|
|
d8894c |
Subject: [PATCH] Fix a use-after-free bug in the fts3 snippet() function.
|
|
|
d8894c |
|
|
|
d8894c |
---
|
|
|
d8894c |
ext/fts3/fts3.c | 1 +
|
|
|
d8894c |
test/fts3snippet2.test | 59 ++++++++++++++++++++++++++++++++++++++++++
|
|
|
d8894c |
2 files changed, 60 insertions(+)
|
|
|
d8894c |
create mode 100644 test/fts3snippet2.test
|
|
|
d8894c |
|
|
|
d8894c |
diff --git a/ext/fts3/fts3.c b/ext/fts3/fts3.c
|
|
|
d8894c |
index 84fc8a5..9ddd201 100644
|
|
|
d8894c |
--- a/ext/fts3/fts3.c
|
|
|
d8894c |
+++ b/ext/fts3/fts3.c
|
|
|
d8894c |
@@ -5213,6 +5213,7 @@ static void fts3EvalNextRow(
|
|
|
d8894c |
fts3EvalNextRow(pCsr, pLeft, pRc);
|
|
|
d8894c |
}
|
|
|
d8894c |
}
|
|
|
d8894c |
+ pRight->bEof = pLeft->bEof = 1;
|
|
|
d8894c |
}
|
|
|
d8894c |
}
|
|
|
d8894c |
break;
|
|
|
d8894c |
diff --git a/test/fts3snippet2.test b/test/fts3snippet2.test
|
|
|
d8894c |
new file mode 100644
|
|
|
d8894c |
index 0000000..607b01e
|
|
|
d8894c |
--- /dev/null
|
|
|
d8894c |
+++ b/test/fts3snippet2.test
|
|
|
d8894c |
@@ -0,0 +1,59 @@
|
|
|
d8894c |
+# 2020-05-14
|
|
|
d8894c |
+#
|
|
|
d8894c |
+# The author disclaims copyright to this source code. In place of
|
|
|
d8894c |
+# a legal notice, here is a blessing:
|
|
|
d8894c |
+#
|
|
|
d8894c |
+# May you do good and not evil.
|
|
|
d8894c |
+# May you find forgiveness for yourself and forgive others.
|
|
|
d8894c |
+# May you share freely, never taking more than you give.
|
|
|
d8894c |
+#
|
|
|
d8894c |
+#*************************************************************************
|
|
|
d8894c |
+#
|
|
|
d8894c |
+# The tests in this file test the FTS3 auxillary functions offsets(),
|
|
|
d8894c |
+# snippet() and matchinfo() work. At time of writing, running this file
|
|
|
d8894c |
+# provides full coverage of fts3_snippet.c.
|
|
|
d8894c |
+#
|
|
|
d8894c |
+
|
|
|
d8894c |
+set testdir [file dirname $argv0]
|
|
|
d8894c |
+source $testdir/tester.tcl
|
|
|
d8894c |
+set testprefix fts3snippet
|
|
|
d8894c |
+
|
|
|
d8894c |
+# If SQLITE_ENABLE_FTS3 is not defined, omit this file.
|
|
|
d8894c |
+ifcapable !fts3 { finish_test ; return }
|
|
|
d8894c |
+source $testdir/fts3_common.tcl
|
|
|
d8894c |
+
|
|
|
d8894c |
+set sqlite_fts3_enable_parentheses 1
|
|
|
d8894c |
+#-------------------------------------------------------------------------
|
|
|
d8894c |
+# Request a snippet from a query with more than 64 phrases.
|
|
|
d8894c |
+#
|
|
|
d8894c |
+reset_db
|
|
|
d8894c |
+do_execsql_test 1.0 {
|
|
|
d8894c |
+ CREATE VIRTUAL TABLE f USING fts3(b);
|
|
|
d8894c |
+ INSERT INTO f VALUES ( x'746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218');
|
|
|
d8894c |
+}
|
|
|
d8894c |
+
|
|
|
d8894c |
+do_execsql_test 1.1 {
|
|
|
d8894c |
+ SELECT length(snippet(f))>0 FROM f WHERE b MATCH x'1065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a010f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c2a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e082a011065616e656d655a616c702a2f65732e0f42014001380230018218021001081e0a3d746e6e6d64612e0f42';
|
|
|
d8894c |
+} {1}
|
|
|
d8894c |
+
|
|
|
d8894c |
+reset_db
|
|
|
d8894c |
+do_execsql_test 2.0 {
|
|
|
d8894c |
+ CREATE VIRTUAL TABLE t0 USING fts3(col0 INTEGER PRIMARY KEY,col1 VARCHAR(8),col2 BINARY,col3 BINARY);
|
|
|
d8894c |
+ INSERT INTO t0 VALUES (1, '1234','aaaa','bbbb');
|
|
|
d8894c |
+ SELECT snippet(t0) FROM t0 WHERE t0 MATCH x'0a4d4d4d4d320a4f52d70a310a310a4e4541520a0a31f6ce0a4f520a0a310a310a310a4f520a75fc2a242424' ;
|
|
|
d8894c |
+} {1}
|
|
|
d8894c |
+
|
|
|
d8894c |
+reset_db
|
|
|
d8894c |
+do_execsql_test 2.1 {
|
|
|
d8894c |
+ CREATE VIRTUAL TABLE t0 USING fts3(
|
|
|
d8894c |
+ col0 INTEGER PRIMARY KEY,col1 VARCHAR(8),col2 BINARY,col3 BINARY
|
|
|
d8894c |
+ );
|
|
|
d8894c |
+ INSERT INTO t0 VALUES ('one', '1234','aaaa','bbbb');
|
|
|
d8894c |
+}
|
|
|
d8894c |
+do_execsql_test 2.2 {
|
|
|
d8894c |
+ SELECT snippet(t0) FROM t0 WHERE t0 MATCH
|
|
|
d8894c |
+ '(def AND (one NEAR abc)) OR one'
|
|
|
d8894c |
+} {one}
|
|
|
d8894c |
+
|
|
|
d8894c |
+set sqlite_fts3_enable_parentheses 0
|
|
|
d8894c |
+finish_test
|
|
|
d8894c |
--
|
|
|
d8894c |
2.24.1
|
|
|
d8894c |
|