Re: Fix out-of-bounds array indexing in JsonValueList

From: "Tristan Partin" <tristan(at)partin(dot)io>
To: "Greg Burd" <greg(at)burd(dot)me>, "Peter Eisentraut" <peter(at)eisentraut(dot)org>
Cc: "pgsql-hackers" <pgsql-hackers(at)lists(dot)postgresql(dot)org>, "Tom Lane" <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Subject: Re: Fix out-of-bounds array indexing in JsonValueList
Date: 2026-10-06 21:41:31
Message-ID: DLY2YVZS10MH.2JNDFEMHDZTEP@partin.io
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Mon Oct 5, 2026 at 2:37 PM UTC, Greg Burd wrote:
>
>> On Oct 5, 2026, at 7:51 AM, Peter Eisentraut <peter(at)eisentraut(dot)org> wrote:
>>
>> On 29.09.26 07:50, Peter Eisentraut wrote:
>>> On 29.09.26 06:04, Tristan Partin wrote:
>>>> When compiling Postgres with -fsanitize=bounds, I get the following
>>>> errors in the log:
>>>>
>>>> jsonpath_exec.c:3832:3: runtime error: index 3 out of bounds for
>>>> type 'JsonbValue[2]'
>>>> jsonpath_exec.c:3918:10: runtime error: index 3 out of bounds for
>>>> type 'JsonbValue[2]'
>>>
>>> I've run into this problem as well, but only when compiling with -
>>> fstrict-flex-arrays=1. Is that what you are using?
>>>
>>> I would like to get this fixed, because this site appears to be the only
>>> problem of this kind. I will check your proposal.
>>
>> I played around with this a bit more and came up with the attached
>> solution, which is much simpler but requires that we don't go higher
>> than -fstrict-flex-arrays=1 -- which we can't anyway for other reasons
>> shown in the patch.
>> <v1.5-0001-Add-compiler-option-fstrict-flex-arrays-1.patch>
>
> Thanks Peter.
>
> I took a look. It seems to make the right trade-offs for where we are
> and add value where we can. I like the use of the union, too bad that
> struct isn't at the end so we could use FLEXIBLE_ARRAY_MEMBER.

I concur with Greg that it looks fine. Attached is another potential
solution if we didn't want treewide -fstrict-flex-arrays=1. I saw that
GCC supports a strict_flex_array attribute, which Clang does not
currently support. Your solution is probably better for that reason, but
I figured that I would post this anyway.

--
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)

Attachment Content-Type Size
strict-flex-arrays.diff text/x-patch 2.3 KB

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Tristan Partin 2026-10-06 21:56:47 Re: Add ASCII fast path to Unicode normalization functions
Previous Message Andrew Dunstan 2026-10-06 21:38:57 Re: [PG19] COPY (query) TO ... (FORMAT json) uses the table's column names