Commit 7d5a3769 authored by cznic's avatar cznic
Browse files

CHANGELOG.md: slim the v1.60.0 section

1071 words in 17 bullets become 730 in 14, per the HACKING.md entry-style
rule: the documentation-only bullets stop paraphrasing the documents they
announce, SECURITY.md joins IRP.md and LICENSE-3RD-PARTY.md joins the SBOM,
the stranded "Resolves #257" line attaches to the URI-parameters bullet it
credits, and the vendor.json bullet drops "the vendored code is unchanged",
which was true of merge request !140 alone and false of this release, whose
lib/ is re-vendored. The release-critical and behavior-change bullets are
unchanged.

Co-Authored-By: default avatarClaude Fable 5.1 <noreply@anthropic.com>
parent a604165a
Loading
Loading
Loading
Loading
+8 −11
Changes for CHANGELOG.md: 8 added lines, 11 removed lines.
Original line number Diff line number Diff line
@@ -6,20 +6,17 @@ Entries for v1.38.1 through v1.44.1 and for v1.49.1 were added on 2026-09-05, re
     - **A fault while reading the memory-mapped `-shm` file of a WAL database no longer crashes the process.** The statement fails with a disk I/O error, extended code `SQLITE_IOERR_IN_PAGE` (8714), and the connection stays usable, as in MSVC builds of SQLite. On by default on every platform and not switchable; `lib.SehInject` and `lib.SehPending` inject such a fault for tests. Resolves [GitLab issue #221](https://gitlab.com/cznic/sqlite/-/issues/221), thanks Roman (@requilence) for the report, and supersedes [libsqlite3!4](https://gitlab.com/cznic/libsqlite3/-/merge_requests/4) and [GitHub pull request #7](https://github.com/modernc-org/sqlite/pull/7), thanks hazyhaar for the two rounds, the `ccgo` finding and the Windows Server runs!
     - Re-vendor `lib/` from [modernc.org/libsqlite3 v1.15.0](https://gitlab.com/cznic/libsqlite3/-/tags/v1.15.0) and `vec/` from [modernc.org/libsqlite_vec v0.6.0](https://gitlab.com/cznic/libsqlite_vec/-/tags/v0.6.0); SQLite stays 3.53.4 and sqlite-vec v0.1.9. **Go 1.26 is now required**, and the pinned `modernc.org/libc` becomes [v1.77.1](https://gitlab.com/cznic/libc/-/tags/v1.77.1); as always, downstream `go.mod` files must pin the same `modernc.org/libc` version this repository's `go.mod` does, see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).
     - **Nine exported `lib` constants that never had a meaningful value are gone**: `INFINITY`, `MB_CUR_MAX`, `NAN`, `RESERVED_BYTE`, `SHARED_FIRST`, `SQLITE_CANTOPEN_BKPT`, `SQLITE_CORRUPT_BKPT`, `SQLITE_DEFAULT_LOOKASIDE` and `SQLITE_MISUSE_BKPT`. The transpiler now evaluates object-like macros as C expressions, so other constants take their C value (`lib.WALINDEX_PGSZ` is 32768, not 0) and some appear; the full list is in [libsqlite3's CHANGELOG](https://gitlab.com/cznic/libsqlite3/-/blob/master/CHANGELOG.md) under 2026-09-19.
     - `make vendor` now writes `vendor.json`: the `modernc.org/libsqlite3` and `modernc.org/libsqlite_vec` commits and the Go toolchain `lib/` and `vec/` were vendored with, so `git show vX.Y.Z:vendor.json` says which revisions a release carries. It refuses a dirty sibling checkout, siblings on different `modernc.org/libc` versions, or a `libsqlite_vec` built against another `libsqlite3`. The suite fails when `lib/`, `vec/` or the libc in `go.mod` no longer match the stamp, so a libc bump goes in the same push as `make vendor`. Tooling only; the vendored code is unchanged. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
     - `make vendor` now writes `vendor.json`, the `modernc.org/libsqlite3` and `modernc.org/libsqlite_vec` commits and the Go toolchain `lib/` and `vec/` were vendored with, so `git show vX.Y.Z:vendor.json` says which revisions a release carries; the test suite fails when they no longer match. Tooling only. See [GitLab merge request #140](https://gitlab.com/cznic/sqlite/-/merge_requests/140).
     - **`vfs.FS.Close` now refuses while a database opened through it is still open**, returning an error that wraps the new `vfs.ErrInUse` and leaving the VFS registered. It used to free the VFS the open connection still called through, so the next query crashed the process or read through freed memory. Close the databases first, then the `FS`.
     - Fix handle reuse in `modernc.org/sqlite/vfs` on 32-bit targets: after 2^32 file opens in one process the handle counter wrapped and could overwrite a live entry, such as a file system registered at start-up, and crash. 64-bit targets were not affected.
     - **The pluggable page cache now panics when a `Cache` breaks its contract** by returning nil, or a different `Page`, from `Fetch` for a page SQLite still holds pinned. It used to free memory SQLite was still using, corrupting the database without an error. Only a `Cache` implementation with that bug is affected; `modernc.org/sqlite/pcache` is not.
     - Document three limits of the pluggable page cache: a program importing `modernc.org/sqlite/vec` cannot call `RegisterPageCache` (it fails with `SQLITE_MISUSE`), `PageCache.Create` may be called concurrently, and under `cache=shared` a `Cache` is called from several goroutines, serialized by SQLite, so it wants a mutex of its own to run clean under `-race`. Documentation only.
     - Document two properties of connections in the package documentation: state set on a pooled connection -- PRAGMAs set with `Exec`, ATTACHed databases, temporary tables, anything registered through `sql.Conn.Raw` -- is inherited by the next caller to borrow it, and a driver connection reached through `Raw` is not safe for concurrent use even though every connection is opened `SQLITE_OPEN_FULLMUTEX`. Documentation only.
     - Add `StrictPragmas`, **opt-in and off by default**: once enabled, a connection whose `_pragma` DSN value holds more than one SQL statement fails to open with `ErrMultiStatementPragma`, before any DSN parameter is applied. A `_pragma` value runs as SQL text, so `_pragma=foreign_keys(1);ATTACH 'x.db' AS x` also attaches, and creates, `x.db`; the `Driver.Open` documentation said "a PRAGMA statement" and now says what actually happens. Enabling it is recommended for any application whose DSN is not a compile-time constant.
     - Document SQLite's own URI query parameters on `Driver.Open`: `mode`, `cache`, `immutable`, `nolock`, `psow` and `modeof`. Every connection is opened with `SQLITE_OPEN_URI`, so in a DSN starting with `file:` these have always worked; only the driver's own keys were listed. The docstring also spells out the trap that a plain file name has its query stripped before SQLite sees it, so `/path/to.db?mode=ro` opens read-write. Documentation only.
     - Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257).
     - Add `IRP.md`, an incident response plan: who runs a response when there are two maintainers in different time zones, how a report is scoped across the three layers this module is built from, the fix path for each, and what to do when a released version is itself the problem -- a published Go module version cannot be recalled, so `retract` plus a new release is the remedy. Linked from `SECURITY.md`. Documentation only.
     - Add `CONTRIBUTING.md`: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the `AUTHORS`/`CONTRIBUTORS` convention. Contribution guidance previously existed only in `GOVERNANCE.md` and `HACKING.md`, neither of which a first-time contributor is likely to open. Documentation only.
     - Add `SECURITY.md`: report a vulnerability through GitHub private vulnerability reporting, a confidential GitLab issue, or the project's Service Desk address, never a public issue. It states what is in scope -- including transpilation faults, where the generated Go does not faithfully implement the C it came from -- that only the latest release is supported, and that a confirmed report is disclosed through a GitHub advisory, an entry in the Go vulnerability database so `govulncheck` reports it, and a release note. Documentation only.
     - Ship a Software Bill of Materials: `sbom.cdx.json` (CycloneDX 1.6) and `sbom.spdx.json` (SPDX 2.3), both validated against the published schemas, with `SBOM.md` explaining what they cover. They name what an SBOM built from the module graph cannot see -- the transpiled SQLite 3.53.4 and `sqlite-vec` C, and the upstreams `modernc.org/libc` vendors, musl among them -- and mark every component as linked into your binary, test-only, or compiled into nothing. Documentation only.
     - Ship `LICENSE-3RD-PARTY.md`, a transitively flattened inventory of every third-party component this module carries: the whole Go module graph, the transpiled SQLite and `sqlite-vec` C that no `go.mod` names, and the upstreams `modernc.org/libc` carries in turn, musl among them. It reproduces all seventeen distinct license texts in full and separates what is linked into your binary from what only appears in the module graph. The `LICENSE` name prefix is what makes `go mod vendor` carry it into downstream `vendor/` trees. Documentation only.
     - Document three limits of the pluggable page cache on `RegisterPageCache` and `Cache`: it cannot be combined with `modernc.org/sqlite/vec`, `PageCache.Create` may be called concurrently, and under `cache=shared` a `Cache` is called from several goroutines. Documentation only.
     - Document in the package documentation that state set on a pooled connection is inherited by the next caller to borrow it, and that a connection reached through `sql.Conn.Raw` is not safe for concurrent use. Documentation only.
     - Add `StrictPragmas`, **opt-in and off by default**: once enabled, a connection whose `_pragma` DSN value holds more than one SQL statement fails to open with `ErrMultiStatementPragma`, before any DSN parameter is applied. A `_pragma` value runs as SQL text, so anything after a `;` runs too. Recommended for any application whose DSN is not a compile-time constant.
     - Document SQLite's own URI query parameters on `Driver.Open`: `mode`, `cache`, `immutable`, `nolock`, `psow` and `modeof`, which have always worked in a DSN starting with `file:`, and the trap that a plain file name has its query stripped before SQLite sees it, so `/path/to.db?mode=ro` opens read-write. Resolves [GitLab issue #257](https://gitlab.com/cznic/sqlite/-/issues/257). Documentation only.
     - Add `SECURITY.md`, the vulnerability reporting policy: three private channels, what is in scope, that only the latest release is supported, and how a confirmed report is disclosed, including an entry in the Go vulnerability database so `govulncheck` reports it. `IRP.md`, linked from it, is the maintainers' incident response plan. Documentation only.
     - Add `CONTRIBUTING.md`: where to send a merge request, which files are generated and must not be edited by hand, how to build and test across the 20 supported targets, and the `AUTHORS`/`CONTRIBUTORS` convention. Documentation only.
     - Ship `LICENSE-3RD-PARTY.md`, a transitively flattened inventory of every third-party component this module carries with all seventeen license texts in full, and a Software Bill of Materials, `sbom.cdx.json` (CycloneDX 1.6) and `sbom.spdx.json` (SPDX 2.3), explained in `SBOM.md`. Both cover what a module-graph tool cannot see: the transpiled SQLite and `sqlite-vec` C, and the upstreams `modernc.org/libc` carries, musl among them. Documentation only.

 - 2026-09-15 v1.59.0:
     - Bump the pinned `modernc.org/libc` to [v1.75.7](https://gitlab.com/cznic/libc/-/tags/v1.75.7) and re-vendor `lib/` and `vec/`. The transpiled SQLite is unchanged, still 3.53.4. On the Linux targets the new libc replaces transpiled musl `memcpy`, `memmove`, `memset`, `memcmp` and `strlen` with native Go, cutting CPU time on query-heavy workloads by up to a third; see the new Performance section below. As always, downstream `go.mod` files must pin the same `modernc.org/libc` version this repository's `go.mod` does; see [GitLab issue #177](https://gitlab.com/cznic/sqlite/-/issues/177).