Commits on Source 12

  • Toni Spets's avatar
    Support more underscore keys in DSN · 5831f4be
    Toni Spets authored and Ian Chechin's avatar Ian Chechin committed
    For improved DSN compatibility, the following keys have been added:
    
        _foreign_keys | _fk
        _busy_timeout | _timeout
        _journal_mode | _journal
        _synchronous | _sync
        _auto_vacuum | _vacuum
        _query_only
    
    Their values are passed as-is to exec for their respective PRAGMAs and not
    validated in any way. The compatibility here is intended when switching
    between modernc.org/sqlite and mattn/go-sqlite3, where it is handy to have
    higher DSN compatibility and to avoid dangerous mistakes like not having
    foreign keys enabled.
    5831f4be
  • Ian Chechin's avatar
    sqlite: document mattn-compat DSN pragma keys and test them together · 97841221
    Ian Chechin authored
    Follow-up to the DSN shorthand keys carried over from !73: document
    _busy_timeout/_fk/_journal/_sync/_vacuum/_query_only in the driver DSN
    reference, note the fixed apply order (busy_timeout first, query_only last)
    at the query_only call site, and add a combined-DSN test asserting the keys
    coexist in a single DSN regardless of the order they appear in it.
    97841221
  • Ian Chechin's avatar
    sqlite: validate mattn-compat DSN keys and fix auto_vacuum apply order · 266b979e
    Ian Chechin authored
    Addresses the !134 review:
    
    - Apply _auto_vacuum before the _pragma list and the other shorthand keys.
      auto_vacuum only takes effect while the database is new; a _journal_mode
      change materialises page 1 and locks it in, so the previous order made
      _journal_mode=wal&_auto_vacuum=1 silently resolve to auto_vacuum=0. The
      "Test combined DSN" case now includes _auto_vacuum and asserts it reads
      back as 1, proving the fixed order.
    - Validate every shorthand value against the set github.com/mattn/go-sqlite3
      accepts and return an error on anything else, instead of silently ignoring
      it, so a _synchronous or _foreign_keys typo no longer downgrades durability
      or drops enforcement. This also removes the DSN-injection surface these keys
      had, since a value is now either a known token or an error.
    - When a key and its alias are both present, the alias wins, matching mattn
      (_foreign_keys=off&_fk=on -> on).
    - Document the apply order, precedence, accepted values, and that only _pragma
      values are executed verbatim and must be trusted.
    - CHANGELOG entry for #134.
    266b979e
  • cznic's avatar
    Merge branch 'dsn-compat-keys' into 'master' · b31f5212
    cznic authored
    Support more underscore keys in DSN (continues !73)
    
    See merge request !134
    
    Co-Authored-By: default avatarClaude Opus 4.8 <noreply@anthropic.com>
    b31f5212
  • cznic's avatar
    CHANGELOG.md: correct the !134 DSN shorthand-key entry · d7210fc8
    cznic authored
    The v1.55.0 entry said the new mattn-compatible keys were "parsed but had
    no effect in prior releases". They were not parsed at all; applyQueryParams
    never looked at them. It also described an unrecognized value as failing
    "instead of being silently ignored", a contrast against an unreleased
    iteration of !134 rather than against v1.54.0, which would read to a user
    upgrading as though their DSN had previously been tolerated and ignored.
    
    Restate both breaks against the last released version: keys that were
    ignored now take effect (with the consequence spelled out rather than just
    the key named), and a value outside the accepted set now fails the
    connection where the same DSN previously opened successfully - e.g. a
    duration-style _busy_timeout=5s, which is not the integer that key
    requires. The latter was missing entirely and is the sharper of the two.
    
    Co-Authored-By: default avatarClaude Opus 4.8 <noreply@anthropic.com>
    d7210fc8
  • cznic's avatar
    sqlite: select DSN shorthand aliases by presence, matching mattn (!134 follow-up) · 63a57e47
    cznic authored
    dsnPick treated an empty value as absent, so "_foreign_keys=on&_fk=" fell
    back to the primary key and enabled foreign keys. mattn/go-sqlite3 selects
    between a key and its alias by presence alone and then reads that key's
    value, so the empty alias wins and suppresses the PRAGMA entirely.
    
    Match that: pick on presence, return the selected key's value as-is. An
    empty value still skips the PRAGMA at the call sites, and skips validation
    with it, so an empty shorthand is not an error.
    
    Co-Authored-By: default avatarClaude Opus 4.8 <noreply@anthropic.com>
    63a57e47
  • cznic's avatar
    sqlite: validate all DSN parameters before applying any of them · 0895392f
    cznic authored
    applyQueryParams validated each parameter as it reached it, so a DSN whose
    last parameter was bad still executed every PRAGMA ahead of it before
    failing. PRAGMA journal_mode and auto_vacuum are persistent changes to the
    database file, so
    
    	file:x.db?_journal_mode=wal&_synchronous=bogus
    
    failed the connection and left x.db converted to WAL regardless. A failed
    Open must not change the database.
    
    Split the function into a validation phase and an apply phase: everything
    checkable is rejected before the first c.exec. Assignments to c stay in the
    validation phase, since newConn closes and discards the connection when this
    returns an error and they cannot outlive the failure. The documented apply
    order is unchanged and still covered by the combined-DSN test.
    
    This predates the !134 shorthand keys - master already behaved this way for
    _pragma combined with a late-rejected _txlock, which is why the new test
    covers that case too. _pragma remains the o...
    0895392f
  • cznic's avatar
    CHANGELOG.md: document the DSN validation-order change · cfb97341
    cznic authored
    Adds a v1.55.0 entry for validating every DSN parameter before applying any
    of them. It gets its own bullet rather than folding into the !134 paragraph
    because it changes behavior for parameters that have shipped for years -
    _txlock, _timezone, _time_format, _time_integer_format, _inttotime and
    _texttotime - so it concerns readers who never touch the new mattn-compatible
    keys.
    
    The alias-selection fix is folded into the !134 paragraph instead. v1.55.0 is
    not tagged, so no release ever shipped the fallback behavior and describing it
    as a fix would document a bug nobody could have hit.
    
    Also corrects that paragraph's closing claim that "all other existing
    parameters are unchanged", which the validation-order change made false: those
    parameters are affected in when they are validated, though not in what they
    accept or what they mean.
    
    Co-Authored-By: default avatarClaude Opus 4.8 <noreply@anthropic.com>
    cfb97341
  • cznic's avatar
    sqlite: add NewConnector, a driver.Connector for sql.OpenDB · 2c7e3eb3
    cznic authored
    database/sql offers no way to reach a registered driver: sql.Drivers returns
    names only and there is no sql.Driver(name). The single route from the
    "sqlite" name back to the driver value is (*sql.DB).Driver(), which is why
    callers who need it resort to
    
    	db, _ := sql.Open("sqlite", "")
    	drv := db.Driver()
    	db.Close()
    
    That opens nothing - it works only because sql.Open does not connect and
    *Driver does not implement driver.DriverContext. Both are properties this
    package could change without noticing it had broken anyone.
    
    Callers want the driver in order to interpose on the physical connections
    database/sql opens: tracing, metrics, connection-scoped setup. Handing out
    the driver alone would not be enough, because the only way to get a wrapper
    into a *sql.DB through sql.Open is sql.Register, which is process-global,
    panics on a name it has already seen and cannot be undone - so a library has
    to invent a unique name per configuration. TestConnectio...
    2c7e3eb3
  • cznic's avatar
    sqlite: document that a constructed Driver is not the registered one · e7a39d2d
    cznic authored
    Driver has been exported since 65f6d7e4 (2017), where "Make sqlite public"
    renamed the unexported sqlite type as part of publishing the package. The
    struct then held a connection counter and a mutex, so constructing one cost
    nothing and lost nothing. a9227519 (2022) moved the function and collation
    registries onto it and introduced the package-level instance, which is when
    a constructed Driver started silently lacking things; 14082cad (2023) added
    (*Driver).RegisterConnectionHook, which is only meaningful on an instance the
    caller builds, and so made the export load-bearing.
    
    The result is a type that is legitimately constructible for the private-hook
    pattern yet carries none of what the package-level Register* functions
    install. This documents that on the type and on the method, including the
    consequence easiest to miss: a registered function replaces a SQLite built-in
    of the same name, so a constructed Driver can evaluate upper(x) or date(x)
    differently from a connection opened through sql.Open.
    
    The half-global virtual table module behavior is documented as it stands
    rather than changed. registerModules reads the package-level driver, so
    modules do reach a constructed Driver while functions and collations do not.
    Making that consistent breaks somebody in either direction - inheriting
    silently changes query results for anyone whose registration shadows a
    built-in, isolating turns a working CREATE VIRTUAL TABLE into "no such
    module" - so it wants an issue of its own rather than a doc commit.
    
    No behavior changes.
    
    Co-Authored-By: default avatarClaude Opus 5 (1M context) <noreply@anthropic.com>
    e7a39d2d
  • cznic's avatar
    sqlite: validate the connector dsn with getVFSName, not a bare ParseQuery · 581eb450
    cznic authored
    NewConnector parsed the query string itself to reject a malformed dsn early.
    getVFSName is what newConn calls for the same purpose, and it does strictly
    more: the same url.ParseQuery, plus a check for conflicting vfs parameters.
    Calling it instead drops an import, removes the repeated parse, and keeps what
    NewConnector rejects aligned with what opening a connection rejects by
    construction rather than by matching two call sites by hand.
    
    The eager contract widens accordingly: "file:x?vfs=a&vfs=b" is now reported by
    NewConnector rather than by the first Connect. It was already an error either
    way, so no dsn changes from accepted to rejected. Everything a connection must
    exist to check - unknown parameters, out-of-range values - is still reported by
    Connect, as documented.
    
    v1.56.0 is not tagged, so no release shipped the narrower behavior.
    
    Co-Authored-By: default avatarClaude Opus 5 (1M context) <noreply@anthropic.com>
    581eb450
  • cznic's avatar
    lib, vec: re-vendor, bump libc to v1.74.4, sweep the docs · cc920f9b
    cznic authored
    Re-vendor the transpiled sources from ../libsqlite3 and ../libsqlite_vec.
    SQLite stays at 3.53.3; what changes is that the amalgamation now carries
    libsqlite3's sqlite_superjournal.patch, fixing an upstream 3.53.3
    data-corruption bug in journal rollback. After a crash during the commit of a
    multi-database (ATTACH) transaction the super-journal name and its checksum
    can be left zeroed while the name length and the trailing magic survive; the
    checksum is a plain byte sum, so an all-zero name still validates,
    readSuperJournal() hands back a non-NULL pointer to an empty string, and
    pager_playback() deletes the hot journal without replaying it. All 19 targets
    carry the patch; master had it on none.
    
    Verified by expanding both the old and the new trees and diffing per target:
    17 of 19 targets differ by exactly that one line. linux/s390x additionally
    picks up modernc.org/cc/v4 v4.29.1's MSB-first big-endian bit-field
    allocation, it being this module's only big-endian target. linux/riscv64 was
    regenerated on GCC 11.4.0 rather than 13.3.0, which only moves the COMPILER=
    entry PRAGMA compile_options reports and drops some unexported predefined
    macro constants; no SQLite code generation differs.
    
    go.mod goes to the current releases throughout. modernc.org/libc lands on
    v1.74.4 rather than the v1.74.3 ../libsqlite3 pins, that version being
    retracted upstream for a freeaddrinfo lock leak that deadlocks name
    resolution.
    
    Documentation:
    
      - openbsd/amd64 and openbsd/arm64 join the supported platforms table. Both
        have been in builder.json's test matrix since January and are cross-built
        by make build_all_targets, but were never listed.
      - Document the vfs DSN query parameter on Driver.Open.
      - Rewrite "Debug and development versions". It described a GO_GENERATE
        environment variable that is no longer read anywhere and ccgo/v3; drop
        with it the //go:generate naming generator.go, deleted from this repo back
        at SQLite 3.45.1, which made go generate ./... fail.
      - Add the package doc comments vec and vfs were missing.
      - Correct two stale claims in CLAUDE.md.
    
    make build_all_targets and make test are green (249 pass, 0 fail, 2 skip), as
    are ./vfs/..., ./pcache/... and ./vtab/....
    
    Co-Authored-By: default avatarClaude Opus 5 (1M context) <noreply@anthropic.com>
    cc920f9b
Loading
Loading