Re: Way to get connection params on failure?

Marc Abramowitz <[email protected]>
Newsgroups gmane.comp.db.tds.freetds
Message-ID <CAAgNOZ3UDhgP3Fqwrva9CPtLNf5PwGumXBg3r1L9Bc=or7MUTQ@mail.gmail.com>
Hi Freddy,

I just updated the merge request so that I don't access the DSTR fields
directly.

As for the buffer being freed, I also had concerns about that, but I think
it's okay. You will notice that this code is very similar to the code right
above it for doing the dynamic parameter substitution -- they both do:

```
        constructed_message.msgtext = buffer;
```

Then later on this happens:

```
  /* we're done with the dynamic string now. */
  free((char*) constructed_message.msgtext);
```

so that should free the buffer. So I think it's good.

I have not looked at libtds. pymssql only uses dblib, so I don't have a use
case and it would be harder for me to test. Perhaps someone else would be
better suited for moving it to libtds?

Let me know if other changes are needed or if you want the commits
squashed, etc.

Cheers,
Marc


On Thu, Jan 9, 2014 at 3:19 AM, Frediano Ziglio <[email protected]> wrote:

> Hi,
>   Dstr fields should not be acccessed directly. Are you sure buffer is
> freed?
>
> Beside this patch looks good. Perhaps should be moved in libtds so all
> layers will use this code.
>
> About dynamic parameters values should be controlled as are only errors
> from our library, not from server
>
> Frediano
> Il 06/gen/2014 19:08 "Marc Abramowitz" <[email protected]> ha scritto:
>
> > On Sun, Jan 5, 2014 at 11:32 AM, Frediano Ziglio <[email protected]>
> > wrote:
> >
> > > The problem of your implementation is that TDSECONN is passed by
> > > libTDS and not all libraries add the required parameter so you can
> > > have a not formatted string in other libraries.
> > >
> > > Mixing normal string and string with format looks a bit security
> suspect
> > > to me.
> > >
> >
> > Yeah, that smelled a little funny to me too.
> >
> > I updated my PR so that dbperror itself appends the server_name, if
> > available, to the error message. So no need to pass it into dbperror.
> >
> > https://gitorious.org/freetds/freetds/merge_requests/24/diffs
> >
> > Hopefully, that's better.
> >
> > Marc
> > _______________________________________________
> > FreeTDS mailing list
> > [email protected]
> > http://lists.ibiblio.org/mailman/listinfo/freetds
> >
> _______________________________________________
> FreeTDS mailing list
> [email protected]
> http://lists.ibiblio.org/mailman/listinfo/freetds
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.