Re: Fix out-of-bounds array indexing in JsonValueList

From: Greg Burd <greg(at)burd(dot)me>
To: Peter Eisentraut <peter(at)eisentraut(dot)org>
Cc: Tristan Partin <tristan(at)partin(dot)io>, pgsql-hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Subject: Re: Fix out-of-bounds array indexing in JsonValueList
Date: 2026-10-05 14:37:09
Message-ID: AA25318C-5CF5-48A1-AD87-52C50CA790A2@burd.me
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers


> On Oct 5, 2026, at 7:51 AM, Peter Eisentraut <peter(at)eisentraut(dot)org> wrote:
>
> On 29.09.26 07:50, Peter Eisentraut wrote:
>> On 29.09.26 06:04, Tristan Partin wrote:
>>> When compiling Postgres with -fsanitize=bounds, I get the following
>>> errors in the log:
>>>
>>> jsonpath_exec.c:3832:3: runtime error: index 3 out of bounds for
>>> type 'JsonbValue[2]'
>>> jsonpath_exec.c:3918:10: runtime error: index 3 out of bounds for
>>> type 'JsonbValue[2]'
>>
>> I've run into this problem as well, but only when compiling with -
>> fstrict-flex-arrays=1. Is that what you are using?
>>
>> I would like to get this fixed, because this site appears to be the only
>> problem of this kind. I will check your proposal.
>
> I played around with this a bit more and came up with the attached
> solution, which is much simpler but requires that we don't go higher
> than -fstrict-flex-arrays=1 -- which we can't anyway for other reasons
> shown in the patch.
> <v1.5-0001-Add-compiler-option-fstrict-flex-arrays-1.patch>

Thanks Peter.

I took a look. It seems to make the right trade-offs for where we are
and add value where we can. I like the use of the union, too bad that
struct isn't at the end so we could use FLEXIBLE_ARRAY_MEMBER.

+1

-greg

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Matthias van de Meent 2026-10-05 14:39:17 Re: Let an ordering index scan hand its ORDER BY value to the target list
Previous Message Lucas Jeffrey 2026-10-05 14:31:43 Re: Re: Re: [PATCH] Fix segmentation fault caused by reentrancy in RI_Fkey_cascade_del (ri_triggers.c)