Make sure that SELECT argument is an integer or return an error.

Unfortunately we had still the lame atoi() without any error checking in
place, so "SELECT foo" would work as "SELECT 0". This was not an huge
problem per se but some people expected that DB can be strings and not
just numbers, and without errors you get the feeling that they can be
numbers, but not the behavior.

Now getLongFromObjectOrReply() is used as almost everybody else across
the code, generating an error if the number is not an integer or
overflows the long type.

Thanks to @mipearson for reporting that on Twitter.
1 parent 03a851e commit 3756e141a1c66ab52d272fc4688803b4897954de @antirez committed Sep 11, 2012
Showing with 5 additions and 1 deletion.
  1. +5 −1 src/db.c
6 src/db.c
@@ -244,7 +244,11 @@ void existsCommand(redisClient *c) {
void selectCommand(redisClient *c) {
- int id = atoi(c->argv[1]->ptr);
+ long id;
+ if (getLongFromObjectOrReply(c, c->argv[1], &id,
+ "invalid DB index") != REDIS_OK)
+ return;
if (selectDb(c,id) == REDIS_ERR) {
addReplyError(c,"invalid DB index");

