xref: /sqlite-3.40.0/src/expr.c (revision 6fccc35a)
1cce7d176Sdrh /*
2b19a2bc6Sdrh ** 2001 September 15
3cce7d176Sdrh **
4b19a2bc6Sdrh ** The author disclaims copyright to this source code.  In place of
5b19a2bc6Sdrh ** a legal notice, here is a blessing:
6cce7d176Sdrh **
7b19a2bc6Sdrh **    May you do good and not evil.
8b19a2bc6Sdrh **    May you find forgiveness for yourself and forgive others.
9b19a2bc6Sdrh **    May you share freely, never taking more than you give.
10cce7d176Sdrh **
11cce7d176Sdrh *************************************************************************
121ccde15dSdrh ** This file contains routines used for analyzing expressions and
13b19a2bc6Sdrh ** for generating VDBE code that evaluates expressions in SQLite.
14cce7d176Sdrh **
15*6fccc35aSdrh ** $Id: expr.c,v 1.381 2008/06/27 00:52:45 drh Exp $
16cce7d176Sdrh */
17cce7d176Sdrh #include "sqliteInt.h"
1804738cb9Sdrh #include <ctype.h>
19a2e00042Sdrh 
20e014a838Sdanielk1977 /*
21e014a838Sdanielk1977 ** Return the 'affinity' of the expression pExpr if any.
22e014a838Sdanielk1977 **
23e014a838Sdanielk1977 ** If pExpr is a column, a reference to a column via an 'AS' alias,
24e014a838Sdanielk1977 ** or a sub-select with a column as the return value, then the
25e014a838Sdanielk1977 ** affinity of that column is returned. Otherwise, 0x00 is returned,
26e014a838Sdanielk1977 ** indicating no affinity for the expression.
27e014a838Sdanielk1977 **
28e014a838Sdanielk1977 ** i.e. the WHERE clause expresssions in the following statements all
29e014a838Sdanielk1977 ** have an affinity:
30e014a838Sdanielk1977 **
31e014a838Sdanielk1977 ** CREATE TABLE t1(a);
32e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE a;
33e014a838Sdanielk1977 ** SELECT a AS b FROM t1 WHERE b;
34e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE (select a from t1);
35e014a838Sdanielk1977 */
36bf3b721fSdanielk1977 char sqlite3ExprAffinity(Expr *pExpr){
37487e262fSdrh   int op = pExpr->op;
38487e262fSdrh   if( op==TK_SELECT ){
39bf3b721fSdanielk1977     return sqlite3ExprAffinity(pExpr->pSelect->pEList->a[0].pExpr);
40a37cdde0Sdanielk1977   }
41487e262fSdrh #ifndef SQLITE_OMIT_CAST
42487e262fSdrh   if( op==TK_CAST ){
438a51256cSdrh     return sqlite3AffinityType(&pExpr->token);
44487e262fSdrh   }
45487e262fSdrh #endif
46a37cdde0Sdanielk1977   return pExpr->affinity;
47a37cdde0Sdanielk1977 }
48a37cdde0Sdanielk1977 
4953db1458Sdrh /*
508b4c40d8Sdrh ** Set the collating sequence for expression pExpr to be the collating
518b4c40d8Sdrh ** sequence named by pToken.   Return a pointer to the revised expression.
52a34001c9Sdrh ** The collating sequence is marked as "explicit" using the EP_ExpCollate
53a34001c9Sdrh ** flag.  An explicit collating sequence will override implicit
54a34001c9Sdrh ** collating sequences.
558b4c40d8Sdrh */
568b4c40d8Sdrh Expr *sqlite3ExprSetColl(Parse *pParse, Expr *pExpr, Token *pName){
5739002505Sdanielk1977   char *zColl = 0;            /* Dequoted name of collation sequence */
588b4c40d8Sdrh   CollSeq *pColl;
5939002505Sdanielk1977   zColl = sqlite3NameFromToken(pParse->db, pName);
6039002505Sdanielk1977   if( pExpr && zColl ){
6139002505Sdanielk1977     pColl = sqlite3LocateCollSeq(pParse, zColl, -1);
628b4c40d8Sdrh     if( pColl ){
638b4c40d8Sdrh       pExpr->pColl = pColl;
648b4c40d8Sdrh       pExpr->flags |= EP_ExpCollate;
658b4c40d8Sdrh     }
6639002505Sdanielk1977   }
6739002505Sdanielk1977   sqlite3_free(zColl);
688b4c40d8Sdrh   return pExpr;
698b4c40d8Sdrh }
708b4c40d8Sdrh 
718b4c40d8Sdrh /*
720202b29eSdanielk1977 ** Return the default collation sequence for the expression pExpr. If
730202b29eSdanielk1977 ** there is no default collation type, return 0.
740202b29eSdanielk1977 */
757cedc8d4Sdanielk1977 CollSeq *sqlite3ExprCollSeq(Parse *pParse, Expr *pExpr){
767cedc8d4Sdanielk1977   CollSeq *pColl = 0;
770202b29eSdanielk1977   if( pExpr ){
787e09fe0bSdrh     int op;
797cedc8d4Sdanielk1977     pColl = pExpr->pColl;
807e09fe0bSdrh     op = pExpr->op;
817e09fe0bSdrh     if( (op==TK_CAST || op==TK_UPLUS) && !pColl ){
827cedc8d4Sdanielk1977       return sqlite3ExprCollSeq(pParse, pExpr->pLeft);
830202b29eSdanielk1977     }
840202b29eSdanielk1977   }
857cedc8d4Sdanielk1977   if( sqlite3CheckCollSeq(pParse, pColl) ){
867cedc8d4Sdanielk1977     pColl = 0;
877cedc8d4Sdanielk1977   }
887cedc8d4Sdanielk1977   return pColl;
890202b29eSdanielk1977 }
900202b29eSdanielk1977 
910202b29eSdanielk1977 /*
92626a879aSdrh ** pExpr is an operand of a comparison operator.  aff2 is the
93626a879aSdrh ** type affinity of the other operand.  This routine returns the
9453db1458Sdrh ** type affinity that should be used for the comparison operator.
9553db1458Sdrh */
96e014a838Sdanielk1977 char sqlite3CompareAffinity(Expr *pExpr, char aff2){
97bf3b721fSdanielk1977   char aff1 = sqlite3ExprAffinity(pExpr);
98e014a838Sdanielk1977   if( aff1 && aff2 ){
998df447f0Sdrh     /* Both sides of the comparison are columns. If one has numeric
1008df447f0Sdrh     ** affinity, use that. Otherwise use no affinity.
101e014a838Sdanielk1977     */
1028a51256cSdrh     if( sqlite3IsNumericAffinity(aff1) || sqlite3IsNumericAffinity(aff2) ){
103e014a838Sdanielk1977       return SQLITE_AFF_NUMERIC;
104e014a838Sdanielk1977     }else{
105e014a838Sdanielk1977       return SQLITE_AFF_NONE;
106e014a838Sdanielk1977     }
107e014a838Sdanielk1977   }else if( !aff1 && !aff2 ){
1085f6a87b3Sdrh     /* Neither side of the comparison is a column.  Compare the
1095f6a87b3Sdrh     ** results directly.
110e014a838Sdanielk1977     */
1115f6a87b3Sdrh     return SQLITE_AFF_NONE;
112e014a838Sdanielk1977   }else{
113e014a838Sdanielk1977     /* One side is a column, the other is not. Use the columns affinity. */
114fe05af87Sdrh     assert( aff1==0 || aff2==0 );
115e014a838Sdanielk1977     return (aff1 + aff2);
116e014a838Sdanielk1977   }
117e014a838Sdanielk1977 }
118e014a838Sdanielk1977 
11953db1458Sdrh /*
12053db1458Sdrh ** pExpr is a comparison operator.  Return the type affinity that should
12153db1458Sdrh ** be applied to both operands prior to doing the comparison.
12253db1458Sdrh */
123e014a838Sdanielk1977 static char comparisonAffinity(Expr *pExpr){
124e014a838Sdanielk1977   char aff;
125e014a838Sdanielk1977   assert( pExpr->op==TK_EQ || pExpr->op==TK_IN || pExpr->op==TK_LT ||
126e014a838Sdanielk1977           pExpr->op==TK_GT || pExpr->op==TK_GE || pExpr->op==TK_LE ||
127e014a838Sdanielk1977           pExpr->op==TK_NE );
128e014a838Sdanielk1977   assert( pExpr->pLeft );
129bf3b721fSdanielk1977   aff = sqlite3ExprAffinity(pExpr->pLeft);
130e014a838Sdanielk1977   if( pExpr->pRight ){
131e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pRight, aff);
132e014a838Sdanielk1977   }
133e014a838Sdanielk1977   else if( pExpr->pSelect ){
134e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pSelect->pEList->a[0].pExpr, aff);
135e014a838Sdanielk1977   }
136e014a838Sdanielk1977   else if( !aff ){
137de087bd5Sdrh     aff = SQLITE_AFF_NONE;
138e014a838Sdanielk1977   }
139e014a838Sdanielk1977   return aff;
140e014a838Sdanielk1977 }
141e014a838Sdanielk1977 
142e014a838Sdanielk1977 /*
143e014a838Sdanielk1977 ** pExpr is a comparison expression, eg. '=', '<', IN(...) etc.
144e014a838Sdanielk1977 ** idx_affinity is the affinity of an indexed column. Return true
145e014a838Sdanielk1977 ** if the index with affinity idx_affinity may be used to implement
146e014a838Sdanielk1977 ** the comparison in pExpr.
147e014a838Sdanielk1977 */
148e014a838Sdanielk1977 int sqlite3IndexAffinityOk(Expr *pExpr, char idx_affinity){
149e014a838Sdanielk1977   char aff = comparisonAffinity(pExpr);
1508a51256cSdrh   switch( aff ){
1518a51256cSdrh     case SQLITE_AFF_NONE:
1528a51256cSdrh       return 1;
1538a51256cSdrh     case SQLITE_AFF_TEXT:
1548a51256cSdrh       return idx_affinity==SQLITE_AFF_TEXT;
1558a51256cSdrh     default:
1568a51256cSdrh       return sqlite3IsNumericAffinity(idx_affinity);
1578a51256cSdrh   }
158e014a838Sdanielk1977 }
159e014a838Sdanielk1977 
160a37cdde0Sdanielk1977 /*
16135573356Sdrh ** Return the P5 value that should be used for a binary comparison
162a37cdde0Sdanielk1977 ** opcode (OP_Eq, OP_Ge etc.) used to compare pExpr1 and pExpr2.
163a37cdde0Sdanielk1977 */
16435573356Sdrh static u8 binaryCompareP5(Expr *pExpr1, Expr *pExpr2, int jumpIfNull){
16535573356Sdrh   u8 aff = (char)sqlite3ExprAffinity(pExpr2);
16635573356Sdrh   aff = sqlite3CompareAffinity(pExpr1, aff) | jumpIfNull;
16735573356Sdrh   return aff;
168a37cdde0Sdanielk1977 }
169a37cdde0Sdanielk1977 
170a2e00042Sdrh /*
1710202b29eSdanielk1977 ** Return a pointer to the collation sequence that should be used by
1720202b29eSdanielk1977 ** a binary comparison operator comparing pLeft and pRight.
1730202b29eSdanielk1977 **
1740202b29eSdanielk1977 ** If the left hand expression has a collating sequence type, then it is
1750202b29eSdanielk1977 ** used. Otherwise the collation sequence for the right hand expression
1760202b29eSdanielk1977 ** is used, or the default (BINARY) if neither expression has a collating
1770202b29eSdanielk1977 ** type.
178bcbb04e5Sdanielk1977 **
179bcbb04e5Sdanielk1977 ** Argument pRight (but not pLeft) may be a null pointer. In this case,
180bcbb04e5Sdanielk1977 ** it is not considered.
1810202b29eSdanielk1977 */
182bcbb04e5Sdanielk1977 CollSeq *sqlite3BinaryCompareCollSeq(
183bcbb04e5Sdanielk1977   Parse *pParse,
184bcbb04e5Sdanielk1977   Expr *pLeft,
185bcbb04e5Sdanielk1977   Expr *pRight
186bcbb04e5Sdanielk1977 ){
187ec41ddacSdrh   CollSeq *pColl;
188ec41ddacSdrh   assert( pLeft );
189ec41ddacSdrh   if( pLeft->flags & EP_ExpCollate ){
190ec41ddacSdrh     assert( pLeft->pColl );
191ec41ddacSdrh     pColl = pLeft->pColl;
192bcbb04e5Sdanielk1977   }else if( pRight && pRight->flags & EP_ExpCollate ){
193ec41ddacSdrh     assert( pRight->pColl );
194ec41ddacSdrh     pColl = pRight->pColl;
195ec41ddacSdrh   }else{
196ec41ddacSdrh     pColl = sqlite3ExprCollSeq(pParse, pLeft);
1970202b29eSdanielk1977     if( !pColl ){
1987cedc8d4Sdanielk1977       pColl = sqlite3ExprCollSeq(pParse, pRight);
1990202b29eSdanielk1977     }
200ec41ddacSdrh   }
2010202b29eSdanielk1977   return pColl;
2020202b29eSdanielk1977 }
2030202b29eSdanielk1977 
2040202b29eSdanielk1977 /*
205da250ea5Sdrh ** Generate the operands for a comparison operation.  Before
206da250ea5Sdrh ** generating the code for each operand, set the EP_AnyAff
207da250ea5Sdrh ** flag on the expression so that it will be able to used a
208da250ea5Sdrh ** cached column value that has previously undergone an
209da250ea5Sdrh ** affinity change.
210da250ea5Sdrh */
211da250ea5Sdrh static void codeCompareOperands(
212da250ea5Sdrh   Parse *pParse,    /* Parsing and code generating context */
213da250ea5Sdrh   Expr *pLeft,      /* The left operand */
214da250ea5Sdrh   int *pRegLeft,    /* Register where left operand is stored */
215da250ea5Sdrh   int *pFreeLeft,   /* Free this register when done */
216da250ea5Sdrh   Expr *pRight,     /* The right operand */
217da250ea5Sdrh   int *pRegRight,   /* Register where right operand is stored */
218da250ea5Sdrh   int *pFreeRight   /* Write temp register for right operand there */
219da250ea5Sdrh ){
220da250ea5Sdrh   while( pLeft->op==TK_UPLUS ) pLeft = pLeft->pLeft;
221da250ea5Sdrh   pLeft->flags |= EP_AnyAff;
222da250ea5Sdrh   *pRegLeft = sqlite3ExprCodeTemp(pParse, pLeft, pFreeLeft);
223da250ea5Sdrh   while( pRight->op==TK_UPLUS ) pRight = pRight->pLeft;
224da250ea5Sdrh   pRight->flags |= EP_AnyAff;
225da250ea5Sdrh   *pRegRight = sqlite3ExprCodeTemp(pParse, pRight, pFreeRight);
226da250ea5Sdrh }
227da250ea5Sdrh 
228da250ea5Sdrh /*
229be5c89acSdrh ** Generate code for a comparison operator.
230be5c89acSdrh */
231be5c89acSdrh static int codeCompare(
232be5c89acSdrh   Parse *pParse,    /* The parsing (and code generating) context */
233be5c89acSdrh   Expr *pLeft,      /* The left operand */
234be5c89acSdrh   Expr *pRight,     /* The right operand */
235be5c89acSdrh   int opcode,       /* The comparison opcode */
23635573356Sdrh   int in1, int in2, /* Register holding operands */
237be5c89acSdrh   int dest,         /* Jump here if true.  */
238be5c89acSdrh   int jumpIfNull    /* If true, jump if either operand is NULL */
239be5c89acSdrh ){
24035573356Sdrh   int p5;
24135573356Sdrh   int addr;
24235573356Sdrh   CollSeq *p4;
24335573356Sdrh 
24435573356Sdrh   p4 = sqlite3BinaryCompareCollSeq(pParse, pLeft, pRight);
24535573356Sdrh   p5 = binaryCompareP5(pLeft, pRight, jumpIfNull);
24635573356Sdrh   addr = sqlite3VdbeAddOp4(pParse->pVdbe, opcode, in2, dest, in1,
24735573356Sdrh                            (void*)p4, P4_COLLSEQ);
24835573356Sdrh   sqlite3VdbeChangeP5(pParse->pVdbe, p5);
2492f7794c1Sdrh   if( p5 & SQLITE_AFF_MASK ){
250da250ea5Sdrh     sqlite3ExprCacheAffinityChange(pParse, in1, 1);
251da250ea5Sdrh     sqlite3ExprCacheAffinityChange(pParse, in2, 1);
2522f7794c1Sdrh   }
25335573356Sdrh   return addr;
254be5c89acSdrh }
255be5c89acSdrh 
2564b5255acSdanielk1977 #if SQLITE_MAX_EXPR_DEPTH>0
2574b5255acSdanielk1977 /*
2584b5255acSdanielk1977 ** Check that argument nHeight is less than or equal to the maximum
2594b5255acSdanielk1977 ** expression depth allowed. If it is not, leave an error message in
2604b5255acSdanielk1977 ** pParse.
2614b5255acSdanielk1977 */
2624b5255acSdanielk1977 static int checkExprHeight(Parse *pParse, int nHeight){
2634b5255acSdanielk1977   int rc = SQLITE_OK;
2644b5255acSdanielk1977   int mxHeight = pParse->db->aLimit[SQLITE_LIMIT_EXPR_DEPTH];
2654b5255acSdanielk1977   if( nHeight>mxHeight ){
2664b5255acSdanielk1977     sqlite3ErrorMsg(pParse,
2674b5255acSdanielk1977        "Expression tree is too large (maximum depth %d)", mxHeight
2684b5255acSdanielk1977     );
2694b5255acSdanielk1977     rc = SQLITE_ERROR;
2704b5255acSdanielk1977   }
2714b5255acSdanielk1977   return rc;
2724b5255acSdanielk1977 }
2734b5255acSdanielk1977 
2744b5255acSdanielk1977 /* The following three functions, heightOfExpr(), heightOfExprList()
2754b5255acSdanielk1977 ** and heightOfSelect(), are used to determine the maximum height
2764b5255acSdanielk1977 ** of any expression tree referenced by the structure passed as the
2774b5255acSdanielk1977 ** first argument.
2784b5255acSdanielk1977 **
2794b5255acSdanielk1977 ** If this maximum height is greater than the current value pointed
2804b5255acSdanielk1977 ** to by pnHeight, the second parameter, then set *pnHeight to that
2814b5255acSdanielk1977 ** value.
2824b5255acSdanielk1977 */
2834b5255acSdanielk1977 static void heightOfExpr(Expr *p, int *pnHeight){
2844b5255acSdanielk1977   if( p ){
2854b5255acSdanielk1977     if( p->nHeight>*pnHeight ){
2864b5255acSdanielk1977       *pnHeight = p->nHeight;
2874b5255acSdanielk1977     }
2884b5255acSdanielk1977   }
2894b5255acSdanielk1977 }
2904b5255acSdanielk1977 static void heightOfExprList(ExprList *p, int *pnHeight){
2914b5255acSdanielk1977   if( p ){
2924b5255acSdanielk1977     int i;
2934b5255acSdanielk1977     for(i=0; i<p->nExpr; i++){
2944b5255acSdanielk1977       heightOfExpr(p->a[i].pExpr, pnHeight);
2954b5255acSdanielk1977     }
2964b5255acSdanielk1977   }
2974b5255acSdanielk1977 }
2984b5255acSdanielk1977 static void heightOfSelect(Select *p, int *pnHeight){
2994b5255acSdanielk1977   if( p ){
3004b5255acSdanielk1977     heightOfExpr(p->pWhere, pnHeight);
3014b5255acSdanielk1977     heightOfExpr(p->pHaving, pnHeight);
3024b5255acSdanielk1977     heightOfExpr(p->pLimit, pnHeight);
3034b5255acSdanielk1977     heightOfExpr(p->pOffset, pnHeight);
3044b5255acSdanielk1977     heightOfExprList(p->pEList, pnHeight);
3054b5255acSdanielk1977     heightOfExprList(p->pGroupBy, pnHeight);
3064b5255acSdanielk1977     heightOfExprList(p->pOrderBy, pnHeight);
3074b5255acSdanielk1977     heightOfSelect(p->pPrior, pnHeight);
3084b5255acSdanielk1977   }
3094b5255acSdanielk1977 }
3104b5255acSdanielk1977 
3114b5255acSdanielk1977 /*
3124b5255acSdanielk1977 ** Set the Expr.nHeight variable in the structure passed as an
3134b5255acSdanielk1977 ** argument. An expression with no children, Expr.pList or
3144b5255acSdanielk1977 ** Expr.pSelect member has a height of 1. Any other expression
3154b5255acSdanielk1977 ** has a height equal to the maximum height of any other
3164b5255acSdanielk1977 ** referenced Expr plus one.
3174b5255acSdanielk1977 */
3184b5255acSdanielk1977 static void exprSetHeight(Expr *p){
3194b5255acSdanielk1977   int nHeight = 0;
3204b5255acSdanielk1977   heightOfExpr(p->pLeft, &nHeight);
3214b5255acSdanielk1977   heightOfExpr(p->pRight, &nHeight);
3224b5255acSdanielk1977   heightOfExprList(p->pList, &nHeight);
3234b5255acSdanielk1977   heightOfSelect(p->pSelect, &nHeight);
3244b5255acSdanielk1977   p->nHeight = nHeight + 1;
3254b5255acSdanielk1977 }
3264b5255acSdanielk1977 
3274b5255acSdanielk1977 /*
3284b5255acSdanielk1977 ** Set the Expr.nHeight variable using the exprSetHeight() function. If
3294b5255acSdanielk1977 ** the height is greater than the maximum allowed expression depth,
3304b5255acSdanielk1977 ** leave an error in pParse.
3314b5255acSdanielk1977 */
3324b5255acSdanielk1977 void sqlite3ExprSetHeight(Parse *pParse, Expr *p){
3334b5255acSdanielk1977   exprSetHeight(p);
3344b5255acSdanielk1977   checkExprHeight(pParse, p->nHeight);
3354b5255acSdanielk1977 }
3364b5255acSdanielk1977 
3374b5255acSdanielk1977 /*
3384b5255acSdanielk1977 ** Return the maximum height of any expression tree referenced
3394b5255acSdanielk1977 ** by the select statement passed as an argument.
3404b5255acSdanielk1977 */
3414b5255acSdanielk1977 int sqlite3SelectExprHeight(Select *p){
3424b5255acSdanielk1977   int nHeight = 0;
3434b5255acSdanielk1977   heightOfSelect(p, &nHeight);
3444b5255acSdanielk1977   return nHeight;
3454b5255acSdanielk1977 }
3464b5255acSdanielk1977 #else
3474b5255acSdanielk1977   #define checkExprHeight(x,y)
3484b5255acSdanielk1977   #define exprSetHeight(y)
3494b5255acSdanielk1977 #endif /* SQLITE_MAX_EXPR_DEPTH>0 */
3504b5255acSdanielk1977 
351be5c89acSdrh /*
352a76b5dfcSdrh ** Construct a new expression node and return a pointer to it.  Memory
35317435752Sdrh ** for this node is obtained from sqlite3_malloc().  The calling function
354a76b5dfcSdrh ** is responsible for making sure the node eventually gets freed.
355a76b5dfcSdrh */
35617435752Sdrh Expr *sqlite3Expr(
357a1644fd8Sdanielk1977   sqlite3 *db,            /* Handle for sqlite3DbMallocZero() (may be null) */
35817435752Sdrh   int op,                 /* Expression opcode */
35917435752Sdrh   Expr *pLeft,            /* Left operand */
36017435752Sdrh   Expr *pRight,           /* Right operand */
36117435752Sdrh   const Token *pToken     /* Argument token */
36217435752Sdrh ){
363a76b5dfcSdrh   Expr *pNew;
36426e4a8b1Sdrh   pNew = sqlite3DbMallocZero(db, sizeof(Expr));
365a76b5dfcSdrh   if( pNew==0 ){
366d5d56523Sdanielk1977     /* When malloc fails, delete pLeft and pRight. Expressions passed to
367d5d56523Sdanielk1977     ** this function must always be allocated with sqlite3Expr() for this
368d5d56523Sdanielk1977     ** reason.
369d5d56523Sdanielk1977     */
370d5d56523Sdanielk1977     sqlite3ExprDelete(pLeft);
371d5d56523Sdanielk1977     sqlite3ExprDelete(pRight);
372a76b5dfcSdrh     return 0;
373a76b5dfcSdrh   }
374a76b5dfcSdrh   pNew->op = op;
375a76b5dfcSdrh   pNew->pLeft = pLeft;
376a76b5dfcSdrh   pNew->pRight = pRight;
377a58fdfb1Sdanielk1977   pNew->iAgg = -1;
378a76b5dfcSdrh   if( pToken ){
3794b59ab5eSdrh     assert( pToken->dyn==0 );
380145716b3Sdrh     pNew->span = pNew->token = *pToken;
381a34001c9Sdrh   }else if( pLeft ){
382a34001c9Sdrh     if( pRight ){
3834adee20fSdanielk1977       sqlite3ExprSpan(pNew, &pLeft->span, &pRight->span);
3845ffb3ac8Sdrh       if( pRight->flags & EP_ExpCollate ){
385a34001c9Sdrh         pNew->flags |= EP_ExpCollate;
386a34001c9Sdrh         pNew->pColl = pRight->pColl;
387a34001c9Sdrh       }
388a34001c9Sdrh     }
3895ffb3ac8Sdrh     if( pLeft->flags & EP_ExpCollate ){
390a34001c9Sdrh       pNew->flags |= EP_ExpCollate;
391a34001c9Sdrh       pNew->pColl = pLeft->pColl;
392a34001c9Sdrh     }
393a76b5dfcSdrh   }
394fc976065Sdanielk1977 
3954b5255acSdanielk1977   exprSetHeight(pNew);
396a76b5dfcSdrh   return pNew;
397a76b5dfcSdrh }
398a76b5dfcSdrh 
399a76b5dfcSdrh /*
40017435752Sdrh ** Works like sqlite3Expr() except that it takes an extra Parse*
40117435752Sdrh ** argument and notifies the associated connection object if malloc fails.
402206f3d96Sdrh */
40317435752Sdrh Expr *sqlite3PExpr(
40417435752Sdrh   Parse *pParse,          /* Parsing context */
40517435752Sdrh   int op,                 /* Expression opcode */
40617435752Sdrh   Expr *pLeft,            /* Left operand */
40717435752Sdrh   Expr *pRight,           /* Right operand */
40817435752Sdrh   const Token *pToken     /* Argument token */
40917435752Sdrh ){
4104b5255acSdanielk1977   Expr *p = sqlite3Expr(pParse->db, op, pLeft, pRight, pToken);
4114b5255acSdanielk1977   if( p ){
4124b5255acSdanielk1977     checkExprHeight(pParse, p->nHeight);
4134b5255acSdanielk1977   }
4144b5255acSdanielk1977   return p;
415206f3d96Sdrh }
416206f3d96Sdrh 
417206f3d96Sdrh /*
4184e0cff60Sdrh ** When doing a nested parse, you can include terms in an expression
419b7654111Sdrh ** that look like this:   #1 #2 ...  These terms refer to registers
420b7654111Sdrh ** in the virtual machine.  #N is the N-th register.
4214e0cff60Sdrh **
4224e0cff60Sdrh ** This routine is called by the parser to deal with on of those terms.
4234e0cff60Sdrh ** It immediately generates code to store the value in a memory location.
4244e0cff60Sdrh ** The returns an expression that will code to extract the value from
4254e0cff60Sdrh ** that memory location as needed.
4264e0cff60Sdrh */
4274e0cff60Sdrh Expr *sqlite3RegisterExpr(Parse *pParse, Token *pToken){
4284e0cff60Sdrh   Vdbe *v = pParse->pVdbe;
4294e0cff60Sdrh   Expr *p;
4304e0cff60Sdrh   if( pParse->nested==0 ){
4314e0cff60Sdrh     sqlite3ErrorMsg(pParse, "near \"%T\": syntax error", pToken);
432a1644fd8Sdanielk1977     return sqlite3PExpr(pParse, TK_NULL, 0, 0, 0);
4334e0cff60Sdrh   }
434bb7ac00bSdrh   if( v==0 ) return 0;
435a1644fd8Sdanielk1977   p = sqlite3PExpr(pParse, TK_REGISTER, 0, 0, pToken);
43673c42a13Sdrh   if( p==0 ){
43773c42a13Sdrh     return 0;  /* Malloc failed */
43873c42a13Sdrh   }
439b7654111Sdrh   p->iTable = atoi((char*)&pToken->z[1]);
4404e0cff60Sdrh   return p;
4414e0cff60Sdrh }
4424e0cff60Sdrh 
4434e0cff60Sdrh /*
44491bb0eedSdrh ** Join two expressions using an AND operator.  If either expression is
44591bb0eedSdrh ** NULL, then just return the other expression.
44691bb0eedSdrh */
4471e536953Sdanielk1977 Expr *sqlite3ExprAnd(sqlite3 *db, Expr *pLeft, Expr *pRight){
44891bb0eedSdrh   if( pLeft==0 ){
44991bb0eedSdrh     return pRight;
45091bb0eedSdrh   }else if( pRight==0 ){
45191bb0eedSdrh     return pLeft;
45291bb0eedSdrh   }else{
453880c15beSdanielk1977     return sqlite3Expr(db, TK_AND, pLeft, pRight, 0);
45491bb0eedSdrh   }
45591bb0eedSdrh }
45691bb0eedSdrh 
45791bb0eedSdrh /*
4586977fea8Sdrh ** Set the Expr.span field of the given expression to span all
459a76b5dfcSdrh ** text between the two given tokens.
460a76b5dfcSdrh */
4614adee20fSdanielk1977 void sqlite3ExprSpan(Expr *pExpr, Token *pLeft, Token *pRight){
4624efc4754Sdrh   assert( pRight!=0 );
4634efc4754Sdrh   assert( pLeft!=0 );
464f3a65f7eSdrh   if( pExpr && pRight->z && pLeft->z ){
465ad6d9460Sdrh     assert( pLeft->dyn==0 || pLeft->z[pLeft->n]==0 );
466145716b3Sdrh     if( pLeft->dyn==0 && pRight->dyn==0 ){
4676977fea8Sdrh       pExpr->span.z = pLeft->z;
46897903fefSdrh       pExpr->span.n = pRight->n + (pRight->z - pLeft->z);
4694b59ab5eSdrh     }else{
4706977fea8Sdrh       pExpr->span.z = 0;
4714b59ab5eSdrh     }
472a76b5dfcSdrh   }
473a76b5dfcSdrh }
474a76b5dfcSdrh 
475a76b5dfcSdrh /*
476a76b5dfcSdrh ** Construct a new expression node for a function with multiple
477a76b5dfcSdrh ** arguments.
478a76b5dfcSdrh */
47917435752Sdrh Expr *sqlite3ExprFunction(Parse *pParse, ExprList *pList, Token *pToken){
480a76b5dfcSdrh   Expr *pNew;
4814b202ae2Sdanielk1977   assert( pToken );
48217435752Sdrh   pNew = sqlite3DbMallocZero(pParse->db, sizeof(Expr) );
483a76b5dfcSdrh   if( pNew==0 ){
484d5d56523Sdanielk1977     sqlite3ExprListDelete(pList); /* Avoid leaking memory when malloc fails */
485a76b5dfcSdrh     return 0;
486a76b5dfcSdrh   }
487a76b5dfcSdrh   pNew->op = TK_FUNCTION;
488a76b5dfcSdrh   pNew->pList = pList;
4894b59ab5eSdrh   assert( pToken->dyn==0 );
490a76b5dfcSdrh   pNew->token = *pToken;
4916977fea8Sdrh   pNew->span = pNew->token;
492fc976065Sdanielk1977 
4934b5255acSdanielk1977   sqlite3ExprSetHeight(pParse, pNew);
494a76b5dfcSdrh   return pNew;
495a76b5dfcSdrh }
496a76b5dfcSdrh 
497a76b5dfcSdrh /*
498fa6bc000Sdrh ** Assign a variable number to an expression that encodes a wildcard
499fa6bc000Sdrh ** in the original SQL statement.
500fa6bc000Sdrh **
501fa6bc000Sdrh ** Wildcards consisting of a single "?" are assigned the next sequential
502fa6bc000Sdrh ** variable number.
503fa6bc000Sdrh **
504fa6bc000Sdrh ** Wildcards of the form "?nnn" are assigned the number "nnn".  We make
505fa6bc000Sdrh ** sure "nnn" is not too be to avoid a denial of service attack when
506fa6bc000Sdrh ** the SQL statement comes from an external source.
507fa6bc000Sdrh **
508fa6bc000Sdrh ** Wildcards of the form ":aaa" or "$aaa" are assigned the same number
509fa6bc000Sdrh ** as the previous instance of the same wildcard.  Or if this is the first
510fa6bc000Sdrh ** instance of the wildcard, the next sequenial variable number is
511fa6bc000Sdrh ** assigned.
512fa6bc000Sdrh */
513fa6bc000Sdrh void sqlite3ExprAssignVarNumber(Parse *pParse, Expr *pExpr){
514fa6bc000Sdrh   Token *pToken;
51517435752Sdrh   sqlite3 *db = pParse->db;
51617435752Sdrh 
517fa6bc000Sdrh   if( pExpr==0 ) return;
518fa6bc000Sdrh   pToken = &pExpr->token;
519fa6bc000Sdrh   assert( pToken->n>=1 );
520fa6bc000Sdrh   assert( pToken->z!=0 );
521fa6bc000Sdrh   assert( pToken->z[0]!=0 );
522fa6bc000Sdrh   if( pToken->n==1 ){
523fa6bc000Sdrh     /* Wildcard of the form "?".  Assign the next variable number */
524fa6bc000Sdrh     pExpr->iTable = ++pParse->nVar;
525fa6bc000Sdrh   }else if( pToken->z[0]=='?' ){
526fa6bc000Sdrh     /* Wildcard of the form "?nnn".  Convert "nnn" to an integer and
527fa6bc000Sdrh     ** use it as the variable number */
528fa6bc000Sdrh     int i;
5292646da7eSdrh     pExpr->iTable = i = atoi((char*)&pToken->z[1]);
530c5499befSdrh     testcase( i==0 );
531c5499befSdrh     testcase( i==1 );
532c5499befSdrh     testcase( i==db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER]-1 );
533c5499befSdrh     testcase( i==db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER] );
534bb4957f8Sdrh     if( i<1 || i>db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER] ){
535fa6bc000Sdrh       sqlite3ErrorMsg(pParse, "variable number must be between ?1 and ?%d",
536bb4957f8Sdrh           db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER]);
537fa6bc000Sdrh     }
538fa6bc000Sdrh     if( i>pParse->nVar ){
539fa6bc000Sdrh       pParse->nVar = i;
540fa6bc000Sdrh     }
541fa6bc000Sdrh   }else{
542fa6bc000Sdrh     /* Wildcards of the form ":aaa" or "$aaa".  Reuse the same variable
543fa6bc000Sdrh     ** number as the prior appearance of the same name, or if the name
544fa6bc000Sdrh     ** has never appeared before, reuse the same variable number
545fa6bc000Sdrh     */
546fa6bc000Sdrh     int i, n;
547fa6bc000Sdrh     n = pToken->n;
548fa6bc000Sdrh     for(i=0; i<pParse->nVarExpr; i++){
549fa6bc000Sdrh       Expr *pE;
550fa6bc000Sdrh       if( (pE = pParse->apVarExpr[i])!=0
551fa6bc000Sdrh           && pE->token.n==n
552fa6bc000Sdrh           && memcmp(pE->token.z, pToken->z, n)==0 ){
553fa6bc000Sdrh         pExpr->iTable = pE->iTable;
554fa6bc000Sdrh         break;
555fa6bc000Sdrh       }
556fa6bc000Sdrh     }
557fa6bc000Sdrh     if( i>=pParse->nVarExpr ){
558fa6bc000Sdrh       pExpr->iTable = ++pParse->nVar;
559fa6bc000Sdrh       if( pParse->nVarExpr>=pParse->nVarExprAlloc-1 ){
560fa6bc000Sdrh         pParse->nVarExprAlloc += pParse->nVarExprAlloc + 10;
56117435752Sdrh         pParse->apVarExpr =
56217435752Sdrh             sqlite3DbReallocOrFree(
56317435752Sdrh               db,
56417435752Sdrh               pParse->apVarExpr,
56517435752Sdrh               pParse->nVarExprAlloc*sizeof(pParse->apVarExpr[0])
56617435752Sdrh             );
567fa6bc000Sdrh       }
56817435752Sdrh       if( !db->mallocFailed ){
569fa6bc000Sdrh         assert( pParse->apVarExpr!=0 );
570fa6bc000Sdrh         pParse->apVarExpr[pParse->nVarExpr++] = pExpr;
571fa6bc000Sdrh       }
572fa6bc000Sdrh     }
573fa6bc000Sdrh   }
574bb4957f8Sdrh   if( !pParse->nErr && pParse->nVar>db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER] ){
575832b2664Sdanielk1977     sqlite3ErrorMsg(pParse, "too many SQL variables");
576832b2664Sdanielk1977   }
577fa6bc000Sdrh }
578fa6bc000Sdrh 
579fa6bc000Sdrh /*
580a2e00042Sdrh ** Recursively delete an expression tree.
581a2e00042Sdrh */
5824adee20fSdanielk1977 void sqlite3ExprDelete(Expr *p){
583a2e00042Sdrh   if( p==0 ) return;
58417435752Sdrh   if( p->span.dyn ) sqlite3_free((char*)p->span.z);
58517435752Sdrh   if( p->token.dyn ) sqlite3_free((char*)p->token.z);
5864adee20fSdanielk1977   sqlite3ExprDelete(p->pLeft);
5874adee20fSdanielk1977   sqlite3ExprDelete(p->pRight);
5884adee20fSdanielk1977   sqlite3ExprListDelete(p->pList);
5894adee20fSdanielk1977   sqlite3SelectDelete(p->pSelect);
59017435752Sdrh   sqlite3_free(p);
591a2e00042Sdrh }
592a2e00042Sdrh 
593d2687b77Sdrh /*
594d2687b77Sdrh ** The Expr.token field might be a string literal that is quoted.
595d2687b77Sdrh ** If so, remove the quotation marks.
596d2687b77Sdrh */
59717435752Sdrh void sqlite3DequoteExpr(sqlite3 *db, Expr *p){
598d2687b77Sdrh   if( ExprHasAnyProperty(p, EP_Dequoted) ){
599d2687b77Sdrh     return;
600d2687b77Sdrh   }
601d2687b77Sdrh   ExprSetProperty(p, EP_Dequoted);
602d2687b77Sdrh   if( p->token.dyn==0 ){
60317435752Sdrh     sqlite3TokenCopy(db, &p->token, &p->token);
604d2687b77Sdrh   }
605d2687b77Sdrh   sqlite3Dequote((char*)p->token.z);
606d2687b77Sdrh }
607d2687b77Sdrh 
608a76b5dfcSdrh 
609a76b5dfcSdrh /*
610ff78bd2fSdrh ** The following group of routines make deep copies of expressions,
611ff78bd2fSdrh ** expression lists, ID lists, and select statements.  The copies can
612ff78bd2fSdrh ** be deleted (by being passed to their respective ...Delete() routines)
613ff78bd2fSdrh ** without effecting the originals.
614ff78bd2fSdrh **
6154adee20fSdanielk1977 ** The expression list, ID, and source lists return by sqlite3ExprListDup(),
6164adee20fSdanielk1977 ** sqlite3IdListDup(), and sqlite3SrcListDup() can not be further expanded
617ad3cab52Sdrh ** by subsequent calls to sqlite*ListAppend() routines.
618ff78bd2fSdrh **
619ad3cab52Sdrh ** Any tables that the SrcList might point to are not duplicated.
620ff78bd2fSdrh */
6211e536953Sdanielk1977 Expr *sqlite3ExprDup(sqlite3 *db, Expr *p){
622ff78bd2fSdrh   Expr *pNew;
623ff78bd2fSdrh   if( p==0 ) return 0;
62417435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*p) );
625ff78bd2fSdrh   if( pNew==0 ) return 0;
6263b167c75Sdrh   memcpy(pNew, p, sizeof(*pNew));
6276977fea8Sdrh   if( p->token.z!=0 ){
62817435752Sdrh     pNew->token.z = (u8*)sqlite3DbStrNDup(db, (char*)p->token.z, p->token.n);
6294b59ab5eSdrh     pNew->token.dyn = 1;
6304b59ab5eSdrh   }else{
6314efc4754Sdrh     assert( pNew->token.z==0 );
6324b59ab5eSdrh   }
6336977fea8Sdrh   pNew->span.z = 0;
63417435752Sdrh   pNew->pLeft = sqlite3ExprDup(db, p->pLeft);
63517435752Sdrh   pNew->pRight = sqlite3ExprDup(db, p->pRight);
63617435752Sdrh   pNew->pList = sqlite3ExprListDup(db, p->pList);
63717435752Sdrh   pNew->pSelect = sqlite3SelectDup(db, p->pSelect);
638ff78bd2fSdrh   return pNew;
639ff78bd2fSdrh }
64017435752Sdrh void sqlite3TokenCopy(sqlite3 *db, Token *pTo, Token *pFrom){
64117435752Sdrh   if( pTo->dyn ) sqlite3_free((char*)pTo->z);
6424b59ab5eSdrh   if( pFrom->z ){
6434b59ab5eSdrh     pTo->n = pFrom->n;
64417435752Sdrh     pTo->z = (u8*)sqlite3DbStrNDup(db, (char*)pFrom->z, pFrom->n);
6454b59ab5eSdrh     pTo->dyn = 1;
6464b59ab5eSdrh   }else{
6474b59ab5eSdrh     pTo->z = 0;
6484b59ab5eSdrh   }
6494b59ab5eSdrh }
65017435752Sdrh ExprList *sqlite3ExprListDup(sqlite3 *db, ExprList *p){
651ff78bd2fSdrh   ExprList *pNew;
652145716b3Sdrh   struct ExprList_item *pItem, *pOldItem;
653ff78bd2fSdrh   int i;
654ff78bd2fSdrh   if( p==0 ) return 0;
65517435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*pNew) );
656ff78bd2fSdrh   if( pNew==0 ) return 0;
65731dad9daSdanielk1977   pNew->iECursor = 0;
6584305d103Sdrh   pNew->nExpr = pNew->nAlloc = p->nExpr;
65917435752Sdrh   pNew->a = pItem = sqlite3DbMallocRaw(db,  p->nExpr*sizeof(p->a[0]) );
660e0048400Sdanielk1977   if( pItem==0 ){
66117435752Sdrh     sqlite3_free(pNew);
662e0048400Sdanielk1977     return 0;
663e0048400Sdanielk1977   }
664145716b3Sdrh   pOldItem = p->a;
665145716b3Sdrh   for(i=0; i<p->nExpr; i++, pItem++, pOldItem++){
6664b59ab5eSdrh     Expr *pNewExpr, *pOldExpr;
66717435752Sdrh     pItem->pExpr = pNewExpr = sqlite3ExprDup(db, pOldExpr = pOldItem->pExpr);
6686977fea8Sdrh     if( pOldExpr->span.z!=0 && pNewExpr ){
6696977fea8Sdrh       /* Always make a copy of the span for top-level expressions in the
6704b59ab5eSdrh       ** expression list.  The logic in SELECT processing that determines
6714b59ab5eSdrh       ** the names of columns in the result set needs this information */
67217435752Sdrh       sqlite3TokenCopy(db, &pNewExpr->span, &pOldExpr->span);
6734b59ab5eSdrh     }
6741f3e905cSdrh     assert( pNewExpr==0 || pNewExpr->span.z!=0
6756f7adc8aSdrh             || pOldExpr->span.z==0
67617435752Sdrh             || db->mallocFailed );
67717435752Sdrh     pItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
678145716b3Sdrh     pItem->sortOrder = pOldItem->sortOrder;
679145716b3Sdrh     pItem->isAgg = pOldItem->isAgg;
6803e7bc9caSdrh     pItem->done = 0;
681ff78bd2fSdrh   }
682ff78bd2fSdrh   return pNew;
683ff78bd2fSdrh }
68493758c8dSdanielk1977 
68593758c8dSdanielk1977 /*
68693758c8dSdanielk1977 ** If cursors, triggers, views and subqueries are all omitted from
68793758c8dSdanielk1977 ** the build, then none of the following routines, except for
68893758c8dSdanielk1977 ** sqlite3SelectDup(), can be called. sqlite3SelectDup() is sometimes
68993758c8dSdanielk1977 ** called with a NULL argument.
69093758c8dSdanielk1977 */
6916a67fe8eSdanielk1977 #if !defined(SQLITE_OMIT_VIEW) || !defined(SQLITE_OMIT_TRIGGER) \
6926a67fe8eSdanielk1977  || !defined(SQLITE_OMIT_SUBQUERY)
69317435752Sdrh SrcList *sqlite3SrcListDup(sqlite3 *db, SrcList *p){
694ad3cab52Sdrh   SrcList *pNew;
695ad3cab52Sdrh   int i;
696113088ecSdrh   int nByte;
697ad3cab52Sdrh   if( p==0 ) return 0;
698113088ecSdrh   nByte = sizeof(*p) + (p->nSrc>0 ? sizeof(p->a[0]) * (p->nSrc-1) : 0);
69917435752Sdrh   pNew = sqlite3DbMallocRaw(db, nByte );
700ad3cab52Sdrh   if( pNew==0 ) return 0;
7014305d103Sdrh   pNew->nSrc = pNew->nAlloc = p->nSrc;
702ad3cab52Sdrh   for(i=0; i<p->nSrc; i++){
7034efc4754Sdrh     struct SrcList_item *pNewItem = &pNew->a[i];
7044efc4754Sdrh     struct SrcList_item *pOldItem = &p->a[i];
705ed8a3bb1Sdrh     Table *pTab;
70617435752Sdrh     pNewItem->zDatabase = sqlite3DbStrDup(db, pOldItem->zDatabase);
70717435752Sdrh     pNewItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
70817435752Sdrh     pNewItem->zAlias = sqlite3DbStrDup(db, pOldItem->zAlias);
7094efc4754Sdrh     pNewItem->jointype = pOldItem->jointype;
7104efc4754Sdrh     pNewItem->iCursor = pOldItem->iCursor;
7111787ccabSdanielk1977     pNewItem->isPopulated = pOldItem->isPopulated;
712ed8a3bb1Sdrh     pTab = pNewItem->pTab = pOldItem->pTab;
713ed8a3bb1Sdrh     if( pTab ){
714ed8a3bb1Sdrh       pTab->nRef++;
715a1cb183dSdanielk1977     }
71617435752Sdrh     pNewItem->pSelect = sqlite3SelectDup(db, pOldItem->pSelect);
71717435752Sdrh     pNewItem->pOn = sqlite3ExprDup(db, pOldItem->pOn);
71817435752Sdrh     pNewItem->pUsing = sqlite3IdListDup(db, pOldItem->pUsing);
7196c18b6e0Sdanielk1977     pNewItem->colUsed = pOldItem->colUsed;
720ad3cab52Sdrh   }
721ad3cab52Sdrh   return pNew;
722ad3cab52Sdrh }
72317435752Sdrh IdList *sqlite3IdListDup(sqlite3 *db, IdList *p){
724ff78bd2fSdrh   IdList *pNew;
725ff78bd2fSdrh   int i;
726ff78bd2fSdrh   if( p==0 ) return 0;
72717435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*pNew) );
728ff78bd2fSdrh   if( pNew==0 ) return 0;
7294305d103Sdrh   pNew->nId = pNew->nAlloc = p->nId;
73017435752Sdrh   pNew->a = sqlite3DbMallocRaw(db, p->nId*sizeof(p->a[0]) );
731d5d56523Sdanielk1977   if( pNew->a==0 ){
73217435752Sdrh     sqlite3_free(pNew);
733d5d56523Sdanielk1977     return 0;
734d5d56523Sdanielk1977   }
735ff78bd2fSdrh   for(i=0; i<p->nId; i++){
7364efc4754Sdrh     struct IdList_item *pNewItem = &pNew->a[i];
7374efc4754Sdrh     struct IdList_item *pOldItem = &p->a[i];
73817435752Sdrh     pNewItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
7394efc4754Sdrh     pNewItem->idx = pOldItem->idx;
740ff78bd2fSdrh   }
741ff78bd2fSdrh   return pNew;
742ff78bd2fSdrh }
74317435752Sdrh Select *sqlite3SelectDup(sqlite3 *db, Select *p){
744ff78bd2fSdrh   Select *pNew;
745ff78bd2fSdrh   if( p==0 ) return 0;
74617435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*p) );
747ff78bd2fSdrh   if( pNew==0 ) return 0;
748ff78bd2fSdrh   pNew->isDistinct = p->isDistinct;
74917435752Sdrh   pNew->pEList = sqlite3ExprListDup(db, p->pEList);
75017435752Sdrh   pNew->pSrc = sqlite3SrcListDup(db, p->pSrc);
75117435752Sdrh   pNew->pWhere = sqlite3ExprDup(db, p->pWhere);
75217435752Sdrh   pNew->pGroupBy = sqlite3ExprListDup(db, p->pGroupBy);
75317435752Sdrh   pNew->pHaving = sqlite3ExprDup(db, p->pHaving);
75417435752Sdrh   pNew->pOrderBy = sqlite3ExprListDup(db, p->pOrderBy);
755ff78bd2fSdrh   pNew->op = p->op;
75617435752Sdrh   pNew->pPrior = sqlite3SelectDup(db, p->pPrior);
75717435752Sdrh   pNew->pLimit = sqlite3ExprDup(db, p->pLimit);
75817435752Sdrh   pNew->pOffset = sqlite3ExprDup(db, p->pOffset);
75992b01d53Sdrh   pNew->iLimit = 0;
76092b01d53Sdrh   pNew->iOffset = 0;
761a1cb183dSdanielk1977   pNew->isResolved = p->isResolved;
762a1cb183dSdanielk1977   pNew->isAgg = p->isAgg;
763b9bb7c18Sdrh   pNew->usesEphm = 0;
7648e647b81Sdrh   pNew->disallowOrderBy = 0;
7650342b1f5Sdrh   pNew->pRightmost = 0;
766b9bb7c18Sdrh   pNew->addrOpenEphm[0] = -1;
767b9bb7c18Sdrh   pNew->addrOpenEphm[1] = -1;
768b9bb7c18Sdrh   pNew->addrOpenEphm[2] = -1;
769ff78bd2fSdrh   return pNew;
770ff78bd2fSdrh }
77193758c8dSdanielk1977 #else
77217435752Sdrh Select *sqlite3SelectDup(sqlite3 *db, Select *p){
77393758c8dSdanielk1977   assert( p==0 );
77493758c8dSdanielk1977   return 0;
77593758c8dSdanielk1977 }
77693758c8dSdanielk1977 #endif
777ff78bd2fSdrh 
778ff78bd2fSdrh 
779ff78bd2fSdrh /*
780a76b5dfcSdrh ** Add a new element to the end of an expression list.  If pList is
781a76b5dfcSdrh ** initially NULL, then create a new expression list.
782a76b5dfcSdrh */
78317435752Sdrh ExprList *sqlite3ExprListAppend(
78417435752Sdrh   Parse *pParse,          /* Parsing context */
78517435752Sdrh   ExprList *pList,        /* List to which to append. Might be NULL */
78617435752Sdrh   Expr *pExpr,            /* Expression to be appended */
78717435752Sdrh   Token *pName            /* AS keyword for the expression */
78817435752Sdrh ){
78917435752Sdrh   sqlite3 *db = pParse->db;
790a76b5dfcSdrh   if( pList==0 ){
79117435752Sdrh     pList = sqlite3DbMallocZero(db, sizeof(ExprList) );
792a76b5dfcSdrh     if( pList==0 ){
793d5d56523Sdanielk1977       goto no_mem;
794a76b5dfcSdrh     }
7954efc4754Sdrh     assert( pList->nAlloc==0 );
796a76b5dfcSdrh   }
7974305d103Sdrh   if( pList->nAlloc<=pList->nExpr ){
798d5d56523Sdanielk1977     struct ExprList_item *a;
799d5d56523Sdanielk1977     int n = pList->nAlloc*2 + 4;
80026783a58Sdanielk1977     a = sqlite3DbRealloc(db, pList->a, n*sizeof(pList->a[0]));
801d5d56523Sdanielk1977     if( a==0 ){
802d5d56523Sdanielk1977       goto no_mem;
803a76b5dfcSdrh     }
804d5d56523Sdanielk1977     pList->a = a;
805d5d56523Sdanielk1977     pList->nAlloc = n;
806a76b5dfcSdrh   }
8074efc4754Sdrh   assert( pList->a!=0 );
8084efc4754Sdrh   if( pExpr || pName ){
8094efc4754Sdrh     struct ExprList_item *pItem = &pList->a[pList->nExpr++];
8104efc4754Sdrh     memset(pItem, 0, sizeof(*pItem));
81117435752Sdrh     pItem->zName = sqlite3NameFromToken(db, pName);
812e94ddc9eSdanielk1977     pItem->pExpr = pExpr;
813a76b5dfcSdrh   }
814a76b5dfcSdrh   return pList;
815d5d56523Sdanielk1977 
816d5d56523Sdanielk1977 no_mem:
817d5d56523Sdanielk1977   /* Avoid leaking memory if malloc has failed. */
818d5d56523Sdanielk1977   sqlite3ExprDelete(pExpr);
819d5d56523Sdanielk1977   sqlite3ExprListDelete(pList);
820d5d56523Sdanielk1977   return 0;
821a76b5dfcSdrh }
822a76b5dfcSdrh 
823a76b5dfcSdrh /*
8247a15a4beSdanielk1977 ** If the expression list pEList contains more than iLimit elements,
8257a15a4beSdanielk1977 ** leave an error message in pParse.
8267a15a4beSdanielk1977 */
8277a15a4beSdanielk1977 void sqlite3ExprListCheckLength(
8287a15a4beSdanielk1977   Parse *pParse,
8297a15a4beSdanielk1977   ExprList *pEList,
8307a15a4beSdanielk1977   const char *zObject
8317a15a4beSdanielk1977 ){
832b1a6c3c1Sdrh   int mx = pParse->db->aLimit[SQLITE_LIMIT_COLUMN];
833c5499befSdrh   testcase( pEList && pEList->nExpr==mx );
834c5499befSdrh   testcase( pEList && pEList->nExpr==mx+1 );
835b1a6c3c1Sdrh   if( pEList && pEList->nExpr>mx ){
8367a15a4beSdanielk1977     sqlite3ErrorMsg(pParse, "too many columns in %s", zObject);
8377a15a4beSdanielk1977   }
8387a15a4beSdanielk1977 }
8397a15a4beSdanielk1977 
8407a15a4beSdanielk1977 /*
841a76b5dfcSdrh ** Delete an entire expression list.
842a76b5dfcSdrh */
8434adee20fSdanielk1977 void sqlite3ExprListDelete(ExprList *pList){
844a76b5dfcSdrh   int i;
845be5c89acSdrh   struct ExprList_item *pItem;
846a76b5dfcSdrh   if( pList==0 ) return;
8471bdd9b57Sdrh   assert( pList->a!=0 || (pList->nExpr==0 && pList->nAlloc==0) );
8481bdd9b57Sdrh   assert( pList->nExpr<=pList->nAlloc );
849be5c89acSdrh   for(pItem=pList->a, i=0; i<pList->nExpr; i++, pItem++){
850be5c89acSdrh     sqlite3ExprDelete(pItem->pExpr);
85117435752Sdrh     sqlite3_free(pItem->zName);
852a76b5dfcSdrh   }
85317435752Sdrh   sqlite3_free(pList->a);
85417435752Sdrh   sqlite3_free(pList);
855a76b5dfcSdrh }
856a76b5dfcSdrh 
857a76b5dfcSdrh /*
858678ccce8Sdrh ** Walk an expression tree.  Call xFunc for each node visited.  xFunc
859678ccce8Sdrh ** is called on the node before xFunc is called on the nodes children.
86073b211abSdrh **
861626a879aSdrh ** The return value from xFunc determines whether the tree walk continues.
862626a879aSdrh ** 0 means continue walking the tree.  1 means do not walk children
863626a879aSdrh ** of the current node but continue with siblings.  2 means abandon
864626a879aSdrh ** the tree walk completely.
865626a879aSdrh **
866626a879aSdrh ** The return value from this routine is 1 to abandon the tree walk
867626a879aSdrh ** and 0 to continue.
86887abf5c0Sdrh **
86987abf5c0Sdrh ** NOTICE:  This routine does *not* descend into subqueries.
870626a879aSdrh */
871a58fdfb1Sdanielk1977 static int walkExprList(ExprList *, int (*)(void *, Expr*), void *);
872626a879aSdrh static int walkExprTree(Expr *pExpr, int (*xFunc)(void*,Expr*), void *pArg){
873626a879aSdrh   int rc;
874626a879aSdrh   if( pExpr==0 ) return 0;
875626a879aSdrh   rc = (*xFunc)(pArg, pExpr);
876626a879aSdrh   if( rc==0 ){
877626a879aSdrh     if( walkExprTree(pExpr->pLeft, xFunc, pArg) ) return 1;
878626a879aSdrh     if( walkExprTree(pExpr->pRight, xFunc, pArg) ) return 1;
879a58fdfb1Sdanielk1977     if( walkExprList(pExpr->pList, xFunc, pArg) ) return 1;
880626a879aSdrh   }
881626a879aSdrh   return rc>1;
882626a879aSdrh }
883626a879aSdrh 
884626a879aSdrh /*
885a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in list p.
886a58fdfb1Sdanielk1977 */
887a58fdfb1Sdanielk1977 static int walkExprList(ExprList *p, int (*xFunc)(void *, Expr*), void *pArg){
888a58fdfb1Sdanielk1977   int i;
889a58fdfb1Sdanielk1977   struct ExprList_item *pItem;
890a58fdfb1Sdanielk1977   if( !p ) return 0;
891a58fdfb1Sdanielk1977   for(i=p->nExpr, pItem=p->a; i>0; i--, pItem++){
892a58fdfb1Sdanielk1977     if( walkExprTree(pItem->pExpr, xFunc, pArg) ) return 1;
893a58fdfb1Sdanielk1977   }
894a58fdfb1Sdanielk1977   return 0;
895a58fdfb1Sdanielk1977 }
896a58fdfb1Sdanielk1977 
897a58fdfb1Sdanielk1977 /*
898a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in Select p, not including
899a58fdfb1Sdanielk1977 ** expressions that are part of sub-selects in any FROM clause or the LIMIT
900a58fdfb1Sdanielk1977 ** or OFFSET expressions..
901a58fdfb1Sdanielk1977 */
902a58fdfb1Sdanielk1977 static int walkSelectExpr(Select *p, int (*xFunc)(void *, Expr*), void *pArg){
903a58fdfb1Sdanielk1977   walkExprList(p->pEList, xFunc, pArg);
904a58fdfb1Sdanielk1977   walkExprTree(p->pWhere, xFunc, pArg);
905a58fdfb1Sdanielk1977   walkExprList(p->pGroupBy, xFunc, pArg);
906a58fdfb1Sdanielk1977   walkExprTree(p->pHaving, xFunc, pArg);
907a58fdfb1Sdanielk1977   walkExprList(p->pOrderBy, xFunc, pArg);
90815d7982aSdanielk1977   if( p->pPrior ){
90915d7982aSdanielk1977     walkSelectExpr(p->pPrior, xFunc, pArg);
91015d7982aSdanielk1977   }
911a58fdfb1Sdanielk1977   return 0;
912a58fdfb1Sdanielk1977 }
913a58fdfb1Sdanielk1977 
914a58fdfb1Sdanielk1977 
915a58fdfb1Sdanielk1977 /*
916626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
917626a879aSdrh **
918626a879aSdrh ** pArg is really a pointer to an integer.  If we can tell by looking
91973b211abSdrh ** at pExpr that the expression that contains pExpr is not a constant
92073b211abSdrh ** expression, then set *pArg to 0 and return 2 to abandon the tree walk.
92173b211abSdrh ** If pExpr does does not disqualify the expression from being a constant
92273b211abSdrh ** then do nothing.
92373b211abSdrh **
92473b211abSdrh ** After walking the whole tree, if no nodes are found that disqualify
92573b211abSdrh ** the expression as constant, then we assume the whole expression
92673b211abSdrh ** is constant.  See sqlite3ExprIsConstant() for additional information.
927626a879aSdrh */
928626a879aSdrh static int exprNodeIsConstant(void *pArg, Expr *pExpr){
9290a168377Sdrh   int *pN = (int*)pArg;
9300a168377Sdrh 
9310a168377Sdrh   /* If *pArg is 3 then any term of the expression that comes from
9320a168377Sdrh   ** the ON or USING clauses of a join disqualifies the expression
9330a168377Sdrh   ** from being considered constant. */
9340a168377Sdrh   if( (*pN)==3 && ExprHasAnyProperty(pExpr, EP_FromJoin) ){
9350a168377Sdrh     *pN = 0;
9360a168377Sdrh     return 2;
9370a168377Sdrh   }
9380a168377Sdrh 
939626a879aSdrh   switch( pExpr->op ){
940eb55bd2fSdrh     /* Consider functions to be constant if all their arguments are constant
941eb55bd2fSdrh     ** and *pArg==2 */
942eb55bd2fSdrh     case TK_FUNCTION:
9430a168377Sdrh       if( (*pN)==2 ) return 0;
944eb55bd2fSdrh       /* Fall through */
945626a879aSdrh     case TK_ID:
946626a879aSdrh     case TK_COLUMN:
947626a879aSdrh     case TK_DOT:
948626a879aSdrh     case TK_AGG_FUNCTION:
94913449892Sdrh     case TK_AGG_COLUMN:
950fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
951fe2093d7Sdrh     case TK_SELECT:
952fe2093d7Sdrh     case TK_EXISTS:
953c5499befSdrh       testcase( pExpr->op==TK_SELECT );
954c5499befSdrh       testcase( pExpr->op==TK_EXISTS );
955fe2093d7Sdrh #endif
956c5499befSdrh       testcase( pExpr->op==TK_ID );
957c5499befSdrh       testcase( pExpr->op==TK_COLUMN );
958c5499befSdrh       testcase( pExpr->op==TK_DOT );
959c5499befSdrh       testcase( pExpr->op==TK_AGG_FUNCTION );
960c5499befSdrh       testcase( pExpr->op==TK_AGG_COLUMN );
9610a168377Sdrh       *pN = 0;
962626a879aSdrh       return 2;
96387abf5c0Sdrh     case TK_IN:
96487abf5c0Sdrh       if( pExpr->pSelect ){
9650a168377Sdrh         *pN = 0;
96687abf5c0Sdrh         return 2;
96787abf5c0Sdrh       }
968626a879aSdrh     default:
969626a879aSdrh       return 0;
970626a879aSdrh   }
971626a879aSdrh }
972626a879aSdrh 
973626a879aSdrh /*
974fef5208cSdrh ** Walk an expression tree.  Return 1 if the expression is constant
975eb55bd2fSdrh ** and 0 if it involves variables or function calls.
9762398937bSdrh **
9772398937bSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
9782398937bSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
9792398937bSdrh ** a constant.
980fef5208cSdrh */
9814adee20fSdanielk1977 int sqlite3ExprIsConstant(Expr *p){
982626a879aSdrh   int isConst = 1;
983626a879aSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
984626a879aSdrh   return isConst;
985fef5208cSdrh }
986fef5208cSdrh 
987fef5208cSdrh /*
988eb55bd2fSdrh ** Walk an expression tree.  Return 1 if the expression is constant
9890a168377Sdrh ** that does no originate from the ON or USING clauses of a join.
9900a168377Sdrh ** Return 0 if it involves variables or function calls or terms from
9910a168377Sdrh ** an ON or USING clause.
9920a168377Sdrh */
9930a168377Sdrh int sqlite3ExprIsConstantNotJoin(Expr *p){
9940a168377Sdrh   int isConst = 3;
9950a168377Sdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
9960a168377Sdrh   return isConst!=0;
9970a168377Sdrh }
9980a168377Sdrh 
9990a168377Sdrh /*
10000a168377Sdrh ** Walk an expression tree.  Return 1 if the expression is constant
1001eb55bd2fSdrh ** or a function call with constant arguments.  Return and 0 if there
1002eb55bd2fSdrh ** are any variables.
1003eb55bd2fSdrh **
1004eb55bd2fSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
1005eb55bd2fSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
1006eb55bd2fSdrh ** a constant.
1007eb55bd2fSdrh */
1008eb55bd2fSdrh int sqlite3ExprIsConstantOrFunction(Expr *p){
1009eb55bd2fSdrh   int isConst = 2;
1010eb55bd2fSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
1011eb55bd2fSdrh   return isConst!=0;
1012eb55bd2fSdrh }
1013eb55bd2fSdrh 
1014eb55bd2fSdrh /*
101573b211abSdrh ** If the expression p codes a constant integer that is small enough
1016202b2df7Sdrh ** to fit in a 32-bit integer, return 1 and put the value of the integer
1017202b2df7Sdrh ** in *pValue.  If the expression is not an integer or if it is too big
1018202b2df7Sdrh ** to fit in a signed 32-bit integer, return 0 and leave *pValue unchanged.
1019e4de1febSdrh */
10204adee20fSdanielk1977 int sqlite3ExprIsInteger(Expr *p, int *pValue){
102192b01d53Sdrh   int rc = 0;
102292b01d53Sdrh   if( p->flags & EP_IntValue ){
102392b01d53Sdrh     *pValue = p->iTable;
1024e4de1febSdrh     return 1;
1025e4de1febSdrh   }
102692b01d53Sdrh   switch( p->op ){
102792b01d53Sdrh     case TK_INTEGER: {
102892b01d53Sdrh       rc = sqlite3GetInt32((char*)p->token.z, pValue);
1029202b2df7Sdrh       break;
1030202b2df7Sdrh     }
10314b59ab5eSdrh     case TK_UPLUS: {
103292b01d53Sdrh       rc = sqlite3ExprIsInteger(p->pLeft, pValue);
1033f6e369a1Sdrh       break;
10344b59ab5eSdrh     }
1035e4de1febSdrh     case TK_UMINUS: {
1036e4de1febSdrh       int v;
10374adee20fSdanielk1977       if( sqlite3ExprIsInteger(p->pLeft, &v) ){
1038e4de1febSdrh         *pValue = -v;
103992b01d53Sdrh         rc = 1;
1040e4de1febSdrh       }
1041e4de1febSdrh       break;
1042e4de1febSdrh     }
1043e4de1febSdrh     default: break;
1044e4de1febSdrh   }
104592b01d53Sdrh   if( rc ){
104692b01d53Sdrh     p->op = TK_INTEGER;
104792b01d53Sdrh     p->flags |= EP_IntValue;
104892b01d53Sdrh     p->iTable = *pValue;
104992b01d53Sdrh   }
105092b01d53Sdrh   return rc;
1051e4de1febSdrh }
1052e4de1febSdrh 
1053e4de1febSdrh /*
1054c4a3c779Sdrh ** Return TRUE if the given string is a row-id column name.
1055c4a3c779Sdrh */
10564adee20fSdanielk1977 int sqlite3IsRowid(const char *z){
10574adee20fSdanielk1977   if( sqlite3StrICmp(z, "_ROWID_")==0 ) return 1;
10584adee20fSdanielk1977   if( sqlite3StrICmp(z, "ROWID")==0 ) return 1;
10594adee20fSdanielk1977   if( sqlite3StrICmp(z, "OID")==0 ) return 1;
1060c4a3c779Sdrh   return 0;
1061c4a3c779Sdrh }
1062c4a3c779Sdrh 
1063c4a3c779Sdrh /*
10648141f61eSdrh ** Given the name of a column of the form X.Y.Z or Y.Z or just Z, look up
10658141f61eSdrh ** that name in the set of source tables in pSrcList and make the pExpr
10668141f61eSdrh ** expression node refer back to that source column.  The following changes
10678141f61eSdrh ** are made to pExpr:
10688141f61eSdrh **
10698141f61eSdrh **    pExpr->iDb           Set the index in db->aDb[] of the database holding
10708141f61eSdrh **                         the table.
10718141f61eSdrh **    pExpr->iTable        Set to the cursor number for the table obtained
10728141f61eSdrh **                         from pSrcList.
10738141f61eSdrh **    pExpr->iColumn       Set to the column number within the table.
10748141f61eSdrh **    pExpr->op            Set to TK_COLUMN.
10758141f61eSdrh **    pExpr->pLeft         Any expression this points to is deleted
10768141f61eSdrh **    pExpr->pRight        Any expression this points to is deleted.
10778141f61eSdrh **
10788141f61eSdrh ** The pDbToken is the name of the database (the "X").  This value may be
10798141f61eSdrh ** NULL meaning that name is of the form Y.Z or Z.  Any available database
10808141f61eSdrh ** can be used.  The pTableToken is the name of the table (the "Y").  This
10818141f61eSdrh ** value can be NULL if pDbToken is also NULL.  If pTableToken is NULL it
10828141f61eSdrh ** means that the form of the name is Z and that columns from any table
10838141f61eSdrh ** can be used.
10848141f61eSdrh **
10858141f61eSdrh ** If the name cannot be resolved unambiguously, leave an error message
10868141f61eSdrh ** in pParse and return non-zero.  Return zero on success.
10878141f61eSdrh */
10888141f61eSdrh static int lookupName(
10898141f61eSdrh   Parse *pParse,       /* The parsing context */
10908141f61eSdrh   Token *pDbToken,     /* Name of the database containing table, or NULL */
10918141f61eSdrh   Token *pTableToken,  /* Name of table containing column, or NULL */
10928141f61eSdrh   Token *pColumnToken, /* Name of the column. */
1093626a879aSdrh   NameContext *pNC,    /* The name context used to resolve the name */
10948141f61eSdrh   Expr *pExpr          /* Make this EXPR node point to the selected column */
10958141f61eSdrh ){
10968141f61eSdrh   char *zDb = 0;       /* Name of the database.  The "X" in X.Y.Z */
10978141f61eSdrh   char *zTab = 0;      /* Name of the table.  The "Y" in X.Y.Z or Y.Z */
10988141f61eSdrh   char *zCol = 0;      /* Name of the column.  The "Z" */
10998141f61eSdrh   int i, j;            /* Loop counters */
11008141f61eSdrh   int cnt = 0;         /* Number of matching column names */
11018141f61eSdrh   int cntTab = 0;      /* Number of matching table names */
11029bb575fdSdrh   sqlite3 *db = pParse->db;  /* The database */
110351669863Sdrh   struct SrcList_item *pItem;       /* Use for looping over pSrcList items */
110451669863Sdrh   struct SrcList_item *pMatch = 0;  /* The matching pSrcList item */
110573b211abSdrh   NameContext *pTopNC = pNC;        /* First namecontext in the list */
1106728b5779Sdrh   Schema *pSchema = 0;              /* Schema of the expression */
11078141f61eSdrh 
11088141f61eSdrh   assert( pColumnToken && pColumnToken->z ); /* The Z in X.Y.Z cannot be NULL */
110917435752Sdrh   zDb = sqlite3NameFromToken(db, pDbToken);
111017435752Sdrh   zTab = sqlite3NameFromToken(db, pTableToken);
111117435752Sdrh   zCol = sqlite3NameFromToken(db, pColumnToken);
111217435752Sdrh   if( db->mallocFailed ){
1113d5d56523Sdanielk1977     goto lookupname_end;
11148141f61eSdrh   }
11158141f61eSdrh 
11168141f61eSdrh   pExpr->iTable = -1;
1117626a879aSdrh   while( pNC && cnt==0 ){
1118ffe07b2dSdrh     ExprList *pEList;
1119626a879aSdrh     SrcList *pSrcList = pNC->pSrcList;
1120626a879aSdrh 
1121b3bce662Sdanielk1977     if( pSrcList ){
112251669863Sdrh       for(i=0, pItem=pSrcList->a; i<pSrcList->nSrc; i++, pItem++){
112343617e9aSdrh         Table *pTab;
112443617e9aSdrh         int iDb;
11258141f61eSdrh         Column *pCol;
11268141f61eSdrh 
112743617e9aSdrh         pTab = pItem->pTab;
112843617e9aSdrh         assert( pTab!=0 );
112943617e9aSdrh         iDb = sqlite3SchemaToIndex(db, pTab->pSchema);
11308141f61eSdrh         assert( pTab->nCol>0 );
11318141f61eSdrh         if( zTab ){
11328141f61eSdrh           if( pItem->zAlias ){
11338141f61eSdrh             char *zTabName = pItem->zAlias;
11344adee20fSdanielk1977             if( sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
11358141f61eSdrh           }else{
11368141f61eSdrh             char *zTabName = pTab->zName;
11374adee20fSdanielk1977             if( zTabName==0 || sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
1138da184236Sdanielk1977             if( zDb!=0 && sqlite3StrICmp(db->aDb[iDb].zName, zDb)!=0 ){
11398141f61eSdrh               continue;
11408141f61eSdrh             }
11418141f61eSdrh           }
11428141f61eSdrh         }
11438141f61eSdrh         if( 0==(cntTab++) ){
11448141f61eSdrh           pExpr->iTable = pItem->iCursor;
1145728b5779Sdrh           pSchema = pTab->pSchema;
114651669863Sdrh           pMatch = pItem;
11478141f61eSdrh         }
11488141f61eSdrh         for(j=0, pCol=pTab->aCol; j<pTab->nCol; j++, pCol++){
11494adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
1150b3bf556eSdanielk1977             const char *zColl = pTab->aCol[j].zColl;
1151873fac0cSdrh             IdList *pUsing;
11528141f61eSdrh             cnt++;
11538141f61eSdrh             pExpr->iTable = pItem->iCursor;
115451669863Sdrh             pMatch = pItem;
1155728b5779Sdrh             pSchema = pTab->pSchema;
11568141f61eSdrh             /* Substitute the rowid (column -1) for the INTEGER PRIMARY KEY */
11578141f61eSdrh             pExpr->iColumn = j==pTab->iPKey ? -1 : j;
1158a37cdde0Sdanielk1977             pExpr->affinity = pTab->aCol[j].affinity;
11598b4c40d8Sdrh             if( (pExpr->flags & EP_ExpCollate)==0 ){
1160b3bf556eSdanielk1977               pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
11618b4c40d8Sdrh             }
116261dfc31dSdrh             if( i<pSrcList->nSrc-1 ){
116361dfc31dSdrh               if( pItem[1].jointype & JT_NATURAL ){
1164355ef361Sdrh                 /* If this match occurred in the left table of a natural join,
1165355ef361Sdrh                 ** then skip the right table to avoid a duplicate match */
1166355ef361Sdrh                 pItem++;
1167355ef361Sdrh                 i++;
116861dfc31dSdrh               }else if( (pUsing = pItem[1].pUsing)!=0 ){
1169873fac0cSdrh                 /* If this match occurs on a column that is in the USING clause
1170873fac0cSdrh                 ** of a join, skip the search of the right table of the join
1171873fac0cSdrh                 ** to avoid a duplicate match there. */
1172873fac0cSdrh                 int k;
1173873fac0cSdrh                 for(k=0; k<pUsing->nId; k++){
1174873fac0cSdrh                   if( sqlite3StrICmp(pUsing->a[k].zName, zCol)==0 ){
1175873fac0cSdrh                     pItem++;
1176873fac0cSdrh                     i++;
1177873fac0cSdrh                     break;
1178873fac0cSdrh                   }
1179873fac0cSdrh                 }
1180873fac0cSdrh               }
118161dfc31dSdrh             }
11828141f61eSdrh             break;
11838141f61eSdrh           }
11848141f61eSdrh         }
11858141f61eSdrh       }
1186b3bce662Sdanielk1977     }
11878141f61eSdrh 
1188b7f9164eSdrh #ifndef SQLITE_OMIT_TRIGGER
11898141f61eSdrh     /* If we have not already resolved the name, then maybe
11908141f61eSdrh     ** it is a new.* or old.* trigger argument reference
11918141f61eSdrh     */
11928141f61eSdrh     if( zDb==0 && zTab!=0 && cnt==0 && pParse->trigStack!=0 ){
11938141f61eSdrh       TriggerStack *pTriggerStack = pParse->trigStack;
11948141f61eSdrh       Table *pTab = 0;
11958f2c54e6Sdanielk1977       u32 *piColMask;
11964adee20fSdanielk1977       if( pTriggerStack->newIdx != -1 && sqlite3StrICmp("new", zTab) == 0 ){
11978141f61eSdrh         pExpr->iTable = pTriggerStack->newIdx;
11988141f61eSdrh         assert( pTriggerStack->pTab );
11998141f61eSdrh         pTab = pTriggerStack->pTab;
12008f2c54e6Sdanielk1977         piColMask = &(pTriggerStack->newColMask);
12014adee20fSdanielk1977       }else if( pTriggerStack->oldIdx != -1 && sqlite3StrICmp("old", zTab)==0 ){
12028141f61eSdrh         pExpr->iTable = pTriggerStack->oldIdx;
12038141f61eSdrh         assert( pTriggerStack->pTab );
12048141f61eSdrh         pTab = pTriggerStack->pTab;
12058f2c54e6Sdanielk1977         piColMask = &(pTriggerStack->oldColMask);
12068141f61eSdrh       }
12078141f61eSdrh 
12088141f61eSdrh       if( pTab ){
1209f0113000Sdanielk1977         int iCol;
12108141f61eSdrh         Column *pCol = pTab->aCol;
12118141f61eSdrh 
1212728b5779Sdrh         pSchema = pTab->pSchema;
12138141f61eSdrh         cntTab++;
1214f0113000Sdanielk1977         for(iCol=0; iCol < pTab->nCol; iCol++, pCol++) {
12154adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
1216f0113000Sdanielk1977             const char *zColl = pTab->aCol[iCol].zColl;
12178141f61eSdrh             cnt++;
1218f0113000Sdanielk1977             pExpr->iColumn = iCol==pTab->iPKey ? -1 : iCol;
1219f0113000Sdanielk1977             pExpr->affinity = pTab->aCol[iCol].affinity;
12208b4c40d8Sdrh             if( (pExpr->flags & EP_ExpCollate)==0 ){
1221b3bf556eSdanielk1977               pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
12228b4c40d8Sdrh             }
1223aee18ef8Sdanielk1977             pExpr->pTab = pTab;
12248f2c54e6Sdanielk1977             if( iCol>=0 ){
1225c5499befSdrh               testcase( iCol==31 );
1226c5499befSdrh               testcase( iCol==32 );
12278f2c54e6Sdanielk1977               *piColMask |= ((u32)1<<iCol) | (iCol>=32?0xffffffff:0);
12288f2c54e6Sdanielk1977             }
12298141f61eSdrh             break;
12308141f61eSdrh           }
12318141f61eSdrh         }
12328141f61eSdrh       }
12338141f61eSdrh     }
1234b7f9164eSdrh #endif /* !defined(SQLITE_OMIT_TRIGGER) */
12358141f61eSdrh 
12368141f61eSdrh     /*
12378141f61eSdrh     ** Perhaps the name is a reference to the ROWID
12388141f61eSdrh     */
12394adee20fSdanielk1977     if( cnt==0 && cntTab==1 && sqlite3IsRowid(zCol) ){
12408141f61eSdrh       cnt = 1;
12418141f61eSdrh       pExpr->iColumn = -1;
12428a51256cSdrh       pExpr->affinity = SQLITE_AFF_INTEGER;
12438141f61eSdrh     }
12448141f61eSdrh 
12458141f61eSdrh     /*
12468141f61eSdrh     ** If the input is of the form Z (not Y.Z or X.Y.Z) then the name Z
12478141f61eSdrh     ** might refer to an result-set alias.  This happens, for example, when
12488141f61eSdrh     ** we are resolving names in the WHERE clause of the following command:
12498141f61eSdrh     **
12508141f61eSdrh     **     SELECT a+b AS x FROM table WHERE x<10;
12518141f61eSdrh     **
12528141f61eSdrh     ** In cases like this, replace pExpr with a copy of the expression that
12538141f61eSdrh     ** forms the result set entry ("a+b" in the example) and return immediately.
12548141f61eSdrh     ** Note that the expression in the result set should have already been
12558141f61eSdrh     ** resolved by the time the WHERE clause is resolved.
12568141f61eSdrh     */
1257ffe07b2dSdrh     if( cnt==0 && (pEList = pNC->pEList)!=0 && zTab==0 ){
12588141f61eSdrh       for(j=0; j<pEList->nExpr; j++){
12598141f61eSdrh         char *zAs = pEList->a[j].zName;
12604adee20fSdanielk1977         if( zAs!=0 && sqlite3StrICmp(zAs, zCol)==0 ){
126136379e97Sdrh           Expr *pDup, *pOrig;
12628141f61eSdrh           assert( pExpr->pLeft==0 && pExpr->pRight==0 );
12634f07e5fbSdrh           assert( pExpr->pList==0 );
12644f07e5fbSdrh           assert( pExpr->pSelect==0 );
126536379e97Sdrh           pOrig = pEList->a[j].pExpr;
126636379e97Sdrh           if( !pNC->allowAgg && ExprHasProperty(pOrig, EP_Agg) ){
126736379e97Sdrh             sqlite3ErrorMsg(pParse, "misuse of aliased aggregate %s", zAs);
126817435752Sdrh             sqlite3_free(zCol);
126936379e97Sdrh             return 2;
127036379e97Sdrh           }
12711e536953Sdanielk1977           pDup = sqlite3ExprDup(db, pOrig);
12724f07e5fbSdrh           if( pExpr->flags & EP_ExpCollate ){
12734f07e5fbSdrh             pDup->pColl = pExpr->pColl;
12744f07e5fbSdrh             pDup->flags |= EP_ExpCollate;
12754f07e5fbSdrh           }
127617435752Sdrh           if( pExpr->span.dyn ) sqlite3_free((char*)pExpr->span.z);
127717435752Sdrh           if( pExpr->token.dyn ) sqlite3_free((char*)pExpr->token.z);
12784f07e5fbSdrh           memcpy(pExpr, pDup, sizeof(*pExpr));
127917435752Sdrh           sqlite3_free(pDup);
128015ccce1cSdrh           cnt = 1;
1281c9cf6e3dSdanielk1977           pMatch = 0;
12828141f61eSdrh           assert( zTab==0 && zDb==0 );
128315ccce1cSdrh           goto lookupname_end_2;
12848141f61eSdrh         }
12858141f61eSdrh       }
12868141f61eSdrh     }
12878141f61eSdrh 
1288626a879aSdrh     /* Advance to the next name context.  The loop will exit when either
1289626a879aSdrh     ** we have a match (cnt>0) or when we run out of name contexts.
1290626a879aSdrh     */
1291626a879aSdrh     if( cnt==0 ){
1292626a879aSdrh       pNC = pNC->pNext;
1293626a879aSdrh     }
1294626a879aSdrh   }
1295626a879aSdrh 
12968141f61eSdrh   /*
12978141f61eSdrh   ** If X and Y are NULL (in other words if only the column name Z is
12988141f61eSdrh   ** supplied) and the value of Z is enclosed in double-quotes, then
12998141f61eSdrh   ** Z is a string literal if it doesn't match any column names.  In that
13008141f61eSdrh   ** case, we need to return right away and not make any changes to
13018141f61eSdrh   ** pExpr.
130215ccce1cSdrh   **
130315ccce1cSdrh   ** Because no reference was made to outer contexts, the pNC->nRef
130415ccce1cSdrh   ** fields are not changed in any context.
13058141f61eSdrh   */
13068141f61eSdrh   if( cnt==0 && zTab==0 && pColumnToken->z[0]=='"' ){
130717435752Sdrh     sqlite3_free(zCol);
13088141f61eSdrh     return 0;
13098141f61eSdrh   }
13108141f61eSdrh 
13118141f61eSdrh   /*
13128141f61eSdrh   ** cnt==0 means there was not match.  cnt>1 means there were two or
13138141f61eSdrh   ** more matches.  Either way, we have an error.
13148141f61eSdrh   */
13158141f61eSdrh   if( cnt!=1 ){
1316de4fcfddSdrh     const char *zErr;
1317de4fcfddSdrh     zErr = cnt==0 ? "no such column" : "ambiguous column name";
13188141f61eSdrh     if( zDb ){
1319de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s.%s.%s", zErr, zDb, zTab, zCol);
13208141f61eSdrh     }else if( zTab ){
1321de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s.%s", zErr, zTab, zCol);
13228141f61eSdrh     }else{
1323de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s", zErr, zCol);
13248141f61eSdrh     }
132573b211abSdrh     pTopNC->nErr++;
13268141f61eSdrh   }
13278141f61eSdrh 
132851669863Sdrh   /* If a column from a table in pSrcList is referenced, then record
132951669863Sdrh   ** this fact in the pSrcList.a[].colUsed bitmask.  Column 0 causes
133051669863Sdrh   ** bit 0 to be set.  Column 1 sets bit 1.  And so forth.  If the
133151669863Sdrh   ** column number is greater than the number of bits in the bitmask
133251669863Sdrh   ** then set the high-order bit of the bitmask.
133351669863Sdrh   */
133451669863Sdrh   if( pExpr->iColumn>=0 && pMatch!=0 ){
133551669863Sdrh     int n = pExpr->iColumn;
1336c5499befSdrh     testcase( n==sizeof(Bitmask)*8-1 );
133751669863Sdrh     if( n>=sizeof(Bitmask)*8 ){
133851669863Sdrh       n = sizeof(Bitmask)*8-1;
133951669863Sdrh     }
134051669863Sdrh     assert( pMatch->iCursor==pExpr->iTable );
1341ca83ac51Sdrh     pMatch->colUsed |= ((Bitmask)1)<<n;
134251669863Sdrh   }
134351669863Sdrh 
1344d5d56523Sdanielk1977 lookupname_end:
13458141f61eSdrh   /* Clean up and return
13468141f61eSdrh   */
134717435752Sdrh   sqlite3_free(zDb);
134817435752Sdrh   sqlite3_free(zTab);
13494adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pLeft);
13508141f61eSdrh   pExpr->pLeft = 0;
13514adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pRight);
13528141f61eSdrh   pExpr->pRight = 0;
13538141f61eSdrh   pExpr->op = TK_COLUMN;
135415ccce1cSdrh lookupname_end_2:
135517435752Sdrh   sqlite3_free(zCol);
1356626a879aSdrh   if( cnt==1 ){
1357b3bce662Sdanielk1977     assert( pNC!=0 );
1358728b5779Sdrh     sqlite3AuthRead(pParse, pExpr, pSchema, pNC->pSrcList);
1359aee18ef8Sdanielk1977     if( pMatch && !pMatch->pSelect ){
1360aee18ef8Sdanielk1977       pExpr->pTab = pMatch->pTab;
1361aee18ef8Sdanielk1977     }
136215ccce1cSdrh     /* Increment the nRef value on all name contexts from TopNC up to
136315ccce1cSdrh     ** the point where the name matched. */
136415ccce1cSdrh     for(;;){
136515ccce1cSdrh       assert( pTopNC!=0 );
136615ccce1cSdrh       pTopNC->nRef++;
136715ccce1cSdrh       if( pTopNC==pNC ) break;
136815ccce1cSdrh       pTopNC = pTopNC->pNext;
1369626a879aSdrh     }
137015ccce1cSdrh     return 0;
137115ccce1cSdrh   } else {
137215ccce1cSdrh     return 1;
137315ccce1cSdrh   }
13748141f61eSdrh }
13758141f61eSdrh 
13768141f61eSdrh /*
1377626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
1378626a879aSdrh **
137973b211abSdrh ** Resolve symbolic names into TK_COLUMN operators for the current
1380626a879aSdrh ** node in the expression tree.  Return 0 to continue the search down
138173b211abSdrh ** the tree or 2 to abort the tree walk.
138273b211abSdrh **
138373b211abSdrh ** This routine also does error checking and name resolution for
138473b211abSdrh ** function names.  The operator for aggregate functions is changed
138573b211abSdrh ** to TK_AGG_FUNCTION.
1386626a879aSdrh */
1387626a879aSdrh static int nameResolverStep(void *pArg, Expr *pExpr){
1388626a879aSdrh   NameContext *pNC = (NameContext*)pArg;
1389626a879aSdrh   Parse *pParse;
1390626a879aSdrh 
1391b3bce662Sdanielk1977   if( pExpr==0 ) return 1;
1392626a879aSdrh   assert( pNC!=0 );
1393626a879aSdrh   pParse = pNC->pParse;
1394b3bce662Sdanielk1977 
1395626a879aSdrh   if( ExprHasAnyProperty(pExpr, EP_Resolved) ) return 1;
1396626a879aSdrh   ExprSetProperty(pExpr, EP_Resolved);
1397626a879aSdrh #ifndef NDEBUG
1398f0113000Sdanielk1977   if( pNC->pSrcList && pNC->pSrcList->nAlloc>0 ){
1399f0113000Sdanielk1977     SrcList *pSrcList = pNC->pSrcList;
1400940fac9dSdanielk1977     int i;
1401f0113000Sdanielk1977     for(i=0; i<pNC->pSrcList->nSrc; i++){
1402626a879aSdrh       assert( pSrcList->a[i].iCursor>=0 && pSrcList->a[i].iCursor<pParse->nTab);
1403626a879aSdrh     }
1404626a879aSdrh   }
1405626a879aSdrh #endif
1406626a879aSdrh   switch( pExpr->op ){
1407626a879aSdrh     /* Double-quoted strings (ex: "abc") are used as identifiers if
1408626a879aSdrh     ** possible.  Otherwise they remain as strings.  Single-quoted
1409626a879aSdrh     ** strings (ex: 'abc') are always string literals.
1410626a879aSdrh     */
1411626a879aSdrh     case TK_STRING: {
1412626a879aSdrh       if( pExpr->token.z[0]=='\'' ) break;
1413626a879aSdrh       /* Fall thru into the TK_ID case if this is a double-quoted string */
1414626a879aSdrh     }
1415626a879aSdrh     /* A lone identifier is the name of a column.
1416626a879aSdrh     */
1417626a879aSdrh     case TK_ID: {
1418626a879aSdrh       lookupName(pParse, 0, 0, &pExpr->token, pNC, pExpr);
1419626a879aSdrh       return 1;
1420626a879aSdrh     }
1421626a879aSdrh 
1422626a879aSdrh     /* A table name and column name:     ID.ID
1423626a879aSdrh     ** Or a database, table and column:  ID.ID.ID
1424626a879aSdrh     */
1425626a879aSdrh     case TK_DOT: {
1426626a879aSdrh       Token *pColumn;
1427626a879aSdrh       Token *pTable;
1428626a879aSdrh       Token *pDb;
1429626a879aSdrh       Expr *pRight;
1430626a879aSdrh 
1431b3bce662Sdanielk1977       /* if( pSrcList==0 ) break; */
1432626a879aSdrh       pRight = pExpr->pRight;
1433626a879aSdrh       if( pRight->op==TK_ID ){
1434626a879aSdrh         pDb = 0;
1435626a879aSdrh         pTable = &pExpr->pLeft->token;
1436626a879aSdrh         pColumn = &pRight->token;
1437626a879aSdrh       }else{
1438626a879aSdrh         assert( pRight->op==TK_DOT );
1439626a879aSdrh         pDb = &pExpr->pLeft->token;
1440626a879aSdrh         pTable = &pRight->pLeft->token;
1441626a879aSdrh         pColumn = &pRight->pRight->token;
1442626a879aSdrh       }
1443626a879aSdrh       lookupName(pParse, pDb, pTable, pColumn, pNC, pExpr);
1444626a879aSdrh       return 1;
1445626a879aSdrh     }
1446626a879aSdrh 
1447626a879aSdrh     /* Resolve function names
1448626a879aSdrh     */
1449b71090fdSdrh     case TK_CONST_FUNC:
1450626a879aSdrh     case TK_FUNCTION: {
1451626a879aSdrh       ExprList *pList = pExpr->pList;    /* The argument list */
1452626a879aSdrh       int n = pList ? pList->nExpr : 0;  /* Number of arguments */
1453626a879aSdrh       int no_such_func = 0;       /* True if no such function exists */
1454626a879aSdrh       int wrong_num_args = 0;     /* True if wrong number of arguments */
1455626a879aSdrh       int is_agg = 0;             /* True if is an aggregate function */
1456626a879aSdrh       int i;
14575169bbc6Sdrh       int auth;                   /* Authorization to use the function */
1458626a879aSdrh       int nId;                    /* Number of characters in function name */
1459626a879aSdrh       const char *zId;            /* The function name. */
146073b211abSdrh       FuncDef *pDef;              /* Information about the function */
146114db2665Sdanielk1977       int enc = ENC(pParse->db);  /* The database encoding */
1462626a879aSdrh 
14632646da7eSdrh       zId = (char*)pExpr->token.z;
1464b71090fdSdrh       nId = pExpr->token.n;
1465626a879aSdrh       pDef = sqlite3FindFunction(pParse->db, zId, nId, n, enc, 0);
1466626a879aSdrh       if( pDef==0 ){
1467626a879aSdrh         pDef = sqlite3FindFunction(pParse->db, zId, nId, -1, enc, 0);
1468626a879aSdrh         if( pDef==0 ){
1469626a879aSdrh           no_such_func = 1;
1470626a879aSdrh         }else{
1471626a879aSdrh           wrong_num_args = 1;
1472626a879aSdrh         }
1473626a879aSdrh       }else{
1474626a879aSdrh         is_agg = pDef->xFunc==0;
1475626a879aSdrh       }
14762fca7fefSdrh #ifndef SQLITE_OMIT_AUTHORIZATION
14775169bbc6Sdrh       if( pDef ){
14785169bbc6Sdrh         auth = sqlite3AuthCheck(pParse, SQLITE_FUNCTION, 0, pDef->zName, 0);
14795169bbc6Sdrh         if( auth!=SQLITE_OK ){
14805169bbc6Sdrh           if( auth==SQLITE_DENY ){
14815169bbc6Sdrh             sqlite3ErrorMsg(pParse, "not authorized to use function: %s",
14825169bbc6Sdrh                                     pDef->zName);
14835169bbc6Sdrh             pNC->nErr++;
14845169bbc6Sdrh           }
14855169bbc6Sdrh           pExpr->op = TK_NULL;
14865169bbc6Sdrh           return 1;
14875169bbc6Sdrh         }
14885169bbc6Sdrh       }
1489b8b14219Sdrh #endif
1490626a879aSdrh       if( is_agg && !pNC->allowAgg ){
1491626a879aSdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate function %.*s()", nId,zId);
1492626a879aSdrh         pNC->nErr++;
1493626a879aSdrh         is_agg = 0;
1494626a879aSdrh       }else if( no_such_func ){
1495626a879aSdrh         sqlite3ErrorMsg(pParse, "no such function: %.*s", nId, zId);
1496626a879aSdrh         pNC->nErr++;
1497626a879aSdrh       }else if( wrong_num_args ){
1498626a879aSdrh         sqlite3ErrorMsg(pParse,"wrong number of arguments to function %.*s()",
1499626a879aSdrh              nId, zId);
1500626a879aSdrh         pNC->nErr++;
1501626a879aSdrh       }
1502626a879aSdrh       if( is_agg ){
1503626a879aSdrh         pExpr->op = TK_AGG_FUNCTION;
1504626a879aSdrh         pNC->hasAgg = 1;
1505626a879aSdrh       }
150673b211abSdrh       if( is_agg ) pNC->allowAgg = 0;
1507626a879aSdrh       for(i=0; pNC->nErr==0 && i<n; i++){
150873b211abSdrh         walkExprTree(pList->a[i].pExpr, nameResolverStep, pNC);
1509626a879aSdrh       }
151073b211abSdrh       if( is_agg ) pNC->allowAgg = 1;
1511626a879aSdrh       /* FIX ME:  Compute pExpr->affinity based on the expected return
1512626a879aSdrh       ** type of the function
1513626a879aSdrh       */
1514626a879aSdrh       return is_agg;
1515626a879aSdrh     }
1516b3bce662Sdanielk1977 #ifndef SQLITE_OMIT_SUBQUERY
1517b3bce662Sdanielk1977     case TK_SELECT:
1518b3bce662Sdanielk1977     case TK_EXISTS:
1519b3bce662Sdanielk1977 #endif
1520b3bce662Sdanielk1977     case TK_IN: {
1521b3bce662Sdanielk1977       if( pExpr->pSelect ){
15228a9f38feSdrh         int nRef = pNC->nRef;
152306f6541eSdrh #ifndef SQLITE_OMIT_CHECK
152406f6541eSdrh         if( pNC->isCheck ){
152506f6541eSdrh           sqlite3ErrorMsg(pParse,"subqueries prohibited in CHECK constraints");
152606f6541eSdrh         }
152706f6541eSdrh #endif
1528b3bce662Sdanielk1977         sqlite3SelectResolve(pParse, pExpr->pSelect, pNC);
1529b3bce662Sdanielk1977         assert( pNC->nRef>=nRef );
1530b3bce662Sdanielk1977         if( nRef!=pNC->nRef ){
1531b3bce662Sdanielk1977           ExprSetProperty(pExpr, EP_VarSelect);
1532b3bce662Sdanielk1977         }
1533b3bce662Sdanielk1977       }
15344284fb07Sdrh       break;
1535b3bce662Sdanielk1977     }
15364284fb07Sdrh #ifndef SQLITE_OMIT_CHECK
15374284fb07Sdrh     case TK_VARIABLE: {
15384284fb07Sdrh       if( pNC->isCheck ){
15394284fb07Sdrh         sqlite3ErrorMsg(pParse,"parameters prohibited in CHECK constraints");
15404284fb07Sdrh       }
15414284fb07Sdrh       break;
15424284fb07Sdrh     }
15434284fb07Sdrh #endif
1544626a879aSdrh   }
1545626a879aSdrh   return 0;
1546626a879aSdrh }
1547626a879aSdrh 
1548626a879aSdrh /*
1549cce7d176Sdrh ** This routine walks an expression tree and resolves references to
1550967e8b73Sdrh ** table columns.  Nodes of the form ID.ID or ID resolve into an
1551aacc543eSdrh ** index to the table in the table list and a column offset.  The
1552aacc543eSdrh ** Expr.opcode for such nodes is changed to TK_COLUMN.  The Expr.iTable
1553aacc543eSdrh ** value is changed to the index of the referenced table in pTabList
1554832508b7Sdrh ** plus the "base" value.  The base value will ultimately become the
1555aacc543eSdrh ** VDBE cursor number for a cursor that is pointing into the referenced
1556aacc543eSdrh ** table.  The Expr.iColumn value is changed to the index of the column
1557aacc543eSdrh ** of the referenced table.  The Expr.iColumn value for the special
1558aacc543eSdrh ** ROWID column is -1.  Any INTEGER PRIMARY KEY column is tried as an
1559aacc543eSdrh ** alias for ROWID.
156019a775c2Sdrh **
1561626a879aSdrh ** Also resolve function names and check the functions for proper
1562626a879aSdrh ** usage.  Make sure all function names are recognized and all functions
1563626a879aSdrh ** have the correct number of arguments.  Leave an error message
1564626a879aSdrh ** in pParse->zErrMsg if anything is amiss.  Return the number of errors.
1565626a879aSdrh **
156673b211abSdrh ** If the expression contains aggregate functions then set the EP_Agg
156773b211abSdrh ** property on the expression.
1568626a879aSdrh */
1569626a879aSdrh int sqlite3ExprResolveNames(
1570b3bce662Sdanielk1977   NameContext *pNC,       /* Namespace to resolve expressions in. */
1571b3bce662Sdanielk1977   Expr *pExpr             /* The expression to be analyzed. */
1572626a879aSdrh ){
157313449892Sdrh   int savedHasAgg;
1574bb4957f8Sdrh 
157573b211abSdrh   if( pExpr==0 ) return 0;
1576bb4957f8Sdrh #if SQLITE_MAX_EXPR_DEPTH>0
1577bb4957f8Sdrh   {
15784b5255acSdanielk1977     if( checkExprHeight(pNC->pParse, pExpr->nHeight + pNC->pParse->nHeight) ){
1579fc976065Sdanielk1977       return 1;
1580fc976065Sdanielk1977     }
1581fc976065Sdanielk1977     pNC->pParse->nHeight += pExpr->nHeight;
1582bb4957f8Sdrh   }
1583fc976065Sdanielk1977 #endif
158413449892Sdrh   savedHasAgg = pNC->hasAgg;
158513449892Sdrh   pNC->hasAgg = 0;
1586b3bce662Sdanielk1977   walkExprTree(pExpr, nameResolverStep, pNC);
1587bb4957f8Sdrh #if SQLITE_MAX_EXPR_DEPTH>0
1588fc976065Sdanielk1977   pNC->pParse->nHeight -= pExpr->nHeight;
1589fc976065Sdanielk1977 #endif
1590b3bce662Sdanielk1977   if( pNC->nErr>0 ){
159173b211abSdrh     ExprSetProperty(pExpr, EP_Error);
159273b211abSdrh   }
159313449892Sdrh   if( pNC->hasAgg ){
159413449892Sdrh     ExprSetProperty(pExpr, EP_Agg);
159513449892Sdrh   }else if( savedHasAgg ){
159613449892Sdrh     pNC->hasAgg = 1;
159713449892Sdrh   }
159873b211abSdrh   return ExprHasProperty(pExpr, EP_Error);
1599626a879aSdrh }
1600626a879aSdrh 
16011398ad36Sdrh /*
16021398ad36Sdrh ** A pointer instance of this structure is used to pass information
16031398ad36Sdrh ** through walkExprTree into codeSubqueryStep().
16041398ad36Sdrh */
16051398ad36Sdrh typedef struct QueryCoder QueryCoder;
16061398ad36Sdrh struct QueryCoder {
16071398ad36Sdrh   Parse *pParse;       /* The parsing context */
16081398ad36Sdrh   NameContext *pNC;    /* Namespace of first enclosing query */
16091398ad36Sdrh };
16101398ad36Sdrh 
16119a96b668Sdanielk1977 #ifdef SQLITE_TEST
16129a96b668Sdanielk1977   int sqlite3_enable_in_opt = 1;
16139a96b668Sdanielk1977 #else
16149a96b668Sdanielk1977   #define sqlite3_enable_in_opt 1
16159a96b668Sdanielk1977 #endif
16169a96b668Sdanielk1977 
16179a96b668Sdanielk1977 /*
1618b287f4b6Sdrh ** Return true if the IN operator optimization is enabled and
1619b287f4b6Sdrh ** the SELECT statement p exists and is of the
1620b287f4b6Sdrh ** simple form:
1621b287f4b6Sdrh **
1622b287f4b6Sdrh **     SELECT <column> FROM <table>
1623b287f4b6Sdrh **
1624b287f4b6Sdrh ** If this is the case, it may be possible to use an existing table
1625b287f4b6Sdrh ** or index instead of generating an epheremal table.
1626b287f4b6Sdrh */
1627b287f4b6Sdrh #ifndef SQLITE_OMIT_SUBQUERY
1628b287f4b6Sdrh static int isCandidateForInOpt(Select *p){
1629b287f4b6Sdrh   SrcList *pSrc;
1630b287f4b6Sdrh   ExprList *pEList;
1631b287f4b6Sdrh   Table *pTab;
1632b287f4b6Sdrh   if( !sqlite3_enable_in_opt ) return 0; /* IN optimization must be enabled */
1633b287f4b6Sdrh   if( p==0 ) return 0;                   /* right-hand side of IN is SELECT */
1634b287f4b6Sdrh   if( p->pPrior ) return 0;              /* Not a compound SELECT */
1635b287f4b6Sdrh   if( p->isDistinct ) return 0;          /* No DISTINCT keyword */
1636b287f4b6Sdrh   if( p->isAgg ) return 0;               /* Contains no aggregate functions */
1637b287f4b6Sdrh   if( p->pGroupBy ) return 0;            /* Has no GROUP BY clause */
1638b287f4b6Sdrh   if( p->pLimit ) return 0;              /* Has no LIMIT clause */
1639b287f4b6Sdrh   if( p->pOffset ) return 0;
1640b287f4b6Sdrh   if( p->pWhere ) return 0;              /* Has no WHERE clause */
1641b287f4b6Sdrh   pSrc = p->pSrc;
1642b287f4b6Sdrh   if( pSrc==0 ) return 0;                /* A single table in the FROM clause */
1643b287f4b6Sdrh   if( pSrc->nSrc!=1 ) return 0;
1644b287f4b6Sdrh   if( pSrc->a[0].pSelect ) return 0;     /* FROM clause is not a subquery */
1645b287f4b6Sdrh   pTab = pSrc->a[0].pTab;
1646b287f4b6Sdrh   if( pTab==0 ) return 0;
1647b287f4b6Sdrh   if( pTab->pSelect ) return 0;          /* FROM clause is not a view */
1648b287f4b6Sdrh   if( IsVirtual(pTab) ) return 0;        /* FROM clause not a virtual table */
1649b287f4b6Sdrh   pEList = p->pEList;
1650b287f4b6Sdrh   if( pEList->nExpr!=1 ) return 0;       /* One column in the result set */
1651b287f4b6Sdrh   if( pEList->a[0].pExpr->op!=TK_COLUMN ) return 0; /* Result is a column */
1652b287f4b6Sdrh   return 1;
1653b287f4b6Sdrh }
1654b287f4b6Sdrh #endif /* SQLITE_OMIT_SUBQUERY */
1655b287f4b6Sdrh 
1656b287f4b6Sdrh /*
16579a96b668Sdanielk1977 ** This function is used by the implementation of the IN (...) operator.
16589a96b668Sdanielk1977 ** It's job is to find or create a b-tree structure that may be used
16599a96b668Sdanielk1977 ** either to test for membership of the (...) set or to iterate through
166085b623f2Sdrh ** its members, skipping duplicates.
16619a96b668Sdanielk1977 **
16629a96b668Sdanielk1977 ** The cursor opened on the structure (database table, database index
16639a96b668Sdanielk1977 ** or ephermal table) is stored in pX->iTable before this function returns.
16649a96b668Sdanielk1977 ** The returned value indicates the structure type, as follows:
16659a96b668Sdanielk1977 **
16669a96b668Sdanielk1977 **   IN_INDEX_ROWID - The cursor was opened on a database table.
16672d401ab8Sdrh **   IN_INDEX_INDEX - The cursor was opened on a database index.
16689a96b668Sdanielk1977 **   IN_INDEX_EPH -   The cursor was opened on a specially created and
16699a96b668Sdanielk1977 **                    populated epheremal table.
16709a96b668Sdanielk1977 **
16719a96b668Sdanielk1977 ** An existing structure may only be used if the SELECT is of the simple
16729a96b668Sdanielk1977 ** form:
16739a96b668Sdanielk1977 **
16749a96b668Sdanielk1977 **     SELECT <column> FROM <table>
16759a96b668Sdanielk1977 **
16760cdc022eSdanielk1977 ** If prNotFound parameter is 0, then the structure will be used to iterate
16779a96b668Sdanielk1977 ** through the set members, skipping any duplicates. In this case an
16789a96b668Sdanielk1977 ** epheremal table must be used unless the selected <column> is guaranteed
16799a96b668Sdanielk1977 ** to be unique - either because it is an INTEGER PRIMARY KEY or it
16809a96b668Sdanielk1977 ** is unique by virtue of a constraint or implicit index.
16810cdc022eSdanielk1977 **
16820cdc022eSdanielk1977 ** If the prNotFound parameter is not 0, then the structure will be used
16830cdc022eSdanielk1977 ** for fast set membership tests. In this case an epheremal table must
16840cdc022eSdanielk1977 ** be used unless <column> is an INTEGER PRIMARY KEY or an index can
16850cdc022eSdanielk1977 ** be found with <column> as its left-most column.
16860cdc022eSdanielk1977 **
16870cdc022eSdanielk1977 ** When the structure is being used for set membership tests, the user
16880cdc022eSdanielk1977 ** needs to know whether or not the structure contains an SQL NULL
16890cdc022eSdanielk1977 ** value in order to correctly evaluate expressions like "X IN (Y, Z)".
16900cdc022eSdanielk1977 ** If there is a chance that the structure may contain a NULL value at
16910cdc022eSdanielk1977 ** runtime, then a register is allocated and the register number written
16920cdc022eSdanielk1977 ** to *prNotFound. If there is no chance that the structure contains a
16930cdc022eSdanielk1977 ** NULL value, then *prNotFound is left unchanged.
16940cdc022eSdanielk1977 **
16950cdc022eSdanielk1977 ** If a register is allocated and its location stored in *prNotFound, then
16960cdc022eSdanielk1977 ** its initial value is NULL. If the structure does not remain constant
16970cdc022eSdanielk1977 ** for the duration of the query (i.e. the set is a correlated sub-select),
16980cdc022eSdanielk1977 ** the value of the allocated register is reset to NULL each time the
16990cdc022eSdanielk1977 ** structure is repopulated. This allows the caller to use vdbe code
17000cdc022eSdanielk1977 ** equivalent to the following:
17010cdc022eSdanielk1977 **
17020cdc022eSdanielk1977 **   if( register==NULL ){
17030cdc022eSdanielk1977 **     has_null = <test if data structure contains null>
17040cdc022eSdanielk1977 **     register = 1
17050cdc022eSdanielk1977 **   }
17060cdc022eSdanielk1977 **
17070cdc022eSdanielk1977 ** in order to avoid running the <test if data structure contains null>
17080cdc022eSdanielk1977 ** test more often than is necessary.
17099a96b668Sdanielk1977 */
1710284f4acaSdanielk1977 #ifndef SQLITE_OMIT_SUBQUERY
17110cdc022eSdanielk1977 int sqlite3FindInIndex(Parse *pParse, Expr *pX, int *prNotFound){
17129a96b668Sdanielk1977   Select *p;
17139a96b668Sdanielk1977   int eType = 0;
17149a96b668Sdanielk1977   int iTab = pParse->nTab++;
17150cdc022eSdanielk1977   int mustBeUnique = !prNotFound;
17169a96b668Sdanielk1977 
17179a96b668Sdanielk1977   /* The follwing if(...) expression is true if the SELECT is of the
17189a96b668Sdanielk1977   ** simple form:
17199a96b668Sdanielk1977   **
17209a96b668Sdanielk1977   **     SELECT <column> FROM <table>
17219a96b668Sdanielk1977   **
17229a96b668Sdanielk1977   ** If this is the case, it may be possible to use an existing table
17239a96b668Sdanielk1977   ** or index instead of generating an epheremal table.
17249a96b668Sdanielk1977   */
1725b287f4b6Sdrh   p = pX->pSelect;
1726b287f4b6Sdrh   if( isCandidateForInOpt(p) ){
17279a96b668Sdanielk1977     sqlite3 *db = pParse->db;
17289a96b668Sdanielk1977     Index *pIdx;
17299a96b668Sdanielk1977     Expr *pExpr = p->pEList->a[0].pExpr;
17309a96b668Sdanielk1977     int iCol = pExpr->iColumn;
17319a96b668Sdanielk1977     Vdbe *v = sqlite3GetVdbe(pParse);
17329a96b668Sdanielk1977 
17339a96b668Sdanielk1977     /* This function is only called from two places. In both cases the vdbe
17349a96b668Sdanielk1977     ** has already been allocated. So assume sqlite3GetVdbe() is always
17359a96b668Sdanielk1977     ** successful here.
17369a96b668Sdanielk1977     */
17379a96b668Sdanielk1977     assert(v);
17389a96b668Sdanielk1977     if( iCol<0 ){
17390a07c107Sdrh       int iMem = ++pParse->nMem;
17409a96b668Sdanielk1977       int iAddr;
17419a96b668Sdanielk1977       Table *pTab = p->pSrc->a[0].pTab;
17429a96b668Sdanielk1977       int iDb = sqlite3SchemaToIndex(db, pTab->pSchema);
17439a96b668Sdanielk1977       sqlite3VdbeUsesBtree(v, iDb);
17449a96b668Sdanielk1977 
1745892d3179Sdrh       iAddr = sqlite3VdbeAddOp1(v, OP_If, iMem);
17464c583128Sdrh       sqlite3VdbeAddOp2(v, OP_Integer, 1, iMem);
17479a96b668Sdanielk1977 
17489a96b668Sdanielk1977       sqlite3OpenTable(pParse, iTab, iDb, pTab, OP_OpenRead);
17499a96b668Sdanielk1977       eType = IN_INDEX_ROWID;
17509a96b668Sdanielk1977 
17519a96b668Sdanielk1977       sqlite3VdbeJumpHere(v, iAddr);
17529a96b668Sdanielk1977     }else{
17539a96b668Sdanielk1977       /* The collation sequence used by the comparison. If an index is to
17549a96b668Sdanielk1977       ** be used in place of a temp-table, it must be ordered according
17559a96b668Sdanielk1977       ** to this collation sequence.
17569a96b668Sdanielk1977       */
17579a96b668Sdanielk1977       CollSeq *pReq = sqlite3BinaryCompareCollSeq(pParse, pX->pLeft, pExpr);
17589a96b668Sdanielk1977 
17599a96b668Sdanielk1977       /* Check that the affinity that will be used to perform the
17609a96b668Sdanielk1977       ** comparison is the same as the affinity of the column. If
17619a96b668Sdanielk1977       ** it is not, it is not possible to use any index.
17629a96b668Sdanielk1977       */
17639a96b668Sdanielk1977       Table *pTab = p->pSrc->a[0].pTab;
17649a96b668Sdanielk1977       char aff = comparisonAffinity(pX);
17659a96b668Sdanielk1977       int affinity_ok = (pTab->aCol[iCol].affinity==aff||aff==SQLITE_AFF_NONE);
17669a96b668Sdanielk1977 
17679a96b668Sdanielk1977       for(pIdx=pTab->pIndex; pIdx && eType==0 && affinity_ok; pIdx=pIdx->pNext){
17689a96b668Sdanielk1977         if( (pIdx->aiColumn[0]==iCol)
17699a96b668Sdanielk1977          && (pReq==sqlite3FindCollSeq(db, ENC(db), pIdx->azColl[0], -1, 0))
17709a96b668Sdanielk1977          && (!mustBeUnique || (pIdx->nColumn==1 && pIdx->onError!=OE_None))
17719a96b668Sdanielk1977         ){
17729a96b668Sdanielk1977           int iDb;
17730a07c107Sdrh           int iMem = ++pParse->nMem;
17749a96b668Sdanielk1977           int iAddr;
17759a96b668Sdanielk1977           char *pKey;
17769a96b668Sdanielk1977 
17779a96b668Sdanielk1977           pKey = (char *)sqlite3IndexKeyinfo(pParse, pIdx);
17789a96b668Sdanielk1977           iDb = sqlite3SchemaToIndex(db, pIdx->pSchema);
17799a96b668Sdanielk1977           sqlite3VdbeUsesBtree(v, iDb);
17809a96b668Sdanielk1977 
1781892d3179Sdrh           iAddr = sqlite3VdbeAddOp1(v, OP_If, iMem);
17824c583128Sdrh           sqlite3VdbeAddOp2(v, OP_Integer, 1, iMem);
17839a96b668Sdanielk1977 
1784cd3e8f7cSdanielk1977           sqlite3VdbeAddOp2(v, OP_SetNumColumns, 0, pIdx->nColumn);
1785207872a4Sdanielk1977           sqlite3VdbeAddOp4(v, OP_OpenRead, iTab, pIdx->tnum, iDb,
178666a5167bSdrh                                pKey,P4_KEYINFO_HANDOFF);
1787207872a4Sdanielk1977           VdbeComment((v, "%s", pIdx->zName));
17889a96b668Sdanielk1977           eType = IN_INDEX_INDEX;
17899a96b668Sdanielk1977 
17909a96b668Sdanielk1977           sqlite3VdbeJumpHere(v, iAddr);
17910cdc022eSdanielk1977           if( prNotFound && !pTab->aCol[iCol].notNull ){
17920cdc022eSdanielk1977             *prNotFound = ++pParse->nMem;
17930cdc022eSdanielk1977           }
17949a96b668Sdanielk1977         }
17959a96b668Sdanielk1977       }
17969a96b668Sdanielk1977     }
17979a96b668Sdanielk1977   }
17989a96b668Sdanielk1977 
17999a96b668Sdanielk1977   if( eType==0 ){
18000cdc022eSdanielk1977     int rMayHaveNull = 0;
18010cdc022eSdanielk1977     if( prNotFound ){
18020cdc022eSdanielk1977       *prNotFound = rMayHaveNull = ++pParse->nMem;
18030cdc022eSdanielk1977     }
18040cdc022eSdanielk1977     sqlite3CodeSubselect(pParse, pX, rMayHaveNull);
18059a96b668Sdanielk1977     eType = IN_INDEX_EPH;
18069a96b668Sdanielk1977   }else{
18079a96b668Sdanielk1977     pX->iTable = iTab;
18089a96b668Sdanielk1977   }
18099a96b668Sdanielk1977   return eType;
18109a96b668Sdanielk1977 }
1811284f4acaSdanielk1977 #endif
1812626a879aSdrh 
1813626a879aSdrh /*
18149cbe6352Sdrh ** Generate code for scalar subqueries used as an expression
18159cbe6352Sdrh ** and IN operators.  Examples:
1816626a879aSdrh **
18179cbe6352Sdrh **     (SELECT a FROM b)          -- subquery
18189cbe6352Sdrh **     EXISTS (SELECT a FROM b)   -- EXISTS subquery
18199cbe6352Sdrh **     x IN (4,5,11)              -- IN operator with list on right-hand side
18209cbe6352Sdrh **     x IN (SELECT a FROM b)     -- IN operator with subquery on the right
1821fef5208cSdrh **
18229cbe6352Sdrh ** The pExpr parameter describes the expression that contains the IN
18239cbe6352Sdrh ** operator or subquery.
1824cce7d176Sdrh */
182551522cd3Sdrh #ifndef SQLITE_OMIT_SUBQUERY
18260cdc022eSdanielk1977 void sqlite3CodeSubselect(Parse *pParse, Expr *pExpr, int rMayHaveNull){
182757dbd7b3Sdrh   int testAddr = 0;                       /* One-time test address */
1828b3bce662Sdanielk1977   Vdbe *v = sqlite3GetVdbe(pParse);
1829b3bce662Sdanielk1977   if( v==0 ) return;
1830b3bce662Sdanielk1977 
1831fc976065Sdanielk1977 
183257dbd7b3Sdrh   /* This code must be run in its entirety every time it is encountered
183357dbd7b3Sdrh   ** if any of the following is true:
183457dbd7b3Sdrh   **
183557dbd7b3Sdrh   **    *  The right-hand side is a correlated subquery
183657dbd7b3Sdrh   **    *  The right-hand side is an expression list containing variables
183757dbd7b3Sdrh   **    *  We are inside a trigger
183857dbd7b3Sdrh   **
183957dbd7b3Sdrh   ** If all of the above are false, then we can run this code just once
184057dbd7b3Sdrh   ** save the results, and reuse the same result on subsequent invocations.
1841b3bce662Sdanielk1977   */
1842b3bce662Sdanielk1977   if( !ExprHasAnyProperty(pExpr, EP_VarSelect) && !pParse->trigStack ){
18430a07c107Sdrh     int mem = ++pParse->nMem;
1844892d3179Sdrh     sqlite3VdbeAddOp1(v, OP_If, mem);
1845892d3179Sdrh     testAddr = sqlite3VdbeAddOp2(v, OP_Integer, 1, mem);
184617435752Sdrh     assert( testAddr>0 || pParse->db->mallocFailed );
1847b3bce662Sdanielk1977   }
1848b3bce662Sdanielk1977 
1849cce7d176Sdrh   switch( pExpr->op ){
1850fef5208cSdrh     case TK_IN: {
1851e014a838Sdanielk1977       char affinity;
1852d3d39e93Sdrh       KeyInfo keyInfo;
1853b9bb7c18Sdrh       int addr;        /* Address of OP_OpenEphemeral instruction */
1854d3d39e93Sdrh 
18550cdc022eSdanielk1977       if( rMayHaveNull ){
18560cdc022eSdanielk1977         sqlite3VdbeAddOp2(v, OP_Null, 0, rMayHaveNull);
18570cdc022eSdanielk1977       }
18580cdc022eSdanielk1977 
1859bf3b721fSdanielk1977       affinity = sqlite3ExprAffinity(pExpr->pLeft);
1860e014a838Sdanielk1977 
1861e014a838Sdanielk1977       /* Whether this is an 'x IN(SELECT...)' or an 'x IN(<exprlist>)'
186257dbd7b3Sdrh       ** expression it is handled the same way. A virtual table is
1863e014a838Sdanielk1977       ** filled with single-field index keys representing the results
1864e014a838Sdanielk1977       ** from the SELECT or the <exprlist>.
1865fef5208cSdrh       **
1866e014a838Sdanielk1977       ** If the 'x' expression is a column value, or the SELECT...
1867e014a838Sdanielk1977       ** statement returns a column value, then the affinity of that
1868e014a838Sdanielk1977       ** column is used to build the index keys. If both 'x' and the
1869e014a838Sdanielk1977       ** SELECT... statement are columns, then numeric affinity is used
1870e014a838Sdanielk1977       ** if either column has NUMERIC or INTEGER affinity. If neither
1871e014a838Sdanielk1977       ** 'x' nor the SELECT... statement are columns, then numeric affinity
1872e014a838Sdanielk1977       ** is used.
1873fef5208cSdrh       */
1874832508b7Sdrh       pExpr->iTable = pParse->nTab++;
1875cd3e8f7cSdanielk1977       addr = sqlite3VdbeAddOp2(v, OP_OpenEphemeral, pExpr->iTable, 1);
1876d3d39e93Sdrh       memset(&keyInfo, 0, sizeof(keyInfo));
1877d3d39e93Sdrh       keyInfo.nField = 1;
1878e014a838Sdanielk1977 
1879e014a838Sdanielk1977       if( pExpr->pSelect ){
1880e014a838Sdanielk1977         /* Case 1:     expr IN (SELECT ...)
1881e014a838Sdanielk1977         **
1882e014a838Sdanielk1977         ** Generate code to write the results of the select into the temporary
1883e014a838Sdanielk1977         ** table allocated and opened above.
1884e014a838Sdanielk1977         */
18851013c932Sdrh         SelectDest dest;
1886be5c89acSdrh         ExprList *pEList;
18871013c932Sdrh 
18881013c932Sdrh         sqlite3SelectDestInit(&dest, SRT_Set, pExpr->iTable);
18891013c932Sdrh         dest.affinity = (int)affinity;
1890e014a838Sdanielk1977         assert( (pExpr->iTable&0x0000FFFF)==pExpr->iTable );
18916c8c8ce0Sdanielk1977         if( sqlite3Select(pParse, pExpr->pSelect, &dest, 0, 0, 0, 0) ){
189294ccde58Sdrh           return;
189394ccde58Sdrh         }
1894be5c89acSdrh         pEList = pExpr->pSelect->pEList;
1895be5c89acSdrh         if( pEList && pEList->nExpr>0 ){
1896bcbb04e5Sdanielk1977           keyInfo.aColl[0] = sqlite3BinaryCompareCollSeq(pParse, pExpr->pLeft,
1897be5c89acSdrh               pEList->a[0].pExpr);
18980202b29eSdanielk1977         }
1899fef5208cSdrh       }else if( pExpr->pList ){
1900fef5208cSdrh         /* Case 2:     expr IN (exprlist)
1901fef5208cSdrh         **
1902e014a838Sdanielk1977         ** For each expression, build an index key from the evaluation and
1903e014a838Sdanielk1977         ** store it in the temporary table. If <expr> is a column, then use
1904e014a838Sdanielk1977         ** that columns affinity when building index keys. If <expr> is not
1905e014a838Sdanielk1977         ** a column, use numeric affinity.
1906fef5208cSdrh         */
1907e014a838Sdanielk1977         int i;
190857dbd7b3Sdrh         ExprList *pList = pExpr->pList;
190957dbd7b3Sdrh         struct ExprList_item *pItem;
1910ecc31805Sdrh         int r1, r2, r3;
191157dbd7b3Sdrh 
1912e014a838Sdanielk1977         if( !affinity ){
19138159a35fSdrh           affinity = SQLITE_AFF_NONE;
1914e014a838Sdanielk1977         }
19150202b29eSdanielk1977         keyInfo.aColl[0] = pExpr->pLeft->pColl;
1916e014a838Sdanielk1977 
1917e014a838Sdanielk1977         /* Loop through each expression in <exprlist>. */
19182d401ab8Sdrh         r1 = sqlite3GetTempReg(pParse);
19192d401ab8Sdrh         r2 = sqlite3GetTempReg(pParse);
192057dbd7b3Sdrh         for(i=pList->nExpr, pItem=pList->a; i>0; i--, pItem++){
192157dbd7b3Sdrh           Expr *pE2 = pItem->pExpr;
1922e014a838Sdanielk1977 
192357dbd7b3Sdrh           /* If the expression is not constant then we will need to
192457dbd7b3Sdrh           ** disable the test that was generated above that makes sure
192557dbd7b3Sdrh           ** this code only executes once.  Because for a non-constant
192657dbd7b3Sdrh           ** expression we need to rerun this code each time.
192757dbd7b3Sdrh           */
1928892d3179Sdrh           if( testAddr && !sqlite3ExprIsConstant(pE2) ){
1929892d3179Sdrh             sqlite3VdbeChangeToNoop(v, testAddr-1, 2);
193057dbd7b3Sdrh             testAddr = 0;
19314794b980Sdrh           }
1932e014a838Sdanielk1977 
1933e014a838Sdanielk1977           /* Evaluate the expression and insert it into the temp table */
1934e55cbd72Sdrh           pParse->disableColCache++;
1935ecc31805Sdrh           r3 = sqlite3ExprCodeTarget(pParse, pE2, r1);
1936c5499befSdrh           assert( pParse->disableColCache>0 );
1937e55cbd72Sdrh           pParse->disableColCache--;
1938ecc31805Sdrh           sqlite3VdbeAddOp4(v, OP_MakeRecord, r3, 1, r2, &affinity, 1);
19393c31fc23Sdrh           sqlite3ExprCacheAffinityChange(pParse, r3, 1);
19402d401ab8Sdrh           sqlite3VdbeAddOp2(v, OP_IdxInsert, pExpr->iTable, r2);
1941fef5208cSdrh         }
19422d401ab8Sdrh         sqlite3ReleaseTempReg(pParse, r1);
19432d401ab8Sdrh         sqlite3ReleaseTempReg(pParse, r2);
1944fef5208cSdrh       }
194566a5167bSdrh       sqlite3VdbeChangeP4(v, addr, (void *)&keyInfo, P4_KEYINFO);
1946b3bce662Sdanielk1977       break;
1947fef5208cSdrh     }
1948fef5208cSdrh 
194951522cd3Sdrh     case TK_EXISTS:
195019a775c2Sdrh     case TK_SELECT: {
1951fef5208cSdrh       /* This has to be a scalar SELECT.  Generate code to put the
1952fef5208cSdrh       ** value of this select in a memory cell and record the number
1953967e8b73Sdrh       ** of the memory cell in iColumn.
1954fef5208cSdrh       */
19552646da7eSdrh       static const Token one = { (u8*)"1", 0, 1 };
195651522cd3Sdrh       Select *pSel;
19576c8c8ce0Sdanielk1977       SelectDest dest;
19581398ad36Sdrh 
195951522cd3Sdrh       pSel = pExpr->pSelect;
19601013c932Sdrh       sqlite3SelectDestInit(&dest, 0, ++pParse->nMem);
196151522cd3Sdrh       if( pExpr->op==TK_SELECT ){
19626c8c8ce0Sdanielk1977         dest.eDest = SRT_Mem;
19634c583128Sdrh         sqlite3VdbeAddOp2(v, OP_Null, 0, dest.iParm);
1964d4e70ebdSdrh         VdbeComment((v, "Init subquery result"));
196551522cd3Sdrh       }else{
19666c8c8ce0Sdanielk1977         dest.eDest = SRT_Exists;
19674c583128Sdrh         sqlite3VdbeAddOp2(v, OP_Integer, 0, dest.iParm);
1968d4e70ebdSdrh         VdbeComment((v, "Init EXISTS result"));
196951522cd3Sdrh       }
1970ec7429aeSdrh       sqlite3ExprDelete(pSel->pLimit);
1971a1644fd8Sdanielk1977       pSel->pLimit = sqlite3PExpr(pParse, TK_INTEGER, 0, 0, &one);
19726c8c8ce0Sdanielk1977       if( sqlite3Select(pParse, pSel, &dest, 0, 0, 0, 0) ){
197394ccde58Sdrh         return;
197494ccde58Sdrh       }
19756c8c8ce0Sdanielk1977       pExpr->iColumn = dest.iParm;
1976b3bce662Sdanielk1977       break;
197719a775c2Sdrh     }
1978cce7d176Sdrh   }
1979b3bce662Sdanielk1977 
198057dbd7b3Sdrh   if( testAddr ){
1981892d3179Sdrh     sqlite3VdbeJumpHere(v, testAddr-1);
1982b3bce662Sdanielk1977   }
1983fc976065Sdanielk1977 
1984b3bce662Sdanielk1977   return;
1985cce7d176Sdrh }
198651522cd3Sdrh #endif /* SQLITE_OMIT_SUBQUERY */
1987cce7d176Sdrh 
1988cce7d176Sdrh /*
1989598f1340Sdrh ** Duplicate an 8-byte value
1990598f1340Sdrh */
1991598f1340Sdrh static char *dup8bytes(Vdbe *v, const char *in){
1992598f1340Sdrh   char *out = sqlite3DbMallocRaw(sqlite3VdbeDb(v), 8);
1993598f1340Sdrh   if( out ){
1994598f1340Sdrh     memcpy(out, in, 8);
1995598f1340Sdrh   }
1996598f1340Sdrh   return out;
1997598f1340Sdrh }
1998598f1340Sdrh 
1999598f1340Sdrh /*
2000598f1340Sdrh ** Generate an instruction that will put the floating point
20019cbf3425Sdrh ** value described by z[0..n-1] into register iMem.
20020cf19ed8Sdrh **
20030cf19ed8Sdrh ** The z[] string will probably not be zero-terminated.  But the
20040cf19ed8Sdrh ** z[n] character is guaranteed to be something that does not look
20050cf19ed8Sdrh ** like the continuation of the number.
2006598f1340Sdrh */
20079de221dfSdrh static void codeReal(Vdbe *v, const char *z, int n, int negateFlag, int iMem){
2008598f1340Sdrh   assert( z || v==0 || sqlite3VdbeDb(v)->mallocFailed );
2009598f1340Sdrh   if( z ){
2010598f1340Sdrh     double value;
2011598f1340Sdrh     char *zV;
20120cf19ed8Sdrh     assert( !isdigit(z[n]) );
2013598f1340Sdrh     sqlite3AtoF(z, &value);
20142eaf93d3Sdrh     if( sqlite3IsNaN(value) ){
20152eaf93d3Sdrh       sqlite3VdbeAddOp2(v, OP_Null, 0, iMem);
20162eaf93d3Sdrh     }else{
2017598f1340Sdrh       if( negateFlag ) value = -value;
2018598f1340Sdrh       zV = dup8bytes(v, (char*)&value);
20199de221dfSdrh       sqlite3VdbeAddOp4(v, OP_Real, 0, iMem, 0, zV, P4_REAL);
2020598f1340Sdrh     }
2021598f1340Sdrh   }
20222eaf93d3Sdrh }
2023598f1340Sdrh 
2024598f1340Sdrh 
2025598f1340Sdrh /*
2026fec19aadSdrh ** Generate an instruction that will put the integer describe by
20279cbf3425Sdrh ** text z[0..n-1] into register iMem.
20280cf19ed8Sdrh **
20290cf19ed8Sdrh ** The z[] string will probably not be zero-terminated.  But the
20300cf19ed8Sdrh ** z[n] character is guaranteed to be something that does not look
20310cf19ed8Sdrh ** like the continuation of the number.
2032fec19aadSdrh */
203392b01d53Sdrh static void codeInteger(Vdbe *v, Expr *pExpr, int negFlag, int iMem){
203492b01d53Sdrh   const char *z;
203592b01d53Sdrh   if( pExpr->flags & EP_IntValue ){
203692b01d53Sdrh     int i = pExpr->iTable;
203792b01d53Sdrh     if( negFlag ) i = -i;
203892b01d53Sdrh     sqlite3VdbeAddOp2(v, OP_Integer, i, iMem);
203992b01d53Sdrh   }else if( (z = (char*)pExpr->token.z)!=0 ){
2040fec19aadSdrh     int i;
204192b01d53Sdrh     int n = pExpr->token.n;
20420cf19ed8Sdrh     assert( !isdigit(z[n]) );
20436fec0762Sdrh     if( sqlite3GetInt32(z, &i) ){
20449de221dfSdrh       if( negFlag ) i = -i;
20459de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Integer, i, iMem);
20469de221dfSdrh     }else if( sqlite3FitsIn64Bits(z, negFlag) ){
2047598f1340Sdrh       i64 value;
2048598f1340Sdrh       char *zV;
2049598f1340Sdrh       sqlite3Atoi64(z, &value);
20509de221dfSdrh       if( negFlag ) value = -value;
2051598f1340Sdrh       zV = dup8bytes(v, (char*)&value);
20529de221dfSdrh       sqlite3VdbeAddOp4(v, OP_Int64, 0, iMem, 0, zV, P4_INT64);
2053fec19aadSdrh     }else{
20549de221dfSdrh       codeReal(v, z, n, negFlag, iMem);
2055fec19aadSdrh     }
2056fec19aadSdrh   }
2057c9cf901dSdanielk1977 }
2058fec19aadSdrh 
2059945498f3Sdrh 
2060945498f3Sdrh /*
2061945498f3Sdrh ** Generate code that will extract the iColumn-th column from
2062e55cbd72Sdrh ** table pTab and store the column value in a register.  An effort
2063e55cbd72Sdrh ** is made to store the column value in register iReg, but this is
2064e55cbd72Sdrh ** not guaranteed.  The location of the column value is returned.
2065e55cbd72Sdrh **
2066e55cbd72Sdrh ** There must be an open cursor to pTab in iTable when this routine
2067e55cbd72Sdrh ** is called.  If iColumn<0 then code is generated that extracts the rowid.
2068da250ea5Sdrh **
2069da250ea5Sdrh ** This routine might attempt to reuse the value of the column that
2070da250ea5Sdrh ** has already been loaded into a register.  The value will always
2071da250ea5Sdrh ** be used if it has not undergone any affinity changes.  But if
2072da250ea5Sdrh ** an affinity change has occurred, then the cached value will only be
2073da250ea5Sdrh ** used if allowAffChng is true.
2074945498f3Sdrh */
2075e55cbd72Sdrh int sqlite3ExprCodeGetColumn(
2076e55cbd72Sdrh   Parse *pParse,   /* Parsing and code generating context */
20772133d822Sdrh   Table *pTab,     /* Description of the table we are reading from */
20782133d822Sdrh   int iColumn,     /* Index of the table column */
20792133d822Sdrh   int iTable,      /* The cursor pointing to the table */
2080da250ea5Sdrh   int iReg,        /* Store results here */
2081da250ea5Sdrh   int allowAffChng /* True if prior affinity changes are OK */
20822133d822Sdrh ){
2083e55cbd72Sdrh   Vdbe *v = pParse->pVdbe;
2084e55cbd72Sdrh   int i;
2085da250ea5Sdrh   struct yColCache *p;
2086e55cbd72Sdrh 
2087da250ea5Sdrh   for(i=0, p=pParse->aColCache; i<pParse->nColCache; i++, p++){
2088da250ea5Sdrh     if( p->iTable==iTable && p->iColumn==iColumn
2089da250ea5Sdrh            && (!p->affChange || allowAffChng) ){
2090e55cbd72Sdrh #if 0
2091e55cbd72Sdrh       sqlite3VdbeAddOp0(v, OP_Noop);
2092da250ea5Sdrh       VdbeComment((v, "OPT: tab%d.col%d -> r%d", iTable, iColumn, p->iReg));
2093e55cbd72Sdrh #endif
2094da250ea5Sdrh       return p->iReg;
2095e55cbd72Sdrh     }
2096e55cbd72Sdrh   }
2097e55cbd72Sdrh   assert( v!=0 );
2098945498f3Sdrh   if( iColumn<0 ){
2099945498f3Sdrh     int op = (pTab && IsVirtual(pTab)) ? OP_VRowid : OP_Rowid;
21002133d822Sdrh     sqlite3VdbeAddOp2(v, op, iTable, iReg);
2101945498f3Sdrh   }else if( pTab==0 ){
21022133d822Sdrh     sqlite3VdbeAddOp3(v, OP_Column, iTable, iColumn, iReg);
2103945498f3Sdrh   }else{
2104945498f3Sdrh     int op = IsVirtual(pTab) ? OP_VColumn : OP_Column;
21052133d822Sdrh     sqlite3VdbeAddOp3(v, op, iTable, iColumn, iReg);
2106945498f3Sdrh     sqlite3ColumnDefault(v, pTab, iColumn);
2107945498f3Sdrh #ifndef SQLITE_OMIT_FLOATING_POINT
2108945498f3Sdrh     if( pTab->aCol[iColumn].affinity==SQLITE_AFF_REAL ){
21092133d822Sdrh       sqlite3VdbeAddOp1(v, OP_RealAffinity, iReg);
2110945498f3Sdrh     }
2111945498f3Sdrh #endif
2112945498f3Sdrh   }
2113e55cbd72Sdrh   if( pParse->disableColCache==0 ){
2114e55cbd72Sdrh     i = pParse->iColCache;
2115da250ea5Sdrh     p = &pParse->aColCache[i];
2116da250ea5Sdrh     p->iTable = iTable;
2117da250ea5Sdrh     p->iColumn = iColumn;
2118da250ea5Sdrh     p->iReg = iReg;
2119c5499befSdrh     p->affChange = 0;
2120e55cbd72Sdrh     i++;
21212f7794c1Sdrh     if( i>=ArraySize(pParse->aColCache) ) i = 0;
2122e55cbd72Sdrh     if( i>pParse->nColCache ) pParse->nColCache = i;
21232f7794c1Sdrh     pParse->iColCache = i;
2124e55cbd72Sdrh   }
2125e55cbd72Sdrh   return iReg;
2126e55cbd72Sdrh }
2127e55cbd72Sdrh 
2128e55cbd72Sdrh /*
2129e55cbd72Sdrh ** Clear all column cache entries associated with the vdbe
2130e55cbd72Sdrh ** cursor with cursor number iTable.
2131e55cbd72Sdrh */
2132e55cbd72Sdrh void sqlite3ExprClearColumnCache(Parse *pParse, int iTable){
2133e55cbd72Sdrh   if( iTable<0 ){
2134e55cbd72Sdrh     pParse->nColCache = 0;
2135e55cbd72Sdrh     pParse->iColCache = 0;
2136e55cbd72Sdrh   }else{
2137e55cbd72Sdrh     int i;
2138e55cbd72Sdrh     for(i=0; i<pParse->nColCache; i++){
2139e55cbd72Sdrh       if( pParse->aColCache[i].iTable==iTable ){
2140c5499befSdrh         testcase( i==pParse->nColCache-1 );
2141e55cbd72Sdrh         pParse->aColCache[i] = pParse->aColCache[--pParse->nColCache];
2142e55cbd72Sdrh         pParse->iColCache = pParse->nColCache;
2143e55cbd72Sdrh       }
2144e55cbd72Sdrh     }
2145da250ea5Sdrh   }
2146da250ea5Sdrh }
2147e55cbd72Sdrh 
2148e55cbd72Sdrh /*
2149da250ea5Sdrh ** Record the fact that an affinity change has occurred on iCount
2150da250ea5Sdrh ** registers starting with iStart.
2151e55cbd72Sdrh */
2152da250ea5Sdrh void sqlite3ExprCacheAffinityChange(Parse *pParse, int iStart, int iCount){
2153da250ea5Sdrh   int iEnd = iStart + iCount - 1;
2154e55cbd72Sdrh   int i;
2155e55cbd72Sdrh   for(i=0; i<pParse->nColCache; i++){
2156e55cbd72Sdrh     int r = pParse->aColCache[i].iReg;
2157da250ea5Sdrh     if( r>=iStart && r<=iEnd ){
2158da250ea5Sdrh       pParse->aColCache[i].affChange = 1;
2159e55cbd72Sdrh     }
2160e55cbd72Sdrh   }
2161e55cbd72Sdrh }
2162e55cbd72Sdrh 
2163e55cbd72Sdrh /*
2164b21e7c70Sdrh ** Generate code to move content from registers iFrom...iFrom+nReg-1
2165b21e7c70Sdrh ** over to iTo..iTo+nReg-1. Keep the column cache up-to-date.
2166e55cbd72Sdrh */
2167b21e7c70Sdrh void sqlite3ExprCodeMove(Parse *pParse, int iFrom, int iTo, int nReg){
2168e55cbd72Sdrh   int i;
2169e55cbd72Sdrh   if( iFrom==iTo ) return;
2170b21e7c70Sdrh   sqlite3VdbeAddOp3(pParse->pVdbe, OP_Move, iFrom, iTo, nReg);
2171e55cbd72Sdrh   for(i=0; i<pParse->nColCache; i++){
2172b21e7c70Sdrh     int x = pParse->aColCache[i].iReg;
2173b21e7c70Sdrh     if( x>=iFrom && x<iFrom+nReg ){
2174b21e7c70Sdrh       pParse->aColCache[i].iReg += iTo-iFrom;
2175e55cbd72Sdrh     }
2176e55cbd72Sdrh   }
2177945498f3Sdrh }
2178945498f3Sdrh 
2179fec19aadSdrh /*
218092b01d53Sdrh ** Generate code to copy content from registers iFrom...iFrom+nReg-1
218192b01d53Sdrh ** over to iTo..iTo+nReg-1.
218292b01d53Sdrh */
218392b01d53Sdrh void sqlite3ExprCodeCopy(Parse *pParse, int iFrom, int iTo, int nReg){
218492b01d53Sdrh   int i;
218592b01d53Sdrh   if( iFrom==iTo ) return;
218692b01d53Sdrh   for(i=0; i<nReg; i++){
218792b01d53Sdrh     sqlite3VdbeAddOp2(pParse->pVdbe, OP_Copy, iFrom+i, iTo+i);
218892b01d53Sdrh   }
218992b01d53Sdrh }
219092b01d53Sdrh 
219192b01d53Sdrh /*
2192652fbf55Sdrh ** Return true if any register in the range iFrom..iTo (inclusive)
2193652fbf55Sdrh ** is used as part of the column cache.
2194652fbf55Sdrh */
2195652fbf55Sdrh static int usedAsColumnCache(Parse *pParse, int iFrom, int iTo){
2196652fbf55Sdrh   int i;
2197652fbf55Sdrh   for(i=0; i<pParse->nColCache; i++){
2198652fbf55Sdrh     int r = pParse->aColCache[i].iReg;
2199652fbf55Sdrh     if( r>=iFrom && r<=iTo ) return 1;
2200652fbf55Sdrh   }
2201652fbf55Sdrh   return 0;
2202652fbf55Sdrh }
2203652fbf55Sdrh 
2204652fbf55Sdrh /*
2205652fbf55Sdrh ** Theres is a value in register iCurrent.  We ultimately want
2206652fbf55Sdrh ** the value to be in register iTarget.  It might be that
2207652fbf55Sdrh ** iCurrent and iTarget are the same register.
2208652fbf55Sdrh **
2209652fbf55Sdrh ** We are going to modify the value, so we need to make sure it
2210652fbf55Sdrh ** is not a cached register.  If iCurrent is a cached register,
2211652fbf55Sdrh ** then try to move the value over to iTarget.  If iTarget is a
2212652fbf55Sdrh ** cached register, then clear the corresponding cache line.
2213652fbf55Sdrh **
2214652fbf55Sdrh ** Return the register that the value ends up in.
2215652fbf55Sdrh */
2216652fbf55Sdrh int sqlite3ExprWritableRegister(Parse *pParse, int iCurrent, int iTarget){
2217da250ea5Sdrh   int i;
2218652fbf55Sdrh   assert( pParse->pVdbe!=0 );
2219652fbf55Sdrh   if( !usedAsColumnCache(pParse, iCurrent, iCurrent) ){
2220652fbf55Sdrh     return iCurrent;
2221652fbf55Sdrh   }
22222f7794c1Sdrh   if( iCurrent!=iTarget ){
2223652fbf55Sdrh     sqlite3VdbeAddOp2(pParse->pVdbe, OP_SCopy, iCurrent, iTarget);
22242f7794c1Sdrh   }
2225da250ea5Sdrh   for(i=0; i<pParse->nColCache; i++){
2226da250ea5Sdrh     if( pParse->aColCache[i].iReg==iTarget ){
2227da250ea5Sdrh       pParse->aColCache[i] = pParse->aColCache[--pParse->nColCache];
2228da250ea5Sdrh       pParse->iColCache = pParse->nColCache;
2229da250ea5Sdrh     }
2230da250ea5Sdrh   }
2231652fbf55Sdrh   return iTarget;
2232652fbf55Sdrh }
2233652fbf55Sdrh 
2234652fbf55Sdrh /*
2235191b54cbSdrh ** If the last instruction coded is an ephemeral copy of any of
2236191b54cbSdrh ** the registers in the nReg registers beginning with iReg, then
2237191b54cbSdrh ** convert the last instruction from OP_SCopy to OP_Copy.
2238191b54cbSdrh */
2239191b54cbSdrh void sqlite3ExprHardCopy(Parse *pParse, int iReg, int nReg){
2240191b54cbSdrh   int addr;
2241191b54cbSdrh   VdbeOp *pOp;
2242191b54cbSdrh   Vdbe *v;
2243191b54cbSdrh 
2244191b54cbSdrh   v = pParse->pVdbe;
2245191b54cbSdrh   addr = sqlite3VdbeCurrentAddr(v);
2246191b54cbSdrh   pOp = sqlite3VdbeGetOp(v, addr-1);
2247d7eb2ed5Sdanielk1977   assert( pOp || pParse->db->mallocFailed );
2248d7eb2ed5Sdanielk1977   if( pOp && pOp->opcode==OP_SCopy && pOp->p1>=iReg && pOp->p1<iReg+nReg ){
2249191b54cbSdrh     pOp->opcode = OP_Copy;
2250191b54cbSdrh   }
2251191b54cbSdrh }
2252191b54cbSdrh 
2253191b54cbSdrh /*
2254cce7d176Sdrh ** Generate code into the current Vdbe to evaluate the given
22552dcef11bSdrh ** expression.  Attempt to store the results in register "target".
22562dcef11bSdrh ** Return the register where results are stored.
2257389a1adbSdrh **
22582dcef11bSdrh ** With this routine, there is no guaranteed that results will
22592dcef11bSdrh ** be stored in target.  The result might be stored in some other
22602dcef11bSdrh ** register if it is convenient to do so.  The calling function
22612dcef11bSdrh ** must check the return code and move the results to the desired
22622dcef11bSdrh ** register.
2263cce7d176Sdrh */
2264678ccce8Sdrh int sqlite3ExprCodeTarget(Parse *pParse, Expr *pExpr, int target){
22652dcef11bSdrh   Vdbe *v = pParse->pVdbe;  /* The VM under construction */
22662dcef11bSdrh   int op;                   /* The opcode being coded */
22672dcef11bSdrh   int inReg = target;       /* Results stored in register inReg */
22682dcef11bSdrh   int regFree1 = 0;         /* If non-zero free this temporary register */
22692dcef11bSdrh   int regFree2 = 0;         /* If non-zero free this temporary register */
2270678ccce8Sdrh   int r1, r2, r3, r4;       /* Various register numbers */
2271ffe07b2dSdrh 
2272389a1adbSdrh   assert( v!=0 || pParse->db->mallocFailed );
22739cbf3425Sdrh   assert( target>0 && target<=pParse->nMem );
2274389a1adbSdrh   if( v==0 ) return 0;
2275389a1adbSdrh 
2276389a1adbSdrh   if( pExpr==0 ){
2277389a1adbSdrh     op = TK_NULL;
2278389a1adbSdrh   }else{
2279f2bc013cSdrh     op = pExpr->op;
2280389a1adbSdrh   }
2281f2bc013cSdrh   switch( op ){
228213449892Sdrh     case TK_AGG_COLUMN: {
228313449892Sdrh       AggInfo *pAggInfo = pExpr->pAggInfo;
228413449892Sdrh       struct AggInfo_col *pCol = &pAggInfo->aCol[pExpr->iAgg];
228513449892Sdrh       if( !pAggInfo->directMode ){
22869de221dfSdrh         assert( pCol->iMem>0 );
22879de221dfSdrh         inReg = pCol->iMem;
228813449892Sdrh         break;
228913449892Sdrh       }else if( pAggInfo->useSortingIdx ){
2290389a1adbSdrh         sqlite3VdbeAddOp3(v, OP_Column, pAggInfo->sortingIdx,
2291389a1adbSdrh                               pCol->iSorterColumn, target);
229213449892Sdrh         break;
229313449892Sdrh       }
229413449892Sdrh       /* Otherwise, fall thru into the TK_COLUMN case */
229513449892Sdrh     }
2296967e8b73Sdrh     case TK_COLUMN: {
2297ffe07b2dSdrh       if( pExpr->iTable<0 ){
2298ffe07b2dSdrh         /* This only happens when coding check constraints */
2299aa9b8963Sdrh         assert( pParse->ckBase>0 );
2300aa9b8963Sdrh         inReg = pExpr->iColumn + pParse->ckBase;
2301c4a3c779Sdrh       }else{
2302c5499befSdrh         testcase( (pExpr->flags & EP_AnyAff)!=0 );
2303e55cbd72Sdrh         inReg = sqlite3ExprCodeGetColumn(pParse, pExpr->pTab,
2304da250ea5Sdrh                                  pExpr->iColumn, pExpr->iTable, target,
2305da250ea5Sdrh                                  pExpr->flags & EP_AnyAff);
23062282792aSdrh       }
2307cce7d176Sdrh       break;
2308cce7d176Sdrh     }
2309cce7d176Sdrh     case TK_INTEGER: {
231092b01d53Sdrh       codeInteger(v, pExpr, 0, target);
2311fec19aadSdrh       break;
231251e9a445Sdrh     }
2313598f1340Sdrh     case TK_FLOAT: {
23149de221dfSdrh       codeReal(v, (char*)pExpr->token.z, pExpr->token.n, 0, target);
2315598f1340Sdrh       break;
2316598f1340Sdrh     }
2317fec19aadSdrh     case TK_STRING: {
23181e536953Sdanielk1977       sqlite3DequoteExpr(pParse->db, pExpr);
23199de221dfSdrh       sqlite3VdbeAddOp4(v,OP_String8, 0, target, 0,
232066a5167bSdrh                         (char*)pExpr->token.z, pExpr->token.n);
2321cce7d176Sdrh       break;
2322cce7d176Sdrh     }
2323f0863fe5Sdrh     case TK_NULL: {
23249de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Null, 0, target);
2325f0863fe5Sdrh       break;
2326f0863fe5Sdrh     }
23275338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_BLOB_LITERAL
2328c572ef7fSdanielk1977     case TK_BLOB: {
23296c8c6cecSdrh       int n;
23306c8c6cecSdrh       const char *z;
2331ca48c90fSdrh       char *zBlob;
2332ca48c90fSdrh       assert( pExpr->token.n>=3 );
2333ca48c90fSdrh       assert( pExpr->token.z[0]=='x' || pExpr->token.z[0]=='X' );
2334ca48c90fSdrh       assert( pExpr->token.z[1]=='\'' );
2335ca48c90fSdrh       assert( pExpr->token.z[pExpr->token.n-1]=='\'' );
23366c8c6cecSdrh       n = pExpr->token.n - 3;
23372646da7eSdrh       z = (char*)pExpr->token.z + 2;
2338ca48c90fSdrh       zBlob = sqlite3HexToBlob(sqlite3VdbeDb(v), z, n);
2339ca48c90fSdrh       sqlite3VdbeAddOp4(v, OP_Blob, n/2, target, 0, zBlob, P4_DYNAMIC);
2340c572ef7fSdanielk1977       break;
2341c572ef7fSdanielk1977     }
23425338a5f7Sdanielk1977 #endif
234350457896Sdrh     case TK_VARIABLE: {
23449de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Variable, pExpr->iTable, target);
2345895d7472Sdrh       if( pExpr->token.n>1 ){
234666a5167bSdrh         sqlite3VdbeChangeP4(v, -1, (char*)pExpr->token.z, pExpr->token.n);
2347895d7472Sdrh       }
234850457896Sdrh       break;
234950457896Sdrh     }
23504e0cff60Sdrh     case TK_REGISTER: {
23519de221dfSdrh       inReg = pExpr->iTable;
23524e0cff60Sdrh       break;
23534e0cff60Sdrh     }
2354487e262fSdrh #ifndef SQLITE_OMIT_CAST
2355487e262fSdrh     case TK_CAST: {
2356487e262fSdrh       /* Expressions of the form:   CAST(pLeft AS token) */
2357f0113000Sdanielk1977       int aff, to_op;
23582dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
23598a51256cSdrh       aff = sqlite3AffinityType(&pExpr->token);
2360f0113000Sdanielk1977       to_op = aff - SQLITE_AFF_TEXT + OP_ToText;
2361f0113000Sdanielk1977       assert( to_op==OP_ToText    || aff!=SQLITE_AFF_TEXT    );
2362f0113000Sdanielk1977       assert( to_op==OP_ToBlob    || aff!=SQLITE_AFF_NONE    );
2363f0113000Sdanielk1977       assert( to_op==OP_ToNumeric || aff!=SQLITE_AFF_NUMERIC );
2364f0113000Sdanielk1977       assert( to_op==OP_ToInt     || aff!=SQLITE_AFF_INTEGER );
2365f0113000Sdanielk1977       assert( to_op==OP_ToReal    || aff!=SQLITE_AFF_REAL    );
2366c5499befSdrh       testcase( to_op==OP_ToText );
2367c5499befSdrh       testcase( to_op==OP_ToBlob );
2368c5499befSdrh       testcase( to_op==OP_ToNumeric );
2369c5499befSdrh       testcase( to_op==OP_ToInt );
2370c5499befSdrh       testcase( to_op==OP_ToReal );
23712dcef11bSdrh       sqlite3VdbeAddOp1(v, to_op, inReg);
2372c5499befSdrh       testcase( usedAsColumnCache(pParse, inReg, inReg) );
2373b3843a82Sdrh       sqlite3ExprCacheAffinityChange(pParse, inReg, 1);
2374487e262fSdrh       break;
2375487e262fSdrh     }
2376487e262fSdrh #endif /* SQLITE_OMIT_CAST */
2377c9b84a1fSdrh     case TK_LT:
2378c9b84a1fSdrh     case TK_LE:
2379c9b84a1fSdrh     case TK_GT:
2380c9b84a1fSdrh     case TK_GE:
2381c9b84a1fSdrh     case TK_NE:
2382c9b84a1fSdrh     case TK_EQ: {
2383f2bc013cSdrh       assert( TK_LT==OP_Lt );
2384f2bc013cSdrh       assert( TK_LE==OP_Le );
2385f2bc013cSdrh       assert( TK_GT==OP_Gt );
2386f2bc013cSdrh       assert( TK_GE==OP_Ge );
2387f2bc013cSdrh       assert( TK_EQ==OP_Eq );
2388f2bc013cSdrh       assert( TK_NE==OP_Ne );
2389c5499befSdrh       testcase( op==TK_LT );
2390c5499befSdrh       testcase( op==TK_LE );
2391c5499befSdrh       testcase( op==TK_GT );
2392c5499befSdrh       testcase( op==TK_GE );
2393c5499befSdrh       testcase( op==TK_EQ );
2394c5499befSdrh       testcase( op==TK_NE );
2395da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
2396da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
239735573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
239835573356Sdrh                   r1, r2, inReg, SQLITE_STOREP2);
2399c5499befSdrh       testcase( regFree1==0 );
2400c5499befSdrh       testcase( regFree2==0 );
2401a37cdde0Sdanielk1977       break;
2402c9b84a1fSdrh     }
2403cce7d176Sdrh     case TK_AND:
2404cce7d176Sdrh     case TK_OR:
2405cce7d176Sdrh     case TK_PLUS:
2406cce7d176Sdrh     case TK_STAR:
2407cce7d176Sdrh     case TK_MINUS:
2408bf4133cbSdrh     case TK_REM:
2409bf4133cbSdrh     case TK_BITAND:
2410bf4133cbSdrh     case TK_BITOR:
241117c40294Sdrh     case TK_SLASH:
2412bf4133cbSdrh     case TK_LSHIFT:
2413855eb1cfSdrh     case TK_RSHIFT:
24140040077dSdrh     case TK_CONCAT: {
2415f2bc013cSdrh       assert( TK_AND==OP_And );
2416f2bc013cSdrh       assert( TK_OR==OP_Or );
2417f2bc013cSdrh       assert( TK_PLUS==OP_Add );
2418f2bc013cSdrh       assert( TK_MINUS==OP_Subtract );
2419f2bc013cSdrh       assert( TK_REM==OP_Remainder );
2420f2bc013cSdrh       assert( TK_BITAND==OP_BitAnd );
2421f2bc013cSdrh       assert( TK_BITOR==OP_BitOr );
2422f2bc013cSdrh       assert( TK_SLASH==OP_Divide );
2423f2bc013cSdrh       assert( TK_LSHIFT==OP_ShiftLeft );
2424f2bc013cSdrh       assert( TK_RSHIFT==OP_ShiftRight );
2425f2bc013cSdrh       assert( TK_CONCAT==OP_Concat );
2426c5499befSdrh       testcase( op==TK_AND );
2427c5499befSdrh       testcase( op==TK_OR );
2428c5499befSdrh       testcase( op==TK_PLUS );
2429c5499befSdrh       testcase( op==TK_MINUS );
2430c5499befSdrh       testcase( op==TK_REM );
2431c5499befSdrh       testcase( op==TK_BITAND );
2432c5499befSdrh       testcase( op==TK_BITOR );
2433c5499befSdrh       testcase( op==TK_SLASH );
2434c5499befSdrh       testcase( op==TK_LSHIFT );
2435c5499befSdrh       testcase( op==TK_RSHIFT );
2436c5499befSdrh       testcase( op==TK_CONCAT );
24372dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
24382dcef11bSdrh       r2 = sqlite3ExprCodeTemp(pParse, pExpr->pRight, &regFree2);
24395b6afba9Sdrh       sqlite3VdbeAddOp3(v, op, r2, r1, target);
2440c5499befSdrh       testcase( regFree1==0 );
2441c5499befSdrh       testcase( regFree2==0 );
24420040077dSdrh       break;
24430040077dSdrh     }
2444cce7d176Sdrh     case TK_UMINUS: {
2445fec19aadSdrh       Expr *pLeft = pExpr->pLeft;
2446fec19aadSdrh       assert( pLeft );
2447fec19aadSdrh       if( pLeft->op==TK_FLOAT || pLeft->op==TK_INTEGER ){
2448fec19aadSdrh         if( pLeft->op==TK_FLOAT ){
244992b01d53Sdrh           codeReal(v, (char*)pLeft->token.z, pLeft->token.n, 1, target);
2450e6840900Sdrh         }else{
245192b01d53Sdrh           codeInteger(v, pLeft, 1, target);
2452e6840900Sdrh         }
24533c84ddffSdrh       }else{
24542dcef11bSdrh         regFree1 = r1 = sqlite3GetTempReg(pParse);
24553c84ddffSdrh         sqlite3VdbeAddOp2(v, OP_Integer, 0, r1);
2456e55cbd72Sdrh         r2 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree2);
24572dcef11bSdrh         sqlite3VdbeAddOp3(v, OP_Subtract, r2, r1, target);
2458c5499befSdrh         testcase( regFree2==0 );
24593c84ddffSdrh       }
24609de221dfSdrh       inReg = target;
24616e142f54Sdrh       break;
24626e142f54Sdrh     }
2463bf4133cbSdrh     case TK_BITNOT:
24646e142f54Sdrh     case TK_NOT: {
2465f2bc013cSdrh       assert( TK_BITNOT==OP_BitNot );
2466f2bc013cSdrh       assert( TK_NOT==OP_Not );
2467c5499befSdrh       testcase( op==TK_BITNOT );
2468c5499befSdrh       testcase( op==TK_NOT );
24692dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
2470c5499befSdrh       testcase( inReg==target );
2471c5499befSdrh       testcase( usedAsColumnCache(pParse, inReg, inReg) );
2472652fbf55Sdrh       inReg = sqlite3ExprWritableRegister(pParse, inReg, target);
24732dcef11bSdrh       sqlite3VdbeAddOp1(v, op, inReg);
2474cce7d176Sdrh       break;
2475cce7d176Sdrh     }
2476cce7d176Sdrh     case TK_ISNULL:
2477cce7d176Sdrh     case TK_NOTNULL: {
24786a288a33Sdrh       int addr;
2479f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
2480f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
2481c5499befSdrh       testcase( op==TK_ISNULL );
2482c5499befSdrh       testcase( op==TK_NOTNULL );
24839de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Integer, 1, target);
24842dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
2485c5499befSdrh       testcase( regFree1==0 );
24862dcef11bSdrh       addr = sqlite3VdbeAddOp1(v, op, r1);
24879de221dfSdrh       sqlite3VdbeAddOp2(v, OP_AddImm, target, -1);
24886a288a33Sdrh       sqlite3VdbeJumpHere(v, addr);
2489a37cdde0Sdanielk1977       break;
2490f2bc013cSdrh     }
24912282792aSdrh     case TK_AGG_FUNCTION: {
249213449892Sdrh       AggInfo *pInfo = pExpr->pAggInfo;
24937e56e711Sdrh       if( pInfo==0 ){
24947e56e711Sdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate: %T",
24957e56e711Sdrh             &pExpr->span);
24967e56e711Sdrh       }else{
24979de221dfSdrh         inReg = pInfo->aFunc[pExpr->iAgg].iMem;
24987e56e711Sdrh       }
24992282792aSdrh       break;
25002282792aSdrh     }
2501b71090fdSdrh     case TK_CONST_FUNC:
2502cce7d176Sdrh     case TK_FUNCTION: {
2503cce7d176Sdrh       ExprList *pList = pExpr->pList;
250489425d5eSdrh       int nExpr = pList ? pList->nExpr : 0;
25050bce8354Sdrh       FuncDef *pDef;
25064b59ab5eSdrh       int nId;
25074b59ab5eSdrh       const char *zId;
250813449892Sdrh       int constMask = 0;
2509682f68b0Sdanielk1977       int i;
251017435752Sdrh       sqlite3 *db = pParse->db;
251117435752Sdrh       u8 enc = ENC(db);
2512dc1bdc4fSdanielk1977       CollSeq *pColl = 0;
251317435752Sdrh 
2514c5499befSdrh       testcase( op==TK_CONST_FUNC );
2515c5499befSdrh       testcase( op==TK_FUNCTION );
25162646da7eSdrh       zId = (char*)pExpr->token.z;
2517b71090fdSdrh       nId = pExpr->token.n;
2518d8123366Sdanielk1977       pDef = sqlite3FindFunction(pParse->db, zId, nId, nExpr, enc, 0);
25190bce8354Sdrh       assert( pDef!=0 );
2520892d3179Sdrh       if( pList ){
2521892d3179Sdrh         nExpr = pList->nExpr;
25222dcef11bSdrh         r1 = sqlite3GetTempRange(pParse, nExpr);
2523191b54cbSdrh         sqlite3ExprCodeExprList(pParse, pList, r1, 1);
2524892d3179Sdrh       }else{
2525d847eaadSdrh         nExpr = r1 = 0;
2526892d3179Sdrh       }
2527b7f6f68fSdrh #ifndef SQLITE_OMIT_VIRTUALTABLE
2528a43fa227Sdrh       /* Possibly overload the function if the first argument is
2529a43fa227Sdrh       ** a virtual table column.
2530a43fa227Sdrh       **
2531a43fa227Sdrh       ** For infix functions (LIKE, GLOB, REGEXP, and MATCH) use the
2532a43fa227Sdrh       ** second argument, not the first, as the argument to test to
2533a43fa227Sdrh       ** see if it is a column in a virtual table.  This is done because
2534a43fa227Sdrh       ** the left operand of infix functions (the operand we want to
2535a43fa227Sdrh       ** control overloading) ends up as the second argument to the
2536a43fa227Sdrh       ** function.  The expression "A glob B" is equivalent to
2537a43fa227Sdrh       ** "glob(B,A).  We want to use the A in "A glob B" to test
2538a43fa227Sdrh       ** for function overloading.  But we use the B term in "glob(B,A)".
2539a43fa227Sdrh       */
25406a03a1c5Sdrh       if( nExpr>=2 && (pExpr->flags & EP_InfixFunc) ){
254117435752Sdrh         pDef = sqlite3VtabOverloadFunction(db, pDef, nExpr, pList->a[1].pExpr);
25426a03a1c5Sdrh       }else if( nExpr>0 ){
254317435752Sdrh         pDef = sqlite3VtabOverloadFunction(db, pDef, nExpr, pList->a[0].pExpr);
2544b7f6f68fSdrh       }
2545b7f6f68fSdrh #endif
2546682f68b0Sdanielk1977       for(i=0; i<nExpr && i<32; i++){
2547d02eb1fdSdanielk1977         if( sqlite3ExprIsConstant(pList->a[i].pExpr) ){
254813449892Sdrh           constMask |= (1<<i);
2549d02eb1fdSdanielk1977         }
2550dc1bdc4fSdanielk1977         if( pDef->needCollSeq && !pColl ){
2551dc1bdc4fSdanielk1977           pColl = sqlite3ExprCollSeq(pParse, pList->a[i].pExpr);
2552dc1bdc4fSdanielk1977         }
2553dc1bdc4fSdanielk1977       }
2554dc1bdc4fSdanielk1977       if( pDef->needCollSeq ){
2555dc1bdc4fSdanielk1977         if( !pColl ) pColl = pParse->db->pDfltColl;
255666a5167bSdrh         sqlite3VdbeAddOp4(v, OP_CollSeq, 0, 0, 0, (char *)pColl, P4_COLLSEQ);
2557682f68b0Sdanielk1977       }
25582dcef11bSdrh       sqlite3VdbeAddOp4(v, OP_Function, constMask, r1, target,
255966a5167bSdrh                         (char*)pDef, P4_FUNCDEF);
256098757157Sdrh       sqlite3VdbeChangeP5(v, nExpr);
25612dcef11bSdrh       if( nExpr ){
25622dcef11bSdrh         sqlite3ReleaseTempRange(pParse, r1, nExpr);
25632dcef11bSdrh       }
2564da250ea5Sdrh       sqlite3ExprCacheAffinityChange(pParse, r1, nExpr);
25656ec2733bSdrh       break;
25666ec2733bSdrh     }
2567fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
2568fe2093d7Sdrh     case TK_EXISTS:
256919a775c2Sdrh     case TK_SELECT: {
2570c5499befSdrh       testcase( op==TK_EXISTS );
2571c5499befSdrh       testcase( op==TK_SELECT );
257241714d6fSdrh       if( pExpr->iColumn==0 ){
25730cdc022eSdanielk1977         sqlite3CodeSubselect(pParse, pExpr, 0);
257441714d6fSdrh       }
25759de221dfSdrh       inReg = pExpr->iColumn;
257619a775c2Sdrh       break;
257719a775c2Sdrh     }
2578fef5208cSdrh     case TK_IN: {
25790cdc022eSdanielk1977       int rNotFound = 0;
25800cdc022eSdanielk1977       int rMayHaveNull = 0;
2581*6fccc35aSdrh       int j2, j3, j4, j5;
258294a11211Sdrh       char affinity;
25839a96b668Sdanielk1977       int eType;
25849a96b668Sdanielk1977 
25853c31fc23Sdrh       VdbeNoopComment((v, "begin IN expr r%d", target));
25860cdc022eSdanielk1977       eType = sqlite3FindInIndex(pParse, pExpr, &rMayHaveNull);
25870cdc022eSdanielk1977       if( rMayHaveNull ){
25880cdc022eSdanielk1977         rNotFound = ++pParse->nMem;
25890cdc022eSdanielk1977       }
2590e014a838Sdanielk1977 
2591e014a838Sdanielk1977       /* Figure out the affinity to use to create a key from the results
2592e014a838Sdanielk1977       ** of the expression. affinityStr stores a static string suitable for
259366a5167bSdrh       ** P4 of OP_MakeRecord.
2594e014a838Sdanielk1977       */
259594a11211Sdrh       affinity = comparisonAffinity(pExpr);
2596e014a838Sdanielk1977 
2597e014a838Sdanielk1977 
2598e014a838Sdanielk1977       /* Code the <expr> from "<expr> IN (...)". The temporary table
2599e014a838Sdanielk1977       ** pExpr->iTable contains the values that make up the (...) set.
2600e014a838Sdanielk1977       */
260166ba23ceSdrh       pParse->disableColCache++;
260266ba23ceSdrh       sqlite3ExprCode(pParse, pExpr->pLeft, target);
260366ba23ceSdrh       pParse->disableColCache--;
260466ba23ceSdrh       j2 = sqlite3VdbeAddOp1(v, OP_IsNull, target);
26059a96b668Sdanielk1977       if( eType==IN_INDEX_ROWID ){
260666ba23ceSdrh         j3 = sqlite3VdbeAddOp1(v, OP_MustBeInt, target);
260766ba23ceSdrh         j4 = sqlite3VdbeAddOp3(v, OP_NotExists, pExpr->iTable, 0, target);
260866ba23ceSdrh         sqlite3VdbeAddOp2(v, OP_Integer, 1, target);
26096a288a33Sdrh         j5 = sqlite3VdbeAddOp0(v, OP_Goto);
26106a288a33Sdrh         sqlite3VdbeJumpHere(v, j3);
26116a288a33Sdrh         sqlite3VdbeJumpHere(v, j4);
26120cdc022eSdanielk1977         sqlite3VdbeAddOp2(v, OP_Integer, 0, target);
26139a96b668Sdanielk1977       }else{
26142dcef11bSdrh         r2 = regFree2 = sqlite3GetTempReg(pParse);
26150cdc022eSdanielk1977 
26160cdc022eSdanielk1977         /* Create a record and test for set membership. If the set contains
26170cdc022eSdanielk1977         ** the value, then jump to the end of the test code. The target
26180cdc022eSdanielk1977         ** register still contains the true (1) value written to it earlier.
26190cdc022eSdanielk1977         */
262066ba23ceSdrh         sqlite3VdbeAddOp4(v, OP_MakeRecord, target, 1, r2, &affinity, 1);
262166ba23ceSdrh         sqlite3VdbeAddOp2(v, OP_Integer, 1, target);
26222dcef11bSdrh         j5 = sqlite3VdbeAddOp3(v, OP_Found, pExpr->iTable, 0, r2);
26230cdc022eSdanielk1977 
26240cdc022eSdanielk1977         /* If the set membership test fails, then the result of the
26250cdc022eSdanielk1977         ** "x IN (...)" expression must be either 0 or NULL. If the set
26260cdc022eSdanielk1977         ** contains no NULL values, then the result is 0. If the set
26270cdc022eSdanielk1977         ** contains one or more NULL values, then the result of the
26280cdc022eSdanielk1977         ** expression is also NULL.
26290cdc022eSdanielk1977         */
26300cdc022eSdanielk1977         if( rNotFound==0 ){
26310cdc022eSdanielk1977           /* This branch runs if it is known at compile time (now) that
26320cdc022eSdanielk1977           ** the set contains no NULL values. This happens as the result
26330cdc022eSdanielk1977           ** of a "NOT NULL" constraint in the database schema. No need
26340cdc022eSdanielk1977           ** to test the data structure at runtime in this case.
26350cdc022eSdanielk1977           */
26360cdc022eSdanielk1977           sqlite3VdbeAddOp2(v, OP_Integer, 0, target);
26370cdc022eSdanielk1977         }else{
26380cdc022eSdanielk1977           /* This block populates the rNotFound register with either NULL
26390cdc022eSdanielk1977           ** or 0 (an integer value). If the data structure contains one
26400cdc022eSdanielk1977           ** or more NULLs, then set rNotFound to NULL. Otherwise, set it
26410cdc022eSdanielk1977           ** to 0. If register rMayHaveNull is already set to some value
26420cdc022eSdanielk1977           ** other than NULL, then the test has already been run and
26430cdc022eSdanielk1977           ** rNotFound is already populated.
26440cdc022eSdanielk1977           */
264566ba23ceSdrh           static const char nullRecord[] = { 0x02, 0x00 };
26460cdc022eSdanielk1977           j3 = sqlite3VdbeAddOp1(v, OP_NotNull, rMayHaveNull);
26470cdc022eSdanielk1977           sqlite3VdbeAddOp2(v, OP_Null, 0, rNotFound);
264866ba23ceSdrh           sqlite3VdbeAddOp4(v, OP_Blob, 2, rMayHaveNull, 0,
264966ba23ceSdrh                              nullRecord, P4_STATIC);
265066ba23ceSdrh           j4 = sqlite3VdbeAddOp3(v, OP_Found, pExpr->iTable, 0, rMayHaveNull);
26510cdc022eSdanielk1977           sqlite3VdbeAddOp2(v, OP_Integer, 0, rNotFound);
26520cdc022eSdanielk1977           sqlite3VdbeJumpHere(v, j4);
26530cdc022eSdanielk1977           sqlite3VdbeJumpHere(v, j3);
26540cdc022eSdanielk1977 
26550cdc022eSdanielk1977           /* Copy the value of register rNotFound (which is either NULL or 0)
26560cdc022eSdanielk1977 	  ** into the target register. This will be the result of the
26570cdc022eSdanielk1977           ** expression.
26580cdc022eSdanielk1977           */
26590cdc022eSdanielk1977           sqlite3VdbeAddOp2(v, OP_Copy, rNotFound, target);
26609a96b668Sdanielk1977         }
26610cdc022eSdanielk1977       }
26626a288a33Sdrh       sqlite3VdbeJumpHere(v, j2);
26636a288a33Sdrh       sqlite3VdbeJumpHere(v, j5);
26643c31fc23Sdrh       VdbeComment((v, "end IN expr r%d", target));
2665fef5208cSdrh       break;
2666fef5208cSdrh     }
266793758c8dSdanielk1977 #endif
26682dcef11bSdrh     /*
26692dcef11bSdrh     **    x BETWEEN y AND z
26702dcef11bSdrh     **
26712dcef11bSdrh     ** This is equivalent to
26722dcef11bSdrh     **
26732dcef11bSdrh     **    x>=y AND x<=z
26742dcef11bSdrh     **
26752dcef11bSdrh     ** X is stored in pExpr->pLeft.
26762dcef11bSdrh     ** Y is stored in pExpr->pList->a[0].pExpr.
26772dcef11bSdrh     ** Z is stored in pExpr->pList->a[1].pExpr.
26782dcef11bSdrh     */
2679fef5208cSdrh     case TK_BETWEEN: {
2680be5c89acSdrh       Expr *pLeft = pExpr->pLeft;
2681be5c89acSdrh       struct ExprList_item *pLItem = pExpr->pList->a;
2682be5c89acSdrh       Expr *pRight = pLItem->pExpr;
268335573356Sdrh 
2684da250ea5Sdrh       codeCompareOperands(pParse, pLeft, &r1, &regFree1,
2685da250ea5Sdrh                                   pRight, &r2, &regFree2);
2686c5499befSdrh       testcase( regFree1==0 );
2687c5499befSdrh       testcase( regFree2==0 );
26882dcef11bSdrh       r3 = sqlite3GetTempReg(pParse);
2689678ccce8Sdrh       r4 = sqlite3GetTempReg(pParse);
269035573356Sdrh       codeCompare(pParse, pLeft, pRight, OP_Ge,
269135573356Sdrh                   r1, r2, r3, SQLITE_STOREP2);
2692be5c89acSdrh       pLItem++;
2693be5c89acSdrh       pRight = pLItem->pExpr;
26942dcef11bSdrh       sqlite3ReleaseTempReg(pParse, regFree2);
26952dcef11bSdrh       r2 = sqlite3ExprCodeTemp(pParse, pRight, &regFree2);
2696c5499befSdrh       testcase( regFree2==0 );
2697678ccce8Sdrh       codeCompare(pParse, pLeft, pRight, OP_Le, r1, r2, r4, SQLITE_STOREP2);
2698678ccce8Sdrh       sqlite3VdbeAddOp3(v, OP_And, r3, r4, target);
26992dcef11bSdrh       sqlite3ReleaseTempReg(pParse, r3);
2700678ccce8Sdrh       sqlite3ReleaseTempReg(pParse, r4);
2701fef5208cSdrh       break;
2702fef5208cSdrh     }
27034f07e5fbSdrh     case TK_UPLUS: {
27042dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
2705a2e00042Sdrh       break;
2706a2e00042Sdrh     }
27072dcef11bSdrh 
27082dcef11bSdrh     /*
27092dcef11bSdrh     ** Form A:
27102dcef11bSdrh     **   CASE x WHEN e1 THEN r1 WHEN e2 THEN r2 ... WHEN eN THEN rN ELSE y END
27112dcef11bSdrh     **
27122dcef11bSdrh     ** Form B:
27132dcef11bSdrh     **   CASE WHEN e1 THEN r1 WHEN e2 THEN r2 ... WHEN eN THEN rN ELSE y END
27142dcef11bSdrh     **
27152dcef11bSdrh     ** Form A is can be transformed into the equivalent form B as follows:
27162dcef11bSdrh     **   CASE WHEN x=e1 THEN r1 WHEN x=e2 THEN r2 ...
27172dcef11bSdrh     **        WHEN x=eN THEN rN ELSE y END
27182dcef11bSdrh     **
27192dcef11bSdrh     ** X (if it exists) is in pExpr->pLeft.
27202dcef11bSdrh     ** Y is in pExpr->pRight.  The Y is also optional.  If there is no
27212dcef11bSdrh     ** ELSE clause and no other term matches, then the result of the
27222dcef11bSdrh     ** exprssion is NULL.
27232dcef11bSdrh     ** Ei is in pExpr->pList->a[i*2] and Ri is pExpr->pList->a[i*2+1].
27242dcef11bSdrh     **
27252dcef11bSdrh     ** The result of the expression is the Ri for the first matching Ei,
27262dcef11bSdrh     ** or if there is no matching Ei, the ELSE term Y, or if there is
27272dcef11bSdrh     ** no ELSE term, NULL.
27282dcef11bSdrh     */
272917a7f8ddSdrh     case TK_CASE: {
27302dcef11bSdrh       int endLabel;                     /* GOTO label for end of CASE stmt */
27312dcef11bSdrh       int nextCase;                     /* GOTO label for next WHEN clause */
27322dcef11bSdrh       int nExpr;                        /* 2x number of WHEN terms */
27332dcef11bSdrh       int i;                            /* Loop counter */
27342dcef11bSdrh       ExprList *pEList;                 /* List of WHEN terms */
27352dcef11bSdrh       struct ExprList_item *aListelem;  /* Array of WHEN terms */
27362dcef11bSdrh       Expr opCompare;                   /* The X==Ei expression */
27372dcef11bSdrh       Expr cacheX;                      /* Cached expression X */
27382dcef11bSdrh       Expr *pX;                         /* The X expression */
27392dcef11bSdrh       Expr *pTest;                      /* X==Ei (form A) or just Ei (form B) */
274017a7f8ddSdrh 
274117a7f8ddSdrh       assert(pExpr->pList);
274217a7f8ddSdrh       assert((pExpr->pList->nExpr % 2) == 0);
274317a7f8ddSdrh       assert(pExpr->pList->nExpr > 0);
2744be5c89acSdrh       pEList = pExpr->pList;
2745be5c89acSdrh       aListelem = pEList->a;
2746be5c89acSdrh       nExpr = pEList->nExpr;
27472dcef11bSdrh       endLabel = sqlite3VdbeMakeLabel(v);
27482dcef11bSdrh       if( (pX = pExpr->pLeft)!=0 ){
27492dcef11bSdrh         cacheX = *pX;
2750c5499befSdrh         testcase( pX->op==TK_COLUMN || pX->op==TK_REGISTER );
27512dcef11bSdrh         cacheX.iTable = sqlite3ExprCodeTemp(pParse, pX, &regFree1);
2752c5499befSdrh         testcase( regFree1==0 );
27532dcef11bSdrh         cacheX.op = TK_REGISTER;
2754678ccce8Sdrh         cacheX.iColumn = 0;
27552dcef11bSdrh         opCompare.op = TK_EQ;
27562dcef11bSdrh         opCompare.pLeft = &cacheX;
27572dcef11bSdrh         pTest = &opCompare;
2758cce7d176Sdrh       }
2759c5499befSdrh       pParse->disableColCache++;
2760f5905aa7Sdrh       for(i=0; i<nExpr; i=i+2){
27612dcef11bSdrh         if( pX ){
27622dcef11bSdrh           opCompare.pRight = aListelem[i].pExpr;
2763f5905aa7Sdrh         }else{
27642dcef11bSdrh           pTest = aListelem[i].pExpr;
276517a7f8ddSdrh         }
27662dcef11bSdrh         nextCase = sqlite3VdbeMakeLabel(v);
2767c5499befSdrh         testcase( pTest->op==TK_COLUMN || pTest->op==TK_REGISTER );
27682dcef11bSdrh         sqlite3ExprIfFalse(pParse, pTest, nextCase, SQLITE_JUMPIFNULL);
2769c5499befSdrh         testcase( aListelem[i+1].pExpr->op==TK_COLUMN );
2770c5499befSdrh         testcase( aListelem[i+1].pExpr->op==TK_REGISTER );
27719de221dfSdrh         sqlite3ExprCode(pParse, aListelem[i+1].pExpr, target);
27722dcef11bSdrh         sqlite3VdbeAddOp2(v, OP_Goto, 0, endLabel);
27732dcef11bSdrh         sqlite3VdbeResolveLabel(v, nextCase);
2774f570f011Sdrh       }
277517a7f8ddSdrh       if( pExpr->pRight ){
27769de221dfSdrh         sqlite3ExprCode(pParse, pExpr->pRight, target);
277717a7f8ddSdrh       }else{
27789de221dfSdrh         sqlite3VdbeAddOp2(v, OP_Null, 0, target);
277917a7f8ddSdrh       }
27802dcef11bSdrh       sqlite3VdbeResolveLabel(v, endLabel);
2781c5499befSdrh       assert( pParse->disableColCache>0 );
2782c5499befSdrh       pParse->disableColCache--;
27836f34903eSdanielk1977       break;
27846f34903eSdanielk1977     }
27855338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_TRIGGER
27866f34903eSdanielk1977     case TK_RAISE: {
27876f34903eSdanielk1977       if( !pParse->trigStack ){
27884adee20fSdanielk1977         sqlite3ErrorMsg(pParse,
2789da93d238Sdrh                        "RAISE() may only be used within a trigger-program");
2790389a1adbSdrh         return 0;
27916f34903eSdanielk1977       }
2792ad6d9460Sdrh       if( pExpr->iColumn!=OE_Ignore ){
2793ad6d9460Sdrh          assert( pExpr->iColumn==OE_Rollback ||
27946f34903eSdanielk1977                  pExpr->iColumn == OE_Abort ||
2795ad6d9460Sdrh                  pExpr->iColumn == OE_Fail );
27961e536953Sdanielk1977          sqlite3DequoteExpr(pParse->db, pExpr);
279766a5167bSdrh          sqlite3VdbeAddOp4(v, OP_Halt, SQLITE_CONSTRAINT, pExpr->iColumn, 0,
27982646da7eSdrh                         (char*)pExpr->token.z, pExpr->token.n);
27996f34903eSdanielk1977       } else {
28006f34903eSdanielk1977          assert( pExpr->iColumn == OE_Ignore );
280166a5167bSdrh          sqlite3VdbeAddOp2(v, OP_ContextPop, 0, 0);
280266a5167bSdrh          sqlite3VdbeAddOp2(v, OP_Goto, 0, pParse->trigStack->ignoreJump);
2803d4e70ebdSdrh          VdbeComment((v, "raise(IGNORE)"));
28046f34903eSdanielk1977       }
2805ffe07b2dSdrh       break;
280617a7f8ddSdrh     }
28075338a5f7Sdanielk1977 #endif
2808ffe07b2dSdrh   }
28092dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
28102dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
28112dcef11bSdrh   return inReg;
28125b6afba9Sdrh }
28132dcef11bSdrh 
28142dcef11bSdrh /*
28152dcef11bSdrh ** Generate code to evaluate an expression and store the results
28162dcef11bSdrh ** into a register.  Return the register number where the results
28172dcef11bSdrh ** are stored.
28182dcef11bSdrh **
28192dcef11bSdrh ** If the register is a temporary register that can be deallocated,
2820678ccce8Sdrh ** then write its number into *pReg.  If the result register is not
28212dcef11bSdrh ** a temporary, then set *pReg to zero.
28222dcef11bSdrh */
28232dcef11bSdrh int sqlite3ExprCodeTemp(Parse *pParse, Expr *pExpr, int *pReg){
28242dcef11bSdrh   int r1 = sqlite3GetTempReg(pParse);
28252dcef11bSdrh   int r2 = sqlite3ExprCodeTarget(pParse, pExpr, r1);
28262dcef11bSdrh   if( r2==r1 ){
28272dcef11bSdrh     *pReg = r1;
28282dcef11bSdrh   }else{
28292dcef11bSdrh     sqlite3ReleaseTempReg(pParse, r1);
28302dcef11bSdrh     *pReg = 0;
28312dcef11bSdrh   }
28322dcef11bSdrh   return r2;
28332dcef11bSdrh }
28342dcef11bSdrh 
28352dcef11bSdrh /*
28362dcef11bSdrh ** Generate code that will evaluate expression pExpr and store the
28372dcef11bSdrh ** results in register target.  The results are guaranteed to appear
28382dcef11bSdrh ** in register target.
28392dcef11bSdrh */
28402dcef11bSdrh int sqlite3ExprCode(Parse *pParse, Expr *pExpr, int target){
28419cbf3425Sdrh   int inReg;
28429cbf3425Sdrh 
28439cbf3425Sdrh   assert( target>0 && target<=pParse->nMem );
28449cbf3425Sdrh   inReg = sqlite3ExprCodeTarget(pParse, pExpr, target);
28450e359b30Sdrh   assert( pParse->pVdbe || pParse->db->mallocFailed );
28460e359b30Sdrh   if( inReg!=target && pParse->pVdbe ){
28479cbf3425Sdrh     sqlite3VdbeAddOp2(pParse->pVdbe, OP_SCopy, inReg, target);
284817a7f8ddSdrh   }
2849389a1adbSdrh   return target;
2850cce7d176Sdrh }
2851cce7d176Sdrh 
2852cce7d176Sdrh /*
28532dcef11bSdrh ** Generate code that evalutes the given expression and puts the result
2854de4fcfddSdrh ** in register target.
285525303780Sdrh **
28562dcef11bSdrh ** Also make a copy of the expression results into another "cache" register
28572dcef11bSdrh ** and modify the expression so that the next time it is evaluated,
28582dcef11bSdrh ** the result is a copy of the cache register.
28592dcef11bSdrh **
28602dcef11bSdrh ** This routine is used for expressions that are used multiple
28612dcef11bSdrh ** times.  They are evaluated once and the results of the expression
28622dcef11bSdrh ** are reused.
286325303780Sdrh */
28642dcef11bSdrh int sqlite3ExprCodeAndCache(Parse *pParse, Expr *pExpr, int target){
286525303780Sdrh   Vdbe *v = pParse->pVdbe;
28662dcef11bSdrh   int inReg;
28672dcef11bSdrh   inReg = sqlite3ExprCode(pParse, pExpr, target);
2868de4fcfddSdrh   assert( target>0 );
28692dcef11bSdrh   if( pExpr->op!=TK_REGISTER ){
287025303780Sdrh     int iMem;
28712dcef11bSdrh     iMem = ++pParse->nMem;
28722dcef11bSdrh     sqlite3VdbeAddOp2(v, OP_Copy, inReg, iMem);
28732dcef11bSdrh     pExpr->iTable = iMem;
2874678ccce8Sdrh     pExpr->iColumn = pExpr->op;
287525303780Sdrh     pExpr->op = TK_REGISTER;
287625303780Sdrh   }
28772dcef11bSdrh   return inReg;
287825303780Sdrh }
28792dcef11bSdrh 
2880678ccce8Sdrh /*
288147de955eSdrh ** Return TRUE if pExpr is an constant expression that is appropriate
288247de955eSdrh ** for factoring out of a loop.  Appropriate expressions are:
288347de955eSdrh **
288447de955eSdrh **    *  Any expression that evaluates to two or more opcodes.
288547de955eSdrh **
288647de955eSdrh **    *  Any OP_Integer, OP_Real, OP_String, OP_Blob, OP_Null,
288747de955eSdrh **       or OP_Variable that does not need to be placed in a
288847de955eSdrh **       specific register.
288947de955eSdrh **
289047de955eSdrh ** There is no point in factoring out single-instruction constant
289147de955eSdrh ** expressions that need to be placed in a particular register.
289247de955eSdrh ** We could factor them out, but then we would end up adding an
289347de955eSdrh ** OP_SCopy instruction to move the value into the correct register
289447de955eSdrh ** later.  We might as well just use the original instruction and
289547de955eSdrh ** avoid the OP_SCopy.
289647de955eSdrh */
289747de955eSdrh static int isAppropriateForFactoring(Expr *p){
289847de955eSdrh   if( !sqlite3ExprIsConstantNotJoin(p) ){
289947de955eSdrh     return 0;  /* Only constant expressions are appropriate for factoring */
290047de955eSdrh   }
290147de955eSdrh   if( (p->flags & EP_FixedDest)==0 ){
290247de955eSdrh     return 1;  /* Any constant without a fixed destination is appropriate */
290347de955eSdrh   }
290447de955eSdrh   while( p->op==TK_UPLUS ) p = p->pLeft;
290547de955eSdrh   switch( p->op ){
290647de955eSdrh #ifndef SQLITE_OMIT_BLOB_LITERAL
290747de955eSdrh     case TK_BLOB:
290847de955eSdrh #endif
290947de955eSdrh     case TK_VARIABLE:
291047de955eSdrh     case TK_INTEGER:
291147de955eSdrh     case TK_FLOAT:
291247de955eSdrh     case TK_NULL:
291347de955eSdrh     case TK_STRING: {
291447de955eSdrh       testcase( p->op==TK_BLOB );
291547de955eSdrh       testcase( p->op==TK_VARIABLE );
291647de955eSdrh       testcase( p->op==TK_INTEGER );
291747de955eSdrh       testcase( p->op==TK_FLOAT );
291847de955eSdrh       testcase( p->op==TK_NULL );
291947de955eSdrh       testcase( p->op==TK_STRING );
292047de955eSdrh       /* Single-instruction constants with a fixed destination are
292147de955eSdrh       ** better done in-line.  If we factor them, they will just end
292247de955eSdrh       ** up generating an OP_SCopy to move the value to the destination
292347de955eSdrh       ** register. */
292447de955eSdrh       return 0;
292547de955eSdrh     }
292647de955eSdrh     case TK_UMINUS: {
292747de955eSdrh        if( p->pLeft->op==TK_FLOAT || p->pLeft->op==TK_INTEGER ){
292847de955eSdrh          return 0;
292947de955eSdrh        }
293047de955eSdrh        break;
293147de955eSdrh     }
293247de955eSdrh     default: {
293347de955eSdrh       break;
293447de955eSdrh     }
293547de955eSdrh   }
293647de955eSdrh   return 1;
293747de955eSdrh }
293847de955eSdrh 
293947de955eSdrh /*
294047de955eSdrh ** If pExpr is a constant expression that is appropriate for
294147de955eSdrh ** factoring out of a loop, then evaluate the expression
2942678ccce8Sdrh ** into a register and convert the expression into a TK_REGISTER
2943678ccce8Sdrh ** expression.
2944678ccce8Sdrh */
2945678ccce8Sdrh static int evalConstExpr(void *pArg, Expr *pExpr){
2946678ccce8Sdrh   Parse *pParse = (Parse*)pArg;
294747de955eSdrh   switch( pExpr->op ){
294847de955eSdrh     case TK_REGISTER: {
2949678ccce8Sdrh       return 1;
2950678ccce8Sdrh     }
295147de955eSdrh     case TK_FUNCTION:
295247de955eSdrh     case TK_AGG_FUNCTION:
295347de955eSdrh     case TK_CONST_FUNC: {
295447de955eSdrh       /* The arguments to a function have a fixed destination.
295547de955eSdrh       ** Mark them this way to avoid generated unneeded OP_SCopy
295647de955eSdrh       ** instructions.
295747de955eSdrh       */
295847de955eSdrh       ExprList *pList = pExpr->pList;
295947de955eSdrh       if( pList ){
296047de955eSdrh         int i = pList->nExpr;
296147de955eSdrh         struct ExprList_item *pItem = pList->a;
296247de955eSdrh         for(; i>0; i--, pItem++){
296347de955eSdrh           if( pItem->pExpr ) pItem->pExpr->flags |= EP_FixedDest;
296447de955eSdrh         }
296547de955eSdrh       }
296647de955eSdrh       break;
296747de955eSdrh     }
296847de955eSdrh   }
296947de955eSdrh   if( isAppropriateForFactoring(pExpr) ){
2970678ccce8Sdrh     int r1 = ++pParse->nMem;
2971678ccce8Sdrh     int r2;
2972678ccce8Sdrh     r2 = sqlite3ExprCodeTarget(pParse, pExpr, r1);
2973c5499befSdrh     if( r1!=r2 ) sqlite3ReleaseTempReg(pParse, r1);
2974678ccce8Sdrh     pExpr->iColumn = pExpr->op;
2975678ccce8Sdrh     pExpr->op = TK_REGISTER;
2976678ccce8Sdrh     pExpr->iTable = r2;
2977678ccce8Sdrh     return 1;
2978678ccce8Sdrh   }
2979678ccce8Sdrh   return 0;
2980678ccce8Sdrh }
2981678ccce8Sdrh 
2982678ccce8Sdrh /*
2983678ccce8Sdrh ** Preevaluate constant subexpressions within pExpr and store the
2984678ccce8Sdrh ** results in registers.  Modify pExpr so that the constant subexpresions
2985678ccce8Sdrh ** are TK_REGISTER opcodes that refer to the precomputed values.
2986678ccce8Sdrh */
2987678ccce8Sdrh void sqlite3ExprCodeConstants(Parse *pParse, Expr *pExpr){
2988678ccce8Sdrh    walkExprTree(pExpr, evalConstExpr, pParse);
2989678ccce8Sdrh }
2990678ccce8Sdrh 
299125303780Sdrh 
299225303780Sdrh /*
2993268380caSdrh ** Generate code that pushes the value of every element of the given
29949cbf3425Sdrh ** expression list into a sequence of registers beginning at target.
2995268380caSdrh **
2996892d3179Sdrh ** Return the number of elements evaluated.
2997268380caSdrh */
29984adee20fSdanielk1977 int sqlite3ExprCodeExprList(
2999268380caSdrh   Parse *pParse,     /* Parsing context */
3000389a1adbSdrh   ExprList *pList,   /* The expression list to be coded */
3001191b54cbSdrh   int target,        /* Where to write results */
3002191b54cbSdrh   int doHardCopy     /* Call sqlite3ExprHardCopy on each element if true */
3003268380caSdrh ){
3004268380caSdrh   struct ExprList_item *pItem;
30059cbf3425Sdrh   int i, n;
3006892d3179Sdrh   assert( pList!=0 || pParse->db->mallocFailed );
3007892d3179Sdrh   if( pList==0 ){
3008892d3179Sdrh     return 0;
3009892d3179Sdrh   }
30109cbf3425Sdrh   assert( target>0 );
3011268380caSdrh   n = pList->nExpr;
3012191b54cbSdrh   for(pItem=pList->a, i=0; i<n; i++, pItem++){
3013191b54cbSdrh     sqlite3ExprCode(pParse, pItem->pExpr, target+i);
3014191b54cbSdrh     if( doHardCopy ) sqlite3ExprHardCopy(pParse, target, n);
3015268380caSdrh   }
3016f9b596ebSdrh   return n;
3017268380caSdrh }
3018268380caSdrh 
3019268380caSdrh /*
3020cce7d176Sdrh ** Generate code for a boolean expression such that a jump is made
3021cce7d176Sdrh ** to the label "dest" if the expression is true but execution
3022cce7d176Sdrh ** continues straight thru if the expression is false.
3023f5905aa7Sdrh **
3024f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false), then
302535573356Sdrh ** take the jump if the jumpIfNull flag is SQLITE_JUMPIFNULL.
3026f2bc013cSdrh **
3027f2bc013cSdrh ** This code depends on the fact that certain token values (ex: TK_EQ)
3028f2bc013cSdrh ** are the same as opcode values (ex: OP_Eq) that implement the corresponding
3029f2bc013cSdrh ** operation.  Special comments in vdbe.c and the mkopcodeh.awk script in
3030f2bc013cSdrh ** the make process cause these values to align.  Assert()s in the code
3031f2bc013cSdrh ** below verify that the numbers are aligned correctly.
3032cce7d176Sdrh */
30334adee20fSdanielk1977 void sqlite3ExprIfTrue(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
3034cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
3035cce7d176Sdrh   int op = 0;
30362dcef11bSdrh   int regFree1 = 0;
30372dcef11bSdrh   int regFree2 = 0;
30382dcef11bSdrh   int r1, r2;
30392dcef11bSdrh 
304035573356Sdrh   assert( jumpIfNull==SQLITE_JUMPIFNULL || jumpIfNull==0 );
3041daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
3042f2bc013cSdrh   op = pExpr->op;
3043f2bc013cSdrh   switch( op ){
3044cce7d176Sdrh     case TK_AND: {
30454adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
3046c5499befSdrh       testcase( jumpIfNull==0 );
3047c5499befSdrh       testcase( pParse->disableColCache==0 );
304835573356Sdrh       sqlite3ExprIfFalse(pParse, pExpr->pLeft, d2,jumpIfNull^SQLITE_JUMPIFNULL);
3049e55cbd72Sdrh       pParse->disableColCache++;
30504adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
3051c5499befSdrh       assert( pParse->disableColCache>0 );
3052e55cbd72Sdrh       pParse->disableColCache--;
30534adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
3054cce7d176Sdrh       break;
3055cce7d176Sdrh     }
3056cce7d176Sdrh     case TK_OR: {
3057c5499befSdrh       testcase( jumpIfNull==0 );
3058c5499befSdrh       testcase( pParse->disableColCache==0 );
30594adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
3060e55cbd72Sdrh       pParse->disableColCache++;
30614adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
3062c5499befSdrh       assert( pParse->disableColCache>0 );
3063e55cbd72Sdrh       pParse->disableColCache--;
3064cce7d176Sdrh       break;
3065cce7d176Sdrh     }
3066cce7d176Sdrh     case TK_NOT: {
3067c5499befSdrh       testcase( jumpIfNull==0 );
30684adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
3069cce7d176Sdrh       break;
3070cce7d176Sdrh     }
3071cce7d176Sdrh     case TK_LT:
3072cce7d176Sdrh     case TK_LE:
3073cce7d176Sdrh     case TK_GT:
3074cce7d176Sdrh     case TK_GE:
3075cce7d176Sdrh     case TK_NE:
30760ac65892Sdrh     case TK_EQ: {
3077f2bc013cSdrh       assert( TK_LT==OP_Lt );
3078f2bc013cSdrh       assert( TK_LE==OP_Le );
3079f2bc013cSdrh       assert( TK_GT==OP_Gt );
3080f2bc013cSdrh       assert( TK_GE==OP_Ge );
3081f2bc013cSdrh       assert( TK_EQ==OP_Eq );
3082f2bc013cSdrh       assert( TK_NE==OP_Ne );
3083c5499befSdrh       testcase( op==TK_LT );
3084c5499befSdrh       testcase( op==TK_LE );
3085c5499befSdrh       testcase( op==TK_GT );
3086c5499befSdrh       testcase( op==TK_GE );
3087c5499befSdrh       testcase( op==TK_EQ );
3088c5499befSdrh       testcase( op==TK_NE );
3089c5499befSdrh       testcase( jumpIfNull==0 );
3090da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
3091da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
309235573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
30932dcef11bSdrh                   r1, r2, dest, jumpIfNull);
3094c5499befSdrh       testcase( regFree1==0 );
3095c5499befSdrh       testcase( regFree2==0 );
3096cce7d176Sdrh       break;
3097cce7d176Sdrh     }
3098cce7d176Sdrh     case TK_ISNULL:
3099cce7d176Sdrh     case TK_NOTNULL: {
3100f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
3101f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
3102c5499befSdrh       testcase( op==TK_ISNULL );
3103c5499befSdrh       testcase( op==TK_NOTNULL );
31042dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
31052dcef11bSdrh       sqlite3VdbeAddOp2(v, op, r1, dest);
3106c5499befSdrh       testcase( regFree1==0 );
3107cce7d176Sdrh       break;
3108cce7d176Sdrh     }
3109fef5208cSdrh     case TK_BETWEEN: {
31102dcef11bSdrh       /*    x BETWEEN y AND z
31110202b29eSdanielk1977       **
31122dcef11bSdrh       ** Is equivalent to
31132dcef11bSdrh       **
31142dcef11bSdrh       **    x>=y AND x<=z
31152dcef11bSdrh       **
31162dcef11bSdrh       ** Code it as such, taking care to do the common subexpression
31172dcef11bSdrh       ** elementation of x.
31180202b29eSdanielk1977       */
31192dcef11bSdrh       Expr exprAnd;
31202dcef11bSdrh       Expr compLeft;
31212dcef11bSdrh       Expr compRight;
31222dcef11bSdrh       Expr exprX;
31230202b29eSdanielk1977 
31242dcef11bSdrh       exprX = *pExpr->pLeft;
31252dcef11bSdrh       exprAnd.op = TK_AND;
31262dcef11bSdrh       exprAnd.pLeft = &compLeft;
31272dcef11bSdrh       exprAnd.pRight = &compRight;
31282dcef11bSdrh       compLeft.op = TK_GE;
31292dcef11bSdrh       compLeft.pLeft = &exprX;
31302dcef11bSdrh       compLeft.pRight = pExpr->pList->a[0].pExpr;
31312dcef11bSdrh       compRight.op = TK_LE;
31322dcef11bSdrh       compRight.pLeft = &exprX;
31332dcef11bSdrh       compRight.pRight = pExpr->pList->a[1].pExpr;
31342dcef11bSdrh       exprX.iTable = sqlite3ExprCodeTemp(pParse, &exprX, &regFree1);
3135c5499befSdrh       testcase( regFree1==0 );
31362dcef11bSdrh       exprX.op = TK_REGISTER;
3137c5499befSdrh       testcase( jumpIfNull==0 );
31382dcef11bSdrh       sqlite3ExprIfTrue(pParse, &exprAnd, dest, jumpIfNull);
3139fef5208cSdrh       break;
3140fef5208cSdrh     }
3141cce7d176Sdrh     default: {
31422dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr, &regFree1);
31432dcef11bSdrh       sqlite3VdbeAddOp3(v, OP_If, r1, dest, jumpIfNull!=0);
3144c5499befSdrh       testcase( regFree1==0 );
3145c5499befSdrh       testcase( jumpIfNull==0 );
3146cce7d176Sdrh       break;
3147cce7d176Sdrh     }
3148cce7d176Sdrh   }
31492dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
31502dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
3151cce7d176Sdrh }
3152cce7d176Sdrh 
3153cce7d176Sdrh /*
315466b89c8fSdrh ** Generate code for a boolean expression such that a jump is made
3155cce7d176Sdrh ** to the label "dest" if the expression is false but execution
3156cce7d176Sdrh ** continues straight thru if the expression is true.
3157f5905aa7Sdrh **
3158f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false) then
315935573356Sdrh ** jump if jumpIfNull is SQLITE_JUMPIFNULL or fall through if jumpIfNull
316035573356Sdrh ** is 0.
3161cce7d176Sdrh */
31624adee20fSdanielk1977 void sqlite3ExprIfFalse(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
3163cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
3164cce7d176Sdrh   int op = 0;
31652dcef11bSdrh   int regFree1 = 0;
31662dcef11bSdrh   int regFree2 = 0;
31672dcef11bSdrh   int r1, r2;
31682dcef11bSdrh 
316935573356Sdrh   assert( jumpIfNull==SQLITE_JUMPIFNULL || jumpIfNull==0 );
3170daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
3171f2bc013cSdrh 
3172f2bc013cSdrh   /* The value of pExpr->op and op are related as follows:
3173f2bc013cSdrh   **
3174f2bc013cSdrh   **       pExpr->op            op
3175f2bc013cSdrh   **       ---------          ----------
3176f2bc013cSdrh   **       TK_ISNULL          OP_NotNull
3177f2bc013cSdrh   **       TK_NOTNULL         OP_IsNull
3178f2bc013cSdrh   **       TK_NE              OP_Eq
3179f2bc013cSdrh   **       TK_EQ              OP_Ne
3180f2bc013cSdrh   **       TK_GT              OP_Le
3181f2bc013cSdrh   **       TK_LE              OP_Gt
3182f2bc013cSdrh   **       TK_GE              OP_Lt
3183f2bc013cSdrh   **       TK_LT              OP_Ge
3184f2bc013cSdrh   **
3185f2bc013cSdrh   ** For other values of pExpr->op, op is undefined and unused.
3186f2bc013cSdrh   ** The value of TK_ and OP_ constants are arranged such that we
3187f2bc013cSdrh   ** can compute the mapping above using the following expression.
3188f2bc013cSdrh   ** Assert()s verify that the computation is correct.
3189f2bc013cSdrh   */
3190f2bc013cSdrh   op = ((pExpr->op+(TK_ISNULL&1))^1)-(TK_ISNULL&1);
3191f2bc013cSdrh 
3192f2bc013cSdrh   /* Verify correct alignment of TK_ and OP_ constants
3193f2bc013cSdrh   */
3194f2bc013cSdrh   assert( pExpr->op!=TK_ISNULL || op==OP_NotNull );
3195f2bc013cSdrh   assert( pExpr->op!=TK_NOTNULL || op==OP_IsNull );
3196f2bc013cSdrh   assert( pExpr->op!=TK_NE || op==OP_Eq );
3197f2bc013cSdrh   assert( pExpr->op!=TK_EQ || op==OP_Ne );
3198f2bc013cSdrh   assert( pExpr->op!=TK_LT || op==OP_Ge );
3199f2bc013cSdrh   assert( pExpr->op!=TK_LE || op==OP_Gt );
3200f2bc013cSdrh   assert( pExpr->op!=TK_GT || op==OP_Le );
3201f2bc013cSdrh   assert( pExpr->op!=TK_GE || op==OP_Lt );
3202f2bc013cSdrh 
3203cce7d176Sdrh   switch( pExpr->op ){
3204cce7d176Sdrh     case TK_AND: {
3205c5499befSdrh       testcase( jumpIfNull==0 );
3206c5499befSdrh       testcase( pParse->disableColCache==0 );
32074adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
3208e55cbd72Sdrh       pParse->disableColCache++;
32094adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
3210c5499befSdrh       assert( pParse->disableColCache>0 );
3211e55cbd72Sdrh       pParse->disableColCache--;
3212cce7d176Sdrh       break;
3213cce7d176Sdrh     }
3214cce7d176Sdrh     case TK_OR: {
32154adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
3216c5499befSdrh       testcase( jumpIfNull==0 );
3217c5499befSdrh       testcase( pParse->disableColCache==0 );
321835573356Sdrh       sqlite3ExprIfTrue(pParse, pExpr->pLeft, d2, jumpIfNull^SQLITE_JUMPIFNULL);
3219e55cbd72Sdrh       pParse->disableColCache++;
32204adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
3221c5499befSdrh       assert( pParse->disableColCache>0 );
3222e55cbd72Sdrh       pParse->disableColCache--;
32234adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
3224cce7d176Sdrh       break;
3225cce7d176Sdrh     }
3226cce7d176Sdrh     case TK_NOT: {
32274adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
3228cce7d176Sdrh       break;
3229cce7d176Sdrh     }
3230cce7d176Sdrh     case TK_LT:
3231cce7d176Sdrh     case TK_LE:
3232cce7d176Sdrh     case TK_GT:
3233cce7d176Sdrh     case TK_GE:
3234cce7d176Sdrh     case TK_NE:
3235cce7d176Sdrh     case TK_EQ: {
3236c5499befSdrh       testcase( op==TK_LT );
3237c5499befSdrh       testcase( op==TK_LE );
3238c5499befSdrh       testcase( op==TK_GT );
3239c5499befSdrh       testcase( op==TK_GE );
3240c5499befSdrh       testcase( op==TK_EQ );
3241c5499befSdrh       testcase( op==TK_NE );
3242c5499befSdrh       testcase( jumpIfNull==0 );
3243da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
3244da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
324535573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
32462dcef11bSdrh                   r1, r2, dest, jumpIfNull);
3247c5499befSdrh       testcase( regFree1==0 );
3248c5499befSdrh       testcase( regFree2==0 );
3249cce7d176Sdrh       break;
3250cce7d176Sdrh     }
3251cce7d176Sdrh     case TK_ISNULL:
3252cce7d176Sdrh     case TK_NOTNULL: {
3253c5499befSdrh       testcase( op==TK_ISNULL );
3254c5499befSdrh       testcase( op==TK_NOTNULL );
32552dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
32562dcef11bSdrh       sqlite3VdbeAddOp2(v, op, r1, dest);
3257c5499befSdrh       testcase( regFree1==0 );
3258cce7d176Sdrh       break;
3259cce7d176Sdrh     }
3260fef5208cSdrh     case TK_BETWEEN: {
32612dcef11bSdrh       /*    x BETWEEN y AND z
32620202b29eSdanielk1977       **
32632dcef11bSdrh       ** Is equivalent to
32642dcef11bSdrh       **
32652dcef11bSdrh       **    x>=y AND x<=z
32662dcef11bSdrh       **
32672dcef11bSdrh       ** Code it as such, taking care to do the common subexpression
32682dcef11bSdrh       ** elementation of x.
32690202b29eSdanielk1977       */
32702dcef11bSdrh       Expr exprAnd;
32712dcef11bSdrh       Expr compLeft;
32722dcef11bSdrh       Expr compRight;
32732dcef11bSdrh       Expr exprX;
3274be5c89acSdrh 
32752dcef11bSdrh       exprX = *pExpr->pLeft;
32762dcef11bSdrh       exprAnd.op = TK_AND;
32772dcef11bSdrh       exprAnd.pLeft = &compLeft;
32782dcef11bSdrh       exprAnd.pRight = &compRight;
32792dcef11bSdrh       compLeft.op = TK_GE;
32802dcef11bSdrh       compLeft.pLeft = &exprX;
32812dcef11bSdrh       compLeft.pRight = pExpr->pList->a[0].pExpr;
32822dcef11bSdrh       compRight.op = TK_LE;
32832dcef11bSdrh       compRight.pLeft = &exprX;
32842dcef11bSdrh       compRight.pRight = pExpr->pList->a[1].pExpr;
32852dcef11bSdrh       exprX.iTable = sqlite3ExprCodeTemp(pParse, &exprX, &regFree1);
3286c5499befSdrh       testcase( regFree1==0 );
32872dcef11bSdrh       exprX.op = TK_REGISTER;
3288c5499befSdrh       testcase( jumpIfNull==0 );
32892dcef11bSdrh       sqlite3ExprIfFalse(pParse, &exprAnd, dest, jumpIfNull);
3290fef5208cSdrh       break;
3291fef5208cSdrh     }
3292cce7d176Sdrh     default: {
32932dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr, &regFree1);
32942dcef11bSdrh       sqlite3VdbeAddOp3(v, OP_IfNot, r1, dest, jumpIfNull!=0);
3295c5499befSdrh       testcase( regFree1==0 );
3296c5499befSdrh       testcase( jumpIfNull==0 );
3297cce7d176Sdrh       break;
3298cce7d176Sdrh     }
3299cce7d176Sdrh   }
33002dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
33012dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
3302cce7d176Sdrh }
33032282792aSdrh 
33042282792aSdrh /*
33052282792aSdrh ** Do a deep comparison of two expression trees.  Return TRUE (non-zero)
33062282792aSdrh ** if they are identical and return FALSE if they differ in any way.
3307d40aab0eSdrh **
3308d40aab0eSdrh ** Sometimes this routine will return FALSE even if the two expressions
3309d40aab0eSdrh ** really are equivalent.  If we cannot prove that the expressions are
3310d40aab0eSdrh ** identical, we return FALSE just to be safe.  So if this routine
3311d40aab0eSdrh ** returns false, then you do not really know for certain if the two
3312d40aab0eSdrh ** expressions are the same.  But if you get a TRUE return, then you
3313d40aab0eSdrh ** can be sure the expressions are the same.  In the places where
3314d40aab0eSdrh ** this routine is used, it does not hurt to get an extra FALSE - that
3315d40aab0eSdrh ** just might result in some slightly slower code.  But returning
3316d40aab0eSdrh ** an incorrect TRUE could lead to a malfunction.
33172282792aSdrh */
33184adee20fSdanielk1977 int sqlite3ExprCompare(Expr *pA, Expr *pB){
33192282792aSdrh   int i;
33204b202ae2Sdanielk1977   if( pA==0||pB==0 ){
33214b202ae2Sdanielk1977     return pB==pA;
33222282792aSdrh   }
33232282792aSdrh   if( pA->op!=pB->op ) return 0;
3324fd357974Sdrh   if( (pA->flags & EP_Distinct)!=(pB->flags & EP_Distinct) ) return 0;
33254adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pLeft, pB->pLeft) ) return 0;
33264adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pRight, pB->pRight) ) return 0;
33272282792aSdrh   if( pA->pList ){
33282282792aSdrh     if( pB->pList==0 ) return 0;
33292282792aSdrh     if( pA->pList->nExpr!=pB->pList->nExpr ) return 0;
33302282792aSdrh     for(i=0; i<pA->pList->nExpr; i++){
33314adee20fSdanielk1977       if( !sqlite3ExprCompare(pA->pList->a[i].pExpr, pB->pList->a[i].pExpr) ){
33322282792aSdrh         return 0;
33332282792aSdrh       }
33342282792aSdrh     }
33352282792aSdrh   }else if( pB->pList ){
33362282792aSdrh     return 0;
33372282792aSdrh   }
33382282792aSdrh   if( pA->pSelect || pB->pSelect ) return 0;
33392f2c01e5Sdrh   if( pA->iTable!=pB->iTable || pA->iColumn!=pB->iColumn ) return 0;
3340dd73521bSdrh   if( pA->op!=TK_COLUMN && pA->token.z ){
33412282792aSdrh     if( pB->token.z==0 ) return 0;
33426977fea8Sdrh     if( pB->token.n!=pA->token.n ) return 0;
33432646da7eSdrh     if( sqlite3StrNICmp((char*)pA->token.z,(char*)pB->token.z,pB->token.n)!=0 ){
33442646da7eSdrh       return 0;
33452646da7eSdrh     }
33462282792aSdrh   }
33472282792aSdrh   return 1;
33482282792aSdrh }
33492282792aSdrh 
335013449892Sdrh 
33512282792aSdrh /*
335213449892Sdrh ** Add a new element to the pAggInfo->aCol[] array.  Return the index of
335313449892Sdrh ** the new element.  Return a negative number if malloc fails.
33542282792aSdrh */
335517435752Sdrh static int addAggInfoColumn(sqlite3 *db, AggInfo *pInfo){
335613449892Sdrh   int i;
3357cf643729Sdrh   pInfo->aCol = sqlite3ArrayAllocate(
335817435752Sdrh        db,
3359cf643729Sdrh        pInfo->aCol,
3360cf643729Sdrh        sizeof(pInfo->aCol[0]),
3361cf643729Sdrh        3,
3362cf643729Sdrh        &pInfo->nColumn,
3363cf643729Sdrh        &pInfo->nColumnAlloc,
3364cf643729Sdrh        &i
3365cf643729Sdrh   );
336613449892Sdrh   return i;
33672282792aSdrh }
336813449892Sdrh 
336913449892Sdrh /*
337013449892Sdrh ** Add a new element to the pAggInfo->aFunc[] array.  Return the index of
337113449892Sdrh ** the new element.  Return a negative number if malloc fails.
337213449892Sdrh */
337317435752Sdrh static int addAggInfoFunc(sqlite3 *db, AggInfo *pInfo){
337413449892Sdrh   int i;
3375cf643729Sdrh   pInfo->aFunc = sqlite3ArrayAllocate(
337617435752Sdrh        db,
3377cf643729Sdrh        pInfo->aFunc,
3378cf643729Sdrh        sizeof(pInfo->aFunc[0]),
3379cf643729Sdrh        3,
3380cf643729Sdrh        &pInfo->nFunc,
3381cf643729Sdrh        &pInfo->nFuncAlloc,
3382cf643729Sdrh        &i
3383cf643729Sdrh   );
338413449892Sdrh   return i;
33852282792aSdrh }
33862282792aSdrh 
33872282792aSdrh /*
3388626a879aSdrh ** This is an xFunc for walkExprTree() used to implement
3389626a879aSdrh ** sqlite3ExprAnalyzeAggregates().  See sqlite3ExprAnalyzeAggregates
3390626a879aSdrh ** for additional information.
33912282792aSdrh **
3392626a879aSdrh ** This routine analyzes the aggregate function at pExpr.
33932282792aSdrh */
3394626a879aSdrh static int analyzeAggregate(void *pArg, Expr *pExpr){
33952282792aSdrh   int i;
3396a58fdfb1Sdanielk1977   NameContext *pNC = (NameContext *)pArg;
3397a58fdfb1Sdanielk1977   Parse *pParse = pNC->pParse;
3398a58fdfb1Sdanielk1977   SrcList *pSrcList = pNC->pSrcList;
339913449892Sdrh   AggInfo *pAggInfo = pNC->pAggInfo;
340013449892Sdrh 
34012282792aSdrh   switch( pExpr->op ){
340289c69d00Sdrh     case TK_AGG_COLUMN:
3403967e8b73Sdrh     case TK_COLUMN: {
340413449892Sdrh       /* Check to see if the column is in one of the tables in the FROM
340513449892Sdrh       ** clause of the aggregate query */
340613449892Sdrh       if( pSrcList ){
340713449892Sdrh         struct SrcList_item *pItem = pSrcList->a;
340813449892Sdrh         for(i=0; i<pSrcList->nSrc; i++, pItem++){
340913449892Sdrh           struct AggInfo_col *pCol;
341013449892Sdrh           if( pExpr->iTable==pItem->iCursor ){
341113449892Sdrh             /* If we reach this point, it means that pExpr refers to a table
341213449892Sdrh             ** that is in the FROM clause of the aggregate query.
341313449892Sdrh             **
341413449892Sdrh             ** Make an entry for the column in pAggInfo->aCol[] if there
341513449892Sdrh             ** is not an entry there already.
341613449892Sdrh             */
34177f906d63Sdrh             int k;
341813449892Sdrh             pCol = pAggInfo->aCol;
34197f906d63Sdrh             for(k=0; k<pAggInfo->nColumn; k++, pCol++){
342013449892Sdrh               if( pCol->iTable==pExpr->iTable &&
342113449892Sdrh                   pCol->iColumn==pExpr->iColumn ){
34222282792aSdrh                 break;
34232282792aSdrh               }
34242282792aSdrh             }
34251e536953Sdanielk1977             if( (k>=pAggInfo->nColumn)
34261e536953Sdanielk1977              && (k = addAggInfoColumn(pParse->db, pAggInfo))>=0
34271e536953Sdanielk1977             ){
34287f906d63Sdrh               pCol = &pAggInfo->aCol[k];
34290817d0dfSdanielk1977               pCol->pTab = pExpr->pTab;
343013449892Sdrh               pCol->iTable = pExpr->iTable;
343113449892Sdrh               pCol->iColumn = pExpr->iColumn;
34320a07c107Sdrh               pCol->iMem = ++pParse->nMem;
343313449892Sdrh               pCol->iSorterColumn = -1;
34345774b806Sdrh               pCol->pExpr = pExpr;
343513449892Sdrh               if( pAggInfo->pGroupBy ){
343613449892Sdrh                 int j, n;
343713449892Sdrh                 ExprList *pGB = pAggInfo->pGroupBy;
343813449892Sdrh                 struct ExprList_item *pTerm = pGB->a;
343913449892Sdrh                 n = pGB->nExpr;
344013449892Sdrh                 for(j=0; j<n; j++, pTerm++){
344113449892Sdrh                   Expr *pE = pTerm->pExpr;
344213449892Sdrh                   if( pE->op==TK_COLUMN && pE->iTable==pExpr->iTable &&
344313449892Sdrh                       pE->iColumn==pExpr->iColumn ){
344413449892Sdrh                     pCol->iSorterColumn = j;
344513449892Sdrh                     break;
34462282792aSdrh                   }
344713449892Sdrh                 }
344813449892Sdrh               }
344913449892Sdrh               if( pCol->iSorterColumn<0 ){
345013449892Sdrh                 pCol->iSorterColumn = pAggInfo->nSortingColumn++;
345113449892Sdrh               }
345213449892Sdrh             }
345313449892Sdrh             /* There is now an entry for pExpr in pAggInfo->aCol[] (either
345413449892Sdrh             ** because it was there before or because we just created it).
345513449892Sdrh             ** Convert the pExpr to be a TK_AGG_COLUMN referring to that
345613449892Sdrh             ** pAggInfo->aCol[] entry.
345713449892Sdrh             */
345813449892Sdrh             pExpr->pAggInfo = pAggInfo;
345913449892Sdrh             pExpr->op = TK_AGG_COLUMN;
34607f906d63Sdrh             pExpr->iAgg = k;
346113449892Sdrh             break;
346213449892Sdrh           } /* endif pExpr->iTable==pItem->iCursor */
346313449892Sdrh         } /* end loop over pSrcList */
3464a58fdfb1Sdanielk1977       }
3465626a879aSdrh       return 1;
34662282792aSdrh     }
34672282792aSdrh     case TK_AGG_FUNCTION: {
346813449892Sdrh       /* The pNC->nDepth==0 test causes aggregate functions in subqueries
346913449892Sdrh       ** to be ignored */
3470a58fdfb1Sdanielk1977       if( pNC->nDepth==0 ){
347113449892Sdrh         /* Check to see if pExpr is a duplicate of another aggregate
347213449892Sdrh         ** function that is already in the pAggInfo structure
347313449892Sdrh         */
347413449892Sdrh         struct AggInfo_func *pItem = pAggInfo->aFunc;
347513449892Sdrh         for(i=0; i<pAggInfo->nFunc; i++, pItem++){
347613449892Sdrh           if( sqlite3ExprCompare(pItem->pExpr, pExpr) ){
34772282792aSdrh             break;
34782282792aSdrh           }
34792282792aSdrh         }
348013449892Sdrh         if( i>=pAggInfo->nFunc ){
348113449892Sdrh           /* pExpr is original.  Make a new entry in pAggInfo->aFunc[]
348213449892Sdrh           */
348314db2665Sdanielk1977           u8 enc = ENC(pParse->db);
34841e536953Sdanielk1977           i = addAggInfoFunc(pParse->db, pAggInfo);
348513449892Sdrh           if( i>=0 ){
348613449892Sdrh             pItem = &pAggInfo->aFunc[i];
348713449892Sdrh             pItem->pExpr = pExpr;
34880a07c107Sdrh             pItem->iMem = ++pParse->nMem;
348913449892Sdrh             pItem->pFunc = sqlite3FindFunction(pParse->db,
34902646da7eSdrh                    (char*)pExpr->token.z, pExpr->token.n,
3491d8123366Sdanielk1977                    pExpr->pList ? pExpr->pList->nExpr : 0, enc, 0);
3492fd357974Sdrh             if( pExpr->flags & EP_Distinct ){
3493fd357974Sdrh               pItem->iDistinct = pParse->nTab++;
3494fd357974Sdrh             }else{
3495fd357974Sdrh               pItem->iDistinct = -1;
3496fd357974Sdrh             }
34972282792aSdrh           }
349813449892Sdrh         }
349913449892Sdrh         /* Make pExpr point to the appropriate pAggInfo->aFunc[] entry
350013449892Sdrh         */
35012282792aSdrh         pExpr->iAgg = i;
350213449892Sdrh         pExpr->pAggInfo = pAggInfo;
3503626a879aSdrh         return 1;
35042282792aSdrh       }
35052282792aSdrh     }
3506a58fdfb1Sdanielk1977   }
350713449892Sdrh 
350813449892Sdrh   /* Recursively walk subqueries looking for TK_COLUMN nodes that need
350913449892Sdrh   ** to be changed to TK_AGG_COLUMN.  But increment nDepth so that
351013449892Sdrh   ** TK_AGG_FUNCTION nodes in subqueries will be unchanged.
351113449892Sdrh   */
3512a58fdfb1Sdanielk1977   if( pExpr->pSelect ){
3513a58fdfb1Sdanielk1977     pNC->nDepth++;
3514a58fdfb1Sdanielk1977     walkSelectExpr(pExpr->pSelect, analyzeAggregate, pNC);
3515a58fdfb1Sdanielk1977     pNC->nDepth--;
3516a58fdfb1Sdanielk1977   }
3517626a879aSdrh   return 0;
35182282792aSdrh }
3519626a879aSdrh 
3520626a879aSdrh /*
3521626a879aSdrh ** Analyze the given expression looking for aggregate functions and
3522626a879aSdrh ** for variables that need to be added to the pParse->aAgg[] array.
3523626a879aSdrh ** Make additional entries to the pParse->aAgg[] array as necessary.
3524626a879aSdrh **
3525626a879aSdrh ** This routine should only be called after the expression has been
3526626a879aSdrh ** analyzed by sqlite3ExprResolveNames().
3527626a879aSdrh */
3528d2b3e23bSdrh void sqlite3ExprAnalyzeAggregates(NameContext *pNC, Expr *pExpr){
3529a58fdfb1Sdanielk1977   walkExprTree(pExpr, analyzeAggregate, pNC);
35302282792aSdrh }
35315d9a4af9Sdrh 
35325d9a4af9Sdrh /*
35335d9a4af9Sdrh ** Call sqlite3ExprAnalyzeAggregates() for every expression in an
35345d9a4af9Sdrh ** expression list.  Return the number of errors.
35355d9a4af9Sdrh **
35365d9a4af9Sdrh ** If an error is found, the analysis is cut short.
35375d9a4af9Sdrh */
3538d2b3e23bSdrh void sqlite3ExprAnalyzeAggList(NameContext *pNC, ExprList *pList){
35395d9a4af9Sdrh   struct ExprList_item *pItem;
35405d9a4af9Sdrh   int i;
35415d9a4af9Sdrh   if( pList ){
3542d2b3e23bSdrh     for(pItem=pList->a, i=0; i<pList->nExpr; i++, pItem++){
3543d2b3e23bSdrh       sqlite3ExprAnalyzeAggregates(pNC, pItem->pExpr);
35445d9a4af9Sdrh     }
35455d9a4af9Sdrh   }
35465d9a4af9Sdrh }
3547892d3179Sdrh 
3548892d3179Sdrh /*
3549892d3179Sdrh ** Allocate or deallocate temporary use registers during code generation.
3550892d3179Sdrh */
3551892d3179Sdrh int sqlite3GetTempReg(Parse *pParse){
3552e55cbd72Sdrh   int i, r;
3553e55cbd72Sdrh   if( pParse->nTempReg==0 ){
3554892d3179Sdrh     return ++pParse->nMem;
3555892d3179Sdrh   }
3556e55cbd72Sdrh   for(i=0; i<pParse->nTempReg; i++){
3557e55cbd72Sdrh     r = pParse->aTempReg[i];
3558e55cbd72Sdrh     if( usedAsColumnCache(pParse, r, r) ) continue;
3559e55cbd72Sdrh   }
3560e55cbd72Sdrh   if( i>=pParse->nTempReg ){
3561e55cbd72Sdrh     return ++pParse->nMem;
3562e55cbd72Sdrh   }
3563e55cbd72Sdrh   while( i<pParse->nTempReg-1 ){
3564e55cbd72Sdrh     pParse->aTempReg[i] = pParse->aTempReg[i+1];
3565e55cbd72Sdrh   }
3566e55cbd72Sdrh   pParse->nTempReg--;
3567e55cbd72Sdrh   return r;
3568892d3179Sdrh }
3569892d3179Sdrh void sqlite3ReleaseTempReg(Parse *pParse, int iReg){
35702dcef11bSdrh   if( iReg && pParse->nTempReg<ArraySize(pParse->aTempReg) ){
3571892d3179Sdrh     pParse->aTempReg[pParse->nTempReg++] = iReg;
3572892d3179Sdrh   }
3573892d3179Sdrh }
3574892d3179Sdrh 
3575892d3179Sdrh /*
3576892d3179Sdrh ** Allocate or deallocate a block of nReg consecutive registers
3577892d3179Sdrh */
3578892d3179Sdrh int sqlite3GetTempRange(Parse *pParse, int nReg){
3579e55cbd72Sdrh   int i, n;
3580892d3179Sdrh   i = pParse->iRangeReg;
3581e55cbd72Sdrh   n = pParse->nRangeReg;
3582e55cbd72Sdrh   if( nReg<=n && !usedAsColumnCache(pParse, i, i+n-1) ){
3583892d3179Sdrh     pParse->iRangeReg += nReg;
3584892d3179Sdrh     pParse->nRangeReg -= nReg;
3585892d3179Sdrh   }else{
3586892d3179Sdrh     i = pParse->nMem+1;
3587892d3179Sdrh     pParse->nMem += nReg;
3588892d3179Sdrh   }
3589892d3179Sdrh   return i;
3590892d3179Sdrh }
3591892d3179Sdrh void sqlite3ReleaseTempRange(Parse *pParse, int iReg, int nReg){
3592892d3179Sdrh   if( nReg>pParse->nRangeReg ){
3593892d3179Sdrh     pParse->nRangeReg = nReg;
3594892d3179Sdrh     pParse->iRangeReg = iReg;
3595892d3179Sdrh   }
3596892d3179Sdrh }
3597