sqlite: excess bound parameters produce an opaque "column index out of range" error
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- javascript, node.js, sqlite
- Ambito
- databases
Direzione di ricerca
Inizia in src/node_sqlite.cc, in StatementSync::BindParams, esaminando la gestione esistente di param_count e il ciclo di binding anonimo. Riproduci il problema con gli snippet SQL forniti; il lavoro è completato quando gli argomenti anonimi in eccesso riportano un errore chiaro sul numero di parametri invece di SQLite errcode 25, senza modificare il comportamento di binding esistente.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Version
v24.15.0 (also present on main)
Platform
Darwin 25.6.0 arm64 (platform-independent — pure BindParams logic)
Subsystem
sqlite
What steps will reproduce the bug?
const { DatabaseSync } = require('node:sqlite');
const db = new DatabaseSync(':memory:');
db.exec('CREATE TABLE t(a)');
const ins = db.prepare('INSERT INTO t VALUES (?)');
ins.run(1, 2); // ERR_SQLITE_ERROR, errcode 25, "column index out of range"
db.prepare('SELECT 1').get(5); // same
Any excess anonymous argument reproduces it, regardless of type — 2, 'x', and null all give the identical message.
How often does it reproduce? Is there a required condition?
Always, whenever the number of anonymous arguments exceeds the statement's sqlite3_bind_parameter_count().
What is the expected behavior? Why is that the expected behavior?
An error naming the actual problem — that more parameters were supplied than the statement accepts, ideally with both counts. Something like:
TypeError [ERR_INVALID_ARG_COUNT]: Statement accepts 1 parameter, but 2 were provided.
Two reasons this matters:
-
The message describes the wrong thing. "Column index out of range" is SQLite's wording for a binding index, but to a JS caller "column" reads as a table column, pointing them at their schema rather than their call site. Nothing in the message indicates an argument-count mismatch.
-
It's inconsistent with how the adjacent failure is reported. A wrong-type argument gets a precise Node-authored error:
ERR_INVALID_ARG_TYPE: Provided value cannot be bound to SQLite parameter 2.A wrong-count argument falls through to a raw SQLite error code. Both are caller mistakes in the same call, caught in the same function.
What do you see instead?
ERR_SQLITE_ERROR with errcode: 25 and message column index out of range.
Additional information
The anonymous-binding loop in StatementSync::BindParams (src/node_sqlite.cc) iterates args from anon_start to args.Length() without comparing that span against sqlite3_bind_parameter_count(), so the overflow surfaces from sqlite3_bind_* instead. param_count is already fetched a few lines above, inside the bare-named-params block. A pre-loop guard would cover every excess-argument case at once.
Worth deciding up front whether this should throw at all, or ignore extra arguments the way ordinary JS functions do. Throwing seems better for a database API, and it's the current behavior, so a guard would preserve semantics while fixing only the message. Note this would be a breaking change for anyone matching on ERR_SQLITE_ERROR/errcode 25, so it likely wants semver-major treatment.
Surfaced while reviewing #62008, which changes undefined handling in the same function; the two are independent.
- Lingua principale
- JavaScript
- Stelle
- 122k
- Fork
- 37.4k
- Merge medio
- 4g 3h
- PR unite (30g)
- 279
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nodejs/node
-
doc
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
build
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
feature request
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Issue simili
-
awaiting triage bug Causes friction Hop Gui P1 P2 Transforms
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Improve Title Support Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
georgestephanis/p2026#40 ·
-
Enatega Customer and Rider app: Add-ons price is not visible to customer after order is placed. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
Margaret-Petersen/food-delivery-app-clone-react-native#1981 ·