| From: | Manu <manuelreyesbravo(at)gmail(dot)com> |
|---|---|
| To: | pgsql-bugs(at)lists(dot)postgresql(dot)org |
| Cc: | chaturvedipalak1911(at)gmail(dot)com, kehan5800(at)gmail(dot)com |
| Subject: | Re: BUG #19701: GIN trigram index loses rows at similarity_threshold 0 |
| Date: | 2026-10-02 18:01:07 |
| Message-ID: | 179096406728.463468.10787135519393288680@gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-bugs |
Hi Palak,
> No further comments from me. The patch look good to me.
Thanks for the review.
Before anyone picks it up: cfbot fails v2 on the two Linux tasks
(CF 7382). Those builds use -fsanitize=undefined, and the server aborts
on the new "'' <<% t" query:
runtime error: load of value 126, which is not a valid value for
type 'bool' (calc_word_similarity, trgm_op.c:922)
The bug is not in v2; v2 only reaches it. After its merge loop,
calc_word_similarity() reads found[j] once more. When neither string
has a trigram, found[] has no elements and that read is past its end
(126 is 0x7E, the sentinel byte after a chunk in cassert builds).
Master does the same with "SELECT word_similarity('', '')". The value
never changes the result: with no trigrams in the second string the
similarity is 0 without using it.
v3 attached:
0001 checks len > 0 before that read, with a test for
word_similarity('', '').
0002 is v2, unchanged.
Built with the same sanitizer flags as cfbot, plus --enable-cassert:
master, 0001's test without its fix: aborts
master + v2: aborts on '' <<% t
master + v3: all 4 pg_trgm tests pass
REL_14_STABLE + v3: all 4 pg_trgm tests pass
Regards,
Manu
| Attachment | Content-Type | Size |
|---|---|---|
| v3-0001-Fix-out-of-bounds-read-in-pg_trgm-word-similarity.patch | text/x-patch | 2.6 KB |
| v3-0002-Don-t-lose-rows-in-pg_trgm-index-scans-with-a-zer.patch | text/x-patch | 11.0 KB |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Nate Clark | 2026-10-02 18:20:03 | Re: BUG #19720: pg_trgm GiST index corruption from gtrgm_union() dropping SIGNKEY |
| Previous Message | mostafa nabil | 2026-10-02 09:21:52 | Re: BUG #19628: Uninterruptible vacuum during hash index processing |