From: Aki Tuomi Date: Fri, 7 Nov 2025 07:21:01 +0000 (+0200) Subject: [PATCH] lib-sql: driver-sqlite - Use sqlite3_snprintf() to quote values X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~79 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=9efb88853888f58d20f0064785db471712a55dbb;p=dovecot.git [PATCH] lib-sql: driver-sqlite - Use sqlite3_snprintf() to quote values This does it the sqlite3 way. Gbp-Pq: Name 0001-lib-sql-driver-sqlite-Use-sqlite3_snprintf-to-quote-.patch --- diff --git a/src/lib-sql/driver-sqlite.c b/src/lib-sql/driver-sqlite.c index 282a83b..06903b8 100644 --- a/src/lib-sql/driver-sqlite.c +++ b/src/lib-sql/driver-sqlite.c @@ -225,30 +225,11 @@ static const char * driver_sqlite_escape_string(struct sql_db *_db ATTR_UNUSED, const char *string) { - const char *p; - char *dest, *destbegin; - - /* find the first ' */ - for (p = string; *p != '\''; p++) { - if (*p == '\0') - return t_strdup_noconst(string); - } - - /* @UNSAFE: escape ' with '' */ - dest = destbegin = t_buffer_get((p - string) + strlen(string) * 2 + 1); - - memcpy(dest, string, p - string); - dest += p - string; - - for (; *p != '\0'; p++) { - *dest++ = *p; - if (*p == '\'') - *dest++ = *p; - } - *dest++ = '\0'; - t_buffer_alloc(dest - destbegin); - - return destbegin; + const size_t len = strlen(string) * 2 + 1; + char *escaped = t_malloc_no0(len); + if (sqlite3_snprintf(len, escaped, "%q", string) == NULL) + i_unreached(); + return escaped; } static const char *