Re: BUG #19730: PostgreSQL `pg_backup_start` accepts newlines in the backup label, producing an unrestorable `backup

From: shihao zhong <zhong950419(at)gmail(dot)com>
To: Michael Paquier <michael(at)paquier(dot)xyz>
Cc: "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>, "theshallow27(at)gmail(dot)com" <theshallow27(at)gmail(dot)com>, "pgsql-bugs(at)lists(dot)postgresql(dot)org" <pgsql-bugs(at)lists(dot)postgresql(dot)org>
Subject: Re: BUG #19730: PostgreSQL `pg_backup_start` accepts newlines in the backup label, producing an unrestorable `backup
Date: 2026-10-02 04:07:41
Message-ID: CAGRkXqS7znpXT6P-iLnTZthnMm1EtUx+N8yZ-WSkU3i38vi1fg@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

> In short, I'm on board with the addition of an extra check that
> enforces this policy in do_pg_backup_start()
>
> Perhaps we should add one test query somewhere in a TAP script of
> src/test/recovery/, while on it.

Fair enough. Patch attached. It is the check from the report, with
the error wording of b380a56a3f95, and a test next to the "backup
label too long" one in 020_archive_status.pl.

One thing to note. A label that ends with a newline works today, and
this patch rejects it. A script that reads the label from a file can
hit that, so I think this should go to master only.

Thanks,
Shihao

Attachment Content-Type Size
v1-0001-Reject-CR-and-LF-in-backup-labels.patch application/octet-stream 2.4 KB

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Michael Paquier 2026-10-02 04:32:20 Re: BUG #19730: PostgreSQL `pg_backup_start` accepts newlines in the backup label, producing an unrestorable `backup
Previous Message Michael Paquier 2026-10-02 03:49:27 Re: BUG #19730: PostgreSQL `pg_backup_start` accepts newlines in the backup label, producing an unrestorable `backup