Skip to content

fix(SQL): Escape Database Names#92

Open
janfa wants to merge 1 commit intoDBDiff:masterfrom
janfa:fix-db-name-escaping
Open

fix(SQL): Escape Database Names#92
janfa wants to merge 1 commit intoDBDiff:masterfrom
janfa:fix-db-name-escaping

Conversation

@janfa
Copy link
Copy Markdown

@janfa janfa commented May 19, 2019

Like with #14 wrap database- and table names with Backticks to prevent conflicting with mysql-reserved keys

IncubuzzCC
IncubuzzCC approved these changes Jul 4, 2020
Copy link
Copy Markdown

@IncubuzzCC IncubuzzCC left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Bugfix] This change fixes code-breaking issues when dealing database - or table names or using reserved or ambiguous names or special characters such as underscores within them.

jasdeepkhalsa added a commit that referenced this pull request Mar 25, 2026
MySQL data diff queries in LocalTableData now use backtick-quoted
`db`.`table` references instead of bare db.table. This prevents
MySQL from interpreting hyphens in database names (e.g. 'my-db') as
subtraction operators, which caused PDO syntax error 1064.

Fixed in getOldNewDiff() (2 queries) and getChangeDiff() (1 query +
key column references).

Added unit test verifying MySQLDialect::quote() correctly handles
hyphenated names, names with backticks, and names with spaces.

Refs: bugs.md Bug #3, PR #92
jasdeepkhalsa added a commit that referenced this pull request Mar 26, 2026
MySQL data diff queries in LocalTableData now use backtick-quoted
`db`.`table` references instead of bare db.table. This prevents
MySQL from interpreting hyphens in database names (e.g. 'my-db') as
subtraction operators, which caused PDO syntax error 1064.

Fixed in getOldNewDiff() (2 queries) and getChangeDiff() (1 query +
key column references).

Added unit test verifying MySQLDialect::quote() correctly handles
hyphenated names, names with backticks, and names with spaces.

Related contributor PR: #92
jasdeepkhalsa added a commit that referenced this pull request Mar 26, 2026
## Fix 10 bugs — data integrity, SQL generation, and robustness

This PR fixes 10 bugs across the SQL generator, data diff pipeline, and
core runtime. Each fix has independent unit tests and, where applicable,
dedicated end-to-end scenarios.

---

### Changes

#### Bug 1 — Empty constraint name generates invalid SQL
`AlterTableDropConstraintSQL::getUp()` now throws a dedicated
`InvalidConstraintException` (extending `BaseException`) instead of
emitting `DROP CONSTRAINT \`\``.
New custom exception class:
`src/Exceptions/InvalidConstraintException.php`.

#### Bug 2 & 9 — `UpdateDataSQL` crashes on `DiffOpAdd` / emits empty
string for NULL
`getDown()` crashed with a fatal error when the diff contained
`DiffOpAdd` objects (which have no `getOldValue()`). Also, both
directions wrote empty string instead of SQL `NULL` for null column
values.
Closes contributor PR #93.

#### Bug 3 — Hyphenated database names cause MySQL syntax error 1064
`LocalTableData` data-diff queries now use backtick-quoted ``
`db`.`table` `` references. MySQL was interpreting hyphens as
subtraction operators.
Closes contributor PR #92.

#### Bug 4 — `TableIterator::next()` passes Illuminate `Collection` to
`array_merge()`
`->get()` returns a `Collection`; it is now converted with `->toArray()`
and `stdClass` rows are normalised to associative arrays before being
passed to `ArrayDiff`.

#### Bug 5 — Null engine value generates `ALTER TABLE … ENGINE = ;`
`AlterTableEngineSQL::getUp()` and `getDown()` return empty string when
either engine value is empty/null. `TableSchema::getDiff()` also skips
engine diff creation in this case.

#### Bug 6 — Views appear in table diff and generate `DROP TABLE`
instead of `DROP VIEW`
`MySQLAdapter::getTables()` now uses `SHOW FULL TABLES WHERE Table_type
= 'BASE TABLE'`. PostgreSQL and SQLite adapters were already correct.
Closes contributor PR #123.

#### Bug 7 — Rows with NULL columns are silently dropped from data diff
MySQL `CONCAT()` returns `NULL` if any argument is `NULL`, collapsing
all such rows to an identical hash. Fix wraps each column in
`IFNULL(col, '\0')` and adds a NULL-presence bitmap as a secondary
comparison field.
Closes contributor PRs #77 and #63.

#### Bug 8 — INSERT statements use positional `VALUES(...)` instead of
named columns
`InsertDataSQL::getUp()` and `DeleteDataSQL::getDown()` now emit
explicit column lists: `` INSERT INTO `t` (`col1`,`col2`) VALUES(...)
``. This prevents silent data corruption when column order differs
between source and target.

#### Bug 10 — Library hardcodes `memory_limit = 512M` via `ini_set`
Both `ini_set('memory_limit', '512M')` calls removed from
`DBDiff::run()` and `DBDiff::getDiffResult()`. The CLI entry points now
set a sensible 1G default instead (see below).

---

### Tests

| Area | What was added |
|------|---------------|
| Unit | `AlterTableDropConstraintSQLTest`, `UpdateDataSQLTest`,
`MySQLDialectQuoteTest`, `ArrayDiffTest`, `AlterTableEngineSQLTest`,
`InsertDataSQLTest`, `DropTableSQLTest`, `AddTableSQLTest`,
`MemoryLimitTest` |
| E2E | `End2EndTest::testHyphenatedDatabaseNames` (Bug 3) |
| Comprehensive | `AbstractComprehensiveTest::testViewsExcludedFromDiff`
(Bug 6), `::testNullableColumnDataDetected` (Bug 7) |
| Baselines | All PostgreSQL 14–18 and SQLite comprehensive/e2e
baselines updated for Bug 8's new column-list INSERT format |

---

### Configurable memory limit

The CLI entry points (`dbdiff`, `dbdiff.php`, PHAR) now set a default
PHP memory limit of **1G** on startup. PHP's built-in default of 128M is
too low for real-world database sizes. The limit is fully configurable
at three levels (highest wins):

1. `--memory-limit=<value>` CLI flag (e.g. `--memory-limit=2G`)
2. `memory_limit: <value>` top-level key in `.dbdiff` / `dbdiff.yml`
3. `1G` hard default in the entry point scripts

Any PHP shorthand is accepted (`512M`, `1G`, `2G`, `-1` for unlimited).
The `ini_set` lives only in the CLI entry points — library consumers
embedding DBDiff via Composer are unaffected.

---

### SonarQube
- Trailing whitespace removed from `LocalTableData.php` L413–414
- `\RuntimeException` replaced with dedicated
`InvalidConstraintException` in `AlterTableDropConstraintSQL`
- `$memory_limit` renamed to `$memoryLimit` in `DefaultParams` to match
camelCase convention
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants