sqlite/test/fuzz.test

375 lines
9.5 KiB
Plaintext
Raw Normal View History

# 2007 May 10
#
# The author disclaims copyright to this source code. In place of
# a legal notice, here is a blessing:
#
# May you do good and not evil.
# May you find forgiveness for yourself and forgive others.
# May you share freely, never taking more than you give.
#
#***********************************************************************
# This file implements regression tests for SQLite library. The
# focus of this file is generating semi-random strings of SQL
# (a.k.a. "fuzz") and sending it into the parser to try to generate
# errors.
#
# $Id: fuzz.test,v 1.7 2007/05/11 16:58:04 danielk1977 Exp $
set testdir [file dirname $argv0]
source $testdir/tester.tcl
set ::REPEATS 20
set ::REPEATS 5000
proc fuzz {TemplateList} {
set n [llength $TemplateList]
set i [expr {int(rand()*$n)}]
return [uplevel 1 subst -novar [list [lindex $TemplateList $i]]]
}
# Fuzzy generation primitives:
#
# Literal
# UnaryOp
# BinaryOp
# Expr
# Table
# Select
# Insert
#
# Returns a string representing an SQL literal.
#
proc Literal {} {
set TemplateList {
456 0 -456 1 -1
2147483648 2147483647 2147483649 -2147483647 -2147483648 -2147483649
'The' 'first' 'experiments' 'in' 'hardware' 'fault' 'injection'
zeroblob(1000)
NULL
56.1 -56.1
123456789.1234567899
}
fuzz $TemplateList
}
# Returns a string containing an SQL unary operator (e.g. "+" or "NOT").
#
proc UnaryOp {} {
set TemplateList {+ - NOT ~}
fuzz $TemplateList
}
# Returns a string containing an SQL binary operator (e.g. "*" or "/").
#
proc BinaryOp {} {
set TemplateList {
|| * / % + - << >> & | < <= > >= = == != <> AND OR
LIKE GLOB {NOT LIKE}
}
fuzz $TemplateList
}
# Return the complete text of an SQL expression.
#
set ::ExprDepth 0
proc Expr { {c {}} } {
incr ::ExprDepth
set TemplateList [concat $c {[Literal]}]
if {$::ExprDepth < 5} {
lappend TemplateList \
{[Expr $c] [BinaryOp] [Expr $c]} \
{[UnaryOp] [Expr $c]} \
{[Expr $c] ISNULL} \
{[Expr $c] NOTNULL} \
{CAST([Expr $c] AS blob)} \
{CAST([Expr $c] AS text)} \
{CAST([Expr $c] AS integer)} \
{CAST([Expr $c] AS real)} \
{abs([Expr])} \
{coalesce([Expr], [Expr])} \
{hex([Expr])} \
{length([Expr])} \
{lower([Expr])} \
{upper([Expr])} \
{quote([Expr])} \
{random()} \
{randomblob(min(max([Expr],1), 500))} \
{typeof([Expr])} \
{substr([Expr],[Expr],[Expr])} \
{CASE WHEN [Expr $c] THEN [Expr $c] ELSE [Expr $c] END} \
{[Literal]} {[Literal]} {[Literal]}
}
if {$::SelectDepth < 10} {
lappend TemplateList \
{([Select 1])} \
{[Expr $c] IN ([Select 1])} \
{[Expr $c] NOT IN ([Select 1])} \
{EXISTS ([Select 1])} \
}
set res [fuzz $TemplateList]
incr ::ExprDepth -1
return $res
}
# Return a valid table name.
#
set ::TableList [list]
proc Table {} {
set TemplateList [concat sqlite_master $::TableList]
fuzz $TemplateList
}
# Return a SELECT statement.
#
set ::SelectDepth 0
set ::ColumnList [list]
proc Select {{isExpr 0}} {
incr ::SelectDepth
set TemplateList {
{SELECT [Expr]}
{SELECT [Literal]}
}
if {$::SelectDepth < 5} {
lappend TemplateList \
{SELECT [Expr] FROM ([Select])} \
{SELECT [Expr $::ColumnList] FROM [Table]} \
if {0 == $isExpr} {
lappend TemplateList \
{SELECT [Expr], [Expr] FROM ([Select]) ORDER BY [Expr]} \
{SELECT * FROM ([Select]) ORDER BY [Expr]} \
{SELECT * FROM [Table]} \
{SELECT * FROM [Table] WHERE [Expr $::ColumnList]} \
{SELECT * FROM [Table],[Table] AS t2 WHERE [Expr $::ColumnList] LIMIT 1}
}
}
set res [fuzz $TemplateList]
incr ::SelectDepth -1
set res
}
# Generate and return a fuzzy INSERT statement.
#
proc Insert {} {
set TemplateList {
{INSERT INTO [Table] VALUES([Expr], [Expr], [Expr]);}
{INSERT INTO [Table] VALUES([Expr], [Expr], [Expr], [Expr]);}
{INSERT INTO [Table] VALUES([Expr], [Expr]);}
}
fuzz $TemplateList
}
proc Column {} {
fuzz $::ColumnList
}
# Generate and return a fuzzy UPDATE statement.
#
proc Update {} {
set TemplateList {
{UPDATE [Table]
SET [Column] = [Expr $::ColumnList]
WHERE [Expr $::ColumnList]}
}
fuzz $TemplateList
}
proc Delete {} {
set TemplateList {
{DELETE FROM [Table] WHERE [Expr $::ColumnList]}
}
fuzz $TemplateList
}
proc Statement {} {
set TemplateList {
{[Update]}
{[Insert]}
{[Select]}
{[Delete]}
}
fuzz $TemplateList
}
########################################################################
set ::log [open fuzzy.log w]
#
# Usage: do_fuzzy_test <testname> ?<options>?
#
# -template
# -errorlist
#
proc do_fuzzy_test {testname args} {
set ::fuzzyopts(-errorlist) [list]
array set ::fuzzyopts $args
lappend ::fuzzyopts(-errorlist) {parser stack overflow} {ORDER BY column}
for {set ii 0} {$ii < $::REPEATS} {incr ii} {
do_test ${testname}.$ii {
set ::sql [subst $::fuzzyopts(-template)]
puts $::log $::sql
flush $::log
set rc [catch {execsql $::sql} msg]
set e 1
if {$rc} {
set e 0
foreach error $::fuzzyopts(-errorlist) {
if {0 == [string first $error $msg]} {
set e 1
break
}
}
}
if {$e == 0} {
puts ""
puts $::sql
puts $msg
}
set e
} {1}
}
}
#----------------------------------------------------------------
# These tests caused errors that were first caught by the tests
# in this file. They are still here.
do_test fuzz-1.1 {
execsql {
SELECT 'abc' LIKE X'ABCD';
}
} {0}
do_test fuzz-1.2 {
execsql {
SELECT 'abc' LIKE zeroblob(10);
}
} {0}
do_test fuzz-1.3 {
execsql {
SELECT zeroblob(10) LIKE 'abc';
}
} {0}
do_test fuzz-1.4 {
execsql {
SELECT (- -21) % NOT (456 LIKE zeroblob(10));
}
} {0}
do_test fuzz-1.5 {
execsql {
SELECT (SELECT (
SELECT (SELECT -2147483648) FROM (SELECT 1) ORDER BY 1
))
}
} {-2147483648}
do_test fuzz-1.6 {
execsql {
SELECT 'abc', zeroblob(1) FROM (SELECT 1) ORDER BY 1
}
} [execsql {SELECT 'abc', zeroblob(1)}]
do_test fuzz-1.7 {
execsql {
SELECT ( SELECT zeroblob(1000) FROM (
SELECT * FROM (SELECT 'first') ORDER BY NOT 'in')
)
}
} [execsql {SELECT zeroblob(1000)}]
do_test fuzz-1.8 {
# Problems with opcode OP_ToText (did not account for MEM_Zero).
# Also MemExpandBlob() was marking expanded blobs as nul-terminated.
# They are not.
execsql {
SELECT CAST(zeroblob(1000) AS text);
}
} {{}}
do_test fuzz-1.9 {
# This was causing a NULL pointer dereference of Expr.pList.
execsql {
SELECT 1 FROM (SELECT * FROM sqlite_master WHERE random())
}
} {}
do_test fuzz-1.10 {
# Bug in calculation of Parse.ckOffset causing an assert()
# to fail. Probably harmless.
execsql {
SELECT coalesce(1, substr( 1, 2, length('in' IN (SELECT 1))))
}
} {1}
#----------------------------------------------------------------
# Test some fuzzily generated expressions.
#
do_fuzzy_test fuzz-2 -template { SELECT [Expr] }
do_test fuzz-3.1 {
execsql {
CREATE TABLE abc(a, b, c);
CREATE TABLE def(a, b, c);
CREATE TABLE ghi(a, b, c);
}
} {}
set ::TableList [list abc def ghi]
#----------------------------------------------------------------
# Test some fuzzily generated SELECT statements.
#
do_fuzzy_test fuzz-3.2 -template {[Select]}
#----------------------------------------------------------------
# Insert a small amount of data into the database and then run
# some more generated SELECT statements.
#
do_test fuzz-4.1 {
execsql {
INSERT INTO abc VALUES(1, 2, 3);
INSERT INTO abc VALUES(4, 5, 6);
INSERT INTO abc VALUES(7, 8, 9);
INSERT INTO def VALUES(1, 2, 3);
INSERT INTO def VALUES(4, 5, 6);
INSERT INTO def VALUES(7, 8, 9);
INSERT INTO ghi VALUES(1, 2, 3);
INSERT INTO ghi VALUES(4, 5, 6);
INSERT INTO ghi VALUES(7, 8, 9);
CREATE INDEX abc_i ON abc(a, b, c);
CREATE INDEX def_i ON def(c, a, b);
CREATE INDEX ghi_i ON ghi(b, c, a);
}
} {}
do_fuzzy_test fuzz-4.2 -template {[Select]}
#----------------------------------------------------------------
# Test some fuzzy INSERT statements:
#
do_test fuzz-5.1 {execsql BEGIN} {}
do_fuzzy_test fuzz-5.2 -template {[Insert]} -errorlist table
integrity_check fuzz-5.2.integrity
do_test fuzz-5.3 {execsql COMMIT} {}
integrity_check fuzz-5.4.integrity
#----------------------------------------------------------------
# Now that there is data in the datbase, run some more SELECT
# statements
#
set ::ColumnList [list a b c]
set E {{no such col} {ambiguous column name}}
do_fuzzy_test fuzz-6.1 -template {[Select]} -errorlist $E
#----------------------------------------------------------------
# Run some SELECTs, INSERTs, UPDATEs and DELETEs in a transaction.
#
set E {{no such col} {ambiguous column name} {table}}
do_test fuzz-7.1 {execsql BEGIN} {}
do_fuzzy_test fuzz-7.2 -template {[Statement]} -errorlist $E
integrity_check fuzz-7.3.integrity
do_test fuzz-7.4 {execsql COMMIT} {}
integrity_check fuzz-7.5.integrity
close $::log
finish_test