg(MANDOCERR_ARG_EXCESS, r->parse,
1848 		    ln, pos, ".%s ... %s", roff_name[tok], cp);
1849 
1850 	return ROFF_IGN;
1851 }
1852 
1853 static enum rofferr
1854 roff_block_sub(ROFF_ARGS)
1855 {
1856 	enum roff_tok	t;
1857 	int		i, j;
1858 
1859 	/*
1860 	 * First check whether a custom macro exists at this level.  If
1861 	 * it does, then check against it.  This is some of groff's
1862 	 * stranger behaviours.  If we encountered a custom end-scope
1863 	 * tag and that tag also happens to be a "real" macro, then we
1864 	 * need to try interpreting it again as a real macro.  If it's
1865 	 * not, then return ignore.  Else continue.
1866 	 */
1867 
1868 	if (r->last->end) {
1869 		for (i = pos, j = 0; r->last->end[j]; j++, i++)
1870 			if (buf->buf[i] != r->last->end[j])
1871 				break;
1872 
1873 		if (r->last->end[j] == '\0' &&
1874 		    (buf->buf[i] == '\0' ||
1875 		     buf->buf[i] == ' ' ||
1876 		     buf->buf[i] == '\t')) {
1877 			roffnode_pop(r);
1878 			roffnode_cleanscope(r);
1879 
1880 			while (buf->buf[i] == ' ' || buf->buf[i] == '\t')
1881 				i++;
1882 
1883 			pos = i;
1884 			if (roff_parse(r, buf->buf, &pos, ln, ppos) !=
1885 			    TOKEN_NONE)
1886 				return ROFF_RERUN;
1887 			return ROFF_IGN;
1888 		}
1889 	}
1890 
1891 	/*
1892 	 * If we have no custom end-query or lookup failed, then try
1893 	 * pulling it out of the hashtable.
1894 	 */
1895 
1896 	t = roff_parse(r, buf->buf, &pos, ln, ppos);
1897 
1898 	if (t != ROFF_cblock) {
1899 		if (tok != ROFF_ig)
1900 			roff_setstr(r, r->last->name, buf->buf + ppos, 2);
1901 		return ROFF_IGN;
1902 	}
1903 
1904 	return (*roffs[t].proc)(r, t, buf, ln, ppos, pos, offs);
1905 }
1906 
1907 static enum rofferr
1908 roff_block_text(ROFF_ARGS)
1909 {
1910 
1911 	if (tok != ROFF_ig)
1912 		roff_setstr(r, r->last->name, buf->buf + pos, 2);
1913 
1914 	return ROFF_IGN;
1915 }
1916 
1917 static enum rofferr
1918 roff_cond_sub(ROFF_ARGS)
1919 {
1920 	enum roff_tok	 t;
1921 	char		*ep;
1922 	int		 rr;
1923 
1924 	rr = r->last->rule;
1925 	roffnode_cleanscope(r);
1926 
1927 	/*
1928 	 * If `\}' occurs on a macro line without a preceding macro,
1929 	 * drop the line completely.
1930 	 */
1931 
1932 	ep = buf->buf + pos;
1933 	if (ep[0] == '\\' && ep[1] == '}')
1934 		rr = 0;
1935 
1936 	/* Always check for the closing delimiter `\}'. */
1937 
1938 	while ((ep = strchr(ep, '\\')) != NULL) {
1939 		switch (ep[1]) {
1940 		case '}':
1941 			memmove(ep, ep + 2, strlen(ep + 2) + 1);
1942 			roff_ccond(r, ln, ep - buf->buf);
1943 			break;
1944 		case '\0':
1945 			++ep;
1946 			break;
1947 		default:
1948 			ep += 2;
1949 			break;
1950 		}
1951 	}
1952 
1953 	/*
1954 	 * Fully handle known macros when they are structurally
1955 	 * required or when the conditional evaluated to true.
1956 	 */
1957 
1958 	t = roff_parse(r, buf->buf, &pos, ln, ppos);
1959 	return t != TOKEN_NONE && (rr || roffs[t].flags & ROFFMAC_STRUCT)
1960 	    ? (*roffs[t].proc)(r, t, buf, ln, ppos, pos, offs) : rr
1961 	    ? ROFF_CONT : ROFF_IGN;
1962 }
1963 
1964 static enum rofferr
1965 roff_cond_text(ROFF_ARGS)
1966 {
1967 	char		*ep;
1968 	int		 rr;
1969 
1970 	rr = r->last->rule;
1971 	roffnode_cleanscope(r);
1972 
1973 	ep = buf->buf + pos;
1974 	while ((ep = strchr(ep, '\\')) != NULL) {
1975 		if (*(++ep) == '}') {
1976 			*ep = '&';
1977 			roff_ccond(r, ln, ep - buf->buf - 1);
1978 		}
1979 		if (*ep != '\0')
1980 			++ep;
1981 	}
1982 	return rr ? ROFF_CONT : ROFF_IGN;
1983 }
1984 
1985 /* --- handling of numeric and conditional expressions -------------------- */
1986 
1987 /*
1988  * Parse a single signed integer number.  Stop at the first non-digit.
1989  * If there is at least one digit, return success and advance the
1990  * parse point, else return failure and let the parse point unchanged.
1991  * Ignore overflows, treat them just like the C language.
1992  */
1993 static int
1994 roff_getnum(const char *v, int *pos, int *res, int flags)
1995 {
1996 	int	 myres, scaled, n, p;
1997 
1998 	if (NULL == res)
1999 		res = &myres;
2000 
2001 	p = *pos;
2002 	n = v[p] == '-';
2003 	if (n || v[p] == '+')
2004 		p++;
2005 
2006 	if (flags & ROFFNUM_WHITE)
2007 		while (isspace((unsigned char)v[p]))
2008 			p++;
2009 
2010 	for (*res = 0; isdigit((unsigned char)v[p]); p++)
2011 		*res = 10 * *res + v[p] - '0';
2012 	if (p == *pos + n)
2013 		return 0;
2014 
2015 	if (n)
2016 		*res = -*res;
2017 
2018 	/* Each number may be followed by one optional scaling unit. */
2019 
2020 	switch (v[p]) {
2021 	case 'f':
2022 		scaled = *res * 65536;
2023 		break;
2024 	case 'i':
2025 		scaled = *res * 240;
2026 		break;
2027 	case 'c':
2028 		scaled = *res * 240 / 2.54;
2029 		break;
2030 	case 'v':
2031 	case 'P':
2032 		scaled = *res * 40;
2033 		break;
2034 	case 'm':
2035 	case 'n':
2036 		scaled = *res * 24;
2037 		break;
2038 	case 'p':
2039 		scaled = *res * 10 / 3;
2040 		break;
2041 	case 'u':
2042 		scaled = *res;
2043 		break;
2044 	case 'M':
2045 		scaled = *res * 6 / 25;
2046 		break;
2047 	default:
2048 		scaled = *res;
2049 		p--;
2050 		break;
2051 	}
2052 	if (flags & ROFFNUM_SCALE)
2053 		*res = scaled;
2054 
2055 	*pos = p + 1;
2056 	return 1;
2057 }
2058 
2059 /*
2060  * Evaluate a string comparison condition.
2061  * The first character is the delimiter.
2062  * Succeed if the string up to its second occurrence
2063  * matches the string up to its third occurence.
2064  * Advance the cursor after the third occurrence
2065  * or lacking that, to the end of the line.
2066  */
2067 static int
2068 roff_evalstrcond(const char *v, int *pos)
2069 {
2070 	const char	*s1, *s2, *s3;
2071 	int		 match;
2072 
2073 	match = 0;
2074 	s1 = v + *pos;		/* initial delimiter */
2075 	s2 = s1 + 1;		/* for scanning the first string */
2076 	s3 = strchr(s2, *s1);	/* for scanning the second string */
2077 
2078 	if (NULL == s3)		/* found no middle delimiter */
2079 		goto out;
2080 
2081 	while ('\0' != *++s3) {
2082 		if (*s2 != *s3) {  /* mismatch */
2083 			s3 = strchr(s3, *s1);
2084 			break;
2085 		}
2086 		if (*s3 == *s1) {  /* found the final delimiter */
2087 			match = 1;
2088 			break;
2089 		}
2090 		s2++;
2091 	}
2092 
2093 out:
2094 	if (NULL == s3)
2095 		s3 = strchr(s2, '\0');
2096 	else if (*s3 != '\0')
2097 		s3++;
2098 	*pos = s3 - v;
2099 	return match;
2100 }
2101 
2102 /*
2103  * Evaluate an optionally negated single character, numerical,
2104  * or string condition.
2105  */
2106 static int
2107 roff_evalcond(struct roff *r, int ln, char *v, int *pos)
2108 {
2109 	char	*cp, *name;
2110 	size_t	 sz;
2111 	int	 deftype, number, savepos, istrue, wanttrue;
2112 
2113 	if ('!' == v[*pos]) {
2114 		wanttrue = 0;
2115 		(*pos)++;
2116 	} else
2117 		wanttrue = 1;
2118 
2119 	switch (v[*pos]) {
2120 	case '\0':
2121 		return 0;
2122 	case 'n':
2123 	case 'o':
2124 		(*pos)++;
2125 		return wanttrue;
2126 	case 'c':
2127 	case 'e':
2128 	case 't':
2129 	case 'v':
2130 		(*pos)++;
2131 		return !wanttrue;
2132 	case 'd':
2133 	case 'r':
2134 		cp = v + *pos + 1;
2135 		while (*cp == ' ')
2136 			cp++;
2137 		name = cp;
2138 		sz = roff_getname(r, &cp, ln, cp - v);
2139 		if (sz == 0)
2140 			istrue = 0;
2141 		else if (v[*pos] == 'r')
2142 			istrue = roff_hasregn(r, name, sz);
2143 		else {
2144 			deftype = ROFFDEF_ANY;
2145 		        roff_getstrn(r, name, sz, &deftype);
2146 			istrue = !!deftype;
2147 		}
2148 		*pos = cp - v;
2149 		return istrue == wanttrue;
2150 	default:
2151 		break;
2152 	}
2153 
2154 	savepos = *pos;
2155 	if (roff_evalnum(r, ln, v, pos, &number, ROFFNUM_SCALE))
2156 		return (number > 0) == wanttrue;
2157 	else if (*pos == savepos)
2158 		return roff_evalstrcond(v, pos) == wanttrue;
2159 	else
2160 		return 0;
2161 }
2162 
2163 static enum rofferr
2164 roff_line_ignore(ROFF_ARGS)
2165 {
2166 
2167 	return ROFF_IGN;
2168 }
2169 
2170 static enum rofferr
2171 roff_insec(ROFF_ARGS)
2172 {
2173 
2174 	mandoc_msg(MANDOCERR_REQ_INSEC, r->parse,
2175 	    ln, ppos, roff_name[tok]);
2176 	return ROFF_IGN;
2177 }
2178 
2179 static enum rofferr
2180 roff_unsupp(ROFF_ARGS)
2181 {
2182 
2183 	mandoc_msg(MANDOCERR_REQ_UNSUPP, r->parse,
2184 	    ln, ppos, roff_name[tok]);
2185 	return ROFF_IGN;
2186 }
2187 
2188 static enum rofferr
2189 roff_cond(ROFF_ARGS)
2190 {
2191 
2192 	roffnode_push(r, tok, NULL, ln, ppos);
2193 
2194 	/*
2195 	 * An `.el' has no conditional body: it will consume the value
2196 	 * of the current rstack entry set in prior `ie' calls or
2197 	 * defaults to DENY.
2198 	 *
2199 	 * If we're not an `el', however, then evaluate the conditional.
2200 	 */
2201 
2202 	r->last->rule = tok == ROFF_el ?
2203 	    (r->rstackpos < 0 ? 0 : r->rstack[r->rstackpos--]) :
2204 	    roff_evalcond(r, ln, buf->buf, &pos);
2205 
2206 	/*
2207 	 * An if-else will put the NEGATION of the current evaluated
2208 	 * conditional into the stack of rules.
2209 	 */
2210 
2211 	if (tok == ROFF_ie) {
2212 		if (r->rstackpos + 1 == r->rstacksz) {
2213 			r->rstacksz += 16;
2214 			r->rstack = mandoc_reallocarray(r->rstack,
2215 			    r->rstacksz, sizeof(int));
2216 		}
2217 		r->rstack[++r->rstackpos] = !r->last->rule;
2218 	}
2219 
2220 	/* If the parent has false as its rule, then so do we. */
2221 
2222 	if (r->last->parent && !r->last->parent->rule)
2223 		r->last->rule = 0;
2224 
2225 	/*
2226 	 * Determine scope.
2227 	 * If there is nothing on the line after the conditional,
2228 	 * not even whitespace, use next-line scope.
2229 	 */
2230 
2231 	if (buf->buf[pos] == '\0') {
2232 		r->last->endspan = 2;
2233 		goto out;
2234 	}
2235 
2236 	while (buf->buf[pos] == ' ')
2237 		pos++;
2238 
2239 	/* An opening brace requests multiline scope. */
2240 
2241 	if (buf->buf[pos] == '\\' && buf->buf[pos + 1] == '{') {
2242 		r->last->endspan = -1;
2243 		pos += 2;
2244 		while (buf->buf[pos] == ' ')
2245 			pos++;
2246 		goto out;
2247 	}
2248 
2249 	/*
2250 	 * Anything else following the conditional causes
2251 	 * single-line scope.  Warn if the scope contains
2252 	 * nothing but trailing whitespace.
2253 	 */
2254 
2255 	if (buf->buf[pos] == '\0')
2256 		mandoc_msg(MANDOCERR_COND_EMPTY, r->parse,
2257 		    ln, ppos, roff_name[tok]);
2258 
2259 	r->last->endspan = 1;
2260 
2261 out:
2262 	*offs = pos;
2263 	return ROFF_RERUN;
2264 }
2265 
2266 static enum rofferr
2267 roff_ds(ROFF_ARGS)
2268 {
2269 	char		*string;
2270 	const char	*name;
2271 	size_t		 namesz;
2272 
2273 	/* Ignore groff compatibility mode for now. */
2274 
2275 	if (tok == ROFF_ds1)
2276 		tok = ROFF_ds;
2277 	else if (tok == ROFF_as1)
2278 		tok = ROFF_as;
2279 
2280 	/*
2281 	 * The first word is the name of the string.
2282 	 * If it is empty or terminated by an escape sequence,
2283 	 * abort the `ds' request without defining anything.
2284 	 */
2285 
2286 	name = string = buf->buf + pos;
2287 	if (*name == '\0')
2288 		return ROFF_IGN;
2289 
2290 	namesz = roff_getname(r, &string, ln, pos);
2291 	if (name[namesz] == '\\')
2292 		return ROFF_IGN;
2293 
2294 	/* Read past the initial double-quote, if any. */
2295 	if (*string == '"')
2296 		string++;
2297 
2298 	/* The rest is the value. */
2299 	roff_setstrn(&r->strtab, name, namesz, string, strlen(string),
2300 	    ROFF_as == tok);
2301 	roff_setstrn(&r->rentab, name, namesz, NULL, 0, 0);
2302 	return ROFF_IGN;
2303 }
2304 
2305 /*
2306  * Parse a single operator, one or two characters long.
2307  * If the operator is recognized, return success and advance the
2308  * parse point, else return failure and let the parse point unchanged.
2309  */
2310 static int
2311 roff_getop(const char *v, int *pos, char *res)
2312 {
2313 
2314 	*res = v[*pos];
2315 
2316 	switch (*res) {
2317 	case '+':
2318 	case '-':
2319 	case '*':
2320 	case '/':
2321 	case '%':
2322 	case '&':
2323 	case ':':
2324 		break;
2325 	case '<':
2326 		switch (v[*pos + 1]) {
2327 		case '=':
2328 			*res = 'l';
2329 			(*pos)++;
2330 			break;
2331 		case '>':
2332 			*res = '!';
2333 			(*pos)++;
2334 			break;
2335 		case '?':
2336 			*res = 'i';
2337 			(*pos)++;
2338 			break;
2339 		default:
2340 			break;
2341 		}
2342 		break;
2343 	case '>':
2344 		switch (v[*pos + 1]) {
2345 		case '=':
2346 			*res = 'g';
2347 			(*pos)++;
2348 			break;
2349 		case '?':
2350 			*res = 'a';
2351 			(*pos)++;
2352 			break;
2353 		default:
2354 			break;
2355 		}
2356 		break;
2357 	case '=':
2358 		if ('=' == v[*pos + 1])
2359 			(*pos)++;
2360 		break;
2361 	default:
2362 		return 0;
2363 	}
2364 	(*pos)++;
2365 
2366 	return *res;
2367 }
2368 
2369 /*
2370  * Evaluate either a parenthesized numeric expression
2371  * or a single signed integer number.
2372  */
2373 static int
2374 roff_evalpar(struct roff *r, int ln,
2375 	const char *v, int *pos, int *res, int flags)
2376 {
2377 
2378 	if ('(' != v[*pos])
2379 		return roff_getnum(v, pos, res, flags);
2380 
2381 	(*pos)++;
2382 	if ( ! roff_evalnum(r, ln, v, pos, res, flags | ROFFNUM_WHITE))
2383 		return 0;
2384 
2385 	/*
2386 	 * Omission of the closing parenthesis
2387 	 * is an error in validation mode,
2388 	 * but ignored in evaluation mode.
2389 	 */
2390 
2391 	if (')' == v[*pos])
2392 		(*pos)++;
2393 	else if (NULL == res)
2394 		return 0;
2395 
2396 	return 1;
2397 }
2398 
2399 /*
2400  * Evaluate a complete numeric expression.
2401  * Proceed left to right, there is no concept of precedence.
2402  */
2403 static int
2404 roff_evalnum(struct roff *r, int ln, const char *v,
2405 	int *pos, int *res, int flags)
2406 {
2407 	int		 mypos, operand2;
2408 	char		 operator;
2409 
2410 	if (NULL == pos) {
2411 		mypos = 0;
2412 		pos = &mypos;
2413 	}
2414 
2415 	if (flags & ROFFNUM_WHITE)
2416 		while (isspace((unsigned char)v[*pos]))
2417 			(*pos)++;
2418 
2419 	if ( ! roff_evalpar(r, ln, v, pos, res, flags))
2420 		return 0;
2421 
2422 	while (1) {
2423 		if (flags & ROFFNUM_WHITE)
2424 			while (isspace((unsigned char)v[*pos]))
2425 				(*pos)++;
2426 
2427 		if ( ! roff_getop(v, pos, &operator))
2428 			break;
2429 
2430 		if (flags & ROFFNUM_WHITE)
2431 			while (isspace((unsigned char)v[*pos]))
2432 				(*pos)++;
2433 
2434 		if ( ! roff_evalpar(r, ln, v, pos, &operand2, flags))
2435 			return 0;
2436 
2437 		if (flags & ROFFNUM_WHITE)
2438 			while (isspace((unsigned char)v[*pos]))
2439 				(*pos)++;
2440 
2441 		if (NULL == res)
2442 			continue;
2443 
2444 		switch (operator) {
2445 		case '+':
2446 			*res += operand2;
2447 			break;
2448 		case '-':
2449 			*res -= operand2;
2450 			break;
2451 		case '*':
2452 			*res *= operand2;
2453 			break;
2454 		case '/':
2455 			if (operand2 == 0) {
2456 				mandoc_msg(MANDOCERR_DIVZERO,
2457 					r->parse, ln, *pos, v);
2458 				*res = 0;
2459 				break;
2460 			}
2461 			*res /= operand2;
2462 			break;
2463 		case '%':
2464 			if (operand2 == 0) {
2465 				mandoc_msg(MANDOCERR_DIVZERO,
2466 					r->parse, ln, *pos, v);
2467 				*res = 0;
2468 				break;
2469 			}
2470 			*res %= operand2;
2471 			break;
2472 		case '<':
2473 			*res = *res < operand2;
2474 			break;
2475 		case '>':
2476 			*res = *res > operand2;
2477 			break;
2478 		case 'l':
2479 			*res = *res <= operand2;
2480 			break;
2481 		case 'g':
2482 			*res = *res >= operand2;
2483 			break;
2484 		case '=':
2485 			*res = *res == operand2;
2486 			break;
2487 		case '!':
2488 			*res = *res != operand2;
2489 			break;
2490 		case '&':
2491 			*res = *res && operand2;
2492 			break;
2493 		case ':':
2494 			*res = *res || operand2;
2495 			break;
2496 		case 'i':
2497 			if (operand2 < *res)
2498 				*res = operand2;
2499 			break;
2500 		case 'a':
2501 			if (operand2 > *res)
2502 				*res = operand2;
2503 			break;
2504 		default:
2505 			abort();
2506 		}
2507 	}
2508 	return 1;
2509 }
2510 
2511 /* --- register management ------------------------------------------------ */
2512 
2513 void
2514 roff_setreg(struct roff *r, const char *name, int val, char sign)
2515 {
2516 	struct roffreg	*reg;
2517 
2518 	/* Search for an existing register with the same name. */
2519 	reg = r->regtab;
2520 
2521 	while (reg && strcmp(name, reg->key.p))
2522 		reg = reg->next;
2523 
2524 	if (NULL == reg) {
2525 		/* Create a new register. */
2526 		reg = mandoc_malloc(sizeof(struct roffreg));
2527 		reg->key.p = mandoc_strdup(name);
2528 		reg->key.sz = strlen(name);
2529 		reg->val = 0;
2530 		reg->next = r->regtab;
2531 		r->regtab = reg;
2532 	}
2533 
2534 	if ('+' == sign)
2535 		reg->val += val;
2536 	else if ('-' == sign)
2537 		reg->val -= val;
2538 	else
2539 		reg->val = val;
2540 }
2541 
2542 /*
2543  * Handle some predefined read-only number registers.
2544  * For now, return -1 if the requested register is not predefined;
2545  * in case a predefined read-only register having the value -1
2546  * were to turn up, another special value would have to be chosen.
2547  */
2548 static int
2549 roff_getregro(const struct roff *r, const char *name)
2550 {
2551 
2552 	switch (*name) {
2553 	case '$':  /* Number of arguments of the last macro evaluated. */
2554 		return r->argc;
2555 	case 'A':  /* ASCII approximation mode is always off. */
2556 		return 0;
2557 	case 'g':  /* Groff compatibility mode is always on. */
2558 		return 1;
2559 	case 'H':  /* Fixed horizontal resolution. */
2560 		return 24;
2561 	case 'j':  /* Always adjust left margin only. */
2562 		return 0;
2563 	case 'T':  /* Some output device is always defined. */
2564 		return 1;
2565 	case 'V':  /* Fixed vertical resolution. */
2566 		return 40;
2567 	default:
2568 		return -1;
2569 	}
2570 }
2571 
2572 int
2573 roff_getreg(const struct roff *r, const char *name)
2574 {
2575 	struct roffreg	*reg;
2576 	int		 val;
2577 
2578 	if ('.' == name[0] && '\0' != name[1] && '\0' == name[2]) {
2579 		val = roff_getregro(r, name + 1);
2580 		if (-1 != val)
2581 			return val;
2582 	}
2583 
2584 	for (reg = r->regtab; reg; reg = reg->next)
2585 		if (0 == strcmp(name, reg->key.p))
2586 			return reg->val;
2587 
2588 	return 0;
2589 }
2590 
2591 static int
2592 roff_getregn(const struct roff *r, const char *name, size_t len)
2593 {
2594 	struct roffreg	*reg;
2595 	int		 val;
2596 
2597 	if ('.' == name[0] && 2 == len) {
2598 		val = roff_getregro(r, name + 1);
2599 		if (-1 != val)
2600 			return val;
2601 	}
2602 
2603 	for (reg = r->regtab; reg; reg = reg->next)
2604 		if (len == reg->key.sz &&
2605 		    0 == strncmp(name, reg->key.p, len))
2606 			return reg->val;
2607 
2608 	return 0;
2609 }
2610 
2611 static int
2612 roff_hasregn(const struct roff *r, const char *name, size_t len)
2613 {
2614 	struct roffreg	*reg;
2615 	int		 val;
2616 
2617 	if ('.' == name[0] && 2 == len) {
2618 		val = roff_getregro(r, name + 1);
2619 		if (-1 != val)
2620 			return 1;
2621 	}
2622 
2623 	for (reg = r->regtab; reg; reg = reg->next)
2624 		if (len == reg->key.sz &&
2625 		    0 == strncmp(name, reg->key.p, len))
2626 			return 1;
2627 
2628 	return 0;
2629 }
2630 
2631 static void
2632 roff_freereg(struct roffreg *reg)
2633 {
2634 	struct roffreg	*old_reg;
2635 
2636 	while (NULL != reg) {
2637 		free(reg->key.p);
2638 		old_reg = reg;
2639 		reg = reg->next;
2640 		free(old_reg);
2641 	}
2642 }
2643 
2644 static enum rofferr
2645 roff_nr(ROFF_ARGS)
2646 {
2647 	char		*key, *val;
2648 	size_t		 keysz;
2649 	int		 iv;
2650 	char		 sign;
2651 
2652 	key = val = buf->buf + pos;
2653 	if (*key == '\0')
2654 		return ROFF_IGN;
2655 
2656 	keysz = roff_getname(r, &val, ln, pos);
2657 	if (key[keysz] == '\\')
2658 		return ROFF_IGN;
2659 	key[keysz] = '\0';
2660 
2661 	sign = *val;
2662 	if (sign == '+' || sign == '-')
2663 		val++;
2664 
2665 	if (roff_evalnum(r, ln, val, NULL, &iv, ROFFNUM_SCALE))
2666 		roff_setreg(r, key, iv, sign);
2667 
2668 	return ROFF_IGN;
2669 }
2670 
2671 static enum rofferr
2672 roff_rr(ROFF_ARGS)
2673 {
2674 	struct roffreg	*reg, **prev;
2675 	char		*name, *cp;
2676 	size_t		 namesz;
2677 
2678 	name = cp = buf->buf + pos;
2679 	if (*name == '\0')
2680 		return ROFF_IGN;
2681 	namesz = roff_getname(r, &cp, ln, pos);
2682 	name[namesz] = '\0';
2683 
2684 	prev = &r->regtab;
2685 	while (1) {
2686 		reg = *prev;
2687 		if (reg == NULL || !strcmp(name, reg->key.p))
2688 			break;
2689 		prev = &reg->next;
2690 	}
2691 	if (reg != NULL) {
2692 		*prev = reg->next;
2693 		free(reg->key.p);
2694 		free(reg);
2695 	}
2696 	return ROFF_IGN;
2697 }
2698 
2699 /* --- handler functions for roff requests -------------------------------- */
2700 
2701 static enum rofferr
2702 roff_rm(ROFF_ARGS)
2703 {
2704 	const char	 *name;
2705 	char		 *cp;
2706 	size_t		  namesz;
2707 
2708 	cp = buf->buf + pos;
2709 	while (*cp != '\0') {
2710 		name = cp;
2711 		namesz = roff_getname(r, &cp, ln, (int)(cp - buf->buf));
2712 		roff_setstrn(&r->strtab, name, namesz, NULL, 0, 0);
2713 		roff_setstrn(&r->rentab, name, namesz, NULL, 0, 0);
2714 		if (name[namesz] == '\\')
2715 			break;
2716 	}
2717 	return ROFF_IGN;
2718 }
2719 
2720 static enum rofferr
2721 roff_it(ROFF_ARGS)
2722 {
2723 	int		 iv;
2724 
2725 	/* Parse the number of lines. */
2726 
2727 	if ( ! roff_evalnum(r, ln, buf->buf, &pos, &iv, 0)) {
2728 		mandoc_msg(MANDOCERR_IT_NONUM, r->parse,
2729 		    ln, ppos, buf->buf + 1);
2730 		return ROFF_IGN;
2731 	}
2732 
2733 	while (isspace((unsigned char)buf->buf[pos]))
2734 		pos++;
2735 
2736 	/*
2737 	 * Arm the input line trap.
2738 	 * Special-casing "an-trap" is an ugly workaround to cope
2739 	 * with DocBook stupidly fiddling with man(7) internals.
2740 	 */
2741 
2742 	roffit_lines = iv;
2743 	roffit_macro = mandoc_strdup(iv != 1 ||
2744 	    strcmp(buf->buf + pos, "an-trap") ?
2745 	    buf->buf + pos : "br");
2746 	return ROFF_IGN;
2747 }
2748 
2749 static enum rofferr
2750 roff_Dd(ROFF_ARGS)
2751 {
2752 	int		 mask;
2753 	enum roff_tok	 t, te;
2754 
2755 	switch (tok) {
2756 	case ROFF_Dd:
2757 		tok = MDOC_Dd;
2758 		te = MDOC_MAX;
2759 		if (r->format == 0)
2760 			r->format = MPARSE_MDOC;
2761 		mask = MPARSE_MDOC | MPARSE_QUICK;
2762 		break;
2763 	case ROFF_TH:
2764 		tok = MAN_TH;
2765 		te = MAN_MAX;
2766 		if (r->format == 0)
2767 			r->format = MPARSE_MAN;
2768 		mask = MPARSE_QUICK;
2769 		break;
2770 	default:
2771 		abort();
2772 	}
2773 	if ((r->options & mask) == 0)
2774 		for (t = tok; t < te; t++)
2775 			roff_setstr(r, roff_name[t], NULL, 0);
2776 	return ROFF_CONT;
2777 }
2778 
2779 static enum rofferr
2780 roff_TE(ROFF_ARGS)
2781 {
2782 	if (r->tbl == NULL) {
2783 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
2784 		    ln, ppos, "TE");
2785 		return ROFF_IGN;
2786 	}
2787 	if (tbl_end(r->tbl) == 0) {
2788 		r->tbl = NULL;
2789 		free(buf->buf);
2790 		buf->buf = mandoc_strdup(".sp");
2791 		buf->sz = 4;
2792 		return ROFF_REPARSE;
2793 	}
2794 	r->tbl = NULL;
2795 	return ROFF_IGN;
2796 }
2797 
2798 static enum rofferr
2799 roff_T_(ROFF_ARGS)
2800 {
2801 
2802 	if (NULL == r->tbl)
2803 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse,
2804 		    ln, ppos, "T&");
2805 	else
2806 		tbl_restart(ln, ppos, r->tbl);
2807 
2808 	return ROFF_IGN;
2809 }
2810 
2811 /*
2812  * Handle in-line equation delimiters.
2813  */
2814 static enum rofferr
2815 roff_eqndelim(struct roff *r, struct buf *buf, int pos)
2816 {
2817 	char		*cp1, *cp2;
2818 	const char	*bef_pr, *bef_nl, *mac, *aft_nl, *aft_pr;
2819 
2820 	/*
2821 	 * Outside equations, look for an opening delimiter.
2822 	 * If we are inside an equation, we already know it is
2823 	 * in-line, or this function wouldn't have been called;
2824 	 * so look for a closing delimiter.
2825 	 */
2826 
2827 	cp1 = buf->buf + pos;
2828 	cp2 = strchr(cp1, r->eqn == NULL ?
2829 	    r->last_eqn->odelim : r->last_eqn->cdelim);
2830 	if (cp2 == NULL)
2831 		return ROFF_CONT;
2832 
2833 	*cp2++ = '\0';
2834 	bef_pr = bef_nl = aft_nl = aft_pr = "";
2835 
2836 	/* Handle preceding text, protecting whitespace. */
2837 
2838 	if (*buf->buf != '\0') {
2839 		if (r->eqn == NULL)
2840 			bef_pr = "\\&";
2841 		bef_nl = "\n";
2842 	}
2843 
2844 	/*
2845 	 * Prepare replacing the delimiter with an equation macro
2846 	 * and drop leading white space from the equation.
2847 	 */
2848 
2849 	if (r->eqn == NULL) {
2850 		while (*cp2 == ' ')
2851 			cp2++;
2852 		mac = ".EQ";
2853 	} else
2854 		mac = ".EN";
2855 
2856 	/* Handle following text, protecting whitespace. */
2857 
2858 	if (*cp2 != '\0') {
2859 		aft_nl = "\n";
2860 		if (r->eqn != NULL)
2861 			aft_pr = "\\&";
2862 	}
2863 
2864 	/* Do the actual replacement. */
2865 
2866 	buf->sz = mandoc_asprintf(&cp1, "%s%s%s%s%s%s%s", buf->buf,
2867 	    bef_pr, bef_nl, mac, aft_nl, aft_pr, cp2) + 1;
2868 	free(buf->buf);
2869 	buf->buf = cp1;
2870 
2871 	/* Toggle the in-line state of the eqn subsystem. */
2872 
2873 	r->eqn_inline = r->eqn == NULL;
2874 	return ROFF_REPARSE;
2875 }
2876 
2877 static enum rofferr
2878 roff_EQ(ROFF_ARGS)
2879 {
2880 	struct roff_node	*n;
2881 
2882 	if (r->man->macroset == MACROSET_MAN)
2883 		man_breakscope(r->man, ROFF_EQ);
2884 	n = roff_node_alloc(r->man, ln, ppos, ROFFT_EQN, TOKEN_NONE);
2885 	if (ln > r->man->last->line)
2886 		n->flags |= NODE_LINE;
2887 	n->eqn = mandoc_calloc(1, sizeof(*n->eqn));
2888 	n->eqn->expectargs = UINT_MAX;
2889 	roff_node_append(r->man, n);
2890 	r->man->next = ROFF_NEXT_SIBLING;
2891 
2892 	assert(r->eqn == NULL);
2893 	if (r->last_eqn == NULL)
2894 		r->last_eqn = eqn_alloc(r->parse);
2895 	else
2896 		eqn_reset(r->last_eqn);
2897 	r->eqn = r->last_eqn;
2898 	r->eqn->node = n;
2899 
2900 	if (buf->buf[pos] != '\0')
2901 		mandoc_vmsg(MANDOCERR_ARG_SKIP, r->parse, ln, pos,
2902 		    ".EQ %s", buf->buf + pos);
2903 
2904 	return ROFF_IGN;
2905 }
2906 
2907 static enum rofferr
2908 roff_EN(ROFF_ARGS)
2909 {
2910 	if (r->eqn != NULL) {
2911 		eqn_parse(r->eqn);
2912 		r->eqn = NULL;
2913 	} else
2914 		mandoc_msg(MANDOCERR_BLK_NOTOPEN, r->parse, ln, ppos, "EN");
2915 	if (buf->buf[pos] != '\0')
2916 		mandoc_vmsg(MANDOCERR_ARG_SKIP, r->parse, ln, pos,
2917 		    "EN %s", buf->buf + pos);
2918 	return ROFF_IGN;
2919 }
2920 
2921 static enum rofferr
2922 roff_TS(ROFF_ARGS)
2923 {
2924 	if (r->tbl != NULL) {
2925 		mandoc_msg(MANDOCERR_BLK_BROKEN, r->parse,
2926 		    ln, ppos, "TS breaks TS");
2927 		tbl_end(r->tbl);
2928 	}
2929 	r->tbl = tbl_alloc(ppos, ln, r->parse);
2930 	if (r->last_tbl)
2931 		r->last_tbl->next = r->tbl;
2932 	else
2933 		r->first_tbl = r->tbl;
2934 	r->last_tbl = r->tbl;
2935 	return ROFF_IGN;
2936 }
2937 
2938 static enum rofferr
2939 roff_onearg(ROFF_ARGS)
2940 {
2941 	struct roff_node	*n;
2942 	char			*cp;
2943 	int			 npos;
2944 
2945 	if (r->man->flags & (MAN_BLINE | MAN_ELINE) &&
2946 	    (tok == ROFF_ce || tok == ROFF_rj || tok == ROFF_sp ||
2947 	     tok == ROFF_ti))
2948 		man_breakscope(r->man, tok);
2949 
2950 	if (roffce_node != NULL && (tok == ROFF_ce || tok == ROFF_rj)) {
2951 		r->man->last = roffce_node;
2952 		r->man->next = ROFF_NEXT_SIBLING;
2953 	}
2954 
2955 	roff_elem_alloc(r->man, ln, ppos, tok);
2956 	n = r->man->last;
2957 
2958 	cp = buf->buf + pos;
2959 	if (*cp != '\0') {
2960 		while (*cp != '\0' && *cp != ' ')
2961 			cp++;
2962 		while (*cp == ' ')
2963 			*cp++ = '\0';
2964 		if (*cp != '\0')
2965 			mandoc_vmsg(MANDOCERR_ARG_EXCESS,
2966 			    r->parse, ln, cp - buf->buf,
2967 			    "%s ... %s", roff_name[tok], cp);
2968 		roff_word_alloc(r->man, ln, pos, buf->buf + pos);
2969 	}
2970 
2971 	if (tok == ROFF_ce || tok == ROFF_rj) {
2972 		if (r->man->last->type == ROFFT_ELEM) {
2973 			roff_word_alloc(r->man, ln, pos, "1");
2974 			r->man->last->flags |= NODE_NOSRC;
2975 		}
2976 		npos = 0;
2977 		if (roff_evalnum(r, ln, r->man->last->string, &npos,
2978 		    &roffce_lines, 0) == 0) {
2979 			mandoc_vmsg(MANDOCERR_CE_NONUM,
2980 			    r->parse, ln, pos, "ce %s", buf->buf + pos);
2981 			roffce_lines = 1;
2982 		}
2983 		if (roffce_lines < 1) {
2984 			r->man->last = r->man->last->parent;
2985 			roffce_node = NULL;
2986 			roffce_lines = 0;
2987 		} else
2988 			roffce_node = r->man->last->parent;
2989 	} else {
2990 		n->flags |= NODE_VALID | NODE_ENDED;
2991 		r->man->last = n;
2992 	}
2993 	n->flags |= NODE_LINE;
2994 	r->man->next = ROFF_NEXT_SIBLING;
2995 	return ROFF_IGN;
2996 }
2997 
2998 static enum rofferr
2999 roff_manyarg(ROFF_ARGS)
3000 {
3001 	struct roff_node	*n;
3002 	char			*sp, *ep;
3003 
3004 	roff_elem_alloc(r->man, ln, ppos, tok);
3005 	n = r->man->last;
3006 
3007 	for (sp = ep = buf->buf + pos; *sp != '\0'; sp = ep) {
3008 		while (*ep != '\0' && *ep != ' ')
3009 			ep++;
3010 		while (*ep == ' ')
3011 			*ep++ = '\0';
3012 		roff_word_alloc(r->man, ln, sp - buf->buf, sp);
3013 	}
3014 
3015 	n->flags |= NODE_LINE | NODE_VALID | NODE_ENDED;
3016 	r->man->last = n;
3017 	r->man->next = ROFF_NEXT_SIBLING;
3018 	return ROFF_IGN;
3019 }
3020 
3021 static enum rofferr
3022 roff_als(ROFF_ARGS)
3023 {
3024 	char		*oldn, *newn, *end, *value;
3025 	size_t		 oldsz, newsz, valsz;
3026 
3027 	newn = oldn = buf->buf + pos;
3028 	if (*newn == '\0')
3029 		return ROFF_IGN;
3030 
3031 	newsz = roff_getname(r, &oldn, ln, pos);
3032 	if (newn[newsz] == '\\' || *oldn == '\0')
3033 		return ROFF_IGN;
3034 
3035 	end = oldn;
3036 	oldsz = roff_getname(r, &end, ln, oldn - buf->buf);
3037 	if (oldsz == 0)
3038 		return ROFF_IGN;
3039 
3040 	valsz = mandoc_asprintf(&value, ".%.*s \\$*\\\"\n",
3041 	    (int)oldsz, oldn);
3042 	roff_setstrn(&r->strtab, newn, newsz, value, valsz, 0);
3043 	roff_setstrn(&r->rentab, newn, newsz, NULL, 0, 0);
3044 	free(value);
3045 	return ROFF_IGN;
3046 }
3047 
3048 static enum rofferr
3049 roff_br(ROFF_ARGS)
3050 {
3051 	if (r->man->flags & (MAN_BLINE | MAN_ELINE))
3052 		man_breakscope(r->man, ROFF_br);
3053 	roff_elem_alloc(r->man, ln, ppos, ROFF_br);
3054 	if (buf->buf[pos] != '\0')
3055 		mandoc_vmsg(MANDOCERR_ARG_SKIP, r->parse, ln, pos,
3056 		    "%s %s", roff_name[tok], buf->buf + pos);
3057 	r->man->last->flags |= NODE_LINE | NODE_VALID | NODE_ENDED;
3058 	r->man->next = ROFF_NEXT_SIBLING;
3059 	return ROFF_IGN;
3060 }
3061 
3062 static enum rofferr
3063 roff_cc(ROFF_ARGS)
3064 {
3065 	const char	*p;
3066 
3067 	p = buf->buf + pos;
3068 
3069 	if (*p == '\0' || (r->control = *p++) == '.')
3070 		r->control = '\0';
3071 
3072 	if (*p != '\0')
3073 		mandoc_vmsg(MANDOCERR_ARG_EXCESS, r->parse,
3074 		    ln, p - buf->buf, "cc ... %s", p);
3075 
3076 	return ROFF_IGN;
3077 }
3078 
3079 static enum rofferr
3080 roff_ec(ROFF_ARGS)
3081 {
3082 	const char	*p;
3083 
3084 	p = buf->buf + pos;
3085 	if (*p == '\0')
3086 		r->escape = '\\';
3087 	else {
3088 		r->escape = *p;
3089 		if (*++p != '\0')
3090 			mandoc_vmsg(MANDOCERR_ARG_EXCESS, r->parse,
3091 			    ln, p - buf->buf, "ec ... %s", p);
3092 	}
3093 	return ROFF_IGN;
3094 }
3095 
3096 static enum rofferr
3097 roff_eo(ROFF_ARGS)
3098 {
3099 	r->escape = '\0';
3100 	if (buf->buf[pos] != '\0')
3101 		mandoc_vmsg(MANDOCERR_ARG_SKIP, r->parse,
3102 		    ln, pos, "eo %s", buf->buf + pos);
3103 	return ROFF_IGN;
3104 }
3105 
3106 static enum rofferr
3107 roff_tr(ROFF_ARGS)
3108 {
3109 	const char	*p, *first, *second;
3110 	size_t		 fsz, ssz;
3111 	enum mandoc_esc	 esc;
3112 
3113 	p = buf->buf + pos;
3114 
3115 	if (*p == '\0') {
3116 		mandoc_msg(MANDOCERR_REQ_EMPTY, r->parse, ln, ppos, "tr");
3117 		return ROFF_IGN;
3118 	}
3119 
3120 	while (*p != '\0') {
3121 		fsz = ssz = 1;
3122 
3123 		first = p++;
3124 		if (*first == '\\') {
3125 			esc = mandoc_escape(&p, NULL, NULL);
3126 			if (esc == ESCAPE_ERROR) {
3127 				mandoc_msg(MANDOCERR_ESC_BAD, r->parse,
3128 				    ln, (int)(p - buf->buf), first);
3129 				return ROFF_IGN;
3130 			}
3131 			fsz = (size_t)(p - first);
3132 		}
3133 
3134 		second = p++;
3135 		if (*second == '\\') {
3136 			esc = mandoc_escape(&p, NULL, NULL);
3137 			if (esc == ESCAPE_ERROR) {
3138 				mandoc_msg(MANDOCERR_ESC_BAD, r->parse,
3139 				    ln, (int)(p - buf->buf), second);
3140 				return ROFF_IGN;
3141 			}
3142 			ssz = (size_t)(p - second);
3143 		} else if (*second == '\0') {
3144 			mandoc_vmsg(MANDOCERR_TR_ODD, r->parse,
3145 			    ln, first - buf->buf, "tr %s", first);
3146 			second = " ";
3147 			p--;
3148 		}
3149 
3150 		if (fsz > 1) {
3151 			roff_setstrn(&r->xmbtab, first, fsz,
3152 			    second, ssz, 0);
3153 			continue;
3154 		}
3155 
3156 		if (r->xtab == NULL)
3157 			r->xtab = mandoc_calloc(128,
3158 			    sizeof(struct roffstr));
3159 
3160 		free(r->xtab[(int)*first].p);
3161 		r->xtab[(int)*first].p = mandoc_strndup(second, ssz);
3162 		r->xtab[(int)*first].sz = ssz;
3163 	}
3164 
3165 	return ROFF_IGN;
3166 }
3167 
3168 static enum rofferr
3169 roff_rn(ROFF_ARGS)
3170 {
3171 	const char	*value;
3172 	char		*oldn, *newn, *end;
3173 	size_t		 oldsz, newsz;
3174 	int		 deftype;
3175 
3176 	oldn = newn = buf->buf + pos;
3177 	if (*oldn == '\0')
3178 		return ROFF_IGN;
3179 
3180 	oldsz = roff_getname(r, &newn, ln, pos);
3181 	if (oldn[oldsz] == '\\' || *newn == '\0')
3182 		return ROFF_IGN;
3183 
3184 	end = newn;
3185 	newsz = roff_getname(r, &end, ln, newn - buf->buf);
3186 	if (newsz == 0)
3187 		return ROFF_IGN;
3188 
3189 	deftype = ROFFDEF_ANY;
3190 	value = roff_getstrn(r, oldn, oldsz, &deftype);
3191 	switch (deftype) {
3192 	case ROFFDEF_USER:
3193 		roff_setstrn(&r->strtab, newn, newsz, value, strlen(value), 0);
3194 		roff_setstrn(&r->strtab, oldn, oldsz, NULL, 0, 0);
3195 		roff_setstrn(&r->rentab, newn, newsz, NULL, 0, 0);
3196 		break;
3197 	case ROFFDEF_PRE:
3198 		roff_setstrn(&r->strtab, newn, newsz, value, strlen(value), 0);
3199 		roff_setstrn(&r->rentab, newn, newsz, NULL, 0, 0);
3200 		break;
3201 	case ROFFDEF_REN:
3202 		roff_setstrn(&r->rentab, newn, newsz, value, strlen(value), 0);
3203 		roff_setstrn(&r->rentab, oldn, oldsz, NULL, 0, 0);
3204 		roff_setstrn(&r->strtab, newn, newsz, NULL, 0, 0);
3205 		break;
3206 	case ROFFDEF_STD:
3207 		roff_setstrn(&r->rentab, newn, newsz, oldn, oldsz, 0);
3208 		roff_setstrn(&r->strtab, newn, newsz, NULL, 0, 0);
3209 		break;
3210 	default:
3211 		roff_setstrn(&r->strtab, newn, newsz, NULL, 0, 0);
3212 		roff_setstrn(&r->rentab, newn, newsz, NULL, 0, 0);
3213 		break;
3214 	}
3215 	return ROFF_IGN;
3216 }
3217 
3218 static enum rofferr
3219 roff_so(ROFF_ARGS)
3220 {
3221 	char *name, *cp;
3222 
3223 	name = buf->buf + pos;
3224 	mandoc_vmsg(MANDOCERR_SO, r->parse, ln, ppos, "so %s", name);
3225 
3226 	/*
3227 	 * Handle `so'.  Be EXTREMELY careful, as we shouldn't be
3228 	 * opening anything that's not in our cwd or anything beneath
3229 	 * it.  Thus, explicitly disallow traversing up the file-system
3230 	 * or using absolute paths.
3231 	 */
3232 
3233 	if (*name == '/' || strstr(name, "../") || strstr(name, "/..")) {
3234 		mandoc_vmsg(MANDOCERR_SO_PATH, r->parse, ln, ppos,
3235 		    ".so %s", name);
3236 		buf->sz = mandoc_asprintf(&cp,
3237 		    ".sp\nSee the file %s.\n.sp", name) + 1;
3238 		free(buf->buf);
3239 		buf->buf = cp;
3240 		*offs = 0;
3241 		return ROFF_REPARSE;
3242 	}
3243 
3244 	*offs = pos;
3245 	return ROFF_SO;
3246 }
3247 
3248 /* --- user defined strings and macros ------------------------------------ */
3249 
3250 static enum rofferr
3251 roff_userdef(ROFF_ARGS)
3252 {
3253 	const char	 *arg[16], *ap;
3254 	char		 *cp, *n1, *n2;
3255 	int		  expand_count, i, ib, ie;
3256 	size_t		  asz, rsz;
3257 
3258 	/*
3259 	 * Collect pointers to macro argument strings
3260 	 * and NUL-terminate them.
3261 	 */
3262 
3263 	r->argc = 0;
3264 	cp = buf->buf + pos;
3265 	for (i = 0; i < 16; i++) {
3266 		if (*cp == '\0')
3267 			arg[i] = "";
3268 		else {
3269 			arg[i] = mandoc_getarg(r->parse, &cp, ln, &pos);
3270 			r->argc = i + 1;
3271 		}
3272 	}
3273 
3274 	/*
3275 	 * Expand macro arguments.
3276 	 */
3277 
3278 	buf->sz = strlen(r->current_string) + 1;
3279 	n1 = n2 = cp = mandoc_malloc(buf->sz);
3280 	memcpy(n1, r->current_string, buf->sz);
3281 	expand_count = 0;
3282 	while (*cp != '\0') {
3283 
3284 		/* Scan ahead for the next argument invocation. */
3285 
3286 		if (*cp++ != '\\')
3287 			continue;
3288 		if (*cp++ != '$')
3289 			continue;
3290 		if (*cp == '*') {  /* \\$* inserts all arguments */
3291 			ib = 0;
3292 			ie = r->argc - 1;
3293 		} else {  /* \\$1 .. \\$9 insert one argument */
3294 			ib = ie = *cp - '1';
3295 			if (ib < 0 || ib > 8)
3296 				continue;
3297 		}
3298 		cp -= 2;
3299 
3300 		/*
3301 		 * Prevent infinite recursion.
3302 		 */
3303 
3304 		if (cp >= n2)
3305 			expand_count = 1;
3306 		else if (++expand_count > EXPAND_LIMIT) {
3307 			mandoc_msg(MANDOCERR_ROFFLOOP, r->parse,
3308 			    ln, (int)(cp - n1), NULL);
3309 			free(buf->buf);
3310 			buf->buf = n1;
3311 			return ROFF_IGN;
3312 		}
3313 
3314 		/*
3315 		 * Determine the size of the expanded argument,
3316 		 * taking escaping of quotes into account.
3317 		 */
3318 
3319 		asz = ie > ib ? ie - ib : 0;  /* for blanks */
3320 		for (i = ib; i <= ie; i++) {
3321 			for (ap = arg[i]; *ap != '\0'; ap++) {
3322 				asz++;
3323 				if (*ap == '"')
3324 					asz += 3;
3325 			}
3326 		}
3327 		if (asz != 3) {
3328 
3329 			/*
3330 			 * Determine the size of the rest of the
3331 			 * unexpanded macro, including the NUL.
3332 			 */
3333 
3334 			rsz = buf->sz - (cp - n1) - 3;
3335 
3336 			/*
3337 			 * When shrinking, move before
3338 			 * releasing the storage.
3339 			 */
3340 
3341 			if (asz < 3)
3342 				memmove(cp + asz, cp + 3, rsz);
3343 
3344 			/*
3345 			 * Resize the storage for the macro
3346 			 * and readjust the parse pointer.
3347 			 */
3348 
3349 			buf->sz += asz - 3;
3350 			n2 = mandoc_realloc(n1, buf->sz);
3351 			cp = n2 + (cp - n1);
3352 			n1 = n2;
3353 
3354 			/*
3355 			 * When growing, make room
3356 			 * for the expanded argument.
3357 			 */
3358 
3359 			if (asz > 3)
3360 				memmove(cp + asz, cp + 3, rsz);
3361 		}
3362 
3363 		/* Copy the expanded argument, escaping quotes. */
3364 
3365 		n2 = cp;
3366 		for (i = ib; i <= ie; i++) {
3367 			for (ap = arg[i]; *ap != '\0'; ap++) {
3368 				if (*ap == '"') {
3369 					memcpy(n2, "\\(dq", 4);
3370 					n2 += 4;
3371 				} else
3372 					*n2++ = *ap;
3373 			}
3374 			if (i < ie)
3375 				*n2++ = ' ';
3376 		}
3377 	}
3378 
3379 	/*
3380 	 * Replace the macro invocation
3381 	 * by the expanded macro.
3382 	 */
3383 
3384 	free(buf->buf);
3385 	buf->buf = n1;
3386 	*offs = 0;
3387 
3388 	return buf->sz > 1 && buf->buf[buf->sz - 2] == '\n' ?
3389 	   ROFF_REPARSE : ROFF_APPEND;
3390 }
3391 
3392 /*
3393  * Calling a high-level macro that was renamed with .rn.
3394  * r->current_string has already been set up by roff_parse().
3395  */
3396 static enum rofferr
3397 roff_renamed(ROFF_ARGS)
3398 {
3399 	char	*nbuf;
3400 
3401 	buf->sz = mandoc_asprintf(&nbuf, ".%s%s%s", r->current_string,
3402 	    buf->buf[pos] == '\0' ? "" : " ", buf->buf + pos) + 1;
3403 	free(buf->buf);
3404 	buf->buf = nbuf;
3405 	return ROFF_CONT;
3406 }
3407 
3408 static size_t
3409 roff_getname(struct roff *r, char **cpp, int ln, int pos)
3410 {
3411 	char	 *name, *cp;
3412 	size_t	  namesz;
3413 
3414 	name = *cpp;
3415 	if ('\0' == *name)
3416 		return 0;
3417 
3418 	/* Read until end of name and terminate it with NUL. */
3419 	for (cp = name; 1; cp++) {
3420 		if ('\0' == *cp || ' ' == *cp) {
3421 			namesz = cp - name;
3422 			break;
3423 		}
3424 		if ('\\' != *cp)
3425 			continue;
3426 		namesz = cp - name;
3427 		if ('{' == cp[1] || '}' == cp[1])
3428 			break;
3429 		cp++;
3430 		if ('\\' == *cp)
3431 			continue;
3432 		mandoc_vmsg(MANDOCERR_NAMESC, r->parse, ln, pos,
3433 		    "%.*s", (int)(cp - name + 1), name);
3434 		mandoc_escape((const char **)&cp, NULL, NULL);
3435 		break;
3436 	}
3437 
3438 	/* Read past spaces. */
3439 	while (' ' == *cp)
3440 		cp++;
3441 
3442 	*cpp = cp;
3443 	return namesz;
3444 }
3445 
3446 /*
3447  * Store *string into the user-defined string called *name.
3448  * To clear an existing entry, call with (*r, *name, NULL, 0).
3449  * append == 0: replace mode
3450  * append == 1: single-line append mode
3451  * append == 2: multiline append mode, append '\n' after each call
3452  */
3453 static void
3454 roff_setstr(struct roff *r, const char *name, const char *string,
3455 	int append)
3456 {
3457 	size_t	 namesz;
3458 
3459 	namesz = strlen(name);
3460 	roff_setstrn(&r->strtab, name, namesz, string,
3461 	    string ? strlen(string) : 0, append);
3462 	roff_setstrn(&r->rentab, name, namesz, NULL, 0, 0);
3463 }
3464 
3465 static void
3466 roff_setstrn(struct roffkv **r, const char *name, size_t namesz,
3467 		const char *string, size_t stringsz, int append)
3468 {
3469 	struct roffkv	*n;
3470 	char		*c;
3471 	int		 i;
3472 	size_t		 oldch, newch;
3473 
3474 	/* Search for an existing string with the same name. */
3475 	n = *r;
3476 
3477 	while (n && (namesz != n->key.sz ||
3478 			strncmp(n->key.p, name, namesz)))
3479 		n = n->next;
3480 
3481 	if (NULL == n) {
3482 		/* Create a new string table entry. */
3483 		n = mandoc_malloc(sizeof(struct roffkv));
3484 		n->key.p = mandoc_strndup(name, namesz);
3485 		n->key.sz = namesz;
3486 		n->val.p = NULL;
3487 		n->val.sz = 0;
3488 		n->next = *r;
3489 		*r = n;
3490 	} else if (0 == append) {
3491 		free(n->val.p);
3492 		n->val.p = NULL;
3493 		n->val.sz = 0;
3494 	}
3495 
3496 	if (NULL == string)
3497 		return;
3498 
3499 	/*
3500 	 * One additional byte for the '\n' in multiline mode,
3501 	 * and one for the terminating '\0'.
3502 	 */
3503 	newch = stringsz + (1 < append ? 2u : 1u);
3504 
3505 	if (NULL == n->val.p) {
3506 		n->val.p = mandoc_malloc(newch);
3507 		*n->val.p = '\0';
3508 		oldch = 0;
3509 	} else {
3510 		oldch = n->val.sz;
3511 		n->val.p = mandoc_realloc(n->val.p, oldch + newch);
3512 	}
3513 
3514 	/* Skip existing content in the destination buffer. */
3515 	c = n->val.p + (int)oldch;
3516 
3517 	/* Append new content to the destination buffer. */
3518 	i = 0;
3519 	while (i < (int)stringsz) {
3520 		/*
3521 		 * Rudimentary roff copy mode:
3522 		 * Handle escaped backslashes.
3523 		 */
3524 		if ('\\' == string[i] && '\\' == string[i + 1])
3525 			i++;
3526 		*c++ = string[i++];
3527 	}
3528 
3529 	/* Append terminating bytes. */
3530 	if (1 < append)
3531 		*c++ = '\n';
3532 
3533 	*c = '\0';
3534 	n->val.sz = (int)(c - n->val.p);
3535 }
3536 
3537 static const char *
3538 roff_getstrn(const struct roff *r, const char *name, size_t len,
3539     int *deftype)
3540 {
3541 	const struct roffkv	*n;
3542 	int			 i;
3543 	enum roff_tok		 tok;
3544 
3545 	if (*deftype & ROFFDEF_USER) {
3546 		for (n = r->strtab; n != NULL; n = n->next) {
3547 			if (strncmp(name, n->key.p, len) == 0 &&
3548 			    n->key.p[len] == '\0' &&
3549 			    n->val.p != NULL) {
3550 				*deftype = ROFFDEF_USER;
3551 				return n->val.p;
3552 			}
3553 		}
3554 	}
3555 	if (*deftype & ROFFDEF_PRE) {
3556 		for (i = 0; i < PREDEFS_MAX; i++) {
3557 			if (strncmp(name, predefs[i].name, len) == 0 &&
3558 			    predefs[i].name[len] == '\0') {
3559 				*deftype = ROFFDEF_PRE;
3560 				return predefs[i].str;
3561 			}
3562 		}
3563 	}
3564 	if (*deftype & ROFFDEF_REN) {
3565 		for (n = r->rentab; n != NULL; n = n->next) {
3566 			if (strncmp(name, n->key.p, len) == 0 &&
3567 			    n->key.p[len] == '\0' &&
3568 			    n->val.p != NULL) {
3569 				*deftype = ROFFDEF_REN;
3570 				return n->val.p;
3571 			}
3572 		}
3573 	}
3574 	if (*deftype & ROFFDEF_STD) {
3575 		if (r->man->macroset != MACROSET_MAN) {
3576 			for (tok = MDOC_Dd; tok < MDOC_MAX; tok++) {
3577 				if (strncmp(name, roff_name[tok], len) == 0 &&
3578 				    roff_name[tok][len] == '\0') {
3579 					*deftype = ROFFDEF_STD;
3580 					return NULL;
3581 				}
3582 			}
3583 		}
3584 		if (r->man->macroset != MACROSET_MDOC) {
3585 			for (tok = MAN_TH; tok < MAN_MAX; tok++) {
3586 				if (strncmp(name, roff_name[tok], len) == 0 &&
3587 				    roff_name[tok][len] == '\0') {
3588 					*deftype = ROFFDEF_STD;
3589 					return NULL;
3590 				}
3591 			}
3592 		}
3593 	}
3594 	*deftype = 0;
3595 	return NULL;
3596 }
3597 
3598 static void
3599 roff_freestr(struct roffkv *r)
3600 {
3601 	struct roffkv	 *n, *nn;
3602 
3603 	for (n = r; n; n = nn) {
3604 		free(n->key.p);
3605 		free(n->val.p);
3606 		nn = n->next;
3607 		free(n);
3608 	}
3609 }
3610 
3611 /* --- accessors and utility functions ------------------------------------ */
3612 
3613 /*
3614  * Duplicate an input string, making the appropriate character
3615  * conversations (as stipulated by `tr') along the way.
3616  * Returns a heap-allocated string with all the replacements made.
3617  */
3618 char *
3619 roff_strdup(const struct roff *r, const char *p)
3620 {
3621 	const struct roffkv *cp;
3622 	char		*res;
3623 	const char	*pp;
3624 	size_t		 ssz, sz;
3625 	enum mandoc_esc	 esc;
3626 
3627 	if (NULL == r->xmbtab && NULL == r->xtab)
3628 		return mandoc_strdup(p);
3629 	else if ('\0' == *p)
3630 		return mandoc_strdup("");
3631 
3632 	/*
3633 	 * Step through each character looking for term matches
3634 	 * (remember that a `tr' can be invoked with an escape, which is
3635 	 * a glyph but the escape is multi-character).
3636 	 * We only do this if the character hash has been initialised
3637 	 * and the string is >0 length.
3638 	 */
3639 
3640 	res = NULL;
3641 	ssz = 0;
3642 
3643 	while ('\0' != *p) {
3644 		assert((unsigned int)*p < 128);
3645 		if ('\\' != *p && r->xtab && r->xtab[(unsigned int)*p].p) {
3646 			sz = r->xtab[(int)*p].sz;
3647 			res = mandoc_realloc(res, ssz + sz + 1);
3648 			memcpy(res + ssz, r->xtab[(int)*p].p, sz);
3649 			ssz += sz;
3650 			p++;
3651 			continue;
3652 		} else if ('\\' != *p) {
3653 			res = mandoc_realloc(res, ssz + 2);
3654 			res[ssz++] = *p++;
3655 			continue;
3656 		}
3657 
3658 		/* Search for term matches. */
3659 		for (cp = r->xmbtab; cp; cp = cp->next)
3660 			if (0 == strncmp(p, cp->key.p, cp->key.sz))
3661 				break;
3662 
3663 		if (NULL != cp) {
3664 			/*
3665 			 * A match has been found.
3666 			 * Append the match to the array and move
3667 			 * forward by its keysize.
3668 			 */
3669 			res = mandoc_realloc(res,
3670 			    ssz + cp->val.sz + 1);
3671 			memcpy(res + ssz, cp->val.p, cp->val.sz);
3672 			ssz += cp->val.sz;
3673 			p += (int)cp->key.sz;
3674 			continue;
3675 		}
3676 
3677 		/*
3678 		 * Handle escapes carefully: we need to copy
3679 		 * over just the escape itself, or else we might
3680 		 * do replacements within the escape itself.
3681 		 * Make sure to pass along the bogus string.
3682 		 */
3683 		pp = p++;
3684 		esc = mandoc_escape(&p, NULL, NULL);
3685 		if (ESCAPE_ERROR == esc) {
3686 			sz = strlen(pp);
3687 			res = mandoc_realloc(res, ssz + sz + 1);
3688 			memcpy(res + ssz, pp, sz);
3689 			break;
3690 		}
3691 		/*
3692 		 * We bail out on bad escapes.
3693 		 * No need to warn: we already did so when
3694 		 * roff_res() was called.
3695 		 */
3696 		sz = (int)(p - pp);
3697 		res = mandoc_realloc(res, ssz + sz + 1);
3698 		memcpy(res + ssz, pp, sz);
3699 		ssz += sz;
3700 	}
3701 
3702 	res[(int)ssz] = '\0';
3703 	return res;
3704 }
3705 
3706 int
3707 roff_getformat(const struct roff *r)
3708 {
3709 
3710 	return r->format;
3711 }
3712 
3713 /*
3714  * Find out whether a line is a macro line or not.
3715  * If it is, adjust the current position and return one; if it isn't,
3716  * return zero and don't change the current position.
3717  * If the control character has been set with `.cc', then let that grain
3718  * precedence.
3719  * This is slighly contrary to groff, where using the non-breaking
3720  * control character when `cc' has been invoked will cause the
3721  * non-breaking macro contents to be printed verbatim.
3722  */
3723 int
3724 roff_getcontrol(const struct roff *r, const char *cp, int *ppos)
3725 {
3726 	int		pos;
3727 
3728 	pos = *ppos;
3729 
3730 	if (r->control != '\0' && cp[pos] == r->control)
3731 		pos++;
3732 	else if (r->control != '\0')
3733 		return 0;
3734 	else if ('\\' == cp[pos] && '.' == cp[pos + 1])
3735 		pos += 2;
3736 	else if ('.' == cp[pos] || '\'' == cp[pos])
3737 		pos++;
3738 	else
3739 		return 0;
3740 
3741 	while (' ' == cp[pos] || '\t' == cp[pos])
3742 		pos++;
3743 
3744 	*ppos = pos;
3745 	return 1;
3746 }
3747