xref: /sqlite-3.40.0/src/resolve.c (revision 181d75ef)
1 /*
2 ** 2008 August 18
3 **
4 ** The author disclaims copyright to this source code.  In place of
5 ** a legal notice, here is a blessing:
6 **
7 **    May you do good and not evil.
8 **    May you find forgiveness for yourself and forgive others.
9 **    May you share freely, never taking more than you give.
10 **
11 *************************************************************************
12 **
13 ** This file contains routines used for walking the parser tree and
14 ** resolve all identifiers by associating them with a particular
15 ** table and column.
16 */
17 #include "sqliteInt.h"
18 
19 /*
20 ** Magic table number to mean the EXCLUDED table in an UPSERT statement.
21 */
22 #define EXCLUDED_TABLE_NUMBER  2
23 
24 /*
25 ** Walk the expression tree pExpr and increase the aggregate function
26 ** depth (the Expr.op2 field) by N on every TK_AGG_FUNCTION node.
27 ** This needs to occur when copying a TK_AGG_FUNCTION node from an
28 ** outer query into an inner subquery.
29 **
30 ** incrAggFunctionDepth(pExpr,n) is the main routine.  incrAggDepth(..)
31 ** is a helper function - a callback for the tree walker.
32 **
33 ** See also the sqlite3WindowExtraAggFuncDepth() routine in window.c
34 */
35 static int incrAggDepth(Walker *pWalker, Expr *pExpr){
36   if( pExpr->op==TK_AGG_FUNCTION ) pExpr->op2 += pWalker->u.n;
37   return WRC_Continue;
38 }
39 static void incrAggFunctionDepth(Expr *pExpr, int N){
40   if( N>0 ){
41     Walker w;
42     memset(&w, 0, sizeof(w));
43     w.xExprCallback = incrAggDepth;
44     w.u.n = N;
45     sqlite3WalkExpr(&w, pExpr);
46   }
47 }
48 
49 /*
50 ** Turn the pExpr expression into an alias for the iCol-th column of the
51 ** result set in pEList.
52 **
53 ** If the reference is followed by a COLLATE operator, then make sure
54 ** the COLLATE operator is preserved.  For example:
55 **
56 **     SELECT a+b, c+d FROM t1 ORDER BY 1 COLLATE nocase;
57 **
58 ** Should be transformed into:
59 **
60 **     SELECT a+b, c+d FROM t1 ORDER BY (a+b) COLLATE nocase;
61 **
62 ** The nSubquery parameter specifies how many levels of subquery the
63 ** alias is removed from the original expression.  The usual value is
64 ** zero but it might be more if the alias is contained within a subquery
65 ** of the original expression.  The Expr.op2 field of TK_AGG_FUNCTION
66 ** structures must be increased by the nSubquery amount.
67 */
68 static void resolveAlias(
69   Parse *pParse,         /* Parsing context */
70   ExprList *pEList,      /* A result set */
71   int iCol,              /* A column in the result set.  0..pEList->nExpr-1 */
72   Expr *pExpr,           /* Transform this into an alias to the result set */
73   int nSubquery          /* Number of subqueries that the label is moving */
74 ){
75   Expr *pOrig;           /* The iCol-th column of the result set */
76   Expr *pDup;            /* Copy of pOrig */
77   sqlite3 *db;           /* The database connection */
78 
79   assert( iCol>=0 && iCol<pEList->nExpr );
80   pOrig = pEList->a[iCol].pExpr;
81   assert( pOrig!=0 );
82   db = pParse->db;
83   pDup = sqlite3ExprDup(db, pOrig, 0);
84   if( db->mallocFailed ){
85     sqlite3ExprDelete(db, pDup);
86     pDup = 0;
87   }else{
88     incrAggFunctionDepth(pDup, nSubquery);
89     if( pExpr->op==TK_COLLATE ){
90       assert( !ExprHasProperty(pExpr, EP_IntValue) );
91       pDup = sqlite3ExprAddCollateString(pParse, pDup, pExpr->u.zToken);
92     }
93 
94     /* Before calling sqlite3ExprDelete(), set the EP_Static flag. This
95     ** prevents ExprDelete() from deleting the Expr structure itself,
96     ** allowing it to be repopulated by the memcpy() on the following line.
97     ** The pExpr->u.zToken might point into memory that will be freed by the
98     ** sqlite3DbFree(db, pDup) on the last line of this block, so be sure to
99     ** make a copy of the token before doing the sqlite3DbFree().
100     */
101     ExprSetProperty(pExpr, EP_Static);
102     sqlite3ExprDelete(db, pExpr);
103     memcpy(pExpr, pDup, sizeof(*pExpr));
104     if( !ExprHasProperty(pExpr, EP_IntValue) && pExpr->u.zToken!=0 ){
105       assert( (pExpr->flags & (EP_Reduced|EP_TokenOnly))==0 );
106       pExpr->u.zToken = sqlite3DbStrDup(db, pExpr->u.zToken);
107       pExpr->flags |= EP_MemToken;
108     }
109     if( ExprHasProperty(pExpr, EP_WinFunc) ){
110       if( ALWAYS(pExpr->y.pWin!=0) ){
111         pExpr->y.pWin->pOwner = pExpr;
112       }
113     }
114     sqlite3DbFree(db, pDup);
115   }
116 }
117 
118 /*
119 ** Subqueries stores the original database, table and column names for their
120 ** result sets in ExprList.a[].zSpan, in the form "DATABASE.TABLE.COLUMN".
121 ** Check to see if the zSpan given to this routine matches the zDb, zTab,
122 ** and zCol.  If any of zDb, zTab, and zCol are NULL then those fields will
123 ** match anything.
124 */
125 int sqlite3MatchEName(
126   const struct ExprList_item *pItem,
127   const char *zCol,
128   const char *zTab,
129   const char *zDb
130 ){
131   int n;
132   const char *zSpan;
133   if( pItem->fg.eEName!=ENAME_TAB ) return 0;
134   zSpan = pItem->zEName;
135   for(n=0; ALWAYS(zSpan[n]) && zSpan[n]!='.'; n++){}
136   if( zDb && (sqlite3StrNICmp(zSpan, zDb, n)!=0 || zDb[n]!=0) ){
137     return 0;
138   }
139   zSpan += n+1;
140   for(n=0; ALWAYS(zSpan[n]) && zSpan[n]!='.'; n++){}
141   if( zTab && (sqlite3StrNICmp(zSpan, zTab, n)!=0 || zTab[n]!=0) ){
142     return 0;
143   }
144   zSpan += n+1;
145   if( zCol && sqlite3StrICmp(zSpan, zCol)!=0 ){
146     return 0;
147   }
148   return 1;
149 }
150 
151 /*
152 ** Return TRUE if the double-quoted string  mis-feature should be supported.
153 */
154 static int areDoubleQuotedStringsEnabled(sqlite3 *db, NameContext *pTopNC){
155   if( db->init.busy ) return 1;  /* Always support for legacy schemas */
156   if( pTopNC->ncFlags & NC_IsDDL ){
157     /* Currently parsing a DDL statement */
158     if( sqlite3WritableSchema(db) && (db->flags & SQLITE_DqsDML)!=0 ){
159       return 1;
160     }
161     return (db->flags & SQLITE_DqsDDL)!=0;
162   }else{
163     /* Currently parsing a DML statement */
164     return (db->flags & SQLITE_DqsDML)!=0;
165   }
166 }
167 
168 /*
169 ** The argument is guaranteed to be a non-NULL Expr node of type TK_COLUMN.
170 ** return the appropriate colUsed mask.
171 */
172 Bitmask sqlite3ExprColUsed(Expr *pExpr){
173   int n;
174   Table *pExTab;
175 
176   n = pExpr->iColumn;
177   assert( ExprUseYTab(pExpr) );
178   pExTab = pExpr->y.pTab;
179   assert( pExTab!=0 );
180   if( (pExTab->tabFlags & TF_HasGenerated)!=0
181    && (pExTab->aCol[n].colFlags & COLFLAG_GENERATED)!=0
182   ){
183     testcase( pExTab->nCol==BMS-1 );
184     testcase( pExTab->nCol==BMS );
185     return pExTab->nCol>=BMS ? ALLBITS : MASKBIT(pExTab->nCol)-1;
186   }else{
187     testcase( n==BMS-1 );
188     testcase( n==BMS );
189     if( n>=BMS ) n = BMS-1;
190     return ((Bitmask)1)<<n;
191   }
192 }
193 
194 /*
195 ** Create a new expression term for the column specified by pMatch and
196 ** iColumn.  Append this new expression term to the FULL JOIN Match set
197 ** in *ppList.  Create a new *ppList if this is the first term in the
198 ** set.
199 */
200 static void extendFJMatch(
201   Parse *pParse,          /* Parsing context */
202   ExprList **ppList,      /* ExprList to extend */
203   SrcItem *pMatch,        /* Source table containing the column */
204   i16 iColumn             /* The column number */
205 ){
206   Expr *pNew = sqlite3ExprAlloc(pParse->db, TK_COLUMN, 0, 0);
207   if( pNew ){
208     pNew->iTable = pMatch->iCursor;
209     pNew->iColumn = iColumn;
210     pNew->y.pTab = pMatch->pTab;
211     assert( (pMatch->fg.jointype & (JT_LEFT|JT_LTORJ))!=0 );
212     ExprSetProperty(pNew, EP_CanBeNull);
213     *ppList = sqlite3ExprListAppend(pParse, *ppList, pNew);
214   }
215 }
216 
217 /*
218 ** Given the name of a column of the form X.Y.Z or Y.Z or just Z, look up
219 ** that name in the set of source tables in pSrcList and make the pExpr
220 ** expression node refer back to that source column.  The following changes
221 ** are made to pExpr:
222 **
223 **    pExpr->iDb           Set the index in db->aDb[] of the database X
224 **                         (even if X is implied).
225 **    pExpr->iTable        Set to the cursor number for the table obtained
226 **                         from pSrcList.
227 **    pExpr->y.pTab        Points to the Table structure of X.Y (even if
228 **                         X and/or Y are implied.)
229 **    pExpr->iColumn       Set to the column number within the table.
230 **    pExpr->op            Set to TK_COLUMN.
231 **    pExpr->pLeft         Any expression this points to is deleted
232 **    pExpr->pRight        Any expression this points to is deleted.
233 **
234 ** The zDb variable is the name of the database (the "X").  This value may be
235 ** NULL meaning that name is of the form Y.Z or Z.  Any available database
236 ** can be used.  The zTable variable is the name of the table (the "Y").  This
237 ** value can be NULL if zDb is also NULL.  If zTable is NULL it
238 ** means that the form of the name is Z and that columns from any table
239 ** can be used.
240 **
241 ** If the name cannot be resolved unambiguously, leave an error message
242 ** in pParse and return WRC_Abort.  Return WRC_Prune on success.
243 */
244 static int lookupName(
245   Parse *pParse,       /* The parsing context */
246   const char *zDb,     /* Name of the database containing table, or NULL */
247   const char *zTab,    /* Name of table containing column, or NULL */
248   const char *zCol,    /* Name of the column. */
249   NameContext *pNC,    /* The name context used to resolve the name */
250   Expr *pExpr          /* Make this EXPR node point to the selected column */
251 ){
252   int i, j;                         /* Loop counters */
253   int cnt = 0;                      /* Number of matching column names */
254   int cntTab = 0;                   /* Number of matching table names */
255   int nSubquery = 0;                /* How many levels of subquery */
256   sqlite3 *db = pParse->db;         /* The database connection */
257   SrcItem *pItem;                   /* Use for looping over pSrcList items */
258   SrcItem *pMatch = 0;              /* The matching pSrcList item */
259   NameContext *pTopNC = pNC;        /* First namecontext in the list */
260   Schema *pSchema = 0;              /* Schema of the expression */
261   int eNewExprOp = TK_COLUMN;       /* New value for pExpr->op on success */
262   Table *pTab = 0;                  /* Table holding the row */
263   Column *pCol;                     /* A column of pTab */
264   ExprList *pFJMatch = 0;           /* Matches for FULL JOIN .. USING */
265 
266   assert( pNC );     /* the name context cannot be NULL. */
267   assert( zCol );    /* The Z in X.Y.Z cannot be NULL */
268   assert( zDb==0 || zTab!=0 );
269   assert( !ExprHasProperty(pExpr, EP_TokenOnly|EP_Reduced) );
270 
271   /* Initialize the node to no-match */
272   pExpr->iTable = -1;
273   ExprSetVVAProperty(pExpr, EP_NoReduce);
274 
275   /* Translate the schema name in zDb into a pointer to the corresponding
276   ** schema.  If not found, pSchema will remain NULL and nothing will match
277   ** resulting in an appropriate error message toward the end of this routine
278   */
279   if( zDb ){
280     testcase( pNC->ncFlags & NC_PartIdx );
281     testcase( pNC->ncFlags & NC_IsCheck );
282     if( (pNC->ncFlags & (NC_PartIdx|NC_IsCheck))!=0 ){
283       /* Silently ignore database qualifiers inside CHECK constraints and
284       ** partial indices.  Do not raise errors because that might break
285       ** legacy and because it does not hurt anything to just ignore the
286       ** database name. */
287       zDb = 0;
288     }else{
289       for(i=0; i<db->nDb; i++){
290         assert( db->aDb[i].zDbSName );
291         if( sqlite3StrICmp(db->aDb[i].zDbSName,zDb)==0 ){
292           pSchema = db->aDb[i].pSchema;
293           break;
294         }
295       }
296       if( i==db->nDb && sqlite3StrICmp("main", zDb)==0 ){
297         /* This branch is taken when the main database has been renamed
298         ** using SQLITE_DBCONFIG_MAINDBNAME. */
299         pSchema = db->aDb[0].pSchema;
300         zDb = db->aDb[0].zDbSName;
301       }
302     }
303   }
304 
305   /* Start at the inner-most context and move outward until a match is found */
306   assert( pNC && cnt==0 );
307   do{
308     ExprList *pEList;
309     SrcList *pSrcList = pNC->pSrcList;
310 
311     if( pSrcList ){
312       for(i=0, pItem=pSrcList->a; i<pSrcList->nSrc; i++, pItem++){
313         u8 hCol;
314         pTab = pItem->pTab;
315         assert( pTab!=0 && pTab->zName!=0 );
316         assert( pTab->nCol>0 || pParse->nErr );
317         assert( pItem->fg.isNestedFrom == IsNestedFrom(pItem->pSelect) );
318         if( pItem->fg.isNestedFrom ){
319           /* In this case, pItem is a subquery that has been formed from a
320           ** parenthesized subset of the FROM clause terms.  Example:
321           **   .... FROM t1 LEFT JOIN (t2 RIGHT JOIN t3 USING(x)) USING(y) ...
322           **                          \_________________________/
323           **             This pItem -------------^
324           */
325           int hit = 0;
326           assert( pItem->pSelect!=0 );
327           pEList = pItem->pSelect->pEList;
328           assert( pEList!=0 );
329           assert( pEList->nExpr==pTab->nCol );
330           for(j=0; j<pEList->nExpr; j++){
331             if( !sqlite3MatchEName(&pEList->a[j], zCol, zTab, zDb) ){
332               continue;
333             }
334             if( cnt>0 ){
335               if( pItem->fg.isUsing==0
336                || sqlite3IdListIndex(pItem->u3.pUsing, zCol)<0
337               ){
338                 /* Two or more tables have the same column name which is
339                 ** not joined by USING.  This is an error.  Signal as much
340                 ** by clearing pFJMatch and letting cnt go above 1. */
341                 sqlite3ExprListDelete(db, pFJMatch);
342                 pFJMatch = 0;
343               }else
344               if( (pItem->fg.jointype & JT_RIGHT)==0 ){
345                 /* An INNER or LEFT JOIN.  Use the left-most table */
346                 continue;
347               }else
348               if( (pItem->fg.jointype & JT_LEFT)==0 ){
349                 /* A RIGHT JOIN.  Use the right-most table */
350                 cnt = 0;
351                 sqlite3ExprListDelete(db, pFJMatch);
352                 pFJMatch = 0;
353               }else{
354                 /* For a FULL JOIN, we must construct a coalesce() func */
355                 extendFJMatch(pParse, &pFJMatch, pMatch, pExpr->iColumn);
356               }
357             }
358             cnt++;
359             cntTab = 2;
360             pMatch = pItem;
361             pExpr->iColumn = j;
362             pEList->a[j].fg.bUsed = 1;
363             hit = 1;
364             if( pEList->a[j].fg.bUsingTerm ) break;
365           }
366           if( hit || zTab==0 ) continue;
367         }
368         assert( zDb==0 || zTab!=0 );
369         if( zTab ){
370           const char *zTabName;
371           if( zDb ){
372             if( pTab->pSchema!=pSchema ) continue;
373             if( pSchema==0 && strcmp(zDb,"*")!=0 ) continue;
374           }
375           zTabName = pItem->zAlias ? pItem->zAlias : pTab->zName;
376           assert( zTabName!=0 );
377           if( sqlite3StrICmp(zTabName, zTab)!=0 ){
378             continue;
379           }
380           assert( ExprUseYTab(pExpr) );
381           if( IN_RENAME_OBJECT && pItem->zAlias ){
382             sqlite3RenameTokenRemap(pParse, 0, (void*)&pExpr->y.pTab);
383           }
384         }
385         hCol = sqlite3StrIHash(zCol);
386         for(j=0, pCol=pTab->aCol; j<pTab->nCol; j++, pCol++){
387           if( pCol->hName==hCol
388            && sqlite3StrICmp(pCol->zCnName, zCol)==0
389           ){
390             if( cnt>0 ){
391               if( pItem->fg.isUsing==0
392                || sqlite3IdListIndex(pItem->u3.pUsing, zCol)<0
393               ){
394                 /* Two or more tables have the same column name which is
395                 ** not joined by USING.  This is an error.  Signal as much
396                 ** by clearing pFJMatch and letting cnt go above 1. */
397                 sqlite3ExprListDelete(db, pFJMatch);
398                 pFJMatch = 0;
399               }else
400               if( (pItem->fg.jointype & JT_RIGHT)==0 ){
401                 /* An INNER or LEFT JOIN.  Use the left-most table */
402                 continue;
403               }else
404               if( (pItem->fg.jointype & JT_LEFT)==0 ){
405                 /* A RIGHT JOIN.  Use the right-most table */
406                 cnt = 0;
407                 sqlite3ExprListDelete(db, pFJMatch);
408                 pFJMatch = 0;
409               }else{
410                 /* For a FULL JOIN, we must construct a coalesce() func */
411                 extendFJMatch(pParse, &pFJMatch, pMatch, pExpr->iColumn);
412               }
413             }
414             cnt++;
415             pMatch = pItem;
416             /* Substitute the rowid (column -1) for the INTEGER PRIMARY KEY */
417             pExpr->iColumn = j==pTab->iPKey ? -1 : (i16)j;
418             if( pItem->fg.isNestedFrom ){
419               sqlite3SrcItemColumnUsed(pItem, j);
420             }
421             break;
422           }
423         }
424         if( 0==cnt && VisibleRowid(pTab) ){
425           cntTab++;
426           pMatch = pItem;
427         }
428       }
429       if( pMatch ){
430         pExpr->iTable = pMatch->iCursor;
431         assert( ExprUseYTab(pExpr) );
432         pExpr->y.pTab = pMatch->pTab;
433         if( (pMatch->fg.jointype & (JT_LEFT|JT_LTORJ))!=0 ){
434           ExprSetProperty(pExpr, EP_CanBeNull);
435         }
436         pSchema = pExpr->y.pTab->pSchema;
437       }
438     } /* if( pSrcList ) */
439 
440 #if !defined(SQLITE_OMIT_TRIGGER) || !defined(SQLITE_OMIT_UPSERT)
441     /* If we have not already resolved the name, then maybe
442     ** it is a new.* or old.* trigger argument reference.  Or
443     ** maybe it is an excluded.* from an upsert.  Or maybe it is
444     ** a reference in the RETURNING clause to a table being modified.
445     */
446     if( cnt==0 && zDb==0 ){
447       pTab = 0;
448 #ifndef SQLITE_OMIT_TRIGGER
449       if( pParse->pTriggerTab!=0 ){
450         int op = pParse->eTriggerOp;
451         assert( op==TK_DELETE || op==TK_UPDATE || op==TK_INSERT );
452         if( pParse->bReturning ){
453           if( (pNC->ncFlags & NC_UBaseReg)!=0
454            && (zTab==0 || sqlite3StrICmp(zTab,pParse->pTriggerTab->zName)==0)
455           ){
456             pExpr->iTable = op!=TK_DELETE;
457             pTab = pParse->pTriggerTab;
458           }
459         }else if( op!=TK_DELETE && zTab && sqlite3StrICmp("new",zTab) == 0 ){
460           pExpr->iTable = 1;
461           pTab = pParse->pTriggerTab;
462         }else if( op!=TK_INSERT && zTab && sqlite3StrICmp("old",zTab)==0 ){
463           pExpr->iTable = 0;
464           pTab = pParse->pTriggerTab;
465         }
466       }
467 #endif /* SQLITE_OMIT_TRIGGER */
468 #ifndef SQLITE_OMIT_UPSERT
469       if( (pNC->ncFlags & NC_UUpsert)!=0 && zTab!=0 ){
470         Upsert *pUpsert = pNC->uNC.pUpsert;
471         if( pUpsert && sqlite3StrICmp("excluded",zTab)==0 ){
472           pTab = pUpsert->pUpsertSrc->a[0].pTab;
473           pExpr->iTable = EXCLUDED_TABLE_NUMBER;
474         }
475       }
476 #endif /* SQLITE_OMIT_UPSERT */
477 
478       if( pTab ){
479         int iCol;
480         u8 hCol = sqlite3StrIHash(zCol);
481         pSchema = pTab->pSchema;
482         cntTab++;
483         for(iCol=0, pCol=pTab->aCol; iCol<pTab->nCol; iCol++, pCol++){
484           if( pCol->hName==hCol
485            && sqlite3StrICmp(pCol->zCnName, zCol)==0
486           ){
487             if( iCol==pTab->iPKey ){
488               iCol = -1;
489             }
490             break;
491           }
492         }
493         if( iCol>=pTab->nCol && sqlite3IsRowid(zCol) && VisibleRowid(pTab) ){
494           /* IMP: R-51414-32910 */
495           iCol = -1;
496         }
497         if( iCol<pTab->nCol ){
498           cnt++;
499           pMatch = 0;
500 #ifndef SQLITE_OMIT_UPSERT
501           if( pExpr->iTable==EXCLUDED_TABLE_NUMBER ){
502             testcase( iCol==(-1) );
503             assert( ExprUseYTab(pExpr) );
504             if( IN_RENAME_OBJECT ){
505               pExpr->iColumn = iCol;
506               pExpr->y.pTab = pTab;
507               eNewExprOp = TK_COLUMN;
508             }else{
509               pExpr->iTable = pNC->uNC.pUpsert->regData +
510                  sqlite3TableColumnToStorage(pTab, iCol);
511               eNewExprOp = TK_REGISTER;
512             }
513           }else
514 #endif /* SQLITE_OMIT_UPSERT */
515           {
516             assert( ExprUseYTab(pExpr) );
517             pExpr->y.pTab = pTab;
518             if( pParse->bReturning ){
519               eNewExprOp = TK_REGISTER;
520               pExpr->op2 = TK_COLUMN;
521               pExpr->iTable = pNC->uNC.iBaseReg + (pTab->nCol+1)*pExpr->iTable +
522                  sqlite3TableColumnToStorage(pTab, iCol) + 1;
523             }else{
524               pExpr->iColumn = (i16)iCol;
525               eNewExprOp = TK_TRIGGER;
526 #ifndef SQLITE_OMIT_TRIGGER
527               if( iCol<0 ){
528                 pExpr->affExpr = SQLITE_AFF_INTEGER;
529               }else if( pExpr->iTable==0 ){
530                 testcase( iCol==31 );
531                 testcase( iCol==32 );
532                 pParse->oldmask |= (iCol>=32 ? 0xffffffff : (((u32)1)<<iCol));
533               }else{
534                 testcase( iCol==31 );
535                 testcase( iCol==32 );
536                 pParse->newmask |= (iCol>=32 ? 0xffffffff : (((u32)1)<<iCol));
537               }
538 #endif /* SQLITE_OMIT_TRIGGER */
539             }
540           }
541         }
542       }
543     }
544 #endif /* !defined(SQLITE_OMIT_TRIGGER) || !defined(SQLITE_OMIT_UPSERT) */
545 
546     /*
547     ** Perhaps the name is a reference to the ROWID
548     */
549     if( cnt==0
550      && cntTab==1
551      && pMatch
552      && (pNC->ncFlags & (NC_IdxExpr|NC_GenCol))==0
553      && sqlite3IsRowid(zCol)
554      && ALWAYS(VisibleRowid(pMatch->pTab))
555     ){
556       cnt = 1;
557       pExpr->iColumn = -1;
558       pExpr->affExpr = SQLITE_AFF_INTEGER;
559     }
560 
561     /*
562     ** If the input is of the form Z (not Y.Z or X.Y.Z) then the name Z
563     ** might refer to an result-set alias.  This happens, for example, when
564     ** we are resolving names in the WHERE clause of the following command:
565     **
566     **     SELECT a+b AS x FROM table WHERE x<10;
567     **
568     ** In cases like this, replace pExpr with a copy of the expression that
569     ** forms the result set entry ("a+b" in the example) and return immediately.
570     ** Note that the expression in the result set should have already been
571     ** resolved by the time the WHERE clause is resolved.
572     **
573     ** The ability to use an output result-set column in the WHERE, GROUP BY,
574     ** or HAVING clauses, or as part of a larger expression in the ORDER BY
575     ** clause is not standard SQL.  This is a (goofy) SQLite extension, that
576     ** is supported for backwards compatibility only. Hence, we issue a warning
577     ** on sqlite3_log() whenever the capability is used.
578     */
579     if( cnt==0
580      && (pNC->ncFlags & NC_UEList)!=0
581      && zTab==0
582     ){
583       pEList = pNC->uNC.pEList;
584       assert( pEList!=0 );
585       for(j=0; j<pEList->nExpr; j++){
586         char *zAs = pEList->a[j].zEName;
587         if( pEList->a[j].fg.eEName==ENAME_NAME
588          && sqlite3_stricmp(zAs, zCol)==0
589         ){
590           Expr *pOrig;
591           assert( pExpr->pLeft==0 && pExpr->pRight==0 );
592           assert( ExprUseXList(pExpr)==0 || pExpr->x.pList==0 );
593           assert( ExprUseXSelect(pExpr)==0 || pExpr->x.pSelect==0 );
594           pOrig = pEList->a[j].pExpr;
595           if( (pNC->ncFlags&NC_AllowAgg)==0 && ExprHasProperty(pOrig, EP_Agg) ){
596             sqlite3ErrorMsg(pParse, "misuse of aliased aggregate %s", zAs);
597             return WRC_Abort;
598           }
599           if( ExprHasProperty(pOrig, EP_Win)
600            && ((pNC->ncFlags&NC_AllowWin)==0 || pNC!=pTopNC )
601           ){
602             sqlite3ErrorMsg(pParse, "misuse of aliased window function %s",zAs);
603             return WRC_Abort;
604           }
605           if( sqlite3ExprVectorSize(pOrig)!=1 ){
606             sqlite3ErrorMsg(pParse, "row value misused");
607             return WRC_Abort;
608           }
609           resolveAlias(pParse, pEList, j, pExpr, nSubquery);
610           cnt = 1;
611           pMatch = 0;
612           assert( zTab==0 && zDb==0 );
613           if( IN_RENAME_OBJECT ){
614             sqlite3RenameTokenRemap(pParse, 0, (void*)pExpr);
615           }
616           goto lookupname_end;
617         }
618       }
619     }
620 
621     /* Advance to the next name context.  The loop will exit when either
622     ** we have a match (cnt>0) or when we run out of name contexts.
623     */
624     if( cnt ) break;
625     pNC = pNC->pNext;
626     nSubquery++;
627   }while( pNC );
628 
629 
630   /*
631   ** If X and Y are NULL (in other words if only the column name Z is
632   ** supplied) and the value of Z is enclosed in double-quotes, then
633   ** Z is a string literal if it doesn't match any column names.  In that
634   ** case, we need to return right away and not make any changes to
635   ** pExpr.
636   **
637   ** Because no reference was made to outer contexts, the pNC->nRef
638   ** fields are not changed in any context.
639   */
640   if( cnt==0 && zTab==0 ){
641     assert( pExpr->op==TK_ID );
642     if( ExprHasProperty(pExpr,EP_DblQuoted)
643      && areDoubleQuotedStringsEnabled(db, pTopNC)
644     ){
645       /* If a double-quoted identifier does not match any known column name,
646       ** then treat it as a string.
647       **
648       ** This hack was added in the early days of SQLite in a misguided attempt
649       ** to be compatible with MySQL 3.x, which used double-quotes for strings.
650       ** I now sorely regret putting in this hack. The effect of this hack is
651       ** that misspelled identifier names are silently converted into strings
652       ** rather than causing an error, to the frustration of countless
653       ** programmers. To all those frustrated programmers, my apologies.
654       **
655       ** Someday, I hope to get rid of this hack. Unfortunately there is
656       ** a huge amount of legacy SQL that uses it. So for now, we just
657       ** issue a warning.
658       */
659       sqlite3_log(SQLITE_WARNING,
660         "double-quoted string literal: \"%w\"", zCol);
661 #ifdef SQLITE_ENABLE_NORMALIZE
662       sqlite3VdbeAddDblquoteStr(db, pParse->pVdbe, zCol);
663 #endif
664       pExpr->op = TK_STRING;
665       memset(&pExpr->y, 0, sizeof(pExpr->y));
666       return WRC_Prune;
667     }
668     if( sqlite3ExprIdToTrueFalse(pExpr) ){
669       return WRC_Prune;
670     }
671   }
672 
673   /*
674   ** cnt==0 means there was not match.
675   ** cnt>1 means there were two or more matches.
676   **
677   ** cnt==0 is always an error.  cnt>1 is often an error, but might
678   ** be multiple matches for a NATURAL LEFT JOIN or a LEFT JOIN USING.
679   */
680   assert( pFJMatch==0 || cnt>0 );
681   assert( !ExprHasProperty(pExpr, EP_xIsSelect|EP_IntValue) );
682   if( cnt!=1 ){
683     const char *zErr;
684     if( pFJMatch ){
685       if( pFJMatch->nExpr==cnt-1 ){
686         if( ExprHasProperty(pExpr,EP_Leaf) ){
687           ExprClearProperty(pExpr,EP_Leaf);
688         }else{
689           sqlite3ExprDelete(db, pExpr->pLeft);
690           pExpr->pLeft = 0;
691           sqlite3ExprDelete(db, pExpr->pRight);
692           pExpr->pRight = 0;
693         }
694         extendFJMatch(pParse, &pFJMatch, pMatch, pExpr->iColumn);
695         pExpr->op = TK_FUNCTION;
696         pExpr->u.zToken = "coalesce";
697         pExpr->x.pList = pFJMatch;
698         cnt = 1;
699         goto lookupname_end;
700       }else{
701         sqlite3ExprListDelete(db, pFJMatch);
702         pFJMatch = 0;
703       }
704     }
705     zErr = cnt==0 ? "no such column" : "ambiguous column name";
706     if( zDb ){
707       sqlite3ErrorMsg(pParse, "%s: %s.%s.%s", zErr, zDb, zTab, zCol);
708     }else if( zTab ){
709       sqlite3ErrorMsg(pParse, "%s: %s.%s", zErr, zTab, zCol);
710     }else{
711       sqlite3ErrorMsg(pParse, "%s: %s", zErr, zCol);
712     }
713     sqlite3RecordErrorOffsetOfExpr(pParse->db, pExpr);
714     pParse->checkSchema = 1;
715     pTopNC->nNcErr++;
716   }
717   assert( pFJMatch==0 );
718 
719   /* Remove all substructure from pExpr */
720   if( !ExprHasProperty(pExpr,(EP_TokenOnly|EP_Leaf)) ){
721     sqlite3ExprDelete(db, pExpr->pLeft);
722     pExpr->pLeft = 0;
723     sqlite3ExprDelete(db, pExpr->pRight);
724     pExpr->pRight = 0;
725     ExprSetProperty(pExpr, EP_Leaf);
726   }
727 
728   /* If a column from a table in pSrcList is referenced, then record
729   ** this fact in the pSrcList.a[].colUsed bitmask.  Column 0 causes
730   ** bit 0 to be set.  Column 1 sets bit 1.  And so forth.  Bit 63 is
731   ** set if the 63rd or any subsequent column is used.
732   **
733   ** The colUsed mask is an optimization used to help determine if an
734   ** index is a covering index.  The correct answer is still obtained
735   ** if the mask contains extra set bits.  However, it is important to
736   ** avoid setting bits beyond the maximum column number of the table.
737   ** (See ticket [b92e5e8ec2cdbaa1]).
738   **
739   ** If a generated column is referenced, set bits for every column
740   ** of the table.
741   */
742   if( pExpr->iColumn>=0 && pMatch!=0 ){
743     pMatch->colUsed |= sqlite3ExprColUsed(pExpr);
744   }
745 
746   pExpr->op = eNewExprOp;
747 lookupname_end:
748   if( cnt==1 ){
749     assert( pNC!=0 );
750 #ifndef SQLITE_OMIT_AUTHORIZATION
751     if( pParse->db->xAuth
752      && (pExpr->op==TK_COLUMN || pExpr->op==TK_TRIGGER)
753     ){
754       sqlite3AuthRead(pParse, pExpr, pSchema, pNC->pSrcList);
755     }
756 #endif
757     /* Increment the nRef value on all name contexts from TopNC up to
758     ** the point where the name matched. */
759     for(;;){
760       assert( pTopNC!=0 );
761       pTopNC->nRef++;
762       if( pTopNC==pNC ) break;
763       pTopNC = pTopNC->pNext;
764     }
765     return WRC_Prune;
766   } else {
767     return WRC_Abort;
768   }
769 }
770 
771 /*
772 ** Allocate and return a pointer to an expression to load the column iCol
773 ** from datasource iSrc in SrcList pSrc.
774 */
775 Expr *sqlite3CreateColumnExpr(sqlite3 *db, SrcList *pSrc, int iSrc, int iCol){
776   Expr *p = sqlite3ExprAlloc(db, TK_COLUMN, 0, 0);
777   if( p ){
778     SrcItem *pItem = &pSrc->a[iSrc];
779     Table *pTab;
780     assert( ExprUseYTab(p) );
781     pTab = p->y.pTab = pItem->pTab;
782     p->iTable = pItem->iCursor;
783     if( p->y.pTab->iPKey==iCol ){
784       p->iColumn = -1;
785     }else{
786       p->iColumn = (ynVar)iCol;
787       if( (pTab->tabFlags & TF_HasGenerated)!=0
788        && (pTab->aCol[iCol].colFlags & COLFLAG_GENERATED)!=0
789       ){
790         testcase( pTab->nCol==63 );
791         testcase( pTab->nCol==64 );
792         pItem->colUsed = pTab->nCol>=64 ? ALLBITS : MASKBIT(pTab->nCol)-1;
793       }else{
794         testcase( iCol==BMS );
795         testcase( iCol==BMS-1 );
796         pItem->colUsed |= ((Bitmask)1)<<(iCol>=BMS ? BMS-1 : iCol);
797       }
798     }
799   }
800   return p;
801 }
802 
803 /*
804 ** Report an error that an expression is not valid for some set of
805 ** pNC->ncFlags values determined by validMask.
806 **
807 ** static void notValid(
808 **   Parse *pParse,       // Leave error message here
809 **   NameContext *pNC,    // The name context
810 **   const char *zMsg,    // Type of error
811 **   int validMask,       // Set of contexts for which prohibited
812 **   Expr *pExpr          // Invalidate this expression on error
813 ** ){...}
814 **
815 ** As an optimization, since the conditional is almost always false
816 ** (because errors are rare), the conditional is moved outside of the
817 ** function call using a macro.
818 */
819 static void notValidImpl(
820    Parse *pParse,       /* Leave error message here */
821    NameContext *pNC,    /* The name context */
822    const char *zMsg,    /* Type of error */
823    Expr *pExpr,         /* Invalidate this expression on error */
824    Expr *pError         /* Associate error with this expression */
825 ){
826   const char *zIn = "partial index WHERE clauses";
827   if( pNC->ncFlags & NC_IdxExpr )      zIn = "index expressions";
828 #ifndef SQLITE_OMIT_CHECK
829   else if( pNC->ncFlags & NC_IsCheck ) zIn = "CHECK constraints";
830 #endif
831 #ifndef SQLITE_OMIT_GENERATED_COLUMNS
832   else if( pNC->ncFlags & NC_GenCol ) zIn = "generated columns";
833 #endif
834   sqlite3ErrorMsg(pParse, "%s prohibited in %s", zMsg, zIn);
835   if( pExpr ) pExpr->op = TK_NULL;
836   sqlite3RecordErrorOffsetOfExpr(pParse->db, pError);
837 }
838 #define sqlite3ResolveNotValid(P,N,M,X,E,R) \
839   assert( ((X)&~(NC_IsCheck|NC_PartIdx|NC_IdxExpr|NC_GenCol))==0 ); \
840   if( ((N)->ncFlags & (X))!=0 ) notValidImpl(P,N,M,E,R);
841 
842 /*
843 ** Expression p should encode a floating point value between 1.0 and 0.0.
844 ** Return 1024 times this value.  Or return -1 if p is not a floating point
845 ** value between 1.0 and 0.0.
846 */
847 static int exprProbability(Expr *p){
848   double r = -1.0;
849   if( p->op!=TK_FLOAT ) return -1;
850   assert( !ExprHasProperty(p, EP_IntValue) );
851   sqlite3AtoF(p->u.zToken, &r, sqlite3Strlen30(p->u.zToken), SQLITE_UTF8);
852   assert( r>=0.0 );
853   if( r>1.0 ) return -1;
854   return (int)(r*134217728.0);
855 }
856 
857 /*
858 ** This routine is callback for sqlite3WalkExpr().
859 **
860 ** Resolve symbolic names into TK_COLUMN operators for the current
861 ** node in the expression tree.  Return 0 to continue the search down
862 ** the tree or 2 to abort the tree walk.
863 **
864 ** This routine also does error checking and name resolution for
865 ** function names.  The operator for aggregate functions is changed
866 ** to TK_AGG_FUNCTION.
867 */
868 static int resolveExprStep(Walker *pWalker, Expr *pExpr){
869   NameContext *pNC;
870   Parse *pParse;
871 
872   pNC = pWalker->u.pNC;
873   assert( pNC!=0 );
874   pParse = pNC->pParse;
875   assert( pParse==pWalker->pParse );
876 
877 #ifndef NDEBUG
878   if( pNC->pSrcList && pNC->pSrcList->nAlloc>0 ){
879     SrcList *pSrcList = pNC->pSrcList;
880     int i;
881     for(i=0; i<pNC->pSrcList->nSrc; i++){
882       assert( pSrcList->a[i].iCursor>=0 && pSrcList->a[i].iCursor<pParse->nTab);
883     }
884   }
885 #endif
886   switch( pExpr->op ){
887 
888     /* The special operator TK_ROW means use the rowid for the first
889     ** column in the FROM clause.  This is used by the LIMIT and ORDER BY
890     ** clause processing on UPDATE and DELETE statements, and by
891     ** UPDATE ... FROM statement processing.
892     */
893     case TK_ROW: {
894       SrcList *pSrcList = pNC->pSrcList;
895       SrcItem *pItem;
896       assert( pSrcList && pSrcList->nSrc>=1 );
897       pItem = pSrcList->a;
898       pExpr->op = TK_COLUMN;
899       assert( ExprUseYTab(pExpr) );
900       pExpr->y.pTab = pItem->pTab;
901       pExpr->iTable = pItem->iCursor;
902       pExpr->iColumn--;
903       pExpr->affExpr = SQLITE_AFF_INTEGER;
904       break;
905     }
906 
907     /* An optimization:  Attempt to convert
908     **
909     **      "expr IS NOT NULL"  -->  "TRUE"
910     **      "expr IS NULL"      -->  "FALSE"
911     **
912     ** if we can prove that "expr" is never NULL.  Call this the
913     ** "NOT NULL strength reduction optimization".
914     **
915     ** If this optimization occurs, also restore the NameContext ref-counts
916     ** to the state they where in before the "column" LHS expression was
917     ** resolved.  This prevents "column" from being counted as having been
918     ** referenced, which might prevent a SELECT from being erroneously
919     ** marked as correlated.
920     */
921     case TK_NOTNULL:
922     case TK_ISNULL: {
923       int anRef[8];
924       NameContext *p;
925       int i;
926       for(i=0, p=pNC; p && i<ArraySize(anRef); p=p->pNext, i++){
927         anRef[i] = p->nRef;
928       }
929       sqlite3WalkExpr(pWalker, pExpr->pLeft);
930       if( 0==sqlite3ExprCanBeNull(pExpr->pLeft) && !IN_RENAME_OBJECT ){
931         testcase( ExprHasProperty(pExpr, EP_OuterON) );
932         assert( !ExprHasProperty(pExpr, EP_IntValue) );
933         if( pExpr->op==TK_NOTNULL ){
934           pExpr->u.zToken = "true";
935           ExprSetProperty(pExpr, EP_IsTrue);
936         }else{
937           pExpr->u.zToken = "false";
938           ExprSetProperty(pExpr, EP_IsFalse);
939         }
940         pExpr->op = TK_TRUEFALSE;
941         for(i=0, p=pNC; p && i<ArraySize(anRef); p=p->pNext, i++){
942           p->nRef = anRef[i];
943         }
944         sqlite3ExprDelete(pParse->db, pExpr->pLeft);
945         pExpr->pLeft = 0;
946       }
947       return WRC_Prune;
948     }
949 
950     /* A column name:                    ID
951     ** Or table name and column name:    ID.ID
952     ** Or a database, table and column:  ID.ID.ID
953     **
954     ** The TK_ID and TK_OUT cases are combined so that there will only
955     ** be one call to lookupName().  Then the compiler will in-line
956     ** lookupName() for a size reduction and performance increase.
957     */
958     case TK_ID:
959     case TK_DOT: {
960       const char *zColumn;
961       const char *zTable;
962       const char *zDb;
963       Expr *pRight;
964 
965       if( pExpr->op==TK_ID ){
966         zDb = 0;
967         zTable = 0;
968         assert( !ExprHasProperty(pExpr, EP_IntValue) );
969         zColumn = pExpr->u.zToken;
970       }else{
971         Expr *pLeft = pExpr->pLeft;
972         testcase( pNC->ncFlags & NC_IdxExpr );
973         testcase( pNC->ncFlags & NC_GenCol );
974         sqlite3ResolveNotValid(pParse, pNC, "the \".\" operator",
975                                NC_IdxExpr|NC_GenCol, 0, pExpr);
976         pRight = pExpr->pRight;
977         if( pRight->op==TK_ID ){
978           zDb = 0;
979         }else{
980           assert( pRight->op==TK_DOT );
981           assert( !ExprHasProperty(pRight, EP_IntValue) );
982           zDb = pLeft->u.zToken;
983           pLeft = pRight->pLeft;
984           pRight = pRight->pRight;
985         }
986         assert( ExprUseUToken(pLeft) && ExprUseUToken(pRight) );
987         zTable = pLeft->u.zToken;
988         zColumn = pRight->u.zToken;
989         assert( ExprUseYTab(pExpr) );
990         if( IN_RENAME_OBJECT ){
991           sqlite3RenameTokenRemap(pParse, (void*)pExpr, (void*)pRight);
992           sqlite3RenameTokenRemap(pParse, (void*)&pExpr->y.pTab, (void*)pLeft);
993         }
994       }
995       return lookupName(pParse, zDb, zTable, zColumn, pNC, pExpr);
996     }
997 
998     /* Resolve function names
999     */
1000     case TK_FUNCTION: {
1001       ExprList *pList = pExpr->x.pList;    /* The argument list */
1002       int n = pList ? pList->nExpr : 0;    /* Number of arguments */
1003       int no_such_func = 0;       /* True if no such function exists */
1004       int wrong_num_args = 0;     /* True if wrong number of arguments */
1005       int is_agg = 0;             /* True if is an aggregate function */
1006       const char *zId;            /* The function name. */
1007       FuncDef *pDef;              /* Information about the function */
1008       u8 enc = ENC(pParse->db);   /* The database encoding */
1009       int savedAllowFlags = (pNC->ncFlags & (NC_AllowAgg | NC_AllowWin));
1010 #ifndef SQLITE_OMIT_WINDOWFUNC
1011       Window *pWin = (IsWindowFunc(pExpr) ? pExpr->y.pWin : 0);
1012 #endif
1013       assert( !ExprHasProperty(pExpr, EP_xIsSelect|EP_IntValue) );
1014       zId = pExpr->u.zToken;
1015       pDef = sqlite3FindFunction(pParse->db, zId, n, enc, 0);
1016       if( pDef==0 ){
1017         pDef = sqlite3FindFunction(pParse->db, zId, -2, enc, 0);
1018         if( pDef==0 ){
1019           no_such_func = 1;
1020         }else{
1021           wrong_num_args = 1;
1022         }
1023       }else{
1024         is_agg = pDef->xFinalize!=0;
1025         if( pDef->funcFlags & SQLITE_FUNC_UNLIKELY ){
1026           ExprSetProperty(pExpr, EP_Unlikely);
1027           if( n==2 ){
1028             pExpr->iTable = exprProbability(pList->a[1].pExpr);
1029             if( pExpr->iTable<0 ){
1030               sqlite3ErrorMsg(pParse,
1031                 "second argument to %#T() must be a "
1032                 "constant between 0.0 and 1.0", pExpr);
1033               pNC->nNcErr++;
1034             }
1035           }else{
1036             /* EVIDENCE-OF: R-61304-29449 The unlikely(X) function is
1037             ** equivalent to likelihood(X, 0.0625).
1038             ** EVIDENCE-OF: R-01283-11636 The unlikely(X) function is
1039             ** short-hand for likelihood(X,0.0625).
1040             ** EVIDENCE-OF: R-36850-34127 The likely(X) function is short-hand
1041             ** for likelihood(X,0.9375).
1042             ** EVIDENCE-OF: R-53436-40973 The likely(X) function is equivalent
1043             ** to likelihood(X,0.9375). */
1044             /* TUNING: unlikely() probability is 0.0625.  likely() is 0.9375 */
1045             pExpr->iTable = pDef->zName[0]=='u' ? 8388608 : 125829120;
1046           }
1047         }
1048 #ifndef SQLITE_OMIT_AUTHORIZATION
1049         {
1050           int auth = sqlite3AuthCheck(pParse, SQLITE_FUNCTION, 0,pDef->zName,0);
1051           if( auth!=SQLITE_OK ){
1052             if( auth==SQLITE_DENY ){
1053               sqlite3ErrorMsg(pParse, "not authorized to use function: %#T",
1054                                       pExpr);
1055               pNC->nNcErr++;
1056             }
1057             pExpr->op = TK_NULL;
1058             return WRC_Prune;
1059           }
1060         }
1061 #endif
1062         if( pDef->funcFlags & (SQLITE_FUNC_CONSTANT|SQLITE_FUNC_SLOCHNG) ){
1063           /* For the purposes of the EP_ConstFunc flag, date and time
1064           ** functions and other functions that change slowly are considered
1065           ** constant because they are constant for the duration of one query.
1066           ** This allows them to be factored out of inner loops. */
1067           ExprSetProperty(pExpr,EP_ConstFunc);
1068         }
1069         if( (pDef->funcFlags & SQLITE_FUNC_CONSTANT)==0 ){
1070           /* Clearly non-deterministic functions like random(), but also
1071           ** date/time functions that use 'now', and other functions like
1072           ** sqlite_version() that might change over time cannot be used
1073           ** in an index or generated column.  Curiously, they can be used
1074           ** in a CHECK constraint.  SQLServer, MySQL, and PostgreSQL all
1075           ** all this. */
1076           sqlite3ResolveNotValid(pParse, pNC, "non-deterministic functions",
1077                                  NC_IdxExpr|NC_PartIdx|NC_GenCol, 0, pExpr);
1078         }else{
1079           assert( (NC_SelfRef & 0xff)==NC_SelfRef ); /* Must fit in 8 bits */
1080           pExpr->op2 = pNC->ncFlags & NC_SelfRef;
1081           if( pNC->ncFlags & NC_FromDDL ) ExprSetProperty(pExpr, EP_FromDDL);
1082         }
1083         if( (pDef->funcFlags & SQLITE_FUNC_INTERNAL)!=0
1084          && pParse->nested==0
1085          && (pParse->db->mDbFlags & DBFLAG_InternalFunc)==0
1086         ){
1087           /* Internal-use-only functions are disallowed unless the
1088           ** SQL is being compiled using sqlite3NestedParse() or
1089           ** the SQLITE_TESTCTRL_INTERNAL_FUNCTIONS test-control has be
1090           ** used to activate internal functions for testing purposes */
1091           no_such_func = 1;
1092           pDef = 0;
1093         }else
1094         if( (pDef->funcFlags & (SQLITE_FUNC_DIRECT|SQLITE_FUNC_UNSAFE))!=0
1095          && !IN_RENAME_OBJECT
1096         ){
1097           sqlite3ExprFunctionUsable(pParse, pExpr, pDef);
1098         }
1099       }
1100 
1101       if( 0==IN_RENAME_OBJECT ){
1102 #ifndef SQLITE_OMIT_WINDOWFUNC
1103         assert( is_agg==0 || (pDef->funcFlags & SQLITE_FUNC_MINMAX)
1104           || (pDef->xValue==0 && pDef->xInverse==0)
1105           || (pDef->xValue && pDef->xInverse && pDef->xSFunc && pDef->xFinalize)
1106         );
1107         if( pDef && pDef->xValue==0 && pWin ){
1108           sqlite3ErrorMsg(pParse,
1109               "%#T() may not be used as a window function", pExpr
1110           );
1111           pNC->nNcErr++;
1112         }else if(
1113               (is_agg && (pNC->ncFlags & NC_AllowAgg)==0)
1114            || (is_agg && (pDef->funcFlags&SQLITE_FUNC_WINDOW) && !pWin)
1115            || (is_agg && pWin && (pNC->ncFlags & NC_AllowWin)==0)
1116         ){
1117           const char *zType;
1118           if( (pDef->funcFlags & SQLITE_FUNC_WINDOW) || pWin ){
1119             zType = "window";
1120           }else{
1121             zType = "aggregate";
1122           }
1123           sqlite3ErrorMsg(pParse, "misuse of %s function %#T()",zType,pExpr);
1124           pNC->nNcErr++;
1125           is_agg = 0;
1126         }
1127 #else
1128         if( (is_agg && (pNC->ncFlags & NC_AllowAgg)==0) ){
1129           sqlite3ErrorMsg(pParse,"misuse of aggregate function %#T()",pExpr);
1130           pNC->nNcErr++;
1131           is_agg = 0;
1132         }
1133 #endif
1134         else if( no_such_func && pParse->db->init.busy==0
1135 #ifdef SQLITE_ENABLE_UNKNOWN_SQL_FUNCTION
1136                   && pParse->explain==0
1137 #endif
1138         ){
1139           sqlite3ErrorMsg(pParse, "no such function: %#T", pExpr);
1140           pNC->nNcErr++;
1141         }else if( wrong_num_args ){
1142           sqlite3ErrorMsg(pParse,"wrong number of arguments to function %#T()",
1143                pExpr);
1144           pNC->nNcErr++;
1145         }
1146 #ifndef SQLITE_OMIT_WINDOWFUNC
1147         else if( is_agg==0 && ExprHasProperty(pExpr, EP_WinFunc) ){
1148           sqlite3ErrorMsg(pParse,
1149               "FILTER may not be used with non-aggregate %#T()",
1150               pExpr
1151           );
1152           pNC->nNcErr++;
1153         }
1154 #endif
1155         if( is_agg ){
1156           /* Window functions may not be arguments of aggregate functions.
1157           ** Or arguments of other window functions. But aggregate functions
1158           ** may be arguments for window functions.  */
1159 #ifndef SQLITE_OMIT_WINDOWFUNC
1160           pNC->ncFlags &= ~(NC_AllowWin | (!pWin ? NC_AllowAgg : 0));
1161 #else
1162           pNC->ncFlags &= ~NC_AllowAgg;
1163 #endif
1164         }
1165       }
1166 #ifndef SQLITE_OMIT_WINDOWFUNC
1167       else if( ExprHasProperty(pExpr, EP_WinFunc) ){
1168         is_agg = 1;
1169       }
1170 #endif
1171       sqlite3WalkExprList(pWalker, pList);
1172       if( is_agg ){
1173 #ifndef SQLITE_OMIT_WINDOWFUNC
1174         if( pWin ){
1175           Select *pSel = pNC->pWinSelect;
1176           assert( pWin==0 || (ExprUseYWin(pExpr) && pWin==pExpr->y.pWin) );
1177           if( IN_RENAME_OBJECT==0 ){
1178             sqlite3WindowUpdate(pParse, pSel ? pSel->pWinDefn : 0, pWin, pDef);
1179             if( pParse->db->mallocFailed ) break;
1180           }
1181           sqlite3WalkExprList(pWalker, pWin->pPartition);
1182           sqlite3WalkExprList(pWalker, pWin->pOrderBy);
1183           sqlite3WalkExpr(pWalker, pWin->pFilter);
1184           sqlite3WindowLink(pSel, pWin);
1185           pNC->ncFlags |= NC_HasWin;
1186         }else
1187 #endif /* SQLITE_OMIT_WINDOWFUNC */
1188         {
1189           NameContext *pNC2;          /* For looping up thru outer contexts */
1190           pExpr->op = TK_AGG_FUNCTION;
1191           pExpr->op2 = 0;
1192 #ifndef SQLITE_OMIT_WINDOWFUNC
1193           if( ExprHasProperty(pExpr, EP_WinFunc) ){
1194             sqlite3WalkExpr(pWalker, pExpr->y.pWin->pFilter);
1195           }
1196 #endif
1197           pNC2 = pNC;
1198           while( pNC2
1199               && sqlite3ReferencesSrcList(pParse, pExpr, pNC2->pSrcList)==0
1200           ){
1201             pExpr->op2++;
1202             pNC2 = pNC2->pNext;
1203           }
1204           assert( pDef!=0 || IN_RENAME_OBJECT );
1205           if( pNC2 && pDef ){
1206             assert( SQLITE_FUNC_MINMAX==NC_MinMaxAgg );
1207             assert( SQLITE_FUNC_ANYORDER==NC_OrderAgg );
1208             testcase( (pDef->funcFlags & SQLITE_FUNC_MINMAX)!=0 );
1209             testcase( (pDef->funcFlags & SQLITE_FUNC_ANYORDER)!=0 );
1210             pNC2->ncFlags |= NC_HasAgg
1211               | ((pDef->funcFlags^SQLITE_FUNC_ANYORDER)
1212                   & (SQLITE_FUNC_MINMAX|SQLITE_FUNC_ANYORDER));
1213           }
1214         }
1215         pNC->ncFlags |= savedAllowFlags;
1216       }
1217       /* FIX ME:  Compute pExpr->affinity based on the expected return
1218       ** type of the function
1219       */
1220       return WRC_Prune;
1221     }
1222 #ifndef SQLITE_OMIT_SUBQUERY
1223     case TK_SELECT:
1224     case TK_EXISTS:  testcase( pExpr->op==TK_EXISTS );
1225 #endif
1226     case TK_IN: {
1227       testcase( pExpr->op==TK_IN );
1228       if( ExprUseXSelect(pExpr) ){
1229         int nRef = pNC->nRef;
1230         testcase( pNC->ncFlags & NC_IsCheck );
1231         testcase( pNC->ncFlags & NC_PartIdx );
1232         testcase( pNC->ncFlags & NC_IdxExpr );
1233         testcase( pNC->ncFlags & NC_GenCol );
1234         if( pNC->ncFlags & NC_SelfRef ){
1235           notValidImpl(pParse, pNC, "subqueries", pExpr, pExpr);
1236         }else{
1237           sqlite3WalkSelect(pWalker, pExpr->x.pSelect);
1238         }
1239         assert( pNC->nRef>=nRef );
1240         if( nRef!=pNC->nRef ){
1241           ExprSetProperty(pExpr, EP_VarSelect);
1242           pNC->ncFlags |= NC_VarSelect;
1243         }
1244       }
1245       break;
1246     }
1247     case TK_VARIABLE: {
1248       testcase( pNC->ncFlags & NC_IsCheck );
1249       testcase( pNC->ncFlags & NC_PartIdx );
1250       testcase( pNC->ncFlags & NC_IdxExpr );
1251       testcase( pNC->ncFlags & NC_GenCol );
1252       sqlite3ResolveNotValid(pParse, pNC, "parameters",
1253                NC_IsCheck|NC_PartIdx|NC_IdxExpr|NC_GenCol, pExpr, pExpr);
1254       break;
1255     }
1256     case TK_IS:
1257     case TK_ISNOT: {
1258       Expr *pRight = sqlite3ExprSkipCollateAndLikely(pExpr->pRight);
1259       assert( !ExprHasProperty(pExpr, EP_Reduced) );
1260       /* Handle special cases of "x IS TRUE", "x IS FALSE", "x IS NOT TRUE",
1261       ** and "x IS NOT FALSE". */
1262       if( ALWAYS(pRight) && (pRight->op==TK_ID || pRight->op==TK_TRUEFALSE) ){
1263         int rc = resolveExprStep(pWalker, pRight);
1264         if( rc==WRC_Abort ) return WRC_Abort;
1265         if( pRight->op==TK_TRUEFALSE ){
1266           pExpr->op2 = pExpr->op;
1267           pExpr->op = TK_TRUTH;
1268           return WRC_Continue;
1269         }
1270       }
1271       /* no break */ deliberate_fall_through
1272     }
1273     case TK_BETWEEN:
1274     case TK_EQ:
1275     case TK_NE:
1276     case TK_LT:
1277     case TK_LE:
1278     case TK_GT:
1279     case TK_GE: {
1280       int nLeft, nRight;
1281       if( pParse->db->mallocFailed ) break;
1282       assert( pExpr->pLeft!=0 );
1283       nLeft = sqlite3ExprVectorSize(pExpr->pLeft);
1284       if( pExpr->op==TK_BETWEEN ){
1285         assert( ExprUseXList(pExpr) );
1286         nRight = sqlite3ExprVectorSize(pExpr->x.pList->a[0].pExpr);
1287         if( nRight==nLeft ){
1288           nRight = sqlite3ExprVectorSize(pExpr->x.pList->a[1].pExpr);
1289         }
1290       }else{
1291         assert( pExpr->pRight!=0 );
1292         nRight = sqlite3ExprVectorSize(pExpr->pRight);
1293       }
1294       if( nLeft!=nRight ){
1295         testcase( pExpr->op==TK_EQ );
1296         testcase( pExpr->op==TK_NE );
1297         testcase( pExpr->op==TK_LT );
1298         testcase( pExpr->op==TK_LE );
1299         testcase( pExpr->op==TK_GT );
1300         testcase( pExpr->op==TK_GE );
1301         testcase( pExpr->op==TK_IS );
1302         testcase( pExpr->op==TK_ISNOT );
1303         testcase( pExpr->op==TK_BETWEEN );
1304         sqlite3ErrorMsg(pParse, "row value misused");
1305         sqlite3RecordErrorOffsetOfExpr(pParse->db, pExpr);
1306       }
1307       break;
1308     }
1309   }
1310   assert( pParse->db->mallocFailed==0 || pParse->nErr!=0 );
1311   return pParse->nErr ? WRC_Abort : WRC_Continue;
1312 }
1313 
1314 /*
1315 ** pEList is a list of expressions which are really the result set of the
1316 ** a SELECT statement.  pE is a term in an ORDER BY or GROUP BY clause.
1317 ** This routine checks to see if pE is a simple identifier which corresponds
1318 ** to the AS-name of one of the terms of the expression list.  If it is,
1319 ** this routine return an integer between 1 and N where N is the number of
1320 ** elements in pEList, corresponding to the matching entry.  If there is
1321 ** no match, or if pE is not a simple identifier, then this routine
1322 ** return 0.
1323 **
1324 ** pEList has been resolved.  pE has not.
1325 */
1326 static int resolveAsName(
1327   Parse *pParse,     /* Parsing context for error messages */
1328   ExprList *pEList,  /* List of expressions to scan */
1329   Expr *pE           /* Expression we are trying to match */
1330 ){
1331   int i;             /* Loop counter */
1332 
1333   UNUSED_PARAMETER(pParse);
1334 
1335   if( pE->op==TK_ID ){
1336     const char *zCol;
1337     assert( !ExprHasProperty(pE, EP_IntValue) );
1338     zCol = pE->u.zToken;
1339     for(i=0; i<pEList->nExpr; i++){
1340       if( pEList->a[i].fg.eEName==ENAME_NAME
1341        && sqlite3_stricmp(pEList->a[i].zEName, zCol)==0
1342       ){
1343         return i+1;
1344       }
1345     }
1346   }
1347   return 0;
1348 }
1349 
1350 /*
1351 ** pE is a pointer to an expression which is a single term in the
1352 ** ORDER BY of a compound SELECT.  The expression has not been
1353 ** name resolved.
1354 **
1355 ** At the point this routine is called, we already know that the
1356 ** ORDER BY term is not an integer index into the result set.  That
1357 ** case is handled by the calling routine.
1358 **
1359 ** Attempt to match pE against result set columns in the left-most
1360 ** SELECT statement.  Return the index i of the matching column,
1361 ** as an indication to the caller that it should sort by the i-th column.
1362 ** The left-most column is 1.  In other words, the value returned is the
1363 ** same integer value that would be used in the SQL statement to indicate
1364 ** the column.
1365 **
1366 ** If there is no match, return 0.  Return -1 if an error occurs.
1367 */
1368 static int resolveOrderByTermToExprList(
1369   Parse *pParse,     /* Parsing context for error messages */
1370   Select *pSelect,   /* The SELECT statement with the ORDER BY clause */
1371   Expr *pE           /* The specific ORDER BY term */
1372 ){
1373   int i;             /* Loop counter */
1374   ExprList *pEList;  /* The columns of the result set */
1375   NameContext nc;    /* Name context for resolving pE */
1376   sqlite3 *db;       /* Database connection */
1377   int rc;            /* Return code from subprocedures */
1378   u8 savedSuppErr;   /* Saved value of db->suppressErr */
1379 
1380   assert( sqlite3ExprIsInteger(pE, &i)==0 );
1381   pEList = pSelect->pEList;
1382 
1383   /* Resolve all names in the ORDER BY term expression
1384   */
1385   memset(&nc, 0, sizeof(nc));
1386   nc.pParse = pParse;
1387   nc.pSrcList = pSelect->pSrc;
1388   nc.uNC.pEList = pEList;
1389   nc.ncFlags = NC_AllowAgg|NC_UEList|NC_NoSelect;
1390   nc.nNcErr = 0;
1391   db = pParse->db;
1392   savedSuppErr = db->suppressErr;
1393   db->suppressErr = 1;
1394   rc = sqlite3ResolveExprNames(&nc, pE);
1395   db->suppressErr = savedSuppErr;
1396   if( rc ) return 0;
1397 
1398   /* Try to match the ORDER BY expression against an expression
1399   ** in the result set.  Return an 1-based index of the matching
1400   ** result-set entry.
1401   */
1402   for(i=0; i<pEList->nExpr; i++){
1403     if( sqlite3ExprCompare(0, pEList->a[i].pExpr, pE, -1)<2 ){
1404       return i+1;
1405     }
1406   }
1407 
1408   /* If no match, return 0. */
1409   return 0;
1410 }
1411 
1412 /*
1413 ** Generate an ORDER BY or GROUP BY term out-of-range error.
1414 */
1415 static void resolveOutOfRangeError(
1416   Parse *pParse,         /* The error context into which to write the error */
1417   const char *zType,     /* "ORDER" or "GROUP" */
1418   int i,                 /* The index (1-based) of the term out of range */
1419   int mx,                /* Largest permissible value of i */
1420   Expr *pError           /* Associate the error with the expression */
1421 ){
1422   sqlite3ErrorMsg(pParse,
1423     "%r %s BY term out of range - should be "
1424     "between 1 and %d", i, zType, mx);
1425   sqlite3RecordErrorOffsetOfExpr(pParse->db, pError);
1426 }
1427 
1428 /*
1429 ** Analyze the ORDER BY clause in a compound SELECT statement.   Modify
1430 ** each term of the ORDER BY clause is a constant integer between 1
1431 ** and N where N is the number of columns in the compound SELECT.
1432 **
1433 ** ORDER BY terms that are already an integer between 1 and N are
1434 ** unmodified.  ORDER BY terms that are integers outside the range of
1435 ** 1 through N generate an error.  ORDER BY terms that are expressions
1436 ** are matched against result set expressions of compound SELECT
1437 ** beginning with the left-most SELECT and working toward the right.
1438 ** At the first match, the ORDER BY expression is transformed into
1439 ** the integer column number.
1440 **
1441 ** Return the number of errors seen.
1442 */
1443 static int resolveCompoundOrderBy(
1444   Parse *pParse,        /* Parsing context.  Leave error messages here */
1445   Select *pSelect       /* The SELECT statement containing the ORDER BY */
1446 ){
1447   int i;
1448   ExprList *pOrderBy;
1449   ExprList *pEList;
1450   sqlite3 *db;
1451   int moreToDo = 1;
1452 
1453   pOrderBy = pSelect->pOrderBy;
1454   if( pOrderBy==0 ) return 0;
1455   db = pParse->db;
1456   if( pOrderBy->nExpr>db->aLimit[SQLITE_LIMIT_COLUMN] ){
1457     sqlite3ErrorMsg(pParse, "too many terms in ORDER BY clause");
1458     return 1;
1459   }
1460   for(i=0; i<pOrderBy->nExpr; i++){
1461     pOrderBy->a[i].fg.done = 0;
1462   }
1463   pSelect->pNext = 0;
1464   while( pSelect->pPrior ){
1465     pSelect->pPrior->pNext = pSelect;
1466     pSelect = pSelect->pPrior;
1467   }
1468   while( pSelect && moreToDo ){
1469     struct ExprList_item *pItem;
1470     moreToDo = 0;
1471     pEList = pSelect->pEList;
1472     assert( pEList!=0 );
1473     for(i=0, pItem=pOrderBy->a; i<pOrderBy->nExpr; i++, pItem++){
1474       int iCol = -1;
1475       Expr *pE, *pDup;
1476       if( pItem->fg.done ) continue;
1477       pE = sqlite3ExprSkipCollateAndLikely(pItem->pExpr);
1478       if( NEVER(pE==0) ) continue;
1479       if( sqlite3ExprIsInteger(pE, &iCol) ){
1480         if( iCol<=0 || iCol>pEList->nExpr ){
1481           resolveOutOfRangeError(pParse, "ORDER", i+1, pEList->nExpr, pE);
1482           return 1;
1483         }
1484       }else{
1485         iCol = resolveAsName(pParse, pEList, pE);
1486         if( iCol==0 ){
1487           /* Now test if expression pE matches one of the values returned
1488           ** by pSelect. In the usual case this is done by duplicating the
1489           ** expression, resolving any symbols in it, and then comparing
1490           ** it against each expression returned by the SELECT statement.
1491           ** Once the comparisons are finished, the duplicate expression
1492           ** is deleted.
1493           **
1494           ** If this is running as part of an ALTER TABLE operation and
1495           ** the symbols resolve successfully, also resolve the symbols in the
1496           ** actual expression. This allows the code in alter.c to modify
1497           ** column references within the ORDER BY expression as required.  */
1498           pDup = sqlite3ExprDup(db, pE, 0);
1499           if( !db->mallocFailed ){
1500             assert(pDup);
1501             iCol = resolveOrderByTermToExprList(pParse, pSelect, pDup);
1502             if( IN_RENAME_OBJECT && iCol>0 ){
1503               resolveOrderByTermToExprList(pParse, pSelect, pE);
1504             }
1505           }
1506           sqlite3ExprDelete(db, pDup);
1507         }
1508       }
1509       if( iCol>0 ){
1510         /* Convert the ORDER BY term into an integer column number iCol,
1511         ** taking care to preserve the COLLATE clause if it exists. */
1512         if( !IN_RENAME_OBJECT ){
1513           Expr *pNew = sqlite3Expr(db, TK_INTEGER, 0);
1514           if( pNew==0 ) return 1;
1515           pNew->flags |= EP_IntValue;
1516           pNew->u.iValue = iCol;
1517           if( pItem->pExpr==pE ){
1518             pItem->pExpr = pNew;
1519           }else{
1520             Expr *pParent = pItem->pExpr;
1521             assert( pParent->op==TK_COLLATE );
1522             while( pParent->pLeft->op==TK_COLLATE ) pParent = pParent->pLeft;
1523             assert( pParent->pLeft==pE );
1524             pParent->pLeft = pNew;
1525           }
1526           sqlite3ExprDelete(db, pE);
1527           pItem->u.x.iOrderByCol = (u16)iCol;
1528         }
1529         pItem->fg.done = 1;
1530       }else{
1531         moreToDo = 1;
1532       }
1533     }
1534     pSelect = pSelect->pNext;
1535   }
1536   for(i=0; i<pOrderBy->nExpr; i++){
1537     if( pOrderBy->a[i].fg.done==0 ){
1538       sqlite3ErrorMsg(pParse, "%r ORDER BY term does not match any "
1539             "column in the result set", i+1);
1540       return 1;
1541     }
1542   }
1543   return 0;
1544 }
1545 
1546 /*
1547 ** Check every term in the ORDER BY or GROUP BY clause pOrderBy of
1548 ** the SELECT statement pSelect.  If any term is reference to a
1549 ** result set expression (as determined by the ExprList.a.u.x.iOrderByCol
1550 ** field) then convert that term into a copy of the corresponding result set
1551 ** column.
1552 **
1553 ** If any errors are detected, add an error message to pParse and
1554 ** return non-zero.  Return zero if no errors are seen.
1555 */
1556 int sqlite3ResolveOrderGroupBy(
1557   Parse *pParse,        /* Parsing context.  Leave error messages here */
1558   Select *pSelect,      /* The SELECT statement containing the clause */
1559   ExprList *pOrderBy,   /* The ORDER BY or GROUP BY clause to be processed */
1560   const char *zType     /* "ORDER" or "GROUP" */
1561 ){
1562   int i;
1563   sqlite3 *db = pParse->db;
1564   ExprList *pEList;
1565   struct ExprList_item *pItem;
1566 
1567   if( pOrderBy==0 || pParse->db->mallocFailed || IN_RENAME_OBJECT ) return 0;
1568   if( pOrderBy->nExpr>db->aLimit[SQLITE_LIMIT_COLUMN] ){
1569     sqlite3ErrorMsg(pParse, "too many terms in %s BY clause", zType);
1570     return 1;
1571   }
1572   pEList = pSelect->pEList;
1573   assert( pEList!=0 );  /* sqlite3SelectNew() guarantees this */
1574   for(i=0, pItem=pOrderBy->a; i<pOrderBy->nExpr; i++, pItem++){
1575     if( pItem->u.x.iOrderByCol ){
1576       if( pItem->u.x.iOrderByCol>pEList->nExpr ){
1577         resolveOutOfRangeError(pParse, zType, i+1, pEList->nExpr, 0);
1578         return 1;
1579       }
1580       resolveAlias(pParse, pEList, pItem->u.x.iOrderByCol-1, pItem->pExpr,0);
1581     }
1582   }
1583   return 0;
1584 }
1585 
1586 #ifndef SQLITE_OMIT_WINDOWFUNC
1587 /*
1588 ** Walker callback for windowRemoveExprFromSelect().
1589 */
1590 static int resolveRemoveWindowsCb(Walker *pWalker, Expr *pExpr){
1591   UNUSED_PARAMETER(pWalker);
1592   if( ExprHasProperty(pExpr, EP_WinFunc) ){
1593     Window *pWin = pExpr->y.pWin;
1594     sqlite3WindowUnlinkFromSelect(pWin);
1595   }
1596   return WRC_Continue;
1597 }
1598 
1599 /*
1600 ** Remove any Window objects owned by the expression pExpr from the
1601 ** Select.pWin list of Select object pSelect.
1602 */
1603 static void windowRemoveExprFromSelect(Select *pSelect, Expr *pExpr){
1604   if( pSelect->pWin ){
1605     Walker sWalker;
1606     memset(&sWalker, 0, sizeof(Walker));
1607     sWalker.xExprCallback = resolveRemoveWindowsCb;
1608     sWalker.u.pSelect = pSelect;
1609     sqlite3WalkExpr(&sWalker, pExpr);
1610   }
1611 }
1612 #else
1613 # define windowRemoveExprFromSelect(a, b)
1614 #endif /* SQLITE_OMIT_WINDOWFUNC */
1615 
1616 /*
1617 ** pOrderBy is an ORDER BY or GROUP BY clause in SELECT statement pSelect.
1618 ** The Name context of the SELECT statement is pNC.  zType is either
1619 ** "ORDER" or "GROUP" depending on which type of clause pOrderBy is.
1620 **
1621 ** This routine resolves each term of the clause into an expression.
1622 ** If the order-by term is an integer I between 1 and N (where N is the
1623 ** number of columns in the result set of the SELECT) then the expression
1624 ** in the resolution is a copy of the I-th result-set expression.  If
1625 ** the order-by term is an identifier that corresponds to the AS-name of
1626 ** a result-set expression, then the term resolves to a copy of the
1627 ** result-set expression.  Otherwise, the expression is resolved in
1628 ** the usual way - using sqlite3ResolveExprNames().
1629 **
1630 ** This routine returns the number of errors.  If errors occur, then
1631 ** an appropriate error message might be left in pParse.  (OOM errors
1632 ** excepted.)
1633 */
1634 static int resolveOrderGroupBy(
1635   NameContext *pNC,     /* The name context of the SELECT statement */
1636   Select *pSelect,      /* The SELECT statement holding pOrderBy */
1637   ExprList *pOrderBy,   /* An ORDER BY or GROUP BY clause to resolve */
1638   const char *zType     /* Either "ORDER" or "GROUP", as appropriate */
1639 ){
1640   int i, j;                      /* Loop counters */
1641   int iCol;                      /* Column number */
1642   struct ExprList_item *pItem;   /* A term of the ORDER BY clause */
1643   Parse *pParse;                 /* Parsing context */
1644   int nResult;                   /* Number of terms in the result set */
1645 
1646   assert( pOrderBy!=0 );
1647   nResult = pSelect->pEList->nExpr;
1648   pParse = pNC->pParse;
1649   for(i=0, pItem=pOrderBy->a; i<pOrderBy->nExpr; i++, pItem++){
1650     Expr *pE = pItem->pExpr;
1651     Expr *pE2 = sqlite3ExprSkipCollateAndLikely(pE);
1652     if( NEVER(pE2==0) ) continue;
1653     if( zType[0]!='G' ){
1654       iCol = resolveAsName(pParse, pSelect->pEList, pE2);
1655       if( iCol>0 ){
1656         /* If an AS-name match is found, mark this ORDER BY column as being
1657         ** a copy of the iCol-th result-set column.  The subsequent call to
1658         ** sqlite3ResolveOrderGroupBy() will convert the expression to a
1659         ** copy of the iCol-th result-set expression. */
1660         pItem->u.x.iOrderByCol = (u16)iCol;
1661         continue;
1662       }
1663     }
1664     if( sqlite3ExprIsInteger(pE2, &iCol) ){
1665       /* The ORDER BY term is an integer constant.  Again, set the column
1666       ** number so that sqlite3ResolveOrderGroupBy() will convert the
1667       ** order-by term to a copy of the result-set expression */
1668       if( iCol<1 || iCol>0xffff ){
1669         resolveOutOfRangeError(pParse, zType, i+1, nResult, pE2);
1670         return 1;
1671       }
1672       pItem->u.x.iOrderByCol = (u16)iCol;
1673       continue;
1674     }
1675 
1676     /* Otherwise, treat the ORDER BY term as an ordinary expression */
1677     pItem->u.x.iOrderByCol = 0;
1678     if( sqlite3ResolveExprNames(pNC, pE) ){
1679       return 1;
1680     }
1681     for(j=0; j<pSelect->pEList->nExpr; j++){
1682       if( sqlite3ExprCompare(0, pE, pSelect->pEList->a[j].pExpr, -1)==0 ){
1683         /* Since this expresion is being changed into a reference
1684         ** to an identical expression in the result set, remove all Window
1685         ** objects belonging to the expression from the Select.pWin list. */
1686         windowRemoveExprFromSelect(pSelect, pE);
1687         pItem->u.x.iOrderByCol = j+1;
1688       }
1689     }
1690   }
1691   return sqlite3ResolveOrderGroupBy(pParse, pSelect, pOrderBy, zType);
1692 }
1693 
1694 /*
1695 ** Resolve names in the SELECT statement p and all of its descendants.
1696 */
1697 static int resolveSelectStep(Walker *pWalker, Select *p){
1698   NameContext *pOuterNC;  /* Context that contains this SELECT */
1699   NameContext sNC;        /* Name context of this SELECT */
1700   int isCompound;         /* True if p is a compound select */
1701   int nCompound;          /* Number of compound terms processed so far */
1702   Parse *pParse;          /* Parsing context */
1703   int i;                  /* Loop counter */
1704   ExprList *pGroupBy;     /* The GROUP BY clause */
1705   Select *pLeftmost;      /* Left-most of SELECT of a compound */
1706   sqlite3 *db;            /* Database connection */
1707 
1708 
1709   assert( p!=0 );
1710   if( p->selFlags & SF_Resolved ){
1711     return WRC_Prune;
1712   }
1713   pOuterNC = pWalker->u.pNC;
1714   pParse = pWalker->pParse;
1715   db = pParse->db;
1716 
1717   /* Normally sqlite3SelectExpand() will be called first and will have
1718   ** already expanded this SELECT.  However, if this is a subquery within
1719   ** an expression, sqlite3ResolveExprNames() will be called without a
1720   ** prior call to sqlite3SelectExpand().  When that happens, let
1721   ** sqlite3SelectPrep() do all of the processing for this SELECT.
1722   ** sqlite3SelectPrep() will invoke both sqlite3SelectExpand() and
1723   ** this routine in the correct order.
1724   */
1725   if( (p->selFlags & SF_Expanded)==0 ){
1726     sqlite3SelectPrep(pParse, p, pOuterNC);
1727     return pParse->nErr ? WRC_Abort : WRC_Prune;
1728   }
1729 
1730   isCompound = p->pPrior!=0;
1731   nCompound = 0;
1732   pLeftmost = p;
1733   while( p ){
1734     assert( (p->selFlags & SF_Expanded)!=0 );
1735     assert( (p->selFlags & SF_Resolved)==0 );
1736     assert( db->suppressErr==0 ); /* SF_Resolved not set if errors suppressed */
1737     p->selFlags |= SF_Resolved;
1738 
1739 
1740     /* Resolve the expressions in the LIMIT and OFFSET clauses. These
1741     ** are not allowed to refer to any names, so pass an empty NameContext.
1742     */
1743     memset(&sNC, 0, sizeof(sNC));
1744     sNC.pParse = pParse;
1745     sNC.pWinSelect = p;
1746     if( sqlite3ResolveExprNames(&sNC, p->pLimit) ){
1747       return WRC_Abort;
1748     }
1749 
1750     /* If the SF_Converted flags is set, then this Select object was
1751     ** was created by the convertCompoundSelectToSubquery() function.
1752     ** In this case the ORDER BY clause (p->pOrderBy) should be resolved
1753     ** as if it were part of the sub-query, not the parent. This block
1754     ** moves the pOrderBy down to the sub-query. It will be moved back
1755     ** after the names have been resolved.  */
1756     if( p->selFlags & SF_Converted ){
1757       Select *pSub = p->pSrc->a[0].pSelect;
1758       assert( p->pSrc->nSrc==1 && p->pOrderBy );
1759       assert( pSub->pPrior && pSub->pOrderBy==0 );
1760       pSub->pOrderBy = p->pOrderBy;
1761       p->pOrderBy = 0;
1762     }
1763 
1764     /* Recursively resolve names in all subqueries in the FROM clause
1765     */
1766     for(i=0; i<p->pSrc->nSrc; i++){
1767       SrcItem *pItem = &p->pSrc->a[i];
1768       if( pItem->pSelect && (pItem->pSelect->selFlags & SF_Resolved)==0 ){
1769         int nRef = pOuterNC ? pOuterNC->nRef : 0;
1770         const char *zSavedContext = pParse->zAuthContext;
1771 
1772         if( pItem->zName ) pParse->zAuthContext = pItem->zName;
1773         sqlite3ResolveSelectNames(pParse, pItem->pSelect, pOuterNC);
1774         pParse->zAuthContext = zSavedContext;
1775         if( pParse->nErr ) return WRC_Abort;
1776         assert( db->mallocFailed==0 );
1777 
1778         /* If the number of references to the outer context changed when
1779         ** expressions in the sub-select were resolved, the sub-select
1780         ** is correlated. It is not required to check the refcount on any
1781         ** but the innermost outer context object, as lookupName() increments
1782         ** the refcount on all contexts between the current one and the
1783         ** context containing the column when it resolves a name. */
1784         if( pOuterNC ){
1785           assert( pItem->fg.isCorrelated==0 && pOuterNC->nRef>=nRef );
1786           pItem->fg.isCorrelated = (pOuterNC->nRef>nRef);
1787         }
1788       }
1789     }
1790 
1791     /* Set up the local name-context to pass to sqlite3ResolveExprNames() to
1792     ** resolve the result-set expression list.
1793     */
1794     sNC.ncFlags = NC_AllowAgg|NC_AllowWin;
1795     sNC.pSrcList = p->pSrc;
1796     sNC.pNext = pOuterNC;
1797 
1798     /* Resolve names in the result set. */
1799     if( sqlite3ResolveExprListNames(&sNC, p->pEList) ) return WRC_Abort;
1800     sNC.ncFlags &= ~NC_AllowWin;
1801 
1802     /* If there are no aggregate functions in the result-set, and no GROUP BY
1803     ** expression, do not allow aggregates in any of the other expressions.
1804     */
1805     assert( (p->selFlags & SF_Aggregate)==0 );
1806     pGroupBy = p->pGroupBy;
1807     if( pGroupBy || (sNC.ncFlags & NC_HasAgg)!=0 ){
1808       assert( NC_MinMaxAgg==SF_MinMaxAgg );
1809       assert( NC_OrderAgg==SF_OrderByReqd );
1810       p->selFlags |= SF_Aggregate | (sNC.ncFlags&(NC_MinMaxAgg|NC_OrderAgg));
1811     }else{
1812       sNC.ncFlags &= ~NC_AllowAgg;
1813     }
1814 
1815     /* Add the output column list to the name-context before parsing the
1816     ** other expressions in the SELECT statement. This is so that
1817     ** expressions in the WHERE clause (etc.) can refer to expressions by
1818     ** aliases in the result set.
1819     **
1820     ** Minor point: If this is the case, then the expression will be
1821     ** re-evaluated for each reference to it.
1822     */
1823     assert( (sNC.ncFlags & (NC_UAggInfo|NC_UUpsert|NC_UBaseReg))==0 );
1824     sNC.uNC.pEList = p->pEList;
1825     sNC.ncFlags |= NC_UEList;
1826     if( p->pHaving ){
1827       if( !pGroupBy ){
1828         sqlite3ErrorMsg(pParse, "a GROUP BY clause is required before HAVING");
1829         return WRC_Abort;
1830       }
1831       if( sqlite3ResolveExprNames(&sNC, p->pHaving) ) return WRC_Abort;
1832     }
1833     if( sqlite3ResolveExprNames(&sNC, p->pWhere) ) return WRC_Abort;
1834 
1835     /* Resolve names in table-valued-function arguments */
1836     for(i=0; i<p->pSrc->nSrc; i++){
1837       SrcItem *pItem = &p->pSrc->a[i];
1838       if( pItem->fg.isTabFunc
1839        && sqlite3ResolveExprListNames(&sNC, pItem->u1.pFuncArg)
1840       ){
1841         return WRC_Abort;
1842       }
1843     }
1844 
1845 #ifndef SQLITE_OMIT_WINDOWFUNC
1846     if( IN_RENAME_OBJECT ){
1847       Window *pWin;
1848       for(pWin=p->pWinDefn; pWin; pWin=pWin->pNextWin){
1849         if( sqlite3ResolveExprListNames(&sNC, pWin->pOrderBy)
1850          || sqlite3ResolveExprListNames(&sNC, pWin->pPartition)
1851         ){
1852           return WRC_Abort;
1853         }
1854       }
1855     }
1856 #endif
1857 
1858     /* The ORDER BY and GROUP BY clauses may not refer to terms in
1859     ** outer queries
1860     */
1861     sNC.pNext = 0;
1862     sNC.ncFlags |= NC_AllowAgg|NC_AllowWin;
1863 
1864     /* If this is a converted compound query, move the ORDER BY clause from
1865     ** the sub-query back to the parent query. At this point each term
1866     ** within the ORDER BY clause has been transformed to an integer value.
1867     ** These integers will be replaced by copies of the corresponding result
1868     ** set expressions by the call to resolveOrderGroupBy() below.  */
1869     if( p->selFlags & SF_Converted ){
1870       Select *pSub = p->pSrc->a[0].pSelect;
1871       p->pOrderBy = pSub->pOrderBy;
1872       pSub->pOrderBy = 0;
1873     }
1874 
1875     /* Process the ORDER BY clause for singleton SELECT statements.
1876     ** The ORDER BY clause for compounds SELECT statements is handled
1877     ** below, after all of the result-sets for all of the elements of
1878     ** the compound have been resolved.
1879     **
1880     ** If there is an ORDER BY clause on a term of a compound-select other
1881     ** than the right-most term, then that is a syntax error.  But the error
1882     ** is not detected until much later, and so we need to go ahead and
1883     ** resolve those symbols on the incorrect ORDER BY for consistency.
1884     */
1885     if( p->pOrderBy!=0
1886      && isCompound<=nCompound  /* Defer right-most ORDER BY of a compound */
1887      && resolveOrderGroupBy(&sNC, p, p->pOrderBy, "ORDER")
1888     ){
1889       return WRC_Abort;
1890     }
1891     if( db->mallocFailed ){
1892       return WRC_Abort;
1893     }
1894     sNC.ncFlags &= ~NC_AllowWin;
1895 
1896     /* Resolve the GROUP BY clause.  At the same time, make sure
1897     ** the GROUP BY clause does not contain aggregate functions.
1898     */
1899     if( pGroupBy ){
1900       struct ExprList_item *pItem;
1901 
1902       if( resolveOrderGroupBy(&sNC, p, pGroupBy, "GROUP") || db->mallocFailed ){
1903         return WRC_Abort;
1904       }
1905       for(i=0, pItem=pGroupBy->a; i<pGroupBy->nExpr; i++, pItem++){
1906         if( ExprHasProperty(pItem->pExpr, EP_Agg) ){
1907           sqlite3ErrorMsg(pParse, "aggregate functions are not allowed in "
1908               "the GROUP BY clause");
1909           return WRC_Abort;
1910         }
1911       }
1912     }
1913 
1914     /* If this is part of a compound SELECT, check that it has the right
1915     ** number of expressions in the select list. */
1916     if( p->pNext && p->pEList->nExpr!=p->pNext->pEList->nExpr ){
1917       sqlite3SelectWrongNumTermsError(pParse, p->pNext);
1918       return WRC_Abort;
1919     }
1920 
1921     /* Advance to the next term of the compound
1922     */
1923     p = p->pPrior;
1924     nCompound++;
1925   }
1926 
1927   /* Resolve the ORDER BY on a compound SELECT after all terms of
1928   ** the compound have been resolved.
1929   */
1930   if( isCompound && resolveCompoundOrderBy(pParse, pLeftmost) ){
1931     return WRC_Abort;
1932   }
1933 
1934   return WRC_Prune;
1935 }
1936 
1937 /*
1938 ** This routine walks an expression tree and resolves references to
1939 ** table columns and result-set columns.  At the same time, do error
1940 ** checking on function usage and set a flag if any aggregate functions
1941 ** are seen.
1942 **
1943 ** To resolve table columns references we look for nodes (or subtrees) of the
1944 ** form X.Y.Z or Y.Z or just Z where
1945 **
1946 **      X:   The name of a database.  Ex:  "main" or "temp" or
1947 **           the symbolic name assigned to an ATTACH-ed database.
1948 **
1949 **      Y:   The name of a table in a FROM clause.  Or in a trigger
1950 **           one of the special names "old" or "new".
1951 **
1952 **      Z:   The name of a column in table Y.
1953 **
1954 ** The node at the root of the subtree is modified as follows:
1955 **
1956 **    Expr.op        Changed to TK_COLUMN
1957 **    Expr.pTab      Points to the Table object for X.Y
1958 **    Expr.iColumn   The column index in X.Y.  -1 for the rowid.
1959 **    Expr.iTable    The VDBE cursor number for X.Y
1960 **
1961 **
1962 ** To resolve result-set references, look for expression nodes of the
1963 ** form Z (with no X and Y prefix) where the Z matches the right-hand
1964 ** size of an AS clause in the result-set of a SELECT.  The Z expression
1965 ** is replaced by a copy of the left-hand side of the result-set expression.
1966 ** Table-name and function resolution occurs on the substituted expression
1967 ** tree.  For example, in:
1968 **
1969 **      SELECT a+b AS x, c+d AS y FROM t1 ORDER BY x;
1970 **
1971 ** The "x" term of the order by is replaced by "a+b" to render:
1972 **
1973 **      SELECT a+b AS x, c+d AS y FROM t1 ORDER BY a+b;
1974 **
1975 ** Function calls are checked to make sure that the function is
1976 ** defined and that the correct number of arguments are specified.
1977 ** If the function is an aggregate function, then the NC_HasAgg flag is
1978 ** set and the opcode is changed from TK_FUNCTION to TK_AGG_FUNCTION.
1979 ** If an expression contains aggregate functions then the EP_Agg
1980 ** property on the expression is set.
1981 **
1982 ** An error message is left in pParse if anything is amiss.  The number
1983 ** if errors is returned.
1984 */
1985 int sqlite3ResolveExprNames(
1986   NameContext *pNC,       /* Namespace to resolve expressions in. */
1987   Expr *pExpr             /* The expression to be analyzed. */
1988 ){
1989   int savedHasAgg;
1990   Walker w;
1991 
1992   if( pExpr==0 ) return SQLITE_OK;
1993   savedHasAgg = pNC->ncFlags & (NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
1994   pNC->ncFlags &= ~(NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
1995   w.pParse = pNC->pParse;
1996   w.xExprCallback = resolveExprStep;
1997   w.xSelectCallback = (pNC->ncFlags & NC_NoSelect) ? 0 : resolveSelectStep;
1998   w.xSelectCallback2 = 0;
1999   w.u.pNC = pNC;
2000 #if SQLITE_MAX_EXPR_DEPTH>0
2001   w.pParse->nHeight += pExpr->nHeight;
2002   if( sqlite3ExprCheckHeight(w.pParse, w.pParse->nHeight) ){
2003     return SQLITE_ERROR;
2004   }
2005 #endif
2006   sqlite3WalkExpr(&w, pExpr);
2007 #if SQLITE_MAX_EXPR_DEPTH>0
2008   w.pParse->nHeight -= pExpr->nHeight;
2009 #endif
2010   assert( EP_Agg==NC_HasAgg );
2011   assert( EP_Win==NC_HasWin );
2012   testcase( pNC->ncFlags & NC_HasAgg );
2013   testcase( pNC->ncFlags & NC_HasWin );
2014   ExprSetProperty(pExpr, pNC->ncFlags & (NC_HasAgg|NC_HasWin) );
2015   pNC->ncFlags |= savedHasAgg;
2016   return pNC->nNcErr>0 || w.pParse->nErr>0;
2017 }
2018 
2019 /*
2020 ** Resolve all names for all expression in an expression list.  This is
2021 ** just like sqlite3ResolveExprNames() except that it works for an expression
2022 ** list rather than a single expression.
2023 */
2024 int sqlite3ResolveExprListNames(
2025   NameContext *pNC,       /* Namespace to resolve expressions in. */
2026   ExprList *pList         /* The expression list to be analyzed. */
2027 ){
2028   int i;
2029   int savedHasAgg = 0;
2030   Walker w;
2031   if( pList==0 ) return WRC_Continue;
2032   w.pParse = pNC->pParse;
2033   w.xExprCallback = resolveExprStep;
2034   w.xSelectCallback = resolveSelectStep;
2035   w.xSelectCallback2 = 0;
2036   w.u.pNC = pNC;
2037   savedHasAgg = pNC->ncFlags & (NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
2038   pNC->ncFlags &= ~(NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
2039   for(i=0; i<pList->nExpr; i++){
2040     Expr *pExpr = pList->a[i].pExpr;
2041     if( pExpr==0 ) continue;
2042 #if SQLITE_MAX_EXPR_DEPTH>0
2043     w.pParse->nHeight += pExpr->nHeight;
2044     if( sqlite3ExprCheckHeight(w.pParse, w.pParse->nHeight) ){
2045       return WRC_Abort;
2046     }
2047 #endif
2048     sqlite3WalkExpr(&w, pExpr);
2049 #if SQLITE_MAX_EXPR_DEPTH>0
2050     w.pParse->nHeight -= pExpr->nHeight;
2051 #endif
2052     assert( EP_Agg==NC_HasAgg );
2053     assert( EP_Win==NC_HasWin );
2054     testcase( pNC->ncFlags & NC_HasAgg );
2055     testcase( pNC->ncFlags & NC_HasWin );
2056     if( pNC->ncFlags & (NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg) ){
2057       ExprSetProperty(pExpr, pNC->ncFlags & (NC_HasAgg|NC_HasWin) );
2058       savedHasAgg |= pNC->ncFlags &
2059                           (NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
2060       pNC->ncFlags &= ~(NC_HasAgg|NC_MinMaxAgg|NC_HasWin|NC_OrderAgg);
2061     }
2062     if( w.pParse->nErr>0 ) return WRC_Abort;
2063   }
2064   pNC->ncFlags |= savedHasAgg;
2065   return WRC_Continue;
2066 }
2067 
2068 /*
2069 ** Resolve all names in all expressions of a SELECT and in all
2070 ** decendents of the SELECT, including compounds off of p->pPrior,
2071 ** subqueries in expressions, and subqueries used as FROM clause
2072 ** terms.
2073 **
2074 ** See sqlite3ResolveExprNames() for a description of the kinds of
2075 ** transformations that occur.
2076 **
2077 ** All SELECT statements should have been expanded using
2078 ** sqlite3SelectExpand() prior to invoking this routine.
2079 */
2080 void sqlite3ResolveSelectNames(
2081   Parse *pParse,         /* The parser context */
2082   Select *p,             /* The SELECT statement being coded. */
2083   NameContext *pOuterNC  /* Name context for parent SELECT statement */
2084 ){
2085   Walker w;
2086 
2087   assert( p!=0 );
2088   w.xExprCallback = resolveExprStep;
2089   w.xSelectCallback = resolveSelectStep;
2090   w.xSelectCallback2 = 0;
2091   w.pParse = pParse;
2092   w.u.pNC = pOuterNC;
2093   sqlite3WalkSelect(&w, p);
2094 }
2095 
2096 /*
2097 ** Resolve names in expressions that can only reference a single table
2098 ** or which cannot reference any tables at all.  Examples:
2099 **
2100 **                                                    "type" flag
2101 **                                                    ------------
2102 **    (1)   CHECK constraints                         NC_IsCheck
2103 **    (2)   WHERE clauses on partial indices          NC_PartIdx
2104 **    (3)   Expressions in indexes on expressions     NC_IdxExpr
2105 **    (4)   Expression arguments to VACUUM INTO.      0
2106 **    (5)   GENERATED ALWAYS as expressions           NC_GenCol
2107 **
2108 ** In all cases except (4), the Expr.iTable value for Expr.op==TK_COLUMN
2109 ** nodes of the expression is set to -1 and the Expr.iColumn value is
2110 ** set to the column number.  In case (4), TK_COLUMN nodes cause an error.
2111 **
2112 ** Any errors cause an error message to be set in pParse.
2113 */
2114 int sqlite3ResolveSelfReference(
2115   Parse *pParse,   /* Parsing context */
2116   Table *pTab,     /* The table being referenced, or NULL */
2117   int type,        /* NC_IsCheck, NC_PartIdx, NC_IdxExpr, NC_GenCol, or 0 */
2118   Expr *pExpr,     /* Expression to resolve.  May be NULL. */
2119   ExprList *pList  /* Expression list to resolve.  May be NULL. */
2120 ){
2121   SrcList sSrc;                   /* Fake SrcList for pParse->pNewTable */
2122   NameContext sNC;                /* Name context for pParse->pNewTable */
2123   int rc;
2124 
2125   assert( type==0 || pTab!=0 );
2126   assert( type==NC_IsCheck || type==NC_PartIdx || type==NC_IdxExpr
2127           || type==NC_GenCol || pTab==0 );
2128   memset(&sNC, 0, sizeof(sNC));
2129   memset(&sSrc, 0, sizeof(sSrc));
2130   if( pTab ){
2131     sSrc.nSrc = 1;
2132     sSrc.a[0].zName = pTab->zName;
2133     sSrc.a[0].pTab = pTab;
2134     sSrc.a[0].iCursor = -1;
2135     if( pTab->pSchema!=pParse->db->aDb[1].pSchema ){
2136       /* Cause EP_FromDDL to be set on TK_FUNCTION nodes of non-TEMP
2137       ** schema elements */
2138       type |= NC_FromDDL;
2139     }
2140   }
2141   sNC.pParse = pParse;
2142   sNC.pSrcList = &sSrc;
2143   sNC.ncFlags = type | NC_IsDDL;
2144   if( (rc = sqlite3ResolveExprNames(&sNC, pExpr))!=SQLITE_OK ) return rc;
2145   if( pList ) rc = sqlite3ResolveExprListNames(&sNC, pList);
2146   return rc;
2147 }
2148