AryaWu/sqlite
0
1/*2** 2001 September 153**4** The author disclaims copyright to this source code. In place of5** a legal notice, here is a blessing:6**7** May you do good and not evil.8** May you find forgiveness for yourself and forgive others.9** May you share freely, never taking more than you give.10**11*************************************************************************12** The code in this file implements the function that runs the13** bytecode of a prepared statement.14**15** Various scripts scan this source file in order to generate HTML16** documentation, headers files, or other derived files. The formatting17** of the code in this file is, therefore, important. See other comments18** in this file for details. If in doubt, do not deviate from existing19** commenting and indentation practices when changing or adding code.20*/21#include "sqliteInt.h"22#include "vdbeInt.h"23 24/*25** High-resolution hardware timer used for debugging and testing only.26*/27#if defined(VDBE_PROFILE) \28 || defined(SQLITE_PERFORMANCE_TRACE) \29 || defined(SQLITE_ENABLE_STMT_SCANSTATUS)30# include "hwtime.h"31#endif32 33/*34** Invoke this macro on memory cells just prior to changing the35** value of the cell. This macro verifies that shallow copies are36** not misused. A shallow copy of a string or blob just copies a37** pointer to the string or blob, not the content. If the original38** is changed while the copy is still in use, the string or blob might39** be changed out from under the copy. This macro verifies that nothing40** like that ever happens.41*/42#ifdef SQLITE_DEBUG43# define memAboutToChange(P,M) sqlite3VdbeMemAboutToChange(P,M)44#else45# define memAboutToChange(P,M)46#endif47 48/*49** The following global variable is incremented every time a cursor50** moves, either by the OP_SeekXX, OP_Next, or OP_Prev opcodes. The test51** procedures use this information to make sure that indices are52** working correctly. This variable has no function other than to53** help verify the correct operation of the library.54*/55#ifdef SQLITE_TEST56int sqlite3_search_count = 0;57#endif58 59/*60** When this global variable is positive, it gets decremented once before61** each instruction in the VDBE. When it reaches zero, the u1.isInterrupted62** field of the sqlite3 structure is set in order to simulate an interrupt.63**64** This facility is used for testing purposes only. It does not function65** in an ordinary build.66*/67#ifdef SQLITE_TEST68int sqlite3_interrupt_count = 0;69#endif70 71/*72** The next global variable is incremented each type the OP_Sort opcode73** is executed. The test procedures use this information to make sure that74** sorting is occurring or not occurring at appropriate times. This variable75** has no function other than to help verify the correct operation of the76** library.77*/78#ifdef SQLITE_TEST79int sqlite3_sort_count = 0;80#endif81 82/*83** The next global variable records the size of the largest MEM_Blob84** or MEM_Str that has been used by a VDBE opcode. The test procedures85** use this information to make sure that the zero-blob functionality86** is working correctly. This variable has no function other than to87** help verify the correct operation of the library.88*/89#ifdef SQLITE_TEST90int sqlite3_max_blobsize = 0;91static void updateMaxBlobsize(Mem *p){92 if( (p->flags & (MEM_Str|MEM_Blob))!=0 && p->n>sqlite3_max_blobsize ){93 sqlite3_max_blobsize = p->n;94 }95}96#endif97 98/*99** This macro evaluates to true if either the update hook or the preupdate100** hook are enabled for database connect DB.101*/102#ifdef SQLITE_ENABLE_PREUPDATE_HOOK103# define HAS_UPDATE_HOOK(DB) ((DB)->xPreUpdateCallback||(DB)->xUpdateCallback)104#else105# define HAS_UPDATE_HOOK(DB) ((DB)->xUpdateCallback)106#endif107 108/*109** The next global variable is incremented each time the OP_Found opcode110** is executed. This is used to test whether or not the foreign key111** operation implemented using OP_FkIsZero is working. This variable112** has no function other than to help verify the correct operation of the113** library.114*/115#ifdef SQLITE_TEST116int sqlite3_found_count = 0;117#endif118 119/*120** Test a register to see if it exceeds the current maximum blob size.121** If it does, record the new maximum blob size.122*/123#if defined(SQLITE_TEST) && !defined(SQLITE_UNTESTABLE)124# define UPDATE_MAX_BLOBSIZE(P) updateMaxBlobsize(P)125#else126# define UPDATE_MAX_BLOBSIZE(P)127#endif128 129#ifdef SQLITE_DEBUG130/* This routine provides a convenient place to set a breakpoint during131** tracing with PRAGMA vdbe_trace=on. The breakpoint fires right after132** each opcode is printed. Variables "pc" (program counter) and pOp are133** available to add conditionals to the breakpoint. GDB example:134**135** break test_trace_breakpoint if pc=22136**137** Other useful labels for breakpoints include:138** test_addop_breakpoint(pc,pOp)139** sqlite3CorruptError(lineno)140** sqlite3MisuseError(lineno)141** sqlite3CantopenError(lineno)142*/143static void test_trace_breakpoint(int pc, Op *pOp, Vdbe *v){144 static u64 n = 0;145 (void)pc;146 (void)pOp;147 (void)v;148 n++;149 if( n==LARGEST_UINT64 ) abort(); /* So that n is used, preventing a warning */150}151#endif152 153/*154** Invoke the VDBE coverage callback, if that callback is defined. This155** feature is used for test suite validation only and does not appear an156** production builds.157**158** M is the type of branch. I is the direction taken for this instance of159** the branch.160**161** M: 2 - two-way branch (I=0: fall-thru 1: jump )162** 3 - two-way + NULL (I=0: fall-thru 1: jump 2: NULL )163** 4 - OP_Jump (I=0: jump p1 1: jump p2 2: jump p3)164**165** In other words, if M is 2, then I is either 0 (for fall-through) or166** 1 (for when the branch is taken). If M is 3, the I is 0 for an167** ordinary fall-through, I is 1 if the branch was taken, and I is 2168** if the result of comparison is NULL. For M=3, I=2 the jump may or169** may not be taken, depending on the SQLITE_JUMPIFNULL flags in p5.170** When M is 4, that means that an OP_Jump is being run. I is 0, 1, or 2171** depending on if the operands are less than, equal, or greater than.172**173** iSrcLine is the source code line (from the __LINE__ macro) that174** generated the VDBE instruction combined with flag bits. The source175** code line number is in the lower 24 bits of iSrcLine and the upper176** 8 bytes are flags. The lower three bits of the flags indicate177** values for I that should never occur. For example, if the branch is178** always taken, the flags should be 0x05 since the fall-through and179** alternate branch are never taken. If a branch is never taken then180** flags should be 0x06 since only the fall-through approach is allowed.181**182** Bit 0x08 of the flags indicates an OP_Jump opcode that is only183** interested in equal or not-equal. In other words, I==0 and I==2184** should be treated as equivalent185**186** Since only a line number is retained, not the filename, this macro187** only works for amalgamation builds. But that is ok, since these macros188** should be no-ops except for special builds used to measure test coverage.189*/190#if !defined(SQLITE_VDBE_COVERAGE)191# define VdbeBranchTaken(I,M)192#else193# define VdbeBranchTaken(I,M) vdbeTakeBranch(pOp->iSrcLine,I,M)194 static void vdbeTakeBranch(u32 iSrcLine, u8 I, u8 M){195 u8 mNever;196 assert( I<=2 ); /* 0: fall through, 1: taken, 2: alternate taken */197 assert( M<=4 ); /* 2: two-way branch, 3: three-way branch, 4: OP_Jump */198 assert( I<M ); /* I can only be 2 if M is 3 or 4 */199 /* Transform I from a integer [0,1,2] into a bitmask of [1,2,4] */200 I = 1<<I;201 /* The upper 8 bits of iSrcLine are flags. The lower three bits of202 ** the flags indicate directions that the branch can never go. If203 ** a branch really does go in one of those directions, assert right204 ** away. */205 mNever = iSrcLine >> 24;206 assert( (I & mNever)==0 );207 if( sqlite3GlobalConfig.xVdbeBranch==0 ) return; /*NO_TEST*/208 /* Invoke the branch coverage callback with three arguments:209 ** iSrcLine - the line number of the VdbeCoverage() macro, with210 ** flags removed.211 ** I - Mask of bits 0x07 indicating which cases are are212 ** fulfilled by this instance of the jump. 0x01 means213 ** fall-thru, 0x02 means taken, 0x04 means NULL. Any214 ** impossible cases (ex: if the comparison is never NULL)215 ** are filled in automatically so that the coverage216 ** measurement logic does not flag those impossible cases217 ** as missed coverage.218 ** M - Type of jump. Same as M argument above219 */220 I |= mNever;221 if( M==2 ) I |= 0x04;222 if( M==4 ){223 I |= 0x08;224 if( (mNever&0x08)!=0 && (I&0x05)!=0) I |= 0x05; /*NO_TEST*/225 }226 sqlite3GlobalConfig.xVdbeBranch(sqlite3GlobalConfig.pVdbeBranchArg,227 iSrcLine&0xffffff, I, M);228 }229#endif230 231/*232** An ephemeral string value (signified by the MEM_Ephem flag) contains233** a pointer to a dynamically allocated string where some other entity234** is responsible for deallocating that string. Because the register235** does not control the string, it might be deleted without the register236** knowing it.237**238** This routine converts an ephemeral string into a dynamically allocated239** string that the register itself controls. In other words, it240** converts an MEM_Ephem string into a string with P.z==P.zMalloc.241*/242#define Deephemeralize(P) \243 if( ((P)->flags&MEM_Ephem)!=0 \244 && sqlite3VdbeMemMakeWriteable(P) ){ goto no_mem;}245 246/* Return true if the cursor was opened using the OP_OpenSorter opcode. */247#define isSorter(x) ((x)->eCurType==CURTYPE_SORTER)248 249/*250** Allocate VdbeCursor number iCur. Return a pointer to it. Return NULL251** if we run out of memory.252*/253static VdbeCursor *allocateCursor(254 Vdbe *p, /* The virtual machine */255 int iCur, /* Index of the new VdbeCursor */256 int nField, /* Number of fields in the table or index */257 u8 eCurType /* Type of the new cursor */258){259 /* Find the memory cell that will be used to store the blob of memory260 ** required for this VdbeCursor structure. It is convenient to use a261 ** vdbe memory cell to manage the memory allocation required for a262 ** VdbeCursor structure for the following reasons:263 **264 ** * Sometimes cursor numbers are used for a couple of different265 ** purposes in a vdbe program. The different uses might require266 ** different sized allocations. Memory cells provide growable267 ** allocations.268 **269 ** * When using ENABLE_MEMORY_MANAGEMENT, memory cell buffers can270 ** be freed lazily via the sqlite3_release_memory() API. This271 ** minimizes the number of malloc calls made by the system.272 **273 ** The memory cell for cursor 0 is aMem[0]. The rest are allocated from274 ** the top of the register space. Cursor 1 is at Mem[p->nMem-1].275 ** Cursor 2 is at Mem[p->nMem-2]. And so forth.276 */277 Mem *pMem = iCur>0 ? &p->aMem[p->nMem-iCur] : p->aMem;278 279 i64 nByte;280 VdbeCursor *pCx = 0;281 nByte = SZ_VDBECURSOR(nField);282 assert( ROUND8(nByte)==nByte );283 if( eCurType==CURTYPE_BTREE ) nByte += sqlite3BtreeCursorSize();284 285 assert( iCur>=0 && iCur<p->nCursor );286 if( p->apCsr[iCur] ){ /*OPTIMIZATION-IF-FALSE*/287 sqlite3VdbeFreeCursorNN(p, p->apCsr[iCur]);288 p->apCsr[iCur] = 0;289 }290 291 /* There used to be a call to sqlite3VdbeMemClearAndResize() to make sure292 ** the pMem used to hold space for the cursor has enough storage available293 ** in pMem->zMalloc. But for the special case of the aMem[] entries used294 ** to hold cursors, it is faster to in-line the logic. */295 assert( pMem->flags==MEM_Undefined );296 assert( (pMem->flags & MEM_Dyn)==0 );297 assert( pMem->szMalloc==0 || pMem->z==pMem->zMalloc );298 if( pMem->szMalloc<nByte ){299 if( pMem->szMalloc>0 ){300 sqlite3DbFreeNN(pMem->db, pMem->zMalloc);301 }302 pMem->z = pMem->zMalloc = sqlite3DbMallocRaw(pMem->db, nByte);303 if( pMem->zMalloc==0 ){304 pMem->szMalloc = 0;305 return 0;306 }307 pMem->szMalloc = (int)nByte;308 }309 310 p->apCsr[iCur] = pCx = (VdbeCursor*)pMem->zMalloc;311 memset(pCx, 0, offsetof(VdbeCursor,pAltCursor));312 pCx->eCurType = eCurType;313 pCx->nField = nField;314 pCx->aOffset = &pCx->aType[nField];315 if( eCurType==CURTYPE_BTREE ){316 assert( ROUND8(SZ_VDBECURSOR(nField))==SZ_VDBECURSOR(nField) );317 pCx->uc.pCursor = (BtCursor*)&pMem->z[SZ_VDBECURSOR(nField)];318 sqlite3BtreeCursorZero(pCx->uc.pCursor);319 }320 return pCx;321}322 323/*324** The string in pRec is known to look like an integer and to have a325** floating point value of rValue. Return true and set *piValue to the326** integer value if the string is in range to be an integer. Otherwise,327** return false.328*/329static int alsoAnInt(Mem *pRec, double rValue, i64 *piValue){330 i64 iValue;331 iValue = sqlite3RealToI64(rValue);332 if( sqlite3RealSameAsInt(rValue,iValue) ){333 *piValue = iValue;334 return 1;335 }336 return 0==sqlite3Atoi64(pRec->z, piValue, pRec->n, pRec->enc);337}338 339/*340** Try to convert a value into a numeric representation if we can341** do so without loss of information. In other words, if the string342** looks like a number, convert it into a number. If it does not343** look like a number, leave it alone.344**345** If the bTryForInt flag is true, then extra effort is made to give346** an integer representation. Strings that look like floating point347** values but which have no fractional component (example: '48.00')348** will have a MEM_Int representation when bTryForInt is true.349**350** If bTryForInt is false, then if the input string contains a decimal351** point or exponential notation, the result is only MEM_Real, even352** if there is an exact integer representation of the quantity.353*/354static void applyNumericAffinity(Mem *pRec, int bTryForInt){355 double rValue;356 u8 enc = pRec->enc;357 int rc;358 assert( (pRec->flags & (MEM_Str|MEM_Int|MEM_Real|MEM_IntReal))==MEM_Str );359 rc = sqlite3AtoF(pRec->z, &rValue, pRec->n, enc);360 if( rc<=0 ) return;361 if( rc==1 && alsoAnInt(pRec, rValue, &pRec->u.i) ){362 pRec->flags |= MEM_Int;363 }else{364 pRec->u.r = rValue;365 pRec->flags |= MEM_Real;366 if( bTryForInt ) sqlite3VdbeIntegerAffinity(pRec);367 }368 /* TEXT->NUMERIC is many->one. Hence, it is important to invalidate the369 ** string representation after computing a numeric equivalent, because the370 ** string representation might not be the canonical representation for the371 ** numeric value. Ticket [343634942dd54ab57b7024] 2018-01-31. */372 pRec->flags &= ~MEM_Str;373}374 375/*376** Processing is determine by the affinity parameter:377**378** SQLITE_AFF_INTEGER:379** SQLITE_AFF_REAL:380** SQLITE_AFF_NUMERIC:381** Try to convert pRec to an integer representation or a382** floating-point representation if an integer representation383** is not possible. Note that the integer representation is384** always preferred, even if the affinity is REAL, because385** an integer representation is more space efficient on disk.386**387** SQLITE_AFF_FLEXNUM:388** If the value is text, then try to convert it into a number of389** some kind (integer or real) but do not make any other changes.390**391** SQLITE_AFF_TEXT:392** Convert pRec to a text representation.393**394** SQLITE_AFF_BLOB:395** SQLITE_AFF_NONE:396** No-op. pRec is unchanged.397*/398static void applyAffinity(399 Mem *pRec, /* The value to apply affinity to */400 char affinity, /* The affinity to be applied */401 u8 enc /* Use this text encoding */402){403 if( affinity>=SQLITE_AFF_NUMERIC ){404 assert( affinity==SQLITE_AFF_INTEGER || affinity==SQLITE_AFF_REAL405 || affinity==SQLITE_AFF_NUMERIC || affinity==SQLITE_AFF_FLEXNUM );406 if( (pRec->flags & MEM_Int)==0 ){ /*OPTIMIZATION-IF-FALSE*/407 if( (pRec->flags & (MEM_Real|MEM_IntReal))==0 ){408 if( pRec->flags & MEM_Str ) applyNumericAffinity(pRec,1);409 }else if( affinity<=SQLITE_AFF_REAL ){410 sqlite3VdbeIntegerAffinity(pRec);411 }412 }413 }else if( affinity==SQLITE_AFF_TEXT ){414 /* Only attempt the conversion to TEXT if there is an integer or real415 ** representation (blob and NULL do not get converted) but no string416 ** representation. It would be harmless to repeat the conversion if417 ** there is already a string rep, but it is pointless to waste those418 ** CPU cycles. */419 if( 0==(pRec->flags&MEM_Str) ){ /*OPTIMIZATION-IF-FALSE*/420 if( (pRec->flags&(MEM_Real|MEM_Int|MEM_IntReal)) ){421 testcase( pRec->flags & MEM_Int );422 testcase( pRec->flags & MEM_Real );423 testcase( pRec->flags & MEM_IntReal );424 sqlite3VdbeMemStringify(pRec, enc, 1);425 }426 }427 pRec->flags &= ~(MEM_Real|MEM_Int|MEM_IntReal);428 }429}430 431/*432** Try to convert the type of a function argument or a result column433** into a numeric representation. Use either INTEGER or REAL whichever434** is appropriate. But only do the conversion if it is possible without435** loss of information and return the revised type of the argument.436*/437int sqlite3_value_numeric_type(sqlite3_value *pVal){438 int eType = sqlite3_value_type(pVal);439 if( eType==SQLITE_TEXT ){440 Mem *pMem = (Mem*)pVal;441 applyNumericAffinity(pMem, 0);442 eType = sqlite3_value_type(pVal);443 }444 return eType;445}446 447/*448** Exported version of applyAffinity(). This one works on sqlite3_value*,449** not the internal Mem* type.450*/451void sqlite3ValueApplyAffinity(452 sqlite3_value *pVal,453 u8 affinity,454 u8 enc455){456 applyAffinity((Mem *)pVal, affinity, enc);457}458 459/*460** pMem currently only holds a string type (or maybe a BLOB that we can461** interpret as a string if we want to). Compute its corresponding462** numeric type, if has one. Set the pMem->u.r and pMem->u.i fields463** accordingly.464*/465static u16 SQLITE_NOINLINE computeNumericType(Mem *pMem){466 int rc;467 sqlite3_int64 ix;468 assert( (pMem->flags & (MEM_Int|MEM_Real|MEM_IntReal))==0 );469 assert( (pMem->flags & (MEM_Str|MEM_Blob))!=0 );470 if( ExpandBlob(pMem) ){471 pMem->u.i = 0;472 return MEM_Int;473 }474 rc = sqlite3AtoF(pMem->z, &pMem->u.r, pMem->n, pMem->enc);475 if( rc<=0 ){476 if( rc==0 && sqlite3Atoi64(pMem->z, &ix, pMem->n, pMem->enc)<=1 ){477 pMem->u.i = ix;478 return MEM_Int;479 }else{480 return MEM_Real;481 }482 }else if( rc==1 && sqlite3Atoi64(pMem->z, &ix, pMem->n, pMem->enc)==0 ){483 pMem->u.i = ix;484 return MEM_Int;485 }486 return MEM_Real;487}488 489/*490** Return the numeric type for pMem, either MEM_Int or MEM_Real or both or491** none. 492**493** Unlike applyNumericAffinity(), this routine does not modify pMem->flags.494** But it does set pMem->u.r and pMem->u.i appropriately.495*/496static u16 numericType(Mem *pMem){497 assert( (pMem->flags & MEM_Null)==0498 || pMem->db==0 || pMem->db->mallocFailed );499 if( pMem->flags & (MEM_Int|MEM_Real|MEM_IntReal|MEM_Null) ){500 testcase( pMem->flags & MEM_Int );501 testcase( pMem->flags & MEM_Real );502 testcase( pMem->flags & MEM_IntReal );503 return pMem->flags & (MEM_Int|MEM_Real|MEM_IntReal|MEM_Null);504 }505 assert( pMem->flags & (MEM_Str|MEM_Blob) );506 testcase( pMem->flags & MEM_Str );507 testcase( pMem->flags & MEM_Blob );508 return computeNumericType(pMem);509 return 0;510}511 512#ifdef SQLITE_DEBUG513/*514** Write a nice string representation of the contents of cell pMem515** into buffer zBuf, length nBuf.516*/517void sqlite3VdbeMemPrettyPrint(Mem *pMem, StrAccum *pStr){518 int f = pMem->flags;519 static const char *const encnames[] = {"(X)", "(8)", "(16LE)", "(16BE)"};520 if( f&MEM_Blob ){521 int i;522 char c;523 if( f & MEM_Dyn ){524 c = 'z';525 assert( (f & (MEM_Static|MEM_Ephem))==0 );526 }else if( f & MEM_Static ){527 c = 't';528 assert( (f & (MEM_Dyn|MEM_Ephem))==0 );529 }else if( f & MEM_Ephem ){530 c = 'e';531 assert( (f & (MEM_Static|MEM_Dyn))==0 );532 }else{533 c = 's';534 }535 sqlite3_str_appendf(pStr, "%cx[", c);536 for(i=0; i<25 && i<pMem->n; i++){537 sqlite3_str_appendf(pStr, "%02X", ((int)pMem->z[i] & 0xFF));538 }539 sqlite3_str_appendf(pStr, "|");540 for(i=0; i<25 && i<pMem->n; i++){541 char z = pMem->z[i];542 sqlite3_str_appendchar(pStr, 1, (z<32||z>126)?'.':z);543 }544 sqlite3_str_appendf(pStr,"]");545 if( f & MEM_Zero ){546 sqlite3_str_appendf(pStr, "+%dz",pMem->u.nZero);547 }548 }else if( f & MEM_Str ){549 int j;550 u8 c;551 if( f & MEM_Dyn ){552 c = 'z';553 assert( (f & (MEM_Static|MEM_Ephem))==0 );554 }else if( f & MEM_Static ){555 c = 't';556 assert( (f & (MEM_Dyn|MEM_Ephem))==0 );557 }else if( f & MEM_Ephem ){558 c = 'e';559 assert( (f & (MEM_Static|MEM_Dyn))==0 );560 }else{561 c = 's';562 }563 sqlite3_str_appendf(pStr, " %c%d[", c, pMem->n);564 for(j=0; j<25 && j<pMem->n; j++){565 c = pMem->z[j];566 sqlite3_str_appendchar(pStr, 1, (c>=0x20&&c<=0x7f) ? c : '.');567 }568 sqlite3_str_appendf(pStr, "]%s", encnames[pMem->enc]);569 if( f & MEM_Term ){570 sqlite3_str_appendf(pStr, "(0-term)");571 }572 }573}574#endif575 576#ifdef SQLITE_DEBUG577/*578** Print the value of a register for tracing purposes:579*/580static void memTracePrint(Mem *p){581 if( p->flags & MEM_Undefined ){582 printf(" undefined");583 }else if( p->flags & MEM_Null ){584 printf(p->flags & MEM_Zero ? " NULL-nochng" : " NULL");585 }else if( (p->flags & (MEM_Int|MEM_Str))==(MEM_Int|MEM_Str) ){586 printf(" si:%lld", p->u.i);587 }else if( (p->flags & (MEM_IntReal))!=0 ){588 printf(" ir:%lld", p->u.i);589 }else if( p->flags & MEM_Int ){590 printf(" i:%lld", p->u.i);591#ifndef SQLITE_OMIT_FLOATING_POINT592 }else if( p->flags & MEM_Real ){593 printf(" r:%.17g", p->u.r);594#endif595 }else if( sqlite3VdbeMemIsRowSet(p) ){596 printf(" (rowset)");597 }else{598 StrAccum acc;599 char zBuf[1000];600 sqlite3StrAccumInit(&acc, 0, zBuf, sizeof(zBuf), 0);601 sqlite3VdbeMemPrettyPrint(p, &acc);602 printf(" %s", sqlite3StrAccumFinish(&acc));603 }604 if( p->flags & MEM_Subtype ) printf(" subtype=0x%02x", p->eSubtype);605}606static void registerTrace(int iReg, Mem *p){607 printf("R[%d] = ", iReg);608 memTracePrint(p);609 if( p->pScopyFrom ){610 assert( p->pScopyFrom->bScopy );611 printf(" <== R[%d]", (int)(p->pScopyFrom - &p[-iReg]));612 }613 printf("\n");614 sqlite3VdbeCheckMemInvariants(p);615}616/**/ void sqlite3PrintMem(Mem *pMem){617 memTracePrint(pMem);618 printf("\n");619 fflush(stdout);620}621#endif622 623#ifdef SQLITE_DEBUG624/*625** Show the values of all registers in the virtual machine. Used for626** interactive debugging.627*/628void sqlite3VdbeRegisterDump(Vdbe *v){629 int i;630 for(i=1; i<v->nMem; i++) registerTrace(i, v->aMem+i);631}632#endif /* SQLITE_DEBUG */633 634 635#ifdef SQLITE_DEBUG636# define REGISTER_TRACE(R,M) if(db->flags&SQLITE_VdbeTrace)registerTrace(R,M)637#else638# define REGISTER_TRACE(R,M)639#endif640 641#ifndef NDEBUG642/*643** This function is only called from within an assert() expression. It644** checks that the sqlite3.nTransaction variable is correctly set to645** the number of non-transaction savepoints currently in the646** linked list starting at sqlite3.pSavepoint.647**648** Usage:649**650** assert( checkSavepointCount(db) );651*/652static int checkSavepointCount(sqlite3 *db){653 int n = 0;654 Savepoint *p;655 for(p=db->pSavepoint; p; p=p->pNext) n++;656 assert( n==(db->nSavepoint + db->isTransactionSavepoint) );657 return 1;658}659#endif660 661/*662** Return the register of pOp->p2 after first preparing it to be663** overwritten with an integer value.664*/665static SQLITE_NOINLINE Mem *out2PrereleaseWithClear(Mem *pOut){666 sqlite3VdbeMemSetNull(pOut);667 pOut->flags = MEM_Int;668 return pOut;669}670static Mem *out2Prerelease(Vdbe *p, VdbeOp *pOp){671 Mem *pOut;672 assert( pOp->p2>0 );673 assert( pOp->p2<=(p->nMem+1 - p->nCursor) );674 pOut = &p->aMem[pOp->p2];675 memAboutToChange(p, pOut);676 if( VdbeMemDynamic(pOut) ){ /*OPTIMIZATION-IF-FALSE*/677 return out2PrereleaseWithClear(pOut);678 }else{679 pOut->flags = MEM_Int;680 return pOut;681 }682}683 684/*685** Compute a bloom filter hash using pOp->p4.i registers from aMem[] beginning686** with pOp->p3. Return the hash.687*/688static u64 filterHash(const Mem *aMem, const Op *pOp){689 int i, mx;690 u64 h = 0;691 692 assert( pOp->p4type==P4_INT32 );693 for(i=pOp->p3, mx=i+pOp->p4.i; i<mx; i++){694 const Mem *p = &aMem[i];695 if( p->flags & (MEM_Int|MEM_IntReal) ){696 h += p->u.i;697 }else if( p->flags & MEM_Real ){698 h += sqlite3VdbeIntValue(p);699 }else if( p->flags & (MEM_Str|MEM_Blob) ){700 /* All strings have the same hash and all blobs have the same hash,701 ** though, at least, those hashes are different from each other and702 ** from NULL. */703 h += 4093 + (p->flags & (MEM_Str|MEM_Blob));704 }705 }706 return h;707}708 709 710/*711** For OP_Column, factor out the case where content is loaded from712** overflow pages, so that the code to implement this case is separate713** the common case where all content fits on the page. Factoring out714** the code reduces register pressure and helps the common case715** to run faster.716*/717static SQLITE_NOINLINE int vdbeColumnFromOverflow(718 VdbeCursor *pC, /* The BTree cursor from which we are reading */719 int iCol, /* The column to read */720 u32 t, /* The serial-type code for the column value */721 i64 iOffset, /* Offset to the start of the content value */722 u32 cacheStatus, /* Current Vdbe.cacheCtr value */723 u32 colCacheCtr, /* Current value of the column cache counter */724 Mem *pDest /* Store the value into this register. */725){726 int rc;727 sqlite3 *db = pDest->db;728 int encoding = pDest->enc;729 int len = sqlite3VdbeSerialTypeLen(t);730 assert( pC->eCurType==CURTYPE_BTREE );731 if( len>db->aLimit[SQLITE_LIMIT_LENGTH] ) return SQLITE_TOOBIG;732 if( len > 4000 && pC->pKeyInfo==0 ){733 /* Cache large column values that are on overflow pages using734 ** an RCStr (reference counted string) so that if they are reloaded,735 ** that do not have to be copied a second time. The overhead of736 ** creating and managing the cache is such that this is only737 ** profitable for larger TEXT and BLOB values.738 **739 ** Only do this on table-btrees so that writes to index-btrees do not740 ** need to clear the cache. This buys performance in the common case741 ** in exchange for generality.742 */743 VdbeTxtBlbCache *pCache;744 char *pBuf;745 if( pC->colCache==0 ){746 pC->pCache = sqlite3DbMallocZero(db, sizeof(VdbeTxtBlbCache) );747 if( pC->pCache==0 ) return SQLITE_NOMEM;748 pC->colCache = 1;749 }750 pCache = pC->pCache;751 if( pCache->pCValue==0752 || pCache->iCol!=iCol753 || pCache->cacheStatus!=cacheStatus754 || pCache->colCacheCtr!=colCacheCtr755 || pCache->iOffset!=sqlite3BtreeOffset(pC->uc.pCursor)756 ){757 if( pCache->pCValue ) sqlite3RCStrUnref(pCache->pCValue);758 pBuf = pCache->pCValue = sqlite3RCStrNew( len+3 );759 if( pBuf==0 ) return SQLITE_NOMEM;760 rc = sqlite3BtreePayload(pC->uc.pCursor, iOffset, len, pBuf);761 if( rc ) return rc;762 pBuf[len] = 0;763 pBuf[len+1] = 0;764 pBuf[len+2] = 0;765 pCache->iCol = iCol;766 pCache->cacheStatus = cacheStatus;767 pCache->colCacheCtr = colCacheCtr;768 pCache->iOffset = sqlite3BtreeOffset(pC->uc.pCursor);769 }else{770 pBuf = pCache->pCValue;771 }772 assert( t>=12 );773 sqlite3RCStrRef(pBuf);774 if( t&1 ){775 rc = sqlite3VdbeMemSetStr(pDest, pBuf, len, encoding,776 sqlite3RCStrUnref);777 pDest->flags |= MEM_Term;778 }else{779 rc = sqlite3VdbeMemSetStr(pDest, pBuf, len, 0,780 sqlite3RCStrUnref);781 }782 }else{783 rc = sqlite3VdbeMemFromBtree(pC->uc.pCursor, iOffset, len, pDest);784 if( rc ) return rc;785 sqlite3VdbeSerialGet((const u8*)pDest->z, t, pDest);786 if( (t&1)!=0 && encoding==SQLITE_UTF8 ){787 pDest->z[len] = 0;788 pDest->flags |= MEM_Term;789 }790 }791 pDest->flags &= ~MEM_Ephem;792 return rc;793}794 795/*796** Send a "statement aborts" message to the error log.797*/798static SQLITE_NOINLINE void sqlite3VdbeLogAbort(799 Vdbe *p, /* The statement that is running at the time of failure */800 int rc, /* Error code */801 Op *pOp, /* Opcode that filed */802 Op *aOp /* All opcodes */803){804 const char *zSql = p->zSql; /* Original SQL text */805 const char *zPrefix = ""; /* Prefix added to SQL text */806 int pc; /* Opcode address */807 char zXtra[100]; /* Buffer space to store zPrefix */808 809 if( p->pFrame ){810 assert( aOp[0].opcode==OP_Init );811 if( aOp[0].p4.z!=0 ){812 assert( aOp[0].p4.z[0]=='-' 813 && aOp[0].p4.z[1]=='-' 814 && aOp[0].p4.z[2]==' ' );815 sqlite3_snprintf(sizeof(zXtra), zXtra,"/* %s */ ",aOp[0].p4.z+3);816 zPrefix = zXtra;817 }else{818 zPrefix = "/* unknown trigger */ ";819 }820 }821 pc = (int)(pOp - aOp);822 sqlite3_log(rc, "statement aborts at %d: %s; [%s%s]",823 pc, p->zErrMsg, zPrefix, zSql);824}825 826/*827** Return the symbolic name for the data type of a pMem828*/829static const char *vdbeMemTypeName(Mem *pMem){830 static const char *azTypes[] = {831 /* SQLITE_INTEGER */ "INT",832 /* SQLITE_FLOAT */ "REAL",833 /* SQLITE_TEXT */ "TEXT",834 /* SQLITE_BLOB */ "BLOB",835 /* SQLITE_NULL */ "NULL"836 };837 return azTypes[sqlite3_value_type(pMem)-1];838}839 840/*841** Execute as much of a VDBE program as we can.842** This is the core of sqlite3_step(). 843*/844int sqlite3VdbeExec(845 Vdbe *p /* The VDBE */846){847 Op *aOp = p->aOp; /* Copy of p->aOp */848 Op *pOp = aOp; /* Current operation */849#ifdef SQLITE_DEBUG850 Op *pOrigOp; /* Value of pOp at the top of the loop */851 int nExtraDelete = 0; /* Verifies FORDELETE and AUXDELETE flags */852 u8 iCompareIsInit = 0; /* iCompare is initialized */853#endif854 int rc = SQLITE_OK; /* Value to return */855 sqlite3 *db = p->db; /* The database */856 u8 resetSchemaOnFault = 0; /* Reset schema after an error if positive */857 u8 encoding = ENC(db); /* The database encoding */858 int iCompare = 0; /* Result of last comparison */859 u64 nVmStep = 0; /* Number of virtual machine steps */860#ifndef SQLITE_OMIT_PROGRESS_CALLBACK861 u64 nProgressLimit; /* Invoke xProgress() when nVmStep reaches this */862#endif863 Mem *aMem = p->aMem; /* Copy of p->aMem */864 Mem *pIn1 = 0; /* 1st input operand */865 Mem *pIn2 = 0; /* 2nd input operand */866 Mem *pIn3 = 0; /* 3rd input operand */867 Mem *pOut = 0; /* Output operand */868 u32 colCacheCtr = 0; /* Column cache counter */869#if defined(SQLITE_ENABLE_STMT_SCANSTATUS) || defined(VDBE_PROFILE)870 u64 *pnCycle = 0;871 int bStmtScanStatus = IS_STMT_SCANSTATUS(db)!=0;872#endif873 /*** INSERT STACK UNION HERE ***/874 875 assert( p->eVdbeState==VDBE_RUN_STATE ); /* sqlite3_step() verifies this */876 if( DbMaskNonZero(p->lockMask) ){877 sqlite3VdbeEnter(p);878 }879#ifndef SQLITE_OMIT_PROGRESS_CALLBACK880 if( db->xProgress ){881 u32 iPrior = p->aCounter[SQLITE_STMTSTATUS_VM_STEP];882 assert( 0 < db->nProgressOps );883 nProgressLimit = db->nProgressOps - (iPrior % db->nProgressOps);884 }else{885 nProgressLimit = LARGEST_UINT64;886 }887#endif888 if( p->rc==SQLITE_NOMEM ){889 /* This happens if a malloc() inside a call to sqlite3_column_text() or890 ** sqlite3_column_text16() failed. */891 goto no_mem;892 }893 assert( p->rc==SQLITE_OK || (p->rc&0xff)==SQLITE_BUSY );894 testcase( p->rc!=SQLITE_OK );895 p->rc = SQLITE_OK;896 assert( p->bIsReader || p->readOnly!=0 );897 p->iCurrentTime = 0;898 assert( p->explain==0 );899 db->busyHandler.nBusy = 0;900 if( AtomicLoad(&db->u1.isInterrupted) ) goto abort_due_to_interrupt;901 sqlite3VdbeIOTraceSql(p);902#ifdef SQLITE_DEBUG903 sqlite3BeginBenignMalloc();904 if( p->pc==0905 && (p->db->flags & (SQLITE_VdbeListing|SQLITE_VdbeEQP|SQLITE_VdbeTrace))!=0906 ){907 int i;908 int once = 1;909 sqlite3VdbePrintSql(p);910 if( p->db->flags & SQLITE_VdbeListing ){911 printf("VDBE Program Listing:\n");912 for(i=0; i<p->nOp; i++){913 sqlite3VdbePrintOp(stdout, i, &aOp[i]);914 }915 }916 if( p->db->flags & SQLITE_VdbeEQP ){917 for(i=0; i<p->nOp; i++){918 if( aOp[i].opcode==OP_Explain ){919 if( once ) printf("VDBE Query Plan:\n");920 printf("%s\n", aOp[i].p4.z);921 once = 0;922 }923 }924 }925 if( p->db->flags & SQLITE_VdbeTrace ) printf("VDBE Trace:\n");926 }927 sqlite3EndBenignMalloc();928#endif929 for(pOp=&aOp[p->pc]; 1; pOp++){930 /* Errors are detected by individual opcodes, with an immediate931 ** jumps to abort_due_to_error. */932 assert( rc==SQLITE_OK );933 934 assert( pOp>=aOp && pOp<&aOp[p->nOp]);935 nVmStep++;936 937#if defined(VDBE_PROFILE)938 pOp->nExec++;939 pnCycle = &pOp->nCycle;940 if( sqlite3NProfileCnt==0 ) *pnCycle -= sqlite3Hwtime();941#elif defined(SQLITE_ENABLE_STMT_SCANSTATUS)942 if( bStmtScanStatus ){943 pOp->nExec++;944 pnCycle = &pOp->nCycle;945 *pnCycle -= sqlite3Hwtime();946 }947#endif948 949 /* Only allow tracing if SQLITE_DEBUG is defined.950 */951#ifdef SQLITE_DEBUG952 if( db->flags & SQLITE_VdbeTrace ){953 sqlite3VdbePrintOp(stdout, (int)(pOp - aOp), pOp);954 test_trace_breakpoint((int)(pOp - aOp),pOp,p);955 }956#endif957 958 959 /* Check to see if we need to simulate an interrupt. This only happens960 ** if we have a special test build.961 */962#ifdef SQLITE_TEST963 if( sqlite3_interrupt_count>0 ){964 sqlite3_interrupt_count--;965 if( sqlite3_interrupt_count==0 ){966 sqlite3_interrupt(db);967 }968 }969#endif970 971 /* Sanity checking on other operands */972#ifdef SQLITE_DEBUG973 {974 u8 opProperty = sqlite3OpcodeProperty[pOp->opcode];975 if( (opProperty & OPFLG_IN1)!=0 ){976 assert( pOp->p1>0 );977 assert( pOp->p1<=(p->nMem+1 - p->nCursor) );978 assert( memIsValid(&aMem[pOp->p1]) );979 assert( sqlite3VdbeCheckMemInvariants(&aMem[pOp->p1]) );980 REGISTER_TRACE(pOp->p1, &aMem[pOp->p1]);981 }982 if( (opProperty & OPFLG_IN2)!=0 ){983 assert( pOp->p2>0 );984 assert( pOp->p2<=(p->nMem+1 - p->nCursor) );985 assert( memIsValid(&aMem[pOp->p2]) );986 assert( sqlite3VdbeCheckMemInvariants(&aMem[pOp->p2]) );987 REGISTER_TRACE(pOp->p2, &aMem[pOp->p2]);988 }989 if( (opProperty & OPFLG_IN3)!=0 ){990 assert( pOp->p3>0 );991 assert( pOp->p3<=(p->nMem+1 - p->nCursor) );992 assert( memIsValid(&aMem[pOp->p3]) );993 assert( sqlite3VdbeCheckMemInvariants(&aMem[pOp->p3]) );994 REGISTER_TRACE(pOp->p3, &aMem[pOp->p3]);995 }996 if( (opProperty & OPFLG_OUT2)!=0 ){997 assert( pOp->p2>0 );998 assert( pOp->p2<=(p->nMem+1 - p->nCursor) );999 memAboutToChange(p, &aMem[pOp->p2]);1000 }1001 if( (opProperty & OPFLG_OUT3)!=0 ){1002 assert( pOp->p3>0 );1003 assert( pOp->p3<=(p->nMem+1 - p->nCursor) );1004 memAboutToChange(p, &aMem[pOp->p3]);1005 }1006 }1007#endif1008#ifdef SQLITE_DEBUG1009 pOrigOp = pOp;1010#endif1011 1012 switch( pOp->opcode ){1013 1014/*****************************************************************************1015** What follows is a massive switch statement where each case implements a1016** separate instruction in the virtual machine. If we follow the usual1017** indentation conventions, each case should be indented by 6 spaces. But1018** that is a lot of wasted space on the left margin. So the code within1019** the switch statement will break with convention and be flush-left. Another1020** big comment (similar to this one) will mark the point in the code where1021** we transition back to normal indentation.1022**1023** The formatting of each case is important. The makefile for SQLite1024** generates two C files "opcodes.h" and "opcodes.c" by scanning this1025** file looking for lines that begin with "case OP_". The opcodes.h files1026** will be filled with #defines that give unique integer values to each1027** opcode and the opcodes.c file is filled with an array of strings where1028** each string is the symbolic name for the corresponding opcode. If the1029** case statement is followed by a comment of the form "/# same as ... #/"1030** that comment is used to determine the particular value of the opcode.1031**1032** Other keywords in the comment that follows each case are used to1033** construct the OPFLG_INITIALIZER value that initializes opcodeProperty[].1034** Keywords include: in1, in2, in3, out2, out3. See1035** the mkopcodeh.awk script for additional information.1036**1037** Documentation about VDBE opcodes is generated by scanning this file1038** for lines of that contain "Opcode:". That line and all subsequent1039** comment lines are used in the generation of the opcode.html documentation1040** file.1041**1042** SUMMARY:1043**1044** Formatting is important to scripts that scan this file.1045** Do not deviate from the formatting style currently in use.1046**1047*****************************************************************************/1048 1049/* Opcode: Goto * P2 * * *1050**1051** An unconditional jump to address P2.1052** The next instruction executed will be1053** the one at index P2 from the beginning of1054** the program.1055**1056** The P1 parameter is not actually used by this opcode. However, it1057** is sometimes set to 1 instead of 0 as a hint to the command-line shell1058** that this Goto is the bottom of a loop and that the lines from P2 down1059** to the current line should be indented for EXPLAIN output.1060*/1061case OP_Goto: { /* jump */1062 1063#ifdef SQLITE_DEBUG1064 /* In debugging mode, when the p5 flags is set on an OP_Goto, that1065 ** means we should really jump back to the preceding OP_ReleaseReg1066 ** instruction. */1067 if( pOp->p5 ){1068 assert( pOp->p2 < (int)(pOp - aOp) );1069 assert( pOp->p2 > 1 );1070 pOp = &aOp[pOp->p2 - 2];1071 assert( pOp[1].opcode==OP_ReleaseReg );1072 goto check_for_interrupt;1073 }1074#endif1075 1076jump_to_p2_and_check_for_interrupt:1077 pOp = &aOp[pOp->p2 - 1];1078 1079 /* Opcodes that are used as the bottom of a loop (OP_Next, OP_Prev,1080 ** OP_VNext, or OP_SorterNext) all jump here upon1081 ** completion. Check to see if sqlite3_interrupt() has been called1082 ** or if the progress callback needs to be invoked.1083 **1084 ** This code uses unstructured "goto" statements and does not look clean.1085 ** But that is not due to sloppy coding habits. The code is written this1086 ** way for performance, to avoid having to run the interrupt and progress1087 ** checks on every opcode. This helps sqlite3_step() to run about 1.5%1088 ** faster according to "valgrind --tool=cachegrind" */1089check_for_interrupt:1090 if( AtomicLoad(&db->u1.isInterrupted) ) goto abort_due_to_interrupt;1091#ifndef SQLITE_OMIT_PROGRESS_CALLBACK1092 /* Call the progress callback if it is configured and the required number1093 ** of VDBE ops have been executed (either since this invocation of1094 ** sqlite3VdbeExec() or since last time the progress callback was called).1095 ** If the progress callback returns non-zero, exit the virtual machine with1096 ** a return code SQLITE_ABORT.1097 */1098 while( nVmStep>=nProgressLimit && db->xProgress!=0 ){1099 assert( db->nProgressOps!=0 );1100 nProgressLimit += db->nProgressOps;1101 if( db->xProgress(db->pProgressArg) ){1102 nProgressLimit = LARGEST_UINT64;1103 rc = SQLITE_INTERRUPT;1104 goto abort_due_to_error;1105 }1106 }1107#endif1108 1109 break;1110}1111 1112/* Opcode: Gosub P1 P2 * * *1113**1114** Write the current address onto register P11115** and then jump to address P2.1116*/1117case OP_Gosub: { /* jump */1118 assert( pOp->p1>0 && pOp->p1<=(p->nMem+1 - p->nCursor) );1119 pIn1 = &aMem[pOp->p1];1120 assert( VdbeMemDynamic(pIn1)==0 );1121 memAboutToChange(p, pIn1);1122 pIn1->flags = MEM_Int;1123 pIn1->u.i = (int)(pOp-aOp);1124 REGISTER_TRACE(pOp->p1, pIn1);1125 goto jump_to_p2_and_check_for_interrupt;1126}1127 1128/* Opcode: Return P1 P2 P3 * *1129**1130** Jump to the address stored in register P1. If P1 is a return address1131** register, then this accomplishes a return from a subroutine.1132**1133** If P3 is 1, then the jump is only taken if register P1 holds an integer1134** values, otherwise execution falls through to the next opcode, and the1135** OP_Return becomes a no-op. If P3 is 0, then register P1 must hold an1136** integer or else an assert() is raised. P3 should be set to 1 when1137** this opcode is used in combination with OP_BeginSubrtn, and set to 01138** otherwise.1139**1140** The value in register P1 is unchanged by this opcode.1141**1142** P2 is not used by the byte-code engine. However, if P2 is positive1143** and also less than the current address, then the "EXPLAIN" output1144** formatter in the CLI will indent all opcodes from the P2 opcode up1145** to be not including the current Return. P2 should be the first opcode1146** in the subroutine from which this opcode is returning. Thus the P21147** value is a byte-code indentation hint. See tag-20220407a in1148** wherecode.c and shell.c.1149*/1150case OP_Return: { /* in1 */1151 pIn1 = &aMem[pOp->p1];1152 if( pIn1->flags & MEM_Int ){1153 if( pOp->p3 ){ VdbeBranchTaken(1, 2); }1154 pOp = &aOp[pIn1->u.i];1155 }else if( ALWAYS(pOp->p3) ){1156 VdbeBranchTaken(0, 2);1157 }1158 break;1159}1160 1161/* Opcode: InitCoroutine P1 P2 P3 * *1162**1163** Set up register P1 so that it will Yield to the coroutine1164** located at address P3.1165**1166** If P2!=0 then the coroutine implementation immediately follows1167** this opcode. So jump over the coroutine implementation to1168** address P2.1169**1170** See also: EndCoroutine1171*/1172case OP_InitCoroutine: { /* jump0 */1173 assert( pOp->p1>0 && pOp->p1<=(p->nMem+1 - p->nCursor) );1174 assert( pOp->p2>=0 && pOp->p2<p->nOp );1175 assert( pOp->p3>=0 && pOp->p3<p->nOp );1176 pOut = &aMem[pOp->p1];1177 assert( !VdbeMemDynamic(pOut) );1178 pOut->u.i = pOp->p3 - 1;1179 pOut->flags = MEM_Int;1180 if( pOp->p2==0 ) break;1181 1182 /* Most jump operations do a goto to this spot in order to update1183 ** the pOp pointer. */1184jump_to_p2:1185 assert( pOp->p2>0 ); /* There are never any jumps to instruction 0 */1186 assert( pOp->p2<p->nOp ); /* Jumps must be in range */1187 pOp = &aOp[pOp->p2 - 1];1188 break;1189}1190 1191/* Opcode: EndCoroutine P1 * * * *1192**1193** The instruction at the address in register P1 is a Yield.1194** Jump to the P2 parameter of that Yield.1195** After the jump, the value register P1 is left with a value1196** such that subsequent OP_Yields go back to the this same1197** OP_EndCoroutine instruction.1198**1199** See also: InitCoroutine1200*/