| From: | David Rowley <dgrowleyml(at)gmail(dot)com> |
|---|---|
| To: | 1950233439(at)qq(dot)com, pgsql-bugs(at)lists(dot)postgresql(dot)org |
| Subject: | Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts |
| Date: | 2026-10-01 02:22:44 |
| Message-ID: | CAApHDvpLyFmTL-LmOBucG42Zz+3ytkSFGAJsbohVhVS2eydQxQ@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-bugs |
On Fri, 11 Sept 2026 at 00:11, PG Bug reporting form
<noreply(at)postgresql(dot)org> wrote:
> `int8shl()` and `int8shr()` in `src/backend/utils/adt/int8.c` (lines
> 1255–1270) apply `arg1 << arg2` and `arg1 >> arg2` directly on `int64`
> without validating the shift amount `arg2`. Under C11 §6.5.7, shifting by a
> negative count, by a count ≥ 64, or left-shifting a signed value into
> overflow are all undefined behavior. Every other bigint arithmetic operator
> in PostgreSQL (`+`, `-`, `*`, unary `-`) raises `ERROR: bigint out of range`
> on overflow, making the shift operators the sole exception and creating a
> semantic inconsistency that can silently corrupt permission bitmasks or
> financial calculations.
There has been a documentation-only fix to mention that this behaviour
is intended in [1].
David
[1] https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5229d4b31
| From | Date | Subject | |
|---|---|---|---|
| Next Message | shihao zhong | 2026-10-01 03:04:19 | Re: BUG #19705: One NaN box makes a BRIN box_inclusion_ops index omit unrelated rows |
| Previous Message | Michael Paquier | 2026-09-30 23:53:40 | Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ |