Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts

From: David Rowley <dgrowleyml(at)gmail(dot)com>
To: 1950233439(at)qq(dot)com, pgsql-bugs(at)lists(dot)postgresql(dot)org
Subject: Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts
Date: 2026-10-01 02:22:44
Message-ID: CAApHDvpLyFmTL-LmOBucG42Zz+3ytkSFGAJsbohVhVS2eydQxQ@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

On Fri, 11 Sept 2026 at 00:11, PG Bug reporting form
<noreply(at)postgresql(dot)org> wrote:
> `int8shl()` and `int8shr()` in `src/backend/utils/adt/int8.c` (lines
> 1255–1270) apply `arg1 << arg2` and `arg1 >> arg2` directly on `int64`
> without validating the shift amount `arg2`. Under C11 §6.5.7, shifting by a
> negative count, by a count ≥ 64, or left-shifting a signed value into
> overflow are all undefined behavior. Every other bigint arithmetic operator
> in PostgreSQL (`+`, `-`, `*`, unary `-`) raises `ERROR: bigint out of range`
> on overflow, making the shift operators the sole exception and creating a
> semantic inconsistency that can silently corrupt permission bitmasks or
> financial calculations.

There has been a documentation-only fix to mention that this behaviour
is intended in [1].

David

[1] https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5229d4b31

In response to

Browse pgsql-bugs by date

  From Date Subject
Next Message shihao zhong 2026-10-01 03:04:19 Re: BUG #19705: One NaN box makes a BRIN box_inclusion_ops index omit unrelated rows
Previous Message Michael Paquier 2026-09-30 23:53:40 Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ