]> git.cameronkatri.com Git - mandoc.git/blobdiff - mdoc_validate.c
Protect against malicious manual pages containing .ll requests with
[mandoc.git] / mdoc_validate.c
index da9be6d113589f7b2285a5ba077bb82197dbb73e..d455523e4785c27d79569e38ee5c24d6816fc668 100644 (file)
@@ -1,7 +1,7 @@
-/*     $Id: mdoc_validate.c,v 1.342 2017/06/24 18:58:33 schwarze Exp $ */
+/*     $Id: mdoc_validate.c,v 1.358 2018/04/11 17:11:13 schwarze Exp $ */
 /*
  * Copyright (c) 2008-2012 Kristaps Dzonsons <kristaps@bsd.lv>
- * Copyright (c) 2010-2017 Ingo Schwarze <schwarze@openbsd.org>
+ * Copyright (c) 2010-2018 Ingo Schwarze <schwarze@openbsd.org>
  * Copyright (c) 2010 Joerg Sonnenberger <joerg@netbsd.org>
  *
  * Permission to use, copy, modify, and distribute this software for any
@@ -33,6 +33,7 @@
 
 #include "mandoc_aux.h"
 #include "mandoc.h"
+#include "mandoc_xr.h"
 #include "roff.h"
 #include "mdoc.h"
 #include "libmandoc.h"
@@ -52,14 +53,16 @@ enum        check_ineq {
 typedef        void    (*v_post)(POST_ARGS);
 
 static int      build_list(struct roff_man *, int);
-static void     check_text(struct roff_man *, int, int, char *);
 static void     check_argv(struct roff_man *,
                        struct roff_node *, struct mdoc_argv *);
 static void     check_args(struct roff_man *, struct roff_node *);
+static void     check_text(struct roff_man *, int, int, char *);
+static void     check_text_em(struct roff_man *, int, int, char *);
 static void     check_toptext(struct roff_man *, int, int, const char *);
 static int      child_an(const struct roff_node *);
 static size_t          macro2len(enum roff_tok);
 static void     rewrite_macro2len(struct roff_man *, char **);
+static int      similar(const char *, const char *);
 
 static void     post_an(POST_ARGS);
 static void     post_an_norm(POST_ARGS);
@@ -76,6 +79,7 @@ static        void     post_defaults(POST_ARGS);
 static void     post_display(POST_ARGS);
 static void     post_dd(POST_ARGS);
 static void     post_delim(POST_ARGS);
+static void     post_delim_nb(POST_ARGS);
 static void     post_dt(POST_ARGS);
 static void     post_en(POST_ARGS);
 static void     post_es(POST_ARGS);
@@ -107,6 +111,7 @@ static      void     post_sh_authors(POST_ARGS);
 static void     post_sm(POST_ARGS);
 static void     post_st(POST_ARGS);
 static void     post_std(POST_ARGS);
+static void     post_sx(POST_ARGS);
 static void     post_useless(POST_ARGS);
 static void     post_xr(POST_ARGS);
 static void     post_xx(POST_ARGS);
@@ -125,33 +130,33 @@ static    const v_post __mdoc_valids[MDOC_MAX - MDOC_Dd] = {
        post_bl,        /* Bl */
        NULL,           /* El */
        post_it,        /* It */
-       post_delim,     /* Ad */
+       post_delim_nb,  /* Ad */
        post_an,        /* An */
        NULL,           /* Ap */
        post_defaults,  /* Ar */
        NULL,           /* Cd */
-       post_delim,     /* Cm */
-       post_delim,     /* Dv */
-       post_delim,     /* Er */
-       post_delim,     /* Ev */
+       post_delim_nb,  /* Cm */
+       post_delim_nb,  /* Dv */
+       post_delim_nb,  /* Er */
+       post_delim_nb,  /* Ev */
        post_ex,        /* Ex */
        post_fa,        /* Fa */
        NULL,           /* Fd */
-       post_delim,     /* Fl */
+       post_delim_nb,  /* Fl */
        post_fn,        /* Fn */
-       post_delim,     /* Ft */
-       post_delim,     /* Ic */
-       post_delim,     /* In */
+       post_delim_nb,  /* Ft */
+       post_delim_nb,  /* Ic */
+       post_delim_nb,  /* In */
        post_defaults,  /* Li */
        post_nd,        /* Nd */
        post_nm,        /* Nm */
-       post_delim,     /* Op */
+       post_delim_nb,  /* Op */
        post_obsolete,  /* Ot */
        post_defaults,  /* Pa */
        post_rv,        /* Rv */
        post_st,        /* St */
-       post_delim,     /* Va */
-       post_delim,     /* Vt */
+       post_delim_nb,  /* Va */
+       post_delim_nb,  /* Vt */
        post_xr,        /* Xr */
        NULL,           /* %A */
        post_hyph,      /* %B */ /* FIXME: can be used outside Rs/Re. */
@@ -165,12 +170,12 @@ static    const v_post __mdoc_valids[MDOC_MAX - MDOC_Dd] = {
        post_hyph,      /* %T */ /* FIXME: can be used outside Rs/Re. */
        NULL,           /* %V */
        NULL,           /* Ac */
-       post_delim,     /* Ao */
-       post_delim,     /* Aq */
+       NULL,           /* Ao */
+       post_delim_nb,  /* Aq */
        post_at,        /* At */
        NULL,           /* Bc */
        post_bf,        /* Bf */
-       post_delim,     /* Bo */
+       NULL,           /* Bo */
        NULL,           /* Bq */
        post_xx,        /* Bsx */
        post_bx,        /* Bx */
@@ -180,37 +185,37 @@ static    const v_post __mdoc_valids[MDOC_MAX - MDOC_Dd] = {
        NULL,           /* Dq */
        NULL,           /* Ec */
        NULL,           /* Ef */
-       post_delim,     /* Em */
+       post_delim_nb,  /* Em */
        NULL,           /* Eo */
        post_xx,        /* Fx */
-       post_delim,     /* Ms */
+       post_delim_nb,  /* Ms */
        NULL,           /* No */
        post_ns,        /* Ns */
        post_xx,        /* Nx */
        post_xx,        /* Ox */
        NULL,           /* Pc */
        NULL,           /* Pf */
-       post_delim,     /* Po */
-       post_delim,     /* Pq */
+       NULL,           /* Po */
+       post_delim_nb,  /* Pq */
        NULL,           /* Qc */
-       post_delim,     /* Ql */
-       post_delim,     /* Qo */
-       post_delim,     /* Qq */
+       post_delim_nb,  /* Ql */
+       NULL,           /* Qo */
+       post_delim_nb,  /* Qq */
        NULL,           /* Re */
        post_rs,        /* Rs */
        NULL,           /* Sc */
-       post_delim,     /* So */
-       post_delim,     /* Sq */
+       NULL,           /* So */
+       post_delim_nb,  /* Sq */
        post_sm,        /* Sm */
-       post_hyph,      /* Sx */
-       post_delim,     /* Sy */
+       post_sx,        /* Sx */
+       post_delim_nb,  /* Sy */
        post_useless,   /* Tn */
        post_xx,        /* Ux */
        NULL,           /* Xc */
        NULL,           /* Xo */
        post_fo,        /* Fo */
        NULL,           /* Fc */
-       post_delim,     /* Oo */
+       NULL,           /* Oo */
        NULL,           /* Oc */
        post_bk,        /* Bk */
        NULL,           /* Ek */
@@ -220,10 +225,10 @@ static    const v_post __mdoc_valids[MDOC_MAX - MDOC_Dd] = {
        post_eoln,      /* Ud */
        post_lb,        /* Lb */
        post_par,       /* Lp */
-       post_delim,     /* Lk */
+       post_delim_nb,  /* Lk */
        post_defaults,  /* Mt */
-       post_delim,     /* Brq */
-       post_delim,     /* Bro */
+       post_delim_nb,  /* Brq */
+       NULL,           /* Bro */
        NULL,           /* Brc */
        NULL,           /* %C */
        post_es,        /* Es */
@@ -284,7 +289,7 @@ static      const char * const secnames[SEC__MAX] = {
 void
 mdoc_node_validate(struct roff_man *mdoc)
 {
-       struct roff_node *n;
+       struct roff_node *n, *np;
        const v_post *p;
 
        n = mdoc->last;
@@ -301,15 +306,21 @@ mdoc_node_validate(struct roff_man *mdoc)
        mdoc->next = ROFF_NEXT_SIBLING;
        switch (n->type) {
        case ROFFT_TEXT:
+               np = n->parent;
                if (n->sec != SEC_SYNOPSIS ||
-                   (n->parent->tok != MDOC_Cd && n->parent->tok != MDOC_Fd))
+                   (np->tok != MDOC_Cd && np->tok != MDOC_Fd))
                        check_text(mdoc, n->line, n->pos, n->string);
-               if (n->parent->tok == MDOC_It ||
-                   (n->parent->type == ROFFT_BODY &&
-                    (n->parent->tok == MDOC_Sh ||
-                     n->parent->tok == MDOC_Ss)))
+               if (np->tok != MDOC_Ql && np->tok != MDOC_Dl &&
+                   (np->tok != MDOC_Bd ||
+                    (mdoc->flags & MDOC_LITERAL) == 0) &&
+                   (np->tok != MDOC_It || np->type != ROFFT_HEAD ||
+                    np->parent->parent->norm->Bl.type != LIST_diag))
+                       check_text_em(mdoc, n->line, n->pos, n->string);
+               if (np->tok == MDOC_It || (np->type == ROFFT_BODY &&
+                   (np->tok == MDOC_Sh || np->tok == MDOC_Ss)))
                        check_toptext(mdoc, n->line, n->pos, n->string);
                break;
+       case ROFFT_COMMENT:
        case ROFFT_EQN:
        case ROFFT_TBL:
                break;
@@ -390,6 +401,58 @@ check_text(struct roff_man *mdoc, int ln, int pos, char *p)
                    ln, pos + (int)(p - cp), NULL);
 }
 
+static void
+check_text_em(struct roff_man *mdoc, int ln, int pos, char *p)
+{
+       const struct roff_node  *np, *nn;
+       char                    *cp;
+
+       np = mdoc->last->prev;
+       nn = mdoc->last->next;
+
+       /* Look for em-dashes wrongly encoded as "--". */
+
+       for (cp = p; *cp != '\0'; cp++) {
+               if (cp[0] != '-' || cp[1] != '-')
+                       continue;
+               cp++;
+
+               /* Skip input sequences of more than two '-'. */
+
+               if (cp[1] == '-') {
+                       while (cp[1] == '-')
+                               cp++;
+                       continue;
+               }
+
+               /* Skip "--" directly attached to something else. */
+
+               if ((cp - p > 1 && cp[-2] != ' ') ||
+                   (cp[1] != '\0' && cp[1] != ' '))
+                       continue;
+
+               /* Require a letter right before or right afterwards. */
+
+               if ((cp - p > 2 ?
+                    isalpha((unsigned char)cp[-3]) :
+                    np != NULL &&
+                    np->type == ROFFT_TEXT &&
+                    np->string != '\0' &&
+                    isalpha((unsigned char)np->string[
+                      strlen(np->string) - 1])) ||
+                   (cp[2] != '\0' ?
+                    isalpha((unsigned char)cp[2]) :
+                    nn != NULL &&
+                    nn->type == ROFFT_TEXT &&
+                    nn->string != '\0' &&
+                    isalpha((unsigned char)*nn->string))) {
+                       mandoc_msg(MANDOCERR_DASHDASH, mdoc->parse,
+                           ln, pos + (int)(cp - p) - 1, NULL);
+                       break;
+               }
+       }
+}
+
 static void
 check_toptext(struct roff_man *mdoc, int ln, int pos, const char *p)
 {
@@ -427,6 +490,34 @@ check_toptext(struct roff_man *mdoc, int ln, int pos, const char *p)
 
 static void
 post_delim(POST_ARGS)
+{
+       const struct roff_node  *nch;
+       const char              *lc;
+       enum mdelim              delim;
+       enum roff_tok            tok;
+
+       tok = mdoc->last->tok;
+       nch = mdoc->last->last;
+       if (nch == NULL || nch->type != ROFFT_TEXT)
+               return;
+       lc = strchr(nch->string, '\0') - 1;
+       if (lc < nch->string)
+               return;
+       delim = mdoc_isdelim(lc);
+       if (delim == DELIM_NONE || delim == DELIM_OPEN)
+               return;
+       if (*lc == ')' && (tok == MDOC_Nd || tok == MDOC_Sh ||
+           tok == MDOC_Ss || tok == MDOC_Fo))
+               return;
+
+       mandoc_vmsg(MANDOCERR_DELIM, mdoc->parse,
+           nch->line, nch->pos + (lc - nch->string),
+           "%s%s %s", roff_name[tok],
+           nch == mdoc->last->child ? "" : " ...", nch->string);
+}
+
+static void
+post_delim_nb(POST_ARGS)
 {
        const struct roff_node  *nch;
        const char              *lc, *cp;
@@ -498,8 +589,7 @@ post_delim(POST_ARGS)
 
        /* At least three alphabetic words with a sentence ending. */
        if (strchr("!.:?", *lc) != NULL && (tok == MDOC_Em ||
-           tok == MDOC_Li || tok == MDOC_Po || tok == MDOC_Pq ||
-           tok == MDOC_Sy)) {
+           tok == MDOC_Li || tok == MDOC_Pq || tok == MDOC_Sy)) {
                nw = 0;
                for (cp = lc - 1; cp >= nch->string; cp--) {
                        if (*cp == ' ') {
@@ -514,7 +604,7 @@ post_delim(POST_ARGS)
                }
        }
 
-       mandoc_vmsg(MANDOCERR_DELIM, mdoc->parse,
+       mandoc_vmsg(MANDOCERR_DELIM_NB, mdoc->parse,
            nch->line, nch->pos + (lc - nch->string),
            "%s%s %s", roff_name[tok],
            nch == mdoc->last->child ? "" : " ...", nch->string);
@@ -668,7 +758,7 @@ post_bl_norm(POST_ARGS)
 
        switch (n->norm->Bl.type) {
        case LIST_tag:
-               if (NULL == n->norm->Bl.width)
+               if (n->norm->Bl.width == NULL)
                        mandoc_msg(MANDOCERR_BL_NOWIDTH, mdoc->parse,
                            n->line, n->pos, "Bl -tag");
                break;
@@ -677,19 +767,20 @@ post_bl_norm(POST_ARGS)
        case LIST_ohang:
        case LIST_inset:
        case LIST_item:
-               if (n->norm->Bl.width)
+               if (n->norm->Bl.width != NULL)
                        mandoc_vmsg(MANDOCERR_BL_SKIPW, mdoc->parse,
                            wa->line, wa->pos, "Bl -%s",
                            mdoc_argnames[mdoclt]);
+               n->norm->Bl.width = NULL;
                break;
        case LIST_bullet:
        case LIST_dash:
        case LIST_hyphen:
-               if (NULL == n->norm->Bl.width)
+               if (n->norm->Bl.width == NULL)
                        n->norm->Bl.width = "2n";
                break;
        case LIST_enum:
-               if (NULL == n->norm->Bl.width)
+               if (n->norm->Bl.width == NULL)
                        n->norm->Bl.width = "3n";
                break;
        default:
@@ -895,7 +986,7 @@ post_lb(POST_ARGS)
        struct roff_node        *n;
        const char              *p;
 
-       post_delim(mdoc);
+       post_delim_nb(mdoc);
 
        n = mdoc->last;
        assert(n->child->type == ROFFT_TEXT);
@@ -914,10 +1005,10 @@ post_lb(POST_ARGS)
 
        roff_word_alloc(mdoc, n->line, n->pos, "library");
        mdoc->last->flags = NODE_NOSRC;
-       roff_word_alloc(mdoc, n->line, n->pos, "\\(Lq");
+       roff_word_alloc(mdoc, n->line, n->pos, "\\(lq");
        mdoc->last->flags = NODE_DELIMO | NODE_NOSRC;
        mdoc->last = mdoc->last->next;
-       roff_word_alloc(mdoc, n->line, n->pos, "\\(Rq");
+       roff_word_alloc(mdoc, n->line, n->pos, "\\(rq");
        mdoc->last->flags = NODE_DELIMC | NODE_NOSRC;
        mdoc->last = n;
 }
@@ -966,6 +1057,8 @@ post_std(POST_ARGS)
 {
        struct roff_node *n;
 
+       post_delim(mdoc);
+
        n = mdoc->last;
        if (n->args && n->args->argc == 1)
                if (n->args->argv[0].arg == MDOC_Std)
@@ -1133,7 +1226,8 @@ post_fo(POST_ARGS)
                    "Fo ... %s", n->child->next->string);
                while (n->child != n->last)
                        roff_node_delete(mdoc, n->last);
-       }
+       } else
+               post_delim(mdoc);
 
        post_fname(mdoc);
 }
@@ -1157,7 +1251,7 @@ post_fa(POST_ARGS)
                        break;
                }
        }
-       post_delim(mdoc);
+       post_delim_nb(mdoc);
 }
 
 static void
@@ -1167,6 +1261,10 @@ post_nm(POST_ARGS)
 
        n = mdoc->last;
 
+       if (n->sec == SEC_NAME && n->child != NULL &&
+           n->child->type == ROFFT_TEXT && mdoc->meta.msec != NULL)
+               mandoc_xr_add(mdoc->meta.msec, n->child->string, -1, -1);
+
        if (n->last != NULL &&
            (n->last->tok == MDOC_Pp ||
             n->last->tok == MDOC_Lp))
@@ -1180,11 +1278,18 @@ post_nm(POST_ARGS)
                mandoc_msg(MANDOCERR_NM_NONAME, mdoc->parse,
                    n->line, n->pos, "Nm");
 
-       if (n->type == ROFFT_ELEM)
+       switch (n->type) {
+       case ROFFT_ELEM:
+               post_delim_nb(mdoc);
+               break;
+       case ROFFT_HEAD:
                post_delim(mdoc);
+               break;
+       default:
+               return;
+       }
 
-       if ((n->type != ROFFT_ELEM && n->type != ROFFT_HEAD) ||
-           (n->child != NULL && n->child->type == ROFFT_TEXT) ||
+       if ((n->child != NULL && n->child->type == ROFFT_TEXT) ||
            mdoc->meta.name == NULL)
                return;
 
@@ -1198,7 +1303,6 @@ static void
 post_nd(POST_ARGS)
 {
        struct roff_node        *n;
-       size_t                   sz;
 
        n = mdoc->last;
 
@@ -1212,11 +1316,8 @@ post_nd(POST_ARGS)
        if (n->child == NULL)
                mandoc_msg(MANDOCERR_ND_EMPTY, mdoc->parse,
                    n->line, n->pos, "Nd");
-       else if (n->last->type == ROFFT_TEXT &&
-           (sz = strlen(n->last->string)) != 0 &&
-           n->last->string[sz - 1] == '.')
-               mandoc_msg(MANDOCERR_ND_DOT, mdoc->parse,
-                   n->last->line, n->last->pos + sz - 1, NULL);
+       else
+               post_delim(mdoc);
 
        post_hyph(mdoc);
 }
@@ -1274,7 +1375,7 @@ post_defaults(POST_ARGS)
        struct roff_node *nn;
 
        if (mdoc->last->child != NULL) {
-               post_delim(mdoc);
+               post_delim_nb(mdoc);
                return;
        }
 
@@ -1349,7 +1450,7 @@ post_an(POST_ARGS)
                        mandoc_msg(MANDOCERR_MACRO_EMPTY, mdoc->parse,
                            np->line, np->pos, "An");
                else
-                       post_delim(mdoc);
+                       post_delim_nb(mdoc);
        } else if (nch != NULL)
                mandoc_vmsg(MANDOCERR_ARG_EXCESS, mdoc->parse,
                    nch->line, nch->pos, "An ... %s", nch->string);
@@ -1377,8 +1478,9 @@ post_xx(POST_ARGS)
 {
        struct roff_node        *n;
        const char              *os;
+       char                    *v;
 
-       post_delim(mdoc);
+       post_delim_nb(mdoc);
 
        n = mdoc->last;
        switch (n->tok) {
@@ -1393,6 +1495,20 @@ post_xx(POST_ARGS)
                break;
        case MDOC_Nx:
                os = "NetBSD";
+               if (n->child == NULL)
+                       break;
+               v = n->child->string;
+               if ((v[0] != '0' && v[0] != '1') || v[1] != '.' ||
+                   v[2] < '0' || v[2] > '9' ||
+                   v[3] < 'a' || v[3] > 'z' || v[4] != '\0')
+                       break;
+               n->child->flags |= NODE_NOPRT;
+               mdoc->next = ROFF_NEXT_CHILD;
+               roff_word_alloc(mdoc, n->child->line, n->child->pos, v);
+               v = mdoc->last->string;
+               v[3] = toupper((unsigned char)v[3]);
+               mdoc->last->flags |= NODE_NOSRC;
+               mdoc->last = n;
                break;
        case MDOC_Ox:
                os = "OpenBSD";
@@ -1459,15 +1575,30 @@ post_it(POST_ARGS)
 
                assert(nit->head->child == NULL);
 
-               i = 0;
-               for (nch = nit->child; nch != NULL; nch = nch->next)
-                       if (nch->type == ROFFT_BODY)
-                               i++;
+               if (nit->head->next->child == NULL &&
+                   nit->head->next->next == NULL) {
+                       mandoc_msg(MANDOCERR_MACRO_EMPTY, mdoc->parse,
+                           nit->line, nit->pos, "It");
+                       roff_node_delete(mdoc, nit);
+                       break;
+               }
 
+               i = 0;
+               for (nch = nit->child; nch != NULL; nch = nch->next) {
+                       if (nch->type != ROFFT_BODY)
+                               continue;
+                       if (i++ && nch->flags & NODE_LINE)
+                               mandoc_msg(MANDOCERR_TA_LINE, mdoc->parse,
+                                   nch->line, nch->pos, "Ta");
+               }
                if (i < cols || i > cols + 1)
                        mandoc_vmsg(MANDOCERR_BL_COL,
                            mdoc->parse, nit->line, nit->pos,
                            "%d columns, %d cells", cols, i);
+               else if (nit->head->next->child != NULL &&
+                   nit->head->next->child->line > nit->line)
+                       mandoc_msg(MANDOCERR_IT_NOARG, mdoc->parse,
+                           nit->line, nit->pos, "Bl -column It");
                break;
        default:
                abort();
@@ -1841,7 +1972,10 @@ post_root(POST_ARGS)
                        arch++;
                if (*arch == NULL) {
                        n = mdoc->first->child;
-                       while (n->tok != MDOC_Dt)
+                       while (n->tok != MDOC_Dt ||
+                           n->child == NULL ||
+                           n->child->next == NULL ||
+                           n->child->next->next == NULL)
                                n = n->next;
                        n = n->child->next->next;
                        mandoc_vmsg(MANDOCERR_ARCH_BAD,
@@ -1855,8 +1989,10 @@ post_root(POST_ARGS)
        /* Check that we begin with a proper `Sh'. */
 
        n = mdoc->first->child;
-       while (n != NULL && n->tok != TOKEN_NONE &&
-           mdoc_macros[n->tok].flags & MDOC_PROLOGUE)
+       while (n != NULL &&
+           (n->type == ROFFT_COMMENT ||
+            (n->tok >= MDOC_Dd &&
+             mdoc_macros[n->tok].flags & MDOC_PROLOGUE)))
                n = n->next;
 
        if (n == NULL)
@@ -1982,10 +2118,20 @@ post_hyph(POST_ARGS)
 static void
 post_ns(POST_ARGS)
 {
+       struct roff_node        *n;
 
-       if (mdoc->last->flags & NODE_LINE)
+       n = mdoc->last;
+       if (n->flags & NODE_LINE ||
+           (n->next != NULL && n->next->flags & NODE_DELIMC))
                mandoc_msg(MANDOCERR_NS_SKIP, mdoc->parse,
-                   mdoc->last->line, mdoc->last->pos, NULL);
+                   n->line, n->pos, NULL);
+}
+
+static void
+post_sx(POST_ARGS)
+{
+       post_delim(mdoc);
+       post_hyph(mdoc);
 }
 
 static void
@@ -2148,11 +2294,54 @@ post_sh_authors(POST_ARGS)
                    mdoc->last->line, mdoc->last->pos, NULL);
 }
 
+/*
+ * Return an upper bound for the string distance (allowing
+ * transpositions).  Not a full Levenshtein implementation
+ * because Levenshtein is quadratic in the string length
+ * and this function is called for every standard name,
+ * so the check for each custom name would be cubic.
+ * The following crude heuristics is linear, resulting
+ * in quadratic behaviour for checking one custom name,
+ * which does not cause measurable slowdown.
+ */
+static int
+similar(const char *s1, const char *s2)
+{
+       const int       maxdist = 3;
+       int             dist = 0;
+
+       while (s1[0] != '\0' && s2[0] != '\0') {
+               if (s1[0] == s2[0]) {
+                       s1++;
+                       s2++;
+                       continue;
+               }
+               if (++dist > maxdist)
+                       return INT_MAX;
+               if (s1[1] == s2[1]) {  /* replacement */
+                       s1++;
+                       s2++;
+               } else if (s1[0] == s2[1] && s1[1] == s2[0]) {
+                       s1 += 2;        /* transposition */
+                       s2 += 2;
+               } else if (s1[0] == s2[1])  /* insertion */
+                       s2++;
+               else if (s1[1] == s2[0])  /* deletion */
+                       s1++;
+               else
+                       return INT_MAX;
+       }
+       dist += strlen(s1) + strlen(s2);
+       return dist > maxdist ? INT_MAX : dist;
+}
+
 static void
 post_sh_head(POST_ARGS)
 {
        struct roff_node        *nch;
        const char              *goodsec;
+       const char *const       *testsec;
+       int                      dist, mindist;
        enum roff_sec            sec;
 
        /*
@@ -2190,8 +2379,25 @@ post_sh_head(POST_ARGS)
 
        /* We don't care about custom sections after this. */
 
-       if (sec == SEC_CUSTOM)
+       if (sec == SEC_CUSTOM) {
+               if ((nch = mdoc->last->child) == NULL ||
+                   nch->type != ROFFT_TEXT || nch->next != NULL)
+                       return;
+               goodsec = NULL;
+               mindist = INT_MAX;
+               for (testsec = secnames + 1; *testsec != NULL; testsec++) {
+                       dist = similar(nch->string, *testsec);
+                       if (dist < mindist) {
+                               goodsec = *testsec;
+                               mindist = dist;
+                       }
+               }
+               if (goodsec != NULL)
+                       mandoc_vmsg(MANDOCERR_SEC_TYPO, mdoc->parse,
+                           nch->line, nch->pos, "Sh %s instead of %s",
+                           nch->string, goodsec);
                return;
+       }
 
        /*
         * Check whether our non-custom section is being repeated or is
@@ -2257,9 +2463,15 @@ post_xr(POST_ARGS)
        if (nch->next == NULL) {
                mandoc_vmsg(MANDOCERR_XR_NOSEC, mdoc->parse,
                    n->line, n->pos, "Xr %s", nch->string);
-       } else
+       } else {
                assert(nch->next == n->last);
-       post_delim(mdoc);
+               if(mandoc_xr_add(nch->next->string, nch->string,
+                   nch->line, nch->pos))
+                       mandoc_vmsg(MANDOCERR_XR_SELF, mdoc->parse,
+                           nch->line, nch->pos, "Xr %s %s",
+                           nch->string, nch->next->string);
+       }
+       post_delim_nb(mdoc);
 }
 
 static void
@@ -2272,6 +2484,7 @@ post_ignpar(POST_ARGS)
                post_prevpar(mdoc);
                return;
        case ROFFT_HEAD:
+               post_delim(mdoc);
                post_hyph(mdoc);
                return;
        case ROFFT_BODY:
@@ -2508,7 +2721,7 @@ post_bx(POST_ARGS)
        struct roff_node        *n, *nch;
        const char              *macro;
 
-       post_delim(mdoc);
+       post_delim_nb(mdoc);
 
        n = mdoc->last;
        nch = n->child;
@@ -2574,6 +2787,8 @@ post_os(POST_ARGS)
                mandoc_msg(MANDOCERR_PROLOG_LATE, mdoc->parse,
                    n->line, n->pos, "Os");
 
+       post_delim(mdoc);
+
        /*
         * Set the operating system by way of the `Os' macro.
         * The order of precedence is: