xref: /sqlite-3.40.0/test/fuzz2.test (revision 2b8c5a00)
1db83f823Sdrh# 2007 May 10
2db83f823Sdrh#
3db83f823Sdrh# The author disclaims copyright to this source code.  In place of
4db83f823Sdrh# a legal notice, here is a blessing:
5db83f823Sdrh#
6db83f823Sdrh#    May you do good and not evil.
7db83f823Sdrh#    May you find forgiveness for yourself and forgive others.
8db83f823Sdrh#    May you share freely, never taking more than you give.
9db83f823Sdrh#
10db83f823Sdrh#***********************************************************************
11db83f823Sdrh# This file implements regression tests for SQLite library.
12db83f823Sdrh#
13db83f823Sdrh# This file checks error recovery from malformed SQL strings.
14db83f823Sdrh#
15db83f823Sdrh
16db83f823Sdrhset testdir [file dirname $argv0]
17db83f823Sdrhsource $testdir/tester.tcl
18db83f823Sdrh
197e326c09Sdrh
207e326c09Sdrhproc fuzzcatch {sql} {
217e326c09Sdrh  return [lindex [catchsql $sql] 0]
227e326c09Sdrh}
237e326c09Sdrh
24db83f823Sdrhdo_test fuzz2-1.1 {
257e326c09Sdrh  fuzzcatch {SELECT ALL "AAAAAA" . * GROUP BY LIMIT round(1), #12}
267e326c09Sdrh} {1}
27db83f823Sdrhdo_test fuzz2-2.0 {
287e326c09Sdrh  fuzzcatch {SELECT + #100}
297e326c09Sdrh} {1}
30db83f823Sdrhdo_test fuzz2-2.1 {
317e326c09Sdrh  fuzzcatch {SELECT 1 WHERE ( #61 NOT MATCH ROUND( 1 ) )}
327e326c09Sdrh} {1}
33db83f823Sdrhdo_test fuzz2-2.2 {
347e326c09Sdrh  fuzzcatch {SELECT 1 LIMIT NOT #59 COLLATE AAAAAA NOT IN
35db83f823Sdrh    ( "AAAAAA" NOTNULL <= x'414141414141' IS NULL , ( ROUND ( 1.0 ) ) )}
367e326c09Sdrh} {1}
37db83f823Sdrhdo_test fuzz2-2.3 {
387e326c09Sdrh  fuzzcatch {INSERT OR REPLACE INTO AAAAAA . "AAAAAA" ( "AAAAAA" ) SELECT DISTINCT * , ( SELECT #252 IN ( SELECT DISTINCT AAAAAA . * ) )}
397e326c09Sdrh} {1}
40db83f823Sdrhdo_test fuzz2-2.4 {
417e326c09Sdrh  fuzzcatch {SELECT 1 LIMIT NOT #59 COLLATE AAAAAA NOT IN round(1.0)}
427e326c09Sdrh} {1}
43db83f823Sdrhdo_test fuzz2-2.5 {
447e326c09Sdrh  fuzzcatch {SELECT( #239 )}
457e326c09Sdrh} {1}
46db83f823Sdrhdo_test fuzz2-2.6 {
477e326c09Sdrh  fuzzcatch {DELETE FROM AAAAAA WHERE #65 NOT NULL}
487e326c09Sdrh} {1}
49db83f823Sdrhdo_test fuzz2-2.7 {
507e326c09Sdrh  fuzzcatch {ATTACH ROUND( 1.0 ) in  AAAAAA . "AAAAAA" AS #122 ISNULL}
517e326c09Sdrh} {1}
52db83f823Sdrhdo_test fuzz2-2.8 {
537e326c09Sdrh  fuzzcatch {SELECT 1 LIMIT  #122 ISNULL}
547e326c09Sdrh} {1}
55db83f823Sdrhdo_test fuzz2-2.9 {
567e326c09Sdrh  fuzzcatch {CREATE VIEW AAAAAA . "AAAAAA" AS SELECT DISTINCT #162 IS NULL "AAAAAA"}
577e326c09Sdrh} {1}
58db83f823Sdrhdo_test fuzz2-2.10 {
597e326c09Sdrh  fuzzcatch {DELETE FROM AAAAAA WHERE #202 IS NOT NULL ISNULL}
607e326c09Sdrh} {1}
61db83f823Sdrhdo_test fuzz2-2.11 {
627e326c09Sdrh  fuzzcatch {UPDATE OR IGNORE "AAAAAA" . "AAAAAA" SET "AAAAAA" = NOT #96}
637e326c09Sdrh} {1}
64db83f823Sdrhdo_test fuzz2-2.12 {
657e326c09Sdrh  fuzzcatch {SELECT - #196}
667e326c09Sdrh} {1}
67f33a7a8cSshaneh
68f33a7a8cSshanehifcapable {trigger} {  # Only do the following tests if triggers are enabled
69f33a7a8cSshaneh
70db83f823Sdrhdo_test fuzz2-3.0 {
717e326c09Sdrh  fuzzcatch {CREATE TRIGGER "AAAAAA" . "AAAAAA" AFTER UPDATE OF "AAAAAA" , "AAAAAA" ON "AAAAAA" . "AAAAAA" FOR EACH ROW BEGIN UPDATE AAAAAA SET "AAAAAA" = #162;  END}
727e326c09Sdrh} {1}
73db83f823Sdrhdo_test fuzz2-3.1 {
747e326c09Sdrh  fuzzcatch {CREATE TRIGGER IF NOT EXISTS "AAAAAA" UPDATE ON "AAAAAA" . AAAAAA FOR EACH ROW BEGIN DELETE FROM "AAAAAA" ; INSERT INTO AAAAAA ( "AAAAAA" ) SELECT DISTINCT "AAAAAA" "AAAAAA" , #167 AAAAAA , "AAAAAA" . * ORDER BY "AAAAAA" ASC , x'414141414141' BETWEEN RAISE ( FAIL , "AAAAAA" ) AND AAAAAA ( * ) NOT NULL DESC LIMIT AAAAAA ; REPLACE INTO AAAAAA ( AAAAAA ) VALUES ( AAAAAA ( * ) ) ; END}
757e326c09Sdrh} {1}
76db83f823Sdrhdo_test fuzz2-3.2 {
777e326c09Sdrh  fuzzcatch {CREATE TEMP TRIGGER IF NOT EXISTS AAAAAA . "AAAAAA" BEFORE UPDATE OF "AAAAAA" ON AAAAAA . "AAAAAA" BEGIN SELECT ALL * , #175 "AAAAAA" FROM "AAAAAA" . AAAAAA;  END}
787e326c09Sdrh} {1}
79f33a7a8cSshaneh
80f33a7a8cSshaneh} ;# End of ifcapable {trigger}
81f33a7a8cSshaneh
82db83f823Sdrhdo_test fuzz2-4.0 {
837e326c09Sdrh  fuzzcatch {ATTACH DATABASE #168 AS whatever}
847e326c09Sdrh} {1}
85db83f823Sdrhdo_test fuzz2-4.1 {
867e326c09Sdrh  fuzzcatch {DETACH #133}
877e326c09Sdrh} {1}
88db83f823Sdrhdo_test fuzz2-5.0 {
897e326c09Sdrh  fuzzcatch {SELECT 1 LIMIT ( SELECT DISTINCT * , AAAAAA , * , AAAAAA , "AAAAAA" . * FROM "AAAAAA" ON ROUND( 1 ) COLLATE AAAAAA OR "AAAAAA" USING ( AAAAAA , "AAAAAA" ) WHERE ROUND( 1 ) GROUP BY ORDER BY #84 ASC , #44 DESC , ( SELECT "AAAAAA" . * , "AAAAAA" . * FROM , ( ) "AAAAAA" USING ( )}
907e326c09Sdrh} {1}
91db83f823Sdrhdo_test fuzz2-5.1 {
927e326c09Sdrh  fuzzcatch {SELECT 1 WHERE 1 == AAAAAA ( * ) BETWEEN + - ~ + "AAAAAA" . AAAAAA | RAISE ( IGNORE ) COLLATE AAAAAA NOT IN ( SELECT DISTINCT "AAAAAA" . * , * , * WHERE ( SELECT ALL AAAAAA AS "AAAAAA" HAVING CAST ( "AAAAAA" . "AAAAAA" . "AAAAAA" AS AAAAAA ) ORDER BY , , IS NULL ASC , ~ AND DESC LIMIT ( ( "AAAAAA" ) NOT BETWEEN ( ) NOT IN ( ) AND AAAAAA ( ) IS NOT NULL ) OFFSET AAAAAA ( ALL , , ) ) GROUP BY ORDER BY "AAAAAA" . AAAAAA ASC , NULL IN ( SELECT UNION ALL SELECT ALL WHERE HAVING ORDER BY LIMIT UNION SELECT DISTINCT FROM ( ) WHERE + HAVING >> ORDER BY LIMIT . . , "AAAAAA" ) , CAST ( ~ "AAAAAA" . AAAAAA AS "AAAAAA" AAAAAA "AAAAAA" ( + 4294967295 , - 4294967296.0 ) ) ASC LIMIT AAAAAA INTERSECT SELECT ALL * GROUP BY , AAAAAA ( DISTINCT , ) != #241 NOT IN ( , , ) , , CTIME_KW HAVING AAAAAA ORDER BY #103 DESC , #81 ASC LIMIT AAAAAA OFFSET ~ AAAAAA ( ALL AAAAAA . AAAAAA >= AAAAAA . "AAAAAA" . "AAAAAA" ) ) NOTNULL NOT NULL}
937e326c09Sdrh} {1}
94db83f823Sdrhdo_test fuzz2-5.2 {
957e326c09Sdrh  fuzzcatch {SELECT 1 WHERE 1 == AAAAAA ( * ) BETWEEN + - ~ + "AAAAAA" . AAAAAA | RAISE ( IGNORE ) COLLATE AAAAAA NOT IN ( SELECT DISTINCT "AAAAAA" . * , * , * WHERE ( SELECT ALL AAAAAA AS "AAAAAA" HAVING CAST ( "AAAAAA" . "AAAAAA" . "AAAAAA" AS AAAAAA ) ORDER BY , , IS NULL ASC , ~ AND DESC LIMIT ( ( "AAAAAA" ) NOT BETWEEN ( ) NOT IN ( ) AND AAAAAA ( ) IS NOT NULL ) OFFSET AAAAAA ( ALL , , ) ) GROUP BY ORDER BY "AAAAAA" . AAAAAA ASC , NULL IN ( SELECT UNION ALL SELECT ALL WHERE HAVING ORDER BY LIMIT UNION SELECT DISTINCT FROM ( ) WHERE + HAVING >> ORDER BY LIMIT . . , "AAAAAA" ) , CAST ( ~ "AAAAAA" . AAAAAA AS "AAAAAA" AAAAAA "AAAAAA" ( + 4294967295 , - 4294967296.0 ) ) ASC LIMIT AAAAAA INTERSECT SELECT ALL * GROUP BY , AAAAAA ( DISTINCT , ) != #241 NOT IN ( , , ) , , CTIME_KW HAVING AAAAAA ORDER BY #103 DESC , #81 ASC LIMIT AAAAAA OFFSET ~ AAAAAA ( ALL AAAAAA . AAAAAA >= AAAAAA . "AAAAAA" . "AAAAAA" ) ) NOTNULL NOT NULL}
967e326c09Sdrh} {1}
97db83f823Sdrhdo_test fuzz2-5.3 {
987e326c09Sdrh  fuzzcatch {UPDATE "AAAAAA" SET "AAAAAA" = - EXISTS ( SELECT DISTINCT * , * ORDER BY #202 ASC , #147 , ~ AAAAAA . "AAAAAA" ASC LIMIT AAAAAA . "AAAAAA" , RAISE ( ABORT , AAAAAA ) UNION ALL SELECT DISTINCT AAAAAA . * , * FROM ( SELECT DISTINCT}
997e326c09Sdrh} {1}
100db83f823Sdrhdo_test fuzz2-5.4 {
1017e326c09Sdrh  fuzzcatch {REPLACE INTO AAAAAA SELECT DISTINCT "AAAAAA" . * WHERE AAAAAA ( AAAAAA ( ) ) GROUP BY AAAAAA . AAAAAA . "AAAAAA" IN "AAAAAA" | AAAAAA ( ALL , ) ORDER BY #238, #92 DESC LIMIT 0 OFFSET - RAISE ( IGNORE ) NOT NULL > RAISE ( IGNORE ) IS NULL}
1027e326c09Sdrh} {1}
103db83f823Sdrhdo_test fuzz2-5.5 {
1047e326c09Sdrh  fuzzcatch {SELECT ALL * GROUP BY EXISTS ( SELECT "AAAAAA" . * , AAAAAA ( * ) AS AAAAAA FROM "AAAAAA" . "AAAAAA" AS "AAAAAA" USING ( AAAAAA , "AAAAAA" , "AAAAAA" ) WHERE AAAAAA ( DISTINCT ) - RAISE ( FAIL , "AAAAAA" ) HAVING "AAAAAA" . "AAAAAA" . AAAAAA ORDER BY #182 , #55 ) BETWEEN EXISTS ( SELECT ALL * FROM ( ( }
1057e326c09Sdrh} {1}
106db83f823Sdrh
107655814d2Sdrh# Test cases discovered by Michal Zalewski on 2015-01-03 and reported on the
108655814d2Sdrh# sqlite-users mailing list.  All of these cases cause segfaults in
109655814d2Sdrh# SQLite 3.8.7.4 and earlier.
110655814d2Sdrh#
111655814d2Sdrhdo_test fuzz2-6.1 {
112655814d2Sdrh  catchsql {SELECT n()AND+#0;}
113655814d2Sdrh} {1 {near "#0": syntax error}}
114655814d2Sdrhdo_test fuzz2-6.2 {
115655814d2Sdrh  catchsql {SELECT strftime()}
116655814d2Sdrh} {0 {{}}}
117655814d2Sdrhdo_test fuzz2-6.3 {
118655814d2Sdrh  catchsql {DETACH(SELECT group_concat(q));}
119655814d2Sdrh} {1 {no such column: q}}
120655814d2Sdrhdo_test fuzz2-6.4a {
121655814d2Sdrh  db eval {DROP TABLE IF EXISTS t0; CREATE TABLE t0(t);}
122655814d2Sdrh  catchsql {INSERT INTO t0 SELECT strftime();}
123655814d2Sdrh} {0 {}}
124655814d2Sdrhdo_test fuzz2-6.4b {
125655814d2Sdrh  db eval {SELECT quote(t) FROM t0}
126655814d2Sdrh} {NULL}
127655814d2Sdrh
128*2b8c5a00Sdrh# Another test case discovered by Michal Zalewski, this on on 2015-01-22.
129*2b8c5a00Sdrh# Ticket 32b63d542433ca6757cd695aca42addf8ed67aa6
130*2b8c5a00Sdrh#
131*2b8c5a00Sdrhdo_test fuzz2-7.1 {
132*2b8c5a00Sdrh  catchsql {select e.*,0 from(s,(L))e;}
133*2b8c5a00Sdrh} {1 {no such table: s}}
134*2b8c5a00Sdrhdo_test fuzz2-7.2 {
135*2b8c5a00Sdrh  catchsql {SELECT c.* FROM (a,b) AS c}
136*2b8c5a00Sdrh} {1 {no such table: a}}
137*2b8c5a00Sdrh
138655814d2Sdrh
139db83f823Sdrhfinish_test
140