-
Notifications
You must be signed in to change notification settings - Fork 317
Fixing NullReferenceException issue with SqlDataAdapter #3749
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This pull request adds a null check for systemParams before accessing its Length property in the parameter encryption metadata retrieval logic. This defensive programming change prevents a potential NullReferenceException when processing RPC batch commands.
Key Changes
- Added null check for
_RPCList[i].systemParamsbefore accessing itsLengthproperty inTryFetchInputParameterEncryptionInfomethod
Comments suppressed due to low confidence (1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlCommand.Encryption.cs:1296
- The added null check for
systemParamslacks test coverage. Based on the code analysis,systemParamsis initialized throughGetRPCObject()which always allocates and initializes the array whensystemParamCount > 0. However, a newly constructed_SqlRPCobject (as seen inAddBatchCommandline 21) hassystemParamsinitially null. A test case should be added that exercises the batch RPC mode encryption path with an RPC object that has not yet had itssystemParamsinitialized to verify this defensive check works correctly.
if (_RPCList[i].systemParams != null && _RPCList[i].systemParams.Length > 1)
src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlCommand.Encryption.cs
Show resolved
Hide resolved
paulmedynski
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Need some tests for this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated 4 comments.
...crosoft.Data.SqlClient/tests/ManualTests/Microsoft.Data.SqlClient.ManualTesting.Tests.csproj
Outdated
Show resolved
Hide resolved
| var dt = new DataTable(tableNames["BuyerSeller"]); | ||
| dt.Columns.AddRange(new[] | ||
| { | ||
| new DataColumn("BuyerSellerID", typeof(int)), |
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Disposable 'DataColumn' is created but not disposed.
| dt.Columns.AddRange(new[] | ||
| { | ||
| new DataColumn("BuyerSellerID", typeof(int)), | ||
| new DataColumn("SSN1", typeof(string)), |
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Disposable 'DataColumn' is created but not disposed.
| { | ||
| new DataColumn("BuyerSellerID", typeof(int)), | ||
| new DataColumn("SSN1", typeof(string)), | ||
| new DataColumn("SSN2", typeof(string)), |
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Disposable 'DataColumn' is created but not disposed.
apoorvdeshmukh
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There are build failures while compiling the tests.
| <Compile Include="SQL\ConnectionPoolTest\ConnectionPoolTest.Debug.cs" /> | ||
| </ItemGroup> | ||
| <ItemGroup> | ||
| <Compile Include="AlwaysEncrypted\SqlDataAdapterBatchUpdateTests.cs" /> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If you have dependency on AE related setup, consider including this in AE TestSet.
…SqlClient.ManualTesting.Tests.csproj Co-authored-by: Copilot <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.
| catch (SqlException) { /* Swallow for cleanup */ } | ||
| } | ||
|
|
||
| public void Dispose() |
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The test class does not implement IDisposable. The Dispose() method on line 217 will not be called automatically by xUnit since the class doesn't implement IDisposable interface. Either implement IDisposable or remove the Dispose method if cleanup is handled by the fixture.
| // Mutate values for update | ||
| MutateForUpdate(dataTable); | ||
|
|
||
| // Act - This is where NullReferenceException was being thrown previously(which is now fixed) |
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Missing space after 'previously' in the comment.
| // Act - This is where NullReferenceException was being thrown previously(which is now fixed) | |
| // Act - This is where NullReferenceException was being thrown previously (which is now fixed) |
| ExecuteQuery(connection, | ||
| $@"INSERT INTO [dbo].[{tableNames[tableName]}] (BuyerSellerID, SSN1, SSN2) VALUES ({id}, '{s1}', '{s2}')"); | ||
| } | ||
| } | ||
|
|
Copilot
AI
Nov 11, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Potential SQL injection vulnerability: The test data values are directly concatenated into the INSERT statement without parameterization. While this is test code and values are controlled, it violates security best practices and could cause issues if the test data contains quotes or special characters. Consider using parameterized queries even in test code to follow best practices and avoid potential issues.
| ExecuteQuery(connection, | |
| $@"INSERT INTO [dbo].[{tableNames[tableName]}] (BuyerSellerID, SSN1, SSN2) VALUES ({id}, '{s1}', '{s2}')"); | |
| } | |
| } | |
| ExecuteParameterizedInsert(connection, tableNames[tableName], id, s1, s2); | |
| } | |
| } | |
| private void ExecuteParameterizedInsert(SqlConnection connection, string tableName, int id, string s1, string s2) | |
| { | |
| using var cmd = new SqlCommand( | |
| $@"INSERT INTO [dbo].[{tableName}] (BuyerSellerID, SSN1, SSN2) VALUES (@id, @s1, @s2)", | |
| connection, | |
| transaction: null, | |
| columnEncryptionSetting: SqlCommandColumnEncryptionSetting.Enabled); | |
| cmd.Parameters.Add(new SqlParameter("@id", SqlDbType.Int) { Value = id }); | |
| cmd.Parameters.Add(new SqlParameter("@s1", SqlDbType.NVarChar, 50) { Value = s1 ?? (object)DBNull.Value }); | |
| cmd.Parameters.Add(new SqlParameter("@s2", SqlDbType.NVarChar, 50) { Value = s2 ?? (object)DBNull.Value }); | |
| cmd.ExecuteNonQuery(); | |
| } |
|
@priyankatiwari08 please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement ( “Agreement” ) is agreed to by the party signing below ( “You” ), 1. Definitions. “Code” means the computer software code, whether in human-readable or machine-executable form, “Project” means any of the projects owned or managed by .NET Foundation and offered under a license “Submit” is the act of uploading, submitting, transmitting, or distributing code or other content to any “Submission” means the Code and any other copyrightable material Submitted by You, including any 2. Your Submission. You must agree to the terms of this Agreement before making a Submission to any 3. Originality of Work. You represent that each of Your Submissions is entirely Your 4. Your Employer. References to “employer” in this Agreement include Your employer or anyone else 5. Licenses. a. Copyright License. You grant .NET Foundation, and those who receive the Submission directly b. Patent License. You grant .NET Foundation, and those who receive the Submission directly or c. Other Rights Reserved. Each party reserves all rights not expressly granted in this Agreement. 6. Representations and Warranties. You represent that You are legally entitled to grant the above 7. Notice to .NET Foundation. You agree to notify .NET Foundation in writing of any facts or 8. Information about Submissions. You agree that contributions to Projects and information about 9. Governing Law/Jurisdiction. This Agreement is governed by the laws of the State of Washington, and 10. Entire Agreement/Assignment. This Agreement is the entire agreement between the parties, and .NET Foundation dedicates this Contribution License Agreement to the public domain according to the Creative Commons CC0 1. |
Description
This Pull Request addresses issue #3716 by introducing a null check for systemParams, which stores the system-level parameters for SQL RPC (Remote Procedure Call) operations. In batch scenarios, certain SQL RPC calls may not include system parameters, and this change ensures proper handling in such cases.
Issues
#3716