xref: /sqlite-3.40.0/src/expr.c (revision 2fca7fef)
1cce7d176Sdrh /*
2b19a2bc6Sdrh ** 2001 September 15
3cce7d176Sdrh **
4b19a2bc6Sdrh ** The author disclaims copyright to this source code.  In place of
5b19a2bc6Sdrh ** a legal notice, here is a blessing:
6cce7d176Sdrh **
7b19a2bc6Sdrh **    May you do good and not evil.
8b19a2bc6Sdrh **    May you find forgiveness for yourself and forgive others.
9b19a2bc6Sdrh **    May you share freely, never taking more than you give.
10cce7d176Sdrh **
11cce7d176Sdrh *************************************************************************
121ccde15dSdrh ** This file contains routines used for analyzing expressions and
13b19a2bc6Sdrh ** for generating VDBE code that evaluates expressions in SQLite.
14cce7d176Sdrh **
15*2fca7fefSdrh ** $Id: expr.c,v 1.269 2006/11/23 11:59:13 drh Exp $
16cce7d176Sdrh */
17cce7d176Sdrh #include "sqliteInt.h"
1804738cb9Sdrh #include <ctype.h>
19a2e00042Sdrh 
20e014a838Sdanielk1977 /*
21e014a838Sdanielk1977 ** Return the 'affinity' of the expression pExpr if any.
22e014a838Sdanielk1977 **
23e014a838Sdanielk1977 ** If pExpr is a column, a reference to a column via an 'AS' alias,
24e014a838Sdanielk1977 ** or a sub-select with a column as the return value, then the
25e014a838Sdanielk1977 ** affinity of that column is returned. Otherwise, 0x00 is returned,
26e014a838Sdanielk1977 ** indicating no affinity for the expression.
27e014a838Sdanielk1977 **
28e014a838Sdanielk1977 ** i.e. the WHERE clause expresssions in the following statements all
29e014a838Sdanielk1977 ** have an affinity:
30e014a838Sdanielk1977 **
31e014a838Sdanielk1977 ** CREATE TABLE t1(a);
32e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE a;
33e014a838Sdanielk1977 ** SELECT a AS b FROM t1 WHERE b;
34e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE (select a from t1);
35e014a838Sdanielk1977 */
36bf3b721fSdanielk1977 char sqlite3ExprAffinity(Expr *pExpr){
37487e262fSdrh   int op = pExpr->op;
38487e262fSdrh   if( op==TK_AS ){
39bf3b721fSdanielk1977     return sqlite3ExprAffinity(pExpr->pLeft);
40a37cdde0Sdanielk1977   }
41487e262fSdrh   if( op==TK_SELECT ){
42bf3b721fSdanielk1977     return sqlite3ExprAffinity(pExpr->pSelect->pEList->a[0].pExpr);
43a37cdde0Sdanielk1977   }
44487e262fSdrh #ifndef SQLITE_OMIT_CAST
45487e262fSdrh   if( op==TK_CAST ){
468a51256cSdrh     return sqlite3AffinityType(&pExpr->token);
47487e262fSdrh   }
48487e262fSdrh #endif
49a37cdde0Sdanielk1977   return pExpr->affinity;
50a37cdde0Sdanielk1977 }
51a37cdde0Sdanielk1977 
5253db1458Sdrh /*
530202b29eSdanielk1977 ** Return the default collation sequence for the expression pExpr. If
540202b29eSdanielk1977 ** there is no default collation type, return 0.
550202b29eSdanielk1977 */
567cedc8d4Sdanielk1977 CollSeq *sqlite3ExprCollSeq(Parse *pParse, Expr *pExpr){
577cedc8d4Sdanielk1977   CollSeq *pColl = 0;
580202b29eSdanielk1977   if( pExpr ){
597cedc8d4Sdanielk1977     pColl = pExpr->pColl;
60487e262fSdrh     if( (pExpr->op==TK_AS || pExpr->op==TK_CAST) && !pColl ){
617cedc8d4Sdanielk1977       return sqlite3ExprCollSeq(pParse, pExpr->pLeft);
620202b29eSdanielk1977     }
630202b29eSdanielk1977   }
647cedc8d4Sdanielk1977   if( sqlite3CheckCollSeq(pParse, pColl) ){
657cedc8d4Sdanielk1977     pColl = 0;
667cedc8d4Sdanielk1977   }
677cedc8d4Sdanielk1977   return pColl;
680202b29eSdanielk1977 }
690202b29eSdanielk1977 
700202b29eSdanielk1977 /*
71626a879aSdrh ** pExpr is an operand of a comparison operator.  aff2 is the
72626a879aSdrh ** type affinity of the other operand.  This routine returns the
7353db1458Sdrh ** type affinity that should be used for the comparison operator.
7453db1458Sdrh */
75e014a838Sdanielk1977 char sqlite3CompareAffinity(Expr *pExpr, char aff2){
76bf3b721fSdanielk1977   char aff1 = sqlite3ExprAffinity(pExpr);
77e014a838Sdanielk1977   if( aff1 && aff2 ){
788df447f0Sdrh     /* Both sides of the comparison are columns. If one has numeric
798df447f0Sdrh     ** affinity, use that. Otherwise use no affinity.
80e014a838Sdanielk1977     */
818a51256cSdrh     if( sqlite3IsNumericAffinity(aff1) || sqlite3IsNumericAffinity(aff2) ){
82e014a838Sdanielk1977       return SQLITE_AFF_NUMERIC;
83e014a838Sdanielk1977     }else{
84e014a838Sdanielk1977       return SQLITE_AFF_NONE;
85e014a838Sdanielk1977     }
86e014a838Sdanielk1977   }else if( !aff1 && !aff2 ){
875f6a87b3Sdrh     /* Neither side of the comparison is a column.  Compare the
885f6a87b3Sdrh     ** results directly.
89e014a838Sdanielk1977     */
905f6a87b3Sdrh     return SQLITE_AFF_NONE;
91e014a838Sdanielk1977   }else{
92e014a838Sdanielk1977     /* One side is a column, the other is not. Use the columns affinity. */
93fe05af87Sdrh     assert( aff1==0 || aff2==0 );
94e014a838Sdanielk1977     return (aff1 + aff2);
95e014a838Sdanielk1977   }
96e014a838Sdanielk1977 }
97e014a838Sdanielk1977 
9853db1458Sdrh /*
9953db1458Sdrh ** pExpr is a comparison operator.  Return the type affinity that should
10053db1458Sdrh ** be applied to both operands prior to doing the comparison.
10153db1458Sdrh */
102e014a838Sdanielk1977 static char comparisonAffinity(Expr *pExpr){
103e014a838Sdanielk1977   char aff;
104e014a838Sdanielk1977   assert( pExpr->op==TK_EQ || pExpr->op==TK_IN || pExpr->op==TK_LT ||
105e014a838Sdanielk1977           pExpr->op==TK_GT || pExpr->op==TK_GE || pExpr->op==TK_LE ||
106e014a838Sdanielk1977           pExpr->op==TK_NE );
107e014a838Sdanielk1977   assert( pExpr->pLeft );
108bf3b721fSdanielk1977   aff = sqlite3ExprAffinity(pExpr->pLeft);
109e014a838Sdanielk1977   if( pExpr->pRight ){
110e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pRight, aff);
111e014a838Sdanielk1977   }
112e014a838Sdanielk1977   else if( pExpr->pSelect ){
113e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pSelect->pEList->a[0].pExpr, aff);
114e014a838Sdanielk1977   }
115e014a838Sdanielk1977   else if( !aff ){
116e014a838Sdanielk1977     aff = SQLITE_AFF_NUMERIC;
117e014a838Sdanielk1977   }
118e014a838Sdanielk1977   return aff;
119e014a838Sdanielk1977 }
120e014a838Sdanielk1977 
121e014a838Sdanielk1977 /*
122e014a838Sdanielk1977 ** pExpr is a comparison expression, eg. '=', '<', IN(...) etc.
123e014a838Sdanielk1977 ** idx_affinity is the affinity of an indexed column. Return true
124e014a838Sdanielk1977 ** if the index with affinity idx_affinity may be used to implement
125e014a838Sdanielk1977 ** the comparison in pExpr.
126e014a838Sdanielk1977 */
127e014a838Sdanielk1977 int sqlite3IndexAffinityOk(Expr *pExpr, char idx_affinity){
128e014a838Sdanielk1977   char aff = comparisonAffinity(pExpr);
1298a51256cSdrh   switch( aff ){
1308a51256cSdrh     case SQLITE_AFF_NONE:
1318a51256cSdrh       return 1;
1328a51256cSdrh     case SQLITE_AFF_TEXT:
1338a51256cSdrh       return idx_affinity==SQLITE_AFF_TEXT;
1348a51256cSdrh     default:
1358a51256cSdrh       return sqlite3IsNumericAffinity(idx_affinity);
1368a51256cSdrh   }
137e014a838Sdanielk1977 }
138e014a838Sdanielk1977 
139a37cdde0Sdanielk1977 /*
140a37cdde0Sdanielk1977 ** Return the P1 value that should be used for a binary comparison
141a37cdde0Sdanielk1977 ** opcode (OP_Eq, OP_Ge etc.) used to compare pExpr1 and pExpr2.
142a37cdde0Sdanielk1977 ** If jumpIfNull is true, then set the low byte of the returned
143a37cdde0Sdanielk1977 ** P1 value to tell the opcode to jump if either expression
144a37cdde0Sdanielk1977 ** evaluates to NULL.
145a37cdde0Sdanielk1977 */
146e014a838Sdanielk1977 static int binaryCompareP1(Expr *pExpr1, Expr *pExpr2, int jumpIfNull){
147bf3b721fSdanielk1977   char aff = sqlite3ExprAffinity(pExpr2);
148f0863fe5Sdrh   return ((int)sqlite3CompareAffinity(pExpr1, aff))+(jumpIfNull?0x100:0);
149a37cdde0Sdanielk1977 }
150a37cdde0Sdanielk1977 
151a2e00042Sdrh /*
1520202b29eSdanielk1977 ** Return a pointer to the collation sequence that should be used by
1530202b29eSdanielk1977 ** a binary comparison operator comparing pLeft and pRight.
1540202b29eSdanielk1977 **
1550202b29eSdanielk1977 ** If the left hand expression has a collating sequence type, then it is
1560202b29eSdanielk1977 ** used. Otherwise the collation sequence for the right hand expression
1570202b29eSdanielk1977 ** is used, or the default (BINARY) if neither expression has a collating
1580202b29eSdanielk1977 ** type.
1590202b29eSdanielk1977 */
1607cedc8d4Sdanielk1977 static CollSeq* binaryCompareCollSeq(Parse *pParse, Expr *pLeft, Expr *pRight){
1617cedc8d4Sdanielk1977   CollSeq *pColl = sqlite3ExprCollSeq(pParse, pLeft);
1620202b29eSdanielk1977   if( !pColl ){
1637cedc8d4Sdanielk1977     pColl = sqlite3ExprCollSeq(pParse, pRight);
1640202b29eSdanielk1977   }
1650202b29eSdanielk1977   return pColl;
1660202b29eSdanielk1977 }
1670202b29eSdanielk1977 
1680202b29eSdanielk1977 /*
169be5c89acSdrh ** Generate code for a comparison operator.
170be5c89acSdrh */
171be5c89acSdrh static int codeCompare(
172be5c89acSdrh   Parse *pParse,    /* The parsing (and code generating) context */
173be5c89acSdrh   Expr *pLeft,      /* The left operand */
174be5c89acSdrh   Expr *pRight,     /* The right operand */
175be5c89acSdrh   int opcode,       /* The comparison opcode */
176be5c89acSdrh   int dest,         /* Jump here if true.  */
177be5c89acSdrh   int jumpIfNull    /* If true, jump if either operand is NULL */
178be5c89acSdrh ){
179be5c89acSdrh   int p1 = binaryCompareP1(pLeft, pRight, jumpIfNull);
180be5c89acSdrh   CollSeq *p3 = binaryCompareCollSeq(pParse, pLeft, pRight);
181be5c89acSdrh   return sqlite3VdbeOp3(pParse->pVdbe, opcode, p1, dest, (void*)p3, P3_COLLSEQ);
182be5c89acSdrh }
183be5c89acSdrh 
184be5c89acSdrh /*
185a76b5dfcSdrh ** Construct a new expression node and return a pointer to it.  Memory
186a76b5dfcSdrh ** for this node is obtained from sqliteMalloc().  The calling function
187a76b5dfcSdrh ** is responsible for making sure the node eventually gets freed.
188a76b5dfcSdrh */
189e4e72072Sdrh Expr *sqlite3Expr(int op, Expr *pLeft, Expr *pRight, const Token *pToken){
190a76b5dfcSdrh   Expr *pNew;
191a76b5dfcSdrh   pNew = sqliteMalloc( sizeof(Expr) );
192a76b5dfcSdrh   if( pNew==0 ){
193d5d56523Sdanielk1977     /* When malloc fails, delete pLeft and pRight. Expressions passed to
194d5d56523Sdanielk1977     ** this function must always be allocated with sqlite3Expr() for this
195d5d56523Sdanielk1977     ** reason.
196d5d56523Sdanielk1977     */
197d5d56523Sdanielk1977     sqlite3ExprDelete(pLeft);
198d5d56523Sdanielk1977     sqlite3ExprDelete(pRight);
199a76b5dfcSdrh     return 0;
200a76b5dfcSdrh   }
201a76b5dfcSdrh   pNew->op = op;
202a76b5dfcSdrh   pNew->pLeft = pLeft;
203a76b5dfcSdrh   pNew->pRight = pRight;
204a58fdfb1Sdanielk1977   pNew->iAgg = -1;
205a76b5dfcSdrh   if( pToken ){
2064b59ab5eSdrh     assert( pToken->dyn==0 );
207145716b3Sdrh     pNew->span = pNew->token = *pToken;
208145716b3Sdrh   }else if( pLeft && pRight ){
2094adee20fSdanielk1977     sqlite3ExprSpan(pNew, &pLeft->span, &pRight->span);
210a76b5dfcSdrh   }
211a76b5dfcSdrh   return pNew;
212a76b5dfcSdrh }
213a76b5dfcSdrh 
214a76b5dfcSdrh /*
215206f3d96Sdrh ** Works like sqlite3Expr() but frees its pLeft and pRight arguments
216206f3d96Sdrh ** if it fails due to a malloc problem.
217206f3d96Sdrh */
218206f3d96Sdrh Expr *sqlite3ExprOrFree(int op, Expr *pLeft, Expr *pRight, const Token *pToken){
219206f3d96Sdrh   Expr *pNew = sqlite3Expr(op, pLeft, pRight, pToken);
220206f3d96Sdrh   if( pNew==0 ){
221206f3d96Sdrh     sqlite3ExprDelete(pLeft);
222206f3d96Sdrh     sqlite3ExprDelete(pRight);
223206f3d96Sdrh   }
224206f3d96Sdrh   return pNew;
225206f3d96Sdrh }
226206f3d96Sdrh 
227206f3d96Sdrh /*
2284e0cff60Sdrh ** When doing a nested parse, you can include terms in an expression
2294e0cff60Sdrh ** that look like this:   #0 #1 #2 ...  These terms refer to elements
230288d37f1Sdrh ** on the stack.  "#0" means the top of the stack.
231288d37f1Sdrh ** "#1" means the next down on the stack.  And so forth.
2324e0cff60Sdrh **
2334e0cff60Sdrh ** This routine is called by the parser to deal with on of those terms.
2344e0cff60Sdrh ** It immediately generates code to store the value in a memory location.
2354e0cff60Sdrh ** The returns an expression that will code to extract the value from
2364e0cff60Sdrh ** that memory location as needed.
2374e0cff60Sdrh */
2384e0cff60Sdrh Expr *sqlite3RegisterExpr(Parse *pParse, Token *pToken){
2394e0cff60Sdrh   Vdbe *v = pParse->pVdbe;
2404e0cff60Sdrh   Expr *p;
2414e0cff60Sdrh   int depth;
2424e0cff60Sdrh   if( pParse->nested==0 ){
2434e0cff60Sdrh     sqlite3ErrorMsg(pParse, "near \"%T\": syntax error", pToken);
2444e0cff60Sdrh     return 0;
2454e0cff60Sdrh   }
246bb7ac00bSdrh   if( v==0 ) return 0;
2474e0cff60Sdrh   p = sqlite3Expr(TK_REGISTER, 0, 0, pToken);
24873c42a13Sdrh   if( p==0 ){
24973c42a13Sdrh     return 0;  /* Malloc failed */
25073c42a13Sdrh   }
2512646da7eSdrh   depth = atoi((char*)&pToken->z[1]);
2524e0cff60Sdrh   p->iTable = pParse->nMem++;
2534e0cff60Sdrh   sqlite3VdbeAddOp(v, OP_Dup, depth, 0);
2544e0cff60Sdrh   sqlite3VdbeAddOp(v, OP_MemStore, p->iTable, 1);
2554e0cff60Sdrh   return p;
2564e0cff60Sdrh }
2574e0cff60Sdrh 
2584e0cff60Sdrh /*
25991bb0eedSdrh ** Join two expressions using an AND operator.  If either expression is
26091bb0eedSdrh ** NULL, then just return the other expression.
26191bb0eedSdrh */
26291bb0eedSdrh Expr *sqlite3ExprAnd(Expr *pLeft, Expr *pRight){
26391bb0eedSdrh   if( pLeft==0 ){
26491bb0eedSdrh     return pRight;
26591bb0eedSdrh   }else if( pRight==0 ){
26691bb0eedSdrh     return pLeft;
26791bb0eedSdrh   }else{
26891bb0eedSdrh     return sqlite3Expr(TK_AND, pLeft, pRight, 0);
26991bb0eedSdrh   }
27091bb0eedSdrh }
27191bb0eedSdrh 
27291bb0eedSdrh /*
2736977fea8Sdrh ** Set the Expr.span field of the given expression to span all
274a76b5dfcSdrh ** text between the two given tokens.
275a76b5dfcSdrh */
2764adee20fSdanielk1977 void sqlite3ExprSpan(Expr *pExpr, Token *pLeft, Token *pRight){
2774efc4754Sdrh   assert( pRight!=0 );
2784efc4754Sdrh   assert( pLeft!=0 );
2799e12800dSdanielk1977   if( !sqlite3MallocFailed() && pRight->z && pLeft->z ){
280ad6d9460Sdrh     assert( pLeft->dyn==0 || pLeft->z[pLeft->n]==0 );
281145716b3Sdrh     if( pLeft->dyn==0 && pRight->dyn==0 ){
2826977fea8Sdrh       pExpr->span.z = pLeft->z;
28397903fefSdrh       pExpr->span.n = pRight->n + (pRight->z - pLeft->z);
2844b59ab5eSdrh     }else{
2856977fea8Sdrh       pExpr->span.z = 0;
2864b59ab5eSdrh     }
287a76b5dfcSdrh   }
288a76b5dfcSdrh }
289a76b5dfcSdrh 
290a76b5dfcSdrh /*
291a76b5dfcSdrh ** Construct a new expression node for a function with multiple
292a76b5dfcSdrh ** arguments.
293a76b5dfcSdrh */
2944adee20fSdanielk1977 Expr *sqlite3ExprFunction(ExprList *pList, Token *pToken){
295a76b5dfcSdrh   Expr *pNew;
2964b202ae2Sdanielk1977   assert( pToken );
297a76b5dfcSdrh   pNew = sqliteMalloc( sizeof(Expr) );
298a76b5dfcSdrh   if( pNew==0 ){
299d5d56523Sdanielk1977     sqlite3ExprListDelete(pList); /* Avoid leaking memory when malloc fails */
300a76b5dfcSdrh     return 0;
301a76b5dfcSdrh   }
302a76b5dfcSdrh   pNew->op = TK_FUNCTION;
303a76b5dfcSdrh   pNew->pList = pList;
3044b59ab5eSdrh   assert( pToken->dyn==0 );
305a76b5dfcSdrh   pNew->token = *pToken;
3066977fea8Sdrh   pNew->span = pNew->token;
307a76b5dfcSdrh   return pNew;
308a76b5dfcSdrh }
309a76b5dfcSdrh 
310a76b5dfcSdrh /*
311fa6bc000Sdrh ** Assign a variable number to an expression that encodes a wildcard
312fa6bc000Sdrh ** in the original SQL statement.
313fa6bc000Sdrh **
314fa6bc000Sdrh ** Wildcards consisting of a single "?" are assigned the next sequential
315fa6bc000Sdrh ** variable number.
316fa6bc000Sdrh **
317fa6bc000Sdrh ** Wildcards of the form "?nnn" are assigned the number "nnn".  We make
318fa6bc000Sdrh ** sure "nnn" is not too be to avoid a denial of service attack when
319fa6bc000Sdrh ** the SQL statement comes from an external source.
320fa6bc000Sdrh **
321fa6bc000Sdrh ** Wildcards of the form ":aaa" or "$aaa" are assigned the same number
322fa6bc000Sdrh ** as the previous instance of the same wildcard.  Or if this is the first
323fa6bc000Sdrh ** instance of the wildcard, the next sequenial variable number is
324fa6bc000Sdrh ** assigned.
325fa6bc000Sdrh */
326fa6bc000Sdrh void sqlite3ExprAssignVarNumber(Parse *pParse, Expr *pExpr){
327fa6bc000Sdrh   Token *pToken;
328fa6bc000Sdrh   if( pExpr==0 ) return;
329fa6bc000Sdrh   pToken = &pExpr->token;
330fa6bc000Sdrh   assert( pToken->n>=1 );
331fa6bc000Sdrh   assert( pToken->z!=0 );
332fa6bc000Sdrh   assert( pToken->z[0]!=0 );
333fa6bc000Sdrh   if( pToken->n==1 ){
334fa6bc000Sdrh     /* Wildcard of the form "?".  Assign the next variable number */
335fa6bc000Sdrh     pExpr->iTable = ++pParse->nVar;
336fa6bc000Sdrh   }else if( pToken->z[0]=='?' ){
337fa6bc000Sdrh     /* Wildcard of the form "?nnn".  Convert "nnn" to an integer and
338fa6bc000Sdrh     ** use it as the variable number */
339fa6bc000Sdrh     int i;
3402646da7eSdrh     pExpr->iTable = i = atoi((char*)&pToken->z[1]);
341fa6bc000Sdrh     if( i<1 || i>SQLITE_MAX_VARIABLE_NUMBER ){
342fa6bc000Sdrh       sqlite3ErrorMsg(pParse, "variable number must be between ?1 and ?%d",
343fa6bc000Sdrh           SQLITE_MAX_VARIABLE_NUMBER);
344fa6bc000Sdrh     }
345fa6bc000Sdrh     if( i>pParse->nVar ){
346fa6bc000Sdrh       pParse->nVar = i;
347fa6bc000Sdrh     }
348fa6bc000Sdrh   }else{
349fa6bc000Sdrh     /* Wildcards of the form ":aaa" or "$aaa".  Reuse the same variable
350fa6bc000Sdrh     ** number as the prior appearance of the same name, or if the name
351fa6bc000Sdrh     ** has never appeared before, reuse the same variable number
352fa6bc000Sdrh     */
353fa6bc000Sdrh     int i, n;
354fa6bc000Sdrh     n = pToken->n;
355fa6bc000Sdrh     for(i=0; i<pParse->nVarExpr; i++){
356fa6bc000Sdrh       Expr *pE;
357fa6bc000Sdrh       if( (pE = pParse->apVarExpr[i])!=0
358fa6bc000Sdrh           && pE->token.n==n
359fa6bc000Sdrh           && memcmp(pE->token.z, pToken->z, n)==0 ){
360fa6bc000Sdrh         pExpr->iTable = pE->iTable;
361fa6bc000Sdrh         break;
362fa6bc000Sdrh       }
363fa6bc000Sdrh     }
364fa6bc000Sdrh     if( i>=pParse->nVarExpr ){
365fa6bc000Sdrh       pExpr->iTable = ++pParse->nVar;
366fa6bc000Sdrh       if( pParse->nVarExpr>=pParse->nVarExprAlloc-1 ){
367fa6bc000Sdrh         pParse->nVarExprAlloc += pParse->nVarExprAlloc + 10;
368e7259296Sdanielk1977         sqliteReallocOrFree((void**)&pParse->apVarExpr,
369fa6bc000Sdrh                        pParse->nVarExprAlloc*sizeof(pParse->apVarExpr[0]) );
370fa6bc000Sdrh       }
3719e12800dSdanielk1977       if( !sqlite3MallocFailed() ){
372fa6bc000Sdrh         assert( pParse->apVarExpr!=0 );
373fa6bc000Sdrh         pParse->apVarExpr[pParse->nVarExpr++] = pExpr;
374fa6bc000Sdrh       }
375fa6bc000Sdrh     }
376fa6bc000Sdrh   }
377fa6bc000Sdrh }
378fa6bc000Sdrh 
379fa6bc000Sdrh /*
380a2e00042Sdrh ** Recursively delete an expression tree.
381a2e00042Sdrh */
3824adee20fSdanielk1977 void sqlite3ExprDelete(Expr *p){
383a2e00042Sdrh   if( p==0 ) return;
3844efc4754Sdrh   if( p->span.dyn ) sqliteFree((char*)p->span.z);
3854efc4754Sdrh   if( p->token.dyn ) sqliteFree((char*)p->token.z);
3864adee20fSdanielk1977   sqlite3ExprDelete(p->pLeft);
3874adee20fSdanielk1977   sqlite3ExprDelete(p->pRight);
3884adee20fSdanielk1977   sqlite3ExprListDelete(p->pList);
3894adee20fSdanielk1977   sqlite3SelectDelete(p->pSelect);
390a2e00042Sdrh   sqliteFree(p);
391a2e00042Sdrh }
392a2e00042Sdrh 
393d2687b77Sdrh /*
394d2687b77Sdrh ** The Expr.token field might be a string literal that is quoted.
395d2687b77Sdrh ** If so, remove the quotation marks.
396d2687b77Sdrh */
397d2687b77Sdrh void sqlite3DequoteExpr(Expr *p){
398d2687b77Sdrh   if( ExprHasAnyProperty(p, EP_Dequoted) ){
399d2687b77Sdrh     return;
400d2687b77Sdrh   }
401d2687b77Sdrh   ExprSetProperty(p, EP_Dequoted);
402d2687b77Sdrh   if( p->token.dyn==0 ){
403d2687b77Sdrh     sqlite3TokenCopy(&p->token, &p->token);
404d2687b77Sdrh   }
405d2687b77Sdrh   sqlite3Dequote((char*)p->token.z);
406d2687b77Sdrh }
407d2687b77Sdrh 
408a76b5dfcSdrh 
409a76b5dfcSdrh /*
410ff78bd2fSdrh ** The following group of routines make deep copies of expressions,
411ff78bd2fSdrh ** expression lists, ID lists, and select statements.  The copies can
412ff78bd2fSdrh ** be deleted (by being passed to their respective ...Delete() routines)
413ff78bd2fSdrh ** without effecting the originals.
414ff78bd2fSdrh **
4154adee20fSdanielk1977 ** The expression list, ID, and source lists return by sqlite3ExprListDup(),
4164adee20fSdanielk1977 ** sqlite3IdListDup(), and sqlite3SrcListDup() can not be further expanded
417ad3cab52Sdrh ** by subsequent calls to sqlite*ListAppend() routines.
418ff78bd2fSdrh **
419ad3cab52Sdrh ** Any tables that the SrcList might point to are not duplicated.
420ff78bd2fSdrh */
4214adee20fSdanielk1977 Expr *sqlite3ExprDup(Expr *p){
422ff78bd2fSdrh   Expr *pNew;
423ff78bd2fSdrh   if( p==0 ) return 0;
424fcb78a49Sdrh   pNew = sqliteMallocRaw( sizeof(*p) );
425ff78bd2fSdrh   if( pNew==0 ) return 0;
4263b167c75Sdrh   memcpy(pNew, p, sizeof(*pNew));
4276977fea8Sdrh   if( p->token.z!=0 ){
4282646da7eSdrh     pNew->token.z = (u8*)sqliteStrNDup((char*)p->token.z, p->token.n);
4294b59ab5eSdrh     pNew->token.dyn = 1;
4304b59ab5eSdrh   }else{
4314efc4754Sdrh     assert( pNew->token.z==0 );
4324b59ab5eSdrh   }
4336977fea8Sdrh   pNew->span.z = 0;
4344adee20fSdanielk1977   pNew->pLeft = sqlite3ExprDup(p->pLeft);
4354adee20fSdanielk1977   pNew->pRight = sqlite3ExprDup(p->pRight);
4364adee20fSdanielk1977   pNew->pList = sqlite3ExprListDup(p->pList);
4374adee20fSdanielk1977   pNew->pSelect = sqlite3SelectDup(p->pSelect);
438aee18ef8Sdanielk1977   pNew->pTab = p->pTab;
439ff78bd2fSdrh   return pNew;
440ff78bd2fSdrh }
4414adee20fSdanielk1977 void sqlite3TokenCopy(Token *pTo, Token *pFrom){
4424b59ab5eSdrh   if( pTo->dyn ) sqliteFree((char*)pTo->z);
4434b59ab5eSdrh   if( pFrom->z ){
4444b59ab5eSdrh     pTo->n = pFrom->n;
4452646da7eSdrh     pTo->z = (u8*)sqliteStrNDup((char*)pFrom->z, pFrom->n);
4464b59ab5eSdrh     pTo->dyn = 1;
4474b59ab5eSdrh   }else{
4484b59ab5eSdrh     pTo->z = 0;
4494b59ab5eSdrh   }
4504b59ab5eSdrh }
4514adee20fSdanielk1977 ExprList *sqlite3ExprListDup(ExprList *p){
452ff78bd2fSdrh   ExprList *pNew;
453145716b3Sdrh   struct ExprList_item *pItem, *pOldItem;
454ff78bd2fSdrh   int i;
455ff78bd2fSdrh   if( p==0 ) return 0;
456ff78bd2fSdrh   pNew = sqliteMalloc( sizeof(*pNew) );
457ff78bd2fSdrh   if( pNew==0 ) return 0;
4584305d103Sdrh   pNew->nExpr = pNew->nAlloc = p->nExpr;
4593e7bc9caSdrh   pNew->a = pItem = sqliteMalloc( p->nExpr*sizeof(p->a[0]) );
460e0048400Sdanielk1977   if( pItem==0 ){
461e0048400Sdanielk1977     sqliteFree(pNew);
462e0048400Sdanielk1977     return 0;
463e0048400Sdanielk1977   }
464145716b3Sdrh   pOldItem = p->a;
465145716b3Sdrh   for(i=0; i<p->nExpr; i++, pItem++, pOldItem++){
4664b59ab5eSdrh     Expr *pNewExpr, *pOldExpr;
467145716b3Sdrh     pItem->pExpr = pNewExpr = sqlite3ExprDup(pOldExpr = pOldItem->pExpr);
4686977fea8Sdrh     if( pOldExpr->span.z!=0 && pNewExpr ){
4696977fea8Sdrh       /* Always make a copy of the span for top-level expressions in the
4704b59ab5eSdrh       ** expression list.  The logic in SELECT processing that determines
4714b59ab5eSdrh       ** the names of columns in the result set needs this information */
4724adee20fSdanielk1977       sqlite3TokenCopy(&pNewExpr->span, &pOldExpr->span);
4734b59ab5eSdrh     }
4741f3e905cSdrh     assert( pNewExpr==0 || pNewExpr->span.z!=0
4756f7adc8aSdrh             || pOldExpr->span.z==0
4769e12800dSdanielk1977             || sqlite3MallocFailed() );
477145716b3Sdrh     pItem->zName = sqliteStrDup(pOldItem->zName);
478145716b3Sdrh     pItem->sortOrder = pOldItem->sortOrder;
479145716b3Sdrh     pItem->isAgg = pOldItem->isAgg;
4803e7bc9caSdrh     pItem->done = 0;
481ff78bd2fSdrh   }
482ff78bd2fSdrh   return pNew;
483ff78bd2fSdrh }
48493758c8dSdanielk1977 
48593758c8dSdanielk1977 /*
48693758c8dSdanielk1977 ** If cursors, triggers, views and subqueries are all omitted from
48793758c8dSdanielk1977 ** the build, then none of the following routines, except for
48893758c8dSdanielk1977 ** sqlite3SelectDup(), can be called. sqlite3SelectDup() is sometimes
48993758c8dSdanielk1977 ** called with a NULL argument.
49093758c8dSdanielk1977 */
4916a67fe8eSdanielk1977 #if !defined(SQLITE_OMIT_VIEW) || !defined(SQLITE_OMIT_TRIGGER) \
4926a67fe8eSdanielk1977  || !defined(SQLITE_OMIT_SUBQUERY)
4934adee20fSdanielk1977 SrcList *sqlite3SrcListDup(SrcList *p){
494ad3cab52Sdrh   SrcList *pNew;
495ad3cab52Sdrh   int i;
496113088ecSdrh   int nByte;
497ad3cab52Sdrh   if( p==0 ) return 0;
498113088ecSdrh   nByte = sizeof(*p) + (p->nSrc>0 ? sizeof(p->a[0]) * (p->nSrc-1) : 0);
4994efc4754Sdrh   pNew = sqliteMallocRaw( nByte );
500ad3cab52Sdrh   if( pNew==0 ) return 0;
5014305d103Sdrh   pNew->nSrc = pNew->nAlloc = p->nSrc;
502ad3cab52Sdrh   for(i=0; i<p->nSrc; i++){
5034efc4754Sdrh     struct SrcList_item *pNewItem = &pNew->a[i];
5044efc4754Sdrh     struct SrcList_item *pOldItem = &p->a[i];
505ed8a3bb1Sdrh     Table *pTab;
5064efc4754Sdrh     pNewItem->zDatabase = sqliteStrDup(pOldItem->zDatabase);
5074efc4754Sdrh     pNewItem->zName = sqliteStrDup(pOldItem->zName);
5084efc4754Sdrh     pNewItem->zAlias = sqliteStrDup(pOldItem->zAlias);
5094efc4754Sdrh     pNewItem->jointype = pOldItem->jointype;
5104efc4754Sdrh     pNewItem->iCursor = pOldItem->iCursor;
5111787ccabSdanielk1977     pNewItem->isPopulated = pOldItem->isPopulated;
512ed8a3bb1Sdrh     pTab = pNewItem->pTab = pOldItem->pTab;
513ed8a3bb1Sdrh     if( pTab ){
514ed8a3bb1Sdrh       pTab->nRef++;
515a1cb183dSdanielk1977     }
5164adee20fSdanielk1977     pNewItem->pSelect = sqlite3SelectDup(pOldItem->pSelect);
5174adee20fSdanielk1977     pNewItem->pOn = sqlite3ExprDup(pOldItem->pOn);
5184adee20fSdanielk1977     pNewItem->pUsing = sqlite3IdListDup(pOldItem->pUsing);
5196c18b6e0Sdanielk1977     pNewItem->colUsed = pOldItem->colUsed;
520ad3cab52Sdrh   }
521ad3cab52Sdrh   return pNew;
522ad3cab52Sdrh }
5234adee20fSdanielk1977 IdList *sqlite3IdListDup(IdList *p){
524ff78bd2fSdrh   IdList *pNew;
525ff78bd2fSdrh   int i;
526ff78bd2fSdrh   if( p==0 ) return 0;
5274efc4754Sdrh   pNew = sqliteMallocRaw( sizeof(*pNew) );
528ff78bd2fSdrh   if( pNew==0 ) return 0;
5294305d103Sdrh   pNew->nId = pNew->nAlloc = p->nId;
5304efc4754Sdrh   pNew->a = sqliteMallocRaw( p->nId*sizeof(p->a[0]) );
531d5d56523Sdanielk1977   if( pNew->a==0 ){
532d5d56523Sdanielk1977     sqliteFree(pNew);
533d5d56523Sdanielk1977     return 0;
534d5d56523Sdanielk1977   }
535ff78bd2fSdrh   for(i=0; i<p->nId; i++){
5364efc4754Sdrh     struct IdList_item *pNewItem = &pNew->a[i];
5374efc4754Sdrh     struct IdList_item *pOldItem = &p->a[i];
5384efc4754Sdrh     pNewItem->zName = sqliteStrDup(pOldItem->zName);
5394efc4754Sdrh     pNewItem->idx = pOldItem->idx;
540ff78bd2fSdrh   }
541ff78bd2fSdrh   return pNew;
542ff78bd2fSdrh }
5434adee20fSdanielk1977 Select *sqlite3SelectDup(Select *p){
544ff78bd2fSdrh   Select *pNew;
545ff78bd2fSdrh   if( p==0 ) return 0;
5464efc4754Sdrh   pNew = sqliteMallocRaw( sizeof(*p) );
547ff78bd2fSdrh   if( pNew==0 ) return 0;
548ff78bd2fSdrh   pNew->isDistinct = p->isDistinct;
5494adee20fSdanielk1977   pNew->pEList = sqlite3ExprListDup(p->pEList);
5504adee20fSdanielk1977   pNew->pSrc = sqlite3SrcListDup(p->pSrc);
5514adee20fSdanielk1977   pNew->pWhere = sqlite3ExprDup(p->pWhere);
5524adee20fSdanielk1977   pNew->pGroupBy = sqlite3ExprListDup(p->pGroupBy);
5534adee20fSdanielk1977   pNew->pHaving = sqlite3ExprDup(p->pHaving);
5544adee20fSdanielk1977   pNew->pOrderBy = sqlite3ExprListDup(p->pOrderBy);
555ff78bd2fSdrh   pNew->op = p->op;
5564adee20fSdanielk1977   pNew->pPrior = sqlite3SelectDup(p->pPrior);
557a2dc3b1aSdanielk1977   pNew->pLimit = sqlite3ExprDup(p->pLimit);
558a2dc3b1aSdanielk1977   pNew->pOffset = sqlite3ExprDup(p->pOffset);
5597b58daeaSdrh   pNew->iLimit = -1;
5607b58daeaSdrh   pNew->iOffset = -1;
561a1cb183dSdanielk1977   pNew->isResolved = p->isResolved;
562a1cb183dSdanielk1977   pNew->isAgg = p->isAgg;
563b9bb7c18Sdrh   pNew->usesEphm = 0;
5648e647b81Sdrh   pNew->disallowOrderBy = 0;
5650342b1f5Sdrh   pNew->pRightmost = 0;
566b9bb7c18Sdrh   pNew->addrOpenEphm[0] = -1;
567b9bb7c18Sdrh   pNew->addrOpenEphm[1] = -1;
568b9bb7c18Sdrh   pNew->addrOpenEphm[2] = -1;
569ff78bd2fSdrh   return pNew;
570ff78bd2fSdrh }
57193758c8dSdanielk1977 #else
57293758c8dSdanielk1977 Select *sqlite3SelectDup(Select *p){
57393758c8dSdanielk1977   assert( p==0 );
57493758c8dSdanielk1977   return 0;
57593758c8dSdanielk1977 }
57693758c8dSdanielk1977 #endif
577ff78bd2fSdrh 
578ff78bd2fSdrh 
579ff78bd2fSdrh /*
580a76b5dfcSdrh ** Add a new element to the end of an expression list.  If pList is
581a76b5dfcSdrh ** initially NULL, then create a new expression list.
582a76b5dfcSdrh */
5834adee20fSdanielk1977 ExprList *sqlite3ExprListAppend(ExprList *pList, Expr *pExpr, Token *pName){
584a76b5dfcSdrh   if( pList==0 ){
585a76b5dfcSdrh     pList = sqliteMalloc( sizeof(ExprList) );
586a76b5dfcSdrh     if( pList==0 ){
587d5d56523Sdanielk1977       goto no_mem;
588a76b5dfcSdrh     }
5894efc4754Sdrh     assert( pList->nAlloc==0 );
590a76b5dfcSdrh   }
5914305d103Sdrh   if( pList->nAlloc<=pList->nExpr ){
592d5d56523Sdanielk1977     struct ExprList_item *a;
593d5d56523Sdanielk1977     int n = pList->nAlloc*2 + 4;
594d5d56523Sdanielk1977     a = sqliteRealloc(pList->a, n*sizeof(pList->a[0]));
595d5d56523Sdanielk1977     if( a==0 ){
596d5d56523Sdanielk1977       goto no_mem;
597a76b5dfcSdrh     }
598d5d56523Sdanielk1977     pList->a = a;
599d5d56523Sdanielk1977     pList->nAlloc = n;
600a76b5dfcSdrh   }
6014efc4754Sdrh   assert( pList->a!=0 );
6024efc4754Sdrh   if( pExpr || pName ){
6034efc4754Sdrh     struct ExprList_item *pItem = &pList->a[pList->nExpr++];
6044efc4754Sdrh     memset(pItem, 0, sizeof(*pItem));
605a99db3b6Sdrh     pItem->zName = sqlite3NameFromToken(pName);
606e94ddc9eSdanielk1977     pItem->pExpr = pExpr;
607a76b5dfcSdrh   }
608a76b5dfcSdrh   return pList;
609d5d56523Sdanielk1977 
610d5d56523Sdanielk1977 no_mem:
611d5d56523Sdanielk1977   /* Avoid leaking memory if malloc has failed. */
612d5d56523Sdanielk1977   sqlite3ExprDelete(pExpr);
613d5d56523Sdanielk1977   sqlite3ExprListDelete(pList);
614d5d56523Sdanielk1977   return 0;
615a76b5dfcSdrh }
616a76b5dfcSdrh 
617a76b5dfcSdrh /*
618a76b5dfcSdrh ** Delete an entire expression list.
619a76b5dfcSdrh */
6204adee20fSdanielk1977 void sqlite3ExprListDelete(ExprList *pList){
621a76b5dfcSdrh   int i;
622be5c89acSdrh   struct ExprList_item *pItem;
623a76b5dfcSdrh   if( pList==0 ) return;
6241bdd9b57Sdrh   assert( pList->a!=0 || (pList->nExpr==0 && pList->nAlloc==0) );
6251bdd9b57Sdrh   assert( pList->nExpr<=pList->nAlloc );
626be5c89acSdrh   for(pItem=pList->a, i=0; i<pList->nExpr; i++, pItem++){
627be5c89acSdrh     sqlite3ExprDelete(pItem->pExpr);
628be5c89acSdrh     sqliteFree(pItem->zName);
629a76b5dfcSdrh   }
630a76b5dfcSdrh   sqliteFree(pList->a);
631a76b5dfcSdrh   sqliteFree(pList);
632a76b5dfcSdrh }
633a76b5dfcSdrh 
634a76b5dfcSdrh /*
635626a879aSdrh ** Walk an expression tree.  Call xFunc for each node visited.
63673b211abSdrh **
637626a879aSdrh ** The return value from xFunc determines whether the tree walk continues.
638626a879aSdrh ** 0 means continue walking the tree.  1 means do not walk children
639626a879aSdrh ** of the current node but continue with siblings.  2 means abandon
640626a879aSdrh ** the tree walk completely.
641626a879aSdrh **
642626a879aSdrh ** The return value from this routine is 1 to abandon the tree walk
643626a879aSdrh ** and 0 to continue.
64487abf5c0Sdrh **
64587abf5c0Sdrh ** NOTICE:  This routine does *not* descend into subqueries.
646626a879aSdrh */
647a58fdfb1Sdanielk1977 static int walkExprList(ExprList *, int (*)(void *, Expr*), void *);
648626a879aSdrh static int walkExprTree(Expr *pExpr, int (*xFunc)(void*,Expr*), void *pArg){
649626a879aSdrh   int rc;
650626a879aSdrh   if( pExpr==0 ) return 0;
651626a879aSdrh   rc = (*xFunc)(pArg, pExpr);
652626a879aSdrh   if( rc==0 ){
653626a879aSdrh     if( walkExprTree(pExpr->pLeft, xFunc, pArg) ) return 1;
654626a879aSdrh     if( walkExprTree(pExpr->pRight, xFunc, pArg) ) return 1;
655a58fdfb1Sdanielk1977     if( walkExprList(pExpr->pList, xFunc, pArg) ) return 1;
656626a879aSdrh   }
657626a879aSdrh   return rc>1;
658626a879aSdrh }
659626a879aSdrh 
660626a879aSdrh /*
661a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in list p.
662a58fdfb1Sdanielk1977 */
663a58fdfb1Sdanielk1977 static int walkExprList(ExprList *p, int (*xFunc)(void *, Expr*), void *pArg){
664a58fdfb1Sdanielk1977   int i;
665a58fdfb1Sdanielk1977   struct ExprList_item *pItem;
666a58fdfb1Sdanielk1977   if( !p ) return 0;
667a58fdfb1Sdanielk1977   for(i=p->nExpr, pItem=p->a; i>0; i--, pItem++){
668a58fdfb1Sdanielk1977     if( walkExprTree(pItem->pExpr, xFunc, pArg) ) return 1;
669a58fdfb1Sdanielk1977   }
670a58fdfb1Sdanielk1977   return 0;
671a58fdfb1Sdanielk1977 }
672a58fdfb1Sdanielk1977 
673a58fdfb1Sdanielk1977 /*
674a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in Select p, not including
675a58fdfb1Sdanielk1977 ** expressions that are part of sub-selects in any FROM clause or the LIMIT
676a58fdfb1Sdanielk1977 ** or OFFSET expressions..
677a58fdfb1Sdanielk1977 */
678a58fdfb1Sdanielk1977 static int walkSelectExpr(Select *p, int (*xFunc)(void *, Expr*), void *pArg){
679a58fdfb1Sdanielk1977   walkExprList(p->pEList, xFunc, pArg);
680a58fdfb1Sdanielk1977   walkExprTree(p->pWhere, xFunc, pArg);
681a58fdfb1Sdanielk1977   walkExprList(p->pGroupBy, xFunc, pArg);
682a58fdfb1Sdanielk1977   walkExprTree(p->pHaving, xFunc, pArg);
683a58fdfb1Sdanielk1977   walkExprList(p->pOrderBy, xFunc, pArg);
684a58fdfb1Sdanielk1977   return 0;
685a58fdfb1Sdanielk1977 }
686a58fdfb1Sdanielk1977 
687a58fdfb1Sdanielk1977 
688a58fdfb1Sdanielk1977 /*
689626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
690626a879aSdrh **
691626a879aSdrh ** pArg is really a pointer to an integer.  If we can tell by looking
69273b211abSdrh ** at pExpr that the expression that contains pExpr is not a constant
69373b211abSdrh ** expression, then set *pArg to 0 and return 2 to abandon the tree walk.
69473b211abSdrh ** If pExpr does does not disqualify the expression from being a constant
69573b211abSdrh ** then do nothing.
69673b211abSdrh **
69773b211abSdrh ** After walking the whole tree, if no nodes are found that disqualify
69873b211abSdrh ** the expression as constant, then we assume the whole expression
69973b211abSdrh ** is constant.  See sqlite3ExprIsConstant() for additional information.
700626a879aSdrh */
701626a879aSdrh static int exprNodeIsConstant(void *pArg, Expr *pExpr){
702626a879aSdrh   switch( pExpr->op ){
703eb55bd2fSdrh     /* Consider functions to be constant if all their arguments are constant
704eb55bd2fSdrh     ** and *pArg==2 */
705eb55bd2fSdrh     case TK_FUNCTION:
706eb55bd2fSdrh       if( *((int*)pArg)==2 ) return 0;
707eb55bd2fSdrh       /* Fall through */
708626a879aSdrh     case TK_ID:
709626a879aSdrh     case TK_COLUMN:
710626a879aSdrh     case TK_DOT:
711626a879aSdrh     case TK_AGG_FUNCTION:
71213449892Sdrh     case TK_AGG_COLUMN:
713fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
714fe2093d7Sdrh     case TK_SELECT:
715fe2093d7Sdrh     case TK_EXISTS:
716fe2093d7Sdrh #endif
717626a879aSdrh       *((int*)pArg) = 0;
718626a879aSdrh       return 2;
71987abf5c0Sdrh     case TK_IN:
72087abf5c0Sdrh       if( pExpr->pSelect ){
72187abf5c0Sdrh         *((int*)pArg) = 0;
72287abf5c0Sdrh         return 2;
72387abf5c0Sdrh       }
724626a879aSdrh     default:
725626a879aSdrh       return 0;
726626a879aSdrh   }
727626a879aSdrh }
728626a879aSdrh 
729626a879aSdrh /*
730fef5208cSdrh ** Walk an expression tree.  Return 1 if the expression is constant
731eb55bd2fSdrh ** and 0 if it involves variables or function calls.
7322398937bSdrh **
7332398937bSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
7342398937bSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
7352398937bSdrh ** a constant.
736fef5208cSdrh */
7374adee20fSdanielk1977 int sqlite3ExprIsConstant(Expr *p){
738626a879aSdrh   int isConst = 1;
739626a879aSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
740626a879aSdrh   return isConst;
741fef5208cSdrh }
742fef5208cSdrh 
743fef5208cSdrh /*
744eb55bd2fSdrh ** Walk an expression tree.  Return 1 if the expression is constant
745eb55bd2fSdrh ** or a function call with constant arguments.  Return and 0 if there
746eb55bd2fSdrh ** are any variables.
747eb55bd2fSdrh **
748eb55bd2fSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
749eb55bd2fSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
750eb55bd2fSdrh ** a constant.
751eb55bd2fSdrh */
752eb55bd2fSdrh int sqlite3ExprIsConstantOrFunction(Expr *p){
753eb55bd2fSdrh   int isConst = 2;
754eb55bd2fSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
755eb55bd2fSdrh   return isConst!=0;
756eb55bd2fSdrh }
757eb55bd2fSdrh 
758eb55bd2fSdrh /*
75973b211abSdrh ** If the expression p codes a constant integer that is small enough
760202b2df7Sdrh ** to fit in a 32-bit integer, return 1 and put the value of the integer
761202b2df7Sdrh ** in *pValue.  If the expression is not an integer or if it is too big
762202b2df7Sdrh ** to fit in a signed 32-bit integer, return 0 and leave *pValue unchanged.
763e4de1febSdrh */
7644adee20fSdanielk1977 int sqlite3ExprIsInteger(Expr *p, int *pValue){
765e4de1febSdrh   switch( p->op ){
766e4de1febSdrh     case TK_INTEGER: {
7672646da7eSdrh       if( sqlite3GetInt32((char*)p->token.z, pValue) ){
768e4de1febSdrh         return 1;
769e4de1febSdrh       }
770202b2df7Sdrh       break;
771202b2df7Sdrh     }
7724b59ab5eSdrh     case TK_UPLUS: {
7734adee20fSdanielk1977       return sqlite3ExprIsInteger(p->pLeft, pValue);
7744b59ab5eSdrh     }
775e4de1febSdrh     case TK_UMINUS: {
776e4de1febSdrh       int v;
7774adee20fSdanielk1977       if( sqlite3ExprIsInteger(p->pLeft, &v) ){
778e4de1febSdrh         *pValue = -v;
779e4de1febSdrh         return 1;
780e4de1febSdrh       }
781e4de1febSdrh       break;
782e4de1febSdrh     }
783e4de1febSdrh     default: break;
784e4de1febSdrh   }
785e4de1febSdrh   return 0;
786e4de1febSdrh }
787e4de1febSdrh 
788e4de1febSdrh /*
789c4a3c779Sdrh ** Return TRUE if the given string is a row-id column name.
790c4a3c779Sdrh */
7914adee20fSdanielk1977 int sqlite3IsRowid(const char *z){
7924adee20fSdanielk1977   if( sqlite3StrICmp(z, "_ROWID_")==0 ) return 1;
7934adee20fSdanielk1977   if( sqlite3StrICmp(z, "ROWID")==0 ) return 1;
7944adee20fSdanielk1977   if( sqlite3StrICmp(z, "OID")==0 ) return 1;
795c4a3c779Sdrh   return 0;
796c4a3c779Sdrh }
797c4a3c779Sdrh 
798c4a3c779Sdrh /*
7998141f61eSdrh ** Given the name of a column of the form X.Y.Z or Y.Z or just Z, look up
8008141f61eSdrh ** that name in the set of source tables in pSrcList and make the pExpr
8018141f61eSdrh ** expression node refer back to that source column.  The following changes
8028141f61eSdrh ** are made to pExpr:
8038141f61eSdrh **
8048141f61eSdrh **    pExpr->iDb           Set the index in db->aDb[] of the database holding
8058141f61eSdrh **                         the table.
8068141f61eSdrh **    pExpr->iTable        Set to the cursor number for the table obtained
8078141f61eSdrh **                         from pSrcList.
8088141f61eSdrh **    pExpr->iColumn       Set to the column number within the table.
8098141f61eSdrh **    pExpr->op            Set to TK_COLUMN.
8108141f61eSdrh **    pExpr->pLeft         Any expression this points to is deleted
8118141f61eSdrh **    pExpr->pRight        Any expression this points to is deleted.
8128141f61eSdrh **
8138141f61eSdrh ** The pDbToken is the name of the database (the "X").  This value may be
8148141f61eSdrh ** NULL meaning that name is of the form Y.Z or Z.  Any available database
8158141f61eSdrh ** can be used.  The pTableToken is the name of the table (the "Y").  This
8168141f61eSdrh ** value can be NULL if pDbToken is also NULL.  If pTableToken is NULL it
8178141f61eSdrh ** means that the form of the name is Z and that columns from any table
8188141f61eSdrh ** can be used.
8198141f61eSdrh **
8208141f61eSdrh ** If the name cannot be resolved unambiguously, leave an error message
8218141f61eSdrh ** in pParse and return non-zero.  Return zero on success.
8228141f61eSdrh */
8238141f61eSdrh static int lookupName(
8248141f61eSdrh   Parse *pParse,       /* The parsing context */
8258141f61eSdrh   Token *pDbToken,     /* Name of the database containing table, or NULL */
8268141f61eSdrh   Token *pTableToken,  /* Name of table containing column, or NULL */
8278141f61eSdrh   Token *pColumnToken, /* Name of the column. */
828626a879aSdrh   NameContext *pNC,    /* The name context used to resolve the name */
8298141f61eSdrh   Expr *pExpr          /* Make this EXPR node point to the selected column */
8308141f61eSdrh ){
8318141f61eSdrh   char *zDb = 0;       /* Name of the database.  The "X" in X.Y.Z */
8328141f61eSdrh   char *zTab = 0;      /* Name of the table.  The "Y" in X.Y.Z or Y.Z */
8338141f61eSdrh   char *zCol = 0;      /* Name of the column.  The "Z" */
8348141f61eSdrh   int i, j;            /* Loop counters */
8358141f61eSdrh   int cnt = 0;         /* Number of matching column names */
8368141f61eSdrh   int cntTab = 0;      /* Number of matching table names */
8379bb575fdSdrh   sqlite3 *db = pParse->db;  /* The database */
83851669863Sdrh   struct SrcList_item *pItem;       /* Use for looping over pSrcList items */
83951669863Sdrh   struct SrcList_item *pMatch = 0;  /* The matching pSrcList item */
84073b211abSdrh   NameContext *pTopNC = pNC;        /* First namecontext in the list */
8418141f61eSdrh 
8428141f61eSdrh   assert( pColumnToken && pColumnToken->z ); /* The Z in X.Y.Z cannot be NULL */
843a99db3b6Sdrh   zDb = sqlite3NameFromToken(pDbToken);
844a99db3b6Sdrh   zTab = sqlite3NameFromToken(pTableToken);
845a99db3b6Sdrh   zCol = sqlite3NameFromToken(pColumnToken);
8469e12800dSdanielk1977   if( sqlite3MallocFailed() ){
847d5d56523Sdanielk1977     goto lookupname_end;
8488141f61eSdrh   }
8498141f61eSdrh 
8508141f61eSdrh   pExpr->iTable = -1;
851626a879aSdrh   while( pNC && cnt==0 ){
852ffe07b2dSdrh     ExprList *pEList;
853626a879aSdrh     SrcList *pSrcList = pNC->pSrcList;
854626a879aSdrh 
855b3bce662Sdanielk1977     if( pSrcList ){
85651669863Sdrh       for(i=0, pItem=pSrcList->a; i<pSrcList->nSrc; i++, pItem++){
85743617e9aSdrh         Table *pTab;
85843617e9aSdrh         int iDb;
8598141f61eSdrh         Column *pCol;
8608141f61eSdrh 
86143617e9aSdrh         pTab = pItem->pTab;
86243617e9aSdrh         assert( pTab!=0 );
86343617e9aSdrh         iDb = sqlite3SchemaToIndex(db, pTab->pSchema);
8648141f61eSdrh         assert( pTab->nCol>0 );
8658141f61eSdrh         if( zTab ){
8668141f61eSdrh           if( pItem->zAlias ){
8678141f61eSdrh             char *zTabName = pItem->zAlias;
8684adee20fSdanielk1977             if( sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
8698141f61eSdrh           }else{
8708141f61eSdrh             char *zTabName = pTab->zName;
8714adee20fSdanielk1977             if( zTabName==0 || sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
872da184236Sdanielk1977             if( zDb!=0 && sqlite3StrICmp(db->aDb[iDb].zName, zDb)!=0 ){
8738141f61eSdrh               continue;
8748141f61eSdrh             }
8758141f61eSdrh           }
8768141f61eSdrh         }
8778141f61eSdrh         if( 0==(cntTab++) ){
8788141f61eSdrh           pExpr->iTable = pItem->iCursor;
879da184236Sdanielk1977           pExpr->pSchema = pTab->pSchema;
88051669863Sdrh           pMatch = pItem;
8818141f61eSdrh         }
8828141f61eSdrh         for(j=0, pCol=pTab->aCol; j<pTab->nCol; j++, pCol++){
8834adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
884b3bf556eSdanielk1977             const char *zColl = pTab->aCol[j].zColl;
885873fac0cSdrh             IdList *pUsing;
8868141f61eSdrh             cnt++;
8878141f61eSdrh             pExpr->iTable = pItem->iCursor;
88851669863Sdrh             pMatch = pItem;
889da184236Sdanielk1977             pExpr->pSchema = pTab->pSchema;
8908141f61eSdrh             /* Substitute the rowid (column -1) for the INTEGER PRIMARY KEY */
8918141f61eSdrh             pExpr->iColumn = j==pTab->iPKey ? -1 : j;
892a37cdde0Sdanielk1977             pExpr->affinity = pTab->aCol[j].affinity;
893b3bf556eSdanielk1977             pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
894355ef361Sdrh             if( pItem->jointype & JT_NATURAL ){
895355ef361Sdrh               /* If this match occurred in the left table of a natural join,
896355ef361Sdrh               ** then skip the right table to avoid a duplicate match */
897355ef361Sdrh               pItem++;
898355ef361Sdrh               i++;
899355ef361Sdrh             }
900873fac0cSdrh             if( (pUsing = pItem->pUsing)!=0 ){
901873fac0cSdrh               /* If this match occurs on a column that is in the USING clause
902873fac0cSdrh               ** of a join, skip the search of the right table of the join
903873fac0cSdrh               ** to avoid a duplicate match there. */
904873fac0cSdrh               int k;
905873fac0cSdrh               for(k=0; k<pUsing->nId; k++){
906873fac0cSdrh                 if( sqlite3StrICmp(pUsing->a[k].zName, zCol)==0 ){
907873fac0cSdrh                   pItem++;
908873fac0cSdrh                   i++;
909873fac0cSdrh                   break;
910873fac0cSdrh                 }
911873fac0cSdrh               }
912873fac0cSdrh             }
9138141f61eSdrh             break;
9148141f61eSdrh           }
9158141f61eSdrh         }
9168141f61eSdrh       }
917b3bce662Sdanielk1977     }
9188141f61eSdrh 
919b7f9164eSdrh #ifndef SQLITE_OMIT_TRIGGER
9208141f61eSdrh     /* If we have not already resolved the name, then maybe
9218141f61eSdrh     ** it is a new.* or old.* trigger argument reference
9228141f61eSdrh     */
9238141f61eSdrh     if( zDb==0 && zTab!=0 && cnt==0 && pParse->trigStack!=0 ){
9248141f61eSdrh       TriggerStack *pTriggerStack = pParse->trigStack;
9258141f61eSdrh       Table *pTab = 0;
9264adee20fSdanielk1977       if( pTriggerStack->newIdx != -1 && sqlite3StrICmp("new", zTab) == 0 ){
9278141f61eSdrh         pExpr->iTable = pTriggerStack->newIdx;
9288141f61eSdrh         assert( pTriggerStack->pTab );
9298141f61eSdrh         pTab = pTriggerStack->pTab;
9304adee20fSdanielk1977       }else if( pTriggerStack->oldIdx != -1 && sqlite3StrICmp("old", zTab)==0 ){
9318141f61eSdrh         pExpr->iTable = pTriggerStack->oldIdx;
9328141f61eSdrh         assert( pTriggerStack->pTab );
9338141f61eSdrh         pTab = pTriggerStack->pTab;
9348141f61eSdrh       }
9358141f61eSdrh 
9368141f61eSdrh       if( pTab ){
937f0113000Sdanielk1977         int iCol;
9388141f61eSdrh         Column *pCol = pTab->aCol;
9398141f61eSdrh 
940da184236Sdanielk1977         pExpr->pSchema = pTab->pSchema;
9418141f61eSdrh         cntTab++;
942f0113000Sdanielk1977         for(iCol=0; iCol < pTab->nCol; iCol++, pCol++) {
9434adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
944f0113000Sdanielk1977             const char *zColl = pTab->aCol[iCol].zColl;
9458141f61eSdrh             cnt++;
946f0113000Sdanielk1977             pExpr->iColumn = iCol==pTab->iPKey ? -1 : iCol;
947f0113000Sdanielk1977             pExpr->affinity = pTab->aCol[iCol].affinity;
948b3bf556eSdanielk1977             pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
949aee18ef8Sdanielk1977             pExpr->pTab = pTab;
9508141f61eSdrh             break;
9518141f61eSdrh           }
9528141f61eSdrh         }
9538141f61eSdrh       }
9548141f61eSdrh     }
955b7f9164eSdrh #endif /* !defined(SQLITE_OMIT_TRIGGER) */
9568141f61eSdrh 
9578141f61eSdrh     /*
9588141f61eSdrh     ** Perhaps the name is a reference to the ROWID
9598141f61eSdrh     */
9604adee20fSdanielk1977     if( cnt==0 && cntTab==1 && sqlite3IsRowid(zCol) ){
9618141f61eSdrh       cnt = 1;
9628141f61eSdrh       pExpr->iColumn = -1;
9638a51256cSdrh       pExpr->affinity = SQLITE_AFF_INTEGER;
9648141f61eSdrh     }
9658141f61eSdrh 
9668141f61eSdrh     /*
9678141f61eSdrh     ** If the input is of the form Z (not Y.Z or X.Y.Z) then the name Z
9688141f61eSdrh     ** might refer to an result-set alias.  This happens, for example, when
9698141f61eSdrh     ** we are resolving names in the WHERE clause of the following command:
9708141f61eSdrh     **
9718141f61eSdrh     **     SELECT a+b AS x FROM table WHERE x<10;
9728141f61eSdrh     **
9738141f61eSdrh     ** In cases like this, replace pExpr with a copy of the expression that
9748141f61eSdrh     ** forms the result set entry ("a+b" in the example) and return immediately.
9758141f61eSdrh     ** Note that the expression in the result set should have already been
9768141f61eSdrh     ** resolved by the time the WHERE clause is resolved.
9778141f61eSdrh     */
978ffe07b2dSdrh     if( cnt==0 && (pEList = pNC->pEList)!=0 && zTab==0 ){
9798141f61eSdrh       for(j=0; j<pEList->nExpr; j++){
9808141f61eSdrh         char *zAs = pEList->a[j].zName;
9814adee20fSdanielk1977         if( zAs!=0 && sqlite3StrICmp(zAs, zCol)==0 ){
9828141f61eSdrh           assert( pExpr->pLeft==0 && pExpr->pRight==0 );
9838141f61eSdrh           pExpr->op = TK_AS;
9848141f61eSdrh           pExpr->iColumn = j;
9854adee20fSdanielk1977           pExpr->pLeft = sqlite3ExprDup(pEList->a[j].pExpr);
98615ccce1cSdrh           cnt = 1;
9878141f61eSdrh           assert( zTab==0 && zDb==0 );
98815ccce1cSdrh           goto lookupname_end_2;
9898141f61eSdrh         }
9908141f61eSdrh       }
9918141f61eSdrh     }
9928141f61eSdrh 
993626a879aSdrh     /* Advance to the next name context.  The loop will exit when either
994626a879aSdrh     ** we have a match (cnt>0) or when we run out of name contexts.
995626a879aSdrh     */
996626a879aSdrh     if( cnt==0 ){
997626a879aSdrh       pNC = pNC->pNext;
998626a879aSdrh     }
999626a879aSdrh   }
1000626a879aSdrh 
10018141f61eSdrh   /*
10028141f61eSdrh   ** If X and Y are NULL (in other words if only the column name Z is
10038141f61eSdrh   ** supplied) and the value of Z is enclosed in double-quotes, then
10048141f61eSdrh   ** Z is a string literal if it doesn't match any column names.  In that
10058141f61eSdrh   ** case, we need to return right away and not make any changes to
10068141f61eSdrh   ** pExpr.
100715ccce1cSdrh   **
100815ccce1cSdrh   ** Because no reference was made to outer contexts, the pNC->nRef
100915ccce1cSdrh   ** fields are not changed in any context.
10108141f61eSdrh   */
10118141f61eSdrh   if( cnt==0 && zTab==0 && pColumnToken->z[0]=='"' ){
10128141f61eSdrh     sqliteFree(zCol);
10138141f61eSdrh     return 0;
10148141f61eSdrh   }
10158141f61eSdrh 
10168141f61eSdrh   /*
10178141f61eSdrh   ** cnt==0 means there was not match.  cnt>1 means there were two or
10188141f61eSdrh   ** more matches.  Either way, we have an error.
10198141f61eSdrh   */
10208141f61eSdrh   if( cnt!=1 ){
10218141f61eSdrh     char *z = 0;
10228141f61eSdrh     char *zErr;
10238141f61eSdrh     zErr = cnt==0 ? "no such column: %s" : "ambiguous column name: %s";
10248141f61eSdrh     if( zDb ){
1025f93339deSdrh       sqlite3SetString(&z, zDb, ".", zTab, ".", zCol, (char*)0);
10268141f61eSdrh     }else if( zTab ){
1027f93339deSdrh       sqlite3SetString(&z, zTab, ".", zCol, (char*)0);
10288141f61eSdrh     }else{
10298141f61eSdrh       z = sqliteStrDup(zCol);
10308141f61eSdrh     }
10314adee20fSdanielk1977     sqlite3ErrorMsg(pParse, zErr, z);
10328141f61eSdrh     sqliteFree(z);
103373b211abSdrh     pTopNC->nErr++;
10348141f61eSdrh   }
10358141f61eSdrh 
103651669863Sdrh   /* If a column from a table in pSrcList is referenced, then record
103751669863Sdrh   ** this fact in the pSrcList.a[].colUsed bitmask.  Column 0 causes
103851669863Sdrh   ** bit 0 to be set.  Column 1 sets bit 1.  And so forth.  If the
103951669863Sdrh   ** column number is greater than the number of bits in the bitmask
104051669863Sdrh   ** then set the high-order bit of the bitmask.
104151669863Sdrh   */
104251669863Sdrh   if( pExpr->iColumn>=0 && pMatch!=0 ){
104351669863Sdrh     int n = pExpr->iColumn;
104451669863Sdrh     if( n>=sizeof(Bitmask)*8 ){
104551669863Sdrh       n = sizeof(Bitmask)*8-1;
104651669863Sdrh     }
104751669863Sdrh     assert( pMatch->iCursor==pExpr->iTable );
104851669863Sdrh     pMatch->colUsed |= 1<<n;
104951669863Sdrh   }
105051669863Sdrh 
1051d5d56523Sdanielk1977 lookupname_end:
10528141f61eSdrh   /* Clean up and return
10538141f61eSdrh   */
10548141f61eSdrh   sqliteFree(zDb);
10558141f61eSdrh   sqliteFree(zTab);
10564adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pLeft);
10578141f61eSdrh   pExpr->pLeft = 0;
10584adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pRight);
10598141f61eSdrh   pExpr->pRight = 0;
10608141f61eSdrh   pExpr->op = TK_COLUMN;
106115ccce1cSdrh lookupname_end_2:
106215ccce1cSdrh   sqliteFree(zCol);
1063626a879aSdrh   if( cnt==1 ){
1064b3bce662Sdanielk1977     assert( pNC!=0 );
1065626a879aSdrh     sqlite3AuthRead(pParse, pExpr, pNC->pSrcList);
1066aee18ef8Sdanielk1977     if( pMatch && !pMatch->pSelect ){
1067aee18ef8Sdanielk1977       pExpr->pTab = pMatch->pTab;
1068aee18ef8Sdanielk1977     }
106915ccce1cSdrh     /* Increment the nRef value on all name contexts from TopNC up to
107015ccce1cSdrh     ** the point where the name matched. */
107115ccce1cSdrh     for(;;){
107215ccce1cSdrh       assert( pTopNC!=0 );
107315ccce1cSdrh       pTopNC->nRef++;
107415ccce1cSdrh       if( pTopNC==pNC ) break;
107515ccce1cSdrh       pTopNC = pTopNC->pNext;
1076626a879aSdrh     }
107715ccce1cSdrh     return 0;
107815ccce1cSdrh   } else {
107915ccce1cSdrh     return 1;
108015ccce1cSdrh   }
10818141f61eSdrh }
10828141f61eSdrh 
10838141f61eSdrh /*
1084626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
1085626a879aSdrh **
108673b211abSdrh ** Resolve symbolic names into TK_COLUMN operators for the current
1087626a879aSdrh ** node in the expression tree.  Return 0 to continue the search down
108873b211abSdrh ** the tree or 2 to abort the tree walk.
108973b211abSdrh **
109073b211abSdrh ** This routine also does error checking and name resolution for
109173b211abSdrh ** function names.  The operator for aggregate functions is changed
109273b211abSdrh ** to TK_AGG_FUNCTION.
1093626a879aSdrh */
1094626a879aSdrh static int nameResolverStep(void *pArg, Expr *pExpr){
1095626a879aSdrh   NameContext *pNC = (NameContext*)pArg;
1096626a879aSdrh   Parse *pParse;
1097626a879aSdrh 
1098b3bce662Sdanielk1977   if( pExpr==0 ) return 1;
1099626a879aSdrh   assert( pNC!=0 );
1100626a879aSdrh   pParse = pNC->pParse;
1101b3bce662Sdanielk1977 
1102626a879aSdrh   if( ExprHasAnyProperty(pExpr, EP_Resolved) ) return 1;
1103626a879aSdrh   ExprSetProperty(pExpr, EP_Resolved);
1104626a879aSdrh #ifndef NDEBUG
1105f0113000Sdanielk1977   if( pNC->pSrcList && pNC->pSrcList->nAlloc>0 ){
1106f0113000Sdanielk1977     SrcList *pSrcList = pNC->pSrcList;
1107940fac9dSdanielk1977     int i;
1108f0113000Sdanielk1977     for(i=0; i<pNC->pSrcList->nSrc; i++){
1109626a879aSdrh       assert( pSrcList->a[i].iCursor>=0 && pSrcList->a[i].iCursor<pParse->nTab);
1110626a879aSdrh     }
1111626a879aSdrh   }
1112626a879aSdrh #endif
1113626a879aSdrh   switch( pExpr->op ){
1114626a879aSdrh     /* Double-quoted strings (ex: "abc") are used as identifiers if
1115626a879aSdrh     ** possible.  Otherwise they remain as strings.  Single-quoted
1116626a879aSdrh     ** strings (ex: 'abc') are always string literals.
1117626a879aSdrh     */
1118626a879aSdrh     case TK_STRING: {
1119626a879aSdrh       if( pExpr->token.z[0]=='\'' ) break;
1120626a879aSdrh       /* Fall thru into the TK_ID case if this is a double-quoted string */
1121626a879aSdrh     }
1122626a879aSdrh     /* A lone identifier is the name of a column.
1123626a879aSdrh     */
1124626a879aSdrh     case TK_ID: {
1125626a879aSdrh       lookupName(pParse, 0, 0, &pExpr->token, pNC, pExpr);
1126626a879aSdrh       return 1;
1127626a879aSdrh     }
1128626a879aSdrh 
1129626a879aSdrh     /* A table name and column name:     ID.ID
1130626a879aSdrh     ** Or a database, table and column:  ID.ID.ID
1131626a879aSdrh     */
1132626a879aSdrh     case TK_DOT: {
1133626a879aSdrh       Token *pColumn;
1134626a879aSdrh       Token *pTable;
1135626a879aSdrh       Token *pDb;
1136626a879aSdrh       Expr *pRight;
1137626a879aSdrh 
1138b3bce662Sdanielk1977       /* if( pSrcList==0 ) break; */
1139626a879aSdrh       pRight = pExpr->pRight;
1140626a879aSdrh       if( pRight->op==TK_ID ){
1141626a879aSdrh         pDb = 0;
1142626a879aSdrh         pTable = &pExpr->pLeft->token;
1143626a879aSdrh         pColumn = &pRight->token;
1144626a879aSdrh       }else{
1145626a879aSdrh         assert( pRight->op==TK_DOT );
1146626a879aSdrh         pDb = &pExpr->pLeft->token;
1147626a879aSdrh         pTable = &pRight->pLeft->token;
1148626a879aSdrh         pColumn = &pRight->pRight->token;
1149626a879aSdrh       }
1150626a879aSdrh       lookupName(pParse, pDb, pTable, pColumn, pNC, pExpr);
1151626a879aSdrh       return 1;
1152626a879aSdrh     }
1153626a879aSdrh 
1154626a879aSdrh     /* Resolve function names
1155626a879aSdrh     */
1156b71090fdSdrh     case TK_CONST_FUNC:
1157626a879aSdrh     case TK_FUNCTION: {
1158626a879aSdrh       ExprList *pList = pExpr->pList;    /* The argument list */
1159626a879aSdrh       int n = pList ? pList->nExpr : 0;  /* Number of arguments */
1160626a879aSdrh       int no_such_func = 0;       /* True if no such function exists */
1161626a879aSdrh       int wrong_num_args = 0;     /* True if wrong number of arguments */
1162626a879aSdrh       int is_agg = 0;             /* True if is an aggregate function */
1163626a879aSdrh       int i;
11645169bbc6Sdrh       int auth;                   /* Authorization to use the function */
1165626a879aSdrh       int nId;                    /* Number of characters in function name */
1166626a879aSdrh       const char *zId;            /* The function name. */
116773b211abSdrh       FuncDef *pDef;              /* Information about the function */
116814db2665Sdanielk1977       int enc = ENC(pParse->db);  /* The database encoding */
1169626a879aSdrh 
11702646da7eSdrh       zId = (char*)pExpr->token.z;
1171b71090fdSdrh       nId = pExpr->token.n;
1172626a879aSdrh       pDef = sqlite3FindFunction(pParse->db, zId, nId, n, enc, 0);
1173626a879aSdrh       if( pDef==0 ){
1174626a879aSdrh         pDef = sqlite3FindFunction(pParse->db, zId, nId, -1, enc, 0);
1175626a879aSdrh         if( pDef==0 ){
1176626a879aSdrh           no_such_func = 1;
1177626a879aSdrh         }else{
1178626a879aSdrh           wrong_num_args = 1;
1179626a879aSdrh         }
1180626a879aSdrh       }else{
1181626a879aSdrh         is_agg = pDef->xFunc==0;
1182626a879aSdrh       }
1183*2fca7fefSdrh #ifndef SQLITE_OMIT_AUTHORIZATION
11845169bbc6Sdrh       if( pDef ){
11855169bbc6Sdrh         auth = sqlite3AuthCheck(pParse, SQLITE_FUNCTION, 0, pDef->zName, 0);
11865169bbc6Sdrh         if( auth!=SQLITE_OK ){
11875169bbc6Sdrh           if( auth==SQLITE_DENY ){
11885169bbc6Sdrh             sqlite3ErrorMsg(pParse, "not authorized to use function: %s",
11895169bbc6Sdrh                                     pDef->zName);
11905169bbc6Sdrh             pNC->nErr++;
11915169bbc6Sdrh           }
11925169bbc6Sdrh           pExpr->op = TK_NULL;
11935169bbc6Sdrh           return 1;
11945169bbc6Sdrh         }
11955169bbc6Sdrh       }
1196b8b14219Sdrh #endif
1197626a879aSdrh       if( is_agg && !pNC->allowAgg ){
1198626a879aSdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate function %.*s()", nId,zId);
1199626a879aSdrh         pNC->nErr++;
1200626a879aSdrh         is_agg = 0;
1201626a879aSdrh       }else if( no_such_func ){
1202626a879aSdrh         sqlite3ErrorMsg(pParse, "no such function: %.*s", nId, zId);
1203626a879aSdrh         pNC->nErr++;
1204626a879aSdrh       }else if( wrong_num_args ){
1205626a879aSdrh         sqlite3ErrorMsg(pParse,"wrong number of arguments to function %.*s()",
1206626a879aSdrh              nId, zId);
1207626a879aSdrh         pNC->nErr++;
1208626a879aSdrh       }
1209626a879aSdrh       if( is_agg ){
1210626a879aSdrh         pExpr->op = TK_AGG_FUNCTION;
1211626a879aSdrh         pNC->hasAgg = 1;
1212626a879aSdrh       }
121373b211abSdrh       if( is_agg ) pNC->allowAgg = 0;
1214626a879aSdrh       for(i=0; pNC->nErr==0 && i<n; i++){
121573b211abSdrh         walkExprTree(pList->a[i].pExpr, nameResolverStep, pNC);
1216626a879aSdrh       }
121773b211abSdrh       if( is_agg ) pNC->allowAgg = 1;
1218626a879aSdrh       /* FIX ME:  Compute pExpr->affinity based on the expected return
1219626a879aSdrh       ** type of the function
1220626a879aSdrh       */
1221626a879aSdrh       return is_agg;
1222626a879aSdrh     }
1223b3bce662Sdanielk1977 #ifndef SQLITE_OMIT_SUBQUERY
1224b3bce662Sdanielk1977     case TK_SELECT:
1225b3bce662Sdanielk1977     case TK_EXISTS:
1226b3bce662Sdanielk1977 #endif
1227b3bce662Sdanielk1977     case TK_IN: {
1228b3bce662Sdanielk1977       if( pExpr->pSelect ){
12298a9f38feSdrh         int nRef = pNC->nRef;
123006f6541eSdrh #ifndef SQLITE_OMIT_CHECK
123106f6541eSdrh         if( pNC->isCheck ){
123206f6541eSdrh           sqlite3ErrorMsg(pParse,"subqueries prohibited in CHECK constraints");
123306f6541eSdrh         }
123406f6541eSdrh #endif
1235b3bce662Sdanielk1977         sqlite3SelectResolve(pParse, pExpr->pSelect, pNC);
1236b3bce662Sdanielk1977         assert( pNC->nRef>=nRef );
1237b3bce662Sdanielk1977         if( nRef!=pNC->nRef ){
1238b3bce662Sdanielk1977           ExprSetProperty(pExpr, EP_VarSelect);
1239b3bce662Sdanielk1977         }
1240b3bce662Sdanielk1977       }
12414284fb07Sdrh       break;
1242b3bce662Sdanielk1977     }
12434284fb07Sdrh #ifndef SQLITE_OMIT_CHECK
12444284fb07Sdrh     case TK_VARIABLE: {
12454284fb07Sdrh       if( pNC->isCheck ){
12464284fb07Sdrh         sqlite3ErrorMsg(pParse,"parameters prohibited in CHECK constraints");
12474284fb07Sdrh       }
12484284fb07Sdrh       break;
12494284fb07Sdrh     }
12504284fb07Sdrh #endif
1251626a879aSdrh   }
1252626a879aSdrh   return 0;
1253626a879aSdrh }
1254626a879aSdrh 
1255626a879aSdrh /*
1256cce7d176Sdrh ** This routine walks an expression tree and resolves references to
1257967e8b73Sdrh ** table columns.  Nodes of the form ID.ID or ID resolve into an
1258aacc543eSdrh ** index to the table in the table list and a column offset.  The
1259aacc543eSdrh ** Expr.opcode for such nodes is changed to TK_COLUMN.  The Expr.iTable
1260aacc543eSdrh ** value is changed to the index of the referenced table in pTabList
1261832508b7Sdrh ** plus the "base" value.  The base value will ultimately become the
1262aacc543eSdrh ** VDBE cursor number for a cursor that is pointing into the referenced
1263aacc543eSdrh ** table.  The Expr.iColumn value is changed to the index of the column
1264aacc543eSdrh ** of the referenced table.  The Expr.iColumn value for the special
1265aacc543eSdrh ** ROWID column is -1.  Any INTEGER PRIMARY KEY column is tried as an
1266aacc543eSdrh ** alias for ROWID.
126719a775c2Sdrh **
1268626a879aSdrh ** Also resolve function names and check the functions for proper
1269626a879aSdrh ** usage.  Make sure all function names are recognized and all functions
1270626a879aSdrh ** have the correct number of arguments.  Leave an error message
1271626a879aSdrh ** in pParse->zErrMsg if anything is amiss.  Return the number of errors.
1272626a879aSdrh **
127373b211abSdrh ** If the expression contains aggregate functions then set the EP_Agg
127473b211abSdrh ** property on the expression.
1275626a879aSdrh */
1276626a879aSdrh int sqlite3ExprResolveNames(
1277b3bce662Sdanielk1977   NameContext *pNC,       /* Namespace to resolve expressions in. */
1278b3bce662Sdanielk1977   Expr *pExpr             /* The expression to be analyzed. */
1279626a879aSdrh ){
128013449892Sdrh   int savedHasAgg;
128173b211abSdrh   if( pExpr==0 ) return 0;
128213449892Sdrh   savedHasAgg = pNC->hasAgg;
128313449892Sdrh   pNC->hasAgg = 0;
1284b3bce662Sdanielk1977   walkExprTree(pExpr, nameResolverStep, pNC);
1285b3bce662Sdanielk1977   if( pNC->nErr>0 ){
128673b211abSdrh     ExprSetProperty(pExpr, EP_Error);
128773b211abSdrh   }
128813449892Sdrh   if( pNC->hasAgg ){
128913449892Sdrh     ExprSetProperty(pExpr, EP_Agg);
129013449892Sdrh   }else if( savedHasAgg ){
129113449892Sdrh     pNC->hasAgg = 1;
129213449892Sdrh   }
129373b211abSdrh   return ExprHasProperty(pExpr, EP_Error);
1294626a879aSdrh }
1295626a879aSdrh 
12961398ad36Sdrh /*
12971398ad36Sdrh ** A pointer instance of this structure is used to pass information
12981398ad36Sdrh ** through walkExprTree into codeSubqueryStep().
12991398ad36Sdrh */
13001398ad36Sdrh typedef struct QueryCoder QueryCoder;
13011398ad36Sdrh struct QueryCoder {
13021398ad36Sdrh   Parse *pParse;       /* The parsing context */
13031398ad36Sdrh   NameContext *pNC;    /* Namespace of first enclosing query */
13041398ad36Sdrh };
13051398ad36Sdrh 
1306626a879aSdrh 
1307626a879aSdrh /*
13089cbe6352Sdrh ** Generate code for scalar subqueries used as an expression
13099cbe6352Sdrh ** and IN operators.  Examples:
1310626a879aSdrh **
13119cbe6352Sdrh **     (SELECT a FROM b)          -- subquery
13129cbe6352Sdrh **     EXISTS (SELECT a FROM b)   -- EXISTS subquery
13139cbe6352Sdrh **     x IN (4,5,11)              -- IN operator with list on right-hand side
13149cbe6352Sdrh **     x IN (SELECT a FROM b)     -- IN operator with subquery on the right
1315fef5208cSdrh **
13169cbe6352Sdrh ** The pExpr parameter describes the expression that contains the IN
13179cbe6352Sdrh ** operator or subquery.
1318cce7d176Sdrh */
131951522cd3Sdrh #ifndef SQLITE_OMIT_SUBQUERY
1320b3bce662Sdanielk1977 void sqlite3CodeSubselect(Parse *pParse, Expr *pExpr){
132157dbd7b3Sdrh   int testAddr = 0;                       /* One-time test address */
1322b3bce662Sdanielk1977   Vdbe *v = sqlite3GetVdbe(pParse);
1323b3bce662Sdanielk1977   if( v==0 ) return;
1324b3bce662Sdanielk1977 
132557dbd7b3Sdrh   /* This code must be run in its entirety every time it is encountered
132657dbd7b3Sdrh   ** if any of the following is true:
132757dbd7b3Sdrh   **
132857dbd7b3Sdrh   **    *  The right-hand side is a correlated subquery
132957dbd7b3Sdrh   **    *  The right-hand side is an expression list containing variables
133057dbd7b3Sdrh   **    *  We are inside a trigger
133157dbd7b3Sdrh   **
133257dbd7b3Sdrh   ** If all of the above are false, then we can run this code just once
133357dbd7b3Sdrh   ** save the results, and reuse the same result on subsequent invocations.
1334b3bce662Sdanielk1977   */
1335b3bce662Sdanielk1977   if( !ExprHasAnyProperty(pExpr, EP_VarSelect) && !pParse->trigStack ){
1336b3bce662Sdanielk1977     int mem = pParse->nMem++;
1337b3bce662Sdanielk1977     sqlite3VdbeAddOp(v, OP_MemLoad, mem, 0);
133857dbd7b3Sdrh     testAddr = sqlite3VdbeAddOp(v, OP_If, 0, 0);
13399e12800dSdanielk1977     assert( testAddr>0 || sqlite3MallocFailed() );
1340d654be80Sdrh     sqlite3VdbeAddOp(v, OP_MemInt, 1, mem);
1341b3bce662Sdanielk1977   }
1342b3bce662Sdanielk1977 
1343cce7d176Sdrh   switch( pExpr->op ){
1344fef5208cSdrh     case TK_IN: {
1345e014a838Sdanielk1977       char affinity;
1346d3d39e93Sdrh       KeyInfo keyInfo;
1347b9bb7c18Sdrh       int addr;        /* Address of OP_OpenEphemeral instruction */
1348d3d39e93Sdrh 
1349bf3b721fSdanielk1977       affinity = sqlite3ExprAffinity(pExpr->pLeft);
1350e014a838Sdanielk1977 
1351e014a838Sdanielk1977       /* Whether this is an 'x IN(SELECT...)' or an 'x IN(<exprlist>)'
135257dbd7b3Sdrh       ** expression it is handled the same way. A virtual table is
1353e014a838Sdanielk1977       ** filled with single-field index keys representing the results
1354e014a838Sdanielk1977       ** from the SELECT or the <exprlist>.
1355fef5208cSdrh       **
1356e014a838Sdanielk1977       ** If the 'x' expression is a column value, or the SELECT...
1357e014a838Sdanielk1977       ** statement returns a column value, then the affinity of that
1358e014a838Sdanielk1977       ** column is used to build the index keys. If both 'x' and the
1359e014a838Sdanielk1977       ** SELECT... statement are columns, then numeric affinity is used
1360e014a838Sdanielk1977       ** if either column has NUMERIC or INTEGER affinity. If neither
1361e014a838Sdanielk1977       ** 'x' nor the SELECT... statement are columns, then numeric affinity
1362e014a838Sdanielk1977       ** is used.
1363fef5208cSdrh       */
1364832508b7Sdrh       pExpr->iTable = pParse->nTab++;
1365b9bb7c18Sdrh       addr = sqlite3VdbeAddOp(v, OP_OpenEphemeral, pExpr->iTable, 0);
1366d3d39e93Sdrh       memset(&keyInfo, 0, sizeof(keyInfo));
1367d3d39e93Sdrh       keyInfo.nField = 1;
1368f3218feaSdrh       sqlite3VdbeAddOp(v, OP_SetNumColumns, pExpr->iTable, 1);
1369e014a838Sdanielk1977 
1370e014a838Sdanielk1977       if( pExpr->pSelect ){
1371e014a838Sdanielk1977         /* Case 1:     expr IN (SELECT ...)
1372e014a838Sdanielk1977         **
1373e014a838Sdanielk1977         ** Generate code to write the results of the select into the temporary
1374e014a838Sdanielk1977         ** table allocated and opened above.
1375e014a838Sdanielk1977         */
1376e014a838Sdanielk1977         int iParm = pExpr->iTable +  (((int)affinity)<<16);
1377be5c89acSdrh         ExprList *pEList;
1378e014a838Sdanielk1977         assert( (pExpr->iTable&0x0000FFFF)==pExpr->iTable );
1379b3bce662Sdanielk1977         sqlite3Select(pParse, pExpr->pSelect, SRT_Set, iParm, 0, 0, 0, 0);
1380be5c89acSdrh         pEList = pExpr->pSelect->pEList;
1381be5c89acSdrh         if( pEList && pEList->nExpr>0 ){
13827cedc8d4Sdanielk1977           keyInfo.aColl[0] = binaryCompareCollSeq(pParse, pExpr->pLeft,
1383be5c89acSdrh               pEList->a[0].pExpr);
13840202b29eSdanielk1977         }
1385fef5208cSdrh       }else if( pExpr->pList ){
1386fef5208cSdrh         /* Case 2:     expr IN (exprlist)
1387fef5208cSdrh         **
1388e014a838Sdanielk1977 	** For each expression, build an index key from the evaluation and
1389e014a838Sdanielk1977         ** store it in the temporary table. If <expr> is a column, then use
1390e014a838Sdanielk1977         ** that columns affinity when building index keys. If <expr> is not
1391e014a838Sdanielk1977         ** a column, use numeric affinity.
1392fef5208cSdrh         */
1393e014a838Sdanielk1977         int i;
139457dbd7b3Sdrh         ExprList *pList = pExpr->pList;
139557dbd7b3Sdrh         struct ExprList_item *pItem;
139657dbd7b3Sdrh 
1397e014a838Sdanielk1977         if( !affinity ){
13988159a35fSdrh           affinity = SQLITE_AFF_NONE;
1399e014a838Sdanielk1977         }
14000202b29eSdanielk1977         keyInfo.aColl[0] = pExpr->pLeft->pColl;
1401e014a838Sdanielk1977 
1402e014a838Sdanielk1977         /* Loop through each expression in <exprlist>. */
140357dbd7b3Sdrh         for(i=pList->nExpr, pItem=pList->a; i>0; i--, pItem++){
140457dbd7b3Sdrh           Expr *pE2 = pItem->pExpr;
1405e014a838Sdanielk1977 
140657dbd7b3Sdrh           /* If the expression is not constant then we will need to
140757dbd7b3Sdrh           ** disable the test that was generated above that makes sure
140857dbd7b3Sdrh           ** this code only executes once.  Because for a non-constant
140957dbd7b3Sdrh           ** expression we need to rerun this code each time.
141057dbd7b3Sdrh           */
14116c30be8eSdrh           if( testAddr>0 && !sqlite3ExprIsConstant(pE2) ){
1412f8875400Sdrh             sqlite3VdbeChangeToNoop(v, testAddr-1, 3);
141357dbd7b3Sdrh             testAddr = 0;
14144794b980Sdrh           }
1415e014a838Sdanielk1977 
1416e014a838Sdanielk1977           /* Evaluate the expression and insert it into the temp table */
14174adee20fSdanielk1977           sqlite3ExprCode(pParse, pE2);
141894a11211Sdrh           sqlite3VdbeOp3(v, OP_MakeRecord, 1, 0, &affinity, 1);
1419f0863fe5Sdrh           sqlite3VdbeAddOp(v, OP_IdxInsert, pExpr->iTable, 0);
1420fef5208cSdrh         }
1421fef5208cSdrh       }
14220202b29eSdanielk1977       sqlite3VdbeChangeP3(v, addr, (void *)&keyInfo, P3_KEYINFO);
1423b3bce662Sdanielk1977       break;
1424fef5208cSdrh     }
1425fef5208cSdrh 
142651522cd3Sdrh     case TK_EXISTS:
142719a775c2Sdrh     case TK_SELECT: {
1428fef5208cSdrh       /* This has to be a scalar SELECT.  Generate code to put the
1429fef5208cSdrh       ** value of this select in a memory cell and record the number
1430967e8b73Sdrh       ** of the memory cell in iColumn.
1431fef5208cSdrh       */
14322646da7eSdrh       static const Token one = { (u8*)"1", 0, 1 };
143351522cd3Sdrh       Select *pSel;
1434ec7429aeSdrh       int iMem;
1435ec7429aeSdrh       int sop;
14361398ad36Sdrh 
1437ec7429aeSdrh       pExpr->iColumn = iMem = pParse->nMem++;
143851522cd3Sdrh       pSel = pExpr->pSelect;
143951522cd3Sdrh       if( pExpr->op==TK_SELECT ){
144051522cd3Sdrh         sop = SRT_Mem;
1441ec7429aeSdrh         sqlite3VdbeAddOp(v, OP_MemNull, iMem, 0);
1442ec7429aeSdrh         VdbeComment((v, "# Init subquery result"));
144351522cd3Sdrh       }else{
144451522cd3Sdrh         sop = SRT_Exists;
1445ec7429aeSdrh         sqlite3VdbeAddOp(v, OP_MemInt, 0, iMem);
1446ec7429aeSdrh         VdbeComment((v, "# Init EXISTS result"));
144751522cd3Sdrh       }
1448ec7429aeSdrh       sqlite3ExprDelete(pSel->pLimit);
1449ec7429aeSdrh       pSel->pLimit = sqlite3Expr(TK_INTEGER, 0, 0, &one);
1450ec7429aeSdrh       sqlite3Select(pParse, pSel, sop, iMem, 0, 0, 0, 0);
1451b3bce662Sdanielk1977       break;
145219a775c2Sdrh     }
1453cce7d176Sdrh   }
1454b3bce662Sdanielk1977 
145557dbd7b3Sdrh   if( testAddr ){
1456d654be80Sdrh     sqlite3VdbeJumpHere(v, testAddr);
1457b3bce662Sdanielk1977   }
1458b3bce662Sdanielk1977   return;
1459cce7d176Sdrh }
146051522cd3Sdrh #endif /* SQLITE_OMIT_SUBQUERY */
1461cce7d176Sdrh 
1462cce7d176Sdrh /*
1463fec19aadSdrh ** Generate an instruction that will put the integer describe by
1464fec19aadSdrh ** text z[0..n-1] on the stack.
1465fec19aadSdrh */
1466fec19aadSdrh static void codeInteger(Vdbe *v, const char *z, int n){
1467fec19aadSdrh   int i;
14686fec0762Sdrh   if( sqlite3GetInt32(z, &i) ){
14696fec0762Sdrh     sqlite3VdbeAddOp(v, OP_Integer, i, 0);
14706fec0762Sdrh   }else if( sqlite3FitsIn64Bits(z) ){
147129dda4aeSdrh     sqlite3VdbeOp3(v, OP_Int64, 0, 0, z, n);
1472fec19aadSdrh   }else{
1473fec19aadSdrh     sqlite3VdbeOp3(v, OP_Real, 0, 0, z, n);
1474fec19aadSdrh   }
1475fec19aadSdrh }
1476fec19aadSdrh 
1477fec19aadSdrh /*
1478cce7d176Sdrh ** Generate code into the current Vdbe to evaluate the given
14791ccde15dSdrh ** expression and leave the result on the top of stack.
1480f2bc013cSdrh **
1481f2bc013cSdrh ** This code depends on the fact that certain token values (ex: TK_EQ)
1482f2bc013cSdrh ** are the same as opcode values (ex: OP_Eq) that implement the corresponding
1483f2bc013cSdrh ** operation.  Special comments in vdbe.c and the mkopcodeh.awk script in
1484f2bc013cSdrh ** the make process cause these values to align.  Assert()s in the code
1485f2bc013cSdrh ** below verify that the numbers are aligned correctly.
1486cce7d176Sdrh */
14874adee20fSdanielk1977 void sqlite3ExprCode(Parse *pParse, Expr *pExpr){
1488cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
1489cce7d176Sdrh   int op;
1490ffe07b2dSdrh   int stackChng = 1;    /* Amount of change to stack depth */
1491ffe07b2dSdrh 
14927977a17fSdanielk1977   if( v==0 ) return;
14937977a17fSdanielk1977   if( pExpr==0 ){
1494f0863fe5Sdrh     sqlite3VdbeAddOp(v, OP_Null, 0, 0);
14957977a17fSdanielk1977     return;
14967977a17fSdanielk1977   }
1497f2bc013cSdrh   op = pExpr->op;
1498f2bc013cSdrh   switch( op ){
149913449892Sdrh     case TK_AGG_COLUMN: {
150013449892Sdrh       AggInfo *pAggInfo = pExpr->pAggInfo;
150113449892Sdrh       struct AggInfo_col *pCol = &pAggInfo->aCol[pExpr->iAgg];
150213449892Sdrh       if( !pAggInfo->directMode ){
150313449892Sdrh         sqlite3VdbeAddOp(v, OP_MemLoad, pCol->iMem, 0);
150413449892Sdrh         break;
150513449892Sdrh       }else if( pAggInfo->useSortingIdx ){
150613449892Sdrh         sqlite3VdbeAddOp(v, OP_Column, pAggInfo->sortingIdx,
150713449892Sdrh                               pCol->iSorterColumn);
150813449892Sdrh         break;
150913449892Sdrh       }
151013449892Sdrh       /* Otherwise, fall thru into the TK_COLUMN case */
151113449892Sdrh     }
1512967e8b73Sdrh     case TK_COLUMN: {
1513ffe07b2dSdrh       if( pExpr->iTable<0 ){
1514ffe07b2dSdrh         /* This only happens when coding check constraints */
1515ffe07b2dSdrh         assert( pParse->ckOffset>0 );
1516ffe07b2dSdrh         sqlite3VdbeAddOp(v, OP_Dup, pParse->ckOffset-pExpr->iColumn-1, 1);
1517ffe07b2dSdrh       }else if( pExpr->iColumn>=0 ){
15188a51256cSdrh         Table *pTab = pExpr->pTab;
15198a51256cSdrh         int iCol = pExpr->iColumn;
15204cbdda9eSdrh         int op = (pTab && IsVirtual(pTab)) ? OP_VColumn : OP_Column;
15217dabaa12Sdanielk1977         sqlite3VdbeAddOp(v, op, pExpr->iTable, iCol);
15228a51256cSdrh         sqlite3ColumnDefault(v, pTab, iCol);
15238a51256cSdrh #ifndef SQLITE_OMIT_FLOATING_POINT
15248a51256cSdrh         if( pTab && pTab->aCol[iCol].affinity==SQLITE_AFF_REAL ){
15258a51256cSdrh           sqlite3VdbeAddOp(v, OP_RealAffinity, 0, 0);
15268a51256cSdrh         }
15278a51256cSdrh #endif
1528c4a3c779Sdrh       }else{
15297dabaa12Sdanielk1977         Table *pTab = pExpr->pTab;
15304cbdda9eSdrh         int op = (pTab && IsVirtual(pTab)) ? OP_VRowid : OP_Rowid;
15317dabaa12Sdanielk1977         sqlite3VdbeAddOp(v, op, pExpr->iTable, 0);
15322282792aSdrh       }
1533cce7d176Sdrh       break;
1534cce7d176Sdrh     }
1535cce7d176Sdrh     case TK_INTEGER: {
15362646da7eSdrh       codeInteger(v, (char*)pExpr->token.z, pExpr->token.n);
1537fec19aadSdrh       break;
153851e9a445Sdrh     }
1539fec19aadSdrh     case TK_FLOAT:
1540fec19aadSdrh     case TK_STRING: {
1541f2bc013cSdrh       assert( TK_FLOAT==OP_Real );
1542f2bc013cSdrh       assert( TK_STRING==OP_String8 );
1543d2687b77Sdrh       sqlite3DequoteExpr(pExpr);
15442646da7eSdrh       sqlite3VdbeOp3(v, op, 0, 0, (char*)pExpr->token.z, pExpr->token.n);
1545cce7d176Sdrh       break;
1546cce7d176Sdrh     }
1547f0863fe5Sdrh     case TK_NULL: {
1548f0863fe5Sdrh       sqlite3VdbeAddOp(v, OP_Null, 0, 0);
1549f0863fe5Sdrh       break;
1550f0863fe5Sdrh     }
15515338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_BLOB_LITERAL
1552c572ef7fSdanielk1977     case TK_BLOB: {
15536c8c6cecSdrh       int n;
15546c8c6cecSdrh       const char *z;
1555f2bc013cSdrh       assert( TK_BLOB==OP_HexBlob );
15566c8c6cecSdrh       n = pExpr->token.n - 3;
15572646da7eSdrh       z = (char*)pExpr->token.z + 2;
15586c8c6cecSdrh       assert( n>=0 );
15596c8c6cecSdrh       if( n==0 ){
15606c8c6cecSdrh         z = "";
15616c8c6cecSdrh       }
15626c8c6cecSdrh       sqlite3VdbeOp3(v, op, 0, 0, z, n);
1563c572ef7fSdanielk1977       break;
1564c572ef7fSdanielk1977     }
15655338a5f7Sdanielk1977 #endif
156650457896Sdrh     case TK_VARIABLE: {
15674adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Variable, pExpr->iTable, 0);
1568895d7472Sdrh       if( pExpr->token.n>1 ){
15692646da7eSdrh         sqlite3VdbeChangeP3(v, -1, (char*)pExpr->token.z, pExpr->token.n);
1570895d7472Sdrh       }
157150457896Sdrh       break;
157250457896Sdrh     }
15734e0cff60Sdrh     case TK_REGISTER: {
15744e0cff60Sdrh       sqlite3VdbeAddOp(v, OP_MemLoad, pExpr->iTable, 0);
15754e0cff60Sdrh       break;
15764e0cff60Sdrh     }
1577487e262fSdrh #ifndef SQLITE_OMIT_CAST
1578487e262fSdrh     case TK_CAST: {
1579487e262fSdrh       /* Expressions of the form:   CAST(pLeft AS token) */
1580f0113000Sdanielk1977       int aff, to_op;
1581487e262fSdrh       sqlite3ExprCode(pParse, pExpr->pLeft);
15828a51256cSdrh       aff = sqlite3AffinityType(&pExpr->token);
1583f0113000Sdanielk1977       to_op = aff - SQLITE_AFF_TEXT + OP_ToText;
1584f0113000Sdanielk1977       assert( to_op==OP_ToText    || aff!=SQLITE_AFF_TEXT    );
1585f0113000Sdanielk1977       assert( to_op==OP_ToBlob    || aff!=SQLITE_AFF_NONE    );
1586f0113000Sdanielk1977       assert( to_op==OP_ToNumeric || aff!=SQLITE_AFF_NUMERIC );
1587f0113000Sdanielk1977       assert( to_op==OP_ToInt     || aff!=SQLITE_AFF_INTEGER );
1588f0113000Sdanielk1977       assert( to_op==OP_ToReal    || aff!=SQLITE_AFF_REAL    );
1589f0113000Sdanielk1977       sqlite3VdbeAddOp(v, to_op, 0, 0);
1590ffe07b2dSdrh       stackChng = 0;
1591487e262fSdrh       break;
1592487e262fSdrh     }
1593487e262fSdrh #endif /* SQLITE_OMIT_CAST */
1594c9b84a1fSdrh     case TK_LT:
1595c9b84a1fSdrh     case TK_LE:
1596c9b84a1fSdrh     case TK_GT:
1597c9b84a1fSdrh     case TK_GE:
1598c9b84a1fSdrh     case TK_NE:
1599c9b84a1fSdrh     case TK_EQ: {
1600f2bc013cSdrh       assert( TK_LT==OP_Lt );
1601f2bc013cSdrh       assert( TK_LE==OP_Le );
1602f2bc013cSdrh       assert( TK_GT==OP_Gt );
1603f2bc013cSdrh       assert( TK_GE==OP_Ge );
1604f2bc013cSdrh       assert( TK_EQ==OP_Eq );
1605f2bc013cSdrh       assert( TK_NE==OP_Ne );
1606a37cdde0Sdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
1607a37cdde0Sdanielk1977       sqlite3ExprCode(pParse, pExpr->pRight);
1608be5c89acSdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op, 0, 0);
1609ffe07b2dSdrh       stackChng = -1;
1610a37cdde0Sdanielk1977       break;
1611c9b84a1fSdrh     }
1612cce7d176Sdrh     case TK_AND:
1613cce7d176Sdrh     case TK_OR:
1614cce7d176Sdrh     case TK_PLUS:
1615cce7d176Sdrh     case TK_STAR:
1616cce7d176Sdrh     case TK_MINUS:
1617bf4133cbSdrh     case TK_REM:
1618bf4133cbSdrh     case TK_BITAND:
1619bf4133cbSdrh     case TK_BITOR:
162017c40294Sdrh     case TK_SLASH:
1621bf4133cbSdrh     case TK_LSHIFT:
1622855eb1cfSdrh     case TK_RSHIFT:
16230040077dSdrh     case TK_CONCAT: {
1624f2bc013cSdrh       assert( TK_AND==OP_And );
1625f2bc013cSdrh       assert( TK_OR==OP_Or );
1626f2bc013cSdrh       assert( TK_PLUS==OP_Add );
1627f2bc013cSdrh       assert( TK_MINUS==OP_Subtract );
1628f2bc013cSdrh       assert( TK_REM==OP_Remainder );
1629f2bc013cSdrh       assert( TK_BITAND==OP_BitAnd );
1630f2bc013cSdrh       assert( TK_BITOR==OP_BitOr );
1631f2bc013cSdrh       assert( TK_SLASH==OP_Divide );
1632f2bc013cSdrh       assert( TK_LSHIFT==OP_ShiftLeft );
1633f2bc013cSdrh       assert( TK_RSHIFT==OP_ShiftRight );
1634f2bc013cSdrh       assert( TK_CONCAT==OP_Concat );
16354adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
16364adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pRight);
1637855eb1cfSdrh       sqlite3VdbeAddOp(v, op, 0, 0);
1638ffe07b2dSdrh       stackChng = -1;
16390040077dSdrh       break;
16400040077dSdrh     }
1641cce7d176Sdrh     case TK_UMINUS: {
1642fec19aadSdrh       Expr *pLeft = pExpr->pLeft;
1643fec19aadSdrh       assert( pLeft );
1644fec19aadSdrh       if( pLeft->op==TK_FLOAT || pLeft->op==TK_INTEGER ){
1645fec19aadSdrh         Token *p = &pLeft->token;
16469267bdceSdrh         char *z = sqlite3MPrintf("-%.*s", p->n, p->z);
1647fec19aadSdrh         if( pLeft->op==TK_FLOAT ){
1648fec19aadSdrh           sqlite3VdbeOp3(v, OP_Real, 0, 0, z, p->n+1);
1649e6840900Sdrh         }else{
1650fec19aadSdrh           codeInteger(v, z, p->n+1);
1651e6840900Sdrh         }
16526e142f54Sdrh         sqliteFree(z);
16536e142f54Sdrh         break;
16546e142f54Sdrh       }
16551ccde15dSdrh       /* Fall through into TK_NOT */
16566e142f54Sdrh     }
1657bf4133cbSdrh     case TK_BITNOT:
16586e142f54Sdrh     case TK_NOT: {
1659f2bc013cSdrh       assert( TK_BITNOT==OP_BitNot );
1660f2bc013cSdrh       assert( TK_NOT==OP_Not );
16614adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
16624adee20fSdanielk1977       sqlite3VdbeAddOp(v, op, 0, 0);
1663ffe07b2dSdrh       stackChng = 0;
1664cce7d176Sdrh       break;
1665cce7d176Sdrh     }
1666cce7d176Sdrh     case TK_ISNULL:
1667cce7d176Sdrh     case TK_NOTNULL: {
1668cce7d176Sdrh       int dest;
1669f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
1670f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
16714adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Integer, 1, 0);
16724adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
16734adee20fSdanielk1977       dest = sqlite3VdbeCurrentAddr(v) + 2;
16744adee20fSdanielk1977       sqlite3VdbeAddOp(v, op, 1, dest);
16754adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_AddImm, -1, 0);
1676ffe07b2dSdrh       stackChng = 0;
1677a37cdde0Sdanielk1977       break;
1678f2bc013cSdrh     }
16792282792aSdrh     case TK_AGG_FUNCTION: {
168013449892Sdrh       AggInfo *pInfo = pExpr->pAggInfo;
16817e56e711Sdrh       if( pInfo==0 ){
16827e56e711Sdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate: %T",
16837e56e711Sdrh             &pExpr->span);
16847e56e711Sdrh       }else{
168513449892Sdrh         sqlite3VdbeAddOp(v, OP_MemLoad, pInfo->aFunc[pExpr->iAgg].iMem, 0);
16867e56e711Sdrh       }
16872282792aSdrh       break;
16882282792aSdrh     }
1689b71090fdSdrh     case TK_CONST_FUNC:
1690cce7d176Sdrh     case TK_FUNCTION: {
1691cce7d176Sdrh       ExprList *pList = pExpr->pList;
169289425d5eSdrh       int nExpr = pList ? pList->nExpr : 0;
16930bce8354Sdrh       FuncDef *pDef;
16944b59ab5eSdrh       int nId;
16954b59ab5eSdrh       const char *zId;
169613449892Sdrh       int constMask = 0;
1697682f68b0Sdanielk1977       int i;
169814db2665Sdanielk1977       u8 enc = ENC(pParse->db);
1699dc1bdc4fSdanielk1977       CollSeq *pColl = 0;
17002646da7eSdrh       zId = (char*)pExpr->token.z;
1701b71090fdSdrh       nId = pExpr->token.n;
1702d8123366Sdanielk1977       pDef = sqlite3FindFunction(pParse->db, zId, nId, nExpr, enc, 0);
17030bce8354Sdrh       assert( pDef!=0 );
1704f9b596ebSdrh       nExpr = sqlite3ExprCodeExprList(pParse, pList);
1705b7f6f68fSdrh #ifndef SQLITE_OMIT_VIRTUALTABLE
1706a43fa227Sdrh       /* Possibly overload the function if the first argument is
1707a43fa227Sdrh       ** a virtual table column.
1708a43fa227Sdrh       **
1709a43fa227Sdrh       ** For infix functions (LIKE, GLOB, REGEXP, and MATCH) use the
1710a43fa227Sdrh       ** second argument, not the first, as the argument to test to
1711a43fa227Sdrh       ** see if it is a column in a virtual table.  This is done because
1712a43fa227Sdrh       ** the left operand of infix functions (the operand we want to
1713a43fa227Sdrh       ** control overloading) ends up as the second argument to the
1714a43fa227Sdrh       ** function.  The expression "A glob B" is equivalent to
1715a43fa227Sdrh       ** "glob(B,A).  We want to use the A in "A glob B" to test
1716a43fa227Sdrh       ** for function overloading.  But we use the B term in "glob(B,A)".
1717a43fa227Sdrh       */
17186a03a1c5Sdrh       if( nExpr>=2 && (pExpr->flags & EP_InfixFunc) ){
17196a03a1c5Sdrh         pDef = sqlite3VtabOverloadFunction(pDef, nExpr, pList->a[1].pExpr);
17206a03a1c5Sdrh       }else if( nExpr>0 ){
1721b7f6f68fSdrh         pDef = sqlite3VtabOverloadFunction(pDef, nExpr, pList->a[0].pExpr);
1722b7f6f68fSdrh       }
1723b7f6f68fSdrh #endif
1724682f68b0Sdanielk1977       for(i=0; i<nExpr && i<32; i++){
1725d02eb1fdSdanielk1977         if( sqlite3ExprIsConstant(pList->a[i].pExpr) ){
172613449892Sdrh           constMask |= (1<<i);
1727d02eb1fdSdanielk1977         }
1728dc1bdc4fSdanielk1977         if( pDef->needCollSeq && !pColl ){
1729dc1bdc4fSdanielk1977           pColl = sqlite3ExprCollSeq(pParse, pList->a[i].pExpr);
1730dc1bdc4fSdanielk1977         }
1731dc1bdc4fSdanielk1977       }
1732dc1bdc4fSdanielk1977       if( pDef->needCollSeq ){
1733dc1bdc4fSdanielk1977         if( !pColl ) pColl = pParse->db->pDfltColl;
1734d8123366Sdanielk1977         sqlite3VdbeOp3(v, OP_CollSeq, 0, 0, (char *)pColl, P3_COLLSEQ);
1735682f68b0Sdanielk1977       }
173613449892Sdrh       sqlite3VdbeOp3(v, OP_Function, constMask, nExpr, (char*)pDef, P3_FUNCDEF);
1737ffe07b2dSdrh       stackChng = 1-nExpr;
17386ec2733bSdrh       break;
17396ec2733bSdrh     }
1740fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
1741fe2093d7Sdrh     case TK_EXISTS:
174219a775c2Sdrh     case TK_SELECT: {
174341714d6fSdrh       if( pExpr->iColumn==0 ){
1744b3bce662Sdanielk1977         sqlite3CodeSubselect(pParse, pExpr);
174541714d6fSdrh       }
17464adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_MemLoad, pExpr->iColumn, 0);
1747ad6d9460Sdrh       VdbeComment((v, "# load subquery result"));
174819a775c2Sdrh       break;
174919a775c2Sdrh     }
1750fef5208cSdrh     case TK_IN: {
1751fef5208cSdrh       int addr;
175294a11211Sdrh       char affinity;
1753afa5f680Sdrh       int ckOffset = pParse->ckOffset;
1754b3bce662Sdanielk1977       sqlite3CodeSubselect(pParse, pExpr);
1755e014a838Sdanielk1977 
1756e014a838Sdanielk1977       /* Figure out the affinity to use to create a key from the results
1757e014a838Sdanielk1977       ** of the expression. affinityStr stores a static string suitable for
1758ededfd5eSdanielk1977       ** P3 of OP_MakeRecord.
1759e014a838Sdanielk1977       */
176094a11211Sdrh       affinity = comparisonAffinity(pExpr);
1761e014a838Sdanielk1977 
17624adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Integer, 1, 0);
1763afa5f680Sdrh       pParse->ckOffset = ckOffset+1;
1764e014a838Sdanielk1977 
1765e014a838Sdanielk1977       /* Code the <expr> from "<expr> IN (...)". The temporary table
1766e014a838Sdanielk1977       ** pExpr->iTable contains the values that make up the (...) set.
1767e014a838Sdanielk1977       */
17684adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
17694adee20fSdanielk1977       addr = sqlite3VdbeCurrentAddr(v);
1770e014a838Sdanielk1977       sqlite3VdbeAddOp(v, OP_NotNull, -1, addr+4);            /* addr + 0 */
17714adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Pop, 2, 0);
1772f0863fe5Sdrh       sqlite3VdbeAddOp(v, OP_Null, 0, 0);
1773e014a838Sdanielk1977       sqlite3VdbeAddOp(v, OP_Goto, 0, addr+7);
177494a11211Sdrh       sqlite3VdbeOp3(v, OP_MakeRecord, 1, 0, &affinity, 1);   /* addr + 4 */
1775e014a838Sdanielk1977       sqlite3VdbeAddOp(v, OP_Found, pExpr->iTable, addr+7);
1776e014a838Sdanielk1977       sqlite3VdbeAddOp(v, OP_AddImm, -1, 0);                  /* addr + 6 */
1777e014a838Sdanielk1977 
1778fef5208cSdrh       break;
1779fef5208cSdrh     }
178093758c8dSdanielk1977 #endif
1781fef5208cSdrh     case TK_BETWEEN: {
1782be5c89acSdrh       Expr *pLeft = pExpr->pLeft;
1783be5c89acSdrh       struct ExprList_item *pLItem = pExpr->pList->a;
1784be5c89acSdrh       Expr *pRight = pLItem->pExpr;
1785be5c89acSdrh       sqlite3ExprCode(pParse, pLeft);
17864adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Dup, 0, 0);
1787be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
1788be5c89acSdrh       codeCompare(pParse, pLeft, pRight, OP_Ge, 0, 0);
17894adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Pull, 1, 0);
1790be5c89acSdrh       pLItem++;
1791be5c89acSdrh       pRight = pLItem->pExpr;
1792be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
1793be5c89acSdrh       codeCompare(pParse, pLeft, pRight, OP_Le, 0, 0);
17944adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_And, 0, 0);
1795fef5208cSdrh       break;
1796fef5208cSdrh     }
179751e9a445Sdrh     case TK_UPLUS:
1798a2e00042Sdrh     case TK_AS: {
17994adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
1800ffe07b2dSdrh       stackChng = 0;
1801a2e00042Sdrh       break;
1802a2e00042Sdrh     }
180317a7f8ddSdrh     case TK_CASE: {
180417a7f8ddSdrh       int expr_end_label;
1805f5905aa7Sdrh       int jumpInst;
1806f5905aa7Sdrh       int nExpr;
180717a7f8ddSdrh       int i;
1808be5c89acSdrh       ExprList *pEList;
1809be5c89acSdrh       struct ExprList_item *aListelem;
181017a7f8ddSdrh 
181117a7f8ddSdrh       assert(pExpr->pList);
181217a7f8ddSdrh       assert((pExpr->pList->nExpr % 2) == 0);
181317a7f8ddSdrh       assert(pExpr->pList->nExpr > 0);
1814be5c89acSdrh       pEList = pExpr->pList;
1815be5c89acSdrh       aListelem = pEList->a;
1816be5c89acSdrh       nExpr = pEList->nExpr;
18174adee20fSdanielk1977       expr_end_label = sqlite3VdbeMakeLabel(v);
181817a7f8ddSdrh       if( pExpr->pLeft ){
18194adee20fSdanielk1977         sqlite3ExprCode(pParse, pExpr->pLeft);
1820cce7d176Sdrh       }
1821f5905aa7Sdrh       for(i=0; i<nExpr; i=i+2){
1822be5c89acSdrh         sqlite3ExprCode(pParse, aListelem[i].pExpr);
182317a7f8ddSdrh         if( pExpr->pLeft ){
18244adee20fSdanielk1977           sqlite3VdbeAddOp(v, OP_Dup, 1, 1);
1825be5c89acSdrh           jumpInst = codeCompare(pParse, pExpr->pLeft, aListelem[i].pExpr,
1826be5c89acSdrh                                  OP_Ne, 0, 1);
18274adee20fSdanielk1977           sqlite3VdbeAddOp(v, OP_Pop, 1, 0);
1828f5905aa7Sdrh         }else{
18294adee20fSdanielk1977           jumpInst = sqlite3VdbeAddOp(v, OP_IfNot, 1, 0);
183017a7f8ddSdrh         }
1831be5c89acSdrh         sqlite3ExprCode(pParse, aListelem[i+1].pExpr);
18324adee20fSdanielk1977         sqlite3VdbeAddOp(v, OP_Goto, 0, expr_end_label);
1833d654be80Sdrh         sqlite3VdbeJumpHere(v, jumpInst);
183417a7f8ddSdrh       }
1835f570f011Sdrh       if( pExpr->pLeft ){
18364adee20fSdanielk1977         sqlite3VdbeAddOp(v, OP_Pop, 1, 0);
1837f570f011Sdrh       }
183817a7f8ddSdrh       if( pExpr->pRight ){
18394adee20fSdanielk1977         sqlite3ExprCode(pParse, pExpr->pRight);
184017a7f8ddSdrh       }else{
1841f0863fe5Sdrh         sqlite3VdbeAddOp(v, OP_Null, 0, 0);
184217a7f8ddSdrh       }
18434adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, expr_end_label);
18446f34903eSdanielk1977       break;
18456f34903eSdanielk1977     }
18465338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_TRIGGER
18476f34903eSdanielk1977     case TK_RAISE: {
18486f34903eSdanielk1977       if( !pParse->trigStack ){
18494adee20fSdanielk1977         sqlite3ErrorMsg(pParse,
1850da93d238Sdrh                        "RAISE() may only be used within a trigger-program");
18516f34903eSdanielk1977 	return;
18526f34903eSdanielk1977       }
1853ad6d9460Sdrh       if( pExpr->iColumn!=OE_Ignore ){
1854ad6d9460Sdrh          assert( pExpr->iColumn==OE_Rollback ||
18556f34903eSdanielk1977                  pExpr->iColumn == OE_Abort ||
1856ad6d9460Sdrh                  pExpr->iColumn == OE_Fail );
1857d2687b77Sdrh          sqlite3DequoteExpr(pExpr);
18584adee20fSdanielk1977          sqlite3VdbeOp3(v, OP_Halt, SQLITE_CONSTRAINT, pExpr->iColumn,
18592646da7eSdrh                         (char*)pExpr->token.z, pExpr->token.n);
18606f34903eSdanielk1977       } else {
18616f34903eSdanielk1977          assert( pExpr->iColumn == OE_Ignore );
1862344737f6Sdrh          sqlite3VdbeAddOp(v, OP_ContextPop, 0, 0);
1863ad6d9460Sdrh          sqlite3VdbeAddOp(v, OP_Goto, 0, pParse->trigStack->ignoreJump);
1864ad6d9460Sdrh          VdbeComment((v, "# raise(IGNORE)"));
18656f34903eSdanielk1977       }
1866ffe07b2dSdrh       stackChng = 0;
1867ffe07b2dSdrh       break;
186817a7f8ddSdrh     }
18695338a5f7Sdanielk1977 #endif
1870ffe07b2dSdrh   }
1871ffe07b2dSdrh 
1872ffe07b2dSdrh   if( pParse->ckOffset ){
1873ffe07b2dSdrh     pParse->ckOffset += stackChng;
1874ffe07b2dSdrh     assert( pParse->ckOffset );
187517a7f8ddSdrh   }
1876cce7d176Sdrh }
1877cce7d176Sdrh 
187893758c8dSdanielk1977 #ifndef SQLITE_OMIT_TRIGGER
1879cce7d176Sdrh /*
188025303780Sdrh ** Generate code that evalutes the given expression and leaves the result
188125303780Sdrh ** on the stack.  See also sqlite3ExprCode().
188225303780Sdrh **
188325303780Sdrh ** This routine might also cache the result and modify the pExpr tree
188425303780Sdrh ** so that it will make use of the cached result on subsequent evaluations
188525303780Sdrh ** rather than evaluate the whole expression again.  Trivial expressions are
188625303780Sdrh ** not cached.  If the expression is cached, its result is stored in a
188725303780Sdrh ** memory location.
188825303780Sdrh */
188925303780Sdrh void sqlite3ExprCodeAndCache(Parse *pParse, Expr *pExpr){
189025303780Sdrh   Vdbe *v = pParse->pVdbe;
189125303780Sdrh   int iMem;
189225303780Sdrh   int addr1, addr2;
189325303780Sdrh   if( v==0 ) return;
189425303780Sdrh   addr1 = sqlite3VdbeCurrentAddr(v);
189525303780Sdrh   sqlite3ExprCode(pParse, pExpr);
189625303780Sdrh   addr2 = sqlite3VdbeCurrentAddr(v);
189725303780Sdrh   if( addr2>addr1+1 || sqlite3VdbeGetOp(v, addr1)->opcode==OP_Function ){
189825303780Sdrh     iMem = pExpr->iTable = pParse->nMem++;
189925303780Sdrh     sqlite3VdbeAddOp(v, OP_MemStore, iMem, 0);
190025303780Sdrh     pExpr->op = TK_REGISTER;
190125303780Sdrh   }
190225303780Sdrh }
190393758c8dSdanielk1977 #endif
190425303780Sdrh 
190525303780Sdrh /*
1906268380caSdrh ** Generate code that pushes the value of every element of the given
1907f9b596ebSdrh ** expression list onto the stack.
1908268380caSdrh **
1909268380caSdrh ** Return the number of elements pushed onto the stack.
1910268380caSdrh */
19114adee20fSdanielk1977 int sqlite3ExprCodeExprList(
1912268380caSdrh   Parse *pParse,     /* Parsing context */
1913f9b596ebSdrh   ExprList *pList    /* The expression list to be coded */
1914268380caSdrh ){
1915268380caSdrh   struct ExprList_item *pItem;
1916268380caSdrh   int i, n;
1917268380caSdrh   if( pList==0 ) return 0;
1918268380caSdrh   n = pList->nExpr;
1919c182d163Sdrh   for(pItem=pList->a, i=n; i>0; i--, pItem++){
19204adee20fSdanielk1977     sqlite3ExprCode(pParse, pItem->pExpr);
1921268380caSdrh   }
1922f9b596ebSdrh   return n;
1923268380caSdrh }
1924268380caSdrh 
1925268380caSdrh /*
1926cce7d176Sdrh ** Generate code for a boolean expression such that a jump is made
1927cce7d176Sdrh ** to the label "dest" if the expression is true but execution
1928cce7d176Sdrh ** continues straight thru if the expression is false.
1929f5905aa7Sdrh **
1930f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false), then
1931f5905aa7Sdrh ** take the jump if the jumpIfNull flag is true.
1932f2bc013cSdrh **
1933f2bc013cSdrh ** This code depends on the fact that certain token values (ex: TK_EQ)
1934f2bc013cSdrh ** are the same as opcode values (ex: OP_Eq) that implement the corresponding
1935f2bc013cSdrh ** operation.  Special comments in vdbe.c and the mkopcodeh.awk script in
1936f2bc013cSdrh ** the make process cause these values to align.  Assert()s in the code
1937f2bc013cSdrh ** below verify that the numbers are aligned correctly.
1938cce7d176Sdrh */
19394adee20fSdanielk1977 void sqlite3ExprIfTrue(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
1940cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
1941cce7d176Sdrh   int op = 0;
1942ffe07b2dSdrh   int ckOffset = pParse->ckOffset;
1943daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
1944f2bc013cSdrh   op = pExpr->op;
1945f2bc013cSdrh   switch( op ){
1946cce7d176Sdrh     case TK_AND: {
19474adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
19484adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, d2, !jumpIfNull);
19494adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
19504adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
1951cce7d176Sdrh       break;
1952cce7d176Sdrh     }
1953cce7d176Sdrh     case TK_OR: {
19544adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
19554adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
1956cce7d176Sdrh       break;
1957cce7d176Sdrh     }
1958cce7d176Sdrh     case TK_NOT: {
19594adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
1960cce7d176Sdrh       break;
1961cce7d176Sdrh     }
1962cce7d176Sdrh     case TK_LT:
1963cce7d176Sdrh     case TK_LE:
1964cce7d176Sdrh     case TK_GT:
1965cce7d176Sdrh     case TK_GE:
1966cce7d176Sdrh     case TK_NE:
19670ac65892Sdrh     case TK_EQ: {
1968f2bc013cSdrh       assert( TK_LT==OP_Lt );
1969f2bc013cSdrh       assert( TK_LE==OP_Le );
1970f2bc013cSdrh       assert( TK_GT==OP_Gt );
1971f2bc013cSdrh       assert( TK_GE==OP_Ge );
1972f2bc013cSdrh       assert( TK_EQ==OP_Eq );
1973f2bc013cSdrh       assert( TK_NE==OP_Ne );
19744adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
19754adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pRight);
1976be5c89acSdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op, dest, jumpIfNull);
1977cce7d176Sdrh       break;
1978cce7d176Sdrh     }
1979cce7d176Sdrh     case TK_ISNULL:
1980cce7d176Sdrh     case TK_NOTNULL: {
1981f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
1982f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
19834adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
19844adee20fSdanielk1977       sqlite3VdbeAddOp(v, op, 1, dest);
1985cce7d176Sdrh       break;
1986cce7d176Sdrh     }
1987fef5208cSdrh     case TK_BETWEEN: {
19880202b29eSdanielk1977       /* The expression "x BETWEEN y AND z" is implemented as:
19890202b29eSdanielk1977       **
19900202b29eSdanielk1977       ** 1 IF (x < y) GOTO 3
19910202b29eSdanielk1977       ** 2 IF (x <= z) GOTO <dest>
19920202b29eSdanielk1977       ** 3 ...
19930202b29eSdanielk1977       */
1994f5905aa7Sdrh       int addr;
1995be5c89acSdrh       Expr *pLeft = pExpr->pLeft;
1996be5c89acSdrh       Expr *pRight = pExpr->pList->a[0].pExpr;
1997be5c89acSdrh       sqlite3ExprCode(pParse, pLeft);
19984adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Dup, 0, 0);
1999be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
2000be5c89acSdrh       addr = codeCompare(pParse, pLeft, pRight, OP_Lt, 0, !jumpIfNull);
20010202b29eSdanielk1977 
2002be5c89acSdrh       pRight = pExpr->pList->a[1].pExpr;
2003be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
2004be5c89acSdrh       codeCompare(pParse, pLeft, pRight, OP_Le, dest, jumpIfNull);
20050202b29eSdanielk1977 
20064adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Integer, 0, 0);
2007d654be80Sdrh       sqlite3VdbeJumpHere(v, addr);
20084adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Pop, 1, 0);
2009fef5208cSdrh       break;
2010fef5208cSdrh     }
2011cce7d176Sdrh     default: {
20124adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr);
20134adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_If, jumpIfNull, dest);
2014cce7d176Sdrh       break;
2015cce7d176Sdrh     }
2016cce7d176Sdrh   }
2017ffe07b2dSdrh   pParse->ckOffset = ckOffset;
2018cce7d176Sdrh }
2019cce7d176Sdrh 
2020cce7d176Sdrh /*
202166b89c8fSdrh ** Generate code for a boolean expression such that a jump is made
2022cce7d176Sdrh ** to the label "dest" if the expression is false but execution
2023cce7d176Sdrh ** continues straight thru if the expression is true.
2024f5905aa7Sdrh **
2025f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false) then
2026f5905aa7Sdrh ** jump if jumpIfNull is true or fall through if jumpIfNull is false.
2027cce7d176Sdrh */
20284adee20fSdanielk1977 void sqlite3ExprIfFalse(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
2029cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
2030cce7d176Sdrh   int op = 0;
2031ffe07b2dSdrh   int ckOffset = pParse->ckOffset;
2032daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
2033f2bc013cSdrh 
2034f2bc013cSdrh   /* The value of pExpr->op and op are related as follows:
2035f2bc013cSdrh   **
2036f2bc013cSdrh   **       pExpr->op            op
2037f2bc013cSdrh   **       ---------          ----------
2038f2bc013cSdrh   **       TK_ISNULL          OP_NotNull
2039f2bc013cSdrh   **       TK_NOTNULL         OP_IsNull
2040f2bc013cSdrh   **       TK_NE              OP_Eq
2041f2bc013cSdrh   **       TK_EQ              OP_Ne
2042f2bc013cSdrh   **       TK_GT              OP_Le
2043f2bc013cSdrh   **       TK_LE              OP_Gt
2044f2bc013cSdrh   **       TK_GE              OP_Lt
2045f2bc013cSdrh   **       TK_LT              OP_Ge
2046f2bc013cSdrh   **
2047f2bc013cSdrh   ** For other values of pExpr->op, op is undefined and unused.
2048f2bc013cSdrh   ** The value of TK_ and OP_ constants are arranged such that we
2049f2bc013cSdrh   ** can compute the mapping above using the following expression.
2050f2bc013cSdrh   ** Assert()s verify that the computation is correct.
2051f2bc013cSdrh   */
2052f2bc013cSdrh   op = ((pExpr->op+(TK_ISNULL&1))^1)-(TK_ISNULL&1);
2053f2bc013cSdrh 
2054f2bc013cSdrh   /* Verify correct alignment of TK_ and OP_ constants
2055f2bc013cSdrh   */
2056f2bc013cSdrh   assert( pExpr->op!=TK_ISNULL || op==OP_NotNull );
2057f2bc013cSdrh   assert( pExpr->op!=TK_NOTNULL || op==OP_IsNull );
2058f2bc013cSdrh   assert( pExpr->op!=TK_NE || op==OP_Eq );
2059f2bc013cSdrh   assert( pExpr->op!=TK_EQ || op==OP_Ne );
2060f2bc013cSdrh   assert( pExpr->op!=TK_LT || op==OP_Ge );
2061f2bc013cSdrh   assert( pExpr->op!=TK_LE || op==OP_Gt );
2062f2bc013cSdrh   assert( pExpr->op!=TK_GT || op==OP_Le );
2063f2bc013cSdrh   assert( pExpr->op!=TK_GE || op==OP_Lt );
2064f2bc013cSdrh 
2065cce7d176Sdrh   switch( pExpr->op ){
2066cce7d176Sdrh     case TK_AND: {
20674adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
20684adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
2069cce7d176Sdrh       break;
2070cce7d176Sdrh     }
2071cce7d176Sdrh     case TK_OR: {
20724adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
20734adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, d2, !jumpIfNull);
20744adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
20754adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
2076cce7d176Sdrh       break;
2077cce7d176Sdrh     }
2078cce7d176Sdrh     case TK_NOT: {
20794adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
2080cce7d176Sdrh       break;
2081cce7d176Sdrh     }
2082cce7d176Sdrh     case TK_LT:
2083cce7d176Sdrh     case TK_LE:
2084cce7d176Sdrh     case TK_GT:
2085cce7d176Sdrh     case TK_GE:
2086cce7d176Sdrh     case TK_NE:
2087cce7d176Sdrh     case TK_EQ: {
20884adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
20894adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pRight);
2090be5c89acSdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op, dest, jumpIfNull);
2091cce7d176Sdrh       break;
2092cce7d176Sdrh     }
2093cce7d176Sdrh     case TK_ISNULL:
2094cce7d176Sdrh     case TK_NOTNULL: {
20954adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr->pLeft);
20964adee20fSdanielk1977       sqlite3VdbeAddOp(v, op, 1, dest);
2097cce7d176Sdrh       break;
2098cce7d176Sdrh     }
2099fef5208cSdrh     case TK_BETWEEN: {
21000202b29eSdanielk1977       /* The expression is "x BETWEEN y AND z". It is implemented as:
21010202b29eSdanielk1977       **
21020202b29eSdanielk1977       ** 1 IF (x >= y) GOTO 3
21030202b29eSdanielk1977       ** 2 GOTO <dest>
21040202b29eSdanielk1977       ** 3 IF (x > z) GOTO <dest>
21050202b29eSdanielk1977       */
2106fef5208cSdrh       int addr;
2107be5c89acSdrh       Expr *pLeft = pExpr->pLeft;
2108be5c89acSdrh       Expr *pRight = pExpr->pList->a[0].pExpr;
2109be5c89acSdrh       sqlite3ExprCode(pParse, pLeft);
21104adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Dup, 0, 0);
2111be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
21124adee20fSdanielk1977       addr = sqlite3VdbeCurrentAddr(v);
2113be5c89acSdrh       codeCompare(pParse, pLeft, pRight, OP_Ge, addr+3, !jumpIfNull);
2114be5c89acSdrh 
21154adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Pop, 1, 0);
21164adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_Goto, 0, dest);
2117be5c89acSdrh       pRight = pExpr->pList->a[1].pExpr;
2118be5c89acSdrh       sqlite3ExprCode(pParse, pRight);
2119be5c89acSdrh       codeCompare(pParse, pLeft, pRight, OP_Gt, dest, jumpIfNull);
2120fef5208cSdrh       break;
2121fef5208cSdrh     }
2122cce7d176Sdrh     default: {
21234adee20fSdanielk1977       sqlite3ExprCode(pParse, pExpr);
21244adee20fSdanielk1977       sqlite3VdbeAddOp(v, OP_IfNot, jumpIfNull, dest);
2125cce7d176Sdrh       break;
2126cce7d176Sdrh     }
2127cce7d176Sdrh   }
2128ffe07b2dSdrh   pParse->ckOffset = ckOffset;
2129cce7d176Sdrh }
21302282792aSdrh 
21312282792aSdrh /*
21322282792aSdrh ** Do a deep comparison of two expression trees.  Return TRUE (non-zero)
21332282792aSdrh ** if they are identical and return FALSE if they differ in any way.
21342282792aSdrh */
21354adee20fSdanielk1977 int sqlite3ExprCompare(Expr *pA, Expr *pB){
21362282792aSdrh   int i;
21374b202ae2Sdanielk1977   if( pA==0||pB==0 ){
21384b202ae2Sdanielk1977     return pB==pA;
21392282792aSdrh   }
21402282792aSdrh   if( pA->op!=pB->op ) return 0;
2141fd357974Sdrh   if( (pA->flags & EP_Distinct)!=(pB->flags & EP_Distinct) ) return 0;
21424adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pLeft, pB->pLeft) ) return 0;
21434adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pRight, pB->pRight) ) return 0;
21442282792aSdrh   if( pA->pList ){
21452282792aSdrh     if( pB->pList==0 ) return 0;
21462282792aSdrh     if( pA->pList->nExpr!=pB->pList->nExpr ) return 0;
21472282792aSdrh     for(i=0; i<pA->pList->nExpr; i++){
21484adee20fSdanielk1977       if( !sqlite3ExprCompare(pA->pList->a[i].pExpr, pB->pList->a[i].pExpr) ){
21492282792aSdrh         return 0;
21502282792aSdrh       }
21512282792aSdrh     }
21522282792aSdrh   }else if( pB->pList ){
21532282792aSdrh     return 0;
21542282792aSdrh   }
21552282792aSdrh   if( pA->pSelect || pB->pSelect ) return 0;
21562f2c01e5Sdrh   if( pA->iTable!=pB->iTable || pA->iColumn!=pB->iColumn ) return 0;
21572282792aSdrh   if( pA->token.z ){
21582282792aSdrh     if( pB->token.z==0 ) return 0;
21596977fea8Sdrh     if( pB->token.n!=pA->token.n ) return 0;
21602646da7eSdrh     if( sqlite3StrNICmp((char*)pA->token.z,(char*)pB->token.z,pB->token.n)!=0 ){
21612646da7eSdrh       return 0;
21622646da7eSdrh     }
21632282792aSdrh   }
21642282792aSdrh   return 1;
21652282792aSdrh }
21662282792aSdrh 
216713449892Sdrh 
21682282792aSdrh /*
216913449892Sdrh ** Add a new element to the pAggInfo->aCol[] array.  Return the index of
217013449892Sdrh ** the new element.  Return a negative number if malloc fails.
21712282792aSdrh */
217213449892Sdrh static int addAggInfoColumn(AggInfo *pInfo){
217313449892Sdrh   int i;
217413449892Sdrh   i = sqlite3ArrayAllocate((void**)&pInfo->aCol, sizeof(pInfo->aCol[0]), 3);
217513449892Sdrh   if( i<0 ){
21762282792aSdrh     return -1;
21772282792aSdrh   }
217813449892Sdrh   return i;
21792282792aSdrh }
218013449892Sdrh 
218113449892Sdrh /*
218213449892Sdrh ** Add a new element to the pAggInfo->aFunc[] array.  Return the index of
218313449892Sdrh ** the new element.  Return a negative number if malloc fails.
218413449892Sdrh */
218513449892Sdrh static int addAggInfoFunc(AggInfo *pInfo){
218613449892Sdrh   int i;
218713449892Sdrh   i = sqlite3ArrayAllocate((void**)&pInfo->aFunc, sizeof(pInfo->aFunc[0]), 2);
218813449892Sdrh   if( i<0 ){
218913449892Sdrh     return -1;
219013449892Sdrh   }
219113449892Sdrh   return i;
21922282792aSdrh }
21932282792aSdrh 
21942282792aSdrh /*
2195626a879aSdrh ** This is an xFunc for walkExprTree() used to implement
2196626a879aSdrh ** sqlite3ExprAnalyzeAggregates().  See sqlite3ExprAnalyzeAggregates
2197626a879aSdrh ** for additional information.
21982282792aSdrh **
2199626a879aSdrh ** This routine analyzes the aggregate function at pExpr.
22002282792aSdrh */
2201626a879aSdrh static int analyzeAggregate(void *pArg, Expr *pExpr){
22022282792aSdrh   int i;
2203a58fdfb1Sdanielk1977   NameContext *pNC = (NameContext *)pArg;
2204a58fdfb1Sdanielk1977   Parse *pParse = pNC->pParse;
2205a58fdfb1Sdanielk1977   SrcList *pSrcList = pNC->pSrcList;
220613449892Sdrh   AggInfo *pAggInfo = pNC->pAggInfo;
220713449892Sdrh 
22082282792aSdrh 
22092282792aSdrh   switch( pExpr->op ){
2210967e8b73Sdrh     case TK_COLUMN: {
221113449892Sdrh       /* Check to see if the column is in one of the tables in the FROM
221213449892Sdrh       ** clause of the aggregate query */
221313449892Sdrh       if( pSrcList ){
221413449892Sdrh         struct SrcList_item *pItem = pSrcList->a;
221513449892Sdrh         for(i=0; i<pSrcList->nSrc; i++, pItem++){
221613449892Sdrh           struct AggInfo_col *pCol;
221713449892Sdrh           if( pExpr->iTable==pItem->iCursor ){
221813449892Sdrh             /* If we reach this point, it means that pExpr refers to a table
221913449892Sdrh             ** that is in the FROM clause of the aggregate query.
222013449892Sdrh             **
222113449892Sdrh             ** Make an entry for the column in pAggInfo->aCol[] if there
222213449892Sdrh             ** is not an entry there already.
222313449892Sdrh             */
222413449892Sdrh             pCol = pAggInfo->aCol;
222513449892Sdrh             for(i=0; i<pAggInfo->nColumn; i++, pCol++){
222613449892Sdrh               if( pCol->iTable==pExpr->iTable &&
222713449892Sdrh                   pCol->iColumn==pExpr->iColumn ){
22282282792aSdrh                 break;
22292282792aSdrh               }
22302282792aSdrh             }
223113449892Sdrh             if( i>=pAggInfo->nColumn && (i = addAggInfoColumn(pAggInfo))>=0 ){
223213449892Sdrh               pCol = &pAggInfo->aCol[i];
223313449892Sdrh               pCol->iTable = pExpr->iTable;
223413449892Sdrh               pCol->iColumn = pExpr->iColumn;
223513449892Sdrh               pCol->iMem = pParse->nMem++;
223613449892Sdrh               pCol->iSorterColumn = -1;
22375774b806Sdrh               pCol->pExpr = pExpr;
223813449892Sdrh               if( pAggInfo->pGroupBy ){
223913449892Sdrh                 int j, n;
224013449892Sdrh                 ExprList *pGB = pAggInfo->pGroupBy;
224113449892Sdrh                 struct ExprList_item *pTerm = pGB->a;
224213449892Sdrh                 n = pGB->nExpr;
224313449892Sdrh                 for(j=0; j<n; j++, pTerm++){
224413449892Sdrh                   Expr *pE = pTerm->pExpr;
224513449892Sdrh                   if( pE->op==TK_COLUMN && pE->iTable==pExpr->iTable &&
224613449892Sdrh                       pE->iColumn==pExpr->iColumn ){
224713449892Sdrh                     pCol->iSorterColumn = j;
224813449892Sdrh                     break;
22492282792aSdrh                   }
225013449892Sdrh                 }
225113449892Sdrh               }
225213449892Sdrh               if( pCol->iSorterColumn<0 ){
225313449892Sdrh                 pCol->iSorterColumn = pAggInfo->nSortingColumn++;
225413449892Sdrh               }
225513449892Sdrh             }
225613449892Sdrh             /* There is now an entry for pExpr in pAggInfo->aCol[] (either
225713449892Sdrh             ** because it was there before or because we just created it).
225813449892Sdrh             ** Convert the pExpr to be a TK_AGG_COLUMN referring to that
225913449892Sdrh             ** pAggInfo->aCol[] entry.
226013449892Sdrh             */
226113449892Sdrh             pExpr->pAggInfo = pAggInfo;
226213449892Sdrh             pExpr->op = TK_AGG_COLUMN;
2263aaf88729Sdrh             pExpr->iAgg = i;
226413449892Sdrh             break;
226513449892Sdrh           } /* endif pExpr->iTable==pItem->iCursor */
226613449892Sdrh         } /* end loop over pSrcList */
2267a58fdfb1Sdanielk1977       }
2268626a879aSdrh       return 1;
22692282792aSdrh     }
22702282792aSdrh     case TK_AGG_FUNCTION: {
227113449892Sdrh       /* The pNC->nDepth==0 test causes aggregate functions in subqueries
227213449892Sdrh       ** to be ignored */
2273a58fdfb1Sdanielk1977       if( pNC->nDepth==0 ){
227413449892Sdrh         /* Check to see if pExpr is a duplicate of another aggregate
227513449892Sdrh         ** function that is already in the pAggInfo structure
227613449892Sdrh         */
227713449892Sdrh         struct AggInfo_func *pItem = pAggInfo->aFunc;
227813449892Sdrh         for(i=0; i<pAggInfo->nFunc; i++, pItem++){
227913449892Sdrh           if( sqlite3ExprCompare(pItem->pExpr, pExpr) ){
22802282792aSdrh             break;
22812282792aSdrh           }
22822282792aSdrh         }
228313449892Sdrh         if( i>=pAggInfo->nFunc ){
228413449892Sdrh           /* pExpr is original.  Make a new entry in pAggInfo->aFunc[]
228513449892Sdrh           */
228614db2665Sdanielk1977           u8 enc = ENC(pParse->db);
228713449892Sdrh           i = addAggInfoFunc(pAggInfo);
228813449892Sdrh           if( i>=0 ){
228913449892Sdrh             pItem = &pAggInfo->aFunc[i];
229013449892Sdrh             pItem->pExpr = pExpr;
229113449892Sdrh             pItem->iMem = pParse->nMem++;
229213449892Sdrh             pItem->pFunc = sqlite3FindFunction(pParse->db,
22932646da7eSdrh                    (char*)pExpr->token.z, pExpr->token.n,
2294d8123366Sdanielk1977                    pExpr->pList ? pExpr->pList->nExpr : 0, enc, 0);
2295fd357974Sdrh             if( pExpr->flags & EP_Distinct ){
2296fd357974Sdrh               pItem->iDistinct = pParse->nTab++;
2297fd357974Sdrh             }else{
2298fd357974Sdrh               pItem->iDistinct = -1;
2299fd357974Sdrh             }
23002282792aSdrh           }
230113449892Sdrh         }
230213449892Sdrh         /* Make pExpr point to the appropriate pAggInfo->aFunc[] entry
230313449892Sdrh         */
23042282792aSdrh         pExpr->iAgg = i;
230513449892Sdrh         pExpr->pAggInfo = pAggInfo;
2306626a879aSdrh         return 1;
23072282792aSdrh       }
23082282792aSdrh     }
2309a58fdfb1Sdanielk1977   }
231013449892Sdrh 
231113449892Sdrh   /* Recursively walk subqueries looking for TK_COLUMN nodes that need
231213449892Sdrh   ** to be changed to TK_AGG_COLUMN.  But increment nDepth so that
231313449892Sdrh   ** TK_AGG_FUNCTION nodes in subqueries will be unchanged.
231413449892Sdrh   */
2315a58fdfb1Sdanielk1977   if( pExpr->pSelect ){
2316a58fdfb1Sdanielk1977     pNC->nDepth++;
2317a58fdfb1Sdanielk1977     walkSelectExpr(pExpr->pSelect, analyzeAggregate, pNC);
2318a58fdfb1Sdanielk1977     pNC->nDepth--;
2319a58fdfb1Sdanielk1977   }
2320626a879aSdrh   return 0;
23212282792aSdrh }
2322626a879aSdrh 
2323626a879aSdrh /*
2324626a879aSdrh ** Analyze the given expression looking for aggregate functions and
2325626a879aSdrh ** for variables that need to be added to the pParse->aAgg[] array.
2326626a879aSdrh ** Make additional entries to the pParse->aAgg[] array as necessary.
2327626a879aSdrh **
2328626a879aSdrh ** This routine should only be called after the expression has been
2329626a879aSdrh ** analyzed by sqlite3ExprResolveNames().
2330626a879aSdrh **
2331626a879aSdrh ** If errors are seen, leave an error message in zErrMsg and return
2332626a879aSdrh ** the number of errors.
2333626a879aSdrh */
2334a58fdfb1Sdanielk1977 int sqlite3ExprAnalyzeAggregates(NameContext *pNC, Expr *pExpr){
2335a58fdfb1Sdanielk1977   int nErr = pNC->pParse->nErr;
2336a58fdfb1Sdanielk1977   walkExprTree(pExpr, analyzeAggregate, pNC);
2337a58fdfb1Sdanielk1977   return pNC->pParse->nErr - nErr;
23382282792aSdrh }
23395d9a4af9Sdrh 
23405d9a4af9Sdrh /*
23415d9a4af9Sdrh ** Call sqlite3ExprAnalyzeAggregates() for every expression in an
23425d9a4af9Sdrh ** expression list.  Return the number of errors.
23435d9a4af9Sdrh **
23445d9a4af9Sdrh ** If an error is found, the analysis is cut short.
23455d9a4af9Sdrh */
23465d9a4af9Sdrh int sqlite3ExprAnalyzeAggList(NameContext *pNC, ExprList *pList){
23475d9a4af9Sdrh   struct ExprList_item *pItem;
23485d9a4af9Sdrh   int i;
23495d9a4af9Sdrh   int nErr = 0;
23505d9a4af9Sdrh   if( pList ){
23515d9a4af9Sdrh     for(pItem=pList->a, i=0; nErr==0 && i<pList->nExpr; i++, pItem++){
23525d9a4af9Sdrh       nErr += sqlite3ExprAnalyzeAggregates(pNC, pItem->pExpr);
23535d9a4af9Sdrh     }
23545d9a4af9Sdrh   }
23555d9a4af9Sdrh   return nErr;
23565d9a4af9Sdrh }
2357