fix: reject SQL containing more than one statement - #439
Draft
huytdps13400 wants to merge 1 commit into
Draft
huytdps13400 wants to merge 1 commit into
huytdps13400 wants to merge 1 commit into
Conversation
sqlite3_prepare_v2 compiles only the first statement and reports the rest through its tail pointer, which prepareStatement ignored. execute, executeAsync, batch commands, loadFile lines and prepare therefore ran the first statement and silently dropped the rest. Prepare the tail and throw when it holds another statement. Whitespace, comments and extra semicolons still pass. This matches the better-sqlite3 Node mock, which already rejects multi-statement SQL. Fixes margelo#3 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@huytdps13400 is attempting to deploy a commit to the Margelo Team on Vercel. A member of the Team first needs to authorize it. |
huytdps13400
marked this pull request as draft
October 2, 2026 19:25
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3
Root cause
prepareStatementcallssqlite3_prepare_v2with a null tail pointer. SQLite compiles only the first statement and reports the rest through that pointer, soexecute,executeAsync, batch commands,loadFilelines andprepareran the first statement and silently dropped the rest. For example,db.execute('CREATE TABLE foo (id INTEGER); CREATE TABLE bar (id INTEGER);')createsfooand reports success, butbarnever exists.Changes
prepareStatementnow keeps the tail.hasTrailingStatement(new headerNitroSQLiteStatementTail.hpp) prepares it and treats a non-null statement or a prepare failure as another statement. The query then fails withSqlExecutionError: Query contains more than one SQL statement. Whitespace,--and/* */comments, and extra semicolons prepare to a null statement and still pass. An empty tail skips the extra prepare.execute,executeAsyncandpreparetake one SQL statement.NitroSQLiteStatementGroup.hpppattern: the check is a header shared with a host test (tests/cpp/statementTail.test.cpp). The test is wired intoscripts/test-cpp.shand thecpp_testsCI paths.execute.spec.ts. It checks thatexecute,executeAsyncandpreparereject the issue's query and that neither table is created.Behavior change: SQL that used to run only its first statement now throws or rejects. This includes a
loadFileline with two statements, which now rolls back the import.Verification
mainlogic (prepare without tail + step, against the bundled SQLite):step rc=101 (DONE),table foo exists: 1,table bar exists: 0, with no error.statementTail.test.cppwith the tail ignored, as onmain:[FAIL] trailing statement was not detected: CREATE TABLE foo (id INTEGER); CREATE TABLE bar (id INTEGER);. With the fix:[PASS] detects SQL after the first statement.bash scripts/test-cpp.sh: all pass.NitroSQLiteOperations.cpppassesclang++ -std=c++20 -Wall -Wextra -fsyntax-onlyagainst the Nitro and nitrogen headers.scripts/clang-format.sh(clang-format 18) produces no diff.bun typecheckpasses, and both lint commands produce no diff.packages/react-native-nitro-sqlite105/105 andexample(mocha config) 8/8.execute.spec.tsbecause I had no simulator or emulator here. It is modeled on the existing "rejects a query that contains no SQL" test.Platforms: iOS, Android and macOS (shared C++).
This fix was prepared with AI assistance (Claude Code) and verified locally with the tests above.
馃 Generated with Claude Code