Skip to content

sqlite: throw on oversized strings instead of aborting - #66521

Open
trivikr wants to merge 1 commit into
nodejs:mainfrom
trivikr:sqlite-error-msg-v8-string-limit
Open

trivikr wants to merge 1 commit into
nodejs:mainfrom
trivikr:sqlite-error-msg-v8-string-limit

Conversation

@trivikr

@trivikr trivikr commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Fixes: #66520
Fixes: #66522

Several conversions from SQLite text to V8 strings passed a length of -1 to String::NewFromUtf8(). With that length, V8 skips its length check and aborts the process when the UTF-8 text exceeds String::kMaxLength.

SQLite error messages embed the offending identifier or token, so CreateSQLiteErrorImpl() could hit this. NullableSQLiteStringToValue(), used for setAuthorizer() callback arguments and statement.columns() metadata, had the same problem, and the authorizer also called ToLocalChecked() on each argument.

Convert error messages with Utf8StringMaybeOneByte(), and check the length up front in NullableSQLiteStringToValue(), so oversized strings throw ERR_STRING_TOO_LONG as column values already do. In the authorizer, deny the action and let the pending error reach the caller.


Assisted-by: claude:opus-5.5

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/sqlite

@nodejs-github-bot nodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. sqlite Issues and PRs related to the SQLite subsystem. labels Oct 5, 2026
@trivikr
trivikr force-pushed the sqlite-error-msg-v8-string-limit branch from bc4915c to c6c38b5 Compare October 5, 2026 03:18
Several conversions from SQLite text to V8 strings passed a length of
-1 to String::NewFromUtf8(). With that length, V8 skips its length
check and aborts the process when the UTF-8 text exceeds
String::kMaxLength.

SQLite error messages embed the offending identifier or token, so
CreateSQLiteErrorImpl() could hit this. NullableSQLiteStringToValue(),
used for setAuthorizer() callback arguments and statement.columns()
metadata, had the same problem, and the authorizer also called
ToLocalChecked() on each argument.

Convert error messages with Utf8StringMaybeOneByte(), and check the
length up front in NullableSQLiteStringToValue(), so oversized strings
throw ERR_STRING_TOO_LONG as column values already do. In the
authorizer, deny the action and let the pending error reach the caller.

Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com>
Assisted-by: claude:opus-5.5
@trivikr
trivikr force-pushed the sqlite-error-msg-v8-string-limit branch from c6c38b5 to a9632cc Compare October 5, 2026 03:25
@trivikr trivikr changed the title sqlite: throw on oversized error messages sqlite: throw on oversized strings instead of aborting Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. sqlite Issues and PRs related to the SQLite subsystem.

Projects

None yet

2 participants