Skip to content

Conversation

jsha
Copy link
Contributor

@jsha jsha commented Jun 10, 2020

According to
https://github.blog/2020-05-20-three-bugs-in-the-go-mysql-driver/, when
QueryContext is called with a context that is cancelled during scan, you
can receive incomplete or corrupted results. This can cause security bugs.
As I understand it, the corruption is fixed upstream, but it's still possible
to get incomplete results that will only show up in the error result from Close.

It's still possible and correct to call defer rows.Close(), since the
database/sql docs say this:

https://godoc.org/database/sql#Rows.Close

Close is idempotent and does not affect the result of Err.

According to
https://github.blog/2020-05-20-three-bugs-in-the-go-mysql-driver/, when
QueryContext is called with a context that is cancelled during scan, you
can receive incomplete or corrupted results. As I understand it, the
corruption is fixed upstream, but it's still possible to get incomplete
results that will only show up in the error result from Close.

It's still possible and correct to call `defer rows.Close()`, since the
database/sql docs say this:

https://godoc.org/database/sql#Rows.Close

> Close is idempotent and does not affect the result of Err.
pgporada pushed a commit to letsencrypt/borp that referenced this pull request Jul 5, 2023
According to
https://github.blog/2020-05-20-three-bugs-in-the-go-mysql-driver/, when
QueryContext is called with a context that is cancelled during scan, you
can receive incomplete or corrupted results. As I understand it, the
corruption is fixed upstream, but it's still possible to get incomplete
results that will only show up in the error result from Close.

It's still possible and correct to call `defer rows.Close()`, since the
database/sql docs say this:

https://godoc.org/database/sql#Rows.Close

> Close is idempotent and does not affect the result of Err.

Note: This is a recreation of go-gorp#420

Co-authored-by: Jacob Hoffman-Andrews <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant