]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH] lib-sql: driver-sqlite - Use sqlite3_snprintf() to quote values
authorAki Tuomi <aki.tuomi@open-xchange.com>
Fri, 7 Nov 2025 07:21:01 +0000 (09:21 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
This does it the sqlite3 way.

Gbp-Pq: Name 0001-lib-sql-driver-sqlite-Use-sqlite3_snprintf-to-quote-.patch

src/lib-sql/driver-sqlite.c

index 282a83bbf47039a35659ac9949cff923bc58d88b..06903b8d120c321b4010e603e4de655897163a46 100644 (file)
@@ -225,30 +225,11 @@ static const char *
 driver_sqlite_escape_string(struct sql_db *_db ATTR_UNUSED,
                            const char *string)
 {
-       const char *p;
-       char *dest, *destbegin;
-
-       /* find the first ' */
-       for (p = string; *p != '\''; p++) {
-               if (*p == '\0')
-                       return t_strdup_noconst(string);
-       }
-
-       /* @UNSAFE: escape ' with '' */
-       dest = destbegin = t_buffer_get((p - string) + strlen(string) * 2 + 1);
-
-       memcpy(dest, string, p - string);
-       dest += p - string;
-
-       for (; *p != '\0'; p++) {
-               *dest++ = *p;
-               if (*p == '\'')
-                       *dest++ = *p;
-       }
-       *dest++ = '\0';
-       t_buffer_alloc(dest - destbegin);
-
-       return destbegin;
+       const size_t len = strlen(string) * 2 + 1;
+       char *escaped = t_malloc_no0(len);
+       if (sqlite3_snprintf(len, escaped, "%q", string) == NULL)
+               i_unreached();
+       return escaped;
 }
 
 static const char *