Skip to content

Commit 7dc8126

Browse files
committed
Handle sqlite3PagerSharedLock() error SQLITE_BUSY
In a multi-threaded non-WAL-journaled setting, concurrent writers can block readers causing sqlite3PagerSharedLock() of verify_page1() to fail with SQLITE_BUSY. Consequently, sqlite3PagerPagecount() returned 0 as the page count of the database, which resulted in sqleet thinking the database was empty and thus using a wrong KDF salt. This ultimately caused accessing an encrypted database to fail with SQLITE_NOTADB. This commit adds missing handling of SQLITE_BUSY when acquiring a shared pager lock. If blocked, sqleet invokes SQLite3 busy handler configured with sqlite3_busy_timeout() or sqlite3_busy_handler() functions. If the busy handler is unset or it returns 0, then SQLITE_BUSY becomes return value of sqlite3_key() (unfortunately sqlite3_open() with key embedded in the URI does not pass SQLITE_BUSY from sqlite3_key() to the caller). Future work includes optional skipping of the verification of the codec encryption key (so that sqlite3_open() & sqlite3_key() succeed with an incorrect key, but subsequent attempts to access the database fail with the incorrect key). Moreover, shared cache feature of SQLite3 appears to be unstable when using sqleet in a multi-threaded program. Shared cache with sqleet-databases needs more testing to guarantee a proper support.
1 parent 06e922a commit 7dc8126

File tree

1 file changed

+69
-61
lines changed

1 file changed

+69
-61
lines changed

sqleet.c

Lines changed: 69 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -364,53 +364,6 @@ void *codec_handle(void *codec, void *pdata, Pgno page, int mode)
364364
return data;
365365
}
366366

367-
/* Verify encryption key by reading page1 (and triggering KDF) */
368-
static int verify_page1(Pager *pager)
369-
{
370-
int rc, count;
371-
sqlite3PagerSharedLock(pager);
372-
sqlite3PagerPagecount(pager, &count);
373-
if (count > 0) {
374-
/* Non-empty database, read page1 */
375-
DbPage *page;
376-
sqlite3PcacheTruncate(pager->pPCache, 0);
377-
if ((rc = sqlite3PagerGet(pager, 1, &page, 0)) == SQLITE_OK) {
378-
/* Validate the read database header */
379-
rc = SQLITE_NOTADB;
380-
if (!memcmp(page->pData, "SQLite format 3", 16)) {
381-
const uint8_t *data = page->pData;
382-
const uint16_t pagesize = (data[16] << 8) | data[17];
383-
if (pagesize >= 512 && !(pagesize & (pagesize-1))) {
384-
if (data[21] == 64 && data[22] == 32 && data[23] == 32) {
385-
uint32_t version = data[96];
386-
version = (version << 8) | data[97];
387-
version = (version << 8) | data[98];
388-
version = (version << 8) | data[99];
389-
if (3000000 <= version && version < 4000000)
390-
rc = SQLITE_OK;
391-
}
392-
}
393-
}
394-
sqlite3PagerUnref(page);
395-
} else {
396-
Codec *codec = sqlite3PagerGetCodec(pager);
397-
if (codec && codec->error != SQLITE_OK)
398-
rc = codec->error;
399-
sqlite3PagerSetCodec(pager, NULL, NULL, NULL, NULL);
400-
}
401-
} else {
402-
/* Empty database */
403-
Codec *codec = sqlite3PagerGetCodec(pager);
404-
if (codec && !(codec->flags & SQLEET_HAS_KEY)) {
405-
/* Derive a new key */
406-
codec_kdf(codec);
407-
}
408-
rc = SQLITE_OK;
409-
}
410-
pager_unlock(pager);
411-
return rc;
412-
}
413-
414367
/*
415368
* A hack to control the page size of attached vacuum database.
416369
* Otherwise the database inherits page size from the source database.
@@ -440,30 +393,85 @@ static void size_hook(void *pcodec, int new_pagesize, int reserved)
440393
*/
441394
static int codec_set_to(Codec *codec, Btree *pBt)
442395
{
443-
Pager *pager = sqlite3BtreePager(pBt);
396+
Pager *pager;
397+
int rc, count;
398+
sqlite3BtreeEnter(pBt);
399+
pager = sqlite3BtreePager(pBt);
400+
401+
/* Prepare codec */
444402
if (codec) {
445-
/* Adjust the page size and reserved area */
446-
const int reserved = codec->writer ? PAGE_RESERVED_LEN : 0;
447403
if (!codec->pagesize)
448404
codec->pagesize = sqlite3BtreeGetPageSize(pBt);
449405
if (!(codec->pagebuf = sqlite3_malloc(codec->pagesize))) {
450-
codec_free(codec);
451-
return SQLITE_NOMEM;
406+
rc = SQLITE_NOMEM;
407+
goto kill_codec;
452408
}
453-
sqlite3BtreeSetPageSize(pBt, codec->pagesize, reserved, 0);
454-
455-
/* Force secure delete */
456-
sqlite3BtreeSecureDelete(pBt, 1);
457-
458-
/* Set pager codec and try to read page1 */
459409
codec->btree = pBt;
460410
codec->error = SQLITE_OK;
411+
}
412+
413+
/* Acquire shared pager lock (may block due to concurrent writes) */
414+
while ((rc = sqlite3PagerSharedLock(pager)) != SQLITE_OK) {
415+
if (rc != SQLITE_BUSY || !btreeInvokeBusyHandler(pBt->pBt))
416+
goto kill_codec;
417+
}
418+
419+
/* Set (or unset) pager codec */
420+
if (codec) {
421+
const int reserved = codec->writer ? PAGE_RESERVED_LEN : 0;
422+
sqlite3BtreeSetPageSize(pBt, codec->pagesize, reserved, 0);
423+
sqlite3BtreeSecureDelete(pBt, 1);
461424
sqlite3PagerSetCodec(pager, codec_handle, size_hook, codec_free, codec);
462425
} else {
463-
/* Unset a codec */
464426
sqlite3PagerSetCodec(pager, NULL, NULL, NULL, NULL);
465427
}
466-
return verify_page1(pager);
428+
429+
/* Verify codec */
430+
sqlite3PagerPagecount(pager, &count);
431+
if (count > 0) {
432+
/* Non-empty database, read page 1 with the codec */
433+
DbPage *page;
434+
sqlite3PcacheClear(pager->pPCache);
435+
if ((rc = sqlite3PagerGet(pager, 1, &page, 0)) == SQLITE_OK) {
436+
rc = SQLITE_NOTADB;
437+
if (!memcmp(page->pData, "SQLite format 3", 16)) {
438+
const uint8_t *data = page->pData;
439+
const uint16_t pagesize = (data[16] << 8) | data[17];
440+
if (pagesize >= 512 && !(pagesize & (pagesize-1))) {
441+
if (data[21] == 64 && data[22] == 32 && data[23] == 32) {
442+
uint32_t version = data[96];
443+
version = (version << 8) | data[97];
444+
version = (version << 8) | data[98];
445+
version = (version << 8) | data[99];
446+
if (3000000 <= version && version < 4000000)
447+
rc = SQLITE_OK;
448+
}
449+
}
450+
}
451+
sqlite3PagerUnrefPageOne(page);
452+
} else if (codec) {
453+
/* Invalid codec */
454+
if (codec->error != SQLITE_OK)
455+
rc = codec->error;
456+
sqlite3PagerSetCodec(pager, NULL, NULL, NULL, NULL);
457+
}
458+
} else {
459+
/* Empty database, assume the codec is valid */
460+
if (codec && !(codec->flags & SQLEET_HAS_KEY)) {
461+
/* Derive a new encryption key */
462+
codec_kdf(codec);
463+
}
464+
rc = SQLITE_OK;
465+
}
466+
467+
pager_unlock(pager);
468+
sqlite3BtreeLeave(pBt);
469+
return rc;
470+
471+
kill_codec:
472+
codec_free(codec);
473+
sqlite3BtreeLeave(pBt);
474+
return rc;
467475
}
468476

469477
void sqlite3CodecGetKey(sqlite3 *db, int nDb, void **zKey, int *nKey)
@@ -579,7 +587,7 @@ int sqlite3_rekey_v2(sqlite3 *db, const char *zDbName,
579587
reader->writer = reader->reader;
580588
}
581589
} else {
582-
rc = verify_page1(pager);
590+
rc = codec_set_to(NULL, pBt);
583591
}
584592
goto leave;
585593
}

0 commit comments

Comments
 (0)