On Thu, Aug 6, 2026 at 7:02 AM Ruediger Pluem <[email protected]> wrote:
>
>
>
> On 8/3/26 2:34 PM, [email protected] wrote:
> > Author: covener
> > Date: Mon Aug  3 12:34:29 2026
> > New Revision: 1936814
> >
> > Log:
> > apr_dbd: oracle escaping
> >
> > Reviewed By: covener, jorton, jfclere
> >
> > Modified:
> >    apr/apr/trunk/dbd/apr_dbd_oracle.c
> >
> > Modified: apr/apr/trunk/dbd/apr_dbd_oracle.c
> > ==============================================================================
> > --- apr/apr/trunk/dbd/apr_dbd_oracle.c        Mon Aug  3 12:33:18 2026      
> >   (r1936813)
> > +++ apr/apr/trunk/dbd/apr_dbd_oracle.c        Mon Aug  3 12:34:29 2026      
> >   (r1936814)
> > @@ -849,7 +849,25 @@ static int dbd_oracle_query(apr_dbd_t *s
> >  static const char *dbd_oracle_escape(apr_pool_t *pool, const char *arg,
> >                                       apr_dbd_t *sql)
> >  {
> > -    return arg;        /* OCI has no concept of string escape */
> > +    char *newstr, *src, *dst, *sq;
>
> Shouldn't src, sq be const ?
>
> > +    int qcount;
> > +
> > +    /* return the original if there are no single-quotes */
> > +    if (!(sq = strchr(s, '\'')))
>
> Shouldn't this be arg instead of s above?
> As there is no s this breaks compilation.
>
> > +        return (char *)s;
>
> Shouldn't this be
>
>            return arg;
>
> > +    /* count the single-quotes and allocate a new buffer */
> > +    for (qcount = 1; (sq = strchr(sq + 1, '\'')); )
> > +        qcount++;
> > +    newstr = apr_palloc(pool, strlen(s) + qcount + 1);
> > +
> > +    /* move chars, doubling all single-quotes */
> > +    src = (char *)s;
>
> Shouldn't this be
>
>        src = arg;
>
> > +    for (dst = newstr; *src; src++) {
> > +        if ((*dst++ = *src) == '\'')
> > +            *dst++ = '\'';
> > +    }
> > +    *dst = 0;
> > +    return newstr;
> >  }
> >
> >  static int dbd_oracle_prepare(apr_pool_t *pool, apr_dbd_t *sql,
> >
> >
>

Yes, must be different from where it's lifted (and not being built on
my system).  At this stage I think a follow-on release is needed.
I will add something to the announcement.

Reply via email to