[PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack

From: Vadim Shakirov <vadimsakirov5(at)gmail(dot)com>
To: pgsql-hackers(at)lists(dot)postgresql(dot)org
Subject: [PATCH v1] Fix out-of-bounds access in pg_bsd_indent's parser stack
Date: 2026-09-30 10:51:34
Message-ID: 20260930105134.568062-1-vadimsakirov5@gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

parser_state stores parser state in p_stack, il, and cstk, which
share the tos index. The existing overflow check used p_stack, the
largest array, allowing out-of-bounds accesses to cstk and il. Size
all three arrays equally.

Also widen the overflow check by one element: the lbrace case pushes
two entries (lbrace and then stmt), so there must be room for two
more elements when parse() is entered.
---
src/tools/pg_bsd_indent/indent_globs.h | 4 ++--
src/tools/pg_bsd_indent/parse.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/src/tools/pg_bsd_indent/indent_globs.h b/src/tools/pg_bsd_indent/indent_globs.h
index 917961bd3d6..e88dd52c891 100644
--- a/src/tools/pg_bsd_indent/indent_globs.h
+++ b/src/tools/pg_bsd_indent/indent_globs.h
@@ -234,8 +234,8 @@ extern int ifdef_level;
struct parser_state {
int last_token;
int p_stack[256]; /* this is the parsers stack */
- int il[64]; /* this stack stores indentation levels */
- float cstk[32]; /* used to store case stmt indentation levels */
+ int il[256]; /* this stack stores indentation levels */
+ float cstk[256]; /* used to store case stmt indentation levels */
int box_com; /* set to true when we are in a "boxed"
* comment. In that case, the first non-blank
* char should be lined up with the / in / followed by * */
diff --git a/src/tools/pg_bsd_indent/parse.c b/src/tools/pg_bsd_indent/parse.c
index 94cea724393..f50a03193e1 100644
--- a/src/tools/pg_bsd_indent/parse.c
+++ b/src/tools/pg_bsd_indent/parse.c
@@ -203,7 +203,7 @@ parse(int tk) /* tk: the code for the construct scanned */

} /* end of switch */

- if (ps.tos >= nitems(ps.p_stack) - 1)
+ if (ps.tos >= nitems(ps.p_stack) - 2)
errx(1, "Parser stack overflow");

reduce(); /* see if any reduction can be done */
--
2.43.0

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message jian he 2026-09-30 11:04:25 Re: on_error table, saving error info to a table
Previous Message Etsuro Fujita 2026-09-30 10:50:59 Re: Typo in version check in postgresAcquireSampleRowsFunc