aws / aws/amazon-documentdb-odbc-driver

Incorrect behavior on SQLGetData with out of range numeric data

Open
#192 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
C++
Stars
6
Forks
2
PR merge metrics
No merged PRs in 30d

Description

Issue: With query to get bigint (e.g., `SELECT CAST(9223372036854775807 AS BIGINT)`), and call `SQLGetData(hstmt, 1, SQL_C_SLONG, &sCustID, 0, &cbCustID);` (example is based on [Microsoft SQLGetData documentation](https://learn.microsoft.com/en-us/sql/odbc/reference/syntax/sqlgetdata-function?view=sql-server-ver16)), SQLGetData returns SQL_SUCCESS instead of returning SQL_ERROR with error state `22003 - Numeric value out of range`.

Possible cause from looking at the code: When SQLGetData is called, `DocumentDbColumn::PutInt*` is called to get numeric data (converted from `bsoncxx::type` to C type), and then eventually `ApplicationDataBuffer::PutNum` is called to save the data without any conversion or checks for data size.

Contributor guide

Open the contributing guide

Research direction

Start at SQLGetData and trace the mentioned DocumentDbColumn::PutInt* calls through ApplicationDataBuffer::PutNum, checking where numeric range validation is absent. Done means an out-of-range BIGINT requested as SQL_C_SLONG returns SQL_ERROR with error state 22003 instead of SQL_SUCCESS.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
databases
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.