Skip to content

sqlite: process aborts when an authorizer argument or column metadata exceeds the V8 string limit #66522

Description

@trivikr

Version

main

Platform

All

Subsystem

sqlite

What steps will reproduce the bug?

import { Database, constants } from 'node:sqlite';
import { constants as _constants } from 'node:buffer';
const { MAX_STRING_LENGTH } = _constants;

const db = new Database(':memory:');
// '\u20ac' is 1 UTF-16 unit but 3 UTF-8 bytes.
const name = '\u20ac'.repeat(Math.ceil(MAX_STRING_LENGTH / 3) + 10);

try {
  if (process.argv[2] === 'columns') {
    db.exec(`CREATE TABLE t (x "${name}")`);
    db.prepare('SELECT x FROM t').columns();
  } else {
    db.setAuthorizer(() => constants.SQLITE_OK);
    db.prepare(`CREATE TABLE "${name}" (x)`);
  }
} catch (err) {
  console.log(err.code);
}

Run node repro.js for the authorizer trigger and node repro.js columns for the statement.columns() trigger.

How often does it reproduce? Is there a required condition?

Always

What is the expected behavior? Why is that the expected behavior?

Both calls should throw a catchable error and not abort the process. With a 10-character name, both complete normally. When SQLite text doesn't fit in a JS string, node:sqlite already throws ERR_STRING_TOO_LONG for column values (#66209) and for error messages. These strings should do the same.

What do you see instead?

#
# Fatal error
# Check failed: String::kMaxLength >= len.
#
#
#
#FailureMessage Object: 0x16ce74ca8
----- Native stack trace -----

Additional information

Noticed while fixing #66520

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

sqliteIssues and PRs related to the SQLite subsystem.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions