Skip to content

fix: DynamoDB placeholder generation no longer overwrites caller values - #4836

Open
TrueFurina wants to merge 2 commits into
boto:developfrom
TrueFurina:fix-4831
Open

TrueFurina wants to merge 2 commits into
boto:developfrom
TrueFurina:fix-4831

Conversation

@TrueFurina

Copy link
Copy Markdown

Fixes #4831

Problem: ConditionExpressionBuilder restarts placeholder numbering at #n0/:v0 on every request, and the generated placeholders are merged over the caller's with dict.update — so a caller-supplied #n0/:v0 gets silently overwritten and the expression resolves to the wrong value.

Fix: after reset(), start placeholder numbering after the highest #n / :v index the caller already provided, so generated placeholders never collide with the caller's ExpressionAttributeNames/ExpressionAttributeValues.

@TrueFurina
TrueFurina requested a review from a team as a code owner August 28, 2026 03:11
@TrueFurina

Copy link
Copy Markdown
Author

Nudging this politely. The behavioral delta is narrow: dynamodb.types placeholder generation could overwrite entries in the caller's ExpressionAttributeValues/Names dicts when the same placeholder was regenerated, so mutating callers (reusing a dict across update_item calls) saw values silently replaced. After the fix the generator copies before merging. No checks are configured on this fork branch, so pending likely just reflects that. If boto3's direction is that callers must not reuse these dicts, I'm fine closing this in favor of a docs note instead — guidance appreciated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DynamoDB: Attr-generated placeholders overwrite the caller's ExpressionAttributeValues

1 participant