Loading
Commits on Source 12
-
For improved DSN compatibility, the following keys have been added: _foreign_keys | _fk _busy_timeout | _timeout _journal_mode | _journal _synchronous | _sync _auto_vacuum | _vacuum _query_only Their values are passed as-is to exec for their respective PRAGMAs and not validated in any way. The compatibility here is intended when switching between modernc.org/sqlite and mattn/go-sqlite3, where it is handy to have higher DSN compatibility and to avoid dangerous mistakes like not having foreign keys enabled. -
Ian Chechin authored
Follow-up to the DSN shorthand keys carried over from !73: document _busy_timeout/_fk/_journal/_sync/_vacuum/_query_only in the driver DSN reference, note the fixed apply order (busy_timeout first, query_only last) at the query_only call site, and add a combined-DSN test asserting the keys coexist in a single DSN regardless of the order they appear in it.
-
Ian Chechin authored
Addresses the !134 review: - Apply _auto_vacuum before the _pragma list and the other shorthand keys. auto_vacuum only takes effect while the database is new; a _journal_mode change materialises page 1 and locks it in, so the previous order made _journal_mode=wal&_auto_vacuum=1 silently resolve to auto_vacuum=0. The "Test combined DSN" case now includes _auto_vacuum and asserts it reads back as 1, proving the fixed order. - Validate every shorthand value against the set github.com/mattn/go-sqlite3 accepts and return an error on anything else, instead of silently ignoring it, so a _synchronous or _foreign_keys typo no longer downgrades durability or drops enforcement. This also removes the DSN-injection surface these keys had, since a value is now either a known token or an error. - When a key and its alias are both present, the alias wins, matching mattn (_foreign_keys=off&_fk=on -> on). - Document the apply order, precedence, accepted values, and that only _pragma values are executed verbatim and must be trusted. - CHANGELOG entry for #134.
-
cznic authored
Support more underscore keys in DSN (continues !73) See merge request !134 Co-Authored-By:
Claude Opus 4.8 <noreply@anthropic.com>
-
cznic authored
The v1.55.0 entry said the new mattn-compatible keys were "parsed but had no effect in prior releases". They were not parsed at all; applyQueryParams never looked at them. It also described an unrecognized value as failing "instead of being silently ignored", a contrast against an unreleased iteration of !134 rather than against v1.54.0, which would read to a user upgrading as though their DSN had previously been tolerated and ignored. Restate both breaks against the last released version: keys that were ignored now take effect (with the consequence spelled out rather than just the key named), and a value outside the accepted set now fails the connection where the same DSN previously opened successfully - e.g. a duration-style _busy_timeout=5s, which is not the integer that key requires. The latter was missing entirely and is the sharper of the two. Co-Authored-By:
Claude Opus 4.8 <noreply@anthropic.com>
-
cznic authored
dsnPick treated an empty value as absent, so "_foreign_keys=on&_fk=" fell back to the primary key and enabled foreign keys. mattn/go-sqlite3 selects between a key and its alias by presence alone and then reads that key's value, so the empty alias wins and suppresses the PRAGMA entirely. Match that: pick on presence, return the selected key's value as-is. An empty value still skips the PRAGMA at the call sites, and skips validation with it, so an empty shorthand is not an error. Co-Authored-By:Claude Opus 4.8 <noreply@anthropic.com>
-
cznic authored
applyQueryParams validated each parameter as it reached it, so a DSN whose last parameter was bad still executed every PRAGMA ahead of it before failing. PRAGMA journal_mode and auto_vacuum are persistent changes to the database file, so file:x.db?_journal_mode=wal&_synchronous=bogus failed the connection and left x.db converted to WAL regardless. A failed Open must not change the database. Split the function into a validation phase and an apply phase: everything checkable is rejected before the first c.exec. Assignments to c stay in the validation phase, since newConn closes and discards the connection when this returns an error and they cannot outlive the failure. The documented apply order is unchanged and still covered by the combined-DSN test. This predates the !134 shorthand keys - master already behaved this way for _pragma combined with a late-rejected _txlock, which is why the new test covers that case too. _pragma remains the o...
-
cznic authored
Adds a v1.55.0 entry for validating every DSN parameter before applying any of them. It gets its own bullet rather than folding into the !134 paragraph because it changes behavior for parameters that have shipped for years - _txlock, _timezone, _time_format, _time_integer_format, _inttotime and _texttotime - so it concerns readers who never touch the new mattn-compatible keys. The alias-selection fix is folded into the !134 paragraph instead. v1.55.0 is not tagged, so no release ever shipped the fallback behavior and describing it as a fix would document a bug nobody could have hit. Also corrects that paragraph's closing claim that "all other existing parameters are unchanged", which the validation-order change made false: those parameters are affected in when they are validated, though not in what they accept or what they mean. Co-Authored-By:
Claude Opus 4.8 <noreply@anthropic.com>
-
cznic authored
database/sql offers no way to reach a registered driver: sql.Drivers returns names only and there is no sql.Driver(name). The single route from the "sqlite" name back to the driver value is (*sql.DB).Driver(), which is why callers who need it resort to db, _ := sql.Open("sqlite", "") drv := db.Driver() db.Close() That opens nothing - it works only because sql.Open does not connect and *Driver does not implement driver.DriverContext. Both are properties this package could change without noticing it had broken anyone. Callers want the driver in order to interpose on the physical connections database/sql opens: tracing, metrics, connection-scoped setup. Handing out the driver alone would not be enough, because the only way to get a wrapper into a *sql.DB through sql.Open is sql.Register, which is process-global, panics on a name it has already seen and cannot be undone - so a library has to invent a unique name per configuration. TestConnectio... -
cznic authored
Driver has been exported since 65f6d7e4 (2017), where "Make sqlite public" renamed the unexported sqlite type as part of publishing the package. The struct then held a connection counter and a mutex, so constructing one cost nothing and lost nothing. a9227519 (2022) moved the function and collation registries onto it and introduced the package-level instance, which is when a constructed Driver started silently lacking things; 14082cad (2023) added (*Driver).RegisterConnectionHook, which is only meaningful on an instance the caller builds, and so made the export load-bearing. The result is a type that is legitimately constructible for the private-hook pattern yet carries none of what the package-level Register* functions install. This documents that on the type and on the method, including the consequence easiest to miss: a registered function replaces a SQLite built-in of the same name, so a constructed Driver can evaluate upper(x) or date(x) differently from a connection opened through sql.Open. The half-global virtual table module behavior is documented as it stands rather than changed. registerModules reads the package-level driver, so modules do reach a constructed Driver while functions and collations do not. Making that consistent breaks somebody in either direction - inheriting silently changes query results for anyone whose registration shadows a built-in, isolating turns a working CREATE VIRTUAL TABLE into "no such module" - so it wants an issue of its own rather than a doc commit. No behavior changes. Co-Authored-By:
Claude Opus 5 (1M context) <noreply@anthropic.com>
-
cznic authored
NewConnector parsed the query string itself to reject a malformed dsn early. getVFSName is what newConn calls for the same purpose, and it does strictly more: the same url.ParseQuery, plus a check for conflicting vfs parameters. Calling it instead drops an import, removes the repeated parse, and keeps what NewConnector rejects aligned with what opening a connection rejects by construction rather than by matching two call sites by hand. The eager contract widens accordingly: "file:x?vfs=a&vfs=b" is now reported by NewConnector rather than by the first Connect. It was already an error either way, so no dsn changes from accepted to rejected. Everything a connection must exist to check - unknown parameters, out-of-range values - is still reported by Connect, as documented. v1.56.0 is not tagged, so no release shipped the narrower behavior. Co-Authored-By:Claude Opus 5 (1M context) <noreply@anthropic.com>
-
cznic authored
Re-vendor the transpiled sources from ../libsqlite3 and ../libsqlite_vec. SQLite stays at 3.53.3; what changes is that the amalgamation now carries libsqlite3's sqlite_superjournal.patch, fixing an upstream 3.53.3 data-corruption bug in journal rollback. After a crash during the commit of a multi-database (ATTACH) transaction the super-journal name and its checksum can be left zeroed while the name length and the trailing magic survive; the checksum is a plain byte sum, so an all-zero name still validates, readSuperJournal() hands back a non-NULL pointer to an empty string, and pager_playback() deletes the hot journal without replaying it. All 19 targets carry the patch; master had it on none. Verified by expanding both the old and the new trees and diffing per target: 17 of 19 targets differ by exactly that one line. linux/s390x additionally picks up modernc.org/cc/v4 v4.29.1's MSB-first big-endian bit-field allocation, it being this module's only big-endian target. linux/riscv64 was regenerated on GCC 11.4.0 rather than 13.3.0, which only moves the COMPILER= entry PRAGMA compile_options reports and drops some unexported predefined macro constants; no SQLite code generation differs. go.mod goes to the current releases throughout. modernc.org/libc lands on v1.74.4 rather than the v1.74.3 ../libsqlite3 pins, that version being retracted upstream for a freeaddrinfo lock leak that deadlocks name resolution. Documentation: - openbsd/amd64 and openbsd/arm64 join the supported platforms table. Both have been in builder.json's test matrix since January and are cross-built by make build_all_targets, but were never listed. - Document the vfs DSN query parameter on Driver.Open. - Rewrite "Debug and development versions". It described a GO_GENERATE environment variable that is no longer read anywhere and ccgo/v3; drop with it the //go:generate naming generator.go, deleted from this repo back at SQLite 3.45.1, which made go generate ./... fail. - Add the package doc comments vec and vfs were missing. - Correct two stale claims in CLAUDE.md. make build_all_targets and make test are green (249 pass, 0 fail, 2 skip), as are ./vfs/..., ./pcache/... and ./vtab/.... Co-Authored-By:Claude Opus 5 (1M context) <noreply@anthropic.com>