[PATCH] pg_combinebackup: make the OID range check in parse_oid() effective

From: Egor Ivkov <e(dot)ivkov(at)arenadata(dot)io>
To: "pgsql-hackers(at)lists(dot)postgresql(dot)org" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: [PATCH] pg_combinebackup: make the OID range check in parse_oid() effective
Date: 2026-09-22 20:10:03
Message-ID: 64321790107663@mail.360.yandex.ru
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers



Hi,


 


parse_oid() in pg_combinebackup assigns the result of strtoul() to an Oid


before range-checking it:


 


    Oid         oid;


    ...


    oid = strtoul(s, &ep, 10);


    if (errno != 0 || *ep != '\0' || oid < 1 || oid > PG_UINT32_MAX)


        return false;


 


Since Oid is 32 bits, the value has already been truncated by the time


"oid > PG_UINT32_MAX" is evaluated, so on platforms where unsigned long is


wider than 32 bits that test can never fire.  An out-of-range string is


then accepted as its truncated value rather than being rejected:


"4294967297" is accepted as OID 1, and "-1" is accepted as OID 4294967295.


 


parse_oid() is only fed directory names found under pg_tblspc, so the


practical consequence is limited: pg_combinebackup treats a bogus


directory name as a valid tablespace OID instead of ignoring it.  It still


seems worth fixing.


 


The attached patch keeps the parsed value in an unsigned long until it has


been checked and casts to Oid afterwards, matching what


parse_relfilenumber() in pg_upgrade already does.


 


The patch is against master.  The same code is present unchanged back to


v17 (dc212340058), and the patch applies cleanly to REL_17_STABLE,


REL_18_STABLE and REL_19_STABLE.


 


Regards,


Egor Ivkov

Attachment Content-Type Size
unknown_filename text/html 1.6 KB
v1-0001-pg_combinebackup-make-the-OID-range-check-in-pars.patch text/x-diff 1.7 KB

Browse pgsql-hackers by date

  From Date Subject
Next Message Manu 2026-09-22 20:14:28 Re: [BUG?] check_exclusion_or_unique_constraint false negative
Previous Message Jeff Davis 2026-09-22 20:06:29 Re: JSON_TABLE: table => column ON ERROR propagation