xref: /sqlite-3.40.0/src/expr.c (revision da250ea5)
1cce7d176Sdrh /*
2b19a2bc6Sdrh ** 2001 September 15
3cce7d176Sdrh **
4b19a2bc6Sdrh ** The author disclaims copyright to this source code.  In place of
5b19a2bc6Sdrh ** a legal notice, here is a blessing:
6cce7d176Sdrh **
7b19a2bc6Sdrh **    May you do good and not evil.
8b19a2bc6Sdrh **    May you find forgiveness for yourself and forgive others.
9b19a2bc6Sdrh **    May you share freely, never taking more than you give.
10cce7d176Sdrh **
11cce7d176Sdrh *************************************************************************
121ccde15dSdrh ** This file contains routines used for analyzing expressions and
13b19a2bc6Sdrh ** for generating VDBE code that evaluates expressions in SQLite.
14cce7d176Sdrh **
15*da250ea5Sdrh ** $Id: expr.c,v 1.362 2008/04/01 05:07:15 drh Exp $
16cce7d176Sdrh */
17cce7d176Sdrh #include "sqliteInt.h"
1804738cb9Sdrh #include <ctype.h>
19a2e00042Sdrh 
20e014a838Sdanielk1977 /*
21e014a838Sdanielk1977 ** Return the 'affinity' of the expression pExpr if any.
22e014a838Sdanielk1977 **
23e014a838Sdanielk1977 ** If pExpr is a column, a reference to a column via an 'AS' alias,
24e014a838Sdanielk1977 ** or a sub-select with a column as the return value, then the
25e014a838Sdanielk1977 ** affinity of that column is returned. Otherwise, 0x00 is returned,
26e014a838Sdanielk1977 ** indicating no affinity for the expression.
27e014a838Sdanielk1977 **
28e014a838Sdanielk1977 ** i.e. the WHERE clause expresssions in the following statements all
29e014a838Sdanielk1977 ** have an affinity:
30e014a838Sdanielk1977 **
31e014a838Sdanielk1977 ** CREATE TABLE t1(a);
32e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE a;
33e014a838Sdanielk1977 ** SELECT a AS b FROM t1 WHERE b;
34e014a838Sdanielk1977 ** SELECT * FROM t1 WHERE (select a from t1);
35e014a838Sdanielk1977 */
36bf3b721fSdanielk1977 char sqlite3ExprAffinity(Expr *pExpr){
37487e262fSdrh   int op = pExpr->op;
38487e262fSdrh   if( op==TK_SELECT ){
39bf3b721fSdanielk1977     return sqlite3ExprAffinity(pExpr->pSelect->pEList->a[0].pExpr);
40a37cdde0Sdanielk1977   }
41487e262fSdrh #ifndef SQLITE_OMIT_CAST
42487e262fSdrh   if( op==TK_CAST ){
438a51256cSdrh     return sqlite3AffinityType(&pExpr->token);
44487e262fSdrh   }
45487e262fSdrh #endif
46a37cdde0Sdanielk1977   return pExpr->affinity;
47a37cdde0Sdanielk1977 }
48a37cdde0Sdanielk1977 
4953db1458Sdrh /*
508b4c40d8Sdrh ** Set the collating sequence for expression pExpr to be the collating
518b4c40d8Sdrh ** sequence named by pToken.   Return a pointer to the revised expression.
52a34001c9Sdrh ** The collating sequence is marked as "explicit" using the EP_ExpCollate
53a34001c9Sdrh ** flag.  An explicit collating sequence will override implicit
54a34001c9Sdrh ** collating sequences.
558b4c40d8Sdrh */
568b4c40d8Sdrh Expr *sqlite3ExprSetColl(Parse *pParse, Expr *pExpr, Token *pName){
5739002505Sdanielk1977   char *zColl = 0;            /* Dequoted name of collation sequence */
588b4c40d8Sdrh   CollSeq *pColl;
5939002505Sdanielk1977   zColl = sqlite3NameFromToken(pParse->db, pName);
6039002505Sdanielk1977   if( pExpr && zColl ){
6139002505Sdanielk1977     pColl = sqlite3LocateCollSeq(pParse, zColl, -1);
628b4c40d8Sdrh     if( pColl ){
638b4c40d8Sdrh       pExpr->pColl = pColl;
648b4c40d8Sdrh       pExpr->flags |= EP_ExpCollate;
658b4c40d8Sdrh     }
6639002505Sdanielk1977   }
6739002505Sdanielk1977   sqlite3_free(zColl);
688b4c40d8Sdrh   return pExpr;
698b4c40d8Sdrh }
708b4c40d8Sdrh 
718b4c40d8Sdrh /*
720202b29eSdanielk1977 ** Return the default collation sequence for the expression pExpr. If
730202b29eSdanielk1977 ** there is no default collation type, return 0.
740202b29eSdanielk1977 */
757cedc8d4Sdanielk1977 CollSeq *sqlite3ExprCollSeq(Parse *pParse, Expr *pExpr){
767cedc8d4Sdanielk1977   CollSeq *pColl = 0;
770202b29eSdanielk1977   if( pExpr ){
787e09fe0bSdrh     int op;
797cedc8d4Sdanielk1977     pColl = pExpr->pColl;
807e09fe0bSdrh     op = pExpr->op;
817e09fe0bSdrh     if( (op==TK_CAST || op==TK_UPLUS) && !pColl ){
827cedc8d4Sdanielk1977       return sqlite3ExprCollSeq(pParse, pExpr->pLeft);
830202b29eSdanielk1977     }
840202b29eSdanielk1977   }
857cedc8d4Sdanielk1977   if( sqlite3CheckCollSeq(pParse, pColl) ){
867cedc8d4Sdanielk1977     pColl = 0;
877cedc8d4Sdanielk1977   }
887cedc8d4Sdanielk1977   return pColl;
890202b29eSdanielk1977 }
900202b29eSdanielk1977 
910202b29eSdanielk1977 /*
92626a879aSdrh ** pExpr is an operand of a comparison operator.  aff2 is the
93626a879aSdrh ** type affinity of the other operand.  This routine returns the
9453db1458Sdrh ** type affinity that should be used for the comparison operator.
9553db1458Sdrh */
96e014a838Sdanielk1977 char sqlite3CompareAffinity(Expr *pExpr, char aff2){
97bf3b721fSdanielk1977   char aff1 = sqlite3ExprAffinity(pExpr);
98e014a838Sdanielk1977   if( aff1 && aff2 ){
998df447f0Sdrh     /* Both sides of the comparison are columns. If one has numeric
1008df447f0Sdrh     ** affinity, use that. Otherwise use no affinity.
101e014a838Sdanielk1977     */
1028a51256cSdrh     if( sqlite3IsNumericAffinity(aff1) || sqlite3IsNumericAffinity(aff2) ){
103e014a838Sdanielk1977       return SQLITE_AFF_NUMERIC;
104e014a838Sdanielk1977     }else{
105e014a838Sdanielk1977       return SQLITE_AFF_NONE;
106e014a838Sdanielk1977     }
107e014a838Sdanielk1977   }else if( !aff1 && !aff2 ){
1085f6a87b3Sdrh     /* Neither side of the comparison is a column.  Compare the
1095f6a87b3Sdrh     ** results directly.
110e014a838Sdanielk1977     */
1115f6a87b3Sdrh     return SQLITE_AFF_NONE;
112e014a838Sdanielk1977   }else{
113e014a838Sdanielk1977     /* One side is a column, the other is not. Use the columns affinity. */
114fe05af87Sdrh     assert( aff1==0 || aff2==0 );
115e014a838Sdanielk1977     return (aff1 + aff2);
116e014a838Sdanielk1977   }
117e014a838Sdanielk1977 }
118e014a838Sdanielk1977 
11953db1458Sdrh /*
12053db1458Sdrh ** pExpr is a comparison operator.  Return the type affinity that should
12153db1458Sdrh ** be applied to both operands prior to doing the comparison.
12253db1458Sdrh */
123e014a838Sdanielk1977 static char comparisonAffinity(Expr *pExpr){
124e014a838Sdanielk1977   char aff;
125e014a838Sdanielk1977   assert( pExpr->op==TK_EQ || pExpr->op==TK_IN || pExpr->op==TK_LT ||
126e014a838Sdanielk1977           pExpr->op==TK_GT || pExpr->op==TK_GE || pExpr->op==TK_LE ||
127e014a838Sdanielk1977           pExpr->op==TK_NE );
128e014a838Sdanielk1977   assert( pExpr->pLeft );
129bf3b721fSdanielk1977   aff = sqlite3ExprAffinity(pExpr->pLeft);
130e014a838Sdanielk1977   if( pExpr->pRight ){
131e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pRight, aff);
132e014a838Sdanielk1977   }
133e014a838Sdanielk1977   else if( pExpr->pSelect ){
134e014a838Sdanielk1977     aff = sqlite3CompareAffinity(pExpr->pSelect->pEList->a[0].pExpr, aff);
135e014a838Sdanielk1977   }
136e014a838Sdanielk1977   else if( !aff ){
137de087bd5Sdrh     aff = SQLITE_AFF_NONE;
138e014a838Sdanielk1977   }
139e014a838Sdanielk1977   return aff;
140e014a838Sdanielk1977 }
141e014a838Sdanielk1977 
142e014a838Sdanielk1977 /*
143e014a838Sdanielk1977 ** pExpr is a comparison expression, eg. '=', '<', IN(...) etc.
144e014a838Sdanielk1977 ** idx_affinity is the affinity of an indexed column. Return true
145e014a838Sdanielk1977 ** if the index with affinity idx_affinity may be used to implement
146e014a838Sdanielk1977 ** the comparison in pExpr.
147e014a838Sdanielk1977 */
148e014a838Sdanielk1977 int sqlite3IndexAffinityOk(Expr *pExpr, char idx_affinity){
149e014a838Sdanielk1977   char aff = comparisonAffinity(pExpr);
1508a51256cSdrh   switch( aff ){
1518a51256cSdrh     case SQLITE_AFF_NONE:
1528a51256cSdrh       return 1;
1538a51256cSdrh     case SQLITE_AFF_TEXT:
1548a51256cSdrh       return idx_affinity==SQLITE_AFF_TEXT;
1558a51256cSdrh     default:
1568a51256cSdrh       return sqlite3IsNumericAffinity(idx_affinity);
1578a51256cSdrh   }
158e014a838Sdanielk1977 }
159e014a838Sdanielk1977 
160a37cdde0Sdanielk1977 /*
16135573356Sdrh ** Return the P5 value that should be used for a binary comparison
162a37cdde0Sdanielk1977 ** opcode (OP_Eq, OP_Ge etc.) used to compare pExpr1 and pExpr2.
163a37cdde0Sdanielk1977 */
16435573356Sdrh static u8 binaryCompareP5(Expr *pExpr1, Expr *pExpr2, int jumpIfNull){
16535573356Sdrh   u8 aff = (char)sqlite3ExprAffinity(pExpr2);
16635573356Sdrh   aff = sqlite3CompareAffinity(pExpr1, aff) | jumpIfNull;
16735573356Sdrh   return aff;
168a37cdde0Sdanielk1977 }
169a37cdde0Sdanielk1977 
170a2e00042Sdrh /*
1710202b29eSdanielk1977 ** Return a pointer to the collation sequence that should be used by
1720202b29eSdanielk1977 ** a binary comparison operator comparing pLeft and pRight.
1730202b29eSdanielk1977 **
1740202b29eSdanielk1977 ** If the left hand expression has a collating sequence type, then it is
1750202b29eSdanielk1977 ** used. Otherwise the collation sequence for the right hand expression
1760202b29eSdanielk1977 ** is used, or the default (BINARY) if neither expression has a collating
1770202b29eSdanielk1977 ** type.
178bcbb04e5Sdanielk1977 **
179bcbb04e5Sdanielk1977 ** Argument pRight (but not pLeft) may be a null pointer. In this case,
180bcbb04e5Sdanielk1977 ** it is not considered.
1810202b29eSdanielk1977 */
182bcbb04e5Sdanielk1977 CollSeq *sqlite3BinaryCompareCollSeq(
183bcbb04e5Sdanielk1977   Parse *pParse,
184bcbb04e5Sdanielk1977   Expr *pLeft,
185bcbb04e5Sdanielk1977   Expr *pRight
186bcbb04e5Sdanielk1977 ){
187ec41ddacSdrh   CollSeq *pColl;
188ec41ddacSdrh   assert( pLeft );
189ec41ddacSdrh   if( pLeft->flags & EP_ExpCollate ){
190ec41ddacSdrh     assert( pLeft->pColl );
191ec41ddacSdrh     pColl = pLeft->pColl;
192bcbb04e5Sdanielk1977   }else if( pRight && pRight->flags & EP_ExpCollate ){
193ec41ddacSdrh     assert( pRight->pColl );
194ec41ddacSdrh     pColl = pRight->pColl;
195ec41ddacSdrh   }else{
196ec41ddacSdrh     pColl = sqlite3ExprCollSeq(pParse, pLeft);
1970202b29eSdanielk1977     if( !pColl ){
1987cedc8d4Sdanielk1977       pColl = sqlite3ExprCollSeq(pParse, pRight);
1990202b29eSdanielk1977     }
200ec41ddacSdrh   }
2010202b29eSdanielk1977   return pColl;
2020202b29eSdanielk1977 }
2030202b29eSdanielk1977 
2040202b29eSdanielk1977 /*
205*da250ea5Sdrh ** Generate the operands for a comparison operation.  Before
206*da250ea5Sdrh ** generating the code for each operand, set the EP_AnyAff
207*da250ea5Sdrh ** flag on the expression so that it will be able to used a
208*da250ea5Sdrh ** cached column value that has previously undergone an
209*da250ea5Sdrh ** affinity change.
210*da250ea5Sdrh */
211*da250ea5Sdrh static void codeCompareOperands(
212*da250ea5Sdrh   Parse *pParse,    /* Parsing and code generating context */
213*da250ea5Sdrh   Expr *pLeft,      /* The left operand */
214*da250ea5Sdrh   int *pRegLeft,    /* Register where left operand is stored */
215*da250ea5Sdrh   int *pFreeLeft,   /* Free this register when done */
216*da250ea5Sdrh   Expr *pRight,     /* The right operand */
217*da250ea5Sdrh   int *pRegRight,   /* Register where right operand is stored */
218*da250ea5Sdrh   int *pFreeRight   /* Write temp register for right operand there */
219*da250ea5Sdrh ){
220*da250ea5Sdrh   while( pLeft->op==TK_UPLUS ) pLeft = pLeft->pLeft;
221*da250ea5Sdrh   pLeft->flags |= EP_AnyAff;
222*da250ea5Sdrh   *pRegLeft = sqlite3ExprCodeTemp(pParse, pLeft, pFreeLeft);
223*da250ea5Sdrh   while( pRight->op==TK_UPLUS ) pRight = pRight->pLeft;
224*da250ea5Sdrh   pRight->flags |= EP_AnyAff;
225*da250ea5Sdrh   *pRegRight = sqlite3ExprCodeTemp(pParse, pRight, pFreeRight);
226*da250ea5Sdrh }
227*da250ea5Sdrh 
228*da250ea5Sdrh /*
229be5c89acSdrh ** Generate code for a comparison operator.
230be5c89acSdrh */
231be5c89acSdrh static int codeCompare(
232be5c89acSdrh   Parse *pParse,    /* The parsing (and code generating) context */
233be5c89acSdrh   Expr *pLeft,      /* The left operand */
234be5c89acSdrh   Expr *pRight,     /* The right operand */
235be5c89acSdrh   int opcode,       /* The comparison opcode */
23635573356Sdrh   int in1, int in2, /* Register holding operands */
237be5c89acSdrh   int dest,         /* Jump here if true.  */
238be5c89acSdrh   int jumpIfNull    /* If true, jump if either operand is NULL */
239be5c89acSdrh ){
24035573356Sdrh   int p5;
24135573356Sdrh   int addr;
24235573356Sdrh   CollSeq *p4;
24335573356Sdrh 
24435573356Sdrh   p4 = sqlite3BinaryCompareCollSeq(pParse, pLeft, pRight);
24535573356Sdrh   p5 = binaryCompareP5(pLeft, pRight, jumpIfNull);
24635573356Sdrh   addr = sqlite3VdbeAddOp4(pParse->pVdbe, opcode, in2, dest, in1,
24735573356Sdrh                            (void*)p4, P4_COLLSEQ);
24835573356Sdrh   sqlite3VdbeChangeP5(pParse->pVdbe, p5);
2492f7794c1Sdrh   if( p5 & SQLITE_AFF_MASK ){
250*da250ea5Sdrh     sqlite3ExprCacheAffinityChange(pParse, in1, 1);
251*da250ea5Sdrh     sqlite3ExprCacheAffinityChange(pParse, in2, 1);
2522f7794c1Sdrh   }
25335573356Sdrh   return addr;
254be5c89acSdrh }
255be5c89acSdrh 
256be5c89acSdrh /*
257a76b5dfcSdrh ** Construct a new expression node and return a pointer to it.  Memory
25817435752Sdrh ** for this node is obtained from sqlite3_malloc().  The calling function
259a76b5dfcSdrh ** is responsible for making sure the node eventually gets freed.
260a76b5dfcSdrh */
26117435752Sdrh Expr *sqlite3Expr(
262a1644fd8Sdanielk1977   sqlite3 *db,            /* Handle for sqlite3DbMallocZero() (may be null) */
26317435752Sdrh   int op,                 /* Expression opcode */
26417435752Sdrh   Expr *pLeft,            /* Left operand */
26517435752Sdrh   Expr *pRight,           /* Right operand */
26617435752Sdrh   const Token *pToken     /* Argument token */
26717435752Sdrh ){
268a76b5dfcSdrh   Expr *pNew;
269a1644fd8Sdanielk1977   pNew = sqlite3DbMallocZero(db, sizeof(Expr));
270a76b5dfcSdrh   if( pNew==0 ){
271d5d56523Sdanielk1977     /* When malloc fails, delete pLeft and pRight. Expressions passed to
272d5d56523Sdanielk1977     ** this function must always be allocated with sqlite3Expr() for this
273d5d56523Sdanielk1977     ** reason.
274d5d56523Sdanielk1977     */
275d5d56523Sdanielk1977     sqlite3ExprDelete(pLeft);
276d5d56523Sdanielk1977     sqlite3ExprDelete(pRight);
277a76b5dfcSdrh     return 0;
278a76b5dfcSdrh   }
279a76b5dfcSdrh   pNew->op = op;
280a76b5dfcSdrh   pNew->pLeft = pLeft;
281a76b5dfcSdrh   pNew->pRight = pRight;
282a58fdfb1Sdanielk1977   pNew->iAgg = -1;
283a76b5dfcSdrh   if( pToken ){
2844b59ab5eSdrh     assert( pToken->dyn==0 );
285145716b3Sdrh     pNew->span = pNew->token = *pToken;
286a34001c9Sdrh   }else if( pLeft ){
287a34001c9Sdrh     if( pRight ){
2884adee20fSdanielk1977       sqlite3ExprSpan(pNew, &pLeft->span, &pRight->span);
2895ffb3ac8Sdrh       if( pRight->flags & EP_ExpCollate ){
290a34001c9Sdrh         pNew->flags |= EP_ExpCollate;
291a34001c9Sdrh         pNew->pColl = pRight->pColl;
292a34001c9Sdrh       }
293a34001c9Sdrh     }
2945ffb3ac8Sdrh     if( pLeft->flags & EP_ExpCollate ){
295a34001c9Sdrh       pNew->flags |= EP_ExpCollate;
296a34001c9Sdrh       pNew->pColl = pLeft->pColl;
297a34001c9Sdrh     }
298a76b5dfcSdrh   }
299fc976065Sdanielk1977 
300fc976065Sdanielk1977   sqlite3ExprSetHeight(pNew);
301a76b5dfcSdrh   return pNew;
302a76b5dfcSdrh }
303a76b5dfcSdrh 
304a76b5dfcSdrh /*
30517435752Sdrh ** Works like sqlite3Expr() except that it takes an extra Parse*
30617435752Sdrh ** argument and notifies the associated connection object if malloc fails.
307206f3d96Sdrh */
30817435752Sdrh Expr *sqlite3PExpr(
30917435752Sdrh   Parse *pParse,          /* Parsing context */
31017435752Sdrh   int op,                 /* Expression opcode */
31117435752Sdrh   Expr *pLeft,            /* Left operand */
31217435752Sdrh   Expr *pRight,           /* Right operand */
31317435752Sdrh   const Token *pToken     /* Argument token */
31417435752Sdrh ){
315a1644fd8Sdanielk1977   return sqlite3Expr(pParse->db, op, pLeft, pRight, pToken);
316206f3d96Sdrh }
317206f3d96Sdrh 
318206f3d96Sdrh /*
3194e0cff60Sdrh ** When doing a nested parse, you can include terms in an expression
320b7654111Sdrh ** that look like this:   #1 #2 ...  These terms refer to registers
321b7654111Sdrh ** in the virtual machine.  #N is the N-th register.
3224e0cff60Sdrh **
3234e0cff60Sdrh ** This routine is called by the parser to deal with on of those terms.
3244e0cff60Sdrh ** It immediately generates code to store the value in a memory location.
3254e0cff60Sdrh ** The returns an expression that will code to extract the value from
3264e0cff60Sdrh ** that memory location as needed.
3274e0cff60Sdrh */
3284e0cff60Sdrh Expr *sqlite3RegisterExpr(Parse *pParse, Token *pToken){
3294e0cff60Sdrh   Vdbe *v = pParse->pVdbe;
3304e0cff60Sdrh   Expr *p;
3314e0cff60Sdrh   if( pParse->nested==0 ){
3324e0cff60Sdrh     sqlite3ErrorMsg(pParse, "near \"%T\": syntax error", pToken);
333a1644fd8Sdanielk1977     return sqlite3PExpr(pParse, TK_NULL, 0, 0, 0);
3344e0cff60Sdrh   }
335bb7ac00bSdrh   if( v==0 ) return 0;
336a1644fd8Sdanielk1977   p = sqlite3PExpr(pParse, TK_REGISTER, 0, 0, pToken);
33773c42a13Sdrh   if( p==0 ){
33873c42a13Sdrh     return 0;  /* Malloc failed */
33973c42a13Sdrh   }
340b7654111Sdrh   p->iTable = atoi((char*)&pToken->z[1]);
3414e0cff60Sdrh   return p;
3424e0cff60Sdrh }
3434e0cff60Sdrh 
3444e0cff60Sdrh /*
34591bb0eedSdrh ** Join two expressions using an AND operator.  If either expression is
34691bb0eedSdrh ** NULL, then just return the other expression.
34791bb0eedSdrh */
3481e536953Sdanielk1977 Expr *sqlite3ExprAnd(sqlite3 *db, Expr *pLeft, Expr *pRight){
34991bb0eedSdrh   if( pLeft==0 ){
35091bb0eedSdrh     return pRight;
35191bb0eedSdrh   }else if( pRight==0 ){
35291bb0eedSdrh     return pLeft;
35391bb0eedSdrh   }else{
354880c15beSdanielk1977     return sqlite3Expr(db, TK_AND, pLeft, pRight, 0);
35591bb0eedSdrh   }
35691bb0eedSdrh }
35791bb0eedSdrh 
35891bb0eedSdrh /*
3596977fea8Sdrh ** Set the Expr.span field of the given expression to span all
360a76b5dfcSdrh ** text between the two given tokens.
361a76b5dfcSdrh */
3624adee20fSdanielk1977 void sqlite3ExprSpan(Expr *pExpr, Token *pLeft, Token *pRight){
3634efc4754Sdrh   assert( pRight!=0 );
3644efc4754Sdrh   assert( pLeft!=0 );
365f3a65f7eSdrh   if( pExpr && pRight->z && pLeft->z ){
366ad6d9460Sdrh     assert( pLeft->dyn==0 || pLeft->z[pLeft->n]==0 );
367145716b3Sdrh     if( pLeft->dyn==0 && pRight->dyn==0 ){
3686977fea8Sdrh       pExpr->span.z = pLeft->z;
36997903fefSdrh       pExpr->span.n = pRight->n + (pRight->z - pLeft->z);
3704b59ab5eSdrh     }else{
3716977fea8Sdrh       pExpr->span.z = 0;
3724b59ab5eSdrh     }
373a76b5dfcSdrh   }
374a76b5dfcSdrh }
375a76b5dfcSdrh 
376a76b5dfcSdrh /*
377a76b5dfcSdrh ** Construct a new expression node for a function with multiple
378a76b5dfcSdrh ** arguments.
379a76b5dfcSdrh */
38017435752Sdrh Expr *sqlite3ExprFunction(Parse *pParse, ExprList *pList, Token *pToken){
381a76b5dfcSdrh   Expr *pNew;
3824b202ae2Sdanielk1977   assert( pToken );
38317435752Sdrh   pNew = sqlite3DbMallocZero(pParse->db, sizeof(Expr) );
384a76b5dfcSdrh   if( pNew==0 ){
385d5d56523Sdanielk1977     sqlite3ExprListDelete(pList); /* Avoid leaking memory when malloc fails */
386a76b5dfcSdrh     return 0;
387a76b5dfcSdrh   }
388a76b5dfcSdrh   pNew->op = TK_FUNCTION;
389a76b5dfcSdrh   pNew->pList = pList;
3904b59ab5eSdrh   assert( pToken->dyn==0 );
391a76b5dfcSdrh   pNew->token = *pToken;
3926977fea8Sdrh   pNew->span = pNew->token;
393fc976065Sdanielk1977 
394fc976065Sdanielk1977   sqlite3ExprSetHeight(pNew);
395a76b5dfcSdrh   return pNew;
396a76b5dfcSdrh }
397a76b5dfcSdrh 
398a76b5dfcSdrh /*
399fa6bc000Sdrh ** Assign a variable number to an expression that encodes a wildcard
400fa6bc000Sdrh ** in the original SQL statement.
401fa6bc000Sdrh **
402fa6bc000Sdrh ** Wildcards consisting of a single "?" are assigned the next sequential
403fa6bc000Sdrh ** variable number.
404fa6bc000Sdrh **
405fa6bc000Sdrh ** Wildcards of the form "?nnn" are assigned the number "nnn".  We make
406fa6bc000Sdrh ** sure "nnn" is not too be to avoid a denial of service attack when
407fa6bc000Sdrh ** the SQL statement comes from an external source.
408fa6bc000Sdrh **
409fa6bc000Sdrh ** Wildcards of the form ":aaa" or "$aaa" are assigned the same number
410fa6bc000Sdrh ** as the previous instance of the same wildcard.  Or if this is the first
411fa6bc000Sdrh ** instance of the wildcard, the next sequenial variable number is
412fa6bc000Sdrh ** assigned.
413fa6bc000Sdrh */
414fa6bc000Sdrh void sqlite3ExprAssignVarNumber(Parse *pParse, Expr *pExpr){
415fa6bc000Sdrh   Token *pToken;
41617435752Sdrh   sqlite3 *db = pParse->db;
41717435752Sdrh 
418fa6bc000Sdrh   if( pExpr==0 ) return;
419fa6bc000Sdrh   pToken = &pExpr->token;
420fa6bc000Sdrh   assert( pToken->n>=1 );
421fa6bc000Sdrh   assert( pToken->z!=0 );
422fa6bc000Sdrh   assert( pToken->z[0]!=0 );
423fa6bc000Sdrh   if( pToken->n==1 ){
424fa6bc000Sdrh     /* Wildcard of the form "?".  Assign the next variable number */
425fa6bc000Sdrh     pExpr->iTable = ++pParse->nVar;
426fa6bc000Sdrh   }else if( pToken->z[0]=='?' ){
427fa6bc000Sdrh     /* Wildcard of the form "?nnn".  Convert "nnn" to an integer and
428fa6bc000Sdrh     ** use it as the variable number */
429fa6bc000Sdrh     int i;
4302646da7eSdrh     pExpr->iTable = i = atoi((char*)&pToken->z[1]);
431bb4957f8Sdrh     if( i<1 || i>db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER] ){
432fa6bc000Sdrh       sqlite3ErrorMsg(pParse, "variable number must be between ?1 and ?%d",
433bb4957f8Sdrh           db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER]);
434fa6bc000Sdrh     }
435fa6bc000Sdrh     if( i>pParse->nVar ){
436fa6bc000Sdrh       pParse->nVar = i;
437fa6bc000Sdrh     }
438fa6bc000Sdrh   }else{
439fa6bc000Sdrh     /* Wildcards of the form ":aaa" or "$aaa".  Reuse the same variable
440fa6bc000Sdrh     ** number as the prior appearance of the same name, or if the name
441fa6bc000Sdrh     ** has never appeared before, reuse the same variable number
442fa6bc000Sdrh     */
443fa6bc000Sdrh     int i, n;
444fa6bc000Sdrh     n = pToken->n;
445fa6bc000Sdrh     for(i=0; i<pParse->nVarExpr; i++){
446fa6bc000Sdrh       Expr *pE;
447fa6bc000Sdrh       if( (pE = pParse->apVarExpr[i])!=0
448fa6bc000Sdrh           && pE->token.n==n
449fa6bc000Sdrh           && memcmp(pE->token.z, pToken->z, n)==0 ){
450fa6bc000Sdrh         pExpr->iTable = pE->iTable;
451fa6bc000Sdrh         break;
452fa6bc000Sdrh       }
453fa6bc000Sdrh     }
454fa6bc000Sdrh     if( i>=pParse->nVarExpr ){
455fa6bc000Sdrh       pExpr->iTable = ++pParse->nVar;
456fa6bc000Sdrh       if( pParse->nVarExpr>=pParse->nVarExprAlloc-1 ){
457fa6bc000Sdrh         pParse->nVarExprAlloc += pParse->nVarExprAlloc + 10;
45817435752Sdrh         pParse->apVarExpr =
45917435752Sdrh             sqlite3DbReallocOrFree(
46017435752Sdrh               db,
46117435752Sdrh               pParse->apVarExpr,
46217435752Sdrh               pParse->nVarExprAlloc*sizeof(pParse->apVarExpr[0])
46317435752Sdrh             );
464fa6bc000Sdrh       }
46517435752Sdrh       if( !db->mallocFailed ){
466fa6bc000Sdrh         assert( pParse->apVarExpr!=0 );
467fa6bc000Sdrh         pParse->apVarExpr[pParse->nVarExpr++] = pExpr;
468fa6bc000Sdrh       }
469fa6bc000Sdrh     }
470fa6bc000Sdrh   }
471bb4957f8Sdrh   if( !pParse->nErr && pParse->nVar>db->aLimit[SQLITE_LIMIT_VARIABLE_NUMBER] ){
472832b2664Sdanielk1977     sqlite3ErrorMsg(pParse, "too many SQL variables");
473832b2664Sdanielk1977   }
474fa6bc000Sdrh }
475fa6bc000Sdrh 
476fa6bc000Sdrh /*
477a2e00042Sdrh ** Recursively delete an expression tree.
478a2e00042Sdrh */
4794adee20fSdanielk1977 void sqlite3ExprDelete(Expr *p){
480a2e00042Sdrh   if( p==0 ) return;
48117435752Sdrh   if( p->span.dyn ) sqlite3_free((char*)p->span.z);
48217435752Sdrh   if( p->token.dyn ) sqlite3_free((char*)p->token.z);
4834adee20fSdanielk1977   sqlite3ExprDelete(p->pLeft);
4844adee20fSdanielk1977   sqlite3ExprDelete(p->pRight);
4854adee20fSdanielk1977   sqlite3ExprListDelete(p->pList);
4864adee20fSdanielk1977   sqlite3SelectDelete(p->pSelect);
48717435752Sdrh   sqlite3_free(p);
488a2e00042Sdrh }
489a2e00042Sdrh 
490d2687b77Sdrh /*
491d2687b77Sdrh ** The Expr.token field might be a string literal that is quoted.
492d2687b77Sdrh ** If so, remove the quotation marks.
493d2687b77Sdrh */
49417435752Sdrh void sqlite3DequoteExpr(sqlite3 *db, Expr *p){
495d2687b77Sdrh   if( ExprHasAnyProperty(p, EP_Dequoted) ){
496d2687b77Sdrh     return;
497d2687b77Sdrh   }
498d2687b77Sdrh   ExprSetProperty(p, EP_Dequoted);
499d2687b77Sdrh   if( p->token.dyn==0 ){
50017435752Sdrh     sqlite3TokenCopy(db, &p->token, &p->token);
501d2687b77Sdrh   }
502d2687b77Sdrh   sqlite3Dequote((char*)p->token.z);
503d2687b77Sdrh }
504d2687b77Sdrh 
505a76b5dfcSdrh 
506a76b5dfcSdrh /*
507ff78bd2fSdrh ** The following group of routines make deep copies of expressions,
508ff78bd2fSdrh ** expression lists, ID lists, and select statements.  The copies can
509ff78bd2fSdrh ** be deleted (by being passed to their respective ...Delete() routines)
510ff78bd2fSdrh ** without effecting the originals.
511ff78bd2fSdrh **
5124adee20fSdanielk1977 ** The expression list, ID, and source lists return by sqlite3ExprListDup(),
5134adee20fSdanielk1977 ** sqlite3IdListDup(), and sqlite3SrcListDup() can not be further expanded
514ad3cab52Sdrh ** by subsequent calls to sqlite*ListAppend() routines.
515ff78bd2fSdrh **
516ad3cab52Sdrh ** Any tables that the SrcList might point to are not duplicated.
517ff78bd2fSdrh */
5181e536953Sdanielk1977 Expr *sqlite3ExprDup(sqlite3 *db, Expr *p){
519ff78bd2fSdrh   Expr *pNew;
520ff78bd2fSdrh   if( p==0 ) return 0;
52117435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*p) );
522ff78bd2fSdrh   if( pNew==0 ) return 0;
5233b167c75Sdrh   memcpy(pNew, p, sizeof(*pNew));
5246977fea8Sdrh   if( p->token.z!=0 ){
52517435752Sdrh     pNew->token.z = (u8*)sqlite3DbStrNDup(db, (char*)p->token.z, p->token.n);
5264b59ab5eSdrh     pNew->token.dyn = 1;
5274b59ab5eSdrh   }else{
5284efc4754Sdrh     assert( pNew->token.z==0 );
5294b59ab5eSdrh   }
5306977fea8Sdrh   pNew->span.z = 0;
53117435752Sdrh   pNew->pLeft = sqlite3ExprDup(db, p->pLeft);
53217435752Sdrh   pNew->pRight = sqlite3ExprDup(db, p->pRight);
53317435752Sdrh   pNew->pList = sqlite3ExprListDup(db, p->pList);
53417435752Sdrh   pNew->pSelect = sqlite3SelectDup(db, p->pSelect);
535ff78bd2fSdrh   return pNew;
536ff78bd2fSdrh }
53717435752Sdrh void sqlite3TokenCopy(sqlite3 *db, Token *pTo, Token *pFrom){
53817435752Sdrh   if( pTo->dyn ) sqlite3_free((char*)pTo->z);
5394b59ab5eSdrh   if( pFrom->z ){
5404b59ab5eSdrh     pTo->n = pFrom->n;
54117435752Sdrh     pTo->z = (u8*)sqlite3DbStrNDup(db, (char*)pFrom->z, pFrom->n);
5424b59ab5eSdrh     pTo->dyn = 1;
5434b59ab5eSdrh   }else{
5444b59ab5eSdrh     pTo->z = 0;
5454b59ab5eSdrh   }
5464b59ab5eSdrh }
54717435752Sdrh ExprList *sqlite3ExprListDup(sqlite3 *db, ExprList *p){
548ff78bd2fSdrh   ExprList *pNew;
549145716b3Sdrh   struct ExprList_item *pItem, *pOldItem;
550ff78bd2fSdrh   int i;
551ff78bd2fSdrh   if( p==0 ) return 0;
55217435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*pNew) );
553ff78bd2fSdrh   if( pNew==0 ) return 0;
55431dad9daSdanielk1977   pNew->iECursor = 0;
5554305d103Sdrh   pNew->nExpr = pNew->nAlloc = p->nExpr;
55617435752Sdrh   pNew->a = pItem = sqlite3DbMallocRaw(db,  p->nExpr*sizeof(p->a[0]) );
557e0048400Sdanielk1977   if( pItem==0 ){
55817435752Sdrh     sqlite3_free(pNew);
559e0048400Sdanielk1977     return 0;
560e0048400Sdanielk1977   }
561145716b3Sdrh   pOldItem = p->a;
562145716b3Sdrh   for(i=0; i<p->nExpr; i++, pItem++, pOldItem++){
5634b59ab5eSdrh     Expr *pNewExpr, *pOldExpr;
56417435752Sdrh     pItem->pExpr = pNewExpr = sqlite3ExprDup(db, pOldExpr = pOldItem->pExpr);
5656977fea8Sdrh     if( pOldExpr->span.z!=0 && pNewExpr ){
5666977fea8Sdrh       /* Always make a copy of the span for top-level expressions in the
5674b59ab5eSdrh       ** expression list.  The logic in SELECT processing that determines
5684b59ab5eSdrh       ** the names of columns in the result set needs this information */
56917435752Sdrh       sqlite3TokenCopy(db, &pNewExpr->span, &pOldExpr->span);
5704b59ab5eSdrh     }
5711f3e905cSdrh     assert( pNewExpr==0 || pNewExpr->span.z!=0
5726f7adc8aSdrh             || pOldExpr->span.z==0
57317435752Sdrh             || db->mallocFailed );
57417435752Sdrh     pItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
575145716b3Sdrh     pItem->sortOrder = pOldItem->sortOrder;
576145716b3Sdrh     pItem->isAgg = pOldItem->isAgg;
5773e7bc9caSdrh     pItem->done = 0;
578ff78bd2fSdrh   }
579ff78bd2fSdrh   return pNew;
580ff78bd2fSdrh }
58193758c8dSdanielk1977 
58293758c8dSdanielk1977 /*
58393758c8dSdanielk1977 ** If cursors, triggers, views and subqueries are all omitted from
58493758c8dSdanielk1977 ** the build, then none of the following routines, except for
58593758c8dSdanielk1977 ** sqlite3SelectDup(), can be called. sqlite3SelectDup() is sometimes
58693758c8dSdanielk1977 ** called with a NULL argument.
58793758c8dSdanielk1977 */
5886a67fe8eSdanielk1977 #if !defined(SQLITE_OMIT_VIEW) || !defined(SQLITE_OMIT_TRIGGER) \
5896a67fe8eSdanielk1977  || !defined(SQLITE_OMIT_SUBQUERY)
59017435752Sdrh SrcList *sqlite3SrcListDup(sqlite3 *db, SrcList *p){
591ad3cab52Sdrh   SrcList *pNew;
592ad3cab52Sdrh   int i;
593113088ecSdrh   int nByte;
594ad3cab52Sdrh   if( p==0 ) return 0;
595113088ecSdrh   nByte = sizeof(*p) + (p->nSrc>0 ? sizeof(p->a[0]) * (p->nSrc-1) : 0);
59617435752Sdrh   pNew = sqlite3DbMallocRaw(db, nByte );
597ad3cab52Sdrh   if( pNew==0 ) return 0;
5984305d103Sdrh   pNew->nSrc = pNew->nAlloc = p->nSrc;
599ad3cab52Sdrh   for(i=0; i<p->nSrc; i++){
6004efc4754Sdrh     struct SrcList_item *pNewItem = &pNew->a[i];
6014efc4754Sdrh     struct SrcList_item *pOldItem = &p->a[i];
602ed8a3bb1Sdrh     Table *pTab;
60317435752Sdrh     pNewItem->zDatabase = sqlite3DbStrDup(db, pOldItem->zDatabase);
60417435752Sdrh     pNewItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
60517435752Sdrh     pNewItem->zAlias = sqlite3DbStrDup(db, pOldItem->zAlias);
6064efc4754Sdrh     pNewItem->jointype = pOldItem->jointype;
6074efc4754Sdrh     pNewItem->iCursor = pOldItem->iCursor;
6081787ccabSdanielk1977     pNewItem->isPopulated = pOldItem->isPopulated;
609ed8a3bb1Sdrh     pTab = pNewItem->pTab = pOldItem->pTab;
610ed8a3bb1Sdrh     if( pTab ){
611ed8a3bb1Sdrh       pTab->nRef++;
612a1cb183dSdanielk1977     }
61317435752Sdrh     pNewItem->pSelect = sqlite3SelectDup(db, pOldItem->pSelect);
61417435752Sdrh     pNewItem->pOn = sqlite3ExprDup(db, pOldItem->pOn);
61517435752Sdrh     pNewItem->pUsing = sqlite3IdListDup(db, pOldItem->pUsing);
6166c18b6e0Sdanielk1977     pNewItem->colUsed = pOldItem->colUsed;
617ad3cab52Sdrh   }
618ad3cab52Sdrh   return pNew;
619ad3cab52Sdrh }
62017435752Sdrh IdList *sqlite3IdListDup(sqlite3 *db, IdList *p){
621ff78bd2fSdrh   IdList *pNew;
622ff78bd2fSdrh   int i;
623ff78bd2fSdrh   if( p==0 ) return 0;
62417435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*pNew) );
625ff78bd2fSdrh   if( pNew==0 ) return 0;
6264305d103Sdrh   pNew->nId = pNew->nAlloc = p->nId;
62717435752Sdrh   pNew->a = sqlite3DbMallocRaw(db, p->nId*sizeof(p->a[0]) );
628d5d56523Sdanielk1977   if( pNew->a==0 ){
62917435752Sdrh     sqlite3_free(pNew);
630d5d56523Sdanielk1977     return 0;
631d5d56523Sdanielk1977   }
632ff78bd2fSdrh   for(i=0; i<p->nId; i++){
6334efc4754Sdrh     struct IdList_item *pNewItem = &pNew->a[i];
6344efc4754Sdrh     struct IdList_item *pOldItem = &p->a[i];
63517435752Sdrh     pNewItem->zName = sqlite3DbStrDup(db, pOldItem->zName);
6364efc4754Sdrh     pNewItem->idx = pOldItem->idx;
637ff78bd2fSdrh   }
638ff78bd2fSdrh   return pNew;
639ff78bd2fSdrh }
64017435752Sdrh Select *sqlite3SelectDup(sqlite3 *db, Select *p){
641ff78bd2fSdrh   Select *pNew;
642ff78bd2fSdrh   if( p==0 ) return 0;
64317435752Sdrh   pNew = sqlite3DbMallocRaw(db, sizeof(*p) );
644ff78bd2fSdrh   if( pNew==0 ) return 0;
645ff78bd2fSdrh   pNew->isDistinct = p->isDistinct;
64617435752Sdrh   pNew->pEList = sqlite3ExprListDup(db, p->pEList);
64717435752Sdrh   pNew->pSrc = sqlite3SrcListDup(db, p->pSrc);
64817435752Sdrh   pNew->pWhere = sqlite3ExprDup(db, p->pWhere);
64917435752Sdrh   pNew->pGroupBy = sqlite3ExprListDup(db, p->pGroupBy);
65017435752Sdrh   pNew->pHaving = sqlite3ExprDup(db, p->pHaving);
65117435752Sdrh   pNew->pOrderBy = sqlite3ExprListDup(db, p->pOrderBy);
652ff78bd2fSdrh   pNew->op = p->op;
65317435752Sdrh   pNew->pPrior = sqlite3SelectDup(db, p->pPrior);
65417435752Sdrh   pNew->pLimit = sqlite3ExprDup(db, p->pLimit);
65517435752Sdrh   pNew->pOffset = sqlite3ExprDup(db, p->pOffset);
6567b58daeaSdrh   pNew->iLimit = -1;
6577b58daeaSdrh   pNew->iOffset = -1;
658a1cb183dSdanielk1977   pNew->isResolved = p->isResolved;
659a1cb183dSdanielk1977   pNew->isAgg = p->isAgg;
660b9bb7c18Sdrh   pNew->usesEphm = 0;
6618e647b81Sdrh   pNew->disallowOrderBy = 0;
6620342b1f5Sdrh   pNew->pRightmost = 0;
663b9bb7c18Sdrh   pNew->addrOpenEphm[0] = -1;
664b9bb7c18Sdrh   pNew->addrOpenEphm[1] = -1;
665b9bb7c18Sdrh   pNew->addrOpenEphm[2] = -1;
666ff78bd2fSdrh   return pNew;
667ff78bd2fSdrh }
66893758c8dSdanielk1977 #else
66917435752Sdrh Select *sqlite3SelectDup(sqlite3 *db, Select *p){
67093758c8dSdanielk1977   assert( p==0 );
67193758c8dSdanielk1977   return 0;
67293758c8dSdanielk1977 }
67393758c8dSdanielk1977 #endif
674ff78bd2fSdrh 
675ff78bd2fSdrh 
676ff78bd2fSdrh /*
677a76b5dfcSdrh ** Add a new element to the end of an expression list.  If pList is
678a76b5dfcSdrh ** initially NULL, then create a new expression list.
679a76b5dfcSdrh */
68017435752Sdrh ExprList *sqlite3ExprListAppend(
68117435752Sdrh   Parse *pParse,          /* Parsing context */
68217435752Sdrh   ExprList *pList,        /* List to which to append. Might be NULL */
68317435752Sdrh   Expr *pExpr,            /* Expression to be appended */
68417435752Sdrh   Token *pName            /* AS keyword for the expression */
68517435752Sdrh ){
68617435752Sdrh   sqlite3 *db = pParse->db;
687a76b5dfcSdrh   if( pList==0 ){
68817435752Sdrh     pList = sqlite3DbMallocZero(db, sizeof(ExprList) );
689a76b5dfcSdrh     if( pList==0 ){
690d5d56523Sdanielk1977       goto no_mem;
691a76b5dfcSdrh     }
6924efc4754Sdrh     assert( pList->nAlloc==0 );
693a76b5dfcSdrh   }
6944305d103Sdrh   if( pList->nAlloc<=pList->nExpr ){
695d5d56523Sdanielk1977     struct ExprList_item *a;
696d5d56523Sdanielk1977     int n = pList->nAlloc*2 + 4;
69726783a58Sdanielk1977     a = sqlite3DbRealloc(db, pList->a, n*sizeof(pList->a[0]));
698d5d56523Sdanielk1977     if( a==0 ){
699d5d56523Sdanielk1977       goto no_mem;
700a76b5dfcSdrh     }
701d5d56523Sdanielk1977     pList->a = a;
702d5d56523Sdanielk1977     pList->nAlloc = n;
703a76b5dfcSdrh   }
7044efc4754Sdrh   assert( pList->a!=0 );
7054efc4754Sdrh   if( pExpr || pName ){
7064efc4754Sdrh     struct ExprList_item *pItem = &pList->a[pList->nExpr++];
7074efc4754Sdrh     memset(pItem, 0, sizeof(*pItem));
70817435752Sdrh     pItem->zName = sqlite3NameFromToken(db, pName);
709e94ddc9eSdanielk1977     pItem->pExpr = pExpr;
710a76b5dfcSdrh   }
711a76b5dfcSdrh   return pList;
712d5d56523Sdanielk1977 
713d5d56523Sdanielk1977 no_mem:
714d5d56523Sdanielk1977   /* Avoid leaking memory if malloc has failed. */
715d5d56523Sdanielk1977   sqlite3ExprDelete(pExpr);
716d5d56523Sdanielk1977   sqlite3ExprListDelete(pList);
717d5d56523Sdanielk1977   return 0;
718a76b5dfcSdrh }
719a76b5dfcSdrh 
720a76b5dfcSdrh /*
7217a15a4beSdanielk1977 ** If the expression list pEList contains more than iLimit elements,
7227a15a4beSdanielk1977 ** leave an error message in pParse.
7237a15a4beSdanielk1977 */
7247a15a4beSdanielk1977 void sqlite3ExprListCheckLength(
7257a15a4beSdanielk1977   Parse *pParse,
7267a15a4beSdanielk1977   ExprList *pEList,
7277a15a4beSdanielk1977   const char *zObject
7287a15a4beSdanielk1977 ){
729b1a6c3c1Sdrh   int mx = pParse->db->aLimit[SQLITE_LIMIT_COLUMN];
730b1a6c3c1Sdrh   if( pEList && pEList->nExpr>mx ){
7317a15a4beSdanielk1977     sqlite3ErrorMsg(pParse, "too many columns in %s", zObject);
7327a15a4beSdanielk1977   }
7337a15a4beSdanielk1977 }
7347a15a4beSdanielk1977 
735fc976065Sdanielk1977 
736fc976065Sdanielk1977 /* The following three functions, heightOfExpr(), heightOfExprList()
737fc976065Sdanielk1977 ** and heightOfSelect(), are used to determine the maximum height
738fc976065Sdanielk1977 ** of any expression tree referenced by the structure passed as the
739fc976065Sdanielk1977 ** first argument.
740fc976065Sdanielk1977 **
741fc976065Sdanielk1977 ** If this maximum height is greater than the current value pointed
742fc976065Sdanielk1977 ** to by pnHeight, the second parameter, then set *pnHeight to that
743fc976065Sdanielk1977 ** value.
744fc976065Sdanielk1977 */
745fc976065Sdanielk1977 static void heightOfExpr(Expr *p, int *pnHeight){
746fc976065Sdanielk1977   if( p ){
747fc976065Sdanielk1977     if( p->nHeight>*pnHeight ){
748fc976065Sdanielk1977       *pnHeight = p->nHeight;
749fc976065Sdanielk1977     }
750fc976065Sdanielk1977   }
751fc976065Sdanielk1977 }
752fc976065Sdanielk1977 static void heightOfExprList(ExprList *p, int *pnHeight){
753fc976065Sdanielk1977   if( p ){
754fc976065Sdanielk1977     int i;
755fc976065Sdanielk1977     for(i=0; i<p->nExpr; i++){
756fc976065Sdanielk1977       heightOfExpr(p->a[i].pExpr, pnHeight);
757fc976065Sdanielk1977     }
758fc976065Sdanielk1977   }
759fc976065Sdanielk1977 }
760fc976065Sdanielk1977 static void heightOfSelect(Select *p, int *pnHeight){
761fc976065Sdanielk1977   if( p ){
762fc976065Sdanielk1977     heightOfExpr(p->pWhere, pnHeight);
763fc976065Sdanielk1977     heightOfExpr(p->pHaving, pnHeight);
764fc976065Sdanielk1977     heightOfExpr(p->pLimit, pnHeight);
765fc976065Sdanielk1977     heightOfExpr(p->pOffset, pnHeight);
766fc976065Sdanielk1977     heightOfExprList(p->pEList, pnHeight);
767fc976065Sdanielk1977     heightOfExprList(p->pGroupBy, pnHeight);
768fc976065Sdanielk1977     heightOfExprList(p->pOrderBy, pnHeight);
769fc976065Sdanielk1977     heightOfSelect(p->pPrior, pnHeight);
770fc976065Sdanielk1977   }
771fc976065Sdanielk1977 }
772fc976065Sdanielk1977 
773fc976065Sdanielk1977 /*
774fc976065Sdanielk1977 ** Set the Expr.nHeight variable in the structure passed as an
775fc976065Sdanielk1977 ** argument. An expression with no children, Expr.pList or
776fc976065Sdanielk1977 ** Expr.pSelect member has a height of 1. Any other expression
777fc976065Sdanielk1977 ** has a height equal to the maximum height of any other
778fc976065Sdanielk1977 ** referenced Expr plus one.
779fc976065Sdanielk1977 */
780fc976065Sdanielk1977 void sqlite3ExprSetHeight(Expr *p){
781fc976065Sdanielk1977   int nHeight = 0;
782fc976065Sdanielk1977   heightOfExpr(p->pLeft, &nHeight);
783fc976065Sdanielk1977   heightOfExpr(p->pRight, &nHeight);
784fc976065Sdanielk1977   heightOfExprList(p->pList, &nHeight);
785fc976065Sdanielk1977   heightOfSelect(p->pSelect, &nHeight);
786fc976065Sdanielk1977   p->nHeight = nHeight + 1;
787fc976065Sdanielk1977 }
788fc976065Sdanielk1977 
789fc976065Sdanielk1977 /*
790fc976065Sdanielk1977 ** Return the maximum height of any expression tree referenced
791fc976065Sdanielk1977 ** by the select statement passed as an argument.
792fc976065Sdanielk1977 */
793fc976065Sdanielk1977 int sqlite3SelectExprHeight(Select *p){
794fc976065Sdanielk1977   int nHeight = 0;
795fc976065Sdanielk1977   heightOfSelect(p, &nHeight);
796fc976065Sdanielk1977   return nHeight;
797fc976065Sdanielk1977 }
798fc976065Sdanielk1977 
7997a15a4beSdanielk1977 /*
800a76b5dfcSdrh ** Delete an entire expression list.
801a76b5dfcSdrh */
8024adee20fSdanielk1977 void sqlite3ExprListDelete(ExprList *pList){
803a76b5dfcSdrh   int i;
804be5c89acSdrh   struct ExprList_item *pItem;
805a76b5dfcSdrh   if( pList==0 ) return;
8061bdd9b57Sdrh   assert( pList->a!=0 || (pList->nExpr==0 && pList->nAlloc==0) );
8071bdd9b57Sdrh   assert( pList->nExpr<=pList->nAlloc );
808be5c89acSdrh   for(pItem=pList->a, i=0; i<pList->nExpr; i++, pItem++){
809be5c89acSdrh     sqlite3ExprDelete(pItem->pExpr);
81017435752Sdrh     sqlite3_free(pItem->zName);
811a76b5dfcSdrh   }
81217435752Sdrh   sqlite3_free(pList->a);
81317435752Sdrh   sqlite3_free(pList);
814a76b5dfcSdrh }
815a76b5dfcSdrh 
816a76b5dfcSdrh /*
817678ccce8Sdrh ** Walk an expression tree.  Call xFunc for each node visited.  xFunc
818678ccce8Sdrh ** is called on the node before xFunc is called on the nodes children.
81973b211abSdrh **
820626a879aSdrh ** The return value from xFunc determines whether the tree walk continues.
821626a879aSdrh ** 0 means continue walking the tree.  1 means do not walk children
822626a879aSdrh ** of the current node but continue with siblings.  2 means abandon
823626a879aSdrh ** the tree walk completely.
824626a879aSdrh **
825626a879aSdrh ** The return value from this routine is 1 to abandon the tree walk
826626a879aSdrh ** and 0 to continue.
82787abf5c0Sdrh **
82887abf5c0Sdrh ** NOTICE:  This routine does *not* descend into subqueries.
829626a879aSdrh */
830a58fdfb1Sdanielk1977 static int walkExprList(ExprList *, int (*)(void *, Expr*), void *);
831626a879aSdrh static int walkExprTree(Expr *pExpr, int (*xFunc)(void*,Expr*), void *pArg){
832626a879aSdrh   int rc;
833626a879aSdrh   if( pExpr==0 ) return 0;
834626a879aSdrh   rc = (*xFunc)(pArg, pExpr);
835626a879aSdrh   if( rc==0 ){
836626a879aSdrh     if( walkExprTree(pExpr->pLeft, xFunc, pArg) ) return 1;
837626a879aSdrh     if( walkExprTree(pExpr->pRight, xFunc, pArg) ) return 1;
838a58fdfb1Sdanielk1977     if( walkExprList(pExpr->pList, xFunc, pArg) ) return 1;
839626a879aSdrh   }
840626a879aSdrh   return rc>1;
841626a879aSdrh }
842626a879aSdrh 
843626a879aSdrh /*
844a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in list p.
845a58fdfb1Sdanielk1977 */
846a58fdfb1Sdanielk1977 static int walkExprList(ExprList *p, int (*xFunc)(void *, Expr*), void *pArg){
847a58fdfb1Sdanielk1977   int i;
848a58fdfb1Sdanielk1977   struct ExprList_item *pItem;
849a58fdfb1Sdanielk1977   if( !p ) return 0;
850a58fdfb1Sdanielk1977   for(i=p->nExpr, pItem=p->a; i>0; i--, pItem++){
851a58fdfb1Sdanielk1977     if( walkExprTree(pItem->pExpr, xFunc, pArg) ) return 1;
852a58fdfb1Sdanielk1977   }
853a58fdfb1Sdanielk1977   return 0;
854a58fdfb1Sdanielk1977 }
855a58fdfb1Sdanielk1977 
856a58fdfb1Sdanielk1977 /*
857a58fdfb1Sdanielk1977 ** Call walkExprTree() for every expression in Select p, not including
858a58fdfb1Sdanielk1977 ** expressions that are part of sub-selects in any FROM clause or the LIMIT
859a58fdfb1Sdanielk1977 ** or OFFSET expressions..
860a58fdfb1Sdanielk1977 */
861a58fdfb1Sdanielk1977 static int walkSelectExpr(Select *p, int (*xFunc)(void *, Expr*), void *pArg){
862a58fdfb1Sdanielk1977   walkExprList(p->pEList, xFunc, pArg);
863a58fdfb1Sdanielk1977   walkExprTree(p->pWhere, xFunc, pArg);
864a58fdfb1Sdanielk1977   walkExprList(p->pGroupBy, xFunc, pArg);
865a58fdfb1Sdanielk1977   walkExprTree(p->pHaving, xFunc, pArg);
866a58fdfb1Sdanielk1977   walkExprList(p->pOrderBy, xFunc, pArg);
86715d7982aSdanielk1977   if( p->pPrior ){
86815d7982aSdanielk1977     walkSelectExpr(p->pPrior, xFunc, pArg);
86915d7982aSdanielk1977   }
870a58fdfb1Sdanielk1977   return 0;
871a58fdfb1Sdanielk1977 }
872a58fdfb1Sdanielk1977 
873a58fdfb1Sdanielk1977 
874a58fdfb1Sdanielk1977 /*
875626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
876626a879aSdrh **
877626a879aSdrh ** pArg is really a pointer to an integer.  If we can tell by looking
87873b211abSdrh ** at pExpr that the expression that contains pExpr is not a constant
87973b211abSdrh ** expression, then set *pArg to 0 and return 2 to abandon the tree walk.
88073b211abSdrh ** If pExpr does does not disqualify the expression from being a constant
88173b211abSdrh ** then do nothing.
88273b211abSdrh **
88373b211abSdrh ** After walking the whole tree, if no nodes are found that disqualify
88473b211abSdrh ** the expression as constant, then we assume the whole expression
88573b211abSdrh ** is constant.  See sqlite3ExprIsConstant() for additional information.
886626a879aSdrh */
887626a879aSdrh static int exprNodeIsConstant(void *pArg, Expr *pExpr){
8880a168377Sdrh   int *pN = (int*)pArg;
8890a168377Sdrh 
8900a168377Sdrh   /* If *pArg is 3 then any term of the expression that comes from
8910a168377Sdrh   ** the ON or USING clauses of a join disqualifies the expression
8920a168377Sdrh   ** from being considered constant. */
8930a168377Sdrh   if( (*pN)==3 && ExprHasAnyProperty(pExpr, EP_FromJoin) ){
8940a168377Sdrh     *pN = 0;
8950a168377Sdrh     return 2;
8960a168377Sdrh   }
8970a168377Sdrh 
898626a879aSdrh   switch( pExpr->op ){
899eb55bd2fSdrh     /* Consider functions to be constant if all their arguments are constant
900eb55bd2fSdrh     ** and *pArg==2 */
901eb55bd2fSdrh     case TK_FUNCTION:
9020a168377Sdrh       if( (*pN)==2 ) return 0;
903eb55bd2fSdrh       /* Fall through */
904626a879aSdrh     case TK_ID:
905626a879aSdrh     case TK_COLUMN:
906626a879aSdrh     case TK_DOT:
907626a879aSdrh     case TK_AGG_FUNCTION:
90813449892Sdrh     case TK_AGG_COLUMN:
909fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
910fe2093d7Sdrh     case TK_SELECT:
911fe2093d7Sdrh     case TK_EXISTS:
912fe2093d7Sdrh #endif
9130a168377Sdrh       *pN = 0;
914626a879aSdrh       return 2;
91587abf5c0Sdrh     case TK_IN:
91687abf5c0Sdrh       if( pExpr->pSelect ){
9170a168377Sdrh         *pN = 0;
91887abf5c0Sdrh         return 2;
91987abf5c0Sdrh       }
920626a879aSdrh     default:
921626a879aSdrh       return 0;
922626a879aSdrh   }
923626a879aSdrh }
924626a879aSdrh 
925626a879aSdrh /*
926fef5208cSdrh ** Walk an expression tree.  Return 1 if the expression is constant
927eb55bd2fSdrh ** and 0 if it involves variables or function calls.
9282398937bSdrh **
9292398937bSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
9302398937bSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
9312398937bSdrh ** a constant.
932fef5208cSdrh */
9334adee20fSdanielk1977 int sqlite3ExprIsConstant(Expr *p){
934626a879aSdrh   int isConst = 1;
935626a879aSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
936626a879aSdrh   return isConst;
937fef5208cSdrh }
938fef5208cSdrh 
939fef5208cSdrh /*
940eb55bd2fSdrh ** Walk an expression tree.  Return 1 if the expression is constant
9410a168377Sdrh ** that does no originate from the ON or USING clauses of a join.
9420a168377Sdrh ** Return 0 if it involves variables or function calls or terms from
9430a168377Sdrh ** an ON or USING clause.
9440a168377Sdrh */
9450a168377Sdrh int sqlite3ExprIsConstantNotJoin(Expr *p){
9460a168377Sdrh   int isConst = 3;
9470a168377Sdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
9480a168377Sdrh   return isConst!=0;
9490a168377Sdrh }
9500a168377Sdrh 
9510a168377Sdrh /*
9520a168377Sdrh ** Walk an expression tree.  Return 1 if the expression is constant
953eb55bd2fSdrh ** or a function call with constant arguments.  Return and 0 if there
954eb55bd2fSdrh ** are any variables.
955eb55bd2fSdrh **
956eb55bd2fSdrh ** For the purposes of this function, a double-quoted string (ex: "abc")
957eb55bd2fSdrh ** is considered a variable but a single-quoted string (ex: 'abc') is
958eb55bd2fSdrh ** a constant.
959eb55bd2fSdrh */
960eb55bd2fSdrh int sqlite3ExprIsConstantOrFunction(Expr *p){
961eb55bd2fSdrh   int isConst = 2;
962eb55bd2fSdrh   walkExprTree(p, exprNodeIsConstant, &isConst);
963eb55bd2fSdrh   return isConst!=0;
964eb55bd2fSdrh }
965eb55bd2fSdrh 
966eb55bd2fSdrh /*
96773b211abSdrh ** If the expression p codes a constant integer that is small enough
968202b2df7Sdrh ** to fit in a 32-bit integer, return 1 and put the value of the integer
969202b2df7Sdrh ** in *pValue.  If the expression is not an integer or if it is too big
970202b2df7Sdrh ** to fit in a signed 32-bit integer, return 0 and leave *pValue unchanged.
971e4de1febSdrh */
9724adee20fSdanielk1977 int sqlite3ExprIsInteger(Expr *p, int *pValue){
973e4de1febSdrh   switch( p->op ){
974e4de1febSdrh     case TK_INTEGER: {
9752646da7eSdrh       if( sqlite3GetInt32((char*)p->token.z, pValue) ){
976e4de1febSdrh         return 1;
977e4de1febSdrh       }
978202b2df7Sdrh       break;
979202b2df7Sdrh     }
9804b59ab5eSdrh     case TK_UPLUS: {
9814adee20fSdanielk1977       return sqlite3ExprIsInteger(p->pLeft, pValue);
9824b59ab5eSdrh     }
983e4de1febSdrh     case TK_UMINUS: {
984e4de1febSdrh       int v;
9854adee20fSdanielk1977       if( sqlite3ExprIsInteger(p->pLeft, &v) ){
986e4de1febSdrh         *pValue = -v;
987e4de1febSdrh         return 1;
988e4de1febSdrh       }
989e4de1febSdrh       break;
990e4de1febSdrh     }
991e4de1febSdrh     default: break;
992e4de1febSdrh   }
993e4de1febSdrh   return 0;
994e4de1febSdrh }
995e4de1febSdrh 
996e4de1febSdrh /*
997c4a3c779Sdrh ** Return TRUE if the given string is a row-id column name.
998c4a3c779Sdrh */
9994adee20fSdanielk1977 int sqlite3IsRowid(const char *z){
10004adee20fSdanielk1977   if( sqlite3StrICmp(z, "_ROWID_")==0 ) return 1;
10014adee20fSdanielk1977   if( sqlite3StrICmp(z, "ROWID")==0 ) return 1;
10024adee20fSdanielk1977   if( sqlite3StrICmp(z, "OID")==0 ) return 1;
1003c4a3c779Sdrh   return 0;
1004c4a3c779Sdrh }
1005c4a3c779Sdrh 
1006c4a3c779Sdrh /*
10078141f61eSdrh ** Given the name of a column of the form X.Y.Z or Y.Z or just Z, look up
10088141f61eSdrh ** that name in the set of source tables in pSrcList and make the pExpr
10098141f61eSdrh ** expression node refer back to that source column.  The following changes
10108141f61eSdrh ** are made to pExpr:
10118141f61eSdrh **
10128141f61eSdrh **    pExpr->iDb           Set the index in db->aDb[] of the database holding
10138141f61eSdrh **                         the table.
10148141f61eSdrh **    pExpr->iTable        Set to the cursor number for the table obtained
10158141f61eSdrh **                         from pSrcList.
10168141f61eSdrh **    pExpr->iColumn       Set to the column number within the table.
10178141f61eSdrh **    pExpr->op            Set to TK_COLUMN.
10188141f61eSdrh **    pExpr->pLeft         Any expression this points to is deleted
10198141f61eSdrh **    pExpr->pRight        Any expression this points to is deleted.
10208141f61eSdrh **
10218141f61eSdrh ** The pDbToken is the name of the database (the "X").  This value may be
10228141f61eSdrh ** NULL meaning that name is of the form Y.Z or Z.  Any available database
10238141f61eSdrh ** can be used.  The pTableToken is the name of the table (the "Y").  This
10248141f61eSdrh ** value can be NULL if pDbToken is also NULL.  If pTableToken is NULL it
10258141f61eSdrh ** means that the form of the name is Z and that columns from any table
10268141f61eSdrh ** can be used.
10278141f61eSdrh **
10288141f61eSdrh ** If the name cannot be resolved unambiguously, leave an error message
10298141f61eSdrh ** in pParse and return non-zero.  Return zero on success.
10308141f61eSdrh */
10318141f61eSdrh static int lookupName(
10328141f61eSdrh   Parse *pParse,       /* The parsing context */
10338141f61eSdrh   Token *pDbToken,     /* Name of the database containing table, or NULL */
10348141f61eSdrh   Token *pTableToken,  /* Name of table containing column, or NULL */
10358141f61eSdrh   Token *pColumnToken, /* Name of the column. */
1036626a879aSdrh   NameContext *pNC,    /* The name context used to resolve the name */
10378141f61eSdrh   Expr *pExpr          /* Make this EXPR node point to the selected column */
10388141f61eSdrh ){
10398141f61eSdrh   char *zDb = 0;       /* Name of the database.  The "X" in X.Y.Z */
10408141f61eSdrh   char *zTab = 0;      /* Name of the table.  The "Y" in X.Y.Z or Y.Z */
10418141f61eSdrh   char *zCol = 0;      /* Name of the column.  The "Z" */
10428141f61eSdrh   int i, j;            /* Loop counters */
10438141f61eSdrh   int cnt = 0;         /* Number of matching column names */
10448141f61eSdrh   int cntTab = 0;      /* Number of matching table names */
10459bb575fdSdrh   sqlite3 *db = pParse->db;  /* The database */
104651669863Sdrh   struct SrcList_item *pItem;       /* Use for looping over pSrcList items */
104751669863Sdrh   struct SrcList_item *pMatch = 0;  /* The matching pSrcList item */
104873b211abSdrh   NameContext *pTopNC = pNC;        /* First namecontext in the list */
1049728b5779Sdrh   Schema *pSchema = 0;              /* Schema of the expression */
10508141f61eSdrh 
10518141f61eSdrh   assert( pColumnToken && pColumnToken->z ); /* The Z in X.Y.Z cannot be NULL */
105217435752Sdrh   zDb = sqlite3NameFromToken(db, pDbToken);
105317435752Sdrh   zTab = sqlite3NameFromToken(db, pTableToken);
105417435752Sdrh   zCol = sqlite3NameFromToken(db, pColumnToken);
105517435752Sdrh   if( db->mallocFailed ){
1056d5d56523Sdanielk1977     goto lookupname_end;
10578141f61eSdrh   }
10588141f61eSdrh 
10598141f61eSdrh   pExpr->iTable = -1;
1060626a879aSdrh   while( pNC && cnt==0 ){
1061ffe07b2dSdrh     ExprList *pEList;
1062626a879aSdrh     SrcList *pSrcList = pNC->pSrcList;
1063626a879aSdrh 
1064b3bce662Sdanielk1977     if( pSrcList ){
106551669863Sdrh       for(i=0, pItem=pSrcList->a; i<pSrcList->nSrc; i++, pItem++){
106643617e9aSdrh         Table *pTab;
106743617e9aSdrh         int iDb;
10688141f61eSdrh         Column *pCol;
10698141f61eSdrh 
107043617e9aSdrh         pTab = pItem->pTab;
107143617e9aSdrh         assert( pTab!=0 );
107243617e9aSdrh         iDb = sqlite3SchemaToIndex(db, pTab->pSchema);
10738141f61eSdrh         assert( pTab->nCol>0 );
10748141f61eSdrh         if( zTab ){
10758141f61eSdrh           if( pItem->zAlias ){
10768141f61eSdrh             char *zTabName = pItem->zAlias;
10774adee20fSdanielk1977             if( sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
10788141f61eSdrh           }else{
10798141f61eSdrh             char *zTabName = pTab->zName;
10804adee20fSdanielk1977             if( zTabName==0 || sqlite3StrICmp(zTabName, zTab)!=0 ) continue;
1081da184236Sdanielk1977             if( zDb!=0 && sqlite3StrICmp(db->aDb[iDb].zName, zDb)!=0 ){
10828141f61eSdrh               continue;
10838141f61eSdrh             }
10848141f61eSdrh           }
10858141f61eSdrh         }
10868141f61eSdrh         if( 0==(cntTab++) ){
10878141f61eSdrh           pExpr->iTable = pItem->iCursor;
1088728b5779Sdrh           pSchema = pTab->pSchema;
108951669863Sdrh           pMatch = pItem;
10908141f61eSdrh         }
10918141f61eSdrh         for(j=0, pCol=pTab->aCol; j<pTab->nCol; j++, pCol++){
10924adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
1093b3bf556eSdanielk1977             const char *zColl = pTab->aCol[j].zColl;
1094873fac0cSdrh             IdList *pUsing;
10958141f61eSdrh             cnt++;
10968141f61eSdrh             pExpr->iTable = pItem->iCursor;
109751669863Sdrh             pMatch = pItem;
1098728b5779Sdrh             pSchema = pTab->pSchema;
10998141f61eSdrh             /* Substitute the rowid (column -1) for the INTEGER PRIMARY KEY */
11008141f61eSdrh             pExpr->iColumn = j==pTab->iPKey ? -1 : j;
1101a37cdde0Sdanielk1977             pExpr->affinity = pTab->aCol[j].affinity;
11028b4c40d8Sdrh             if( (pExpr->flags & EP_ExpCollate)==0 ){
1103b3bf556eSdanielk1977               pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
11048b4c40d8Sdrh             }
110561dfc31dSdrh             if( i<pSrcList->nSrc-1 ){
110661dfc31dSdrh               if( pItem[1].jointype & JT_NATURAL ){
1107355ef361Sdrh                 /* If this match occurred in the left table of a natural join,
1108355ef361Sdrh                 ** then skip the right table to avoid a duplicate match */
1109355ef361Sdrh                 pItem++;
1110355ef361Sdrh                 i++;
111161dfc31dSdrh               }else if( (pUsing = pItem[1].pUsing)!=0 ){
1112873fac0cSdrh                 /* If this match occurs on a column that is in the USING clause
1113873fac0cSdrh                 ** of a join, skip the search of the right table of the join
1114873fac0cSdrh                 ** to avoid a duplicate match there. */
1115873fac0cSdrh                 int k;
1116873fac0cSdrh                 for(k=0; k<pUsing->nId; k++){
1117873fac0cSdrh                   if( sqlite3StrICmp(pUsing->a[k].zName, zCol)==0 ){
1118873fac0cSdrh                     pItem++;
1119873fac0cSdrh                     i++;
1120873fac0cSdrh                     break;
1121873fac0cSdrh                   }
1122873fac0cSdrh                 }
1123873fac0cSdrh               }
112461dfc31dSdrh             }
11258141f61eSdrh             break;
11268141f61eSdrh           }
11278141f61eSdrh         }
11288141f61eSdrh       }
1129b3bce662Sdanielk1977     }
11308141f61eSdrh 
1131b7f9164eSdrh #ifndef SQLITE_OMIT_TRIGGER
11328141f61eSdrh     /* If we have not already resolved the name, then maybe
11338141f61eSdrh     ** it is a new.* or old.* trigger argument reference
11348141f61eSdrh     */
11358141f61eSdrh     if( zDb==0 && zTab!=0 && cnt==0 && pParse->trigStack!=0 ){
11368141f61eSdrh       TriggerStack *pTriggerStack = pParse->trigStack;
11378141f61eSdrh       Table *pTab = 0;
11388f2c54e6Sdanielk1977       u32 *piColMask;
11394adee20fSdanielk1977       if( pTriggerStack->newIdx != -1 && sqlite3StrICmp("new", zTab) == 0 ){
11408141f61eSdrh         pExpr->iTable = pTriggerStack->newIdx;
11418141f61eSdrh         assert( pTriggerStack->pTab );
11428141f61eSdrh         pTab = pTriggerStack->pTab;
11438f2c54e6Sdanielk1977         piColMask = &(pTriggerStack->newColMask);
11444adee20fSdanielk1977       }else if( pTriggerStack->oldIdx != -1 && sqlite3StrICmp("old", zTab)==0 ){
11458141f61eSdrh         pExpr->iTable = pTriggerStack->oldIdx;
11468141f61eSdrh         assert( pTriggerStack->pTab );
11478141f61eSdrh         pTab = pTriggerStack->pTab;
11488f2c54e6Sdanielk1977         piColMask = &(pTriggerStack->oldColMask);
11498141f61eSdrh       }
11508141f61eSdrh 
11518141f61eSdrh       if( pTab ){
1152f0113000Sdanielk1977         int iCol;
11538141f61eSdrh         Column *pCol = pTab->aCol;
11548141f61eSdrh 
1155728b5779Sdrh         pSchema = pTab->pSchema;
11568141f61eSdrh         cntTab++;
1157f0113000Sdanielk1977         for(iCol=0; iCol < pTab->nCol; iCol++, pCol++) {
11584adee20fSdanielk1977           if( sqlite3StrICmp(pCol->zName, zCol)==0 ){
1159f0113000Sdanielk1977             const char *zColl = pTab->aCol[iCol].zColl;
11608141f61eSdrh             cnt++;
1161f0113000Sdanielk1977             pExpr->iColumn = iCol==pTab->iPKey ? -1 : iCol;
1162f0113000Sdanielk1977             pExpr->affinity = pTab->aCol[iCol].affinity;
11638b4c40d8Sdrh             if( (pExpr->flags & EP_ExpCollate)==0 ){
1164b3bf556eSdanielk1977               pExpr->pColl = sqlite3FindCollSeq(db, ENC(db), zColl,-1, 0);
11658b4c40d8Sdrh             }
1166aee18ef8Sdanielk1977             pExpr->pTab = pTab;
11678f2c54e6Sdanielk1977             if( iCol>=0 ){
11688f2c54e6Sdanielk1977               *piColMask |= ((u32)1<<iCol) | (iCol>=32?0xffffffff:0);
11698f2c54e6Sdanielk1977             }
11708141f61eSdrh             break;
11718141f61eSdrh           }
11728141f61eSdrh         }
11738141f61eSdrh       }
11748141f61eSdrh     }
1175b7f9164eSdrh #endif /* !defined(SQLITE_OMIT_TRIGGER) */
11768141f61eSdrh 
11778141f61eSdrh     /*
11788141f61eSdrh     ** Perhaps the name is a reference to the ROWID
11798141f61eSdrh     */
11804adee20fSdanielk1977     if( cnt==0 && cntTab==1 && sqlite3IsRowid(zCol) ){
11818141f61eSdrh       cnt = 1;
11828141f61eSdrh       pExpr->iColumn = -1;
11838a51256cSdrh       pExpr->affinity = SQLITE_AFF_INTEGER;
11848141f61eSdrh     }
11858141f61eSdrh 
11868141f61eSdrh     /*
11878141f61eSdrh     ** If the input is of the form Z (not Y.Z or X.Y.Z) then the name Z
11888141f61eSdrh     ** might refer to an result-set alias.  This happens, for example, when
11898141f61eSdrh     ** we are resolving names in the WHERE clause of the following command:
11908141f61eSdrh     **
11918141f61eSdrh     **     SELECT a+b AS x FROM table WHERE x<10;
11928141f61eSdrh     **
11938141f61eSdrh     ** In cases like this, replace pExpr with a copy of the expression that
11948141f61eSdrh     ** forms the result set entry ("a+b" in the example) and return immediately.
11958141f61eSdrh     ** Note that the expression in the result set should have already been
11968141f61eSdrh     ** resolved by the time the WHERE clause is resolved.
11978141f61eSdrh     */
1198ffe07b2dSdrh     if( cnt==0 && (pEList = pNC->pEList)!=0 && zTab==0 ){
11998141f61eSdrh       for(j=0; j<pEList->nExpr; j++){
12008141f61eSdrh         char *zAs = pEList->a[j].zName;
12014adee20fSdanielk1977         if( zAs!=0 && sqlite3StrICmp(zAs, zCol)==0 ){
120236379e97Sdrh           Expr *pDup, *pOrig;
12038141f61eSdrh           assert( pExpr->pLeft==0 && pExpr->pRight==0 );
12044f07e5fbSdrh           assert( pExpr->pList==0 );
12054f07e5fbSdrh           assert( pExpr->pSelect==0 );
120636379e97Sdrh           pOrig = pEList->a[j].pExpr;
120736379e97Sdrh           if( !pNC->allowAgg && ExprHasProperty(pOrig, EP_Agg) ){
120836379e97Sdrh             sqlite3ErrorMsg(pParse, "misuse of aliased aggregate %s", zAs);
120917435752Sdrh             sqlite3_free(zCol);
121036379e97Sdrh             return 2;
121136379e97Sdrh           }
12121e536953Sdanielk1977           pDup = sqlite3ExprDup(db, pOrig);
12134f07e5fbSdrh           if( pExpr->flags & EP_ExpCollate ){
12144f07e5fbSdrh             pDup->pColl = pExpr->pColl;
12154f07e5fbSdrh             pDup->flags |= EP_ExpCollate;
12164f07e5fbSdrh           }
121717435752Sdrh           if( pExpr->span.dyn ) sqlite3_free((char*)pExpr->span.z);
121817435752Sdrh           if( pExpr->token.dyn ) sqlite3_free((char*)pExpr->token.z);
12194f07e5fbSdrh           memcpy(pExpr, pDup, sizeof(*pExpr));
122017435752Sdrh           sqlite3_free(pDup);
122115ccce1cSdrh           cnt = 1;
1222c9cf6e3dSdanielk1977           pMatch = 0;
12238141f61eSdrh           assert( zTab==0 && zDb==0 );
122415ccce1cSdrh           goto lookupname_end_2;
12258141f61eSdrh         }
12268141f61eSdrh       }
12278141f61eSdrh     }
12288141f61eSdrh 
1229626a879aSdrh     /* Advance to the next name context.  The loop will exit when either
1230626a879aSdrh     ** we have a match (cnt>0) or when we run out of name contexts.
1231626a879aSdrh     */
1232626a879aSdrh     if( cnt==0 ){
1233626a879aSdrh       pNC = pNC->pNext;
1234626a879aSdrh     }
1235626a879aSdrh   }
1236626a879aSdrh 
12378141f61eSdrh   /*
12388141f61eSdrh   ** If X and Y are NULL (in other words if only the column name Z is
12398141f61eSdrh   ** supplied) and the value of Z is enclosed in double-quotes, then
12408141f61eSdrh   ** Z is a string literal if it doesn't match any column names.  In that
12418141f61eSdrh   ** case, we need to return right away and not make any changes to
12428141f61eSdrh   ** pExpr.
124315ccce1cSdrh   **
124415ccce1cSdrh   ** Because no reference was made to outer contexts, the pNC->nRef
124515ccce1cSdrh   ** fields are not changed in any context.
12468141f61eSdrh   */
12478141f61eSdrh   if( cnt==0 && zTab==0 && pColumnToken->z[0]=='"' ){
124817435752Sdrh     sqlite3_free(zCol);
12498141f61eSdrh     return 0;
12508141f61eSdrh   }
12518141f61eSdrh 
12528141f61eSdrh   /*
12538141f61eSdrh   ** cnt==0 means there was not match.  cnt>1 means there were two or
12548141f61eSdrh   ** more matches.  Either way, we have an error.
12558141f61eSdrh   */
12568141f61eSdrh   if( cnt!=1 ){
1257de4fcfddSdrh     const char *zErr;
1258de4fcfddSdrh     zErr = cnt==0 ? "no such column" : "ambiguous column name";
12598141f61eSdrh     if( zDb ){
1260de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s.%s.%s", zErr, zDb, zTab, zCol);
12618141f61eSdrh     }else if( zTab ){
1262de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s.%s", zErr, zTab, zCol);
12638141f61eSdrh     }else{
1264de4fcfddSdrh       sqlite3ErrorMsg(pParse, "%s: %s", zErr, zCol);
12658141f61eSdrh     }
126673b211abSdrh     pTopNC->nErr++;
12678141f61eSdrh   }
12688141f61eSdrh 
126951669863Sdrh   /* If a column from a table in pSrcList is referenced, then record
127051669863Sdrh   ** this fact in the pSrcList.a[].colUsed bitmask.  Column 0 causes
127151669863Sdrh   ** bit 0 to be set.  Column 1 sets bit 1.  And so forth.  If the
127251669863Sdrh   ** column number is greater than the number of bits in the bitmask
127351669863Sdrh   ** then set the high-order bit of the bitmask.
127451669863Sdrh   */
127551669863Sdrh   if( pExpr->iColumn>=0 && pMatch!=0 ){
127651669863Sdrh     int n = pExpr->iColumn;
127751669863Sdrh     if( n>=sizeof(Bitmask)*8 ){
127851669863Sdrh       n = sizeof(Bitmask)*8-1;
127951669863Sdrh     }
128051669863Sdrh     assert( pMatch->iCursor==pExpr->iTable );
1281ca83ac51Sdrh     pMatch->colUsed |= ((Bitmask)1)<<n;
128251669863Sdrh   }
128351669863Sdrh 
1284d5d56523Sdanielk1977 lookupname_end:
12858141f61eSdrh   /* Clean up and return
12868141f61eSdrh   */
128717435752Sdrh   sqlite3_free(zDb);
128817435752Sdrh   sqlite3_free(zTab);
12894adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pLeft);
12908141f61eSdrh   pExpr->pLeft = 0;
12914adee20fSdanielk1977   sqlite3ExprDelete(pExpr->pRight);
12928141f61eSdrh   pExpr->pRight = 0;
12938141f61eSdrh   pExpr->op = TK_COLUMN;
129415ccce1cSdrh lookupname_end_2:
129517435752Sdrh   sqlite3_free(zCol);
1296626a879aSdrh   if( cnt==1 ){
1297b3bce662Sdanielk1977     assert( pNC!=0 );
1298728b5779Sdrh     sqlite3AuthRead(pParse, pExpr, pSchema, pNC->pSrcList);
1299aee18ef8Sdanielk1977     if( pMatch && !pMatch->pSelect ){
1300aee18ef8Sdanielk1977       pExpr->pTab = pMatch->pTab;
1301aee18ef8Sdanielk1977     }
130215ccce1cSdrh     /* Increment the nRef value on all name contexts from TopNC up to
130315ccce1cSdrh     ** the point where the name matched. */
130415ccce1cSdrh     for(;;){
130515ccce1cSdrh       assert( pTopNC!=0 );
130615ccce1cSdrh       pTopNC->nRef++;
130715ccce1cSdrh       if( pTopNC==pNC ) break;
130815ccce1cSdrh       pTopNC = pTopNC->pNext;
1309626a879aSdrh     }
131015ccce1cSdrh     return 0;
131115ccce1cSdrh   } else {
131215ccce1cSdrh     return 1;
131315ccce1cSdrh   }
13148141f61eSdrh }
13158141f61eSdrh 
13168141f61eSdrh /*
1317626a879aSdrh ** This routine is designed as an xFunc for walkExprTree().
1318626a879aSdrh **
131973b211abSdrh ** Resolve symbolic names into TK_COLUMN operators for the current
1320626a879aSdrh ** node in the expression tree.  Return 0 to continue the search down
132173b211abSdrh ** the tree or 2 to abort the tree walk.
132273b211abSdrh **
132373b211abSdrh ** This routine also does error checking and name resolution for
132473b211abSdrh ** function names.  The operator for aggregate functions is changed
132573b211abSdrh ** to TK_AGG_FUNCTION.
1326626a879aSdrh */
1327626a879aSdrh static int nameResolverStep(void *pArg, Expr *pExpr){
1328626a879aSdrh   NameContext *pNC = (NameContext*)pArg;
1329626a879aSdrh   Parse *pParse;
1330626a879aSdrh 
1331b3bce662Sdanielk1977   if( pExpr==0 ) return 1;
1332626a879aSdrh   assert( pNC!=0 );
1333626a879aSdrh   pParse = pNC->pParse;
1334b3bce662Sdanielk1977 
1335626a879aSdrh   if( ExprHasAnyProperty(pExpr, EP_Resolved) ) return 1;
1336626a879aSdrh   ExprSetProperty(pExpr, EP_Resolved);
1337626a879aSdrh #ifndef NDEBUG
1338f0113000Sdanielk1977   if( pNC->pSrcList && pNC->pSrcList->nAlloc>0 ){
1339f0113000Sdanielk1977     SrcList *pSrcList = pNC->pSrcList;
1340940fac9dSdanielk1977     int i;
1341f0113000Sdanielk1977     for(i=0; i<pNC->pSrcList->nSrc; i++){
1342626a879aSdrh       assert( pSrcList->a[i].iCursor>=0 && pSrcList->a[i].iCursor<pParse->nTab);
1343626a879aSdrh     }
1344626a879aSdrh   }
1345626a879aSdrh #endif
1346626a879aSdrh   switch( pExpr->op ){
1347626a879aSdrh     /* Double-quoted strings (ex: "abc") are used as identifiers if
1348626a879aSdrh     ** possible.  Otherwise they remain as strings.  Single-quoted
1349626a879aSdrh     ** strings (ex: 'abc') are always string literals.
1350626a879aSdrh     */
1351626a879aSdrh     case TK_STRING: {
1352626a879aSdrh       if( pExpr->token.z[0]=='\'' ) break;
1353626a879aSdrh       /* Fall thru into the TK_ID case if this is a double-quoted string */
1354626a879aSdrh     }
1355626a879aSdrh     /* A lone identifier is the name of a column.
1356626a879aSdrh     */
1357626a879aSdrh     case TK_ID: {
1358626a879aSdrh       lookupName(pParse, 0, 0, &pExpr->token, pNC, pExpr);
1359626a879aSdrh       return 1;
1360626a879aSdrh     }
1361626a879aSdrh 
1362626a879aSdrh     /* A table name and column name:     ID.ID
1363626a879aSdrh     ** Or a database, table and column:  ID.ID.ID
1364626a879aSdrh     */
1365626a879aSdrh     case TK_DOT: {
1366626a879aSdrh       Token *pColumn;
1367626a879aSdrh       Token *pTable;
1368626a879aSdrh       Token *pDb;
1369626a879aSdrh       Expr *pRight;
1370626a879aSdrh 
1371b3bce662Sdanielk1977       /* if( pSrcList==0 ) break; */
1372626a879aSdrh       pRight = pExpr->pRight;
1373626a879aSdrh       if( pRight->op==TK_ID ){
1374626a879aSdrh         pDb = 0;
1375626a879aSdrh         pTable = &pExpr->pLeft->token;
1376626a879aSdrh         pColumn = &pRight->token;
1377626a879aSdrh       }else{
1378626a879aSdrh         assert( pRight->op==TK_DOT );
1379626a879aSdrh         pDb = &pExpr->pLeft->token;
1380626a879aSdrh         pTable = &pRight->pLeft->token;
1381626a879aSdrh         pColumn = &pRight->pRight->token;
1382626a879aSdrh       }
1383626a879aSdrh       lookupName(pParse, pDb, pTable, pColumn, pNC, pExpr);
1384626a879aSdrh       return 1;
1385626a879aSdrh     }
1386626a879aSdrh 
1387626a879aSdrh     /* Resolve function names
1388626a879aSdrh     */
1389b71090fdSdrh     case TK_CONST_FUNC:
1390626a879aSdrh     case TK_FUNCTION: {
1391626a879aSdrh       ExprList *pList = pExpr->pList;    /* The argument list */
1392626a879aSdrh       int n = pList ? pList->nExpr : 0;  /* Number of arguments */
1393626a879aSdrh       int no_such_func = 0;       /* True if no such function exists */
1394626a879aSdrh       int wrong_num_args = 0;     /* True if wrong number of arguments */
1395626a879aSdrh       int is_agg = 0;             /* True if is an aggregate function */
1396626a879aSdrh       int i;
13975169bbc6Sdrh       int auth;                   /* Authorization to use the function */
1398626a879aSdrh       int nId;                    /* Number of characters in function name */
1399626a879aSdrh       const char *zId;            /* The function name. */
140073b211abSdrh       FuncDef *pDef;              /* Information about the function */
140114db2665Sdanielk1977       int enc = ENC(pParse->db);  /* The database encoding */
1402626a879aSdrh 
14032646da7eSdrh       zId = (char*)pExpr->token.z;
1404b71090fdSdrh       nId = pExpr->token.n;
1405626a879aSdrh       pDef = sqlite3FindFunction(pParse->db, zId, nId, n, enc, 0);
1406626a879aSdrh       if( pDef==0 ){
1407626a879aSdrh         pDef = sqlite3FindFunction(pParse->db, zId, nId, -1, enc, 0);
1408626a879aSdrh         if( pDef==0 ){
1409626a879aSdrh           no_such_func = 1;
1410626a879aSdrh         }else{
1411626a879aSdrh           wrong_num_args = 1;
1412626a879aSdrh         }
1413626a879aSdrh       }else{
1414626a879aSdrh         is_agg = pDef->xFunc==0;
1415626a879aSdrh       }
14162fca7fefSdrh #ifndef SQLITE_OMIT_AUTHORIZATION
14175169bbc6Sdrh       if( pDef ){
14185169bbc6Sdrh         auth = sqlite3AuthCheck(pParse, SQLITE_FUNCTION, 0, pDef->zName, 0);
14195169bbc6Sdrh         if( auth!=SQLITE_OK ){
14205169bbc6Sdrh           if( auth==SQLITE_DENY ){
14215169bbc6Sdrh             sqlite3ErrorMsg(pParse, "not authorized to use function: %s",
14225169bbc6Sdrh                                     pDef->zName);
14235169bbc6Sdrh             pNC->nErr++;
14245169bbc6Sdrh           }
14255169bbc6Sdrh           pExpr->op = TK_NULL;
14265169bbc6Sdrh           return 1;
14275169bbc6Sdrh         }
14285169bbc6Sdrh       }
1429b8b14219Sdrh #endif
1430626a879aSdrh       if( is_agg && !pNC->allowAgg ){
1431626a879aSdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate function %.*s()", nId,zId);
1432626a879aSdrh         pNC->nErr++;
1433626a879aSdrh         is_agg = 0;
1434626a879aSdrh       }else if( no_such_func ){
1435626a879aSdrh         sqlite3ErrorMsg(pParse, "no such function: %.*s", nId, zId);
1436626a879aSdrh         pNC->nErr++;
1437626a879aSdrh       }else if( wrong_num_args ){
1438626a879aSdrh         sqlite3ErrorMsg(pParse,"wrong number of arguments to function %.*s()",
1439626a879aSdrh              nId, zId);
1440626a879aSdrh         pNC->nErr++;
1441626a879aSdrh       }
1442626a879aSdrh       if( is_agg ){
1443626a879aSdrh         pExpr->op = TK_AGG_FUNCTION;
1444626a879aSdrh         pNC->hasAgg = 1;
1445626a879aSdrh       }
144673b211abSdrh       if( is_agg ) pNC->allowAgg = 0;
1447626a879aSdrh       for(i=0; pNC->nErr==0 && i<n; i++){
144873b211abSdrh         walkExprTree(pList->a[i].pExpr, nameResolverStep, pNC);
1449626a879aSdrh       }
145073b211abSdrh       if( is_agg ) pNC->allowAgg = 1;
1451626a879aSdrh       /* FIX ME:  Compute pExpr->affinity based on the expected return
1452626a879aSdrh       ** type of the function
1453626a879aSdrh       */
1454626a879aSdrh       return is_agg;
1455626a879aSdrh     }
1456b3bce662Sdanielk1977 #ifndef SQLITE_OMIT_SUBQUERY
1457b3bce662Sdanielk1977     case TK_SELECT:
1458b3bce662Sdanielk1977     case TK_EXISTS:
1459b3bce662Sdanielk1977 #endif
1460b3bce662Sdanielk1977     case TK_IN: {
1461b3bce662Sdanielk1977       if( pExpr->pSelect ){
14628a9f38feSdrh         int nRef = pNC->nRef;
146306f6541eSdrh #ifndef SQLITE_OMIT_CHECK
146406f6541eSdrh         if( pNC->isCheck ){
146506f6541eSdrh           sqlite3ErrorMsg(pParse,"subqueries prohibited in CHECK constraints");
146606f6541eSdrh         }
146706f6541eSdrh #endif
1468b3bce662Sdanielk1977         sqlite3SelectResolve(pParse, pExpr->pSelect, pNC);
1469b3bce662Sdanielk1977         assert( pNC->nRef>=nRef );
1470b3bce662Sdanielk1977         if( nRef!=pNC->nRef ){
1471b3bce662Sdanielk1977           ExprSetProperty(pExpr, EP_VarSelect);
1472b3bce662Sdanielk1977         }
1473b3bce662Sdanielk1977       }
14744284fb07Sdrh       break;
1475b3bce662Sdanielk1977     }
14764284fb07Sdrh #ifndef SQLITE_OMIT_CHECK
14774284fb07Sdrh     case TK_VARIABLE: {
14784284fb07Sdrh       if( pNC->isCheck ){
14794284fb07Sdrh         sqlite3ErrorMsg(pParse,"parameters prohibited in CHECK constraints");
14804284fb07Sdrh       }
14814284fb07Sdrh       break;
14824284fb07Sdrh     }
14834284fb07Sdrh #endif
1484626a879aSdrh   }
1485626a879aSdrh   return 0;
1486626a879aSdrh }
1487626a879aSdrh 
1488626a879aSdrh /*
1489cce7d176Sdrh ** This routine walks an expression tree and resolves references to
1490967e8b73Sdrh ** table columns.  Nodes of the form ID.ID or ID resolve into an
1491aacc543eSdrh ** index to the table in the table list and a column offset.  The
1492aacc543eSdrh ** Expr.opcode for such nodes is changed to TK_COLUMN.  The Expr.iTable
1493aacc543eSdrh ** value is changed to the index of the referenced table in pTabList
1494832508b7Sdrh ** plus the "base" value.  The base value will ultimately become the
1495aacc543eSdrh ** VDBE cursor number for a cursor that is pointing into the referenced
1496aacc543eSdrh ** table.  The Expr.iColumn value is changed to the index of the column
1497aacc543eSdrh ** of the referenced table.  The Expr.iColumn value for the special
1498aacc543eSdrh ** ROWID column is -1.  Any INTEGER PRIMARY KEY column is tried as an
1499aacc543eSdrh ** alias for ROWID.
150019a775c2Sdrh **
1501626a879aSdrh ** Also resolve function names and check the functions for proper
1502626a879aSdrh ** usage.  Make sure all function names are recognized and all functions
1503626a879aSdrh ** have the correct number of arguments.  Leave an error message
1504626a879aSdrh ** in pParse->zErrMsg if anything is amiss.  Return the number of errors.
1505626a879aSdrh **
150673b211abSdrh ** If the expression contains aggregate functions then set the EP_Agg
150773b211abSdrh ** property on the expression.
1508626a879aSdrh */
1509626a879aSdrh int sqlite3ExprResolveNames(
1510b3bce662Sdanielk1977   NameContext *pNC,       /* Namespace to resolve expressions in. */
1511b3bce662Sdanielk1977   Expr *pExpr             /* The expression to be analyzed. */
1512626a879aSdrh ){
151313449892Sdrh   int savedHasAgg;
1514bb4957f8Sdrh 
151573b211abSdrh   if( pExpr==0 ) return 0;
1516bb4957f8Sdrh #if SQLITE_MAX_EXPR_DEPTH>0
1517bb4957f8Sdrh   {
1518bb4957f8Sdrh     int mxDepth = pNC->pParse->db->aLimit[SQLITE_LIMIT_EXPR_DEPTH];
1519bb4957f8Sdrh     if( (pExpr->nHeight+pNC->pParse->nHeight)>mxDepth ){
1520fc976065Sdanielk1977       sqlite3ErrorMsg(pNC->pParse,
1521bb4957f8Sdrh          "Expression tree is too large (maximum depth %d)", mxDepth
1522fc976065Sdanielk1977       );
1523fc976065Sdanielk1977       return 1;
1524fc976065Sdanielk1977     }
1525fc976065Sdanielk1977     pNC->pParse->nHeight += pExpr->nHeight;
1526bb4957f8Sdrh   }
1527fc976065Sdanielk1977 #endif
152813449892Sdrh   savedHasAgg = pNC->hasAgg;
152913449892Sdrh   pNC->hasAgg = 0;
1530b3bce662Sdanielk1977   walkExprTree(pExpr, nameResolverStep, pNC);
1531bb4957f8Sdrh #if SQLITE_MAX_EXPR_DEPTH>0
1532fc976065Sdanielk1977   pNC->pParse->nHeight -= pExpr->nHeight;
1533fc976065Sdanielk1977 #endif
1534b3bce662Sdanielk1977   if( pNC->nErr>0 ){
153573b211abSdrh     ExprSetProperty(pExpr, EP_Error);
153673b211abSdrh   }
153713449892Sdrh   if( pNC->hasAgg ){
153813449892Sdrh     ExprSetProperty(pExpr, EP_Agg);
153913449892Sdrh   }else if( savedHasAgg ){
154013449892Sdrh     pNC->hasAgg = 1;
154113449892Sdrh   }
154273b211abSdrh   return ExprHasProperty(pExpr, EP_Error);
1543626a879aSdrh }
1544626a879aSdrh 
15451398ad36Sdrh /*
15461398ad36Sdrh ** A pointer instance of this structure is used to pass information
15471398ad36Sdrh ** through walkExprTree into codeSubqueryStep().
15481398ad36Sdrh */
15491398ad36Sdrh typedef struct QueryCoder QueryCoder;
15501398ad36Sdrh struct QueryCoder {
15511398ad36Sdrh   Parse *pParse;       /* The parsing context */
15521398ad36Sdrh   NameContext *pNC;    /* Namespace of first enclosing query */
15531398ad36Sdrh };
15541398ad36Sdrh 
15559a96b668Sdanielk1977 #ifdef SQLITE_TEST
15569a96b668Sdanielk1977   int sqlite3_enable_in_opt = 1;
15579a96b668Sdanielk1977 #else
15589a96b668Sdanielk1977   #define sqlite3_enable_in_opt 1
15599a96b668Sdanielk1977 #endif
15609a96b668Sdanielk1977 
15619a96b668Sdanielk1977 /*
15629a96b668Sdanielk1977 ** This function is used by the implementation of the IN (...) operator.
15639a96b668Sdanielk1977 ** It's job is to find or create a b-tree structure that may be used
15649a96b668Sdanielk1977 ** either to test for membership of the (...) set or to iterate through
156585b623f2Sdrh ** its members, skipping duplicates.
15669a96b668Sdanielk1977 **
15679a96b668Sdanielk1977 ** The cursor opened on the structure (database table, database index
15689a96b668Sdanielk1977 ** or ephermal table) is stored in pX->iTable before this function returns.
15699a96b668Sdanielk1977 ** The returned value indicates the structure type, as follows:
15709a96b668Sdanielk1977 **
15719a96b668Sdanielk1977 **   IN_INDEX_ROWID - The cursor was opened on a database table.
15722d401ab8Sdrh **   IN_INDEX_INDEX - The cursor was opened on a database index.
15739a96b668Sdanielk1977 **   IN_INDEX_EPH -   The cursor was opened on a specially created and
15749a96b668Sdanielk1977 **                    populated epheremal table.
15759a96b668Sdanielk1977 **
15769a96b668Sdanielk1977 ** An existing structure may only be used if the SELECT is of the simple
15779a96b668Sdanielk1977 ** form:
15789a96b668Sdanielk1977 **
15799a96b668Sdanielk1977 **     SELECT <column> FROM <table>
15809a96b668Sdanielk1977 **
15819a96b668Sdanielk1977 ** If the mustBeUnique parameter is false, the structure will be used
15829a96b668Sdanielk1977 ** for fast set membership tests. In this case an epheremal table must
15839a96b668Sdanielk1977 ** be used unless <column> is an INTEGER PRIMARY KEY or an index can
158485b623f2Sdrh ** be found with <column> as its left-most column.
15859a96b668Sdanielk1977 **
15869a96b668Sdanielk1977 ** If mustBeUnique is true, then the structure will be used to iterate
15879a96b668Sdanielk1977 ** through the set members, skipping any duplicates. In this case an
15889a96b668Sdanielk1977 ** epheremal table must be used unless the selected <column> is guaranteed
15899a96b668Sdanielk1977 ** to be unique - either because it is an INTEGER PRIMARY KEY or it
15909a96b668Sdanielk1977 ** is unique by virtue of a constraint or implicit index.
15919a96b668Sdanielk1977 */
1592284f4acaSdanielk1977 #ifndef SQLITE_OMIT_SUBQUERY
15939a96b668Sdanielk1977 int sqlite3FindInIndex(Parse *pParse, Expr *pX, int mustBeUnique){
15949a96b668Sdanielk1977   Select *p;
15959a96b668Sdanielk1977   int eType = 0;
15969a96b668Sdanielk1977   int iTab = pParse->nTab++;
15979a96b668Sdanielk1977 
15989a96b668Sdanielk1977   /* The follwing if(...) expression is true if the SELECT is of the
15999a96b668Sdanielk1977   ** simple form:
16009a96b668Sdanielk1977   **
16019a96b668Sdanielk1977   **     SELECT <column> FROM <table>
16029a96b668Sdanielk1977   **
16039a96b668Sdanielk1977   ** If this is the case, it may be possible to use an existing table
16049a96b668Sdanielk1977   ** or index instead of generating an epheremal table.
16059a96b668Sdanielk1977   */
16069a96b668Sdanielk1977   if( sqlite3_enable_in_opt
1607c81945e4Sdrh    && (p=pX->pSelect)!=0 && !p->pPrior
16089a96b668Sdanielk1977    && !p->isDistinct && !p->isAgg && !p->pGroupBy
16099a96b668Sdanielk1977    && p->pSrc && p->pSrc->nSrc==1 && !p->pSrc->a[0].pSelect
1610b2b95d41Sdanielk1977    && p->pSrc->a[0].pTab && !p->pSrc->a[0].pTab->pSelect
16119a96b668Sdanielk1977    && p->pEList->nExpr==1 && p->pEList->a[0].pExpr->op==TK_COLUMN
16129a96b668Sdanielk1977    && !p->pLimit && !p->pOffset && !p->pWhere
16139a96b668Sdanielk1977   ){
16149a96b668Sdanielk1977     sqlite3 *db = pParse->db;
16159a96b668Sdanielk1977     Index *pIdx;
16169a96b668Sdanielk1977     Expr *pExpr = p->pEList->a[0].pExpr;
16179a96b668Sdanielk1977     int iCol = pExpr->iColumn;
16189a96b668Sdanielk1977     Vdbe *v = sqlite3GetVdbe(pParse);
16199a96b668Sdanielk1977 
16209a96b668Sdanielk1977     /* This function is only called from two places. In both cases the vdbe
16219a96b668Sdanielk1977     ** has already been allocated. So assume sqlite3GetVdbe() is always
16229a96b668Sdanielk1977     ** successful here.
16239a96b668Sdanielk1977     */
16249a96b668Sdanielk1977     assert(v);
16259a96b668Sdanielk1977     if( iCol<0 ){
16260a07c107Sdrh       int iMem = ++pParse->nMem;
16279a96b668Sdanielk1977       int iAddr;
16289a96b668Sdanielk1977       Table *pTab = p->pSrc->a[0].pTab;
16299a96b668Sdanielk1977       int iDb = sqlite3SchemaToIndex(db, pTab->pSchema);
16309a96b668Sdanielk1977       sqlite3VdbeUsesBtree(v, iDb);
16319a96b668Sdanielk1977 
1632892d3179Sdrh       iAddr = sqlite3VdbeAddOp1(v, OP_If, iMem);
16334c583128Sdrh       sqlite3VdbeAddOp2(v, OP_Integer, 1, iMem);
16349a96b668Sdanielk1977 
16359a96b668Sdanielk1977       sqlite3OpenTable(pParse, iTab, iDb, pTab, OP_OpenRead);
16369a96b668Sdanielk1977       eType = IN_INDEX_ROWID;
16379a96b668Sdanielk1977 
16389a96b668Sdanielk1977       sqlite3VdbeJumpHere(v, iAddr);
16399a96b668Sdanielk1977     }else{
16409a96b668Sdanielk1977       /* The collation sequence used by the comparison. If an index is to
16419a96b668Sdanielk1977       ** be used in place of a temp-table, it must be ordered according
16429a96b668Sdanielk1977       ** to this collation sequence.
16439a96b668Sdanielk1977       */
16449a96b668Sdanielk1977       CollSeq *pReq = sqlite3BinaryCompareCollSeq(pParse, pX->pLeft, pExpr);
16459a96b668Sdanielk1977 
16469a96b668Sdanielk1977       /* Check that the affinity that will be used to perform the
16479a96b668Sdanielk1977       ** comparison is the same as the affinity of the column. If
16489a96b668Sdanielk1977       ** it is not, it is not possible to use any index.
16499a96b668Sdanielk1977       */
16509a96b668Sdanielk1977       Table *pTab = p->pSrc->a[0].pTab;
16519a96b668Sdanielk1977       char aff = comparisonAffinity(pX);
16529a96b668Sdanielk1977       int affinity_ok = (pTab->aCol[iCol].affinity==aff||aff==SQLITE_AFF_NONE);
16539a96b668Sdanielk1977 
16549a96b668Sdanielk1977       for(pIdx=pTab->pIndex; pIdx && eType==0 && affinity_ok; pIdx=pIdx->pNext){
16559a96b668Sdanielk1977         if( (pIdx->aiColumn[0]==iCol)
16569a96b668Sdanielk1977          && (pReq==sqlite3FindCollSeq(db, ENC(db), pIdx->azColl[0], -1, 0))
16579a96b668Sdanielk1977          && (!mustBeUnique || (pIdx->nColumn==1 && pIdx->onError!=OE_None))
16589a96b668Sdanielk1977         ){
16599a96b668Sdanielk1977           int iDb;
16600a07c107Sdrh           int iMem = ++pParse->nMem;
16619a96b668Sdanielk1977           int iAddr;
16629a96b668Sdanielk1977           char *pKey;
16639a96b668Sdanielk1977 
16649a96b668Sdanielk1977           pKey = (char *)sqlite3IndexKeyinfo(pParse, pIdx);
16659a96b668Sdanielk1977           iDb = sqlite3SchemaToIndex(db, pIdx->pSchema);
16669a96b668Sdanielk1977           sqlite3VdbeUsesBtree(v, iDb);
16679a96b668Sdanielk1977 
1668892d3179Sdrh           iAddr = sqlite3VdbeAddOp1(v, OP_If, iMem);
16694c583128Sdrh           sqlite3VdbeAddOp2(v, OP_Integer, 1, iMem);
16709a96b668Sdanielk1977 
1671cd3e8f7cSdanielk1977           sqlite3VdbeAddOp2(v, OP_SetNumColumns, 0, pIdx->nColumn);
1672207872a4Sdanielk1977           sqlite3VdbeAddOp4(v, OP_OpenRead, iTab, pIdx->tnum, iDb,
167366a5167bSdrh                                pKey,P4_KEYINFO_HANDOFF);
1674207872a4Sdanielk1977           VdbeComment((v, "%s", pIdx->zName));
16759a96b668Sdanielk1977           eType = IN_INDEX_INDEX;
16769a96b668Sdanielk1977 
16779a96b668Sdanielk1977           sqlite3VdbeJumpHere(v, iAddr);
16789a96b668Sdanielk1977         }
16799a96b668Sdanielk1977       }
16809a96b668Sdanielk1977     }
16819a96b668Sdanielk1977   }
16829a96b668Sdanielk1977 
16839a96b668Sdanielk1977   if( eType==0 ){
16849a96b668Sdanielk1977     sqlite3CodeSubselect(pParse, pX);
16859a96b668Sdanielk1977     eType = IN_INDEX_EPH;
16869a96b668Sdanielk1977   }else{
16879a96b668Sdanielk1977     pX->iTable = iTab;
16889a96b668Sdanielk1977   }
16899a96b668Sdanielk1977   return eType;
16909a96b668Sdanielk1977 }
1691284f4acaSdanielk1977 #endif
1692626a879aSdrh 
1693626a879aSdrh /*
16949cbe6352Sdrh ** Generate code for scalar subqueries used as an expression
16959cbe6352Sdrh ** and IN operators.  Examples:
1696626a879aSdrh **
16979cbe6352Sdrh **     (SELECT a FROM b)          -- subquery
16989cbe6352Sdrh **     EXISTS (SELECT a FROM b)   -- EXISTS subquery
16999cbe6352Sdrh **     x IN (4,5,11)              -- IN operator with list on right-hand side
17009cbe6352Sdrh **     x IN (SELECT a FROM b)     -- IN operator with subquery on the right
1701fef5208cSdrh **
17029cbe6352Sdrh ** The pExpr parameter describes the expression that contains the IN
17039cbe6352Sdrh ** operator or subquery.
1704cce7d176Sdrh */
170551522cd3Sdrh #ifndef SQLITE_OMIT_SUBQUERY
1706b3bce662Sdanielk1977 void sqlite3CodeSubselect(Parse *pParse, Expr *pExpr){
170757dbd7b3Sdrh   int testAddr = 0;                       /* One-time test address */
1708b3bce662Sdanielk1977   Vdbe *v = sqlite3GetVdbe(pParse);
1709b3bce662Sdanielk1977   if( v==0 ) return;
1710b3bce662Sdanielk1977 
1711fc976065Sdanielk1977 
171257dbd7b3Sdrh   /* This code must be run in its entirety every time it is encountered
171357dbd7b3Sdrh   ** if any of the following is true:
171457dbd7b3Sdrh   **
171557dbd7b3Sdrh   **    *  The right-hand side is a correlated subquery
171657dbd7b3Sdrh   **    *  The right-hand side is an expression list containing variables
171757dbd7b3Sdrh   **    *  We are inside a trigger
171857dbd7b3Sdrh   **
171957dbd7b3Sdrh   ** If all of the above are false, then we can run this code just once
172057dbd7b3Sdrh   ** save the results, and reuse the same result on subsequent invocations.
1721b3bce662Sdanielk1977   */
1722b3bce662Sdanielk1977   if( !ExprHasAnyProperty(pExpr, EP_VarSelect) && !pParse->trigStack ){
17230a07c107Sdrh     int mem = ++pParse->nMem;
1724892d3179Sdrh     sqlite3VdbeAddOp1(v, OP_If, mem);
1725892d3179Sdrh     testAddr = sqlite3VdbeAddOp2(v, OP_Integer, 1, mem);
172617435752Sdrh     assert( testAddr>0 || pParse->db->mallocFailed );
1727b3bce662Sdanielk1977   }
1728b3bce662Sdanielk1977 
1729cce7d176Sdrh   switch( pExpr->op ){
1730fef5208cSdrh     case TK_IN: {
1731e014a838Sdanielk1977       char affinity;
1732d3d39e93Sdrh       KeyInfo keyInfo;
1733b9bb7c18Sdrh       int addr;        /* Address of OP_OpenEphemeral instruction */
1734d3d39e93Sdrh 
1735bf3b721fSdanielk1977       affinity = sqlite3ExprAffinity(pExpr->pLeft);
1736e014a838Sdanielk1977 
1737e014a838Sdanielk1977       /* Whether this is an 'x IN(SELECT...)' or an 'x IN(<exprlist>)'
173857dbd7b3Sdrh       ** expression it is handled the same way. A virtual table is
1739e014a838Sdanielk1977       ** filled with single-field index keys representing the results
1740e014a838Sdanielk1977       ** from the SELECT or the <exprlist>.
1741fef5208cSdrh       **
1742e014a838Sdanielk1977       ** If the 'x' expression is a column value, or the SELECT...
1743e014a838Sdanielk1977       ** statement returns a column value, then the affinity of that
1744e014a838Sdanielk1977       ** column is used to build the index keys. If both 'x' and the
1745e014a838Sdanielk1977       ** SELECT... statement are columns, then numeric affinity is used
1746e014a838Sdanielk1977       ** if either column has NUMERIC or INTEGER affinity. If neither
1747e014a838Sdanielk1977       ** 'x' nor the SELECT... statement are columns, then numeric affinity
1748e014a838Sdanielk1977       ** is used.
1749fef5208cSdrh       */
1750832508b7Sdrh       pExpr->iTable = pParse->nTab++;
1751cd3e8f7cSdanielk1977       addr = sqlite3VdbeAddOp2(v, OP_OpenEphemeral, pExpr->iTable, 1);
1752d3d39e93Sdrh       memset(&keyInfo, 0, sizeof(keyInfo));
1753d3d39e93Sdrh       keyInfo.nField = 1;
1754e014a838Sdanielk1977 
1755e014a838Sdanielk1977       if( pExpr->pSelect ){
1756e014a838Sdanielk1977         /* Case 1:     expr IN (SELECT ...)
1757e014a838Sdanielk1977         **
1758e014a838Sdanielk1977         ** Generate code to write the results of the select into the temporary
1759e014a838Sdanielk1977         ** table allocated and opened above.
1760e014a838Sdanielk1977         */
17611013c932Sdrh         SelectDest dest;
1762be5c89acSdrh         ExprList *pEList;
17631013c932Sdrh 
17641013c932Sdrh         sqlite3SelectDestInit(&dest, SRT_Set, pExpr->iTable);
17651013c932Sdrh         dest.affinity = (int)affinity;
1766e014a838Sdanielk1977         assert( (pExpr->iTable&0x0000FFFF)==pExpr->iTable );
17676c8c8ce0Sdanielk1977         if( sqlite3Select(pParse, pExpr->pSelect, &dest, 0, 0, 0, 0) ){
176894ccde58Sdrh           return;
176994ccde58Sdrh         }
1770be5c89acSdrh         pEList = pExpr->pSelect->pEList;
1771be5c89acSdrh         if( pEList && pEList->nExpr>0 ){
1772bcbb04e5Sdanielk1977           keyInfo.aColl[0] = sqlite3BinaryCompareCollSeq(pParse, pExpr->pLeft,
1773be5c89acSdrh               pEList->a[0].pExpr);
17740202b29eSdanielk1977         }
1775fef5208cSdrh       }else if( pExpr->pList ){
1776fef5208cSdrh         /* Case 2:     expr IN (exprlist)
1777fef5208cSdrh         **
1778e014a838Sdanielk1977         ** For each expression, build an index key from the evaluation and
1779e014a838Sdanielk1977         ** store it in the temporary table. If <expr> is a column, then use
1780e014a838Sdanielk1977         ** that columns affinity when building index keys. If <expr> is not
1781e014a838Sdanielk1977         ** a column, use numeric affinity.
1782fef5208cSdrh         */
1783e014a838Sdanielk1977         int i;
178457dbd7b3Sdrh         ExprList *pList = pExpr->pList;
178557dbd7b3Sdrh         struct ExprList_item *pItem;
17862d401ab8Sdrh         int r1, r2;
178757dbd7b3Sdrh 
1788e014a838Sdanielk1977         if( !affinity ){
17898159a35fSdrh           affinity = SQLITE_AFF_NONE;
1790e014a838Sdanielk1977         }
17910202b29eSdanielk1977         keyInfo.aColl[0] = pExpr->pLeft->pColl;
1792e014a838Sdanielk1977 
1793e014a838Sdanielk1977         /* Loop through each expression in <exprlist>. */
17942d401ab8Sdrh         r1 = sqlite3GetTempReg(pParse);
17952d401ab8Sdrh         r2 = sqlite3GetTempReg(pParse);
179657dbd7b3Sdrh         for(i=pList->nExpr, pItem=pList->a; i>0; i--, pItem++){
179757dbd7b3Sdrh           Expr *pE2 = pItem->pExpr;
1798e014a838Sdanielk1977 
179957dbd7b3Sdrh           /* If the expression is not constant then we will need to
180057dbd7b3Sdrh           ** disable the test that was generated above that makes sure
180157dbd7b3Sdrh           ** this code only executes once.  Because for a non-constant
180257dbd7b3Sdrh           ** expression we need to rerun this code each time.
180357dbd7b3Sdrh           */
1804892d3179Sdrh           if( testAddr && !sqlite3ExprIsConstant(pE2) ){
1805892d3179Sdrh             sqlite3VdbeChangeToNoop(v, testAddr-1, 2);
180657dbd7b3Sdrh             testAddr = 0;
18074794b980Sdrh           }
1808e014a838Sdanielk1977 
1809e014a838Sdanielk1977           /* Evaluate the expression and insert it into the temp table */
1810e55cbd72Sdrh           pParse->disableColCache++;
18112d401ab8Sdrh           sqlite3ExprCode(pParse, pE2, r1);
1812e55cbd72Sdrh           pParse->disableColCache--;
18131db639ceSdrh           sqlite3VdbeAddOp4(v, OP_MakeRecord, r1, 1, r2, &affinity, 1);
1814*da250ea5Sdrh           sqlite3ExprCacheAffinityChange(pParse, r1, 1);
18152d401ab8Sdrh           sqlite3VdbeAddOp2(v, OP_IdxInsert, pExpr->iTable, r2);
1816fef5208cSdrh         }
18172d401ab8Sdrh         sqlite3ReleaseTempReg(pParse, r1);
18182d401ab8Sdrh         sqlite3ReleaseTempReg(pParse, r2);
1819fef5208cSdrh       }
182066a5167bSdrh       sqlite3VdbeChangeP4(v, addr, (void *)&keyInfo, P4_KEYINFO);
1821b3bce662Sdanielk1977       break;
1822fef5208cSdrh     }
1823fef5208cSdrh 
182451522cd3Sdrh     case TK_EXISTS:
182519a775c2Sdrh     case TK_SELECT: {
1826fef5208cSdrh       /* This has to be a scalar SELECT.  Generate code to put the
1827fef5208cSdrh       ** value of this select in a memory cell and record the number
1828967e8b73Sdrh       ** of the memory cell in iColumn.
1829fef5208cSdrh       */
18302646da7eSdrh       static const Token one = { (u8*)"1", 0, 1 };
183151522cd3Sdrh       Select *pSel;
18326c8c8ce0Sdanielk1977       SelectDest dest;
18331398ad36Sdrh 
183451522cd3Sdrh       pSel = pExpr->pSelect;
18351013c932Sdrh       sqlite3SelectDestInit(&dest, 0, ++pParse->nMem);
183651522cd3Sdrh       if( pExpr->op==TK_SELECT ){
18376c8c8ce0Sdanielk1977         dest.eDest = SRT_Mem;
18384c583128Sdrh         sqlite3VdbeAddOp2(v, OP_Null, 0, dest.iParm);
1839d4e70ebdSdrh         VdbeComment((v, "Init subquery result"));
184051522cd3Sdrh       }else{
18416c8c8ce0Sdanielk1977         dest.eDest = SRT_Exists;
18424c583128Sdrh         sqlite3VdbeAddOp2(v, OP_Integer, 0, dest.iParm);
1843d4e70ebdSdrh         VdbeComment((v, "Init EXISTS result"));
184451522cd3Sdrh       }
1845ec7429aeSdrh       sqlite3ExprDelete(pSel->pLimit);
1846a1644fd8Sdanielk1977       pSel->pLimit = sqlite3PExpr(pParse, TK_INTEGER, 0, 0, &one);
18476c8c8ce0Sdanielk1977       if( sqlite3Select(pParse, pSel, &dest, 0, 0, 0, 0) ){
184894ccde58Sdrh         return;
184994ccde58Sdrh       }
18506c8c8ce0Sdanielk1977       pExpr->iColumn = dest.iParm;
1851b3bce662Sdanielk1977       break;
185219a775c2Sdrh     }
1853cce7d176Sdrh   }
1854b3bce662Sdanielk1977 
185557dbd7b3Sdrh   if( testAddr ){
1856892d3179Sdrh     sqlite3VdbeJumpHere(v, testAddr-1);
1857b3bce662Sdanielk1977   }
1858fc976065Sdanielk1977 
1859b3bce662Sdanielk1977   return;
1860cce7d176Sdrh }
186151522cd3Sdrh #endif /* SQLITE_OMIT_SUBQUERY */
1862cce7d176Sdrh 
1863cce7d176Sdrh /*
1864598f1340Sdrh ** Duplicate an 8-byte value
1865598f1340Sdrh */
1866598f1340Sdrh static char *dup8bytes(Vdbe *v, const char *in){
1867598f1340Sdrh   char *out = sqlite3DbMallocRaw(sqlite3VdbeDb(v), 8);
1868598f1340Sdrh   if( out ){
1869598f1340Sdrh     memcpy(out, in, 8);
1870598f1340Sdrh   }
1871598f1340Sdrh   return out;
1872598f1340Sdrh }
1873598f1340Sdrh 
1874598f1340Sdrh /*
1875598f1340Sdrh ** Generate an instruction that will put the floating point
18769cbf3425Sdrh ** value described by z[0..n-1] into register iMem.
18770cf19ed8Sdrh **
18780cf19ed8Sdrh ** The z[] string will probably not be zero-terminated.  But the
18790cf19ed8Sdrh ** z[n] character is guaranteed to be something that does not look
18800cf19ed8Sdrh ** like the continuation of the number.
1881598f1340Sdrh */
18829de221dfSdrh static void codeReal(Vdbe *v, const char *z, int n, int negateFlag, int iMem){
1883598f1340Sdrh   assert( z || v==0 || sqlite3VdbeDb(v)->mallocFailed );
1884598f1340Sdrh   if( z ){
1885598f1340Sdrh     double value;
1886598f1340Sdrh     char *zV;
18870cf19ed8Sdrh     assert( !isdigit(z[n]) );
1888598f1340Sdrh     sqlite3AtoF(z, &value);
1889598f1340Sdrh     if( negateFlag ) value = -value;
1890598f1340Sdrh     zV = dup8bytes(v, (char*)&value);
18919de221dfSdrh     sqlite3VdbeAddOp4(v, OP_Real, 0, iMem, 0, zV, P4_REAL);
1892598f1340Sdrh   }
1893598f1340Sdrh }
1894598f1340Sdrh 
1895598f1340Sdrh 
1896598f1340Sdrh /*
1897fec19aadSdrh ** Generate an instruction that will put the integer describe by
18989cbf3425Sdrh ** text z[0..n-1] into register iMem.
18990cf19ed8Sdrh **
19000cf19ed8Sdrh ** The z[] string will probably not be zero-terminated.  But the
19010cf19ed8Sdrh ** z[n] character is guaranteed to be something that does not look
19020cf19ed8Sdrh ** like the continuation of the number.
1903fec19aadSdrh */
19049de221dfSdrh static void codeInteger(Vdbe *v, const char *z, int n, int negFlag, int iMem){
1905abb6fcabSdrh   assert( z || v==0 || sqlite3VdbeDb(v)->mallocFailed );
1906c9cf901dSdanielk1977   if( z ){
1907fec19aadSdrh     int i;
19080cf19ed8Sdrh     assert( !isdigit(z[n]) );
19096fec0762Sdrh     if( sqlite3GetInt32(z, &i) ){
19109de221dfSdrh       if( negFlag ) i = -i;
19119de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Integer, i, iMem);
19129de221dfSdrh     }else if( sqlite3FitsIn64Bits(z, negFlag) ){
1913598f1340Sdrh       i64 value;
1914598f1340Sdrh       char *zV;
1915598f1340Sdrh       sqlite3Atoi64(z, &value);
19169de221dfSdrh       if( negFlag ) value = -value;
1917598f1340Sdrh       zV = dup8bytes(v, (char*)&value);
19189de221dfSdrh       sqlite3VdbeAddOp4(v, OP_Int64, 0, iMem, 0, zV, P4_INT64);
1919fec19aadSdrh     }else{
19209de221dfSdrh       codeReal(v, z, n, negFlag, iMem);
1921fec19aadSdrh     }
1922fec19aadSdrh   }
1923c9cf901dSdanielk1977 }
1924fec19aadSdrh 
1925945498f3Sdrh 
1926945498f3Sdrh /*
1927945498f3Sdrh ** Generate code that will extract the iColumn-th column from
1928e55cbd72Sdrh ** table pTab and store the column value in a register.  An effort
1929e55cbd72Sdrh ** is made to store the column value in register iReg, but this is
1930e55cbd72Sdrh ** not guaranteed.  The location of the column value is returned.
1931e55cbd72Sdrh **
1932e55cbd72Sdrh ** There must be an open cursor to pTab in iTable when this routine
1933e55cbd72Sdrh ** is called.  If iColumn<0 then code is generated that extracts the rowid.
1934*da250ea5Sdrh **
1935*da250ea5Sdrh ** This routine might attempt to reuse the value of the column that
1936*da250ea5Sdrh ** has already been loaded into a register.  The value will always
1937*da250ea5Sdrh ** be used if it has not undergone any affinity changes.  But if
1938*da250ea5Sdrh ** an affinity change has occurred, then the cached value will only be
1939*da250ea5Sdrh ** used if allowAffChng is true.
1940945498f3Sdrh */
1941e55cbd72Sdrh int sqlite3ExprCodeGetColumn(
1942e55cbd72Sdrh   Parse *pParse,   /* Parsing and code generating context */
19432133d822Sdrh   Table *pTab,     /* Description of the table we are reading from */
19442133d822Sdrh   int iColumn,     /* Index of the table column */
19452133d822Sdrh   int iTable,      /* The cursor pointing to the table */
1946*da250ea5Sdrh   int iReg,        /* Store results here */
1947*da250ea5Sdrh   int allowAffChng /* True if prior affinity changes are OK */
19482133d822Sdrh ){
1949e55cbd72Sdrh   Vdbe *v = pParse->pVdbe;
1950e55cbd72Sdrh   int i;
1951*da250ea5Sdrh   struct yColCache *p;
1952e55cbd72Sdrh 
1953*da250ea5Sdrh   for(i=0, p=pParse->aColCache; i<pParse->nColCache; i++, p++){
1954*da250ea5Sdrh     if( p->iTable==iTable && p->iColumn==iColumn
1955*da250ea5Sdrh            && (!p->affChange || allowAffChng) ){
1956e55cbd72Sdrh #if 0
1957e55cbd72Sdrh       sqlite3VdbeAddOp0(v, OP_Noop);
1958*da250ea5Sdrh       VdbeComment((v, "OPT: tab%d.col%d -> r%d", iTable, iColumn, p->iReg));
1959e55cbd72Sdrh #endif
1960*da250ea5Sdrh       return p->iReg;
1961e55cbd72Sdrh     }
1962e55cbd72Sdrh   }
1963e55cbd72Sdrh   assert( v!=0 );
1964945498f3Sdrh   if( iColumn<0 ){
1965945498f3Sdrh     int op = (pTab && IsVirtual(pTab)) ? OP_VRowid : OP_Rowid;
19662133d822Sdrh     sqlite3VdbeAddOp2(v, op, iTable, iReg);
1967945498f3Sdrh   }else if( pTab==0 ){
19682133d822Sdrh     sqlite3VdbeAddOp3(v, OP_Column, iTable, iColumn, iReg);
1969945498f3Sdrh   }else{
1970945498f3Sdrh     int op = IsVirtual(pTab) ? OP_VColumn : OP_Column;
19712133d822Sdrh     sqlite3VdbeAddOp3(v, op, iTable, iColumn, iReg);
1972945498f3Sdrh     sqlite3ColumnDefault(v, pTab, iColumn);
1973945498f3Sdrh #ifndef SQLITE_OMIT_FLOATING_POINT
1974945498f3Sdrh     if( pTab->aCol[iColumn].affinity==SQLITE_AFF_REAL ){
19752133d822Sdrh       sqlite3VdbeAddOp1(v, OP_RealAffinity, iReg);
1976945498f3Sdrh     }
1977945498f3Sdrh #endif
1978945498f3Sdrh   }
1979e55cbd72Sdrh   if( pParse->disableColCache==0 ){
1980e55cbd72Sdrh     i = pParse->iColCache;
1981*da250ea5Sdrh     p = &pParse->aColCache[i];
1982*da250ea5Sdrh     p->iTable = iTable;
1983*da250ea5Sdrh     p->iColumn = iColumn;
1984*da250ea5Sdrh     p->iReg = iReg;
1985e55cbd72Sdrh     i++;
19862f7794c1Sdrh     if( i>=ArraySize(pParse->aColCache) ) i = 0;
1987e55cbd72Sdrh     if( i>pParse->nColCache ) pParse->nColCache = i;
19882f7794c1Sdrh     pParse->iColCache = i;
1989e55cbd72Sdrh   }
1990e55cbd72Sdrh   return iReg;
1991e55cbd72Sdrh }
1992e55cbd72Sdrh 
1993e55cbd72Sdrh /*
1994e55cbd72Sdrh ** Disable (+1) or enable (-1) the adding of new column cache entries.
1995e55cbd72Sdrh */
1996e55cbd72Sdrh void sqlite3ExprColumnCacheDisable(Parse *pParse, int disable){
1997e55cbd72Sdrh   assert( disable==-1 || disable==+1 );
1998e55cbd72Sdrh   assert( pParse->disableColCache>0 || disable==1 );
1999e55cbd72Sdrh   pParse->disableColCache += disable;
2000e55cbd72Sdrh }
2001e55cbd72Sdrh 
2002e55cbd72Sdrh /*
2003e55cbd72Sdrh ** Clear all column cache entries associated with the vdbe
2004e55cbd72Sdrh ** cursor with cursor number iTable.
2005e55cbd72Sdrh */
2006e55cbd72Sdrh void sqlite3ExprClearColumnCache(Parse *pParse, int iTable){
2007e55cbd72Sdrh   if( iTable<0 ){
2008e55cbd72Sdrh     pParse->nColCache = 0;
2009e55cbd72Sdrh     pParse->iColCache = 0;
2010e55cbd72Sdrh   }else{
2011e55cbd72Sdrh     int i;
2012e55cbd72Sdrh     for(i=0; i<pParse->nColCache; i++){
2013e55cbd72Sdrh       if( pParse->aColCache[i].iTable==iTable ){
2014e55cbd72Sdrh         pParse->aColCache[i] = pParse->aColCache[--pParse->nColCache];
2015e55cbd72Sdrh         pParse->iColCache = pParse->nColCache;
2016e55cbd72Sdrh       }
2017e55cbd72Sdrh     }
2018*da250ea5Sdrh   }
2019*da250ea5Sdrh }
2020e55cbd72Sdrh 
2021e55cbd72Sdrh /*
2022*da250ea5Sdrh ** Record the fact that an affinity change has occurred on iCount
2023*da250ea5Sdrh ** registers starting with iStart.
2024e55cbd72Sdrh */
2025*da250ea5Sdrh void sqlite3ExprCacheAffinityChange(Parse *pParse, int iStart, int iCount){
2026*da250ea5Sdrh   int iEnd = iStart + iCount - 1;
2027e55cbd72Sdrh   int i;
2028e55cbd72Sdrh   for(i=0; i<pParse->nColCache; i++){
2029e55cbd72Sdrh     int r = pParse->aColCache[i].iReg;
2030*da250ea5Sdrh     if( r>=iStart && r<=iEnd ){
2031*da250ea5Sdrh       pParse->aColCache[i].affChange = 1;
2032e55cbd72Sdrh     }
2033e55cbd72Sdrh   }
2034e55cbd72Sdrh }
2035e55cbd72Sdrh 
2036e55cbd72Sdrh /*
2037e55cbd72Sdrh ** Generate code to moves content from one register to another.
2038e55cbd72Sdrh ** Keep the column cache up-to-date.
2039e55cbd72Sdrh */
2040e55cbd72Sdrh void sqlite3ExprCodeMove(Parse *pParse, int iFrom, int iTo){
2041e55cbd72Sdrh   int i;
2042e55cbd72Sdrh   if( iFrom==iTo ) return;
2043e55cbd72Sdrh   sqlite3VdbeAddOp2(pParse->pVdbe, OP_Move, iFrom, iTo);
2044e55cbd72Sdrh   for(i=0; i<pParse->nColCache; i++){
2045e55cbd72Sdrh     if( pParse->aColCache[i].iReg==iFrom ){
2046e55cbd72Sdrh       pParse->aColCache[i].iReg = iTo;
2047e55cbd72Sdrh     }
2048e55cbd72Sdrh   }
2049945498f3Sdrh }
2050945498f3Sdrh 
2051fec19aadSdrh /*
2052652fbf55Sdrh ** Return true if any register in the range iFrom..iTo (inclusive)
2053652fbf55Sdrh ** is used as part of the column cache.
2054652fbf55Sdrh */
2055652fbf55Sdrh static int usedAsColumnCache(Parse *pParse, int iFrom, int iTo){
2056652fbf55Sdrh   int i;
2057652fbf55Sdrh   for(i=0; i<pParse->nColCache; i++){
2058652fbf55Sdrh     int r = pParse->aColCache[i].iReg;
2059652fbf55Sdrh     if( r>=iFrom && r<=iTo ) return 1;
2060652fbf55Sdrh   }
2061652fbf55Sdrh   return 0;
2062652fbf55Sdrh }
2063652fbf55Sdrh 
2064652fbf55Sdrh /*
2065652fbf55Sdrh ** Theres is a value in register iCurrent.  We ultimately want
2066652fbf55Sdrh ** the value to be in register iTarget.  It might be that
2067652fbf55Sdrh ** iCurrent and iTarget are the same register.
2068652fbf55Sdrh **
2069652fbf55Sdrh ** We are going to modify the value, so we need to make sure it
2070652fbf55Sdrh ** is not a cached register.  If iCurrent is a cached register,
2071652fbf55Sdrh ** then try to move the value over to iTarget.  If iTarget is a
2072652fbf55Sdrh ** cached register, then clear the corresponding cache line.
2073652fbf55Sdrh **
2074652fbf55Sdrh ** Return the register that the value ends up in.
2075652fbf55Sdrh */
2076652fbf55Sdrh int sqlite3ExprWritableRegister(Parse *pParse, int iCurrent, int iTarget){
2077*da250ea5Sdrh   int i;
2078652fbf55Sdrh   assert( pParse->pVdbe!=0 );
2079652fbf55Sdrh   if( !usedAsColumnCache(pParse, iCurrent, iCurrent) ){
2080652fbf55Sdrh     return iCurrent;
2081652fbf55Sdrh   }
20822f7794c1Sdrh   if( iCurrent!=iTarget ){
2083652fbf55Sdrh     sqlite3VdbeAddOp2(pParse->pVdbe, OP_SCopy, iCurrent, iTarget);
20842f7794c1Sdrh   }
2085*da250ea5Sdrh   for(i=0; i<pParse->nColCache; i++){
2086*da250ea5Sdrh     if( pParse->aColCache[i].iReg==iTarget ){
2087*da250ea5Sdrh       pParse->aColCache[i] = pParse->aColCache[--pParse->nColCache];
2088*da250ea5Sdrh       pParse->iColCache = pParse->nColCache;
2089*da250ea5Sdrh     }
2090*da250ea5Sdrh   }
2091652fbf55Sdrh   return iTarget;
2092652fbf55Sdrh }
2093652fbf55Sdrh 
2094652fbf55Sdrh /*
2095cce7d176Sdrh ** Generate code into the current Vdbe to evaluate the given
20962dcef11bSdrh ** expression.  Attempt to store the results in register "target".
20972dcef11bSdrh ** Return the register where results are stored.
2098389a1adbSdrh **
20992dcef11bSdrh ** With this routine, there is no guaranteed that results will
21002dcef11bSdrh ** be stored in target.  The result might be stored in some other
21012dcef11bSdrh ** register if it is convenient to do so.  The calling function
21022dcef11bSdrh ** must check the return code and move the results to the desired
21032dcef11bSdrh ** register.
2104cce7d176Sdrh */
2105678ccce8Sdrh int sqlite3ExprCodeTarget(Parse *pParse, Expr *pExpr, int target){
21062dcef11bSdrh   Vdbe *v = pParse->pVdbe;  /* The VM under construction */
21072dcef11bSdrh   int op;                   /* The opcode being coded */
21082dcef11bSdrh   int inReg = target;       /* Results stored in register inReg */
21092dcef11bSdrh   int regFree1 = 0;         /* If non-zero free this temporary register */
21102dcef11bSdrh   int regFree2 = 0;         /* If non-zero free this temporary register */
2111678ccce8Sdrh   int r1, r2, r3, r4;       /* Various register numbers */
2112ffe07b2dSdrh 
2113389a1adbSdrh   assert( v!=0 || pParse->db->mallocFailed );
21149cbf3425Sdrh   assert( target>0 && target<=pParse->nMem );
2115389a1adbSdrh   if( v==0 ) return 0;
2116389a1adbSdrh 
2117389a1adbSdrh   if( pExpr==0 ){
2118389a1adbSdrh     op = TK_NULL;
2119389a1adbSdrh   }else{
2120f2bc013cSdrh     op = pExpr->op;
2121389a1adbSdrh   }
2122f2bc013cSdrh   switch( op ){
212313449892Sdrh     case TK_AGG_COLUMN: {
212413449892Sdrh       AggInfo *pAggInfo = pExpr->pAggInfo;
212513449892Sdrh       struct AggInfo_col *pCol = &pAggInfo->aCol[pExpr->iAgg];
212613449892Sdrh       if( !pAggInfo->directMode ){
21279de221dfSdrh         assert( pCol->iMem>0 );
21289de221dfSdrh         inReg = pCol->iMem;
212913449892Sdrh         break;
213013449892Sdrh       }else if( pAggInfo->useSortingIdx ){
2131389a1adbSdrh         sqlite3VdbeAddOp3(v, OP_Column, pAggInfo->sortingIdx,
2132389a1adbSdrh                               pCol->iSorterColumn, target);
213313449892Sdrh         break;
213413449892Sdrh       }
213513449892Sdrh       /* Otherwise, fall thru into the TK_COLUMN case */
213613449892Sdrh     }
2137967e8b73Sdrh     case TK_COLUMN: {
2138ffe07b2dSdrh       if( pExpr->iTable<0 ){
2139ffe07b2dSdrh         /* This only happens when coding check constraints */
2140aa9b8963Sdrh         assert( pParse->ckBase>0 );
2141aa9b8963Sdrh         inReg = pExpr->iColumn + pParse->ckBase;
2142c4a3c779Sdrh       }else{
2143e55cbd72Sdrh         inReg = sqlite3ExprCodeGetColumn(pParse, pExpr->pTab,
2144*da250ea5Sdrh                                  pExpr->iColumn, pExpr->iTable, target,
2145*da250ea5Sdrh                                  pExpr->flags & EP_AnyAff);
21462282792aSdrh       }
2147cce7d176Sdrh       break;
2148cce7d176Sdrh     }
2149cce7d176Sdrh     case TK_INTEGER: {
21509de221dfSdrh       codeInteger(v, (char*)pExpr->token.z, pExpr->token.n, 0, target);
2151fec19aadSdrh       break;
215251e9a445Sdrh     }
2153598f1340Sdrh     case TK_FLOAT: {
21549de221dfSdrh       codeReal(v, (char*)pExpr->token.z, pExpr->token.n, 0, target);
2155598f1340Sdrh       break;
2156598f1340Sdrh     }
2157fec19aadSdrh     case TK_STRING: {
21581e536953Sdanielk1977       sqlite3DequoteExpr(pParse->db, pExpr);
21599de221dfSdrh       sqlite3VdbeAddOp4(v,OP_String8, 0, target, 0,
216066a5167bSdrh                         (char*)pExpr->token.z, pExpr->token.n);
2161cce7d176Sdrh       break;
2162cce7d176Sdrh     }
2163f0863fe5Sdrh     case TK_NULL: {
21649de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Null, 0, target);
2165f0863fe5Sdrh       break;
2166f0863fe5Sdrh     }
21675338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_BLOB_LITERAL
2168c572ef7fSdanielk1977     case TK_BLOB: {
21696c8c6cecSdrh       int n;
21706c8c6cecSdrh       const char *z;
2171ca48c90fSdrh       char *zBlob;
2172ca48c90fSdrh       assert( pExpr->token.n>=3 );
2173ca48c90fSdrh       assert( pExpr->token.z[0]=='x' || pExpr->token.z[0]=='X' );
2174ca48c90fSdrh       assert( pExpr->token.z[1]=='\'' );
2175ca48c90fSdrh       assert( pExpr->token.z[pExpr->token.n-1]=='\'' );
21766c8c6cecSdrh       n = pExpr->token.n - 3;
21772646da7eSdrh       z = (char*)pExpr->token.z + 2;
2178ca48c90fSdrh       zBlob = sqlite3HexToBlob(sqlite3VdbeDb(v), z, n);
2179ca48c90fSdrh       sqlite3VdbeAddOp4(v, OP_Blob, n/2, target, 0, zBlob, P4_DYNAMIC);
2180c572ef7fSdanielk1977       break;
2181c572ef7fSdanielk1977     }
21825338a5f7Sdanielk1977 #endif
218350457896Sdrh     case TK_VARIABLE: {
21849de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Variable, pExpr->iTable, target);
2185895d7472Sdrh       if( pExpr->token.n>1 ){
218666a5167bSdrh         sqlite3VdbeChangeP4(v, -1, (char*)pExpr->token.z, pExpr->token.n);
2187895d7472Sdrh       }
218850457896Sdrh       break;
218950457896Sdrh     }
21904e0cff60Sdrh     case TK_REGISTER: {
21919de221dfSdrh       inReg = pExpr->iTable;
21924e0cff60Sdrh       break;
21934e0cff60Sdrh     }
2194487e262fSdrh #ifndef SQLITE_OMIT_CAST
2195487e262fSdrh     case TK_CAST: {
2196487e262fSdrh       /* Expressions of the form:   CAST(pLeft AS token) */
2197f0113000Sdanielk1977       int aff, to_op;
21982dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
21998a51256cSdrh       aff = sqlite3AffinityType(&pExpr->token);
2200f0113000Sdanielk1977       to_op = aff - SQLITE_AFF_TEXT + OP_ToText;
2201f0113000Sdanielk1977       assert( to_op==OP_ToText    || aff!=SQLITE_AFF_TEXT    );
2202f0113000Sdanielk1977       assert( to_op==OP_ToBlob    || aff!=SQLITE_AFF_NONE    );
2203f0113000Sdanielk1977       assert( to_op==OP_ToNumeric || aff!=SQLITE_AFF_NUMERIC );
2204f0113000Sdanielk1977       assert( to_op==OP_ToInt     || aff!=SQLITE_AFF_INTEGER );
2205f0113000Sdanielk1977       assert( to_op==OP_ToReal    || aff!=SQLITE_AFF_REAL    );
22062dcef11bSdrh       sqlite3VdbeAddOp1(v, to_op, inReg);
2207487e262fSdrh       break;
2208487e262fSdrh     }
2209487e262fSdrh #endif /* SQLITE_OMIT_CAST */
2210c9b84a1fSdrh     case TK_LT:
2211c9b84a1fSdrh     case TK_LE:
2212c9b84a1fSdrh     case TK_GT:
2213c9b84a1fSdrh     case TK_GE:
2214c9b84a1fSdrh     case TK_NE:
2215c9b84a1fSdrh     case TK_EQ: {
2216f2bc013cSdrh       assert( TK_LT==OP_Lt );
2217f2bc013cSdrh       assert( TK_LE==OP_Le );
2218f2bc013cSdrh       assert( TK_GT==OP_Gt );
2219f2bc013cSdrh       assert( TK_GE==OP_Ge );
2220f2bc013cSdrh       assert( TK_EQ==OP_Eq );
2221f2bc013cSdrh       assert( TK_NE==OP_Ne );
2222*da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
2223*da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
222435573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
222535573356Sdrh                   r1, r2, inReg, SQLITE_STOREP2);
2226a37cdde0Sdanielk1977       break;
2227c9b84a1fSdrh     }
2228cce7d176Sdrh     case TK_AND:
2229cce7d176Sdrh     case TK_OR:
2230cce7d176Sdrh     case TK_PLUS:
2231cce7d176Sdrh     case TK_STAR:
2232cce7d176Sdrh     case TK_MINUS:
2233bf4133cbSdrh     case TK_REM:
2234bf4133cbSdrh     case TK_BITAND:
2235bf4133cbSdrh     case TK_BITOR:
223617c40294Sdrh     case TK_SLASH:
2237bf4133cbSdrh     case TK_LSHIFT:
2238855eb1cfSdrh     case TK_RSHIFT:
22390040077dSdrh     case TK_CONCAT: {
2240f2bc013cSdrh       assert( TK_AND==OP_And );
2241f2bc013cSdrh       assert( TK_OR==OP_Or );
2242f2bc013cSdrh       assert( TK_PLUS==OP_Add );
2243f2bc013cSdrh       assert( TK_MINUS==OP_Subtract );
2244f2bc013cSdrh       assert( TK_REM==OP_Remainder );
2245f2bc013cSdrh       assert( TK_BITAND==OP_BitAnd );
2246f2bc013cSdrh       assert( TK_BITOR==OP_BitOr );
2247f2bc013cSdrh       assert( TK_SLASH==OP_Divide );
2248f2bc013cSdrh       assert( TK_LSHIFT==OP_ShiftLeft );
2249f2bc013cSdrh       assert( TK_RSHIFT==OP_ShiftRight );
2250f2bc013cSdrh       assert( TK_CONCAT==OP_Concat );
22512dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
22522dcef11bSdrh       r2 = sqlite3ExprCodeTemp(pParse, pExpr->pRight, &regFree2);
22535b6afba9Sdrh       sqlite3VdbeAddOp3(v, op, r2, r1, target);
22540040077dSdrh       break;
22550040077dSdrh     }
2256cce7d176Sdrh     case TK_UMINUS: {
2257fec19aadSdrh       Expr *pLeft = pExpr->pLeft;
2258fec19aadSdrh       assert( pLeft );
2259fec19aadSdrh       if( pLeft->op==TK_FLOAT || pLeft->op==TK_INTEGER ){
2260fec19aadSdrh         Token *p = &pLeft->token;
2261fec19aadSdrh         if( pLeft->op==TK_FLOAT ){
22629de221dfSdrh           codeReal(v, (char*)p->z, p->n, 1, target);
2263e6840900Sdrh         }else{
22649de221dfSdrh           codeInteger(v, (char*)p->z, p->n, 1, target);
2265e6840900Sdrh         }
22663c84ddffSdrh       }else{
22672dcef11bSdrh         regFree1 = r1 = sqlite3GetTempReg(pParse);
22683c84ddffSdrh         sqlite3VdbeAddOp2(v, OP_Integer, 0, r1);
2269e55cbd72Sdrh         r2 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree2);
22702dcef11bSdrh         sqlite3VdbeAddOp3(v, OP_Subtract, r2, r1, target);
22713c84ddffSdrh       }
22729de221dfSdrh       inReg = target;
22736e142f54Sdrh       break;
22746e142f54Sdrh     }
2275bf4133cbSdrh     case TK_BITNOT:
22766e142f54Sdrh     case TK_NOT: {
2277f2bc013cSdrh       assert( TK_BITNOT==OP_BitNot );
2278f2bc013cSdrh       assert( TK_NOT==OP_Not );
22792dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
2280652fbf55Sdrh       inReg = sqlite3ExprWritableRegister(pParse, inReg, target);
22812dcef11bSdrh       sqlite3VdbeAddOp1(v, op, inReg);
2282cce7d176Sdrh       break;
2283cce7d176Sdrh     }
2284cce7d176Sdrh     case TK_ISNULL:
2285cce7d176Sdrh     case TK_NOTNULL: {
22866a288a33Sdrh       int addr;
2287f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
2288f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
22899de221dfSdrh       sqlite3VdbeAddOp2(v, OP_Integer, 1, target);
22902dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
22912dcef11bSdrh       addr = sqlite3VdbeAddOp1(v, op, r1);
22929de221dfSdrh       sqlite3VdbeAddOp2(v, OP_AddImm, target, -1);
22936a288a33Sdrh       sqlite3VdbeJumpHere(v, addr);
2294a37cdde0Sdanielk1977       break;
2295f2bc013cSdrh     }
22962282792aSdrh     case TK_AGG_FUNCTION: {
229713449892Sdrh       AggInfo *pInfo = pExpr->pAggInfo;
22987e56e711Sdrh       if( pInfo==0 ){
22997e56e711Sdrh         sqlite3ErrorMsg(pParse, "misuse of aggregate: %T",
23007e56e711Sdrh             &pExpr->span);
23017e56e711Sdrh       }else{
23029de221dfSdrh         inReg = pInfo->aFunc[pExpr->iAgg].iMem;
23037e56e711Sdrh       }
23042282792aSdrh       break;
23052282792aSdrh     }
2306b71090fdSdrh     case TK_CONST_FUNC:
2307cce7d176Sdrh     case TK_FUNCTION: {
2308cce7d176Sdrh       ExprList *pList = pExpr->pList;
230989425d5eSdrh       int nExpr = pList ? pList->nExpr : 0;
23100bce8354Sdrh       FuncDef *pDef;
23114b59ab5eSdrh       int nId;
23124b59ab5eSdrh       const char *zId;
231313449892Sdrh       int constMask = 0;
2314682f68b0Sdanielk1977       int i;
231517435752Sdrh       sqlite3 *db = pParse->db;
231617435752Sdrh       u8 enc = ENC(db);
2317dc1bdc4fSdanielk1977       CollSeq *pColl = 0;
231817435752Sdrh 
23192646da7eSdrh       zId = (char*)pExpr->token.z;
2320b71090fdSdrh       nId = pExpr->token.n;
2321d8123366Sdanielk1977       pDef = sqlite3FindFunction(pParse->db, zId, nId, nExpr, enc, 0);
23220bce8354Sdrh       assert( pDef!=0 );
2323892d3179Sdrh       if( pList ){
2324892d3179Sdrh         nExpr = pList->nExpr;
23252dcef11bSdrh         r1 = sqlite3GetTempRange(pParse, nExpr);
23262dcef11bSdrh         sqlite3ExprCodeExprList(pParse, pList, r1);
2327892d3179Sdrh       }else{
2328d847eaadSdrh         nExpr = r1 = 0;
2329892d3179Sdrh       }
2330b7f6f68fSdrh #ifndef SQLITE_OMIT_VIRTUALTABLE
2331a43fa227Sdrh       /* Possibly overload the function if the first argument is
2332a43fa227Sdrh       ** a virtual table column.
2333a43fa227Sdrh       **
2334a43fa227Sdrh       ** For infix functions (LIKE, GLOB, REGEXP, and MATCH) use the
2335a43fa227Sdrh       ** second argument, not the first, as the argument to test to
2336a43fa227Sdrh       ** see if it is a column in a virtual table.  This is done because
2337a43fa227Sdrh       ** the left operand of infix functions (the operand we want to
2338a43fa227Sdrh       ** control overloading) ends up as the second argument to the
2339a43fa227Sdrh       ** function.  The expression "A glob B" is equivalent to
2340a43fa227Sdrh       ** "glob(B,A).  We want to use the A in "A glob B" to test
2341a43fa227Sdrh       ** for function overloading.  But we use the B term in "glob(B,A)".
2342a43fa227Sdrh       */
23436a03a1c5Sdrh       if( nExpr>=2 && (pExpr->flags & EP_InfixFunc) ){
234417435752Sdrh         pDef = sqlite3VtabOverloadFunction(db, pDef, nExpr, pList->a[1].pExpr);
23456a03a1c5Sdrh       }else if( nExpr>0 ){
234617435752Sdrh         pDef = sqlite3VtabOverloadFunction(db, pDef, nExpr, pList->a[0].pExpr);
2347b7f6f68fSdrh       }
2348b7f6f68fSdrh #endif
2349682f68b0Sdanielk1977       for(i=0; i<nExpr && i<32; i++){
2350d02eb1fdSdanielk1977         if( sqlite3ExprIsConstant(pList->a[i].pExpr) ){
235113449892Sdrh           constMask |= (1<<i);
2352d02eb1fdSdanielk1977         }
2353dc1bdc4fSdanielk1977         if( pDef->needCollSeq && !pColl ){
2354dc1bdc4fSdanielk1977           pColl = sqlite3ExprCollSeq(pParse, pList->a[i].pExpr);
2355dc1bdc4fSdanielk1977         }
2356dc1bdc4fSdanielk1977       }
2357dc1bdc4fSdanielk1977       if( pDef->needCollSeq ){
2358dc1bdc4fSdanielk1977         if( !pColl ) pColl = pParse->db->pDfltColl;
235966a5167bSdrh         sqlite3VdbeAddOp4(v, OP_CollSeq, 0, 0, 0, (char *)pColl, P4_COLLSEQ);
2360682f68b0Sdanielk1977       }
23612dcef11bSdrh       sqlite3VdbeAddOp4(v, OP_Function, constMask, r1, target,
236266a5167bSdrh                         (char*)pDef, P4_FUNCDEF);
236398757157Sdrh       sqlite3VdbeChangeP5(v, nExpr);
23642dcef11bSdrh       if( nExpr ){
23652dcef11bSdrh         sqlite3ReleaseTempRange(pParse, r1, nExpr);
23662dcef11bSdrh       }
2367*da250ea5Sdrh       sqlite3ExprCacheAffinityChange(pParse, r1, nExpr);
23686ec2733bSdrh       break;
23696ec2733bSdrh     }
2370fe2093d7Sdrh #ifndef SQLITE_OMIT_SUBQUERY
2371fe2093d7Sdrh     case TK_EXISTS:
237219a775c2Sdrh     case TK_SELECT: {
237341714d6fSdrh       if( pExpr->iColumn==0 ){
2374b3bce662Sdanielk1977         sqlite3CodeSubselect(pParse, pExpr);
237541714d6fSdrh       }
23769de221dfSdrh       inReg = pExpr->iColumn;
237719a775c2Sdrh       break;
237819a775c2Sdrh     }
2379fef5208cSdrh     case TK_IN: {
23806a288a33Sdrh       int j1, j2, j3, j4, j5;
238194a11211Sdrh       char affinity;
23829a96b668Sdanielk1977       int eType;
23839a96b668Sdanielk1977 
23849a96b668Sdanielk1977       eType = sqlite3FindInIndex(pParse, pExpr, 0);
2385e014a838Sdanielk1977 
2386e014a838Sdanielk1977       /* Figure out the affinity to use to create a key from the results
2387e014a838Sdanielk1977       ** of the expression. affinityStr stores a static string suitable for
238866a5167bSdrh       ** P4 of OP_MakeRecord.
2389e014a838Sdanielk1977       */
239094a11211Sdrh       affinity = comparisonAffinity(pExpr);
2391e014a838Sdanielk1977 
23922dcef11bSdrh       sqlite3VdbeAddOp2(v, OP_Integer, 1, target);
2393e014a838Sdanielk1977 
2394e014a838Sdanielk1977       /* Code the <expr> from "<expr> IN (...)". The temporary table
2395e014a838Sdanielk1977       ** pExpr->iTable contains the values that make up the (...) set.
2396e014a838Sdanielk1977       */
23972dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
23982dcef11bSdrh       j1 = sqlite3VdbeAddOp1(v, OP_NotNull, r1);
23992dcef11bSdrh       sqlite3VdbeAddOp2(v, OP_Null, 0, target);
24006a288a33Sdrh       j2  = sqlite3VdbeAddOp0(v, OP_Goto);
24016a288a33Sdrh       sqlite3VdbeJumpHere(v, j1);
24029a96b668Sdanielk1977       if( eType==IN_INDEX_ROWID ){
2403678ccce8Sdrh         j3 = sqlite3VdbeAddOp1(v, OP_MustBeInt, r1);
24042dcef11bSdrh         j4 = sqlite3VdbeAddOp3(v, OP_NotExists, pExpr->iTable, 0, r1);
24056a288a33Sdrh         j5 = sqlite3VdbeAddOp0(v, OP_Goto);
24066a288a33Sdrh         sqlite3VdbeJumpHere(v, j3);
24076a288a33Sdrh         sqlite3VdbeJumpHere(v, j4);
24089a96b668Sdanielk1977       }else{
24092dcef11bSdrh         r2 = regFree2 = sqlite3GetTempReg(pParse);
24101db639ceSdrh         sqlite3VdbeAddOp4(v, OP_MakeRecord, r1, 1, r2, &affinity, 1);
2411*da250ea5Sdrh         sqlite3ExprCacheAffinityChange(pParse, r1, 1);
24122dcef11bSdrh         j5 = sqlite3VdbeAddOp3(v, OP_Found, pExpr->iTable, 0, r2);
24139a96b668Sdanielk1977       }
24142dcef11bSdrh       sqlite3VdbeAddOp2(v, OP_AddImm, target, -1);
24156a288a33Sdrh       sqlite3VdbeJumpHere(v, j2);
24166a288a33Sdrh       sqlite3VdbeJumpHere(v, j5);
2417fef5208cSdrh       break;
2418fef5208cSdrh     }
241993758c8dSdanielk1977 #endif
24202dcef11bSdrh     /*
24212dcef11bSdrh     **    x BETWEEN y AND z
24222dcef11bSdrh     **
24232dcef11bSdrh     ** This is equivalent to
24242dcef11bSdrh     **
24252dcef11bSdrh     **    x>=y AND x<=z
24262dcef11bSdrh     **
24272dcef11bSdrh     ** X is stored in pExpr->pLeft.
24282dcef11bSdrh     ** Y is stored in pExpr->pList->a[0].pExpr.
24292dcef11bSdrh     ** Z is stored in pExpr->pList->a[1].pExpr.
24302dcef11bSdrh     */
2431fef5208cSdrh     case TK_BETWEEN: {
2432be5c89acSdrh       Expr *pLeft = pExpr->pLeft;
2433be5c89acSdrh       struct ExprList_item *pLItem = pExpr->pList->a;
2434be5c89acSdrh       Expr *pRight = pLItem->pExpr;
243535573356Sdrh 
2436*da250ea5Sdrh       codeCompareOperands(pParse, pLeft, &r1, &regFree1,
2437*da250ea5Sdrh                                   pRight, &r2, &regFree2);
24382dcef11bSdrh       r3 = sqlite3GetTempReg(pParse);
2439678ccce8Sdrh       r4 = sqlite3GetTempReg(pParse);
244035573356Sdrh       codeCompare(pParse, pLeft, pRight, OP_Ge,
244135573356Sdrh                   r1, r2, r3, SQLITE_STOREP2);
2442be5c89acSdrh       pLItem++;
2443be5c89acSdrh       pRight = pLItem->pExpr;
24442dcef11bSdrh       sqlite3ReleaseTempReg(pParse, regFree2);
24452dcef11bSdrh       r2 = sqlite3ExprCodeTemp(pParse, pRight, &regFree2);
2446678ccce8Sdrh       codeCompare(pParse, pLeft, pRight, OP_Le, r1, r2, r4, SQLITE_STOREP2);
2447678ccce8Sdrh       sqlite3VdbeAddOp3(v, OP_And, r3, r4, target);
24482dcef11bSdrh       sqlite3ReleaseTempReg(pParse, r3);
2449678ccce8Sdrh       sqlite3ReleaseTempReg(pParse, r4);
2450fef5208cSdrh       break;
2451fef5208cSdrh     }
24524f07e5fbSdrh     case TK_UPLUS: {
24532dcef11bSdrh       inReg = sqlite3ExprCodeTarget(pParse, pExpr->pLeft, target);
2454a2e00042Sdrh       break;
2455a2e00042Sdrh     }
24562dcef11bSdrh 
24572dcef11bSdrh     /*
24582dcef11bSdrh     ** Form A:
24592dcef11bSdrh     **   CASE x WHEN e1 THEN r1 WHEN e2 THEN r2 ... WHEN eN THEN rN ELSE y END
24602dcef11bSdrh     **
24612dcef11bSdrh     ** Form B:
24622dcef11bSdrh     **   CASE WHEN e1 THEN r1 WHEN e2 THEN r2 ... WHEN eN THEN rN ELSE y END
24632dcef11bSdrh     **
24642dcef11bSdrh     ** Form A is can be transformed into the equivalent form B as follows:
24652dcef11bSdrh     **   CASE WHEN x=e1 THEN r1 WHEN x=e2 THEN r2 ...
24662dcef11bSdrh     **        WHEN x=eN THEN rN ELSE y END
24672dcef11bSdrh     **
24682dcef11bSdrh     ** X (if it exists) is in pExpr->pLeft.
24692dcef11bSdrh     ** Y is in pExpr->pRight.  The Y is also optional.  If there is no
24702dcef11bSdrh     ** ELSE clause and no other term matches, then the result of the
24712dcef11bSdrh     ** exprssion is NULL.
24722dcef11bSdrh     ** Ei is in pExpr->pList->a[i*2] and Ri is pExpr->pList->a[i*2+1].
24732dcef11bSdrh     **
24742dcef11bSdrh     ** The result of the expression is the Ri for the first matching Ei,
24752dcef11bSdrh     ** or if there is no matching Ei, the ELSE term Y, or if there is
24762dcef11bSdrh     ** no ELSE term, NULL.
24772dcef11bSdrh     */
247817a7f8ddSdrh     case TK_CASE: {
24792dcef11bSdrh       int endLabel;                     /* GOTO label for end of CASE stmt */
24802dcef11bSdrh       int nextCase;                     /* GOTO label for next WHEN clause */
24812dcef11bSdrh       int nExpr;                        /* 2x number of WHEN terms */
24822dcef11bSdrh       int i;                            /* Loop counter */
24832dcef11bSdrh       ExprList *pEList;                 /* List of WHEN terms */
24842dcef11bSdrh       struct ExprList_item *aListelem;  /* Array of WHEN terms */
24852dcef11bSdrh       Expr opCompare;                   /* The X==Ei expression */
24862dcef11bSdrh       Expr cacheX;                      /* Cached expression X */
24872dcef11bSdrh       Expr *pX;                         /* The X expression */
24882dcef11bSdrh       Expr *pTest;                      /* X==Ei (form A) or just Ei (form B) */
248917a7f8ddSdrh 
249017a7f8ddSdrh       assert(pExpr->pList);
249117a7f8ddSdrh       assert((pExpr->pList->nExpr % 2) == 0);
249217a7f8ddSdrh       assert(pExpr->pList->nExpr > 0);
2493be5c89acSdrh       pEList = pExpr->pList;
2494be5c89acSdrh       aListelem = pEList->a;
2495be5c89acSdrh       nExpr = pEList->nExpr;
24962dcef11bSdrh       endLabel = sqlite3VdbeMakeLabel(v);
24972dcef11bSdrh       if( (pX = pExpr->pLeft)!=0 ){
24982dcef11bSdrh         cacheX = *pX;
24992dcef11bSdrh         cacheX.iTable = sqlite3ExprCodeTemp(pParse, pX, &regFree1);
25002dcef11bSdrh         cacheX.op = TK_REGISTER;
2501678ccce8Sdrh         cacheX.iColumn = 0;
25022dcef11bSdrh         opCompare.op = TK_EQ;
25032dcef11bSdrh         opCompare.pLeft = &cacheX;
25042dcef11bSdrh         pTest = &opCompare;
2505cce7d176Sdrh       }
2506652fbf55Sdrh       sqlite3ExprColumnCacheDisable(pParse, 1);
2507f5905aa7Sdrh       for(i=0; i<nExpr; i=i+2){
25082dcef11bSdrh         if( pX ){
25092dcef11bSdrh           opCompare.pRight = aListelem[i].pExpr;
2510f5905aa7Sdrh         }else{
25112dcef11bSdrh           pTest = aListelem[i].pExpr;
251217a7f8ddSdrh         }
25132dcef11bSdrh         nextCase = sqlite3VdbeMakeLabel(v);
25142dcef11bSdrh         sqlite3ExprIfFalse(pParse, pTest, nextCase, SQLITE_JUMPIFNULL);
25159de221dfSdrh         sqlite3ExprCode(pParse, aListelem[i+1].pExpr, target);
25162dcef11bSdrh         sqlite3VdbeAddOp2(v, OP_Goto, 0, endLabel);
25172dcef11bSdrh         sqlite3VdbeResolveLabel(v, nextCase);
2518f570f011Sdrh       }
251917a7f8ddSdrh       if( pExpr->pRight ){
25209de221dfSdrh         sqlite3ExprCode(pParse, pExpr->pRight, target);
252117a7f8ddSdrh       }else{
25229de221dfSdrh         sqlite3VdbeAddOp2(v, OP_Null, 0, target);
252317a7f8ddSdrh       }
25242dcef11bSdrh       sqlite3VdbeResolveLabel(v, endLabel);
2525e55cbd72Sdrh       sqlite3ExprColumnCacheDisable(pParse, -1);
25266f34903eSdanielk1977       break;
25276f34903eSdanielk1977     }
25285338a5f7Sdanielk1977 #ifndef SQLITE_OMIT_TRIGGER
25296f34903eSdanielk1977     case TK_RAISE: {
25306f34903eSdanielk1977       if( !pParse->trigStack ){
25314adee20fSdanielk1977         sqlite3ErrorMsg(pParse,
2532da93d238Sdrh                        "RAISE() may only be used within a trigger-program");
2533389a1adbSdrh         return 0;
25346f34903eSdanielk1977       }
2535ad6d9460Sdrh       if( pExpr->iColumn!=OE_Ignore ){
2536ad6d9460Sdrh          assert( pExpr->iColumn==OE_Rollback ||
25376f34903eSdanielk1977                  pExpr->iColumn == OE_Abort ||
2538ad6d9460Sdrh                  pExpr->iColumn == OE_Fail );
25391e536953Sdanielk1977          sqlite3DequoteExpr(pParse->db, pExpr);
254066a5167bSdrh          sqlite3VdbeAddOp4(v, OP_Halt, SQLITE_CONSTRAINT, pExpr->iColumn, 0,
25412646da7eSdrh                         (char*)pExpr->token.z, pExpr->token.n);
25426f34903eSdanielk1977       } else {
25436f34903eSdanielk1977          assert( pExpr->iColumn == OE_Ignore );
254466a5167bSdrh          sqlite3VdbeAddOp2(v, OP_ContextPop, 0, 0);
254566a5167bSdrh          sqlite3VdbeAddOp2(v, OP_Goto, 0, pParse->trigStack->ignoreJump);
2546d4e70ebdSdrh          VdbeComment((v, "raise(IGNORE)"));
25476f34903eSdanielk1977       }
2548ffe07b2dSdrh       break;
254917a7f8ddSdrh     }
25505338a5f7Sdanielk1977 #endif
2551ffe07b2dSdrh   }
25522dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
25532dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
25542dcef11bSdrh   return inReg;
25555b6afba9Sdrh }
25562dcef11bSdrh 
25572dcef11bSdrh /*
25582dcef11bSdrh ** Generate code to evaluate an expression and store the results
25592dcef11bSdrh ** into a register.  Return the register number where the results
25602dcef11bSdrh ** are stored.
25612dcef11bSdrh **
25622dcef11bSdrh ** If the register is a temporary register that can be deallocated,
2563678ccce8Sdrh ** then write its number into *pReg.  If the result register is not
25642dcef11bSdrh ** a temporary, then set *pReg to zero.
25652dcef11bSdrh */
25662dcef11bSdrh int sqlite3ExprCodeTemp(Parse *pParse, Expr *pExpr, int *pReg){
25672dcef11bSdrh   int r1 = sqlite3GetTempReg(pParse);
25682dcef11bSdrh   int r2 = sqlite3ExprCodeTarget(pParse, pExpr, r1);
25692dcef11bSdrh   if( r2==r1 ){
25702dcef11bSdrh     *pReg = r1;
25712dcef11bSdrh   }else{
25722dcef11bSdrh     sqlite3ReleaseTempReg(pParse, r1);
25732dcef11bSdrh     *pReg = 0;
25742dcef11bSdrh   }
25752dcef11bSdrh   return r2;
25762dcef11bSdrh }
25772dcef11bSdrh 
25782dcef11bSdrh /*
25792dcef11bSdrh ** Generate code that will evaluate expression pExpr and store the
25802dcef11bSdrh ** results in register target.  The results are guaranteed to appear
25812dcef11bSdrh ** in register target.
25822dcef11bSdrh */
25832dcef11bSdrh int sqlite3ExprCode(Parse *pParse, Expr *pExpr, int target){
25849cbf3425Sdrh   int inReg;
25859cbf3425Sdrh 
25869cbf3425Sdrh   assert( target>0 && target<=pParse->nMem );
25879cbf3425Sdrh   inReg = sqlite3ExprCodeTarget(pParse, pExpr, target);
25880e359b30Sdrh   assert( pParse->pVdbe || pParse->db->mallocFailed );
25890e359b30Sdrh   if( inReg!=target && pParse->pVdbe ){
25909cbf3425Sdrh     sqlite3VdbeAddOp2(pParse->pVdbe, OP_SCopy, inReg, target);
259117a7f8ddSdrh   }
2592389a1adbSdrh   return target;
2593cce7d176Sdrh }
2594cce7d176Sdrh 
2595cce7d176Sdrh /*
25962dcef11bSdrh ** Generate code that evalutes the given expression and puts the result
2597de4fcfddSdrh ** in register target.
259825303780Sdrh **
25992dcef11bSdrh ** Also make a copy of the expression results into another "cache" register
26002dcef11bSdrh ** and modify the expression so that the next time it is evaluated,
26012dcef11bSdrh ** the result is a copy of the cache register.
26022dcef11bSdrh **
26032dcef11bSdrh ** This routine is used for expressions that are used multiple
26042dcef11bSdrh ** times.  They are evaluated once and the results of the expression
26052dcef11bSdrh ** are reused.
260625303780Sdrh */
26072dcef11bSdrh int sqlite3ExprCodeAndCache(Parse *pParse, Expr *pExpr, int target){
260825303780Sdrh   Vdbe *v = pParse->pVdbe;
26092dcef11bSdrh   int inReg;
26102dcef11bSdrh   inReg = sqlite3ExprCode(pParse, pExpr, target);
2611de4fcfddSdrh   assert( target>0 );
26122dcef11bSdrh   if( pExpr->op!=TK_REGISTER ){
261325303780Sdrh     int iMem;
26142dcef11bSdrh     iMem = ++pParse->nMem;
26152dcef11bSdrh     sqlite3VdbeAddOp2(v, OP_Copy, inReg, iMem);
26162dcef11bSdrh     pExpr->iTable = iMem;
2617678ccce8Sdrh     pExpr->iColumn = pExpr->op;
261825303780Sdrh     pExpr->op = TK_REGISTER;
261925303780Sdrh   }
26202dcef11bSdrh   return inReg;
262125303780Sdrh }
26222dcef11bSdrh 
2623678ccce8Sdrh /*
2624678ccce8Sdrh ** If pExpr is a constant expression, then evaluate the expression
2625678ccce8Sdrh ** into a register and convert the expression into a TK_REGISTER
2626678ccce8Sdrh ** expression.
2627678ccce8Sdrh */
2628678ccce8Sdrh static int evalConstExpr(void *pArg, Expr *pExpr){
2629678ccce8Sdrh   Parse *pParse = (Parse*)pArg;
2630678ccce8Sdrh   if( pExpr->op==TK_REGISTER ){
2631678ccce8Sdrh     return 1;
2632678ccce8Sdrh   }
2633678ccce8Sdrh   if( sqlite3ExprIsConstantNotJoin(pExpr) ){
2634678ccce8Sdrh     int r1 = ++pParse->nMem;
2635678ccce8Sdrh     int r2;
2636678ccce8Sdrh     r2 = sqlite3ExprCodeTarget(pParse, pExpr, r1);
2637678ccce8Sdrh     if( r1!=r2 ) pParse->nMem--;
2638678ccce8Sdrh     pExpr->iColumn = pExpr->op;
2639678ccce8Sdrh     pExpr->op = TK_REGISTER;
2640678ccce8Sdrh     pExpr->iTable = r2;
2641678ccce8Sdrh     return 1;
2642678ccce8Sdrh   }
2643678ccce8Sdrh   return 0;
2644678ccce8Sdrh }
2645678ccce8Sdrh 
2646678ccce8Sdrh /*
2647678ccce8Sdrh ** Preevaluate constant subexpressions within pExpr and store the
2648678ccce8Sdrh ** results in registers.  Modify pExpr so that the constant subexpresions
2649678ccce8Sdrh ** are TK_REGISTER opcodes that refer to the precomputed values.
2650678ccce8Sdrh */
2651678ccce8Sdrh void sqlite3ExprCodeConstants(Parse *pParse, Expr *pExpr){
2652678ccce8Sdrh    walkExprTree(pExpr, evalConstExpr, pParse);
2653678ccce8Sdrh }
2654678ccce8Sdrh 
265525303780Sdrh 
265625303780Sdrh /*
2657268380caSdrh ** Generate code that pushes the value of every element of the given
26589cbf3425Sdrh ** expression list into a sequence of registers beginning at target.
2659268380caSdrh **
2660892d3179Sdrh ** Return the number of elements evaluated.
2661268380caSdrh */
26624adee20fSdanielk1977 int sqlite3ExprCodeExprList(
2663268380caSdrh   Parse *pParse,     /* Parsing context */
2664389a1adbSdrh   ExprList *pList,   /* The expression list to be coded */
2665389a1adbSdrh   int target         /* Where to write results */
2666268380caSdrh ){
2667268380caSdrh   struct ExprList_item *pItem;
26689cbf3425Sdrh   int i, n;
2669892d3179Sdrh   assert( pList!=0 || pParse->db->mallocFailed );
2670892d3179Sdrh   if( pList==0 ){
2671892d3179Sdrh     return 0;
2672892d3179Sdrh   }
26739cbf3425Sdrh   assert( target>0 );
2674268380caSdrh   n = pList->nExpr;
2675c182d163Sdrh   for(pItem=pList->a, i=n; i>0; i--, pItem++){
2676389a1adbSdrh     sqlite3ExprCode(pParse, pItem->pExpr, target);
26779cbf3425Sdrh     target++;
2678268380caSdrh   }
2679f9b596ebSdrh   return n;
2680268380caSdrh }
2681268380caSdrh 
2682268380caSdrh /*
2683cce7d176Sdrh ** Generate code for a boolean expression such that a jump is made
2684cce7d176Sdrh ** to the label "dest" if the expression is true but execution
2685cce7d176Sdrh ** continues straight thru if the expression is false.
2686f5905aa7Sdrh **
2687f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false), then
268835573356Sdrh ** take the jump if the jumpIfNull flag is SQLITE_JUMPIFNULL.
2689f2bc013cSdrh **
2690f2bc013cSdrh ** This code depends on the fact that certain token values (ex: TK_EQ)
2691f2bc013cSdrh ** are the same as opcode values (ex: OP_Eq) that implement the corresponding
2692f2bc013cSdrh ** operation.  Special comments in vdbe.c and the mkopcodeh.awk script in
2693f2bc013cSdrh ** the make process cause these values to align.  Assert()s in the code
2694f2bc013cSdrh ** below verify that the numbers are aligned correctly.
2695cce7d176Sdrh */
26964adee20fSdanielk1977 void sqlite3ExprIfTrue(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
2697cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
2698cce7d176Sdrh   int op = 0;
26992dcef11bSdrh   int regFree1 = 0;
27002dcef11bSdrh   int regFree2 = 0;
27012dcef11bSdrh   int r1, r2;
27022dcef11bSdrh 
270335573356Sdrh   assert( jumpIfNull==SQLITE_JUMPIFNULL || jumpIfNull==0 );
2704daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
2705f2bc013cSdrh   op = pExpr->op;
2706f2bc013cSdrh   switch( op ){
2707cce7d176Sdrh     case TK_AND: {
27084adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
270935573356Sdrh       sqlite3ExprIfFalse(pParse, pExpr->pLeft, d2,jumpIfNull^SQLITE_JUMPIFNULL);
2710e55cbd72Sdrh       pParse->disableColCache++;
27114adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
2712e55cbd72Sdrh       pParse->disableColCache--;
27134adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
2714cce7d176Sdrh       break;
2715cce7d176Sdrh     }
2716cce7d176Sdrh     case TK_OR: {
27174adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
2718e55cbd72Sdrh       pParse->disableColCache++;
27194adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pRight, dest, jumpIfNull);
2720e55cbd72Sdrh       pParse->disableColCache--;
2721cce7d176Sdrh       break;
2722cce7d176Sdrh     }
2723cce7d176Sdrh     case TK_NOT: {
27244adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
2725cce7d176Sdrh       break;
2726cce7d176Sdrh     }
2727cce7d176Sdrh     case TK_LT:
2728cce7d176Sdrh     case TK_LE:
2729cce7d176Sdrh     case TK_GT:
2730cce7d176Sdrh     case TK_GE:
2731cce7d176Sdrh     case TK_NE:
27320ac65892Sdrh     case TK_EQ: {
2733f2bc013cSdrh       assert( TK_LT==OP_Lt );
2734f2bc013cSdrh       assert( TK_LE==OP_Le );
2735f2bc013cSdrh       assert( TK_GT==OP_Gt );
2736f2bc013cSdrh       assert( TK_GE==OP_Ge );
2737f2bc013cSdrh       assert( TK_EQ==OP_Eq );
2738f2bc013cSdrh       assert( TK_NE==OP_Ne );
2739*da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
2740*da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
274135573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
27422dcef11bSdrh                   r1, r2, dest, jumpIfNull);
2743cce7d176Sdrh       break;
2744cce7d176Sdrh     }
2745cce7d176Sdrh     case TK_ISNULL:
2746cce7d176Sdrh     case TK_NOTNULL: {
2747f2bc013cSdrh       assert( TK_ISNULL==OP_IsNull );
2748f2bc013cSdrh       assert( TK_NOTNULL==OP_NotNull );
27492dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
27502dcef11bSdrh       sqlite3VdbeAddOp2(v, op, r1, dest);
2751cce7d176Sdrh       break;
2752cce7d176Sdrh     }
2753fef5208cSdrh     case TK_BETWEEN: {
27542dcef11bSdrh       /*    x BETWEEN y AND z
27550202b29eSdanielk1977       **
27562dcef11bSdrh       ** Is equivalent to
27572dcef11bSdrh       **
27582dcef11bSdrh       **    x>=y AND x<=z
27592dcef11bSdrh       **
27602dcef11bSdrh       ** Code it as such, taking care to do the common subexpression
27612dcef11bSdrh       ** elementation of x.
27620202b29eSdanielk1977       */
27632dcef11bSdrh       Expr exprAnd;
27642dcef11bSdrh       Expr compLeft;
27652dcef11bSdrh       Expr compRight;
27662dcef11bSdrh       Expr exprX;
27670202b29eSdanielk1977 
27682dcef11bSdrh       exprX = *pExpr->pLeft;
27692dcef11bSdrh       exprAnd.op = TK_AND;
27702dcef11bSdrh       exprAnd.pLeft = &compLeft;
27712dcef11bSdrh       exprAnd.pRight = &compRight;
27722dcef11bSdrh       compLeft.op = TK_GE;
27732dcef11bSdrh       compLeft.pLeft = &exprX;
27742dcef11bSdrh       compLeft.pRight = pExpr->pList->a[0].pExpr;
27752dcef11bSdrh       compRight.op = TK_LE;
27762dcef11bSdrh       compRight.pLeft = &exprX;
27772dcef11bSdrh       compRight.pRight = pExpr->pList->a[1].pExpr;
27782dcef11bSdrh       exprX.iTable = sqlite3ExprCodeTemp(pParse, &exprX, &regFree1);
27792dcef11bSdrh       exprX.op = TK_REGISTER;
27802dcef11bSdrh       sqlite3ExprIfTrue(pParse, &exprAnd, dest, jumpIfNull);
2781fef5208cSdrh       break;
2782fef5208cSdrh     }
2783cce7d176Sdrh     default: {
27842dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr, &regFree1);
27852dcef11bSdrh       sqlite3VdbeAddOp3(v, OP_If, r1, dest, jumpIfNull!=0);
2786cce7d176Sdrh       break;
2787cce7d176Sdrh     }
2788cce7d176Sdrh   }
27892dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
27902dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
2791cce7d176Sdrh }
2792cce7d176Sdrh 
2793cce7d176Sdrh /*
279466b89c8fSdrh ** Generate code for a boolean expression such that a jump is made
2795cce7d176Sdrh ** to the label "dest" if the expression is false but execution
2796cce7d176Sdrh ** continues straight thru if the expression is true.
2797f5905aa7Sdrh **
2798f5905aa7Sdrh ** If the expression evaluates to NULL (neither true nor false) then
279935573356Sdrh ** jump if jumpIfNull is SQLITE_JUMPIFNULL or fall through if jumpIfNull
280035573356Sdrh ** is 0.
2801cce7d176Sdrh */
28024adee20fSdanielk1977 void sqlite3ExprIfFalse(Parse *pParse, Expr *pExpr, int dest, int jumpIfNull){
2803cce7d176Sdrh   Vdbe *v = pParse->pVdbe;
2804cce7d176Sdrh   int op = 0;
28052dcef11bSdrh   int regFree1 = 0;
28062dcef11bSdrh   int regFree2 = 0;
28072dcef11bSdrh   int r1, r2;
28082dcef11bSdrh 
280935573356Sdrh   assert( jumpIfNull==SQLITE_JUMPIFNULL || jumpIfNull==0 );
2810daffd0e5Sdrh   if( v==0 || pExpr==0 ) return;
2811f2bc013cSdrh 
2812f2bc013cSdrh   /* The value of pExpr->op and op are related as follows:
2813f2bc013cSdrh   **
2814f2bc013cSdrh   **       pExpr->op            op
2815f2bc013cSdrh   **       ---------          ----------
2816f2bc013cSdrh   **       TK_ISNULL          OP_NotNull
2817f2bc013cSdrh   **       TK_NOTNULL         OP_IsNull
2818f2bc013cSdrh   **       TK_NE              OP_Eq
2819f2bc013cSdrh   **       TK_EQ              OP_Ne
2820f2bc013cSdrh   **       TK_GT              OP_Le
2821f2bc013cSdrh   **       TK_LE              OP_Gt
2822f2bc013cSdrh   **       TK_GE              OP_Lt
2823f2bc013cSdrh   **       TK_LT              OP_Ge
2824f2bc013cSdrh   **
2825f2bc013cSdrh   ** For other values of pExpr->op, op is undefined and unused.
2826f2bc013cSdrh   ** The value of TK_ and OP_ constants are arranged such that we
2827f2bc013cSdrh   ** can compute the mapping above using the following expression.
2828f2bc013cSdrh   ** Assert()s verify that the computation is correct.
2829f2bc013cSdrh   */
2830f2bc013cSdrh   op = ((pExpr->op+(TK_ISNULL&1))^1)-(TK_ISNULL&1);
2831f2bc013cSdrh 
2832f2bc013cSdrh   /* Verify correct alignment of TK_ and OP_ constants
2833f2bc013cSdrh   */
2834f2bc013cSdrh   assert( pExpr->op!=TK_ISNULL || op==OP_NotNull );
2835f2bc013cSdrh   assert( pExpr->op!=TK_NOTNULL || op==OP_IsNull );
2836f2bc013cSdrh   assert( pExpr->op!=TK_NE || op==OP_Eq );
2837f2bc013cSdrh   assert( pExpr->op!=TK_EQ || op==OP_Ne );
2838f2bc013cSdrh   assert( pExpr->op!=TK_LT || op==OP_Ge );
2839f2bc013cSdrh   assert( pExpr->op!=TK_LE || op==OP_Gt );
2840f2bc013cSdrh   assert( pExpr->op!=TK_GT || op==OP_Le );
2841f2bc013cSdrh   assert( pExpr->op!=TK_GE || op==OP_Lt );
2842f2bc013cSdrh 
2843cce7d176Sdrh   switch( pExpr->op ){
2844cce7d176Sdrh     case TK_AND: {
28454adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pLeft, dest, jumpIfNull);
2846e55cbd72Sdrh       pParse->disableColCache++;
28474adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
2848e55cbd72Sdrh       pParse->disableColCache--;
2849cce7d176Sdrh       break;
2850cce7d176Sdrh     }
2851cce7d176Sdrh     case TK_OR: {
28524adee20fSdanielk1977       int d2 = sqlite3VdbeMakeLabel(v);
285335573356Sdrh       sqlite3ExprIfTrue(pParse, pExpr->pLeft, d2, jumpIfNull^SQLITE_JUMPIFNULL);
2854e55cbd72Sdrh       pParse->disableColCache++;
28554adee20fSdanielk1977       sqlite3ExprIfFalse(pParse, pExpr->pRight, dest, jumpIfNull);
2856e55cbd72Sdrh       pParse->disableColCache--;
28574adee20fSdanielk1977       sqlite3VdbeResolveLabel(v, d2);
2858cce7d176Sdrh       break;
2859cce7d176Sdrh     }
2860cce7d176Sdrh     case TK_NOT: {
28614adee20fSdanielk1977       sqlite3ExprIfTrue(pParse, pExpr->pLeft, dest, jumpIfNull);
2862cce7d176Sdrh       break;
2863cce7d176Sdrh     }
2864cce7d176Sdrh     case TK_LT:
2865cce7d176Sdrh     case TK_LE:
2866cce7d176Sdrh     case TK_GT:
2867cce7d176Sdrh     case TK_GE:
2868cce7d176Sdrh     case TK_NE:
2869cce7d176Sdrh     case TK_EQ: {
2870*da250ea5Sdrh       codeCompareOperands(pParse, pExpr->pLeft, &r1, &regFree1,
2871*da250ea5Sdrh                                   pExpr->pRight, &r2, &regFree2);
287235573356Sdrh       codeCompare(pParse, pExpr->pLeft, pExpr->pRight, op,
28732dcef11bSdrh                   r1, r2, dest, jumpIfNull);
2874cce7d176Sdrh       break;
2875cce7d176Sdrh     }
2876cce7d176Sdrh     case TK_ISNULL:
2877cce7d176Sdrh     case TK_NOTNULL: {
28782dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr->pLeft, &regFree1);
28792dcef11bSdrh       sqlite3VdbeAddOp2(v, op, r1, dest);
2880cce7d176Sdrh       break;
2881cce7d176Sdrh     }
2882fef5208cSdrh     case TK_BETWEEN: {
28832dcef11bSdrh       /*    x BETWEEN y AND z
28840202b29eSdanielk1977       **
28852dcef11bSdrh       ** Is equivalent to
28862dcef11bSdrh       **
28872dcef11bSdrh       **    x>=y AND x<=z
28882dcef11bSdrh       **
28892dcef11bSdrh       ** Code it as such, taking care to do the common subexpression
28902dcef11bSdrh       ** elementation of x.
28910202b29eSdanielk1977       */
28922dcef11bSdrh       Expr exprAnd;
28932dcef11bSdrh       Expr compLeft;
28942dcef11bSdrh       Expr compRight;
28952dcef11bSdrh       Expr exprX;
2896be5c89acSdrh 
28972dcef11bSdrh       exprX = *pExpr->pLeft;
28982dcef11bSdrh       exprAnd.op = TK_AND;
28992dcef11bSdrh       exprAnd.pLeft = &compLeft;
29002dcef11bSdrh       exprAnd.pRight = &compRight;
29012dcef11bSdrh       compLeft.op = TK_GE;
29022dcef11bSdrh       compLeft.pLeft = &exprX;
29032dcef11bSdrh       compLeft.pRight = pExpr->pList->a[0].pExpr;
29042dcef11bSdrh       compRight.op = TK_LE;
29052dcef11bSdrh       compRight.pLeft = &exprX;
29062dcef11bSdrh       compRight.pRight = pExpr->pList->a[1].pExpr;
29072dcef11bSdrh       exprX.iTable = sqlite3ExprCodeTemp(pParse, &exprX, &regFree1);
29082dcef11bSdrh       exprX.op = TK_REGISTER;
29092dcef11bSdrh       sqlite3ExprIfFalse(pParse, &exprAnd, dest, jumpIfNull);
2910fef5208cSdrh       break;
2911fef5208cSdrh     }
2912cce7d176Sdrh     default: {
29132dcef11bSdrh       r1 = sqlite3ExprCodeTemp(pParse, pExpr, &regFree1);
29142dcef11bSdrh       sqlite3VdbeAddOp3(v, OP_IfNot, r1, dest, jumpIfNull!=0);
2915cce7d176Sdrh       break;
2916cce7d176Sdrh     }
2917cce7d176Sdrh   }
29182dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree1);
29192dcef11bSdrh   sqlite3ReleaseTempReg(pParse, regFree2);
2920cce7d176Sdrh }
29212282792aSdrh 
29222282792aSdrh /*
29232282792aSdrh ** Do a deep comparison of two expression trees.  Return TRUE (non-zero)
29242282792aSdrh ** if they are identical and return FALSE if they differ in any way.
2925d40aab0eSdrh **
2926d40aab0eSdrh ** Sometimes this routine will return FALSE even if the two expressions
2927d40aab0eSdrh ** really are equivalent.  If we cannot prove that the expressions are
2928d40aab0eSdrh ** identical, we return FALSE just to be safe.  So if this routine
2929d40aab0eSdrh ** returns false, then you do not really know for certain if the two
2930d40aab0eSdrh ** expressions are the same.  But if you get a TRUE return, then you
2931d40aab0eSdrh ** can be sure the expressions are the same.  In the places where
2932d40aab0eSdrh ** this routine is used, it does not hurt to get an extra FALSE - that
2933d40aab0eSdrh ** just might result in some slightly slower code.  But returning
2934d40aab0eSdrh ** an incorrect TRUE could lead to a malfunction.
29352282792aSdrh */
29364adee20fSdanielk1977 int sqlite3ExprCompare(Expr *pA, Expr *pB){
29372282792aSdrh   int i;
29384b202ae2Sdanielk1977   if( pA==0||pB==0 ){
29394b202ae2Sdanielk1977     return pB==pA;
29402282792aSdrh   }
29412282792aSdrh   if( pA->op!=pB->op ) return 0;
2942fd357974Sdrh   if( (pA->flags & EP_Distinct)!=(pB->flags & EP_Distinct) ) return 0;
29434adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pLeft, pB->pLeft) ) return 0;
29444adee20fSdanielk1977   if( !sqlite3ExprCompare(pA->pRight, pB->pRight) ) return 0;
29452282792aSdrh   if( pA->pList ){
29462282792aSdrh     if( pB->pList==0 ) return 0;
29472282792aSdrh     if( pA->pList->nExpr!=pB->pList->nExpr ) return 0;
29482282792aSdrh     for(i=0; i<pA->pList->nExpr; i++){
29494adee20fSdanielk1977       if( !sqlite3ExprCompare(pA->pList->a[i].pExpr, pB->pList->a[i].pExpr) ){
29502282792aSdrh         return 0;
29512282792aSdrh       }
29522282792aSdrh     }
29532282792aSdrh   }else if( pB->pList ){
29542282792aSdrh     return 0;
29552282792aSdrh   }
29562282792aSdrh   if( pA->pSelect || pB->pSelect ) return 0;
29572f2c01e5Sdrh   if( pA->iTable!=pB->iTable || pA->iColumn!=pB->iColumn ) return 0;
2958dd73521bSdrh   if( pA->op!=TK_COLUMN && pA->token.z ){
29592282792aSdrh     if( pB->token.z==0 ) return 0;
29606977fea8Sdrh     if( pB->token.n!=pA->token.n ) return 0;
29612646da7eSdrh     if( sqlite3StrNICmp((char*)pA->token.z,(char*)pB->token.z,pB->token.n)!=0 ){
29622646da7eSdrh       return 0;
29632646da7eSdrh     }
29642282792aSdrh   }
29652282792aSdrh   return 1;
29662282792aSdrh }
29672282792aSdrh 
296813449892Sdrh 
29692282792aSdrh /*
297013449892Sdrh ** Add a new element to the pAggInfo->aCol[] array.  Return the index of
297113449892Sdrh ** the new element.  Return a negative number if malloc fails.
29722282792aSdrh */
297317435752Sdrh static int addAggInfoColumn(sqlite3 *db, AggInfo *pInfo){
297413449892Sdrh   int i;
2975cf643729Sdrh   pInfo->aCol = sqlite3ArrayAllocate(
297617435752Sdrh        db,
2977cf643729Sdrh        pInfo->aCol,
2978cf643729Sdrh        sizeof(pInfo->aCol[0]),
2979cf643729Sdrh        3,
2980cf643729Sdrh        &pInfo->nColumn,
2981cf643729Sdrh        &pInfo->nColumnAlloc,
2982cf643729Sdrh        &i
2983cf643729Sdrh   );
298413449892Sdrh   return i;
29852282792aSdrh }
298613449892Sdrh 
298713449892Sdrh /*
298813449892Sdrh ** Add a new element to the pAggInfo->aFunc[] array.  Return the index of
298913449892Sdrh ** the new element.  Return a negative number if malloc fails.
299013449892Sdrh */
299117435752Sdrh static int addAggInfoFunc(sqlite3 *db, AggInfo *pInfo){
299213449892Sdrh   int i;
2993cf643729Sdrh   pInfo->aFunc = sqlite3ArrayAllocate(
299417435752Sdrh        db,
2995cf643729Sdrh        pInfo->aFunc,
2996cf643729Sdrh        sizeof(pInfo->aFunc[0]),
2997cf643729Sdrh        3,
2998cf643729Sdrh        &pInfo->nFunc,
2999cf643729Sdrh        &pInfo->nFuncAlloc,
3000cf643729Sdrh        &i
3001cf643729Sdrh   );
300213449892Sdrh   return i;
30032282792aSdrh }
30042282792aSdrh 
30052282792aSdrh /*
3006626a879aSdrh ** This is an xFunc for walkExprTree() used to implement
3007626a879aSdrh ** sqlite3ExprAnalyzeAggregates().  See sqlite3ExprAnalyzeAggregates
3008626a879aSdrh ** for additional information.
30092282792aSdrh **
3010626a879aSdrh ** This routine analyzes the aggregate function at pExpr.
30112282792aSdrh */
3012626a879aSdrh static int analyzeAggregate(void *pArg, Expr *pExpr){
30132282792aSdrh   int i;
3014a58fdfb1Sdanielk1977   NameContext *pNC = (NameContext *)pArg;
3015a58fdfb1Sdanielk1977   Parse *pParse = pNC->pParse;
3016a58fdfb1Sdanielk1977   SrcList *pSrcList = pNC->pSrcList;
301713449892Sdrh   AggInfo *pAggInfo = pNC->pAggInfo;
301813449892Sdrh 
30192282792aSdrh   switch( pExpr->op ){
302089c69d00Sdrh     case TK_AGG_COLUMN:
3021967e8b73Sdrh     case TK_COLUMN: {
302213449892Sdrh       /* Check to see if the column is in one of the tables in the FROM
302313449892Sdrh       ** clause of the aggregate query */
302413449892Sdrh       if( pSrcList ){
302513449892Sdrh         struct SrcList_item *pItem = pSrcList->a;
302613449892Sdrh         for(i=0; i<pSrcList->nSrc; i++, pItem++){
302713449892Sdrh           struct AggInfo_col *pCol;
302813449892Sdrh           if( pExpr->iTable==pItem->iCursor ){
302913449892Sdrh             /* If we reach this point, it means that pExpr refers to a table
303013449892Sdrh             ** that is in the FROM clause of the aggregate query.
303113449892Sdrh             **
303213449892Sdrh             ** Make an entry for the column in pAggInfo->aCol[] if there
303313449892Sdrh             ** is not an entry there already.
303413449892Sdrh             */
30357f906d63Sdrh             int k;
303613449892Sdrh             pCol = pAggInfo->aCol;
30377f906d63Sdrh             for(k=0; k<pAggInfo->nColumn; k++, pCol++){
303813449892Sdrh               if( pCol->iTable==pExpr->iTable &&
303913449892Sdrh                   pCol->iColumn==pExpr->iColumn ){
30402282792aSdrh                 break;
30412282792aSdrh               }
30422282792aSdrh             }
30431e536953Sdanielk1977             if( (k>=pAggInfo->nColumn)
30441e536953Sdanielk1977              && (k = addAggInfoColumn(pParse->db, pAggInfo))>=0
30451e536953Sdanielk1977             ){
30467f906d63Sdrh               pCol = &pAggInfo->aCol[k];
30470817d0dfSdanielk1977               pCol->pTab = pExpr->pTab;
304813449892Sdrh               pCol->iTable = pExpr->iTable;
304913449892Sdrh               pCol->iColumn = pExpr->iColumn;
30500a07c107Sdrh               pCol->iMem = ++pParse->nMem;
305113449892Sdrh               pCol->iSorterColumn = -1;
30525774b806Sdrh               pCol->pExpr = pExpr;
305313449892Sdrh               if( pAggInfo->pGroupBy ){
305413449892Sdrh                 int j, n;
305513449892Sdrh                 ExprList *pGB = pAggInfo->pGroupBy;
305613449892Sdrh                 struct ExprList_item *pTerm = pGB->a;
305713449892Sdrh                 n = pGB->nExpr;
305813449892Sdrh                 for(j=0; j<n; j++, pTerm++){
305913449892Sdrh                   Expr *pE = pTerm->pExpr;
306013449892Sdrh                   if( pE->op==TK_COLUMN && pE->iTable==pExpr->iTable &&
306113449892Sdrh                       pE->iColumn==pExpr->iColumn ){
306213449892Sdrh                     pCol->iSorterColumn = j;
306313449892Sdrh                     break;
30642282792aSdrh                   }
306513449892Sdrh                 }
306613449892Sdrh               }
306713449892Sdrh               if( pCol->iSorterColumn<0 ){
306813449892Sdrh                 pCol->iSorterColumn = pAggInfo->nSortingColumn++;
306913449892Sdrh               }
307013449892Sdrh             }
307113449892Sdrh             /* There is now an entry for pExpr in pAggInfo->aCol[] (either
307213449892Sdrh             ** because it was there before or because we just created it).
307313449892Sdrh             ** Convert the pExpr to be a TK_AGG_COLUMN referring to that
307413449892Sdrh             ** pAggInfo->aCol[] entry.
307513449892Sdrh             */
307613449892Sdrh             pExpr->pAggInfo = pAggInfo;
307713449892Sdrh             pExpr->op = TK_AGG_COLUMN;
30787f906d63Sdrh             pExpr->iAgg = k;
307913449892Sdrh             break;
308013449892Sdrh           } /* endif pExpr->iTable==pItem->iCursor */
308113449892Sdrh         } /* end loop over pSrcList */
3082a58fdfb1Sdanielk1977       }
3083626a879aSdrh       return 1;
30842282792aSdrh     }
30852282792aSdrh     case TK_AGG_FUNCTION: {
308613449892Sdrh       /* The pNC->nDepth==0 test causes aggregate functions in subqueries
308713449892Sdrh       ** to be ignored */
3088a58fdfb1Sdanielk1977       if( pNC->nDepth==0 ){
308913449892Sdrh         /* Check to see if pExpr is a duplicate of another aggregate
309013449892Sdrh         ** function that is already in the pAggInfo structure
309113449892Sdrh         */
309213449892Sdrh         struct AggInfo_func *pItem = pAggInfo->aFunc;
309313449892Sdrh         for(i=0; i<pAggInfo->nFunc; i++, pItem++){
309413449892Sdrh           if( sqlite3ExprCompare(pItem->pExpr, pExpr) ){
30952282792aSdrh             break;
30962282792aSdrh           }
30972282792aSdrh         }
309813449892Sdrh         if( i>=pAggInfo->nFunc ){
309913449892Sdrh           /* pExpr is original.  Make a new entry in pAggInfo->aFunc[]
310013449892Sdrh           */
310114db2665Sdanielk1977           u8 enc = ENC(pParse->db);
31021e536953Sdanielk1977           i = addAggInfoFunc(pParse->db, pAggInfo);
310313449892Sdrh           if( i>=0 ){
310413449892Sdrh             pItem = &pAggInfo->aFunc[i];
310513449892Sdrh             pItem->pExpr = pExpr;
31060a07c107Sdrh             pItem->iMem = ++pParse->nMem;
310713449892Sdrh             pItem->pFunc = sqlite3FindFunction(pParse->db,
31082646da7eSdrh                    (char*)pExpr->token.z, pExpr->token.n,
3109d8123366Sdanielk1977                    pExpr->pList ? pExpr->pList->nExpr : 0, enc, 0);
3110fd357974Sdrh             if( pExpr->flags & EP_Distinct ){
3111fd357974Sdrh               pItem->iDistinct = pParse->nTab++;
3112fd357974Sdrh             }else{
3113fd357974Sdrh               pItem->iDistinct = -1;
3114fd357974Sdrh             }
31152282792aSdrh           }
311613449892Sdrh         }
311713449892Sdrh         /* Make pExpr point to the appropriate pAggInfo->aFunc[] entry
311813449892Sdrh         */
31192282792aSdrh         pExpr->iAgg = i;
312013449892Sdrh         pExpr->pAggInfo = pAggInfo;
3121626a879aSdrh         return 1;
31222282792aSdrh       }
31232282792aSdrh     }
3124a58fdfb1Sdanielk1977   }
312513449892Sdrh 
312613449892Sdrh   /* Recursively walk subqueries looking for TK_COLUMN nodes that need
312713449892Sdrh   ** to be changed to TK_AGG_COLUMN.  But increment nDepth so that
312813449892Sdrh   ** TK_AGG_FUNCTION nodes in subqueries will be unchanged.
312913449892Sdrh   */
3130a58fdfb1Sdanielk1977   if( pExpr->pSelect ){
3131a58fdfb1Sdanielk1977     pNC->nDepth++;
3132a58fdfb1Sdanielk1977     walkSelectExpr(pExpr->pSelect, analyzeAggregate, pNC);
3133a58fdfb1Sdanielk1977     pNC->nDepth--;
3134a58fdfb1Sdanielk1977   }
3135626a879aSdrh   return 0;
31362282792aSdrh }
3137626a879aSdrh 
3138626a879aSdrh /*
3139626a879aSdrh ** Analyze the given expression looking for aggregate functions and
3140626a879aSdrh ** for variables that need to be added to the pParse->aAgg[] array.
3141626a879aSdrh ** Make additional entries to the pParse->aAgg[] array as necessary.
3142626a879aSdrh **
3143626a879aSdrh ** This routine should only be called after the expression has been
3144626a879aSdrh ** analyzed by sqlite3ExprResolveNames().
3145626a879aSdrh */
3146d2b3e23bSdrh void sqlite3ExprAnalyzeAggregates(NameContext *pNC, Expr *pExpr){
3147a58fdfb1Sdanielk1977   walkExprTree(pExpr, analyzeAggregate, pNC);
31482282792aSdrh }
31495d9a4af9Sdrh 
31505d9a4af9Sdrh /*
31515d9a4af9Sdrh ** Call sqlite3ExprAnalyzeAggregates() for every expression in an
31525d9a4af9Sdrh ** expression list.  Return the number of errors.
31535d9a4af9Sdrh **
31545d9a4af9Sdrh ** If an error is found, the analysis is cut short.
31555d9a4af9Sdrh */
3156d2b3e23bSdrh void sqlite3ExprAnalyzeAggList(NameContext *pNC, ExprList *pList){
31575d9a4af9Sdrh   struct ExprList_item *pItem;
31585d9a4af9Sdrh   int i;
31595d9a4af9Sdrh   if( pList ){
3160d2b3e23bSdrh     for(pItem=pList->a, i=0; i<pList->nExpr; i++, pItem++){
3161d2b3e23bSdrh       sqlite3ExprAnalyzeAggregates(pNC, pItem->pExpr);
31625d9a4af9Sdrh     }
31635d9a4af9Sdrh   }
31645d9a4af9Sdrh }
3165892d3179Sdrh 
3166892d3179Sdrh /*
3167892d3179Sdrh ** Allocate or deallocate temporary use registers during code generation.
3168892d3179Sdrh */
3169892d3179Sdrh int sqlite3GetTempReg(Parse *pParse){
3170e55cbd72Sdrh   int i, r;
3171e55cbd72Sdrh   if( pParse->nTempReg==0 ){
3172892d3179Sdrh     return ++pParse->nMem;
3173892d3179Sdrh   }
3174e55cbd72Sdrh   for(i=0; i<pParse->nTempReg; i++){
3175e55cbd72Sdrh     r = pParse->aTempReg[i];
3176e55cbd72Sdrh     if( usedAsColumnCache(pParse, r, r) ) continue;
3177e55cbd72Sdrh   }
3178e55cbd72Sdrh   if( i>=pParse->nTempReg ){
3179e55cbd72Sdrh     return ++pParse->nMem;
3180e55cbd72Sdrh   }
3181e55cbd72Sdrh   while( i<pParse->nTempReg-1 ){
3182e55cbd72Sdrh     pParse->aTempReg[i] = pParse->aTempReg[i+1];
3183e55cbd72Sdrh   }
3184e55cbd72Sdrh   pParse->nTempReg--;
3185e55cbd72Sdrh   return r;
3186892d3179Sdrh }
3187892d3179Sdrh void sqlite3ReleaseTempReg(Parse *pParse, int iReg){
31882dcef11bSdrh   if( iReg && pParse->nTempReg<ArraySize(pParse->aTempReg) ){
31892dcef11bSdrh     assert( iReg>0 );
3190892d3179Sdrh     pParse->aTempReg[pParse->nTempReg++] = iReg;
3191892d3179Sdrh   }
3192892d3179Sdrh }
3193892d3179Sdrh 
3194892d3179Sdrh /*
3195892d3179Sdrh ** Allocate or deallocate a block of nReg consecutive registers
3196892d3179Sdrh */
3197892d3179Sdrh int sqlite3GetTempRange(Parse *pParse, int nReg){
3198e55cbd72Sdrh   int i, n;
3199892d3179Sdrh   i = pParse->iRangeReg;
3200e55cbd72Sdrh   n = pParse->nRangeReg;
3201e55cbd72Sdrh   if( nReg<=n && !usedAsColumnCache(pParse, i, i+n-1) ){
3202892d3179Sdrh     pParse->iRangeReg += nReg;
3203892d3179Sdrh     pParse->nRangeReg -= nReg;
3204892d3179Sdrh   }else{
3205892d3179Sdrh     i = pParse->nMem+1;
3206892d3179Sdrh     pParse->nMem += nReg;
3207892d3179Sdrh   }
3208892d3179Sdrh   return i;
3209892d3179Sdrh }
3210892d3179Sdrh void sqlite3ReleaseTempRange(Parse *pParse, int iReg, int nReg){
3211892d3179Sdrh   if( nReg>pParse->nRangeReg ){
3212892d3179Sdrh     pParse->nRangeReg = nReg;
3213892d3179Sdrh     pParse->iRangeReg = iReg;
3214892d3179Sdrh   }
3215892d3179Sdrh }
3216