| From: | Greg Burd <greg(at)burd(dot)me> |
|---|---|
| To: | Peter Eisentraut <peter(at)eisentraut(dot)org> |
| Cc: | Tristan Partin <tristan(at)partin(dot)io>, pgsql-hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
| Subject: | Re: Fix out-of-bounds array indexing in JsonValueList |
| Date: | 2026-10-05 14:37:09 |
| Message-ID: | AA25318C-5CF5-48A1-AD87-52C50CA790A2@burd.me |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
> On Oct 5, 2026, at 7:51 AM, Peter Eisentraut <peter(at)eisentraut(dot)org> wrote:
>
> On 29.09.26 07:50, Peter Eisentraut wrote:
>> On 29.09.26 06:04, Tristan Partin wrote:
>>> When compiling Postgres with -fsanitize=bounds, I get the following
>>> errors in the log:
>>>
>>> jsonpath_exec.c:3832:3: runtime error: index 3 out of bounds for
>>> type 'JsonbValue[2]'
>>> jsonpath_exec.c:3918:10: runtime error: index 3 out of bounds for
>>> type 'JsonbValue[2]'
>>
>> I've run into this problem as well, but only when compiling with -
>> fstrict-flex-arrays=1. Is that what you are using?
>>
>> I would like to get this fixed, because this site appears to be the only
>> problem of this kind. I will check your proposal.
>
> I played around with this a bit more and came up with the attached
> solution, which is much simpler but requires that we don't go higher
> than -fstrict-flex-arrays=1 -- which we can't anyway for other reasons
> shown in the patch.
> <v1.5-0001-Add-compiler-option-fstrict-flex-arrays-1.patch>
Thanks Peter.
I took a look. It seems to make the right trade-offs for where we are
and add value where we can. I like the use of the union, too bad that
struct isn't at the end so we could use FLEXIBLE_ARRAY_MEMBER.
+1
-greg
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Matthias van de Meent | 2026-10-05 14:39:17 | Re: Let an ordering index scan hand its ORDER BY value to the target list |
| Previous Message | Lucas Jeffrey | 2026-10-05 14:31:43 | Re: Re: Re: [PATCH] Fix segmentation fault caused by reentrancy in RI_Fkey_cascade_del (ri_triggers.c) |