Skip to content

JDBC Driver: PreparedStatement counts ? placeholders inside SQL comments (regression since 0.1.36) #2835

Description

@enaviduka-bit

Problem

When a SQL query contains parameters inside comments (e.g. -- filter by ${param}
which gets replaced with -- filter by ? before reaching the driver), the driver
counts those ? placeholders inside comments as actual parameters.

This causes:

  • Old driver (ru.yandex, 0.1.x): ArrayIndexOutOfBoundsException: Index 2 out of bounds for length 2
  • New driver (com.clickhouse, 0.3+): Parameter index must between 1 and 2 but we got 3

Example SQL (after parameter substitution by the application)

-- filter by ? and ?
SELECT *
FROM my_table
WHERE severity = ?
  AND status = ?

Driver sees 4 placeholders, application binds 2 values → exception.

Expected behavior

? inside SQL comments (-- and /* */) should be ignored when counting
PreparedStatement parameter placeholders.

Versions tested

All versions below have this bug:

  • 0.2.6
  • 0.3.2
  • 0.4.6
  • 0.5.0
  • 0.7.2 (with both com.clickhouse.jdbc.ClickHouseDriver and ru.yandex.clickhouse.ClickHouseDriver)
  • 0.9.8 (with ClickHouseDriver, DriverV1, and jdbc_sql_parser=JAVACC/ANTLR4/ANTLR4_PARAMS_PARSER)

Working version

clickhouse-jdbc-0.1.36 (ru.yandex.clickhouse.ClickHouseDriver) correctly ignores
? inside comments.

Environment

  • ClickHouse server: 25.3 / 25.8
  • Pentaho 9.4 (CDA/PRE data access)
  • Java 11

Activity

  1. added this to the 0.11.0 milestone on Aug 31, 2026
  2. chernser commented on Sep 25, 2026

    @chernser
    Contributor

    @polyglotAI-bot verify if there is an issue still. Add tests and minimum

  3. polyglotAI-bot commented on Sep 25, 2026

    @polyglotAI-bot
    Collaborator

    @chernser verified on current main: the reported defect no longer reproduces. A ? inside a -- or /* */ comment is not counted as a parameter placeholder by either driver.

    The issue's own example reports 2 parameters (not 4):

    -- filter by ? and ?
    SELECT * FROM my_table WHERE severity = ? AND status = ?

    jdbc-v1 had no test pinning this, so I opened #3154 with tests only (no production change): a @DataProvider on JdbcParameterizedQueryTest covering the comment forms, an empty comment, a ; inside a comment, a nested block comment and a quoted-literal contrast case, plus an end-to-end PreparedStatement test.

    One residual, jdbc-v1 only, not fixed: the v1 scan still counts a ? inside a //, # or #! comment and inside a heredoc ($$...$$, $tag$...$tag$) — forms the server does accept (confirmed against a live server). That is the same v1 parser gap as #3035 / #3037, which you closed as wontfix for v1 ("requires parser refactor - will be fixed in V2"), so #3154 proposes no v1 parser change and asserts none of those forms. jdbc-v2 handles all of them correctly.

    Suggest closing this issue once #3154 is merged, unless you want the v1 residual tracked separately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions